΢Èí°ä²¼5Ô·ݲ¹¶¡£¬½¨¸´Ô̺¬3¸ö0dayÔÚÄÚµÄ75¸ö·ì϶
°ä²¼¹¦·ò 2022-05-115ÔÂ10ÈÕ£¬Î¢Èí°ä²¼Á˱¾ÔµÄÖܶþ²¹¶¡£¬×ܼƽ¨¸´ÁË75¸ö·ì϶£¬ÆäÖÐÒ»¸öÒѱ»ÀûÓá£Õâ´Î¸üн¨¸´ÁË3¸ö0 day·ì϶£¬±ðÀëΪWindows LSAºýŪ·ì϶£¨CVE-2022-26925£©£¬¿Éͨ¹ýŲÓÃLSARPC½Ó¿ÚÉϵIJ½Ö貢ǿÔìÓò½ÚÔìÆ÷ʹÓÃNTLM½øÐÐÉí·ÝÑéÖ¤£¬Òѱ»»ý¼«ÀûÓã»Windows Hyper-V»Ø¾ø·þÎñ·ì϶£¨CVE-2022-22713£©£»Magnitude Simba Amazon Redshift ODBCÇý¶¯·¨Ê½Öеķì϶£¨CVE-2022-29972£©¡£´Ë±í£¬»¹½¨¸´ÁËÔ¶³Ì×ÀÃæ¿Í»§¶ËRCE·ì϶£¨CVE-2022-22017£©ºÍActive DirectoryÓò·þÎñÌØÈ¨ÌáÉý·ì϶£¨CVE-2022-26923£©µÈ¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-may-2022-patch-tuesday-fixes-3-zero-days-75-flaws/
2¡¢´÷¶û¡¢Æ»¹ûºÍNetflixÒò½«·þÎñ³·³ö¶íÂÞ˹¶øÃæ¶ÔËßËÏ
¾Ý5ÔÂ9ÈÕ±¨Â·£¬ÔÚ´÷¶û¹«Ë¾Î´ÄÜÏò±¾µØÏµÍ³¼¯³ÉÉÌÌṩ¸¶·Ñ·þÎñºó£¬ÄªË¹¿ÆÖٲ÷¨Ôº³ä¹«ÁËÊôÓڸù«Ë¾µÄ½ü1100ÍòÃÀÔª¡£¾ÝϤ£¬ÊÇITϵͳ¼¯³ÉÉÌTalmerÔÚÉÏÔ³õ¸æ×´ÁË´÷¶û£¬ÔÒòÊǸù«Ë¾ÊÂÏÈÒÑÏò´÷¶ûÖ§¸¶ÁË·þÎñÓöȣ¬µ«Î´µÃµ½ÕâЩ·þÎñ¡£ÉϸöÔÂÄ©£¬Æ»¹û¹«Ë¾ÓÉÓڴӸùú³·ÏúÁËÆäÖ§¸¶·þÎñApple Pay£¬Ò²Ãæ¶ÔÀàËÆµÄ˾·¨ÎÊÌ⣬ҪÇóÅâ³¥9000Íò¬²¼£¨Ô¼129ÍòÃÀÔª£©¡£NetflixÔÚ4ÔÂÒòÀàËÆµÄÎ¥·´Óû§Ìõ¿î±êÔÒòÔâµ½¼¯ÌåËßËÏ£¬ÒªÇóÅâ³¥6000Íò¬²¼£¨86ÍòÃÀÔª£©¡£
https://www.bleepingcomputer.com/news/technology/dell-apple-netflix-face-lawsuits-for-pulling-services-out-of-russia/
3¡¢KasperskyÔÚGoogle Play¼ì²âµ½¶à¸öϰȾJokerµÄÀûÓÃ
¾ÝKasperskyÔÚ5ÔÂ6ÈÕ°ä²¼µÄ»ã±¨£¬Google PlayÖдæÔÚ¶à¸öϰȾÁËJokerµÄÀûÓá£Trojan.AndroidOS.JockerϵÁÐľÂíÄܹ»À¹½Ø¶ÌÐÅÖз¢Ë͵ĴúÂë²¢ÈÆ¹ý·´Ú²Æ½â¾ö¹æ»®£¬ËüÃÇͨ³£ÔÚ Google PlayÉÏ´«²¼¡£¹¥»÷ÕßÏÈÏÂÔØºÏ·¨ÀûÓò¢ÏòÆäÖÐÔö³¤¶ñÒâ´úÂ룬ÔÙÒÔ·ÖÆçµÄÃû³Æ³ÁÐÂÉÏ´«µ½Google Play¡£Õâ´Î·¢Ïֵı»Ï°È¾ÀûÓñðÀëΪStyle Message¡¢Blood Pressure AppºÍCamera PDF Scanner¡£Ä¿Ç°ËüÃÇÒÑ´ÓGoogle PlayÖÐÒÆ³ý£¬µ«ÈÔ¿É´ÓµÚÈý·½Æ½Ì¨»ñµÃ¡£
https://securelist.com/mobile-subscription-trojans-and-their-tricks/106412/
4¡¢ÎÚ¿ËÀ¼CERT-UA·¢ÏÖÖ¼ÔÚ·Ö·¢JesterµÄ´ó¹æÄ£´¹µö»î¶¯
ýÌå5ÔÂ9ÈÕ±¨Â·£¬ÎÚ¿ËÀ¼ÍÆËã»úÓ¦¼±ÏìÓ¦Ó××é(CERT-UA)¼ì²âµ½´«²¼ÇÔÈ¡¶ñÒâÈí¼þJesterµÄ´ó¹æÄ£´¹µö»î¶¯¡£´¹µöÓʼþÒÔ¡°»¯Ñ§¹¥»÷¡±ÎªÖ÷Ì⣬Ô̺¬ÁËÖ¸Ïò¶ñÒâMicrosoft ExcelÎļþµÄÁ´½Ó£¬Ö¸±ê´ò¿ªÎĵµ²¢¼¤»îǶÈëµÄºêºó£¬Ï°È¾¹ý³ÌÆðÍ·¡£Æ¾¾ÝCERT-UA²¼¸æ£¬¿ÉÖ´ÐÐÎļþÊÇ´Ó±»Ï°È¾µÄÍøÕ¾ÏÂÔØµÄ£¬¶ø²»ÊÇÖ±½Ó´Ó¹¥»÷Õß½ÚÔìµÄ»ù´¡ÉèÊ©¡£Ä¿Ç°£¬Éв»Ã÷ÏÔÕâ´Î»î¶¯±³ºó¹¥»÷ÕßµÄÉí·Ý¡£
https://securityaffairs.co/wordpress/131113/breaking-news/cert-ua-warns-jester-stealer-attacks.html
5¡¢BlackBerry°ä²¼¹ØÓÚÁ®¼ÛµÄóÒ×RAT DCRatµÄ·ÖÎö»ã±¨
BlackBerryÔÚ5ÔÂ9ÈÕ°ä²¼Á˹ØÓÚóÒ×RAT DCRat£¨ÓÖ³ÆDarkCrystal RAT£©µÄ·ÖÎö»ã±¨¡£DCRatÊÇÒ»¸öÖ°ÄÜÆëÈ«µÄºóÃÅ£¬ÊÇ¡°boldenis44¡±ºÍ¡°crystalcoder¡±ÓÃ.NET¿ª·¢µÄ¡£ËüÊÇ×î±ãÒ˵ÄóÒ×RATÖ®Ò»£¬Æ½Éú¶©ÔķѽöΪ4200¬²¼£¨40ÃÀÔª£©¡£¸Ã¶ñÒâÈí¼þÓÉ3¸ö²¿ÃÅ×é³É£ºÇÔÈ¡Æ÷/¿Í»§¶Ë¿ÉÖ´ÐÐÎļþ¡¢PHPÒ³ÃæºÍÖÎÀíÔ±¹¤¾ß£¬ÓµÓмල¡¢¿úËÅ¡¢ÐÅÏ¢ÇÔÈ¡¡¢DDoS¹¥»÷ÒÔ¼°´úÂëÖ´ÐеÈÖ°ÄÜ¡£
https://blogs.blackberry.com/en/2022/05/dirty-deeds-done-dirt-cheap-russian-rat-offers-backdoor-bargains
6¡¢Resecurity°ä²¼¹ØÓÚеÄPhaaS FrappoµÄ¼¼Êõ·ÖÎö»ã±¨
ýÌå5ÔÂ10ÈÕ±¨Â·£¬Resecurity·¢ÏÖÁËÒ»ÖÖеÄPhishing-As-A-Service£¨PhaaS£©Frappo¡£¸Ã·þÎñ×îÔçÓÚ2021Äê3ÔÂ22ÈÕ³öÏÖ£¬½üÆÚÓÖÌṩÁËÉæ¼°Îª20¶à¼Ò½ðÈÚ»ú¹¹¡¢ÔÚÏßÁãÊÛÉ̺ÍÓŲ½µÈ·þÎñµÄ´¹µöÒ³Ãæ¡£´Ë±í£¬´¹µöÒ³ÃæµÄ²¿Êð¹ý³ÌÊÇÆëÈ«×Ô¶¯»¯µÄ£¬FrappoÀûÓÃÒ»¸öÔ¤ÏÈÅäÖõÄDockerÈÝÆ÷ºÍÒ»¸ö°²È«Í¨Â·£¬ÓÃÀ´Í¨¹ýAPIÍøÂçÍ´´¦¡£×êÑÐÈËÔ±³Æ£¬ÏñFrappoÕâÑùµÄ´¹µö¼´·þÎñÒѱ»ÓÃÓÚÕÊ»§ÊÕÊÜ¡¢BEC¹¥»÷¡¢Êý¾Ý͵ÇԵȻ£¬¹¥»÷ÕßÒ»ÏòÔÚÀûÓÃÏȽøµÄ¹¤¾ßºÍÕ½ÊõÀ´¹¥»÷È«ÇòµÄÏû·ÑÕß¡£
https://securityaffairs.co/wordpress/131136/cyber-crime/frappo-phishing-as-a-service.html


¾©¹«Íø°²±¸11010802024551ºÅ