Cado Security°µÊ¾½©Ê¬ÍøÂçAbcbotÓëXantheÓйØÁª

°ä²¼¹¦·ò 2022-01-12

΢Èí°ä²¼1ÔÂÖܶþ²¹¶¡£¬£¬ £¬£¬£¬£¬£¬£¬½¨¸´6¸ö0 dayÔÚÄÚµÄ97¸ö·ì϶


½ØÍ¼20220112121945.png


1ÔÂ11ÈÕ£¬£¬ £¬£¬£¬£¬£¬£¬Î¢Èí°ä²¼Á˽ñÄê¶ÈµÄÊ׸öÖܶþ²¹¶¡£¬£¬ £¬£¬£¬£¬£¬£¬×ܼƽ¨¸´97¸ö°²È«·ì϶£¨²»Ô̺¬29¸öMicrosoft Edge·ì϶£©¡£¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ×îÑϳÁµÄÊÇHTTPºÍ̸ջԶ³Ì´úÂëÖ´Ðзì϶£¨CVE-2022-21907£©£¬£¬ £¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.8£¬£¬ £¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËͶñÒâÊý¾Ý°üµ½Ö¸±ê·þÎñÆ÷À´ÀûÓø÷ì϶¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬ £¬£¬£¬£¬£¬£¬¸üл¹½¨¸´ÁË6¸ö0 day£¬£¬ £¬£¬£¬£¬£¬£¬Ô̺¬¿ªÔ´Curl¿âÖеÄRCE£¨CVE-2021-22947£©¡¢¿ªÔ´ Libarchive¿âÖеÄRCE£¨CVE-2021-36976£©ºÍ±¾µØWindows°²È«ÖÐÐÄAPIÖеÄRCE£¨CVE-2022-21874£©µÈ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-january-2022-patch-tuesday-fixes-6-zero-days-97-flaws/


EDPSÒªÇóÅ·ÖÞÐ̾¯×é֯ɾ³ýÓë·¸×ï»î¶¯Î޹صÄÓ×ÎÒÊý¾Ý


¾ÝýÌå1ÔÂ10ÈÕ±¨Â·£¬£¬ £¬£¬£¬£¬£¬£¬Å·ÃËÊý¾Ý±£»£»£»£» £»£»£»£»¤¼à¹Ü»ú¹¹EDPSºÅÁîÒªÇóÅ·ÖÞÐ̾¯×é֯ɾ³ýÓë·¸×ï»î¶¯Î޹صÄÓ×ÎÒÊý¾Ý¡£¡£¡£¡£¡£¡£µ±¾ÖÖ¸³ö£¬£¬ £¬£¬£¬£¬£¬£¬ÔÚûº±¼û¾ÝÖ÷Ìå·ÖÀàµÄÇé¿öÏ´洢´óÁ¿Êý¾Ý»á¶ÔÓ×Îҵĸù»ùÈ¨ÊÆ×é³É·çÏÕ£¬£¬ £¬£¬£¬£¬£¬£¬Ï൱ÓÚ´ó¹æÄ£¼à¶½¡£¡£¡£¡£¡£¡£¾Ý¡¶ÎÀ±¨¡·±¨Â·£¬£¬ £¬£¬£¬£¬£¬£¬»º´æÖÁÉÙÔ̺¬4 PB¡£¡£¡£¡£¡£¡£EDPS»¹»®¶¨ÁËÁù¸öÔµı£ÁôÆÚ£¬£¬ £¬£¬£¬£¬£¬£¬ÒÔ¹ýÂ˺ÍÌáÈ¡Ó×ÎÒÊý¾Ý£¬£¬ £¬£¬£¬£¬£¬£¬²¢´ÍÓë¸Ã¿ç¾³·¨ÂÉ»ú¹¹Ò»ÄêµÄ¹¦·òÀ´Éó²éÆäÊý¾Ý¿â¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2022/01/europol-ordered-to-delete-data-of.html


WordPress°ä²¼¸üУ¬£¬ £¬£¬£¬£¬£¬£¬½¨¸´SQL×¢ÈëµÈ4¸ö°²È«·ì϶


ýÌå1ÔÂ11ÈÕ±¨Â·£¬£¬ £¬£¬£¬£¬£¬£¬WordPress°ä²¼¸üУ¬£¬ £¬£¬£¬£¬£¬£¬×ܼƽ¨¸´4¸ö°²È«·ì϶¡£¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ·ì϶Ô̺¬SQL×¢Èë·ì϶£¨CVE-2022-21661£©£¬£¬ £¬£¬£¬£¬£¬£¬¿Éͨ¹ýʹÓÃWP-QueryµÄ²å¼þºÍÖ÷ÌâÀûÓ㻣»£»£» £»£»£»£»XSS·ì϶£¨CVE-2022-21662£©£¬£¬ £¬£¬£¬£¬£¬£¬¿ÉÓÃÀ´Ö²ÈëºóÃÅ»òͨ¹ýÀÄÓÃpost slugÀ´½ÚÔìÍøÕ¾£»£»£»£» £»£»£»£»SQL×¢Èë·ì϶£¨CVE-2022-21664£©£¬£¬ £¬£¬£¬£¬£¬£¬¿Éͨ¹ýWP_Meta_QueryÀûÓ㻣»£»£» £»£»£»£»¶ÔÏó×¢Èë·ì϶£¨CVE-2022-21663£©£¬£¬ £¬£¬£¬£¬£¬£¬±ØÒªÈëÇÖÖÎÀíÔ¹ØÊ»§ÄÜÁ¦ÀûÓᣡ£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/126556/security/wordpress-5-8-3.html


΢ÈíÅû¶macOS·ì϶powerdir(CVE-2021-30970)ϸ½Ú


1ÔÂ10ÈÕ£¬£¬ £¬£¬£¬£¬£¬£¬Î¢Èí°ä²¼¹ØÓÚmacOSÖеķì϶powerdir(CVE-2021-30970)µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£Î¢Èí°µÊ¾£¬£¬ £¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓø÷ìÏ¶ÈÆ¹ýͨÃ÷¡¢Ô޳ɺͽÚÔì(TCC)¼¼ÊõÀ´½Ó¼ûÓû§µÄÊý¾Ý¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖ£¬£¬ £¬£¬£¬£¬£¬£¬Äܹ»Í¨¹ý±à³ÌµÄ·½Ê½´Û¸ÄÖ¸±êÓû§Ö÷Ŀ¼²¢Ö²ÈëαTCCÊý¾Ý¿â£¬£¬ £¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ƾ¾ÝÓû§Êܱ£»£»£»£» £»£»£»£»¤µÄÓ×ÎÒÊý¾Ý²ß¶¯¹¥»÷¡£¡£¡£¡£¡£¡£Î¢ÈíÍŶÓÔÚ2021Äê7ÔÂ15ÈÕ½«·ì϶»ã±¨¸øApple¹«Ë¾£¬£¬ £¬£¬£¬£¬£¬£¬AppleÔÚ12ÔÂ13ÈÕ°ä²¼µÄ°²È«¸üÐÂÖн¨¸´¡£¡£¡£¡£¡£¡£


https://www.microsoft.com/security/blog/2022/01/10/new-macos-vulnerability-powerdir-could-lead-to-unauthorized-user-data-access/


Cado Security°µÊ¾½©Ê¬ÍøÂçAbcbotÓëXantheÓйØÁª


Cado SecurityÔÚ1ÔÂ10ÈÕ°ä²¼µÄ»ã±¨ÏÔʾ£¬£¬ £¬£¬£¬£¬£¬£¬½©Ê¬ÍøÂçAbcbotÓëXantheÓйØÁª¡£¡£¡£¡£¡£¡£AbcbotÔÚ2021Äê11Ô³õ´Î±»¹«¿ª£¬£¬ £¬£¬£¬£¬£¬£¬Æäʱ¹¥»÷ÁË»ªÎª¡¢ÌÚѶ¡¢°Ù¶ÈºÍ°¢ÀïÔÆµÈÔÆ·þÎñÌṩÉÌ¡£¡£¡£¡£¡£¡£µ«Í¨¹ýËùÓÐÒÑÖªµÄIoCs£¬£¬ £¬£¬£¬£¬£¬£¬Ô̺¬IPµØÖ·¡¢urlºÍÑù±¾£¬£¬ £¬£¬£¬£¬£¬£¬·¢ÏÖAbcbotµÄ´úÂëºÍ»ù´¡ÉèÊ©ÓëÒ»¸öÃûΪXantheµÄ¼ÓÃܽٳֶñÒâÈí¼þ¼Ò×åÓгÁµþ¡£¡£¡£¡£¡£¡£×êÑÐÍŶÓÒÔΪ¶þÕßÓÉͳһ¹¥»÷ÕßÕÆ¹Ü£¬£¬ £¬£¬£¬£¬£¬£¬²¢ÇÒËûÃÇÕý½«Ö¸±ê´ÓÍÚ¿ó×ªÒÆµ½Óë½©Ê¬ÍøÂçÓйصĻ¡£¡£¡£¡£¡£¡£


https://www.cadosecurity.com/abcbot-an-evolution-of-xanthe/


Check Point³Æ2021ÄêÍøÂç¹¥»÷»î¶¯Í¬±ÈÔö³¤50%


1ÔÂ10ÈÕ£¬£¬ £¬£¬£¬£¬£¬£¬Check Point research°ä²¼»ã±¨³Æ2021ÄêÍøÂç¹¥»÷»î¶¯Í¬±ÈÔö³¤50%¡£¡£¡£¡£¡£¡£»ã±¨»¹Ö¸³ö£¬£¬ £¬£¬£¬£¬£¬£¬ÔÚ2021ÄêµÚËÄʱ¶È£¬£¬ £¬£¬£¬£¬£¬£¬Ã¿¸ö×éÖ¯µÄÿÖÜÔâµ½µÄ¹¥»÷´ÎÊý´ïµ½º¹Çà×î¸ß£¬£¬ £¬£¬£¬£¬£¬£¬¾ùÔÈΪ925´Î¡£¡£¡£¡£¡£¡£2021Ä꣬£¬ £¬£¬£¬£¬£¬£¬½ÌÓýºÍ×êÑÐÐÐÒµÊÇÔâµ½¹¥»÷×î¶àµÄÐÐÒµ£¬£¬ £¬£¬£¬£¬£¬£¬¾ùÔÈÿÖÜ1605´Î¹¥»÷£¬£¬ £¬£¬£¬£¬£¬£¬Õâ±È2020ÄêÔö³¤ÁË75%¡£¡£¡£¡£¡£¡£°´µØÓò»®·Ö£¬£¬ £¬£¬£¬£¬£¬£¬·ÇÖÞÔâµ½¹¥»÷×î¶à£¬£¬ £¬£¬£¬£¬£¬£¬¾ùÔÈÿÖÜ1582´Î£¬£¬ £¬£¬£¬£¬£¬£¬±È2020ÄêÔö³¤13%£¬£¬ £¬£¬£¬£¬£¬£¬½ôËæÆäºóµÄÊÇÑÇÌ«µØÓò£¬£¬ £¬£¬£¬£¬£¬£¬Ã¿ÖÜÔâµ½1353´Î¹¥»÷£¨Ôö³¤25%£©¡£¡£¡£¡£¡£¡£


https://blog.checkpoint.com/2022/01/10/check-point-research-cyber-attacks-increased-50-year-over-year/


°²È«¹¤¾ß


Mortar 


Mortar¿ÉÄÜÈÆ¹ýÏÖ´ú·´²¡¶¾²úÆ·ºÍÏȽøµÄXDR½â¾ö¹æ»®£¬£¬ £¬£¬£¬£¬£¬£¬Ô̺¬Kaspersky¡¢ESETºÍMcafeeµÈ¡£¡£¡£¡£¡£¡£


https://www.kitploit.com/2022/01/mortar-evasion-technique-to-defeat-and.html


RecoverPy


¿ÉÓÃÀ´¸´Ô­±»¸²¸Ç»òɾ³ýµÄÊý¾Ý£¬£¬ £¬£¬£¬£¬£¬£¬Ä¿Ç°½öÔÚLinuxϵͳÉÏ¿ÉÓᣡ£¡£¡£¡£¡£


https://github.com/PabloLec/RecoverPy


°²È«·ÖÎö


Linux Mint 20.3 °ä²¼


Linux Mint °ä²¼ÁË 20.3 °æ£¬£¬ £¬£¬£¬£¬£¬£¬´úºÅΪ¡°Una¡±£¬£¬ £¬£¬£¬£¬£¬£¬×÷Ϊ³Ö¾ÃÖ§³Ö°æ±¾£¬£¬ £¬£¬£¬£¬£¬£¬²¢³ÐŵÔÚ 2025 ÄêÄê֮ǰ°²È«¸üС£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/linux/linux-mint-203-released-promising-security-updates-until-2025/


ÀÕË÷Èí¼þAvosLocker Õë¶Ô VMware ESXi ·þÎñÆ÷


AvosLockerÔÚÆä×î½üµÄ¶ñÒâÈí¼þ±äÖÖÖÐÔö³¤ÁË¶Ô Linux ϵͳµÄÖ§³Ö£¬£¬ £¬£¬£¬£¬£¬£¬³ö¸ñÊÇÕë¶Ô VMware ESXi Ðé¹¹»ú¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/linux-version-of-avoslocker-ransomware-targets-vmware-esxi-servers/