×êÑÐÈËÔ±Åû¶SQLiteÊý¾Ý¿âÖÐÒÑ´æÔÚ22ÄêµÄ°²È«·ì϶

°ä²¼¹¦·ò 2022-10-27
1¡¢×êÑÐÈËÔ±Åû¶SQLiteÊý¾Ý¿âÖÐÒÑ´æÔÚ22ÄêµÄ°²È«·ì϶

      

¾ÝýÌå10ÔÂ25ÈÕ±¨Â·£¬£¬£¬£¬£¬×êÑÐÈËÔ±Åû¶ÁËSQLiteÊý¾Ý¿â¿âÖÐÕûÊýÒç¶Âí½Å£¨CVE-2022-35737£©¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇ2000Äê10ÔµĴúÂë¸ü¸ÄʱÒýÈëµÄ£¬£¬£¬£¬£¬Õâ¸öÒÑ´æÔÚ22ÄêµÄ·ì϶ӰÏìÁËSQLite°æ±¾1.0.12µ½3.39.1¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÔÚC APIµÄ×Ö·û´®²ÎÊýÖÐʹÓÃÊýÊ®ÒÚ×Ö½Ú¿ÉÄܵ¼ÖÂÊý×éÌìǵÒç³ö£¬£¬£¬£¬£¬¹¥»÷Õ߳ɹ¦ÀûÓø÷ì϶¿ÉÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬ÔÚ±àдËüµÄʱ³½£¨2000ÄêµÄSQLiteÔ´´úÂëÖУ©£¬£¬£¬£¬£¬ÆäÊ±ÏµÍ³ÖØÒªÊÇ32λ¼Ü¹¹£¬£¬£¬£¬£¬Õâ¿ÉÄܲ¢²»ÊÇÒ»¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬·ì϶ÒÑÔÚ2022Äê7ÔÂ21ÈÕ°ä²¼µÄ°æ±¾3.39.2Öн¨¸´¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/137629/hacking/cve-2022-35737-sqlite-bug.html


2¡¢VMware½¨¸´Cloud Foundation²úÆ·ÖеÄRCE·ì϶

      

ÔÚ10ÔÂ25ÈÕ°ä²¼°²È«¸üУ¬£¬£¬£¬£¬½¨¸´Cloud FoundationÖеķì϶(CVE-2021-39144)¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶CVSSv3ÆÀ·Ö9.8£¬£¬£¬£¬£¬Î»ÓÚCloud FoundationʹÓõÄXStream¿ªÔ´¿âÖУ¬£¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»ÔÚ²»±ØÒªÓû§½»»¥µÄ¹¥»÷ÖÐÔ¶³ÌÀûÓÃËü¡£¡£¡£¡£¡£¡£¡£VMware»¹ÎªÎÞ·¨Á¢¼´×°Öò¹¶¡µÄÓû§ÌṩÁËÒ»¸öһʱ½â¾ö¹æ»®¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ·ì϶µÄÑϳÁÐÔ£¬£¬£¬£¬£¬VMwareҲΪÒÑÍ£²ú²úÆ·ÌṩÁ˲¹¶¡¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬Õâ´Î¸üл¹½¨¸´ÁËXML±í²¿ÊµÌå·ì϶(CVE-2022-31678)£¬£¬£¬£¬£¬¿Éµ¼Ö»ؾø·þÎñ»òÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2022/10/vmware-releases-patch-for-critical-rce.html


3¡¢ºÚ¿ÍʹÓÃPoS¶ñÒâÈí¼þÇÔÈ¡³¬¹ý16ÍòÕÅÐÅÓþ¿¨µÄÐÅÏ¢

      

ýÌå10ÔÂ25Èճƣ¬£¬£¬£¬£¬Group-IB·¢ÏÖÁËÁ½¸öPoS¶ñÒâÈí¼þ£¬£¬£¬£¬£¬ÓÃÓÚ´ÓPoSÖ§¸¶ÖÕ¶ËÇÔÈ¡167000¶àÕÅÐÅÓþ¿¨µÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬±»µÁµÄÊý¾Ýת´¢Äܹ»Í¨¹ýÔÚºÚ¿ÍÂÛ̳ÉÏÏúÊÛ¸øÔËÓªÍÅ»ï´øÀ´¸ß´ï334ÍòÃÀÔªµÄ¾»ÊÕÈë¡£¡£¡£¡£¡£¡£¡£Group-IBÈ·ÈÏÁËÓëÁ½¸öPoS¶ñÒâÈí¼þÓйصÄC2·þÎñÆ÷£¬£¬£¬£¬£¬³ÆÔÚ2022Äê2ÔÂÖÁ9ÔÂÆÚ¼ä£¬£¬£¬£¬£¬MajikPOSºÍTreasure Hunter±ðÀëÇÔÈ¡ÁË77428ºÍ900024ÌõÖ§¸¶¼Í¼¡£¡£¡£¡£¡£¡£¡£´ó²¿Ãű»µÁÐÅÓþ¿¨ÊÇÓÉÃÀ¹ú¡¢²¨¶àÀè¸÷¡¢ÃØÂ³¡¢°ÍÄÃÂí¡¢Ó¢¹ú¡¢¼ÓÄô󡢷¨¹ú¡¢²¨À¼¡¢Å²ÍþºÍ¸ç˹´ïÀè¼ÓµÄÒøÐп¯ÐеÄ¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬Éв»Ã÷ÏÔ¹¥»÷ÕßÉí·Ý£¬£¬£¬£¬£¬ÒÔ¼°Êý¾ÝÊÇ·ñÒѱ»ÏúÊÛ¡£¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2022/10/cybercriminals-used-two-pos-malware-to.html


4¡¢¹ú¼ÊƱÎñ¹«Ë¾See Tickets³ÆÆä¿Í»§µÄÖ§¸¶ÐÅϢй¶

      

¾Ý10ÔÂ25ÈÕ±¨Â·£¬£¬£¬£¬£¬Æ±Îñ·þÎñÌṩÉÌSee TicketsÅû¶ÁËһ·Êý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬Í¨Öª¿Í»§¹¥»÷Õß¿ÉÄÜÀûÓÃÆäÍøÕ¾ÉϵÄskimmer½Ó¼ûÁËËûÃǵÄÖ§¸¶¿¨¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£See TicketsÓÚ2021Äê4Ô·¢ÏÖÁËÕâһй¶ÊÂÎñ£¬£¬£¬£¬£¬Ö±µ½2022Äê1ÔÂ8ÈÕ£¬£¬£¬£¬£¬²ÅÔÚÆäÍøÕ¾ÉÏÆëȫɾ³ýÁ˶ñÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£½øÒ»´ëÊ©²éºó£¬£¬£¬£¬£¬See TicketsÓÚ2022Äê9ÔÂ12Èյóö½áÂÛ£¬£¬£¬£¬£¬Î´¾­ÊÚȨµÄ¸÷·½¿ÉÄÜÒѾ­ÇÔÈ¡Á˿ͻ§µÄÖ§¸¶¿¨ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Ï°È¾²úÉúÔÚ2019Äê6ÔÂ25ÈÕ£¬£¬£¬£¬£¬Òò¶øÊý¾Ýй¶ÊÂÎñµÄ³ÖÐø¹¦·ò³¤´ï2.5Äê¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/see-tickets-discloses-25-years-long-credit-card-theft-breach/ 


5¡¢Microsoft°ä²¼¹ØÓÚVice Society¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨

      

10ÔÂ25ÈÕ£¬£¬£¬£¬£¬Microsoft°ä²¼Á˹ØÓÚVice Society£¨DEV-0832£©Õë¶ÔÈ«Çò½ÌÓýÐÐÒµµÄ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïÔÚ´ÓǰһÄêÀûÓÃÁ˶àÖÖÉÌÆ·ÀÕË÷Èí¼þµÄ±äÌ壬£¬£¬£¬£¬Ô̺¬BlackCat¡¢QuantumLocker¡¢Zeppelin£¬£¬£¬£¬£¬ÒÔ¼°×î½üµÄZeppelinµÄVice Society±äÌå¡£¡£¡£¡£¡£¡£¡£×î½üÒ»´Î¹¥»÷²úÉúÔÚ2022Äê9ÔÂÏÂÑ®£¬£¬£¬£¬£¬DEV-0832ÔÙ´ÎʹÓÃÁË.lockedÎļþÀ©´óÃû²¢½«ÀÕË÷Èí¼þpayload¸ÄΪRedAlert±äÌå¡£¡£¡£¡£¡£¡£¡£ÔÚ½ñÄê7ÔµÄÒ»´Î¹¥»÷ÖУ¬£¬£¬£¬£¬¸ÃÍŻﳢÊÔ×°ÖÃQuantumLocker¶þ½øÔìÎļþ²¢ÔÚÎå¸öÓ×ʱÄÚ×°ÖÃZeppelin¶þ½øÔìÎļþ¡£¡£¡£¡£¡£¡£¡£ÕâÅú×¢¸ÃÍÅ»ï¿ÉÄÜÊØ»¤×Ŷà¸öÀÕË÷Èí¼þpayload²¢Æ¾¾ÝÖ¸±ê·ÀÓù½øÐÐÇл»¡£¡£¡£¡£¡£¡£¡£


https://www.microsoft.com/en-us/security/blog/2022/10/25/dev-0832-vice-society-opportunistic-ransomware-campaigns-impacting-us-education-sector/


6¡¢Surfshark°ä²¼2022ÄêQ3È«ÇòÊý¾Ýй¶ÊÂÎñµÄ»ã±¨

      

ýÌå10ÔÂ25ÈÕ±¨Â·£¬£¬£¬£¬£¬Surfshark°ä²¼Á˹ØÓÚ2022ÄêQ3È«ÇòÊý¾Ýй¶ÊÂÎñµÄ»ã±¨¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬2022ÄêµÚÈý¼¾¶È¹²ÓÐ1.089ÒÚ¸öÕË»§±»µÁ£¬£¬£¬£¬£¬±ÈÉÏÒ»¼¾¶ÈÓâÔ½70%£»£»£»£»£»£»Q3ÊÜÊý¾Ýй¶ӰÏì×î´óµÄ5¸ö¹ú¶ÈºÍµØÓòÊǶíÂÞ˹¡¢·¨¹ú¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢ÃÀ¹úºÍÎ÷°àÑÀ£»£»£»£»£»£»¹ÌÈ»¶íÂÞ˹µÄй¶×ÜÊý×î¶à£¨2230Íò£©£¬£¬£¬£¬£¬µ«·¨¹úµÄÊý¾Ýй¼ûܶÈ×î¸ß£¬£¬£¬£¬£¬¾ùÔÈÿ1000È˾ÍÓÐ212¸öй¶ÕË»§£»£»£»£»£»£»ÔÚ´ÓǰʮÄêÖУ¬£¬£¬£¬£¬ÃÀ¹úÒÀÈ»ÊDZ»¹¥»÷×î¶àµÄ¹ú¶È¡£¡£¡£¡£¡£¡£¡£


https://www.infosecurity-magazine.com/news/data-breaches-rise-by-70-q3-2022/