΢Èí³ÆºÚ¿ÍÀûÓÃBoa·þÎñÆ÷Öеķì϶¹¥»÷ÄÜÔ´ÐÐÒµ×éÖ¯

°ä²¼¹¦·ò 2022-11-24
1¡¢Î¢Èí³ÆºÚ¿ÍÀûÓÃBoa·þÎñÆ÷Öеķì϶¹¥»÷ÄÜÔ´ÐÐÒµ×éÖ¯

΢ÈíÔÚ11ÔÂ22ÈÕ°ä²¼»ã±¨£¬ £¬ £¬£¬£¬£¬£¬£¬³Æ·¢ÏÖ¹¥»÷ÕßÀûÓÃBoa web·þÎñÆ÷Öеķì϶¹¥»÷ÄÜÔ´ÐÐÒµ×éÖ¯¡£ ¡£¡£¡£¡£¡£¡£Recorded FutureÔøÓÚ2022Äê4ÔÂÅû¶Õë¶ÔÓ¡¶È¶à¸öµçÍøÔËÓªÉ̵Ĺ¥»÷»î¶¯£¬ £¬ £¬£¬£¬£¬£¬£¬µ«Ã»ÓоßÌå×¢Ã÷¹¥»÷ý½é¡£ ¡£¡£¡£¡£¡£¡£Î¢Èí°µÊ¾£¬ £¬ £¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÃÁËBoaÍøÂç·þÎñÆ÷ÖеÄÒ»¸öÒ×Êܹ¥»÷µÄ×é¼þ¡£ ¡£¡£¡£¡£¡£¡£Boa×Ô2005ÄêÒÔÀ´ÒÑÕýʽͣ²ú£¬ £¬ £¬£¬£¬£¬£¬£¬µ«ÎïÁªÍøÉ豸ÈÔÔÚʹÓøýâ¾ö¹æ»®£¬ £¬ £¬£¬£¬£¬£¬£¬Î¢ÈíÒ»¸öÐÇÆÚÄÚº­È«Çò·¢ÏÖÁ˳¬¹ý100Íò¸ö¶³öÔÚ»¥ÁªÍøÉϵÄBoa·þÎñÆ÷×é¼þ¡£ ¡£¡£¡£¡£¡£¡£Boa·þÎñÆ÷´æÔÚ¶à¸ö·ì϶£¬ £¬ £¬£¬£¬£¬£¬£¬Ô̺¬ËÁÒâÎļþ½Ó¼û·ì϶(CVE-2017-9833)ºÍÐÅϢй¶·ì϶(CVE-2021-33558)¡£ ¡£¡£¡£¡£¡£¡£

https://www.microsoft.com/en-us/security/blog/2022/11/22/vulnerable-sdk-components-lead-to-supply-chain-risks-in-iot-and-ot-environments/

2¡¢KillnetÐû³Æ¶Ôµ¼ÖÂÅ·ÖÞÒé»áÍøÕ¾¹Ø¹ØµÄDDS¹¥»÷ÕÆ¹Ü

¾ÝýÌå11ÔÂ23ÈÕ±¨Â·£¬ £¬ £¬£¬£¬£¬£¬£¬ºÚ¿ÍÍÅ»ïKillnetµÄÒ»²¿ÃÅAnonymous RussiaÐû³ÆÌáÒéDDoS¹¥»÷£¬ £¬ £¬£¬£¬£¬£¬£¬µ¼ÖÂÅ·ÖÞÒé»áµÄÍøÕ¾¡£ ¡£¡£¡£¡£¡£¡£Å·ÖÞÒé»áÖ÷ϯ֤ʵÁËÕâÒ»ÊÂÎñ£¬ £¬ £¬£¬£¬£¬£¬£¬³ÆÒé»áµÄITÈËÔ¹ØýÔڻػ÷²¢±£»£» £»£»£»£» £»¤ÏµÍ³¡£ ¡£¡£¡£¡£¡£¡£´Ë±í£¬ £¬ £¬£¬£¬£¬£¬£¬11ÔÂ22ÈÕÁ賿£¬ £¬ £¬£¬£¬£¬£¬£¬Killnet»¹¹¥»÷ÁËÓ¢¹úÍþÁ®Íõ×ÓµÄÍøÕ¾£¬ £¬ £¬£¬£¬£¬£¬£¬Ö»¹Ü¸ÃÍøÕ¾´Ë¿ÌÄܹ»Õý³£ÔËÐУ¬ £¬ £¬£¬£¬£¬£¬£¬µ«Cloudflare¶ÔÏνӽøÐÐÁ˶î±íµÄ°²È«²é³­¡£ ¡£¡£¡£¡£¡£¡£Killnet»¹·¢Ìû³Æ£¬ £¬ £¬£¬£¬£¬£¬£¬ÆäÖ¸±êÊÇÂ×¶ØÖ¤È¯ÂòÂôËù¡¢Ó¢¹ú¾ü¶ÓºÍÒøÐÐ×Ô¶¯ËãÕÊϵͳ(Bacs)µÄÍøÕ¾¡£ ¡£¡£¡£¡£¡£¡£

https://www.bleepingcomputer.com/news/security/pro-russian-hacktivists-take-down-eu-parliament-site-in-ddos-attack/

3¡¢²¨¶àÀè¸÷µÄDCHÒ½ÔºÔâµ½ÀÕË÷¹¥»÷Ó°ÏìÔ¼120ÍòÃû»¼Õß

ýÌå11ÔÂ22Èճƣ¬ £¬ £¬£¬£¬£¬£¬£¬²¨¶àÀè¸÷µÄÒ½ÉúÖÐÐÄÒ½Ôº£¨DCH£©Ôâµ½ÐÂÀÕË÷ÍÅ»ïProject RelicµÄ¹¥»÷¡£ ¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÒѹ«¿ªÆäÇÔÈ¡µÄ211 GBÎļþÖеÄ114 MBÊý¾Ý£¬ £¬ £¬£¬£¬£¬£¬£¬Ñù±¾Êý¾ÝÔ̺¬ÁËҽԺϵͳµÄÄÚ²¿Îļþ£¬ £¬ £¬£¬£¬£¬£¬£¬¹ØÓÚÔ±¹¤µÄÎļþÒÔ¼°Éæ¼°²¡ÈËÒ½ÁÆÐÅÏ¢µÄÎļþµÈ¡£ ¡£¡£¡£¡£¡£¡£DCHÔÚ11ÔÂ9ÈÕ֪ͨHHS£¬ £¬ £¬£¬£¬£¬£¬£¬ÓÐ1195220Ãû»¼ÕßÊܵ½Õâ´ÎÊÂÎñµÄÓ°Ïì¡£ ¡£¡£¡£¡£¡£¡£¾ÝBlackPoint³Æ£¬ £¬ £¬£¬£¬£¬£¬£¬Project RelicÀÕË÷Èí¼þÊÇÓÃGo˵»°¿ª·¢µÄ£¬ £¬ £¬£¬£¬£¬£¬£¬µ«ÓÃÓÚ×°ÖöñÒâÈí¼þºÍÇÔÈ¡Êý¾ÝµÄ²½ÖèÒÀȻδ֪¡£ ¡£¡£¡£¡£¡£¡£

https://www.databreaches.net/doctors-center-hospital-reports-1-2-million-patients-affected-by-ransomware-attack/

4¡¢¶íÂÞ˹RoskomnadzorµÄÄÚÍø±»Cyber PartisansÈëÇÖ

¾Ý11ÔÂ22ÈÕ±¨Â·£¬ £¬ £¬£¬£¬£¬£¬£¬¶íÂÞ˹»¥ÁªÍøºÍýÌå¼à¹Ü»ú¹¹RoskomnadzorÔâµ½ºÚ¿Í¹¥»÷¡£ ¡£¡£¡£¡£¡£¡£Cyber PartisansÓÚÉÏÖÜÎåÐû³Æ´Ó¸Ã»ú¹¹ÇÔÈ¡ÁËÊýǧ·ÝÄÚ²¿Îļþ²¢¼ÓÃÜÁËÆäϵͳ¡£ ¡£¡£¡£¡£¡£¡£¶íÂÞ˹ͨÓÃÎÞÏßµçÆµÂÊÖÐÐÄ(GRFC)°µÊ¾£¬ £¬ £¬£¬£¬£¬£¬£¬ºÚ¿ÍÉϸöÔ³õ´Î³¢ÊÔʹÓÃÒÔǰδÀûÓùýµÄ·ì϶ÈëÇָûú¹¹£¬ £¬ £¬£¬£¬£¬£¬£¬Ä¿Ç°ÍøÂç¹¥»÷Òѵõ½½ÚÔ죬 £¬ £¬£¬£¬£¬£¬£¬Ã»ÓÐÈκλúÃÜÐÅϢй¶¡£ ¡£¡£¡£¡£¡£¡£×÷Ϊ»ØÓ¦£¬ £¬ £¬£¬£¬£¬£¬£¬Cyber PartisansÔÚÖÜÁùй©ËûÃÇ»ñµÃÁËÔ±¹¤µÄ»¤ÕÕÊý¾ÝºÍÒ½ÁƼͼ¡¢ÄÚ²¿ÓʼþºÍ¸Ã»ú¹¹ÏîÖ÷ÕŻ㱨¡£ ¡£¡£¡£¡£¡£¡£

https://therecord.media/belarusian-hacktivists-claim-to-breach-russias-internet-regulator/

5¡¢Bitdefenderй©SharkBotľÂí³Á·µGoogle PlayÉ̵ê

BitdefenderÔÚ11ÔÂ21Èճƣ¬ £¬ £¬£¬£¬£¬£¬£¬Ò»×é¼Ù×°³ÉÎļþÖÎÀíÆ÷µÄ¶ñÒâAndroidÀûÓÃÒÑÉøÈëµ½¹Ù·½Google PlayÀûÓÃÉ̵꣬ £¬ £¬£¬£¬£¬£¬£¬Ö¼ÔÚʹÓû§Ï°È¾SharkbotľÂí¡£ ¡£¡£¡£¡£¡£¡£·¢ÏֵĶñÒâÀûÓÃΪX-File Manager¡¢FileVoyagerºÍLiteCleaner M¡£ ¡£¡£¡£¡£¡£¡£BitdefenderÒ£²âÊý¾Ý·´Ó³³öÕâ´Î»î¶¯µÄÖ¸±êÁìÓò½ÏÓ×£¬ £¬ £¬£¬£¬£¬£¬£¬´óÎÞÊýÖ¸±êλÓÚÓ¢¹ú£¬ £¬ £¬£¬£¬£¬£¬£¬Æä´ÎÊÇÒâ´óÀû¡¢ÒÁÀʺ͵¹ú¡£ ¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬ £¬ £¬£¬£¬£¬£¬£¬ÕâЩ·¨Ê½¶¼ÒÑ´ÓGoogle PlayÉ̵êÖÐɾ³ý¡£ ¡£¡£¡£¡£¡£¡£

https://www.bitdefender.com/blog/labs/android-sharkbot-droppers-on-google-play-underlines-platforms-security-needs/

6¡¢Kaspersky°ä²¼2023ÄêICSÍøÂçÍþÐ²Ì¬ÊÆµÄÔ¤²â»ã±¨

11ÔÂ22ÈÕ£¬ £¬ £¬£¬£¬£¬£¬£¬Kaspersky°ä²¼Á˹ØÓÚ2023ÄêICSÍøÂçÍþÐ²Ì¬ÊÆµÄÔ¤²â»ã±¨¡£ ¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬ £¬ £¬£¬£¬£¬£¬£¬Ëæ×ÅÏÖÓеĺÍеÄÕ½ÊõÒÔ¼°Õ½ÊõÁªÃ˵ijöÏÖ£¬ £¬ £¬£¬£¬£¬£¬£¬¹¥»÷Ö¸±êµÄµØÀíµØÎ»½«²»³ÉÔ¤·ÀÏß²úÉú±ä¶¯£¬ £¬ £¬£¬£¬£¬£¬£¬×òÌìµÄÃËÓÑ¿ÉÄÜ»á³ÉΪ½ñÌìµÄÖ¸±ê¡£ ¡£¡£¡£¡£¡£¡£ÐÐÒµ³ÁÐĽ«²úÉú±ä¶¯£¬ £¬ £¬£¬£¬£¬£¬£¬ºÜ¿ì¾Í»á¿´µ½Õë¶ÔũҵºÍʳƷ¡¢ÎïÁ÷ºÍÔËÊä¡¢ÄÜÔ´¡¢¸ß¿Æ¼¼ºÍÒ½ÁÆÓйز¿ÃŵĹ¥»÷¡£ ¡£¡£¡£¡£¡£¡£Õë¶Ô´«Í³Ö¸±êµÄAPT¹¥»÷ÈÔ»á´æÔÚ£¬ £¬ £¬£¬£¬£¬£¬£¬ÖØÒªÔ̺¬¾ü¹¤ÆóÒµ¡¢µ±¾Ö»ú¹¹ºÍ¹Ø¼üµÄ»ù´¡ÉèÊ©¡£ ¡£¡£¡£¡£¡£¡£

https://securelist.com/ics-cyberthreats-in-2023/108011/