еÄÀÕË÷ÔËÓªÍÅ»ïDeadBolt¹¥»÷È«ÇòµÄQNAP NASÉ豸

°ä²¼¹¦·ò 2022-01-28

еÄÀÕË÷ÔËÓªÍÅ»ïDeadBolt¹¥»÷È«ÇòµÄQNAP NASÉ豸


ýÌå1ÔÂ25ÈÕ±¨Â·£¬£¬ £¬£¬£¬ÐµÄÀÕË÷ÔËÓªÍÅ»ïDeadBoltÐû³ÆËûÃÇÔÚʹÓÃÉ豸Èí¼þÖеÄÁãÈÕ·ì϶¹¥»÷È«ÇòQNAP NASÉ豸¡£¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷ÆðÍ·ÓÚ1ÔÂ25ÈÕÆðÍ·£¬£¬ £¬£¬£¬´óÁ¿QNAPÉ豸Òѱ»¼ÓÃܲ¢ÇÒÔö³¤ÁË.deadboltÀ©´óÃû£¬£¬ £¬£¬£¬Êê½ðΪ0.03±ÈÌØ±Ò£¨Ô¼1100ÃÀÔª£©¡£¡£¡£¡£¡£¡£ ¡£¡£´Ë±í£¬£¬ £¬£¬£¬¸ÃÍŻﻹ°µÊ¾QNAPÈôÊÇÖ§¸¶5¸ö±ÈÌØ±ÒÄܹ»»ñµÃ¹ØÓÚÁãÈÕ·ì϶µÄÈ«ÊýÐÅÏ¢£¬£¬ £¬£¬£¬Ö§¸¶50¸ö±ÈÌØ±Ò£¨Ô¼ºÏ185ÍòÃÀÔª£©Äܹ»»ñµÃºÏÓÃÓÚËùÓÐQNAPÓû§µÄÖ÷½âÃÜÃÜÔ¿ºÍ·ì϶ÐÅÏ¢¡£¡£¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/new-deadbolt-ransomware-targets-qnap-devices-asks-50-btc-for-master-key/


µç×ÓÉ̳ÇSegwayÔÚMagecart¹¥»÷Öпͻ§ÐÅÏ¢±»µÁ


ýÌå1ÔÂ25ÈÕ±¨Â·£¬£¬ £¬£¬£¬SegwayµÄÔÚÏßÉ̵êÔâµ½Magecart¹¥»÷£¬£¬ £¬£¬£¬¿Í»§ÐÅÏ¢±»µÁ¡£¡£¡£¡£¡£¡£ ¡£¡£Æ¾¾ÝurlscanioÊý¾Ý·ÖÎö£¬£¬ £¬£¬£¬SegwayÍøÕ¾ (store.segway.com) ÖÁÉÙ´Ó1ÔÂ6ÈÕ¾ÍÒѾ­±»ÈëÇÖ£¬£¬ £¬£¬£¬Õâ´Î»î¶¯¿ÉÄÜÓëMagecart Group 12ÓйØ£¬£¬ £¬£¬£¬¸Ã×éÖ¯×Ô2019ÄêÒÔÀ´Ò»ÏòÔÚÇÔÊØÐÅÓþ¿¨ÐÅÏ¢¡£¡£¡£¡£¡£¡£ ¡£¡£×êÑÐÈËÔ±ÒÔΪ£¬£¬ £¬£¬£¬¹¥»÷ÕßÀûÓÃÁËÍøÕ¾Ê¹ÓõÄMagento CMS»òÆä²å¼þÖеķì϶À´×¢Èë¶ñÒâ´úÂë¡£¡£¡£¡£¡£¡£ ¡£¡£½ØÖÁ1ÔÂ25ÈÕ£¬£¬ £¬£¬£¬ÇÔÊØÐÅÏ¢µÄ¶ñÒâ´úÂëÈÔ´æÔÚÓÚ¸ÃÍøÕ¾ÉÏ¡£¡£¡£¡£¡£¡£ ¡£¡£


https://securityaffairs.co/wordpress/127187/cyber-crime/segway-magecart-attack.html


LinuxÄÚºËÒç¶Âí½ÅCVE-2022-0185¿É´ÓÈÝÆ÷ÖÐÌÓÒÝ


ýÌå1ÔÂ25Èճƣ¬£¬ £¬£¬£¬ LinuxÄÚºË×é¼þÖдæÔÚ»ùÓڶѵĻº³åÇøÒç¶Âí½Å¡£¡£¡£¡£¡£¡£ ¡£¡£¸Ã·ì϶׷×ÙΪCVE-2022-0185£¬£¬ £¬£¬£¬¿Éµ¼ÖÂÔ½½çдÈë¡¢»Ø¾ø·þÎñºÍËÁÒâ´úÂëÖ´ÐУ¬£¬ £¬£¬£¬¿ÉÓÃÀ´´ÓKubernetesµÄÈÝÆ÷ÖÐÌÓÒÝ£¬£¬ £¬£¬£¬²¢½Ó¼ûÖ÷»úϵͳÉϵÄ×ÊÔ´¡£¡£¡£¡£¡£¡£ ¡£¡£µ«ÊÇ£¬£¬ £¬£¬£¬¹¥»÷Õß±ØÒªÀûÓ÷ÇÌØÈ¨Ãû³Æ¿Õ¼ä»òʹÓá°unshare¡±À´ÊäÈëÓµÓÐCAP_SYS_ADMINȨÏÞµÄÃû³Æ¿Õ¼ä£¬£¬ £¬£¬£¬ÄÜÁ¦ÀûÓø÷ì϶¡£¡£¡£¡£¡£¡£ ¡£¡£×êÑÐÈËÔ±½¨Ò齫LinuxÄÚºËÉý¼¶µ½5.16.2»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/linux-kernel-bug-can-let-hackers-escape-kubernetes-containers/


Apple°ä²¼°²È«¸üУ¬£¬ £¬£¬£¬½¨¸´Òѱ»ÔÚÒ°ÀûÓõݲȫ·ì϶


1ÔÂ26ÈÕ£¬£¬ £¬£¬£¬Apple°ä²¼°²È«¸üУ¬£¬ £¬£¬£¬½¨¸´ÁËmacOSÖеÄ13¸ö·ì϶£¬£¬ £¬£¬£¬ÒÔ¼°iOS/iPadOSÖеÄ10¸ö·ì϶¡£¡£¡£¡£¡£¡£ ¡£¡£Õâ´Î¹²½¨¸´ÁË2¸öÁãÈÕ·ì϶£¬£¬ £¬£¬£¬µÚÒ»¸öÊÇIOMobileFrameBufferÖеÄÄÚ´æ°Ü»µ·ì϶(CVE-2022-22587)£¬£¬ £¬£¬£¬Ó°ÏìÁËiOS¡¢iPadOSºÍmacOS Monterey£¬£¬ £¬£¬£¬ÀûÓô˷ì϶¿ÉÔÚÖ¸±êÉ豸ÉÏÒÔÄÚºËȨÏÞÖ´ÐÐËÁÒâ´úÂ룻£»£»£»£»ÁíÒ»¸öÊÇWebKit StorageÖеÄÐÅϢй¶·ì϶£¨CVE-2022-22594£©¡£¡£¡£¡£¡£¡£ ¡£¡£AppleÔÚ²¼¸æÖгÆ£¬£¬ £¬£¬£¬CVE-2022-22587¿ÉÄÜÒѱ»»ý¼«ÀûÓᣡ£¡£¡£¡£¡£ ¡£¡£


https://threatpost.com/apple-zero-day-security-exploited/178040/


Trellix°ä²¼Õë¶ÔÎ÷ÑǵØÓòµÄ¼äµý»î¶¯µÄ·ÖÎö»ã±¨


1ÔÂ25ÈÕ£¬£¬ £¬£¬£¬Trellix°ä²¼ÁËÕë¶ÔÎ÷ÑǵØÓò¹ú·ÀÐÐÒµµÄ¼äµý»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£ ¡£¡£Õâ´Î»î¶¯×îÔçÆðÍ·ÓÚ2021Äê6ÔÂ18ÈÕ£¬£¬ £¬£¬£¬ÀûÓÃÁËMicrosoft OneDrive×÷ΪC2·þÎñÆ÷£¬£¬ £¬£¬£¬²¢·ÖΪÁ˶à´ï6¸ö½×¶Î¡£¡£¡£¡£¡£¡£ ¡£¡£Ï°È¾Á´Ê¼ÓÚÔ̺¬MSHTMLÔ¶³Ì´úÂëÖ´Ðзì϶(CVE-2021-40444)·ì϶ÀûÓõÄExcelÎļþ£¬£¬ £¬£¬£¬²¢Ê¹ÓÃÁËÃûΪGraphiteµÄ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£ ¡£¡£Trellix»ùÓÚÔ´´úÂëÒÔ¼°¹¥»÷Ö¸±êºÍÖ¸±êµÄÀàËÆÐÔ£¬£¬ £¬£¬£¬½«Õâ´Î¹¥»÷¹éÒòÓÚ¶íÂÞ˹µÄAPT28×éÖ¯¡£¡£¡£¡£¡£¡£ ¡£¡£


https://www.trellix.com/en-gb/about/newsroom/stories/threat-labs/prime-ministers-office-compromised.html


Proofpoint·¢ÏÖDTPacker·Ö·¢¶à¸öRATºÍÐÅÏ¢ÇÔÈ¡·¨Ê½


ProofpointÔÚ1ÔÂ24ÈÕ°ä²¼µÄ»ã±¨¸ÅÊöÁ˶ñÒâÈí¼þDTPacker¡£¡£¡£¡£¡£¡£ ¡£¡£ËüÊÇÒ»¸ö·ÖΪ2¸ö½×¶ÎµÄÉÌÆ·.NET´ò°ü·¨Ê½£¬£¬ £¬£¬£¬ÆäpayloadʹÓÃÁËÔ̺¬ÌÆÄɵÂÌØÀÊÆÕÐÕÃûµÄ¹Ì¶¨ÃÜÂë¡£¡£¡£¡£¡£¡£ ¡£¡£Proofpoint·¢ÏÖDTPacker·Ö·¢Á˶à¸öRATºÍÐÅÏ¢ÇÔÈ¡·¨Ê½£¬£¬ £¬£¬£¬Ô̺¬Agent Tesla¡¢Ave Maria¡¢AsyncRATºÍFormBook£¬£¬ £¬£¬£¬²¢Ê¹ÓöàÖÖ»ìºÏ¼¼ÊõÀ´Èƹýɱ¶¾Èí¼þ¡¢É³ºÐºÍ¼¼Êõ·ÖÎö¡£¡£¡£¡£¡£¡£ ¡£¡£×Ô2020ÄêÒÔÀ´£¬£¬ £¬£¬£¬DTPackerÓëÊýÊ®´Î¹¥»÷»î¶¯ºÍ¶à¸ö¹¥»÷ÍÅ»ïÓйØ£¬£¬ £¬£¬£¬ÆäÖÐÔ̺¬TA2536ºÍTA2715¡£¡£¡£¡£¡£¡£ ¡£¡£


https://www.proofpoint.com/us/blog/threat-insight/dtpacker-net-packer-curious-password-1


°²È«¹¤¾ß


Yasso


»ã¼¯Á˺ܶàʵÓÃÖ°ÄÜ£¬£¬ £¬£¬£¬×÷Ϊ Intranet ¸¨ÖúÉøÈ빤¾ß¼¯°ä²¼¡£¡£¡£¡£¡£¡£ ¡£¡£


https://securityonline.info/yasso-intranet-assisted-penetration-toolset/


darvester


PoC Discord Óû§ºÍ¹«»áÐÅÏ¢ÍøÂ繤¾ß¡£¡£¡£¡£¡£¡£ ¡£¡£


https://github.com/V3ntus/darvester


chronorace


Äܹ»ÕýÈ·µØÖ´Ðа´Ê±¾ºÕùǰÌáÒÔ¶ã±ÜÀûÓ÷¨Ê½ÒµÎñÂß¼­µÄ¹¤¾ß¡£¡£¡£¡£¡£¡£ ¡£¡£


https://github.com/Cache-Money/chronorace


dep-scan


ÆëÈ«¿ªÔ´µÄ°²È«É󼯹¤¾ß£¬£¬ £¬£¬£¬ÓÃÓÚ»ùÓÚÒÑÖª·ì϶¡¢½¨ÒéºÍÐí¿ÉÏ޶ȵÄÏîÄ¿ÒÀÀµ¹ØÏµ¡£¡£¡£¡£¡£¡£ ¡£¡£


https://github.com/AppThreat/dep-scan


Http Desync Guardian


·ÖÎö HTTP ÒªÇóÒÔ×îÓ×»¯ HTTP Òì²½¹¥»÷µÄ·çÏÕ¡£¡£¡£¡£¡£¡£ ¡£¡£


https://github.com/aws/http-desync-guardian


°²È«·ÖÎö


Ó¢¹úNCSC°ä²¼ÓÃÀ´²éÕÒϵͳÖÐ佨¸´·ì϶µÄNmap¾ç±¾


https://securityaffairs.co/wordpress/127181/hacking/uk-ncsc-scanning-made-easy-sme.html


Windows 11 KB5008353 ÀÛ»ý¸üÐÂÔ¤ÀÀ°ä²¼


https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5008353-cumulative-update-preview-released/


VMware£º½¨²¹ Horizon ·þÎñÆ÷ÒÔÕмÜÔÚ½øÐÐµÄ Log4j ¹¥»÷


https://www.bleepingcomputer.com/news/security/vmware-patch-horizon-servers-against-ongoing-log4j-attacks/


¶íÂÞ˹¿ÛÁôºÚ¿Í×éÖ¯Infraud OrganizationµÄ³ÉÔ±


https://www.bleepingcomputer.com/news/security/russia-arrests-leader-of-infraud-organization-hacker-group/


ÐÂÄ«Î÷¸çÖÝÌá½»ÍøÂ簲ȫ·¨°¸


https://www.infosecurity-magazine.com/news/new-mexico-files-cybersecurity/


2021 ÄêÊ®´óÀÕË÷Èí¼þ¹¥»÷


https://www.cybereason.com/blog/ten-of-the-biggest-ransomware-attacks-of-2021