Google½¨¸´ChromeÖÐÒѱ»ÀûÓõķì϶CVE-2022-3723

°ä²¼¹¦·ò 2022-10-31
1¡¢Google½¨¸´ChromeÖÐÒѱ»ÀûÓõķì϶CVE-2022-3723

      

¾Ý10ÔÂ28ÈÕ±¨Â· £¬Google°ä²¼ÁËChromeµÄ´¹Î£°²È«¸üР£¬½¨¸´×Ô2022ËêÊ×ÒÔÀ´µÄµÚÆß¸öÁãÈÕ·ì϶¡£¸Ã·ì϶(CVE-2022-3723)ÊÇChrome V8 JavascriptÒýÇæÖеÄÒ»¸öÀàÐÍ»ìºÏ·ì϶ £¬ÓÉAvastµÄ×êÑÐÈËÔ±ÓÚ½ñÄê10ÔÂ25Èջ㱨¡£³öÓÚ°²È«Ô­Òò £¬¸Ã¹«Ë¾Ã»ÓÐÌṩÓйطì϶µÄ¾ßÌåÐÅÏ¢ £¬Ò²Ã»ÓÐ×¢Ã÷Éæ¼°¸Ã·ì϶µÄ¹¥»÷»î¶¯Ë®Æ½µÄÐÔÖÊ¡£×êÑÐÈËԱǿÁÒ½¨ÒéChromeÓû§¾¡¿ì¸üÐÂÆää¯ÀÀÆ÷ÒÔ×èÖ¹´ËÀ๥»÷¡£


https://www.bleepingcomputer.com/news/security/google-fixes-seventh-chrome-zero-day-exploited-in-attacks-this-year/


2¡¢Ë¹Âå·¥¿ËºÍ²¨À¼Òé»áµÄITϵͳÔâµ½´ó¹æÄ£ÍøÂç¹¥»÷

      

ýÌå10ÔÂ29ÈÕ³Æ £¬Ë¹Âå·¥¿ËºÍ²¨À¼Òé»áÔâµ½´ó¹æÄ£ÍøÂç¹¥»÷¡£²¨À¼µ±¾Ö³Æ £¬Õâ´Î¹¥»÷¿ÉÄÜÓë²ÎÒéÔºµÄͶƱÓйØ £¬¹¥»÷ÆëÈ«ÖжÏÁËÒé»áµÄIT»ù´¡ÉèÊ©¡£²¢Ð¹Â©Õâ´Î¹¥»÷ÊǶ෽ÏòµÄ £¬Ô̺¬À´×ÔÂÞ˹Áª¹úÄÚ²¿µÄ¹¥»÷¡£Ë¹Âå·¥¿ËÒé»á¸±Ò鳤°µÊ¾ £¬¹¥»÷µ¼ÖÂ˹Âå·¥¿ËÒé»áµÄITϵͳºÍµç»°Ïß·̱»¾ £¬¼¸Ïî·¨°¸µÄͶƱ±»ÖжÏ¡£ËûÃÇĿǰÉÐδȷ¶¨¸ÃÊÂÎñµÄÆðÔ´ £¬Æä¼¼ÊõÈËÔ¹ØýÔÚ½â¾ö¸ÃÎÊÌâ¡£


https://securityaffairs.co/wordpress/137777/hacking/slovak-polish-parliaments-cyberattacks.html


3¡¢Å·ÖÞ×î´óµÄÍ­³ö²úÉÌAurubisÔÚ±»¹¥»÷ºóϵͳ¹Ø¹Ø

      

10ÔÂ28ÈÕ±¨Â· £¬Aurubis³ÆÆäÔâµ½¹¥»÷ £¬±»ÆÈ¹Ø¹ØITϵͳÒÔÔ¤·À¹¥»÷ÊæÕ¹¡£AurubisÊÇÅ·ÖÞ×î´óºÍÊÀ½çµÚ¶þ´óµÄÍ­³ö²úÉÌ £¬Ã¿Äê³ö²ú100Íò¶ÖÒõ¼«Í­¡£Aurubis²¼¸æÏÔʾ £¬ËûÃǹعØÁËÆäµØµãµØµÄ¸÷Ààϵͳ £¬µ«²¢Î´Ó°Ïì³ö²ú¡£Ò±Á¶³§µÄ³ö²úºÍ»·±£ÉèÊ©Õý³£ÔËÐÐ £¬½ø³ö»õÎïÒ²ÔÚÈËÎªÊØ»¤¡£Ä¿Ç° £¬¸Ã¹«Ë¾ÈÔÔÚÆÀ¹ÀÍøÂç¹¥»÷µÄÓ°Ïì £¬ÎÞ·¨¹À¼ÆÏµÍ³¸´Ô­±ØÒª¶à³¤¹¦·ò¡£´Ë¿ÌÈ·µ±ÎñÖ®¼±ÊÇά³Ö²úÁ¿ÔÚÕý³£Ë®Æ½ £¬³öÓÚÕâ¸öÔ­Òò £¬Ò»Ð©²Ù×÷ÒÑתÏòÊÖ¶¯Ä£Ê½ £¬Ö±µ½ÈÛÁ¶³§¸´Ô­ÍÆËã»ú¸¨ÖúµÄ×Ô¶¯»¯¡£


https://www.bleepingcomputer.com/news/security/largest-eu-copper-producer-aurubis-suffers-cyberattack-it-outage/


4¡¢°Ä´óÀûÑÇÁÙ´²³¢ÊÔÊÒ³ÆÀÕË÷¹¥»÷µ¼ÖÂ22ÍòÈËÐÅϢй¶

      

¾ÝýÌå10ÔÂ27ÈÕ³Æ £¬°Ä´óÀûÑÇÁÙ´²³¢ÊÔÊÒ(ACL)й©ÆäMedlab PathologyÒµÎñ²úÉúÁËÊý¾Ýй¶ £¬Ó°ÏìÔ¼223000Ãû»¼ÕߺÍÔ±¹¤¡£ÀÕË÷ÍÅ»ïQuantumÓÚ2022Äê6ÔÂ14ÈÕÔÚÆäTorÍøÕ¾ÉÏ´«ÁËËùÓб»µÁÎļþ £¬¹²86 GBµÄÊý¾Ý £¬Ô̺¬»¼ÕߺÍÔ±¹¤µÄ¾ßÌåÐÅÏ¢¡¢²ÆÕþ»ã±¨¡¢·¢Æ±¡¢ºÏͬ¡¢±í¸ñ¡¢´«Æ±ºÍÆäËû¸öÈËÎļþµÈ¡£Æ¾¾ÝÍøÕ¾Êý¾Ý £¬MedLabµÄÐ¹Â¶Ò³ÃæÒѱ»½Ó¼û130000´Î¡£¹¥»÷²úÉúÓÚ2022Äê2Ô·Ý £¬µ«¸Ã°²È«ÊÂÎñÔÚ²úÉú9¸öÔºó²Å±»Åû¶ £¬ACLµÄ²¼¸æÊÔͼΪÕâÖÖ³ÙÑÓÌṩÀíÓÉ¡£


https://www.databreaches.net/australian-clinical-labs-says-data-of-223000-people-hacked/


5¡¢iOSºÍmacOSÖеÄSiriSpy·ì϶¿ÉÇÔÌýÓû§ÓëSiriµÄ¶Ô»°

      

ýÌåÓÚ10ÔÂ27ÈÕ±¨Â·³Æ £¬Ó°ÏìÁËApple iOSºÍmacOSµÄSiriSpy·ì϶£¨CVE-2022-32946£© £¬Äܹ»±»ÈκοɽӼûÀ¶ÑÀµÄÀûÓ÷¨Ê½ÓÃÀ´ÇÔÌýÓû§ÓëSiriµÄ¶Ô»°¡£ÔÚ²âÊÔAirBuddyµÄÖ°ÄÜʱ £¬×êÑÐÈËÔ±°ÑÎȵ½AirPodsÔ̺¬Ò»¸ö´øÓÐUUIDµÄ·þÎñ £¬²¢ÇÒÓµÓÐÖ§³Ö֪ͨµÄÖ°ÄÜ¡£½øÒ»´ëÊ©²é½«ÉÏÊöUUIDÓëÓÃÓÚSiriºÍÌýд֧³ÖµÄDoAP·þÎñÓйØÁª £¬¹¥»÷ÕßÄܹ»´´½¨Ò»¸ö¶ñÒâÀûÓà £¬¸ÃÀûÓÃÄܹ»Í¨¹ýÀ¶ÑÀÏνӵ½AirPods²¢ÔÚºó¶Ü¼ÔìÒôƵ¡£Ä¿Ç° £¬¸Ã·ì϶Òѱ»½¨¸´¡£


https://securityaffairs.co/wordpress/137710/security/sirispy-apple-flaw-spy-conversations.html


6¡¢Symantec°ä²¼CraneflyÍÅ»ï½üÆÚ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨

      

10ÔÂ28ÈÕ £¬Symantec°ä²¼Á˹ØÓÚCraneflyÍÅ»ï½üÆÚ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö £¬Cranefly£¨±ðÃûUNC3524£©ÔÚʹÓÃÐÂdropper(Trojan.Geppei)À´×°ÖÃÁíÒ»¸öеĶñÒâÈí¼þ(Trojan.Danfuan)ºÍÆäËü¹¤¾ß£¨Hacktool.Regeorg£©¡£Geppei´ÓºÏ·¨µÄIISÈÕÖ¾ÖжÁÈ¡ºÅÁî¡£¶ÁÈ¡µÄºÅÁîÔ̺¬¶ñÒâ±àÂëµÄ.ashxÎļþ £¬ÕâЩÎļþ±»±£Áôµ½ÓɺÅÁî²ÎÊýÈ·¶¨µÄËÁÒâÎļþ¼ÐÖÐ £¬ËüÃÇ×÷ΪºóÃÅÔËÐС£Ö»¹ÜÒÑÔÚÖ¸±êµÄÍøÂçÉÏÂñ·üÁË18¸öÔ £¬µ«×êÑÐÈËÔ±ÉÐδ¹Û²ìµ½¹¥»÷Õß´ÓÖ¸±êÖÐÇÔÈ¡Êý¾ÝµÄ»î¶¯¡£


https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/cranefly-new-tools-technique-geppei-danfuan