΢ÈíÐû²¼5Ô·ݲ¹¶¡ £¬ÐÞ¸´°üÀ¨3¸ö0dayÔÚÄÚµÄ75¸öÎó²î

Ðû²¼Ê±¼ä 2022-05-11
1¡¢Î¢ÈíÐû²¼5Ô·ݲ¹¶¡ £¬ÐÞ¸´°üÀ¨3¸ö0dayÔÚÄÚµÄ75¸öÎó²î


5ÔÂ10ÈÕ £¬Î¢ÈíÐû²¼Á˱¾ÔµÄÖܶþ²¹¶¡ £¬×ܼÆÐÞ¸´ÁË75¸öÎó²î £¬ÆäÖÐÒ»¸öÒѱ»Ê¹Óᣴ˴θüÐÂÐÞ¸´ÁË3¸ö0 dayÎó²î £¬»®·ÖΪWindows LSAÓÕÆ­Îó²î£¨CVE-2022-26925£© £¬¿Éͨ¹ýŲÓÃLSARPC½Ó¿ÚÉϵÄÒªÁì²¢Ç¿ÖÆÓò¿ØÖÆÆ÷ʹÓÃNTLM¾ÙÐÐÉí·ÝÑéÖ¤ £¬Òѱ»Æð¾¢Ê¹Óã»Windows Hyper-V¾Ü¾ø·þÎñÎó²î£¨CVE-2022-22713£©£»Magnitude Simba Amazon Redshift ODBCÇý¶¯³ÌÐòÖеÄÎó²î£¨CVE-2022-29972£©¡£±ðµÄ £¬»¹ÐÞ¸´ÁËÔ¶³Ì×ÀÃæ¿Í»§¶ËRCEÎó²î£¨CVE-2022-22017£©ºÍActive DirectoryÓò·þÎñÌØÈ¨ÌáÉýÎó²î£¨CVE-2022-26923£©µÈ¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-may-2022-patch-tuesday-fixes-3-zero-days-75-flaws/


2¡¢´÷¶û¡¢Æ»¹ûºÍNetflixÒò½«·þÎñ³·³ö¶íÂÞ˹¶øÃæÁÙËßËÏ


¾Ý5ÔÂ9ÈÕ±¨µÀ £¬ÔÚ´÷¶û¹«Ë¾Î´ÄÜÏòÍâµØÏµÍ³¼¯³ÉÉÌÌṩ¸¶·Ñ·þÎñºó £¬ÄªË¹¿ÆÖٲ÷¨ÔºÃ»ÊÕÁËÊôÓڸù«Ë¾µÄ½ü1100ÍòÃÀÔª¡£¾ÝϤ £¬ÊÇITϵͳ¼¯³ÉÉÌTalmerÔÚÉÏÔ³õÆðËßÁË´÷¶û £¬Ôµ¹ÊÔ­ÓÉÊǸù«Ë¾ÊÂÏÈÒÑÏò´÷¶ûÖ§¸¶ÁË·þÎñÓÃ¶È £¬µ«Î´»ñµÃÕâЩ·þÎñ¡£ÉϸöÔÂÄ© £¬Æ»¹û¹«Ë¾ÓÉÓڴӸùú×÷·ÏÁËÆäÖ§¸¶·þÎñApple Pay £¬Ò²ÃæÁÙÀàËÆµÄÖ´·¨ÎÊÌâ £¬ÒªÇóÅâ³¥9000Íò¬²¼£¨Ô¼129ÍòÃÀÔª£©¡£NetflixÔÚ4ÔÂÒòÀàËÆµÄÎ¥·´Óû§Ìõ¿îµÄÔµ¹ÊÔ­ÓÉÔâµ½ÕûÌåËßËÏ £¬ÒªÇóÅâ³¥6000Íò¬²¼£¨86ÍòÃÀÔª£©¡£


https://www.bleepingcomputer.com/news/technology/dell-apple-netflix-face-lawsuits-for-pulling-services-out-of-russia/


3¡¢KasperskyÔÚGoogle Play¼ì²âµ½¶à¸öѬȾJokerµÄÓ¦ÓÃ


¾ÝKasperskyÔÚ5ÔÂ6ÈÕÐû²¼µÄ±¨¸æ £¬Google PlayÖб£´æ¶à¸öѬȾÁËJokerµÄÓ¦Óá£Trojan.AndroidOS.JockerϵÁÐľÂí¿ÉÒÔ×èµ²¶ÌÐÅÖз¢Ë͵ĴúÂë²¢ÈÆ¹ý·´Ú²Æ­½â¾ö¼Æ»® £¬ËüÃÇͨ³£ÔÚ Google PlayÉÏÈö²¥¡£¹¥»÷ÕßÏÈÏÂÔØÕýµ±Ó¦Óò¢ÏòÆäÖÐÌí¼Ó¶ñÒâ´úÂë £¬ÔÙÒÔ²î±ðµÄÃû³ÆÖØÐÂÉÏ´«µ½Google Play¡£´Ë´Î·¢Ã÷µÄ±»Ñ¬È¾Ó¦Óû®·ÖΪStyle Message¡¢Blood Pressure AppºÍCamera PDF Scanner¡£ÏÖÔÚËüÃÇÒÑ´ÓGoogle PlayÖÐÒÆ³ý £¬µ«ÈÔ¿É´ÓµÚÈý·½Æ½Ì¨»ñµÃ¡£


https://securelist.com/mobile-subscription-trojans-and-their-tricks/106412/


4¡¢ÎÚ¿ËÀ¼CERT-UA·¢Ã÷Ö¼ÔÚ·Ö·¢JesterµÄ´ó¹æÄ£´¹ÂÚÔ˶¯


ýÌå5ÔÂ9ÈÕ±¨µÀ £¬ÎÚ¿ËÀ¼ÅÌËã»úÓ¦¼±ÏìӦС×é(CERT-UA)¼ì²âµ½Èö²¥ÇÔÈ¡¶ñÒâÈí¼þJesterµÄ´ó¹æÄ£´¹ÂÚÔ˶¯¡£´¹ÂÚÓʼþÒÔ¡°»¯Ñ§¹¥»÷¡±ÎªÖ÷Ìâ £¬°üÀ¨ÁËÖ¸Ïò¶ñÒâMicrosoft ExcelÎļþµÄÁ´½Ó £¬Ä¿µÄ·­¿ªÎĵµ²¢¼¤»îǶÈëµÄºêºó £¬Ñ¬È¾Àú³Ì×îÏÈ¡£Æ¾Ö¤CERT-UAͨ¸æ £¬¿ÉÖ´ÐÐÎļþÊÇ´Ó±»Ñ¬È¾µÄÍøÕ¾ÏÂÔØµÄ £¬¶ø²»ÊÇÖ±½Ó´Ó¹¥»÷Õß¿ØÖƵĻù´¡ÉèÊ©¡£ÏÖÔÚ £¬Éв»ÇåÎú´Ë´ÎÔ˶¯±³ºó¹¥»÷ÕßµÄÉí·Ý¡£


https://securityaffairs.co/wordpress/131113/breaking-news/cert-ua-warns-jester-stealer-attacks.html


5¡¢BlackBerryÐû²¼¹ØÓÚÁ®¼ÛµÄÉÌÒµRAT DCRatµÄÆÊÎö±¨¸æ


BlackBerryÔÚ5ÔÂ9ÈÕÐû²¼Á˹ØÓÚÉÌÒµRAT DCRat£¨ÓÖ³ÆDarkCrystal RAT£©µÄÆÊÎö±¨¸æ¡£DCRatÊÇÒ»¸ö¹¦Ð§ÆëÈ«µÄºóÃÅ £¬ÊÇ¡°boldenis44¡±ºÍ¡°crystalcoder¡±ÓÃ.NET¿ª·¢µÄ¡£ËüÊÇ×î×ÔÖÆµÄÉÌÒµRATÖ®Ò» £¬ÖÕÉí¶©ÔķѽöΪ4200¬²¼£¨40ÃÀÔª£©¡£¸Ã¶ñÒâÈí¼þÓÉ3¸ö²¿·Ö×é³É£ºÇÔÈ¡Æ÷/¿Í»§¶Ë¿ÉÖ´ÐÐÎļþ¡¢PHPÒ³ÃæºÍ¹ÜÀíÔ±¹¤¾ß £¬¾ßÓмàÊÓ¡¢Õì̽¡¢ÐÅÏ¢ÇÔÈ¡¡¢DDoS¹¥»÷ÒÔ¼°´úÂëÖ´Ðеȹ¦Ð§¡£


https://blogs.blackberry.com/en/2022/05/dirty-deeds-done-dirt-cheap-russian-rat-offers-backdoor-bargains


6¡¢ResecurityÐû²¼¹ØÓÚеÄPhaaS FrappoµÄÊÖÒÕÆÊÎö±¨¸æ


ýÌå5ÔÂ10ÈÕ±¨µÀ £¬Resecurity·¢Ã÷ÁËÒ»ÖÖеÄPhishing-As-A-Service£¨PhaaS£©Frappo¡£¸Ã·þÎñ×îÔçÓÚ2021Äê3ÔÂ22ÈÕ·ºÆð £¬½üÆÚÓÖÌṩÁËÉæ¼°Îª20¶à¼Ò½ðÈÚ»ú¹¹¡¢ÔÚÏßÁãÊÛÉ̺ÍÓŲ½µÈ·þÎñµÄ´¹ÂÚÒ³Ãæ¡£±ðµÄ £¬´¹ÂÚÒ³ÃæµÄ°²ÅÅÀú³ÌÊÇÍêÈ«×Ô¶¯»¯µÄ £¬FrappoʹÓÃÒ»¸öÔ¤ÏÈÉèÖõÄDockerÈÝÆ÷ºÍÒ»¸öÇ徲ͨµÀ £¬ÓÃÀ´Í¨¹ýAPIÍøÂçÆ¾Ö¤¡£Ñо¿Ö°Ô±³Æ £¬ÏñFrappoÕâÑùµÄ´¹ÂÚ¼´·þÎñÒѱ»ÓÃÓÚÕÊ»§½ÓÊÜ¡¢BEC¹¥»÷¡¢Êý¾Ý͵ÇÔµÈÔ˶¯ £¬¹¥»÷ÕßÒ»Ö±ÔÚʹÓÃÏȽøµÄ¹¤¾ßºÍÕ½ÂÔÀ´¹¥»÷È«ÇòµÄÏûºÄÕß¡£  


https://securityaffairs.co/wordpress/131136/cyber-crime/frappo-phishing-as-a-service.html