ISC°ä²¼¸üУ¬½¨¸´BIND DNSÈí¼þÖеĶà¸ö°²È«·ì϶

°ä²¼¹¦·ò 2022-09-27
1¡¢ISC°ä²¼¸üУ¬½¨¸´BIND DNSÈí¼þÖеĶà¸ö°²È«·ì϶

      

9ÔÂ21ÈÕ£¬Internet Systems Consortium(ISC)°ä²¼°²È«¸üУ¬½¨¸´BIND DNSÈí¼þÖеĶà¸ö¿ÉÔ¶³ÌÀûÓõķì϶¡£ÆäÖнÏΪÑϳÁµÄÊÇͨ¹ýTKEY RR´¦ÖÃDiffie-HellmanÃÜÔ¿»¥»»µÄ´úÂëÖеÄÄÚ´æÐ¹Â¶·ì϶£¨CVE-2022-2906£©¡¢ECDSA DNSSECÑéÖ¤ÂëÖеÄÄÚ´æÐ¹Â¶·ì϶£¨CVE-2022-38177£©¡¢¿Éµ¼ÖÂBIND 9½âÎöÆ÷±ÀÀ£µÄ·ì϶£¨CVE-2022-3080£©ºÍEdDSA DNSSECÑéÖ¤ÂëÖеÄй¶·ì϶£¨CVE-2022-38178£©¡£ISC°µÊ¾£¬ÉÐδ·¢ÏÖÉÏÊö·ì϶ÔÚÒ°±í±»ÀûÓõĻ¡£


https://securityaffairs.co/wordpress/136164/security/bind-dns-software-flaws-2.html


2¡¢Google PlayºÍApp StoreÖжà¸ö¸æ°×ÀûÓñ»×°ÖÃ1300Íò´Î

      

¾ÝýÌå9ÔÂ26ÈÕ±¨Â·£¬×êÑÐÈËÔ±ÔÚGoogle PlayÉÏ·¢ÏÖÁË75¸ö¸æ°×ÀûÓã¬ÔÚApp StoreÉÏ·¢ÏÖÁËÁí±í10¸ö¸æ°×ÀûÓã¬×ܹ²±»×°ÖÃÁË1300Íò´Î¡£³ýÁËÏòÊÖ»úÓû§Í¶·Å¿É¼ûºÍ°µ²ØµÄ¸æ°×±í£¬ÕâЩڲƭÀûÓû¹Í¨¹ý¼ÙÒâºÏ·¨µÄÀûÓÃÀ´´´ÊÕ¡£¹ÌÈ»ÕâÖÖÀàÐ͵ÄÀûÓò»´æÔÚÑϳÁµÄÍþв£¬µ«¹¥»÷ÕßÄܹ»ÀûÓÃËüÃǽøÐиüΣÏյĻ¡£×êÑÐÍŶÓÒѽ«ÕâЩ·¢ÏÖ֪ͨGoogleºÍApple£¬Ä¿Ç°ÕâЩÀûÓÃÒÑ´Ó¹Ù·½AndroidºÍiOSÉ̵êÖÐɾ³ý¡£


https://www.bleepingcomputer.com/news/security/adware-on-google-play-and-apple-store-installed-13-million-times/


3¡¢Ó¡¶ÈijҽÁÆÈí¼þ¹«Ë¾Ð¹Â¶170ÍòÈËCovid¿¹Ô­²âÊÔÁ˾Ö

      

ýÌå9ÔÂ25Èճƣ¬Ó¡¶ÈijҽÁÆÈí¼þÌṩÉ̵ÄElasticsearch·þÎñÆ÷й¶ÁË170ÍòÈ˵ÄCovid¿¹Ô­²âÊÔÁ˾Ö¡£AnuragÔÚShodanÉÏɨÃèÅäÖÃÃýÎóµÄÊý¾Ý¿âʱ£¬°ÑÎȵ½Ò»Ì¨·þÎñÆ÷¶³öÁ˳¬¹ý23GBµÄÊý¾Ý¡£ÆäÖÐÔ̺¬´Óǰ¼¸ÄêÍùÀ´ÓÚÓ¡¶ÈµÄÓ¡¶ÈÈ˺ͱí¹úÓο͵ÄÐÅÏ¢£¬ÈçÐÕÃû¡¢¹ú¼®¡¢µØÖ·¡¢µç»°ºÅÂë¡¢Éí·ÝÖ¤ºÅÂë¡¢¼ì²âÁ˾֡¢AadhaarºÅºÍ»¤ÕÕºÅÂëµÈ¡£×êÑÐÈËÔ±°µÊ¾£¬¸ÃÊý¾Ý¿â×Ô2022Äê7ÔÂ2ÈÕÆðͷ¶³ö£¬ÇÒĿǰÈÔ´¦ÓÚ¹«¿ª×´Ì¬¡£


https://www.hackread.com/covid-antigen-test-results-india-leaked/


4¡¢ÎÚ¿ËÀ¼SSUµ·»ÙÔøÇÔÈ¡²¢ÏúÊÛ3000Íò¸öÕË»§µÄºÚ¿ÍÍÅ»ï

      

ýÌå9ÔÂ24ÈÕ±¨Â·³Æ£¬ÎÚ¿ËÀ¼°²È«¾Ö(SSU)µÄÍøÂ粿Ãŵ·»ÙÁËÒ»¸öÔøÇÔÈ¡²¢ÏúÊÛ3000Íò¸öÕË»§µÄºÚ¿ÍÍŻ¾ÝSSU³Æ£¬ËûÃÇ´ÓÕâ´ÎÐж¯ÖлñÀû1400ÍòUAH£¨380000ÃÀÔª£©¡£¹¥»÷Õß×Óͨ¹ý¶ñÒâÈí¼þϰȾÀ´»ñȡʹ´¦ºÍÊý¾Ý£¬ÖØÒªÕë¶ÔÎÚ¿ËÀ¼ºÍÅ·ÃË×éÖ¯µÄϵͳ¡£ËûÃÇ»¹Í¨¹ýÔÚÎÚ¿ËÀ¼±»²»Èݵĵç×ÓÖ§¸¶ÏµÍ³YuMoney¡¢QiwiºÍWebMoneyÊÕ¿î¡£±»²¶µÄÈËÊýÈÔδÅû¶£¬µ«ËûÃǶ¼Òòδ¾­ÊÚȨÏúÊÛ»ò·Ö·¢ÔÚ´æ´¢ÓÚÍÆËã»úºÍÍøÂçÖеĽӼûÊÜÏÞµÄÐÅÏ¢¶øÃæ¶ÔÐÌÊÂËßËϼ°¶àÄê½ûïÀ¡£


https://securityaffairs.co/wordpress/136156/cyber-crime/ukraine-cyber-gang.html


5¡¢Î¢Èí°ä²¼ÀûÓÃOAuthÀûÓù¥»÷Exchange·þÎñÆ÷µÄ·ÖÎö»ã±¨

      

9ÔÂ22ÈÕ£¬Î¢Èí°ä²¼»ã±¨³ÆÆä½üÆÚµ÷²éÁËÒ»ÖÖ¹¥»÷£¬ÆäÖй¥»÷ÕßÔÚ±»Ï°È¾µÄÔÆ×â»§ÖÐ×°ÖöñÒâOAuthÀûÓ÷¨Ê½£¬ÓÃÓÚ½ÚÔìExchange OnlineÉèÖúʹ«²¼À¬»øÓʼþ¡£¹¥»÷ÕßÊ×ÏȶÔδÆôÓÃMFAµÄÏÕÕË»§Ö´ÐÐײ¿â¹¥»÷£¬²¢ÀûÓò»°²È«µÄÖÎÀíÔ¹ØË»§»ñµÃ³õʼ½Ó¼ûȨÏÞ¡£¶øºó£¬¹¥»÷Õ߿ɴ´½¨¶ñÒâOAuthÀûÓ÷¨Ê½£¬¸Ã·¨Ê½»áÔÚµç×ÓÓʼþ·þÎñÆ÷ÖÐÔö³¤¶ñÒâÈëÕ¾ÏÎ½ÓÆ÷¡£×îºó£¬ÀûÓöñÒâÈëÕ¾ÏÎ½ÓÆ÷·¢ËÍ¿´ÆðÀ´ÏñÊÇÀ´×ÔÖ¸±êÓòµÄÀ¬»øÓʼþ¡£


https://www.microsoft.com/security/blog/2022/09/22/malicious-oauth-applications-used-to-compromise-email-servers-and-spread-spam/


6¡¢NSAºÍCISA°ä²¼±£»¤OTºÍICSµÄ¹Ø¼ü»ù´¡ÉèÊ©µÄ°²È«Õ÷ѯ

      

9ÔÂ22ÈÕ£¬CISAºÍNSA½áºÏ°ä²¼Á˹ØÓÚ±£»¤ÔËÓª¼¼Êõ(OT)ºÍ¹¤Òµ½ÚÔìϵͳ(ICS)µÄ¹Ø¼ü»ù´¡ÉèÊ©µÄ½áºÏ°²È«Õ÷ѯ¡£¸Ã²¼¸æ·ÖÏíÁ˹¥»÷ÕßÓÃÀ´·ÛËéÖ§³ÖITµÄOTºÍICS×ʲúµÄËùÓв½ÖèÐÅÏ¢£¬²¢Ç¿µ÷Á˰²È«×¨ÒµÈËÔ±Äܹ»²ÉÈ¡µÄ·ÀÓù´ëÊ©¡£»¹Ö¸³ö£¬ÔËÓª¡¢½ÚÔìºÍ¼à¿ØÈÕ³£¹Ø¼ü»ù´¡ÉèÊ©ºÍ¹¤ÒµÁ÷³ÌµÄOTºÍICS×ʲúÃæ¶ÔµÄÍþвÈÕÒæÔö³¤£¬²¢ÌṩÁËһЩÓÃÀ´Ó¦¶ÔµÐÊÖµÄÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½(TTP)µÄ×î¼Ñ°²È«Êµ¼Ê¡£


https://us-cert.cisa.gov/ncas/current-activity/2022/09/22/cisa-and-nsa-publish-joint-cybersecurity-advisory-control-system