΢ÈíÐû²¼12Ô·ݵÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬×ܼÆÐÞ¸´49¸öÎó²î
Ðû²¼Ê±¼ä 2022-12-14
12ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬Î¢ÈíÐû²¼Öܶþ²¹¶¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬ÐÞ¸´Á˰üÀ¨Ò»¸öÒѱ»¼«Ê¹ÓõÄÎó²îÔÚÄÚµÄ49¸öÎó²î¡£¡£¡£¡£¡£¡£´Ë´Î¸üÐÂÐÞ¸´ÁËÁ½¸öÁãÈÕÎó²î£¬£¬£¬£¬£¬£¬»®·ÖΪWindows SmartScreenÇå¾²¹¦Ð§ÈƹýÎó²î£¨CVE-2022-44698£©£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÖÆ×÷Ò»¸ö¶ñÒâÎļþÀ´ÈƹýMOTW·ÀÓù£»£»£»£»£»ÒÔ¼°DirectXͼÐÎÄÚºËȨÏÞÌáÉýÎó²î£¨CVE-2022-44710£©£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²î¿É»ñµÃSYSTEMȨÏÞ¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬Îó²îCVE-2022-44698Òѱ»Æð¾¢Ê¹Óᣡ£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-december-2022-patch-tuesday-fixes-2-zero-days-49-flaws/
2¡¢UberÒòµÚÈý·½¹©Ó¦ÉÌÔâµ½¹¥»÷Ô´´úÂëºÍÔ±¹¤ÐÅÏ¢µÈй¶
¾ÝýÌå12ÔÂ12ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬ºÚ¿ÍUberLeaksÔÚÂÛ̳ÉÏÐû²¼ÁË´ÓUberºÍUber EatsÇÔÈ¡µÄÊý¾Ý¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨Ô´´úÂë¡¢IT×ʲúÖÎÀí±¨¸æ¡¢Êý¾ÝÏú»Ù±¨¸æ¡¢WindowsÓòµÇ¼ÃûÒÔ¼°Áè¼Ý77000¸öUberÔ±¹¤µÄÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±×î³õÒÔΪÕâЩÊý¾ÝÊÇÔÚ9Ô·ݵĹ¥»÷ÊÂÎñÖб»µÁµÄ£¬£¬£¬£¬£¬£¬µ«UberÌåÏÖÕâÓëµÚÈý·½¹©Ó¦É̵ÄÇå¾²Îó²îÓйء£¡£¡£¡£¡£¡£UberÌåÏÖ£¬£¬£¬£¬£¬£¬ÓÃÓÚ×ʲúÖÎÀíºÍ¸ú×ÙЧÀ͵ÄTeqtivityÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬¹¥»÷Õß»ñµÃÁËÆäΪ¿Í»§´æ´¢Êý¾ÝµÄTeqtivity AWS±¸·ÝЧÀÍÆ÷µÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/uber-suffers-new-data-breach-after-attack-on-vendor-info-leaked-online/
3¡¢ÀÕË÷ÍÅ»ïLockBit³ÆÒÑ´Ó¼ÓÖݲÆÎñ²¿ÇÔÈ¡76 GBµÄÊý¾Ý
¾Ý12ÔÂ12ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬LockBitÉù³ÆÒÑÈëÇÖ¼ÓÀû¸£ÄáÑÇÖݵIJÆÎñ²¿£¬£¬£¬£¬£¬£¬²¢ÇÔÈ¡ÁËÊý¾Ý¿â¡¢ÉñÃØÊý¾Ý¡¢²ÆÎñÎļþºÍITÏà¹ØµÄÎļþ¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹Ðû²¼ÁËĿ¼ºÍ´æ´¢ÎļþÊýÄ¿µÄ½ØÍ¼£¬£¬£¬£¬£¬£¬ÏÔʾÁè¼Ý114000¸öÎļþ¼ÐÖÐÓÐÁè¼Ý246000¸öÎļþ£¬£¬£¬£¬£¬£¬×ܼÆ75.3GBµÄÊý¾Ý¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬LockBitÒªÇóµÄÊê½ð½ð¶îÉв»ÇåÎú£¬£¬£¬£¬£¬£¬¿ÉÊÇÆäÍøÕ¾µÄµ¹¼ÆÊ±ÏÔʾҪÔÚ12ÔÂ24ÈÕ֮ǰ¸¶¡£¡£¡£¡£¡£¡£¼ÓÖÝÖݳ¤½ôÆÈЧÀͰ칫ÊÒÌåÏÖ£¬£¬£¬£¬£¬£¬¼ÓÖÝÍøÂçÇå¾²¼¯³ÉÖÐÐÄ£¨Cal-CSIC£©ÕýÔÚÆð¾¢Ó¦¶Ô´ËÊÂÎñ£¬£¬£¬£¬£¬£¬µ«Ã»ÓÐÌṩ̫¶àϸ½ÚÐÅÏ¢¡£¡£¡£¡£¡£¡£
https://www.cyberscoop.com/lockbit-ransomware-california-department-of-finance/
4¡¢Ó¡¶ÈÍâ½»²¿µÄÍøÕ¾Ð¹Â¶Íâ¼®ÈËÊ¿»¤ÕÕÏêϸÐÅÏ¢µÈÄÚÈÝ
ýÌå12ÔÂ12Èճƣ¬£¬£¬£¬£¬£¬Ó¡¶ÈÍâ½»²¿µÄGlobal Pravasi Rishta PortalÍøÕ¾Ð¹Â¶ÁËÍâ¼®ÈËÊ¿µÄ»¤ÕÕÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¡£ÕâÊÇÒ»¸öÖ¼ÔÚÅþÁ¬3000ÍòÓ¡¶ÈÇÈÃñµÄƽ̨£¬£¬£¬£¬£¬£¬ÒÔÃ÷ÎĵÄÐÎʽ¹ûÕæÁËÐÕÃû¡¢ÆÜÉí¹ú¼ÒÓʼþµØµã¡¢Ö°Òµ×´Ì¬¡¢µç»°ºÍ»¤ÕÕºÅÂëµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£Ð¹Â¶Ôµ¹ÊÔÓÉ¿ÉÄÜÊÇÇå¾²²½·¥È±·¦£¬£¬£¬£¬£¬£¬ÀýÈçȱ·¦Éí·ÝÑéÖ¤ÒªÁì¡£¡£¡£¡£¡£¡£CybernewsÒÑÁªÏµÍâ½»²¿¼û¸æÆäй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬²¢Ã»ÓÐÊÕµ½»Ø¸´£¬£¬£¬£¬£¬£¬µ«¸ÃÎÊÌâÔÚ¼¸Ììºó»ñµÃÏàʶ¾ö¡£¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/139561/data-breach/indian-foreign-ministrys-global-pravasi-rishta-portal-leaks-expat-passport-details.html
5¡¢Check PointÐû²¼¹ØÓÚÀÕË÷Èí¼þAzovµÄÉî¶ÈÆÊÎö±¨¸æ
Check Point ResearchÔÚ12ÔÂ12ÈÕÐû²¼Á˹ØÓÚÀÕË÷Èí¼þAzovµÄÉî¶ÈÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£AzovÊ×ÏÈ×÷Ϊ½©Ê¬ÍøÂçSmokeLoaderµÄpayloadÒýÆðÑо¿Ö°Ô±µÄ×¢ÖØ£¬£¬£¬£¬£¬£¬ËüÓëͨË×ÀÕË÷Èí¼þµÄÇø±ðÖ®Ò»ÊÇËüÐÞ¸ÄÁËijЩ64λ¿ÉÖ´ÐÐÎļþÀ´Ö´ÐÐ×Ô¼ºµÄ´úÂë¡£¡£¡£¡£¡£¡£ÕâÖÖ¶ÔÄ¿µÄµÄ¿ÉÖ´ÐÐÎļþµÄÇÖÂÔÐÔ¶à̬ѬȾµ¼Ö´ó×Ú¹ûÕæ¿ÉÓõÄÎļþ±»AzovѬȾ£¬£¬£¬£¬£¬£¬ÌìÌì¶¼ÓÐÊý°Ù¸öеÄAzovÏà¹ØÑù±¾±»Ìá½»µ½VirusTotal¡£¡£¡£¡£¡£¡£×èÖ¹2022Äê11Ô£¬£¬£¬£¬£¬£¬¸ÃÑù±¾ÒѾÁè¼Ý17000¸ö¡£¡£¡£¡£¡£¡£
https://research.checkpoint.com/2022/pulling-the-curtains-on-azov-ransomware-not-a-skidsware-but-polymorphic-wiper/
6¡¢Unit 42Ðû²¼½üÆÚеÄKerberos¹¥»÷·½·¨µÄÆÊÎö±¨¸æ
12ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬Unit 42Ðû²¼Á˽üÆÚеÄKerberos¹¥»÷·½·¨µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£Active DirectoryµÄÆÕ±éʹÓÃʹKerberos¹¥»÷³ÉΪÐí¶à¹¥»÷ÕßµÄÖ÷ÒªÊֶΣ¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÁËÐµĹ¥»÷ÊÖÒÕ£¬£¬£¬£¬£¬£¬Diamond TicketºÍSapphire Ticket£¬£¬£¬£¬£¬£¬Ê¹¹¥»÷ÕßÄܹ»²»ÊÜÏÞÖÆµØ»á¼ûADÓòÖеÄËùÓÐЧÀͺÍ×ÊÔ´¡£¡£¡£¡£¡£¡£Sapphire Ticket¹¥»÷ÐèÒª»ñÈ¡ÓòÖÐÓû§µÄƾ֤£¬£¬£¬£¬£¬£¬È»ºóʹÓÃÆ¾Ö¤»ñÈ¡TGT£¬£¬£¬£¬£¬£¬²¢½«ÆäÓÃÓÚ½âÃܸßȨÏÞÓû§µÄPAC¡£¡£¡£¡£¡£¡£Diamond Ticket¹¥»÷Ê×ÏÈÊÇ»ñÈ¡TGT£¬£¬£¬£¬£¬£¬È»ºóʹÓÃKRBTGTÕÊ»§µÄÃÜÔ¿½âÃÜTGT²¢ÐÞ¸ÄTicket£¬£¬£¬£¬£¬£¬ÌáÉýȨÏÞ¡£¡£¡£¡£¡£¡£
https://unit42.paloaltonetworks.com/next-gen-kerberos-attacks/