åÚÏëUEFI¹Ì¼þÇý¶¯·¨Ê½Öеķì϶ӰÏìÉϰٿî±Ê¼Ç±¾µçÄÔ
°ä²¼¹¦·ò 2022-04-201¡¢åÚÏëUEFI¹Ì¼þÇý¶¯·¨Ê½Öеķì϶ӰÏìÉϰٿî±Ê¼Ç±¾µçÄÔ
¾ÝýÌå4ÔÂ19ÈÕ±¨Â·£¬ESET×êÑÐÈËÔ±·¢ÏÖÓ°ÏìåÚÏëÉϰٿî±Ê¼Ç±¾µçÄÔµÄ3¸ö·ì϶¡£ÆäÖÐÁ½¸ö·ì϶£¨CVE-2021-3971ºÍCVE-2021-3972£©¿ÉÓÃÀ´½ûÓöԴ洢UEFI¹Ì¼þµÄSPIÉÁ´æÐ¾Æ¬µÄ±£»¤£¬²¢¹Ø¹ØUEFI°²È«Æô¶¯Ö°ÄÜ£¬Ê¹¶ñÒâÈí¼þÔÚϵͳ³ÁÆôºóÈÔ¿É´æÔÚ¡£µÚÈý¸ö·ì϶£¨CVE-2021-3970£©´æÔÚÓÚLenovoVariable SMI´¦Ö÷¨Ê½ÖУ¬¹¥»÷Õß¿ÉÀûÓÃÆäÒÔÌáÉýµÄȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£ESETÓÚ2021Äê10ÔÂ11ÈÕÏòåÚÏë»ã±¨ÕâЩ·ì϶£¬åÚÏëÓÚ4ÔÂ12ÈÕ°ä²¼²¹¶¡¡£
https://www.bleepingcomputer.com/news/security/lenovo-uefi-firmware-driver-bugs-affect-over-100-laptop-models/
2¡¢CISAºÍFBI½áºÏ°ä²¼¹ØÓÚÇø¿éÁ´ÐÐÒµµÄÍøÂ簲ȫÕ÷ѯ
4ÔÂ18ÈÕ£¬ÃÀ¹úFBI¡¢CISAºÍ²ÆÕþ²¿½áºÏ°ä²¼Á˹ØÓÚÇø¿éÁ´ÐÐÒµµÄÍøÂ簲ȫÕ÷ѯ¡£¸ÃÕ÷ѯָ³ö£¬³¯ÏÊAPT×éÖ¯Lazarus¶Ô×¼Çø¿éÁ´¼¼ÊõºÍ¼ÓÃÜÇ®±ÒÐÐÒµµÄ¸÷Àà×éÖ¯£¬Ô̺¬¼ÓÃÜÇ®±ÒÂòÂôËù¡¢È¥ÖÐÐÄ»¯½ðÈÚ (DeFi) ºÍ̸ºÍ¼ÓÃÜÇ®±ÒÒµÎñ¹«Ë¾µÈ¡£¹¥»÷ÕßʹÓø÷ÀàͨѶƽ̨¶ÔÖ¸±ê½øÐÐÉç»á¹¤³Ì¹¥»÷£¬ÓÕʹÆäÔÚWindows»òmacOSϵͳ¸ßµÍÔØÄ¾Âí»¯µÄ¼ÓÃÜÇ®±ÒÀûÓã¬ÒÔÇÔȡ˽Կ»òÀÄÓÃÆäËü·ì϶¡£¸Ã²¼¸æÌṩÁË´ËÀà»î¶¯ÓйصÄÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½(TTP)ºÍIOC£¬ÒÔÔ®ÊÖ×éÖ¯¼ø±ð²¢ÕмÜÕë¶Ô¼ÓÃÜÇ®±ÒµÄÍøÂç¹¥»÷¡£
https://www.cisa.gov/uscert/ncas/alerts/aa22-108a
3¡¢CloudSEK·¢ÏÖ¼ÙÒâWin11Éý¼¶·Ö·¢Inno StealerµÄ»î¶¯
ýÌå4ÔÂ18ÈÕ±¨Â·£¬CloudSEK·¢ÏÖ¼ÙÒâWin11Éý¼¶·Ö·¢Inno StealerµÄ»î¶¯¡£¸Ã»î¶¯Ä¿Ç°ºÜ»îÔ¾£¬Í¨¹ýËÑË÷Á˾ÖͶ¶¾À´ÍÆËͼÙÒâWindows 11ÍÆ¹ãÒ³ÃæµÄ´¹µöÍøÕ¾¡£Ö¸±êµã»÷µ±¼´ÏÂÔØºó»áµÃµ½Ò»¸öISOÎļþ£¬ÆäÖÐÔ̺¬Inno StealerµÄ¼ÓÔØ·¨Ê½¡£Ð¶ñÒâÈí¼þÓÉÓÚʹÓÃÁËInno Setup Windows×°Ö÷¨Ê½¶øµÃÃû£¬ÓëĿǰʢÐÐµÄÆäËüÐÅÏ¢ÇÔÈ¡·¨Ê½µÄ´úÂëûÓÐÈκÎÀàËÆÖ®´¦£¬¿ÉÇÔÈ¡ä¯ÀÀÆ÷cookieºÍ´æ´¢µÄÍ´´¦¡¢¼ÓÃÜÇ®±ÒÇ®°üÖеÄÊý¾ÝÒÔ¼°ÎļþϵͳµÄÊý¾Ý¡£
https://www.bleepingcomputer.com/news/security/unofficial-windows-11-upgrade-installs-info-stealing-malware/
4¡¢°²È«¹«Ë¾PRODAFT°ä²¼ÀÕË÷Èí¼þPYSAµÄÉî¶È·ÖÎö»ã±¨
4ÔÂ14ÈÕ£¬°²È«¹«Ë¾PRODAFT°ä²¼Á˹ØÓÚÀÕË÷Èí¼þPYSAµÄÉî¶È·ÖÎö»ã±¨¡£PYSAÊÇMespinozaµÄ¼ÌÈÎÕߣ¬ÓÚ2019Äê12Ô³õ´Î±»·¢ÏÖ£¬ÒѳÉΪ2021ÄêQ4¼ì²âµ½µÄµÚÈý´óÊ¢ÐÐÀÕË÷Èí¼þ£¬×Ô2020Äê9ÔÂÒÔÀ´Ð¹Â¶Á˶à´ï747¸ö±»¹¥»÷Ö¸±êµÄÐÅÏ¢¡£PRODAFT·¢ÏÖÁËPYSAµÄ¹«¿ª.gitÎļþ¼Ð£¬ÆäÖÐÒ»¸ö³ÉÔ±ÊÇ¡°dodo@mail.pcc¡±£¬Æ¾¾ÝÌá½»º¹ÇàÅжϴËÈËλÓÚÒ»¸öÏÄÁîʱ¹ú¶È¡£PYSAµÄ»ù´¡ÉèÊ©»¹Ô̺¬dockerizedÈÝÆ÷£¬É漰й¶·þÎñÆ÷¡¢Êý¾Ý¿âºÍÖÎÀí·þÎñÆ÷£¬ÒÔ¼°´æ´¢¼ÓÃÜÎļþµÄAmazon S3ÔÆ£¬×ܼÆ31.47TB¡£
https://thehackernews.com/2022/04/researchers-share-in-depth-analysis-of.html
5¡¢CheckPoint°ä²¼2022ÄêÃæ¶Ô×î´óµÄÔÆ°²È«ÌôÕ½µÄ»ã±¨
CheckPointÔÚ4ÔÂ18ÈÕ°ä²¼ÁË2022ÄêÃæ¶ÔµÄ×î´óÔÆ°²È«ÌôÕ½µÄ»ã±¨¡£»ã±¨Ö¸³ö£¬³¬¹ý98%µÄ×é֯ʹÓûùÓÚÔÆµÄ»ù´¡¼Ü¹¹£¬76%µÄ×éÖ¯Õ¼ÓÐÓÉÁ½¸ö»ò¶à¸öÔÆÌṩÉ̵ķþÎñ×é³ÉµÄ¶àÔÆ»·¾³¡£¶àÔÆ»·¾³µÄ¸´ÔÓÐÔµ¼ÖÂÁ˺ܶàÌôÕ½£¬Ô̺¬Êý¾ÝµÄÒþÖԺͱ£»¤¡¢¶àÔÆ»·¾³ÖбØÒªµÄ¼¼Êõ¡¢½â¾ö¹æ»®ÕûºÏÒÔ¼°¿É¼ûÐԺͽÚÔìµÄ²»×㡣ʵÏÖÔÆ°²È«µÄÖØÒªÖ¸±êÔ̺¬Ô¤·ÀÔÆÅäÖÃÃýÎó¡¢±£»¤ÒÑÔÚʹÓõÄÖØÒªÔÆÀûÓ÷¨Ê½¡¢ÊµÏÖ¼à¹ÜºÏ¹æºÍÕмܶñÒâÈí¼þ¡£
https://blog.checkpoint.com/2022/04/18/the-biggest-cloud-security-challenges-in-2022-check-point-software/
6¡¢Fortinet°ä²¼½üÆÚEmotet Maldoc·¢×÷Ç÷ÏòµÄ·ÖÎö»ã±¨
4ÔÂ18ÈÕ£¬Fortinet°ä²¼¹ØÓÚ½üÆÚEmotet·Ö·¢Maldoc»î¶¯µÄ·ÖÎö»ã±¨¡£´ËÂֻÆðÍ·ÓÚ2021Äê11ÔÂ16ÈÕ£¬Ê¹ÓÃÁË´¹µöÓʼþÓëÉç»á¹¤³Ì¹¥»÷Ïà½áºÏµÄ·½Ê½£¬À´ÓÕʹָ±ê×°ÖöñÒâÈí¼þ¡£ÕâЩ´¹µöÓʼþµÄÖ÷ÌâÐÐÖÐͨ³£ÖÐÔ̺¬¡°Re:¡±»ò¡°Fw:¡±£¬Ê¹Æä¿´ÆðÀ´Ô½·¢ºÏ·¨¡£×êÑÐÈËÔ±¼ì²âµ½ÁËÓë´Ë»î¶¯ÓйصÄ5¸ö·ÖÆçÑù±¾£¬ËüÃǵĺê´úÂëºÍÖ´ÐÐÁ÷³Ì´æÔÚ²î¾à¡£´Ë±í£¬¹¥»÷»î¶¯Ê¹ÓõĶñÒâExcelÎļþµÄÕ¼±ÈΪ93%£¬Ô¶¸ßÓÚ7%µÄ¶ñÒâWordÎĵµ¡£
https://www.fortinet.com/blog/threat-research/Trends-in-the-recent-emotet-maldoc-outbreak


¾©¹«Íø°²±¸11010802024551ºÅ