΢Èíµ÷²éDefender½«ºÏ·¨URL¼ø±ðΪ¶ñÒâÁ´½ÓµÄÎÊÌâ

°ä²¼¹¦·ò 2023-03-31

1¡¢Î¢Èíµ÷²éDefender½«ºÏ·¨URL¼ø±ðΪ¶ñÒâÁ´½ÓµÄÎÊÌâ


¾ÝýÌå3ÔÂ29ÈÕ±¨Â· £¬Î¢ÈíÔÚµ÷²éºÏ·¨URLÁ´½Ó±»Microsoft Defender·þÎñ¼ø±ðΪ¶ñÒâÁ´½ÓµÄÎÊÌâ¡£×ÔÎÊÌâ³öÏÖµÄÎå¸ö¶àÓ×ʱÒÔÀ´ £¬Ò»Ð©¿Í»§ÒѾ­ÊÕµ½ÁËÊýÊ®·âÖÒ¸æÓʼþ¡£Î¢Èí°µÊ¾ £¬Ö»¹Ü´æÔÚÎ󱨾¯±¨ £¬µ«Óû§ÒÀÈ»¿ÉÄܽӼûºÏ·¨URL £¬ÆäÒ²ÔÚµ÷²é·þÎñµÄÄÄÒ»²¿ÃÅ·¸´í½«ºÏ·¨µÄURL¼ø±ðΪ¶ñÒâ¡£3ÔÂ29ÈÕ15:08 EDT¸üÐÂÏÔʾ £¬Îó±¨ÎÊÌâÒÑͨ¹ý¸´Ô­×î½ü¶ÔSafeLinksÖ°Äܵĸüнâ¾ö¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-mistakenly-tagging-urls-as-malicious/


2¡¢×êÑÐÈËÔ±·¢ÏÖÀûÓÃľÂí»¯3CX×ÀÃæÀûÓõĹ©¸øÁ´¹¥»÷


ýÌå3ÔÂ29ÈÕ±¨Â·³Æ £¬×êÑÐÈËÔ±Åû¶ÁËÀûÓÃľÂí»¯3CX×ÀÃæÀûÓõĹ©¸øÁ´¹¥»÷¡£3CXÊÇÒ»¼ÒVoIP IPBXÈí¼þ¿ª·¢¹«Ë¾ £¬Æä3CX Phone System±»È«Çò³¬¹ý600000¼Ò¹«Ë¾Ê¹Óá£SentinelOneй© £¬Ä¾Âí»¯3CXDesktopAppÊǹ¥»÷Á´ÖеĵÚÒ»½×¶Î £¬Ëü´ÓGithubÖÐÌáÈ¡¸½¼ÓÁËbase64Êý¾ÝµÄICOÎļþ £¬²¢×îÖÕµ¼ÖµÚÈý½×¶ÎµÄÐÅÏ¢ÇÔÈ¡·¨Ê½DLL¡£3CX CEO Nick Galea°µÊ¾ £¬ÆäʹÓõÄÉÏÓοâÒѱ»Ï°È¾ £¬AndroidºÍiOS°æ±¾²»ÊÜÓ°Ïì¡£Ëû½¨ÒéËùÓÐЧ»§Ð¶ÔØ×ÀÃæÀûÓ÷¨Ê½ £¬×ª¶øÊ¹ÓÃPWA¿Í»§¶Ë¡£


https://www.bleepingcomputer.com/news/security/hackers-compromise-3cx-desktop-app-in-a-supply-chain-attack/


3¡¢GoogleÅû¶ÀûÓÃAndroidºÍiOSÖжà¸ö·ì϶µÄ¹¥»÷»î¶¯


3ÔÂ29ÈÕ £¬GoogleÅû¶ÁË×î½ü·¢ÏÖµÄÁ½¸ö¹¥»÷»î¶¯ £¬ÀûÓÃÁËAndroid¡¢iOSºÍChromeÖжà¸ö·ì϶¡£µÚÒ»¸ö»î¶¯ÓÚ2022Äê11Ô±»·¢ÏÖ £¬ÀûÓÃÁËiOS WebKit RCE·ì϶(CVE-2022-42856)ºÍChrome GPUɳÏäÈÆ¹ý·ì϶(CVE-2022-4135)µÈ £¬ÖØÒªÕë¶ÔÒâ´óÀû¡¢ÂíÀ´Î÷ÑǺ͹þÈø¿Ë˹̹¡£2022Äê12Ô £¬×êÑÐÈËÔ±·¢ÏÖÁ˵ڶþ¸ö»î¶¯ £¬ÀûÓÃÁËCVE-2022-4262ºÍCVE-2023-0266µÈ·ì϶ £¬Õë¶Ô×îа汾µÄÈýÐÇä¯ÀÀÆ÷¡£Ëü½«À´×Ô°¢À­²®½áºÏÇõ³¤¹ú(UAE)µÄÖ¸±ê³Á¶¨Ïòµ½Ã³Ò×¼äµýÈí¼þ¹©¸øÉÌVariston¿ª·¢µÄHeliconia¿ò¼ÜÒ»ÑùµÄµÇÂ½Ò³Ãæ £¬×îÖÕ×°ÖÃÒ»¸ö»ùÓÚC++µÄAndroid¼äµýÈí¼þÌ×¼þ¡£


https://blog.google/threat-analysis-group/spyware-vendors-use-0-days-and-n-days-against-popular-platforms/


4¡¢Èí¼þ¹©¸øÉÌNebuÒòй¶Լ200ÍòÓû§µÄÐÅÏ¢±»¸æ×´


3ÔÂ30ÈÕýÌ峯 £¬Ô¼200ÍòºÉÀ¼¹«ÃñµÄÊý¾Ý±»Ð¹Â¶ £¬É漰һЩʹÓÃNebuÈí¼þµÄÊг¡×êÑлú¹¹¡£ÆäÖÐÒ»¼Ò»ú¹¹ÏÖ½«¸ÃÈí¼þ¹©¸øÉ̸æÉÏ·¨Í¥ £¬Êг¡×êÑлú¹¹Blauwµ«Ô¸Í¨¹ý·¨ÔºÇ¿ÔìÒªÇóNebuÌṩ¸ü¶à¹ØÓÚй¶ÊÂÎñµÄÐÅÏ¢ £¬Ô̺¬ÄÄЩÊý¾ÝÒѱ»Ð¹Â¶ÒÔ¼°ÊÂÎñÊÇÈôºÎ²úÉú¡£¸ÃÊÂÎñÓ°ÏìÁËDe Vrienden van Amstel LIVE¡¢ºÉÀ¼¸ß¶û·ò½áºÏ»á£¨NGF£©¡¢ÔËÓªÉÌNSºÍ¹©¸øÉÌVodafoneZiggoµÈ¡£ºÉÀ¼Êý¾Ý±£»¤¾Ö£¨AP£©°µÊ¾ £¬²»ÅųýÓиü¶àµÄ¹«Ë¾ºÍ×éÖ¯Êܵ½Ó°Ïì¡£


https://www.nu.nl/tech/6257515/data-van-2-miljoen-nederlanders-gelekt-softwareleverancier-voor-rechter-gesleept.html


5¡¢Ó¡¶ÈÔìÒ©¹«Ë¾Sun PharmaceuticalsÔâµ½ÀÕË÷¹¥»÷


¾Ý3ÔÂ30ÈÕ±¨Â· £¬Ó¡¶È×î´óµÄÔìÒ©¹«Ë¾Sun Pharmaceuticalsй©ÆäÔâµ½ÀÕË÷¹¥»÷ £¬¹«Ë¾Êý¾ÝºÍÓ×ÎÒÐÅÏ¢±»µÁ¡£ÕâÊÇÈ«ÇòµÚËÄ´óÌØÖÖ·ÂÔìÒ©¹«Ë¾ £¬2022ÄêÊÕÈë50ÒÚÃÀÔª¡£¸Ã¹«Ë¾°µÊ¾ £¬Ò»¸öÀÕË÷ÍÅ»ïÒÑÐû³Æ¶ÔÕâÆðÊÂÎñÕÆ¹Ü £¬ËüûÓÐй©¸ÃÍÅ»ïµÄÃû×Ö¡£µ«ÊÇ £¬ÀÕË÷ÍÅ»ïBlack CatÓÚ3ÔÂ24ÈÕÔÚÆäÍøÕ¾ÉÏÁгöÁ˸ù«Ë¾¡£¸Ã¹«Ë¾°µÊ¾ £¬×÷ΪÏìÓ¦´ëÊ©Æä¸ôÀëÁËÍøÂç²¢Æô¶¯Á˸´Ô­·¨Ê½ £¬Òò¶ø¹«Ë¾µÄÒµÎñÔËÓªÊܵ½ÁËÓ°Ïì¡£


https://therecord.media/sun-pharma-india-ransomware-attack


6¡¢Kaspersky°ä²¼2022ÄêµÄ½ðÈÚÐÐÒµÍþÐ²Ì¬ÊÆµÄ»ã±¨


3ÔÂ29ÈÕ £¬Kaspersky°ä²¼2022ÄêµÄ½ðÈÚÐÐÒµÍþÐ²Ì¬ÊÆµÄ»ã±¨¡£2022Äê £¬½ðÈÚ´¹µöÕ¼ËùÓд¹µö¹¥»÷µÄ36.3%¡£ÍøµêÆ·ÅÆÊÇ×îÊÜÓ­½ÓµÄµö¶ü £¬Õ¼´¹µöÍøÕ¾½Ó¼û´ÎÊýµÄ15.56%¡£ÊܽðÈÚ¶ñÒâÈí¼þÓ°ÏìµÄÓû§ÊýÁ¿±È2021Äê½µÂäÁË14%¡£RamnitÊÇ×îÊ¢ÐеĶñÒâÈí¼þ¼Ò×å £¬Õ¼±ÈΪ34.4% £¬Æä´ÎÊÇZbot £¬Õ¼16.2%¡£Ôâµ½ÒøÐжñÒâÈí¼þ¹¥»÷µÄAndroidÓû§ÊýÁ¿±ÈÈ¥ÄêÏ÷¼õÁË55%¡£Bian³¬¹ýAgent³ÉΪ×î»îÔ¾µÄÒÆ¶¯¶ñÒâÈí¼þ £¬Õ¼±È24.25% £¬¶øAgentΪ21.57%¡£


https://securelist.com/financial-cyberthreats-in-2022/109219/