Cash³ÆÆä820ÍòµÄÓû§ÐÅÏ¢ÒÑй¶ ÄÚ²¿Ô±¹¤Î¥¹æÏÂÔØ
°ä²¼¹¦·ò 2022-04-08Cash³ÆÆä820ÍòµÄÓû§ÐÅÏ¢ÒÑй¶£¬£¬£¬£¬£¬£¬£¬ÄÚ²¿Ô±¹¤Î¥¹æÏÂÔØ
¾ÝýÌå4ÔÂ5ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬Cash App 820ÍòµÄÓû§ÐÅÏ¢ÒÑй¶¡£¡£¡£¡£¡£¡£¡£Cash AppµÄĸ¹«Ë¾Block,Inc.ÔÚÌá½»µÄ8-K±í¸ñÖаµÊ¾£¬£¬£¬£¬£¬£¬£¬ÊÂÎñ²úÉúÔÚ2021Äê12ÔÂ10ÈÕ£¬£¬£¬£¬£¬£¬£¬ÆäÒ»¸öǰԱ¹¤ÔÚÈ¥Ö°ºóÏÂÔØÁËCash AppµÄÄÚ²¿»ã±¨¡£¡£¡£¡£¡£¡£¡£Õâ´Îй¶ÁËÓû§µÄÓ×ÎÒÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÆäÔÚCash AppÉϵÄͶ×ʻÓйصÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬Èç³Ö¹ÉÁ¿ºÍÂòÂô»î¶¯µÈ¡£¡£¡£¡£¡£¡£¡£Block°µÊ¾£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°ËûÃÇÔÚ֪ͨÊÜй¶ÊÂÎñÓ°ÏìµÄ820Íò¿Í»§ÓйشËʵĸü¶àÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/cash-app-notifies-82-million-us-customers-about-data-breach/
ÎÚ¿ËÀ¼CERT-UA·¢ÏÖArmageddonÐÂÒ»ÂÖ´¹µö¹¥»÷»î¶¯
ýÌå4ÔÂ5Èճƣ¬£¬£¬£¬£¬£¬£¬ÎÚ¿ËÀ¼ÍÆËã»úÓ¦¼±ÏìÓ¦Ó××é(CERT-UA)·¢ÏÖÁËArmageddon(Gamaredon)еĴ¹µö»î¶¯¡£¡£¡£¡£¡£¡£¡£¸Ã»ú¹¹ÒѾȷ¶¨ÁËÁ½¸ö¶ÀÁ¢µÄ°¸¼þ£¬£¬£¬£¬£¬£¬£¬Ò»¸öÕë¶ÔÎÚ¿ËÀ¼µÄ×éÖ¯£¬£¬£¬£¬£¬£¬£¬ÁíÒ»¸öÕë¶ÔÅ·ÃËÈ·µ±¾Ö»ú¹¹¡£¡£¡£¡£¡£¡£¡£Õë¶ÔÎÚ¿ËÀ¼µÄ»î¶¯ÒÔ¶íÂÞ˹ս·¸ÐÅϢΪµö¶ü£¬£¬£¬£¬£¬£¬£¬Ê¹Óø½ÓÐHTMLÎļþµÄ´¹µöÓʼþ·Ö·¢¶ñÒâÈí¼þ£»£»£»£»£»£»£»£»Õë¶ÔÅ·Ã˵ĻÒÔ¾üʺÍÈË·Ö÷Òå¾ÈÖúΪÌ⣬£¬£¬£¬£¬£¬£¬Í¨¹ýÒ»¸öRAR¸½¼þ·Ö·¢¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£ArmageddonÓë¶íÂÞ˹FSBÓйأ¬£¬£¬£¬£¬£¬£¬×Ô2014ÄêÒÔÀ´Ò»Ïò»îÔ¾¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/ukraine-spots-russian-linked-armageddon-phishing-attacks/
ContiÍÅ»ïй¶´ÓParker HannifinÇÔÈ¡µÄÊýGBÎļþ
ýÌå4ÔÂ5ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬£¬£¬ÃÀ¹ú¹¤Òµ¹«Ë¾Parker Hannifin´óÁ¿Êý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÖØÒªÎªº½¿Õº½Ìì¡¢ÒÆ¶¯ºÍ¹¤ÒµÁìÓòµÄ×éÖ¯Ìṩ¾«Ãܹ¤³Ì½â¾ö¹æ»®¡£¡£¡£¡£¡£¡£¡£ËüÔÚ3ÔÂ14ÈÕ¼ì²âµ½ÏµÍ³Ôâµ½ÈëÇÖ£¬£¬£¬£¬£¬£¬£¬Ö®ºóÁ¢¿Ì¹Ø¹Ø²¿ÃÅϵͳ²¢·¢Õ¹µ÷²é¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°µ÷²éÈÔÔÚ½øÐÐÖУ¬£¬£¬£¬£¬£¬£¬µ«ÒÑÈ·¶¨Ô̺¬Ô±¹¤Ó×ÎÒÐÅÏ¢ÔÚÄڵIJ¿ÃÅÊý¾ÝÒѾй¶¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬ContiÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾¹«¿ªÁË´ÓParkerÇÔÈ¡µÄ³¬¹ý5GBÊý¾Ý£¬£¬£¬£¬£¬£¬£¬²¢³ÆÕâ½öΪ±»µÁÊý¾ÝµÄ3%¡£¡£¡£¡£¡£¡£¡£
https://www.securityweek.com/ransomware-gang-leaks-files-stolen-industrial-giant-parker-hannifin
Ó¢¹úThe WorksÔâµ½¹¥»÷ºó²¿ÃÅÁãÊÛÉ̵êÁÙʱ¹ØÃÅ
¾Ý4ÔÂ5ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬Ó¢¹úThe Works³ÆÆäϵͳÔâµ½·¸·¨½Ó¼û£¬£¬£¬£¬£¬£¬£¬µ¼Ö²¿ÃÅÁãÊÛÉ̵êÁÙʱ¹ØÃÅ¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚÓ¢¹úºÍ°®¶ûÀ¼Õ¼ÓÐ530¼ÒÃŵ꣬£¬£¬£¬£¬£¬£¬ÏúÊÛÊé¼®¡¢Íæ¾ß¡¢Îľߡ¢ÒÕÊõÆ·ºÍ¹¤ÒÕ×ÊÁϵȣ¬£¬£¬£¬£¬£¬£¬ÄêÊÕÈëԼΪ3ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¡£The Works²¢Î´Åû¶¹ØÓÚÕâ´Î¹¦·òµÄ¸ü¶àϸ½Ú£¬£¬£¬£¬£¬£¬£¬µ«ÆäÅäËÍ·þÎñÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬ÓÐЩÃŵêÖ»ÄܽÓÊÜÏֽ𡣡£¡£¡£¡£¡£¡£²¿ÃÅýÌ屨·£¬£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñÔ´ÓÚÒ»ÃûÔ±¹¤Ôâµ½¶ñÒâÓʼþµÄ¹¥»÷£¬£¬£¬£¬£¬£¬£¬µ¼Ö¹«Ë¾µÄϵͳϰȾÀÕË÷Èí¼þ¡£¡£¡£¡£¡£¡£¡£
https://www.bitdefender.com/blog/hotforsecurity/the-works-hit-by-hackers-uk-retailer-shuts-some-stores-after-problems-with-payment-tills/
Symantec°ä²¼CicadaÍÅ»ï½üÆÚ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨
4ÔÂ5ÈÕ£¬£¬£¬£¬£¬£¬£¬Symantec°ä²¼ÁËCicada£¨±ðÃûAPT10£©½üÆÚ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯ÆðÍ·ÓÚ2021ÄêÄêÖУ¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶Ô¶à¸ö¹ú¶È£¨Éæ¼°Å·ÖÞ¡¢ÑÇÖ޺ͱ±ÃÀ£©È·µ±¾Ö¡¢Ë¾·¨¡¢×ڽ̺ͷǵ±¾Ö×éÖ¯(NGO)¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏÈͨ¹ý佨¸´µÄMicrosoft Exchange·þÎñÆ÷»ñµÃ³õʼ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓúóÃÅSodamasterµÈ¶ñÒâÈí¼þÖ´Ðй¥»÷¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹Í¨¹ýDLL²àÔØ¼¼Êõ£¬£¬£¬£¬£¬£¬£¬ÀûÓúϷ¨µÄVLCýÌå²¥·ÅÆ÷À´×°ÖÃ×Ô½ç˵¼ÓÔØ·¨Ê½¡£¡£¡£¡£¡£¡£¡£
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/cicada-apt10-china-ngo-government-attacks
Malwarebytes°ä²¼Colibri LoaderлµÄ×êÑл㱨
MalwarebytesÔÚ4ÔÂ5ÈÕ°ä²¼ÁËColibri LoaderлµÄ×êÑл㱨¡£¡£¡£¡£¡£¡£¡£ÕâÊÇÒ»¸öÏà¶Ô½ÏеĶñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬ÓÚ2021Äê8Ô³õ´Î³Ê´Ë¿ÌºÚ¿ÍÂÛ̳ÉÏ£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ·Ö·¢ºÍÖÎÀípayload¡£¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯ÀûÓÃÁ˶ñÒâWordÎĵµ£¬£¬£¬£¬£¬£¬£¬×îÖÕÖ¼ÔÚ·Ö·¢Vidar Stealer¡£¡£¡£¡£¡£¡£¡£ÎĵµÏÅ×ëλÓÚ(securetunnel[.]co)µÄÔ¶³Ì·þÎñÆ÷Ïνӣ¬£¬£¬£¬£¬£¬£¬ÒÔ¼ÓÔØÃûΪtrkal0.dotµÄÔ¶³ÌÄ£°å£¬£¬£¬£¬£¬£¬£¬¸ÃÄ£°åÓë¶ñÒâºêÁªÏ·´Ê¹PowerShellÒÔsetup.exeµÄ´ó¾ÖÏÂÔØColibri Loader¡£¡£¡£¡£¡£¡£¡£
https://blog.malwarebytes.com/threat-intelligence/2022/04/colibri-loader-combines-task-scheduler-and-powershell-in-clever-persistence-technique/
°²È«¹¤¾ß
Process Overwriting
PE×¢Èë¼¼Êõ£¬£¬£¬£¬£¬£¬£¬ÓëProcess Hollowing ºÍ Module OverloadingÇ×êÇÓйء£¡£¡£¡£¡£¡£¡£
https://github.com/hasherezade/process_overwriting
jfscan v1.1.8
»ùÓÚ Masscan ºÍ NMap µÄ³¬¼±¾çºÍ¿É¶¨ÔìµÄ¶Ë¿ÚɨÃèÆ÷¡£¡£¡£¡£¡£¡£¡£
https://github.com/nullt3r/jfscan
Auto-Elevate
´Ë¹¤¾ßÑÝʾÁË UAC ÈÆ¹ýµÄ׳´óÖ°ÄÜºÍ Windows µÄÄÚÖÃÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£
https://github.com/FULLSHADE/Auto-Elevate
Subdomains.Sh
subdomains.sh°ü×°ÓÃÓÚ×ÓÓòö¾ÙµÄ¹¤¾ß£¬£¬£¬£¬£¬£¬£¬ÒÔÔÚ¸ø¶¨ÓòÉÏ×Ô¶¯»¯¹¤×÷Á÷¡£¡£¡£¡£¡£¡£¡£
https://github.com/enenumxela/subdomains.sh
°²È«·ÖÎö
Ó¢ÌØ¶û¹Ø¹ØÔÚ¶íÂÞ˹µÄËùÓÐÒµÎñÔËÓª
https://www.bleepingcomputer.com/news/technology/intel-shuts-down-all-business-operations-in-russia/
Mandiant ¹É¶«¸æ×´×èÖ¹¹È¸è 5.4 ÒÚÃÀÔªµÄÂòÂô
https://www.theregister.com/2022/04/04/mandiant_google_lawsuit/
΢Èí½«±¾µØ Exchange¡¢SharePoint Ôö³¤µ½·ì϶Éͽð´òËã
https://www.bleepingcomputer.com/news/security/microsoft-adds-on-premises-exchange-sharepoint-to-bug-bounty-program/
΢Èí°ä·¢Ð嵀 Windows 11 °²È«¡¢¼ÓÃÜÖ°ÄÜ
https://www.bleepingcomputer.com/news/microsoft/microsoft-announces-new-windows-11-security-encryption-features/
Rockwell PLC ÖеÄÑϳÁ·ì϶¿ÉÄÜÓÃÀ´Ö²Èë¶ñÒâ´úÂë
https://thehackernews.com/2022/04/critical-bugs-in-rockwell-plc-could.html
Spring4Shell (CVE-2022-22965)£º¾ßÌåÐÅÏ¢»ººÍ½â´ëÊ©
https://securelist.com/spring4shell-cve-2022-22965/106239/


¾©¹«Íø°²±¸11010802024551ºÅ