¹È¸è½¨¸´ChromeÖпªÊͺóʹÓ÷ì϶CVE-2022-0609

°ä²¼¹¦·ò 2022-02-17

¹È¸è½¨¸´ChromeÖпªÊͺóʹÓ÷ì϶CVE-2022-0609


2ÔÂ14ÈÕ£¬£¬£¬£¬£¬ £¬¹È¸è°ä²¼´¹Î£¸üУ¬£¬£¬£¬£¬ £¬½¨¸´ChromeÖеĶà¸ö°²È«·ì϶¡£¡£¡£ ¡£¡£¡£Õâ´Î½¨¸´µÄ×îÑϳÁµÄ·ì϶ÊǶ¯»­×é¼þÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2022-0609£©£¬£¬£¬£¬£¬ £¬¿É±»ÓÃÀ´Ö´ÐÐËÁÒâ´úÂë»òÔÚä¯ÀÀÆ÷µÄɳÏäÖÐÌÓÒÝ¡£¡£¡£ ¡£¡£¡£¹È¸è°µÊ¾ËûÃÇÒѾ­¼ì²âµ½ÀûÓÃÕâ¸öÁãÈÕ·ì϶µÄ¹¥»÷£¬£¬£¬£¬£¬ £¬µ«¸Ã¹«Ë¾²¢Î´·ÖÏíÓйع¥»÷»î¶¯µÄÆäËüÐÅÏ¢»ò¸Ã·ì϶µÄ¼¼Êõϸ½Ú¡£¡£¡£ ¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ £¬¸üл¹½¨¸´ÁËWebstore APIÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2022-0605£©ºÍMojoÖеÄÕûÊýÒç¶Âí½Å£¨CVE-2022-0608£©µÈ·ì϶¡£¡£¡£ ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/google-chrome-emergency-update-fixes-zero-day-exploited-in-attacks/


ÎÚ¿ËÀ¼¶à¸ö¹Ù·½×éÖ¯µÄÍøÕ¾Ôâµ½´ó¹æÄ£DDoS¹¥»÷


ÎÚ¿ËÀ¼¶à¸ö¹Ù·½×éÖ¯µÄÍøÕ¾ÔÚ2ÔÂ15ÈÕÔâµ½ÁË´ó¹æÄ£DDoS¹¥»÷¡£¡£¡£ ¡£¡£¡£¸Ã¹úµÄ2¸ö¹úÓÐÒøPrivatbank£¨ÎÚ¿ËÀ¼×î´óµÄÒøÐУ©ºÍOschadbank£¨¹ú¶È´¢ÐîÒøÐУ©´Ó±¾µØ¹¦·òÏÂÎç3µã×óÓÒÆðÍ·¹Ø¹ØÁË2¸öÓ×ʱ£¬£¬£¬£¬£¬ £¬ÔÚ5¸öÓ×ʱºó¸´Ô­Õý³£ÔËÐУ¬£¬£¬£¬£¬ £¬²¢°µÊ¾¿ÉÄÜ»áÔÙ´ÎÔâµ½¹¥»÷¡£¡£¡£ ¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ £¬ÎÚ¿ËÀ¼¹ú·À²¿ºÍÎä×°¶ÓÁеÄÍøÕ¾ÒÀÈ»ÎÞ·¨½Ó¼û¡£¡£¡£ ¡£¡£¡£ÎÚ¿ËÀ¼¹«¹²¹ã²¥µç̨µÄ×ÜÔì×÷ÈËDmitry Khorkin°µÊ¾µç̨ҲÔâµ½Á˹¥»÷£¬£¬£¬£¬£¬ £¬µ«ÆäÍøÕ¾²¢Î´Ì±»¾¡£¡£¡£ ¡£¡£¡£


https://therecord.media/ddos-attacks-hit-websites-of-ukraines-state-banks-defense-ministry-and-armed-forces/


Î÷°àÑÀ¾¯·½µ·»Ù½ðÈÚÚ¿Æ­·¸×ïÍŻﲢ¿ÛÁô8¸öÏÓÒÉÈË


¾ÝýÌå2ÔÂ14ÈÕ±¨Â·£¬£¬£¬£¬£¬ £¬Î÷°àÑÀ¹ú¶È¾¯Ô±¾Ö£¨Polic¨ªa Nacional£©ÔÚÉÏÖܵ·»ÙÁËÒ»¸ö½ðÈÚÚ¿Æ­·¸×ïÍŻ¡£¡£ ¡£¡£¡£¸ÃÍÅ»ïµÄ8Ãû³ÉÔ±±»²¶£¬£¬£¬£¬£¬ £¬12¸öÒøÐÐÕË»§±»¶³½á¡£¡£¡£ ¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬ £¬¸ÃÍÅ»ïµÄµÚһ·¹¥»÷ÊÂÎñ²úÉúÔÚ2021Äê3Ô£¬£¬£¬£¬£¬ £¬ËûÃÇÖØÒª¼Ù×°³ÉÒøÐÐºÍÆäËü×éÖ¯µÄ´ú±í£¬£¬£¬£¬£¬ £¬Ê¹Óô¹µö¹¥»÷ºÍSIM»¥»»¹¥»÷»ñȡָ±êµÄÓ×ÎҺͲÆÕþÐÅÏ¢£¬£¬£¬£¬£¬ £¬²¢´ÓËûÃǵÄÕË»§ÖÐÌáÈ¡×ʽ𡣡£¡£ ¡£¡£¡£½üÄêÀ´£¬£¬£¬£¬£¬ £¬SIM»¥»»ÒÑÑݱäΪһÖÖÈÕÒæÆÕ±éµÄÍøÂç·¸×ï´ó¾Ö£¬£¬£¬£¬£¬ £¬2021Äê12Ô£¬£¬£¬£¬£¬ £¬The Community³ÉÔ±ÒòÉæÏÓÊý°ÙÍòÃÀÔªµÄSIM¿¨»¥»»¹¥»÷±»¿ÛÁô¡£¡£¡£ ¡£¡£¡£


https://thehackernews.com/2022/02/spanish-police-arrest-sim-swappers-who.html


Beetle Eye´æ´¢Í°ÅäÖÃÃýÎóÔ¼700ÍòÓû§µÄÐÅϢй¶


¾Ý2ÔÂ14Èյı¨Â·£¬£¬£¬£¬£¬ £¬Website Planet·¢ÏÖÃÀ¹úÓªÏú¹«Ë¾Beetle EyeÔ¼700ÍòÓû§µÄÐÅϢй¶¡£¡£¡£ ¡£¡£¡£Beetle EyeÒòAWS S3´æ´¢Í°ÅäÖÃÃýÎó¶³öÁ˳¬¹ý6000¸öÎļþ£¬£¬£¬£¬£¬ £¬×ܼƳ¬¹ý1GBÊý¾Ý¡£¡£¡£ ¡£¡£¡£Õâ´Îй¶ÁËÐÕÃû¡¢µØÖ·¡¢ÓÊÕþ±àÂëºÍµç»°ºÅÂëµÈÐÅÏ¢£¬£¬£¬£¬£¬ £¬ÊÜÓ°ÏìµÄÓû§´ó¶àÀ´×ÔÓÚÃÀ¹úºÍ¼ÓÄô󡣡£¡£ ¡£¡£¡£¸Ã´æ´¢Í°ÓÚ2021Äê9ÔÂ9ÈÕ±»·¢ÏÖ£¬£¬£¬£¬£¬ £¬2022Äê2ÔÂ14ÈÕBeetle Eye»Ø¸´³ÆÃô¸ÐÎļþÒѱ»É¾³ý¡£¡£¡£ ¡£¡£¡£


https://www.hackread.com/us-marketing-firm-data-exposed-database-mess-up/


ÈðÊ¿Æû³µ¾­ÏúÉÌEmil Frey³ÆÆäÔâµ½HiveµÄÀÕË÷¹¥»÷


ýÌå2ÔÂ14ÈÕ±¨Â·£¬£¬£¬£¬£¬ £¬ÈðÊ¿Æû³µ¾­ÏúÉÌEmil FreyÔâµ½HiveÀÕË÷¹¥»÷¡£¡£¡£ ¡£¡£¡£ÕâÊÇÅ·ÖÞ×î´óµÄÆû³µ¾­ÏúÉÌÖ®Ò»£¬£¬£¬£¬£¬ £¬ÔÚ2020Äê´´ÔìÁË32.9ÒÚÃÀÔªµÄÏúÊÛ¶î¡£¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾ÓÚ2ÔÂ1Èճʴ˿ÌHiveµÄÒѱ»¹¥»÷Ö¸±êµÄÃûµ¥ÉÏ£¬£¬£¬£¬£¬ £¬²¢ÈÏ¿ÉËûÃÇÔÚ1Ô·ÝÔâµ½¹¥»÷¡£¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾½²»°È˳ƣ¬£¬£¬£¬£¬ £¬ÔÚ1ÔÂ11ÈÕµÄÊÂÎñ²úÉú¼¸Ììºó£¬£¬£¬£¬£¬ £¬¹«Ë¾¾ÍÒѸ´Ô­²¢³ÁÆôÁËóÒ׻¡£¡£¡£ ¡£¡£¡£HiveÔÚ2021Äê¹¥»÷ÁËÖÁÉÙ28¸öÒ½ÁÆ»ú¹¹£¬£¬£¬£¬£¬ £¬»ñµÃÁËFBIµÄ³Áµã¹Ø×¢¡£¡£¡£ ¡£¡£¡£


https://www.itsecurityguru.org/2022/02/14/major-car-dealer-suffers-ransomware-attack/


FortiGuard°ä²¼½üÆÚ·Ö·¢BitRATµÄ»î¶¯µÄ·ÖÎö»ã±¨


2ÔÂ14ÈÕ£¬£¬£¬£¬£¬ £¬FortiGuard Labs°ä²¼Á˹ØÓÚ·Ö·¢BitRATµÄ»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£ ¡£¡£¡£Õâ´Î»î¶¯Ê¹ÓÃÁËÃûΪ¡°NFT_Items.xlsm¡±µÄExcelµç×Ó±í¸ñ£¬£¬£¬£¬£¬ £¬¸ÃÎļþÓÐÁ½¸ö¹¤×÷²¾£¬£¬£¬£¬£¬ £¬ÆäÖÐÒ»¸öÊÇÏ£²®À´ÓïµÄ¡£¡£¡£ ¡£¡£¡£¸Ã¶ñÒâÎļþÒÔ²»³É´úÌæ´ú±Ò(NFT)ÓйØÐÅϢΪµö¶ü£¬£¬£¬£¬£¬ £¬Ô̺¬Ò»¸ö¶ñÒâºê£¬£¬£¬£¬£¬ £¬¿ÉʹÓÃPowerShell¾ç±¾´ÓDiscordÏÂÔØÁíÒ»¸öÎļþNFTEXE.exe£¬£¬£¬£¬£¬ £¬×îÖÕ½«×°ÖÃÔ¶³Ì½Ó¼ûľÂíBitRAT¡£¡£¡£ ¡£¡£¡£


https://www.fortinet.com/blog/threat-research/nft-lure-used-to-distribute-bitrat


°²È«¹¤¾ß


Droopescan


Ò»ÖÖ»ùÓÚ²å¼þµÄɨÃ跨ʽ£¬£¬£¬£¬£¬ £¬¿ÉÔ®ÊÖ°²È«×êÑÐÈËÔ±¼ø±ð¶à¸ö CMS µÄÎÊÌâ¡£¡£¡£ ¡£¡£¡£


https://github.com/SamJoan/droopescan


AutoTimeliner


´ÓÒ×ʧÐÔÄÚ´æ×ª´¢ÖÐ×Ô¶¯Ìáȡȡ֤¹¦·òÏß¡£¡£¡£ ¡£¡£¡£


https://github.com/andreafortuna/autotimeliner


truffleHog


ͨ¹ý git ´æ´¢¿âËÑË÷ÃÜÂ룬£¬£¬£¬£¬ £¬Éî¿ÌÍÚ¾òÌá½»º¹ÇàºÍ·ÖÖ§£¬£¬£¬£¬£¬ £¬Õâ¶ÔÓÚ·¢ÏÖÒâ±íÌá½»µÄÃÜÂ뼫¶ÈÓÐЧ¡£¡£¡£ ¡£¡£¡£


https://github.com/trufflesecurity/truffleHog


WarFox


»ùÓÚÈí¼þµÄ HTTPS Ðűê Windows Ö²È뷨ʽ£¬£¬£¬£¬£¬ £¬ËüʹÓöà²ã´úÀíÍøÂç½øÐÐ C2 ͨѶ¡£¡£¡£ ¡£¡£¡£


https://github.com/FULLSHADE/WarFox


Melody


ΪÍþвµý±¨¶ø¹¹½¨µÄͨÃ÷»¥ÁªÍø´«¸ÐÆ÷£¬£¬£¬£¬£¬ £¬¿ÉÏóÕ÷¸ÐÐËÖµÄÊý¾Ý°üÒÔ½øÇ°½øÒ»²½·ÖÎöºÍÍþв¼à¿Ø¡£¡£¡£ ¡£¡£¡£


https://bonjourmalware.github.io/melody/



°²È«·ÖÎö


QNAP ΪһЩ²»ÊÜÖ§³ÖµÄ NAS É豸À©´ó¹Ø¼ü¸üÐÂ


https://www.bleepingcomputer.com/news/security/qnap-extends-critical-updates-for-some-unsupported-nas-devices/


Kali Linux 2022.1 °ä²¼£¬£¬£¬£¬£¬ £¬Ô̺¬ 6 ¸öй¤¾ß¡¢SSH ¿í·º¼æÈݵÈ


https://www.bleepingcomputer.com/news/security/kali-linux-20221-released-with-6-new-tools-ssh-wide-compat-and-more/


FTC ÖÒ¸æ VoIP ÌṩÉÌ£º·ÖÏí robocall ÐÅÏ¢»ò±»¸æ×´


https://www.bleepingcomputer.com/news/security/ftc-warns-voip-providers-share-your-robocall-info-or-get-sued/


KlaySwap Óû§ÔÚ BGP ½Ù³ÖºóËðʧ×ʽð


https://therecord.media/klayswap-crypto-users-lose-funds-after-bgp-hijack/


ÀûÓà Ghostbuster ¹¤¾ß½â³ýµ¯ÐÔ IP ÊÕÊÜ


https://blog.assetnote.io/2022/02/13/dangling-eips/