ISCÐû²¼¸üУ¬£¬ £¬ÐÞ¸´BIND DNSÈí¼þÖеĶà¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2022-09-27
1¡¢ISCÐû²¼¸üУ¬£¬ £¬ÐÞ¸´BIND DNSÈí¼þÖеĶà¸öÇå¾²Îó²î

      

9ÔÂ21ÈÕ£¬£¬ £¬Internet Systems Consortium(ISC)Ðû²¼Çå¾²¸üУ¬£¬ £¬ÐÞ¸´BIND DNSÈí¼þÖеĶà¸ö¿ÉÔ¶³ÌʹÓõÄÎó²î¡£¡£¡£ ¡£¡£¡£ÆäÖнÏΪÑÏÖØµÄÊÇͨ¹ýTKEY RR´¦Öóͷ£Diffie-HellmanÃÜÔ¿½»Á÷µÄ´úÂëÖеÄÄÚ´æÐ¹Â¶Îó²î£¨CVE-2022-2906£©¡¢ECDSA DNSSECÑéÖ¤ÂëÖеÄÄÚ´æÐ¹Â¶Îó²î£¨CVE-2022-38177£©¡¢¿Éµ¼ÖÂBIND 9ÆÊÎöÆ÷Íß½âµÄÎó²î£¨CVE-2022-3080£©ºÍEdDSA DNSSECÑéÖ¤ÂëÖеÄй¶Îó²î£¨CVE-2022-38178£©¡£¡£¡£ ¡£¡£¡£ISCÌåÏÖ£¬£¬ £¬ÉÐδ·¢Ã÷ÉÏÊöÎó²îÔÚÒ°ÍⱻʹÓõĻ¡£¡£¡£ ¡£¡£¡£


https://securityaffairs.co/wordpress/136164/security/bind-dns-software-flaws-2.html


2¡¢Google PlayºÍApp StoreÖжà¸ö¹ã¸æÓ¦Óñ»×°ÖÃ1300Íò´Î

      

¾ÝýÌå9ÔÂ26ÈÕ±¨µÀ£¬£¬ £¬Ñо¿Ö°Ô±ÔÚGoogle PlayÉÏ·¢Ã÷ÁË75¸ö¹ã¸æÓ¦Ó㬣¬ £¬ÔÚApp StoreÉÏ·¢Ã÷ÁËÁíÍâ10¸ö¹ã¸æÓ¦Ó㬣¬ £¬×ܹ²±»×°ÖÃÁË1300Íò´Î¡£¡£¡£ ¡£¡£¡£³ýÁËÏòÊÖ»úÓû§Í¶·Å¿É¼ûºÍÒþ²ØµÄ¹ã¸æÍ⣬£¬ £¬ÕâЩڲƭӦÓû¹Í¨¹ýð³äÕýµ±µÄÓ¦ÓÃÀ´´´ÊÕ¡£¡£¡£ ¡£¡£¡£ËäÈ»ÕâÖÖÀàÐ͵ÄÓ¦Óò»±£´æÑÏÖØµÄÍþв£¬£¬ £¬µ«¹¥»÷Õß¿ÉÒÔʹÓÃËüÃǾÙÐиüΣÏյĻ¡£¡£¡£ ¡£¡£¡£Ñо¿ÍŶÓÒѽ«ÕâЩ·¢Ã÷֪ͨGoogleºÍApple£¬£¬ £¬ÏÖÔÚÕâЩӦÓÃÒÑ´Ó¹Ù·½AndroidºÍiOSÊÐËÁÖÐɾ³ý¡£¡£¡£ ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/adware-on-google-play-and-apple-store-installed-13-million-times/


3¡¢Ó¡¶ÈijҽÁÆÈí¼þ¹«Ë¾Ð¹Â¶170ÍòÈËCovid¿¹Ô­²âÊÔЧ¹û

      

ýÌå9ÔÂ25Èճƣ¬£¬ £¬Ó¡¶ÈijҽÁÆÈí¼þÌṩÉ̵ÄElasticsearchЧÀÍÆ÷й¶ÁË170ÍòÈ˵ÄCovid¿¹Ô­²âÊÔЧ¹û¡£¡£¡£ ¡£¡£¡£AnuragÔÚShodanÉÏɨÃèÉèÖùýʧµÄÊý¾Ý¿âʱ£¬£¬ £¬×¢Öص½Ò»Ì¨Ð§ÀÍÆ÷̻¶ÁËÁè¼Ý23GBµÄÊý¾Ý¡£¡£¡£ ¡£¡£¡£ÆäÖаüÀ¨ÒÑÍù¼¸ÄêÍùÀ´ÓÚÓ¡¶ÈµÄÓ¡¶ÈÈ˺ÍÍâ¹úÓο͵ÄÐÅÏ¢£¬£¬ £¬ÈçÐÕÃû¡¢¹ú¼®¡¢µØµã¡¢µç»°ºÅÂë¡¢Éí·ÝÖ¤ºÅÂë¡¢¼ì²âЧ¹û¡¢AadhaarºÅºÍ»¤ÕÕºÅÂëµÈ¡£¡£¡£ ¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ£¬£¬ £¬¸ÃÊý¾Ý¿â×Ô2022Äê7ÔÂ2ÈÕ×îÏÈ̻¶£¬£¬ £¬ÇÒÏÖÔÚÈÔ´¦ÓÚ¹ûÕæ×´Ì¬¡£¡£¡£ ¡£¡£¡£


https://www.hackread.com/covid-antigen-test-results-india-leaked/


4¡¢ÎÚ¿ËÀ¼SSUµ·»ÙÔøÇÔÈ¡²¢³öÊÛ3000Íò¸öÕË»§µÄºÚ¿ÍÍÅ»ï

      

ýÌå9ÔÂ24ÈÕ±¨µÀ³Æ£¬£¬ £¬ÎÚ¿ËÀ¼Çå¾²¾Ö(SSU)µÄÍøÂ粿·Öµ·»ÙÁËÒ»¸öÔøÇÔÈ¡²¢³öÊÛ3000Íò¸öÕË»§µÄºÚ¿ÍÍŻ¡£¡£ ¡£¡£¡£¾ÝSSU³Æ£¬£¬ £¬ËûÃÇÒÔºó´ÎÐж¯ÖÐ׬Ǯ1400ÍòUAH£¨380000ÃÀÔª£©¡£¡£¡£ ¡£¡£¡£¹¥»÷Õß×Óͨ¹ý¶ñÒâÈí¼þѬȾÀ´»ñȡƾ֤ºÍÊý¾Ý£¬£¬ £¬Ö÷ÒªÕë¶ÔÎÚ¿ËÀ¼ºÍÅ·ÃË×éÖ¯µÄϵͳ¡£¡£¡£ ¡£¡£¡£ËûÃÇ»¹Í¨¹ýÔÚÎÚ¿ËÀ¼±»Õ¥È¡µÄµç×ÓÖ§¸¶ÏµÍ³YuMoney¡¢QiwiºÍWebMoneyÊÕ¿î¡£¡£¡£ ¡£¡£¡£±»²¶µÄÈËÊýÈÔδÅû¶£¬£¬ £¬µ«ËûÃǶ¼Òòδ¾­ÊÚȨ³öÊÛ»ò·Ö·¢ÔÚ´æ´¢ÓÚÅÌËã»úºÍÍøÂçÖеĻá¼ûÊÜÏÞµÄÐÅÏ¢¶øÃæÁÙÐÌÊÂËßËϼ°¶àÄêî¿Ïµ¡£¡£¡£ ¡£¡£¡£


https://securityaffairs.co/wordpress/136156/cyber-crime/ukraine-cyber-gang.html


5¡¢Î¢ÈíÐû²¼Ê¹ÓÃOAuthÓ¦Óù¥»÷ExchangeЧÀÍÆ÷µÄÆÊÎö±¨¸æ

      

9ÔÂ22ÈÕ£¬£¬ £¬Î¢ÈíÐû²¼±¨¸æ³ÆÆä½üÆÚÊÓ²ìÁËÒ»ÖÖ¹¥»÷£¬£¬ £¬ÆäÖй¥»÷ÕßÔÚ±»Ñ¬È¾µÄÔÆ×â»§ÖÐ×°ÖöñÒâOAuthÓ¦ÓóÌÐò£¬£¬ £¬ÓÃÓÚ¿ØÖÆExchange OnlineÉèÖúÍÈö²¥À¬»øÓʼþ¡£¡£¡£ ¡£¡£¡£¹¥»÷ÕßÊ×ÏȶÔδÆôÓÃMFAµÄÏÕÕË»§Ö´ÐÐײ¿â¹¥»÷£¬£¬ £¬²¢Ê¹Óò»Çå¾²µÄÖÎÀíÔ±ÕË»§»ñµÃ³õʼ»á¼ûȨÏÞ¡£¡£¡£ ¡£¡£¡£È»ºó£¬£¬ £¬¹¥»÷Õ߿ɽ¨Éè¶ñÒâOAuthÓ¦ÓóÌÐò£¬£¬ £¬¸Ã³ÌÐò»áÔÚµç×ÓÓʼþЧÀÍÆ÷ÖÐÌí¼Ó¶ñÒâÈëÕ¾ÅþÁ¬Æ÷¡£¡£¡£ ¡£¡£¡£×îºó£¬£¬ £¬Ê¹ÓöñÒâÈëÕ¾ÅþÁ¬Æ÷·¢ËÍ¿´ÆðÀ´ÏñÊÇÀ´×ÔÄ¿µÄÓòµÄÀ¬»øÓʼþ¡£¡£¡£ ¡£¡£¡£


https://www.microsoft.com/security/blog/2022/09/22/malicious-oauth-applications-used-to-compromise-email-servers-and-spread-spam/


6¡¢NSAºÍCISAÐû²¼±£»£»£» £»£»£»£»¤OTºÍICSµÄÒªº¦»ù´¡ÉèÊ©µÄÇå¾²×Éѯ

      

9ÔÂ22ÈÕ£¬£¬ £¬CISAºÍNSAÁªºÏÐû²¼Á˹ØÓÚ±£»£»£» £»£»£»£»¤ÔËÓªÊÖÒÕ(OT)ºÍ¹¤Òµ¿ØÖÆÏµÍ³(ICS)µÄÒªº¦»ù´¡ÉèÊ©µÄÁªºÏÇå¾²×Éѯ¡£¡£¡£ ¡£¡£¡£¸Ãͨ¸æ·ÖÏíÁ˹¥»÷ÕßÓÃÀ´ÆÆËðÖ§³ÖITµÄOTºÍICS×ʲúµÄËùÓа취ÐÅÏ¢£¬£¬ £¬²¢Ç¿µ÷ÁËÇ徲רҵְԱ¿ÉÒÔ½ÓÄɵķÀÓù²½·¥¡£¡£¡£ ¡£¡£¡£»£»£» £»£»£»£»¹Ö¸³ö£¬£¬ £¬ÔËÓª¡¢¿ØÖÆºÍ¼à¿ØÒ»Ñùƽ³£Òªº¦»ù´¡ÉèÊ©ºÍ¹¤ÒµÁ÷³ÌµÄOTºÍICS×ʲúÃæÁÙµÄÍþвÈÕÒæÔöÌí£¬£¬ £¬²¢ÌṩÁËһЩÓÃÀ´Ó¦¶ÔµÐÊÖµÄÕ½ÂÔ¡¢ÊÖÒպͳÌÐò(TTP)µÄ×î¼ÑÇ徲ʵ¼ù¡£¡£¡£ ¡£¡£¡£


https://us-cert.cisa.gov/ncas/current-activity/2022/09/22/cisa-and-nsa-publish-joint-cybersecurity-advisory-control-system