Verizonй©²¿ÃÅÓû§µÄÐÅϢй¶²¢Ôâµ½SIM¿¨»¥»»¹¥»÷

°ä²¼¹¦·ò 2022-10-20
1¡¢Verizonй©²¿ÃÅÓû§µÄÐÅϢй¶²¢Ôâµ½SIM¿¨»¥»»¹¥»÷

      

¾Ý10ÔÂ18ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬Verizon²¿ÃÅÔ¤¸¶·Ñ¿Í»§µÄÐÅϢй¶¡£¡£¡£¡£¡£Verizon³Æ£¬£¬£¬£¬£¬£¬£¬ÔÚ2022Äê10ÔÂ6ÈÕÖÁ10ÔÂ10ÈÕÆÚ¼ä£¬£¬£¬£¬£¬£¬£¬Î´¾­ÊÚȨµÄµÚÈý·½½Ó¼ûÁËÓû§ÓÃÓÚ×Ô¶¯¸¶¿îµÄÐÅÓþ¿¨µÄ×îºóËÄλÊý×Ö£¬£¬£¬£¬£¬£¬£¬²¢ÔÚSIM¿¨»¥»»¹¥»÷ÖÐʹÓÃÁËй¶µÄÐÅÓþ¿¨ÐÅÏ¢¡£¡£¡£¡£¡£Verizon°µÊ¾£¬£¬£¬£¬£¬£¬£¬ËûÃÇ×î½ü·¢ÏÖÁËÉæ¼°Ô¼250¸öÔ¤¸¶·ÑÎÞÏßÕË»§µÄδ¾­ÊÚȨµÄ»î¶¯£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÒѾ­²ÉÈ¡Á˶î±íµÄ´ëÊ©£¬£¬£¬£¬£¬£¬£¬ÒÔ±£» £»£»£»£»£»¤Æä¿Í»§ÃâÊÜδ¾­ÊÚȨµÄ½Ó¼û»òڲƭ¹¥»÷¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/verizon-notifies-prepaid-customers-their-accounts-were-breached/


2¡¢Oracle°ä²¼2022Äê10Ô·ݰ²È«¸üн¨¸´366¸ö·ì϶     

      

OracleÔÚ10ÔÂ18ÈÕ°ä²¼ÁË2022Äê10Ô·ݵijÁÒª¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´Á˶à¸ö²úÆ·ÖеÄ366¸ö·ì϶¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ½ÏΪÑϳÁµÄ·ì϶Ô̺¬Oracle°²È«±¸·Ý(Apache HTTP·þÎñÆ÷)Öеķì϶CVE-2022-31813¡¢OracleÉÌÎñƽ̨DynamoÀûÓ÷¨Ê½¿ò¼Ü(dom4j)Öеķì϶CVE-2020-10683ºÍOracleÍ¨Ñ¶ÔÆÔ­ÉúÖ÷Ìⰲȫ±ßÔµ±£» £»£»£»£»£»¤´úÀíÖеķì϶CVE-2022-1292¡£¡£¡£¡£¡£ÆäÖв¿ÃÅ·ì϶¿É±»Ô¶³Ì¹¥»÷ÕßÓÃÀ´½ÚÔìÊÜÓ°ÏìµÄϵͳ£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±½¨ÒéÓû§Á¢¼´²é¿´¸üв¢ÀûÓñØÒªµÄ»º½â´ëÊ©¡£¡£¡£¡£¡£


https://www.oracle.com/security-alerts/cpuoct2022.html


3¡¢ÃÀ¹úKeystone HealthÊý¾Ýй¶ÊÂÎñÓ°ÏìÔ¼23Íò»¼Õß

      

ýÌå10ÔÂ18Èճƣ¬£¬£¬£¬£¬£¬£¬±öϦ·¨ÄáÑÇÖÝÒ½ÁƱ£½¡ÌṩÉÌKeystone HealthµÄÊý¾Ýй¶ÊÂÎñÓ°Ïì235237¸ö»¼Õß¡£¡£¡£¡£¡£KeystoneÔÚ8ÔÂ19ÈÕ·¢ÏÖÒ»Â·ÍøÂ簲ȫÊÂÎñµ¼ÖÂÆäijЩϵͳÖжÏ¡£¡£¡£¡£¡£¾­µ÷²é·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬Î´¾­ÊÚȨµÄµÚÈý·½ÔÚ2022Äê7ÔÂ28ÈÕÖÁ8ÔÂ19ÈÕÆÚ¼ä½Ó¼ûÁËÆäϵͳÄÚµÄÎļþ£¬£¬£¬£¬£¬£¬£¬Ô̺¬»¼ÕßÐÕÃû¡¢Éç»á°²È«ºÅÂëºÍÁÙ´²ÐÅÏ¢µÈ¡£¡£¡£¡£¡£¸Ã»ú¹¹°µÊ¾£¬£¬£¬£¬£¬£¬£¬ËüÒѾ­Í¨ÖªÊÜÓ°Ï컼Õߣ¬£¬£¬£¬£¬£¬£¬²¢½«ÎªËûÃÇÌṩÐÅÓþ¼à²â·þÎñ¡£¡£¡£¡£¡£


https://www.securityweek.com/keystone-health-data-breach-impacts-235000-patients


4¡¢KasperskyÅû¶DiceyFÕë¶Ô¶«ÄÏÑÇÔÚÏ߶ij¡µÄ¹¥»÷»î¶¯

      

10ÔÂ17ÈÕ£¬£¬£¬£¬£¬£¬£¬KasperskyÅû¶ÁËDiceyFÕë¶Ô¶«ÄÏÑÇÔÚÏ߶ij¡µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¸Ã»î¶¯ÖÁÉÙ×Ô2021Äê11ÔÂÒÔÀ´Ò»Ïò»îÔ¾£¬£¬£¬£¬£¬£¬£¬ÆäËÆºõ²»ÊdzöÓÚ¾­¼ÃÖ÷ÕÅ£¬£¬£¬£¬£¬£¬£¬¶øÊǽøÐÐÒñ±ÎµÄ¼äµý»î¶¯ºÍ֪ʶ²úȨÇÔÈ¡¡£¡£¡£¡£¡£¸ÃAPTÍÅ»ïʹÓõĹ¥»÷¿ò¼ÜÃûΪGamePlayerFramework£¬£¬£¬£¬£¬£¬£¬ÕâÊǶÔC++¶ñÒâÈí¼þPuppetLoaderµÄC#³Áд¡£¡£¡£¡£¡£DiceyF»¹Ê¹ÓÃÒ»¸ö·ÂÕÕMango Employee Data SynchronizerµÄGUIÀûÓ㬣¬£¬£¬£¬£¬£¬¸ÃÀûÓý«YunaÏÂÔØ·¨Ê½×°Öõ½Ö¸±êµÄÍøÂçÖС£¡£¡£¡£¡£


https://securelist.com/diceyf-deploys-gameplayerframework-in-online-casino-development-studio/107723/


5¡¢SafeBreach³Æ¼ì²âµ½Ò»ÖÖеÄFUD powershellºóÃÅ

      

SafeBreachÔÚ10ÔÂ18ÈÕ³ÆÆä½üÆÚ¼ì²âµ½Ò»ÖÖÐÂµÄÆëÈ«²»³É¼ì²â(FUD)powershellºóÃÅ¡£¡£¡£¡£¡£¹¥»÷ʼÓÚ´øÓжñÒâÎĵµApply Form.docmµÄµç×ÓÓʼþ¡£¡£¡£¡£¡£¸Ã¶ñÒâÎĵµÓÚ2022Äê8ÔÂ25ÈÕ´ÓÔ¼µ©ÉÏ´«£¬£¬£¬£¬£¬£¬£¬¿É×°Öò¢Ö´ÐÐupdater.vbs¾ç±¾£¬£¬£¬£¬£¬£¬£¬À´´´½¨Ò»¸ö´òË㹤×÷¼ÙÒâͨÀýµÄWindows¸üС£¡£¡£¡£¡£VBS¾ç±¾Ö´ÐÐÁ½¸öPowerShell¾ç±¾Script.ps1ºÍTemp.ps1£¬£¬£¬£¬£¬£¬£¬ËüÃÇÔÚVirusTotalÉϾùδ±»¼ì²âΪ¶ñÒâ¾ç±¾¡£¡£¡£¡£¡£Script.ps1»áÏνӵ½¹¥»÷ÕßC2£¬£¬£¬£¬£¬£¬£¬Temp.ps1½âÂëÏìÓ¦ÖеĺÅÁî¡£¡£¡£¡£¡£


https://www.safebreach.com/resources/blog/safebreach-labs-researchers-uncover-new-fully-undetectable-powershell-backdoor/


6¡¢Zoom½¨¸´ºÏÓÃÓÚmacOSµÄ²úÆ·Öеķì϶CVE-2022-28762

      

¾Ý10ÔÂ18ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬Zoom½¨¸´Á˺ÏÓÃÓÚmacOSµÄZoom Client for MeetingsÖеķì϶£¨CVE-2022-28762£©¡£¡£¡£¡£¡£¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.3£¬£¬£¬£¬£¬£¬£¬µ±Í¨¹ýÔËÐÐÌØ¶¨µÄZoomÀûÓÃÆôÓÃÏà»úģʽ²¼¾°×÷ΪZoomÀûÓòãAPIµÄÒ»²¿ÃÅʱ£¬£¬£¬£¬£¬£¬£¬¿Í»§¶Ë»á´ò¿ªÒ»¸ö±¾µØµ÷ÊԶ˿ڡ£¡£¡£¡£¡£±¾µØ¶ñÒâÓû§Äܹ»ÀûÓõ÷ÊÔ¶Ë¿ÚÏνӲ¢½ÚÔìÔÚZoom¿Í»§¶ËÖÐÔËÐеÄÀûÓᣡ£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾»¹½¨¸´ÁËÁíÒ»¸ö·ì϶CVE-2022-28761£¬£¬£¬£¬£¬£¬£¬ËüÓ°ÏìÁËZoom On-Premise Meeting Connector¶àýÌå·ÓÉÆ÷(MMR)¡£¡£¡£¡£¡£ 


https://securityaffairs.co/wordpress/137266/security/zoom-macos-cve-2022-28762.html