Windows KB5013943¸üпɵ¼ÖÂSophosɱ¶¾´¥·¢À¶ÆÁ
°ä²¼¹¦·ò 2022-05-18¾ÝýÌå5ÔÂ16ÈÕ±¨Â·£¬×°ÖÃKB5013943¸üкóµÄWindows 11ÉÏÔËÐÐSophos Homeɱ¶¾Èí¼þ»á´¥·¢À¶ÆÁËÀ»ú£¨BSOD£©ÎÊÌâ¡£Sophos°µÊ¾£¬Õâ¸öÎÊÌâÊÇÓÉÓÚSophos HomeʹÓõÄhmpalert.sys£¨±ðÃûHitManPro.Alert Support£©WindowsÇý¶¯·¨Ê½ÒýÆðµÄ¡£´ËÎÊÌâµÄ½¨¸´·¨Ê½½«×Ô¶¯ÀûÓÃÓÚËùÓÐÊÜÓ°ÏìµÄϵͳ£¬Óû§Äܹ»ÔÚC:\Windows\System32\driversÖвé³hmpalert.sysµÄ¾ßÌåÐÅÏ¢À´È·¶¨½¨¸´·¨Ê½ÊÇ·ñÒѱ»ÀûÓá£Î´½øÐÐ×Ô¶¯½¨¸´µÄÓû§±ØÒª³Á¶¨Ãûhmpalert.sysÇý¶¯·¨Ê½»òÐ¶ÔØÓÐÎÊÌâµÄWindows¸üС£
https://www.bleepingcomputer.com/news/software/sophos-antivirus-driver-caused-bsods-after-windows-kb5013943-update/
2¡¢NVIDIA°ä²¼¸üУ¬½¨¸´ÆäGPUÇý¶¯·¨Ê½ÖеĶà¸ö·ì϶
5ÔÂ16ÈÕ£¬NVIDIA°ä²¼5Ô·ݰ²È«¸üУ¬½¨¸´ÁËÆäGPUÇý¶¯·¨Ê½ÖеĶà¸ö·ì϶¡£Õâ´Î¸üн¨¸´ÁË¿ÉÄܵ¼Ö»ؾø·þÎñ¡¢ÐÅϢй¶¡¢ÌØÈ¨ÌáÉý¡¢´úÂëÖ´Ðеȵķì϶£¬ºÏÓÃÓÚÈí¼þ²úÆ·Tesla¡¢RTX/Quadro¡¢NVS¡¢StudioºÍGeForce£¬º¸ÇÇý¶¯·ÖÖ§R450¡¢R470ºÍR510¡£ÆäÖнÏΪÑϳÁµÄ·ì϶ÊÇCVE-2022-28181¡¢CVE-2022-28182¡¢CVE-2022-28183ºÍCVE-2022-28184£¬ËüÃǽöÐè½ÏµÍµÄȨÏÞÇÒÎÞÐèÓëÓû§½»»¥£¬¹¥»÷Õß¿ÉÀûÓÃÆäÖ´ÐÐÓµÓиü¸ßȨÏ޵ĺÅÁî¡£½¨ÒéËùÓÐЧ»§¾¡¿ì×°ÖÃÒѰ䲼µÄ¸üС£
https://www.bleepingcomputer.com/news/security/nvidia-fixes-ten-vulnerabilities-in-windows-gpu-display-drivers/
3¡¢Malwarebytes·¢ÏÖÕë¶ÔµÂ¹úµÄ×Ô½ç˵PowerShell RAT
MalwarebytesÔÚ5ÔÂ16ÈÕÅû¶ÁËÕë¶ÔµÂ¹úµÄ×Ô½ç˵PowerShell RATµÄϸ½ÚÐÅÏ¢¡£¹¥»÷Õß×¢²áÁËÒ»¸öµÂ¹úÓòÃûcollaboration-bw[.]de£¬²¢¿Ë¡ÁËÕæÊµÍøÕ¾µÄ±í¹Û¡£ÍøÕ¾Ìṩһ¸öÃûΪ2022-Q2-Bedrohungslage-UkraineµÄÎļþ£¬¾Ý³ÆÔ̺¬Á˹ØÓÚÎÚ¿ËÀ¼´óÊÆµÄÐÅÏ¢¡£¸ÃÎļþ»á´¥·¢Ò»¸öÔËÐÐBase64È¥»ìºÏ·¨Ê½µÄPowerShell£¬´Ó¶ø»ñÈ¡²¢Ö´ÐжñÒâ¾ç±¾¡£×îÖÕ£¬¸Ã¾ç±¾»áÏÂÔØÒ»¸ö.txt´ó¾ÖµÄRATºÍÒ»¸öͨ¹ýPowerShellÔ®ÊÔìäÖ´ÐеÄ.cmdÎļþ¡£
https://blog.malwarebytes.com/threat-intelligence/2022/05/custom-powershell-rat-targets-germans-seeking-information-about-the-ukraine-crisis/
4¡¢ÃÀ¹ú¹¤³Ì¹«Ë¾ParkerÔâµ½ÀÕË÷ÍÅ»ïContiµÄ¹¥»÷
¾Ý5ÔÂ16ÈÕ±¨Â·£¬ÃÀ¹ú¹¤³Ì¹«Ë¾Parker-Hannifin CorporationÔâµ½ÁËÀÕË÷ÍÅ»ïContiµÄ¹¥»÷¡£ParkerרÃÅ´ÓÊ»ºÍ½ÚÔì¼¼Êõ£¬³Áµã¹Ø×¢º½¿ÕҺѹÉ豸£¬ÊÕÈëΪ156ÒÚ¡£¸Ã¹«Ë¾°µÊ¾£¬¹¥»÷²úÉúÔÚ½ñÄê3ÔÂ11ÈÕÖÁ14ÈÕÆÚ¼ä£¬ËûÃǵ±¼´Æô¶¯ÁËÊÂÎñÏìÓ¦ºÍ̸£¬²¢¹Ø¹ØÁ˲¿ÃÅϵͳ¡£¾¹ýµ÷²é£¬È·¶¨²¿ÃÅÔ±¹¤µÄÐÅϢй¶£¬Ô̺¬ÐÕÃû¡¢Éç»á°²È«ºÅÂë(SSN)¡¢¼ÒÍ¥µØÖ·¡¢¼ÝÊ»ÅÆÕÕºÅÂë¡¢»¤ÕÕºÅÂë¡¢²ÆÕþÕË»§ÐÅÏ¢ºÍÕÊ»§ÃÜÂëµÈ¡£ContiÔÚ4ÔÂ1ÈÕÐû³Æ¶Ô´ËÊÂÕÆ¹Ü£¬²¢ÔÚ4ÔÂ20ÈÕ°ä²¼ÁËÇÔÈ¡µÄ419 GBÊý¾Ý¡£
https://www.infosecurity-magazine.com/news/parker-conti-ransomware/
5¡¢Kaspersky³Æ2022ÄêHTML¸½¼þÔÚ´¹µö»î¶¯ÖÐÒÀÈ»Á÷ÐÐ
5ÔÂ16ÈÕ£¬Kaspersky°ä²¼»ã±¨³Æ2022ÄêHTML¸½¼þÔÚ´¹µö»î¶¯ÖÐÒÀÈ»Á÷ÐС£¹¥»÷ÕßÖØÒªÊ¹ÓÃÁ½ÖÖÀàÐ͵ÄHTML¸½¼þ£º´øÓÐÖ¸ÏòαÔìÍøÕ¾Á´½ÓµÄHTMLÎļþ£¬»òÒ»¸ö³ÉÊìµÄÍøÂç´¹µöÒ³Ãæ¡£»ã±¨Ö¸³ö£¬ÔÚ2022Äêǰ4¸öÔ£¬¼ì²âµ½½ü200Íò·âÔ̺¬¶ñÒâHTML¸½¼þµÄµç×ÓÓʼþ£¬ÔÚ3Ô·ݴﵽ·åÖµ£¬¼ì²âµ½851000·â£¬¶øÔÚ4Ô½µÖÁ387000´Î¡£×êÑÐÈËÔ±°µÊ¾£¬´ËÀ๥»÷¿ÉÄÜÈÆ¹ý°²È«²úÆ·µÄ¼ì²â£¬Òò¶øÓû§Ó¦¸ÃʼÖÕ½«HTML¸½¼þÊÓΪ¸ß¶È¿ÉÒɵġ£
https://securelist.com/html-attachments-in-phishing-e-mails/106481/
6¡¢Trend Micro°ä²¼¶ñÒâÈí¼þFacestealerµÄ·ÖÎö»ã±¨
Trend MicroÔÚ5ÔÂ16ÈÕ°ä²¼Á˹ØÓÚ¶ñÒâÈí¼þFacestealerµÄ¼¼Êõ·ÖÎö»ã±¨¡£FacestealeÓÚ2021Äê7Ô³õ´Î±»·¢ÏÖ£¬¿ÉÓÃÀ´ÇÔÈ¡FacebookÍ´´¦¡£×êÑÐÈËÔ±°µÊ¾£¬×î½üµÄµ÷²éÔÚGoogle Play É̵êÖз¢ÏÖÁË200¶à¸öFacestealerÀûÓ÷¨Ê½£¬ÆäÖÐһЩÒѾװÖÃÁ˳¬¹ýÊ®Íò´Î¡£ËüÃÇͨ³£¼Ù×°³É½¡ÉíºÍÕÕÆ¬±à×ëµÅצÓ÷¨Ê½£¬ÈçDaily Fitness OL¡¢Enjoy Photo Editor¡¢Panorama CameraºÍPhoto Gaming PuzzleµÈ¡£Ä¿Ç°£¬GoogleÒÑ´ÓÉ̵êÖÐÒÆ³ýÁËÕâЩÀûÓá£
https://www.trendmicro.com/en_us/research/22/e/fake-mobile-apps-steal-facebook-credentials--crypto-related-keys.html


¾©¹«Íø°²±¸11010802024551ºÅ