Ñо¿ÍŶӷ¢Ã÷ʹÓÃÀ¬»øÓʼþ·Ö·¢¶ñÒâÈí¼þMETAµÄ»î¶¯
Ðû²¼Ê±¼ä 2022-04-13Ñо¿ÍŶӷ¢Ã÷ʹÓÃÀ¬»øÓʼþ·Ö·¢¶ñÒâÈí¼þMETAµÄ»î¶¯
¾ÝýÌå4ÔÂ10ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬ÐÂÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þMETAÕýÔÚͨ¹ýÀ¬»øÓʼþ»î¶¯·Ö·¢¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þʹÓôøÓкêµÄExcelµç×Ó±í¸ñѬȾĿµÄ£¬£¬£¬£¬£¬£¬£¬ÒÔÐéαµÄתÕË֪ͨΪÓÕ¶ü£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÇÔÈ¡´æ´¢ÔÚChrome¡¢Edge¡¢FirefoxÒÔ¼°¼ÓÃÜÇ®±ÒÇ®°üÖеÄÃÜÂë¡£¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬META¿Éͨ¹ýPowerShell¸Ä¶¯Windows DefenderÒÔ½«.exeÎļþɨ³ýÔÚɨÃè¹æÄ£Ö®Í⣬£¬£¬£¬£¬£¬£¬ÒÔÈÆ¹ýÇå¾²¼ì²â¡£¡£¡£¡£¡£¡£¡£¡£META¡¢Mars StealerºÍBlackGuardÊÇÐÂÐÍÐÅÏ¢ÇÔÈ¡Èí¼þÖ®Ò»£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÏ£ÍûʹÓÃRaccoon StealerÍ˳öÊг¡µÄʱ»ú£¬£¬£¬£¬£¬£¬£¬Ê¹Æä³ÉΪ¼ÌÈÎÕß¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-meta-information-stealer-distributed-in-malspam-campaign/
NB65ÍÅ»ï»ùÓÚConti¿ª·¢µÄÐÂÀÕË÷Èí¼þÒÔ¶íÂÞ˹ΪĿµÄ
ýÌå4ÔÂ10ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÍÅ»ïNB65ʹÓûùÓÚConti¿ª·¢µÄÐÂÀÕË÷Èí¼þ¹¥»÷¶íÂÞ˹¡£¡£¡£¡£¡£¡£¡£¡£ÔÚÒÑÍùµÄÒ»¸öÔÂÀ£¬£¬£¬£¬£¬£¬NB65¹¥»÷Á˶íÂÞ˹µÄ¶à¸ö×éÖ¯£¬£¬£¬£¬£¬£¬£¬°üÀ¨ÎļþÖÎÀíÔËÓªÉÌTensor¡¢º½Ìì¾ÖRoscosmosºÍ¹ã²¥µçÊǪ́VGTRK¡£¡£¡£¡£¡£¡£¡£¡£×Ô3ÔÂβÒÔÀ´¹¥»÷ÕßתÏòʹÓÃÒ»ÖÖÐÂÕ½ÂÔ£¬£¬£¬£¬£¬£¬£¬ÆäʹÓÃй¶µÄContiÀÕË÷Èí¼þµÄÔ´´úÂ뽨ÉèÁË×Ô¼ºµÄÀÕË÷Èí¼þ¡£¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÉÏÖÜÄ©ÔÚVirusTotal·¢Ã÷Á˸ÃÑù±¾£¬£¬£¬£¬£¬£¬£¬²¢È·¶¨ËüÓëContiÑù±¾66%µÄ´úÂëÏàͬ¡£¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/130051/hacktivism/nb65-modified-version-conti-ransomware.html
Ñо¿Ö°Ô±·¢Ã÷Ê׸öÕë¶ÔAWS LambdaµÄ¶ñÒâÈí¼þDenonia
¾Ý4ÔÂ7ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬Cado Security·¢Ã÷ÁËÊ׸öÕë¶ÔAWS LambdaÔÆÇéÐεĶñÒâÈí¼þDenonia¡£¡£¡£¡£¡£¡£¡£¡£AWS LambdaÊÇÒ»¸öÎÞЧÀÍÆ÷ÅÌËãÆ½Ì¨£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚÔËÐÐÀ´×ÔÊý°Ù¸öAWS SaaSÓ¦ÓóÌÐòµÄ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£DenoniaÊÇÒ»¸ö»ùÓÚGoµÄ·â×°³ÌÐò£¬£¬£¬£¬£¬£¬£¬Òѱ»ÓÃÓÚ¹¥»÷»î¶¯ÖУ¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚ°²ÅÅÒ»¸ö×Ô½ç˵µÄXMRig¼ÓÃܿ󹤡£¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷ÓÚ1Ô·ÝÉÏ´«µ½VirusTotalµÄÑù±¾£¬£¬£¬£¬£¬£¬£¬ËµÃ÷¹¥»÷ÖÁÉÙÒ»Á¬Á˼¸¸öÔ¡£¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚѬȾǰÑÔÉв»Ã÷È·£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÍƶϹ¥»÷Õß¿ÉÄÜʹÓÃÁËй¶µÄAWSÃÜÔ¿¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-malware-targets-serverless-aws-lambda-with-cryptominers/
ÃÀ¹úSuperCareÔâδ¾ÊÚȨ»á¼ûй¶Áè¼Ý30ÍòÈ˵ÄÐÅÏ¢
ýÌå4ÔÂ11Èճƣ¬£¬£¬£¬£¬£¬£¬ÃÀ¹ú¼ÓÀû¸£ÄáÑǵÄSuperCare Healthй¶318379È˵ÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñÔÚ2021Äê7ÔÂ27ÈÕ±»·¢Ã÷£¬£¬£¬£¬£¬£¬£¬ÆäʱÆä¶à¸öϵͳÉϼì²âµ½Î´¾ÊÚȨµÄ»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£ËæºóµÄÊÓ²ìÏÔʾ£¬£¬£¬£¬£¬£¬£¬²¿·ÖϵͳÔÚ7ÔÂ23ÈÕÖÁ7ÔÂ27ÈÕÒѱ»»á¼û¡£¡£¡£¡£¡£¡£¡£¡£½ñÄê2ÔÂ4ÈÕ£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾È·¶¨Ð¹Â¶ÐÅÏ¢°üÀ¨»¼ÕßÐÕÃû¡¢µØµã¡¢²¡ÀúºÅ¡¢Ò½ÔºÕ˺š¢¿µ½¡ºÍÀíÅâÏà¹ØÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¡£¡£SuperCareÓÚ3ÔÂ25ÈÕÏòÊÜÓ°ÏìµÄСÎÒ˽¼Ò·¢³öÁ˸ÃÊÂÎñµÄ֪ͨ£¬£¬£¬£¬£¬£¬£¬²¢ÌåÏÖй¶µÄÊý¾ÝÏÖÔÚ²¢Î´±»ÀÄÓᣡ£¡£¡£¡£¡£¡£¡£
https://www.infosecurity-magazine.com/news/supercare-data-breach-300000/
AvastÐû²¼¹ØÓÚеÄParrot TDS·Ö·¢RATµÄÆÊÎö±¨¸æ
4ÔÂ7ÈÕ£¬£¬£¬£¬£¬£¬£¬AvastÐû²¼¹ØÓÚÒ»ÖÖÃûΪParrotµÄÐÂÐͽ»Í¨Ö¸»Óϵͳ(TDS)µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£¡£ËüÏÖÔÚÕý±»ÓÃÓÚ¹¥»÷»î¶¯FakeUpdate£¬£¬£¬£¬£¬£¬£¬¸Ã»î¶¯Í¨¹ýÐéαµÄä¯ÀÀÆ÷¸üÐÂ֪ͨ·Ö·¢RAT¡£¡£¡£¡£¡£¡£¡£¡£Parrot TDSÒÑѬȾÍйÜÁË16500¶à¸öÍøÕ¾µÄ¶à¸öWebЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬É漰СÎÒ˽¼Ò²©¿ÍÍøÕ¾¡¢´óÑ§ÍøÕ¾ºÍµØ·½Õþ¸®ÍøÕ¾µÈ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯ËƺõÓÚ2022Äê2ÔÂ×îÏÈ£¬£¬£¬£¬£¬£¬£¬µ«Parrot×îÔç¿É×·Ëݵ½2021Äê10Ô¡£¡£¡£¡£¡£¡£¡£¡£Parrot TDS ÓëÆäËüTDSÖ÷񻂿±ðÖ®Ò»ÊÇËüµÄÆÕ±éÐÔ£¬£¬£¬£¬£¬£¬£¬±»Ñ¬È¾ÍøÕ¾¼äËÆºõûÓÐÈκÎÅäºÏµã¡£¡£¡£¡£¡£¡£¡£¡£
https://decoded.avast.io/janrubin/parrot-tds-takes-over-web-servers-and-threatens-millions/
KasperskyÐû²¼¹ØÓÚBlackCatÍÅ»ïµÄÊÖÒÕÆÊÎö±¨¸æ
KasperskÓÚ4ÔÂ7ÈÕÐû²¼Á˹ØÓÚºÚ¿ÍÍÅ»ïBlackCatµÄÊÖÒÕÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£¡£BlackCatÒ²³ÆALPHV£¬£¬£¬£¬£¬£¬£¬ÓÚ2021Äê12Ô³õ×îÏÈ»îÔ¾¡£¡£¡£¡£¡£¡£¡£¡£ÓëÆäËüÀÕË÷Èí¼þ×î´óÇø±ðÖ®Ò»ÊÇBlackCatÊÇÓÃRust±àдµÄ£¬£¬£¬£¬£¬£¬£¬ËûÃǵĻù´¡ÉèÊ©ÍøÕ¾µÄ¿ª·¢·½·¨Ò²ÓëÆäËüÍÅ»ï²î±ð£¬£¬£¬£¬£¬£¬£¬WindowsºÍLinuxÑù±¾¾ùÓС£¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬BlackCatʹÓÃÁË×Ô½ç˵¹¤¾ßFendrµÄ±äÌ壬£¬£¬£¬£¬£¬£¬Ö¤ÊµÆäÓëBlackMatterÓйØÁª¡£¡£¡£¡£¡£¡£¡£¡£±¨¸æ»¹ÆÊÎöÁËBlackCatÖ´Ðй¥»÷ʱµÄÊÖÒÕϸ½Ú¡£¡£¡£¡£¡£¡£¡£¡£
https://securelist.com/a-bad-luck-blackcat/106254/
Çå¾²¹¤¾ß
vmlinux-to-elf
´Ë¹¤¾ßÔÊÐí´Ó vmlinux/vmlinuz/bzImage/zImage ÄÚºËÓ³Ïñ»ñÈ¡ÍêÈ«¿ÉÆÊÎöµÄ .ELF Îļþ¡£¡£¡£¡£¡£¡£¡£¡£
https://github.com/marin-m/vmlinux-to-elf
DumpSMBShare
´Ó Windows SMB ¹²ÏíÔ¶³Ìת´¢ÎļþºÍÎļþ¼Ð¡£¡£¡£¡£¡£¡£¡£¡£
https://github.com/p0dalirius/DumpSMBShare
Skanuvaty
ΣÏյĿìËÙ dns/ÍøÂç/¶Ë¿ÚɨÃèÒÇ£¬£¬£¬£¬£¬£¬£¬¶àºÏÒ»¡£¡£¡£¡£¡£¡£¡£¡£
https://github.com/Esc4iCEscEsc/skanuvaty
Çå¾²ÆÊÎö
Microsoft µÄРAutopatch ¹¦Ð§¿É×ÊÖúÆóÒµ¼á³Öϵͳ¸üÐÂ
https://thehackernews.com/2022/04/microsofts-new-autopatch-feature-to.html
Windows 11 µÄй¦Ð§
https://www.bleepingcomputer.com/news/microsoft/here-are-the-new-features-coming-to-windows-11/
¹È¸èͨ¹ýеĿª·¢Õ½ÂÔ¸ü¸ÄÌá¸ß Android µÄÇå¾²ÐÔ
https://www.bleepingcomputer.com/news/security/google-boosts-android-security-with-new-set-of-dev-policy-changes/
GitHub Action ¿É±ÜÃâÔÚ´úÂëÖÐÌí¼ÓÒÑÖªÎó²î
https://securityaffairs.co/wordpress/130067/security/dependency-review-github-action.html
CVE-2022-22292 ¿ÉÓÃÓÚÈëÇÖÈýÐÇ Android ×°±¸
https://securityaffairs.co/wordpress/129942/hacking/cve-2022-22292-hack-samsung-android-devices.html
Ð嵀 SolarMarker (Jupyter) »î¶¯
https://unit42.paloaltonetworks.com/solarmarker-malware/


¾©¹«Íø°²±¸11010802024551ºÅ