΢Èí°ä²¼·Ç°²È«¸üн¨¸´µ¼ÖÂSSL/TLSÎÕÊÖʧ°ÜµÄÎÊÌâ
°ä²¼¹¦·ò 2022-10-191¡¢Î¢Èí°ä²¼·Ç°²È«¸üн¨¸´µ¼ÖÂSSL/TLSÎÕÊÖʧ°ÜµÄÎÊÌâ
¾Ý10ÔÂ17ÈÕ±¨Â·£¬Î¢ÈíÒѰ䲼´ø±í(OOB)·Ç°²È«¸üУ¬½¨¸´ÓÉ2022Äê10ÔÂWindows°²È«¸üÐÂÒýÆðµÄÔÚ¿Í»§¶ËºÍ·þÎñÆ÷ƽ̨ÉÏ´¥·¢SSL/TLSÎÕÊÖʧ°ÜµÄÎÊÌâ¡£ÔÚ±»Ó°ÏìµÄÉ豸ÉÏ£¬µ±Óë·þÎñÆ÷µÄÏνӳöÏÖÎÊÌâʱ£¬»áÏÔʾSEC_E_ILLEGAL_MESSAGEÃýÎó¡£Î¢ÈíÌáÐÑ£¬ÎÞ·¨Í¨¹ýWindows Update×°ÖøüеÄÓû§£¬¿Éͨ¹ýMicrosoft Update Catalog ²¢ÊÖ¶¯½«ËüÃǵ¼ÈëWSUSºÍMicrosoft Endpoint Configuration ManagerÀ´×°Öá£
https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-windows-tls-handshake-failures-in-out-of-band-updates/
2¡¢HelpSystems´ø±í¸üн¨¸´Cobalt StrikeÖеÄRCE·ì϶
ýÌå10ÔÂ18ÈÕ±¨Â·£¬HelpSystems°ä²¼ÁËÒ»¸ö´ø±í°²È«¸üУ¬ÒÔ½¨¸´ÆäCobalt StrikeÖеÄRCE·ì϶¡£·ì϶׷×ÙΪCVE-2022-42948£¬Ó°ÏìÁËCobalt Strike°æ±¾4.7.1¡£ÆäÔ´ÓÚ2022Äê9ÔÂ20ÈÕ°ä²¼µÄÒ»¸ö²»ÆëÈ«µÄ²¹¶¡£¬¸Ã²¹¶¡ÓÃÓÚ½¨¸´XSS·ì϶(CVE-2022-39197)¡£¹¥»÷ÕßÄܹ»Í¨¹ý²Ù¿Ø¿Í»§¶ËUIÊäÈë×ֶΡ¢·ÂÕÕCSÖ²È뷨ʽǩÈë»òͨ¹ýhookÔÚÖ÷»úÉÏÔËÐеÄCSÖ²È뷨ʽÀ´ÀûÓøÃXSS·ì϶¡£HelpSystems³Æ£¬ÔÚÌØ¶¨Çé¿öÏ£¬Äܹ»ÀûÓÃJava Swing¿ò¼ÜÀ´´¥·¢Ô¶³Ì´úÂëÖ´ÐУ¬Cobalt Strike 4.7.2½¨¸´Á˸÷ì϶¡£
https://thehackernews.com/2022/10/critical-rce-vulnerability-discovered.html
3¡¢¶à¹ú·¨Âɲ¿Ãŵ·»ÙרÃÅÈëÇÖÎÞÔ¿³×ϵͳµÄ³µÁ¾µÄ·¸×ïÍÅ»ï
¾ÝýÌå10ÔÂ17Èճƣ¬·¨¹ú¡¢ÀÍÑάÑǺÍÎ÷°àÑÀ·¨Âɲ¿Ãŵ·»ÙÁËÒ»¸öÀûÓúڿ͹¤¾ßÇÔÈ¡Æû³µµÄÍøÂç·¸×ïÍŻ²¢¿ÛÁôÁË31ÃûÏÓÒÉÈË¡£¹¥»÷ÕßÖ»Õë¶ÔʹÓÃÎÞÔ¿³×½øÈëºÍÆô¶¯ÏµÍ³µÄÆû³µ£¬»áÔÚÀûÓÃËûÃǵÄÎÞÔ¿³×¼¼Êõ½âËø³µÃŲ¢Æô¶¯·¢Æð»úºóµÁ×߯û³µ¡£Õâ´Î·¨ÂÉÐж¯ÓÚ10ÔÂ10ÈÕÆðÍ·£¬¿ÛÁôÁËÀ´×ÔÈý¸ö¹ú¶È22¸öµØÖ·µÄ31ÃûÏÓÒÉÈË£¬ÆäÖÐÔ̺¬Èí¼þ¿ª·¢ÉÌ¡¢¾ÏúÉÌÒÔ¼°Ê¹Óøù¤¾ßÈëÇÔìû³µµÄ͵³µÔô£¬»¹³ä¹«Á˼ÛÖµ1098500Å·ÔªµÄ·¸×ï×ʲú¡£
https://www.bleepingcomputer.com/news/security/police-dismantles-criminal-ring-that-hacked-keyless-cars/
4¡¢µÂ¹úHeilbronn StimmeÔâµ½ÀÕË÷¹¥»÷Ó°Ï챨ֽµÄ¿¯ÐÐ
10ÔÂ17ÈÕ±¨Â·£¬µÂ¹ú±¨ÉçHeilbronn StimmeÔÚÔâµ½ÀÕË÷¹¥»÷ºó´òӡϵͳ̱»¾£¬±»ÆÈÒÔµç×Ó´ó¾Ö³ö°æÐµÄÒ»ÆÚ¡£¹¥»÷²úÉúÔÚÉÏÖÜÎ壬Æäµç»°ºÍµç×ÓÓʼþϵͳÔÚÕû¸öÖÜÄ©ÆÚ¼äÒ»Ïò´¦ÓڹعØ×´Ì¬¡£Ö÷±àUwe Ralf Heer°µÊ¾£¬Õâ´Î¹¥»÷Ó°ÏìÁËÕû¸öStimme MediengruppeýÌ弯ÍÅ£¬ÆäÖÐÔ̺¬Pressedruck¡¢EchoºÍRegioMail¹«Ë¾¡£Heer»¹°µÊ¾£¬½ØÖÁÖÜÁùÏÂÎ磬ºÚ¿Í¶¼Î´Ìá³ö¾ßÌåµÄÊê½ðÒªÇó¡£¹«Ë¾¹¤×÷ÈËÔ±±»ÆÈÔÚ¼ÒÖÐʹÓÃÓ×ÎÒµçÄÔ¹¤×÷£¬¸Ã¹«Ë¾ÔÚµ÷²é´ËÊ£¬²¢×·Çó½â¾ö¼¼ÊõÎÊÌâµÄ²½Öè¡£
https://www.bleepingcomputer.com/news/security/ransomware-attack-halts-circulation-of-some-german-newspapers/
5¡¢ÈÕ±¾¿Æ¼¼¹«Ë¾OomiyaµÄIT»ù´¡ÉèʩϰȾLockBit 3.0
¾ÝýÌå10ÔÂ17ÈÕ±¨Â·£¬ÈÕ±¾¿Æ¼¼¹«Ë¾OomiyaÔâµ½ÁËLockBit 3.0µÄ¹¥»÷¡£OomiyaרһÓÚÉè¼ÆºÍÔì×÷΢µç×ÓºÍÉèʩϵͳÉ豸£¬ÆäÒµÎñ·ÖΪËÄ´óÁìÓò£ºÄ³Î´¾ÊÚȨµÄµÚÈý·½·¸·¨½Ó¼ûÁËËûÃÇÔÚÒ»¸ö²âÊÔÆ½Ì¨ÉϵÄÊý¾Ý¿â»¯Ñ§ºÍ¹¤Òµ²úÆ·µÄÔì×÷ºÍÉè¼Æ¡¢µç×Ó×ÊÁϵÄÉè¼Æ¡¢Ò©Î↑·¢ºÍ¹¤³§Ôì×÷¡£Lockbit 3.0ÔËÓªÍÅ»ïÐû³ÆÒÑÇÔÈ¡¸Ã¹«Ë¾µÄÊý¾Ý£¬²¢ÍþвÈôÊǹ«Ë¾²»¸¶Êê½ð½«ÔÚ10ÔÂ20ÈÕ֮ǰй¶±»µÁÊý¾Ý¡£ÓÉÓÚOomiyaλÓÚÈ«Çò¶à¸öÐÐÒµµÄÖØÒª×éÖ¯µÄ¹©¸øÁ´ÖУ¬ËùÒÔ´ËÊÂÎñ¿ÉÄÜ»á¶ÔµÚÈý·½×éÖ¯Ôì³É³Á´óÓ°Ïì¡£
https://securityaffairs.co/wordpress/137243/cyber-crime/oomiya-lockbit-3-0-ransomware.html
6¡¢°Ä´óÀûÑÇÆÏÌѾÆÁãÊÛÉÌVinomofoÔ¼50Íò¿Í»§µÄÐÅϢй¶
ýÌå10ÔÂ18Èճƣ¬°Ä´óÀûÑÇµÄÆÏÌѾÆÁãÊÛÉÌVinomofoÔâµ½ºÚ¿Í¹¥»÷£¬¶à´ï50Íò¿Í»§µÄÐÅÏ¢¿ÉÄÜÒѾ¶³ö¡£¸Ã¹«Ë¾³Æ£¬Î´¾ÊÚȨµÄµÚÈý·½ÔÚ²âÊÔÆ½Ì¨ÉÏ·¸·¨½Ó¼ûÁËËûÃǵÄÊý¾Ý¿â£¬Éæ¼°¿Í»§µÄÐÕÃû¡¢ÐԱ𡢵®ÉúÈÕÆÚ¡¢µØÖ·¡¢ÓʼþµØÖ·ºÍµç»°ºÅÂëµÈÐÅÏ¢¡£Ä¿Ç°Éв»Ã÷ÏÔÓм¸¶àÈËÊܵ½¸ÃÊÂÎñµÄÓ°Ï죬µ«Óб¨Â·³ÆVinomofoÕ¼ÓÐÔ¼500000¸ö¿Í»§¡£²»¾Ãǰ£¬°Ä´óÀûÑǵçÐÅÔËÓªÉÌOptusÔøÐ¹Â¶³¬¹ý200Íò¿Í»§µÄÊý¾Ý¡£
https://www.infosecurity-magazine.com/news/breaches-expose-millions-at-aussie/


¾©¹«Íø°²±¸11010802024551ºÅ