Google½ô¼±ÐÞ¸´ChromeÖб»ÀûÓõÄ©¶´CVE-2022-4262
Ðû²¼Ê±¼ä 2022-12-0512ÔÂ2ÈÕ£¬GoogleÐû²¼½ô¼±¸üУ¬ÐÞ¸´ChromeÖÐÒѱ»ÀûÓõÄ0 day¡£ÕâÊÇChrome V8 JavaScriptÒýÇæÖеÄÀàÐÍ»ìÏý©¶´(CVE-2022-4262)£¬´ËÀà©¶´Í¨³£±»ÓÃÓÚͨ¹ý¶ÁÈ¡»òдÈ뻺³åÇø½çÏÞÍâµÄÄÚ´æµ¼ÖÂä¯ÀÀÆ÷Í߽⣬Ҳ¿É±»ÓÃÓÚÖ´ÐÐÈÎÒâ´úÂë¡£ËäÈ»GoogleÌåÏÖËüÒѼì²âµ½ÀûÓÃÕâ¸ö©¶´µÄ¹¥»÷£¬µ«ÉÐδ·ÖÏíÓйØÕâЩʼþµÄ¼¼Êõϸ½Ú»òÐÅÏ¢¡£ÕâÊÇGoogle ChromeÔÚ½ñÄêÐÞ¸´µÄµÚ9¸ö0 day¡£
https://chromereleases.googleblog.com/2022/12/stable-channel-update-for-desktop.html
2¡¢Kaspersky·¢ÏÖÖ÷ÒªÕë¶Ô¶íÂÞ˹×éÖ¯µÄÐÂľÂíCryWiper
KasperskyÔÚ12ÔÂ1ÈÕ³ÆÆä·¢ÏÖÁËÒ»¸öÐµÄľÂíCryWiper¡£Ñо¿ÈËÔ±ÔÚ½ñÄêÇïÌìÊ״η¢ÏÖÁËCryWiper£¬Ëü±»ÓÃÓÚÕë¶Ô¶íÂÞ˹×éÖ¯µÄ¹¥»÷£¬¶íÂÞ˹ýÌåÔò͸¶Ëü±»ÓÃÓÚ¹¥»÷¶íÂÞ˹Êг¤°ì¹«ÊҺͷ¨Ôº¡£¸Ã¶ñÒâÈí¼þαװ³ÉÀÕË÷Èí¼þ£¬µ«¶Ô´úÂëµÄ·ÖÎö±íÃ÷Ëüʵ¼ÊÉϲ¢Î´¼ÓÃÜ£¬Ö»ÊÇÆÆ»µÁ˱»Ñ¬È¾ÏµÍ³ÖеÄÊý¾Ý¡£CryWiperÑù±¾ÓÃC++¿ª·¢µÄ64λWindows¿ÉÖ´ÐÐÎļþ£¬ÅäÖÃΪÀÄÓÃÐí¶àWinAPIº¯Êýµ÷Ó᣸öñÒâÈí¼þ»¹»áɾ³ý±»Ñ¬È¾¼ÆËã»úÉϵľíÓ°¸±±¾£¬ÒÔ·ÀֹĿ±ê»Ö¸´Îļþ¡£
https://securelist.ru/novyj-troyanec-crywiper/106114/
3¡¢ÈýÐǵȹ©Ó¦ÉÌʹÓÃµÄÆ½Ì¨Ö¤Êé±»ÀÄÓÃÀ´Ç©Êð¶ñÒâÓ¦ÓÃ
¾ÝýÌå12ÔÂ1ÈÕ±¨µÀ£¬AndroidOEMÉ豸¹©Ó¦ÉÌÓÃÓÚ¶ÔºËÐÄϵͳӦÓýøÐÐÊý×ÖÇ©ÃûµÄ¶à¸öƽ̨֤Êé±»ÓÃÓÚ¶Ô°üÂÞ¶ñÒâÈí¼þµÄÓ¦ÓýøÐÐÇ©Ãû¡£Ñо¿ÈËÔ±·¢ÏÖ¶à¸öʹÓÃÕâЩƽ̨֤ÊéÇ©ÃûµÄ¶ñÒâÈí¼þÑù±¾£¬²¢ÌṩÁËÿ¸öÑù±¾µÄSHA256¹þÏ£ÖµºÍÊý×ÖÇ©ÃûÖ¤Êé¡£ÆäÖв¿ÃÅÊôÓÚÈýÐÇ¡¢LG¡¢RevoviewºÍÁª·¢¿Æ£¬ÆäËüÖ¤ÊéÉÐÎÞ·¨È·¶¨ÊôÓÚË¡£Ê¹ÓÃÕâЩ֤ÊéÇ©ÃûµÄ¶ñÒâÈí¼þ°üÂÞHiddenAdľÂí¡¢ÐÅÏ¢ÇÔÈ¡·¨Ê½¡¢MetasploitºÍ¶ñÒâÈí¼þÖ²È뷨ʽ¡£
https://www.bleepingcomputer.com/news/security/samsung-lg-mediatek-certificates-compromised-to-sign-android-malware/
4¡¢CISA³ÆÀÕË÷Èí¼þCubaÒÑÀÖ³ÉÀÕË÷Áè¼Ý6000ÍòÃÀÔª
CISAºÍFBIÔÚ12ÔÂ1ÈÕÁªºÏÐû²¼Á˹ØÓÚÀÕË÷Èí¼þCubaµÄͨ¸æ¡£×Ô2021Äê12ÔÂÒÔÀ´£¬¸ÃÍÅ»ïÖ÷ÒªÕë¶Ô½ðÈÚ·þÎñ¡¢Õþ¸®ÉèÊ©¡¢Ò½ÁƱ£½¡ºÍ¹«¹²ÎÀÉú¡¢ÖÆÔìºÍÐÅÏ¢¼¼ÊõÐÐÒµ¡£½ØÖÁ2022Äê8Ô£¬FBIÈ·¶¨CubaÔÚÈ«Çò·¶Î§ÄÚÈëÇÖÁË100¶à¸ö×éÖ¯£¬ÀÕË÷Áè¼Ý1.45ÒÚÃÀÔª²¢ÀÖ³ÉÊÕµ½Áè¼Ý6000ÍòÃÀÔª¡£CubaÍÅ»ïÀûÓöàÖÖ¼¼Êõ»ñµÃ³õʼ·ÃÎÊȨÏÞ£¬°üÂÞÀûÓÃÉÌÒµÈí¼þÖеÄÏÖÓЩ¶´¡¢µöÓã»î¶¯¡¢Ð¹Â¶µÄƾ¾ÝÒÔ¼°ºÏ·¨µÄRDP¹¤¾ß¡£Àֳɺ󣬻áͨ¹ýHancitorÔÚÄ¿±êϵͳÉϰ²×°CubaÀÕË÷Èí¼þ¡£
https://www.cisa.gov/uscert/ncas/alerts/aa22-335a
5¡¢ÃÀ¹ú·ðÂÞÀï´ïÖݵÄ˰ÎñÍøÕ¾Ð¹Â¶ÄÉ˰È˵ÄÐÅÏ¢
¾Ý12ÔÂ3ÈÕ±¨µÀ£¬·ðÂÞÀï´ïÖݵÄ˰Îñ¾ÖÍøÕ¾´æÔÚÒ»¸öÄþ¾²Â©¶´£¬Ð¹Â¶ÁËÖÁÉÙÊý°Ù¸öÄÉ˰È˵ÄÉç»áÄþ¾²ºÅÂëºÍÒøÐÐÕʺš£¸Ã©¶´Îª²»Äþ¾²µÄÖ±½Ó¹¤¾ßÒýÓã¨IDOR£©£¬ÓÉÓÚÉêÇë±àºÅÊÇÁ¬ÐøµÄ£¬ÈκÎÈ˶¼¿ÉÒÔͨ¹ý½«ÉêÇë±àºÅµÝÔöһλÀ´ÁоÙÄÉ˰È˵ÄÐÅÏ¢£¬ÏµÍ³ÖÐÓÐÁè¼Ý713000·ÝÉêÇë¡£µÇ¼¸ÃÍøÕ¾µÄÈκÎÈË£¬¶¼¿ÉÒÔͨ¹ýÐ޸İüÂÞÄÉ˰ÈËÉêÇëºÅÂëµÄÍøÖ·²¿ÃÅ£¬·ÃÎÊ¡¢Ð޸ĺÍɾ³ý¸Ã˰Îñ»ú¹Ø´æµµµÄÆóÒµÖ÷µÄ¸öÈË×ÊÁÏ¡£
https://www.databreaches.net/florida-state-tax-website-bug-exposed-filers-data/
6¡¢ZimperiumÐû²¼Schoolyard BullyľÂí¹¥»÷»î¶¯µÄ·ÖÎö
12ÔÂ1ÈÕ£¬ZimperiumÐû²¼Á˹ØÓÚSchoolyard BullyľÂíµÄ¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß¡£¸Ã»î¶¯×Ô2018ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬ÒÑѬȾ71¸ö¹ú¼Ò/µØÓòµÄÖÁÉÙ300000¸öÄ¿±ê£¬Ö÷Òª¼¯ÖÐÔÚÔ½ÄÏ¡£Schoolyard BullyÒòαװ³ÉÎÞº¦ÉõÖÁÓÐÒæµÄ½ÌÓýÓ¦ÓöøµÃÃû£¬ÆäÖ÷ҪĿ±êÊÇÇÔÈ¡FacebookÕÊ»§Æ¾¾Ý¡£¸ÃľÂíͨ¹ýʹÓÃWebViewÔÚÓ¦ÓÃÖдò¿ªºÏ·¨µÄFacebookµÇÂ¼Ò³Ãæ£¬²¢×¢Èë¶ñÒâJavaScriptÀ´ÇÔÈ¡Óû§ÊäÈë¡£¾¡¹ÜÕâЩӦÓÃÏÖÒÑ´ÓGoogle PlayÉ̵êÖÐɾ³ý£¬µ«ËüÃÇÈÔÈ»¿ÉÒÔÔÚµÚÈý·½Ó¦Ó÷¨Ê½É̵êÖлñµÃ¡£
https://www.zimperium.com/blog/schoolyard-bully-trojan-facebook-credential-stealer/