Google½ôÆÈÐÞ¸´ChromeÖб»Ê¹ÓõÄÎó²îCVE-2022-4262
Ðû²¼Ê±¼ä 2022-12-0512ÔÂ2ÈÕ£¬£¬£¬£¬£¬GoogleÐû²¼½ôÆÈ¸üУ¬£¬£¬£¬£¬ÐÞ¸´ChromeÖÐÒѱ»Ê¹ÓõÄ0 day¡£¡£¡£¡£¡£¡£ÕâÊÇChrome V8 JavaScriptÒýÇæÖеÄÀàÐÍ»ìÏýÎó²î(CVE-2022-4262)£¬£¬£¬£¬£¬´ËÀàÎó²îͨ³£±»ÓÃÓÚͨ¹ý¶ÁÈ¡»òдÈ뻺³åÇø½çÏßÍâµÄÄÚ´æµ¼ÖÂä¯ÀÀÆ÷Í߽⣬£¬£¬£¬£¬Ò²¿É±»ÓÃÓÚÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£ËäÈ»GoogleÌåÏÖËüÒѼì²âµ½Ê¹ÓÃÕâ¸öÎó²îµÄ¹¥»÷£¬£¬£¬£¬£¬µ«ÉÐδ·ÖÏíÓйØÕâЩÊÂÎñµÄÊÖÒÕϸ½Ú»òÐÅÏ¢¡£¡£¡£¡£¡£¡£ÕâÊÇGoogle ChromeÔÚ½ñÄêÐÞ¸´µÄµÚ9¸ö0 day¡£¡£¡£¡£¡£¡£
https://chromereleases.googleblog.com/2022/12/stable-channel-update-for-desktop.html
2¡¢Kaspersky·¢Ã÷Ö÷ÒªÕë¶Ô¶íÂÞ˹×éÖ¯µÄÐÂľÂíCryWiper
KasperskyÔÚ12ÔÂ1ÈÕ³ÆÆä·¢Ã÷ÁËÒ»¸öÐµÄľÂíCryWiper¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚ½ñÄêÇïÌìÊ״η¢Ã÷ÁËCryWiper£¬£¬£¬£¬£¬Ëü±»ÓÃÓÚÕë¶Ô¶íÂÞ˹×éÖ¯µÄ¹¥»÷£¬£¬£¬£¬£¬¶íÂÞ˹ýÌåÔò͸¶Ëü±»ÓÃÓÚ¹¥»÷¶íÂÞ˹Êг¤°ì¹«ÊҺͷ¨Ôº¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þαװ³ÉÀÕË÷Èí¼þ£¬£¬£¬£¬£¬µ«¶Ô´úÂëµÄÆÊÎöÅú×¢ËüÏÖʵÉϲ¢Î´¼ÓÃÜ£¬£¬£¬£¬£¬Ö»ÊÇÆÆËðÁ˱»Ñ¬È¾ÏµÍ³ÖеÄÊý¾Ý¡£¡£¡£¡£¡£¡£CryWiperÑù±¾ÓÃC++¿ª·¢µÄ64λWindows¿ÉÖ´ÐÐÎļþ£¬£¬£¬£¬£¬ÉèÖÃΪÀÄÓÃÐí¶àWinAPIº¯ÊýŲÓᣡ£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ»¹»áɾ³ý±»Ñ¬È¾ÅÌËã»úÉϵľíÓ°¸±±¾£¬£¬£¬£¬£¬ÒÔ±ÜÃâÄ¿µÄ»Ö¸´Îļþ¡£¡£¡£¡£¡£¡£
https://securelist.ru/novyj-troyanec-crywiper/106114/
3¡¢ÈýÐǵȹ©Ó¦ÉÌʹÓÃµÄÆ½Ì¨Ö¤Êé±»ÀÄÓÃÀ´Ç©Êð¶ñÒâÓ¦ÓÃ
¾ÝýÌå12ÔÂ1ÈÕ±¨µÀ£¬£¬£¬£¬£¬AndroidOEM×°±¸¹©Ó¦ÉÌÓÃÓÚ¶Ô½¹µãϵͳӦÓþÙÐÐÊý×ÖÊðÃûµÄ¶à¸öƽ̨֤Êé±»ÓÃÓÚ¶Ô°üÀ¨¶ñÒâÈí¼þµÄÓ¦ÓþÙÐÐÊðÃû¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷¶à¸öʹÓÃÕâЩƽ̨֤ÊéÊðÃûµÄ¶ñÒâÈí¼þÑù±¾£¬£¬£¬£¬£¬²¢ÌṩÁËÿ¸öÑù±¾µÄSHA256¹þÏ£ÖµºÍÊý×ÖÊðÃûÖ¤Êé¡£¡£¡£¡£¡£¡£ÆäÖв¿·ÖÊôÓÚÈýÐÇ¡¢LG¡¢RevoviewºÍÁª·¢¿Æ£¬£¬£¬£¬£¬ÆäËüÖ¤ÊéÉÐÎÞ·¨È·¶¨ÊôÓÚË¡£¡£¡£¡£¡£¡£Ê¹ÓÃÕâЩ֤ÊéÊðÃûµÄ¶ñÒâÈí¼þ°üÀ¨HiddenAdľÂí¡¢ÐÅÏ¢ÇÔÈ¡³ÌÐò¡¢MetasploitºÍ¶ñÒâÈí¼þÖ²Èë³ÌÐò¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/samsung-lg-mediatek-certificates-compromised-to-sign-android-malware/
4¡¢CISA³ÆÀÕË÷Èí¼þCubaÒÑÀÖ³ÉÀÕË÷Áè¼Ý6000ÍòÃÀÔª
CISAºÍFBIÔÚ12ÔÂ1ÈÕÁªºÏÐû²¼Á˹ØÓÚÀÕË÷Èí¼þCubaµÄͨ¸æ¡£¡£¡£¡£¡£¡£×Ô2021Äê12ÔÂÒÔÀ´£¬£¬£¬£¬£¬¸ÃÍÅ»ïÖ÷ÒªÕë¶Ô½ðÈÚЧÀÍ¡¢Õþ¸®ÉèÊ©¡¢Ò½ÁƱ£½¡ºÍ¹«¹²ÎÀÉú¡¢ÖÆÔìºÍÐÅÏ¢ÊÖÒÕÐÐÒµ¡£¡£¡£¡£¡£¡£×èÖ¹2022Äê8Ô£¬£¬£¬£¬£¬FBIÈ·¶¨CubaÔÚÈ«Çò¹æÄ£ÄÚÈëÇÖÁË100¶à¸ö×éÖ¯£¬£¬£¬£¬£¬ÀÕË÷Áè¼Ý1.45ÒÚÃÀÔª²¢ÀÖ³ÉÊÕµ½Áè¼Ý6000ÍòÃÀÔª¡£¡£¡£¡£¡£¡£CubaÍÅ»ïʹÓöàÖÖÊÖÒÕ»ñµÃ³õʼ»á¼ûȨÏÞ£¬£¬£¬£¬£¬°üÀ¨Ê¹ÓÃÉÌÒµÈí¼þÖеÄÏÖÓÐÎó²î¡¢´¹Âڻ¡¢Ð¹Â¶µÄƾ֤ÒÔ¼°Õýµ±µÄRDP¹¤¾ß¡£¡£¡£¡£¡£¡£Àֳɺ󣬣¬£¬£¬£¬»áͨ¹ýHancitorÔÚÄ¿µÄϵͳÉÏ×°ÖÃCubaÀÕË÷Èí¼þ¡£¡£¡£¡£¡£¡£
https://www.cisa.gov/uscert/ncas/alerts/aa22-335a
5¡¢ÃÀ¹ú·ðÂÞÀï´ïÖݵÄ˰ÎñÍøÕ¾Ð¹Â¶ÄÉ˰È˵ÄÐÅÏ¢
¾Ý12ÔÂ3ÈÕ±¨µÀ£¬£¬£¬£¬£¬·ðÂÞÀï´ïÖݵÄ˰Îñ¾ÖÍøÕ¾±£´æÒ»¸öÇå¾²Îó²î£¬£¬£¬£¬£¬Ð¹Â¶ÁËÖÁÉÙÊý°Ù¸öÄÉ˰È˵ÄÉç»áÇå¾²ºÅÂëºÍÒøÐÐÕʺ𣡣¡£¡£¡£¡£¸ÃÎó²îΪ²»Çå¾²µÄÖ±½Ó¹¤¾ßÒýÓã¨IDOR£©£¬£¬£¬£¬£¬ÓÉÓÚÉêÇë±àºÅÊÇÒ»Á¬µÄ£¬£¬£¬£¬£¬ÈκÎÈ˶¼¿ÉÒÔͨ¹ý½«ÉêÇë±àºÅµÝÔöһλÀ´Ã¶¾ÙÄÉ˰È˵ÄÐÅÏ¢£¬£¬£¬£¬£¬ÏµÍ³ÖÐÓÐÁè¼Ý713000·ÝÉêÇë¡£¡£¡£¡£¡£¡£µÇ¼¸ÃÍøÕ¾µÄÈκÎÈË£¬£¬£¬£¬£¬¶¼¿ÉÒÔͨ¹ýÐ޸İüÀ¨ÄÉ˰ÈËÉêÇëºÅÂëµÄÍøÖ·²¿·Ö£¬£¬£¬£¬£¬»á¼û¡¢Ð޸ĺÍɾ³ý¸Ã˰Îñ»ú¹Ø´æµµµÄÆóÒµÖ÷µÄСÎÒ˽¼Ò×ÊÁÏ¡£¡£¡£¡£¡£¡£
https://www.databreaches.net/florida-state-tax-website-bug-exposed-filers-data/
6¡¢ZimperiumÐû²¼Schoolyard BullyľÂí¹¥»÷»î¶¯µÄÆÊÎö
12ÔÂ1ÈÕ£¬£¬£¬£¬£¬ZimperiumÐû²¼Á˹ØÓÚSchoolyard BullyľÂíµÄ¹¥»÷»î¶¯µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¸Ã»î¶¯×Ô2018ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬£¬£¬ÒÑѬȾ71¸ö¹ú¼Ò/µØÇøµÄÖÁÉÙ300000¸öÄ¿µÄ£¬£¬£¬£¬£¬Ö÷Òª¼¯ÖÐÔÚÔ½ÄÏ¡£¡£¡£¡£¡£¡£Schoolyard BullyÒòαװ³ÉÎÞº¦ÉõÖÁÓÐÒæµÄ½ÌÓýÓ¦ÓöøµÃÃû£¬£¬£¬£¬£¬ÆäÖ÷ҪĿµÄÊÇÇÔÈ¡FacebookÕÊ»§Æ¾Ö¤¡£¡£¡£¡£¡£¡£¸ÃľÂíͨ¹ýʹÓÃWebViewÔÚÓ¦ÓÃÖз¿ªÕýµ±µÄFacebookµÇÂ¼Ò³Ãæ£¬£¬£¬£¬£¬²¢×¢Èë¶ñÒâJavaScriptÀ´ÇÔÈ¡Óû§ÊäÈë¡£¡£¡£¡£¡£¡£Ö»¹ÜÕâЩӦÓÃÏÖÒÑ´ÓGoogle PlayÊÐËÁÖÐɾ³ý£¬£¬£¬£¬£¬µ«ËüÃÇÈÔÈ»¿ÉÒÔÔÚµÚÈý·½Ó¦ÓóÌÐòÊÐËÁÖлñµÃ¡£¡£¡£¡£¡£¡£
https://www.zimperium.com/blog/schoolyard-bully-trojan-facebook-credential-stealer/


¾©¹«Íø°²±¸11010802024551ºÅ