ISCÐû²¼¸üУ¬ÐÞ¸´BIND DNSÈí¼þÖеĶà¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2022-09-27
9ÔÂ21ÈÕ£¬Internet Systems Consortium(ISC)Ðû²¼Çå¾²¸üУ¬ÐÞ¸´BIND DNSÈí¼þÖеĶà¸ö¿ÉÔ¶³ÌʹÓõÄÎó²î¡£ÆäÖнÏΪÑÏÖØµÄÊÇͨ¹ýTKEY RR´¦Öóͷ£Diffie-HellmanÃÜÔ¿½»Á÷µÄ´úÂëÖеÄÄÚ´æÐ¹Â¶Îó²î£¨CVE-2022-2906£©¡¢ECDSA DNSSECÑéÖ¤ÂëÖеÄÄÚ´æÐ¹Â¶Îó²î£¨CVE-2022-38177£©¡¢¿Éµ¼ÖÂBIND 9ÆÊÎöÆ÷Íß½âµÄÎó²î£¨CVE-2022-3080£©ºÍEdDSA DNSSECÑéÖ¤ÂëÖеÄй¶Îó²î£¨CVE-2022-38178£©¡£ISCÌåÏÖ£¬ÉÐδ·¢Ã÷ÉÏÊöÎó²îÔÚÒ°ÍⱻʹÓõÄÔ˶¯¡£
https://securityaffairs.co/wordpress/136164/security/bind-dns-software-flaws-2.html
2¡¢Google PlayºÍApp StoreÖжà¸ö¹ã¸æÓ¦Óñ»×°ÖÃ1300Íò´Î
¾ÝýÌå9ÔÂ26ÈÕ±¨µÀ£¬Ñо¿Ö°Ô±ÔÚGoogle PlayÉÏ·¢Ã÷ÁË75¸ö¹ã¸æÓ¦Óã¬ÔÚApp StoreÉÏ·¢Ã÷ÁËÁíÍâ10¸ö¹ã¸æÓ¦Óã¬×ܹ²±»×°ÖÃÁË1300Íò´Î¡£³ýÁËÏòÊÖ»úÓû§Í¶·Å¿É¼ûºÍÒþ²ØµÄ¹ã¸æÍ⣬ÕâЩڲÆÓ¦Óû¹Í¨¹ýð³äÕýµ±µÄÓ¦ÓÃÀ´´´ÊÕ¡£ËäÈ»ÕâÖÖÀàÐ͵ÄÓ¦Óò»±£´æÑÏÖØµÄÍþв£¬µ«¹¥»÷Õß¿ÉÒÔʹÓÃËüÃǾÙÐиüΣÏÕµÄÔ˶¯¡£Ñо¿ÍŶÓÒѽ«ÕâЩ·¢Ã÷֪ͨGoogleºÍApple£¬ÏÖÔÚÕâЩӦÓÃÒÑ´Ó¹Ù·½AndroidºÍiOSÊÐËÁÖÐɾ³ý¡£
https://www.bleepingcomputer.com/news/security/adware-on-google-play-and-apple-store-installed-13-million-times/
3¡¢Ó¡¶ÈijҽÁÆÈí¼þ¹«Ë¾Ð¹Â¶170ÍòÈËCovid¿¹Ô²âÊÔЧ¹û
ýÌå9ÔÂ25Èճƣ¬Ó¡¶ÈijҽÁÆÈí¼þÌṩÉ̵ÄElasticsearch·þÎñÆ÷й¶ÁË170ÍòÈ˵ÄCovid¿¹Ô²âÊÔЧ¹û¡£AnuragÔÚShodanÉÏɨÃèÉèÖùýʧµÄÊý¾Ý¿âʱ£¬×¢Öص½Ò»Ì¨·þÎñÆ÷̻¶ÁËÁè¼Ý23GBµÄÊý¾Ý¡£ÆäÖаüÀ¨ÒÑÍù¼¸ÄêÍùÀ´ÓÚÓ¡¶ÈµÄÓ¡¶ÈÈ˺ÍÍâ¹úÓο͵ÄÐÅÏ¢£¬ÈçÐÕÃû¡¢¹ú¼®¡¢µØµã¡¢µç»°ºÅÂë¡¢Éí·ÝÖ¤ºÅÂë¡¢¼ì²âЧ¹û¡¢AadhaarºÅºÍ»¤ÕÕºÅÂëµÈ¡£Ñо¿Ö°Ô±ÌåÏÖ£¬¸ÃÊý¾Ý¿â×Ô2022Äê7ÔÂ2ÈÕ×îÏÈ̻¶£¬ÇÒÏÖÔÚÈÔ´¦ÓÚ¹ûÕæ×´Ì¬¡£
https://www.hackread.com/covid-antigen-test-results-india-leaked/
4¡¢ÎÚ¿ËÀ¼SSUµ·»ÙÔøÇÔÈ¡²¢³öÊÛ3000Íò¸öÕË»§µÄºÚ¿ÍÍÅ»ï
ýÌå9ÔÂ24ÈÕ±¨µÀ³Æ£¬ÎÚ¿ËÀ¼Çå¾²¾Ö(SSU)µÄÍøÂ粿·Öµ·»ÙÁËÒ»¸öÔøÇÔÈ¡²¢³öÊÛ3000Íò¸öÕË»§µÄºÚ¿ÍÍŻ¾ÝSSU³Æ£¬ËûÃÇÒÔºó´ÎÐж¯ÖÐ׬Ǯ1400ÍòUAH£¨380000ÃÀÔª£©¡£¹¥»÷Õß×Óͨ¹ý¶ñÒâÈí¼þѬȾÀ´»ñȡƾ֤ºÍÊý¾Ý£¬Ö÷ÒªÕë¶ÔÎÚ¿ËÀ¼ºÍÅ·ÃË×éÖ¯µÄϵͳ¡£ËûÃÇ»¹Í¨¹ýÔÚÎÚ¿ËÀ¼±»Õ¥È¡µÄµç×ÓÖ§¸¶ÏµÍ³YuMoney¡¢QiwiºÍWebMoneyÊÕ¿î¡£±»²¶µÄÈËÊýÈÔδÅû¶£¬µ«ËûÃǶ¼Òòδ¾ÊÚȨ³öÊÛ»ò·Ö·¢ÔÚ´æ´¢ÓÚÅÌËã»úºÍÍøÂçÖеĻá¼ûÊÜÏÞµÄÐÅÏ¢¶øÃæÁÙÐÌÊÂËßËϼ°¶àÄêî¿Ïµ¡£
https://securityaffairs.co/wordpress/136156/cyber-crime/ukraine-cyber-gang.html
5¡¢Î¢ÈíÐû²¼Ê¹ÓÃOAuthÓ¦Óù¥»÷Exchange·þÎñÆ÷µÄÆÊÎö±¨¸æ
9ÔÂ22ÈÕ£¬Î¢ÈíÐû²¼±¨¸æ³ÆÆä½üÆÚÊÓ²ìÁËÒ»ÖÖ¹¥»÷£¬ÆäÖй¥»÷ÕßÔÚ±»Ñ¬È¾µÄÔÆ×â»§ÖÐ×°ÖöñÒâOAuthÓ¦ÓóÌÐò£¬ÓÃÓÚ¿ØÖÆExchange OnlineÉèÖúÍÈö²¥À¬»øÓʼþ¡£¹¥»÷ÕßÊ×ÏȶÔδÆôÓÃMFAµÄÏÕÕË»§Ö´ÐÐײ¿â¹¥»÷£¬²¢Ê¹Óò»Çå¾²µÄÖÎÀíÔ±ÕË»§»ñµÃ³õʼ»á¼ûȨÏÞ¡£È»ºó£¬¹¥»÷Õ߿ɽ¨Éè¶ñÒâOAuthÓ¦ÓóÌÐò£¬¸Ã³ÌÐò»áÔÚµç×ÓÓʼþ·þÎñÆ÷ÖÐÌí¼Ó¶ñÒâÈëÕ¾ÅþÁ¬Æ÷¡£×îºó£¬Ê¹ÓöñÒâÈëÕ¾ÅþÁ¬Æ÷·¢ËÍ¿´ÆðÀ´ÏñÊÇÀ´×ÔÄ¿µÄÓòµÄÀ¬»øÓʼþ¡£
https://www.microsoft.com/security/blog/2022/09/22/malicious-oauth-applications-used-to-compromise-email-servers-and-spread-spam/
6¡¢NSAºÍCISAÐû²¼±£»¤OTºÍICSµÄÒªº¦»ù´¡ÉèÊ©µÄÇå¾²×Éѯ
9ÔÂ22ÈÕ£¬CISAºÍNSAÍŽáÐû²¼Á˹ØÓÚ±£»¤ÔËÓªÊÖÒÕ(OT)ºÍ¹¤Òµ¿ØÖÆÏµÍ³(ICS)µÄÒªº¦»ù´¡ÉèÊ©µÄÍŽáÇå¾²×Éѯ¡£¸Ãͨ¸æ·ÖÏíÁ˹¥»÷ÕßÓÃÀ´ÆÆËðÖ§³ÖITµÄOTºÍICS×ʲúµÄËùÓа취ÐÅÏ¢£¬²¢Ç¿µ÷ÁËÇ徲רҵְԱ¿ÉÒÔ½ÓÄɵķÀÓù²½·¥¡£»¹Ö¸³ö£¬ÔËÓª¡¢¿ØÖÆºÍ¼à¿ØÒ»Ñùƽ³£Òªº¦»ù´¡ÉèÊ©ºÍ¹¤ÒµÁ÷³ÌµÄOTºÍICS×ʲúÃæÁÙµÄÍþвÈÕÒæÔöÌí£¬²¢ÌṩÁËһЩÓÃÀ´Ó¦¶ÔµÐÊÖµÄÕ½ÂÔ¡¢ÊÖÒպͳÌÐò(TTP)µÄ×î¼ÑÇ徲ʵ¼ù¡£
https://us-cert.cisa.gov/ncas/current-activity/2022/09/22/cisa-and-nsa-publish-joint-cybersecurity-advisory-control-system


¾©¹«Íø°²±¸11010802024551ºÅ