΢ÈíÐû²¼12Ô·ݵÄÄþ¾²¸üУ¬×ܼÆÐÞ¸´49¸ö©¶´

Ðû²¼Ê±¼ä 2022-12-14
1¡¢Î¢ÈíÐû²¼12Ô·ݵÄÄþ¾²¸üУ¬×ܼÆÐÞ¸´49¸ö©¶´

      

12ÔÂ13ÈÕ£¬Î¢ÈíÐû²¼Öܶþ²¹¶¡£¬ÐÞ¸´Á˰üÂÞÒ»¸öÒѱ»¼«ÀûÓõÄ©¶´ÔÚÄÚµÄ49¸ö©¶´¡£´Ë´Î¸üÐÂÐÞ¸´ÁËÁ½¸öÁãÈÕ©¶´£¬·Ö±ðΪWindows SmartScreenÄþ¾²¹¦Ð§Èƹý©¶´£¨CVE-2022-44698£©£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÖÆ×÷Ò»¸ö¶ñÒâÎļþÀ´ÈƹýMOTW·ÀÓù £»ÒÔ¼°DirectXͼÐÎÄÚºËȨÏÞÌáÉý©¶´£¨CVE-2022-44710£©£¬ÀÖ³ÉÀûÓôË©¶´¿É»ñµÃSYSTEMȨÏÞ¡£ÆäÖУ¬Â©¶´CVE-2022-44698Òѱ»»ý¼«ÀûÓá£


https://www.bleepingcomputer.com/news/microsoft/microsoft-december-2022-patch-tuesday-fixes-2-zero-days-49-flaws/


2¡¢UberÒòµÚÈý·½¹©Ó¦ÉÌÔâµ½¹¥»÷Ô´´úÂëºÍÔ±¹¤ÐÅÏ¢µÈй¶

      

¾ÝýÌå12ÔÂ12ÈÕ±¨µÀ£¬ºÚ¿ÍUberLeaksÔÚÂÛ̳ÉÏÐû²¼ÁË´ÓUberºÍUber EatsÇÔÈ¡µÄÊý¾Ý¡£Ð¹Â¶µÄÊý¾Ý°üÂÞÔ´´úÂë¡¢IT×ʲú¹ÜÀí³ÂËß¡¢Êý¾ÝÏú»Ù³ÂËß¡¢WindowsÓòµÇ¼ÃûÒÔ¼°Áè¼Ý77000¸öUberÔ±¹¤µÄÐÅÏ¢µÈ¡£Ñо¿ÈËÔ±×î³õÈÏΪÕâЩÊý¾ÝÊÇÔÚ9Ô·ݵĹ¥»÷ʼþÖб»µÁµÄ£¬µ«UberÌåÏÖÕâÓëµÚÈý·½¹©Ó¦É̵ÄÄþ¾²Â©¶´ÓйØ¡£UberÌåÏÖ£¬ÓÃÓÚ×ʲú¹ÜÀíºÍ¸ú×Ù·þÎñµÄTeqtivityÔâµ½¹¥»÷£¬¹¥»÷Õß»ñµÃÁËÆäΪ¿Í»§´æ´¢Êý¾ÝµÄTeqtivity AWS±¸·Ý·þÎñÆ÷µÄ·ÃÎÊȨÏÞ¡£


https://www.bleepingcomputer.com/news/security/uber-suffers-new-data-breach-after-attack-on-vendor-info-leaked-online/


3¡¢ÀÕË÷ÍÅ»ïLockBit³ÆÒÑ´Ó¼ÓÖݲÆÕþ²¿ÇÔÈ¡76 GBµÄÊý¾Ý

      

¾Ý12ÔÂ12ÈÕ±¨µÀ£¬LockBitÉù³ÆÒÑÈëÇÖ¼ÓÀû¸£ÄáÑÇÖݵIJÆÕþ²¿£¬²¢ÇÔÈ¡ÁËÊý¾Ý¿â¡¢»úÃÜÊý¾Ý¡¢²ÆÕþÎļþºÍITÏà¹ØµÄÎļþ¡£¹¥»÷Õß»¹Ðû²¼ÁËĿ¼ºÍ´æ´¢ÎļþÊýÁ¿µÄ½ØÍ¼£¬ÏÔʾÁè¼Ý114000¸öÎļþ¼ÐÖÐÓÐÁè¼Ý246000¸öÎļþ£¬×ܼÆ75.3GBµÄÊý¾Ý¡£Ä¿Ç°£¬LockBitÒªÇóµÄÊê½ð½ð¶îÉв»Çå³þ£¬µ«ÊÇÆäÍøÕ¾µÄµ¹¼ÆÊ±ÏÔʾҪÔÚ12ÔÂ24ÈÕ֮ǰ¸¶¡£¼ÓÖÝÖݳ¤½ô¼±·þÎñ°ì¹«ÊÒÌåÏÖ£¬¼ÓÖÝÍøÂçÄþ¾²¼¯³ÉÖÐÐÄ£¨Cal-CSIC£©ÕýÔÚ»ý¼«Ó¦¶Ô´Ëʼþ£¬µ«Ã»ÓÐÌṩ̫¶àϸ½ÚÐÅÏ¢¡£


https://www.cyberscoop.com/lockbit-ransomware-california-department-of-finance/


4¡¢Ó¡¶ÈÍâ½»²¿µÄÍøÕ¾Ð¹Â¶Íâ¼®ÈËÊ¿»¤ÕÕÏêϸÐÅÏ¢µÈÄÚÈÝ

      

ýÌå12ÔÂ12Èճƣ¬Ó¡¶ÈÍâ½»²¿µÄGlobal Pravasi Rishta PortalÍøÕ¾Ð¹Â¶ÁËÍâ¼®ÈËÊ¿µÄ»¤ÕÕÏêϸÐÅÏ¢¡£ÕâÊÇÒ»¸öÖ¼ÔÚÁ¬½Ó3000ÍòÓ¡¶ÈÇÈÃñµÄƽ̨£¬ÒÔÃ÷ÎĵÄÐÎʽ¹ûÈ»ÁËÐÕÃû¡¢¾Óס¹ú¼ÒÓʼþµØÖ·¡¢Ö°Òµ×´¿ö¡¢µç»°ºÍ»¤ÕÕºÅÂëµÈÐÅÏ¢¡£Ð¹Â¶Ô­Òò¿ÉÄÜÊÇÄþ¾²´ëÊ©²»×㣬ÀýÈçȱ·¦Éí·ÝÑéÖ¤ÒªÁì¡£CybernewsÒÑÁªÏµÍâ½»²¿¼û¸æÆäй¶Ê¼þ£¬²¢Ã»ÓÐÊÕµ½»Ø¸´£¬µ«¸ÃÎÊÌâÔÚ¼¸ÌìºóµÃµ½Á˽â¾ö¡£


https://securityaffairs.co/wordpress/139561/data-breach/indian-foreign-ministrys-global-pravasi-rishta-portal-leaks-expat-passport-details.html


5¡¢Check PointÐû²¼¹ØÓÚÀÕË÷Èí¼þAzovµÄÉî¶È·ÖÎö³ÂËß

      

Check Point ResearchÔÚ12ÔÂ12ÈÕÐû²¼Á˹ØÓÚÀÕË÷Èí¼þAzovµÄÉî¶È·ÖÎö³ÂËß¡£AzovÊ×ÏÈ×÷Ϊ½©Ê¬ÍøÂçSmokeLoaderµÄpayloadÒýÆðÑо¿ÈËÔ±µÄ×¢Ò⣬ËüÓëÆÕͨÀÕË÷Èí¼þµÄÇø±ðÖ®Ò»ÊÇËüÐÞ¸ÄÁËijЩ64λ¿ÉÖ´ÐÐÎļþÀ´Ö´ÐÐ×Ô¼ºµÄ´úÂë¡£ÕâÖÖ¶ÔÄ¿±êµÄ¿ÉÖ´ÐÐÎļþµÄÇÖÂÔÐÔ¶à̬ѬȾµ¼Ö´óÁ¿¹ûÈ»¿ÉÓõÄÎļþ±»AzovѬȾ£¬Ã¿Ìì¶¼ÓÐÊý°Ù¸öеÄAzovÏà¹ØÑù±¾±»Ìá½»µ½VirusTotal¡£½ØÖÁ2022Äê11Ô£¬¸ÃÑù±¾ÒѾ­Áè¼Ý17000¸ö¡£


https://research.checkpoint.com/2022/pulling-the-curtains-on-azov-ransomware-not-a-skidsware-but-polymorphic-wiper/


6¡¢Unit 42Ðû²¼½üÆÚеÄKerberos¹¥»÷·½Ê½µÄ·ÖÎö³ÂËß

      

12ÔÂ12ÈÕ£¬Unit 42Ðû²¼Á˽üÆÚеÄKerberos¹¥»÷·½Ê½µÄ·ÖÎö³ÂËß¡£Active DirectoryµÄ¹ã·ºÊ¹ÓÃʹKerberos¹¥»÷³ÉΪÐí¶à¹¥»÷ÕßµÄÖ÷ÒªÊֶΣ¬Ñо¿ÈËÔ±·¢ÏÖÁËÐµĹ¥»÷¼¼Êõ£¬Diamond TicketºÍSapphire Ticket£¬Ê¹¹¥»÷ÕßÄܹ»²»ÊÜÏÞÖÆµØ·ÃÎÊADÓòÖеÄËùÓзþÎñºÍ×ÊÔ´¡£Sapphire Ticket¹¥»÷ÐèÒª»ñÈ¡ÓòÖÐÓû§µÄƾ¾Ý£¬È»ºóÀûÓÃÆ¾¾Ý»ñÈ¡TGT£¬²¢½«ÆäÓÃÓÚ½âÃܸßȨÏÞÓû§µÄPAC¡£Diamond Ticket¹¥»÷Ê×ÏÈÊÇ»ñÈ¡TGT£¬È»ºóʹÓÃKRBTGTÕÊ»§µÄÃÜÔ¿½âÃÜTGT²¢ÐÞ¸ÄTicket£¬ÌáÉýȨÏÞ¡£


https://unit42.paloaltonetworks.com/next-gen-kerberos-attacks/