Cado SecurityÌåÏÖ½©Ê¬ÍøÂçAbcbotÓëXantheÓйØÁª
Ðû²¼Ê±¼ä 2022-01-12΢ÈíÐû²¼1ÔÂÖܶþ²¹¶¡£¬ÐÞ¸´6¸ö0 dayÔÚÄÚµÄ97¸ö©¶´
1ÔÂ11ÈÕ£¬Î¢ÈíÐû²¼Á˱¾Äê¶ÈµÄÊ׸öÖܶþ²¹¶¡£¬×ܼÆÐÞ¸´97¸öÄþ¾²Â©¶´£¨²»°üÂÞ29¸öMicrosoft Edge©¶´£©¡£´Ë´ÎÐÞ¸´µÄ×îÑÏÖØµÄÊÇHTTPÐÒéÕ»Ô¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2022-21907£©£¬CVSSÆÀ·ÖΪ9.8£¬¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâÊý¾Ý°üµ½Ä¿±ê·þÎñÆ÷À´ÀûÓøÃ©¶´¡£´ËÍ⣬¸üл¹ÐÞ¸´ÁË6¸ö0 day£¬°üÂÞ¿ªÔ´Curl¿âÖеÄRCE£¨CVE-2021-22947£©¡¢¿ªÔ´ Libarchive¿âÖеÄRCE£¨CVE-2021-36976£©ºÍµ±µØWindowsÄþ¾²ÖÐÐÄAPIÖеÄRCE£¨CVE-2022-21874£©µÈ¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-january-2022-patch-tuesday-fixes-6-zero-days-97-flaws/
EDPSÒªÇóÅ·ÖÞÐ̾¯×é֯ɾ³ýÓë·¸×ï»î¶¯Î޹صĸöÈËÊý¾Ý
¾ÝýÌå1ÔÂ10ÈÕ±¨µÀ£¬Å·ÃËÊý¾Ý±£»¤¼à¹Ü»ú¹¹EDPSÏÂÁîÒªÇóÅ·ÖÞÐ̾¯×é֯ɾ³ýÓë·¸×ï»î¶¯Î޹صĸöÈËÊý¾Ý¡£Õþ¸®Ö¸³ö£¬ÔÚûÓÐÊý¾ÝÖ÷Ìå·ÖÀàµÄÇé¿öÏ´洢´óÁ¿Êý¾Ý»á¶Ô¸öÈ˵Ļù±¾È¨Àû×é³É·çÏÕ£¬Ï൱ÓÚ´ó¹æÄ£¼àÊÓ¡£¾Ý¡¶ÎÀ±¨¡·±¨µÀ£¬»º´æÖÁÉÙ°üÂÞ4 PB¡£EDPS»¹¹æ¶¨ÁËÁù¸öÔµı£ÁôÆÚ£¬ÒÔ¹ýÂ˺ÍÌáÈ¡¸öÈËÊý¾Ý£¬²¢¸øÓè¸Ã¿ç¾³Ö´·¨»ú¹¹Ò»ÄêµÄʱ¼äÀ´Éó²éÆäÊý¾Ý¿â¡£
https://thehackernews.com/2022/01/europol-ordered-to-delete-data-of.html
WordPressÐû²¼¸üУ¬ÐÞ¸´SQL×¢ÈëµÈ4¸öÄþ¾²Â©¶´
ýÌå1ÔÂ11ÈÕ±¨µÀ£¬WordPressÐû²¼¸üУ¬×ܼÆÐÞ¸´4¸öÄþ¾²Â©¶´¡£´Ë´ÎÐÞ¸´µÄ©¶´°üÂÞSQL×¢Èë©¶´£¨CVE-2022-21661£©£¬¿Éͨ¹ýʹÓÃWP-QueryµÄ²å¼þºÍÖ÷ÌâÀûÓã»XSS©¶´£¨CVE-2022-21662£©£¬¿ÉÓÃÀ´Ö²ÈëºóÃÅ»òͨ¹ýÀÄÓÃpost slugÀ´¿ØÖÆÍøÕ¾£»SQL×¢Èë©¶´£¨CVE-2022-21664£©£¬¿Éͨ¹ýWP_Meta_QueryÀûÓ㻹¤¾ß×¢Èë©¶´£¨CVE-2022-21663£©£¬ÐèÒªÈëÇÖ¹ÜÀíÔ±ÕÊ»§²ÅÆøÀûÓá£
https://securityaffairs.co/wordpress/126556/security/wordpress-5-8-3.html
΢ÈíÅû¶macOS©¶´powerdir(CVE-2021-30970)ϸ½Ú
1ÔÂ10ÈÕ£¬Î¢ÈíÐû²¼¹ØÓÚmacOSÖеÄ©¶´powerdir(CVE-2021-30970)µÄ·ÖÎö³ÂËß¡£Î¢ÈíÌåÏÖ£¬¹¥»÷Õß¿ÉÒÔÀûÓøÃ©¶´Èƹý͸Ã÷¡¢Í¬ÒâºÍ¿ØÖÆ(TCC)¼¼ÊõÀ´·ÃÎÊÓû§µÄÊý¾Ý¡£Ñо¿ÈËÔ±·¢ÏÖ£¬¿ÉÒÔͨ¹ý±à³ÌµÄ·½Ê½¸Ä¶¯Ä¿±êÓû§Ö÷Ŀ¼²¢Ö²ÈëαTCCÊý¾Ý¿â£¬¹¥»÷Õß¿ÉÀûÓøÃ©¶´Æ¾¾ÝÓû§Êܱ£»¤µÄ¸öÈËÊý¾Ý³ïı¹¥»÷¡£Î¢ÈíÍŶÓÔÚ2021Äê7ÔÂ15ÈÕ½«Â©¶´³ÂË߸øApple¹«Ë¾£¬AppleÔÚ12ÔÂ13ÈÕÐû²¼µÄÄþ¾²¸üÐÂÖÐÐÞ¸´¡£
https://www.microsoft.com/security/blog/2022/01/10/new-macos-vulnerability-powerdir-could-lead-to-unauthorized-user-data-access/
Cado SecurityÌåÏÖ½©Ê¬ÍøÂçAbcbotÓëXantheÓйØÁª
Cado SecurityÔÚ1ÔÂ10ÈÕÐû²¼µÄ³ÂËßÏÔʾ£¬½©Ê¬ÍøÂçAbcbotÓëXantheÓйØÁª¡£AbcbotÔÚ2021Äê11ÔÂÊ״α»¹ûÈ»£¬Æäʱ¹¥»÷ÁË»ªÎª¡¢ÌÚѶ¡¢°Ù¶ÈºÍ°¢ÀïÔÆµÈÔÆ·þÎñÌṩÉÌ¡£µ«Í¨¹ýËùÓÐÒÑÖªµÄIoCs£¬°üÂÞIPµØÖ·¡¢urlºÍÑù±¾£¬·¢ÏÖAbcbotµÄ´úÂëºÍ»ù´¡ÉèÊ©ÓëÒ»¸öÃûΪXantheµÄ¼ÓÃܽٳֶñÒâÈí¼þ¼Ò×åÓÐÖØµþ¡£Ñо¿ÍŶÓÈÏΪ¶þÕßÓÉͬһ¹¥»÷ÕßÂôÁ¦£¬¶øÇÒËûÃÇÕý½«Ä¿±ê´ÓÍÚ¿ó×ªÒÆµ½Óë½©Ê¬ÍøÂçÏà¹ØµÄ»î¶¯¡£
https://www.cadosecurity.com/abcbot-an-evolution-of-xanthe/
Check Point³Æ2021ÄêÍøÂç¹¥»÷»î¶¯Í¬±ÈÔö¼Ó50%
1ÔÂ10ÈÕ£¬Check Point researchÐû²¼³ÂËß³Æ2021ÄêÍøÂç¹¥»÷»î¶¯Í¬±ÈÔö¼Ó50%¡£³ÂËß»¹Ö¸³ö£¬ÔÚ2021ÄêµÚËļ¾¶È£¬Ã¿¸ö×éÖ¯µÄÿÖÜÔâµ½µÄ¹¥»÷´ÎÊýµ½´ïÀúÊ·×î¸ß£¬Æ½¾ùΪ925´Î¡£2021Ä꣬½ÌÓýºÍÑо¿ÐÐÒµÊÇÔâµ½¹¥»÷×î¶àµÄÐÐÒµ£¬Æ½¾ùÿÖÜ1605´Î¹¥»÷£¬Õâ±È2020ÄêÔö¼ÓÁË75%¡£°´µØÓò»®·Ö£¬·ÇÖÞÔâµ½¹¥»÷×î¶à£¬Æ½¾ùÿÖÜ1582´Î£¬±È2020ÄêÔö¼Ó13%£¬½ôËæÆäºóµÄÊÇÑÇÌ«µØÓò£¬Ã¿ÖÜÔâµ½1353´Î¹¥»÷£¨Ôö¼Ó25%£©¡£
https://blog.checkpoint.com/2022/01/10/check-point-research-cyber-attacks-increased-50-year-over-year/
Äþ¾²¹¤¾ß
Mortar
MortarÄܹ»ÈƹýÏÖ´ú·´²¡¶¾²úÎïºÍÏȽøµÄXDR½â¾ö·½°¸£¬°üÂÞKaspersky¡¢ESETºÍMcafeeµÈ¡£
https://www.kitploit.com/2022/01/mortar-evasion-technique-to-defeat-and.html
RecoverPy
¿ÉÓÃÀ´»Ö¸´±»ÁýÕÖ»òɾ³ýµÄÊý¾Ý£¬Ä¿Ç°½öÔÚLinuxϵͳÉÏ¿ÉÓá£
https://github.com/PabloLec/RecoverPy
Äþ¾²·ÖÎö
Linux Mint 20.3 Ðû²¼
Linux Mint Ðû²¼ÁË 20.3 °æ£¬´úºÅΪ¡°Una¡±£¬×÷Ϊºã¾ÃÖ§³Ö°æ±¾£¬²¢ÔÊÐíÔÚ 2025 ÄêÄê֮ǰÄþ¾²¸üС£
https://www.bleepingcomputer.com/news/linux/linux-mint-203-released-promising-security-updates-until-2025/
ÀÕË÷Èí¼þAvosLocker Õë¶Ô VMware ESXi ·þÎñÆ÷
AvosLockerÔÚÆä×î½üµÄ¶ñÒâÈí¼þ±äÖÖÖÐÔö¼ÓÁË¶Ô Linux ϵͳµÄÖ§³Ö£¬ÌرðÊÇÕë¶Ô VMware ESXi ÐéÄâ»ú¡£
https://www.bleepingcomputer.com/news/security/linux-version-of-avoslocker-ransomware-targets-vmware-esxi-servers/