ÔËÓªÉÌUkrtelecom³ÆÆäÖ÷Ìâ»ù´¡ÉèÊ©Ôâµ½´ó¹æÄ£¹¥»÷

°ä²¼¹¦·ò 2022-03-31

ÔËÓªÉÌUkrtelecom³ÆÆäÖ÷Ìâ»ù´¡ÉèÊ©Ôâµ½´ó¹æÄ£¹¥»÷


¾ÝýÌå3ÔÂ29ÈÕ±¨Â·£¬£¬£¬ £¬£¬£¬ÎÚ¿ËÀ¼ÖØÒªµÄÔËÓªÉÌUkrtelecomÔâµ½ÁË´ó¹æÄ£µÄÍøÂç¹¥»÷£¬£¬£¬ £¬£¬£¬Ôì³ÉÁËÑϳÁµÄÍøÂçÖжϡ£¡£¡£¡£¡£¡£¡£Æ¾¾Ý»¥ÁªÍø¼à¿Ø·þÎñNetBlockµÄÊý¾Ý£¬£¬£¬ £¬£¬£¬ÊµÊ±ÍøÂçÊý¾ÝÏÔʾÏνÓÐÔ½µÂäµ½Õý³£Ë®Æ½µÄ13%¡£¡£¡£¡£¡£¡£¡£ÎÚ¿ËÀ¼SSSCIP°µÊ¾£¬£¬£¬ £¬£¬£¬ºÚ¿Í¹¥»÷ÁËUkrtelecomµÄIT»ù´¡ÉèÊ©£¬£¬£¬ £¬£¬£¬ËûÃÇÒѳɹ¦ÕмÜÕâ´Î¹¥»÷¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬£¬ÎªÁ˱£»£»£»£» £»¤Æä»ù´¡ÉèÊ©²¢³ÖÐøÎªÎÚ¿ËÀ¼Îä×°¶ÓÁÐºÍÆäËû¾üÊÂ×éÖ¯ºÍ¿Í»§Ìṩ·þÎñ£¬£¬£¬ £¬£¬£¬UkrtelecomÁÙʱÏÞ¶ÈÁË´óÎÞÊý¸öÈËºÍÆóÒµ¿Í»§µÄ·þÎñ¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/129585/cyber-warfare-2/ukraine-cyberattack-ukrtelecom.html


΢Èí½¨¸´Windows 11 SMBºÍDirectXÖеÄBSODÎÊÌâ


ýÌå3ÔÂ28ÈÕ±¨Â·£¬£¬£¬ £¬£¬£¬Microsoft°ä²¼Á˺ÏÓÃÓÚWindows 11µÄ¿ÉÑ¡KB5011563ÀÛ»ý¸üС£¡£¡£¡£¡£¡£¡£Õâ´Î¸üÐÂÖØÒª½¨¸´ÁË2¸öÀ¶ÆÁËÀ»ú(BSOD)ÎÊÌ⣬£¬£¬ £¬£¬£¬Ô̺¬DirectXÄÚºË×é¼þÖеÄÖÕ³¡ÃýÎó£¨0xD1£¬£¬£¬ £¬£¬£¬DRIVER_IRQL_NOT_LESS_OR_EQUAL£©ºÍSMB·þÎñÆ÷£¨srv2.sys£©ÖеÄÖÕ³¡ÃýÎó0x1E¡£¡£¡£¡£¡£¡£¡£Õâ´Î¸üл¹Ôö³¤Á˺öàеÄÖ°ÄÜ£¬£¬£¬ £¬£¬£¬ÀýÈçͬʱÏÔʾ×î¶àÈý¸ö¸ßÓÅÏȼ¶Toast֪ͨ¡£¡£¡£¡£¡£¡£¡£Óû§Äܹ»ÔÚÉèÖÃÖÐÊÖ¶¯²é³­¸üУ¬£¬£¬ £¬£¬£¬»ò´ÓMicrosoft¸üÐÂĿ¼ÊÖ¶¯ÏÂÔØ²¢×°Öô˸üС£¡£¡£¡£¡£¡£¡£ 


https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5011563-update-fixes-smb-directx-blue-screens/


ÎÚ¿ËÀ¼µÄ¶à¸öÍøÕ¾Ôâµ½À´×ÔÊý°Ù¸öÍøÕ¾µÄDDoS¹¥»÷


¾Ý3ÔÂ28ÈÕ±¨Â·£¬£¬£¬ £¬£¬£¬MalwareHunterTeam·¢ÏÖÁËÒ»¸ö¶ñÒâ¾ç±¾¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÒÑÀûÓÃWordPressÖеķì϶ÈëÇÖÁËÉϰٸöÍøÕ¾£¬£¬£¬ £¬£¬£¬¶øºó²åÈë¸Ã¶ñÒâ¾ç±¾¶ÔÎÚ¿ËÀ¼µÄÍøÕ¾Ö´ÐÐDDoS¹¥»÷£¬£¬£¬ £¬£¬£¬Éæ¼°ÎÚ¿ËÀ¼µ±¾Ö»ú¹¹¡¢ÖÇÄÒÍÅ¡¢¹ú·À¾üÕÐļºÍ½ðÈÚµÈÓйØÍøÕ¾¡£¡£¡£¡£¡£¡£¡£Õâ¸öJavaScript¾ç±¾½«Ç¿Ôì±»ÈëÇÖµÄä¯ÀÀÆ÷¶ÔÁгöµÄ¶àÓÐÍøÕ¾Ö´ÐÐHTTP GETÒªÇ󣬣¬£¬ £¬£¬£¬Ò»´Î²»³¬¹ý1000¸ö²¢·¢Ïνӡ£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬£¬¶ÔÖ¸±êÍøÕ¾µÄÿ¸öÒªÇó¶¼½«Ê¹ÓÃÒ»¸öËæ»ú²éÎÊ×Ö·û´®£¬£¬£¬ £¬£¬£¬ÕâÑùÒªÇó¾Í²»»áͨ¹ý»º´æ·þÎñ£¨ÈçCloudflare£©Ìṩ·þÎñ£¬£¬£¬ £¬£¬£¬¶øÊÇÖ±½ÓÓɱ»¹¥»÷µÄ·þÎñÆ÷½Ó¹Ü¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/hacked-wordpress-sites-force-visitors-to-ddos-ukrainian-targets/


Minerva°ä²¼¹ØÓÚÀÕË÷Èí¼þSunCryptµÄ·ÖÎö»ã±¨ 


3ÔÂ28ÈÕ£¬£¬£¬ £¬£¬£¬Minerva Labs°ä²¼¹ØÓÚÀÕË÷Èí¼þSunCryptµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£SunCryptÊÇRaaSÍŻ£¬£¬ £¬£¬£¬ÓÚ2019Äê10Ô³õ´Î³öÏÖ£¬£¬£¬ £¬£¬£¬ÊÇ×îÔçʹÓÃÈý³ÁÀÕË÷Õ½ÊõµÄ×éÖ¯Ö®Ò»¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬ £¬£¬£¬´Ë2022 SunCrypt±äÖÖÔö³¤Á˺öàеÄÖ°ÄÜ£¬£¬£¬ £¬£¬£¬Ô̺¬ÖÕÖ¹¹ý³Ì¡¢ÖÕ³¡·þÎñ²¢¶Ï¸ùÀÕË÷Èí¼þÖ´Ðеĺۼ£¡£¡£¡£¡£¡£¡£¡£¸ÃÀÕË÷Èí¼þ»¹Ê¹ÓÃÒ»¸öwinlogon.exe½Ó¼ûÁîÅÆ£¬£¬£¬ £¬£¬£¬²¢Í¨¹ýʹÓÃSetThreadToken APIŲÓý«ÆäÉèÖÃΪÆäÖ÷Ï̡߳£¡£¡£¡£¡£¡£¡£


https://blog.minerva-labs.com/suncrypt-ransomware-gains-new-abilities-in-2022


Rapid7°ä²¼¹ØÓÚ2021Ä갲ȫ·ìÏ¶Ì¬ÊÆµÄ·ÖÎö»ã±¨


3ÔÂ28ÈÕ£¬£¬£¬ £¬£¬£¬Rapid7°ä²¼ÁËÆä×îеķìÏ¶Ì¬ÊÆ·ÖÎö»ã±¨£¬£¬£¬ £¬£¬£¬×êÑÐÁË2021Äê×îÏÔÖøµÄ°²È«·ì϶ºÍÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£2021ÄêµÄÍþвÖУ¬£¬£¬ £¬£¬£¬³¬¹ý50%µÄʼÓÚÁãÈÕ·ì϶¡£¡£¡£¡£¡£¡£¡£¸Ã»ã±¨×êÑÐÁË50¸ö·ì϶£¬£¬£¬ £¬£¬£¬ÆäÖÐÓÐ43¸öÒѱ»ÀûÓ㬣¬£¬ £¬£¬£¬½üÒ»°ëÊÇÔÚ½¨¸´Ö®Ç°±»ÓÃÓÚÁãÈÕ¹¥»÷¡£¡£¡£¡£¡£¡£¡£ÓÃ×÷ÁãÈÕ¹¥»÷µÄ·ì϶ÊýÁ¿±È2020ÄêÔö³¤ÁË100%£¬£¬£¬ £¬£¬£¬ÇÒÀûÓõľùÔȹ¦·ò´Ó2020ÄêµÄ42È«¹ú½µµ½2021ÄêµÄ12Ì죻£»£»£» £»66%µÄ·ì϶±»¹éÀàΪ¿í·ºÍþв£¬£¬£¬ £¬£¬£¬ÆäÖÐ60%ÒÔÉϱ»ÓÃÓÚÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£¡£


https://www.rapid7.com/info/2021-vulnerability-intelligence-report/


CISAÓëÄÜÔ´²¿½áºÏ°ä²¼Õë¶ÔUPSÉ豸µÄ¹¥»÷µÄÕ÷ѯ


3ÔÂ29ÈÕ£¬£¬£¬ £¬£¬£¬ÃÀ¹úCISAÓëÄÜÔ´²¿½áºÏ°ä²¼ÁËÕë¶Ô²»¼ä¶ÏµçÔ´(UPS)É豸µÄ¹¥»÷µÄ°²È«Õ÷ѯ¡£¡£¡£¡£¡£¡£¡£¹«¸æÖ¸³ö£¬£¬£¬ £¬£¬£¬ÕâЩ»ú¹¹·¢ÏÖ¹¥»÷Õßͨ³£Í¨¹ýδ¸ü¸ÄµÄĬÈÏÓû§ÃûºÍÃÜÂëÀ´½Ó¼û¸÷ÀàÁªÍøµÄUPSÉ豸,×éÖ¯Äܹ»Í¨¹ý´Ó»¥ÁªÍøÉÑþ³ØýÖÎÀí½Ó¿ÚÀ´»º½â¶ÔÆäUPSÉ豸µÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£CISAºÍDOE»¹ÌṩÁËÆäËüµÄ»º½â´ëÊ©£¬£¬£¬ £¬£¬£¬ÆäÖÐÔ̺¬²éÕÒ×éÖ¯ÍøÂçÉϵÄËùÓÐUPSºÍÆäËüÓ¦¼±µçԴϵͳ£¬£¬£¬ £¬£¬£¬²¢È·±£ËüÃÇÎÞ·¨Í¨¹ýInternet½Ó¼û¡£¡£¡£¡£¡£¡£¡£


https://www.cisa.gov/uscert/ncas/current-activity/2022/03/29/mitigating-attacks-against-uninterruptable-power-supply-devices




°²È«¹¤¾ß


Gitcolombo


OSINT ¹¤¾ß£¬£¬£¬ £¬£¬£¬ÓÃÓÚ´Ó git ´æ´¢¿âÖÐÌáÈ¡ÓйØÈËÔ±µÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£


https://github.com/soxoj/gitcolombo


ScheduleRunner


AC# ¹¤¾ß£¬£¬£¬ £¬£¬£¬¿É¸ü½Ã½ÝµØ×Ô½ç˵´òË㹤×÷£¬£¬£¬ £¬£¬£¬ÒÔʵÏÖºì¶Ó²Ù×÷ÖеÄÓÆ¾ÃÐԺͺáÏòÒÆ¶¯¡£¡£¡£¡£¡£¡£¡£


https://github.com/netero1010/ScheduleRunner


phantun


Ò»¸öÇáÁ¿¼¶ºÍ¼±¾çµÄ UDP µ½ TCP »ìºÏÆ÷¡£¡£¡£¡£¡£¡£¡£


https://github.com/dndx/phantun/




°²È«·ÖÎö


AnonymousºÚ¿ÍÈëÇÖ 2 ¼Ò¶íÂÞ˹¹¤Òµ¹«Ë¾£¬£¬£¬ £¬£¬£¬Ð¹Â¶ 112GB Êý¾Ý


https://www.hackread.com/anonymous-hack-russian-industrial-firms-data-leak/


Ð嵀 Windows °²È«Ö°ÄÜ¿É×èÖ¹Ò×Êܹ¥»÷µÄÇý¶¯·¨Ê½


https://www.bleepingcomputer.com/news/microsoft/new-windows-security-feature-blocks-vulnerable-drivers/


¶íÂÞ˹ÒòÉ豸Ƿȱ¶øÃæ¶Ô»¥ÁªÍøÖжÏ


https://www.bleepingcomputer.com/news/technology/russia-facing-internet-outages-due-to-equipment-shortage/


΢ÈíΪ AMD Çý¶¯µÄ Surface Laptop 4 °ä²¼¹Ì¼þ¸üÐÂ


https://news.softpedia.com/news/microsoft-releases-firmware-update-for-amd-powered-surface-laptop-4-535118.shtml


Trend MicroÅû¶Purple Fox½üÆÚ¹¥»÷»î¶¯µÄϸ½ÚÐÅÏ¢


https://www.trendmicro.com/en_us/research/22/c/purple-fox-uses-new-arrival-vector-and-improves-malware-arsenal.html