Chrome½¨¸´±»ÀûÓ÷ì϶CVE-2022-3075

°ä²¼¹¦·ò 2022-09-05
1¡¢Chrome´¹Î£¸üн¨¸´Òѱ»ÀûÓõķì϶CVE-2022-3075

      

GoogleÔÚ9ÔÂ2ÈÕ°ä²¼´¹Î£¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´Chromeä¯ÀÀÆ÷ÖÐÒѱ»ÀûÓõķì϶£¨CVE-2022-3075£©¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇMojoÖеÄÊý¾ÝÑéÖ¤²»¼°µ¼ÖµÄ£¬£¬£¬£¬£¬£¬£¬MojoÊÇÒ»×éÔËÐÐʱ¿â£¬£¬£¬£¬£¬£¬£¬¿ÉÓÃÓÚ¿çËÁÒâ¹ý³Ì¼äºÍ¹ý³ÌÄÚÌìǵ´«µÝÐÂÎÅ¡£¡£¡£¡£¡£¡£¡£ä¯ÀÀÆ÷½«×Ô¶¯²é³­¸üУ¬£¬£¬£¬£¬£¬£¬²¢±ÉÈË´ÎÆô¶¯ºó×Ô¶¯×°Öᣡ£¡£¡£¡£¡£¡£Ö»¹Ü¸Ã·ì϶Òѱ»¿í·ºÀûÓ㬣¬£¬£¬£¬£¬£¬µ«Google²¢Î´·ÖÏí¹ØÓÚÕâЩ¹¥»÷µÄϸ½ÚÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÕâÊÇGoogle×Ô½ñÄêËêÊ×ÒÔÀ´½¨¸´µÄµÚ6¸öChromeÁãÈÕ·ì϶¡£¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2022/09/google-release-urgent-chrome-update-to.html


2¡¢Defender½«ChromeºÍEdgeµÅצÓÃÎó±¨ÎªWin32/Hive.ZY

      

¾ÝýÌå9ÔÂ4ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬Ã¿´ÎÔÚWindowsÖдò¿ªGoogle Chrome¡¢Microsoft Edge¡¢DiscordºÍÆäËüElectronÀûÓ÷¨Ê½Ê±£¬£¬£¬£¬£¬£¬£¬Microsoft Defender³ÇÊÐÃýÎ󵨽«ÕâЩÀûÓ÷¨Ê½¼ì²âΪ"Win32/Hive.ZY"¡£¡£¡£¡£¡£¡£¡£ÎÊÌâÆðÍ·ÓÚÉÏÖÜÈÕÔçÉÏ£¬£¬£¬£¬£¬£¬£¬Æäʱ΢ÈíÍÆ³öÁËDefenderÊðÃû¸üР1.373.1508.0£¬£¬£¬£¬£¬£¬£¬ÐÂÔöÁËÁ½¸öÍþв¼ì²â£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Behavior:Win32/Hive.ZY¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬Î¢ÈíÒѰ䲼Defender°²È«ÖÇÄܸüа汾1.373.1537.0£¬£¬£¬£¬£¬£¬£¬¸Ã¸üÐÂËÆºõ½â¾öÁËWin32/Hive.ZYÎó±¨ÎÊÌâ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-falsely-detects-win32-hivezy-in-google-chrome-electron-apps/


3¡¢¶íÂÞ˹Yandex Taxi±»ºÚµ¼ÖÂĪ˹¿Æ´ó¹æÄ£½»Í¨¹£Èû

      

¾Ý9ÔÂ2ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬¶íÂÞ˹µÄ´ò³µÀûÓ÷¨Ê½Yandex Taxi±»ºÚ£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂĪ˹¿Æ³öÏÖ´ó¹æÄ£½»Í¨Óµ¼·¡£¡£¡£¡£¡£¡£¡£¹¥»÷²úÉúÔÚ9ÔÂ1ÈÕ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß½«ÊýÊ®Á¾³ö×â³µÅÉÍùÁËĪ˹¿ÆÖØÒª½Ö·֮һKutuzovsky Prospekt¡£¡£¡£¡£¡£¡£¡£Õâ´Î¶Â³µÔ¼Äª³ÖÐøÁËÈý¸öÓ×ʱ£¬£¬£¬£¬£¬£¬£¬YandexµÄ°²È«ÍŶÓѸËÙ½â¾öÁ˸ÃÎÊÌ⣬£¬£¬£¬£¬£¬£¬²¢³Ðŵ½«¸Ä½øËã·¨ÒÔ·ÀÓù´ËÀ๥»÷¡£¡£¡£¡£¡£¡£¡£ºÚ¿ÍÍÅ»ïAnonymous¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬£¬£¬£¬£¬£¬£¬²¢°µÊ¾¸ÃÐж¯ÊÇÓëIT Army of UkraineºÏ×÷½øÐеÄ¡£¡£¡£¡£¡£¡£¡£


https://www.hackread.com/anonymous-russian-yandex-taxi-app-hacked/


4¡¢ÃÀ¹ú¹ú˰¾Öй¶Լ12ÍòÄÉ˰È˵ÄÐÕÃûºÍÊÕÈëµÈÐÅÏ¢

      

ýÌå9ÔÂ3Èճƣ¬£¬£¬£¬£¬£¬£¬ÃÀ¹ú¹ú˰¾ÖÒâ±íй¶ÁËÔ¼120000ÃûÄÉ˰È˵ÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£±»Ó°ÏìµÄÄÉ˰ÈËÔÚÄÉ˰É걨±íÖÐÌá½»ÁË990-T±í¸ñ£¬£¬£¬£¬£¬£¬£¬¸Ã±í¸ñÓÃÓڻ㱨֧¸¶¸øÃâ˰×éÖ¯µÄÎÞ¹ØÒµÎñÊÕÈ룬£¬£¬£¬£¬£¬£¬ÀýÈç·ÇͶ»ú×éÖ¯»òIRAºÍSEPÍËÐÝÕË»§¡£¡£¡£¡£¡£¡£¡£¶ÔÓÚͨ³£ÄÉ˰ÈËÀ´Ëµ£¬£¬£¬£¬£¬£¬£¬¸Ã±í¸ñÊDZ£ÃܵÄ£¬£¬£¬£¬£¬£¬£¬µ«¶ÔÓÚ·ÇͶ»ú×éÖ¯À´Ëµ£¬£¬£¬£¬£¬£¬£¬¸Ã±í¸ñ±ØÐëÔÚÈýÄêÄÚ¹©¹«¼Ò²éÔÄ¡£¡£¡£¡£¡£¡£¡£ÉÏÖÜÎ壬£¬£¬£¬£¬£¬£¬ÃÀ¹ú¹ú˰¾Ö·¢ÏÖ³ýÁ˴ȱ¯»ú¹¹µÄ990-T±í¸ñÊý¾Ý±í£¬£¬£¬£¬£¬£¬£¬»¹Òâ±íµØ¹«¿ªÁËÄÉ˰ÈËIRAµÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬Éæ¼°ÐÕÃû¡¢ÁªÏµÐÅÏ¢ºÍ»ã±¨µÄÊÕÈëµÈ¡£¡£¡£¡£¡£¡£¡£¸Ã»ú¹¹°µÊ¾Â¶³öµÄÊý¾ÝÒѱ»É¾³ý£¬£¬£¬£¬£¬£¬£¬²¢½«ÔÚ½«À´¼¸ÖÜÄÚ֪ͨÊÜÓ°ÏìµÄ¹«Ãñ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/irs-data-leak-exposes-personal-info-of-120-000-taxpayers/


5¡¢·þ×°¹«Ë¾DamartÔâµ½HiveµÄ¹¥»÷²¢±»ÀÕË÷200ÍòÃÀÔª

      

9ÔÂ2ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬£¬£¬·¨¹ú·þ×°¹«Ë¾DamartÔâµ½ºÚ¿ÍÍÅ»ïHiveµÄ¹¥»÷²¢±»ÀÕË÷200ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£8ÔÂ15ÈÕ£¬£¬£¬£¬£¬£¬£¬DamartÔÚÆäÔÚÏßÉ̵êµÄÖ÷Ò³Éϰ䲼Á˹ØÓÚ´òËã±íÊØ»¤µÄÐÂÎÅ¡£¡£¡£¡£¡£¡£¡£8ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬£¬DamartµÄÏúÊÛÍøÂçÖжÏ£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁË92¼ÒÃŵê¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾°µÊ¾¹¥»÷ÕßÒÑÈëÇÖActive Directory²¢¼ÓÃÜÁËһЩϵͳ£¬£¬£¬£¬£¬£¬£¬·þÎñÖÊÁ¿½µÂäÊÇÒòÆäΪÁ˱ £»£»£»£»£»¤ÏµÍ³¶ø¹Ø¹ØÁËËüÃÇ¡£¡£¡£¡£¡£¡£¡£Hive²¢Î´ÔÚÆäÊý¾Ý¹«¿ªÍøÕ¾ÉÏÁгöDamart£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾Ò²Ò»ÔÙ·ñ¶¨ÆäÊý¾Ý±»µÁ¡£¡£¡£¡£¡£¡£¡£Val¨¦ry MarchiveÖ¸³ö£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß²¢²»Ô¸ÒâÓëÆäĸ¹«Ë¾Damartex½øÐн»Éæ²¢½øÕ¹»ñµÃÈ«ÊýÊê½ð¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/damart-clothing-store-hit-by-hive-ransomware-2-million-demanded/


6¡¢ÈýÐÇй©ÆäÃÀ¹ú·Ö¹«Ë¾µÄÄÚÍø±»ÈëÇÖÇÒ¿Í»§ÐÅϢй¶

      

º«¹úÈýÐǹ«Ë¾ÔÚ9ÔÂ2ÈÕй©£¬£¬£¬£¬£¬£¬£¬Æä²¿Ãſͻ§µÄÐÅÏ¢Ô⵽δ¾­ÊÚȨµÄ½Ó¼û¡£¡£¡£¡£¡£¡£¡£2022Äê7ÔÂÏÂÑ®£¬£¬£¬£¬£¬£¬£¬ÈýÐÇλÓÚÃÀ¹ú·Ö¹«Ë¾µÄ²¿ÃÅϵͳ±»ÈëÇÖ¡£¡£¡£¡£¡£¡£¡£2022Äê8ÔÂ4ÈÕǰºó£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËԱͨ¹ýµ÷²éÈ·¶¨²¿Ãſͻ§µÄÓ×ÎÒÐÅÏ¢Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£ÈýÐǰµÊ¾£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄܽӼûÐÕÃû¡¢ÁªÏµ·½Ê½¡¢È˶¡Í³¼ÆÐÅÏ¢¡¢µ®ÉúÈÕÆÚºÍ²úÆ·×¢²áÊý¾ÝµÈÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬µ«Ã¿¸ö¿Í»§ÊÜÓ°ÏìµÄÐÅÏ¢¿ÉÄÜ»áÓÐËù·ÖÆç¡£¡£¡£¡£¡£¡£¡£ÕâÊÇÈýÐǽñÄê²úÉúµÄµÚ¶þ´ÎÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚ3Ô·ÝÔøÔâµ½Lapsus$µÄ¹¥»÷£¬£¬£¬£¬£¬£¬£¬²¢Ð¹Â¶ÁËÔ̺¬GalaxyÉ豸Դ´úÂëÔÚÄÚµÄ190 GBÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2022/09/samsung-admits-data-breach-that-exposed.html