Cisco°ä²¼°²È«¸üУ¬£¬£¬£¬£¬½¨¸´Æä²¿ÃŲúÆ·ÖеĶà¸ö·ì϶
°ä²¼¹¦·ò 2022-11-07
CiscoÓÚ11ÔÂ2ÈÕ°ä²¼Á˰²È«¸üУ¬£¬£¬£¬£¬½¨¸´Æä²¿ÃŲúÆ·ÖеĶà¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£ÆäÖÐ×îÑϳÁµÄÊÇ¿çÕ¾ÒªÇóαÔì·ì϶£¨CVE-2022-20961£©£¬£¬£¬£¬£¬ËüÓ°ÏìÁËÉí·Ý·þÎñÒýÇæ(ISE)£¬£¬£¬£¬£¬µ××ÓÔÒòÊÇ»ùÓÚWebµÄÖÎÀí½çÃæµÄCSRF±£»£»£»£»£»£»£»¤²»¼°¡£¡£¡£¡£¡£¡£¡£ÒÔ¼°ISE²úÆ·ÖеĽӼû½ÚÔì²»¼°·ì϶£¨CVE-2022-20956£©£¬£¬£¬£¬£¬¿Éͨ¹ýÏòÖ¸±ê·¢ËÍÌØÔìµÄHTTPÒªÇóÀ´ÀûÓᣡ£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬»¹½¨¸´ÁËCisco ESAºÍCisco Secure Email and Web Manager Next Generation ManagementÖеÄSQL×¢Èë·ì϶£¨CVE-2022-20867£©ºÍÌáȨ·ì϶£¨CVE-2022-20868£©µÈ¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/138068/security/cisco-addressed-multiple-flaws.html
2¡¢LockBitÐû³Æ¶ÔµÂ¹úÆû³µ¹«Ë¾ContinentalµÄ¹¥»÷ÕÆ¹Ü
¾ÝýÌå11ÔÂ3ÈÕ±¨Â·£¬£¬£¬£¬£¬ÀÕË÷ÍÅ»ïLockBitÐû³Æ¶ÔµÂ¹úContinental£¨´ó½Æû³µ£©µÄ¹¥»÷ÕÆ¹Ü¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚLockBit°µÊ¾½«°ä²¼ËùÓпÉÓÃÊý¾Ý£¬£¬£¬£¬£¬ÕâÅú×¢¸Ã¹«Ë¾ÉÐδÓëÀÕË÷ÍÅ»ï½øÐн»É棬£¬£¬£¬£¬»òÕßËüÒѾ»Ø¾øÁËÒªÇ󡣡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïÉÐδÌṩÓÐ¹ØÆäй¶µÄÊý¾Ý»òÖ´Ðй¥»÷µÄ¹¦·òµÄϸ½ÚÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾²¢Î´Ö¤ÊµLockBitµÄ˵·¨£¬£¬£¬£¬£¬µ«ÆäÔøÔÚ8ÔÂ24ÈÕй©£¬£¬£¬£¬£¬ËûÃÇÔÚ8Ô³õ¼ì²âµ½Á˹¥»÷»î¶¯£¬£¬£¬£¬£¬¹¥»÷ÕßÈëÇÖÁËContinental¼¯ÍŵIJ¿ÃÅITϵͳ¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/lockbit-ransomware-claims-attack-on-continental-automotive-giant/
3¡¢²¨Òô×Ó¹«Ë¾JeppesenÔâµ½¹¥»÷µ¼Ö²¿ÃÅ·ÉÐдòËãÖжÏ
ýÌå10ÔÂ3Èճƣ¬£¬£¬£¬£¬Ìṩµ¼º½ºÍ·ÉÐдòË㹤¾ßµÄ²¨ÒôÈ«×Ê×Ó¹«Ë¾JeppesenÔÚ´¦Öõ¼Ö²¿Ãź½°àÖжϵݲȫÊÂÎñ¡£¡£¡£¡£¡£¡£¡£²¨Òô¹«Ë¾µÄ½²»°È˳ƣ¬£¬£¬£¬£¬Ö»¹Ü¹¥»÷µ¼Ö²¿ÃÅ·ÉÐдòËãÖжϣ¬£¬£¬£¬£¬µ«Ä¿Ç°Ã»ÓжԷɻú»ò·ÉÐа²È«×é³ÉÍþв¡£¡£¡£¡£¡£¡£¡£ËûÃÇÔÚÓë¿Í»§ºÍ¼à¹Ü»ú¹¹½øÐйµÍ¨£¬£¬£¬£¬£¬²¢ÖÂÁ¦¾¡¿ì¸´Ô·þÎñ¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜÖжϵÄˮƽÉв»Ã÷ÏÔ£¬£¬£¬£¬£¬µ«¸ÃÊÂÎñÓ°ÏìÁ˵±Ç°ºÍеķÉÐй¤×÷֪ͨ£¨NOTAM£©µÄ½Ó¹ÜºÍ´¦Ö㬣¬£¬£¬£¬ËüÓÃÓÚÏòº½¿Õµ±¾ÖÌύ֪ͨ£¬£¬£¬£¬£¬ÒÔÌáÐÑ·ÉÐÐÔ±°ÑÎÈ·ÉÐзÏßÉϵÄDZÔÚΣÏÕ¡£¡£¡£¡£¡£¡£¡£
https://therecord.media/cyber-incident-at-boeing-subsidiary-causes-flight-planning-disruptions/
4¡¢µ¤Âó×î´óÌú·ÔËÓªÉÌDSB±»ºÚºó¸Ã¹ú»ð³µÍ£ÔËÊýÓ×ʱ
¾Ý·͸Éç11ÔÂ3ÈÕ±¨Â·£¬£¬£¬£¬£¬¸Ã¹ú×î´óµÄÌú·ÔËÓª¹«Ë¾DSBµÄËùÓлð³µÔÚÖÜÁùÔçÉÏÍ£ÔË£¬£¬£¬£¬£¬ÇÒÊýÓ×ʱÎÞ·¨¸´ÔÐг̡£¡£¡£¡£¡£¡£¡£DSBµÄ°²È«Ö÷¹Üй©£¬£¬£¬£¬£¬Õâ´ÎÍ£ÔËÊÇÓÉÓÚÆäµÚÈý·½IT·þÎñÌṩÉÌSupeoµÄ²âÊÔ»·¾³±»ÈëÇÖµ¼Öµģ¬£¬£¬£¬£¬¸Ã¹«Ë¾±»ÆÈ¹Ø¹ØÁË·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£SupeoÌṩһ¸öÒÆ¶¯ÀûÓ㬣¬£¬£¬£¬ÓÃÓÚ»ð³µË¾»ú½Ó¼û¹Ø¼üµÄÔËÓªÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£µ±Supeo¾ö¶¨¹Ø¹ØÆä·þÎñÆ÷ʱ£¬£¬£¬£¬£¬¸ÃÀûÓ÷¨Ê½ÖÕ³¡¹¤×÷£¬£¬£¬£¬£¬Ë¾»ú±»ÆÈÍ£³µ¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°Éв»Ã÷ÏÔ¹¥»÷µÄÄ»ºóºÚÊÖ£¬£¬£¬£¬£¬µ«µ÷²éÈÔÔÚ½øÐÐÖС£¡£¡£¡£¡£¡£¡£
https://www.reuters.com/technology/danish-train-standstill-saturday-caused-by-cyber-attack-2022-11-03/
5¡¢Microsoft°ä²¼¹ØÓÚ2022ÄêÊý×Ö·ÀÓùµÄ·ÖÎö»ã±¨
¾Ý11ÔÂ5ÈÕ±¨Â·£¬£¬£¬£¬£¬Î¢Èí°ä²¼ÁË2022ÄêÊý×Ö·ÀÓù»ã±¨¡£¡£¡£¡£¡£¡£¡£Î¢ÈíÖ¸³ö£¬£¬£¬£¬£¬ÔÚ¹«¿ªÅû¶·ì϶ºó£¬£¬£¬£¬£¬¾ùÔÈÖ»Ðè14Ìì¼´¿É±»ÔÚÒ°ÀûÓ㬣¬£¬£¬£¬¶øÔÚGitHubÉϰ䲼·ì϶ÀûÓôúÂëÔò±ØÒª60Ìì¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±¹Û²ìµ½£¬£¬£¬£¬£¬ÁãÈÕ·ì϶×î³õÊÇÔÚÓµÓÐÕë¶ÔÐԵĹ¥»÷Öб»ÀûÓõ쬣¬£¬£¬£¬¶øºóºÜ¿ìÔÚÒ°±í¹¥»÷Öб»Ñ¡È¡¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾×ܽá·£¬£¬£¬£¬£¬·ì϶ÔÚ±»´ó¹æÄ£µØ·¢ÏÖºÍÀûÓ㬣¬£¬£¬£¬²¢ÇÒ¹¦·òÔ½À´Ô½¶Ì¡£¡£¡£¡£¡£¡£¡£ËûÃǽ¨Òé×éÖ¯ÔÚÁãÈÕ·ì϶°ä²¼ºóÁ¢¼´½øÐн¨¸´£¬£¬£¬£¬£¬»¹½¨Òé¼Í¼ºÍÅ̵ãËùÓÐÆóÒµÓ²¼þºÍÈí¼þ×ʲú£¬£¬£¬£¬£¬ÒÔÈ·¶¨ËüÃÇÔâµ½¹¥»÷µÄ·çÏÕ¡£¡£¡£¡£¡£¡£¡£
https://www.microsoft.com/en-us/security/business/microsoft-digital-defense-report-2022
6¡¢SentinelLabs°ä²¼ÀÕË÷Èí¼þBlack BastaµÄ·ÖÎö»ã±¨
11ÔÂ3ÈÕ£¬£¬£¬£¬£¬SentinelLabs°ä²¼Á˹ØÓÚÀÕË÷Èí¼þBlack BastaµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£Black BastaÓÚ2022Äê4Ô³öÏÖ£¬£¬£¬£¬£¬»ã±¨¾ßÌå·ÖÎöÁËBlack BastaµÄTTP£¬£¬£¬£¬£¬Ô̺¬Ê¹ÓÿÉÄÜÓÉFIN7£¨±ðÃûCarbanak£©¿ª·¢ÈËÔ±¿ª·¢µÄ¸÷Àà×Ô½ç˵¹¤¾ß¡£¡£¡£¡£¡£¡£¡£×êÑÐÅú×¢£¬£¬£¬£¬£¬Black BastaºÜ¿ÉÄÜÓëFIN7ÓйØÁª¡£¡£¡£¡£¡£¡£¡£Ëü»áÊØ»¤ºÍ²¿Êð×Ô½ç˵¹¤¾ß£¬£¬£¬£¬£¬Ô̺¬EDRÈÆ¹ý¹¤¾ß¡£¡£¡£¡£¡£¡£¡£ÕâЩEDRÈÆ¹ý¹¤¾ßµÄ¿ª·¢ÕߺܿÉÄÜÊÇ»òÒѾÊÇFIN7µÄ¿ª·¢Õß¡£¡£¡£¡£¡£¡£¡£¹¥»÷ʹÓÃADFindµÄ»ìºÏ°æ±¾£¬£¬£¬£¬£¬²¢ÀûÓÃPrintNightmare¡¢ZeroLogonºÍNoPac½øÐÐÌáȨ¡£¡£¡£¡£¡£¡£¡£
https://www.sentinelone.com/labs/black-basta-ransomware-attacks-deploy-custom-edr-evasion-tools-tied-to-fin7-threat-actor/


¾©¹«Íø°²±¸11010802024551ºÅ