΢Èí°ä²¼´ø±í¸üÐÂÒÔ½â¾ö1Ô·ÝÖܶþ²¹¶¡µ¼ÖµÄÎÊÌâ
°ä²¼¹¦·ò 2022-01-19΢Èí°ä²¼´ø±í¸üÐÂÒÔ½â¾ö1Ô·ÝÖܶþ²¹¶¡µ¼ÖµÄÎÊÌâ

1ÔÂ18ÈÕ£¬£¬£¬£¬£¬Î¢Èí°ä²¼´¹Î£´ø±í(OOB)¸üУ¬£¬£¬£¬£¬ÒÔ½â¾öÓÉ2021Äê1ÔµÄÖܶþ²¹¶¡µ¼ÖµÄÖî¶àÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾°µÊ¾£¬£¬£¬£¬£¬´Ë¸üнâ¾öÁËÓëVPNÏνӡ¢Windows ServerÓò½ÚÔìÆ÷³ÁÐÂÆô¶¯¡¢Ðé¹¹»úÆô¶¯Ê§°ÜÒÔ¼°ReFSÌåʽµÄ¿ÉÒÆ¶¯Ã½ÌåÎÞ·¨×°ÖÃÓйصÄÎÊÌâ¡£¡£¡£¡£¡£¡£¡£Õâ´Î°ä²¼µÄËùÓÐOOB¸üж¼Äܹ»ÔÚMicrosoft Update Catalog¸ßµÍÔØ£¬£¬£¬£¬£¬ÆäÖв¿ÃÅ»¹ÄÜ×÷Ϊ¿ÉÑ¡¸üÐÂÖ±½Óͨ¹ýWindows Update×°Öᣡ£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-oob-updates-for-january-windows-update-issues/
AWS½¨¸´ÐÅϢй¶·ì϶SuperglueºÍBreakingFormation
¾ÝýÌå1ÔÂ14ÈÕ±¨Â·£¬£¬£¬£¬£¬AWSÒѽ¨¸´Æä²úÆ·ÖеÄ2¸öÐÅϢй¶·ì϶¡£¡£¡£¡£¡£¡£¡£Õâ2¸ö·ì϶¾ùÊÇÓÉOrca SecurityÍŶӷ¢Ïֵ쬣¬£¬£¬£¬ÆäÖеÄSuperglue´æÔÚÓÚAWS Glue·þÎñÖУ¬£¬£¬£¬£¬ÊÇÄÚ²¿·þÎñAPIÅäÖÃÃýÎóµ¼Öµģ¬£¬£¬£¬£¬¿É±»ÓÃÀ´ÌáÉýȨÏÞ½Ó¼û¸ÃµØÓòµÄËùÓзþÎñ×ÊÔ´£»£»£»£»£»£»£»£»ÁíÒ»¸öÊÇAWS CloudFormation·þÎñÖеÄBreakingFormation£¬£¬£¬£¬£¬ÕâÊÇÒ»¸öXXE·ì϶£¬£¬£¬£¬£¬¿Éµ¼ÖÂAWS»ù´¡ÉèÊ©·þÎñµÄÎļþºÍƾ֤й¶¡£¡£¡£¡£¡£¡£¡£
https://www.infosecurity-magazine.com/news/aws-patches-glue-bug-customer-data/
×êÑÐÈËÔ±ÑÝʾÈôºÎÀûÓõÚÈý·½ÀûÓÃÖзì϶½âËøÌØË¹ÀÆû³µ
ýÌå1ÔÂ13ÈÕ±¨Â·£¬£¬£¬£¬£¬19ËêµÄDavid Colombo³ÆÆäÄܹ»Ô¶³Ì½ÚÔì¶à¸ö¹ú¶ÈµÄ25Á¾ÌØË¹ÀÆû³µ¡£¡£¡£¡£¡£¡£¡£ColomboÔÚÓµÓиú×ÙÆû³µÒƶ¯ºÍÔ¶³Ì½âËø³µÃŵÈÖ°ÄܵĵÚÈý·½ÀûÓÃÖз¢ÏÖÒ»¸ö·ì϶£¬£¬£¬£¬£¬¸Ã·ì϶ԴÓÚÀûÓÃÒÔ²»°²È«µÄ·½Ê½´æ´¢ÓÃÀ´ÏÎ½ÓÆû³µµÄÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓ÷ì϶ºó³ýÁËÄܹ»½ÚÔìÆû³µ£¬£¬£¬£¬£¬»¹Äܹ»»ñÈ¡Óû§ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬ËûÔڵ¹ú¡¢Ó¢¹ú¡¢ÃÀ¹ú¡¢¼ÓÄôóºÍÖйúµÈ¹ú¶È»¹·¢ÏÖÁ˳¬¹ý125Á¾¿É±»½ÚÔìµÄÌØË¹ÀÆû³µ¡£¡£¡£¡£¡£¡£¡£
https://www.vice.com/en/article/akv7z5/how-a-hacker-controlled-dozens-of-teslas-using-a-flaw-in-third-party-app
NFTƽ̨Lympo±»·¸·¨½Ó¼û£¬£¬£¬£¬£¬Ôì³ÉÔ¼1870ÍòÃÀÔªËðʧ
ýÌå1ÔÂ16Èճƣ¬£¬£¬£¬£¬NFTƽ̨LympoÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬Ôì³ÉÔ¼1870ÍòÃÀÔªËðʧ¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾°ä²¼µÄ¾¯±¨°µÊ¾£¬£¬£¬£¬£¬¹¥»÷²úÉúÔÚ2022Äê1ÔÂ10ÈÕÏÂÎç2:32×óÓÒ£¨UTC+2£©£¬£¬£¬£¬£¬¹¥»÷ÕßÉè·¨½Ó¼ûÁËLympoµÄÈÈÇ®°ü£¬£¬£¬£¬£¬²¢´ÓÖÐÇÔÈ¡ÁËԼĪ1.652ÒÚ¸öLMT¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬LMTµÄ¼ÛÖµ×ÅÂ䳬¹ý92%¡£¡£¡£¡£¡£¡£¡£²úÉú¹¥»÷ºó¸Ãƽ̨Á¢¿Ì²ÉÈ¡ÁËÓ¦¼±´ëÊ©£¬£¬£¬£¬£¬²¢ÁгöÁËÆäÔÚ¼à¿ØµÄºÚ¿ÍÇ®°üµÄµØÖ·¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/126766/cyber-crime/lympo-ntf-platform-hacked.html
ÐÂÄ«Î÷¸çÖݼàÓüMDCÔâµ½ÀÕË÷¹¥»÷±»ÆÈ½øÈëËø¶¨×´Ì¬
¾ÝMalwarebytes 1ÔÂ13ÈÕ±¨Â·£¬£¬£¬£¬£¬ÐÂÄ«Î÷¸çÖݲ®ÄÉÀûÂåÏØµÄ´ó³ÇÊпÛÁôÖÐÐÄ£¨MDC£©Ôâµ½ÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£¡£¹¥»÷²úÉúÔÚ1ÔÂ5ÈÕÎçÒ¹ÖÁ5:30×óÓÒ£¬£¬£¬£¬£¬µ¼Ö¼àÓüÍøÂçÏνÓÖжϣ¬£¬£¬£¬£¬´ó²¿ÃÅÊý¾Ýϵͳ¡¢°²È«¼à¿ØºÍ×Ô¶¯ÃÅÎÞ·¨Ê¹Ó㬣¬£¬£¬£¬Çô·¸Ò²±»¹ØÔÚÀη¿Àï¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬MDCµÄ¶à¸öÊý¾Ý¿âÒѰܻµ£¬£¬£¬£¬£¬2¸ö³ÁÒªµÄϵͳ£ºÊÂÎñ¸ú×Ùϵͳ(ITS)ºÍ×ï·¸ÖÎÀíϵͳ(OMS)Ò²ÎÞ·¨½Ó¼û¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬MDC×ÔÉí²¢·ÇÕâ´Î¹¥»÷µÄÖ¸±ê£¬£¬£¬£¬£¬¸ÃÏØµÄÕû¸öÍøÂçϵͳ¶¼Êܵ½Á˹¥»÷¡£¡£¡£¡£¡£¡£¡£
https://blog.malwarebytes.com/ransomware/2022/01/ransomware-cyberattack-forces-new-mexico-jail-to-lock-down/
ÎÚ¿ËÀ¼¾¯·½µ·»ÙÒѹ¥»÷Å·ÃÀµØÓò50¶à¸ö×éÖ¯µÄºÚ¿ÍÍÅ»ï
1ÔÂ13ÈÕ£¬£¬£¬£¬£¬ÎÚ¿ËÀ¼¾¯·½°ä²¼¹«¸æ³Æ¿ÛÁôÁËÒ»¸öÀÕË÷¹¥»÷ÍŻ¡£¡£¡£¡£¡£¡£¾¯·½°µÊ¾£¬£¬£¬£¬£¬¸Ã×éÖ¯Òѹ¥»÷ÃÀ¹úºÍÅ·ÖÞµØÓò³¬¹ý50¸ö¹«Ë¾£¬£¬£¬£¬£¬ÆäÖÐ36ËêµÄÎÚ¿ËÀ¼Ê×¶¼»ù¸¨¾ÓÃñ±»È·¶¨Îª¸Ã×éÖ¯µÄÍ·×Ó£¬£¬£¬£¬£¬³ÉÔ±Ô̺¬ËûµÄÀÏÆÅºÍÆäËûÈýÃûÊìÈË£¬£¬£¬£¬£¬¾Ý¹À¼Æ¹¥»÷Ôì³ÉµÄ×ÜËðʧ³¬¹ýÒ»°ÙÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°Éв»Ã÷ÏÔ¸ÃÍÅ»ïʹÓúÎÖÖÀÕË÷Èí¼þÀ´¼ÓÃÜÖ¸±êÍÆËã»úÉϵÄÊý¾Ý£¬£¬£¬£¬£¬µ«ËûÃÇͨ¹ýÀ¬»øÓʼþ·Ö·¢¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£³ýÁËÀÕË÷¹¥»÷£¬£¬£¬£¬£¬¸ÃÍŻﻹÌṩIPµØÖ·ºýŪ·þÎñ¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/ukranian-police-arrests-ransomware-gang-that-hit-over-50-firms/
°²È«¹¤¾ß
RAUDI
RAUDIͨ¹ýGitHub ActionsΪ¿ª·¢ÈËԱδÌṩµÄ¹¤¾ß×Ô¶¯ÌìÉú²¢Î¬³Ö¸üÐÂһϵÁÐDocker ¾µÏñ¡£¡£¡£¡£¡£¡£¡£
https://github.com/cybersecsi/RAUDI
Driftwood
Driftwood ÊÇÒ»ÖÖ¹¤¾ß£¬£¬£¬£¬£¬¿ÉÈÃÄú²éÕÒ˽ԿÊÇ·ñÓÃÓÚ TLS µÅ×Ã;£¬£¬£¬£¬£¬»òÕßÓÃ×÷Óû§µÄ GitHub SSH ÃÜÔ¿¡£¡£¡£¡£¡£¡£¡£
https://github.com/trufflesecurity/driftwood
SpoofThatMail
ÓÃÓÚ²é³ÊÇ·ñÄܹ»Æ¾¾ÝDMARC¼Í¼ºýŪÓò»òÓòÁбíµÄ Bash ¾ç±¾
https://github.com/v4d1/SpoofThatMail
°²È«·ÖÎö
CVE-2022-0215:¿çÕ¾ÒªÇóαÔì·ì϶
3¸öWordPress ²å¼þÖеĿçÕ¾ÒªÇóαÔì·ì϶ӰÏìÁË 84,000 ¸öÍøÕ¾¡£¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2022/01/high-severity-vulnerability-in-3.html
Chromium ä¯ÀÀÆ÷È¡µÞɾ³ýĬÈÏËÑË÷ÒýÇæµÄÑ¡Ïî
Chromium ä¯ÀÀÆ÷иü¸ÄʹÓû§ÎÞ·¨É¾³ýĬÈÏËÑË÷ÒýÇæ£¬£¬£¬£¬£¬Ô̺¬Edge¡¢Chrome ºÍ Vivaldi¡£¡£¡£¡£¡£¡£¡£
https://news.softpedia.com/news/chromium-browsers-lose-option-to-remove-default-search-engines-534697.shtml
×êÑÐÈËÔ±¿ª·¢ CAPTCHA Çó½âÆ÷ÒÔÔ®ÊÖ°µÍø×êÑÐ
×êÑÐÈËÔ±¿ª·¢ÁËÒ»ÖÖ»ùÓÚ»úе½ø½¨µÄÑéÖ¤ÂëÇó½âÆ÷£¬£¬£¬£¬£¬ËûÃÇÐû³ÆÄܹ»¿Ë·þÒõÓôÍøÕ¾ÉÏ 94.4% µÄÌôÕ½¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/researchers-develop-captcha-solver-to-aid-dark-web-research/
Android Óû§´Ë¿ÌÄܹ»½ûÓà 2G À´×èÖ¹ Stingray ¹¥»÷
¹È¸èÔÚ Android ÉÏÍÆ³öÁËÒ»¸öÑ¡Ï£¬£¬£¬£¬ÔÊÐíÓû§½ûÓà 2G ÏνÓÒÔ×èÖ¹±»ºÜ¶à·äÎÑÕ¾µãÄ£ÄâÆ÷ÀûÓõÄÒþÖԺͰ²È«ÎÊÌâ¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/android-users-can-now-disable-2g-to-block-stingray-attacks/


¾©¹«Íø°²±¸11010802024551ºÅ