Google°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´ChromeÖеĶà¸ö·ì϶
°ä²¼¹¦·ò 2022-12-0111ÔÂ29ÈÕ£¬£¬£¬£¬£¬£¬Google°ä²¼Chrome°²È«¸üУ¬£¬£¬£¬£¬£¬×ܼƽ¨¸´ÁË28¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£ÆäÖнÏΪÑϳÁµÄÊÇV8ÖеÄÀàÐÍ»ìºÏ·ì϶£¨CVE-2022-4174£©¡¢Camera CaptureÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2022-4175£©¡¢Lacros GraphicsÖеÄÔ½½çдÈë·ì϶£¨CVE-2022-4176£©¡¢À©´óÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2022-4177£©ÒÔ¼°MojoÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2022-4178£©µÈ¡£¡£¡£¡£¡£¡£¡£Google°µÊ¾£¬£¬£¬£¬£¬£¬Ä¿Ç°Ã»ÓйØÓÚÕâЩ·ì϶ÔÚÒ°±í±»ÀûÓõĻ㱨¡£¡£¡£¡£¡£¡£¡£
https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_29.html
2¡¢Lastpassй©ÆäÔÆ´æ´¢·þÎñÖеĿͻ§Êý¾ÝÒѾй¶
LastPassÔÚ11ÔÂ30ÈÕ°ä²¼ÉêÃ÷³Æ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÃÔÚ2022Äê8ÔµĹ¥»÷ÊÂÎñÖÐÇÔÈ¡µÄÐÅÏ¢ÈëÇÖÁËÆäÔÆ´æ´¢·þÎñ¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚÆäµÚÈý·½ÔÆ´æ´¢·þÎñÖмì²âµ½Òì³£»£»£»£»£»£»£»£»î¶¯£¬£¬£¬£¬£¬£¬Ò»µ©³É¹¦½øÈë¹¥»÷Õß»¹Éè·¨½Ó¼û´æ´¢ÔÚ´æ´¢·þÎñÖеĿͻ§Êý¾Ý¡£¡£¡£¡£¡£¡£¡£Lastpass²¹³ä°µÊ¾£¬£¬£¬£¬£¬£¬ËûÃÇÔÚÖÂÁ¦Ïàʶ¸ÃÊÂÎñµÄÓ°ÏìÁìÓò£¬£¬£¬£¬£¬£¬²¢È·¶¨ºÚ¿Í½Ó¼ûÁËÄÄЩÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÕâÊÇLastpassÔÚ½ñÄêÅû¶µÄµÚ¶þÆð°²È«ÊÂÎñ£¬£¬£¬£¬£¬£¬´Ëǰ£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚ8ÔÂÈ·ÈÏÆä¿ª·¢Õß»·¾³Òò¿ª·¢ÕßÕË»§±»µÁ¶øÔâµ½ÈëÇÖ¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/lastpass-says-hackers-accessed-customer-data-in-new-breach/
3¡¢Mandiant·¢ÏÖÀûÓÃUSBÉ豸¹¥»÷·ÆÂɱö×éÖ¯µÄ»î¶¯
¾ÝMandiant 11ÔÂ28ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬½üÆÚ·¢ÏÖÁËÀûÓÃUSBÉ豸×÷Ϊ³õʼϰȾý½éµÄ¼äµý»î¶¯£¬£¬£¬£¬£¬£¬²¢¼¯ÖÐÔÚ·ÆÂɱö¡£¡£¡£¡£¡£¡£¡£Mandiant½«´Ë»î¶¯¸ú×ÙΪUNC4191£¬£¬£¬£¬£¬£¬×îÔç¿É×·Òäµ½2021Äê9Ô£¬£¬£¬£¬£¬£¬¸Ã»î¶¯ÖØÒªÓ°ÏìÁ˶«ÄÏÑǵÄ×éÖ¯£¬£¬£¬£¬£¬£¬²¢ÑÓ³¤µ½ÁËÃÀ¹ú¡¢Å·ÖÞºÍÑÇÌ«µØÓò¡£¡£¡£¡£¡£¡£¡£¼´±ãÖ¸±ê×é֯λÓÚÆäËûµØÎ»£¬£¬£¬£¬£¬£¬UNC4191ËùÕë¶ÔµÄϵͳÏÖʵλÓÚ·ÆÂɱö¡£¡£¡£¡£¡£¡£¡£ÔÚͨ¹ýUSBÉ豸½øÐгõʼϰȾºó£¬£¬£¬£¬£¬£¬¹¥»÷Õß»áÀûÓúϷ¨Ç©ÊðµÄ¶þ½øÔìÎļþÀ´²à¼ÓÔØ3¸öеĶñÒâÈí¼þϵÁУ¬£¬£¬£¬£¬£¬MISTCLOAK¡¢DARKDEWºÍBLUEHAZE¡£¡£¡£¡£¡£¡£¡£³É¹¦ÈëÇÖºó»á×°ÖóÁ¶¨ÃûµÄNCAT¶þ½øÔìÎļþ²¢ÔÚÖ¸±êϵͳÉÏÖ´Ðз´Ïòshell£¬£¬£¬£¬£¬£¬´Ó¶øÎª¹¥»÷ÕßÌṩºóÃŽӼû¡£¡£¡£¡£¡£¡£¡£
https://www.mandiant.com/resources/blog/china-nexus-espionage-southeast-asia
4¡¢Ò˼ÒÔÚµ÷²éÕë¶ÔÆä¿ÆÍþÌØºÍĦÂå¸çÃŵêµÄÍøÂç¹¥»÷
¾Ý11ÔÂ29ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬Ò˼ÒÔÚµ÷²éÕë¶ÔÆä¿ÆÍþÌØºÍĦÂå¸çÃŵêµÄ¹¥»÷ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£ÖÜÒ»£¬£¬£¬£¬£¬£¬¿ÆÍþÌØºÍĦÂå¸çµÄÍøµã±»Ôö³¤µ½Vice SocietyÀÕË÷Èí¼þµÄÍøÕ¾£¬£¬£¬£¬£¬£¬ÍøÕ¾ÉϹ«¿ªµÄÎļþÃûÅú×¢¹¥»÷ÕßÒÑÇÔȡҵÎñºÍÔ±¹¤µÄÊý¾Ý£¬£¬£¬£¬£¬£¬²¢¿ÉÄÜ»¹´ÓÔ¼µ©µÄÒ˼ÒÃŵêÇÔÈ¡ÁËÆäËüÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¹«Ë¾½²»°È˰µÊ¾ËûÃÇÔÚÓëÓйص±¾ÖºÍÍøÂ簲ȫºÏ×÷ͬ°éһ·µ÷²é´ËÊÂÎñ¡£¡£¡£¡£¡£¡£¡£²î²»¶àÒ»Äêǰ£¬£¬£¬£¬£¬£¬Ò˼ÒÔøÃæ¶ÔÕë¶ÔÔ±¹¤ÄÚ²¿ÓÊÏäµÄ´¹µö¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£
https://therecord.media/ikea-investigating-cyberattacks-on-outlets-in-kuwait-morocco/
5¡¢ÐÂÀÕË÷Èí¼þPunisher¼Ù×°³ÉCOVID-19¸ú×ÙÀûÓ÷ַ¢
¾ÝýÌå11ÔÂ29ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÁËÒ»ÖÖÐÂÀÕË÷Èí¼þPunisher±äÌ壬£¬£¬£¬£¬£¬Í¨¹ýÍйÜÔÚcovid19[.]digitalhealthconsulting[.]clÉϵĻùÓÚCOVID-19Ö÷ÌâµÄ´¹µöÍøÕ¾½øÐд«²¼¡£¡£¡£¡£¡£¡£¡£Õâ¸öÍøÕ¾ÌṩαÔìµÄCOVID-19¸ú×ÙÀûÓ㬣¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÖÇÀû¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÒÔΪ£¬£¬£¬£¬£¬£¬Õâ´Î»î¶¯Õë¶ÔµÄÊÇÓ×ÎÒ¶ø·ÇÆóÒµ£¬£¬£¬£¬£¬£¬ËüÀÕË÷¼ÛÖµ1000ÃÀÔªµÄ±ÈÌØ±ÒÀ´½âÃÜÎļþ¡£¡£¡£¡£¡£¡£¡£±»ÕâÖÖÀÕË÷Èí¼þ¼ÓÃܵÄÎļþÒ²ºÜÈÝÒ×±»½âÃÜ£¬£¬£¬£¬£¬£¬ÓÉÓÚËüʹÓÃAES-128¶Ô³ÆËã·¨½øÐмÓÃÜ¡£¡£¡£¡£¡£¡£¡£
https://www.hackread.com/covid-19-app-punisher-ransomware/
6¡¢È«Ó¡¶Èҽѧ¿ÆÑ§×êÑÐËùAIIMS±»¹¥»÷ϵͳ崻ú6Ìì
ýÌå11ÔÂ29Èճƣ¬£¬£¬£¬£¬£¬Î»ÓÚµÂÀïµÄȫӡ¶Èҽѧ¿ÆÑ§×êÑÐËù(AIIMS) Ôâµ½¹¥»÷ºó£¬£¬£¬£¬£¬£¬ÆäϵͳÒÑÂ½Ðøå´»ú6Ìì¡£¡£¡£¡£¡£¡£¡£¾Ý³Æ£¬£¬£¬£¬£¬£¬ºÚ¿ÍÀÕË÷ԼĪ20ÒÚ¬±ÈµÄ¼ÓÃÜÇ®±Ò£¬£¬£¬£¬£¬£¬µ«µÂÀᆵ·½·ñ¶¨AIIMS»ã±¨ÊÕµ½¹ýÈκδËÀàÒªÇ󡣡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬¿ÉÄÜÒѾй¶ÁË3-4ǧÍò»¼ÕßµÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ·þÎñÆ÷´¦ÓÚÍ£»£»£»£»£»£»£»£»ú״̬£¬£¬£¬£¬£¬£¬¼¹Øï¡¢ÃÅÕסԺºÍ»¯ÑéÊҵϼÕß»¤Àí·þÎñ¾ùÓÉÈËΪÖÎÀí¡£¡£¡£¡£¡£¡£¡£µÂÀᆵ·½¡¢ÄÚÕþ²¿ºÍÓ¡¶ÈÍÆËã»úÓ¦¼±ÏìÓ¦Ó××é(CERT-IN)ÔÚµ÷²é´ËÀÕË÷¹¥»÷ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£
https://www.businesstoday.in/latest/in-focus/story/cyber-attack-at-aiims-delhi-hackers-demand-rs-200-cr-in-crypto-says-report-354475-2022-11-28


¾©¹«Íø°²±¸11010802024551ºÅ