×êÑÐÈËÔ±¼ì²âµ½241¸ö¶ñÒânpmºÍPyPI°ü·Ö·¢ÍÚ¿óÈí¼þ
°ä²¼¹¦·ò 2022-08-22
¾ÝýÌå8ÔÂ19ÈÕ±¨Â·£¬ÉÏÖÜÒÑ·¢ÏÖÁËÖÁÉÙ241¸ö¶ñÒâµÄPyPIºÍnpm°ü£¬ÕâЩ°ü»áÔÚϰȾLinuxÉ豸ºó»á×°ÖöñÒâÍÚ¿óÈí¼þ¡£ÉÏÖÜÈý£¬×êÑÐÈËÔ±¹«¿ªÁËÔÚPyPIÉÏ·¢ÏÖµÄ33¸öÏîÄ¿£¬¿ÉÔÚϰȾϵͳºóÆô¶¯¿ªÔ´ÃÅÂÞ±Ò¼ÓÃÜ¿ó¹¤XMRig¡£ÔÚÕâЩ°ü±»É¾³ýºó£¬×êÑÐÈËÔ±ÓÖ·¢ÏÖÁËÁíÒ»×éÓµÓÐÒ»ÑùpayloadµÄ22¸ö°ü¡£SonatypeÔÚ8ÔÂ19ÈÕÅû¶ÁË186¸önpmÓòÃûÇÀ×¢¶ñÒâ°ü£¬ËüÃǾùÀ´×ÔÄäÃûÕÊ»§17b4a931£¬·ÂÕÕÁ˳£ÓõÄhttp-errors JavaScript¿â¡£×êÑÐÈËԱƾ¾Ý¼¼ÊõÖ¸±ê´§¶È£¬Õâ241¸ö¶ñÒâ°üÓÉͳһ¹¥»÷Õß°ä²¼¡£
https://www.bleepingcomputer.com/news/security/241-npm-and-pypi-packages-caught-dropping-linux-cryptominers/
2¡¢ÐÂľÂíGrandoreiroÖØÒªÕë¶ÔÄ«Î÷¸çºÍÎ÷°àÑÀµÈ¹ú¶È
8ÔÂ18ÈÕ£¬Zscaler ThreatLabzÅû¶ÁËÐÂľÂíGrandoreiroÕë¶ÔÄ«Î÷¸çºÍÎ÷°àÑÀµÈ¹ú¶ÈµÄ¹¥»÷»î¶¯¡£¸Ã¶ñÒâÈí¼þÖÁÉÙ×Ô2017ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬Õâ´Î¹¥»÷ÓÚ2022Äê6ÔÂÆðÍ·£¬²¢ÇÒĿǰÈÔÔÚ½øÐÐÖС£¹¥»÷Õß¼Ù×°³ÉÀ´×ÔÄ«Î÷¸ç×ܼì²ì³¤°ì¹«ÊÒ»òÎ÷°àÑÀ¹«¹²²¿£¬×îÖÕpayloadÀûÓôÓASUSTEKÍ·´µÄÖ¤ÊéÊðÃû£¬Í¨¹ý¶þ½øÔìÌî³äµÄ²½Ö轫´óÓ×ÅòÕ͵½400MB£¬À´ÈƹýɳÏä·ÖÎö¡£´Ë±í£¬×îеÄGrandoreiro±äÌåÐÂÔöÁËʹÓÃDGA½øÐÐC2ͨѶµÄÖ°ÄÜ£¬ÕâʹµÃ·¢ÏÖ¶ñÒâÈí¼þµÄ»ù´¡ÉèÊ©²¢½«Æä²ð³ý±äµÃ¸üÄÑ¡£
https://www.zscaler.com/blogs/security-research/grandoreiro-banking-trojan-new-ttps-targeting-various-industry-verticals
3¡¢WPÍøÕ¾±»ÈëÇÖºóÏÔʾαÔìCloudflare¾¯±¨²¢×°ÖöñÒâÈí¼þ
8ÔÂ18ÈÕ£¬Sucuri³ÆWordPressÍøÕ¾±»ÈëÇÖºó»áÏÔʾαÔìµÄCloudflare DDoS±£»¤Ò³Ã棬À´·Ö·¢¶ñÒâÈí¼þ¡£¾ÝϤ£¬¹¥»÷Õß»áÈëÇÖÖ¸±êWordPressÍøÕ¾²¢Ö²ÈëÒ»¸ö»ìºÏµÄJavaScript payload£¬Ëü¿ÉÏÔʾһ¸öαÔìµÄCloudflare DDoS±£»¤½çÃæ¡£Ö®ºó£¬Ö¸±ê»á±»ÒªÇóÏÂÔØÎļþsecurity_install.iso£¬Æä±»ÃèÊöÎªÈÆ¹ýDDoSÑéÖ¤ËùÐèµÄ¹¤¾ß¡£´ò¿ª¸ÃÎļþ»á¿´µ½security_install.exe£¬Ö´ÐиÃEXEÎļþ½«×°ÖöñÒâÈí¼þNetSupport RATºÍRaccoon Stealer¡£
https://www.bleepingcomputer.com/news/security/wordpress-sites-hacked-with-fake-cloudflare-ddos-alerts-pushing-malware/
4¡¢Proofpoint·¢ÏÖTA558¹¥»÷À¶¡ÃÀÖ޾ƵêºÍÓÎÀÀÐÐÒµ
ProofpointÔÚ8ÔÂ18ÈÕ°ä²¼Á˹ØÓÚºÚ¿ÍÍÅ»ïTA558µÄ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£TA558¿ÉÄÜÊÇÒ»¸ö³öÓÚ¾¼Ã¶¯»úµÄÓ×ÐͺڿÍÍŻ×Ô2018ÄêÒÔÀ´ÆðÍ·»îÔ¾£¬ÖØÒªÕë¶ÔλÓÚÀ¶¡ÃÀÖÞµØÓòµÄ¾ÆµêºÍÓÎÀÀÐÐÒµ£¬ÓÐʱҲ»áÕë¶ÔÎ÷Å·ºÍ±±ÃÀµØÓò¡£×î½üµÄ»î¶¯ÖУ¬¹¥»÷Õß´ÓÀûÓÃÔ̺¬ºêµÄMicrosoft Office¸½¼þ£¬×ª¶øÊ¹ÓÃURLºÍISOÎļþÀ´ÊµÏÖ³õʼϰȾ£¬´Ë¾Ù¿ÉÄÜÊǶÔ΢Èí¾ö¶¨Ä¬ÈÏ×èÖ¹´ÓÍøÂçÏÂÔØÎļþÖеĺê×ö³öµÄ»ØÓ¦¡£
https://www.proofpoint.com/us/blog/threat-insight/reservations-requested-ta558-targets-hospitality-and-travel
5¡¢°®É³ÄáÑǵ±¾ÖÐû³ÆÒÑ×èÖ¹KillnetÍÅ»ï¶ÔÆäµÄDDoS¹¥»÷
¾Ý8ÔÂ19ÈÕ±¨Â·£¬°®É³ÄáÑǵ±¾ÖÐû³Æ×Ô2007ÄêÒÔÀ´×îÑϳÁµÄDDoS¹¥»÷¡£Õâ´Î¹¥»÷¼ÈÕë¶Ô¹«¹²»ú¹¹£¬Ò²Õë¶Ô˽Ӫ¹«Ë¾£¬ºÚ¿Í×éÖ¯KillnetÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü¡£´Ë±í£¬µÐÔÖÊ×ϯÐÅÏ¢¹Ù±ç²µÁ˸Ã×éÖ¯¹ØÓÚ200¶à¸öÍøÕ¾Òѱ»²é·âµÄ˵·¨£¬²¢°µÊ¾E-EstoniaÒÑÆô¶¯²¢ÔËÐУ¬·þÎñûÓÐÖжϡ£°®É³ÄáÑÇÍÆËã»úÓ¦¼±ÏìÓ¦Ó××éй©£¬Ô̺¬¾¯Ô±ºÍµ±¾ÖÔÚÄڵĴ¦Ëùµ±¾ÖµÄÍøÕ¾ÒÔ¼°Ò»¼ÒÎïÁ÷¹«Ë¾Ôâµ½¹¥»÷¡£
https://securityaffairs.co/wordpress/134560/cyber-warfare-2/estonia-blocked-cyberattacks-killnet.html
6¡¢MicrosoftÅû¶ChromeOS×é¼þÖÐÄÚ´æ°Ü»µ·ì϶µÄϸ½Ú
MicrosoftÔÚ8ÔÂ19ÈÕ°ä²¼Á˹ØÓÚChromeOS×é¼þÖÐÄÚ´æ°Ü»µ·ì϶µÄ¼¼Êõ·ÖÎö»ã±¨¡£¸Ã·ì϶׷×ÙΪCVE-2022-2587£¬CVSSÆÀ·ÖΪ9.8£¬¿É±»ÓÃÀ´Ö´ÐÐDoS£¬»òÕßÔÚ¼«¶ËÇé¿öÏÂÖ´ÐÐÔ¶³Ì´úÂë¡£¸Ã·ì϶´æÔÚÓÚGoogle ChromeÒôƵ·þÎñÆ÷£¬¿É±»Ô¶³Ì¹¥»÷Õßͨ¹ýÌØÔìµÄÒôƵԪÊý¾ÝÀûÓá£Ä¿Ç°£¬¸Ã·ì϶Òѱ»½¨¸´£¬ÉÐδ±»ÔÚÒ°ÀûÓá£
https://www.microsoft.com/security/blog/2022/08/19/uncovering-a-chromeos-remote-memory-corruption-vulnerability/


¾©¹«Íø°²±¸11010802024551ºÅ