Cado Security°µÊ¾½©Ê¬ÍøÂçAbcbotÓëXantheÓйØÁª

°ä²¼¹¦·ò 2022-01-12

΢Èí°ä²¼1ÔÂÖܶþ²¹¶¡£¬½¨¸´6¸ö0 dayÔÚÄÚµÄ97¸ö·ì϶


½ØÍ¼20220112121945.png


1ÔÂ11ÈÕ£¬Î¢Èí°ä²¼Á˽ñÄê¶ÈµÄÊ׸öÖܶþ²¹¶¡£¬×ܼƽ¨¸´97¸ö°²È«·ì϶£¨²»Ô̺¬29¸öMicrosoft Edge·ì϶£© ¡£Õâ´Î½¨¸´µÄ×îÑϳÁµÄÊÇHTTPºÍ̸ջԶ³Ì´úÂëÖ´Ðзì϶£¨CVE-2022-21907£©£¬CVSSÆÀ·ÖΪ9.8£¬¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËͶñÒâÊý¾Ý°üµ½Ö¸±ê·þÎñÆ÷À´ÀûÓø÷ì϶ ¡£´Ë±í£¬¸üл¹½¨¸´ÁË6¸ö0 day£¬Ô̺¬¿ªÔ´Curl¿âÖеÄRCE£¨CVE-2021-22947£©¡¢¿ªÔ´ Libarchive¿âÖеÄRCE£¨CVE-2021-36976£©ºÍ±¾µØWindows°²È«ÖÐÐÄAPIÖеÄRCE£¨CVE-2022-21874£©µÈ ¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-january-2022-patch-tuesday-fixes-6-zero-days-97-flaws/


EDPSÒªÇóÅ·ÖÞÐ̾¯×é֯ɾ³ýÓë·¸×ï»î¶¯Î޹صÄÓ×ÎÒÊý¾Ý


¾ÝýÌå1ÔÂ10ÈÕ±¨Â·£¬Å·ÃËÊý¾Ý±£»¤¼à¹Ü»ú¹¹EDPSºÅÁîÒªÇóÅ·ÖÞÐ̾¯×é֯ɾ³ýÓë·¸×ï»î¶¯Î޹صÄÓ×ÎÒÊý¾Ý ¡£µ±¾ÖÖ¸³ö£¬ÔÚûº±¼û¾ÝÖ÷Ìå·ÖÀàµÄÇé¿öÏ´洢´óÁ¿Êý¾Ý»á¶ÔÓ×Îҵĸù»ùÈ¨ÊÆ×é³É·çÏÕ£¬Ï൱ÓÚ´ó¹æÄ£¼à¶½ ¡£¾Ý¡¶ÎÀ±¨¡·±¨Â·£¬»º´æÖÁÉÙÔ̺¬4 PB ¡£EDPS»¹»®¶¨ÁËÁù¸öÔµı£ÁôÆÚ£¬ÒÔ¹ýÂ˺ÍÌáÈ¡Ó×ÎÒÊý¾Ý£¬²¢´ÍÓë¸Ã¿ç¾³·¨ÂÉ»ú¹¹Ò»ÄêµÄ¹¦·òÀ´Éó²éÆäÊý¾Ý¿â ¡£


https://thehackernews.com/2022/01/europol-ordered-to-delete-data-of.html


WordPress°ä²¼¸üУ¬½¨¸´SQL×¢ÈëµÈ4¸ö°²È«·ì϶


ýÌå1ÔÂ11ÈÕ±¨Â·£¬WordPress°ä²¼¸üУ¬×ܼƽ¨¸´4¸ö°²È«·ì϶ ¡£Õâ´Î½¨¸´µÄ·ì϶Ô̺¬SQL×¢Èë·ì϶£¨CVE-2022-21661£©£¬¿Éͨ¹ýʹÓÃWP-QueryµÄ²å¼þºÍÖ÷ÌâÀûÓã»XSS·ì϶£¨CVE-2022-21662£©£¬¿ÉÓÃÀ´Ö²ÈëºóÃÅ»òͨ¹ýÀÄÓÃpost slugÀ´½ÚÔìÍøÕ¾£»SQL×¢Èë·ì϶£¨CVE-2022-21664£©£¬¿Éͨ¹ýWP_Meta_QueryÀûÓã»¶ÔÏó×¢Èë·ì϶£¨CVE-2022-21663£©£¬±ØÒªÈëÇÖÖÎÀíÔ¹ØÊ»§ÄÜÁ¦ÀûÓà ¡£


https://securityaffairs.co/wordpress/126556/security/wordpress-5-8-3.html


΢ÈíÅû¶macOS·ì϶powerdir(CVE-2021-30970)ϸ½Ú


1ÔÂ10ÈÕ£¬Î¢Èí°ä²¼¹ØÓÚmacOSÖеķì϶powerdir(CVE-2021-30970)µÄ·ÖÎö»ã±¨ ¡£Î¢Èí°µÊ¾£¬¹¥»÷ÕßÄܹ»ÀûÓø÷ìÏ¶ÈÆ¹ýͨÃ÷¡¢Ô޳ɺͽÚÔì(TCC)¼¼ÊõÀ´½Ó¼ûÓû§µÄÊý¾Ý ¡£×êÑÐÈËÔ±·¢ÏÖ£¬Äܹ»Í¨¹ý±à³ÌµÄ·½Ê½´Û¸ÄÖ¸±êÓû§Ö÷Ŀ¼²¢Ö²ÈëαTCCÊý¾Ý¿â£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ƾ¾ÝÓû§Êܱ£»¤µÄÓ×ÎÒÊý¾Ý²ß¶¯¹¥»÷ ¡£Î¢ÈíÍŶÓÔÚ2021Äê7ÔÂ15ÈÕ½«·ì϶»ã±¨¸øApple¹«Ë¾£¬AppleÔÚ12ÔÂ13ÈÕ°ä²¼µÄ°²È«¸üÐÂÖн¨¸´ ¡£


https://www.microsoft.com/security/blog/2022/01/10/new-macos-vulnerability-powerdir-could-lead-to-unauthorized-user-data-access/


Cado Security°µÊ¾½©Ê¬ÍøÂçAbcbotÓëXantheÓйØÁª


Cado SecurityÔÚ1ÔÂ10ÈÕ°ä²¼µÄ»ã±¨ÏÔʾ£¬½©Ê¬ÍøÂçAbcbotÓëXantheÓйØÁª ¡£AbcbotÔÚ2021Äê11Ô³õ´Î±»¹«¿ª£¬Æäʱ¹¥»÷ÁË»ªÎª¡¢ÌÚѶ¡¢°Ù¶ÈºÍ°¢ÀïÔÆµÈÔÆ·þÎñÌṩÉÌ ¡£µ«Í¨¹ýËùÓÐÒÑÖªµÄIoCs£¬Ô̺¬IPµØÖ·¡¢urlºÍÑù±¾£¬·¢ÏÖAbcbotµÄ´úÂëºÍ»ù´¡ÉèÊ©ÓëÒ»¸öÃûΪXantheµÄ¼ÓÃܽٳֶñÒâÈí¼þ¼Ò×åÓгÁµþ ¡£×êÑÐÍŶÓÒÔΪ¶þÕßÓÉͳһ¹¥»÷ÕßÕÆ¹Ü£¬²¢ÇÒËûÃÇÕý½«Ö¸±ê´ÓÍÚ¿ó×ªÒÆµ½Óë½©Ê¬ÍøÂçÓйصĻ ¡£


https://www.cadosecurity.com/abcbot-an-evolution-of-xanthe/


Check Point³Æ2021ÄêÍøÂç¹¥»÷»î¶¯Í¬±ÈÔö³¤50%


1ÔÂ10ÈÕ£¬Check Point research°ä²¼»ã±¨³Æ2021ÄêÍøÂç¹¥»÷»î¶¯Í¬±ÈÔö³¤50% ¡£»ã±¨»¹Ö¸³ö£¬ÔÚ2021ÄêµÚËÄʱ¶È£¬Ã¿¸ö×éÖ¯µÄÿÖÜÔâµ½µÄ¹¥»÷´ÎÊý´ïµ½º¹Çà×î¸ß£¬¾ùÔÈΪ925´Î ¡£2021Ä꣬½ÌÓýºÍ×êÑÐÐÐÒµÊÇÔâµ½¹¥»÷×î¶àµÄÐÐÒµ£¬¾ùÔÈÿÖÜ1605´Î¹¥»÷£¬Õâ±È2020ÄêÔö³¤ÁË75% ¡£°´µØÓò»®·Ö£¬·ÇÖÞÔâµ½¹¥»÷×î¶à£¬¾ùÔÈÿÖÜ1582´Î£¬±È2020ÄêÔö³¤13%£¬½ôËæÆäºóµÄÊÇÑÇÌ«µØÓò£¬Ã¿ÖÜÔâµ½1353´Î¹¥»÷£¨Ôö³¤25%£© ¡£


https://blog.checkpoint.com/2022/01/10/check-point-research-cyber-attacks-increased-50-year-over-year/


°²È«¹¤¾ß


Mortar 


Mortar¿ÉÄÜÈÆ¹ýÏÖ´ú·´²¡¶¾²úÆ·ºÍÏȽøµÄXDR½â¾ö¹æ»®£¬Ô̺¬Kaspersky¡¢ESETºÍMcafeeµÈ ¡£


https://www.kitploit.com/2022/01/mortar-evasion-technique-to-defeat-and.html


RecoverPy


¿ÉÓÃÀ´¸´Ô­±»¸²¸Ç»òɾ³ýµÄÊý¾Ý£¬Ä¿Ç°½öÔÚLinuxϵͳÉÏ¿ÉÓà ¡£


https://github.com/PabloLec/RecoverPy


°²È«·ÖÎö


Linux Mint 20.3 °ä²¼


Linux Mint °ä²¼ÁË 20.3 °æ£¬´úºÅΪ¡°Una¡±£¬×÷Ϊ³Ö¾ÃÖ§³Ö°æ±¾£¬²¢³ÐŵÔÚ 2025 ÄêÄê֮ǰ°²È«¸üР¡£


https://www.bleepingcomputer.com/news/linux/linux-mint-203-released-promising-security-updates-until-2025/


ÀÕË÷Èí¼þAvosLocker Õë¶Ô VMware ESXi ·þÎñÆ÷


AvosLockerÔÚÆä×î½üµÄ¶ñÒâÈí¼þ±äÖÖÖÐÔö³¤ÁË¶Ô Linux ϵͳµÄÖ§³Ö£¬³ö¸ñÊÇÕë¶Ô VMware ESXi Ðé¹¹»ú ¡£


https://www.bleepingcomputer.com/news/security/linux-version-of-avoslocker-ransomware-targets-vmware-esxi-servers/