΢Èí°ä²¼12Ô·ݵݲȫ¸üУ¬×ܼƽ¨¸´49¸ö·ì϶
°ä²¼¹¦·ò 2022-12-14
12ÔÂ13ÈÕ£¬Î¢Èí°ä²¼Öܶþ²¹¶¡£¬½¨¸´ÁËÔ̺¬Ò»¸öÒѱ»¼«ÀûÓõķì϶ÔÚÄÚµÄ49¸ö·ì϶¡£Õâ´Î¸üн¨¸´ÁËÁ½¸öÁãÈÕ·ì϶£¬±ðÀëΪWindows SmartScreen°²È«Ö°ÄÜÈÆ¹ý·ì϶£¨CVE-2022-44698£©£¬¹¥»÷ÕßÄܹ»Í¨¹ýÔì×÷Ò»¸ö¶ñÒâÎļþÀ´ÈƹýMOTW·ÀÓù£»ÒÔ¼°DirectXͼÐÎÄÚºËȨÏÞÌáÉý·ì϶£¨CVE-2022-44710£©£¬³É¹¦ÀûÓô˷ì϶¿É»ñµÃSYSTEMȨÏÞ¡£ÆäÖУ¬·ì϶CVE-2022-44698Òѱ»»ý¼«ÀûÓá£
https://www.bleepingcomputer.com/news/microsoft/microsoft-december-2022-patch-tuesday-fixes-2-zero-days-49-flaws/
2¡¢UberÒòµÚÈý·½¹©¸øÉÌÔâµ½¹¥»÷Ô´´úÂëºÍÔ±¹¤ÐÅÏ¢µÈй¶
¾ÝýÌå12ÔÂ12ÈÕ±¨Â·£¬ºÚ¿ÍUberLeaksÔÚÂÛ̳Éϰ䲼ÁË´ÓUberºÍUber EatsÇÔÈ¡µÄÊý¾Ý¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬Ô´´úÂë¡¢IT×ʲúÖÎÀí»ã±¨¡¢Êý¾ÝÏú»Ù»ã±¨¡¢WindowsÓòµÇ¼ÃûÒÔ¼°³¬¹ý77000¸öUberÔ±¹¤µÄÐÅÏ¢µÈ¡£×êÑÐÈËÔ±×î³õÒÔΪÕâЩÊý¾ÝÊÇÔÚ9Ô·ݵĹ¥»÷ÊÂÎñÖб»µÁµÄ£¬µ«Uber°µÊ¾ÕâÓëµÚÈý·½¹©¸øÉ̵ݲȫ·ì϶Óйء£Uber°µÊ¾£¬ÓÃÓÚ×ʲúÖÎÀíºÍ¸ú×Ù·þÎñµÄTeqtivityÔâµ½¹¥»÷£¬¹¥»÷Õß»ñµÃÁËÆäΪ¿Í»§´æ´¢Êý¾ÝµÄTeqtivity AWS±¸·Ý·þÎñÆ÷µÄ½Ó¼ûȨÏÞ¡£
https://www.bleepingcomputer.com/news/security/uber-suffers-new-data-breach-after-attack-on-vendor-info-leaked-online/
3¡¢ÀÕË÷ÍÅ»ïLockBit³ÆÒÑ´Ó¼ÓÖݲÆÕþ²¿ÇÔÈ¡76 GBµÄÊý¾Ý
¾Ý12ÔÂ12ÈÕ±¨Â·£¬LockBitÐû³ÆÒÑÈëÇÖ¼ÓÀû¸£ÄáÑÇÖݵIJÆÕþ²¿£¬²¢ÇÔÈ¡ÁËÊý¾Ý¿â¡¢»úÃÜÊý¾Ý¡¢²ÆÕþÎļþºÍITÓйصÄÎļþ¡£¹¥»÷Õß»¹°ä²¼ÁËĿ¼ºÍ´æ´¢ÎļþÊýÁ¿µÄ½ØÍ¼£¬ÏÔʾ³¬¹ý114000¸öÎļþ¼ÐÖÐÓг¬¹ý246000¸öÎļþ£¬×ܼÆ75.3GBµÄÊý¾Ý¡£Ä¿Ç°£¬LockBitÒªÇóµÄÊê½ð½ð¶îÉв»Ã÷ÏÔ£¬µ«ÊÇÆäÍøÕ¾µÄµ¹¼ÆÊ±ÏÔʾҪÔÚ12ÔÂ24ÈÕ֮ǰ¸¶¡£¼ÓÖÝÖݳ¤´¹Î£·þÎñ°ì¹«ÊÒ°µÊ¾£¬¼ÓÖÝÍøÂ簲ȫ¼¯³ÉÖÐÐÄ£¨Cal-CSIC£©ÔÚ»ý¼«Ó¦¶Ô´ËÊÂÎñ£¬µ«Ã»ÓÐÌṩ̫¶àϸ½ÚÐÅÏ¢¡£
https://www.cyberscoop.com/lockbit-ransomware-california-department-of-finance/
4¡¢Ó¡¶È±í½»²¿µÄÍøÕ¾Ð¹Â¶±í¼®ÈËÊ¿»¤ÕÕ¾ßÌåÐÅÏ¢µÈÄÚÈÝ
ýÌå12ÔÂ12Èճƣ¬Ó¡¶È±í½»²¿µÄGlobal Pravasi Rishta PortalÍøÕ¾Ð¹Â¶ÁË±í¼®ÈËÊ¿µÄ»¤ÕÕ¾ßÌåÐÅÏ¢¡£ÕâÊÇÒ»¸öÖ¼ÔÚÏνÓ3000ÍòÓ¡¶ÈÍâÇÈµÄÆ½Ì¨£¬ÒÔÃ÷ÎĵĴó¾Ö¹«¿ªÁËÐÕÃû¡¢¾Óס¹ú¶ÈÓʼþµØÖ·¡¢Ö°ÒµÇé¿ö¡¢µç»°ºÍ»¤ÕÕºÅÂëµÈÐÅÏ¢¡£Ð¹Â¶ÔÒò¿ÉÄÜÊǰ²È«´ëÊ©²»¼°£¬ÀýÈç²»×ãÉí·ÝÑéÖ¤²½Öè¡£CybernewsÒÑÁªÏµ±í½»²¿·î¸æÆäй¶ÊÂÎñ£¬²¢Ã»ÓÐÊÕµ½»Ø¸´£¬µ«¸ÃÎÊÌâÔÚ¼¸ÌìºóµÃµ½Ïàʶ¾ö¡£
https://securityaffairs.co/wordpress/139561/data-breach/indian-foreign-ministrys-global-pravasi-rishta-portal-leaks-expat-passport-details.html
5¡¢Check Point°ä²¼¹ØÓÚÀÕË÷Èí¼þAzovµÄÉî¶È·ÖÎö»ã±¨
Check Point ResearchÔÚ12ÔÂ12ÈÕ°ä²¼Á˹ØÓÚÀÕË÷Èí¼þAzovµÄÉî¶È·ÖÎö»ã±¨¡£AzovÊ×ÏÈ×÷Ϊ½©Ê¬ÍøÂçSmokeLoaderµÄpayloadÒýÆð×êÑÐÈËԱȷ°ÑÎÈ£¬ËüÓëͨ³£ÀÕË÷Èí¼þµÄÇø±ðÖ®Ò»ÊÇËüÅú¸ÄÁËijЩ64λ¿ÉÖ´ÐÐÎļþÀ´Ö´ÐÐ×Ô¼ºµÄ´úÂë¡£ÕâÖÖ¶ÔÖ¸±êµÄ¿ÉÖ´ÐÐÎļþµÄÇÖÂÔÐÔ¶à̬ϰȾµ¼Ö´óÁ¿¹«¿ª¿ÉÓõÄÎļþ±»AzovϰȾ£¬Ã¿Ìì¶¼º±¼û°Ù¸öеÄAzovÓйØÑù±¾±»Ìá½»µ½VirusTotal¡£½ØÖÁ2022Äê11Ô£¬¸ÃÑù±¾ÒѾ³¬¹ý17000¸ö¡£
https://research.checkpoint.com/2022/pulling-the-curtains-on-azov-ransomware-not-a-skidsware-but-polymorphic-wiper/
6¡¢Unit 42°ä²¼½üÆÚеÄKerberos¹¥»÷·½Ê½µÄ·ÖÎö»ã±¨
12ÔÂ12ÈÕ£¬Unit 42°ä²¼Á˽üÆÚеÄKerberos¹¥»÷·½Ê½µÄ·ÖÎö»ã±¨¡£Active DirectoryµÄ¿í·ºÊ¹ÓÃʹKerberos¹¥»÷³ÉΪºÜ¶à¹¥»÷ÕßµÄÖØÒª¼¿Á©£¬×êÑÐÈËÔ±·¢ÏÖÁËÐµĹ¥»÷¼¼Êõ£¬Diamond TicketºÍSapphire Ticket£¬Ê¹¹¥»÷Õß¿ÉÄܲ»ÊÜÏ޶ȵؽӼûADÓòÖеÄËùÓзþÎñºÍ×ÊÔ´¡£Sapphire Ticket¹¥»÷±ØÒª»ñÈ¡ÓòÖÐÓû§µÄÍ´´¦£¬¶øºóÀûÓÃÍ´´¦»ñÈ¡TGT£¬²¢½«ÆäÓÃÓÚ½âÃܸßȨÏÞÓû§µÄPAC¡£Diamond Ticket¹¥»÷Ê×ÏÈÊÇ»ñÈ¡TGT£¬¶øºóʹÓÃKRBTGTÕÊ»§µÄÃÜÔ¿½âÃÜTGT²¢Åú¸ÄTicket£¬ÌáÉýȨÏÞ¡£
https://unit42.paloaltonetworks.com/next-gen-kerberos-attacks/


¾©¹«Íø°²±¸11010802024551ºÅ