CleafyÔÚGoogle Play·¢Ã÷αװ³É¶þάÂëÓ¦ÓõÄTeaBot

Ðû²¼Ê±¼ä 2022-03-04

CleafyÔÚGoogle Play·¢Ã÷αװ³É¶þάÂëÓ¦ÓõÄTeaBot


3ÔÂ1ÈÕ£¬£¬£¬£¬£¬CleafyÐû²¼±¨¸æ³ÆÆäÔÚGoogle PlayÊÐËÁÖз¢Ã÷ÁËÒøÐÐľÂíTeaBot¡£¡£¡£ ¡£¡£¸ÃľÂíαװ³É¶þάÂëÓ¦Óá°QR Code & Barcode ¨C Scanner¡±£¬£¬£¬£¬£¬Òѱ»ÏÂÔØÁè¼Ý10000´Î¡£¡£¡£ ¡£¡£Óë֮ǰ²î±ðµÄÊÇ£¬£¬£¬£¬£¬¸Ã±äÌåÕë¶ÔµÄÄ¿µÄÓ¦ÓÃÖÖÀàÔöÌí£¬£¬£¬£¬£¬ÏÖÒÑϯ¾íÁ˼ÒÍ¥ÒøÐÐÓ¦Óᢰü¹ÜÓ¦ÓúͼÓÃÜÇ®°üµÈÓ¦Óᣡ£¡£ ¡£¡£ÔÚ²»µ½Ò»ÄêµÄʱ¼äÀ£¬£¬£¬£¬TeaBotÕë¶ÔÄ¿µÄµÄÊýÄ¿ÔöÌíÁË500%ÒÔÉÏ£¬£¬£¬£¬£¬´Ó60¸öÔöÌíµ½400¶à¸ö¡£¡£¡£ ¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬TeaBotÖ÷ÒªÃÀ¹úÓû§£¬£¬£¬£¬£¬½üÆÚ»¹ÐÂÔöÁ˶íÓ˹Âå·¥¿ËÓïºÍÖÐÎİ汾£¬£¬£¬£¬£¬ÕâÅú×¢¸Ã¶ñÒâÈí¼þÕýÔÚÃé׼ȫÇò¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/teabot-malware-slips-back-into-google-play-store-to-target-us-users/


CloudSEK³ÆÕë¶ÔÓ¡¶ÈµÄ´¹ÂÚ¹¥»÷ÒÑÔì³ÉÉϰÙÍòÃÀÔªËðʧ


ÐÂ¼ÓÆÂÇå¾²¹«Ë¾CloudSEKÔÚ3ÔÂ1ÈÕÅû¶ÁËÕë¶ÔÓ¡¶ÈµÄ´¹ÂÚ¹¥»÷µÄϸ½ÚÐÅÏ¢¡£¡£¡£ ¡£¡£´Ë´Î¹¥»÷»î¶¯Éæ¼°200¶à¸ö´¹ÂÚÍøÕ¾£¬£¬£¬£¬£¬ÒԵ綯Æû³µÎªÓÕ¶ü£¬£¬£¬£¬£¬ÒÑÔì³É¸ß´ï1000000ÃÀÔªµÄËðʧ¡£¡£¡£ ¡£¡£Ó¡¶ÈÕþ¸®×î½üÍÆ³öÁËÐÂÕþ²ß£¬£¬£¬£¬£¬ÒÔÔö½ø¸Ã¹úµç¶¯Æû³µ£¨EV£©ÐÐÒµµÄÔöÌí¡£¡£¡£ ¡£¡£¹¥»÷Õßͨ¹ýʹÓÃGoogle Ads¡¢Ê¹ÓÃÏà¹ØÒªº¦×ÖÒÔ¼°Ä£ÄâRevoltºÍAtherµÈÆ·ÅÆÀ´ÓÕʹĿµÄ½øÈë´¹ÂÚÍøÕ¾£¬£¬£¬£¬£¬È»ºóÒªÇóËûÃÇÊäÈëСÎÒ˽¼ÒºÍÒøÐп¨ÐÅÏ¢£¬£¬£¬£¬£¬×îÖÕÇÔȡĿµÄµÄÕË»§×ʽ𡣡£¡£ ¡£¡£


https://cloudsek.com/whitepapers_reports/unearthing-the-million-dollar-scams-targeting-the-indian-electric-vehicle-industry-scams/


Malwarebytes·¢Ã÷Ö¼ÔÚÇÔȡ΢ÈíÓû§Æ¾Ö¤µÄ´¹Âڻ


3ÔÂ1ÈÕ£¬£¬£¬£¬£¬MalwarebytesÐû²¼Ò»·Ý±¨¸æ£¬£¬£¬£¬£¬ÏêÊöÁËÕë¶ÔMicrosoftÕÊ»§µÄ´¹Âڻ¡£¡£¡£ ¡£¡£¸Ã»î¶¯ÒÔ¡°MicrosoftÕÊ»§Òì³£µÇ¼»î¶¯¡±ÎªÖ÷Ì⣬£¬£¬£¬£¬Éù³Æ¼ì²âµ½À´×Ô¶íÂÞ˹/Ī˹¿ÆµÄÓû§¸Õ¸ÕÖØÐÂ×°±¸µÇ¼ÕÊ»§¡£¡£¡£ ¡£¡£µ±ÊÕ¼þÈ˵ã»÷´¹ÂÚÓʼþÖеġ°±¨¸æÓû§¡±ºó£¬£¬£¬£¬£¬±ã»áÏò¹¥»÷Õß·¢ËÍÒ»·â°üÀ¨Ô¤Ìî³äÐÂÎŵÄÓʼþ£¬£¬£¬£¬£¬Ö®ºó¿ÉÄܻᱻҪÇóÊäÈëµÇ¼ƾ֤ºÍÒøÐÐÐÅÏ¢µÈ¡£¡£¡£ ¡£¡£


https://blog.malwarebytes.com/scams/2022/03/unusual-sign-in-activity-mail-goes-phishing-for-microsoft-account-holders/


JFrogÐû²¼¹ØÓÚ¿ªÔ´¿âPJSIPÖÐ5¸öÄÚ´æËð»µÎó²îµÄ±¨¸æ


JFrogÔÚ3ÔÂ1ÈÕÐû²¼Á˹ØÓÚPJSIPÖÐ5¸öÄÚ´æËð»µÎó²îµÄ±¨¸æ¡£¡£¡£ ¡£¡£PJSIPÊÇÒ»¸ö¿ªÔ´¶àýÌåͨѶ¿â£¬£¬£¬£¬£¬ÌṩÁËIPµç»°Ó¦ÓÃʹÓõÄAPI¡£¡£¡£ ¡£¡£Îó²î°üÀ¨¿Éµ¼ÖµĴúÂëÖ´ÐеĿÍÕ»Òç³öÎó²î£¨CVE-2021-43299¡¢CVE-2021-43300ºÍCVE-2021-43301£©£¬£¬£¬£¬£¬ÒÔ¼°¿Éµ¼Ö¾ܾøÐ§À͵ÄÔ½½ç¶ÁÈ¡Îó²î£¨CVE-2021-43302£©»ººÍ³åÇøÒç³öÎó²î£¨CVE-2021-43303£©¡£¡£¡£ ¡£¡£ÕâЩÎó²îÒÑͨ¹ý2ÔÂ24ÈÕÐû²¼µÄ²¹¶¡ÐÞ¸´¡£¡£¡£ ¡£¡£


https://jfrog.com/blog/jfrog-discloses-5-memory-corruption-vulnerabilities-in-pjsip-a-popular-multimedia-library/


GoogleÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´ChromeÖеÄ28¸öÎó²î


GoogleÓÚ3ÔÂ1ÈÕÍÆ³öChrome 99£¬£¬£¬£¬£¬ÐÞ¸´ÁË28¸öÇå¾²Îó²î¡£¡£¡£ ¡£¡£ÆäÖнÏΪÑÏÖØµÄÎó²îÊÇANGLEÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2022-0789£©¡¢Cast UIÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2022-0790£©¡¢¶à¹¦Ð§¿òÖÐÊͷźóʹÓÃÎó²î£¨CVE-2022-0791£©¡¢Blink½á¹¹ÖеÄÀàÐÍ»ìÏýÎó²î£¨CVE-2022-0795£©ºÍANGLEÖÐÔ½½ç¶ÁÈ¡Îó²î£¨CVE-2022-0792£©µÈ¡£¡£¡£ ¡£¡£


https://www.cisa.gov/uscert/ncas/current-activity/2022/03/02/google-releases-security-updates-chrome


ESETÐû²¼IsaacWiperºÍHermeticWizardµÄÆÊÎö±¨¸æ


ESETÔÚ3ÔÂ1ÈÕÐû²¼ÁËIsaacWiperºÍHermeticWizardµÄÆÊÎö±¨¸æ¡£¡£¡£ ¡£¡£IsaacWipeÊÇÒ»¸öеÄWiper£¬£¬£¬£¬£¬±£´æÓÚûÓÐAuthenticodeÊðÃûµÄWindows DLL»òEXEÖУ¬£¬£¬£¬£¬×îÔçµÄPE±àÒëʱ¼ä´ÁÊÇ2021Äê10ÔÂ19¡£¡£¡£ ¡£¡£ÓÚ2ÔÂ24ÈÕÔÚÎÚ¿ËÀ¼Õþ¸®»ú¹¹µÄÍøÂçÖб»·¢Ã÷£¬£¬£¬£¬£¬ÉÐδȷ¶¨ÊÇ·ñÓëHermeticWiperÓйØÁª¡£¡£¡£ ¡£¡£HermeticWizardÊÇ×Ô½ç˵È䳿£¬£¬£¬£¬£¬ÓÃÓÚͨ¹ýWMIºÍSMBÔÚÍâµØÍøÂçÖÐÈö²¥HermeticWiper¡£¡£¡£ ¡£¡£


https://www.welivesecurity.com/2022/03/01/isaacwiper-hermeticwizard-wiper-worm-targeting-ukraine/



Çå¾²¹¤¾ß


Searpy


ËÑË÷¹¤¾ß£¬£¬£¬£¬£¬¿ÉÓÃÓÚÊÕÂÞºÍËÝÔ´£¬£¬£¬£¬£¬Ö§³Öpy2ºÍpy3¡£¡£¡£ ¡£¡£


https://github.com/j3ers3/Searpy


CAPEv2


ÊÇÒ»¸ö¶ñÒâÈí¼þɳÏ䣬£¬£¬£¬£¬´Óí§Òâ¶ñÒâÈí¼þ¼Ò×åÖÐÌáÈ¡ÉèÖûò½âѹpayload¡£¡£¡£ ¡£¡£


https://github.com/kevoreilly/CAPEv2


S1EM


S1EM ÊÇÒ»¸ö´øÓÐ SIRP ºÍ Threat Intel µÄ SIEM£¬£¬£¬£¬£¬Ò»¸öÍêÕûµÄÊý¾Ý°ü²¶»ñ£¬£¬£¬£¬£¬¶àºÏÒ»¡£¡£¡£ ¡£¡£


https://github.com/V1D1AN/S1EM


WMEye


ΪʹÓà WMI ºÍÔ¶³Ì MSBuild Ö´ÐÐÖ´ÐкáÏòÒÆ¶¯¶ø¿ª·¢µÄʵÑéÐÔ¹¤¾ß¡£¡£¡£ ¡£¡£


https://github.com/pwn1sher/WMEye



Çå¾²ÆÊÎö


Æ»¹ûÐû²¼ iOS 15.4 Beta 5


https://news.softpedia.com/news/apple-releases-ios-15-4-beta-5-534963.shtml


΢ÈíΪÖÐСÆóÒµÍÆ³öеĶ˵ãÇå¾²½â¾ö¼Æ»®


https://www.bleepingcomputer.com/news/microsoft/microsoft-rolling-out-new-endpoint-security-solution-for-smbs/


ASEC·¢Ã÷αװ³ÉMSIµÄMagniber·Ö·¢»î¶¯


https://asec.ahnlab.com/en/32226/


΢Èí£ºLSASSÍ߽⵼ÖÂWindowsÓò¿ØÖÆÖØÊÓÆô


https://www.bleepingcomputer.com/news/microsoft/microsoft-windows-domain-controller-restarts-caused-by-lsass-crashes/


Reality Winner µÄ Twitter ÕË»§±»ºÚ¿Í¹¥»÷ÒÔÕë¶Ô¼ÇÕß


https://www.bleepingcomputer.com/news/security/reality-winners-twitter-account-was-hacked-to-target-journalists/


VoIPmonitor ¼à¿ØÈí¼þÖз¢Ã÷µÄÑÏÖØÇå¾²Îó²î


https://thehackernews.com/2022/03/critical-security-bugs-uncovered-in.html