Zoho½¨¸´Desktop CentralÖеÄÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶

°ä²¼¹¦·ò 2022-01-20

Zoho½¨¸´Desktop CentralÖеÄÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶


1ÔÂ17ÈÕ£¬£¬£¬£¬£¬Zoho½¨¸´ÁËDesktop CentralºÍDesktop Central MSPͳһ¶ËµãÖÎÀí(UEM)½â¾ö¹æ»®Öеķì϶¡£¡£¡£ ¡£¡£¡£¡£¡£¸Ã·ì϶׷×ÙΪCVE-2021-44757£¬£¬£¬£¬£¬ÊÇÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¬£¬£¬£¬£¬¿ÉÓÃÀ´ÔÚ·þÎñÆ÷ÖÐÖ´ÐÐδ¾­ÊÚȨµÄ²Ù×÷¡£¡£¡£ ¡£¡£¡£¡£¡£Zoho°µÊ¾£¬£¬£¬£¬£¬³É¹¦ÀûÓô˷ì϶£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜ»áÔÚ·þÎñÆ÷É϶ÁÈ¡Êý¾Ý»òдÈëËÁÒâzipÎļþ¡£¡£¡£ ¡£¡£¡£¡£¡£¸Ã¹«Ë¾»¹½¨ÒéÓû§×ñÑ­Desktop CentralºÍDesktop Central MSPµÄ°²È«¼Ó¹ÌÖ¸ÄÏ¡£¡£¡£ ¡£¡£¡£¡£¡£


https://thehackernews.com/2022/01/zoho-releases-patch-for-critical-flaw.html


DHL³ÉΪ2021ÄêQ4´¹µö¹¥»÷»î¶¯Öб»·ÂÕÕ×î¶àµÄÆ·ÅÆ


1ÔÂ17ÈÕ£¬£¬£¬£¬£¬Check Point Research°ä²¼ÁË2021ÄêµÚËÄʱ¶ÈÆ·ÅÆÍøÂç´¹µö»ã±¨¡£¡£¡£ ¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬¿ìµÝ¹«Ë¾DHLÈ¡´ú΢Èí£¬£¬£¬£¬£¬³ÉΪµÚËÄʱ¶ÈµÄ´¹µö¹¥»÷»î¶¯Öб»·ÂÕÕ×î¶àµÄÆ·ÅÆ¡£¡£¡£ ¡£¡£¡£¡£¡£ÓëÆäÓйصĴ¹µö»î¶¯Õ¼×ܹ¥»÷µÄ23%£¬£¬£¬£¬£¬Æä´ÎΪ΢Èí(20%)¡¢WhatsApp(11%)¡¢¹È¸è(10%)ºÍÁìÓ¢(8%)¡£¡£¡£ ¡£¡£¡£¡£¡£³ý´ËÖ®±í£¬£¬£¬£¬£¬Áª¹ú¿ìµÝ(3%)Ò²³õ´Î³Ê´Ë¿ÌǰʮµÄÃûµ¥ÖУ¬£¬£¬£¬£¬ºÁÎÞÒÉÄÑÕâÓëCOVID-19ÈÔÔÚ³ÖÐøÓйØ£¬£¬£¬£¬£¬¹¥»÷ÕßÊÔͼÔÚ½Ú¼ÙÈÕÆÚ¼äÕë¶ÔÔÚÏß¹ºÎïÕß¡£¡£¡£ ¡£¡£¡£¡£¡£


https://blog.checkpoint.com/2022/01/17/dhl-replaces-microsoft-as-most-imitated-brand-in-phishing-attempts-in-q4-2021/


×êÑÐÈËÔ±·¢ÏÖÕë¶Ô¿ÉÔÙÉúÄÜÔ´ÐÐÒµµÄ´ó¹æÄ£¼äµý»î¶¯


¾ÝýÌå1ÔÂ17ÈÕ±¨Â·£¬£¬£¬£¬£¬×êÑÐÈËÔ±William Thomas·¢ÏÖÕë¶Ô¿ÉÔÙÉúÄÜÔ´ºÍ»·¾³±£»£»£» £»£»£»¤µÈÐÐÒµµÄ¼äµý»î¶¯¡£¡£¡£ ¡£¡£¡£¡£¡£ThomasµÄ·ÖÎöÏÔʾ£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁË×Ô½ç˵¹¤¾ß°ü¡°Mail Box¡±£¬£¬£¬£¬£¬²¢ÈëÇÖÁËһЩºÏ·¨µÄÍøÕ¾À´Íйܴ¹µöÒ³Ãæ¡£¡£¡£ ¡£¡£¡£¡£¡£´óÎÞÊý´¹µöÒ³ÃæÍйÜÔÚ*.eu3[.]biz¡¢*.eu3[.]orgºÍ*.eu5[.]netÓòÖУ¬£¬£¬£¬£¬¶ø´óÎÞÊý±»Ï°È¾ÍøÕ¾Î»ÓÚ°ÍÎ÷¡£¡£¡£ ¡£¡£¡£¡£¡£Õâ´Î¹¥»÷»î¶¯µÄÖ¸±êÔ̺¬Ê©ÄÍµÂµçÆø¡¢»ôÄáΤ¶û¡¢»ªÎª¡¢º£Ë¼¡¢ÂÞÂíÄáÑǵçÐÅ¡¢Íþ˹¿µÐÇ´óѧºÍ¼ÓÖÝÖÝÁ¢´óѧµÈ£¬£¬£¬£¬£¬Ö¼ÔÚÇÔÈ¡¹¤×÷ÈËÔ±µÄµÇ¼ʹ´¦¡£¡£¡£ ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/cyber-espionage-campaign-targets-renewable-energy-companies/



Trend Micro°ä²¼¹ØÓÚEarth LuscaÍÅ»ïµÄ·ÖÎö»ã±¨


1ÔÂ17ÈÕ£¬£¬£¬£¬£¬Trend MicroÅû¶ÁËEarth LuscaÍÅ»ïÕë¶ÔÈ«Çò×éÖ¯µÄ¹¥»÷»î¶¯µÄϸ½Ú¡£¡£¡£ ¡£¡£¡£¡£¡£¸Ã×éÖ¯ÖØÒª½øÐмäµý»î¶¯£¬£¬£¬£¬£¬ÆäÖ¸±êÔ̺¬µ±¾ÖºÍ½ÌÓý»ú¹¹¡¢Covid-19×êÑÐ×éÖ¯ºÍýÌåµÈ¡£¡£¡£ ¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬Ò²´æÔÚ¾­¼Ã¶¯»ú£¬£¬£¬£¬£¬ÓÉÓÚËü»¹¶Ô×¼ÁË´ò¶ÄºÍ¼ÓÃÜÇ®±Ò¹«Ë¾£¬£¬£¬£¬£¬×êÑÐÈËÔ±ÒÔΪËüÊÇWinnti clusterµÄÒ»²¿ÃÅ¡£¡£¡£ ¡£¡£¡£¡£¡£ÔÚÕâЩ»î¶¯ÖУ¬£¬£¬£¬£¬¹¥»÷ÕßÊ×ÏÈÀûÓÃÓã²æÊ½´¹µöºÍË®¿Ó¹¥»÷ÈëÇÖÖ¸±êÍøÂ磬£¬£¬£¬£¬¶øºó×°ÖÃCobalt Strike¼°¸÷Àà¶ñÒâÈí¼þ£¬£¬£¬£¬£¬ÓÐʱ»¹»á×°ÖöñÒâ¿ó¹¤Èí¼þ¡£¡£¡£ ¡£¡£¡£¡£¡£


https://www.trendmicro.com/en_us/research/22/a/earth-lusca-sophisticated-infrastructure-varied-tools-and-techni.html



Crowdstrike»ã±¨³Æ2021ÄêLinux¶ñÒâÈí¼þÔö³¤35%


CrowdstrikeÔÚ1ÔÂ13ÈÕ°ä²¼µÄ»ã±¨³Æ£¬£¬£¬£¬£¬2021ÄêLinux¶ñÒâÈí¼þÔö³¤35%¡£¡£¡£ ¡£¡£¡£¡£¡£»ã±¨ÏÔʾ£¬£¬£¬£¬£¬XorDDoS¡¢MiraiºÍMoziÊÇ2021Äê×î³£¼ûµÄ¶ñÒâÈí¼þ¼Ò×壬£¬£¬£¬£¬Õ¼¹Û²ìµ½µÄËùÓÐÕë¶ÔLinuxµÄ¶ñÒâÈí¼þ¹¥»÷µÄ22%¡£¡£¡£ ¡£¡£¡£¡£¡£ÓÈÆäÊÇMozi£¬£¬£¬£¬£¬Æä»î¶¯³Ê±¬Õ¨Ê½Ôö³¤£¬£¬£¬£¬£¬2021ÄêÔÚÒ°´«²¼µÄÑù±¾ÊýÁ¿ÊÇ2020ÄêµÄ10±¶¡£¡£¡£ ¡£¡£¡£¡£¡£ÕâЩ¶ñÒâÈí¼þµÄÖØÒªÖ÷ÕÅÊÇÈëÇÖÒ×Êܹ¥»÷µÄÁªÍøÉ豸£¬£¬£¬£¬£¬½«ËüÃÇÔö³¤µ½½©Ê¬ÍøÂ磬£¬£¬£¬£¬À´Ö´ÐÐDDoS¹¥»÷¡£¡£¡£ ¡£¡£¡£¡£¡£ 


https://www.crowdstrike.com/blog/linux-targeted-malware-increased-by-35-percent-in-2021



Å·ÖÞÐ̾¯×éÖ¯½áºÏ¶à¹úÈ¡µÞ¹¥»÷ÕßʹÓõÄVPNLab.net


¾ÝýÌå1ÔÂ17ÈÕ±¨Â·£¬£¬£¬£¬£¬À´×Ô10¸ö¹ú¶ÈµÄ·¨Âɲ¿ÃŹعØÁ˶ñÒâ¹¥»÷Õß³£ÓõÄVPN·þÎñVPNLab.net¡£¡£¡£ ¡£¡£¡£¡£¡£Õâ´Î½áºÏÐж¯ÓÚ2022Äê1ÔÂ17ÈÕ·¢Õ¹£¬£¬£¬£¬£¬ÓÉÅ·ÖÞÐ̾¯×é֯Эµ÷£¬£¬£¬£¬£¬Éæ¼°µÂ¹ú¡¢ºÉÀ¼¡¢¼ÓÄô󡢽ݿ˺ͷ¨¹úµÈ¹ú¶È¡£¡£¡£ ¡£¡£¡£¡£¡£·¨ÂÉÈËÔ±³ä¹«ÁËVPNLab.netʹÓõÄ15̨·þÎñÆ÷²¢¹Ø¹ØÁËÆäÖ÷ÍøÕ¾£¬£¬£¬£¬£¬Òò¶ø¸Ãƽ̨²»ÔÙ¿ÉÓᣡ£¡£ ¡£¡£¡£¡£¡£ÕâÊǺ¹Çà×îÓÆ¾ÃµÄVPN·þÎñ·þÎñÖ®Ò»£¬£¬£¬£¬£¬´´½¨ÓÚ2008Ä꣬£¬£¬£¬£¬ÒÔÿÄê60ÃÀÔªµÄ¼ÛÖµÌṩ»ùÓÚOpenVPNµÄ¼¼ÊõºÍ2048λµÄ¼ÓÃÜ¡£¡£¡£ ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/europol-shuts-down-vpn-service-used-by-ransomware-groups/


°²È«¹¤¾ß


Wi-Fi Framework


¿É½øÐÐ Wi-Fi ³¢ÊÔ£¬£¬£¬£¬£¬ÓÃÓÚ´´½¨ÍÌÍÂÆ÷¡¢Ö´ÐÐй¥»÷¡¢´´½¨¸ÅÏëÑéÖ¤ÒÔ²âÊÔ·ì϶¡¢×Ô¶¯»¯³¢ÊÔ¡¢Ö´ÐвâÊÔÌ×¼þµÈ¡£¡£¡£ ¡£¡£¡£¡£¡£


https://github.com/domienschepers/wifi-framework


scemu


x86 32bits Ä£ÄâÆ÷£¬£¬£¬£¬£¬ÓÃÓÚ°²È«µØÄ£Äâ shellcode


https://github.com/sha0coder/scemu


chlonium


ÊÇרΪ¿Ë¡ Chromium Cookie ¶øÉè¼ÆµÄÀûÓ÷¨Ê½¡£¡£¡£ ¡£¡£¡£¡£¡£


https://github.com/rxwx/chlonium


°²È«·ÖÎö


IDEMIA ÉúÎï¼ø±ð¶ÁÈ¡Æ÷Öеķì϶


¹¥»÷Õß»¹Äܹ»Í¨¹ýÏòÒ×Êܹ¥»÷µÄÉ豸·¢ËͳÁÆôºÅÁîÀ´ÀûÓø÷ì϶µ¼Ö»ؾø·þÎñ (DoS) ״̬¡£¡£¡£ ¡£¡£¡£¡£¡£


https://www.securityweek.com/vulnerability-idemia-biometric-readers-allows-hackers-unlock-doors


³öÓÚ°²È«Ô­Òò£¬£¬£¬£¬£¬Chrome ÏÞ¶ÈÍøÕ¾¶ÔרÓÃÍøÂçµÄÖ±½Ó½Ó¼û


Chrom´òËã²»Èݹ«¹²ÍøÕ¾Ö±½Ó½Ó¼ûλÓÚרÓÃÍøÂçÖеĶ˵㣬£¬£¬£¬£¬ÒÔÔ¤·Àͨ¹ýä¯ÀÀÆ÷½øÐÐÈëÇÖ¡£¡£¡£ ¡£¡£¡£¡£¡£


https://thehackernews.com/2022/01/chrome-limits-websites-access-to.html


CVE-2022-20660£ºÐÅϢй¶·ì϶


Cisco IP Phone ϵÁÐ 78x1¡¢88x5¡¢88x1¡¢7832¡¢8832¡¢8821 ºÍ 3905 ´æÔÚ²»°²È«µÄÃÜÂë´æ´¢·ì϶¡£¡£¡£ ¡£¡£¡£¡£¡£


https://packetstormsecurity.com/files/165567/SA-20220113-0.txt