°Ä´óÀûÑǵڶþ´óµçÐŹ«Ë¾Optus½üǧÍòÓû§µÄÐÅϢй¶

°ä²¼¹¦·ò 2022-09-26

1¡¢°Ä´óÀûÑǵڶþ´óµçÐŹ«Ë¾Optus½üǧÍòÓû§µÄÐÅϢй¶

      

¾Ý9ÔÂ23ÈÕ±¨Â· £¬°Ä´óÀûÑǵڶþ´óµçÐŹ«Ë¾OptusÔâµ½¹¥»÷ £¬¿ÉÄÜÓ°Ïì¶à´ï900Íò¸öÓû§µÄÊý¾Ý¡£Optus³Æ £¬¹¥»÷ÕßÉè·¨½øÈëÁ˿ͻ§Éí·ÝÊý¾Ý¿â £¬²¢Í¨¹ýÀûÓ÷¨Ê½½Ó¿Ú£¨API£©½«ÆäÊ¢¿ª¸øÆäËûϵͳ¡£ÊÂÎñÈÔÔÚµ÷²éÖÐ £¬OptusÒÔΪÆäÖÐÒ»¸öÍøÂ类¶³öÔÚÁËÒ»¸öÓл¥ÁªÍø½ÓÈëµÄ²âÊÔÍøÂçÖС£¸Ã¹«Ë¾Òɻ󹥻÷ÕßÒѾ­ÇÔÈ¡ÁËÏû·ÑÕßµÄÊý¾Ý¿â £¬²¢¿ÉÄܸ´ÔìÁËÆäÖеÄÈý·ÖÖ®Ò»¡£Optus°µÊ¾ËüÔÚ·¢ÏÖ¹¥»÷ºóÁ¢¼´²ÉÈ¡ÁË´ëÊ© £¬µ«ÊÇûÓÐй©¹ØÓÚ¹¥»÷µÄ¾ßÌåÄÚÈÝ¡£


https://www.hackread.com/optus-data-breach-australia-telecom-firm/


2¡¢Sophos½¨¸´Òѱ»ÀûÓõĴúÂë×¢Èë·ì϶CVE-2022-3236

      

SophosÔÚ9ÔÂ23ÈÕ½¨¸´ÁËÆä·À»ðǽÖдúÂë×¢Èë·ì϶£¨CVE-2022-3236£©¡£¸Ã·ì϶CVSSÆÀ·ÖΪ9.8 £¬Éæ¼°Óû§ÃÅ»§ºÍWebÖÎÀí×é¼þ £¬¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¸Ã¹«Ë¾°µÊ¾ £¬ËüÒѾ­¹Û²ìµ½ÀûÓø÷ì϶µÄ¹¥»÷»î¶¯ £¬ÖØÒªÊÇÔÚÄÏÑǵØÓò £¬²¢²¹³ä˵ËüÖ±½Ó֪ͨÁËÕâЩ×éÖ¯¡£ÆôÓÃÁËÔÊÐí×Ô¶¯×°Öý¨²¹·¨Ê½Ö°ÄܵÄSophos FirewallÓû§ÎÞÐèÖ´ÐÐÈκβÙ×÷ £¬ÇÒÆôÓÃÊÇĬÈÏÉèÖá£SophosÔÚ½ñÄê3Ô»¹½¨¸´ÁËÒ»¸öÀàËÆµÄFirewall·ì϶(CVE-2022-1040) £¬¸Ã·ì϶ҲÔÚÕë¶ÔÄÏÑÇ×éÖ¯µÄ¹¥»÷Öб»ÀûÓá£


https://www.bleepingcomputer.com/news/security/sophos-warns-of-new-firewall-rce-bug-exploited-in-attacks/


3¡¢YouTubeÈ«ÇòÁìÓòÄÚ·þÎñÖжÏÇÒÉв»Ã÷ÏÔÊÂÎñÔ­Òò

      

ýÌå9ÔÂ23ÈÕ³Æ £¬YouTubeÔÚÈ«ÇòÁìÓòÄÚ·þÎñÖжÏ £¬³ÉǧÉÏÍòµÄÓû§»ã±¨ËûÃÇÎÞ·¨½Ó¼ûÖ±²¥¡£ÔÚ³¢ÊÔ½Ó¼ûYouTubeʱ £¬Óû§»á¿´µ½´øÓмÓÔØ¶¯»­µÄºÚÆÁºÍ¡°ÇëÉÔºóÔÙÊÔ¡±µÄÃýÎóÐÂÎÅ¡£ÄÇЩÉè·¨¼ÓÔØÖ±²¥µÄÓû§³ÆÊÓÆµÖͺó £¬Ì¸ÌìÐÂÎÅÒ²Öͺó»òµ××Ó²»ÏÔʾ¡£»¥ÁªÍø¼à¿Ø×éÖ¯NetBlocksҲ֤ʵ £¬YouTubeÕý¾­ÀúÒ»³¡Ó°ÏìÖ±²¥µÄÈ«ÇòÐÔÖжÏ £¬´ËÊÂÎñÓë¹ú¶È¼¶»¥ÁªÍøÖжϻò¹ýÂËÎ޹ء£Ä¿Ç° £¬Éв»Ã÷ÏÔÕâÊÇ´òËãÖеÄÊØ»¤»î¶¯¡¢YouTube·þÎñÆ÷µÄÎÊÌ⻹ÊÇÓë¶ñÒâ¹¥»÷ÓйØ¡£


https://www.bleepingcomputer.com/news/technology/youtube-down-live-streams-hit-by-worldwide-outage/


4¡¢Anonymous³ÆÒÑÈëÇÖ¶íÂÞ˹¹ú·À²¿ÍøÕ¾²¢¹«¿ª30ÍòÈËÊý¾Ý

      

AnonymousÓÚ9ÔÂ23ÈÕÔÚÆäTwitterÕË»§Éϰ䲼ÐÂÎÅ £¬³ÆÒѾ­ÈëÇÖÁ˶íÂÞ˹¹ú·À²¿µÄÍøÕ¾¡£¸ÃÍŻﻹй¶ÁË305925È˵ÄÊý¾Ý £¬ÕâЩÈË¿ÉÄÜÊÇÆÕ¾©×Üͳ°ä·¢µÄÈý²¨¾üÊ»´øÍ·ÖеĵÚÒ»²¨Ô¤±¸ÒÛÎäÊ¿¡£¹¥»÷Õßͨ¹ýProtonDrive¹«¿ªÁËÒ»¸ö90MB´óÓ×µÄTXTÎļþ £¬ÆäÖÐÔ̺¬³¬¹ý30ÍòÈ˵ÄÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µØÓòºÍµØÓò¡£Ä¿Ç°ÎÞ·¨ÑéÖ¤ÕâЩµµ°¸¼òÖ±ÇÐÆðÔ´¡£


https://www.infosecurity-magazine.com/news/russian-reservists-leaked-anonymous/


5¡¢GitHub·¢ÏÖ¼ÙÒâCircleCIƽ̨ÈëÇÔìäÓû§ÕË»§µÄ¹¥»÷»î¶¯

      

¾ÝýÌå9ÔÂ25ÈÕ±¨Â· £¬GitHubÌáÐÑÕë¶ÔÆäÓû§µÄ´¹µö¹¥»÷»î¶¯ £¬Í¨¹ý¼ÙÒâCircleCI DevOpsƽ̨À´ÇÔȡʹ´¦ºÍË«³ÁÉí·ÝÑéÖ¤(2FA)´úÂë¡£¸Ã¹«Ë¾ÓÚ9ÔÂ16ÈÕ»ñϤÕâ´Î¹¥»÷ £¬²¢Ö¸³ö³ýGitHub±í £¬´¹µö»î¶¯ÒÑÓ°Ïìµ½ºÜ¶à×éÖ¯¡£´¹µöÐÅÏ¢Ðû³ÆÓû§µÄCircleCI»á»°ÒѹýÆÚ £¬²¢ÊÔͼÓÕʹÊÕ¼þÈËʹÓÃGitHubÍ´´¦µÇ¼¡£ÊÕ¼þÈ˱»³Á¶¨Ïòµ½Î±ÔìµÄGitHubµÇÂ¼Ò³Ãæºó £¬»á±»ÇÔÈ¡ÊäÈëµÄÍ´´¦ºÍ2FA´úÂë¡£¸Ã¹«Ë¾°µÊ¾ £¬ÊÜÓ²¼þ°²È«ÃÜÔ¿±£»¤µÄÕË»§²»Ò×Ôâµ½µ½ÕâÖÖ¹¥»÷¡£


https://securityaffairs.co/wordpress/136211/hacking/phishing-circleci-github-accounts.html


6¡¢AhnLab°ä²¼FARGO¹¥»÷MS-SQL·þÎñÆ÷µÄ·ÖÎö»ã±¨

      

9ÔÂ23ÈÕ £¬AhnLab°ä²¼»ã±¨³ÆÒ×Êܹ¥»÷µÄMicrosoft SQL·þÎñÆ÷Ôâµ½ÁËFARGOµÄÐÂÒ»ÂÖ¹¥»÷¡£FARGOÓëGlobeImposterÒ»Ñù £¬ÊÇÖØÒªÕë¶ÔMS-SQL·þÎñÆ÷µÄÀÕË÷Èí¼þÖ®Ò» £¬ÔÚ´ÓǰҲ±»³ÆÎªMallox¡£Ï°È¾Ê¼ÓÚÖ¸±êÉ豸ÉϵÄMS-SQL¹ý³ÌʹÓÃcmd.exeºÍpowershell.exeÏÂÔØ.NETÎļþ¡£Payload»á»ñÈ¡ÆäËû¶ñÒâÈí¼þ £¬ÌìÉú²¢ÔËÐÐÖÕÖ¹ÌØ¶¨¹ý³ÌºÍ·þÎñµÄBATÎļþ¡£¶øºó £¬½«ÀÕË÷Èí¼þpayload×¢Èëµ½ºÏ·¨µÄWindows¹ý³ÌAppLaunch.exeÖС£


https://asec.ahnlab.com/en/39152/