×°ÖÃWindows°²È«Æô¶¯DBXµÄ°²È«¸üÐÂʱ¿ÉÄܳöÏÖÃýÎó

°ä²¼¹¦·ò 2022-08-16
1¡¢×°ÖÃWindows°²È«Æô¶¯DBXµÄ°²È«¸üÐÂʱ¿ÉÄܳöÏÖÃýÎó

      

¾Ý8ÔÂ15ÈÕ±¨Â·£¬Î¢Èí°µÊ¾£¬µ±Óû§ÔÚĿǰ֧³ÖµÄ²Ù×÷ϵͳºÍÆóÒµ¼¶·þÎñÆ÷ÉÏ×°ÖÃWindows KB5012170°²È«¸üÐÂʱ£¬¿ÉÄÜ»á³öÏÖ0x800f0922ÃýÎó¡£KB5012170¸üÐÂÊǰ²È«Æô¶¯DBXµÄ°²È«¸üУ¬¸Ã´æ´¢¿âÔ̺¬Í³Ò»¿ÉÀ©´ó¹Ì¼þ½Ó¿Ú(UEFI)Êèµ¼¼ÓÔØ·¨Ê½µÄ³·ÏúÊðÃû¡£ÉÏÖÜ£¬EclypsiumÔøÅû¶ÁË3¸öµÚÈý·½Êèµ¼¼ÓÔØ·¨Ê½ÖÐÈÆ¹ý°²È«Æô¶¯µÄ·ì϶¡£Î¢ÈíÖ¸³ö£¬Äܹ»½«UEFI¸üе½¹©¸øÉÌÌṩµÄ×îаæÕý±¾»º½â¸ÃÎÊÌ⣬²¢½¨ÒéÖ»ÓÐÔÚÈ·±£É豸ÔËÐÐÁ˹©¸øÉÌÌṩµÄÎÞ·ì϶µÄÊèµ¼¼ÓÔØ·¨Ê½°æ±¾Ö®ºóÔÙ¸üÐÂDBX¡£


https://www.bleepingcomputer.com/news/security/windows-kb5012170-secure-boot-dbx-update-may-fail-with-0x800f0922-error/


2¡¢AndroidÒøÐÐľÂíSOVA»Ø¹éÐÂÔöÀÕË÷Èí¼þµÈÖ°ÄÜ

      

¾ÝCleafy 8ÔÂ11ÈÕÅû¶£¬AndroidÒøÐÐľÂíSOVA¾íÍÁ³ÁÀ´²¢ÐÂÔö¶àÖÖÖ°ÄÜ¡£2022Äê7Ô£¬SOVA¶ñÒâÈí¼þ°ä²¼Á˵Ú4¸ö°æ±¾£¬ÆäÖ¸±êÀûÓ÷¨Ê½Ôö³¤µ½200¸ö£¬²¢ÐÂÔöVNCÖ°ÄÜÓÃÓÚÉ豸ÉϵÄڲƭ¡£Ö®ºó£¬×êÑÐÈËÔ±»¹·¢ÏÖÁËSOVA v5µÄÔçÆÚ°æ±¾£¬Ëü½øÐÐÁË´óÁ¿´úÂë¸Ä½ø²¢Ôö³¤ÀÕË÷Èí¼þÄ£¿éµÈÐÂÖ°ÄÜ£¬¸ÃÄ£¿éʹÓÃAES¼ÓÃÜÀ´Ëø¶¨±»Ï°È¾É豸ÖеÄËùÓÐÎļþ£¬²¢¸½¼ÓÀ©´óÃû.enc¡£Ä¿Ç°£¬µÚ5°æ»¹Ã»ÓнøÐÐ¿í·º´«²¼£¬ÇÒ¸ÃÔçÆÚÑù±¾ÖжÌȱVNCÄ£¿é£¬ËùÒÔÕâ¸ö°æ±¾ºÜ¿ÉÄÜÈÔÔÚ¿ª·¢ÖС£


https://www.cleafy.com/cleafy-labs/sova-malware-is-back-and-is-evolving-rapidly


3¡¢CybleɨÃè·¢ÏÖ³¬¹ý9000̨ÔÚÍøÉ϶³öµÄVNC·þÎñÆ÷

      

¾Ý8ÔÂ14ÈÕ±¨Â·£¬Cyble×êÑÐÈËÔ±·¢ÏÖÁËÖÁÉÙ9000̨¶³öµÄVNC£¨Ðé¹¹ÍøÂçÍÆË㣩·þÎñÆ÷£¬ÎÞÐèÉí·ÝÑéÖ¤¼´¿É½Ó¼ûºÍʹÓá£ÕâЩ¶³öµÄÊ·ý¿É±»¹¥»÷ÕßÓÃÀ´½Ó¼ûÄÚ²¿ÍøÂ磬´óÎÞÊýλÓÚÈðµä¡¢ÃÀ¹ú¡¢Î÷°àÑÀºÍ°ÍÎ÷µÈ¹ú¡£ÎªÏàʶ¹¥»÷Õß¹¥»÷VNC·þÎñÆ÷µÄƵÂÊ£¬Cyble¼à¿ØÁ˶ÔVNCµÄĬÈ϶˿Ú5900µÄ¹¥»÷£¬·¢ÏÖÒ»¸öÔÂÄÚÓг¬¹ý600Íò¸öÒªÇó¡£´Ë±í£¬ºÚ¿ÍÂÛ̳¶Ô¶³ö»òÆÆ½âµÄVNC½Ó¼ûµÄÐèÒªÒ²ºÜ¸ß£¬¹¥»÷Õß¿ÉÀÄÓÃVNC½øÐжñÒâ²Ù×÷£¬Èç´ò¿ªÎĵµ¡¢ÏÂÔØÎļþºÍÖ´ÐÐËÁÒâºÅÁîµÈ¡£


https://www.bleepingcomputer.com/news/security/over-9-000-vnc-servers-exposed-online-without-a-password/


4¡¢·ÒÀ¼Òé»áµÄÍøÕ¾ÔÚÔâµ½»Ø¾ø·þÎñ¹¥»÷ºóÁÙʱ¹Ø¹Ø

      

¾ÝýÌå8ÔÂ12ÈÕ±¨Â·£¬·ÒÀ¼Òé»áµÄÍøÕ¾ÒòÔâµ½¹¥»÷ÁÙʱ¹Ø¹Ø¡£·ÒÀ¼Òé»áÔÚTwitterÉϰ䷢ÉêÃ÷³Æ£¬ÉÏÖܶþÏÂÎç2µã30·Ö×óÓÒ£¬Òé»áµÄ±í²¿ÍøÕ¾Ôâµ½Á˻ؾø·þÎñ¹¥»÷£¬Òé»á¡¢·þÎñÌṩÉ̺ÍÍøÂ簲ȫÖÐÐIJÉÈ¡ÁËÏìÓ¦´ëÊ©À´Ï޶ȹ¥»÷¡£Òé»áÔÚÉÏÖÜÈý·¢ÎijÆ£¬¸ÃÍøÕ¾ÒÑÓÚÖܶþÍíÉϸ´Ô­Õý³£¡£¾ÝϤ£¬Õë¶ÔÒé»áµÄ¹¥»÷²úÉúÔڰݵÇÇ©ÊðÖ§³Ö·ÒÀ¼ºÍÈðµä²ÎÓë±±Ô¼µÄÎļþµÄͳһÌì¡£


https://www.databreaches.net/finlands-parliament-hit-with-cyberattack-following-us-move-to-admit-the-country-to-nato/


5¡¢ÐµÄPyPI°üsecretslib¿ÉÔÚLinuxÉÏ×°ÖüÓÃÜ¿ó¹¤

      

SonatypeÔÚ8ÔÂ11ÈÕ³ÆÆä·¢ÏÖÁËÒ»¸öеÄPyPI°üsecretslib£¬¿ÉÔÚLinuxÉÏ×°ÖüÓÃܿ󹤡£¸Ã¶ñÒâÈí¼þÓÚ2022Äê8ÔÂ6ÈÕ°ä²¼£¬±»ÃèÊöΪʹ°ÂÃØÆ¥ÅäºÍÑéÖ¤±äµÃÈÝÒ×£¬ÔÚɾ³ýǰ±»ÒÑÏÂÔØ93´Î¡£Ëü»áÔÚLinuxÄÚ´æÖУ¨Ö±½Ó´ÓRAM£©ÔËÐÐMonero(XMR)¿ó¹¤£¬ÕâÖÖ¼¼ÊõÖØÒªÓÉÎÞÎļþ¶ñÒâÈí¼þºÍ¼ÓÃÜ·¨Ê½Ê¹Óá£´Ë±í£¬¸Ã¶ñÒâ»î¶¯ÏÕЩûÓÐÁôÏÂÈκÎ×ã¼££¬²¢ÀûÓÃÁËÃÀ¹úÄÜÔ´²¿ÔÞÖúµÄ³¢ÊÔÊÒ(ANL.gov)µÄÈí¼þ¹¤³ÌʦµÄÉí·ÝºÍÁªÏµÐÅÏ¢À´Ôö³¤¿ÉÐŶÈ¡£


https://blog.sonatype.com/pypi-package-secretslib-drops-fileless-linux-malware-to-mine-monero


6¡¢KELA°ä²¼2022ÄêµÚ¶þ¼¾¶ÈÀÕË÷Èí¼þÌ¬ÊÆµÄ·ÖÎö»ã±¨

      

8ÔÂ11ÈÕ£¬ÍøÂçµý±¨¹«Ë¾KELA°ä²¼Á˹ØÓÚÀÕË÷Èí¼þµÄ·ÖÎö»ã±¨¡£ÀÕË÷ÍŻﲻÐÝ·¢Õ¹²¢Íþв×ÅÊÀ½ç¸÷µØµÄ×éÖ¯£¬Ö»¹Ü²¿ÃÅÍÅ»ïÔÚ2022ÄêQ2Ï÷¼õ»òÖÕ³¡Á˻£¬µ«ÏñBlack BastaÕâÑùµÄÐÂÍÅ»ï³öÏÖ²¢³ÖÐøÀÕË÷²Æ²¯¡£2022ÄêQ2ÀÕË÷¹¥»÷»î¶¯Ï÷¼õÁË7%£¬¾ùÔÈÿ¸öÔ¼ì²âµ½216´Î¹¥»÷ £»×î»îÔ¾µÄÀÕË÷ÍÅ»ïÊÇLockBit¡¢Black Basta¡¢Alphv¡¢ContiºÍVice Society£¬¶¼Òѹ¥»÷³¬¹ý40¸öÖ¸±ê £»ÀÕË÷¹¥»÷ÕßÖØÒªÕë¶ÔµÄÊÇÔì×÷ÒµºÍ¹¤Òµ¡£


https://ke-la.com/wp-content/uploads/2022/08/KELA-RESEARCH_Ransomware-Victims-and-Network-Access-Sales_Q2-2022.pdf