Google´¹Î£½¨¸´ChromeÖб»ÀûÓõķì϶CVE-2022-4262

°ä²¼¹¦·ò 2022-12-05
1¡¢Google´¹Î£½¨¸´ChromeÖб»ÀûÓõķì϶CVE-2022-4262

12ÔÂ2ÈÕ£¬Google°ä²¼´¹Î£¸üУ¬½¨¸´ChromeÖÐÒѱ»ÀûÓõÄ0 day¡£ÕâÊÇChrome V8 JavaScriptÒýÇæÖеÄÀàÐÍ»ìºÏ·ì϶(CVE-2022-4262)£¬´ËÀà·ì϶ͨ³£±»ÓÃÓÚͨ¹ý¶ÁÈ¡»òдÈ뻺³åÇøÌìǵ±íµÄÄÚ´æµ¼ÖÂä¯ÀÀÆ÷±ÀÀ££¬Ò²¿É±»ÓÃÓÚÖ´ÐÐËÁÒâ´úÂë¡£¹ÌÈ»Google°µÊ¾ËüÒѼì²âµ½ÀûÓÃÕâ¸ö·ì϶µÄ¹¥»÷£¬µ«ÉÐδ·ÖÏíÓйØÕâЩÊÂÎñµÄ¼¼Êõϸ½Ú»òÐÅÏ¢¡£ÕâÊÇGoogle ChromeÔÚ½ñÄ꽨¸´µÄµÚ9¸ö0 day¡£

https://chromereleases.googleblog.com/2022/12/stable-channel-update-for-desktop.html

2¡¢Kaspersky·¢ÏÖÖØÒªÕë¶Ô¶íÂÞ˹×éÖ¯µÄÐÂľÂíCryWiper

KasperskyÔÚ12ÔÂ1ÈÕ³ÆÆä·¢ÏÖÁËÒ»¸öÐµÄľÂíCryWiper¡£×êÑÐÈËÔ±ÔÚ½ñÄêÇïÌì³õ´Î·¢ÏÖÁËCryWiper£¬Ëü±»ÓÃÓÚÕë¶Ô¶íÂÞ˹×éÖ¯µÄ¹¥»÷£¬¶íÂÞ˹ýÌåÔòй©Ëü±»ÓÃÓÚ¹¥»÷¶íÂÞ˹Êг¤°ì¹«ÊҺͷ¨Ôº¡£¸Ã¶ñÒâÈí¼þ¼Ù×°³ÉÀÕË÷Èí¼þ£¬µ«¶Ô´úÂëµÄ·ÖÎöÅú×¢ËüÏÖʵÉϲ¢Î´¼ÓÃÜ£¬Ö»ÊÇ·ÛËéÁ˱»Ï°È¾ÏµÍ³ÖеÄÊý¾Ý¡£CryWiperÑù±¾ÓÃC++¿ª·¢µÄ64λWindows¿ÉÖ´ÐÐÎļþ£¬ÅäÖÃΪÀÄÓúܶàWinAPIº¯ÊýŲÓ᣸öñÒâÈí¼þ»¹»áɾ³ý±»Ï°È¾ÍÆËã»úÉϵľíÓ°¸±±¾£¬ÒÔÔ¤·ÀÖ¸±ê¸´Ô­Îļþ¡£

https://securelist.ru/novyj-troyanec-crywiper/106114/

3¡¢ÈýÐǵȹ©¸øÉÌʹÓÃµÄÆ½Ì¨Ö¤Êé±»ÀÄÓÃÀ´Ç©Êð¶ñÒâÀûÓÃ

¾ÝýÌå12ÔÂ1ÈÕ±¨Â·£¬AndroidOEMÉ豸¹©¸øÉÌÓÃÓÚ¶ÔÖ÷ÌâϵͳÀûÓýøÐÐÊý×ÖÊðÃûµÄ¶à¸öƽ̨֤Êé±»ÓÃÓÚ¶ÔÔ̺¬¶ñÒâÈí¼þµÄÀûÓýøÐÐÊðÃû¡£×êÑÐÈËÔ±·¢ÏÖ¶à¸öʹÓÃÕâЩƽ̨֤ÊéÊðÃûµÄ¶ñÒâÈí¼þÑù±¾£¬²¢ÌṩÁËÿ¸öÑù±¾µÄSHA256¹þÏ£ÖµºÍÊý×ÖÊðÃûÖ¤Êé¡£ÆäÖв¿ÃÅÊôÓÚÈýÐÇ¡¢LG¡¢RevoviewºÍÁª·¢¿Æ£¬ÆäËüÖ¤ÊéÉÐÎÞ·¨È·¶¨ÊôÓÚË­¡£Ê¹ÓÃÕâЩ֤ÊéÊðÃûµÄ¶ñÒâÈí¼þÔ̺¬HiddenAdľÂí¡¢ÐÅÏ¢ÇÔÈ¡·¨Ê½¡¢MetasploitºÍ¶ñÒâÈí¼þÖ²È뷨ʽ¡£

https://www.bleepingcomputer.com/news/security/samsung-lg-mediatek-certificates-compromised-to-sign-android-malware/

4¡¢CISA³ÆÀÕË÷Èí¼þCubaÒѳɹ¦ÀÕË÷³¬¹ý6000ÍòÃÀÔª

CISAºÍFBIÔÚ12ÔÂ1ÈÕ½áºÏ°ä²¼Á˹ØÓÚÀÕË÷Èí¼þCubaµÄ¹«¸æ¡£×Ô2021Äê12ÔÂÒÔÀ´£¬¸ÃÍÅ»ïÖØÒªÕë¶Ô½ðÈÚ·þÎñ¡¢µ±¾ÖÉèÊ©¡¢Ò½ÁƱ£½¡ºÍ¹«¹²ÎÀÉú¡¢Ôì×÷ºÍÐÅÏ¢¼¼ÊõÐÐÒµ¡£½ØÖÁ2022Äê8Ô£¬FBIÈ·¶¨CubaÔÚÈ«ÇòÁìÓòÄÚÈëÇÖÁË100¶à¸ö×éÖ¯£¬ÀÕË÷³¬¹ý1.45ÒÚÃÀÔª²¢³É¹¦ÊÕµ½³¬¹ý6000ÍòÃÀÔª¡£CubaÍÅ»ïÀûÓöàÖÖ¼¼Êõ»ñµÃ³õʼ½Ó¼ûȨÏÞ£¬Ô̺¬ÀûÓÃóÒ×Èí¼þÖеÄÏÖÓзì϶¡¢´¹µö»î¶¯¡¢Ð¹Â¶µÄÍ´´¦ÒÔ¼°ºÏ·¨µÄRDP¹¤¾ß¡£³É¹¦ºó£¬»áͨ¹ýHancitorÔÚÖ¸±êϵͳÉÏ×°ÖÃCubaÀÕË÷Èí¼þ¡£

https://www.cisa.gov/uscert/ncas/alerts/aa22-335a

5¡¢ÃÀ¹ú·ðÂÞÀï´ïÖݵÄ˰ÎñÍøÕ¾Ð¹Â¶ÄÉ˰È˵ÄÐÅÏ¢

¾Ý12ÔÂ3ÈÕ±¨Â·£¬·ðÂÞÀï´ïÖݵÄ˰Îñ¾ÖÍøÕ¾´æÔÚÒ»¸ö°²È«·ì϶£¬Ð¹Â¶ÁËÖÁÉÙÊý°Ù¸öÄÉ˰È˵ÄÉç»á°²È«ºÅÂëºÍÒøÐÐÕʺÅ¡£¸Ã·ì϶Ϊ²»°²È«µÄÖ±½Ó¶ÔÏóÒýÓã¨IDOR£©£¬ÓÉÓÚÉêÇë±àºÅÊÇÂ½ÐøµÄ£¬ÈκÎÈ˶¼Äܹ»Í¨¹ý½«ÉêÇë±àºÅµÝÔöһλÀ´ÁоÙÄÉ˰È˵ÄÐÅÏ¢£¬ÏµÍ³ÖÐÓг¬¹ý713000·ÝÉêÇë¡£µÇ¼¸ÃÍøÕ¾µÄÈκÎÈË£¬¶¼Äܹ»Í¨¹ýÅú¸ÄÔ̺¬ÄÉ˰ÈËÉêÇëºÅÂëµÄÍøÖ·²¿ÃÅ£¬½Ó¼û¡¢Åú¸ÄºÍɾ³ý¸Ã˰Îñ»ú¹Ø´æµµµÄÆóÒµÖ÷µÄÓ×ÎÒ×ÊÁÏ¡£

https://www.databreaches.net/florida-state-tax-website-bug-exposed-filers-data/

6¡¢Zimperium°ä²¼Schoolyard BullyľÂí¹¥»÷»î¶¯µÄ·ÖÎö

12ÔÂ1ÈÕ£¬Zimperium°ä²¼Á˹ØÓÚSchoolyard BullyľÂíµÄ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¸Ã»î¶¯×Ô2018ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬ÒÑϰȾ71¸ö¹ú¶È/µØÓòµÄÖÁÉÙ300000¸öÖ¸±ê£¬ÖØÒª¼¯ÖÐÔÚÔ½ÄÏ¡£Schoolyard BullyÒò¼Ù×°³ÉÎÞº¦ÉõÖÁÓÐÒæµÄ½ÌÓýÀûÓöøµÃÃû£¬ÆäÖØÒªÖ¸±êÊÇÇÔÈ¡FacebookÕÊ»§Í´´¦¡£¸ÃľÂíͨ¹ýʹÓÃWebViewÔÚÀûÓÃÖдò¿ªºÏ·¨µÄFacebookµÇÂ¼Ò³Ãæ£¬²¢×¢Èë¶ñÒâJavaScriptÀ´ÇÔÈ¡Óû§ÊäÈë¡£Ö»¹ÜÕâЩÀûÓÃÏÖÒÑ´ÓGoogle PlayÉ̵êÖÐɾ³ý£¬µ«ËüÃÇÒÀÈ»Äܹ»ÔÚµÚÈý·½ÀûÓ÷¨Ê½É̵êÖлñµÃ¡£

https://www.zimperium.com/blog/schoolyard-bully-trojan-facebook-credential-stealer/