΢ÈíÅû¶LinuxÖÐͳ³ÆÎªNimbuspwnµÄ2¸öÌáȨ·ì϶µÄÏêÇé

°ä²¼¹¦·ò 2022-04-28
1¡¢Î¢ÈíÅû¶LinuxÖÐͳ³ÆÎªNimbuspwnµÄ2¸öÌáȨ·ì϶µÄÏêÇé

΢ÈíÔÚ4ÔÂ26ÈÕÅû¶ÁËLinuxÖÐÒ»×éÃûΪNimbuspwnµÄ·ì϶µÄÏêÇé ¡£·ì϶±ðÀëΪĿ¼±éÀú·ì϶(CVE-2022-29799)¡¢·ûºÅÁ´½Ó¾ºÕùÒÔ¼°Time-of-check-time-of-use(TOCTOU)¾ºÕùǰÌá·ì϶(CVE-2022-29800) £¬¿É±»±¾µØ¹¥»÷ÕßÓÃÀ´ÌáÉýȨÏÞ £¬×°ÖúóÃźÍÀÕË÷Èí¼þµÈ¶ñÒâÈí¼þ ¡£ËüÃÇ´æÔÚÓÚsystemd×é¼þnetworkd-dispatcherÖÐ £¬ÕâÊÇÒ»¸öÓÃÓÚÍøÂçÖÎÀíÆ÷ϵͳ·þÎñµÄÊØ»¤·¨Ê½ ¡£


https://www.microsoft.com/security/blog/2022/04/26/microsoft-finds-new-elevation-of-privilege-linux-vulnerability-nimbuspwn/


2¡¢Google½¨¸´VirusTotalÖеÄRCE·ì϶CVE-2021-22204


ýÌå4ÔÂ26ÈÕ±¨Â· £¬GoogleÒѽ¨¸´VirusTotalƽ̨ÖеÄRCE·ì϶£¨CVE-2021-22204£© ¡£¸Ã·ì϶ÊÇExifTool¶ÔDjVuÎļþ´¦Öò»µ±µ¼ÖµÄ £¬¿É±»¹¥»÷ÕßÓÃÀ´±øÆ÷»¯VirusTotalƽ̨ £¬²¢ÔÚʹÓÃɱ¶¾ÒýÇæµÄµÚÈý·½É³ºÐÉÏʵÏÖÔ¶³Ì´úÂëÖ´ÐÐ ¡£×êÑÐÈËÔ±ÌáÐÑ £¬·ì϶²¢²»Ó°ÏìVirusTotal £¬´úÂëÖ´Ðв»´æÔÚÓÚÆ½Ì¨×ÔÉí £¬¶øÊÇÔÚ·ÖÎöºÍÖ´ÐÐÑù±¾µÄµÚÈý·½É¨Ãèϵͳ ¡£¸Ã·ì϶ÓÚ2021Äê4Ô±»Åû¶ £¬ÓÚ2021Äê5Ô±»½ÓÊÜ £¬¶ø²¹¶¡Óڰ˸öÔºóµÄ2022Äê1Ô°䲼 ¡£


https://www.hackread.com/critical-rce-vulnerability-google-virustotal/


3¡¢StormousÍÅ»ïÐû³ÆÒÑÇÔÈ¡ÊʿڿÉÀÖ¹«Ë¾161 GBµÄÊý¾Ý


¾Ý4ÔÂ26ÈÕ±¨Â· £¬ÀÕË÷ÍÅ»ïStormousÐû³ÆÒÑÇÔÈ¡ÊʿڿÉÀÖ¹«Ë¾³¬¹ý161 GBµÄÊý¾Ý ¡£¹¥»÷ÕßÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ÁгöÁË´ýÊÛÊý¾Ý £¬²¢ÏòÊʿڿÉÀÖ¹«Ë¾ÀÕË÷1.65±ÈÌØ±Ò£¨Ô¼ºÏ64000ÃÀÔª£© ¡£Ð¹Â¶Êý¾ÝÔ̺¬Ñ¹ËõÎĵµ¡¢µç×ÓÓʼþºÍÃÜÂëµÄÎı¾Îļþ¡¢ÕÊ»§ºÍ¸¶¿îÓйØZIPÎĵµµÈ ¡£ÕâÊÇStormousÍÅ»ïµÚÒ»´Î¹«¿ª±»µÁÊý¾Ý ¡ £ÊʿڿÉÀÖ¹«Ë¾°µÊ¾ÖªÏ¤ÓëÆäÓйصÄÍøÂç¹¥»÷µÄ±¨Â·ºó £¬ÔÚµ÷²é´ËÊÂÎñ ¡£


https://securityaffairs.co/wordpress/130614/cyber-crime/stormous-ransomware-hit-coca-cola.html


4¡¢Hive0117¼ÙÒâ¶íÂÞ˹·¨Âɲ¿ÃŶԶ«Å·¹ú¶È½øÐд¹µö¹¥»÷


ýÌå4ÔÂ27ÈÕ³Æ £¬IBMµÄX-ForceÍŶӷ¢ÏÖ½üÆÚÕë¶Ô¶«Å·¹ú¶ÈµÄ´¹µö¹¥»÷ ¡£Õâ´Î´¹µö»î¶¯ÆðÍ·ÓÚ2022Äê2Ô £¬Ö¼ÔÚ·Ö·¢ÃûΪDarkWatchmanµÄÎÞÎļþ¶ñÒâÈí¼þ±äÖÖ ¡£¹¥»÷Õß¼ÙÒâ¶íÂÞ˹µÄ·¨Âɲ¿ÃÅ £¬ÊÕ¼þÈËÊÇÁ¢ÌÕÍð¡¢°®É³ÄáÑǺͶíÂÞ˹µÄµçÕÛ·þÎñÌṩÉ̺͹¤Òµ¹«Ë¾ ¡£´¹µöÓʼþÀ´×Ô˾·¨²¿µÄÕæÊµµØÖ· £¬ÀýÈç¡°mail@r77[.]fssprus[.]ru¡± £¬ÕýÎÄ»¹´øÓÐÕæÊµµÄ±êÖ¾ ¡£Ëù¸½µÄZIPÎļþÔ̺¬×°ÖÃDarkWatchmanµÄ¿ÉÖ´ÐÐÎļþ £¬ºÍ¼ÓÃܵļüÅ̼ͼ·¨Ê½ ¡£


https://www.bleepingcomputer.com/news/security/russian-govt-impersonators-target-telcos-in-phishing-attacks/


5¡¢Secureworks³ÆConti±³ºóÍÅ»ïGold UlrickµÄ»î¶¯¼¤Ôö


ýÌå4ÔÂ26ÈÕ³Æ £¬¹ÌÈ»ÀÕË÷Èí¼þContiÔÚ²»¾Ãǰ²úÉúÁËÊý¾Ýй©ÊÂÎñ £¬µ«Æä±³ºóÍÅ»ïGold UlrickµÄ¹¥»÷ÈÔÔÚ³ÖÐø ¡£ContiÊý¾ÝÐ¹Â¶ÍøÕ¾ÔÚ2021Äê¾ùÔÈÿÔÂÁгö43¸ö±»¹¥»÷Ö¸±ê £¬ÔÚ11Ô´ﵽ·åÖµ £¬Îª95¸ö ¡£2022Äê2ÔÂ27ÈÕ £¬@ContiLeaks¹«¿ªÁËGOLD ULRICKµÄÊý¾ÝºÍͨѶ £¬µ«3Ô·ݱ»¹¥»÷Ö¸±êµÄÊýÁ¿¼¤Ôö £¬½ö´ÎÓÚÈ¥Äê11ÔµķåÖµ ¡£¸ÃÍÅ»ïµÄ³ÉÔ±¡°Jordan Conti¡±°µÊ¾Êý¾Ýй¶¶ÔÆäÓ°ÏìºÜÓ× £¬ÆäÍøÕ¾ÔÚ4ÔµÄǰËÄÌì¾ÍÔö³¤ÁË11¸ö±»¹¥»÷Ö¸±ê ¡£


https://thehackernews.com/2022/04/gold-ulrick-hackers-still-in-action.html


6¡¢Kaspersky°ä²¼2022ÄêQ1 DDoS¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨


2ÔÂ25ÈÕ £¬Kaspersky°ä²¼2022ÄêQ1 DDoS¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨ ¡£»ã±¨Ö¸³ö £¬2022ÄêµÚÒ»¼¾¶ÈµÄDDoS¸ñ¾ÖÊܵ½¶íÂÞ˹ºÍÎÚ¿ËÀ¼Ö®¼ä³ÖÐøÃ¬¶ÜµÄÓ°Ïì ¡£KasperskyÔÚµÚÒ»¼¾¶È×ܹ²¼ì²âµ½ 91052´ÎDDoS¹¥»÷£»44.34%µÄ¹¥»÷Õë¶ÔÃÀ¹ú £¬Õ¼ËùÓй¥»÷µÄ45.02% ¡££»×î¶àµÄDDoS¹¥»÷(16.35%)²úÉúÔÚÖÜÈÕ£»´óÎÞÊý¹¥»÷£¨94.95%£©³ÖÐø²»µ½4Ó×ʱ £¬×µÄ¹¥»÷³ÖÐøÁË549Ó×ʱ£»53.64%µÄ¹¥»÷ÊÇUDPºé·º£»55.53%µÄC&C·þÎñÆ÷λÓÚÃÀ¹ú ¡£


https://securelist.com/ddos-attacks-in-q1-2022/106358/