ÃÀ¹úµ·»ÙSandwormÔËÓªµÄ½©Ê¬ÍøÂçCyclops Blink
°ä²¼¹¦·ò 2022-04-11ÃÀ¹úµ·»ÙSandwormÔËÓªµÄ½©Ê¬ÍøÂçCyclops Blink
¾ÝýÌå4ÔÂ6ÈÕ±¨Â·£¬ÃÀ¹úÒѵ·»ÙÓɶíÂÞ˹ºÚ¿Í×éÖ¯SandwormÔËÓªµÄ½©Ê¬ÍøÂçCyclops Blink¡£Sandworm´Ó2019Äê6ÔÂÆðͷʹÓøý©Ê¬ÍøÂç£¬ÖØÒªÖ¸±êÊÇWatchGuard Firebox·À»ðǽÉ豸ºÍ»ªË¶Â·ÓÉÆ÷¡£Õâ´Î·¨ÂÉÐж¯ÓÚ2022Äê3ÔÂ18ÈÕÆðÍ·£¬Ä¿Ç°ÒÑÔÚËùÓб»Ï°È¾µÄWatchguardÉ豸ÖÐɾ³ý¸Ã¶ñÒâÈí¼þ¡£WatchGuard°ä²¼Á˹ØÓÚ¸´Ô±»Ï°È¾FireboxÉ豸µÄ×¢Ã÷£¬»¹¿ª·¢ÁËÒ»Ì×Cyclops Blink¼ì²â¹¤¾ß£¬ÒÔ¼°Cyclops Blink 4²½Õï¶ÏºÍ½¨¸´´òËã¡£
https://securityaffairs.co/wordpress/129911/cyber-warfare-2/us-disrupts-cyclops-blink-botnet.html
VMware°ä²¼¸üУ¬½¨¸´Æä²úÆ·ÖеĶà¸ö°²È«·ì϶
4ÔÂ6ÈÕ£¬VMware°ä²¼°²È«¸üУ¬½¨¸´ÁËVMware Workspace ONE Access¡¢VMware Identity Manager (vIDM)ºÍvRealize Lifecycle ManagerµÈ²úÆ·ÖеÄ8¸ö·ì϶¡£ÆäÖÐÔ̺¬5¸ö½ÏΪÑϳÁµÄ·ì϶£¬±ðÀëΪ·þÎñÆ÷¶ËÄ£°å×¢ÈëÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2022-22954£¬CVSSÆÀ·Ö9.8£©¡¢OAuth2 ACSÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2022-22955ºÍCVE-2022-22956£¬CVSSÆÀ·Ö9.8£©ÒÔ¼°JDBC×¢ÈëÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2022-22957ºÍCVE-2022-22958£¬CVSSÆÀ·Ö9.1£©¡£
https://www.vmware.com/security/advisories/VMSA-2022-0011.html
Cybereason·¢ÏÖAridViperÕë¶ÔÒÔÉ«Áи߼¶¹ÙÔ±µÄ¼äµý»î¶¯
Cybereason NocturnusÍŶÓÔÚ4ÔÂ6ÈÕ°ä²¼»ã±¨£¬ÏêÊöÁËAridViper£¨ÓÖ³ÆAPT-C-23£©µÄл¡£×êÑÐÈËÔ±½«Õâ´Î¼äµý»î¶¯¶¨ÃûΪOperation Bearded Barbie£¬Ëü¶Ô×¼ÒÔÉ«Áйú·À¡¢·¨Âɺʹ¹Î£·þÎñ²¿Ãŵĸ߼¶¹ÙÔ±£¬¼à¶½Æä»î¶¯²¢ÇÔÈ¡Êý¾Ý¡£¹¥»÷ÕßÀûÓÃÐéαµÄFacebookÕ˺ÅÓÕʹָ±êÏÂÔØÄ¾Âí£¬²¢Ê¹ÓÃÁËеĶñÒâÈí¼þBarb(ie) DownloaderºÍBarbWire Backdoor£¬ÒÔ¼°VolatileVenomбäÖÖ¡£
https://www.cybereason.com/blog/operation-bearded-barbie-apt-c-23-campaign-targeting-israeli-officials
3¸ö¶ñÒâAndroidÀûÓöÔ×¼ÂíÀ´Î÷ÑǵĶà¸ö½ðÈÚ»ú¹¹
4ÔÂ6ÈÕ£¬ESET°ä²¼Á˹ØÓÚ3¸ö¶ñÒâAndroidÀûÓõÄ×êÑл㱨¡£¸Ã»î¶¯×Ô2021Äê11ÔÂÆðÍ·£¬¹¥»÷Õßͨ¹ý¼ÙÒâMaid4u¡¢GrabmaidºÍMaria's CleaningµÈ7¸öºÏ·¨ÍøÕ¾£¬ÓÕʹÓû§ÏÂÔØ¶ñÒâÀûÓã¬ÕâЩÀûÓý«Ö¸±êÊÕµ½µÄËùÓжÌÐÅת·¢µ½¹¥»÷Õߣ¬ÒÔÇÔÈ¡ÒøÐз¢Ë͵Ä2FA´úÂë¡£Õâ´Î»î¶¯ÖØÒªÕë¶ÔÂíÀ´Î÷ÑǵÄ8¼ÒÒøÐУºMaybank¡¢Affin Bank¡¢Public Bank Berhad¡¢CIMB bank¡¢BSN¡¢RHB¡¢Bank Islam MalaysiaºÍHong Leong Bank¡£
https://www.welivesecurity.com/2022/04/06/fake-eshops-prowl-banking-credentials-android-malware/
NB65Ðû³ÆÒÑÇÔÈ¡¶íÂÞ˹¹ã²¥¹«Ë¾VGTRKÔ¼800GBµÄÊý¾Ý
ýÌå4ÔÂ6ÈÕ±¨Â·£¬NB65(Network Battalion 65)Ðû³ÆÒÑÈëÇÖ¶íÂÞ˹µçÊӹ㲥¹«Ë¾VGTRK¡£NB65ÓëAnonymouÓйØÁª£¬VGTRKÊǶíÂÞ˹×î´óµÄýÌ幫˾£¬ÔËÓª×Å5¸ö¹ú¶Èµç̨¡¢2¸ö¹ú¼ÊÍøÂç¡¢5¸ö¹ã²¥µç̨ºÍ80¶à¸öµØÓòµçÊÓºÍ¹ã²¥ÍøÂç¡£NB65ͨ¹ýDDoSecrets¹«¿ªÁËVGTRK 786.2 GBµÄÊý¾Ý£¬ÆäÖÐÔ̺¬4000¸öÎļþºÍ³¬¹ý900000·âµç×ÓÓʼþ¡£Anonymous»¹ÔÚ3ÔÂ26ÈÕй¶Á˶íÂÞ˹ÖÐÑëÒøÐÐ28GBµÄÊý¾Ý¡£
https://www.hackread.com/anonymous-affiliate-nb65-russia-broadcaster-data-breach/
Google PlayÖÐÀûÓÃSDKÍøÂçÐÅÏ¢µÄÀûÓÃÒÑ×°ÖÃ4500Íò´Î
¾Ý4ÔÂ7ÈÕ±¨Â·£¬AppCensus·¢ÏÖGoogle PlayÖеĶà¸öÀûÓÃͨ¹ýµÚÈý·½SDKÍøÂçÓû§Êý¾Ý¡£ÕâЩÀûÓÃÒÑ×°Öó¬¹ý4500Íò´Î£¬Ô̺¬Speed Camera RadarºÍAl-Moazin LiteµÈ£¬ÖØÒªÇÔÈ¡¼ôÌù°åÄÚÈÝ¡¢GPSÊý¾Ý¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂ룬ÒÔ¼°µ÷Ôì½âµ÷Æ÷·ÓÉÆ÷MACµØÖ·ºÍÍøÂçSSID¡£ÍøÂçµ½µÄÊý¾ÝÓÉSDK´«Êäµ½¡°mobile.measurelib.com¡±£¬¸ÃÓòÊôÓÚÒ»¼ÒÃûΪMeasurement SystemsµÄ°ÍÄÃÂí·ÖÎö¹«Ë¾ËùÓС£
https://www.bleepingcomputer.com/news/security/android-apps-with-45-million-installs-used-data-harvesting-sdk/
°²È«¹¤¾ß
Rip Raw
ÊÇÒ»¸öÓÃÓÚ·ÖÎöÊÜϰȾ Linux ϵͳÄÚ´æµÄÓ×¹¤¾ß¡£
https://github.com/cado-security/rip_raw
Grafiki
¹ØÓÚ Sysmon ºÍͼ±íµÄÍþв׷×Ù¹¤¾ß¡£
https://github.com/lucky-luk3/Grafiki/
Odin
Odin ÊÇ»ùÓÚLokiµÄÖÐÑë IoC ɨÃèÆ÷
https://github.com/Hamza-Megahed/odin
°²È«·ÖÎö
Windows 11 ÄÚ²¿°æ±¾ 22593 ÖеÄÒÑÖªÎÊÌâ
https://news.softpedia.com/news/known-issues-in-windows-11-build-22593-535182.shtml
Mozilla Firefox 99 ÏÖÒѿɹ©ÏÂÔØ
https://news.softpedia.com/news/mozilla-firefox-99-is-now-available-for-download-535180.shtml
΢Èí£º¶à¸ö .NET Framework °æ±¾½«ÓÚ 4 Ô EOL
https://www.bleepingcomputer.com/news/microsoft/microsoft-multiple-net-framework-versions-reach-end-of-life-in-april/
AMDÈ·ÈÏGPUÇý¶¯·¨Ê½ÃýÎóδ¾Ðí¿É³¬ÆµCPU
https://www.bleepingcomputer.com/news/hardware/amd-confirms-gpu-driver-bug-overclocks-cpus-without-permission/
Atlassian Jira£¬Confluence ÖжÏÓ°ÏìÈ«ÇòÓû§
https://www.bleepingcomputer.com/news/technology/ongoing-atlassian-jira-confluence-outage-affects-customers-worldwide/
Palo Alto Networks ·À»ðǽ¡¢VPN ´æÔÚ OpenSSL ·ì϶
https://www.bleepingcomputer.com/news/security/palo-alto-networks-firewalls-vpns-vulnerable-to-openssl-bug/
FFDroiderÖ¼ÔÚÇÔÈ¡É罻ýÌåÖеÄÐÅÏ¢
https://www.zscaler.com/blogs/security-research/ffdroider-stealer-targeting-social-media-platform-users


¾©¹«Íø°²±¸11010802024551ºÅ