GoogleÐÞ¸´ChromeÖÐÒѱ»ÀûÓõÄ©¶´CVE-2022-3723

Ðû²¼Ê±¼ä 2022-10-31
1¡¢GoogleÐÞ¸´ChromeÖÐÒѱ»ÀûÓõÄ©¶´CVE-2022-3723

      

¾Ý10ÔÂ28ÈÕ±¨µÀ£¬GoogleÐû²¼ÁËChromeµÄ½ô¼±Äþ¾²¸üУ¬ÐÞ¸´×Ô2022Äê³õÒÔÀ´µÄµÚÆß¸öÁãÈÕ©¶´¡£¸Ã©¶´(CVE-2022-3723)ÊÇChrome V8 JavascriptÒýÇæÖеÄÒ»¸öÀàÐÍ»ìÏý©¶´£¬ÓÉAvastµÄÑо¿ÈËÔ±ÓÚ½ñÄê10ÔÂ25ÈÕ³ÂËß¡£³öÓÚÄþ¾²Ô­Òò£¬¸Ã¹«Ë¾Ã»ÓÐÌṩÓйØÂ©¶´µÄÏêϸÐÅÏ¢£¬Ò²Ã»ÓÐ˵Ã÷Éæ¼°¸Ã©¶´µÄ¹¥»÷»î¶¯Ë®Æ½µÄÐÔÖÊ¡£Ñо¿ÈËԱǿÁÒ½¨ÒéChromeÓû§¾¡¿ì¸üÐÂÆää¯ÀÀÆ÷ÒÔ×èÖ¹´ËÀ๥»÷¡£


https://www.bleepingcomputer.com/news/security/google-fixes-seventh-chrome-zero-day-exploited-in-attacks-this-year/


2¡¢Ë¹Âå·¥¿ËºÍ²¨À¼Òé»áµÄITϵͳÔâµ½´ó¹æÄ£ÍøÂç¹¥»÷

      

ýÌå10ÔÂ29Èճƣ¬Ë¹Âå·¥¿ËºÍ²¨À¼Òé»áÔâµ½´ó¹æÄ£ÍøÂç¹¥»÷¡£²¨À¼Õþ¸®³Æ£¬Õâ´Î¹¥»÷¿ÉÄÜÓë²ÎÒéÔºµÄͶƱÓйØ£¬¹¥»÷ÍêÈ«ÖжÏÁËÒé»áµÄIT»ù´¡ÉèÊ©¡£²¢Í¸Â¶Õâ´Î¹¥»÷ÊÇ¶àÆ«ÏòµÄ£¬°üÂÞÀ´×ÔÂÞ˹Áª°îÄÚ²¿µÄ¹¥»÷¡£Ë¹Âå·¥¿ËÒé»á¸±Ò鳤ÌåÏÖ£¬¹¥»÷µ¼ÖÂ˹Âå·¥¿ËÒé»áµÄITϵͳºÍµç»°Ïß·̱»¾£¬¼¸Ïî·¨°¸µÄͶƱ±»ÖжÏ¡£ËûÃÇĿǰÉÐδȷ¶¨¸ÃʼþµÄÀ´Ô´£¬Æä¼¼ÊõÈËÔ±ÕýÔÚ½â¾ö¸ÃÎÊÌâ¡£


https://securityaffairs.co/wordpress/137777/hacking/slovak-polish-parliaments-cyberattacks.html


3¡¢Å·ÖÞ×î´óµÄÍ­Éú²úÉÌAurubisÔÚ±»¹¥»÷ºóϵͳ¹Ø±Õ

      

10ÔÂ28ÈÕ±¨µÀ£¬Aurubis³ÆÆäÔâµ½¹¥»÷£¬±»ÆÈ¹Ø±ÕITϵͳÒÔ·ÀÖ¹¹¥»÷ÂûÑÓ¡£AurubisÊÇÅ·ÖÞ×î´óºÍÊÀ½çµÚ¶þ´óµÄÍ­Éú²úÉÌ£¬Ã¿ÄêÉú²ú100Íò¶ÖÒõ¼«Í­¡£Aurubisͨ¸æÏÔʾ£¬ËûÃǹرÕÁËÆäËùÔڵصÄÖÖÖÖϵͳ£¬µ«²¢Î´Ó°ÏìÉú²ú¡£Ò±Á¶³§µÄÉú²úºÍ»·±£ÉèÊ©Õý³£ÔËÐУ¬½ø³ö»õÎïÒ²ÔÚÈ˹¤Î¬»¤¡£Ä¿Ç°£¬¸Ã¹«Ë¾ÈÔÕýÔÚÆÀ¹ÀÍøÂç¹¥»÷µÄÓ°Ï죬ÎÞ·¨Ô¤¼ÆÏµÍ³»Ö¸´ÐèÒª¶à³¤Ê±¼ä¡£ÏÖÔڵĵ±ÎñÖ®¼±ÊDZ£³Ö²úÁ¿ÔÚÕý³£Ë®Æ½£¬³öÓÚÕâ¸öÔ­Òò£¬Ò»Ð©²Ù×÷ÒÑתÏòÊÖ¶¯Ä£Ê½£¬Ö±µ½ÈÛÁ¶³§»Ö¸´¼ÆËã»ú¸¨ÖúµÄ×Ô¶¯»¯¡£


https://www.bleepingcomputer.com/news/security/largest-eu-copper-producer-aurubis-suffers-cyberattack-it-outage/


4¡¢°Ä´óÀûÑÇÁÙ´²ÊµÑéÊÒ³ÆÀÕË÷¹¥»÷µ¼ÖÂ22ÍòÈËÐÅϢй¶

      

¾ÝýÌå10ÔÂ27Èճƣ¬°Ä´óÀûÑÇÁÙ´²ÊµÑéÊÒ(ACL)͸¶ÆäMedlab PathologyÒµÎñ·¢ÉúÁËÊý¾Ýй¶£¬Ó°ÏìÔ¼223000Ãû»¼ÕߺÍÔ±¹¤¡£ÀÕË÷ÍÅ»ïQuantumÓÚ2022Äê6ÔÂ14ÈÕÔÚÆäTorÍøÕ¾ÉÏ´«ÁËËùÓб»µÁÎļþ£¬¹²86 GBµÄÊý¾Ý£¬°üÂÞ»¼ÕߺÍÔ±¹¤µÄÏêϸÐÅÏ¢¡¢²ÆÕþ³ÂËß¡¢·¢Æ±¡¢ºÏͬ¡¢±í¸ñ¡¢´«Æ±ºÍÆäËû˽ÈËÎļþµÈ¡£Æ¾¾ÝÍøÕ¾Êý¾Ý£¬MedLabµÄÐ¹Â¶Ò³ÃæÒѱ»·ÃÎÊ130000´Î¡£¹¥»÷·¢ÉúÓÚ2022Äê2Ô·Ý£¬µ«¸ÃÄþ¾²Ê¼þÔÚ·¢Éú9¸öÔºó²Å±»Åû¶£¬ACLµÄͨ¸æÊÔͼΪÕâÖÖÍÏÑÓÌṩÀíÓÉ¡£


https://www.databreaches.net/australian-clinical-labs-says-data-of-223000-people-hacked/


5¡¢iOSºÍmacOSÖеÄSiriSpy©¶´¿ÉÇÔÌýÓû§ÓëSiriµÄ¶Ô»°

      

ýÌåÓÚ10ÔÂ27ÈÕ±¨µÀ³Æ£¬Ó°ÏìÁËApple iOSºÍmacOSµÄSiriSpy©¶´£¨CVE-2022-32946£©£¬¿ÉÒÔ±»ÈκοɷÃÎÊÀ¶ÑÀµÄÓ¦Ó÷¨Ê½ÓÃÀ´ÇÔÌýÓû§ÓëSiriµÄ¶Ô»°¡£ÔÚ²âÊÔAirBuddyµÄ¹¦Ð§Ê±£¬Ñо¿ÈËÔ±×¢Òâµ½AirPods°üÂÞÒ»¸ö´øÓÐUUIDµÄ·þÎñ£¬¶øÇÒ¾ßÓÐÖ§³Ö֪ͨµÄ¹¦Ð§¡£½øÒ»·¨Ê½²é½«ÉÏÊöUUIDÓëÓÃÓÚSiriºÍÌýд֧³ÖµÄDoAP·þÎñÏà¹ØÁª£¬¹¥»÷Õß¿ÉÒÔ´´½¨Ò»¸ö¶ñÒâÓ¦Ó㬸ÃÓ¦ÓÿÉÒÔͨ¹ýÀ¶ÑÀÁ¬½Óµ½AirPods²¢ÔÚºóÌ¨Â¼ÖÆÒôƵ¡£Ä¿Ç°£¬¸Ã©¶´Òѱ»ÐÞ¸´¡£


https://securityaffairs.co/wordpress/137710/security/sirispy-apple-flaw-spy-conversations.html


6¡¢SymantecÐû²¼CraneflyÍÅ»ï½üÆÚ¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß

      

10ÔÂ28ÈÕ£¬SymantecÐû²¼Á˹ØÓÚCraneflyÍÅ»ï½üÆÚ¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬Cranefly£¨ÓÖÃûUNC3524£©ÕýÔÚʹÓÃÐÂdropper(Trojan.Geppei)À´°²×°ÁíÒ»¸öеĶñÒâÈí¼þ(Trojan.Danfuan)ºÍÆäËü¹¤¾ß£¨Hacktool.Regeorg£©¡£Geppei´ÓºÏ·¨µÄIISÈÕÖ¾ÖжÁÈ¡ÃüÁî¡£¶ÁÈ¡µÄÃüÁî°üÂÞ¶ñÒâ±àÂëµÄ.ashxÎļþ£¬ÕâЩÎļþ±»Éú´æµ½ÓÉÃüÁî²ÎÊýÈ·¶¨µÄÈÎÒâÎļþ¼ÐÖУ¬ËüÃÇ×÷ΪºóÃÅÔËÐС£¾¡¹ÜÒÑÔÚÄ¿±êµÄÍøÂçÉÏDZ·üÁË18¸öÔ£¬µ«Ñо¿ÈËÔ±ÉÐδÊӲ쵽¹¥»÷Õß´ÓÄ¿±êÖÐÇÔÈ¡Êý¾ÝµÄ»î¶¯¡£


https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/cranefly-new-tools-technique-geppei-danfuan