¹È¸èÐÞ¸´ChromeÖÐÊͷźóʹÓé¶´CVE-2022-0609
Ðû²¼Ê±¼ä 2022-02-17¹È¸èÐÞ¸´ChromeÖÐÊͷźóʹÓé¶´CVE-2022-0609
2ÔÂ14ÈÕ£¬¹È¸èÐû²¼½ô¼±¸üУ¬ÐÞ¸´ChromeÖеĶà¸öÄþ¾²Â©¶´¡£´Ë´ÎÐÞ¸´µÄ×îÑÏÖØµÄ©¶´ÊǶ¯»×é¼þÖеÄÊͷźóʹÓé¶´£¨CVE-2022-0609£©£¬¿É±»ÓÃÀ´Ö´ÐÐÈÎÒâ´úÂë»òÔÚä¯ÀÀÆ÷µÄɳÏäÖÐÌÓÒÝ¡£¹È¸èÌåÏÖËûÃÇÒѾ¼ì²âµ½ÀûÓÃÕâ¸öÁãÈÕ©¶´µÄ¹¥»÷£¬µ«¸Ã¹«Ë¾²¢Î´·ÖÏíÓйع¥»÷»î¶¯µÄÆäËüÐÅÏ¢»ò¸Ã©¶´µÄ¼¼Êõϸ½Ú¡£´ËÍ⣬¸üл¹ÐÞ¸´ÁËWebstore APIÖеÄÊͷźóʹÓé¶´£¨CVE-2022-0605£©ºÍMojoÖеÄÕûÊýÒç³ö©¶´£¨CVE-2022-0608£©µÈ©¶´¡£
https://www.bleepingcomputer.com/news/security/google-chrome-emergency-update-fixes-zero-day-exploited-in-attacks/
ÎÚ¿ËÀ¼¶à¸ö¹Ù·½×éÖ¯µÄÍøÕ¾Ôâµ½´ó¹æÄ£DDoS¹¥»÷
ÎÚ¿ËÀ¼¶à¸ö¹Ù·½×éÖ¯µÄÍøÕ¾ÔÚ2ÔÂ15ÈÕÔâµ½ÁË´ó¹æÄ£DDoS¹¥»÷¡£¸Ã¹úµÄ2¸ö¹úÓÐÒøPrivatbank£¨ÎÚ¿ËÀ¼×î´óµÄÒøÐУ©ºÍOschadbank£¨¹ú¼Ò´¢ÐîÒøÐУ©´Óµ±µØÊ±¼äÏÂÎç3µã×óÓÒ¿ªÊ¼¹Ø±ÕÁË2¸öСʱ£¬ÔÚ5¸öСʱºó»Ö¸´Õý³£ÔËÐУ¬²¢ÌåÏÖ¿ÉÄÜ»áÔÙ´ÎÔâµ½¹¥»÷¡£´ËÍ⣬ÎÚ¿ËÀ¼¹ú·À²¿ºÍÎä×°¶ÓÎéµÄÍøÕ¾ÈÔÈ»ÎÞ·¨·ÃÎÊ¡£ÎÚ¿ËÀ¼¹«¹²¹ã²¥µç̨µÄ×ÜÖÆ×÷ÈËDmitry KhorkinÌåÏÖµç̨ҲÔâµ½Á˹¥»÷£¬µ«ÆäÍøÕ¾²¢Î´Ì±»¾¡£
https://therecord.media/ddos-attacks-hit-websites-of-ukraines-state-banks-defense-ministry-and-armed-forces/
Î÷°àÑÀ¾¯·½µ·»Ù½ðÈÚÕ©Æ·¸×ïÍŻﲢ´þ²¶8¸öÏÓÒÉÈË
¾ÝýÌå2ÔÂ14ÈÕ±¨µÀ£¬Î÷°àÑÀ¹ú¼Ò¾¯²ì¾Ö£¨Polic¨ªa Nacional£©ÔÚÉÏÖܵ·»ÙÁËÒ»¸ö½ðÈÚÕ©Æ·¸×ïÍŻ¸ÃÍÅ»ïµÄ8Ãû³ÉÔ±±»²¶£¬12¸öÒøÐÐÕË»§±»¶³½á¡£¾ÝϤ£¬¸ÃÍÅ»ïµÄµÚÒ»Æð¹¥»÷ʼþ·¢ÉúÔÚ2021Äê3Ô£¬ËûÃÇÖ÷Ҫαװ³ÉÒøÐÐºÍÆäËü×éÖ¯µÄ´ú±í£¬Ê¹ÓõöÓã¹¥»÷ºÍSIM½»»»¹¥»÷»ñȡĿ±êµÄ¸öÈ˺ͲÆÕþÐÅÏ¢£¬²¢´ÓËûÃǵÄÕË»§ÖÐÌáÈ¡×ʽ𡣽üÄêÀ´£¬SIM½»»»ÒÑÑݱäΪһÖÖÈÕÒæÆÕ±éµÄÍøÂç·¸×ïÐÎʽ£¬2021Äê12Ô£¬The Community³ÉÔ±ÒòÉæÏÓÊý°ÙÍòÃÀÔªµÄSIM¿¨½»»»¹¥»÷±»´þ²¶¡£
https://thehackernews.com/2022/02/spanish-police-arrest-sim-swappers-who.html
Beetle Eye´æ´¢Í°ÅäÖôíÎóÔ¼700ÍòÓû§µÄÐÅϢй¶
¾Ý2ÔÂ14Èյı¨µÀ£¬Website Planet·¢ÏÖÃÀ¹úÓªÏú¹«Ë¾Beetle EyeÔ¼700ÍòÓû§µÄÐÅϢй¶¡£Beetle EyeÒòAWS S3´æ´¢Í°ÅäÖôíÎó̻¶ÁËÁè¼Ý6000¸öÎļþ£¬×ܼÆÁè¼Ý1GBÊý¾Ý¡£´Ë´Îй¶ÁËÐÕÃû¡¢µØÖ·¡¢ÓÊÕþ±àÂëºÍµç»°ºÅÂëµÈÐÅÏ¢£¬ÊÜÓ°ÏìµÄÓû§´ó¶àÀ´×ÔÓÚÃÀ¹úºÍ¼ÓÄô󡣸ô洢ͰÓÚ2021Äê9ÔÂ9ÈÕ±»·¢ÏÖ£¬2022Äê2ÔÂ14ÈÕBeetle Eye»Ø¸´³ÆÃô¸ÐÎļþÒѱ»É¾³ý¡£
https://www.hackread.com/us-marketing-firm-data-exposed-database-mess-up/
ÈðÊ¿Æû³µ¾ÏúÉÌEmil Frey³ÆÆäÔâµ½HiveµÄÀÕË÷¹¥»÷
ýÌå2ÔÂ14ÈÕ±¨µÀ£¬ÈðÊ¿Æû³µ¾ÏúÉÌEmil FreyÔâµ½HiveÀÕË÷¹¥»÷¡£ÕâÊÇÅ·ÖÞ×î´óµÄÆû³µ¾ÏúÉÌÖ®Ò»£¬ÔÚ2020ÄêµÞÔìÁË32.9ÒÚÃÀÔªµÄÏúÊÛ¶î¡£¸Ã¹«Ë¾ÓÚ2ÔÂ1ÈÕ·ºÆðÔÚHiveµÄÒѱ»¹¥»÷Ä¿±êµÄÃûµ¥ÉÏ£¬²¢ÈÏ¿ÉËûÃÇÔÚ1Ô·ÝÔâµ½¹¥»÷¡£¸Ã¹«Ë¾·¢ÑÔÈ˳ƣ¬ÔÚ1ÔÂ11ÈÕµÄʼþ·¢Éú¼¸Ììºó£¬¹«Ë¾¾ÍÒѻָ´²¢ÖØÆôÁËÉÌÒµ»î¶¯¡£HiveÔÚ2021Äê¹¥»÷ÁËÖÁÉÙ28¸öÒ½ÁÆ»ú¹¹£¬»ñµÃÁËFBIµÄÖØµã¹Ø×¢¡£
https://www.itsecurityguru.org/2022/02/14/major-car-dealer-suffers-ransomware-attack/
FortiGuardÐû²¼½üÆÚ·Ö·¢BitRATµÄ»î¶¯µÄ·ÖÎö³ÂËß
2ÔÂ14ÈÕ£¬FortiGuard LabsÐû²¼Á˹ØÓÚ·Ö·¢BitRATµÄ»î¶¯µÄ·ÖÎö³ÂËß¡£´Ë´Î»î¶¯Ê¹ÓÃÁËÃûΪ¡°NFT_Items.xlsm¡±µÄExcelµç×Ó±í¸ñ£¬¸ÃÎļþÓÐÁ½¸öÊÂÇé²¾£¬ÆäÖÐÒ»¸öÊÇÏ£²®À´ÓïµÄ¡£¸Ã¶ñÒâÎļþÒÔ²»ÐÐÌæ´ú´ú±Ò(NFT)Ïà¹ØÐÅϢΪÓÕ¶ü£¬°üÂÞÒ»¸ö¶ñÒâºê£¬¿ÉʹÓÃPowerShell½Å±¾´ÓDiscordÏÂÔØÁíÒ»¸öÎļþNFTEXE.exe£¬×îÖÕ½«°²×°Ô¶³Ì·ÃÎÊľÂíBitRAT¡£
https://www.fortinet.com/blog/threat-research/nft-lure-used-to-distribute-bitrat
Äþ¾²¹¤¾ß
Droopescan
Ò»ÖÖ»ùÓÚ²å¼þµÄɨÃ跨ʽ£¬¿É×ÊÖúÄþ¾²Ñо¿ÈËԱʶ±ð¶à¸ö CMS µÄÎÊÌâ¡£
https://github.com/SamJoan/droopescan
AutoTimeliner
´ÓÒ×ʧÐÔÄÚ´æ×ª´¢ÖÐ×Ô¶¯Ìáȡȡ֤ʱ¼äÏß¡£
https://github.com/andreafortuna/autotimeliner
truffleHog
ͨ¹ý git ´æ´¢¿âËÑË÷ÃÜÂ룬ÉîÈëÍÚ¾òÌá½»ÀúÊ·ºÍ·ÖÖ§£¬Õâ¶ÔÓÚ·¢ÏÖÒâÍâÌá½»µÄÃÜÂë·Ç³£ÓÐЧ¡£
https://github.com/trufflesecurity/truffleHog
WarFox
»ùÓÚÈí¼þµÄ HTTPS Ðűê Windows Ö²È뷨ʽ£¬ËüʹÓöà²ãÊðÀíÍøÂç½øÐÐ C2 ͨÐÅ¡£
https://github.com/FULLSHADE/WarFox
Melody
ΪÍþвÇ鱨¶ø¹¹½¨µÄ͸Ã÷»¥ÁªÍø´«¸ÐÆ÷£¬¿É±êÖ¾¸ÐÐËȤµÄÊý¾Ý°üÒÔ½øÐнøÒ»²½·ÖÎöºÍÍþв¼à¿Ø¡£
https://bonjourmalware.github.io/melody/
Äþ¾²·ÖÎö
QNAP ΪһЩ²»ÊÜÖ§³ÖµÄ NAS É豸À©Õ¹Òªº¦¸üÐÂ
https://www.bleepingcomputer.com/news/security/qnap-extends-critical-updates-for-some-unsupported-nas-devices/
Kali Linux 2022.1 Ðû²¼£¬°üÂÞ 6 ¸öй¤¾ß¡¢SSH ¹ã·º¼æÈݵÈ
https://www.bleepingcomputer.com/news/security/kali-linux-20221-released-with-6-new-tools-ssh-wide-compat-and-more/
FTC ¾¯¸æ VoIP ÌṩÉÌ£º·ÖÏí robocall ÐÅÏ¢»ò±»ÆðËß
https://www.bleepingcomputer.com/news/security/ftc-warns-voip-providers-share-your-robocall-info-or-get-sued/
KlaySwap Óû§ÔÚ BGP ½Ù³ÖºóËðʧ×ʽð
https://therecord.media/klayswap-crypto-users-lose-funds-after-bgp-hijack/
ÀûÓà Ghostbuster ¹¤¾ßÏû³ýµ¯ÐÔ IP ½Ó¹Ü
https://blog.assetnote.io/2022/02/13/dangling-eips/