ÍøÐŰ졶»¥ÁªÍøµ¯´°ÐÅÏ¢ÍÆËÍ·þÎñÖÎÀí»®¶¨£¨Õ÷Ç󶨼û¸å£©¡·

°ä²¼¹¦·ò 2022-03-07

ÍøÐŰ졶»¥ÁªÍøµ¯´°ÐÅÏ¢ÍÆËÍ·þÎñÖÎÀí»®¶¨£¨Õ÷Ç󶨼û¸å£©¡·


3ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬ £¬¹ú¶È»¥ÁªÍøÐÅÏ¢°ì¹«ÊÒ°ä²¼Á˹ØÓÚ¡¶»¥ÁªÍøµ¯´°ÐÅÏ¢ÍÆËÍ·þÎñÖÎÀí»®¶¨£¨Õ÷Ç󶨼û¸å£©¡·¹«¿ªÕ÷Ç󶨼ûµÄ֪ͨ ¡£ ¡£¡£¡£¡£¡£¡£¡£Í¨ÖªÖ¸³ö£¬£¬£¬£¬£¬£¬ £¬Îª¹æ·¶»¥ÁªÍøµ¯´°ÐÅÏ¢ÍÆËÍ·þÎñ£¬£¬£¬£¬£¬£¬ £¬ÊØ»¤¹ú¶È°²È«ºÍ¹«¹²ÀûÒæ£¬£¬£¬£¬£¬£¬ £¬Æ¾¾Ý¡¶ÖлªÈËÃñ¹²ºÍ¹úÍøÂ簲ȫ·¨¡·µÈ˾·¨ÂɹæÔì¶©Á˱¾»®¶¨ ¡£ ¡£¡£¡£¡£¡£¡£¡£ÔÚ¾³ÄÚÌṩ²Ù×÷ϵͳ¡¢ÖÕ¶ËÉ豸¡¢ÀûÓÃÈí¼þ¡¢ÍøÕ¾µÈ·þÎñµÄ£¬£¬£¬£¬£¬£¬ £¬·¢Õ¹»¥ÁªÍøµ¯´°ÐÅÏ¢ÍÆËÍ·þÎñʱ¸Ãµ±×ñÊØ±¾»®¶¨ ¡£ ¡£¡£¡£¡£¡£¡£¡£


http://www.cac.gov.cn/2022-03/02/c_1647826956995841.htm


Unit 42³Æ10Íò¶à¸öÊäÒº±ÃÒ×ÊܶàÄêǰµÄÊý¸ö·ì϶ӰÏì


3ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬ £¬Unit 42°ä²¼»ã±¨³ÆÆäÉó²éÁË200000¶à¸öÉ豸£¬£¬£¬£¬£¬£¬ £¬²¢·¢ÏÔìäÖÐ75%´æÔÚ¶àÄêǰµÄ·ì϶ ¡£ ¡£¡£¡£¡£¡£¡£¡£×îÆÕ±éµÄÊÇǶÈëʽÉ豸µÄVxWorksʵʱ²Ù×÷ϵͳ(RTOS)ÖеÄÄÚ´æ°Ü»µ·ì϶£¨CVE-2019-12255£¬£¬£¬£¬£¬£¬ £¬CVSSÆÀ·Ö9.8£©£¬£¬£¬£¬£¬£¬ £¬´æÔÚÓÚ52%µÄ²úÆ·ÖУ¨104000¶ą̀)£¬£¬£¬£¬£¬£¬ £¬ÒÑÓÚ2019Äê7ÔÂ19ÈÕ±»½¨¸´ ¡£ ¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬ £¬×êÑÐÈËÔ±»¹·¢ÏÖÁËCVE-2020-12040¡¢CVE-2020-12045ºÍCVE-2020-12047µÈ¶à¸öÔÚ2019ÄêºÍ2020Äê¾Í±»Åû¶µÄ·ì϶ ¡£ ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/over-100-000-medical-infusion-pumps-vulnerable-to-years-old-critical-bug/


Proofpoint·¢ÏÖÐÂÒ»ÂÖ´¹µö»î¶¯Asylum Ambuscade


ProofpointÔÚ3ÔÂ1ÈÕ¹«¿ªÁËÐÂÒ»ÂÖ´¹µö»î¶¯Asylum AmbuscadeµÄ¾ßÌåÐÅÏ¢ ¡£ ¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯ÈëÇÖÁËÒ»¸öÎÚ¿ËÀ¼Îä×°¶ÓÁÐÔ±¹¤µÄÓʼþÕÊ»§£¬£¬£¬£¬£¬£¬ £¬Ö¸±êÊDzμÓÖÎÀíÎÚ¿ËÀ¼ÄÑÃñºóÇÚ¹¤×÷µÄÈËÔ± ¡£ ¡£¡£¡£¡£¡£¡£¡£´¹µöÓʼþÀ´×Ôukr[.]net£¬£¬£¬£¬£¬£¬ £¬Ô̺¬Ò»¸ö¶ñÒâºê¸½¼þ£¬£¬£¬£¬£¬£¬ £¬Ö¼ÔÚ·Ö·¢¸öÃûΪSunSeedµÄ»ùÓÚLuaµÄ¶ñÒâÈí¼þ ¡£ ¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏָûÓë2021Äê7Ô°׶íÂÞ˹APT×éÖ¯GhostwriterÌáÒéµÄ¹¥»÷ÀàËÆ£¬£¬£¬£¬£¬£¬ £¬´§¶ÈÕâÁ½´Î¹¥»÷À´×Ôͳһ¹¥»÷Õß ¡£ ¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/128594/apt/asylum-ambuscade-phishing-campaign-ukraine.html


Salt Security°ä²¼¹ØÓÚAPI°²È«Ì¬ÊƵķÖÎö»ã±¨


3ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬ £¬Salt Security°ä²¼Á˹ØÓÚAPI°²È«Ì¬ÊƵķÖÎö»ã±¨ ¡£ ¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬ £¬2021ÄêAPI¹¥»÷Á÷Á¿Ôö³¤ÁË681%£¬£¬£¬£¬£¬£¬ £¬¶øÕûÌåAPIÁ÷Á¿Ôö³¤ÁË321% ¡£ ¡£¡£¡£¡£¡£¡£¡£¸Ã×êÑжÔÀ´×Ô·ÖÆç¹æÄ£¹«Ë¾µÄ250ÃûÔ±¹¤µÄ½øÐе÷²é£¬£¬£¬£¬£¬£¬ £¬·¢ÏÖ34%µÄ¹«Ë¾²»×ãAPI°²È«Õ½Êõ£¬£¬£¬£¬£¬£¬ £¬83%ÊÜ·ÃÕß¶ÔËûÃǵÄÏÖÓÐAPIÖ°Äܲ»×ãÐÅÐÄ£¬£¬£¬£¬£¬£¬ £¬95%µÄÊÜ·ÃÕß°µÊ¾ÔÚÈ¥Äê¾­Àú¹ýAPI°²È«ÊÂÎñ£¬£¬£¬£¬£¬£¬ £¬85%µÄÊÜ·ÃÕßÖ¸³öµ±Ç°µÄ¹¤¾ßÎÞ·¨ÓÐЧ×èÖ¹API¹¥»÷ ¡£ ¡£¡£¡£¡£¡£¡£¡£


https://salt.security/press-releases/salt-security-state-of-api-security-report-reveals-api-attacks-increased-681-in-the-last-12-months?


Barracuda°ä²¼Log4Shell·ì϶ÀûÓûµÄ×êÑл㱨


Barracuda·ÖÎöÁË×Ô2021Äê12ÔÂ10ÈÕÒÔÀ´¼ì²âµ½µÄ¹¥»÷ºÍpayload£¬£¬£¬£¬£¬£¬ £¬²¢ÓÚ3ÔÂ2ÈÕ°ä²¼ÁËLog4Shell·ì϶ÀûÓûµÄ»ã±¨ ¡£ ¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬ £¬´óÎÞÊýÀûÓó¢ÊÔÀ´×ÔÃÀ¹ú£¬£¬£¬£¬£¬£¬ £¬Æä´ÎÊÇÈÕ±¾¡¢ÖÐÅ·ºÍ¶íÂÞ˹ ¡£ ¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖÁ˶à¸öÀûÓø÷ì϶µÄpayload£¬£¬£¬£¬£¬£¬ £¬ÆäÖн©Ê¬ÍøÂçMirai¼°Æä±äÌåµÄÕ¼±È×î´ó£¬£¬£¬£¬£¬£¬ £¬Æä´ÎΪBillGates malware(DDoS)¡¢Kinsing(¼ÓÃÜ¿ó¹¤)¡¢XMRig(¼ÓÃÜ¿ó¹¤)ºÍMuhstik(DDoS) ¡£ ¡£¡£¡£¡£¡£¡£¡£»ã±¨»¹Ìá³öÓÐЧ·À±¸´ËÀ๥»÷µÄ×îµ¥Ò»²½ÖèÊǽ«Log4j¸üе½2.17.1»ò¸ü¸ß°æ±¾£¬£¬£¬£¬£¬£¬ £¬²¢È·±£ËùÓÐWebÀûÓô¦ÓÚ×îÐÂ״̬ ¡£ ¡£¡£¡£¡£¡£¡£¡£


https://blog.barracuda.com/2022/03/02/threat-spotlight-attacks-on-log4shell-vulnerabilities/     


×êÑÐÈËÔ±¹«¿ªLinuxÄÚºËÌáȨ·ì϶CVE-2022-0492µÄϸ½Ú


×êÑÐÈËÔ±ÔÚ3ÔÂ3ÈÕ¹«¿ªÁËLinuxÄÚºËÖеÄÌáȨ·ì϶£¨CVE-2022-0492£©µÄϸ½Ú ¡£ ¡£¡£¡£¡£¡£¡£¡£ËüÊÇLinux½ÚÔì×é(cgroups)ÖеÄÒ»¸öÂß¼­·ì϶£¬£¬£¬£¬£¬£¬ £¬´æÔÚÓÚ/cgroup/cgroup-v1.cº¯ÊýÖеÄcgroup_release_agent_write ¡£ ¡£¡£¡£¡£¡£¡£¡£ÔÚijЩÇé¿öÏ£¬£¬£¬£¬£¬£¬ £¬Æä¿É±»ÓÃÀ´Í¨¹ýcgroups v1µÄrelease_agent¸öÐÔÌáÉýȨÏÞ£¬£¬£¬£¬£¬£¬ £¬²¢ÈƹýÃû³Æ¿Õ¾àÀëÀë ¡£ ¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬ £¬¸Ã·ì϶ ÒÑÔÚ×îеÄLinux°æ±¾Öн¨¸´£¬£¬£¬£¬£¬£¬ £¬×êÑÐÈËÔ±½¨ÒéËùÓÐЧ»§Éý¼¶µ½×îа汾 ¡£ ¡£¡£¡£¡£¡£¡£¡£


https://unit42.paloaltonetworks.com/cve-2022-0492-cgroups/



°²È«¹¤¾ß


BruteShark


ÍøÂçȡ֤·ÖÎö¹¤¾ß (NFAT)£¬£¬£¬£¬£¬£¬ £¬Ëü¶ÔÍøÂçÁ÷Á¿£¨ÖØÒªÊÇ PCAP Îļþ£©½øÐÐÉî¶È´¦ÖúͲ鳭 ¡£ ¡£¡£¡£¡£¡£¡£¡£


https://github.com/odedshimon/BruteShark/


Checkov 


ÓÃÓÚ»ù´¡ÉèÊ©¼´´úÂëµÄ¾²Ì¬´úÂë·ÖÎö¹¤¾ß ¡£ ¡£¡£¡£¡£¡£¡£¡£


https://github.com/bridgecrewio/checkov


JNDI-Injection-Exploit


JNDI×¢ÈëÀûÓù¤¾ß£¬£¬£¬£¬£¬£¬ £¬ÌìÉúJNDIÁ´½Ó²¢Æô¶¯ºó¶ËÓйطþÎñ£¬£¬£¬£¬£¬£¬ £¬¿ÉÓÃÓÚFastjson¡¢JacksonµÈÓйطì϶µÄÑéÖ¤ ¡£ ¡£¡£¡£¡£¡£¡£¡£


https://github.com/welk1n/JNDI-Injection-Exploit



nrich v0.2


Ò»¸öºÅÁîÐй¤¾ß£¬£¬£¬£¬£¬£¬ £¬ÓÃÓÚ¼±¾ç·ÖÎöÎļþÖеÄËùÓÐ IP£¬£¬£¬£¬£¬£¬ £¬²¢²é¿´ÄÄЩӵÓÐÊ¢ÅüÍ·¿Ú/·ì϶ ¡£ ¡£¡£¡£¡£¡£¡£¡£


https://gitlab.com/shodan-public/nrich


fuzzuf


ÊÇÒ»¸ö´øÓÐ×Ô¼ºµÄ DSL µÄ fuzzing ¿ò¼Ü£¬£¬£¬£¬£¬£¬ £¬Í¨¹ý¹¹½¨ fuzzing Ô­ÓïµÄ¹¹½¨¿éÀ´ÃèÊöfuzzing Ñ­»· ¡£ ¡£¡£¡£¡£¡£¡£¡£


https://securityonline.info/fuzzuf-fuzzing-unification-framework/



°²È«·ÖÎö


΢Èí°ä·¢ºÏÓÃÓÚ Windows 11 µÄÐÂÀûÓð²È«Ö°ÄÜ


https://news.softpedia.com/news/microsoft-announces-new-app-security-feature-for-windows-11-534974.shtml



¶íÂÞ˹º½Ìì¾Ö³ÆºÚ¿Í¹¥»÷ÎÀÐÇÊÇÒ»ÖÖÕ½ÕùÐÐΪ


https://www.bleepingcomputer.com/news/security/russian-space-agency-says-hacking-satellites-is-an-act-of-war/



¹¥»÷ÕßÀûÓà Telegram ½øÐÐÓëì¶ÜÓйصĻ


https://blog.checkpoint.com/2022/03/02/telegram-becomes-a-digital-forefront-in-the-conflict/



Ó¢ÌØ¶ûµÄµÚ 12 ´ú Alder Lake ´¦ÖÃÆ÷²»Ô̺¬Î¢Èí Pluton 


https://www.theregister.com/2022/03/02/microsoft_pluton_chip/



Anonymous¼°Æä´ÓÊô»ú¹¹³ÖÐø¶Ô¶íÂÞ˹½øÐй¥»÷


https://securityaffairs.co/wordpress/128576/hacktivism/anonymous-causes-damages-to-russia.html