OutlookÓÊÏä¹ýÂËÆ÷·ºÆðÎÊÌâµ¼ÖÂÓû§ÊÕµ½´ó×ÚÀ¬»øÓʼþ

Ðû²¼Ê±¼ä 2023-02-21

1¡¢OutlookÓÊÏä¹ýÂËÆ÷·ºÆðÎÊÌâµ¼ÖÂÓû§ÊÕµ½´ó×ÚÀ¬»øÓʼþ


¾Ý2ÔÂ20ÈÕ±¨µÀ£¬ £¬£¬£¬£¬£¬Ô½À´Ô½¶àµÄMicrosoftÓû§³ÆÆäOutlookÊÕ¼þÏäÔÚÒÑÍù¼¸Ð¡Ê±ÄÚ±»À¬»øÓʼþÑÍû¡£¡£¡£¡£¡£¡£¡£Ò»Î»Óû§ËµÒÑÍùµÄ2СʱÄÚ£¬ £¬£¬£¬£¬£¬ÆäÊÕ¼þÏäÊÕµ½ÁË36·âÀ¬»øÓʼþ¡£¡£¡£¡£¡£¡£¡ £»£»£»£»£»£»£ÉÐÓÐÓû§·´Ó¦£¬ £¬£¬£¬£¬£¬ÔÚÀ¬»øÓʼþ¹ýÂËÆ÷ÖÐÉèÖá°½öÐÅÈÎÀ´×ÔÎÒµÄÇå¾²·¢¼þÈ˺ÍÓòÁбíÒÔ¼°Çå¾²ÓʼþÁбíÖеĵصãµÄµç×ÓÓʼþ¡±Ò²ÎÞ·¨½â¾ö´ËÎÊÌ⣬ £¬£¬£¬£¬£¬ÕâÅú×¢ÓʼþЧÀ͹ýÂËÆ÷¿ÉÄÜÒѱ»ÍêÈ«ÆÆË𡣡£¡£¡£¡£¡£¡£Ö»¹ÜÓû§Í¶ËßÒ»Ö±£¬ £¬£¬£¬£¬£¬µ«OfficeЧÀÍ×´Ì¬Ò³ÃæÈÔÏÔʾһÇÐÕý³£¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬ £¬£¬£¬£¬£¬Microsoft²¢Î´¶Ô´ËÊÂ×÷³ö»ØÓ¦¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-outlook-flooded-with-spam-due-to-broken-email-filters/


2¡¢Ó¡¶È»ð³µ¶©Æ±Æ½Ì¨RailYatriÔ¼3100ÍòÈËÐÅÏ¢ÔÚ°µÍø¹ûÕæ


ýÌå2ÔÂ20Èճƣ¬ £¬£¬£¬£¬£¬Ó¡¶È»ð³µ¶©Æ±Æ½Ì¨RailYatriÔâµ½ºÚ¿Í¹¥»÷£¬ £¬£¬£¬£¬£¬31062673¸öÓο͵ÄÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚ2022Äê12Ô£¬ £¬£¬£¬£¬£¬µ«±»µÁÊý¾ÝÖ±µ½ÏÖÔڲű»×ß©µ½ºÚ¿ÍÂÛ̳BreachforumsÉÏ¡£¡£¡£¡£¡£¡£¡£ÔçÔÚ2020Äê2Ô£¬ £¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öÉèÖùýʧµÄElasticsearchЧÀÍÆ÷ÊôÓÚRailYatri£¬ £¬£¬£¬£¬£¬ÔÚÓ¡¶ÈCERT-In½éÈëºó¸Ã¹«Ë¾²ÅÏë·¨± £»£»£»£»£»£»£»¤ÆäÊý¾Ý¡£¡£¡£¡£¡£¡£¡£È»¶øÁ½Äêºó£¬ £¬£¬£¬£¬£¬¸Ã¹«Ë¾Ôٴα¬·¢Êý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÒÔΪ£¬ £¬£¬£¬£¬£¬RailYatri±¾¿ÉÒÔ×èÖ¹´Ë´ÎÊý¾Ýй¶ÊÂÎñ£¬ £¬£¬£¬£¬£¬ÈôÊÇËü´ÓÒ»×îÏȾÍʵÑéÊʵ±µÄÍøÂçÇå¾²Õ½ÂÔ¡£¡£¡£¡£¡£¡£¡£


https://www.hackread.com/indian-ticketing-platform-railyatri-hacked/


3¡¢Earth KitsuneÍÅ»ïͨ¹ýË®¿Ó¹¥»÷·Ö·¢ÐµÄWhiskerSpy


2ÔÂ17ÈÕ£¬ £¬£¬£¬£¬£¬Trend Micro³ÆÆä·¢Ã÷ÁËEarth KitsuneÍÅ»ïͨ¹ýË®¿Ó¹¥»÷·Ö·¢WhiskerSpyµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£2022Äêµ×£¬ £¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷Ò»¸öÓ볯ÏÊÏà¹Ø×éÖ¯µÄÍøÕ¾Ôâµ½ÈëÇÖ£¬ £¬£¬£¬£¬£¬²¢±»¸Ä¶¯ÒÔÈö²¥¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£µ±»á¼ûÕßÔÚÍøÕ¾ÉÏԢĿÊÓÆµÊ±£¬ £¬£¬£¬£¬£¬¹¥»÷Õß×¢ÈëµÄ¶ñÒâ¾ç±¾»áÏÔʾһÌõÐÂÎÅÌáÐÑ֪ͨËûÃÇÊÓÆµ±à½âÂëÆ÷¹ýʧ£¬ £¬£¬£¬£¬£¬À´ÓÕʹËûÃÇÏÂÔØ²¢×°ÖÃľÂí»¯µÄ±à½âÂëÆ÷×°ÖóÌÐò¡£¡£¡£¡£¡£¡£¡£¸Ã×°ÖóÌÐò»á¼ÓÔØÒ»¸öеĺóÃÅWhiskerSpy¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬£¬£¬¸Ã»î¶¯Ê¹Óõij¤ÆÚÐÔÊÖÒÕÀÄÓÃÁËGoogle ChromeµÄ±¾»úÐÂÎÅת´ïÖ÷»ú£¬ £¬£¬£¬£¬£¬²¢×°ÖÃÃûΪGoogle Chrome HelperµÄ¶ñÒâÀ©Õ¹¡£¡£¡£¡£¡£¡£¡£


https://www.trendmicro.com/en_us/research/23/b/earth-kitsune-delivers-new-whiskerspy-backdoor.html


4¡¢Check PointÅû¶Õë¶ÔÑÇÃÀÄáÑÇ×éÖ¯µÄÐÂÒ»ÂÖ¹¥»÷»î¶¯


Check PointÔÚ2ÔÂ16ÈÕÅû¶ÁË2022ÄêβÕë¶ÔÑÇÃÀÄáÑÇ×éÖ¯µÄÐÂÒ»ÂÖ¹¥»÷»î¶¯£¬ £¬£¬£¬£¬£¬Ö÷Òª·Ö·¢ºóÃÅOxtaRAT¡£¡£¡£¡£¡£¡£¡£OxtaRATÊÇÒ»ÖÖ»ùÓÚAutoItµÄÔ¶³Ì»á¼ûºÍ×ÀÃæ¼à¿Ø¹¤¾ß£¬ £¬£¬£¬£¬£¬Ëü¿ÉÒÔ´Ó±»Ñ¬È¾µÄÅÌËã»úÖÐËÑË÷ºÍй¶Îļþ¡¢´ÓÍøÂçÉãÏñÍ·ºÍ×ÀÃæÂ¼ÖÆÊÓÆµ¡¢Ê¹ÓÃTightVNCÔ¶³Ì¿ØÖƱ»Ñ¬È¾µÄ×°±¸¡¢×°ÖÃweb shellºÍÖ´Ðж˿ÚɨÃèµÈ¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬ £¬£¬£¬£¬£¬Óë¸ÃÍÅ»ï֮ǰµÄ»î¶¯Ïà±È£¬ £¬£¬£¬£¬£¬2022Äê11ÔÂ×îлµÄѬȾÁ´±¬·¢ÁËת±ä£¬ £¬£¬£¬£¬£¬½ÓÄÉÁËÌá¸ß²Ù×÷Çå¾²ÐԵIJ½·¥£¬ £¬£¬£¬£¬£¬ÒÔ¼°Ê¹ÓÃË¢ÐÂÇÔÈ¡Êý¾Ý·½·¨µÄй¦Ð§¡£¡£¡£¡£¡£¡£¡£


https://research.checkpoint.com/2023/operation-silent-watch-desktop-surveillance-in-azerbaijan-and-armenia/


5¡¢ºÚ¿ÍʹÓÃľÂí»¯×°ÖóÌÐòÕë¶Ô¶«ÑǺͶ«ÄÏÑÇÈö²¥FatalRAT 


¾ÝESET 2ÔÂ16ÈÕ±¨µÀ£¬ £¬£¬£¬£¬£¬ºÚ¿Íͨ¹ý¹È¸èËÑË÷Ч¹ûÖеÄÎóµ¼ÐÔ¹ã¸æ£¬ £¬£¬£¬£¬£¬ÓÕʹĿµÄÏÂÔØÄ¾Âí»¯×°ÖóÌÐò¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚ2022Äê8ÔÂÖÁ2023Äê1ÔÂÊӲ쵽ÕâЩ¹¥»÷£¬ £¬£¬£¬£¬£¬µ«Æ¾Ö¤Ò£²âÊý¾Ý£¬ £¬£¬£¬£¬£¬ÖÁÉÙ´Ó2022Äê5Ô¾Í×îÏÈʹÓÃÏÈǰ°æ±¾µÄ×°ÖóÌÐò¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷Ö÷ÒªÕë¶Ô¶«ÄÏÑǺͶ«Ñǽ²ÖÐÎĵÄÈË£¬ £¬£¬£¬£¬£¬Í¨¹ý½¨ÉèÓëFirefox¡¢WhatsApp»òTelegramµÈÊ¢ÐÐÓ¦ÓÃÏàͬµÄÐéÎ±ÍøÕ¾£¬ £¬£¬£¬£¬£¬·Ö·¢¶ñÒâÈí¼þFatalRAT¡£¡£¡£¡£¡£¡£¡£FatalRAT¿É²¶»ñ»÷¼ü¡¢¸ü¸ÄÄ¿µÄµÄÆÁÄ»Çø·ÖÂÊ¡¢ÏÂÔØºÍÖ´ÐÐÎļþµÈ£¬ £¬£¬£¬£¬£¬ËüÓë2021Ä걨¸æµÄ°æ±¾ºÜÊÇÏàËÆ¡£¡£¡£¡£¡£¡£¡£


https://www.welivesecurity.com/2023/02/16/these-arent-apps-youre-looking-for-fake-installers/


6¡¢KasperskyÐû²¼¹ØÓÚ2022ÄêÀ¬»øÓʼþºÍ´¹ÂڻµÄ±¨¸æ


2ÔÂ16ÈÕ£¬ £¬£¬£¬£¬£¬KasperskyÐû²¼Á˹ØÓÚ2022ÄêÀ¬»øÓʼþºÍ´¹ÂڻµÄ±¨¸æ¡£¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬ £¬£¬£¬£¬£¬ÔÚ2022Ä꣬ £¬£¬£¬£¬£¬È«Çò48.63%µÄÓʼþÊÇÀ¬»øÓʼþ£¬ £¬£¬£¬£¬£¬±ÈÉÏÒ»ÄêÔöÌí3.07¸ö°Ù·Öµã¡£¡£¡£¡£¡£¡£¡£À¬»øÓʼþ×î¶àµÄÔ·ÝÊÇ2Ô£¬ £¬£¬£¬£¬£¬Õ¼±ÈΪ52.78%¡£¡£¡£¡£¡£¡£¡£¶à´ï29.82%µÄÀ¬»øÓʼþÀ´×Ô¶íÂÞ˹£¬ £¬£¬£¬£¬£¬Æä´ÎÊǵ¹ú£¨29.82%£©¡£¡£¡£¡£¡£¡£¡£Ôâµ½´¹ÂÚ¹¥»÷×î¶àµÄ¹ú¼ÒÊÇÔ½ÄÏ(17.03%)£¬ £¬£¬£¬£¬£¬Æä´ÎÊǰÄÃÅ£¨13.88%£©ºÍÂí´ï¼Ó˹¼Ó£¨12.04%£©¡£¡£¡£¡£¡£¡£¡£´ó´ó¶¼´¹ÂÚÒ³Ãæ¶¼ÍйÜÔÚCOMÓò£¨17.69%£©£¬ £¬£¬£¬£¬£¬È»ºóÊÇXYZ(8.79%)¡£¡£¡£¡£¡£¡£¡£ÊÜ´ËÀ๥»÷×î¶àµÄÐÐҵΪ¿ìµÝ¹«Ë¾£¨27.38%£©£¬ £¬£¬£¬£¬£¬ÔÚÏßÊÐËÁ£¨15.56%£©ºÍÖ§¸¶ÏµÍ³£¨10.39%£©´ÎÖ®¡£¡£¡£¡£¡£¡£¡£


https://securelist.com/spam-phishing-scam-report-2022/108692/