JFrog·¢ÏÖClickHouse DBMSÖеÄ7¸öRCEºÍDoS·ì϶
°ä²¼¹¦·ò 2022-03-21JFrog·¢ÏÖClickHouse DBMSÖеÄ7¸öRCEºÍDoS·ì϶
JFrog×êÑÐÍŶÓÔÚ3ÔÂ15ÈÕ°ä²¼»ã±¨£¬£¬£¬£¬£¬£¬ÏêÊöÁË¿ªÔ´Êý¾Ý¿âÖÎÀíϵͳClickHouseÖеÄ7¸ö·ì϶¡£¡£¡£¡£¡£ÆäÖÐÔ̺¬Äܹ»µ¼Ö´úÂëÖ´ÐеĶѻº³åÇøÒç¶Âí½Å£¨CVE-2021-43304ºÍCVE-2021-43305£©£»£»£»£»£»£»¿Éµ¼Ö»ؾø·þÎñ»òÐÅϢй¶µÄ¶ÑÔ½½ç·ì϶£¨CVE-2021-42387ºÍCVE-2021-42388£©£»£»£»£»£»£»ÒÔ¼°DoS·ì϶£¨CVE-2021-42389¡¢CVE-2021-42390ºÍCVE-2021-42391£©¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Í¨¹ýʹÓöñÒâµÄѹËõÎļþÀûÓÃÉÏÊöËÁÒâ·ì϶£¬£¬£¬£¬£¬£¬Ôì³ÉÊý¾Ý¿â·þÎñÆ÷±ÀÀ££¬£¬£¬£¬£¬£¬½¨ÒéÓû§Éý¼¶µ½v21.10.2.15-stable»ò¸ü¸ß°æ±¾ÒÔ½¨¸´·ì϶¡£¡£¡£¡£¡£
×êÑÐÈËÔ±Åû¶CRI-OÖзì϶cr8escapeµÄ¾ßÌåÐÅÏ¢
3ÔÂ15ÈÕ£¬£¬£¬£¬£¬£¬CrowdStrikeÍŶÓÅû¶ÁËCRI-OÖзì϶cr8escape£¨CVE-2022-0811£©µÄ¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£CRI-OÊÇÒ»¸öÇáÁ¿¼¶µÄ£¬£¬£¬£¬£¬£¬×¨ÃŶÔKubernetes½øÐÐÓÅ»¯µÄÈÝÆ÷ÔËÐÐʱ»·¾³¡£¡£¡£¡£¡£¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.8£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±°µÊ¾Ëü¿É±»ÓÃÀ´Èƹý±£»£»£»£»£»£»¤´ëÊ©²¢ÔÚÖ¸±êÖ÷»úÉÏÉèÖÃËÁÒâÄں˲ÎÊý£¬£¬£¬£¬£¬£¬ÈκÎÓÐȨÔÚʹÓÃCRI-OµÄKubernetesÉϲ¿ÊðpodµÄ¹¥»÷Õß¶¼Äܹ»ÀÄÓÃkernel.core_pattern²ÎÊý£¬£¬£¬£¬£¬£¬ÔÚËÁÒâ½ÚµãÉÏÒÔrootȨÏÞ½øÐÐÈÝÆ÷ÌÓÒݺÍÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¸Ã·ì϶ÒÑÔÚ3ÔÂ15ÈÕ°ä²¼µÄ1.23.2°æ±¾Öн¨¸´¡£¡£¡£¡£¡£
https://thehackernews.com/2022/03/new-vulnerability-in-cri-o-engine-lets.html
Emotet»Ø¹é£¬£¬£¬£¬£¬£¬¼ÙÒâÃÀ¹ú¹ú˰¾Ö·¢ËÍ´óÁ¿´¹µöÓʼþ
¾ÝýÌå3ÔÂ16Èճƣ¬£¬£¬£¬£¬£¬Óʼþ°²È«¹«Ë¾Cofense·¢ÏÖEmotetÐÂÒ»ÂֵĴ¹µö»î¶¯¡£¡£¡£¡£¡£ÃÀ¹úĿǰÕýÖµ±¨Ë°¼¾£¬£¬£¬£¬£¬£¬¹¥»÷Õß¼ÙÒ⻥ÁªÍøË°Îñ¾Ö(IRS.gov)£¬£¬£¬£¬£¬£¬ÏòÖ¸±ê·¢ËÍ2021ÄêÄÉ˰É걨±í¡¢W-9±í¸ñºÍ±¨Ë°ÆÚ¼ä³£ÓÃµÄÆäËü˰ÎñÎļþ¡£¡£¡£¡£¡£Ö¸±êÖ´Ðи½¼þÖÐÔ̺¬¶ñÒâºêµÄµö¶üÎļþºó£¬£¬£¬£¬£¬£¬»áÏÂÔØ²¢×°ÖÃEmotet¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ»áÏÂÔØ¶î±íµÄpayload£¬£¬£¬£¬£¬£¬Ô̺¬Cobalt StrikeºÍÔ¶³Ì½Ó¼ûľÂíSystemBCµÈ¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬¸½¼þÖеÄzipÎļþÊÜÃÜÂë±£»£»£»£»£»£»¤£¬£¬£¬£¬£¬£¬Òò¶øºÜÄѱ»°²È«ÓʼþÍø¹Ø¼ì²âµ½¡£¡£¡£¡£¡£
https://www.cyberscoop.com/cofense-emotet-irs-phishing/
AhnLab°ä²¼CirenegRAT½üÆÚ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨
AhnLabÔÚ3ÔÂ16ÈÕ°ä²¼Ò»·Ýл㱨£¬£¬£¬£¬£¬£¬¸ÅÊöÁËGhostCringeÈôºÎÕë¶ÔÒ×Êܹ¥»÷µÄÊý¾Ý¿â·þÎñÆ÷¡£¡£¡£¡£¡£GhostCringeÒ²³ÆÎªCirenegRAT£¬£¬£¬£¬£¬£¬ÊÇ»ùÓÚGh0st RATµÄ´úÂëµÄ¶ñÒâÈí¼þÖ®Ò»£¬£¬£¬£¬£¬£¬ÓÚ2018Äê12Ô³õ´Î±»·¢ÏÖ£¬£¬£¬£¬£¬£¬Í¨¹ýSMB·ì϶½øÐзַ¢¡£¡£¡£¡£¡£Õâ´Î»î¶¯ÖØÒª¶Ô×¼MS-SQLºÍMySQL·þÎñÆ÷£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓùý³Ìmysqld.exe¡¢mysqld-nt.exeºÍsqlserver.exe½«¶ñÒâµÄmcsql.exe¿ÉÖ´ÐÐÎļþдÈë´ÅÅÌ¡£¡£¡£¡£¡£
https://asec.ahnlab.com/en/32572/
Sophos°ä²¼¹ØÓÚCryptoRomÐÂÒ»ÂÖ¹¥»÷µÄ·ÖÎö»ã±¨
3ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬Sophos°ä²¼Á˹ØÓÚCryptoRomÕë¶ÔiPhoneºÍAndroidÓû§µÄ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£CryptoRomÓÚ2021Äê³õ´Î±»Åû¶£¬£¬£¬£¬£¬£¬ÊÇÒ»¸öÔÚÑÇÖÞ¡¢ÃÀ¹úºÍÅ·ÖÞ»îÔ¾µÄ¹ú¼ÊÚ¿ÆÍŻ¡£¡£¡£¡£×êÑаµÊ¾£¬£¬£¬£¬£¬£¬CryptoRomÒѾ¸Ä½øÁ˼¼Êõ£¬£¬£¬£¬£¬£¬ËûÃÇÀûÓÃiOSÖ°ÄÜTestFlightºÍWebClips£¬£¬£¬£¬£¬£¬ÈƹýÑϸñµÄÉóÅúÁ÷³Ì½«¶ñÒâÀûÓÃ×°ÖÃÔÚÖ¸±êµÄÊÖ»úÉÏ¡£¡£¡£¡£¡£»ã±¨³Æ£¬£¬£¬£¬£¬£¬³É¹¦µÄCryptoRom¹¥»÷»î¶¯¿ÉÄܸøÖ¸±êÔì³ÉÎåλÊý¡¢ÁùλÊýÉõÖÁÆßλÊýµÄËðʧ¡£¡£¡£¡£¡£
https://news.sophos.com/en-us/2022/03/16/cryptorom-bitcoin-swindlers-continue-to-target-vulnerable-iphone-and-android-users/
»ªË¶³ÆÆä¶à¿î·ÓÉÆ÷Ò×ÊÜCyclops BlinkµÄ¹¥»÷
»ªË¶£¨ASUS£©ÔÚ3ÔÂ17ÈÕ°ä²¼°²È«¹«¸æ£¬£¬£¬£¬£¬£¬³ÆÆä¶à¿î·ÓÉÆ÷Ò×ÊÜCyclops BlinkµÄ¹¥»÷¡£¡£¡£¡£¡£Ç÷Ïò¿Æ¼¼°µÊ¾¸Ã¶ñÒâÈí¼þÓÐÒ»¸öרÃÅÕë¶Ô»ªË¶Â·ÓÉÆ÷µÄÄ£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬¿É¶ÁÈ¡ÉÁ´æÀ´ÍøÂçÓйØÎļþ¡¢¿ÉÖ´ÐÐÎļþ¡¢Êý¾ÝºÍ¿âµÄÐÅÏ¢¡£¡£¡£¡£¡£¶øºó£¬£¬£¬£¬£¬£¬Ëü»áÔÚÉÁ´æÖгÉÁ¢Óƾû¯£¬£¬£¬£¬£¬£¬¼´±ã¸´Ô³ö³§ÉèÖÃÒ²²»»áɾ³ý¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬»ªË¶ÉÐδ°ä²¼ÐµĹ̼þ¸üÐÂÒÔÕмÜCyclops BlinkµÄ¹¥»÷£¬£¬£¬£¬£¬£¬µ«°ä²¼ÁËÓÃÓÚ±£»£»£»£»£»£»¤É豸µÄ»º½â´ëÊ©¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/asus-warns-of-cyclops-blink-malware-attacks-targeting-routers/
°²È«¹¤¾ß
RefleXXion
ÊÇÒ»¸öʵÓ÷¨Ê½£¬£¬£¬£¬£¬£¬Ö¼ÔÚÔ®ÊÖÈÆ¹ý AV/EPP/EDR µÈʹÓõÄÓû§Ä£Ê½hook¡£¡£¡£¡£¡£
https://github.com/hlldz/RefleXXion
LDAP shell
Õâ¸ö´æ´¢¿âÔ̺¬Ò»¸ö´Ó ldap_shell ¼Ì³ÐµÄÓ×¹¤¾ß¡£¡£¡£¡£¡£
https://github.com/z-Riocool/ldap_shell/
Viper
ÊÇÒ»¸öͼÐλ¯µÄÄÚÍøÉøÈ빤¾ß¡£¡£¡£¡£¡£
https://github.com/FunnyWolf/Viper
Nivistealer
ÓÃÓÚÇÔȡָ±êͼÏñ¼òÖ±ÇеØÎ»É豸ÐÅÏ¢µÈµÈ¡£¡£¡£¡£¡£
https://github.com/swagkarna/Nivistealer
°²È«·ÖÎö
¶íÂÞ˹ʹÓÃÎÚ¿ËÀ¼×ÜͳµÄdeepfake°ä²¼ÐéαÐÅÏ¢
https://securityaffairs.co/wordpress/129124/intelligence/russia-deepfake-video-zelenskyy.html
΢ÈíÆô¶¯ 2022 Äê 3 Ô Windows 11 Bug Bash
https://news.softpedia.com/news/microsoft-kicks-off-the-march-2022-bug-bash-for-windows-11-535050.shtml
Cobalt Strike ·ÖÎöºÍ½Ì³Ì
https://unit42.paloaltonetworks.com/cobalt-strike-malleable-c2-profile/
¼Ù×°³É²úÆ·½éÉܵĶñÒâWordÎļþ
https://asec.ahnlab.com/en/32609/
Ò»ÌìÄÚÊý°Ù¸öÍйÜÔÚGoDaddyµÄÍøÕ¾Ôâµ½ºóÃŹ¥»÷
https://www.wordfence.com/blog/2022/03/increase-in-malware-sightings-on-godaddy-managed-hosting/
Zimperium °ä²¼ÁËÆäÄê¶ÈÒÆ¶¯Íþв»ã±¨
https://www.bleepingcomputer.com/news/security/2021-mobile-security-android-more-vulnerabilities-ios-more-zero-days/


¾©¹«Íø°²±¸11010802024551ºÅ