ÔËÓªÉÌUkrtelecom³ÆÆäºËÐÄ»ù´¡ÉèÊ©Ôâµ½´ó¹æÄ£¹¥»÷

Ðû²¼Ê±¼ä 2022-03-31

ÔËÓªÉÌUkrtelecom³ÆÆäºËÐÄ»ù´¡ÉèÊ©Ôâµ½´ó¹æÄ£¹¥»÷


¾ÝýÌå3ÔÂ29ÈÕ±¨µÀ £¬ÎÚ¿ËÀ¼Ö÷ÒªµÄÔËÓªÉÌUkrtelecomÔâµ½ÁË´ó¹æÄ£µÄÍøÂç¹¥»÷ £¬Ôì³ÉÁËÑÏÖØµÄÍøÂçÖжÏ¡£Æ¾¾Ý»¥ÁªÍø¼à¿Ø·þÎñNetBlockµÄÊý¾Ý £¬ÊµÊ±ÍøÂçÊý¾ÝÏÔʾÁ¬½ÓÐÔϽµµ½Õý³£Ë®Æ½µÄ13%¡£ÎÚ¿ËÀ¼SSSCIPÌåÏÖ £¬ºÚ¿Í¹¥»÷ÁËUkrtelecomµÄIT»ù´¡ÉèÊ© £¬ËûÃÇÒÑÀֳɵÖÓù´Ë´Î¹¥»÷¡£´ËÍâ £¬ÎªÁ˱ £»¤Æä»ù´¡ÉèÊ©²¢¼ÌÐøÎªÎÚ¿ËÀ¼Îä×°¶ÓÎéºÍÆäËû¾üÊÂ×éÖ¯ºÍ¿Í»§Ìṩ·þÎñ £¬UkrtelecomÔÝʱÏÞÖÆÁË´ó¶àÊý˽ÈËºÍÆóÒµ¿Í»§µÄ·þÎñ¡£


https://securityaffairs.co/wordpress/129585/cyber-warfare-2/ukraine-cyberattack-ukrtelecom.html


΢ÈíÐÞ¸´Windows 11 SMBºÍDirectXÖеÄBSODÎÊÌâ


ýÌå3ÔÂ28ÈÕ±¨µÀ £¬MicrosoftÐû²¼ÁËÊÊÓÃÓÚWindows 11µÄ¿ÉÑ¡KB5011563ÀÛ»ý¸üС£´Ë´Î¸üÐÂÖ÷ÒªÐÞ¸´ÁË2¸öÀ¶ÆÁËÀ»ú(BSOD)ÎÊÌâ £¬°üÂÞDirectXÄÚºË×é¼þÖеÄÍ£Ö¹´íÎó£¨0xD1 £¬DRIVER_IRQL_NOT_LESS_OR_EQUAL£©ºÍSMB·þÎñÆ÷£¨srv2.sys£©ÖеÄÍ£Ö¹´íÎó0x1E¡£´Ë´Î¸üл¹Ôö¼ÓÁ˺ܶàÐµĹ¦Ð§ £¬ÀýÈçͬʱÏÔʾ×î¶àÈý¸ö¸ßÓÅÏȼ¶Toast֪ͨ¡£Óû§¿ÉÒÔÔÚÉèÖÃÖÐÊÖ¶¯¼ì²é¸üР£¬»ò´ÓMicrosoft¸üÐÂĿ¼ÊÖ¶¯ÏÂÔØ²¢°²×°´Ë¸üС£ 


https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5011563-update-fixes-smb-directx-blue-screens/


ÎÚ¿ËÀ¼µÄ¶à¸öÍøÕ¾Ôâµ½À´×ÔÊý°Ù¸öÍøÕ¾µÄDDoS¹¥»÷


¾Ý3ÔÂ28ÈÕ±¨µÀ £¬MalwareHunterTeam·¢ÏÖÁËÒ»¸ö¶ñÒâ½Å±¾¡£¹¥»÷ÕßÒÑÀûÓÃWordPressÖеÄ©¶´ÈëÇÖÁËÉϰٸöÍøÕ¾ £¬È»ºó²åÈë¸Ã¶ñÒâ½Å±¾¶ÔÎÚ¿ËÀ¼µÄÍøÕ¾Ö´ÐÐDDoS¹¥»÷ £¬Éæ¼°ÎÚ¿ËÀ¼Õþ¸®»ú¹¹¡¢ÖÇÄÒÍÅ¡¢¹ú·À¾üÕÐļºÍ½ðÈÚµÈÏà¹ØÍøÕ¾¡£Õâ¸öJavaScript½Å±¾½«Ç¿ÖƱ»ÈëÇÖµÄä¯ÀÀÆ÷¶ÔÁгöµÄ¶àÓÐÍøÕ¾Ö´ÐÐHTTP GETÇëÇó £¬Ò»´Î²»Áè¼Ý1000¸ö²¢·¢Á¬½Ó¡£´ËÍâ £¬¶ÔÄ¿±êÍøÕ¾µÄÿ¸öÇëÇó¶¼½«Ê¹ÓÃÒ»¸öËæ»ú²éѯ×Ö·û´® £¬ÕâÑùÇëÇó¾Í²»»áͨ¹ý»º´æ·þÎñ£¨ÈçCloudflare£©Ìṩ·þÎñ £¬¶øÊÇÖ±½ÓÓɱ»¹¥»÷µÄ·þÎñÆ÷½ÓÊÕ¡£


https://www.bleepingcomputer.com/news/security/hacked-wordpress-sites-force-visitors-to-ddos-ukrainian-targets/


MinervaÐû²¼¹ØÓÚÀÕË÷Èí¼þSunCryptµÄ·ÖÎö³ÂËß 


3ÔÂ28ÈÕ £¬Minerva LabsÐû²¼¹ØÓÚÀÕË÷Èí¼þSunCryptµÄ·ÖÎö³ÂËß¡£SunCryptÊÇRaaSÍÅ»ï £¬ÓÚ2019Äê10ÔÂÊ״ηºÆð £¬ÊÇ×îÔçʹÓÃÈýÖØÀÕË÷¼ÆÄ±µÄ×éÖ¯Ö®Ò»¡£³ÂËßÖ¸³ö £¬´Ë2022 SunCrypt±äÖÖÔö¼ÓÁ˺ܶàÐµĹ¦Ð§ £¬°üÂÞÖÕÖ¹½ø³Ì¡¢Í£Ö¹·þÎñ²¢Çå³ýÀÕË÷Èí¼þÖ´Ðеĺۼ£¡£¸ÃÀÕË÷Èí¼þ»¹Ê¹ÓÃÒ»¸öwinlogon.exe·ÃÎÊÁîÅÆ £¬²¢Í¨¹ýʹÓÃSetThreadToken APIµ÷Óý«ÆäÉèÖÃΪÆäÖ÷Ï̡߳£


https://blog.minerva-labs.com/suncrypt-ransomware-gains-new-abilities-in-2022


Rapid7Ðû²¼¹ØÓÚ2021ÄêÄþ¾²Â©¶´Ì¬ÊƵķÖÎö³ÂËß


3ÔÂ28ÈÕ £¬Rapid7Ðû²¼ÁËÆä×îеĩ¶´Ì¬ÊÆ·ÖÎö³ÂËß £¬Ñо¿ÁË2021Äê×îÏÔÖøµÄÄþ¾²Â©¶´ºÍÍøÂç¹¥»÷¡£2021ÄêµÄÍþвÖÐ £¬Áè¼Ý50%µÄʼÓÚÁãÈÕ©¶´¡£¸Ã³ÂËßÑо¿ÁË50¸ö©¶´ £¬ÆäÖÐÓÐ43¸öÒѱ»ÀûÓà £¬½üÒ»°ëÊÇÔÚÐÞ¸´Ö®Ç°±»ÓÃÓÚÁãÈÕ¹¥»÷¡£ÓÃ×÷ÁãÈÕ¹¥»÷µÄ©¶´ÊýÁ¿±È2020ÄêÔö¼ÓÁË100% £¬ÇÒÀûÓÃµÄÆ½¾ùʱ¼ä´Ó2020ÄêµÄ42ÌìϽµµ½2021ÄêµÄ12Ìì £»66%µÄ©¶´±»¹éÀàΪ¹ã·ºÍþв £¬ÆäÖÐ60%ÒÔÉϱ»ÓÃÓÚÀÕË÷¹¥»÷¡£


https://www.rapid7.com/info/2021-vulnerability-intelligence-report/


CISAÓëÄÜÔ´²¿ÁªºÏÐû²¼Õë¶ÔUPSÉ豸µÄ¹¥»÷µÄ×Éѯ


3ÔÂ29ÈÕ £¬ÃÀ¹úCISAÓëÄÜÔ´²¿ÁªºÏÐû²¼ÁËÕë¶Ô²»¼ä¶ÏµçÔ´(UPS)É豸µÄ¹¥»÷µÄÄþ¾²×Éѯ¡£Í¨¸æÖ¸³ö £¬ÕâЩ»ú¹¹·¢ÏÖ¹¥»÷Õßͨ³£Í¨¹ýδ¸ü¸ÄµÄĬÈÏÓû§ÃûºÍÃÜÂëÀ´·ÃÎÊÖÖÖÖÁªÍøµÄUPSÉ豸,×éÖ¯¿ÉÒÔͨ¹ý´Ó»¥ÁªÍøÉÏɾ³ý¹ÜÀí½Ó¿ÚÀ´»º½â¶ÔÆäUPSÉ豸µÄ¹¥»÷¡£CISAºÍDOE»¹ÌṩÁËÆäËüµÄ»º½â´ëÊ© £¬ÆäÖаüÂÞ²éÕÒ×éÖ¯ÍøÂçÉϵÄËùÓÐUPSºÍÆäËüÓ¦¼±µçԴϵͳ £¬²¢È·±£ËüÃÇÎÞ·¨Í¨¹ýInternet·ÃÎÊ¡£


https://www.cisa.gov/uscert/ncas/current-activity/2022/03/29/mitigating-attacks-against-uninterruptable-power-supply-devices




Äþ¾²¹¤¾ß


Gitcolombo


OSINT ¹¤¾ß £¬ÓÃÓÚ´Ó git ´æ´¢¿âÖÐÌáÈ¡ÓйØÈËÔ±µÄÐÅÏ¢¡£


https://github.com/soxoj/gitcolombo


ScheduleRunner


AC# ¹¤¾ß £¬¿É¸üÁé»îµØ×Ô½ç˵¼Æ»®ÈÎÎñ £¬ÒÔʵÏÖºì¶Ó²Ù×÷Öеij־ÃÐԺͺáÏòÒÆ¶¯¡£


https://github.com/netero1010/ScheduleRunner


phantun


Ò»¸öÇáÁ¿¼¶ºÍ¿ìËÙµÄ UDP µ½ TCP »ìÏýÆ÷¡£


https://github.com/dndx/phantun/




Äþ¾²·ÖÎö


AnonymousºÚ¿ÍÈëÇÖ 2 ¼Ò¶íÂÞ˹¹¤Òµ¹«Ë¾ £¬Ð¹Â¶ 112GB Êý¾Ý


https://www.hackread.com/anonymous-hack-russian-industrial-firms-data-leak/


Ð嵀 Windows Äþ¾²¹¦Ð§¿É×èÖ¹Ò×Êܹ¥»÷µÄÇý¶¯·¨Ê½


https://www.bleepingcomputer.com/news/microsoft/new-windows-security-feature-blocks-vulnerable-drivers/


¶íÂÞ˹ÒòÉ豸¶Ìȱ¶øÃæÁÙ»¥ÁªÍøÖжÏ


https://www.bleepingcomputer.com/news/technology/russia-facing-internet-outages-due-to-equipment-shortage/


΢ÈíΪ AMD Çý¶¯µÄ Surface Laptop 4 Ðû²¼¹Ì¼þ¸üÐÂ


https://news.softpedia.com/news/microsoft-releases-firmware-update-for-amd-powered-surface-laptop-4-535118.shtml


Trend MicroÅû¶Purple Fox½üÆÚ¹¥»÷»î¶¯µÄϸ½ÚÐÅÏ¢


https://www.trendmicro.com/en_us/research/22/c/purple-fox-uses-new-arrival-vector-and-improves-malware-arsenal.html