ChromeÐÞ¸´±»ÀûÓé¶´CVE-2022-3075

Ðû²¼Ê±¼ä 2022-09-05
1¡¢Chrome½ô¼±¸üÐÂÐÞ¸´Òѱ»ÀûÓõÄ©¶´CVE-2022-3075

      

GoogleÔÚ9ÔÂ2ÈÕÐû²¼½ô¼±¸üУ¬ÐÞ¸´Chromeä¯ÀÀÆ÷ÖÐÒѱ»ÀûÓõÄ©¶´£¨CVE-2022-3075£© ¡£¸Ã©¶´ÊÇMojoÖеÄÊý¾ÝÑéÖ¤²»×㵼ֵģ¬MojoÊÇÒ»×éÔËÐÐʱ¿â£¬¿ÉÓÃÓÚ¿çÈÎÒâ½ø³Ì¼äºÍ½ø³ÌÄÚ½çÏÞͨ±¨ÏûÏ¢ ¡£ä¯ÀÀÆ÷½«×Ô¶¯¼ì²é¸üУ¬²¢ÔÚÏÂ´ÎÆô¶¯ºó×Ô¶¯°²×° ¡£¾¡¹Ü¸Ã©¶´Òѱ»¹ã·ºÀûÓ㬵«Google²¢Î´·ÖÏí¹ØÓÚÕâЩ¹¥»÷µÄϸ½ÚÐÅÏ¢ ¡£ÕâÊÇGoogle×Ô½ñÄêÄê³õÒÔÀ´ÐÞ¸´µÄµÚ6¸öChromeÁãÈÕ©¶´ ¡£


https://thehackernews.com/2022/09/google-release-urgent-chrome-update-to.html


2¡¢Defender½«ChromeºÍEdgeµÈÓ¦ÓÃÎó±¨ÎªWin32/Hive.ZY

      

¾ÝýÌå9ÔÂ4ÈÕ±¨µÀ£¬Ã¿´ÎÔÚWindowsÖдò¿ªGoogle Chrome¡¢Microsoft Edge¡¢DiscordºÍÆäËüElectronÓ¦Ó÷¨Ê½Ê±£¬Microsoft Defender¶¼ÊдíÎ󵨽«ÕâЩӦÓ÷¨Ê½¼ì²âΪ"Win32/Hive.ZY" ¡£ÎÊÌ⿪ʼÓÚÉÏÖÜÈÕÔçÉÏ£¬Æäʱ΢ÈíÍÆ³öÁËDefenderÇ©Ãû¸üР1.373.1508.0£¬ÐÂÔöÁËÁ½¸öÍþв¼ì²â£¬ÆäÖаüÂÞBehavior:Win32/Hive.ZY ¡£Ä¿Ç°£¬Î¢ÈíÒÑÐû²¼DefenderÄþ¾²ÖÇÄܸüа汾1.373.1537.0£¬¸Ã¸üÐÂËÆºõ½â¾öÁËWin32/Hive.ZYÎó±¨ÎÊÌâ ¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-falsely-detects-win32-hivezy-in-google-chrome-electron-apps/


3¡¢¶íÂÞ˹Yandex Taxi±»ºÚµ¼ÖÂĪ˹¿Æ´ó¹æÄ£½»Í¨¶ÂÈû

      

¾Ý9ÔÂ2ÈÕ±¨µÀ£¬¶íÂÞ˹µÄ´ò³µÓ¦Ó÷¨Ê½Yandex Taxi±»ºÚ£¬µ¼ÖÂĪ˹¿Æ·ºÆð´ó¹æÄ£½»Í¨Óµ¶Â ¡£¹¥»÷·¢ÉúÔÚ9ÔÂ1ÈÕ£¬¹¥»÷Õß½«ÊýÊ®Á¾³ö×â³µÅÉÍùÁËĪ˹¿ÆÖ÷Òª½ÖµÀÖ®Ò»Kutuzovsky Prospekt ¡£´Ë´Î¶Â³µÔ¼ÄªÁ¬ÐøÁËÈý¸öСʱ£¬YandexµÄÄþ¾²ÍŶÓѸËÙ½â¾öÁ˸ÃÎÊÌ⣬²¢ÔÊÐí½«¸ïÐÂËã·¨ÒÔ·ÀÓù´ËÀ๥»÷ ¡£ºÚ¿ÍÍÅ»ïAnonymous¶Ô´Ë´Î¹¥»÷ÂôÁ¦£¬²¢ÌåÏÖ¸ÃÐж¯ÊÇÓëIT Army of UkraineºÏ×÷½øÐеÄ ¡£


https://www.hackread.com/anonymous-russian-yandex-taxi-app-hacked/


4¡¢ÃÀ¹ú¹ú˰¾Öй¶Լ12ÍòÄÉ˰È˵ÄÐÕÃûºÍÊÕÈëµÈÐÅÏ¢

      

ýÌå9ÔÂ3Èճƣ¬ÃÀ¹ú¹ú˰¾ÖÒâÍâй¶ÁËÔ¼120000ÃûÄÉ˰È˵ÄÐÅÏ¢ ¡£±»Ó°ÏìµÄÄÉ˰ÈËÔÚÄÉ˰É걨±íÖÐÌá½»ÁË990-T±í¸ñ£¬¸Ã±í¸ñÓÃÓÚ³ÂËßÖ§¸¶¸øÃâ˰×éÖ¯µÄÎÞ¹ØÒµÎñÊÕÈ룬ÀýÈç·ÇÓªÀû×éÖ¯»òIRAºÍSEPÍËÐÝÕË»§ ¡£¶ÔÓÚÆÕͨÄÉ˰ÈËÀ´Ëµ£¬¸Ã±í¸ñÊDZ£ÃܵÄ£¬µ«¶ÔÓÚ·ÇÓªÀû×éÖ¯À´Ëµ£¬¸Ã±í¸ñ±ØÐëÔÚÈýÄêÄÚ¹©¹«ÖÚ²éÔÄ ¡£ÉÏÖÜÎ壬ÃÀ¹ú¹ú˰¾Ö·¢ÏÖ³ýÁË´ÈÉÆ»ú¹¹µÄ990-T±í¸ñÊý¾ÝÍ⣬»¹ÒâÍâµØ¹ûÈ»ÁËÄÉ˰ÈËIRAµÄÊý¾Ý£¬Éæ¼°ÐÕÃû¡¢ÁªÏµÐÅÏ¢ºÍ³ÂËßµÄÊÕÈëµÈ ¡£¸Ã»ú¹¹ÌåÏÖ̻¶µÄÊý¾ÝÒѱ»É¾³ý£¬²¢½«ÔÚδÀ´¼¸ÖÜÄÚ֪ͨÊÜÓ°ÏìµÄ¹«Ãñ ¡£


https://www.bleepingcomputer.com/news/security/irs-data-leak-exposes-personal-info-of-120-000-taxpayers/


5¡¢·þ×°¹«Ë¾DamartÔâµ½HiveµÄ¹¥»÷²¢±»ÀÕË÷200ÍòÃÀÔª

      

9ÔÂ2ÈÕ±¨µÀ³Æ£¬·¨¹ú·þ×°¹«Ë¾DamartÔâµ½ºÚ¿ÍÍÅ»ïHiveµÄ¹¥»÷²¢±»ÀÕË÷200ÍòÃÀÔª ¡£8ÔÂ15ÈÕ£¬DamartÔÚÆäÔÚÏßÉ̵êµÄÖ÷Ò³ÉÏÐû²¼Á˹ØÓڼƻ®Íâά»¤µÄÏûÏ¢ ¡£8ÔÂ24ÈÕ£¬DamartµÄÏúÊÛÍøÂçÖжÏ£¬Ó°ÏìÁË92¼ÒÃŵê ¡£¸Ã¹«Ë¾ÌåÏÖ¹¥»÷ÕßÒÑÈëÇÖActive Directory²¢¼ÓÃÜÁËһЩϵͳ£¬·þÎñÖÊÁ¿Ï½µÊÇÒòÆäΪÁ˱£»¤ÏµÍ³¶ø¹Ø±ÕÁËËüÃÇ ¡£Hive²¢Î´ÔÚÆäÊý¾Ý¹ûÈ»ÍøÕ¾ÉÏÁгöDamart£¬¸Ã¹«Ë¾Ò²Ò»ÔÙ·ñÈÏÆäÊý¾Ý±»µÁ ¡£Val¨¦ry MarchiveÖ¸³ö£¬¹¥»÷Õß²¢²»Ô¸ÒâÓëÆäĸ¹«Ë¾Damartex½øÐÐ̸Åв¢ÆÚÍû»ñµÃÈ«²¿Êê½ð ¡£


https://www.bleepingcomputer.com/news/security/damart-clothing-store-hit-by-hive-ransomware-2-million-demanded/


6¡¢ÈýÐÇ͸¶ÆäÃÀ¹ú·Ö¹«Ë¾µÄÄÚÍø±»ÈëÇÖÇÒ¿Í»§ÐÅϢй¶

      

º«¹úÈýÐǹ«Ë¾ÔÚ9ÔÂ2ÈÕ͸¶£¬Æä²¿Ãſͻ§µÄÐÅÏ¢Ô⵽δ¾­ÊÚȨµÄ·ÃÎÊ ¡£2022Äê7ÔÂÏÂÑ®£¬ÈýÐÇλÓÚÃÀ¹ú·Ö¹«Ë¾µÄ²¿ÃÅϵͳ±»ÈëÇÖ ¡£2022Äê8ÔÂ4ÈÕǰºó£¬Ñо¿ÈËԱͨ¹ýÊÓ²ìÈ·¶¨²¿Ãſͻ§µÄ¸öÈËÐÅÏ¢Êܵ½Ó°Ïì ¡£ÈýÐÇÌåÏÖ£¬¹¥»÷ÕßÄܹ»·ÃÎÊÐÕÃû¡¢ÁªÏµ·½Ê½¡¢ÈË¿Úͳ¼ÆÐÅÏ¢¡¢³öÉúÈÕÆÚºÍ²úÎï×¢²áÊý¾ÝµÈÐÅÏ¢£¬µ«Ã¿¸ö¿Í»§ÊÜÓ°ÏìµÄÐÅÏ¢¿ÉÄÜ»áÓÐËù²îÒì ¡£ÕâÊÇÈýÐǽñÄê·¢ÉúµÄµÚ¶þ´ÎÊý¾Ýй¶Ê¼þ£¬¸Ã¹«Ë¾ÔÚ3Ô·ÝÔøÔâµ½Lapsus$µÄ¹¥»÷£¬²¢Ð¹Â¶Á˰üÂÞGalaxyÉ豸Դ´úÂëÔÚÄÚµÄ190 GBÐÅÏ¢ ¡£


https://thehackernews.com/2022/09/samsung-admits-data-breach-that-exposed.html