Apple½¨¸´±»ÀûÓõÄÔ½½çдÈë·ì϶CVE-2022-42827
°ä²¼¹¦·ò 2022-10-25
AppleÔÚ10ÔÂ24ÈÕ°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´¿ÉÄÜÒѱ»»ý¼«ÀûÓõķì϶£¨CVE-2022-42827£©¡£¡£¡£¡£¡£ÕâÊÇÒ»¸öÔ½½çдÈë·ì϶£¬£¬£¬£¬£¬£¬£¬ÓÉÈí¼þÔÚµ±Ç°Äڴ滺³åÇøÌìǵ֮±íдÈëÊý¾ÝÒýÆð£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÊý¾Ý°Ü»µ¡¢ÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»£»ò´úÂëÖ´ÐС£¡£¡£¡£¡£ÊÜÓ°ÏìÉ豸Ô̺¬iPhone 8¼°ÒÔÉÏ»úÐÍ¡¢iPad ProËùÓÐÐͺš¢iPad AirµÚ3´ú¼°ÒÔÉÏ»úÐ͵ȡ£¡£¡£¡£¡£Appleͨ¹ý¸Ä½øÌìǵ²é³½¨¸´ÁËiOS 16.1ºÍiPadOS 16Öеķì϶£¬£¬£¬£¬£¬£¬£¬ÕâÊǸù«Ë¾×ÔËêÊ×ÒÔÀ´½¨¸´µÄµÚ9¸öÁãÈÕ·ì϶¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/apple/apple-fixes-new-zero-day-used-in-attacks-against-iphones-ipads/
2¡¢Êýǧ¸öGitHub´æ´¢¿âÌṩÔ̺¬¶ñÒâÈí¼þµÄÐéαPoC
¾Ý10ÔÂ23ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±ÔÚGitHubÉÏ·¢ÏÖÁËÊýǧ¸öÌṩÕë¶Ô¸÷Àà·ì϶µÄÐéα¸ÅÏëÑéÖ¤(PoC)µÄ´æ´¢¿â£¬£¬£¬£¬£¬£¬£¬ÆäÖÐһЩÔ̺¬¶ñÒâÈí¼þ¡£¡£¡£¡£¡£ÔÚ²âÊÔµÄ47313¸ö´æ´¢¿âÖУ¬£¬£¬£¬£¬£¬£¬×ܹ²ÓÐ4893¸öÊǶñÒâµÄ£¬£¬£¬£¬£¬£¬£¬ÆäÖдó¶àÓë2020ÄêÒÔÀ´µÄ·ì϶Óйء£¡£¡£¡£¡£Í¨¹ý×êÑÐÆäÖеÄһЩ°¸Àý£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÁË´óÁ¿µÄ¶ñÒâÈí¼þºÍ¶ñÒâ¾ç±¾£¬£¬£¬£¬£¬£¬£¬´ÓÔ¶³Ì½Ó¼ûľÂíµ½Cobalt Strike¡£¡£¡£¡£¡£ÀýÈçCVE-2019-0708µÄPoC£¬£¬£¬£¬£¬£¬£¬Ô̺¬Ò»¸öbase64»ìºÏµÄPython¾ç±¾£¬£¬£¬£¬£¬£¬£¬¿É´ÓPastebin»ñÈ¡VBScript¡£¡£¡£¡£¡£¸Ã¾ç±¾ÊÇHoudini RAT£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ýWindows CMDÖ´ÐÐÔ¶³ÌºÅÁî¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/thousands-of-github-repositories-deliver-fake-poc-exploits-with-malware/
3¡¢BlackByteÀûÓÃ×Ô½ç˵¹¤¾ßExByte¼±¾çÇÔȡָ±êÊý¾Ý
SymantecÔÚ10ÔÂ21ÈÕÅû¶ÁËÀÕË÷ÍÅ»ïBlackByteʹÓõļ±¾çÇÔȡָ±êÊý¾ÝµÄй¤¾ßExByte¡£¡£¡£¡£¡£ExbyteÊÇÓÃGo±àдµÄ£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚ½«±»µÁÎļþÉÏ´«µ½Mega.co.nzÔÆ´æ´¢·þÎñ¡£¡£¡£¡£¡£ÔÚÖ´ÐÐʱ£¬£¬£¬£¬£¬£¬£¬¸Ã¹¤¾ß»áÖ´Ðз´·ÖÎö²é³ÒÔÈ·¶¨ËüÊÇ·ñÔÚɳºÐ»·¾³ÖÐÔËÐУ¬£¬£¬£¬£¬£¬£¬²¢²é³µ÷ÊÔÆ÷ºÍɱ¶¾¹ý³Ì¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬£¬Exbyte»áö¾ÙϵͳÉϵÄËùÓÐÎĵµÎļþ£¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃÓ²±àÂëµÄÕÊ»§Í´´¦½«ËüÃÇÉÏ´«µ½MegaÉÏд´½¨µÄÎļþ¼Ð¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬½üÆÚµÄBlackByte¹¥»÷»î¶¯ÒÀÀµÓÚÈ¥ÄêµÄProxyShellºÍProxyLogon·ì϶£¬£¬£¬£¬£¬£¬£¬²¢ÀûÓÃAdFind¡¢AnyDesk¡¢NetScanºÍPowerViewµÈ¹¤¾ßºáÏòÒÆ¶¯¡£¡£¡£¡£¡£
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/blackbyte-exbyte-ransomware
4¡¢EyeMedÒò2020ÄêÊý¾Ýй¶ÊÂÎñ±»Å¦Ô¼·£¿£¿£¿£¿£¿£¿£¿£¿î450ÍòÃÀÔª
ýÌå10ÔÂ19Èճƣ¬£¬£¬£¬£¬£¬£¬EyeMedÒò2020Äê´ó¹æÄ£µç×ÓÓʼþºÍÒ½ÁƱ£½¡Êý¾Ýй¶ÊÂÎñ±»Å¦Ô¼ÖÝÔٴη£¿£¿£¿£¿£¿£¿£¿£¿î¡£¡£¡£¡£¡£½ñÄêËêÊ×£¬£¬£¬£¬£¬£¬£¬Å¦Ô¼ÔøÒò2020ÄêÓ°Ïì210ÍòÈ˵ÄÊý¾Ýй¶ÊÂÎñ¶ÔEyeMed´¦ÒÔ60ÍòÃÀÔªµÄ·£¿£¿£¿£¿£¿£¿£¿£¿î¡£¡£¡£¡£¡£Ö®ºóµÄµ÷²é·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶ÊÂÎñÓëEyeMedµÄÎ¥¹æÍ¨Öª´æÔÚһЩ²î¾à£¬£¬£¬£¬£¬£¬£¬ÀýÈ磬£¬£¬£¬£¬£¬£¬EyeMedûÓÐй©¹¥»÷ÕßÔÚÒÑ´Ó±»Ï°È¾µÄÕÊ»§·¢ËÍÁËÖÁÉÙ2000·â´¹µöÓʼþ¡£¡£¡£¡£¡£¸Ã¹«Ë¾½«Îªµ¼ÖÂÊý¾Ýй¶µÄ¶àÏȫΥ¹æÐÐΪ֧¸¶450ÍòÃÀÔªµÄ·£¿£¿£¿£¿£¿£¿£¿£¿î¡£¡£¡£¡£¡£
https://www.scmagazine.com/analysis/privacy/new-york-fines-eyemed-4-5-million-for-2020-email-hack-data-breach
5¡¢ºÚ¿ÍÔÚ°µÍøÊг¡ÏúÊÛCarousell 260Íò¸öÕË»§µÄÐÅÏ¢
¾ÝýÌå10ÔÂ22ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬Ò»¸ö¾ÝÐÅ´ÓÔÚÏßÊг¡Carousell±»µÁµÄÕÊ»§Êý¾Ý¿âÔÚ°µÍøºÍºÚ¿ÍÂÛ̳ÉÏÏúÊÛ¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÔ̺¬260Íò¸öÕË»§ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÊÛ¼ÛΪ1000ÃÀÔª¡£¡£¡£¡£¡£CarousellÉÏÖÜÎ尵ʾ£¬£¬£¬£¬£¬£¬£¬ÓÐ195ÍòÓû§Êܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬²¢°µÊ¾ËûÃǵÄÊý¾ÝÔÚÒ»´ÎϵͳǨáãÖÐÒýÈëÁËÒ»¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬²¢±»µÚÈý·½ÓÃÀ´»ñµÃδ¾ÊÚȨµÄ½Ó¼û£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶ĿǰÒѾ±»½¨¸´¡£¡£¡£¡£¡£ºÚ¿ÍÓÚ10ÔÂ12ÈÕÉÏ´«ÁË2 GBµÄÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Ô̺¬1000¸öÓû§Êý¾ÝµÄÑù±¾Îļþ¡£¡£¡£¡£¡£½ØÖÁÉÏÖÜÁù£¬£¬£¬£¬£¬£¬£¬ºÚ¿Íй©ÒÑÊÛ³öÁ½·Ý¡£¡£¡£¡£¡£
https://www.asiaone.com/singapore/carousell-data-breach-info-26-million-accounts-allegedly-sold-dark-web-hacking-forums
6¡¢Fortinet·¢ÏÖÀûÓÃVMware·ì϶´«²¼¶à¸ö¶ñÒâÈí¼þµÄ»î¶¯
10ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬£¬Fortinet³ÆÆä¹Û²ìµ½ÀûÓÃVMware Workspace One AccessÖзì϶À´´«²¼¸÷Àà¶ñÒâÈí¼þµÄ»î¶¯¡£¡£¡£¡£¡£¸Ã·ì϶׷×ÙΪCVE-2022-22954£¬£¬£¬£¬£¬£¬£¬ÊÇÒ»¸öͨ¹ý·þÎñÆ÷¶ËÄ£°å×¢Èë´¥·¢µÄÔ¶³Ì´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬£¬£¬ÒÑÔÚ2022Äê4Ô±»½¨¸´¡£¡£¡£¡£¡£FortinetÔÚ8Ô·ݹ۲쵽ÐÂÒ»Âֻ£¬£¬£¬£¬£¬£¬£¬ÊÔIJÀûÓ÷ì϶ÔÚLinuxÉ豸װÖÃMirai½©Ê¬ÍøÂ磬£¬£¬£¬£¬£¬£¬ÀûÓúϷ¨WinRaR·Ö·¢¼ÓÃܵÄRAR1ransom£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÍÚ¾òÃÅÂÞ±ÒµÄxmrig±äÌåGuardMiner¡£¡£¡£¡£¡£
https://www.fortinet.com/blog/threat-research/multiple-malware-campaigns-target-vmware-vulnerability


¾©¹«Íø°²±¸11010802024551ºÅ