Google PlayÖжñÒâÈí¼þAutolycosÒѱ»ÏÂÔØ300Íò´Î
Ðû²¼Ê±¼ä 2022-07-15
¾ÝýÌå7ÔÂ13ÈÕ±¨µÀ£¬Google PlayÉ̵êÖдæÔÚÒ»¸öеÄAndroid¶ñÒâÈí¼þAutolycos£¬ÏÂÔØÁ¿ÒÑÁè¼Ý300Íò´Î¡£Autolycos»áÃØÃÜΪÓû§¶©Ôĸ߼¶·þÎñ£¬ÖÁÉÙ´æÔÚÓÚ8¸öAndroidÓ¦ÓÃÖУ¬ÈçVlog Star Video Editor£¨100Íò´ÎÏÂÔØ£©ºÍCreative 3D Launcher£¨100Íò´ÎÏÂÔØ£©µÈ£¬EvinaÑо¿ÈËÔ±ÔÚ2021Äê6Ô·¢ÏÖÕâЩӦÓá£Autolycos»áÒþ±ÎµØÖ´Ðй¥»÷£¬²¢¿ÉÒÔ·ÃÎÊÄ¿±êµÄSMSÎı¾ÏûÏ¢¡£Ä¿Ç°£¬GoogleÒÑÔÚPlayÉ̵êÖÐɾ³ýÁËÕâЩӦÓá£
https://www.bleepingcomputer.com/news/security/new-android-malware-on-google-play-installed-3-million-times/
2¡¢Î¢ÈíÅû¶macOSɳºÐÌÓÒÝ©¶´CVE-2022-26706µÄϸ½Ú
7ÔÂ13ÈÕ£¬Î¢ÈíÅû¶ÁËmacOSÖеÄÒ»¸ö©¶´£¨CVE-2022-26706£©£¬Ëü¿Éͨ¹ýÌØÖÆ´úÂëÈÆ¹ýɳºÐÏÞÖÆ²¢ÔÚϵͳÉÏÖ´ÐдúÂë¡£Ñо¿ÈËÔ±½âÊͳƣ¬¸Ã©¶´ÊÇÔÚmacOSÉÏÔËÐкͼì²âMicrosoft OfficeÎĵµÖеĶñÒâºêÒªÁìʱ·¢Ïֵġ£ÎªÈ·±£Ïòºó¼æÈÝ£¬Microsoft Word¿ÉÒÔ¶Áд´øÓÐǰ׺"~$"µÄÎļþ£¬ÕâÊÇÔÚÓ¦Ó÷¨Ê½µÄɳºÐ¹æÔòÖнç˵µÄ¡£Ê¹ÓÃLaunch Services¶ÔÒ»¸ö´øÓÐÉÏÊöǰ׺µÄÌØÊâPythonÎļþÔËÐÐopen -stdinÃüÁ¿ÉÒÔÔÚmacOSÉϵÄAppɳºÐÌÓÒÝ£¬²¢ÈëÇÖϵͳ¡£¸Ã©¶´ÔÚ½ñÄê5ÔµÄmacOSÄþ¾²¸üÐÂ(Big Sur 11.6.6)ÖÐÐÞ¸´¡£
https://www.microsoft.com/security/blog/2022/07/13/uncovering-a-macos-app-sandbox-escape-vulnerability-a-deep-dive-into-cve-2022-26706/
3¡¢AMDºÍIntel CPUÒ×ÊÜÍÆ²âÖ´Ðй¥»÷RetbleedµÄÓ°Ïì
¾Ý7ÔÂ13ÈÕ±¨µÀ£¬ËÕÀèÊÀÁª°îÀí¹¤Ñ§ÔºµÄÑо¿ÈËÔ±·¢ÏÖÁË¿ÉÓ°ÏìAMDºÍIntel CPUµÄÐÂÍÆ²âÖ´Ðй¥»÷Retbleed¡£RetbleedÒ²³ÆÎªSpectre-BTI£¬°üÂÞ2¸ö©¶´CVE-2022-29900(AMD)ºÍCVE-2022-29901(Intel)£¬¿ÉÈÆ¹ýµ±Ç°µÄ·ÀÓù²¢µ¼Ö»ùÓÚSpectreµÄ¹¥»÷¡£ËäÈ»Ðí¶à²Ù×÷ϵͳʹÓÃÁËÏñRetpolineÕâÑùµÄ±£»¤´ëÊ©À´·ÀÓù·ÖÖ§Ä¿±ê×¢Èë(BTI)£¬µ«Retbleed¿ÉÒÔÈÆ¹ýÕâÖÖ¼ÆÄ±£¬½Ù³ÖÄÚºËÖеķµ»ØÖ¸Áî²¢Ö´ÐÐÈÎÒâÍÆ²âÐÔ´úÂë¡£
https://thehackernews.com/2022/07/new-retbleed-speculative-execution.html
4¡¢°Í»ù˹̹¿Õ¾ü×ܲ¿Ôâµ½Ó¡¶ÈÍÅ»ïSidewinderµÄ¹¥»÷
Check Point7ÔÂ13Èճƣ¬°Í»ù˹̹¿Õ¾ü×ܲ¿Ôâµ½ÁËÒÉËÆÓ¡¶ÈAPT×éÖ¯SidewinderµÄ¹¥»÷¡£2022Äê5Ô£¬Óë¹¥»÷»î¶¯Ïà¹ØµÄ¶à¸ö¶ñÒâÈí¼þÑù±¾ºÍÁ½¸ö¼ÓÃÜÎļþ±»ÉÏ´«µ½VirusTotal¡£ÔÚ½âÃÜÎļþºó£¬CPR·¢ÏÖÒ»¸öÓëSidewinderÍÅ»ïÏà¹ØµÄ.NET DLL£¬¸ÃÍÅ»ïÖ÷ÒªÕë¶Ô°Í»ù˹̹µÄʵÌå¡£µÚ¶þ¸ö¼ÓÃÜÎļþ°üÂÞÁËÄ¿±êÉ豸ÉÏËùÓÐÎļþµÄÁÐ±í£¬ÆäÖдó²¿ÃÅÓë¾üʺͺ½¿ÕÓйء£´ËÍ⣬±»¹¥»÷ϵͳµÄÓû§Ãû°üÂÞAHQ-STRC3£¬¶øAHQ´ú±í°Í»ù˹̹¿Õ¾ü×ܲ¿¡£
https://blog.checkpoint.com/2022/07/13/a-hit-is-made-suspected-india-based-sidewinder-apt-successfully-cyber-attacks-pakistan-military-focused-targets/
5¡¢ÃÀ¹ú×·Õ®¹«Ë¾PFC½ü200ÍòÒ½ÁÆÊý¾ÝÔÚÀÕË÷¹¥»÷ºóй¶
ýÌå7ÔÂ14Èճƣ¬ÃÀ¹úÊÕÕ®¹«Ë¾Professional Finance Company(PFC)й¶ÁË650¶à¼ÒÒ½ÁÆ»ú¹¹µÄ190ÍòÈ˵ÄÐÅÏ¢¡£PFCÖ÷ҪΪҽÁƹ«Ë¾×·ÌÖδ³¥Õ®Îñ£¬ÔÚ2ÔÂ26ÈÕ·¢ÏÖÆäÔâµ½ÁËÀÕË÷¹¥»÷£¬Ö±µ½5Ô³õ²Å֪ͨ¸Ãʼþ¡£PFCµÄÉùÃ÷³ÆÎ´¾ÊÚȨµÄµÚÈý·½·ÃÎÊÁ˰üÂÞ¸öÈËÐÅÏ¢µÄÎļþ£¬ËäÈ»²¢Î´Í¸Â¶ÊÜÓ°ÏìµÄ¸öÈËÊýÁ¿£¬µ«ÎÀÉúÓ빫ÖÚ·þÎñ²¿(DHHS) ÍøÕ¾ÏÔʾ£¬ÓÐ1918841ÈËÊܵ½´ËʼþµÄÓ°Ïì¡£PFCÕýÔÚÁªÏµ¿ÉÄÜÊܵ½Ó°ÏìµÄ¸öÈË£¬²¢½«ÎªËûÃÇÌṩÃâ·ÑµÄÐÅÓÃ¼à¿Ø¡£
https://www.infosecurity-magazine.com/news/healthcare-records-breaches/
6¡¢ZscalerÐû²¼QakbotʹÓõĶà¸öм¼ÊõµÄ·ÖÎö³ÂËß
7ÔÂ12ÈÕ£¬ZscalerÐû²¼Á˹ØÓÚ¶ñÒâÈí¼þQakbotµÄ¼¼Êõ·ÖÎö³ÂËß¡£Qakbot×Ô2008Ä꿪ʼ»îÔ¾£¬ÊÇÒ»ÖÖÇÔÈ¡ÃÜÂëµÄ³£¼ûľÂí£¬½üÆÚ£¬Qakbot±³ºóµÄÔËÓªÍÅ»ïÕýÔÚ¸üÐÂÆäÁ÷´«ÔØÌ壬ÒÔÊÔÍ¼ÈÆ¹ý¼ì²â¡£¹¥»÷Õßͨ¹ýʹÓÃZIPÎļþÀ©Õ¹ÃûÒÔ¼°¾ßÓг£¼û¸ñʽµÄÎļþÃûºÍExcel(XLM) 4.0À´ÓÕʹĿ±êÏÂÔØ°²×°Qakbot¶ñÒ⸽¼þ£¬³ý´ËÖ®Í⣬¹¥»÷Õß»¹ÔÚʹÓÃÁËÆäËü¼¼ÊõÀ´Èƹý×Ô¶¯¼ì²â²¢Ìá¸ßµÄ¹¥»÷ÀÖ³ÉÂÊ£¬°üÂÞ»ìÏý´úÂë¡¢ÀûÓöà¸öURLÀ´·Ö·¢payloadºÍʹÓÃδ֪µÄÎļþÀ©Õ¹ÃûÀ´·Ö·¢payloadµÈ¡£
https://www.zscaler.com/blogs/security-research/rise-qakbot-attacks-traced-evolving-threat-techniques