OpenSSL¼´½«ÐÞ¸´¼ÌHeartbleedÒÔÀ´ÓÖÒ»ÑÏÖØÎó²î
Ðû²¼Ê±¼ä 2022-10-28
¾Ý10ÔÂ26ÈÕ±¨µÀ£¬£¬£¬£¬£¬OpenSSLÏîÄ¿Ðû²¼½«Ðû²¼¸üÐÂÒÔÐÞ¸´¿ªÔ´¹¤¾ß°üÖеÄÒ»¸öÒªº¦Îó²î¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Ö¸³ö£¬£¬£¬£¬£¬ÕâÊÇ×Ô2016Äê9ÔÂÒÔÀ´ÔÚ¹¤¾ß°üÖÐÐÞ¸´µÄµÚÒ»¸öÒªº¦Îó²î¡£¡£¡£¡£¡£¡£Í¨¸æÅú×¢£¬£¬£¬£¬£¬OpenSSL 3.0.7ÊÇÒ»¸öÇå¾²ÐÞ¸´°æ±¾£¬£¬£¬£¬£¬½«ÓÚ2022Äê11ÔÂ1ÈÕ13:00-17:00 UTCÐû²¼¡£¡£¡£¡£¡£¡£¸ÃÑÏÖØÎó²î½öÓ°Ïì3.0¼°¸ü¸ß°æ±¾£¬£¬£¬£¬£¬ÊǼÌ2014ÄêHeartbleedÎó²î(CVE-2014-0160)Ö®ºó£¬£¬£¬£¬£¬OpenSSLÐÞ¸´µÄµÚ¶þ¸öÑÏÖØµÄÎó²î¡£¡£¡£¡£¡£¡£OpenSSL»¹Ðû²¼Á˼´½«ÔÚͳһÌìÐû²¼µÄbugÐÞ¸´°æ±¾1.1.1¡£¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/137689/security/openssl-second-critical-flaw-ever.html
2¡¢Î¢Èí³ÆÊ¹ÓÃServer ManagerÖØÖôÅÅ̿ɵ¼ÖÂÊý¾Ýɥʧ
10ÔÂ26ÈÕ±¨µÀ£¬£¬£¬£¬£¬Î¢Èí³ÆÊ¹ÓÃServer ManagerÖÎÀí¿ØÖÆÌ¨ÖØÖÃÐéÄâ´ÅÅÌʱ£¬£¬£¬£¬£¬¿ÉÄܻᵼÖÂÊý¾Ýɥʧ¡£¡£¡£¡£¡£¡£ÓÉÓÚ´ËÎÊÌ⣬£¬£¬£¬£¬ÊµÑéÖØÖûòɨ³ýÐéÄâ´ÅÅ̵ÄÖÎÀíÔ±¿ÉÄÜ»áÒâÍâµØÖØÖÃÆäËüµÄ´ÅÅÌ¡£¡£¡£¡£¡£¡£ËûÃÇ»¹½«ÔÚʹÃü½ø¶È¶Ô»°¿ò´°¿ÚÖп´µ½¡°ÖØÖôÅÅÌʧ°Ü¡±µÄ¹ýʧ£¬£¬£¬£¬£¬ÒÔ¼°¡°ÕÒµ½¶à¸ö¾ßÓÐÏàͬIDµÄ´ÅÅÌ£¬£¬£¬£¬£¬Çë¸üÐÂÄúµÄ´æ´¢Çý¶¯³ÌÐò£¬£¬£¬£¬£¬È»ºóÖØÊÔ¡£¡£¡£¡£¡£¡£¡±Îª´Ë£¬£¬£¬£¬£¬Î¢ÈíÌṩÁËÒ»ÖÖ½â¾öÒªÁ죬£¬£¬£¬£¬Ê¹ÓÃPowerShellÏÂÁîÔÚ¿ÉÓõĴ洢ÖÎÀíÌṩ³ÌÐòÖмìË÷´ÅÅ̵ÄDeviceID£¬£¬£¬£¬£¬²¢Í¨¹ýɾ³ýËùÓзÖÇøÐÅÏ¢²¢×÷·Ï³õʼ»¯À´É¨³ý´ÅÅÌ£¬£¬£¬£¬£¬À´É¨³ý²Á³ý´ÅÅÌÉϵÄËùÓÐÊý¾Ý¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-server-manager-disk-resets-can-lead-to-data-loss/
3¡¢Ã½Ì幫˾ÌÀÉ·͸Êý¾Ý¿âÉèÖùýʧй¶Áè¼Ý3TBµÄÊý¾Ý
ýÌå10ÔÂ27Èճƣ¬£¬£¬£¬£¬¿ç¹úýÌ幫˾Thomson Reuters£¨ÌÀÉ·͸£©Ð¹Â¶ÁËÖÁÉÙ3 TBµÄÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£¸ÃElasticSearchµÄË÷ÒýÃüÃûÅú×¢Ëü±»ÓÃ×÷ÈÕ־ЧÀÍÆ÷£¬£¬£¬£¬£¬ÒÔÍøÂçͨ¹ýÓû§-¿Í»§¶Ë½»»¥»ñµÃµÄ´ó×ÚÊý¾Ý¡£¡£¡£¡£¡£¡£Êý¾ÝÑù±¾µÄʱ¼ä´ÁÅú×¢ÕâЩÊý¾ÝÊÇ×î½ü¼Í¼µÄ£¬£¬£¬£¬£¬ÆäÖÐһЩÊý¾ÝÊÇ10ÔÂ26ÈÕµÄ×îÐÂÊý¾Ý¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿â°üÀ¨ÒÔ´¿Îı¾ÃûÌÃÉúÑĵĵÚÈý·½Ð§ÀÍÆ÷µÄ»á¼ûƾ֤¡¢µÇ¼ºÍÃÜÂëÖØÖÃÈÕÖ¾¡¢SQLÈÕÖ¾£¬£¬£¬£¬£¬ÒÔ¼°Ïà¹Ø¹«Ë¾ºÍÖ´·¨ÎļþµÈ¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬¸Ã¹«Ë¾Òѹرտª·ÅµÄÊý¾Ý¿â¡£¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/137718/data-breach/thomson-reuters-database-exposed.html
4¡¢KimsukyÍÅ»ïʹÓÃ3¸öAndroid¶ñÒâÈí¼þ¹¥»÷º«¹úµÄ×éÖ¯
Çå¾²¹«Ë¾S2WÓÚ10ÔÂ24ÈÕÅû¶ÁËKimsukyʹÓÃ3¸öAndroid¶ñÒâÈí¼þÕë¶Ôº«¹ú×éÖ¯µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£S2W͸¶ËüÃÇÔÚ¸ú×ÙKimsuky×éÖ¯µÄÀú³ÌÖз¢Ã÷ÁË3ÖÖеĶñÒâÈí¼þ£ºKimsukyÏÖÔÚÕýÔÚ¿ª·¢µÄ¶ñÒâAPK FastFire£¬£¬£¬£¬£¬Ëüαװ³É¹È¸èÇå¾²²å¼þ£»£»£»FastViewer£¬£¬£¬£¬£¬Î±×°³É¿ÉÒÔ¶ÁÈ¡º«ÎÄÎļþ(.hwp)µÄÒÆ¶¯Éó²é³ÌÐòHancom Viewer£»£»£»»ùÓÚAndroid×°±¸µÄÔ¶³Ì¿ØÖƹ¤¾ßAndroSpyµÄÔ´´úÂ뿪·¢µÄFastSpy¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬£¬KimsukyµÄ¹¥»÷Õ½ÂÔÔ½À´Ô½ÏȽø£¬£¬£¬£¬£¬Òò´ËÒª×¢ÖØÕë¶ÔAndroid×°±¸µÄ¹¥»÷¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2022/10/kimsuky-hackers-spotted-using-3-new.html
5¡¢Unit 42Ðû²¼2022ÄêµÚ¶þ¼¾¶ÈWebÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ
10ÔÂ26ÈÕ£¬£¬£¬£¬£¬Unit 42Ðû²¼ÁË2022ÄêµÚ¶þ¼¾¶ÈWebÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬µÚ¶þ¼¾¶È·¢Ã÷ÁËԼĪ751000¸ö°üÀ¨²î±ðÀàÐÍWebÍþвµÄ¶ñÒâÉϰ¶URLÊÂÎñ£¬£¬£¬£¬£¬ÆäÖÐ253000¸öÊÇΨһURL£»£»£»¼ì²âµ½Ô¼Äª1740000¸ö¶ñÒâÖ÷»úURL£¬£¬£¬£¬£¬ÆäÖÐ256000¸öÊÇΨһµÄ£»£»£»ÕâЩÓòÃûÖеĴó´ó¶¼ËƺõÀ´×ÔÃÀ¹ú£»£»£»Top 5µÄÍþвÊǼÓÃܿ󹤡¢JavaScriptÏÂÔØÆ÷¡¢ web skimmer¡¢web scamºÍJavaScriptÖØ¶¨Ïò¹¤¾ß¡£¡£¡£¡£¡£¡£
https://unit42.paloaltonetworks.com/web-threats-malicious-javascript-downloader/
6¡¢Check PointÐû²¼¹ØÓÚ2022ÄêQ3È«ÇòÍøÂç¹¥»÷µÄ±¨¸æ
Check PointÔÚ10ÔÂ26ÈÕÐû²¼Á˹ØÓÚ2022ÄêQ3È«ÇòÍøÂç¹¥»÷µÄ±¨¸æ¡£¡£¡£¡£¡£¡£Óë2021ÄêͬÆÚÏà±È£¬£¬£¬£¬£¬2022ÄêµÚÈý¼¾¶ÈÈ«ÇòµÄÍøÂç¹¥»÷ÔöÌíÁË28%£¬£¬£¬£¬£¬È«Çòÿ¸ö×é֯ƽ¾ùÿÖܱ»¹¥»÷¶à´ï1130´Î¡£¡£¡£¡£¡£¡£ÕâÒ»¼¾¶È±»¹¥»÷×î¶àµÄÐÐÒµÊǽÌÓýºÍÑо¿²¿·Ö£¬£¬£¬£¬£¬Æ½¾ùÿ¸ö×é֯ÿÖܱ»¹¥»÷2148´Î£¬£¬£¬£¬£¬Óë2021ÄêQ3Ïà±ÈÔöÌíÁË18%¡£¡£¡£¡£¡£¡£Ò½ÁƱ£½¡ÐÐÒµÊÇ2022ÄêQ3Ôâµ½ÀÕË÷¹¥»÷×î¶àµÄÐÐÒµ£¬£¬£¬£¬£¬Ã¿42¸ö×éÖ¯ÖоÍÓÐÒ»¸öѬȾÀÕË÷Èí¼þ£¬£¬£¬£¬£¬Í¬±ÈÔöÌí5%¡£¡£¡£¡£¡£¡£
https://blog.checkpoint.com/2022/10/26/third-quarter-of-2022-reveals-increase-in-cyberattacks/