Ó¢¹ú³Æ¶íDZͧÕýÍþв³ÐÔØÁè¼Ý95%¹ú¼ÊÊý¾ÝµÄº£µ×µçÀÂ

Ðû²¼Ê±¼ä 2022-01-13

Ó¢¹ú³Æ¶íDZͧÕýÍþв³ÐÔØÁè¼Ý95%¹ú¼ÊÊý¾ÝµÄº£µ×µçÀÂ


Ó¢¹ú³Æ¶íDZͧÕýÍþв³ÐÔØÁè¼Ý95%¹ú¼ÊÊý¾ÝµÄº£µ×µçÀÂ.png


ýÌå1ÔÂ9ÈÕ±¨µÀ£¬£¬ £¬£¬£¬£¬Ó¢¹ú¹ú·À²¿³¤Tony Radakin³Æ£¬£¬ £¬£¬£¬£¬¶íÂÞ˹DZͧÕýÔÚÍþвº£µ×ÍøÂçµçÀÂÍøÂç¡£¡£ ¡£¡£¡£¡£¡£º£µ×µçÀ³ÐÔØÁè¼Ý95%µÄ¹ú¼ÊÊý¾Ý£¬£¬ £¬£¬£¬£¬½öÔÚ½ðÈÚÁìÓò£¬£¬ £¬£¬£¬£¬ËüÌìÌì¾Í³ÐÔØ×ÅÔ¼10ÍòÒÚÃÀÔªµÄÉúÒâ¡£¡£ ¡£¡£¡£¡£¡£Ó¢¹úÕþ¸®³Æ£¬£¬ £¬£¬£¬£¬½ü20ÄêÖжíÂÞ˹µÄˮϻÏÔÖøÔöÌí£¬£¬ £¬£¬£¬£¬ËûÃÇÔøÔÚ2020Äê12Ô»÷ÖÐÒ»ËÒ¶íÂÞ˹DZͧ¡£¡£ ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ£¬£¬ £¬£¬£¬£¬Ìع¤ÍŻﻹ¿ÉÒÔͨ¹ýÔÚµçÀÂÖÆÔìÀú³ÌÖÐÖ²ÈëºóÃÅÀ´ÇÔÌý´«ÊäµÄÊý¾Ý¡£¡£ ¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/126459/security/undersea-cables-protection.html


Ñо¿ÍŶÓÅû¶ÐÂÀÕË÷Èí¼þNight Sky½üÆÚ¹¥»÷µÄϸ½Ú


¾ÝýÌå1ÔÂ6ÈÕ±¨µÀ£¬£¬ £¬£¬£¬£¬Malware Hunter Team·¢Ã÷ÁËÐÂÀÕË÷Èí¼þNight Sky¡£¡£ ¡£¡£¡£¡£¡£¸ÃÍÅ»ïµÄ»î¶¯×îÏÈÓÚ12ÔÂ27ÈÕ£¬£¬ £¬£¬£¬£¬Í¬ÑùʹÓÃÁËË«ÖØÀÕË÷Õ½ÂÔ¡£¡£ ¡£¡£¡£¡£¡£±ðµÄ£¬£¬ £¬£¬£¬£¬Night Sky²¢Î´Ê¹ÓÃTorÍøÕ¾ÓëÄ¿µÄ̸ÅУ¬£¬ £¬£¬£¬£¬¶øÊÇʹÓÃÓʼþµØµãºÍÔËÐÐRocket.ChatµÄÍøÕ¾¡£¡£ ¡£¡£¡£¡£¡£ÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ÏÔʾÒÑÓÐ2¸ö±»¹¥»÷Ä¿µÄ£¬£¬ £¬£¬£¬£¬Ò»¸öÀ´×ÔÃϼÓÀ­¹ú£¬£¬ £¬£¬£¬£¬ÁíÒ»¸öÀ´×ÔÈÕ±¾£¬£¬ £¬£¬£¬£¬ËüÃÇÆäÖÐÖ®Ò»±»ÀÕË÷800000ÃÀÔª¡£¡£ ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/night-sky-is-the-latest-ransomware-targeting-corporate-networks/


Malwarebytes·¢Ã÷PatchworkÕë¶Ô¿ÆÑÐÐÐÒµµÄ¹¥»÷»î¶¯


MalwarebytesÔÚ1ÔÂ7ÈÕÐû²¼µÄ±¨¸æÖÐÌåÏÖ£¬£¬ £¬£¬£¬£¬Ó¡¶ÈAPT×éÖ¯PatchworkµÄ¿ª·¢ÏµÍ³±»×Ô¼ºµÄRATѬȾ£¬£¬ £¬£¬£¬£¬µ¼ÖÂÆÁÄ»½ØÍ¼ºÍ¼üÅ̼ͼµÈÐÅϢй¶¡£¡£ ¡£¡£¡£¡£¡£Í¨¹ýÕâЩÐÅÏ¢£¬£¬ £¬£¬£¬£¬Ñо¿ÍŶÓÈ·¶¨Á˸ÃÍÅ»ïÔÚ½üÆÚµÄ¹¥»÷»î¶¯¡£¡£ ¡£¡£¡£¡£¡£2021Äê11ÔÂÏÂÑ®ÖÁ12ÔÂÉÏÑ®£¬£¬ £¬£¬£¬£¬¸ÃÍÅ»ïð³ä°Í»ù˹̹Õþ¸®£¬£¬ £¬£¬£¬£¬Ê¹ÓöñÒâRTFÎļþ·Ö·¢Ò»ÖÖÃûΪRagnatelaµÄBADNEWS RATбäÌå¡£¡£ ¡£¡£¡£¡£¡£´Ë´Î¹¥»÷µÄÄ¿µÄ°üÀ¨°Í»ù˹̹¹ú·À²¿¡¢ÒÁ˹À¼±¤¹ú·À´óѧºÍÀ­ºÏ¶û´óѧÉúÎï¿ÆÑ§Ñ§ÔºµÈ¡£¡£ ¡£¡£¡£¡£¡£


https://blog.malwarebytes.com/threat-intelligence/2022/01/patchwork-apt-caught-in-its-own-web/


Google Docs̸ÂÛ¹¦Ð§±»´¹ÂڻÓÃÀ´·¢ËͶñÒâÐÅÏ¢ 


1ÔÂ6ÈÕ£¬£¬ £¬£¬£¬£¬Çå¾²¹«Ë¾AvananÐû²¼ÁËÕë¶ÔOutlookÓû§µÄ´¹ÂڻµÄÆÊÎö±¨¸æ¡£¡£ ¡£¡£¡£¡£¡£´Ë´Î»î¶¯µÄ¹¥»÷Á´ºÜÊǼòÆÓ£¬£¬ £¬£¬£¬£¬¹¥»÷ÕßÊ×ÏȽ¨ÉèÒ»¸öGoogle Doc£¬£¬ £¬£¬£¬£¬²¢ÏòÆäÌí¼ÓÒ»Ìõ̸ÂÛ£¬£¬ £¬£¬£¬£¬¸Ã̸ÂÛ°üÀ¨¶ñÒâÁ´½Ó£¬£¬ £¬£¬£¬£¬²¢Ê¹Óá°@¡±À´Ìá¼°Ä¿µÄ¡£¡£ ¡£¡£¡£¡£¡£¶øGoogleÔò»á×Ô¶¯ÏòÄ¿µÄ·¢ËÍÒ»·âµç×ÓÓʼþ£¬£¬ £¬£¬£¬£¬Í¨ÖªÆäÓÐÌá¼°ËûÃǵÄÐÂ̸ÂÛ£¬£¬ £¬£¬£¬£¬²¢»áÏÔʾ°üÀ¨¶ñÒâÁ´½ÓÔÚÄÚµÄÍêÕû̸ÂÛ¡£¡£ ¡£¡£¡£¡£¡£ÓÉÓÚÕâЩÓʼþÀ´×ÔGoogle£¬£¬ £¬£¬£¬£¬Òò´ËÇå¾²½â¾ö¼Æ»®²»»á½«ËüÃDZê¼ÇΪ¶ñÒâ¡£¡£ ¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/126375/hacking/google-docs-comment-phishing.html


ŵ¶ÙÔÚÓû§µçÄÔÖÐÇ¿ÖÆ×°ÖÃÍÚ¿óÈí¼þNorton Crypto


ýÌå1ÔÂ7ÈÕ±¨µÀ£¬£¬ £¬£¬£¬£¬É±¶¾Èí¼þNorton 360»áÔÚÓû§µçÄÔÖÐÇ¿ÖÆ×°ÖÃÍÚ¿óÈí¼þNorton Crypto¡£¡£ ¡£¡£¡£¡£¡£¾ÝϤ£¬£¬ £¬£¬£¬£¬¸ÃÈí¼þÔÚÈ¥Äê6Ô±»ÄÉÈëNortonɱ¶¾Èí¼þ£¬£¬ £¬£¬£¬£¬¿É×ÊÖúÓû§Ê¹ÓÃÏÔ¿¨×¬È¡ÌØÊâÊÕÈ루Óû§±£´æ85%ÊÕÈ룬£¬ £¬£¬£¬£¬ÆäÓà±»NortonLifeLock³é³É£©¡£¡£ ¡£¡£¡£¡£¡£²¿·ÖÓû§ÌåÏÖ£¬£¬ £¬£¬£¬£¬¸Ã¿ó¹¤Èí¼þ»á×Ô¶¯×°Ö㬣¬ £¬£¬£¬£¬²¢ÇÒ³ý·ÇÐ¶ÔØÕû¸öɱ¶¾Èí¼þ£¬£¬ £¬£¬£¬£¬²»È»²»¿Éµ¥¶Àɾ³ý¡£¡£ ¡£¡£¡£¡£¡£Norton»ØÓ¦³ÆNorton Crypto×÷ΪһÏî¿ÉÑ¡¹¦Ð§Ìṩ£¬£¬ £¬£¬£¬£¬Î´¾­Óû§Ðí²»»áÆôÓᣡ£ ¡£¡£¡£¡£¡£


https://www.hackread.com/norton-antivirus-installs-cryptominer-way-out/


Ñо¿Ö°Ô±ÔÚ16¸ö³£ÓõÄURLÆÊÎö¿âÖз¢Ã÷8¸öÇå¾²Îó²î


¾ÝýÌå1ÔÂ10ÈÕ±¨µÀ³Æ£¬£¬ £¬£¬£¬£¬Çå¾²¹«Ë¾ClarotyºÍSynkµÄÁªºÏÑо¿Åû¶ÁË8¸öÐÂÎó²îµÄϸ½Ú¡£¡£ ¡£¡£¡£¡£¡£Ñо¿·¢Ã÷16¸öURLÆÊÎö¿âÖб£´æ·×ÆçÖºͻìÏýÎÊÌ⣬£¬ £¬£¬£¬£¬ÕâЩÎÊÌâ¿É±»ÓÃÀ´ÈƹýÑéÖ¤²¢ÎªÖÖÖÖ¹¥»÷¹¥»÷ÔØÌå·­¿ª´óÃÅ¡£¡£ ¡£¡£¡£¡£¡£´Ë´ÎÅû¶µÄÎó²î°üÀ¨Belledonne¡¯s SIP Stack(CVE-2021-33056)¡¢Video.js(CVE-2021-23414)¡¢Nagios XI(CVE-2021-37352)ºÍFlask-security-too(CVE-2021-32618)µÈ¡£¡£ ¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬ £¬£¬£¬£¬Îó²îÒѱ»¸÷×ÔµÄά»¤Ö°Ô±ÐÞ¸´¡£¡£ ¡£¡£¡£¡£¡£


https://thehackernews.com/2022/01/researchers-find-bugs-in-over-dozen.html


Çå¾²¹¤¾ß


statiStrings


statiStrings ÊÇ YARA ¹æÔòµÄ×Ö·û´®Í³¼ÆÅÌËãÆ÷¡£¡£ ¡£¡£¡£¡£¡£


https://github.com/Sh3llyR/statiStrings


inject assembly


 ÔÚÏÖÓÐÀú³ÌÖÐÖ´ÐÐ .NET£¬£¬ £¬£¬£¬£¬¿ÉÌæ»» Cobalt Strike µÄ¹Å°å fork ºÍ run Ö´ÐС£¡£ ¡£¡£¡£¡£¡£


https://github.com/kyleavery/inject-assembly


Çå¾²ÆÊÎö


ÃÀ¹úNCSCºÍDoSÐû²¼Õë¶ÔÉÌÒµ¼àÊÓ¹¤¾ßµÄÖ¸ÄÏ


ÃÀ¹úNCSCºÍ¹úÎñÔºÐû²¼ÁªºÏÖ¸ÄÏ£¬£¬ £¬£¬£¬£¬ÌṩÁ˵ÖÓùʹÓÃÉÌÒµ¼àÊÓ¹¤¾ß¾ÙÐеĹ¥»÷µÄ×î¼Ñʵ¼ù¡£¡£ ¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/126497/digital-id/defending-against-surveillance-tools.html


CVE-2021-43326£ºÌáȨÎó²î


Automox Agent 32±£´æÍâµØÈ¨ÏÞÌáÉýÎó²î¡£¡£ ¡£¡£¡£¡£¡£


https://cxsecurity.com/issue/WLB-2022010046