ÃÀ¹úµ·»ÙSandwormÔËÓªµÄ½©Ê¬ÍøÂçCyclops Blink
Ðû²¼Ê±¼ä 2022-04-11ÃÀ¹úµ·»ÙSandwormÔËÓªµÄ½©Ê¬ÍøÂçCyclops Blink
¾ÝýÌå4ÔÂ6ÈÕ±¨µÀ£¬ÃÀ¹úÒѵ·»ÙÓɶíÂÞ˹ºÚ¿Í×éÖ¯SandwormÔËÓªµÄ½©Ê¬ÍøÂçCyclops Blink¡£Sandworm´Ó2019Äê6ÔÂ×îÏÈʹÓøý©Ê¬ÍøÂ磬Ö÷ҪĿµÄÊÇWatchGuard Firebox·À»ðǽװ±¸ºÍ»ªË¶Â·ÓÉÆ÷¡£´Ë´ÎÖ´·¨Ðж¯ÓÚ2022Äê3ÔÂ18ÈÕ×îÏÈ£¬ÏÖÔÚÒÑÔÚËùÓб»Ñ¬È¾µÄWatchguard×°±¸ÖÐɾ³ý¸Ã¶ñÒâÈí¼þ¡£WatchGuardÐû²¼Á˹ØÓÚ»Ö¸´±»Ñ¬È¾Firebox×°±¸µÄ˵Ã÷£¬»¹¿ª·¢ÁËÒ»Ì×Cyclops Blink¼ì²â¹¤¾ß£¬ÒÔ¼°Cyclops Blink 4²½Õï¶ÏºÍÐÞ¸´ÍýÏë¡£
https://securityaffairs.co/wordpress/129911/cyber-warfare-2/us-disrupts-cyclops-blink-botnet.html
VMwareÐû²¼¸üУ¬ÐÞ¸´Æä²úÆ·ÖеĶà¸öÇå¾²Îó²î
4ÔÂ6ÈÕ£¬VMwareÐû²¼Çå¾²¸üУ¬ÐÞ¸´ÁËVMware Workspace ONE Access¡¢VMware Identity Manager (vIDM)ºÍvRealize Lifecycle ManagerµÈ²úÆ·ÖеÄ8¸öÎó²î¡£ÆäÖаüÀ¨5¸ö½ÏΪÑÏÖØµÄÎó²î£¬»®·ÖΪ·þÎñÆ÷¶ËÄ£°å×¢ÈëÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2022-22954£¬CVSSÆÀ·Ö9.8£©¡¢OAuth2 ACSÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2022-22955ºÍCVE-2022-22956£¬CVSSÆÀ·Ö9.8£©ÒÔ¼°JDBC×¢ÈëÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2022-22957ºÍCVE-2022-22958£¬CVSSÆÀ·Ö9.1£©¡£
https://www.vmware.com/security/advisories/VMSA-2022-0011.html
Cybereason·¢Ã÷AridViperÕë¶ÔÒÔÉ«Áи߼¶¹ÙÔ±µÄÌØ¹¤Ô˶¯
Cybereason NocturnusÍŶÓÔÚ4ÔÂ6ÈÕÐû²¼±¨¸æ£¬ÏêÊöÁËAridViper£¨ÓÖ³ÆAPT-C-23£©µÄÐÂÔ˶¯¡£Ñо¿Ö°Ô±½«´Ë´ÎÌØ¹¤Ô˶¯ÃüÃûΪOperation Bearded Barbie£¬ËüÃé×¼ÒÔÉ«Áйú·À¡¢Ö´·¨ºÍ½ôÆÈ·þÎñ²¿·ÖµÄ¸ß¼¶¹ÙÔ±£¬¼àÊÓÆäÔ˶¯²¢ÇÔÈ¡Êý¾Ý¡£¹¥»÷ÕßʹÓÃÐéαµÄFacebookÕ˺ÅÓÕʹĿµÄÏÂÔØÄ¾Âí£¬²¢Ê¹ÓÃÁËеĶñÒâÈí¼þBarb(ie) DownloaderºÍBarbWire Backdoor£¬ÒÔ¼°VolatileVenomбäÖÖ¡£
https://www.cybereason.com/blog/operation-bearded-barbie-apt-c-23-campaign-targeting-israeli-officials
3¸ö¶ñÒâAndroidÓ¦ÓÃÃé×¼ÂíÀ´Î÷ÑǵĶà¸ö½ðÈÚ»ú¹¹
4ÔÂ6ÈÕ£¬ESETÐû²¼Á˹ØÓÚ3¸ö¶ñÒâAndroidÓ¦ÓõÄÑо¿±¨¸æ¡£¸ÃÔ˶¯×Ô2021Äê11ÔÂ×îÏÈ£¬¹¥»÷Õßͨ¹ýð³äMaid4u¡¢GrabmaidºÍMaria's CleaningµÈ7¸öÕýµ±ÍøÕ¾£¬ÓÕʹÓû§ÏÂÔØ¶ñÒâÓ¦Óã¬ÕâЩӦÓý«Ä¿µÄÊÕµ½µÄËùÓжÌÐÅת·¢µ½¹¥»÷Õߣ¬ÒÔÇÔÈ¡ÒøÐз¢Ë͵Ä2FA´úÂë¡£´Ë´ÎÔ˶¯Ö÷ÒªÕë¶ÔÂíÀ´Î÷ÑǵÄ8¼ÒÒøÐУºMaybank¡¢Affin Bank¡¢Public Bank Berhad¡¢CIMB bank¡¢BSN¡¢RHB¡¢Bank Islam MalaysiaºÍHong Leong Bank¡£
https://www.welivesecurity.com/2022/04/06/fake-eshops-prowl-banking-credentials-android-malware/
NB65Éù³ÆÒÑÇÔÈ¡¶íÂÞ˹¹ã²¥¹«Ë¾VGTRKÔ¼800GBµÄÊý¾Ý
ýÌå4ÔÂ6ÈÕ±¨µÀ£¬NB65(Network Battalion 65)Éù³ÆÒÑÈëÇÖ¶íÂÞ˹µçÊӹ㲥¹«Ë¾VGTRK¡£NB65ÓëAnonymouÓйØÁª£¬VGTRKÊǶíÂÞ˹×î´óµÄýÌ幫˾£¬ÔËÓª×Å5¸ö¹ú¼Òµç̨¡¢2¸ö¹ú¼ÊÍøÂç¡¢5¸ö¹ã²¥µç̨ºÍ80¶à¸öµØÇøµçÊÓºÍ¹ã²¥ÍøÂç¡£NB65ͨ¹ýDDoSecrets¹ûÕæÁËVGTRK 786.2 GBµÄÊý¾Ý£¬ÆäÖаüÀ¨4000¸öÎļþºÍÁè¼Ý900000·âµç×ÓÓʼþ¡£Anonymous»¹ÔÚ3ÔÂ26ÈÕй¶Á˶íÂÞ˹ÖÐÑëÒøÐÐ28GBµÄÊý¾Ý¡£
https://www.hackread.com/anonymous-affiliate-nb65-russia-broadcaster-data-breach/
Google PlayÖÐʹÓÃSDKÍøÂçÐÅÏ¢µÄÓ¦ÓÃÒÑ×°ÖÃ4500Íò´Î
¾Ý4ÔÂ7ÈÕ±¨µÀ£¬AppCensus·¢Ã÷Google PlayÖеĶà¸öÓ¦ÓÃͨ¹ýµÚÈý·½SDKÍøÂçÓû§Êý¾Ý¡£ÕâЩӦÓÃÒÑ×°ÖÃÁè¼Ý4500Íò´Î£¬°üÀ¨Speed Camera RadarºÍAl-Moazin LiteµÈ£¬Ö÷ÒªÇÔÈ¡¼ôÌù°åÄÚÈÝ¡¢GPSÊý¾Ý¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂ룬ÒÔ¼°µ÷ÖÆ½âµ÷Æ÷·ÓÉÆ÷MACµØÖ·ºÍÍøÂçSSID¡£ÍøÂçµ½µÄÊý¾ÝÓÉSDK´«Êäµ½¡°mobile.measurelib.com¡±£¬¸ÃÓòÊôÓÚÒ»¼ÒÃûΪMeasurement SystemsµÄ°ÍÄÃÂíÆÊÎö¹«Ë¾ËùÓС£
https://www.bleepingcomputer.com/news/security/android-apps-with-45-million-installs-used-data-harvesting-sdk/
Çå¾²¹¤¾ß
Rip Raw
ÊÇÒ»¸öÓÃÓÚÆÊÎöÊÜѬȾ Linux ϵͳÄÚ´æµÄС¹¤¾ß¡£
https://github.com/cado-security/rip_raw
Grafiki
¹ØÓÚ Sysmon ºÍͼ±íµÄÍþв׷×Ù¹¤¾ß¡£
https://github.com/lucky-luk3/Grafiki/
Odin
Odin ÊÇ»ùÓÚLokiµÄÖÐÑë IoC ɨÃèÆ÷
https://github.com/Hamza-Megahed/odin
Çå¾²ÆÊÎö
Windows 11 ÄÚ²¿°æ±¾ 22593 ÖеÄÒÑÖªÎÊÌâ
https://news.softpedia.com/news/known-issues-in-windows-11-build-22593-535182.shtml
Mozilla Firefox 99 ÏÖÒѿɹ©ÏÂÔØ
https://news.softpedia.com/news/mozilla-firefox-99-is-now-available-for-download-535180.shtml
΢Èí£º¶à¸ö .NET Framework °æ±¾½«ÓÚ 4 Ô EOL
https://www.bleepingcomputer.com/news/microsoft/microsoft-multiple-net-framework-versions-reach-end-of-life-in-april/
AMDÈ·ÈÏGPUÇý¶¯³ÌÐò¹ýʧδ¾ÔÊÐí³¬ÆµCPU
https://www.bleepingcomputer.com/news/hardware/amd-confirms-gpu-driver-bug-overclocks-cpus-without-permission/
Atlassian Jira£¬Confluence ÖÐÖ¹Ó°ÏìÈ«ÇòÓû§
https://www.bleepingcomputer.com/news/technology/ongoing-atlassian-jira-confluence-outage-affects-customers-worldwide/
Palo Alto Networks ·À»ðǽ¡¢VPN ±£´æ OpenSSL Îó²î
https://www.bleepingcomputer.com/news/security/palo-alto-networks-firewalls-vpns-vulnerable-to-openssl-bug/
FFDroiderÖ¼ÔÚÇÔÈ¡É罻ýÌåÖеÄÐÅÏ¢
https://www.zscaler.com/blogs/security-research/ffdroider-stealer-targeting-social-media-platform-users


¾©¹«Íø°²±¸11010802024551ºÅ