ISCÐû²¼¸üУ¬£¬£¬ÐÞ¸´BIND DNSÈí¼þÖеĶà¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2022-09-27
9ÔÂ21ÈÕ£¬£¬£¬Internet Systems Consortium(ISC)Ðû²¼Çå¾²¸üУ¬£¬£¬ÐÞ¸´BIND DNSÈí¼þÖеĶà¸ö¿ÉÔ¶³ÌʹÓõÄÎó²î¡£¡£¡£¡£¡£¡£ÆäÖнÏΪÑÏÖØµÄÊÇͨ¹ýTKEY RR´¦Öóͷ£Diffie-HellmanÃÜÔ¿½»Á÷µÄ´úÂëÖеÄÄÚ´æÐ¹Â¶Îó²î£¨CVE-2022-2906£©¡¢ECDSA DNSSECÑéÖ¤ÂëÖеÄÄÚ´æÐ¹Â¶Îó²î£¨CVE-2022-38177£©¡¢¿Éµ¼ÖÂBIND 9ÆÊÎöÆ÷Íß½âµÄÎó²î£¨CVE-2022-3080£©ºÍEdDSA DNSSECÑéÖ¤ÂëÖеÄй¶Îó²î£¨CVE-2022-38178£©¡£¡£¡£¡£¡£¡£ISCÌåÏÖ£¬£¬£¬ÉÐδ·¢Ã÷ÉÏÊöÎó²îÔÚÒ°ÍⱻʹÓõĻ¡£¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/136164/security/bind-dns-software-flaws-2.html
2¡¢Google PlayºÍApp StoreÖжà¸ö¹ã¸æÓ¦Óñ»×°ÖÃ1300Íò´Î
¾ÝýÌå9ÔÂ26ÈÕ±¨µÀ£¬£¬£¬Ñо¿Ö°Ô±ÔÚGoogle PlayÉÏ·¢Ã÷ÁË75¸ö¹ã¸æÓ¦Ó㬣¬£¬ÔÚApp StoreÉÏ·¢Ã÷ÁËÁíÍâ10¸ö¹ã¸æÓ¦Ó㬣¬£¬×ܹ²±»×°ÖÃÁË1300Íò´Î¡£¡£¡£¡£¡£¡£³ýÁËÏòÊÖ»úÓû§Í¶·Å¿É¼ûºÍÒþ²ØµÄ¹ã¸æÍ⣬£¬£¬ÕâЩڲÆÓ¦Óû¹Í¨¹ýð³äÕýµ±µÄÓ¦ÓÃÀ´´´ÊÕ¡£¡£¡£¡£¡£¡£ËäÈ»ÕâÖÖÀàÐ͵ÄÓ¦Óò»±£´æÑÏÖØµÄÍþв£¬£¬£¬µ«¹¥»÷Õß¿ÉÒÔʹÓÃËüÃǾÙÐиüΣÏյĻ¡£¡£¡£¡£¡£¡£Ñо¿ÍŶÓÒѽ«ÕâЩ·¢Ã÷֪ͨGoogleºÍApple£¬£¬£¬ÏÖÔÚÕâЩӦÓÃÒÑ´Ó¹Ù·½AndroidºÍiOSÊÐËÁÖÐɾ³ý¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/adware-on-google-play-and-apple-store-installed-13-million-times/
3¡¢Ó¡¶ÈijҽÁÆÈí¼þ¹«Ë¾Ð¹Â¶170ÍòÈËCovid¿¹Ô²âÊÔЧ¹û
ýÌå9ÔÂ25Èճƣ¬£¬£¬Ó¡¶ÈijҽÁÆÈí¼þÌṩÉ̵ÄElasticsearchЧÀÍÆ÷й¶ÁË170ÍòÈ˵ÄCovid¿¹Ô²âÊÔЧ¹û¡£¡£¡£¡£¡£¡£AnuragÔÚShodanÉÏɨÃèÉèÖùýʧµÄÊý¾Ý¿âʱ£¬£¬£¬×¢Öص½Ò»Ì¨Ð§ÀÍÆ÷̻¶ÁËÁè¼Ý23GBµÄÊý¾Ý¡£¡£¡£¡£¡£¡£ÆäÖаüÀ¨ÒÑÍù¼¸ÄêÍùÀ´ÓÚÓ¡¶ÈµÄÓ¡¶ÈÈ˺ÍÍâ¹úÓο͵ÄÐÅÏ¢£¬£¬£¬ÈçÐÕÃû¡¢¹ú¼®¡¢µØµã¡¢µç»°ºÅÂë¡¢Éí·ÝÖ¤ºÅÂë¡¢¼ì²âЧ¹û¡¢AadhaarºÅºÍ»¤ÕÕºÅÂëµÈ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬¸ÃÊý¾Ý¿â×Ô2022Äê7ÔÂ2ÈÕ×îÏÈ̻¶£¬£¬£¬ÇÒÏÖÔÚÈÔ´¦ÓÚ¹ûÕæ×´Ì¬¡£¡£¡£¡£¡£¡£
https://www.hackread.com/covid-antigen-test-results-india-leaked/
4¡¢ÎÚ¿ËÀ¼SSUµ·»ÙÔøÇÔÈ¡²¢³öÊÛ3000Íò¸öÕË»§µÄºÚ¿ÍÍÅ»ï
ýÌå9ÔÂ24ÈÕ±¨µÀ³Æ£¬£¬£¬ÎÚ¿ËÀ¼Çå¾²¾Ö(SSU)µÄÍøÂ粿·Öµ·»ÙÁËÒ»¸öÔøÇÔÈ¡²¢³öÊÛ3000Íò¸öÕË»§µÄºÚ¿ÍÍŻ¡£¡£¡£¡£¡£¾ÝSSU³Æ£¬£¬£¬ËûÃÇÒÔºó´ÎÐж¯ÖÐ׬Ǯ1400ÍòUAH£¨380000ÃÀÔª£©¡£¡£¡£¡£¡£¡£¹¥»÷Õß×Óͨ¹ý¶ñÒâÈí¼þѬȾÀ´»ñȡƾ֤ºÍÊý¾Ý£¬£¬£¬Ö÷ÒªÕë¶ÔÎÚ¿ËÀ¼ºÍÅ·ÃË×éÖ¯µÄϵͳ¡£¡£¡£¡£¡£¡£ËûÃÇ»¹Í¨¹ýÔÚÎÚ¿ËÀ¼±»Õ¥È¡µÄµç×ÓÖ§¸¶ÏµÍ³YuMoney¡¢QiwiºÍWebMoneyÊÕ¿î¡£¡£¡£¡£¡£¡£±»²¶µÄÈËÊýÈÔδÅû¶£¬£¬£¬µ«ËûÃǶ¼Òòδ¾ÊÚȨ³öÊÛ»ò·Ö·¢ÔÚ´æ´¢ÓÚÅÌËã»úºÍÍøÂçÖеĻá¼ûÊÜÏÞµÄÐÅÏ¢¶øÃæÁÙÐÌÊÂËßËϼ°¶àÄêî¿Ïµ¡£¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/136156/cyber-crime/ukraine-cyber-gang.html
5¡¢Î¢ÈíÐû²¼Ê¹ÓÃOAuthÓ¦Óù¥»÷ExchangeЧÀÍÆ÷µÄÆÊÎö±¨¸æ
9ÔÂ22ÈÕ£¬£¬£¬Î¢ÈíÐû²¼±¨¸æ³ÆÆä½üÆÚÊÓ²ìÁËÒ»ÖÖ¹¥»÷£¬£¬£¬ÆäÖй¥»÷ÕßÔÚ±»Ñ¬È¾µÄÔÆ×â»§ÖÐ×°ÖöñÒâOAuthÓ¦ÓóÌÐò£¬£¬£¬ÓÃÓÚ¿ØÖÆExchange OnlineÉèÖúÍÈö²¥À¬»øÓʼþ¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏȶÔδÆôÓÃMFAµÄÏÕÕË»§Ö´ÐÐײ¿â¹¥»÷£¬£¬£¬²¢Ê¹Óò»Çå¾²µÄÖÎÀíÔ±ÕË»§»ñµÃ³õʼ»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£È»ºó£¬£¬£¬¹¥»÷Õ߿ɽ¨Éè¶ñÒâOAuthÓ¦ÓóÌÐò£¬£¬£¬¸Ã³ÌÐò»áÔÚµç×ÓÓʼþЧÀÍÆ÷ÖÐÌí¼Ó¶ñÒâÈëÕ¾ÅþÁ¬Æ÷¡£¡£¡£¡£¡£¡£×îºó£¬£¬£¬Ê¹ÓöñÒâÈëÕ¾ÅþÁ¬Æ÷·¢ËÍ¿´ÆðÀ´ÏñÊÇÀ´×ÔÄ¿µÄÓòµÄÀ¬»øÓʼþ¡£¡£¡£¡£¡£¡£
https://www.microsoft.com/security/blog/2022/09/22/malicious-oauth-applications-used-to-compromise-email-servers-and-spread-spam/
6¡¢NSAºÍCISAÐû²¼±£»£»£»£»£»£»£»¤OTºÍICSµÄÒªº¦»ù´¡ÉèÊ©µÄÇå¾²×Éѯ
9ÔÂ22ÈÕ£¬£¬£¬CISAºÍNSAÁªºÏÐû²¼Á˹ØÓÚ±£»£»£»£»£»£»£»¤ÔËÓªÊÖÒÕ(OT)ºÍ¹¤Òµ¿ØÖÆÏµÍ³(ICS)µÄÒªº¦»ù´¡ÉèÊ©µÄÁªºÏÇå¾²×Éѯ¡£¡£¡£¡£¡£¡£¸Ãͨ¸æ·ÖÏíÁ˹¥»÷ÕßÓÃÀ´ÆÆËðÖ§³ÖITµÄOTºÍICS×ʲúµÄËùÓа취ÐÅÏ¢£¬£¬£¬²¢Ç¿µ÷ÁËÇ徲רҵְԱ¿ÉÒÔ½ÓÄɵķÀÓù²½·¥¡£¡£¡£¡£¡£¡£»£»£»£»£»£»£»¹Ö¸³ö£¬£¬£¬ÔËÓª¡¢¿ØÖÆºÍ¼à¿ØÒ»Ñùƽ³£Òªº¦»ù´¡ÉèÊ©ºÍ¹¤ÒµÁ÷³ÌµÄOTºÍICS×ʲúÃæÁÙµÄÍþвÈÕÒæÔöÌí£¬£¬£¬²¢ÌṩÁËһЩÓÃÀ´Ó¦¶ÔµÐÊÖµÄÕ½ÂÔ¡¢ÊÖÒպͳÌÐò(TTP)µÄ×î¼ÑÇ徲ʵ¼ù¡£¡£¡£¡£¡£¡£
https://us-cert.cisa.gov/ncas/current-activity/2022/09/22/cisa-and-nsa-publish-joint-cybersecurity-advisory-control-system