ºÚ¿ÍÔÚ°µÍø³öÊÛº¬½ü5ÒÚÌõWhatsAppÓû§¼Ç¼µÄÊý¾Ý¿â
Ðû²¼Ê±¼ä 2022-11-28¾ÝCybernewsÔÚ11ÔÂ26ÈÕ±¨µÀ£¬ºÚ¿ÍÔÚ°µÍø³öÊÛÒ»¸ö°üÂÞ2022Äê4.87ÒÚWhatsAppÓû§ÊÖ»úºÅÂëµÄÊý¾Ý¿â¡£¸ÃÊý¾Ý¼¯°üÂÞÀ´×Ô84¸ö¹ú¼Ò/µØÓòµÄÓû§Êý¾Ý£¬Éæ¼°ÃÀ¹ú£¨3200Íò£©¡¢°£¼°£¨4500Íò£©¡¢Òâ´óÀû£¨3500Íò£©¡¢É³Ìذ¢À²®£¨2900Íò£©¡¢·¨¹ú£¨2000Íò£©ºÍÍÁ¶úÆä£¨2000Íò£©¡£¹¥»÷ÕßÒÔ7000ÃÀÔªµÄ¼Û¸ñ³öÊÛÃÀ¹úÊý¾Ý£¬Ó¢¹úµÄ2500ÃÀÔª£¬µÂ¹úµÄ2000ÃÀÔª¡£MetaµÄ·¢ÑÔÈË˵£¬¸Ã³ÂËßÊÇÍÆ²âÐÔÖʵ쬻ùÓÚδ¾Ö¤ÊµµÄ½ØÍ¼£¬²¢Ôö²¹Ëµ¸Ã¹«Ë¾Ã»Óз¢ÏÖWhatsAppϵͳÓÐÈκÎÊý¾Ýй¶ÎÊÌâ¡£
https://cybernews.com/news/whatsapp-data-leak/
2¡¢ÐÁÐÁÄÇÌáÖÝÁ¢´óѧÔâµ½ÀÕË÷ÍÅ»ïVice SocietyµÄ¹¥»÷
¾Ý11ÔÂ25ÈÕ±¨µÀ£¬ÐÁÐÁÄÇÌáÖÝÁ¢¼¼ÊõºÍÉçÇøÑ§ÔºÔâµ½ÀÕË÷ÍÅ»ïVice SocietyµÄ¹¥»÷¡£¹¥»÷ÕßÔÚËûÃǵÄÍøÕ¾¹ûÈ»ÁËÒ»³¤´®±»µÁÎļþ£¬ÕâЩÎļþµÄÈÕÆÚ´Ó¼¸Äêǰһֱµ½2022Äê11ÔÂ24ÈÕ£¬Õâ±íÃ÷ѧУ²¢Î´Ö§¸¶Êê½ð¡£¸ÃѧУÒÑ֪ͨÆäѧÉúºÍÔ±¹¤´Ë´Î¹¥»÷ʼþ£¬²¢ÌåÏÖÔÚÏß·þÎñºÍÕý³£ÔËÓªµÄ»Ö¸´ÐèÒªÒ»¶Îʱ¼ä¡£Vice Societyºã¾ÃÒÔÀ´Ò»Ö±Õë¶ÔK-12ѧУºÍ´óѧµÈ½ÌÓý»ú¹¹¡£
https://www.bleepingcomputer.com/news/security/vice-society-ransomware-claims-attack-on-cincinnati-state-college/
3¡¢Sysdig͸¶Áè¼Ý1600¸öDocker Hub¾µÏñÒþ²Ø¶ñÒâ´úÂë
11ÔÂ23ÈÕ£¬SysdigÐû²¼³ÂËß͸¶£¬1652¸ö¹ûÈ»µÄDocker Hub¾µÏñÒþ²ØÁ˶ñÒâ´úÂë¡£×î³£¼ûµÄÀàÐÍÊǼÓÃܿ󹤣¬ÔÚ608¸öÈÝÆ÷¾µÏñÖз¢ÏÖ£¬ËüÃÇÒÔ·þÎñÆ÷×ÊԴΪĿ±ê£¬Îª¹¥»÷ÕßÍÚ¾ò¼ÓÃÜ»õ±Ò¡£Æä´ÎÊÇÒþ²ØÇ¶Èëʽ»úÃܵľµÏñ£¬¹²281¸ö£¬ÕâЩ¾µÏñÖÐǶÈëÁËSSHÃÜÔ¿¡¢AWSƾ֤¡¢GitHubÁîÅÆºÍNPMÁîÅÆµÈ¡£Sysdig»¹·¢ÏÖÐí¶à¶ñÒâ¾µÏñʹÓÃÓòÃû·Âðαװ³ÉºÏ·¨¾µÏñ£¬Ö¼ÔÚÈÃÓû§Ñ¬È¾¼ÓÃܿ󹤣¬ÆäÖÐÁ½¸öÑù±¾Òѱ»ÏÂÔØ½ü17000´Î¡£
https://sysdig.com/blog/analysis-of-supply-chain-attacks-through-public-docker-images/
4¡¢¹ú¼ÊÐ̾¯×éÖ¯µÄÖ´·¨Ðж¯HAECHI-III½É»ñ1.3ÒÚÃÀÔª
¾ÝýÌå11ÔÂ24Èճƣ¬¹ú¼ÊÐ̾¯×éÖ¯´úºÅΪHAECHI IIIµÄÖ´·¨Ðж¯£¬ÒѽɻñÓëÖÖÖÖÍøÂç·¸×ï»î¶¯Ïà¹ØµÄ1.3ÒÚÃÀÔªµÄ×ʲú¡£¸ÃÐж¯µÄʱ¼äΪ2022Äê6ÔÂ28ÈÕÖÁ11ÔÂ23ÈÕ£¬×ܹ²´þ²¶ÁË975ÈË£¬·âÁ˽ü2800¸öÒøÐкÍÐéÄâ×ʲúÕË»§£¬²¢½â¾öÁË1600¶àÆð°¸¼þ¡£´Ë´ÎÖ´·¨Ðж¯»¹·¢ÏÖÁË16ÖÖеķ¸×ïÇ÷ÊÆ£¬Éæ¼°ÖÖÖÖÀËÂþƾֺÍͶ×ÊÆÛÕ©»î¶¯£¬ÕâÓÐÖúÓÚÈ«ÇòÖ´·¨²¿ÃŽÓÄɸüÓÐÕë¶ÔÐÔµÄÖ´·¨Ðж¯¡£
https://thehackernews.com/2022/11/interpol-seized-130-million-from.html
5¡¢´÷¶û¡¢»ÝÆÕºÍÁªÏëµÄÉ豸ÈÔʹÓùýʱµÄOpenSSL¼ÓÃÜ¿â
¾ÝýÌå11ÔÂ25ÈÕ±¨µÀ£¬Binarly·¢ÏÖ£¬´÷¶û¡¢»ÝÆÕºÍÁªÏëµÄÉ豸ÈÔÔÚʹÓùýʱ°æ±¾µÄOpenSSL¼ÓÃܿ⡣Ñо¿·¢ÏÖ£¬ÓëÁªÏëThinkpadÆóÒµÉ豸Ïà¹ØµÄ¹Ì¼þ¾µÏñʹÓÃÁËÈý¸ö²îÒì°æ±¾µÄOpenSSL£º0.9.8zb¡¢1.0.0aºÍ1.0.2j£¬×îºóÒ»¸ö°æ±¾ÓÚ2018ÄêÐû²¼¡£³ÂËßÖ¸³ö£¬µ±Éæ¼°µ½±àÒë´úÂëʱ£¬ÆÈÇÐÐèÒªÒ»¸öÌØ±ðµÄSBOMÑéÖ¤²ã£¬ÒÔ±ãÔÚ¶þ½øÖƲãÃæÉÏÑéÖ¤Ó빩ӦÉÌÌṩµÄʵ¼ÊSBOMÏàÆ¥ÅäµÄµÚÈý·½ÒÀÀµÐÅÏ¢ÁÐ±í£¬trust-but-verifÒªÁìÊÇ´¦ÖÃSBOM¹ÊÕϺͼõÉÙ¹©Ó¦Á´·çÏÕµÄ×î¼Ñ·½Ê½¡£
https://thehackernews.com/2022/11/dell-hp-and-lenovo-devices-found-using.html
6¡¢Dragos³ÆºÚ¿ÍÍÅ»ïÊÔͼ¹¥»÷ºÉÀ¼Òº»¯ÌìÈ»ÆøÕ¾µÄϵͳ
11ÔÂ27ÈÕ±¨µÀ£¬ºÚ¿ÍÍÅ»ïXenotimeºÍKamaciteÒ»Ö±ÔÚÊÔͼ¹¥»÷ºÉÀ¼Â¹Ìص¤GasunieÒº»¯ÌìÈ»ÆøÕ¾µÄϵͳ¡£FBI͸¶XenotimeºÍKamaciteÓë¶íÂÞ˹ÓйØÁª¡£ºÉÀ¼¹«Ë¾ElectricIQÒ²³ÂËß˵£¬Õë¶ÔÅ·Ö޺ͺÉÀ¼ÖØÒª»ù´¡ÉèÊ©µÄ»î¶¯ÓÐËùÔö¼Ó¡£Fox-ITÌåÏÖ£¬ÓÉÓÚÈ«ÇòÄÜԴΣ»ú£¬ºÚ¿ÍÍÅ»ïÒ»Ö±ÔÚ¹¥»÷ÄÜÔ´ÐÐÒµµÄ×éÖ¯£¬ÌرðÊÇÒº»¯ÌìÈ»Æø¹©Ó¦ºÍ·ÖÏúµÄ¹©Ó¦Á´¡£
https://www.databreaches.net/russian-hackers-target-dutch-lng-terminal/