Google´¹Î£½¨¸´ChromeÖб»ÀûÓõķì϶CVE-2022-4262

°ä²¼¹¦·ò 2022-12-05
1¡¢Google´¹Î£½¨¸´ChromeÖб»ÀûÓõķì϶CVE-2022-4262

12ÔÂ2ÈÕ £¬Google°ä²¼´¹Î£¸üР£¬½¨¸´ChromeÖÐÒѱ»ÀûÓõÄ0 day¡£ÕâÊÇChrome V8 JavaScriptÒýÇæÖеÄÀàÐÍ»ìºÏ·ì϶(CVE-2022-4262) £¬´ËÀà·ì϶ͨ³£±»ÓÃÓÚͨ¹ý¶ÁÈ¡»òдÈ뻺³åÇøÌìǵ±íµÄÄÚ´æµ¼ÖÂä¯ÀÀÆ÷±ÀÀ£ £¬Ò²¿É±»ÓÃÓÚÖ´ÐÐËÁÒâ´úÂë¡£¹ÌÈ»Google°µÊ¾ËüÒѼì²âµ½ÀûÓÃÕâ¸ö·ì϶µÄ¹¥»÷ £¬µ«ÉÐδ·ÖÏíÓйØÕâЩÊÂÎñµÄ¼¼Êõϸ½Ú»òÐÅÏ¢¡£ÕâÊÇGoogle ChromeÔÚ½ñÄ꽨¸´µÄµÚ9¸ö0 day¡£

https://chromereleases.googleblog.com/2022/12/stable-channel-update-for-desktop.html

2¡¢Kaspersky·¢ÏÖÖØÒªÕë¶Ô¶íÂÞ˹×éÖ¯µÄÐÂľÂíCryWiper

KasperskyÔÚ12ÔÂ1ÈÕ³ÆÆä·¢ÏÖÁËÒ»¸öÐµÄľÂíCryWiper¡£×êÑÐÈËÔ±ÔÚ½ñÄêÇïÌì³õ´Î·¢ÏÖÁËCryWiper £¬Ëü±»ÓÃÓÚÕë¶Ô¶íÂÞ˹×éÖ¯µÄ¹¥»÷ £¬¶íÂÞ˹ýÌåÔòй©Ëü±»ÓÃÓÚ¹¥»÷¶íÂÞ˹Êг¤°ì¹«ÊҺͷ¨Ôº¡£¸Ã¶ñÒâÈí¼þ¼Ù×°³ÉÀÕË÷Èí¼þ £¬µ«¶Ô´úÂëµÄ·ÖÎöÅú×¢ËüÏÖʵÉϲ¢Î´¼ÓÃÜ £¬Ö»ÊÇ·ÛËéÁ˱»Ï°È¾ÏµÍ³ÖеÄÊý¾Ý¡£CryWiperÑù±¾ÓÃC++¿ª·¢µÄ64λWindows¿ÉÖ´ÐÐÎļþ £¬ÅäÖÃΪÀÄÓúܶàWinAPIº¯ÊýŲÓ᣸öñÒâÈí¼þ»¹»áɾ³ý±»Ï°È¾ÍÆËã»úÉϵľíÓ°¸±±¾ £¬ÒÔÔ¤·ÀÖ¸±ê¸´Ô­Îļþ¡£

https://securelist.ru/novyj-troyanec-crywiper/106114/

3¡¢ÈýÐǵȹ©¸øÉÌʹÓÃµÄÆ½Ì¨Ö¤Êé±»ÀÄÓÃÀ´Ç©Êð¶ñÒâÀûÓÃ

¾ÝýÌå12ÔÂ1ÈÕ±¨Â· £¬AndroidOEMÉ豸¹©¸øÉÌÓÃÓÚ¶ÔÖ÷ÌâϵͳÀûÓýøÐÐÊý×ÖÊðÃûµÄ¶à¸öƽ̨֤Êé±»ÓÃÓÚ¶ÔÔ̺¬¶ñÒâÈí¼þµÄÀûÓýøÐÐÊðÃû¡£×êÑÐÈËÔ±·¢ÏÖ¶à¸öʹÓÃÕâЩƽ̨֤ÊéÊðÃûµÄ¶ñÒâÈí¼þÑù±¾ £¬²¢ÌṩÁËÿ¸öÑù±¾µÄSHA256¹þÏ£ÖµºÍÊý×ÖÊðÃûÖ¤Êé¡£ÆäÖв¿ÃÅÊôÓÚÈýÐÇ¡¢LG¡¢RevoviewºÍÁª·¢¿Æ £¬ÆäËüÖ¤ÊéÉÐÎÞ·¨È·¶¨ÊôÓÚË­¡£Ê¹ÓÃÕâЩ֤ÊéÊðÃûµÄ¶ñÒâÈí¼þÔ̺¬HiddenAdľÂí¡¢ÐÅÏ¢ÇÔÈ¡·¨Ê½¡¢MetasploitºÍ¶ñÒâÈí¼þÖ²È뷨ʽ¡£

https://www.bleepingcomputer.com/news/security/samsung-lg-mediatek-certificates-compromised-to-sign-android-malware/

4¡¢CISA³ÆÀÕË÷Èí¼þCubaÒѳɹ¦ÀÕË÷³¬¹ý6000ÍòÃÀÔª

CISAºÍFBIÔÚ12ÔÂ1ÈÕ½áºÏ°ä²¼Á˹ØÓÚÀÕË÷Èí¼þCubaµÄ¹«¸æ¡£×Ô2021Äê12ÔÂÒÔÀ´ £¬¸ÃÍÅ»ïÖØÒªÕë¶Ô½ðÈÚ·þÎñ¡¢µ±¾ÖÉèÊ©¡¢Ò½ÁƱ£½¡ºÍ¹«¹²ÎÀÉú¡¢Ôì×÷ºÍÐÅÏ¢¼¼ÊõÐÐÒµ¡£½ØÖÁ2022Äê8Ô £¬FBIÈ·¶¨CubaÔÚÈ«ÇòÁìÓòÄÚÈëÇÖÁË100¶à¸ö×éÖ¯ £¬ÀÕË÷³¬¹ý1.45ÒÚÃÀÔª²¢³É¹¦ÊÕµ½³¬¹ý6000ÍòÃÀÔª¡£CubaÍÅ»ïÀûÓöàÖÖ¼¼Êõ»ñµÃ³õʼ½Ó¼ûȨÏÞ £¬Ô̺¬ÀûÓÃóÒ×Èí¼þÖеÄÏÖÓзì϶¡¢´¹µö»î¶¯¡¢Ð¹Â¶µÄÍ´´¦ÒÔ¼°ºÏ·¨µÄRDP¹¤¾ß¡£³É¹¦ºó £¬»áͨ¹ýHancitorÔÚÖ¸±êϵͳÉÏ×°ÖÃCubaÀÕË÷Èí¼þ¡£

https://www.cisa.gov/uscert/ncas/alerts/aa22-335a

5¡¢ÃÀ¹ú·ðÂÞÀï´ïÖݵÄ˰ÎñÍøÕ¾Ð¹Â¶ÄÉ˰È˵ÄÐÅÏ¢

¾Ý12ÔÂ3ÈÕ±¨Â· £¬·ðÂÞÀï´ïÖݵÄ˰Îñ¾ÖÍøÕ¾´æÔÚÒ»¸ö°²È«·ì϶ £¬Ð¹Â¶ÁËÖÁÉÙÊý°Ù¸öÄÉ˰È˵ÄÉç»á°²È«ºÅÂëºÍÒøÐÐÕʺÅ¡£¸Ã·ì϶Ϊ²»°²È«µÄÖ±½Ó¶ÔÏóÒýÓã¨IDOR£© £¬ÓÉÓÚÉêÇë±àºÅÊÇÂ½ÐøµÄ £¬ÈκÎÈ˶¼Äܹ»Í¨¹ý½«ÉêÇë±àºÅµÝÔöһλÀ´ÁоÙÄÉ˰È˵ÄÐÅÏ¢ £¬ÏµÍ³ÖÐÓг¬¹ý713000·ÝÉêÇë¡£µÇ¼¸ÃÍøÕ¾µÄÈκÎÈË £¬¶¼Äܹ»Í¨¹ýÅú¸ÄÔ̺¬ÄÉ˰ÈËÉêÇëºÅÂëµÄÍøÖ·²¿ÃÅ £¬½Ó¼û¡¢Åú¸ÄºÍɾ³ý¸Ã˰Îñ»ú¹Ø´æµµµÄÆóÒµÖ÷µÄÓ×ÎÒ×ÊÁÏ¡£

https://www.databreaches.net/florida-state-tax-website-bug-exposed-filers-data/

6¡¢Zimperium°ä²¼Schoolyard BullyľÂí¹¥»÷»î¶¯µÄ·ÖÎö

12ÔÂ1ÈÕ £¬Zimperium°ä²¼Á˹ØÓÚSchoolyard BullyľÂíµÄ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¸Ã»î¶¯×Ô2018ÄêÒÔÀ´Ò»Ïò»îÔ¾ £¬ÒÑϰȾ71¸ö¹ú¶È/µØÓòµÄÖÁÉÙ300000¸öÖ¸±ê £¬ÖØÒª¼¯ÖÐÔÚÔ½ÄÏ¡£Schoolyard BullyÒò¼Ù×°³ÉÎÞº¦ÉõÖÁÓÐÒæµÄ½ÌÓýÀûÓöøµÃÃû £¬ÆäÖØÒªÖ¸±êÊÇÇÔÈ¡FacebookÕÊ»§Í´´¦¡£¸ÃľÂíͨ¹ýʹÓÃWebViewÔÚÀûÓÃÖдò¿ªºÏ·¨µÄFacebookµÇÂ¼Ò³Ãæ £¬²¢×¢Èë¶ñÒâJavaScriptÀ´ÇÔÈ¡Óû§ÊäÈë¡£Ö»¹ÜÕâЩÀûÓÃÏÖÒÑ´ÓGoogle PlayÉ̵êÖÐɾ³ý £¬µ«ËüÃÇÒÀÈ»Äܹ»ÔÚµÚÈý·½ÀûÓ÷¨Ê½É̵êÖлñµÃ¡£

https://www.zimperium.com/blog/schoolyard-bully-trojan-facebook-credential-stealer/