ÏÖ´úÆû³µ·¢ÉúÊý¾ÝÐ¹Â¶Éæ¼°·¨¹úºÍÒâ´óÀûµÄ¿Í»§

Ðû²¼Ê±¼ä 2023-04-14

1¡¢ÏÖ´úÆû³µ·¢ÉúÊý¾ÝÐ¹Â¶Éæ¼°·¨¹úºÍÒâ´óÀûµÄ¿Í»§


¾ÝýÌå4ÔÂ12ÈÕ±¨µÀ£¬ÏÖ´úÆû³µÅû¶ÁËÒ»ÆðÊý¾Ýй¶Ê¼þ£¬Ó°ÏìÆä·¨¹úºÍÒâ´óÀûµÄ¿Í»§¡£¸Ã¹«Ë¾ÔÚ֪ͨÖгÆ£¬Î´¾­ÊÚȨµÄµÚÈý·½·ÃÎÊÁ˿ͻ§Êý¾Ý¿â£¬ËûÃÇ»¹ÔÚÈ·¶¨Ê¼þµÄ·¶Î§¡£Ð¹Â¶ÐÅÏ¢°üÂÞµç×ÓÓʼþµØÖ·¡¢¼ÒÍ¥µØÖ·¡¢µç»°ºÅÂëºÍ³µÁ¾Ê¶±ðºÅµÈ£¬ÊÜÓ°ÏìµÄÈËÊýÉв»Çå³þ¡£ÎªÓ¦¶ÔÕâһʼþ£¬¸Ã¹«Ë¾Òѽ«ÊÜÓ°ÏìµÄϵͳÏÂÏß¡£½ñÄê2Ô·Ý£¬ÏÖ´úÔøÐû²¼½ô¼±¸üУ¬ÐÞ¸´¿Éͨ¹ýUSBÊý¾ÝÏßµÁ³µµÄ©¶´¡£


https://securityaffairs.com/144732/data-breach/hyundai-suffered-data-breach.html


2¡¢¾©´ÉÐÞ¸´ÆäAndroid´òÓ¡Ó¦ÓÃÖЩ¶´CVE-2023-25954


ýÌå4ÔÂ12Èճƣ¬¾©´É£¨Kyocera£©ÐÞ¸´ÆäAndroid´òÓ¡Ó¦ÓÃÖÐÁ÷´«¶ñÒâÈí¼þµÄ©¶´£¨CVE-2023-25954£©¡£Â©¶´Ó°ÏìÁËKYOCERA Mobile Print¡¢UTAX/TA Mobile PrintºÍOlivetti Mobile Print¡£¾¡¹ÜÕâЩӦÓõÄÐû²¼Õß²îÒ죬µ«ËüÃÇ»ùÓÚÏàͬµÄ´úÂ룬Òò´Ë¶¼ÊÐÊÜÓ°Ïì¡£ÕâЩӦÓ÷¨Ê½ÔÊÐí´Ó¶ñÒâµÚÈý·½Òƶ¯Ó¦Óô«ÊäÊý¾Ý£¬¿ÉÏÂÔØ¶ñÒâpayload¡£¶øÇÒ£¬Í¨¹ýʹÓþ©´ÉÒÆ¶¯´òÓ¡Ó¦ÓõÄä¯ÀÀÆ÷¹¦Ð§£¬¿É·ÃÎʶñÒâÍøÕ¾²¢ÏÂÔØºÍÖ´ÐжñÒâÎļþ£¬µ¼ÖÂÒÆ¶¯É豸ÐÅϢй¶¡£¾©´ÉÒÑÐÞ¸´¸Ã©¶´£¬¼´½«ÍƳöµÄAndroid 14Ò²ÓÐÍû¼õÇá´ËÀà·çÏÕ¡£


https://www.bleepingcomputer.com/news/security/kyocera-android-app-with-1m-installs-can-be-abused-to-drop-malware/


3¡¢NorthOne BankÊý¾Ý¿âÅäÖôíÎóй¶100ÍòÌõ²ÆÕþ¼Ç¼


¾Ý4ÔÂ12ÈÕ±¨µÀ£¬½ðÈڿƼ¼¹«Ë¾NorthOne BankÊý¾Ý¿âÅäÖôíÎó£¬Ð¹Â¶Áè¼Ý100ÍòÌõ²ÆÕþ¼Ç¼¡£Êý¾Ý¿âÖйûÈ»µÄPDFÎļþ°üÂÞʹÓÃÓ¦Ó÷¨Ê½Ö§¸¶²úÎïºÍ·þÎñµÄ¸öÈËºÍÆóÒµµÄ·¢Æ±¡£Éæ¼°ÐÕÃû¡¢µØÖ·ºÍµç»°ºÅÂëµÈ£¬»¹°üÂÞÓйظ¶¿îÓÃ;¡¢×ܽð¶îºÍµ½ÆÚÈÕµÄ×¢ÊÍ£¬ÓÐЩÉõÖÁ°üÂÞ˰ºÅµÈ˰ÎñÐÅÏ¢¡£Ñо¿ÈËÔ±ÓÚ1ÔÂ19ÈÕÊ״γÂËßÁËÕâÒ»·¢ÏÖ£¬Êý¾Ý¿âÔÚ1ÔÂ31ÈÕ±»±£»¤ÆðÀ´¡£Ä¿Ç°Éв»Çå³þÕâЩ¼Ç¼ÒÑ̻¶¶à³¤Ê±¼ä¡£


https://www.websiteplanet.com/news/northone-leak-report/


4¡¢APT36ÀûÓöñÒâÈí¼þCrimson RAT¹¥»÷Ó¡¶ÈµÄ½ÌÓýÐÐÒµ


SentinelLabsÔÚ4ÔÂ13ÈÕÅû¶ÁËAPT36(Transparent Tribe)Õë¶ÔÓ¡¶È½ÌÓýÐÐÒµµÄ¹¥»÷»î¶¯¡£¹¥»÷ÕßÀûÓÃÎäÆ÷»¯µÄMicrosoft OfficeÎĵµ£¬Í¨¹ý¶ñÒâºê»òOLEǶÈë¼¼ÊõÀ´·Ö·¢Crimson RAT¡£Ñо¿ÈËÔ±ÊӲ쵽ÖÖÖÖCrimson RAT .NETµÄʵÏÖ£¬±àÒëʱ¼äÔÚ2022Äê7ÔÂÖÁ9ÔÂÖ®¼ä¡£Æä¹¦Ð§°üÂÞÇÔȡϵͳÐÅÏ¢¡¢²¶×½ÆÁÄ»½ØÍ¼¡¢Æô¶¯ºÍÍ£Ö¹½ø³ÌÒÔ¼°ÁоÙÎļþºÍÇý¶¯Æ÷¡£Crimson RAT±äÌåʵÏÖÁ˲îÒìÇ¿¶ÈµÄ»ìÏý¼¼Êõ£¬ÀýÈ磬¼òµ¥µÄº¯ÊýÃû³Æ»û±äºÍ¶¯Ì¬×Ö·û´®½âÎö¡£


https://www.sentinelone.com/labs/transparent-tribe-apt36-pakistan-aligned-threat-actor-expands-interest-in-indian-education-sector/


5¡¢KasperskyÐû²¼LazarusµÄDeathNote»î¶¯µÄ·ÖÎö³ÂËß


4ÔÂ12ÈÕ£¬KasperskyÐû²¼Á˹ØÓÚLazarus GroupµÄDeathNote»î¶¯µÄ·ÖÎö³ÂËß¡£Ñо¿ÈËÔ±×Ô2019ÄêÒÔÀ´Ò»Ö±ÔÚ¸ú×ٸû£¬·¢ÏÖ¹¥»÷Ä¿±êÔÚ2020Äê4Ô·¢ÉúÁËÖØ´óת±ä£¬Í¬Ê±»¹¸üÐÂÁËÑ¬È¾ÔØÌå¡£DeathNote¼¯Èº±»ÓÃÓÚÕë¶Ô¶«Å·µÄÆû³µºÍѧÊõÐÐÒµ£¬ËüÃǶ¼Óë¹ú·À¹¤ÒµÓйØ¡£¹¥»÷Õß»¹½«ËùÓÐÓÕ¶üÎļþת»»ÎªÓë¹ú·À³Ð°üÉ̺ÍÍâ½»·þÎñÏà¹ØµÄְλÃèÊö¡£´ËÍ⣬ѬȾÁ´Ò²µÃµ½Á˸ïУ¬²»½öÒÀÀµÓÚÎäÆ÷»¯ÎĵµÖеÄÔ¶³ÌÄ£°å×¢Èë¼¼Êõ£¬»¹ÒÀÀµÓÚľÂí»¯µÄ¿ªÔ´PDF¼ì²ì¹¤¾ß¡£


https://securelist.com/the-lazarus-group-deathnote-campaign/109490/


6¡¢CloudflareÐû²¼2023ÄêQ1 DDoSÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß     

 

4ÔÂ11ÈÕ£¬CloudflareÐû²¼ÁË2023ÄêµÚÒ»¼¾¶ÈDDoSÍþÐ²Ì¬ÊÆµÄ³ÂËß¡£³ÂËßÖ¸³ö£¬³¬ÈÝÁ¿DDoS¹¥»÷ÓÐËùÔö¼Ó£¬×î´óµÄÒ»´Îµ½´ïÿÃë7100Íò´ÎÇëÇó(rps)ÒÔÉÏ¡£ÐÂÒ»´ú½©Ê¬ÍøÂçÖð½¥·ÅÆúÁËʹÓôóÁ¿ÎïÁªÍøÉ豸µÄ¼ÆÄ±£¬×ª¶øÊ¹ÓÃÒ×±»¹¥»÷ºÍÅäÖôíÎóµÄVPS·þÎñÆ÷£¬ÆäÇ¿¶È±È»ùÓÚÎïÁªÍøµÄ½©Ê¬ÍøÂç¸ß³ö5000±¶¡£ÀÕË÷DDoS¹¥»÷ͬ±ÈÔö¼Ó60%£¬Õ¼ËùÓÐDDoS¹¥»÷µÄ16%¡£DDoS¹¥»÷Ö÷ÒªÕë¶ÔµÄ¹ú¼ÒÊÇÒÔÉ«ÁУ¬Æä´ÎÊÇÃÀ¹ú¡¢¼ÓÄôóºÍÍÁ¶úÆä¡£


https://blog.cloudflare.com/ddos-threat-report-2023-q1/