AppleÐû²¼½ô¼±¸üУ¬ÐÞ¸´Á½¸öÒѱ»»ý¼«ÀûÓõÄ©¶´
Ðû²¼Ê±¼ä 2022-08-18
8ÔÂ17ÈÕ£¬AppleÐû²¼½ô¼±¸üУ¬ÐÞ¸´Á½¸ö¿É±»ÓÃÀ´ÈëÇÖiPhone¡¢iPad»òMacµÄÁãÈÕ©¶´¡£µÚÒ»¸öÊDzÙ×÷ϵͳÄÚºËÖеÄÔ½½çдÈë©¶´£¨CVE-2022-32894£©£¬¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´ÒÔÄÚºËȨÏÞÖ´ÐдúÂë¡£µÚ¶þ¸öÊÇWebKitÖеÄÔ½½çдÈë©¶´£¨CVE-2022-32893£©£¬¿Éͨ¹ý·ÃÎʶñÒâÍøÕ¾±»Ô¶³ÌÀûÓÃÀ´Ö´ÐÐÈÎÒâ´úÂë¡£AppleÌåÏÖÕâÁ½¸ö©¶´ÒÑÔÚÒ°Íâ±»»ý¼«ÀûÓ㬵«ÊÇûÓÐÐû²¼¹ØÓÚÕâЩ¹¥»÷µÄÏêϸÐÅÏ¢¡£
https://www.securityweek.com/apple-patches-new-macos-ios-zero-days
2¡¢CS:GOƤ·ô½»Òׯ½Ì¨Ôâµ½¹¥»÷Ëðʧ¼ÛÖµ600ÍòÃÀÔªÉÌÆ·
¾ÝýÌå8ÔÂ16Èճƣ¬CS:GO£¨·´¿Ö¾«Ó¢£ºÈ«Çò¹¥ÊÆ£©×î´óµÄƤ·ô½»Òׯ½Ì¨Ö®Ò»CS.MONEYÔâµ½¹¥»÷£¬ÔÚËðʧÁ˼ÛÖµÔ¼600ÍòÃÀÔªµÄ20000¼þÎïÆ·ºóÏÂÏß¡£CS.MONEYÓµÓÐ53ÖÖÎäÆ÷µÄ1696ÖÖÆæÌØÆ¤·ô£¬¹ÜÀíµÄ×Ü×ʲú¼ÛֵΪ16500000ÃÀÔª£¬ÔÚ¹¥»÷ʼþºóϵøµ½ÁË10500000ÃÀÔª¡£¾ÝϤ£¬¹¥»÷Õßͨ¹ýijÖÖ·½Ê½»ñµÃÁËÓÃÓÚSteamÊÚȨµÄMobile Authenticator(MA)ÎļþµÄ·ÃÎÊȨÏÞ£¬È»ºó¿ØÖÆÁË100¸ö°üÂ޸÷þÎñ³ÖÓÐµÄÆ¤·ôµÄbotÕÊ»§£¬²¢½øÐÐÁËԼһǧ±Ê½»Òס£¸Ãƽ̨ÒÑÖжÏÈýÌ죬µ«±»µÁÎïÆ·ÈÔδ±»Õһء£
https://www.bleepingcomputer.com/news/security/cs-go-trading-site-hacked-to-steal-6-million-worth-of-skins/
3¡¢Ó¢¹úË®Îñ¹«Ë¾South Staffordshire WaterÔâµ½Clop¹¥»÷
¾ÝýÌå8ÔÂ16ÈÕ±¨µÀ£¬Ó¢¹úË®Îñ¹«Ë¾South Staffordshire Water³ÆÆäÔâµ½¹¥»÷µ¼ÖÂITϵͳÖжϡ£ÕâÊÇÒ»¼ÒÿÌìΪ160ÍòÏû·ÑÕßÌṩ3.3ÒÚÉýÒûÓÃË®µÄ¹«Ë¾£¬Ëü͸¶´Ëʼþ²¢Î´Ó°ÏìÆä¹©Ë®ÏµÍ³¡£ClopÍÅ»ïÉù³Æ¶Ô´Ë´Î¹¥»÷ÂôÁ¦£¬²¢ÌåÏÖ¿ÉÓ°Ï칩ˮµÄÔËÓªºÍÄþ¾²¡£¸ÃÍŻﻹÉù³ÆÒÑÇÔÈ¡ÁË5TBµÄÊý¾Ý£¬²¢Ðû²¼ÁËÒ»·Ý±»µÁÊý¾ÝÑù±¾£¬ÆäÖаüÂÞ»¤ÕÕ¡¢Éí·ÝÖ¤ºÍSCADAϵͳµÄ½ØÍ¼¡£
https://securityaffairs.co/wordpress/134450/cyber-crime/south-staffordshire-water-cyberattack.html
4¡¢ClarotyÑÝʾÈçºÎͨ¹ýÎäÆ÷»¯µÄPLCÈëÇÖOTµÄÐÂEvil¹¥»÷
¾Ý8ÔÂ16ÈÕ±¨µÀ£¬Claroty·¢ÏÖÒ»ÖÖеÄEvil PLC¹¥»÷·½Ê½£¬¿ÉÓ°ÏìÂÞ¿ËΤ¶û×Ô¶¯»¯¡¢Ê©ÄÍµÂµçÆø¡¢Í¨ÓÃµçÆø¡¢±´¼ÓÀ³¡¢Ð½ܡ¢OVARROºÍ°¬Ä¬ÉúµÄ²úÎï¡£ÕâÖÖ¹¥»÷¿ÉÒÔ½«¿É±à³ÌÂß¼¿ØÖÆÆ÷(PLC)ÎäÆ÷»¯£¬ÀûÓù¤³ÌÊÂÇéÕ¾ÈëÇÖOTºÍÆóÒµµÄÍøÂ磬Ö÷ÒªÕë¶Ô´Óʹ¤ÒµÍøÂç¡¢PLCÅäÖú͹ÊÕÏÅųýµÄ¹¤³Ìʦ¡£¹¥»÷ÕßÊ×ÏÈÔÚÒ»¸ö̻¶ÔÚÍøÉϵÄPLCÖд¥·¢¹ÊÕÏ£¬ÓÕʹ¹¤³Ìʦͨ¹ý¹¤³ÌÊÂÇéÕ¾Èí¼þÁ¬½Óµ½±»Ñ¬È¾PLC¡£µ±¹¤³Ìʦ¼ìË÷PLCÂß¼µÄÊÂÇ鸱±¾Ê±£¬¹¥»÷ÕßÔÙÀûÓÃÆ½Ì¨ÉϵÄ©¶´Ö´ÐжñÒâ´úÂë¡£
https://thehackernews.com/2022/08/new-evil-plc-attack-weaponizes-plcs-to.html
5¡¢ESET·¢ÏÖLazarusÀûÓÃеÄmacOS¶ñÒâÈí¼þµÄ¹¥»÷»î¶¯
ýÌå8ÔÂ16ÈÕ±¨µÀ³Æ£¬³¯ÏʺڿÍÍÅ»ïLazarus¿ÉÔÚ×°ÓÐÓ¢ÌØ¶ûºÍM1оƬ×éµÄÆ»¹ûMacÉÏÖ´ÐжñÒâÈí¼þ£¬ESET½«ÆäÓë»î¶¯Operation In(ter)ceptionÁªÏµÆðÀ´¡£¹¥»÷»î¶¯µÄÓÕ¶üÎļþËäȻʹÓÃ.PDFÀ©Õ¹Ãûµ«Êµ¼ÊÉÏÊÇÒ»¸öMach-O¿ÉÖ´ÐÐÎļþ£¬Æä¹¦Ð§ÊÇÆô¶¯FinderFontsUpdater£¬½ø¶øÖ´ÐÐsafarifontsagent£¬¸ÃÏÂÔØÆ÷Ö¼ÔÚ´ÓÔ¶³Ì·þÎñÆ÷¼ìË÷ÏÂÒ»½×¶ÎµÄpayload¡£ESETÌåÏÖ£¬ÓÕ¶üÊÇʹÓÃÁË2022Äê2Ô·¢±í¸øShankey NohriaµÄÖ¤ÊéÇ©ÊðµÄ£¬AppleÓÚ8ÔÂ12ÈÕÈ¡ÏûÁ˸ÃÖ¤Êé¡£
https://thehackernews.com/2022/08/north-korea-hackers-spotted-targeting.html
6¡¢Ñо¿ÈËÔ±Åû¶RTLSÖпɵ¼ÖÂMitMµÈ¹¥»÷µÄ©¶´µÄÏêÇé
8ÔÂ15ÈÕ£¬NozomiµÄÑо¿ÈËÔ±½ÒʾÁ˶à¸öÓ°ÏìUWB£¨³¬¿í´ø£©RTLS£¨ÊµÊ±¶¨Î»ÏµÍ³£©µÄ©¶´£¬¿É±»ÓÃÀ´Ö´ÐÐÖмäÈ˹¥»÷²¢²Ù¿Ø±êÇ©µØÀíλÖÃÊý¾Ý¡£RTLS¼¼Êõ¹ã·ºÓÃÓÚ¹¤Òµ»·¾³¡¢¹«¹²½»Í¨¡¢Ò½ÁƱ£½¡ºÍÖǻ۶¼ÊÐÓ¦Óã¬Ö÷Òª×÷ÓÃÊÇͨ¹ýʹÓøú×Ù±êÇ©¡¢ÐźŽÓÊÕêºÍÖÐÑë´¦ÖÃϵͳ½ç˵µØÀíΧÀ¸ÇøÓòÀ´ÐÖúÄþ¾²¡£Nozomi½¨ÒéRTLSϵͳµÄ¹ÜÀíԱʹÓ÷À»ðǽÀ´ÏÞÖÆ·ÃÎÊ£¬ÔÚÍøÂçÖмÓÈëÇÖ¼ì²âϵͳ£¬²¢Ê¹ÓôøÓÐÊý¾Ý°üͬ²½¼ÆÊýÆ÷ÖµµÄSSHËíµÀ½øÐÐÊý¾Ý¼ÓÃÜ¡£
https://www.bleepingcomputer.com/news/security/rtls-systems-vulnerable-to-mitm-attacks-location-manipulation/