JFrog·¢ÏÖ200¶à¸öÕë¶ÔAzure¿ª·¢ÈËÔ±µÄ¶ñÒâNPM°ü
°ä²¼¹¦·ò 2022-03-28JFrog·¢ÏÖ200¶à¸öÕë¶ÔAzure¿ª·¢ÈËÔ±µÄ¶ñÒâNPM°ü
JFrogÔÚ3ÔÂ23ÈÕ°ä²¼»ã±¨³Æ£¬£¬£¬£¬£¬£¬£¬£¬·¢ÏÖÁËÖÁÉÙ218¸öÖ¼ÔÚÇÔÈ¡Ó×ÎÒÉí·ÝÐÅÏ¢µÄ¶ñÒâNPM°ü¡£¡£¡£¡£¡£¡£ÕâÊÇÕë¶ÔAzure¿ª·¢ÈËÔ±µÄ´ó¹æÄ£¹©¸øÁ´¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÃÁËÓòÃû·ÂðµÄ¹¥»÷·½Ê½£¬£¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃ×Ô¶¯¾ç±¾´´½¨ÕÊ»§²¢ÉÏ´«¶ñÒâ°ü£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¸²¸ÇÕâЩ¶ñÒâ°ü¶¼À´×Ôͳһ¿ª·¢ÕßµÄÊÂʵ¡£¡£¡£¡£¡£¡£´ËÀàNPM°üÒ»µ©±»×°Öú󣬣¬£¬£¬£¬£¬£¬£¬¾Í»áÍøÂçÓйØÓû§µ±Ç°¹¤×÷Ŀ¼£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÓëÍøÂç½Ó¿ÚºÍDNS·þÎñÆ÷ÓйصÄIPµØÖ·µÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬²¢½«ÕâЩÊý¾Ý·¢Ë͵½Ó²±àÂëµÄÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩ¶ñÒâNPM°üÒѱ»É¾³ý¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2022/03/over-200-malicious-npm-packages-caught.html
΢Èí¸üе¼ÖÂWindows Server 2019µÄDNS½âÎöʧ°Ü
¾ÝýÌå3ÔÂ24ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ×°ÖÃ2022Äê1ÔÂ25ÈÕ°ä²¼µÄ¸üÐÂ(KB5009616)ºó£¬£¬£¬£¬£¬£¬£¬£¬Windows Server 2019µÄDNS½âÎö¿ÉÄÜ»á³öÏÖÎÊÌâ¡£¡£¡£¡£¡£¡£ÕâÊÇDNS´æ¸ùÇøÓòÎÞ·¨ÕýÈ·¼ÓÔØµ¼Öµģ¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜ´¥·¢´ËDNS½âÎöÎÊÌâµÄÁí±íÁ½¸öWindows¸üÐÂÊÇKB5010427£¨2ÔÂ15ÈÕ°ä²¼£©ºÍKB5011551£¨3ÔÂ22ÈÕ°ä²¼£©¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬MicrosoftÒÑͨ¹ýÒÑÖªÎÊÌâ»Ø¹ö(KIR)Ö°Äܽ¨¸´ÁË´ËÎÊÌâ¡£¡£¡£¡£¡£¡£Òª½¨¸´´ËÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬ÖÎÀíÔ±»¹Ðè×°ÖúÍÅäÖÃÁ½¸ö×éÕ½Êõ¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-recent-windows-server-updates-cause-dns-issues/
VMware°ä²¼¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´ÆäCarbon BlackÖеÄ2¸ö·ì϶
3ÔÂ23ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬VMware°ä²¼Á˸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´Ó°ÏìÆäCarbon Black App Controlƽ̨µÄ2¸ö·ì϶¡£¡£¡£¡£¡£¡£Carbon BlackÊÇÀûÓ÷¨Ê½½ÚÔì½â¾ö¹æ»®£¬£¬£¬£¬£¬£¬£¬£¬Õâ´Î½¨¸´µÄ·ì϶±ðÀëΪºÅÁî×¢Èë·ì϶£¨CVE-2022-22951£©£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÓÉÓÚÊäÈëÑéÖ¤²»µ±¶øµ¼ÖÂÔ¶³ÌÖ´ÐдúÂ룻£»£»£»£»£»£»ÒÔ¼°ÎļþÉÏ´«·ì϶£¨CVE-2022-22952£©£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÉÏ´«ÌØÔìÎļþÀ´Ö´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶µÄCVSSÆÀ·Ö¾ùΪ9.1£¬£¬£¬£¬£¬£¬£¬£¬µ«³É¹¦ÀûÓÃËüÃǵÄǰÌáÊÇÓµÓÐÖÎÀíÔ±»ò¸ü¸ßȨÏÞ¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2022/03/vmware-issues-patches-for-critical.html
ÎÚ¿ËÀ¼CERT-UA°ä²¼¹ØÓÚDoubleZero¹¥»÷»î¶¯µÄ¾¯±¨
ýÌå3ÔÂ23ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬ÎÚ¿ËÀ¼CERT-UAÔÚ½üÆÚ°ä²¼ÁËÒ»·Ý¹«¸æ£¬£¬£¬£¬£¬£¬£¬£¬ÖÒ¸æDoubleZeroÕë¶ÔÎÚ¿ËÀ¼×éÖ¯µÄ¹¥»÷¡£¡£¡£¡£¡£¡£¹«¸æÖ¸³öÓÚ3ÔÂ17ÈÕ³õ´Î·¢Ïֻ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÓã²æÊ½´¹µö¹¥»÷·Ö·¢¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£´¹µöÓʼþÔ̺¬Ò»¸ö»ìºÏµÄ.NET·¨Ê½£¬£¬£¬£¬£¬£¬£¬£¬±»¶¨ÃûΪDoubleZero£¬£¬£¬£¬£¬£¬£¬£¬ÊÇΪÁË·ÛËéÖ¸±êϵͳ¶ø¿ª·¢µÄ¡£¡£¡£¡£¡£¡£DoubleZero wipeʹÓÃÁË2ÖÖ¼¼Êõ£¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃ4096×Ö½Ú¸²¸ÇÆäÄÚÈÝ£¨Ê¹ÓÃFileStream.Write£©£¬£¬£¬£¬£¬£¬£¬£¬»òʹÓÃAPIŲÓÃNtFileOpenºÍNtFsControlFile(code:FSCTL_SET_ZERO_DATA)£¬£¬£¬£¬£¬£¬£¬£¬×îºó»¹»áɾ³ýWindows×¢²á±íHKCU¡¢HKU¡¢HKLMºÍHKLM\BCD¡£¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/129417/malware/doublezero-wiper-hit-ukraine.html
¹¥»÷ÕßÀûÓüÙ×°µÄÆÆ½âRATµÈ¶ñÒâÈí¼þÇÔȡָ±êµÄÐÅÏ¢
¾Ý2ÔÂ23ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬¶à¸ö°²È«ÍŶӷ¢ÏÖÁËÀûÓÃαÔìµÄ¶ñÒâÈí¼þ¹¥»÷ºÚ¿ÍµÄ»î¶¯¡£¡£¡£¡£¡£¡£ASECÔÚRussia black hatµÈºÚ¿ÍÂÛ̳ÉÏ·¢ÏÖ¼Ù×°³ÉÆÆ½â°æBitRATºÍQuasar RATµÄÇÔÈ¡·¨Ê½£¬£¬£¬£¬£¬£¬£¬£¬Ö¸±êÔÚµã»÷µö¶üÁ´½Óºó»á±»³Á¶¨Ïòµ½Ò»¸öAnonfilesÒ³Ãæ£¬£¬£¬£¬£¬£¬£¬£¬¶øºó»áÏÂÔØ¶ñÒâÈí¼þClipBanker¡£¡£¡£¡£¡£¡£Cyble·¢ÏÖÁËÐû³ÆÊÇÌṩһ¸öÔÂÃâ·ÑAvD Crypto StealerµÄ»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬Ö¸±ê±ÉÈËÔØËùνµÄ¶ñÒâÈí¼þ¹¹½¨Æ÷²¢Æô¶¯ÃûΪ¡°Payload.exe¡±µÄÎļþºó£¬£¬£¬£¬£¬£¬£¬£¬»áϰȾÕë¶ÔEthereumµÈµÄclipper¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¸Ã»î¶¯ÒѽٳÖÁË422±ÊÂòÂô²¢ÇÔÈ¡ÁË1.3±ÈÌØ±Ò£¨Ô¼54000ÃÀÔª£©¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/hackers-steal-from-hackers-by-pushing-fake-malware-on-forums/
Volexity°ä²¼ÐÂGimmick¶Ô×¼macOSÓû§µÄ·ÖÎö»ã±¨
3ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬°²È«¹«Ë¾Volexity°ä²¼ÁËжñÒâÈí¼þGimmick¶Ô×¼macOSÓû§µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯ÆðÍ·ÓÚ2021Äêµ×£¬£¬£¬£¬£¬£¬£¬£¬À´×ÔÓÚStorm CloudÍŻ¡£¡£¡£¡£¡£¸ÃmacOS±äÌåÖØÒªÊ¹ÓÃObjective C±àд£¬£¬£¬£¬£¬£¬£¬£¬¶øWindows°æ±¾Ê¹ÓÃÁË.NETºÍDelphi¡£¡£¡£¡£¡£¡£³É¹¦×°Öú󣬣¬£¬£¬£¬£¬£¬£¬GimmickÄܹ»×÷ÎªÊØ»¤·¨Ê½Æô¶¯£¬£¬£¬£¬£¬£¬£¬£¬Ò²Äܹ»ÒÔ¶¨ÔìÀûÓ÷¨Ê½µÄ´ó¾ÖÆô¶¯£¬£¬£¬£¬£¬£¬£¬£¬²¢±»ÅäÖÃΪ½öÔÚ¹¤×÷ÈÕÓëC2½øÐÐͨѶ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬Ëü»¹ÓµÓÐ×ÔÎÒÐ¶ÔØÖ°ÄÜ£¬£¬£¬£¬£¬£¬£¬£¬Äܹ»½«×Ô¼º´ÓÖ¸±êÉ豸ÉÑþ³Øý¡£¡£¡£¡£¡£¡£
https://www.volexity.com/blog/2022/03/22/storm-cloud-on-the-horizon-gimmick-malware-strikes-at-macos/
°²È«¹¤¾ß
catalyst
ÊÇÒ»¸ö SOAR ϵͳ£¬£¬£¬£¬£¬£¬£¬£¬¿É×Ô¶¯»¯¾¯±¨´¦ÖúÍÊÂÎñÏìÓ¦Á÷³Ì¡£¡£¡£¡£¡£¡£
https://catalyst-soar.com/
Auto-Elevate
ÇÔÈ¡²¢Ä£ÄâÆä¹ý³Ì TOKEN£¬£¬£¬£¬£¬£¬£¬£¬²¢Ê¹Óñ»µÁÁîÅÆÌìÉúÒ»¸öÐ嵀 SYSTEM ¼¶¹ý³Ì
https://github.com/FULLSHADE/Auto-Elevate
ICMP-TransferTools
ÊÇÒ»×é¾ç±¾£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÔÚÊÜÏÞÍøÂç»·¾³Öн«ÎļþÒÆÈëºÍÒÆ³ö Windows Ö÷»ú¡£¡£¡£¡£¡£¡£
https://github.com/icyguider/ICMP-TransferTools
HTTP Smuggling Calculator
ͨ¹ý×Ô¶¯Ôì×÷ HTTP ÒªÇóÀ´Ö´ÐÐ CL.TE ºÍ TE.CL HTTP ÒªÇó×ß˽¹¥»÷¡£¡£¡£¡£¡£¡£
https://github.com/kleiton0x00/HTTP-Smuggling-Calculator
°²È«·ÖÎö
FBI£º2021 ÄêÒòÍøÂç·¸×ïËðʧ 69 ÒÚÃÀÔª
https://therecord.media/fbi-6-9-billion-lost-through-internet-crimes-in-2021/
ÃÀ¹ú¸æ×´¶íÂÞ˹Igor DekhtyarchukÔËÓª°µÍøÂÛ̳
https://www.bleepingcomputer.com/news/security/fbi-adds-russian-cybercrime-market-owner-to-most-wanted-list/
¶íÂÞ˹½ûÓùȸèÐÂÎÅ
https://www.bleepingcomputer.com/news/technology/russia-bans-google-news-for-unreliable-info-on-war-in-ukraine/
Microsoft PowerToys ÖÐ¶Ï Outlook PDF Ô¤ÀÀ
https://www.bleepingcomputer.com/news/microsoft/microsoft-powertoys-breaks-outlook-pdf-preview/
΢Èí½¨¸´Á˵¼Ö Windows À¶ÆÁµÄÀ¶ÑÀÎÊÌâ
https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-bluetooth-issue-causing-windows-blue-screens/
Anonymous ÌáÒé´ó¹æÄ£µÄ¡°Ó¡Ë¢¹¥»÷¡±
https://www.hackread.com/anonymous-hacks-unsecured-printers-message-russia/


¾©¹«Íø°²±¸11010802024551ºÅ