Kaspersky·¢Ã÷¶à¸ö¶ÌÖÜÆÚµÄÌØ¹¤»î¶¯Õë¶Ô¹¤¿ØÐÐÒµ

Ðû²¼Ê±¼ä 2022-01-25

Kaspersky·¢Ã÷¶à¸ö¶ÌÖÜÆÚµÄÌØ¹¤»î¶¯Õë¶Ô¹¤¿ØÐÐÒµ


1ÔÂ9ÈÕ£¬£¬£¬£¬£¬ £¬£¬KasperskyÐû²¼±¨¸æÅû¶¶à¸öÕë¶Ô¹¤¿ØÐÐÒµµÄÌØ¹¤»î¶¯¡£¡£¡£¡£ ¡£¡£¡£ÕâЩ»î¶¯Ê¹ÓÃÏֳɵÄÌØ¹¤Èí¼þ¹¤¾ß£¬£¬£¬£¬£¬ £¬£¬°üÀ¨AgentTesla¡¢HawkEye¡¢Noon/Formbook¡¢Masslogger¡¢Snake KeyloggerºÍLokibotµÈ¡£¡£¡£¡£ ¡£¡£¡£Kaspersky³ÆÕâЩ¹¥»÷³ÆÎª¡°anomalous¡±£¬£¬£¬£¬£¬ £¬£¬ÓÉÓÚÓë¹Å°åµÄÌØ¹¤¹¥»÷Ïà±È£¬£¬£¬£¬£¬ £¬£¬ËüÃǵÄÉúÃüÖÜÆÚºÜÊǶÌÔÝ£¬£¬£¬£¬£¬ £¬£¬´ó´ó¶¼´ËÀ๥»÷»áÒ»Á¬ÊýÔÂÉõÖÁÊýÄ꣬£¬£¬£¬£¬ £¬£¬¶øÕâЩ»î¶¯Ô¼Îª25Ìì¡£¡£¡£¡£ ¡£¡£¡£


https://securelist.com/hunt-for-corporate-credentials-on-ics-networks/105545/


McAfeeÐÞ¸´AgentÈí¼þÖеÄÌáȨÎó²îCVE-2022-0166


ýÌå1ÔÂ21ÈÕ±¨µÀ£¬£¬£¬£¬£¬ £¬£¬McAfee£¨ÏÖΪTrellix£©ÒÑÐÞ¸´ÌáȨÎó²î£¨CVE-2022-0166£©¡£¡£¡£¡£ ¡£¡£¡£¸ÃÎó²îλÓÚWindows°æ±¾µÄMcAfee AgentÈí¼þÖУ¬£¬£¬£¬£¬ £¬£¬Èí¼þÔÚ¹¹½¨Àú³ÌÖÐʹÓÃopenssl.cnf½«OPENSSLDIR±äÁ¿Ö¸¶¨Îª×°ÖÃĿ¼ÖеÄ×ÓĿ¼£¬£¬£¬£¬£¬ £¬£¬µÍȨÏÞÓû§¿ÉÒÔʹÓøÃÎó²î½¨Éè×ÓĿ¼²¢Ê¹ÓÃSystemȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾ÓÚ1ÔÂ18ÈÕÐû²¼ÁËMcAfee Agent 5.7.5ÐÞ¸´´ËÎó²î¡£¡£¡£¡£ ¡£¡£¡£


https://securityaffairs.co/wordpress/127044/security/mcafee-agent-code-execution-flaw.html


RustÐÞ¸´¿Éɾ³ýÎļþºÍĿ¼µÄÎó²îCVE-2022-21658


RustÇå¾²ÏìÓ¦ÊÂÇé×é(WG)ÔÚ1ÔÂ20ÈÕÐû²¼µÄͨ¸æÖÐÌåÏÖ£¬£¬£¬£¬£¬ £¬£¬Æä²úÆ·±£´æÒ»¸öÑÏÖØµÄÎó²î¡£¡£¡£¡£ ¡£¡£¡£Îó²î±»×·×ÙΪCVE-2022-21658£¬£¬£¬£¬£¬ £¬£¬CVSSÆÀ·ÖΪ7.3£¬£¬£¬£¬£¬ £¬£¬Ó°ÏìÁËRust 1.0.0µ½Rust 1.58.0°æ±¾¡£¡£¡£¡£ ¡£¡£¡£¸ÃÎó²îÔ´ÓÚ±ê×¼¿âº¯Êýstd::fs::remove_dir_allÈÝÒ×Êܵ½ÆôÓ÷ûºÅÁ´½Ó¸ú×ٵľºÕùÌõ¼þµÄÓ°Ï죬£¬£¬£¬£¬ £¬£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÓÕÊ¹ÌØÈ¨³ÌÐòɾ³ýÆäÎÞ·¨»á¼û»òɾ³ýµÄÎļþºÍĿ¼¡£¡£¡£¡£ ¡£¡£¡£¸ÃÍŶÓÔÚÉÏÖÜÐû²¼µÄRust 1.58.1°æ±¾ÖÐÐÞ¸´ÁË´ËÎó²î¡£¡£¡£¡£ ¡£¡£¡£


https://thehackernews.com/2022/01/high-severity-rust-programming-bug.html


Fortinet·¢Ã÷ð³äº½Ô˹«Ë¾·Ö·¢STRRATµÄ´¹Âڻ


FortinetÔÚ1ÔÂ20ÈÕ¹ûÕæÁËÖ¼ÔÚ·Ö·¢Ô¶³Ì»á¼ûľÂíSTRRATµÄ´¹Âڻ¡£¡£¡£¡£ ¡£¡£¡£´Ë´Î»î¶¯Ã°³äº½Ô˹«Ë¾ÂíÊ¿»ùº½Ô˹«Ë¾£¨Maersk Shipping£©£¬£¬£¬£¬£¬ £¬£¬Ê¹ÓÃÒÔ×°ÔË¡¢½»»õÈÕÆÚ¸ü¸Ä»ò¹ºÖÃ֪ͨµÄ´¹ÂÚÓʼþ£¬£¬£¬£¬£¬ £¬£¬µ±Ä¿µÄ·­¿ªÓʼþÖеĸ½¼þºó¾Í»áÔËÐжñÒâºê²¢×°ÖÃSTRRAT¡£¡£¡£¡£ ¡£¡£¡£STRRAT¿ÉÒÔÇÔȡĿµÄµÄÐÅÏ¢£¬£¬£¬£¬£¬ £¬£¬»òÕß¾ÙÐмٵÄÀÕË÷¹¥»÷£¨ÔÚ¹¥»÷ÖÐûÓÐÎļþ±»¼ÓÃÜ£©¡£¡£¡£¡£ ¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬ £¬£¬¹¥»÷ÕßʹÓÃÁËAllatori¹¤¾ß¶ÔÈí¼þ°ü¾ÙÐÐÁË»ìÏý£¬£¬£¬£¬£¬ £¬£¬ÒÔÈÆ¹ýÇå¾²²úÆ·µÄ¼ì²â¡£¡£¡£¡£ ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/phishing-impersonates-shipping-giant-maersk-to-push-strrat-malware/


Check PointÐû²¼2021ÄêÍøÂç¹¥»÷»î¶¯µÄ»ØÊ×±¨¸æ


1ÔÂ21ÈÕ£¬£¬£¬£¬£¬ £¬£¬Check PointÐû²¼ÁË2021ÄêÍøÂç¹¥»÷»î¶¯µÄ»ØÊ×±¨¸æ¡£¡£¡£¡£ ¡£¡£¡£×ÜÌå¶øÑÔ£¬£¬£¬£¬£¬ £¬£¬Óë2020ÄêÏà±È£¬£¬£¬£¬£¬ £¬£¬2021Äê×é֯ÿÖÜÔâÊܵĹ¥»÷´ÎÊýÔöÌíÁË50%¡£¡£¡£¡£ ¡£¡£¡£Õë¶ÔTOP 16ÐÐÒµµÄ¹¥»÷ƽ¾ùÔöÌíÁË55%£¬£¬£¬£¬£¬ £¬£¬ÆäÖнÌÓýºÍÑо¿²¿·ÖÊÇÊܹ¥»÷×î¶àµÄÐÐÒµ£¬£¬£¬£¬£¬ £¬£¬Æ½¾ùÿÖÜÔâµ½1605´Î¹¥»÷£¨ÔöÌí75%£©£¬£¬£¬£¬£¬ £¬£¬Æä´ÎΪÕþ¸®ºÍ¾ü¶Ó£¨1136´Î£¬£¬£¬£¬£¬ £¬£¬ÔöÌí47%£©ÒÔ¼°Í¨Ñ¶ÐÐÒµ£¨1079´Î£¬£¬£¬£¬£¬ £¬£¬ÔöÌí51%£©£»£»£» £»£»£»Õë¶ÔÈí¼þ¹©Ó¦É̹¥»÷´ÎÊýµÄÔö·ù×î´ó£¬£¬£¬£¬£¬ £¬£¬Í¬±ÈÔöÌíÁË146%¡£¡£¡£¡£ ¡£¡£¡£


https://blog.checkpoint.com/2022/01/21/2022-security-report-software-vendors-saw-146-increase-in-cyber-attacks-in-2021-marking-largest-year-on-year-growth/


Cleafy½üÆÚ·¢Ã÷Android¶ñÒâÈí¼þBRATAµÄбäÌå


¾ÝýÌå1ÔÂ24ÈÕ±¨µÀ£¬£¬£¬£¬£¬ £¬£¬Cleafy³ÆAndroid¶ñÒâÈí¼þBRATAÔÚÆäбäÌåÖÐÌí¼Ó¶à¸ö¹¦Ð§¡£¡£¡£¡£ ¡£¡£¡£BRATAÊÇÒ»¿îÖ÷ÒªÕë¶Ô°ÍÎ÷Óû§µÄAndroid RAT£¬£¬£¬£¬£¬ £¬£¬ÔÚ2019ÄêÊ״α»Kaspersky·¢Ã÷¡£¡£¡£¡£ ¡£¡£¡£¸Ã±äÌåÏÖÔÚÖ÷ÒªÕë¶ÔÓ¢¹ú¡¢²¨À¼¡¢Òâ´óÀû¡¢Î÷°àÑÀ¡¢ÖйúºÍÀ­¶¡ÃÀÖ޵ĵç×ÓÒøÐеÄÓû§£¬£¬£¬£¬£¬ £¬£¬ÐÂÔöÁ˼üÅ̼ͼ¹¦Ð§¡¢GPS ¸ú×Ù¹¦Ð§£¬£¬£¬£¬£¬ £¬£¬¿ÉÒÔÖ´Ðгö³§ÖØÖÃÒÔɨ³ýËùÓжñÒâ»î¶¯µÄºÛ¼££¬£¬£¬£¬£¬ £¬£¬»¹Ìí¼ÓÁË¿ÉÒÔÖ§³ÖHTTPºÍWebSocketsµÄÐÂC2ͨѶͨµÀ¡£¡£¡£¡£ ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/android-malware-brata-wipes-your-device-after-stealing-data/


Çå¾²¹¤¾ß


CFRipper


»ùÓÚ Python µÄ¿âºÍ CLI Çå¾²ÆÊÎöÆ÷£¬£¬£¬£¬£¬ £¬£¬ÓÃ×÷ AWS CloudFormation Ç徲ɨÃèºÍÉ󼯹¤¾ß¡£¡£¡£¡£ ¡£¡£¡£


https://github.com/Skyscanner/cfripper


TokenUniverse


ʹÓûá¼ûÁîÅÆºÍ Windows Çå¾²Õ½ÂԵĸ߼¶¹¤¾ß¡£¡£¡£¡£ ¡£¡£¡£


https://github.com/diversenok/TokenUniverse


Registry Spy


Ãâ·ÑµÄ¿ªÔ´¿çƽ̨ Windows ×¢²á±íÉó²éÆ÷¡£¡£¡£¡£ ¡£¡£¡£


https://github.com/andyjsmith/Registry-Spy


SysmonSimulator


ÓÃCÓïÑÔ½¨ÉèµÄ¿ªÔ´ Windows ÊÂÎñÄ£ÄâÊÊÓóÌÐò£¬£¬£¬£¬£¬ £¬£¬¿ÉÓÃÓÚÄ£Äâ´ó´ó¶¼Ê¹Óà WINAPI µÄ¹¥»÷¡£¡£¡£¡£ ¡£¡£¡£


https://github.com/ScarredMonk/SysmonSimulator


HazProne


ÔÆÉøÍ¸²âÊÔ¿ò¼Ü£¬£¬£¬£¬£¬ £¬£¬ÓÃÓÚÉøÍ¸²âÊÔÎó²î¡£¡£¡£¡£ ¡£¡£¡£


https://github.com/stafordtituss/HazProne


Çå¾²ÆÊÎö


΢ÈíĬÈϽûÓÃExcel 4.0ºêÀ´×èÖ¹¶ñÒâÈí¼þ


https://www.bleepingcomputer.com/news/microsoft/microsoft-disables-excel-40-macros-by-default-to-block-malware/


SonicWall ΪÏÝÈëÖØÆôÑ­»·µÄ·À»ðǽ¹²ÏíÌṩÔÝʱÐÞ¸´


https://www.bleepingcomputer.com/news/technology/sonicwall-shares-temp-fix-for-firewalls-stuck-in-reboot-loop/


΢ÈíÁгöÁËÒª×èÖ¹µÄ Windows 10 ×éÕ½ÂÔ


https://www.bleepingcomputer.com/news/microsoft/microsoft-lists-the-windows-10-group-policies-to-avoid/


ProtonMail ÒýÈëÁËÒ»¸öеĵç×ÓÓʼþ¸ú×ÙÆ÷×èֹϵͳ


https://www.bleepingcomputer.com/news/security/protonmail-introduces-a-new-email-tracker-blocking-system/


F5 ÐÞ¸´ÁË BIG-IP¡¢BIG-IQ ºÍ NGINX ²úÆ·ÖÐµÄ 25 ¸öȱÏÝ


https://securityaffairs.co/wordpress/127097/security/f5-big-ip-flaws.html