Google´¹Î£½¨¸´ChromeÖб»ÀûÓõķì϶CVE-2022-4262

°ä²¼¹¦·ò 2022-12-05
1¡¢Google´¹Î£½¨¸´ChromeÖб»ÀûÓõķì϶CVE-2022-4262

12ÔÂ2ÈÕ£¬£¬£¬£¬£¬Google°ä²¼´¹Î£¸üУ¬£¬£¬£¬£¬½¨¸´ChromeÖÐÒѱ»ÀûÓõÄ0 day¡£¡£¡£¡£¡£¡£¡£¡£ÕâÊÇChrome V8 JavaScriptÒýÇæÖеÄÀàÐÍ»ìºÏ·ì϶(CVE-2022-4262)£¬£¬£¬£¬£¬´ËÀà·ì϶ͨ³£±»ÓÃÓÚͨ¹ý¶ÁÈ¡»òдÈ뻺³åÇøÌìǵ±íµÄÄÚ´æµ¼ÖÂä¯ÀÀÆ÷±ÀÀ££¬£¬£¬£¬£¬Ò²¿É±»ÓÃÓÚÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£¹ÌÈ»Google°µÊ¾ËüÒѼì²âµ½ÀûÓÃÕâ¸ö·ì϶µÄ¹¥»÷£¬£¬£¬£¬£¬µ«ÉÐδ·ÖÏíÓйØÕâЩÊÂÎñµÄ¼¼Êõϸ½Ú»òÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ÕâÊÇGoogle ChromeÔÚ½ñÄ꽨¸´µÄµÚ9¸ö0 day¡£¡£¡£¡£¡£¡£¡£¡£

https://chromereleases.googleblog.com/2022/12/stable-channel-update-for-desktop.html

2¡¢Kaspersky·¢ÏÖÖØÒªÕë¶Ô¶íÂÞ˹×éÖ¯µÄÐÂľÂíCryWiper

KasperskyÔÚ12ÔÂ1ÈÕ³ÆÆä·¢ÏÖÁËÒ»¸öÐµÄľÂíCryWiper¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÔÚ½ñÄêÇïÌì³õ´Î·¢ÏÖÁËCryWiper£¬£¬£¬£¬£¬Ëü±»ÓÃÓÚÕë¶Ô¶íÂÞ˹×éÖ¯µÄ¹¥»÷£¬£¬£¬£¬£¬¶íÂÞ˹ýÌåÔòй©Ëü±»ÓÃÓÚ¹¥»÷¶íÂÞ˹Êг¤°ì¹«ÊҺͷ¨Ôº¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ¼Ù×°³ÉÀÕË÷Èí¼þ£¬£¬£¬£¬£¬µ«¶Ô´úÂëµÄ·ÖÎöÅú×¢ËüÏÖʵÉϲ¢Î´¼ÓÃÜ£¬£¬£¬£¬£¬Ö»ÊÇ·ÛËéÁ˱»Ï°È¾ÏµÍ³ÖеÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£CryWiperÑù±¾ÓÃC++¿ª·¢µÄ64λWindows¿ÉÖ´ÐÐÎļþ£¬£¬£¬£¬£¬ÅäÖÃΪÀÄÓúܶàWinAPIº¯ÊýŲÓᣡ£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ»¹»áɾ³ý±»Ï°È¾ÍÆËã»úÉϵľíÓ°¸±±¾£¬£¬£¬£¬£¬ÒÔÔ¤·ÀÖ¸±ê¸´Ô­Îļþ¡£¡£¡£¡£¡£¡£¡£¡£

https://securelist.ru/novyj-troyanec-crywiper/106114/

3¡¢ÈýÐǵȹ©¸øÉÌʹÓÃµÄÆ½Ì¨Ö¤Êé±»ÀÄÓÃÀ´Ç©Êð¶ñÒâÀûÓÃ

¾ÝýÌå12ÔÂ1ÈÕ±¨Â·£¬£¬£¬£¬£¬AndroidOEMÉ豸¹©¸øÉÌÓÃÓÚ¶ÔÖ÷ÌâϵͳÀûÓýøÐÐÊý×ÖÊðÃûµÄ¶à¸öƽ̨֤Êé±»ÓÃÓÚ¶ÔÔ̺¬¶ñÒâÈí¼þµÄÀûÓýøÐÐÊðÃû¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖ¶à¸öʹÓÃÕâЩƽ̨֤ÊéÊðÃûµÄ¶ñÒâÈí¼þÑù±¾£¬£¬£¬£¬£¬²¢ÌṩÁËÿ¸öÑù±¾µÄSHA256¹þÏ£ÖµºÍÊý×ÖÊðÃûÖ¤Êé¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖв¿ÃÅÊôÓÚÈýÐÇ¡¢LG¡¢RevoviewºÍÁª·¢¿Æ£¬£¬£¬£¬£¬ÆäËüÖ¤ÊéÉÐÎÞ·¨È·¶¨ÊôÓÚË­¡£¡£¡£¡£¡£¡£¡£¡£Ê¹ÓÃÕâЩ֤ÊéÊðÃûµÄ¶ñÒâÈí¼þÔ̺¬HiddenAdľÂí¡¢ÐÅÏ¢ÇÔÈ¡·¨Ê½¡¢MetasploitºÍ¶ñÒâÈí¼þÖ²È뷨ʽ¡£¡£¡£¡£¡£¡£¡£¡£

https://www.bleepingcomputer.com/news/security/samsung-lg-mediatek-certificates-compromised-to-sign-android-malware/

4¡¢CISA³ÆÀÕË÷Èí¼þCubaÒѳɹ¦ÀÕË÷³¬¹ý6000ÍòÃÀÔª

CISAºÍFBIÔÚ12ÔÂ1ÈÕ½áºÏ°ä²¼Á˹ØÓÚÀÕË÷Èí¼þCubaµÄ¹«¸æ¡£¡£¡£¡£¡£¡£¡£¡£×Ô2021Äê12ÔÂÒÔÀ´£¬£¬£¬£¬£¬¸ÃÍÅ»ïÖØÒªÕë¶Ô½ðÈÚ·þÎñ¡¢µ±¾ÖÉèÊ©¡¢Ò½ÁƱ£½¡ºÍ¹«¹²ÎÀÉú¡¢Ôì×÷ºÍÐÅÏ¢¼¼ÊõÐÐÒµ¡£¡£¡£¡£¡£¡£¡£¡£½ØÖÁ2022Äê8Ô£¬£¬£¬£¬£¬FBIÈ·¶¨CubaÔÚÈ«ÇòÁìÓòÄÚÈëÇÖÁË100¶à¸ö×éÖ¯£¬£¬£¬£¬£¬ÀÕË÷³¬¹ý1.45ÒÚÃÀÔª²¢³É¹¦ÊÕµ½³¬¹ý6000ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£¡£CubaÍÅ»ïÀûÓöàÖÖ¼¼Êõ»ñµÃ³õʼ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬Ô̺¬ÀûÓÃóÒ×Èí¼þÖеÄÏÖÓзì϶¡¢´¹µö»î¶¯¡¢Ð¹Â¶µÄÍ´´¦ÒÔ¼°ºÏ·¨µÄRDP¹¤¾ß¡£¡£¡£¡£¡£¡£¡£¡£³É¹¦ºó£¬£¬£¬£¬£¬»áͨ¹ýHancitorÔÚÖ¸±êϵͳÉÏ×°ÖÃCubaÀÕË÷Èí¼þ¡£¡£¡£¡£¡£¡£¡£¡£

https://www.cisa.gov/uscert/ncas/alerts/aa22-335a

5¡¢ÃÀ¹ú·ðÂÞÀï´ïÖݵÄ˰ÎñÍøÕ¾Ð¹Â¶ÄÉ˰È˵ÄÐÅÏ¢

¾Ý12ÔÂ3ÈÕ±¨Â·£¬£¬£¬£¬£¬·ðÂÞÀï´ïÖݵÄ˰Îñ¾ÖÍøÕ¾´æÔÚÒ»¸ö°²È«·ì϶£¬£¬£¬£¬£¬Ð¹Â¶ÁËÖÁÉÙÊý°Ù¸öÄÉ˰È˵ÄÉç»á°²È«ºÅÂëºÍÒøÐÐÕʺ𣡣¡£¡£¡£¡£¡£¡£¸Ã·ì϶Ϊ²»°²È«µÄÖ±½Ó¶ÔÏóÒýÓã¨IDOR£©£¬£¬£¬£¬£¬ÓÉÓÚÉêÇë±àºÅÊÇÂ½ÐøµÄ£¬£¬£¬£¬£¬ÈκÎÈ˶¼Äܹ»Í¨¹ý½«ÉêÇë±àºÅµÝÔöһλÀ´ÁоÙÄÉ˰È˵ÄÐÅÏ¢£¬£¬£¬£¬£¬ÏµÍ³ÖÐÓг¬¹ý713000·ÝÉêÇë¡£¡£¡£¡£¡£¡£¡£¡£µÇ¼¸ÃÍøÕ¾µÄÈκÎÈË£¬£¬£¬£¬£¬¶¼Äܹ»Í¨¹ýÅú¸ÄÔ̺¬ÄÉ˰ÈËÉêÇëºÅÂëµÄÍøÖ·²¿ÃÅ£¬£¬£¬£¬£¬½Ó¼û¡¢Åú¸ÄºÍɾ³ý¸Ã˰Îñ»ú¹Ø´æµµµÄÆóÒµÖ÷µÄÓ×ÎÒ×ÊÁÏ¡£¡£¡£¡£¡£¡£¡£¡£

https://www.databreaches.net/florida-state-tax-website-bug-exposed-filers-data/

6¡¢Zimperium°ä²¼Schoolyard BullyľÂí¹¥»÷»î¶¯µÄ·ÖÎö

12ÔÂ1ÈÕ£¬£¬£¬£¬£¬Zimperium°ä²¼Á˹ØÓÚSchoolyard BullyľÂíµÄ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯×Ô2018ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬£¬£¬£¬£¬ÒÑϰȾ71¸ö¹ú¶È/µØÓòµÄÖÁÉÙ300000¸öÖ¸±ê£¬£¬£¬£¬£¬ÖØÒª¼¯ÖÐÔÚÔ½ÄÏ¡£¡£¡£¡£¡£¡£¡£¡£Schoolyard BullyÒò¼Ù×°³ÉÎÞº¦ÉõÖÁÓÐÒæµÄ½ÌÓýÀûÓöøµÃÃû£¬£¬£¬£¬£¬ÆäÖØÒªÖ¸±êÊÇÇÔÈ¡FacebookÕÊ»§Í´´¦¡£¡£¡£¡£¡£¡£¡£¡£¸ÃľÂíͨ¹ýʹÓÃWebViewÔÚÀûÓÃÖдò¿ªºÏ·¨µÄFacebookµÇÂ¼Ò³Ãæ£¬£¬£¬£¬£¬²¢×¢Èë¶ñÒâJavaScriptÀ´ÇÔÈ¡Óû§ÊäÈë¡£¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜÕâЩÀûÓÃÏÖÒÑ´ÓGoogle PlayÉ̵êÖÐɾ³ý£¬£¬£¬£¬£¬µ«ËüÃÇÒÀÈ»Äܹ»ÔÚµÚÈý·½ÀûÓ÷¨Ê½É̵êÖлñµÃ¡£¡£¡£¡£¡£¡£¡£¡£

https://www.zimperium.com/blog/schoolyard-bully-trojan-facebook-credential-stealer/