Cado SecurityÌåÏÖ½©Ê¬ÍøÂçAbcbotÓëXantheÓйØÁª

Ðû²¼Ê±¼ä 2022-01-12

΢ÈíÐû²¼1ÔÂÖܶþ²¹¶¡£¬ÐÞ¸´6¸ö0 dayÔÚÄÚµÄ97¸ö©¶´


½ØÍ¼20220112121945.png


1ÔÂ11ÈÕ£¬Î¢ÈíÐû²¼Á˱¾Äê¶ÈµÄÊ׸öÖܶþ²¹¶¡£¬×ܼÆÐÞ¸´97¸öÄþ¾²Â©¶´£¨²»°üÂÞ29¸öMicrosoft Edge©¶´£© ¡£´Ë´ÎÐÞ¸´µÄ×îÑÏÖØµÄÊÇHTTPЭÒéÕ»Ô¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2022-21907£©£¬CVSSÆÀ·ÖΪ9.8£¬¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâÊý¾Ý°üµ½Ä¿±ê·þÎñÆ÷À´ÀûÓøÃ©¶´ ¡£´ËÍ⣬¸üл¹ÐÞ¸´ÁË6¸ö0 day£¬°üÂÞ¿ªÔ´Curl¿âÖеÄRCE£¨CVE-2021-22947£©¡¢¿ªÔ´ Libarchive¿âÖеÄRCE£¨CVE-2021-36976£©ºÍµ±µØWindowsÄþ¾²ÖÐÐÄAPIÖеÄRCE£¨CVE-2022-21874£©µÈ ¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-january-2022-patch-tuesday-fixes-6-zero-days-97-flaws/


EDPSÒªÇóÅ·ÖÞÐ̾¯×é֯ɾ³ýÓë·¸×ï»î¶¯Î޹صĸöÈËÊý¾Ý


¾ÝýÌå1ÔÂ10ÈÕ±¨µÀ£¬Å·ÃËÊý¾Ý±£»¤¼à¹Ü»ú¹¹EDPSÏÂÁîÒªÇóÅ·ÖÞÐ̾¯×é֯ɾ³ýÓë·¸×ï»î¶¯Î޹صĸöÈËÊý¾Ý ¡£Õþ¸®Ö¸³ö£¬ÔÚûÓÐÊý¾ÝÖ÷Ìå·ÖÀàµÄÇé¿öÏ´洢´óÁ¿Êý¾Ý»á¶Ô¸öÈ˵Ļù±¾È¨Àû×é³É·çÏÕ£¬Ï൱ÓÚ´ó¹æÄ£¼àÊÓ ¡£¾Ý¡¶ÎÀ±¨¡·±¨µÀ£¬»º´æÖÁÉÙ°üÂÞ4 PB ¡£EDPS»¹¹æ¶¨ÁËÁù¸öÔµı£ÁôÆÚ£¬ÒÔ¹ýÂ˺ÍÌáÈ¡¸öÈËÊý¾Ý£¬²¢¸øÓè¸Ã¿ç¾³Ö´·¨»ú¹¹Ò»ÄêµÄʱ¼äÀ´Éó²éÆäÊý¾Ý¿â ¡£


https://thehackernews.com/2022/01/europol-ordered-to-delete-data-of.html


WordPressÐû²¼¸üУ¬ÐÞ¸´SQL×¢ÈëµÈ4¸öÄþ¾²Â©¶´


ýÌå1ÔÂ11ÈÕ±¨µÀ£¬WordPressÐû²¼¸üУ¬×ܼÆÐÞ¸´4¸öÄþ¾²Â©¶´ ¡£´Ë´ÎÐÞ¸´µÄ©¶´°üÂÞSQL×¢Èë©¶´£¨CVE-2022-21661£©£¬¿Éͨ¹ýʹÓÃWP-QueryµÄ²å¼þºÍÖ÷ÌâÀûÓã»XSS©¶´£¨CVE-2022-21662£©£¬¿ÉÓÃÀ´Ö²ÈëºóÃÅ»òͨ¹ýÀÄÓÃpost slugÀ´¿ØÖÆÍøÕ¾£»SQL×¢Èë©¶´£¨CVE-2022-21664£©£¬¿Éͨ¹ýWP_Meta_QueryÀûÓ㻹¤¾ß×¢Èë©¶´£¨CVE-2022-21663£©£¬ÐèÒªÈëÇÖ¹ÜÀíÔ±ÕÊ»§²ÅÆøÀûÓà ¡£


https://securityaffairs.co/wordpress/126556/security/wordpress-5-8-3.html


΢ÈíÅû¶macOS©¶´powerdir(CVE-2021-30970)ϸ½Ú


1ÔÂ10ÈÕ£¬Î¢ÈíÐû²¼¹ØÓÚmacOSÖеÄ©¶´powerdir(CVE-2021-30970)µÄ·ÖÎö³ÂËß ¡£Î¢ÈíÌåÏÖ£¬¹¥»÷Õß¿ÉÒÔÀûÓøÃ©¶´Èƹý͸Ã÷¡¢Í¬ÒâºÍ¿ØÖÆ(TCC)¼¼ÊõÀ´·ÃÎÊÓû§µÄÊý¾Ý ¡£Ñо¿ÈËÔ±·¢ÏÖ£¬¿ÉÒÔͨ¹ý±à³ÌµÄ·½Ê½¸Ä¶¯Ä¿±êÓû§Ö÷Ŀ¼²¢Ö²ÈëαTCCÊý¾Ý¿â£¬¹¥»÷Õß¿ÉÀûÓøÃ©¶´Æ¾¾ÝÓû§Êܱ£»¤µÄ¸öÈËÊý¾Ý³ïı¹¥»÷ ¡£Î¢ÈíÍŶÓÔÚ2021Äê7ÔÂ15ÈÕ½«Â©¶´³ÂË߸øApple¹«Ë¾£¬AppleÔÚ12ÔÂ13ÈÕÐû²¼µÄÄþ¾²¸üÐÂÖÐÐÞ¸´ ¡£


https://www.microsoft.com/security/blog/2022/01/10/new-macos-vulnerability-powerdir-could-lead-to-unauthorized-user-data-access/


Cado SecurityÌåÏÖ½©Ê¬ÍøÂçAbcbotÓëXantheÓйØÁª


Cado SecurityÔÚ1ÔÂ10ÈÕÐû²¼µÄ³ÂËßÏÔʾ£¬½©Ê¬ÍøÂçAbcbotÓëXantheÓйØÁª ¡£AbcbotÔÚ2021Äê11ÔÂÊ״α»¹ûÈ»£¬Æäʱ¹¥»÷ÁË»ªÎª¡¢ÌÚѶ¡¢°Ù¶ÈºÍ°¢ÀïÔÆµÈÔÆ·þÎñÌṩÉÌ ¡£µ«Í¨¹ýËùÓÐÒÑÖªµÄIoCs£¬°üÂÞIPµØÖ·¡¢urlºÍÑù±¾£¬·¢ÏÖAbcbotµÄ´úÂëºÍ»ù´¡ÉèÊ©ÓëÒ»¸öÃûΪXantheµÄ¼ÓÃܽٳֶñÒâÈí¼þ¼Ò×åÓÐÖØµþ ¡£Ñо¿ÍŶÓÈÏΪ¶þÕßÓÉͬһ¹¥»÷ÕßÂôÁ¦£¬¶øÇÒËûÃÇÕý½«Ä¿±ê´ÓÍÚ¿ó×ªÒÆµ½Óë½©Ê¬ÍøÂçÏà¹ØµÄ»î¶¯ ¡£


https://www.cadosecurity.com/abcbot-an-evolution-of-xanthe/


Check Point³Æ2021ÄêÍøÂç¹¥»÷»î¶¯Í¬±ÈÔö¼Ó50%


1ÔÂ10ÈÕ£¬Check Point researchÐû²¼³ÂËß³Æ2021ÄêÍøÂç¹¥»÷»î¶¯Í¬±ÈÔö¼Ó50% ¡£³ÂËß»¹Ö¸³ö£¬ÔÚ2021ÄêµÚËļ¾¶È£¬Ã¿¸ö×éÖ¯µÄÿÖÜÔâµ½µÄ¹¥»÷´ÎÊýµ½´ïÀúÊ·×î¸ß£¬Æ½¾ùΪ925´Î ¡£2021Ä꣬½ÌÓýºÍÑо¿ÐÐÒµÊÇÔâµ½¹¥»÷×î¶àµÄÐÐÒµ£¬Æ½¾ùÿÖÜ1605´Î¹¥»÷£¬Õâ±È2020ÄêÔö¼ÓÁË75% ¡£°´µØÓò»®·Ö£¬·ÇÖÞÔâµ½¹¥»÷×î¶à£¬Æ½¾ùÿÖÜ1582´Î£¬±È2020ÄêÔö¼Ó13%£¬½ôËæÆäºóµÄÊÇÑÇÌ«µØÓò£¬Ã¿ÖÜÔâµ½1353´Î¹¥»÷£¨Ôö¼Ó25%£© ¡£


https://blog.checkpoint.com/2022/01/10/check-point-research-cyber-attacks-increased-50-year-over-year/


Äþ¾²¹¤¾ß


Mortar 


MortarÄܹ»ÈƹýÏÖ´ú·´²¡¶¾²úÎïºÍÏȽøµÄXDR½â¾ö·½°¸£¬°üÂÞKaspersky¡¢ESETºÍMcafeeµÈ ¡£


https://www.kitploit.com/2022/01/mortar-evasion-technique-to-defeat-and.html


RecoverPy


¿ÉÓÃÀ´»Ö¸´±»ÁýÕÖ»òɾ³ýµÄÊý¾Ý£¬Ä¿Ç°½öÔÚLinuxϵͳÉÏ¿ÉÓà ¡£


https://github.com/PabloLec/RecoverPy


Äþ¾²·ÖÎö


Linux Mint 20.3 Ðû²¼


Linux Mint Ðû²¼ÁË 20.3 °æ£¬´úºÅΪ¡°Una¡±£¬×÷Ϊºã¾ÃÖ§³Ö°æ±¾£¬²¢ÔÊÐíÔÚ 2025 ÄêÄê֮ǰÄþ¾²¸üР¡£


https://www.bleepingcomputer.com/news/linux/linux-mint-203-released-promising-security-updates-until-2025/


ÀÕË÷Èí¼þAvosLocker Õë¶Ô VMware ESXi ·þÎñÆ÷


AvosLockerÔÚÆä×î½üµÄ¶ñÒâÈí¼þ±äÖÖÖÐÔö¼ÓÁË¶Ô Linux ϵͳµÄÖ§³Ö£¬ÌرðÊÇÕë¶Ô VMware ESXi ÐéÄâ»ú ¡£


https://www.bleepingcomputer.com/news/security/linux-version-of-avoslocker-ransomware-targets-vmware-esxi-servers/