ISCÐû²¼¸üУ¬ÐÞ¸´BIND DNSÈí¼þÖеĶà¸öÄþ¾²Â©¶´
Ðû²¼Ê±¼ä 2022-09-27
9ÔÂ21ÈÕ£¬Internet Systems Consortium(ISC)Ðû²¼Äþ¾²¸üУ¬ÐÞ¸´BIND DNSÈí¼þÖеĶà¸ö¿ÉÔ¶³ÌÀûÓõÄ©¶´¡£ÆäÖнÏΪÑÏÖØµÄÊÇͨ¹ýTKEY RR´¦ÖÃDiffie-HellmanÃÜÔ¿½»»»µÄ´úÂëÖеÄÄÚ´æÐ¹Â¶Â©¶´£¨CVE-2022-2906£©¡¢ECDSA DNSSECÑéÖ¤ÂëÖеÄÄÚ´æÐ¹Â¶Â©¶´£¨CVE-2022-38177£©¡¢¿Éµ¼ÖÂBIND 9½âÎöÆ÷Íß½âµÄ©¶´£¨CVE-2022-3080£©ºÍEdDSA DNSSECÑéÖ¤ÂëÖеÄй¶©¶´£¨CVE-2022-38178£©¡£ISCÌåÏÖ£¬ÉÐδ·¢ÏÖÉÏÊö©¶´ÔÚÒ°Íâ±»ÀûÓõĻ¡£
https://securityaffairs.co/wordpress/136164/security/bind-dns-software-flaws-2.html
2¡¢Google PlayºÍApp StoreÖжà¸ö¹ã¸æÓ¦Óñ»°²×°1300Íò´Î
¾ÝýÌå9ÔÂ26ÈÕ±¨µÀ£¬Ñо¿ÈËÔ±ÔÚGoogle PlayÉÏ·¢ÏÖÁË75¸ö¹ã¸æÓ¦Óã¬ÔÚApp StoreÉÏ·¢ÏÖÁËÁíÍâ10¸ö¹ã¸æÓ¦Óã¬×ܹ²±»°²×°ÁË1300Íò´Î¡£³ýÁËÏòÊÖ»úÓû§Í¶·Å¿É¼ûºÍÒþ²ØµÄ¹ã¸æÍ⣬ÕâЩÆÛÕ©Ó¦Óû¹Í¨¹ýð³äºÏ·¨µÄÓ¦ÓÃÀ´´´ÊÕ¡£ËäÈ»ÕâÖÖÀàÐ͵ÄÓ¦Óò»´æÔÚÑÏÖØµÄÍþв£¬µ«¹¥»÷Õß¿ÉÒÔÀûÓÃËüÃǽøÐиüΣÏյĻ¡£Ñо¿ÍŶÓÒѽ«ÕâЩ·¢ÏÖ֪ͨGoogleºÍApple£¬Ä¿Ç°ÕâЩӦÓÃÒÑ´Ó¹Ù·½AndroidºÍiOSÉ̵êÖÐɾ³ý¡£
https://www.bleepingcomputer.com/news/security/adware-on-google-play-and-apple-store-installed-13-million-times/
3¡¢Ó¡¶ÈijҽÁÆÈí¼þ¹«Ë¾Ð¹Â¶170ÍòÈËCovid¿¹Ô²âÊÔ½á¹û
ýÌå9ÔÂ25Èճƣ¬Ó¡¶ÈijҽÁÆÈí¼þÌṩÉ̵ÄElasticsearch·þÎñÆ÷й¶ÁË170ÍòÈ˵ÄCovid¿¹Ô²âÊÔ½á¹û¡£AnuragÔÚShodanÉÏɨÃèÅäÖôíÎóµÄÊý¾Ý¿âʱ£¬×¢Ò⵽һ̨·þÎñÆ÷̻¶ÁËÁè¼Ý23GBµÄÊý¾Ý¡£ÆäÖаüÂÞ¹ýÈ¥¼¸ÄêÍùÀ´ÓÚÓ¡¶ÈµÄÓ¡¶ÈÈ˺ÍÍâ¹úÓο͵ÄÐÅÏ¢£¬ÈçÐÕÃû¡¢¹ú¼®¡¢µØÖ·¡¢µç»°ºÅÂë¡¢Éí·ÝÖ¤ºÅÂë¡¢¼ì²â½á¹û¡¢AadhaarºÅºÍ»¤ÕÕºÅÂëµÈ¡£Ñо¿ÈËÔ±ÌåÏÖ£¬¸ÃÊý¾Ý¿â×Ô2022Äê7ÔÂ2ÈÕ¿ªÊ¼Ì»Â¶£¬ÇÒĿǰÈÔ´¦ÓÚ¹ûȻ״̬¡£
https://www.hackread.com/covid-antigen-test-results-india-leaked/
4¡¢ÎÚ¿ËÀ¼SSUµ·»ÙÔøÇÔÈ¡²¢³öÊÛ3000Íò¸öÕË»§µÄºÚ¿ÍÍÅ»ï
ýÌå9ÔÂ24ÈÕ±¨µÀ³Æ£¬ÎÚ¿ËÀ¼Äþ¾²¾Ö(SSU)µÄÍøÂ粿Ãŵ·»ÙÁËÒ»¸öÔøÇÔÈ¡²¢³öÊÛ3000Íò¸öÕË»§µÄºÚ¿ÍÍŻ¾ÝSSU³Æ£¬ËûÃǽñºó´ÎÐж¯ÖлñÀû1400ÍòUAH£¨380000ÃÀÔª£©¡£¹¥»÷Õß×Óͨ¹ý¶ñÒâÈí¼þѬȾÀ´»ñȡƾ¾ÝºÍÊý¾Ý£¬Ö÷ÒªÕë¶ÔÎÚ¿ËÀ¼ºÍÅ·ÃË×éÖ¯µÄϵͳ¡£ËûÃÇ»¹Í¨¹ýÔÚÎÚ¿ËÀ¼±»½ûÖ¹µÄµç×ÓÖ§¸¶ÏµÍ³YuMoney¡¢QiwiºÍWebMoneyÊÕ¿î¡£±»²¶µÄÈËÊýÈÔδÅû¶£¬µ«ËûÃǶ¼Òòδ¾ÊÚȨ³öÊÛ»ò·Ö·¢ÔÚ´æ´¢ÓÚ¼ÆËã»úºÍÍøÂçÖеķÃÎÊÊÜÏÞµÄÐÅÏ¢¶øÃæÁÙÐÌÊÂËßËϼ°¶àÄê¼à½û¡£
https://securityaffairs.co/wordpress/136156/cyber-crime/ukraine-cyber-gang.html
5¡¢Î¢ÈíÐû²¼ÀûÓÃOAuthÓ¦Óù¥»÷Exchange·þÎñÆ÷µÄ·ÖÎö³ÂËß
9ÔÂ22ÈÕ£¬Î¢ÈíÐû²¼³ÂËß³ÆÆä½üÆÚÊÓ²ìÁËÒ»ÖÖ¹¥»÷£¬ÆäÖй¥»÷ÕßÔÚ±»Ñ¬È¾µÄÔÆ×â»§Öа²×°¶ñÒâOAuthÓ¦Ó÷¨Ê½£¬ÓÃÓÚ¿ØÖÆExchange OnlineÉèÖúÍÁ÷´«À¬»øÓʼþ¡£¹¥»÷ÕßÊ×ÏȶÔδÆôÓÃMFAµÄÏÕÕË»§Ö´ÐÐײ¿â¹¥»÷£¬²¢ÀûÓò»Äþ¾²µÄ¹ÜÀíÔ±ÕË»§»ñµÃ³õʼ·ÃÎÊȨÏÞ¡£È»ºó£¬¹¥»÷Õ߿ɴ´½¨¶ñÒâOAuthÓ¦Ó÷¨Ê½£¬¸Ã·¨Ê½»áÔÚµç×ÓÓʼþ·þÎñÆ÷ÖÐÌí¼Ó¶ñÒâÈëÕ¾Á¬½ÓÆ÷¡£×îºó£¬ÀûÓöñÒâÈëÕ¾Á¬½ÓÆ÷·¢ËÍ¿´ÆðÀ´ÏñÊÇÀ´×ÔÄ¿±êÓòµÄÀ¬»øÓʼþ¡£
https://www.microsoft.com/security/blog/2022/09/22/malicious-oauth-applications-used-to-compromise-email-servers-and-spread-spam/
6¡¢NSAºÍCISAÐû²¼±£»¤OTºÍICSµÄÒªº¦»ù´¡ÉèÊ©µÄÄþ¾²×Éѯ
9ÔÂ22ÈÕ£¬CISAºÍNSAÁªºÏÐû²¼Á˹ØÓÚ±£»¤ÔËÓª¼¼Êõ(OT)ºÍ¹¤Òµ¿ØÖÆÏµÍ³(ICS)µÄÒªº¦»ù´¡ÉèÊ©µÄÁªºÏÄþ¾²×Éѯ¡£¸Ãͨ¸æ·ÖÏíÁ˹¥»÷ÕßÓÃÀ´ÆÆ»µÖ§³ÖITµÄOTºÍICS×ʲúµÄËùÓв½ÖèÐÅÏ¢£¬²¢Ç¿µ÷ÁËÄþ¾²×¨ÒµÈËÔ±¿ÉÒÔ½ÓÄɵķÀÓù´ëÊ©¡£»¹Ö¸³ö£¬ÔËÓª¡¢¿ØÖÆºÍ¼à¿ØÈÕ³£Òªº¦»ù´¡ÉèÊ©ºÍ¹¤ÒµÁ÷³ÌµÄOTºÍICS×ʲúÃæÁÙµÄÍþвÈÕÒæÔö¼Ó£¬²¢ÌṩÁËһЩÓÃÀ´Ó¦¶Ô¶ÔÊֵļÆÄ±¡¢¼¼ÊõºÍ·¨Ê½(TTP)µÄ×î¼ÑÄþ¾²Êµ¼ù¡£
https://us-cert.cisa.gov/ncas/current-activity/2022/09/22/cisa-and-nsa-publish-joint-cybersecurity-advisory-control-system