¼ÓÄôó5¼Ò´óÐÍÒøÐÐÒòδ֪ÔÒò·þÎñÖжÏÊýÓ×ʱ
°ä²¼¹¦·ò 2022-02-21¼ÓÄôó5¼Ò´óÐÍÒøÐÐÒòδ֪ÔÒò·þÎñÖжÏÊýÓ×ʱ
¾ÝýÌå2ÔÂ17ÈÕ±¨Â·£¬¼ÓÄôó5¼Ò´óÐÍÒøÐзþÎñÖжÏÊýÓ×ʱ¡£ÖжϲúÉúÔÚ±¾ÖÜÈýÏÂÎç5µãµ½6µãÖ®¼ä£¬Ô̺¬¼ÓÄôó»Ê¼ÒÒøÐУ¨RBC£©¡¢ÃÉÌØÀû¶ûÒøÐУ¨BMO£©¡¢·áÒµÒøÐÓע·Ã÷ÒøÐУ¨TD£©ºÍ¼ÓÄôóµÛ¹úóÒ×ÒøÐУ¨CIBC£©¡£RBC³ÆÓöµ½Á˼¼ÊõÎÊÌ⣬BMOÈ«Çò»ã¿î·þÎñÈ«Ìì¹Ø¹Ø£¬CIBCÉÐδÈÏ¿ÉËûÃǵÄÍøÉÏÒøÐдæÔÚÎÊÌ⣬TD BankµÄÒÆ¶¯ÒøÐÐÎÞ·¨½Ó¼ûµ«°ä²¼ÉêÃ÷³ÆÃ»ÓÐÓöµ½ÈκÎÖжÏÎÊÌ⡣Ŀǰ£¬Õâ´ÎÖжÏÊÂÎñµÄÔÒòÉв»Ã÷È·¡£
https://www.bleepingcomputer.com/news/security/canadas-major-banks-go-offline-in-mysterious-hours-long-outage/
FBI¡¢NSAºÍCISA°ä²¼¶íÂÞ˹ºÚ¿Í¶Ô×¼ÃÀ¹ú¹ú·ÀÐÐÒµµÄ¹«¸æ
2ÔÂ16ÈÕ£¬ÃÀ¹úFBI¡¢NSAºÍCISA½áºÏ°ä²¼Á˶íÂÞ˹ºÚ¿Í¶Ô×¼ÃÀ¹ú¹ú·ÀÐÐÒµµÄ¹«¸æ¡£¹«¸æ³Æ£¬¸Ã»î¶¯ÆðÍ·ÓÚ2020Äê1Ô£¬ÀûÓÃÁËÓã²æÊ½ÍøÂç´¹µö¡¢Í´´¦ÍøÂç¡¢±©Á¦ÆÆ½âµÈ¼¼ÊõºÍ VPN É豸ÖеÄÒÑÖª·ì϶£¬¹¥»÷¹ú¶ÈºË×¼µÄ¹ú·À³Ð°üÉÌ(CDC)£¬ÒÔ»ñÈ¡Óë¹ú·ÀºÍµý±¨ÁìÓòÓйصĻúÃÜÐÅÏ¢¡£¹¥»÷ÕßÓÃÓÚ³õʼ½Ó¼ûºÍȨÏÞÌáÉýµÄ·ì϶Ô̺¬CVE-2018-13379¡¢CVE-2020-0688ºÍCVE-2020-17144¡£
https://www.cisa.gov/news/2022/02/16/new-cybersecurity-advisory-protecting-cleared-defense-contractor-networks-against
Egress³Æ×Ô2Ô·ݼÙÒâLinkedInµÄ´¹µö¹¥»÷Ôö³¤232%
¾Ý2ÔÂ16ÈÕ±¨Â·£¬Egress·¢ÏÖ×Ô2ÔÂ1ÈÕÒÔÀ´£¬¼ÙÒâLinkedInµÄ´¹µö¹¥»÷Ôö³¤ÁË232%¡£¹¥»÷ÕßʹÓÃÁË¿´ÆðÀ´¼«¶ÈÕæÊµµÄHTMLÄ£°å£¬ÒÔ¼°´øÓÐLinkedInÃû³ÆµÄÓʼþµØÖ·£¬Ö¼ÔÚÓÕʹÓû§µã»÷´¹µöÁ´½Ó²¢ÊäÈëÍ´´¦¡£Õâ´Î»î¶¯ÖØÒªÕë¶ÔÓ¢¹úºÍ±±ÃÀµØÓò£¬Ê¹ÓÃÁËOutlook 365ƽ̨£¬²¢Äܹ»Èƹý´«Í³µÄµç×ÓÓʼþ°²È«·ÀÓù»úÔì¡£
https://www.egress.com/resources/cybersecurity-information/phishing/linkedin-phishing-attacks
ÃÀ¹úÁ½¼ÒÒ½ÔºSSHºÍFCHCй¶½ü15Íò»¼ÕßµÄÓ×ÎÒÐÅÏ¢
ýÌå2ÔÂ16Èճƣ¬ÃÀ¹úÒÁÀûŵÒÁÖݽü150000¸ö¾ÓÃñµÄPHIÐÅϢй¶¡£Õâ´Îй¶µÄÐÅÏ¢Ô´ÓÚÁ½¼ÒÒ½Ôº£ºÖ¥¼Ó¸çµÄÄϰ¶Ò½Ôº(SSH)³ÆËûÃÇÓÚ2021Äê12ÔÂ10ÈÕ·¢ÏÖ¿ÉÒɻ£¬¾µ÷²éÈ·¶¨½ü116000¸ö»¼ÕߺÍÔ±¹¤µÄÐÅϢй¶£»ÒÁÀûŵÒÁÖݹþάµÄÒ½ÔºFCHCÔÚ2021Äê11ÔÂ18ÈÕ×óÓÒÔâµ½ÀÕË÷¹¥»÷£¬µ«Ö±µ½11ÔÂ30Èղŷ¢ÏÖÊý¾Ýй¶£¬Éæ¼°31000¸ö»¼Õß¡£ÆäÖУ¬SSH³Æ½«ÎªËùÓÐÊÜÓ°ÏìµÄ¾ÓÃñÌṩÉí·Ý͵ÇÔ±£»¤·þÎñ¡£
https://www.infosecurity-magazine.com/news/healthcare-data-breaches-impact/
Cisco½¨¸´ÆäÓʼþ°²È«É豸ÖÐDoS·ì϶CVE-2022-20653
CiscoÔÚ2ÔÂ16ÈÕ°ä²¼°²È«¸üУ¬½¨¸´ÆäÓʼþ°²È«É豸ÖÐDoS·ì϶£¨CVE-2022-20653£©¡£¸Ã·ì϶´æÔÚÓÚAsyncOSÈí¼þµÄ»ùÓÚDNSµÄ¶¨ÃûʵÌåÉí·ÝÑéÖ¤(DANE)×é¼þÖУ¬ÊÇÓÉÓÚ¶ÔDNSÃû³Æ½âÎöµÄÃýÎó´¦Öò»¼°µ¼Öµġ£Cisco°ä²¼µÄ¹«¸æ³Æ£¬¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËÍÌØÊâÌåʽµÄµç×ÓÓʼþÀ´ÀûÓô˷ì϶£¬³É¹¦ÀûÓÿɵ¼ÖÂÎÞ·¨½Ó¼ûÖÎÀí½çÃæ»ò´¦Ööî±íµÄÓʼþÐÂÎÅ£¬´Ó¶ø´¥·¢DoS¡£
https://www.bleepingcomputer.com/news/security/cisco-bug-can-let-hackers-crash-cisco-secure-email-gateways/
CrowdStrike°ä²¼2021ÄêÈ«ÇòÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨
2ÔÂ15ÈÕ£¬CrowdStrike°ä²¼ÁË2021ÄêÈ«ÇòÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬ÓëÀÕË÷Èí¼þÓйصÄÊý¾Ýй¶ÔÚ2021Äêͬ±ÈÔö³¤ÁË82%£¬´Ó1474ÆðÉÏÉýµ½2686Æð£»62% µÄ¹¥»÷ûÓÐʹÓõ½¶ñÒâÈí¼þ£»×îÒýÈËÖõÖ÷ÕÅ·ì϶ÊÇLog4Shell£¬Ô¶³Ì¹¥»÷ÕßÄܹ»ÀûÓÃÆä×¢ÈëJava´úÂ룻ÀûÓÃÔÆ·þÎñµÄ¹¥»÷»î¶¯Ôö¶à£»Ð³öÏÖÁË21¸öºÚ¿ÍÍŻ½»»¥ÈëÇֻÔö³¤45%£»¹©¸øµÄ¾ùÔÈʱ³¤Îª1Ó×ʱ38·ÖÖÓ¡£
https://www.crowdstrike.com/global-threat-report/
°²È«¹¤¾ß
Unredacter
¸Ã¹¤¾ß¿É´ÓÍÌ͵ÄÏñËØ»¯Í¼ÏñÖгÁ½¨Îı¾¡£
https://github.com/bishopfox/unredacter
Macrome
ÓÃÓÚºì¶ÓºÍ·ÖÎöʦµÄ Excel ºêÎĵµÔĶÁÆ÷/±àдÆ÷¡£
https://github.com/michaelweber/Macrome
FakeLogonScreen
ÊÇÒ»¸öαÔì Windows µÇ¼ÆÁÄ»ÒÔ»ñÈ¡Óû§ÃÜÂëµÄʵÓ÷¨Ê½¡£
https://github.com/bitsadmin/fakelogonscreen
WELA
Windows ÊÂÎñÈÕÖ¾·ÖÎöÆ÷£¬×î´óÖ°ÄÜÊÇ´´½¨Ò×ÓÚ·ÖÎöµÄµÇ¼¹¦·òÏߣ¬ÒÔÔ®ÊÖ¼±¾çȡ֤ºÍÊÂÎñÏìÓ¦¡£
https://github.com/Yamato-Security/WELA/
jwt-hack
ÊÇÓÃÓÚ¶ÔJWT½øÐкڿÍ/°²È«²âÊԵŤ¾ß¡£
https://github.com/hahwul/jwt-hack/
°²È«·ÖÎö
Mozilla ÖÒ¸æ Chrome¡¢Firefox '100' Óû§´úÀí¿ÉÄÜ»á·ÛËéÍøÕ¾
https://www.bleepingcomputer.com/news/software/mozilla-warns-chrome-firefox-100-user-agents-may-break-sites/
Å·ÃËÒþÖÔ¼à¹Ü»ú¹¹µ«Ô¸²»ÈÝ Pegasus ¼äµýÈí¼þ
https://www.bleepingcomputer.com/news/security/blackcat-alphv-claims-swissport-ransomware-attack-leaks-data/
FBI ÖÒ¸æ BEC ¹¥»÷ÕßÔÚÐé¹¹»áÒéÖмÙÒâ CEO
https://www.bleepingcomputer.com/news/security/fbi-warns-of-bec-attackers-impersonating-ceos-in-virtual-meetings/
Á¢ÌÕÍðºÍ²¨À¼°ä²¼ÍøÂç¹¥»÷ÖÒ¸æ
https://www.infosecurity-magazine.com/news/lithuania-poland-cyber-attack/
¹ú¼ÊºìÊ®×ÖίԱ»á°µÊ¾ºÚ¿ÍÀûÓà Zoho ·ì϶ÈëÇÔìäÍøÂç
https://www.bleepingcomputer.com/news/security/red-cross-state-hackers-breached-our-network-using-zoho-bug/
Microsoft£ºÇø¿éÁ´Éϵġ°Ice phishing¡±
https://www.microsoft.com/security/blog/2022/02/16/ice-phishing-on-the-blockchain/


¾©¹«Íø°²±¸11010802024551ºÅ