ÍøÐŰì°ä²¼¡¶Êý¾Ý³ö¾³°²È«ÆÀ¹ÀÉ걨ָÄÏ£¨³õ°æ£©¡·

°ä²¼¹¦·ò 2022-09-02
1¡¢ÍøÐŰì°ä²¼¡¶Êý¾Ý³ö¾³°²È«ÆÀ¹ÀÉ걨ָÄÏ£¨³õ°æ£©¡·

      

8ÔÂ31ÈÕ£¬£¬£¬£¬£¬£¬ £¬ÎªÁËÁìµ¼ºÍÔ®ÊÖÊý¾Ý´¦ÖÃÕ߹淶¡¢ÓÐÐòÉ걨Êý¾Ý³ö¾³°²È«ÆÀ¹À£¬£¬£¬£¬£¬£¬ £¬¹ú¶È»¥ÁªÍøÐÅÏ¢°ì¹«ÊÒ¼ÙÔìÁË¡¶Êý¾Ý³ö¾³°²È«ÆÀ¹ÀÉ걨ָÄÏ£¨³õ°æ£©¡·¡£¡£¡£¡£¡£¡£¸ÃÖ¸Ä϶ÔÊý¾Ý³ö¾³°²È«ÆÀ¹ÀÉ걨·½Ê½¡¢É걨Á÷³Ì¡¢É걨×ÊÁϵȾßÌåÒªÇó×÷³öÁË×¢Ã÷¡£¡£¡£¡£¡£¡£Êý¾Ý´¦ÖÃÕßÒòÒµÎñ±ØÒªÈ·ÐèÏò¾³±íÌṩÊý¾Ý£¬£¬£¬£¬£¬£¬ £¬ÇкÏÊý¾Ý³ö¾³°²È«ÆÀ¹ÀºÏÓÃÇé¾°µÄ£¬£¬£¬£¬£¬£¬ £¬¸Ãµ±Æ¾¾Ý¡¶Êý¾Ý³ö¾³°²È«ÆÀ¹À·¨×Ó¡·»®¶¨£¬£¬£¬£¬£¬£¬ £¬ÒÀÕÕÉ걨ָÄÏÉ걨Êý¾Ý³ö¾³°²È«ÆÀ¹À¡£¡£¡£¡£¡£¡£


http://www.cac.gov.cn/2022-08/31/c_1663568169996202.htm


2¡¢¹ú¼ÊÒÆÃñÕþ²ßÔì¶©ÖÐÐÄÔâµ½ÀÕË÷ÍÅ»ïKarakurtµÄ¹¥»÷

      

ýÌå8ÔÂ31³Æ£¬£¬£¬£¬£¬£¬ £¬¹ú¼ÊÒÆÃñÕþ²ßÔì¶©ÖÐÐÄ£¨ICMPD£©Ôâµ½ÍøÂç¹¥»÷µ¼ÖÂÊý¾Ýй¶¡£¡£¡£¡£¡£¡£ICMPDÔÚ90¸ö¹ú¶È·¢Õ¹ÒÔÒÆÃñΪÖÐÐĵÄ×êÑÓ×¢ÏîÄ¿ºÍ»î¶¯¡£¡£¡£¡£¡£¡£ICMPDûÓÐй©¹¥»÷²úÉúµÄ¹¦·ò£¬£¬£¬£¬£¬£¬ £¬µ«°µÊ¾¹¥»÷ÕßÉè·¨»ñµÃÁ˶Ա£ÁôÊý¾ÝµÄµ¥¸ö·þÎñÆ÷µÄÓÐÏ޵ĽӼû¡£¡£¡£¡£¡£¡£¸Ã»ú¹¹ÔÚ¼ì²â¹¥»÷ºóµÄ45·ÖÖÓÄÚ³ÉÁ¢ÁËÓ¦¼±ÏìÓ¦Ó××飬£¬£¬£¬£¬£¬ £¬¶Ï¿ªÁË±í²¿ÍøÂçÏνӲ¢¹Ø¹ØÁËËùÓÐÍøÕ¾¡£¡£¡£¡£¡£¡£ÀÕË÷ÍÅ»ïKarakurtÔÚTelegramÉÏ³ÆÆä¶Ô´ËÊÂÎñÕÆ¹Ü£¬£¬£¬£¬£¬£¬ £¬ÒÑÇÔÈ¡375GB£¬£¬£¬£¬£¬£¬ £¬Éæ¼°²ÆÕþÎļþ¡¢ÒøÐÐÊý¾ÝºÍÓ×ÎÒÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£ 


https://therecord.media/migration-policy-org-confirms-cyberattack-after-extortion-group-touts-theft/


3¡¢Ragnar LockerÐû³Æ¶ÔTAPÆÏÌÑÑÀº½¿Õ¹«Ë¾µÄ¹¥»÷ÕÆ¹Ü

      

¾Ý8ÔÂ31ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬ £¬ÀÕË÷ÍÅ»ïRagnar LockerÐû³Æ¹¥»÷ÁËÆÏÌÑÑÀ×î´óµÄº½¿Õ¹«Ë¾TAP Air Portugal¡£¡£¡£¡£¡£¡£TAP°µÊ¾£¬£¬£¬£¬£¬£¬ £¬Æä¿Í»§µÄÊý¾Ý²¢Î´Ôâµ½²»µ±½Ó¼û£¬£¬£¬£¬£¬£¬ £¬µ«ÍøÕ¾ºÍÀûÓ÷¨Ê½¶¼ÓÉÓÚ¹¥»÷¶øÎÞ·¨Ê¹Óᣡ£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬ £¬Ragnar Locker±ç²µÁËTAPµÄÕâһ˵·¨£¬£¬£¬£¬£¬£¬ £¬°µÊ¾TAPÊý°ÙGBµÄÊý¾Ý¿ÉÄÜÒѾ­Ð¹Â¶£¬£¬£¬£¬£¬£¬ £¬»¹¹«¿ªÁËÒ»Õŵç×Ó±í¸ñµÄ½ØÍ¼£¬£¬£¬£¬£¬£¬ £¬ÆäÖÐÔ̺¬¿´ÆðÀ´ÊÇ´ÓTAP·þÎñÆ÷ÇÔÈ¡µÄ¿Í»§ÐÅÏ¢¡£¡£¡£¡£¡£¡£  

 

https://www.bleepingcomputer.com/news/security/ragnar-locker-ransomware-claims-attack-on-portugals-flag-airline/


4¡¢Google°ä²¼ChromeµÄ°²È«¸üУ¬£¬£¬£¬£¬£¬ £¬×ܼƽ¨¸´24¸ö·ì϶

      

GoogleÔÚ8ÔÂ30ÈÕ°ä²¼ÁËChromeµÄ°²È«¸üУ¬£¬£¬£¬£¬£¬ £¬×ܼƽ¨¸´24¸ö·ì϶¡£¡£¡£¡£¡£¡£ÆäÖÐ×îÑϳÁµÄÊÇNetwork ServiceÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2022-3038£©¡£¡£¡£¡£¡£¡£Æä´Î£¬£¬£¬£¬£¬£¬ £¬ÊÇWebSQLÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2022-3039£©¡¢LayoutÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2022-3040£©¡¢ÖеĿªÊͺóʹÓ÷ì϶¡¢Screen CaptureÖеĶѻº³åÇøÒç³ö£¨CVE-2022-3043£©ºÍSite IsolationÖеÄÖ´Ðв»µ±£¨CVE-2022-3044£©µÈ¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬ £¬ÉÐÎÞ¹ØÓÚÕâЩ·ì϶ÔÚÒ°±í±»ÀûÓõĻ㱨¡£¡£¡£¡£¡£¡£


https://chromereleases.googleblog.com/2022/08/stable-channel-update-for-desktop_30.html


5¡¢³¬¹ý1800¸öAndroidºÍiOSÀûÓÃй¶Ӳ±àÂëµÄAWSƾ֤

      

¾ÝýÌå9ÔÂ1ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬ £¬SymantecµÄ×êÑÐÈËÔ±·¢ÏÖÁË1859¸öÔ̺¬Ó²±àÂëAWSƾ֤µÄÀûÓ÷¨Ê½£¬£¬£¬£¬£¬£¬ £¬ÆäÖдóÎÞÊýÊÇiOSÀûÓ㬣¬£¬£¬£¬£¬ £¬Ö»ÓÐ37¸öÊÇAndroidÀûÓᣡ£¡£¡£¡£¡£ÕâЩÀûÓ÷¨Ê½ÖÐԼĪ77%Ô̺¬ÓÐЧµÄAWS½Ó¼ûÁîÅÆ£¬£¬£¬£¬£¬£¬ £¬¿ÉÓÃÓÚÖ±½Ó½Ó¼û˽ÓÐÔÆ·þÎñ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬ £¬874¸öÀûÓã¨47%£©Ô̺¬ÓÐЧµÄAWSÁîÅÆ£¬£¬£¬£¬£¬£¬ £¬¿ÉÓÃÓÚ½Ó¼ûÊý°ÙÍò±Ê¼Í¼µÄʵʱ·þÎñÊý¾Ý¿âµÄÔÆÊ·ý¡£¡£¡£¡£¡£¡£ÔÚÒ»¸ö°¸ÀýÖУ¬£¬£¬£¬£¬£¬ £¬Ä³B2B¹«Ë¾Îª³¬¹ý15000¼Ò´óÖÐÐ͹«Ë¾ÌṩÄÚÍøºÍͨÕÛ·þÎñ£¬£¬£¬£¬£¬£¬ £¬¸Ã¹«Ë¾Ïò¿Í»§ÌṩµÄÓÃÓÚ½Ó¼ûÆä·þÎñµÄSDKÔ̺¬AWSÃÜÔ¿£¬£¬£¬£¬£¬£¬ £¬´Ó¶øÐ¹Â¶ÁË´æ´¢ÔÚÆ½Ì¨ÉϵÄËùÓпͻ§µÄÊý¾Ý¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2022/09/over-1800-android-and-ios-apps-found.html


6¡¢Trend Micro°ä²¼2022ÄêÖÐÍøÂç°²È«Ì¬ÊÆµÄ·ÖÎö»ã±¨

      

8ÔÂ31£¬£¬£¬£¬£¬£¬ £¬Trend Micro°ä²¼ÁË2022ÄêÖÐÍøÂç°²È«Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬ £¬¸Ã¹«Ë¾2020ÄêÉϰëÄê×èÖ¹µÄÍþв×ÜÊýΪ63789373773¡£¡£¡£¡£¡£¡£EmotetÔÚ2022ÄêËÀ»Ò¸´È¼£¬£¬£¬£¬£¬£¬ £¬ÓëÈ¥ÄêÉϰëÄêÏà±È£¬£¬£¬£¬£¬£¬ £¬2022ÄêÉϰëÄêEmotet¼ìÕÉÁ¿Ôö³¤ÁË976.7%£¬£¬£¬£¬£¬£¬ £¬ÆäÖÐÈÕ±¾µÄ¼ìÕÉÁ¿×î¸ß¡£¡£¡£¡£¡£¡£RaaSģʽÁ÷ÐУ¬£¬£¬£¬£¬£¬ £¬ÉϰëÄêÓÐ57¸ö»îÔ¾µÄRaaSºÍÀÕË÷ÍŻ£¬£¬£¬£¬£¬ £¬ÒÔ¼°1200¶à¸ö±»¹¥»÷µÄÖ¸±ê¡£¡£¡£¡£¡£¡£ÔÆÅäÖÃÃýÎóÒÀÈ»ÊÇ×îÊܹØ×¢µÄÎÊÌ⣬£¬£¬£¬£¬£¬ £¬ÓÐ243469¸öͨ¹ý10250¶Ë¿Ú¹«¿ªµÄKubernetes¼¯Èº½Úµã¡£¡£¡£¡£¡£¡£


https://www.trendmicro.com/vinfo/us/security/research-and-analysis/threat-reports/roundup/defending-the-expanding-attack-surface-trend-micro-2022-midyear-cybersecurity-report