Kaspersky·¢ÏÖ¶à¸ö¶ÌÖÜÆÚµÄ¼äµý»î¶¯Õë¶Ô¹¤¿ØÐÐÒµ

°ä²¼¹¦·ò 2022-01-25

Kaspersky·¢ÏÖ¶à¸ö¶ÌÖÜÆÚµÄ¼äµý»î¶¯Õë¶Ô¹¤¿ØÐÐÒµ


1ÔÂ9ÈÕ£¬Kaspersky°ä²¼»ã±¨Åû¶¶à¸öÕë¶Ô¹¤¿ØÐÐÒµµÄ¼äµý»î¶¯¡£ÕâЩ»î¶¯Ê¹ÓÃÏֳɵļäµýÈí¼þ¹¤¾ß£¬Ô̺¬AgentTesla¡¢HawkEye¡¢Noon/Formbook¡¢Masslogger¡¢Snake KeyloggerºÍLokibotµÈ¡£Kaspersky³ÆÕâЩ¹¥»÷³ÆÎª¡°anomalous¡±£¬ÓÉÓÚÓ봫ͳµÄ¼äµý¹¥»÷Ïà±È£¬ËüÃǵÄÐÔÃüÖÜÆÚ¼«¶È¶ÌÔÝ£¬´óÎÞÊý´ËÀ๥»÷»á³ÖÐøÊýÔÂÉõÖÁÊýÄ꣬¶øÕâЩ»î¶¯Ô¼Îª25Ìì¡£


https://securelist.com/hunt-for-corporate-credentials-on-ics-networks/105545/


McAfee½¨¸´AgentÈí¼þÖеÄÌáȨ·ì϶CVE-2022-0166


ýÌå1ÔÂ21ÈÕ±¨Â·£¬McAfee£¨ÏÖΪTrellix£©Òѽ¨¸´ÌáȨ·ì϶£¨CVE-2022-0166£©¡£¸Ã·ì϶λÓÚWindows°æ±¾µÄMcAfee AgentÈí¼þÖУ¬Èí¼þÔÚ¹¹½¨¹ý³ÌÖÐʹÓÃopenssl.cnf½«OPENSSLDIR±äÁ¿Ö¸¶¨Îª×°ÖÃĿ¼ÖеÄ×ÓĿ¼£¬µÍȨÏÞÓû§Äܹ»ÀûÓø÷ì϶´´½¨×ÓĿ¼²¢Ê¹ÓÃSystemȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£¸Ã¹«Ë¾ÓÚ1ÔÂ18ÈÕ°ä²¼ÁËMcAfee Agent 5.7.5½¨¸´´Ë·ì϶¡£


https://securityaffairs.co/wordpress/127044/security/mcafee-agent-code-execution-flaw.html


Rust½¨¸´¿Éɾ³ýÎļþºÍĿ¼µÄ·ì϶CVE-2022-21658


Rust°²È«ÏìÓ¦¹¤×÷×é(WG)ÔÚ1ÔÂ20ÈÕ°ä²¼µÄ²¼¸æÖаµÊ¾£¬Æä²úÆ·´æÔÚÒ»¸öÑϳÁµÄ·ì϶¡£·ì϶±»×·×ÙΪCVE-2022-21658£¬CVSSÆÀ·ÖΪ7.3£¬Ó°ÏìÁËRust 1.0.0µ½Rust 1.58.0°æ±¾¡£¸Ã·ì϶ԴÓڳ߶ȿ⺯Êýstd::fs::remove_dir_allÈÝÒ×Êܵ½ÆôÓ÷ûºÅÁ´½Ó¸ú×ٵľºÕùǰÌáµÄÓ°Ï죬¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶ÓÕÊ¹ÌØÈ¨·¨Ê½É¾³ýÆäÎÞ·¨½Ó¼û»òɾ³ýµÄÎļþºÍĿ¼¡£¸ÃÍŶÓÔÚÉÏÖܰ䲼µÄRust 1.58.1°æ±¾Öн¨¸´ÁË´Ë·ì϶¡£


https://thehackernews.com/2022/01/high-severity-rust-programming-bug.html


Fortinet·¢ÏÖ¼ÙÒ⺽Ô˹«Ë¾·Ö·¢STRRATµÄ´¹µö»î¶¯


FortinetÔÚ1ÔÂ20ÈÕ¹«¿ªÁËÖ¼ÔÚ·Ö·¢Ô¶³Ì½Ó¼ûľÂíSTRRATµÄ´¹µö»î¶¯¡£Õâ´Î»î¶¯¼ÙÒ⺽Ô˹«Ë¾ÂíÊ¿»ùº½Ô˹«Ë¾£¨Maersk Shipping£©£¬Ê¹ÓÃÒÔ×°ÔË¡¢½»»õÈÕÆÚ¸ü¸Ä»ò²É°ì֪ͨµÄ´¹µöÓʼþ£¬µ±Ö¸±ê´ò¿ªÓʼþÖеĸ½¼þºó¾Í»áÔËÐжñÒâºê²¢×°ÖÃSTRRAT¡£STRRATÄܹ»ÇÔȡָ±êµÄÐÅÏ¢£¬»òÕß½øÐмٵÄÀÕË÷¹¥»÷£¨ÔÚ¹¥»÷ÖÐûÓÐÎļþ±»¼ÓÃÜ£©¡£´Ë±í£¬¹¥»÷ÕßʹÓÃÁËAllatori¹¤¾ß¶ÔÈí¼þ°ü½øÐÐÁË»ìºÏ£¬ÒÔÈÆ¹ý°²È«²úÆ·µÄ¼ì²â¡£


https://www.bleepingcomputer.com/news/security/phishing-impersonates-shipping-giant-maersk-to-push-strrat-malware/


Check Point°ä²¼2021ÄêÍøÂç¹¥»÷»î¶¯µÄ»ØÊ׻㱨


1ÔÂ21ÈÕ£¬Check Point°ä²¼ÁË2021ÄêÍøÂç¹¥»÷»î¶¯µÄ»ØÊ׻㱨¡£×ÜÌå¶øÑÔ£¬Óë2020ÄêÏà±È£¬2021Äê×é֯ÿÖÜÔâÓöµÄ¹¥»÷´ÎÊýÔö³¤ÁË50%¡£Õë¶ÔTOP 16ÐÐÒµµÄ¹¥»÷¾ùÔÈÔö³¤ÁË55%£¬ÆäÖнÌÓýºÍ×êÑв¿ÃÅÊÇÊܹ¥»÷×î¶àµÄÐÐÒµ£¬¾ùÔÈÿÖÜÔâµ½1605´Î¹¥»÷£¨Ôö³¤75%£©£¬Æä´ÎΪµ±¾ÖºÍ¾ü¶Ó£¨1136´Î£¬Ôö³¤47%£©ÒÔ¼°Í¨Ñ¶ÐÐÒµ£¨1079´Î£¬Ôö³¤51%£©£»Õë¶ÔÈí¼þ¹©¸øÉ̹¥»÷´ÎÊýµÄÔö·ù×î´ó£¬Í¬±ÈÔö³¤ÁË146%¡£


https://blog.checkpoint.com/2022/01/21/2022-security-report-software-vendors-saw-146-increase-in-cyber-attacks-in-2021-marking-largest-year-on-year-growth/


Cleafy½üÆÚ·¢ÏÖAndroid¶ñÒâÈí¼þBRATAµÄбäÌå


¾ÝýÌå1ÔÂ24ÈÕ±¨Â·£¬Cleafy³ÆAndroid¶ñÒâÈí¼þBRATAÔÚÆäбäÌåÖÐÔö³¤¶à¸öÖ°ÄÜ¡£BRATAÊÇÒ»¿îÖØÒªÕë¶Ô°ÍÎ÷Óû§µÄAndroid RAT£¬ÔÚ2019Äê³õ´Î±»Kaspersky·¢ÏÖ¡£¸Ã±äÌå´Ë¿ÌÖØÒªÕë¶ÔÓ¢¹ú¡¢²¨À¼¡¢Òâ´óÀû¡¢Î÷°àÑÀ¡¢ÖйúºÍÀ­¶¡ÃÀÖ޵ĵç×ÓÒøÐеÄÓû§£¬ÐÂÔöÁ˼üÅ̼ͼְÄÜ¡¢GPS ¸ú×ÙÖ°ÄÜ£¬Äܹ»Ö´Ðгö³§³ÁÖÃÒԶϸùËùÓжñÒâ»î¶¯µÄºÛ¼££¬»¹Ôö³¤ÁËÄܹ»Ö§³ÖHTTPºÍWebSocketsµÄÐÂC2ͨѶͨ·¡£


https://www.bleepingcomputer.com/news/security/android-malware-brata-wipes-your-device-after-stealing-data/


°²È«¹¤¾ß


CFRipper


»ùÓÚ Python µÄ¿âºÍ CLI °²È«·ÖÎöÆ÷£¬ÓÃ×÷ AWS CloudFormation °²È«É¨ÃèºÍÉ󼯹¤¾ß¡£


https://github.com/Skyscanner/cfripper


TokenUniverse


ʹÓýӼûÁîÅÆºÍ Windows °²È«Õ½ÊõµÄ¸ß¼¶¹¤¾ß¡£


https://github.com/diversenok/TokenUniverse


Registry Spy


Ãâ·ÑµÄ¿ªÔ´¿çƽ̨ Windows ×¢²á±í²é¿´Æ÷¡£


https://github.com/andyjsmith/Registry-Spy


SysmonSimulator


ÓÃC˵»°´´½¨µÄ¿ªÔ´ Windows ÊÂÎñ·ÂÕÕʵÓ÷¨Ê½£¬¿ÉÓÃÓÚ·ÂÕÕ´óÎÞÊýʹÓà WINAPI µÄ¹¥»÷¡£


https://github.com/ScarredMonk/SysmonSimulator


HazProne


ÔÆÉøÈë²âÊÔ¿ò¼Ü£¬ÓÃÓÚÉøÈë²âÊÔ·ì϶¡£


https://github.com/stafordtituss/HazProne


°²È«·ÖÎö


΢ÈíĬÈϽûÓÃExcel 4.0ºêÀ´×èÖ¹¶ñÒâÈí¼þ


https://www.bleepingcomputer.com/news/microsoft/microsoft-disables-excel-40-macros-by-default-to-block-malware/


SonicWall ΪÏÝÈë³ÁÆôÑ­»·µÄ·À»ðǽ¹²ÏíÌṩһʱ½¨¸´


https://www.bleepingcomputer.com/news/technology/sonicwall-shares-temp-fix-for-firewalls-stuck-in-reboot-loop/


΢ÈíÁгöÁËÒªÔ¤·ÀµÄ Windows 10 ×éÕ½Êõ


https://www.bleepingcomputer.com/news/microsoft/microsoft-lists-the-windows-10-group-policies-to-avoid/


ProtonMail ÒýÈëÁËÒ»¸öеĵç×ÓÓʼþ¸ú×ÙÆ÷×èֹϵͳ


https://www.bleepingcomputer.com/news/security/protonmail-introduces-a-new-email-tracker-blocking-system/


F5 ½¨¸´ÁË BIG-IP¡¢BIG-IQ ºÍ NGINX ²úÆ·ÖÐµÄ 25 ¸öȱµã


https://securityaffairs.co/wordpress/127097/security/f5-big-ip-flaws.html