΢Èí³ÆºÚ¿ÍʹÓÃBoaЧÀÍÆ÷ÖеÄÎó²î¹¥»÷ÄÜÔ´ÐÐÒµ×éÖ¯
Ðû²¼Ê±¼ä 2022-11-24΢ÈíÔÚ11ÔÂ22ÈÕÐû²¼±¨¸æ£¬£¬£¬£¬£¬³Æ·¢Ã÷¹¥»÷ÕßʹÓÃBoa webЧÀÍÆ÷ÖеÄÎó²î¹¥»÷ÄÜÔ´ÐÐÒµ×éÖ¯¡£¡£¡£¡£¡£¡£¡£Recorded FutureÔøÓÚ2022Äê4ÔÂÅû¶Õë¶ÔÓ¡¶È¶à¸öµçÍøÔËÓªÉ̵Ĺ¥»÷»î¶¯£¬£¬£¬£¬£¬µ«Ã»ÓÐÏêϸ˵Ã÷¹¥»÷ǰÑÔ¡£¡£¡£¡£¡£¡£¡£Î¢ÈíÌåÏÖ£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁËBoaÍøÂçЧÀÍÆ÷ÖеÄÒ»¸öÒ×Êܹ¥»÷µÄ×é¼þ¡£¡£¡£¡£¡£¡£¡£Boa×Ô2005ÄêÒÔÀ´ÒÑÕýʽͣ²ú£¬£¬£¬£¬£¬µ«ÎïÁªÍø×°±¸ÈÔÔÚʹÓøýâ¾ö¼Æ»®£¬£¬£¬£¬£¬Î¢ÈíÒ»¸öÐÇÆÚÄÚÔÚÈ«Çò·¢Ã÷ÁËÁè¼Ý100Íò¸ö̻¶ÔÚ»¥ÁªÍøÉϵÄBoaЧÀÍÆ÷×é¼þ¡£¡£¡£¡£¡£¡£¡£BoaЧÀÍÆ÷±£´æ¶à¸öÎó²î£¬£¬£¬£¬£¬°üÀ¨í§ÒâÎļþ»á¼ûÎó²î(CVE-2017-9833)ºÍÐÅϢй¶Îó²î(CVE-2021-33558)¡£¡£¡£¡£¡£¡£¡£
https://www.microsoft.com/en-us/security/blog/2022/11/22/vulnerable-sdk-components-lead-to-supply-chain-risks-in-iot-and-ot-environments/
2¡¢KillnetÉù³Æ¶Ôµ¼ÖÂÅ·ÖÞÒé»áÍøÕ¾¹Ø±ÕµÄDDS¹¥»÷ÈÏÕæ
¾ÝýÌå11ÔÂ23ÈÕ±¨µÀ£¬£¬£¬£¬£¬ºÚ¿ÍÍÅ»ïKillnetµÄÒ»²¿·ÖAnonymous RussiaÉù³ÆÌᳫDDoS¹¥»÷£¬£¬£¬£¬£¬µ¼ÖÂÅ·ÖÞÒé»áµÄÍøÕ¾¡£¡£¡£¡£¡£¡£¡£Å·ÖÞÒé»áÖ÷ϯ֤ʵÁËÕâÒ»ÊÂÎñ£¬£¬£¬£¬£¬³ÆÒé»áµÄITÖ°Ô±ÕýÔÚ»¹»÷²¢±£»£»£»£»£»£»£»¤ÏµÍ³¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬11ÔÂ22ÈÕÆÆÏþ£¬£¬£¬£¬£¬Killnet»¹¹¥»÷ÁËÓ¢¹úÍþÁ®Íõ×ÓµÄÍøÕ¾£¬£¬£¬£¬£¬Ö»¹Ü¸ÃÍøÕ¾ÏÖÔÚ¿ÉÒÔÕý³£ÔËÐУ¬£¬£¬£¬£¬µ«Cloudflare¶ÔÅþÁ¬¾ÙÐÐÁËÌØÁíÍâÇå¾²¼ì²é¡£¡£¡£¡£¡£¡£¡£Killnet»¹·¢Ìû³Æ£¬£¬£¬£¬£¬ÆäÄ¿µÄÊÇÂ×¶ØÖ¤È¯ÉúÒâËù¡¢Ó¢¹ú¾ü¶ÓºÍÒøÐÐ×Ô¶¯ÕûÀíϵͳ(Bacs)µÄÍøÕ¾¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/pro-russian-hacktivists-take-down-eu-parliament-site-in-ddos-attack/
3¡¢²¨¶àÀè¸÷µÄDCHÒ½ÔºÔâµ½ÀÕË÷¹¥»÷Ó°ÏìÔ¼120ÍòÃû»¼Õß
ýÌå11ÔÂ22Èճƣ¬£¬£¬£¬£¬²¨¶àÀè¸÷µÄÒ½ÉúÖÐÐÄÒ½Ôº£¨DCH£©Ôâµ½ÐÂÀÕË÷ÍÅ»ïProject RelicµÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÒѹûÕæÆäÇÔÈ¡µÄ211 GBÎļþÖеÄ114 MBÊý¾Ý£¬£¬£¬£¬£¬Ñù±¾Êý¾Ý°üÀ¨ÁËҽԺϵͳµÄÄÚ²¿Îļþ£¬£¬£¬£¬£¬¹ØÓÚÔ±¹¤µÄÎļþÒÔ¼°Éæ¼°²¡ÈËÒ½ÁÆÐÅÏ¢µÄÎļþµÈ¡£¡£¡£¡£¡£¡£¡£DCHÔÚ11ÔÂ9ÈÕ֪ͨHHS£¬£¬£¬£¬£¬ÓÐ1195220Ãû»¼ÕßÊܵ½´Ë´ÎÊÂÎñµÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¾ÝBlackPoint³Æ£¬£¬£¬£¬£¬Project RelicÀÕË÷Èí¼þÊÇÓÃGoÓïÑÔ¿ª·¢µÄ£¬£¬£¬£¬£¬µ«ÓÃÓÚ×°ÖöñÒâÈí¼þºÍÇÔÈ¡Êý¾ÝµÄÒªÁìÈÔȻδ֪¡£¡£¡£¡£¡£¡£¡£
https://www.databreaches.net/doctors-center-hospital-reports-1-2-million-patients-affected-by-ransomware-attack/
4¡¢¶íÂÞ˹RoskomnadzorµÄÄÚÍø±»Cyber PartisansÈëÇÖ
¾Ý11ÔÂ22ÈÕ±¨µÀ£¬£¬£¬£¬£¬¶íÂÞ˹»¥ÁªÍøºÍýÌåî¿Ïµ»ú¹¹RoskomnadzorÔâµ½ºÚ¿Í¹¥»÷¡£¡£¡£¡£¡£¡£¡£Cyber PartisansÓÚÉÏÖÜÎåÉù³Æ´Ó¸Ã»ú¹¹ÇÔÈ¡ÁËÊýǧ·ÝÄÚ²¿Îļþ²¢¼ÓÃÜÁËÆäϵͳ¡£¡£¡£¡£¡£¡£¡£¶íÂÞ˹ͨÓÃÎÞÏßµçÆµÂÊÖÐÐÄ(GRFC)ÌåÏÖ£¬£¬£¬£¬£¬ºÚ¿ÍÉϸöÔÂÊ×´ÎʵÑéʹÓÃÒÔǰδʹÓùýµÄÎó²îÈëÇָûú¹¹£¬£¬£¬£¬£¬ÏÖÔÚÍøÂç¹¥»÷ÒÑ»ñµÃ¿ØÖÆ£¬£¬£¬£¬£¬Ã»ÓÐÈκÎÉñÃØÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£×÷Ϊ»ØÓ¦£¬£¬£¬£¬£¬Cyber PartisansÔÚÖÜÁù͸¶ËûÃÇ»ñµÃÁËÔ±¹¤µÄ»¤ÕÕÊý¾ÝºÍÒ½ÁƼͼ¡¢ÄÚ²¿ÓʼþºÍ¸Ã»ú¹¹ÏîÄ¿µÄ±¨¸æ¡£¡£¡£¡£¡£¡£¡£
https://therecord.media/belarusian-hacktivists-claim-to-breach-russias-internet-regulator/
5¡¢Bitdefender͸¶SharkBotľÂíÖØ·µGoogle PlayÊÐËÁ
BitdefenderÔÚ11ÔÂ21Èճƣ¬£¬£¬£¬£¬Ò»×éαװ³ÉÎļþÖÎÀíÆ÷µÄ¶ñÒâAndroidÓ¦ÓÃÒÑÉøÍ¸µ½¹Ù·½Google PlayÓ¦ÓÃÊÐËÁ£¬£¬£¬£¬£¬Ö¼ÔÚʹÓû§Ñ¬È¾SharkbotľÂí¡£¡£¡£¡£¡£¡£¡£·¢Ã÷µÄ¶ñÒâÓ¦ÓÃΪX-File Manager¡¢FileVoyagerºÍLiteCleaner M¡£¡£¡£¡£¡£¡£¡£BitdefenderÒ£²âÊý¾Ý·´Ó¦³ö´Ë´Î»î¶¯µÄÄ¿µÄ¹æÄ£½ÏС£¬£¬£¬£¬£¬´ó´ó¶¼Ä¿µÄλÓÚÓ¢¹ú£¬£¬£¬£¬£¬Æä´ÎÊÇÒâ´óÀû¡¢ÒÁÀʺ͵¹ú¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬ÕâЩ³ÌÐò¶¼ÒÑ´ÓGoogle PlayÊÐËÁÖÐɾ³ý¡£¡£¡£¡£¡£¡£¡£
https://www.bitdefender.com/blog/labs/android-sharkbot-droppers-on-google-play-underlines-platforms-security-needs/
6¡¢KasperskyÐû²¼2023ÄêICSÍøÂçÍþÐ²Ì¬ÊÆµÄÕ¹Íû±¨¸æ
11ÔÂ22ÈÕ£¬£¬£¬£¬£¬KasperskyÐû²¼Á˹ØÓÚ2023ÄêICSÍøÂçÍþÐ²Ì¬ÊÆµÄÕ¹Íû±¨¸æ¡£¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬Ëæ×ÅÏÖÓеĺÍеÄÕ½ÊõÒÔ¼°Õ½ÂÔͬÃ˵ķºÆð£¬£¬£¬£¬£¬¹¥»÷Ä¿µÄµÄµØÀíλÖý«²»¿É×èÖ¹µØ±¬·¢×ª±ä£¬£¬£¬£¬£¬×òÌìµÄÃËÓÑ¿ÉÄÜ»á³ÉΪ½ñÌìµÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£ÐÐÒµÖØÐĽ«±¬·¢×ª±ä£¬£¬£¬£¬£¬ºÜ¿ì¾Í»á¿´µ½Õë¶ÔũҵºÍʳÎï¡¢ÎïÁ÷ºÍÔËÊä¡¢ÄÜÔ´¡¢¸ß¿Æ¼¼ºÍÒ½ÁÆÏà¹Ø²¿·ÖµÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£Õë¶Ô¹Å°åÄ¿µÄµÄAPT¹¥»÷ÈԻᱣ´æ£¬£¬£¬£¬£¬Ö÷Òª°üÀ¨¾ü¹¤ÆóÒµ¡¢Õþ¸®»ú¹¹ºÍÒªº¦µÄ»ù´¡ÉèÊ©¡£¡£¡£¡£¡£¡£¡£
https://securelist.com/ics-cyberthreats-in-2023/108011/


¾©¹«Íø°²±¸11010802024551ºÅ