JFrog·¢Ã÷200¶à¸öÕë¶ÔAzure¿ª·¢Ö°Ô±µÄ¶ñÒâNPM°ü

Ðû²¼Ê±¼ä 2022-03-28

JFrog·¢Ã÷200¶à¸öÕë¶ÔAzure¿ª·¢Ö°Ô±µÄ¶ñÒâNPM°ü


JFrogÔÚ3ÔÂ23ÈÕÐû²¼±¨¸æ³Æ£¬£¬£¬£¬£¬£¬£¬·¢Ã÷ÁËÖÁÉÙ218¸öÖ¼ÔÚÇÔȡСÎÒ˽¼ÒÉí·ÝÐÅÏ¢µÄ¶ñÒâNPM°ü¡£¡£¡£¡£ ¡£ÕâÊÇÕë¶ÔAzure¿ª·¢Ö°Ô±µÄ´ó¹æÄ£¹©Ó¦Á´¹¥»÷£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁËÓòÃû·ÂðµÄ¹¥»÷·½·¨£¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃ×Ô¶¯¾ç±¾½¨ÉèÕÊ»§²¢ÉÏ´«¶ñÒâ°ü£¬£¬£¬£¬£¬£¬£¬ÒÔÑÚÊÎÕâЩ¶ñÒâ°ü¶¼À´×Ôͳһ¿ª·¢ÕßµÄÊÂʵ¡£¡£¡£¡£ ¡£´ËÀàNPM°üÒ»µ©±»×°Öú󣬣¬£¬£¬£¬£¬£¬¾Í»áÍøÂçÓйØÓû§Ä¿½ñÊÂÇéĿ¼£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÓëÍøÂç½Ó¿ÚºÍDNSЧÀÍÆ÷Ïà¹ØµÄIPµØµãµÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬²¢½«ÕâЩÊý¾Ý·¢Ë͵½Ó²±àÂëµÄÔ¶³ÌЧÀÍÆ÷¡£¡£¡£¡£ ¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬ÕâЩ¶ñÒâNPM°üÒѱ»É¾³ý¡£¡£¡£¡£ ¡£


https://thehackernews.com/2022/03/over-200-malicious-npm-packages-caught.html


΢Èí¸üе¼ÖÂWindows Server 2019µÄDNSÆÊÎöʧ°Ü


¾ÝýÌå3ÔÂ24ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬ÔÚ×°ÖÃ2022Äê1ÔÂ25ÈÕÐû²¼µÄ¸üÐÂ(KB5009616)ºó£¬£¬£¬£¬£¬£¬£¬Windows Server 2019µÄDNSÆÊÎö¿ÉÄ᷺ܻÆðÎÊÌâ¡£¡£¡£¡£ ¡£ÕâÊÇDNS´æ¸ùÇøÓòÎÞ·¨×¼È·¼ÓÔØµ¼ÖµÄ£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜ´¥·¢´ËDNSÆÊÎöÎÊÌâµÄÁíÍâÁ½¸öWindows¸üÐÂÊÇKB5010427£¨2ÔÂ15ÈÕÐû²¼£©ºÍKB5011551£¨3ÔÂ22ÈÕÐû²¼£©¡£¡£¡£¡£ ¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬MicrosoftÒÑͨ¹ýÒÑÖªÎÊÌâ»Ø¹ö(KIR)¹¦Ð§ÐÞ¸´ÁË´ËÎÊÌâ¡£¡£¡£¡£ ¡£ÒªÐÞ¸´´ËÎÊÌ⣬£¬£¬£¬£¬£¬£¬ÖÎÀíÔ±»¹Ðè×°ÖúÍÉèÖÃÁ½¸ö×éÕ½ÂÔ¡£¡£¡£¡£ ¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-recent-windows-server-updates-cause-dns-issues/


VMwareÐû²¼¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÆäCarbon BlackÖеÄ2¸öÎó²î


3ÔÂ23ÈÕ£¬£¬£¬£¬£¬£¬£¬VMwareÐû²¼Á˸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´Ó°ÏìÆäCarbon Black App Controlƽ̨µÄ2¸öÎó²î¡£¡£¡£¡£ ¡£Carbon BlackÊÇÓ¦ÓóÌÐò¿ØÖƽâ¾ö¼Æ»®£¬£¬£¬£¬£¬£¬£¬´Ë´ÎÐÞ¸´µÄÎó²î»®·ÖΪÏÂÁî×¢ÈëÎó²î£¨CVE-2022-22951£©£¬£¬£¬£¬£¬£¬£¬¿ÉÓÉÓÚÊäÈëÑéÖ¤²»µ±¶øµ¼ÖÂÔ¶³ÌÖ´ÐдúÂ룻 £»£»£»ÒÔ¼°ÎļþÉÏ´«Îó²î£¨CVE-2022-22952£©£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÉÏ´«ÌØÖÆÎļþÀ´Ö´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ ¡£ÕâЩÎó²îµÄCVSSÆÀ·Ö¾ùΪ9.1£¬£¬£¬£¬£¬£¬£¬µ«ÀÖ³ÉʹÓÃËüÃǵÄÌõ¼þÊǾßÓÐÖÎÀíÔ±»ò¸ü¸ßȨÏÞ¡£¡£¡£¡£ ¡£


https://thehackernews.com/2022/03/vmware-issues-patches-for-critical.html


ÎÚ¿ËÀ¼CERT-UAÐû²¼¹ØÓÚDoubleZero¹¥»÷»î¶¯µÄ¾¯±¨


ýÌå3ÔÂ23ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬ÎÚ¿ËÀ¼CERT-UAÔÚ½üÆÚÐû²¼ÁËÒ»·Ýͨ¸æ£¬£¬£¬£¬£¬£¬£¬ÖÒÑÔDoubleZeroÕë¶ÔÎÚ¿ËÀ¼×éÖ¯µÄ¹¥»÷¡£¡£¡£¡£ ¡£Í¨¸æÖ¸³öÓÚ3ÔÂ17ÈÕÊ״η¢Ã÷»î¶¯£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÓã²æÊ½´¹ÂÚ¹¥»÷·Ö·¢¶ñÒâÈí¼þ¡£¡£¡£¡£ ¡£´¹ÂÚÓʼþ°üÀ¨Ò»¸ö»ìÏýµÄ.NET³ÌÐò£¬£¬£¬£¬£¬£¬£¬±»ÃüÃûΪDoubleZero£¬£¬£¬£¬£¬£¬£¬ÊÇΪÁËÆÆËðÄ¿µÄϵͳ¶ø¿ª·¢µÄ¡£¡£¡£¡£ ¡£DoubleZero wipeʹÓÃÁË2ÖÖÊÖÒÕ£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃ4096×Ö½ÚÁýÕÖÆäÄÚÈÝ£¨Ê¹ÓÃFileStream.Write£©£¬£¬£¬£¬£¬£¬£¬»òʹÓÃAPIŲÓÃNtFileOpenºÍNtFsControlFile(code:FSCTL_SET_ZERO_DATA)£¬£¬£¬£¬£¬£¬£¬×îºó»¹»áɾ³ýWindows×¢²á±íHKCU¡¢HKU¡¢HKLMºÍHKLM\BCD¡£¡£¡£¡£ ¡£


https://securityaffairs.co/wordpress/129417/malware/doublezero-wiper-hit-ukraine.html


¹¥»÷ÕßʹÓÃαװµÄÆÆ½âRATµÈ¶ñÒâÈí¼þÇÔȡĿµÄµÄÐÅÏ¢


¾Ý2ÔÂ23ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬¶à¸öÇå¾²ÍŶӷ¢Ã÷ÁËʹÓÃαÔìµÄ¶ñÒâÈí¼þ¹¥»÷ºÚ¿ÍµÄ»î¶¯¡£¡£¡£¡£ ¡£ASECÔÚRussia black hatµÈºÚ¿ÍÂÛ̳ÉÏ·¢Ã÷αװ³ÉÆÆ½â°æBitRATºÍQuasar RATµÄÇÔÈ¡³ÌÐò£¬£¬£¬£¬£¬£¬£¬Ä¿µÄÔÚµã»÷ÓÕ¶üÁ´½Óºó»á±»Öض¨Ïòµ½Ò»¸öAnonfilesÒ³Ãæ£¬£¬£¬£¬£¬£¬£¬È»ºó»áÏÂÔØ¶ñÒâÈí¼þClipBanker¡£¡£¡£¡£ ¡£Cyble·¢Ã÷ÁËÉù³ÆÊÇÌṩһ¸öÔÂÃâ·ÑAvD Crypto StealerµÄ»î¶¯£¬£¬£¬£¬£¬£¬£¬Ä¿µÄÔÚÏÂÔØËùνµÄ¶ñÒâÈí¼þ¹¹½¨Æ÷²¢Æô¶¯ÃûΪ¡°Payload.exe¡±µÄÎļþºó£¬£¬£¬£¬£¬£¬£¬»áѬȾÕë¶ÔEthereumµÈµÄclipper¶ñÒâÈí¼þ¡£¡£¡£¡£ ¡£¸Ã»î¶¯ÒÑÐ®ÖÆÁË422±ÊÉúÒâ²¢ÇÔÈ¡ÁË1.3±ÈÌØ±Ò£¨Ô¼54000ÃÀÔª£©¡£¡£¡£¡£ ¡£


https://www.bleepingcomputer.com/news/security/hackers-steal-from-hackers-by-pushing-fake-malware-on-forums/


VolexityÐû²¼ÐÂGimmickÃé×¼macOSÓû§µÄÆÊÎö±¨¸æ


3ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬£¬Çå¾²¹«Ë¾VolexityÐû²¼ÁËжñÒâÈí¼þGimmickÃé×¼macOSÓû§µÄÆÊÎö±¨¸æ¡£¡£¡£¡£ ¡£´Ë´Î»î¶¯×îÏÈÓÚ2021Äêµ×£¬£¬£¬£¬£¬£¬£¬À´×ÔÓÚStorm CloudÍŻ¡£¡£¡£ ¡£¸ÃmacOS±äÌåÖ÷ҪʹÓÃObjective C±àд£¬£¬£¬£¬£¬£¬£¬¶øWindows°æ±¾Ê¹ÓÃÁË.NETºÍDelphi¡£¡£¡£¡£ ¡£ÀÖ³É×°Öú󣬣¬£¬£¬£¬£¬£¬Gimmick¿ÉÒÔ×÷ÎªÊØ»¤³ÌÐòÆô¶¯£¬£¬£¬£¬£¬£¬£¬Ò²¿ÉÒÔÒÔ¶¨ÖÆÓ¦ÓóÌÐòµÄÐÎʽÆô¶¯£¬£¬£¬£¬£¬£¬£¬²¢±»ÉèÖÃΪ½öÔÚÊÂÇéÈÕÓëC2¾ÙÐÐͨѶ¡£¡£¡£¡£ ¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬Ëü»¹¾ßÓÐ×ÔÎÒÐ¶ÔØ¹¦Ð§£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔ½«×Ô¼º´ÓÄ¿µÄ×°±¸ÉÑþ³Øý¡£¡£¡£¡£ ¡£


https://www.volexity.com/blog/2022/03/22/storm-cloud-on-the-horizon-gimmick-malware-strikes-at-macos/




Çå¾²¹¤¾ß


catalyst


ÊÇÒ»¸ö SOAR ϵͳ£¬£¬£¬£¬£¬£¬£¬¿É×Ô¶¯»¯¾¯±¨´¦Öóͷ£ºÍÊÂÎñÏìÓ¦Á÷³Ì¡£¡£¡£¡£ ¡£


https://catalyst-soar.com/


Auto-Elevate


ÇÔÈ¡²¢Ä£ÄâÆäÀú³Ì TOKEN£¬£¬£¬£¬£¬£¬£¬²¢Ê¹Óñ»µÁÁîÅÆÌìÉúÒ»¸öÐ嵀 SYSTEM ¼¶Àú³Ì


https://github.com/FULLSHADE/Auto-Elevate


ICMP-TransferTools


ÊÇÒ»×é¾ç±¾£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÔÚÊÜÏÞÍøÂçÇéÐÎÖн«ÎļþÒÆÈëºÍÒÆ³ö Windows Ö÷»ú¡£¡£¡£¡£ ¡£


https://github.com/icyguider/ICMP-TransferTools


HTTP Smuggling Calculator


ͨ¹ý×Ô¶¯ÖÆ×÷ HTTP ÇëÇóÀ´Ö´ÐÐ CL.TE ºÍ TE.CL HTTP ÇëÇó×ß˽¹¥»÷¡£¡£¡£¡£ ¡£


https://github.com/kleiton0x00/HTTP-Smuggling-Calculator




Çå¾²ÆÊÎö


FBI£º2021 ÄêÒòÍøÂç·¸·¨Ëðʧ 69 ÒÚÃÀÔª


https://therecord.media/fbi-6-9-billion-lost-through-internet-crimes-in-2021/


ÃÀ¹úÆðËß¶íÂÞ˹Igor DekhtyarchukÔËÓª°µÍøÂÛ̳ 


https://www.bleepingcomputer.com/news/security/fbi-adds-russian-cybercrime-market-owner-to-most-wanted-list/


¶íÂÞ˹½ûÓùȸèÐÂÎÅ


https://www.bleepingcomputer.com/news/technology/russia-bans-google-news-for-unreliable-info-on-war-in-ukraine/


Microsoft PowerToys ÖÐÖ¹ Outlook PDF Ô¤ÀÀ


https://www.bleepingcomputer.com/news/microsoft/microsoft-powertoys-breaks-outlook-pdf-preview/


΢ÈíÐÞ¸´Á˵¼Ö Windows À¶ÆÁµÄÀ¶ÑÀÎÊÌâ


https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-bluetooth-issue-causing-windows-blue-screens/


Anonymous Ìᳫ´ó¹æÄ£µÄ¡°Ó¡Ë¢¹¥»÷¡±


https://www.hackread.com/anonymous-hacks-unsecured-printers-message-russia/