ÔËÓªÉÌUkrtelecom³ÆÆäÖ÷Ìâ»ù´¡ÉèÊ©Ôâµ½´ó¹æÄ£¹¥»÷
°ä²¼¹¦·ò 2022-03-31ÔËÓªÉÌUkrtelecom³ÆÆäÖ÷Ìâ»ù´¡ÉèÊ©Ôâµ½´ó¹æÄ£¹¥»÷
¾ÝýÌå3ÔÂ29ÈÕ±¨Â·£¬ÎÚ¿ËÀ¼ÖØÒªµÄÔËÓªÉÌUkrtelecomÔâµ½ÁË´ó¹æÄ£µÄÍøÂç¹¥»÷£¬Ôì³ÉÁËÑϳÁµÄÍøÂçÖжϡ£Æ¾¾Ý»¥ÁªÍø¼à¿Ø·þÎñNetBlockµÄÊý¾Ý£¬ÊµÊ±ÍøÂçÊý¾ÝÏÔʾÏνÓÐÔ½µÂäµ½Õý³£Ë®Æ½µÄ13%¡£ÎÚ¿ËÀ¼SSSCIP°µÊ¾£¬ºÚ¿Í¹¥»÷ÁËUkrtelecomµÄIT»ù´¡ÉèÊ©£¬ËûÃÇÒѳɹ¦ÕмÜÕâ´Î¹¥»÷¡£´Ë±í£¬ÎªÁ˱£»¤Æä»ù´¡ÉèÊ©²¢³ÖÐøÎªÎÚ¿ËÀ¼Îä×°¶ÓÁÐºÍÆäËû¾üÊÂ×éÖ¯ºÍ¿Í»§Ìṩ·þÎñ£¬UkrtelecomÁÙʱÏÞ¶ÈÁË´óÎÞÊý¸öÈËºÍÆóÒµ¿Í»§µÄ·þÎñ¡£
https://securityaffairs.co/wordpress/129585/cyber-warfare-2/ukraine-cyberattack-ukrtelecom.html
΢Èí½¨¸´Windows 11 SMBºÍDirectXÖеÄBSODÎÊÌâ
ýÌå3ÔÂ28ÈÕ±¨Â·£¬Microsoft°ä²¼Á˺ÏÓÃÓÚWindows 11µÄ¿ÉÑ¡KB5011563ÀÛ»ý¸üС£Õâ´Î¸üÐÂÖØÒª½¨¸´ÁË2¸öÀ¶ÆÁËÀ»ú(BSOD)ÎÊÌ⣬Ô̺¬DirectXÄÚºË×é¼þÖеÄÖÕ³¡ÃýÎó£¨0xD1£¬DRIVER_IRQL_NOT_LESS_OR_EQUAL£©ºÍSMB·þÎñÆ÷£¨srv2.sys£©ÖеÄÖÕ³¡ÃýÎó0x1E¡£Õâ´Î¸üл¹Ôö³¤Á˺öàеÄÖ°ÄÜ£¬ÀýÈçͬʱÏÔʾ×î¶àÈý¸ö¸ßÓÅÏȼ¶Toast֪ͨ¡£Óû§Äܹ»ÔÚÉèÖÃÖÐÊÖ¶¯²é³¸üУ¬»ò´ÓMicrosoft¸üÐÂĿ¼ÊÖ¶¯ÏÂÔØ²¢×°Öô˸üС£
https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5011563-update-fixes-smb-directx-blue-screens/
ÎÚ¿ËÀ¼µÄ¶à¸öÍøÕ¾Ôâµ½À´×ÔÊý°Ù¸öÍøÕ¾µÄDDoS¹¥»÷
¾Ý3ÔÂ28ÈÕ±¨Â·£¬MalwareHunterTeam·¢ÏÖÁËÒ»¸ö¶ñÒâ¾ç±¾¡£¹¥»÷ÕßÒÑÀûÓÃWordPressÖеķì϶ÈëÇÖÁËÉϰٸöÍøÕ¾£¬¶øºó²åÈë¸Ã¶ñÒâ¾ç±¾¶ÔÎÚ¿ËÀ¼µÄÍøÕ¾Ö´ÐÐDDoS¹¥»÷£¬Éæ¼°ÎÚ¿ËÀ¼µ±¾Ö»ú¹¹¡¢ÖÇÄÒÍÅ¡¢¹ú·À¾üÕÐļºÍ½ðÈÚµÈÓйØÍøÕ¾¡£Õâ¸öJavaScript¾ç±¾½«Ç¿Ôì±»ÈëÇÖµÄä¯ÀÀÆ÷¶ÔÁгöµÄ¶àÓÐÍøÕ¾Ö´ÐÐHTTP GETÒªÇó£¬Ò»´Î²»³¬¹ý1000¸ö²¢·¢Ïνӡ£´Ë±í£¬¶ÔÖ¸±êÍøÕ¾µÄÿ¸öÒªÇó¶¼½«Ê¹ÓÃÒ»¸öËæ»ú²éÎÊ×Ö·û´®£¬ÕâÑùÒªÇó¾Í²»»áͨ¹ý»º´æ·þÎñ£¨ÈçCloudflare£©Ìṩ·þÎñ£¬¶øÊÇÖ±½ÓÓɱ»¹¥»÷µÄ·þÎñÆ÷½Ó¹Ü¡£
https://www.bleepingcomputer.com/news/security/hacked-wordpress-sites-force-visitors-to-ddos-ukrainian-targets/
Minerva°ä²¼¹ØÓÚÀÕË÷Èí¼þSunCryptµÄ·ÖÎö»ã±¨
3ÔÂ28ÈÕ£¬Minerva Labs°ä²¼¹ØÓÚÀÕË÷Èí¼þSunCryptµÄ·ÖÎö»ã±¨¡£SunCryptÊÇRaaSÍŻÓÚ2019Äê10Ô³õ´Î³öÏÖ£¬ÊÇ×îÔçʹÓÃÈý³ÁÀÕË÷Õ½ÊõµÄ×éÖ¯Ö®Ò»¡£»ã±¨Ö¸³ö£¬´Ë2022 SunCrypt±äÖÖÔö³¤Á˺öàеÄÖ°ÄÜ£¬Ô̺¬ÖÕÖ¹¹ý³Ì¡¢ÖÕ³¡·þÎñ²¢¶Ï¸ùÀÕË÷Èí¼þÖ´Ðеĺۼ£¡£¸ÃÀÕË÷Èí¼þ»¹Ê¹ÓÃÒ»¸öwinlogon.exe½Ó¼ûÁîÅÆ£¬²¢Í¨¹ýʹÓÃSetThreadToken APIŲÓý«ÆäÉèÖÃΪÆäÖ÷Ï̡߳£
https://blog.minerva-labs.com/suncrypt-ransomware-gains-new-abilities-in-2022
Rapid7°ä²¼¹ØÓÚ2021Ä갲ȫ·ìÏ¶Ì¬ÊÆµÄ·ÖÎö»ã±¨
3ÔÂ28ÈÕ£¬Rapid7°ä²¼ÁËÆä×îеķìÏ¶Ì¬ÊÆ·ÖÎö»ã±¨£¬×êÑÐÁË2021Äê×îÏÔÖøµÄ°²È«·ì϶ºÍÍøÂç¹¥»÷¡£2021ÄêµÄÍþвÖУ¬³¬¹ý50%µÄʼÓÚÁãÈÕ·ì϶¡£¸Ã»ã±¨×êÑÐÁË50¸ö·ì϶£¬ÆäÖÐÓÐ43¸öÒѱ»ÀûÓ㬽üÒ»°ëÊÇÔÚ½¨¸´Ö®Ç°±»ÓÃÓÚÁãÈÕ¹¥»÷¡£ÓÃ×÷ÁãÈÕ¹¥»÷µÄ·ì϶ÊýÁ¿±È2020ÄêÔö³¤ÁË100%£¬ÇÒÀûÓõľùÔȹ¦·ò´Ó2020ÄêµÄ42È«¹ú½µµ½2021ÄêµÄ12Ì죻66%µÄ·ì϶±»¹éÀàΪ¿í·ºÍþв£¬ÆäÖÐ60%ÒÔÉϱ»ÓÃÓÚÀÕË÷¹¥»÷¡£
https://www.rapid7.com/info/2021-vulnerability-intelligence-report/
CISAÓëÄÜÔ´²¿½áºÏ°ä²¼Õë¶ÔUPSÉ豸µÄ¹¥»÷µÄÕ÷ѯ
3ÔÂ29ÈÕ£¬ÃÀ¹úCISAÓëÄÜÔ´²¿½áºÏ°ä²¼ÁËÕë¶Ô²»¼ä¶ÏµçÔ´(UPS)É豸µÄ¹¥»÷µÄ°²È«Õ÷ѯ¡£¹«¸æÖ¸³ö£¬ÕâЩ»ú¹¹·¢ÏÖ¹¥»÷Õßͨ³£Í¨¹ýδ¸ü¸ÄµÄĬÈÏÓû§ÃûºÍÃÜÂëÀ´½Ó¼û¸÷ÀàÁªÍøµÄUPSÉ豸,×éÖ¯Äܹ»Í¨¹ý´Ó»¥ÁªÍøÉÑþ³ØýÖÎÀí½Ó¿ÚÀ´»º½â¶ÔÆäUPSÉ豸µÄ¹¥»÷¡£CISAºÍDOE»¹ÌṩÁËÆäËüµÄ»º½â´ëÊ©£¬ÆäÖÐÔ̺¬²éÕÒ×éÖ¯ÍøÂçÉϵÄËùÓÐUPSºÍÆäËüÓ¦¼±µçԴϵͳ£¬²¢È·±£ËüÃÇÎÞ·¨Í¨¹ýInternet½Ó¼û¡£
https://www.cisa.gov/uscert/ncas/current-activity/2022/03/29/mitigating-attacks-against-uninterruptable-power-supply-devices
°²È«¹¤¾ß
Gitcolombo
OSINT ¹¤¾ß£¬ÓÃÓÚ´Ó git ´æ´¢¿âÖÐÌáÈ¡ÓйØÈËÔ±µÄÐÅÏ¢¡£
https://github.com/soxoj/gitcolombo
ScheduleRunner
AC# ¹¤¾ß£¬¿É¸ü½Ã½ÝµØ×Ô½ç˵´òË㹤×÷£¬ÒÔʵÏÖºì¶Ó²Ù×÷ÖеÄÓÆ¾ÃÐԺͺáÏòÒÆ¶¯¡£
https://github.com/netero1010/ScheduleRunner
phantun
Ò»¸öÇáÁ¿¼¶ºÍ¼±¾çµÄ UDP µ½ TCP »ìºÏÆ÷¡£
https://github.com/dndx/phantun/
°²È«·ÖÎö
AnonymousºÚ¿ÍÈëÇÖ 2 ¼Ò¶íÂÞ˹¹¤Òµ¹«Ë¾£¬Ð¹Â¶ 112GB Êý¾Ý
https://www.hackread.com/anonymous-hack-russian-industrial-firms-data-leak/
Ð嵀 Windows °²È«Ö°ÄÜ¿É×èÖ¹Ò×Êܹ¥»÷µÄÇý¶¯·¨Ê½
https://www.bleepingcomputer.com/news/microsoft/new-windows-security-feature-blocks-vulnerable-drivers/
¶íÂÞ˹ÒòÉ豸Ƿȱ¶øÃæ¶Ô»¥ÁªÍøÖжÏ
https://www.bleepingcomputer.com/news/technology/russia-facing-internet-outages-due-to-equipment-shortage/
΢ÈíΪ AMD Çý¶¯µÄ Surface Laptop 4 °ä²¼¹Ì¼þ¸üÐÂ
https://news.softpedia.com/news/microsoft-releases-firmware-update-for-amd-powered-surface-laptop-4-535118.shtml
Trend MicroÅû¶Purple Fox½üÆÚ¹¥»÷»î¶¯µÄϸ½ÚÐÅÏ¢
https://www.trendmicro.com/en_us/research/22/c/purple-fox-uses-new-arrival-vector-and-improves-malware-arsenal.html


¾©¹«Íø°²±¸11010802024551ºÅ