Ñо¿ÈËÔ±Åû¶SQLiteÊý¾Ý¿âÖÐÒÑ´æÔÚ22ÄêµÄÄþ¾²Â©¶´
Ðû²¼Ê±¼ä 2022-10-27
¾ÝýÌå10ÔÂ25ÈÕ±¨µÀ£¬Ñо¿ÈËÔ±Åû¶ÁËSQLiteÊý¾Ý¿â¿âÖÐÕûÊýÒç³ö©¶´£¨CVE-2022-35737£©¡£¸Ã©¶´ÊÇ2000Äê10ÔµĴúÂë¸ü¸ÄʱÒýÈëµÄ£¬Õâ¸öÒÑ´æÔÚ22ÄêµÄ©¶´Ó°ÏìÁËSQLite°æ±¾1.0.12µ½3.39.1¡£Èç¹ûÔÚC APIµÄ×Ö·û´®²ÎÊýÖÐʹÓÃÊýÊ®ÒÚ×Ö½Ú¿ÉÄܵ¼ÖÂÊý×é½çÏÞÒç³ö£¬¹¥»÷ÕßÀÖ³ÉÀûÓøÃ©¶´¿ÉÔÚÄ¿±êϵͳÉÏÖ´ÐÐÈÎÒâ´úÂë¡£Ñо¿ÈËÔ±³Æ£¬ÔÚ±àдËüµÄʱºò£¨2000ÄêµÄSQLiteÔ´´úÂëÖУ©£¬ÆäʱϵͳÖ÷ÒªÊÇ32λ¼Ü¹¹£¬Õâ¿ÉÄܲ¢²»ÊÇÒ»¸ö©¶´¡£Ä¿Ç°£¬Â©¶´ÒÑÔÚ2022Äê7ÔÂ21ÈÕÐû²¼µÄ°æ±¾3.39.2ÖÐÐÞ¸´¡£
https://securityaffairs.co/wordpress/137629/hacking/cve-2022-35737-sqlite-bug.html
2¡¢VMwareÐÞ¸´Cloud Foundation²úÎïÖеÄRCE©¶´
ÔÚ10ÔÂ25ÈÕÐû²¼Äþ¾²¸üУ¬ÐÞ¸´Cloud FoundationÖеÄ©¶´(CVE-2021-39144)¡£¸Ã©¶´CVSSv3ÆÀ·Ö9.8£¬Î»ÓÚCloud FoundationʹÓõÄXStream¿ªÔ´¿âÖУ¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÔÚ²»ÐèÒªÓû§½»»¥µÄ¹¥»÷ÖÐÔ¶³ÌÀûÓÃËü¡£VMware»¹ÎªÎÞ·¨Á¢¼´°²×°²¹¶¡µÄÓû§ÌṩÁËÒ»¸öÁÙʱ½â¾ö·½°¸¡£ÓÉÓÚ©¶´µÄÑÏÖØÐÔ£¬VMwareҲΪÒÑÍ£²ú²úÎïÌṩÁ˲¹¶¡¡£´ËÍ⣬´Ë´Î¸üл¹ÐÞ¸´ÁËXMLÍⲿʵÌå©¶´(CVE-2022-31678)£¬¿Éµ¼Ö¾ܾø·þÎñ»òÐÅϢй¶¡£
https://thehackernews.com/2022/10/vmware-releases-patch-for-critical-rce.html
3¡¢ºÚ¿ÍʹÓÃPoS¶ñÒâÈí¼þÇÔÈ¡Áè¼Ý16ÍòÕÅÐÅÓÿ¨µÄÐÅÏ¢
ýÌå10ÔÂ25Èճƣ¬Group-IB·¢ÏÖÁËÁ½¸öPoS¶ñÒâÈí¼þ£¬ÓÃÓÚ´ÓPoSÖ§¸¶ÖÕ¶ËÇÔÈ¡167000¶àÕÅÐÅÓÿ¨µÄÊý¾Ý¡£¾ÝϤ£¬±»µÁµÄÊý¾Ýת´¢¿ÉÒÔͨ¹ýÔÚºÚ¿ÍÂÛ̳ÉϳöÊÛ¸øÔËÓªÍÅ»ï´øÀ´¸ß´ï334ÍòÃÀÔªµÄ¾»ÊÕÈë¡£Group-IBÈ·ÈÏÁËÓëÁ½¸öPoS¶ñÒâÈí¼þÏà¹ØµÄC2·þÎñÆ÷£¬³ÆÔÚ2022Äê2ÔÂÖÁ9ÔÂÆÚ¼ä£¬MajikPOSºÍTreasure Hunter·Ö±ðÇÔÈ¡ÁË77428ºÍ900024ÌõÖ§¸¶¼Ç¼¡£´ó²¿Ãű»µÁÐÅÓÿ¨ÊÇÓÉÃÀ¹ú¡¢²¨¶àÀè¸÷¡¢ÃØÂ³¡¢°ÍÄÃÂí¡¢Ó¢¹ú¡¢¼ÓÄô󡢷¨¹ú¡¢²¨À¼¡¢Å²ÍþºÍ¸ç˹´ïÀè¼ÓµÄÒøÐп¯Ðеġ£Ä¿Ç°£¬Éв»Çå³þ¹¥»÷ÕßÉí·Ý£¬ÒÔ¼°Êý¾ÝÊÇ·ñÒѱ»³öÊÛ¡£
https://thehackernews.com/2022/10/cybercriminals-used-two-pos-malware-to.html
4¡¢¹ú¼ÊƱÎñ¹«Ë¾See Tickets³ÆÆä¿Í»§µÄÖ§¸¶ÐÅϢй¶
¾Ý10ÔÂ25ÈÕ±¨µÀ£¬Æ±Îñ·þÎñÌṩÉÌSee TicketsÅû¶ÁËÒ»ÆðÊý¾Ýй¶Ê¼þ£¬Í¨Öª¿Í»§¹¥»÷Õß¿ÉÄÜÀûÓÃÆäÍøÕ¾ÉϵÄskimmer·ÃÎÊÁËËûÃǵÄÖ§¸¶¿¨ÏêϸÐÅÏ¢¡£See TicketsÓÚ2021Äê4Ô·¢ÏÖÁËÕâһй¶Ê¼þ£¬Ö±µ½2022Äê1ÔÂ8ÈÕ£¬²ÅÔÚÆäÍøÕ¾ÉÏÍêȫɾ³ýÁ˶ñÒâ´úÂë¡£½øÒ»·¨Ê½²éºó£¬See TicketsÓÚ2022Äê9ÔÂ12Èյóö½áÂÛ£¬Î´¾ÊÚȨµÄ¸÷·½¿ÉÄÜÒѾÇÔÈ¡Á˿ͻ§µÄÖ§¸¶¿¨ÐÅÏ¢¡£Ñ¬È¾·¢ÉúÔÚ2019Äê6ÔÂ25ÈÕ£¬Òò´ËÊý¾Ýй¶Ê¼þµÄÁ¬ÐøÊ±¼ä³¤´ï2.5Äê¡£
https://www.bleepingcomputer.com/news/security/see-tickets-discloses-25-years-long-credit-card-theft-breach/
5¡¢MicrosoftÐû²¼¹ØÓÚVice Society¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß
10ÔÂ25ÈÕ£¬MicrosoftÐû²¼Á˹ØÓÚVice Society£¨DEV-0832£©Õë¶ÔÈ«Çò½ÌÓýÐÐÒµµÄ¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß¡£¸ÃÍÅ»ïÔÚ¹ýÈ¥Ò»ÄêÀûÓÃÁ˶àÖÖÉÌÆ·ÀÕË÷Èí¼þµÄ±äÌ壬°üÂÞBlackCat¡¢QuantumLocker¡¢Zeppelin£¬ÒÔ¼°×î½üµÄZeppelinµÄVice Society±äÌå¡£×î½üÒ»´Î¹¥»÷·¢ÉúÔÚ2022Äê9ÔÂÏÂÑ®£¬DEV-0832ÔÙ´ÎʹÓÃÁË.lockedÎļþÀ©Õ¹Ãû²¢½«ÀÕË÷Èí¼þpayload¸ÄΪRedAlert±äÌå¡£ÔÚ½ñÄê7ÔµÄÒ»´Î¹¥»÷ÖУ¬¸ÃÍÅ»ïʵÑé°²×°QuantumLocker¶þ½øÖÆÎļþ²¢ÔÚÎå¸öСʱÄÚ°²×°Zeppelin¶þ½øÖÆÎļþ¡£Õâ±íÃ÷¸ÃÍÅ»ï¿ÉÄÜά»¤×Ŷà¸öÀÕË÷Èí¼þpayload²¢Æ¾¾ÝÄ¿±ê·ÀÓù½øÐÐÇл»¡£
https://www.microsoft.com/en-us/security/blog/2022/10/25/dev-0832-vice-society-opportunistic-ransomware-campaigns-impacting-us-education-sector/
6¡¢SurfsharkÐû²¼2022ÄêQ3È«ÇòÊý¾Ýй¶Ê¼þµÄ³ÂËß
ýÌå10ÔÂ25ÈÕ±¨µÀ£¬SurfsharkÐû²¼Á˹ØÓÚ2022ÄêQ3È«ÇòÊý¾Ýй¶Ê¼þµÄ³ÂËß¡£³ÂËßÖ¸³ö£¬2022ÄêµÚÈý¼¾¶È¹²ÓÐ1.089ÒÚ¸öÕË»§±»µÁ£¬±ÈÉÏÒ»¼¾¶È¸ß³ö70%£»Q3ÊÜÊý¾Ýй¶ӰÏì×î´óµÄ5¸ö¹ú¼ÒºÍµØÓòÊǶíÂÞ˹¡¢·¨¹ú¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢ÃÀ¹úºÍÎ÷°àÑÀ£»ËäÈ»¶íÂÞ˹µÄй¶×ÜÊý×î¶à£¨2230Íò£©£¬µ«·¨¹úµÄÊý¾Ýй¶ÃܶÈ×î¸ß£¬Æ½¾ùÿ1000È˾ÍÓÐ212¸öй¶ÕË»§£»ÔÚ¹ýȥʮÄêÖУ¬ÃÀ¹úÈÔÈ»ÊDZ»¹¥»÷×î¶àµÄ¹ú¼Ò¡£
https://www.infosecurity-magazine.com/news/data-breaches-rise-by-70-q3-2022/