Kaspersky·¢ÏÖ¶à¸ö¶ÌÖÜÆÚµÄ¼äµý»î¶¯Õë¶Ô¹¤¿ØÐÐÒµ

Ðû²¼Ê±¼ä 2022-01-25

Kaspersky·¢ÏÖ¶à¸ö¶ÌÖÜÆÚµÄ¼äµý»î¶¯Õë¶Ô¹¤¿ØÐÐÒµ


1ÔÂ9ÈÕ£¬KasperskyÐû²¼³ÂËßÅû¶¶à¸öÕë¶Ô¹¤¿ØÐÐÒµµÄ¼äµý»î¶¯¡£ÕâЩ»î¶¯Ê¹ÓÃÏֳɵļäµýÈí¼þ¹¤¾ß£¬°üÂÞAgentTesla¡¢HawkEye¡¢Noon/Formbook¡¢Masslogger¡¢Snake KeyloggerºÍLokibotµÈ¡£Kaspersky³ÆÕâЩ¹¥»÷³ÆÎª¡°anomalous¡±£¬ÒòΪÓ봫ͳµÄ¼äµý¹¥»÷Ïà±È£¬ËüÃǵÄÉúÃüÖÜÆÚ·Ç³£¶ÌÔÝ£¬´ó¶àÊý´ËÀ๥»÷»áÁ¬ÐøÊýÔÂÉõÖÁÊýÄ꣬¶øÕâЩ»î¶¯Ô¼Îª25Ìì¡£


https://securelist.com/hunt-for-corporate-credentials-on-ics-networks/105545/


McAfeeÐÞ¸´AgentÈí¼þÖеÄÌáȨ©¶´CVE-2022-0166


ýÌå1ÔÂ21ÈÕ±¨µÀ£¬McAfee£¨ÏÖΪTrellix£©ÒÑÐÞ¸´ÌáȨ©¶´£¨CVE-2022-0166£©¡£¸Ã©¶´Î»ÓÚWindows°æ±¾µÄMcAfee AgentÈí¼þÖУ¬Èí¼þÔÚ¹¹½¨¹ý³ÌÖÐʹÓÃopenssl.cnf½«OPENSSLDIR±äÁ¿Ö¸¶¨Îª°²×°Ä¿Â¼ÖеÄ×ÓĿ¼£¬µÍȨÏÞÓû§¿ÉÒÔÀûÓøÃ©¶´´´½¨×ÓĿ¼²¢Ê¹ÓÃSystemȨÏÞÖ´ÐÐÈÎÒâ´úÂë¡£¸Ã¹«Ë¾ÓÚ1ÔÂ18ÈÕÐû²¼ÁËMcAfee Agent 5.7.5ÐÞ¸´´Ë©¶´¡£


https://securityaffairs.co/wordpress/127044/security/mcafee-agent-code-execution-flaw.html


RustÐÞ¸´¿Éɾ³ýÎļþºÍĿ¼µÄ©¶´CVE-2022-21658


RustÄþ¾²ÏìÓ¦ÊÂÇé×é(WG)ÔÚ1ÔÂ20ÈÕÐû²¼µÄͨ¸æÖÐÌåÏÖ£¬Æä²úÎï´æÔÚÒ»¸öÑÏÖØµÄ©¶´¡£Â©¶´±»×·×ÙΪCVE-2022-21658£¬CVSSÆÀ·ÖΪ7.3£¬Ó°ÏìÁËRust 1.0.0µ½Rust 1.58.0°æ±¾¡£¸Ã©¶´Ô´Óڳ߶ȿ⺯Êýstd::fs::remove_dir_allÈÝÒ×Êܵ½ÆôÓ÷ûºÅÁ´½Ó¸ú×ٵľºÕùÌõ¼þµÄÓ°Ï죬¹¥»÷Õß¿ÉÒÔÀûÓøÃ©¶´ÓÕÊ¹ÌØÈ¨·¨Ê½É¾³ýÆäÎÞ·¨·ÃÎÊ»òɾ³ýµÄÎļþºÍĿ¼¡£¸ÃÍŶÓÔÚÉÏÖÜÐû²¼µÄRust 1.58.1°æ±¾ÖÐÐÞ¸´ÁË´Ë©¶´¡£


https://thehackernews.com/2022/01/high-severity-rust-programming-bug.html


Fortinet·¢ÏÖð³äº½Ô˹«Ë¾·Ö·¢STRRATµÄµöÓã»î¶¯


FortinetÔÚ1ÔÂ20ÈÕ¹ûÈ»ÁËÖ¼ÔÚ·Ö·¢Ô¶³Ì·ÃÎÊľÂíSTRRATµÄµöÓã»î¶¯¡£´Ë´Î»î¶¯Ã°³äº½Ô˹«Ë¾ÂíÊ¿»ùº½Ô˹«Ë¾£¨Maersk Shipping£©£¬Ê¹ÓÃÒÔ×°ÔË¡¢½»»õÈÕÆÚ¸ü¸Ä»ò¹ºÖÃ֪ͨµÄµöÓãÓʼþ£¬µ±Ä¿±ê´ò¿ªÓʼþÖеĸ½¼þºó¾Í»áÔËÐжñÒâºê²¢°²×°STRRAT¡£STRRAT¿ÉÒÔÇÔȡĿ±êµÄÐÅÏ¢£¬»òÕß½øÐмٵÄÀÕË÷¹¥»÷£¨ÔÚ¹¥»÷ÖÐûÓÐÎļþ±»¼ÓÃÜ£©¡£´ËÍ⣬¹¥»÷ÕßʹÓÃÁËAllatori¹¤¾ß¶ÔÈí¼þ°ü½øÐÐÁË»ìÏý£¬ÒÔÈÆ¹ýÄþ¾²²úÎïµÄ¼ì²â¡£


https://www.bleepingcomputer.com/news/security/phishing-impersonates-shipping-giant-maersk-to-push-strrat-malware/


Check PointÐû²¼2021ÄêÍøÂç¹¥»÷»î¶¯µÄ»Ø¹Ë³ÂËß


1ÔÂ21ÈÕ£¬Check PointÐû²¼ÁË2021ÄêÍøÂç¹¥»÷»î¶¯µÄ»Ø¹Ë³ÂËß¡£×ÜÌå¶øÑÔ£¬Óë2020ÄêÏà±È£¬2021Äê×é֯ÿÖÜÔâÊܵĹ¥»÷´ÎÊýÔö¼ÓÁË50%¡£Õë¶ÔTOP 16ÐÐÒµµÄ¹¥»÷ƽ¾ùÔö¼ÓÁË55%£¬ÆäÖнÌÓýºÍÑо¿²¿ÃÅÊÇÊܹ¥»÷×î¶àµÄÐÐÒµ£¬Æ½¾ùÿÖÜÔâµ½1605´Î¹¥»÷£¨Ôö³¤75%£©£¬Æä´ÎΪÕþ¸®ºÍ¾ü¶Ó£¨1136´Î£¬Ôö¼Ó47%£©ÒÔ¼°Í¨ÐÅÐÐÒµ£¨1079´Î£¬Ôö¼Ó51%£©  £»Õë¶ÔÈí¼þ¹©Ó¦É̹¥»÷´ÎÊýµÄÔö·ù×î´ó£¬Í¬±ÈÔö³¤ÁË146%¡£


https://blog.checkpoint.com/2022/01/21/2022-security-report-software-vendors-saw-146-increase-in-cyber-attacks-in-2021-marking-largest-year-on-year-growth/


Cleafy½üÆÚ·¢ÏÖAndroid¶ñÒâÈí¼þBRATAµÄбäÌå


¾ÝýÌå1ÔÂ24ÈÕ±¨µÀ£¬Cleafy³ÆAndroid¶ñÒâÈí¼þBRATAÔÚÆäбäÌåÖÐÌí¼Ó¶à¸ö¹¦Ð§¡£BRATAÊÇÒ»¿îÖ÷ÒªÕë¶Ô°ÍÎ÷Óû§µÄAndroid RAT£¬ÔÚ2019ÄêÊ״α»Kaspersky·¢ÏÖ¡£¸Ã±äÌåÏÖÔÚÖ÷ÒªÕë¶ÔÓ¢¹ú¡¢²¨À¼¡¢Òâ´óÀû¡¢Î÷°àÑÀ¡¢ÖйúºÍÀ­¶¡ÃÀÖ޵ĵç×ÓÒøÐеÄÓû§£¬ÐÂÔöÁ˼üÅ̼Ǽ¹¦Ð§¡¢GPS ¸ú×Ù¹¦Ð§£¬¿ÉÒÔÖ´Ðгö³§ÖØÖÃÒÔÇå³ýËùÓжñÒâ»î¶¯µÄºÛ¼££¬»¹Ìí¼ÓÁË¿ÉÒÔÖ§³ÖHTTPºÍWebSocketsµÄÐÂC2ͨÐÅͨµÀ¡£


https://www.bleepingcomputer.com/news/security/android-malware-brata-wipes-your-device-after-stealing-data/


Äþ¾²¹¤¾ß


CFRipper


»ùÓÚ Python µÄ¿âºÍ CLI Äþ¾²·ÖÎöÆ÷£¬ÓÃ×÷ AWS CloudFormation Äþ¾²É¨ÃèºÍÉ󼯹¤¾ß¡£


https://github.com/Skyscanner/cfripper


TokenUniverse


ʹÓ÷ÃÎÊÁîÅÆºÍ Windows Äþ¾²¼ÆÄ±µÄ¸ß¼¶¹¤¾ß¡£


https://github.com/diversenok/TokenUniverse


Registry Spy


Ãâ·ÑµÄ¿ªÔ´¿çƽ̨ Windows ×¢²á±í¼ì²ìÆ÷¡£


https://github.com/andyjsmith/Registry-Spy


SysmonSimulator


ÓÃCÓïÑÔ´´½¨µÄ¿ªÔ´ Windows ʼþÄ£ÄâʵÓ÷¨Ê½£¬¿ÉÓÃÓÚÄ£Äâ´ó¶àÊýʹÓà WINAPI µÄ¹¥»÷¡£


https://github.com/ScarredMonk/SysmonSimulator


HazProne


ÔÆÉøÍ¸²âÊÔ¿ò¼Ü£¬ÓÃÓÚÉøÍ¸²âÊÔ©¶´¡£


https://github.com/stafordtituss/HazProne


Äþ¾²·ÖÎö


΢ÈíĬÈϽûÓÃExcel 4.0ºêÀ´×èÖ¹¶ñÒâÈí¼þ


https://www.bleepingcomputer.com/news/microsoft/microsoft-disables-excel-40-macros-by-default-to-block-malware/


SonicWall ΪÏÝÈëÖØÆôÑ­»·µÄ·À»ðǽ¹²ÏíÌṩÁÙʱÐÞ¸´


https://www.bleepingcomputer.com/news/technology/sonicwall-shares-temp-fix-for-firewalls-stuck-in-reboot-loop/


΢ÈíÁгöÁËÒªÖÆÖ¹µÄ Windows 10 ×鼯ı


https://www.bleepingcomputer.com/news/microsoft/microsoft-lists-the-windows-10-group-policies-to-avoid/


ProtonMail ÒýÈëÁËÒ»¸öеĵç×ÓÓʼþ¸ú×ÙÆ÷×èֹϵͳ


https://www.bleepingcomputer.com/news/security/protonmail-introduces-a-new-email-tracker-blocking-system/


F5 ÐÞ¸´ÁË BIG-IP¡¢BIG-IQ ºÍ NGINX ²úÎïÖÐµÄ 25 ¸öȱÏÝ


https://securityaffairs.co/wordpress/127097/security/f5-big-ip-flaws.html