GoogleÐû²¼Äþ¾²¸üР £¬ÐÞ¸´ChromeÖеĶà¸ö©¶´

Ðû²¼Ê±¼ä 2022-12-01
1¡¢GoogleÐû²¼Äþ¾²¸üР £¬ÐÞ¸´ChromeÖеĶà¸ö©¶´

11ÔÂ29ÈÕ  £¬GoogleÐû²¼ChromeÄþ¾²¸üР £¬×ܼÆÐÞ¸´ÁË28¸ö©¶´¡£ÆäÖнÏΪÑÏÖØµÄÊÇV8ÖеÄÀàÐÍ»ìÏý©¶´£¨CVE-2022-4174£©¡¢Camera CaptureÖеÄÊͷźóʹÓé¶´£¨CVE-2022-4175£©¡¢Lacros GraphicsÖеÄÔ½½çдÈë©¶´£¨CVE-2022-4176£©¡¢À©Õ¹ÖеÄÊͷźóʹÓé¶´£¨CVE-2022-4177£©ÒÔ¼°MojoÖеÄÊͷźóʹÓé¶´£¨CVE-2022-4178£©µÈ¡£GoogleÌåÏÖ  £¬Ä¿Ç°Ã»ÓйØÓÚÕâЩ©¶´ÔÚÒ°Íâ±»ÀûÓõijÂËß¡£

https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_29.html

2¡¢Lastpass͸¶ÆäÔÆ´æ´¢·þÎñÖеĿͻ§Êý¾ÝÒѾ­Ð¹Â¶

LastPassÔÚ11ÔÂ30ÈÕÐû²¼ÉùÃ÷³Æ  £¬¹¥»÷ÕßÀûÓÃÔÚ2022Äê8ÔµĹ¥»÷ʼþÖÐÇÔÈ¡µÄÐÅÏ¢ÈëÇÖÁËÆäÔÆ´æ´¢·þÎñ¡£¸Ã¹«Ë¾ÔÚÆäµÚÈý·½ÔÆ´æ´¢·þÎñÖмì²âµ½Òì³£»î¶¯  £¬Ò»µ©ÀֳɽøÈë¹¥»÷Õß»¹Éè·¨·ÃÎÊ´æ´¢ÔÚ´æ´¢·þÎñÖеĿͻ§Êý¾Ý¡£LastpassÔö²¹ÌåÏÖ  £¬ËûÃÇÕýÔÚŬÁ¦Á˽â¸ÃʼþµÄÓ°Ï췶Χ  £¬²¢È·¶¨ºÚ¿Í·ÃÎÊÁËÄÄЩÐÅÏ¢¡£ÕâÊÇLastpassÔÚ½ñÄêÅû¶µÄµÚ¶þÆðÄþ¾²Ê¼þ  £¬´Ëǰ  £¬¸Ã¹«Ë¾ÔÚ8ÔÂÈ·ÈÏÆä¿ª·¢Õß»·¾³Òò¿ª·¢ÕßÕË»§±»µÁ¶øÔâµ½ÈëÇÖ¡£

https://www.bleepingcomputer.com/news/security/lastpass-says-hackers-accessed-customer-data-in-new-breach/

3¡¢Mandiant·¢ÏÖÀûÓÃUSBÉ豸¹¥»÷·ÆÂɱö×éÖ¯µÄ»î¶¯

¾ÝMandiant 11ÔÂ28ÈÕ±¨µÀ  £¬½üÆÚ·¢ÏÖÁËÀûÓÃUSBÉ豸×÷Ϊ³õʼѬȾý½éµÄ¼äµý»î¶¯  £¬²¢¼¯ÖÐÔÚ·ÆÂɱö¡£Mandiant½«´Ë»î¶¯¸ú×ÙΪUNC4191  £¬×îÔç¿É×·Ëݵ½2021Äê9Ô  £¬¸Ã»î¶¯Ö÷ÒªÓ°ÏìÁ˶«ÄÏÑǵÄ×éÖ¯  £¬²¢ÑÓÉìµ½ÁËÃÀ¹ú¡¢Å·ÖÞºÍÑÇÌ«µØÓò¡£¼´Ê¹Ä¿±ê×é֯λÓÚÆäËûλÖà  £¬UNC4191ËùÕë¶ÔµÄϵͳʵ¼ÊλÓÚ·ÆÂɱö¡£ÔÚͨ¹ýUSBÉ豸½øÐгõʼѬȾºó  £¬¹¥»÷Õß»áÀûÓúϷ¨Ç©ÊðµÄ¶þ½øÖÆÎļþÀ´²à¼ÓÔØ3¸öеĶñÒâÈí¼þϵÁÐ  £¬MISTCLOAK¡¢DARKDEWºÍBLUEHAZE¡£ÀÖ³ÉÈëÇÖºó»á°²×°ÖØÃüÃûµÄNCAT¶þ½øÖÆÎļþ²¢ÔÚÄ¿±êϵͳÉÏÖ´Ðз´Ïòshell  £¬´Ó¶øÎª¹¥»÷ÕßÌṩºóÃÅ·ÃÎÊ¡£

https://www.mandiant.com/resources/blog/china-nexus-espionage-southeast-asia

4¡¢Ò˼ÒÕýÔÚÊÓ²ìÕë¶ÔÆä¿ÆÍþÌØºÍĦÂå¸çÃŵêµÄÍøÂç¹¥»÷

¾Ý11ÔÂ29ÈÕ±¨µÀ  £¬Ò˼ÒÕýÔÚÊÓ²ìÕë¶ÔÆä¿ÆÍþÌØºÍĦÂå¸çÃŵêµÄ¹¥»÷ʼþ¡£ÖÜÒ»  £¬¿ÆÍþÌØºÍĦÂå¸çµÄÍøµã±»Ìí¼Óµ½Vice SocietyÀÕË÷Èí¼þµÄÍøÕ¾  £¬ÍøÕ¾ÉϹûÈ»µÄÎļþÃû±íÃ÷¹¥»÷ÕßÒÑÇÔȡҵÎñºÍÔ±¹¤µÄÊý¾Ý  £¬²¢¿ÉÄÜ»¹´ÓÔ¼µ©µÄÒ˼ÒÃŵêÇÔÈ¡ÁËÆäËüÐÅÏ¢¡£¹«Ë¾·¢ÑÔÈËÌåÏÖËûÃÇÕýÔÚÓëÏà¹ØÕþ¸®ºÍÍøÂçÄþ¾²ºÏ×÷»ï°éÒ»ÆðÊÓ²ì´Ëʼþ¡£²î²»¶àÒ»Äêǰ  £¬Ò˼ÒÔøÃæÁÙÕë¶ÔÔ±¹¤ÄÚ²¿ÓÊÏäµÄµöÓã¹¥»÷»î¶¯¡£

https://therecord.media/ikea-investigating-cyberattacks-on-outlets-in-kuwait-morocco/

5¡¢ÐÂÀÕË÷Èí¼þPunisherαװ³ÉCOVID-19¸ú×ÙÓ¦Ó÷ַ¢

¾ÝýÌå11ÔÂ29ÈÕ±¨µÀ  £¬Ñо¿ÈËÔ±·¢ÏÖÁËÒ»ÖÖÐÂÀÕË÷Èí¼þPunisher±äÌå  £¬Í¨¹ýÍйÜÔÚcovid19[.]digitalhealthconsulting[.]clÉϵĻùÓÚCOVID-19Ö÷ÌâµÄµöÓãÍøÕ¾½øÐÐÁ÷´«¡£Õâ¸öÍøÕ¾ÌṩαÔìµÄCOVID-19¸ú×ÙÓ¦Óà  £¬Ö÷ÒªÕë¶ÔÖÇÀû¡£Ñо¿ÈËÔ±ÈÏΪ  £¬´Ë´Î»î¶¯Õë¶ÔµÄÊǸöÈ˶ø·ÇÆóÒµ  £¬ËüÀÕË÷¼ÛÖµ1000ÃÀÔªµÄ±ÈÌØ±ÒÀ´½âÃÜÎļþ¡£±»ÕâÖÖÀÕË÷Èí¼þ¼ÓÃܵÄÎļþÒ²ºÜÈÝÒ×±»½âÃÜ  £¬ÒòΪËüʹÓÃAES-128¶Ô³ÆËã·¨½øÐмÓÃÜ¡£

https://www.hackread.com/covid-19-app-punisher-ransomware/

6¡¢È«Ó¡¶Èҽѧ¿ÆÑ§Ñо¿ËùAIIMS±»¹¥»÷ϵͳ崻ú6Ìì

ýÌå11ÔÂ29ÈÕ³Æ  £¬Î»ÓÚµÂÀïµÄȫӡ¶Èҽѧ¿ÆÑ§Ñо¿Ëù(AIIMS) Ôâµ½¹¥»÷ºó  £¬ÆäϵͳÒÑÁ¬Ðøå´»ú6Ìì¡£¾Ý³Æ  £¬ºÚ¿ÍÀÕË÷ԼĪ20ÒÚ¬±ÈµÄ¼ÓÃÜ»õ±Ò  £¬µ«µÂÀᆵ·½·ñÈÏAIIMS³ÂËßÊÕµ½¹ýÈκδËÀàÒªÇó¡£Ä¿Ç°  £¬¿ÉÄÜÒѾ­Ð¹Â¶ÁË3-4ǧÍò»¼ÕßµÄÊý¾Ý¡£ÓÉÓÚ·þÎñÆ÷´¦ÓÚÍ£»ú״̬  £¬¼±Õï¡¢ÃÅÕסԺºÍ»¯ÑéÊҵϼÕß»¤Àí·þÎñ¾ùÓÉÈ˹¤¹ÜÀí¡£µÂÀᆵ·½¡¢ÄÚÕþ²¿ºÍÓ¡¶È¼ÆËã»úÓ¦¼±ÏìӦС×é(CERT-IN)ÕýÔÚÊÓ²ì´ËÀÕË÷¹¥»÷ʼþ¡£

https://www.businesstoday.in/latest/in-focus/story/cyber-attack-at-aiims-delhi-hackers-demand-rs-200-cr-in-crypto-says-report-354475-2022-11-28