Apple½¨¸´iPhoneºÍMacÖпÉÄÜÒѱ»»ý¼«ÀûÓõķì϶
°ä²¼¹¦·ò 2022-09-13
ýÌå9ÔÂ12Èճƣ¬£¬£¬£¬£¬£¬£¬£¬Apple°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´ÁËÓÃÓÚ¹¥»÷iPhoneºÍMacµÄ·ì϶¡£¡£¡£¡£¡£¡£¸Ã·ì϶׷×ÙΪCVE-2022-32917£¬£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ý¶ñÒâÔì×÷µÄÀûÓ÷¨Ê½ÒÔÄÚºËȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£ÕâÊǸù«Ë¾×ÔËêÊ×ÒÔÀ´½¨¸´µÄµÚ8¸öÁãÈÕ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬AppleÔÚ°²È«¹«¸æÖÐй©¸Ã·ì϶¿ÉÄÜÒѱ»»ý¼«ÀûÓ㬣¬£¬£¬£¬£¬£¬£¬µ«ÉÐδ°ä²¼ÓйØÕâЩ¹¥»÷µÄÈκÎÐÅÏ¢¡£¡£¡£¡£¡£¡£×êÑÐÈËԱǿÁÒ½¨ÒéÓû§¾¡¿ì½øÐа²È«¸üÐÂÒÔ×èÖ¹´ËÀ๥»÷¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/apple-fixes-eighth-zero-day-used-to-hack-iphones-and-macs-this-year/
2¡¢BRONZE PRESIDENTÍÅ»ïÀûÓÃPlugX¹¥»÷È«ÇòÈ·µ±¾Ö»ú¹¹
SecureworksÔÚ9ÔÂ8ÈÕÅû¶ÁËAPT×éÖ¯BRONZE PRESIDENTÕë¶ÔÅ·ÖÞ¡¢Öж«ºÍÄÏÃÀµÈµØµ±¾Ö»ú¹¹µÄPlugX¶ñÒâÈí¼þ»î¶¯¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÔÚ2022Äê6ÔºÍ7Ô·¢Ïָû£¬£¬£¬£¬£¬£¬£¬£¬Ï°È¾Á´Ê¼ÓÚÒ»¸öÔ̺¬¶ñÒâÈí¼þµÄRAR´æµµ£¬£¬£¬£¬£¬£¬£¬£¬´ò¿ª´æµµºó»áÏÔʾһ¸ö¼Ù×°³ÉÎĵµµÄLNKÎļþ£¬£¬£¬£¬£¬£¬£¬£¬µã»÷¸ÃÎļþºó½«Ö´ÐжñÒâÈí¼þ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹·Ö·¢Á˶ñÒâDLLºÍ¼ÓÃܵÄpayload£¬£¬£¬£¬£¬£¬£¬£¬ºÏ·¨µÄ¶þ½øÔìÎļþÈÝÒ×Ôâµ½DLLËÑË÷°¤´Î½Ù³Ö¹¥»÷¡£¡£¡£¡£¡£¡£
https://www.secureworks.com/blog/bronze-president-targets-government-officials
3¡¢Cofense·¢ÏÖͨ¹ýWeTransfer·þÎñ·Ö·¢LampionµÄ»î¶¯
¾Ý9ÔÂ9ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬Cofense¼ì²âµ½ÐÂÒ»Âֻ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀÄÓÃWeTransfer·þÎñ´ó¹æÄ£·Ö·¢¶ñÒâÈí¼þLampion¡£¡£¡£¡£¡£¡£WeTransferÊÇÒ»ÖֺϷ¨Îļþ¹²Ïí·þÎñ£¬£¬£¬£¬£¬£¬£¬£¬±»ÓÃÀ´Èƹý°²È«Èí¼þ¶Ôµç×ÓÓʼþÖÐʹÓõÄURLµÄ¾¯±¨¡£¡£¡£¡£¡£¡£LampionÔËÓªÍÅ»ï´Ó±»Ï°È¾µÄ¹«Ë¾ÕÊ»§·¢ËÍ´¹µöÓʼþ£¬£¬£¬£¬£¬£¬£¬£¬ÒªÇóÓû§´ÓWeTransferÏÂÔØ¡°¸¶¿îÖ¤Ã÷¡±Îļþ¡£¡£¡£¡£¡£¡£Ö¸±ê»áÊÕµ½Ò»¸öZIP´æµµ£¬£¬£¬£¬£¬£¬£¬£¬²¢×îÖÕÖ´ÐÐLampion¡£¡£¡£¡£¡£¡£Lampionͨ¹ý´ÓC2ÖлñȡעÈëµÄÊý¾Ý²¢ÔÚµÇÂ¼Ò³ÃæÉϸ²¸ÇαÔìµÄ±íµ¥À´Ëø¶¨ÒøÐÐÕË»§¡£¡£¡£¡£¡£¡£µ±Óû§ÊäÈëÆ¾Ö¤Ê±£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩÊý¾Ý½«±»ÇÔÈ¡²¢·¢Ë͸ø¹¥»÷Õß¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/lampion-malware-returns-in-phishing-attacks-abusing-wetransfer/
4¡¢WordfenceÅû¶WP²å¼þBackupBuddyÖÐÒѱ»ÀûÓ÷ì϶µÄϸ½Ú
WordfenceÓÚ9ÔÂ7ÈÕй©£¬£¬£¬£¬£¬£¬£¬£¬WordPress²å¼þBackupBuddyÖеķì϶ÔÚ±»»ý¼«ÀûÓᣡ£¡£¡£¡£¡£¸Ã·ì϶£¨CVE-2022-31474£©Ô¼ÓÐ140000´Î×°Ö㬣¬£¬£¬£¬£¬£¬£¬¿É±»Î´¾Éí·ÝÑéÖ¤µÄÓû§ÓÃÀ´´ÓÖ¸±êÍøÕ¾ÏÂÔØËÁÒâÎļþ£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬/etc/passwdµÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£·ì϶ӰÏì°æ±¾8.5.8.0ÖÁ8.7.4.1£¬£¬£¬£¬£¬£¬£¬£¬ÒÑÔÚ9ÔÂ2ÈÕ°ä²¼µÄ°æ±¾8.7.5Öн¨¸´¡£¡£¡£¡£¡£¡£ÔÚ²éÔĺ¹ÇàÊý¾Ýºó£¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËԱȷ¶¨¹¥»÷ÆðÍ·×Ô2022Äê8ÔÂ26ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬×ÔÄÇʱÆð¸Ã¹«Ë¾ÒÑ×èÖ¹Á˽ü500Íò´ÎÕë¶Ô¸Ã·ì϶µÄ¹¥»÷¡£¡£¡£¡£¡£¡£
https://www.wordfence.com/blog/2022/09/psa-nearly-5-million-attacks-blocked-targeting-0-day-in-backupbuddy-plugin/
5¡¢Ó¢¹úPVCÔì×÷ÉÌEurocellÔâµ½¹¥»÷ºóÔ±¹¤µÄÐÅϢй¶
¾ÝýÌå9ÔÂ12ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬Ó¢¹úPVCÔì×÷ÉÌEurocell֪ͨÆäÏÖÔ±¹¤ºÍǰԱ¹¤¹ØÓÚËûÃǵÄÓ×ÎÒÐÅϢй¶µÄÊÂÎñ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ú¹Êͳƣ¬£¬£¬£¬£¬£¬£¬£¬Î´¾ÊÚȨµÄµÚÈý·½½Ó¼ûÁËÆäϵͳ£¬£¬£¬£¬£¬£¬£¬£¬±»Ð¹Â¶µÄÊý¾ÝÔ̺¬£º¹ÍÓ¶Ìõ¿îºÍǰÌá¡¢µ®ÉúÈÕÆÚ¡¢Ç×Êô¡¢ÒøÐÐÕË»§¡¢NIºÍ˰Îñ²Î¿¼ºÅ¡¢½¡È«ºÍ¸£ÀûÎļþµÈ¡£¡£¡£¡£¡£¡£ÕâЩÐÅÏ¢ºóÐø¿ÉÄܱ»´¹µö¹¥»÷»òÕßÀÕË÷ÀÕË÷ÀûÓ㬣¬£¬£¬£¬£¬£¬£¬Eurocell°µÊ¾Ä¿Ç°ÉÐÎÞÖ¤¾ÝÅú×¢Êý¾Ý±»ÀÄÓᣡ£¡£¡£¡£¡£¸Ã¹«Ë¾ÏÖÓг¬¹ý2000¸öÔ±¹¤£¬£¬£¬£¬£¬£¬£¬£¬µ«¼øÓÚй¶ÐÅÏ¢µÄÀàÐÍ£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜ»¹Óиü¶àµÄǰԱ¹¤Ãæ¶Ô·çÏÕ¡£¡£¡£¡£¡£¡£
https://www.infosecurity-magazine.com/news/hackers-employee-data-pvcmaker/
6¡¢Kaspersky°ä²¼2022ÄêH1¹¤Òµ×Ô¶¯»¯ÏµÍ³ÍþÐ²Ì¬ÊÆµÄ·ÖÎö
9ÔÂ8ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Kaspersky°ä²¼ÁË2022ÄêÉϰëÄ깤ҵ×Ô¶¯»¯ÏµÍ³ÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬£¬£¬×éÖ¯µÄÔËÓª¼¼Êõ»ù´¡ÉèÊ©ÖÐÍÆËã»úÃæ¶ÔµÄÖØÒªÍþвÆðÔ´ÊÇ»¥ÁªÍø16.5%£©¡¢¿ÉÒÆ¶¯Ã½Ì壨3.5%£©ºÍµç×ÓÓʼþ£¨7.0%£©¡£¡£¡£¡£¡£¡£ÔÚÂ¥Óî×Ô¶¯»¯ÐÐÒµ£¬£¬£¬£¬£¬£¬£¬£¬×èÖ¹µÄ¶ñÒ⸽¼þºÍ´¹µöÁ´½ÓµÄICSµÄÕ¼±È(14.4%)ÊÇÈ«Çò¾ùÔÈÖµ(7%)µÄÁ½±¶¡£¡£¡£¡£¡£¡£2022ÄêÉϰëÄ꣬£¬£¬£¬£¬£¬£¬£¬ICS×èÖ¹ÁËÀ´×Ô7219¸öϵÁеĶñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÀÕË÷Èí¼þ¡¢¶ñÒâÎļþ¡¢ÓÃÓÚÒñ±Î¼ÓÃÜÇ®±ÒÍÚ¾òµÄ¶ñÒâÈí¼þºÍ¼äµýÈí¼þµÈ¡£¡£¡£¡£¡£¡£
https://securelist.com/threat-landscape-for-industrial-automation-systems-for-h1-2022/107373/


¾©¹«Íø°²±¸11010802024551ºÅ