ÀÕË÷ÍÅ»ïLapsus$Ðû³ÆÒÑ´ÓÈýÐǵç×ÓÇÔÈ¡190GBµÄÊý¾Ý

°ä²¼¹¦·ò 2022-03-08

ÀÕË÷ÍÅ»ïLapsus$Ðû³ÆÒÑ´ÓÈýÐǵç×ÓÇÔÈ¡190GBµÄÊý¾Ý


3ÔÂ4ÈÕ £¬ÀÕË÷ÍÅ»ïLapsus$°ä²¼Ò»·ÝÉêÃ÷ £¬³ÆÆäÒÑ´ÓÈýÐǵç×ÓÇÔÈ¡190GBµÄÊý¾Ý ¡£¸ÃÍŻォÇÔÈ¡µ½µÄÊý¾Ý²ð·ÖΪÈý¸öѹËõÎļþ £¬±ðÀëΪ£ºÓйØSecurity/Defense/Knox/Bootloader/TrustedAppsµÈÏîÖ÷ÕÅÔ´´úÂëºÍÓйØÊý¾Ý£»ÓйØÉ豸°²È«ºÍ¼ÓÃܵÄÔ´´úÂëºÍÓйØÊý¾Ý£»À´×ÔÈýÐÇGithubµÄ¸÷Àà´æ´¢¿â £¬ÈçÒÆ¶¯·ÀÓù¹¤³Ì¡¢ÈýÐÇÕÊ»§ºó¶Ë¡¢ÈýÐÇͨ³©Ö¤ºó¶Ë/ǰ¶ËºÍSES ¡£Éв»Ã÷ÏÔLapsus$ÊÇ·ñÁªÏµÁËÈýÐÇË÷ÒªÊê½ð £¬ÈýÐÇҲδ¶Ô´ËÊÂ×÷³ö»ØÓ¦ ¡£


https://securityaffairs.co/wordpress/128712/cyber-crime/samsung-electronics-lapsus-ransomware.html


×êÑÐÈËÔ±·¢ÏÖ¶à¸ö¶ñÒâÈí¼þÀûÓÃй¶µÄNVIDIAÖ¤ÊéÊðÃû


¾ÝýÌå3ÔÂ5ÈÕ±¨Â· £¬¹¥»÷ÕßÔÚʹÓñ»µÁµÄNVIDIAÖ¤Êé¶Ô¶ñÒâÈí¼þ½øÐÐÊðÃû ¡£NVIDIAÔÚÉÏÖÜÔâµ½¹¥»÷ £¬ÀÕË÷ÍÅ»ïLapsus$ÇÔÈ¡²¢Ð¹Â¶Á˸ù«Ë¾1TBµÄÊý¾Ý ¡£ÆäÖÐÔ̺¬2¸ö´úÂëÊðÃûÖ¤Êé £¬NVIDIAµÄ¿ª·¢ÈËԱʹÓÃËüÃÇÀ´ÊðÃûÇý¶¯·¨Ê½ºÍ¿ÉÖ´ÐÐÎļþ ¡£Æ¾¾ÝÉÏ´«µ½VirusTotalÑù±¾ £¬×êÑÐÈËÔ±·¢ÏÖÕâЩ֤Êé±»ÓÃÓÚ¶à¸ö¶ñÒâÈí¼þºÍºÚ¿Í¹¤¾ßµÄÊðÃû £¬ÀýÈçCobalt Strike¡¢Mimikatz¡¢Quasar¡¢ÒÔ¼°¶àÖÖºóÃźÍľÂíµÈ ¡£


https://www.bleepingcomputer.com/news/security/malware-now-using-nvidias-stolen-code-signing-certificates/


SharkBot¼Ù×°³Éɱ¶¾Èí¼þͨ¹ýGoogle PlayÉ̵ê·Ö·¢


3ÔÂ3ÈÕ £¬NCC GroupÅû¶Á˶ñÒâÈí¼þSharkBotµÄ·Ö·¢»î¶¯µÄϸ½ÚÐÅÏ¢ ¡£ÔÚÕâ´Î»î¶¯ÖÐ £¬SharkBot¼Ù×°³ÉÓµÓÐϵͳËãÕÊÖ°ÄܵÄɱ¶¾Èí¼þ £¬Í¨¹ýAndroidÀûÓÃÉ̳ÇGoogle Play Store½øÐзַ¢ ¡£¸Ã¶ñÒâÈí¼þÓÚ2021Äê10ÔÂÓÉCleafy³õ´Î·¢ÏÖ £¬ÓëÆäËüÒøÐÐľÂíµÄÇø±ðÊÇÄܹ»Í¨¹ý×Ô¶¯×ªÕËϵͳ(ATS)½øÐÐתÕË ¡£´Ë±í £¬Ëü»¹Äܹ»Í¨¹ýͨ¹ý¡°×Ô¶¯»Ø¸´¡±Ö°ÄÜ £¬Ö±½Ó´ÓC2ÏÂÔØÓµÓÐATSÖ°ÄܵÄSharkBot²¢×Ô¶¯×°ÖÃÔÚÖ¸±êÉ豸ÉÏ ¡£


https://research.nccgroup.com/2022/03/03/sharkbot-a-new-generation-android-banking-trojan-being-distributed-on-google-play-store/


Imperva³ÆÆäÒÑÕмܸߴï250ÍòRPSµÄÀÕË÷DDoS¹¥»÷»î¶¯


°²È«¹«Ë¾ImpervaÔÚ3ÔÂ4ÈÕ°µÊ¾ £¬Ëü×î½üÕмÜÁ˸ߴïÿÃë250Íò´ÎÒªÇó(RPS)µÄÀÕË÷DDoS¹¥»÷»î¶¯ ¡£¹¥»÷µÄÖØÒªÆðÔ´ÊÇÓ¡¶ÈÄáÎ÷ÑÇ £¬Æä´ÎÊÇÃÀ¹ú¡¢Öйú¡¢°ÍÎ÷ºÍÓ¡¶ÈµÈ ¡£¹¥»÷Õß×Ô³ÆÊÇREvil £¬Éв»Ã÷ÏÔÕâÊÇÕæµÄREvilÍŻﻹÊÇðÃû¶¥ÌæÕß £¬ImpervaÍøÂçµÄÖ¤¾ÝÅú×¢Õâ´ÎDDoS¹¥»÷Ô´×Ô½©Ê¬ÍøÂçM¨¥ris ¡£´Ë±í £¬±»¹¥»÷µÄ×éÖ¯ÔÚ¹¥»÷ÆÚ¼äÊÕµ½Á˶à·ÝÊê½ð֪ͨ ¡£


https://thehackernews.com/2022/03/imperva-thwarts-25-million-rps-ransom.html


Avast°ä²¼Õë¶ÔÀÕË÷Èí¼þHermeticRansomµÄÃâ·Ñ½âÃÜÆ÷


ýÌå3ÔÂ3ÈÕ±¨Â· £¬°²È«¹«Ë¾Avast°ä²¼ÁË×Ô2ÔÂ23ÈÕÆðÍ·¹¥»÷ÎÚ¿ËÀ¼µÄÀÕË÷Èí¼þHermeticRansomµÄÃâ·Ñ½âÃÜÆ÷ ¡£Ö®Ç° £¬CrowdstrikeµÄ×êÑÐÈËÔ±·¢ÏÔìä¼ÓÃܹý³ÌÖдæÔÚÒ»¸öÂß¼­·ì϶ £¬¿É±»ÓÃÀ´ÆÆ½â¼ÓÃÜ ¡£×¨¼Ò´§Ä¦ £¬¿ª·¢ÈËÔ±ÔÚ²âÊÔÀÕË÷Èí¼þµÄ·½ÃæÍ¶ÈëµÄ¾«Á¦ÓÐÏÞ £¬¿ÉÄÜÊÇÓÉÓÚ¼ÓÃܲ¢²»ÊÇÆä×îÖÕÖ¸±ê ¡£Avast»¹°ä²¼ÁËÀûÓýâÃÜÆ÷¸´Ô­Êý¾ÝµÄ¾ßÌå×¢Ã÷ ¡£


https://securityaffairs.co/wordpress/128652/breaking-news/free-decryptor-hermeticransom-ukraine.html


Mozilla°ä²¼°²È«¸üн¨¸´FirefoxÖÐ2¸öÒѱ»ÀûÓõÄ0day


¾Ý3ÔÂ6Èյı¨Â· £¬Mozilla Firefox 97.0.2½¨¸´ÁË2¸öÒѱ»»ý¼«ÀûÓõÄÁãÈÕ·ì϶ ¡£Õâ2¸ö·ì϶±ðÀëΪXSLT²ÎÊý´¦ÖÃÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2022-26485£© £¬ÒÔ¼°WebGPU IPC¿ò¼ÜÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2022-26486£© ¡£MozillaûÓй«¿ª¹¥»÷ÕßÊÇÈôºÎÀûÓÃÕâЩ·ì϶µÄ £¬µ«ºÜ¿ÉÄÜÊÇͨ¹ý½«FirefoxÓû§³Á¶¨Ïòµ½¶ñÒâÍøÒ³À´ÊµÏÖµÄ ¡£ÓÉÓÚÕâЩ·ì϶µÄÑϳÁÐÔ¼°ÆäÕý±»ÀûÓà £¬×êÑÐÈËÔ±½¨ÒéËùÓÐЧ»§µ±¼´×°ÖøüР¡£


https://www.bleepingcomputer.com/news/security/mozilla-firefox-9702-fixes-two-actively-exploited-zero-day-bugs/



°²È«¹¤¾ß


Osmedeus


½ø¹¥ÐÔ°²È«µÄ¹¤×÷Á÷ÒýÇæ ¡£


https://github.com/j3ssie/osmedeus



PyShell


¶àƽ̨Python WebShell £¬¿ÉÔÚ Web ·þÎñÆ÷ÉÏ»ñµÃÀàËÆ shell µÄ½çÃæÒÔ½øÐÐÔ¶³Ì½Ó¼û ¡£


https://github.com/JoelGMSec/PyShell



Authz0


×Ô¶¯ÊÚȨ²âÊÔ¹¤¾ß £¬Äܹ»Æ¾¾Ý URL ºÍ Roles ºÍ Credentials ¼ø±ðδ¾­ÊÚȨµÄ½Ó¼û ¡£


https://github.com/hahwul/authz0



patching


¸ÃÏîÄ¿À©´óÁËÊ¢ÐеÄIDA Pro·´»ã±à·¨Ê½ £¬ÒÔ´´½¨¸ü׳´óµÄ½»»¥Ê½¶þ½øÔ콨²¹¹¤×÷Á÷³Ì £¬Ö¼ÔÚʵÏÖ¼±¾çµü´ú ¡£


https://github.com/gaasedelen/patching



shfz


»ùÓÚ TypeScript ³¡¾°µÄ Web ÀûÓ÷¨Ê½ÍÌͲâÊÔ¿ò¼Ü ¡£


https://github.com/shfz/shfz



°²È«·ÖÎö


¶íÂÞ˹¹«¿ª 17,000 ¸ö IP µÄÃûµ¥ £¬¾Ý³ÆÊǶíÂÞ˹×éÖ¯DDOS


https://www.bleepingcomputer.com/news/security/russia-shares-list-of-17-000-ips-allegedly-ddosing-russian-orgs/


ÎÚ¿ËÀ¼²ÎÓë±±Ô¼µý±¨¹²ÏíÍøÂç·ÀÓùÖÐÐÄ


https://www.bleepingcomputer.com/news/government/ukraine-to-join-nato-intel-sharing-cyberdefense-hub/


×êÑÐÈËÔ±¶½´Ù²»ÒªÔÚÍøÂçä¯ÀÀÆ÷ÖÐÇ¿ÔìʹÓò»°²È«µÄÖ¤Êé


https://www.bleepingcomputer.com/news/security/experts-urge-eu-not-to-force-insecure-certificates-in-web-browsers/


¶íÂÞ˹²»ÈݽӼû Facebook¡¢Twitter¡¢±í¹úÐÂÎÅýÌå


https://www.bleepingcomputer.com/news/technology/russia-blocks-access-to-facebook-twitter-foreign-news-outlets/


ÃÀ¹ú²ÎÒéԺͨ¹ýÍøÂ簲ȫ·¨°¸ÒÔ¼ÓÇ¿¹Ø¼ü»ù´¡ÉèÊ©°²È«


https://thehackernews.com/2022/03/us-senate-passes-cybersecurity-bill-to.html