ÃÀ¹úCISA°ä²¼2022ÄêÃâ·ÑÍøÂ簲ȫ¹¤¾ßºÍ·þÎñÇåµ¥

°ä²¼¹¦·ò 2022-02-22

ÃÀ¹úCISA°ä²¼2022ÄêÃâ·ÑÍøÂ簲ȫ¹¤¾ßºÍ·þÎñÇåµ¥


2ÔÂ18ÈÕ£¬£¬£¬ £¬£¬ £¬ÃÀ¹úCISA¼ÙÔì²¢°ä²¼ÁË2022ÄêÃâ·ÑÍøÂ簲ȫ¹¤¾ßºÍ·þÎñÇåµ¥£¬£¬£¬ £¬£¬ £¬Ö¼ÔÚÔ®ÊÖ×éÖ¯¿ÉÄÜÓÐЧ»º½â¡¢¼ì²âºÍÏìÓ¦¶ñÒâ¹¥»÷¡£¡£¡£ ¡£¡£¸ÃÇåµ¥µÄ×ÊÔ´ÖÐÐÄÔ̺¬CISAÌṩµÄ101Ïî·þÎñ¡¢¿ªÔ´·¨Ê½ÒÔ¼°ÆäËü×éÖ¯ÌṩµÄ¹¤¾ß¡£¡£¡£ ¡£¡£´Ë±í£¬£¬£¬ £¬£¬ £¬¸Ã»ú¹¹»¹ÍƳöÁËרÃŵÄÍøÕ¾£¬£¬£¬ £¬£¬ £¬ÓÃÀ´¼Í¼Òѱ»ÀûÓõķì϶¡¢¡°Ò쳣ΣÏÕ¡±µÄ°²È«·¨Ê½¡¢ÕмÜÀÕË÷Èí¼þµÄÖ¸ÄÏÒÔ¼°ÆäËüÍþв¡£¡£¡£ ¡£¡£


https://www.cisa.gov/uscert/ncas/current-activity/2022/02/18/cisa-compiles-free-cybersecurity-services-and-tools-network


WordPress UpdraftPlusËÁÒâÎļþÏÂÔØCVE-2022-0633 


¾ÝýÌå2ÔÂ19ÈÕ±¨Â·£¬£¬£¬ £¬£¬ £¬WordPressµÄ²å¼þUpdraftPlusÖдæÔÚËÁÒâÎļþÏÂÔØ·ì϶£¨CVE-2022-0633£©¡£¡£¡£ ¡£¡£µÍȨÏÞÓû§¿ÉÀûÓÃÆäÀ´ÏÂÔØÍøÕ¾µÄ×îб¸·Ý£¬£¬£¬ £¬£¬ £¬³É¹¦ÀûÓú󣬣¬£¬ £¬£¬ £¬¹¥»÷Õ߿ɽӼûÖ¸±êÍøÕ¾Êý¾Ý¿âÖеÄÌØÈ¨ÐÅÏ¢£¬£¬£¬ £¬£¬ £¬ÈçÓû§ÃûºÍÃÜÂë¡£¡£¡£ ¡£¡£¸Ã·ì϶´æÔÚÓÚUpdraftPlus°æ±¾1.16.7ÖÁ1.22.2ÖУ¬£¬£¬ £¬£¬ £¬Ä¿Ç°£¬£¬£¬ £¬£¬ £¬WordPressÒÑÔÚ300¶àÍò¸öÊÜÓ°ÏìµÄÍøÕ¾ÖÐÇ¿Ôì×°ÖÃÁËUpdraftPlus²¹¶¡¡£¡£¡£ ¡£¡£


https://securityaffairs.co/wordpress/128170/hacking/updraftplus-forced-update.html


ÒÁÀÊTunnelVisionÀûÓÃLog4Shell·ì϶¹¥»÷Öж«ºÍÃÀ¹ú


SentinelLabsÔÚ2ÔÂ17ÈÕ°ä²¼»ã±¨£¬£¬£¬ £¬£¬ £¬¸ÅÊöÁËÒÁÀÊAPT×éÖ¯TunnelVisionÕë¶ÔÖж«ºÍÃÀ¹úµÄ¹¥»÷»î¶¯¡£¡£¡£ ¡£¡£TunnelVision»î¶¯µÄÌØµãÊǸü¶àµØÀûÓÃ1 day·ì϶£¬£¬£¬ £¬£¬ £¬ÀýÈçFortinet FortiOS(CVE-2018-13379)¡¢Microsoft Exchange(ProxyShell)ºÍLog4Shell·ì϶¡£¡£¡£ ¡£¡£´Ë±í£¬£¬£¬ £¬£¬ £¬¸ÃÍŻK¶ÈÒÀÀµËí·¹¤¾ß£¬£¬£¬ £¬£¬ £¬Ëü×î³£ÓõÄÊǼ±¾ç·´Ïò´úÀí¿Í»§¶Ë(FRPC)ºÍPlink¡£¡£¡£ ¡£¡£×êÑÐÈËÔ±»¹Åû¶Á˸ÃÍÅ»ïÀûÓÃLog4Shell¹¥»÷VMware Horizon·þÎñÆ÷µÄ¼¼Êõϸ½Ú¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/iranian-hackers-target-vmware-horizon-servers-with-log4j-exploits/


Avanan³Æ¹¥»÷ÕßÀûÓÃTeamsÕë¶ÔýÌåÐÐÒµ·Ö·¢¶ñÒâÈí¼þ


2ÔÂ17ÈÕ£¬£¬£¬ £¬£¬ £¬Avanan°ä²¼»ã±¨³Æ¹¥»÷ÕßÀûÓÃTeamsÕë¶ÔýÌåÐÐÒµ·Ö·¢¶ñÒâÈí¼þ¡£¡£¡£ ¡£¡£Ëæ×ÅMicrosoft TeamsÔ½À´Ô½ÊÜ»¶Ó­£¨Ã¿Ô»îÔ¾Óû§Ô¼Îª2.7ÒÚ£©£¬£¬£¬ £¬£¬ £¬¸ü¶àµÄ¹¥»÷Õ߯ðÍ·½«ÆäÓÃ×÷¹¥»÷ý½é¡£¡£¡£ ¡£¡£ÕâЩ¹¥»÷ÆðÍ·ÓÚ2022Äê1Ô£¬£¬£¬ £¬£¬ £¬´ÓÏÖº±¼û¾ÝÀ´¿´´óÎÞÊý¹¥»÷²úÉúÔÚÃÀ¹úÎå´óºþµØÓò£¬£¬£¬ £¬£¬ £¬ÖØÒªÕë¶Ô±¾µØÃ½Ìå»ú¹¹¡£¡£¡£ ¡£¡£¾ÝϤ£¬£¬£¬ £¬£¬ £¬¹¥»÷Õß»áÔÚ̸ÌìÖзַ¢¿ÉÖ´ÐÐÎļþ¡°User Centric¡±²¢ÓÕʹÓû§ÔËÐÐËü¡£¡£¡£ ¡£¡£Ò»µ©Ö´ÐУ¬£¬£¬ £¬£¬ £¬¶ñÒâÈí¼þ»á½«Êý¾ÝдÈëϵͳע²á±í¡¢×°ÖÃDLL²¢ÔÚWindowsÉϳÉÁ¢ÓƾÃÐÔ¡£¡£¡£ ¡£¡£


https://www.avanan.com/blog/hackers-attach-malicious-.exe-files-to-teams-conversations


ASEC·¢ÏÖPseudoManuscryptÕë¶Ôº«¹úµÄ¹¥»÷»î¶¯


ASECÔÚ2ÔÂ18ÈÕ±¨Â·³Æ£¬£¬£¬ £¬£¬ £¬×Ô2021Äê5ÔÂÒÔÀ´£¬£¬£¬ £¬£¬ £¬º«¹úµÄºÜ¶àWindowsÉ豸¶¼³ÉΪÁËPseudoManuscryptµÄÖ¸±ê¡£¡£¡£ ¡£¡£¶ñÒâÈí¼þ¼Ù×°³ÉÀàËÆÓÚCryptbotµÄ×°Ö÷¨Ê½£¬£¬£¬ £¬£¬ £¬ÇÒµ±Óû§ËÑË÷CrackºÍKeygenµÈÈí¼þÓйص폷¨ÀûÓÃʱ£¬£¬£¬ £¬£¬ £¬Ëü»¹»áͨ¹ýËÑË÷Ò³ÃæÊ×Ò³µÄ¶ñÒâÍøÕ¾½øÐзַ¢¡£¡£¡£ ¡£¡£¸Ã»î¶¯Ä¿Ç°ÈÔÔÚ½øÐÐÖУ¬£¬£¬ £¬£¬ £¬¸Ã¹úÿÌì¾ùÔÈÈÔÓÐ30¶ą̀µçÄÔ±»Ï°È¾¡£¡£¡£ ¡£¡£¸Ã¶ñÒâÈí¼þÓÚ2021Äê12Ô³õ´Î±»·¢ÏÖ£¬£¬£¬ £¬£¬ £¬Ï°È¾ÁËÈ«Çò195¸ö¹ú¶ÈµÄ35000¶ą̀µçÄÔ¡£¡£¡£ ¡£¡£


https://asec.ahnlab.com/en/31683/


Element VapeÔâµ½Magecart¹¥»÷Óû§ÐÅÓþ¿¨ÐÅϢй¶


ýÌå2ÔÂ18Èճƣ¬£¬£¬ £¬£¬ £¬´óÐ͵ç×ÓÑÌÍøÉÏÉ̵êElement VapeÔâµ½Magecart¹¥»÷¡£¡£¡£ ¡£¡£×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬ £¬£¬ £¬ÍøÕ¾µÄ¶à¸öÍøÒ³´æÔÚÒ»¶Îbase64±àÂë¾ç±¾£¬£¬£¬ £¬£¬ £¬½âÂëºó·¢ÏÖËü»áÔÚµÚÈý·½ÍøÕ¾ÏÂÔØÒ»¸öJavaScriptÎļþ£¬£¬£¬ £¬£¬ £¬Ö¼ÔÚµ±Óû§½áÕËÊ±ÍøÂçÆäÖ§¸¶¿¨ºÍÕ˵¥ÐÅÏ¢£¬£¬£¬ £¬£¬ £¬¶øºó½«ÐÅϢͨ¹ýTelegram·¢Ë͸ø¹¥»÷Õß¡£¡£¡£ ¡£¡£Ä¿Ç°Éв»Ã÷ÏԸöñÒâ¾ç±¾´æÔڶ೤¹¦·ò£¬£¬£¬ £¬£¬ £¬µ«Element VapeÏÖÒѽ¨¸´´ËÎÊÌâ¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/popular-e-cigarette-store-was-compromised-to-steal-credit-cards/



°²È«¹¤¾ß


Njsscan


ÓïÒå¸ÐÖª SAST ¹¤¾ß£¬£¬£¬ £¬£¬ £¬Äܹ»ÔÚ Node.js ÀûÓ÷¨Ê½ÖÐÕÒµ½²»°²È«µÄ´úÂëģʽ¡£¡£¡£ ¡£¡£


https://github.com/ajinabraham/njsscan


Snaffler


ÊÇÒ»¸ö¹©ÉøÈë²âÊÔÕßʹÓõŤ¾ß¡£¡£¡£ ¡£¡£


https://github.com/SnaffCon/Snaffler


KrbRelay


ÖмÌKerberosƱ֤µÄΨһ¹«¹²¹¤¾ßºÍΨһÓà C# ±àдµÄÖм̿ò¼Ü¡£¡£¡£ ¡£¡£


https://securityonline.info/krbrelay-relaying-kerberos-tickets/


Zircolite


Zircolite ÊÇÓà Python 3 ±àдµÄ¶ÀÁ¢¹¤¾ß£¬£¬£¬ £¬£¬ £¬ÔÚ MS Windows EVTX£¨EVTX ºÍ JSON Ìåʽ£©ÉÏʹÓÃSIGMA¹æ¶¨¡£¡£¡£ ¡£¡£


https://github.com/wagga40/Zircolite


presshell


¿ÉÓÃÀ´ÔÚ wordpress ·þÎñÆ÷ÉÏÖ´ÐÐ shell ºÅÁî¡£¡£¡£ ¡£¡£


https://github.com/scheatkode/presshell


°²È«·ÖÎö


Google Drive ½« macOS µÄ¡°.DS_Store¡±ÎļþÏóÕ÷Ϊ¼Óº¦°æÈ¨


https://www.bleepingcomputer.com/news/security/google-drive-flags-macos-ds-store-files-for-copyright-violation/


Windows 11 µÄй¤×÷ÖÎÀíÆ÷


https://www.bleepingcomputer.com/news/microsoft/closer-look-at-windows-11s-new-task-manager/


NSA °ä²¼Ñ¡ÔñÇ¿ Cisco ÃÜÂëÀàÐ͵ÄÖ¸ÄÏ


https://www.darkreading.com/vulnerabilities-threats/nsa-issues-guidance-for-selecting-strong-cisco-password-types


Ó¢ÌØ¶ûÈí¼þºÍ¹Ì¼þ¸üв¹¶¡ 18 ¸ßÑϳÁÐÔ·ì϶


https://www.securityweek.com/intel-software-and-firmware-updates-patch-18-high-severity-vulnerabilities


CISAÖÒ¸æÕë¶ÔÃÀ¹ú¹Ø¼ü»ù´¡ÉèÊ©µÄÍþв


https://www.cisa.gov/uscert/ncas/current-activity/2022/02/18/cisa-insights-foreign-influence-operations-targeting-critical


΢Èí°ä·¢Îª Windows Server Azure Ðé¹¹»úÌṩÈȲ¹¶¡


https://www.bleepingcomputer.com/news/microsoft/microsoft-announces-hotpatching-for-windows-server-azure-vms/