Ó¢¹ú³Æ¶íDZͧÕýÍþв³ÐÔØÁè¼Ý95%¹ú¼ÊÊý¾ÝµÄº£µ×µçÀÂ
Ðû²¼Ê±¼ä 2022-01-13Ó¢¹ú³Æ¶íDZͧÕýÍþв³ÐÔØÁè¼Ý95%¹ú¼ÊÊý¾ÝµÄº£µ×µçÀÂ
ýÌå1ÔÂ9ÈÕ±¨µÀ£¬Ó¢¹ú¹ú·À²¿³¤Tony Radakin³Æ£¬¶íÂÞ˹DZͧÕýÔÚÍþвº£µ×ÍøÂçµçÀÂÍøÂç¡£º£µ×µçÀ³ÐÔØÁè¼Ý95%µÄ¹ú¼ÊÊý¾Ý£¬½öÔÚ½ðÈÚÁìÓò£¬ËüÿÌì¾Í³ÐÔØ×ÅÔ¼10ÍòÒÚÃÀÔªµÄ½»Òס£Ó¢¹úÕþ¸®³Æ£¬½ü20ÄêÖжíÂÞ˹µÄˮϻÏÔÖøÔö¼Ó£¬ËûÃÇÔøÔÚ2020Äê12Ô»÷ÖÐÒ»ËÒ¶íÂÞ˹DZͧ¡£Ñо¿ÈËÔ±ÌåÏÖ£¬¼äµýÍŻﻹ¿ÉÒÔͨ¹ýÔÚµçÀÂÖÆÔì¹ý³ÌÖÐÖ²ÈëºóÃÅÀ´ÇÔÌý´«ÊäµÄÊý¾Ý¡£
https://securityaffairs.co/wordpress/126459/security/undersea-cables-protection.html
Ñо¿ÍŶÓÅû¶ÐÂÀÕË÷Èí¼þNight Sky½üÆÚ¹¥»÷µÄϸ½Ú
¾ÝýÌå1ÔÂ6ÈÕ±¨µÀ£¬Malware Hunter Team·¢ÏÖÁËÐÂÀÕË÷Èí¼þNight Sky¡£¸ÃÍÅ»ïµÄ»î¶¯¿ªÊ¼ÓÚ12ÔÂ27ÈÕ£¬Í¬ÑùʹÓÃÁËË«ÖØÀÕË÷¼ÆÄ±¡£´ËÍ⣬Night Sky²¢Î´Ê¹ÓÃTorÍøÕ¾ÓëÄ¿±ê̸ÅУ¬¶øÊÇʹÓÃÓʼþµØÖ·ºÍÔËÐÐRocket.ChatµÄÍøÕ¾¡£ÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ÏÔʾÒÑÓÐ2¸ö±»¹¥»÷Ä¿±ê£¬Ò»¸öÀ´×ÔÃϼÓÀ¹ú£¬ÁíÒ»¸öÀ´×ÔÈÕ±¾£¬ËüÃÇÆäÖÐÖ®Ò»±»ÀÕË÷800000ÃÀÔª¡£
https://www.bleepingcomputer.com/news/security/night-sky-is-the-latest-ransomware-targeting-corporate-networks/
Malwarebytes·¢ÏÖPatchworkÕë¶Ô¿ÆÑÐÐÐÒµµÄ¹¥»÷»î¶¯
MalwarebytesÔÚ1ÔÂ7ÈÕÐû²¼µÄ³ÂËßÖÐÌåÏÖ£¬Ó¡¶ÈAPT×éÖ¯PatchworkµÄ¿ª·¢ÏµÍ³±»×Ô¼ºµÄRATѬȾ£¬µ¼ÖÂÆÁÄ»½ØÍ¼ºÍ¼üÅ̼ǼµÈÐÅϢй¶¡£Í¨¹ýÕâЩÐÅÏ¢£¬Ñо¿ÍŶÓÈ·¶¨Á˸ÃÍÅ»ïÔÚ½üÆÚµÄ¹¥»÷»î¶¯¡£2021Äê11ÔÂÏÂÑ®ÖÁ12ÔÂÉÏÑ®£¬¸ÃÍÅ»ïð³ä°Í»ù˹̹Õþ¸®£¬ÀûÓöñÒâRTFÎļþ·Ö·¢Ò»ÖÖÃûΪRagnatelaµÄBADNEWS RATбäÌå¡£´Ë´Î¹¥»÷µÄÄ¿±ê°üÂÞ°Í»ù˹̹¹ú·À²¿¡¢ÒÁ˹À¼±¤¹ú·À´óѧºÍÀºÏ¶û´óѧÉúÎï¿ÆÑ§Ñ§ÔºµÈ¡£
https://blog.malwarebytes.com/threat-intelligence/2022/01/patchwork-apt-caught-in-its-own-web/
Google DocsÆÀÂÛ¹¦Ð§±»µöÓã»î¶¯ÓÃÀ´·¢ËͶñÒâÐÅÏ¢
1ÔÂ6ÈÕ£¬Äþ¾²¹«Ë¾AvananÐû²¼ÁËÕë¶ÔOutlookÓû§µÄµöÓã»î¶¯µÄ·ÖÎö³ÂËß¡£´Ë´Î»î¶¯µÄ¹¥»÷Á´·Ç³£¼òµ¥£¬¹¥»÷ÕßÊ×ÏÈ´´½¨Ò»¸öGoogle Doc£¬²¢ÏòÆäÌí¼ÓÒ»ÌõÆÀÂÛ£¬¸ÃÆÀÂÛ°üÂÞ¶ñÒâÁ´½Ó£¬²¢Ê¹Óá°@¡±À´Ìá¼°Ä¿±ê¡£¶øGoogleÔò»á×Ô¶¯ÏòÄ¿±ê·¢ËÍÒ»·âµç×ÓÓʼþ£¬Í¨ÖªÆäÓÐÌá¼°ËûÃǵÄÐÂÆÀÂÛ£¬²¢»áÏÔʾ°üÂÞ¶ñÒâÁ´½ÓÔÚÄÚµÄÍêÕûÆÀÂÛ¡£ÒòΪÕâЩÓʼþÀ´×ÔGoogle£¬Òò´ËÄþ¾²½â¾ö·½°¸²»»á½«ËüÃDZê־Ϊ¶ñÒâ¡£
https://securityaffairs.co/wordpress/126375/hacking/google-docs-comment-phishing.html
ŵ¶ÙÔÚÓû§µçÄÔÖÐÇ¿ÖÆ°²×°ÍÚ¿óÈí¼þNorton Crypto
ýÌå1ÔÂ7ÈÕ±¨µÀ£¬É±¶¾Èí¼þNorton 360»áÔÚÓû§µçÄÔÖÐÇ¿ÖÆ°²×°ÍÚ¿óÈí¼þNorton Crypto¡£¾ÝϤ£¬¸ÃÈí¼þÔÚÈ¥Äê6Ô±»ÄÉÈëNortonɱ¶¾Èí¼þ£¬¿É×ÊÖúÓû§ÀûÓÃÏÔ¿¨×¬È¡ÌرðÊÕÈ루Óû§±£Áô85%ÊÕÈ룬ÆäÓà±»NortonLifeLock³é³É£©¡£²¿ÃÅÓû§ÌåÏÖ£¬¸Ã¿ó¹¤Èí¼þ»á×Ô¶¯°²×°£¬¶øÇÒ³ý·ÇÐ¶ÔØÕû¸öɱ¶¾Èí¼þ£¬·ñÔò²»Äܵ¥¶Àɾ³ý¡£Norton»ØÓ¦³ÆNorton Crypto×÷ΪһÏî¿ÉÑ¡¹¦Ð§Ìṩ£¬Î´¾Óû§Ðí²»»áÆôÓá£
https://www.hackread.com/norton-antivirus-installs-cryptominer-way-out/
Ñо¿ÈËÔ±ÔÚ16¸ö³£ÓõÄURL½âÎö¿âÖз¢ÏÖ8¸öÄþ¾²Â©¶´
¾ÝýÌå1ÔÂ10ÈÕ±¨µÀ³Æ£¬Äþ¾²¹«Ë¾ClarotyºÍSynkµÄÁªºÏÑо¿Åû¶ÁË8¸öЩ¶´µÄϸ½Ú¡£Ñо¿·¢ÏÖ16¸öURL½âÎö¿âÖдæÔÚ·×ÆçÖºͻìÏýÎÊÌ⣬ÕâЩÎÊÌâ¿É±»ÓÃÀ´ÈƹýÑéÖ¤²¢ÎªÖÖÖÖ¹¥»÷¹¥»÷ÔØÌå´ò¿ª´óÃÅ¡£´Ë´ÎÅû¶µÄ©¶´°üÂÞBelledonne¡¯s SIP Stack(CVE-2021-33056)¡¢Video.js(CVE-2021-23414)¡¢Nagios XI(CVE-2021-37352)ºÍFlask-security-too(CVE-2021-32618)µÈ¡£Ä¿Ç°£¬Â©¶´Òѱ»¸÷×ÔµÄά»¤ÈËÔ±ÐÞ¸´¡£
https://thehackernews.com/2022/01/researchers-find-bugs-in-over-dozen.html
Äþ¾²¹¤¾ß
statiStrings
statiStrings ÊÇ YARA ¹æÔòµÄ×Ö·û´®Í³¼Æ¼ÆËãÆ÷¡£
https://github.com/Sh3llyR/statiStrings
inject assembly
ÔÚÏÖÓнø³ÌÖÐÖ´ÐÐ .NET£¬¿ÉÌæ´ú Cobalt Strike µÄ´«Í³ fork ºÍ run Ö´ÐС£
https://github.com/kyleavery/inject-assembly
Äþ¾²·ÖÎö
ÃÀ¹úNCSCºÍDoSÐû²¼Õë¶ÔÉÌÒµ¼àÊÓ¹¤¾ßµÄÖ¸ÄÏ
ÃÀ¹úNCSCºÍ¹úÎñÔºÐû²¼ÁªºÏÖ¸ÄÏ£¬ÌṩÁ˵ÖÓùʹÓÃÉÌÒµ¼àÊÓ¹¤¾ß½øÐеĹ¥»÷µÄ×î¼Ñʵ¼ù¡£
https://securityaffairs.co/wordpress/126497/digital-id/defending-against-surveillance-tools.html
CVE-2021-43326£ºÌáȨ©¶´
Automox Agent 32´æÔÚµ±µØÈ¨ÏÞÌáÉý©¶´¡£
https://cxsecurity.com/issue/WLB-2022010046