΢ÈíÅû¶LinuxÖÐͳ³ÆÎªNimbuspwnµÄ2¸öÌáȨ·ì϶µÄÏêÇé
°ä²¼¹¦·ò 2022-04-28΢ÈíÔÚ4ÔÂ26ÈÕÅû¶ÁËLinuxÖÐÒ»×éÃûΪNimbuspwnµÄ·ì϶µÄÏêÇé¡£·ì϶±ðÀëΪĿ¼±éÀú·ì϶(CVE-2022-29799)¡¢·ûºÅÁ´½Ó¾ºÕùÒÔ¼°Time-of-check-time-of-use(TOCTOU)¾ºÕùǰÌá·ì϶(CVE-2022-29800)£¬¿É±»±¾µØ¹¥»÷ÕßÓÃÀ´ÌáÉýȨÏÞ£¬×°ÖúóÃźÍÀÕË÷Èí¼þµÈ¶ñÒâÈí¼þ¡£ËüÃÇ´æÔÚÓÚsystemd×é¼þnetworkd-dispatcherÖУ¬ÕâÊÇÒ»¸öÓÃÓÚÍøÂçÖÎÀíÆ÷ϵͳ·þÎñµÄÊØ»¤·¨Ê½¡£
https://www.microsoft.com/security/blog/2022/04/26/microsoft-finds-new-elevation-of-privilege-linux-vulnerability-nimbuspwn/
2¡¢Google½¨¸´VirusTotalÖеÄRCE·ì϶CVE-2021-22204
ýÌå4ÔÂ26ÈÕ±¨Â·£¬GoogleÒѽ¨¸´VirusTotalƽ̨ÖеÄRCE·ì϶£¨CVE-2021-22204£©¡£¸Ã·ì϶ÊÇExifTool¶ÔDjVuÎļþ´¦Öò»µ±µ¼Öµģ¬¿É±»¹¥»÷ÕßÓÃÀ´±øÆ÷»¯VirusTotalƽ̨£¬²¢ÔÚʹÓÃɱ¶¾ÒýÇæµÄµÚÈý·½É³ºÐÉÏʵÏÖÔ¶³Ì´úÂëÖ´ÐС£×êÑÐÈËÔ±ÌáÐÑ£¬·ì϶²¢²»Ó°ÏìVirusTotal£¬´úÂëÖ´Ðв»´æÔÚÓÚÆ½Ì¨×ÔÉí£¬¶øÊÇÔÚ·ÖÎöºÍÖ´ÐÐÑù±¾µÄµÚÈý·½É¨Ãèϵͳ¡£¸Ã·ì϶ÓÚ2021Äê4Ô±»Åû¶£¬ÓÚ2021Äê5Ô±»½ÓÊÜ£¬¶ø²¹¶¡Óڰ˸öÔºóµÄ2022Äê1Ô°䲼¡£
https://www.hackread.com/critical-rce-vulnerability-google-virustotal/
3¡¢StormousÍÅ»ïÐû³ÆÒÑÇÔÈ¡ÊʿڿÉÀÖ¹«Ë¾161 GBµÄÊý¾Ý
¾Ý4ÔÂ26ÈÕ±¨Â·£¬ÀÕË÷ÍÅ»ïStormousÐû³ÆÒÑÇÔÈ¡ÊʿڿÉÀÖ¹«Ë¾³¬¹ý161 GBµÄÊý¾Ý¡£¹¥»÷ÕßÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ÁгöÁË´ýÊÛÊý¾Ý£¬²¢ÏòÊʿڿÉÀÖ¹«Ë¾ÀÕË÷1.65±ÈÌØ±Ò£¨Ô¼ºÏ64000ÃÀÔª£©¡£Ð¹Â¶Êý¾ÝÔ̺¬Ñ¹ËõÎĵµ¡¢µç×ÓÓʼþºÍÃÜÂëµÄÎı¾Îļþ¡¢ÕÊ»§ºÍ¸¶¿îÓйØZIPÎĵµµÈ¡£ÕâÊÇStormousÍÅ»ïµÚÒ»´Î¹«¿ª±»µÁÊý¾Ý¡£ÊʿڿÉÀÖ¹«Ë¾°µÊ¾ÖªÏ¤ÓëÆäÓйصÄÍøÂç¹¥»÷µÄ±¨Â·ºó£¬ÔÚµ÷²é´ËÊÂÎñ¡£
https://securityaffairs.co/wordpress/130614/cyber-crime/stormous-ransomware-hit-coca-cola.html
4¡¢Hive0117¼ÙÒâ¶íÂÞ˹·¨Âɲ¿ÃŶԶ«Å·¹ú¶È½øÐд¹µö¹¥»÷
ýÌå4ÔÂ27Èճƣ¬IBMµÄX-ForceÍŶӷ¢ÏÖ½üÆÚÕë¶Ô¶«Å·¹ú¶ÈµÄ´¹µö¹¥»÷¡£Õâ´Î´¹µö»î¶¯ÆðÍ·ÓÚ2022Äê2Ô£¬Ö¼ÔÚ·Ö·¢ÃûΪDarkWatchmanµÄÎÞÎļþ¶ñÒâÈí¼þ±äÖÖ¡£¹¥»÷Õß¼ÙÒâ¶íÂÞ˹µÄ·¨Âɲ¿ÃÅ£¬ÊÕ¼þÈËÊÇÁ¢ÌÕÍð¡¢°®É³ÄáÑǺͶíÂÞ˹µÄµçÕÛ·þÎñÌṩÉ̺͹¤Òµ¹«Ë¾¡£´¹µöÓʼþÀ´×Ô˾·¨²¿µÄÕæÊµµØÖ·£¬ÀýÈç¡°mail@r77[.]fssprus[.]ru¡±£¬ÕýÎÄ»¹´øÓÐÕæÊµµÄ±êÖ¾¡£Ëù¸½µÄZIPÎļþÔ̺¬×°ÖÃDarkWatchmanµÄ¿ÉÖ´ÐÐÎļþ£¬ºÍ¼ÓÃܵļüÅ̼ͼ·¨Ê½¡£
https://www.bleepingcomputer.com/news/security/russian-govt-impersonators-target-telcos-in-phishing-attacks/
5¡¢Secureworks³ÆConti±³ºóÍÅ»ïGold UlrickµÄ»î¶¯¼¤Ôö
ýÌå4ÔÂ26Èճƣ¬¹ÌÈ»ÀÕË÷Èí¼þContiÔÚ²»¾Ãǰ²úÉúÁËÊý¾Ýй©ÊÂÎñ£¬µ«Æä±³ºóÍÅ»ïGold UlrickµÄ¹¥»÷ÈÔÔÚ³ÖÐø¡£ContiÊý¾ÝÐ¹Â¶ÍøÕ¾ÔÚ2021Äê¾ùÔÈÿÔÂÁгö43¸ö±»¹¥»÷Ö¸±ê£¬ÔÚ11Ô´ﵽ·åÖµ£¬Îª95¸ö¡£2022Äê2ÔÂ27ÈÕ£¬@ContiLeaks¹«¿ªÁËGOLD ULRICKµÄÊý¾ÝºÍͨѶ£¬µ«3Ô·ݱ»¹¥»÷Ö¸±êµÄÊýÁ¿¼¤Ôö£¬½ö´ÎÓÚÈ¥Äê11ÔµķåÖµ¡£¸ÃÍÅ»ïµÄ³ÉÔ±¡°Jordan Conti¡±°µÊ¾Êý¾Ýй¶¶ÔÆäÓ°ÏìºÜÓ×£¬ÆäÍøÕ¾ÔÚ4ÔµÄǰËÄÌì¾ÍÔö³¤ÁË11¸ö±»¹¥»÷Ö¸±ê¡£
https://thehackernews.com/2022/04/gold-ulrick-hackers-still-in-action.html
6¡¢Kaspersky°ä²¼2022ÄêQ1 DDoS¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨
2ÔÂ25ÈÕ£¬Kaspersky°ä²¼2022ÄêQ1 DDoS¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬2022ÄêµÚÒ»¼¾¶ÈµÄDDoS¸ñ¾ÖÊܵ½¶íÂÞ˹ºÍÎÚ¿ËÀ¼Ö®¼ä³ÖÐøÃ¬¶ÜµÄÓ°Ïì¡£KasperskyÔÚµÚÒ»¼¾¶È×ܹ²¼ì²âµ½ 91052´ÎDDoS¹¥»÷£»44.34%µÄ¹¥»÷Õë¶ÔÃÀ¹ú£¬Õ¼ËùÓй¥»÷µÄ45.02%¡££»×î¶àµÄDDoS¹¥»÷(16.35%)²úÉúÔÚÖÜÈÕ£»´óÎÞÊý¹¥»÷£¨94.95%£©³ÖÐø²»µ½4Ó×ʱ£¬×µÄ¹¥»÷³ÖÐøÁË549Ó×ʱ£»53.64%µÄ¹¥»÷ÊÇUDPºé·º£»55.53%µÄC&C·þÎñÆ÷λÓÚÃÀ¹ú¡£
https://securelist.com/ddos-attacks-in-q1-2022/106358/


¾©¹«Íø°²±¸11010802024551ºÅ