ÍøÐŰì°ä²¼¡¶Î´³ÉÄêÈËÍøÂç±£»¤ÌõÀý£¨Õ÷Ç󶨼û¸å£©¡·
°ä²¼¹¦·ò 2022-03-17ÍøÐŰì°ä²¼¡¶Î´³ÉÄêÈËÍøÂç±£»¤ÌõÀý£¨Õ÷Ç󶨼û¸å£©¡·
3ÔÂ14ÈÕ£¬¹ú¶È»¥ÁªÍøÐÅÏ¢°ì¹«ÊÒ°ä²¼¹ØÓÚ¡¶Î´³ÉÄêÈËÍøÂç±£»¤ÌõÀý£¨Õ÷Ç󶨼û¸å£©¡·Ôٴι«¿ªÕ÷Ç󶨼ûµÄ֪ͨ¡£Îª±£»¤Î´³ÉÄêÈËÉíÐĽ¡È«ºÍÆäÔÚÍøÂç¿Õ¼äµÄºÏ·¨È¨Àû£¬Ç°ÆÚÍøÐŰì²ÝÄâÁË¡¶Î´³ÉÄêÈËÍøÂç±£»¤ÌõÀý£¨Õ÷Ç󶨼û¸å£©¡·¡£Ö®ºó£¬Æ¾¾Ýж©ÕýµÄ¡¶ÖлªÈËÃñ¹²ºÍ¹úδ³ÉÄêÈ˱£»¤·¨¡·µÈ˾·¨ºÍÉç»á¹«¼Ò·´À¡¶¨¼û£¬¶Ô¸ÃÌõÀý½øÐÐÁËÅú¸ÄÃÀÂú¡£ÌõÀýÖ¸³ö£¬ÍøÂç²úÆ·ºÍ·þÎñÌṩÕ߸õ±³ÉÁ¢½¡È«·À³ÁÃÔÔì¶È£¬²»µÃÏòδ³ÉÄêÈËÌṩÓÕµ¼Æä³ÁÃԵIJúÆ·ºÍ·þÎñ¡£
http://www.cac.gov.cn/2022-03/14/c_1648865100662480.htm
QNAP¹«¸æ³ÆDirty Pipe·ì϶»áÓ°ÏìÆä´ó²¿ÃÅNASÉ豸
Ó²¼þ¹©¸øÉÌQNAPÔÚ3ÔÂ14ÈÕ°ä²¼¹«¸æ£¬³ÆÆä´ó²¿ÃÅÍøÂ總¼Ó´æ´¢(NAS)É豸¶¼Êܵ½Linux·ì϶Dirty PipeµÄÓ°Ïì¡£¹«¸æÖ¸³ö£¬Õâ¸ö·ìÏ¶ÖØÒª»áÓ°ÏìÔËÐÐQTS 5.0.xºÍQuTS hero h5.0.xµÄÉ豸£¬¹¥»÷ÕßÄܹ»ÀûÓÃÆä»ñµÃÖÎÀíԱȨÏÞ²¢×¢Èë¶ñÒâ´úÂë¡£¹ÌÈ»Õë¶ÔLinuxÄں˵IJ¹¶¡ÒÑÓÚÒ»ÖÜǰ°ä²¼£¬µ«¸Ã¹«Ë¾½¨ÒéÓû§¹Ø¹ØÂ·ÓÉÆ÷¶Ë¿Úת·¢Ö°Äܲ¢½ûÓÃQNAP NASµÄUPnPÖ°ÄÜÀ´»º½â¸Ã·ì϶£¬Ö±µ½QNAP°ä²¼×Ô¼ºµÄ°²È«¸üС£
https://www.bleepingcomputer.com/news/security/qnap-warns-severe-linux-bug-affects-most-of-its-nas-devices/
ÒÔÉ«ÁÐÔâµ½´ó¹æÄ£DDoS¹¥»÷£¬µ±¾Ö»ú¹¹¶à¸öÍøÕ¾¹Ø¹Ø
¾ÝýÌå3ÔÂ15ÈÕ±¨Â·£¬ÒÔÉ«Áе±¾Ö»ú¹¹µÄ¶à¸öÍøÕ¾ÔÚ±¾ÖÜÒ»Ôâµ½´ó¹æÄ£DDoS¹¥»÷¡£Ô̺¬ÎÀÉú²¿¡¢ÄÚÕþ²¿ºÍ˾·¨²¿ÔÚÄڵĶà¸ö²¿Î¯¶¼Êܵ½Á˹¥»÷µÄÓ°Ï죬×ÜÀí°ì¹«ÊÒµÄÍøÕ¾Ò²ÁÙʱ¹Ø¹Ø¡£¸Ã¹ú¹ú·À»ú¹¹ºÍ¹ú¶ÈÍøÂç¾ÖÒѰ䷢½øÈ봹Σ״̬£¬Ä¿Ç°ÔÚÈ·¶¨¹¥»÷ÊÇ·ñ¶ÔÒÔÉ«ÁеĹؼü»ù´¡ÉèÊ©Ôì³ÉÁËÖÐÉË¡£±¾µØÃ½Ì峯£¬Õâ´Î¹¥»÷¿ÉÄÜÀ´×ÔÓëÒÁÀÊÓйصĹ¥»÷Õß¡£¾ÝϤ£¬ÕâÊÇÓÐÊ·ÒÔÀ´Õë¶ÔÒÔÉ«ÁеÄ×î´ó¹æÄ£µÄ¹¥»÷»î¶¯¡£
https://securityaffairs.co/wordpress/129063/cyber-warfare-2/massive-ddos-attack-hit-israel.html
PandoraÍÅ»ïÐû³ÆÒÑÈëÇÖDENSO¹«Ë¾²¢ÇÔÈ¡1.4TBµÄÊý¾Ý
ýÌå3ÔÂ14Èճƣ¬DENSOÈÏ¿ÉÆäÔڵ¹úµÄ¼¯ÍŹ«Ë¾ÓÚ3ÔÂ10ÈÕÔâµ½ÈëÇÖ¡£DENSOÊÇÈ«Çò×î´óµÄÆû³µÁ㲿¼þÔì×÷ÉÌÖ®Ò»£¬¸Ã¹«Ë¾°µÊ¾ÔÚ¼ì²âµ½Î´¾ÊÚȨµÄ½Ó¼ûºó£¬µ±¼´¶Â½ØÁ˱»¹¥»÷É豸µÄÍøÂçÏνӣ¬ËùÓгö²ú¹¤³§¶¼½«Õý³£ÔËÐУ¬Òò¶øÔ¤¼ÆÕâ´ÎÊÂÎñ²»»áµ¼Ö¹©¸øÁ´Öжϡ£ÀÕË÷ÍÅ»ïPandoraÐû³Æ¶Ô´ËÊÂÕÆ¹Ü£¬²¢ÒÑÆðͷй¶ÆäÇÔÈ¡µÄ1.4TBÎļþ£¬Æä°ä²¼µÄÑù±¾Êý¾ÝÔ̺¬²É¹º¶©µ¥¡¢¼¼ÊõµÀÀíͼºÍ±£ÃܺÍ̸µÈ¡£
https://www.zdnet.com/article/automotive-giant-denso-reveals-hack-pandora-ransomware-group-takes-credit/
ESET°ä²¼Õë¶ÔÎÚ¿ËÀ¼µÄжñÒâÈí¼þCaddyWiperµÄ»ã±¨
3ÔÂ15ÈÕ£¬ESET°ä²¼Õë¶ÔÎÚ¿ËÀ¼µÄжñÒâÈí¼þCaddyWiperµÄ·ÖÎö»ã±¨¡£ÕâÊÇÒ»¸öÊý¾Ý²Á³ý¶ñÒâÈí¼þ£¬ÓÚ±¾ÖÜÒ»ÉÏÎç³õ´Î±»·¢ÏÖ¡£×êÑÐÈËÔ±ÔÚÒÑÔÚ¶à¸ö×éÖ¯µÄ¼¸Ê®¸öϵͳÉϼì²âµ½Ëü£¬±»ÓÃÀ´·ÛËéÏνÓÇý¶¯ÉϵÄÓû§Êý¾ÝºÍ·ÖÇøÐÅÏ¢¡£CaddyWiperÓëHermeticWiperºÍIsaacWiperµÄ´úÂëûÓÐÀàËÆÖ®´¦£¬µ«ÓÐÖ¤¾ÝÅú×¢¹¥»÷ÕßÔÚÔÚ·Ö·¢¶ñÒâÈí¼þ֮ǰ¾ÍÉøÈëÁËÖ¸±êµÄÍøÂç¡£
https://www.welivesecurity.com/2022/03/15/caddywiper-new-wiper-malware-discovered-ukraine/
OpenSSL°ä²¼°²È«¸üУ¬½¨¸´DoS·ì϶CVE-2022-0778
¾Ý3ÔÂ15ÈÕ±¨Â·£¬OpenSSL°ä²¼°²È«¸üÐÂÒÔ½¨¸´»Ø¾ø·þÎñ(DoS)·ì϶£¨CVE-2022-0778£©¡£¸Ã·ì϶ÓÉGoogle Project Zero×êÑÐÈËÔ±Tavis Ormandy·¢ÏÖ£¬Ô´ÓÚ½âÎöÖ¤ÊéÊ±ÍÆËãģƽ·½¸ùµÄBN_mod_sqrt()º¯ÊýÖдæÔÚÒ»¸öÃýÎ󣬿ÉÄܵ¼ÖÂËüʼÖÕÑ»·ÍÆËã·ÇËØÊýÄ£¡£×êÑÐÈËÔ±³Æ£¬Äܹ»Ê¹ÓÃÎÞЧµÄÏÔʽÇúÏß²ÎÊýÔì×÷ÌåʽÃýÎóµÄÖ¤ÊéÀ´´¥·¢´Ë·ì϶¡£¸Ã·ì϶ӰÏìÁËOpenSSL°æ±¾ 1.0.2¡¢1.1.1ºÍ3.0£¬ÒÑͨ¹ý°ä²¼°æ±¾1.0.2zd¡¢1.1.1nºÍ3.0.2½¨¸´¡£
https://securityaffairs.co/wordpress/129104/security/openssl-dos-vulnerability.html
°²È«¹¤¾ß
CodeAnalysis
×ÛºÏÐԵĴúÂë·ÖÎöºÍÎÊÌâ¸ú×ÙÆ½Ì¨¡£
https://github.com/Tencent/CodeAnalysis
DomainAlerting
ÍøÂçÔ̺¬¹Ø¼ü×ÖµÄ×¢²áµÄÐÂÓòÃû£¬²¢ÖðÈÕ¾¯±¨¡£
https://github.com/pixelbubble/DomainAlerting
NimPackt-v1
ÓÃÓÚ .NET ¿ÉÖ´ÐÐÎļþºÍÔʼ shellcode µÄ»ùÓÚ Nim µÄ´ò°ü·¨Ê½¡£
https://github.com/chvancooten/NimPackt-v1
PurplePanda
´Ó¹Ø×¢È¨ÏÞµÄ·ÖÆçÔÆ/SaaS ÀûÓ÷¨Ê½ÖлñÈ¡×ÊÔ´£¬ÒÔ¼ø±ðÔÆ/saas ÅäÖÃÖеÄȨÏÞÌáÉýõè¾¶ºÍΣÏÕȨÏÞ¡£
https://github.com/carlospolop/PurplePanda
°²È«·ÖÎö
Mozilla Firefox ÒòÃýÎóÐÅÏ¢ÎÊÌâ¶øÉ¾³ýÁ˶íÂÞ˹ËÑË÷ÌṩÉÌ
https://www.bleepingcomputer.com/news/software/mozilla-firefox-removes-russian-search-providers-over-misinformation-concerns/
Æ»¹û°ä²¼ iOS 15.4£¬Óû§¿É´ø×Å¿ÚÕÖʹÓà Face ID
https://news.softpedia.com/news/apple-finally-releases-ios-15-4-face-id-with-a-mask-now-available-for-all-users-535039.shtml
΢ÈíΪ VirtualBox Óû§É¾³ýÁË Windows 11 ¸üÐÂÄ£¿é
https://www.bleepingcomputer.com/news/microsoft/microsoft-removes-windows-11-update-block-for-virtualbox-users/
ºÚ¿Í¶Ô×¼¶íÂÞ˹ʯÓ͹«Ë¾µÄµÂ¹ú·Ö¹«Ë¾
https://securityaffairs.co/wordpress/129052/hacktivism/anonymous-hacked-german-subsidiary-rosneft.html
×êÑÐÈËÔ±·¢ÏÖ½« Kwampirs Óë Shamoon APT ÁªÏµÆðÀ´µÄÐÂÖ¤¾Ý
https://thehackernews.com/2022/03/researchers-find-new-evidence-linking.html
ÓÃÓÚÔÚÎÚ¿ËÀ¼²¿Êð Cobalt Strike µÄÐéα·À²¡¶¾¸üÐÂ
https://www.bleepingcomputer.com/news/security/fake-antivirus-updates-used-to-deploy-cobalt-strike-in-ukraine/


¾©¹«Íø°²±¸11010802024551ºÅ