åÚÏëUEFI¹Ì¼þÇý¶¯·¨Ê½Öеķì϶ӰÏìÉϰٿî±Ê¼Ç±¾µçÄÔ

°ä²¼¹¦·ò 2022-04-20

1¡¢åÚÏëUEFI¹Ì¼þÇý¶¯·¨Ê½Öеķì϶ӰÏìÉϰٿî±Ê¼Ç±¾µçÄÔ


¾ÝýÌå4ÔÂ19ÈÕ±¨Â·£¬£¬£¬ £¬£¬£¬ £¬ £¬ESET×êÑÐÈËÔ±·¢ÏÖÓ°ÏìåÚÏëÉϰٿî±Ê¼Ç±¾µçÄÔµÄ3¸ö·ì϶¡£¡£ ¡£¡£¡£¡£¡£ÆäÖÐÁ½¸ö·ì϶£¨CVE-2021-3971ºÍCVE-2021-3972£©¿ÉÓÃÀ´½ûÓöԴ洢UEFI¹Ì¼þµÄSPIÉÁ´æÐ¾Æ¬µÄ±£»£»£»£»£»¤£¬£¬£¬ £¬£¬£¬ £¬ £¬²¢¹Ø¹ØUEFI°²È«Æô¶¯Ö°ÄÜ£¬£¬£¬ £¬£¬£¬ £¬ £¬Ê¹¶ñÒâÈí¼þÔÚϵͳ³ÁÆôºóÈÔ¿É´æÔÚ¡£¡£ ¡£¡£¡£¡£¡£µÚÈý¸ö·ì϶£¨CVE-2021-3970£©´æÔÚÓÚLenovoVariable SMI´¦Ö÷¨Ê½ÖУ¬£¬£¬ £¬£¬£¬ £¬ £¬¹¥»÷Õß¿ÉÀûÓÃÆäÒÔÌáÉýµÄȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£¡£ ¡£¡£¡£¡£¡£ESETÓÚ2021Äê10ÔÂ11ÈÕÏòåÚÏë»ã±¨ÕâЩ·ì϶£¬£¬£¬ £¬£¬£¬ £¬ £¬åÚÏëÓÚ4ÔÂ12ÈÕ°ä²¼²¹¶¡¡£¡£ ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/lenovo-uefi-firmware-driver-bugs-affect-over-100-laptop-models/


2¡¢CISAºÍFBI½áºÏ°ä²¼¹ØÓÚÇø¿éÁ´ÐÐÒµµÄÍøÂ簲ȫÕ÷ѯ


4ÔÂ18ÈÕ£¬£¬£¬ £¬£¬£¬ £¬ £¬ÃÀ¹úFBI¡¢CISAºÍ²ÆÕþ²¿½áºÏ°ä²¼Á˹ØÓÚÇø¿éÁ´ÐÐÒµµÄÍøÂ簲ȫÕ÷ѯ¡£¡£ ¡£¡£¡£¡£¡£¸ÃÕ÷ѯָ³ö£¬£¬£¬ £¬£¬£¬ £¬ £¬³¯ÏÊAPT×éÖ¯Lazarus¶Ô×¼Çø¿éÁ´¼¼ÊõºÍ¼ÓÃÜÇ®±ÒÐÐÒµµÄ¸÷Àà×éÖ¯£¬£¬£¬ £¬£¬£¬ £¬ £¬Ô̺¬¼ÓÃÜÇ®±ÒÂòÂôËù¡¢È¥ÖÐÐÄ»¯½ðÈÚ (DeFi) ºÍ̸ºÍ¼ÓÃÜÇ®±ÒÒµÎñ¹«Ë¾µÈ¡£¡£ ¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓø÷ÀàͨѶƽ̨¶ÔÖ¸±ê½øÐÐÉç»á¹¤³Ì¹¥»÷£¬£¬£¬ £¬£¬£¬ £¬ £¬ÓÕʹÆäÔÚWindows»òmacOSϵͳ¸ßµÍÔØÄ¾Âí»¯µÄ¼ÓÃÜÇ®±ÒÀûÓ㬣¬£¬ £¬£¬£¬ £¬ £¬ÒÔÇÔȡ˽Կ»òÀÄÓÃÆäËü·ì϶¡£¡£ ¡£¡£¡£¡£¡£¸Ã²¼¸æÌṩÁË´ËÀà»î¶¯ÓйصÄÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½(TTP)ºÍIOC£¬£¬£¬ £¬£¬£¬ £¬ £¬ÒÔÔ®ÊÖ×éÖ¯¼ø±ð²¢ÕмÜÕë¶Ô¼ÓÃÜÇ®±ÒµÄÍøÂç¹¥»÷¡£¡£ ¡£¡£¡£¡£¡£


https://www.cisa.gov/uscert/ncas/alerts/aa22-108a


3¡¢CloudSEK·¢ÏÖ¼ÙÒâWin11Éý¼¶·Ö·¢Inno StealerµÄ»î¶¯


ýÌå4ÔÂ18ÈÕ±¨Â·£¬£¬£¬ £¬£¬£¬ £¬ £¬CloudSEK·¢ÏÖ¼ÙÒâWin11Éý¼¶·Ö·¢Inno StealerµÄ»î¶¯¡£¡£ ¡£¡£¡£¡£¡£¸Ã»î¶¯Ä¿Ç°ºÜ»îÔ¾£¬£¬£¬ £¬£¬£¬ £¬ £¬Í¨¹ýËÑË÷Á˾ÖͶ¶¾À´ÍÆËͼÙÒâWindows 11ÍÆ¹ãÒ³ÃæµÄ´¹µöÍøÕ¾¡£¡£ ¡£¡£¡£¡£¡£Ö¸±êµã»÷Á¢¼´ÏÂÔØºó»áµÃµ½Ò»¸öISOÎļþ£¬£¬£¬ £¬£¬£¬ £¬ £¬ÆäÖÐÔ̺¬Inno StealerµÄ¼ÓÔØ·¨Ê½¡£¡£ ¡£¡£¡£¡£¡£Ð¶ñÒâÈí¼þÓÉÓÚʹÓÃÁËInno Setup Windows×°Ö÷¨Ê½¶øµÃÃû£¬£¬£¬ £¬£¬£¬ £¬ £¬ÓëĿǰʢÐÐµÄÆäËüÐÅÏ¢ÇÔÈ¡·¨Ê½µÄ´úÂëûÓÐÈκÎÀàËÆÖ®´¦£¬£¬£¬ £¬£¬£¬ £¬ £¬¿ÉÇÔÈ¡ä¯ÀÀÆ÷cookieºÍ´æ´¢µÄÍ´´¦¡¢¼ÓÃÜÇ®±ÒÇ®°üÖеÄÊý¾ÝÒÔ¼°ÎļþϵͳµÄÊý¾Ý¡£¡£ ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/unofficial-windows-11-upgrade-installs-info-stealing-malware/


4¡¢°²È«¹«Ë¾PRODAFT°ä²¼ÀÕË÷Èí¼þPYSAµÄÉî¶È·ÖÎö»ã±¨


4ÔÂ14ÈÕ£¬£¬£¬ £¬£¬£¬ £¬ £¬°²È«¹«Ë¾PRODAFT°ä²¼Á˹ØÓÚÀÕË÷Èí¼þPYSAµÄÉî¶È·ÖÎö»ã±¨¡£¡£ ¡£¡£¡£¡£¡£PYSAÊÇMespinozaµÄ¼ÌÈÎÕߣ¬£¬£¬ £¬£¬£¬ £¬ £¬ÓÚ2019Äê12Ô³õ´Î±»·¢ÏÖ£¬£¬£¬ £¬£¬£¬ £¬ £¬ÒѳÉΪ2021ÄêQ4¼ì²âµ½µÄµÚÈý´óÊ¢ÐÐÀÕË÷Èí¼þ£¬£¬£¬ £¬£¬£¬ £¬ £¬×Ô2020Äê9ÔÂÒÔÀ´Ð¹Â¶Á˶à´ï747¸ö±»¹¥»÷Ö¸±êµÄÐÅÏ¢¡£¡£ ¡£¡£¡£¡£¡£PRODAFT·¢ÏÖÁËPYSAµÄ¹«¿ª.gitÎļþ¼Ð£¬£¬£¬ £¬£¬£¬ £¬ £¬ÆäÖÐÒ»¸ö³ÉÔ±ÊÇ¡°dodo@mail.pcc¡±£¬£¬£¬ £¬£¬£¬ £¬ £¬Æ¾¾ÝÌá½»º¹ÇàÅжϴËÈËλÓÚÒ»¸öÏÄÁîʱ¹ú¶È¡£¡£ ¡£¡£¡£¡£¡£PYSAµÄ»ù´¡ÉèÊ©»¹Ô̺¬dockerizedÈÝÆ÷£¬£¬£¬ £¬£¬£¬ £¬ £¬É漰й¶·þÎñÆ÷¡¢Êý¾Ý¿âºÍÖÎÀí·þÎñÆ÷£¬£¬£¬ £¬£¬£¬ £¬ £¬ÒÔ¼°´æ´¢¼ÓÃÜÎļþµÄAmazon S3ÔÆ£¬£¬£¬ £¬£¬£¬ £¬ £¬×ܼÆ31.47TB¡£¡£ ¡£¡£¡£¡£¡£


https://thehackernews.com/2022/04/researchers-share-in-depth-analysis-of.html 


5¡¢CheckPoint°ä²¼2022ÄêÃæ¶Ô×î´óµÄÔÆ°²È«ÌôÕ½µÄ»ã±¨


CheckPointÔÚ4ÔÂ18ÈÕ°ä²¼ÁË2022ÄêÃæ¶ÔµÄ×î´óÔÆ°²È«ÌôÕ½µÄ»ã±¨¡£¡£ ¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬ £¬£¬£¬ £¬ £¬³¬¹ý98%µÄ×é֯ʹÓûùÓÚÔÆµÄ»ù´¡¼Ü¹¹£¬£¬£¬ £¬£¬£¬ £¬ £¬76%µÄ×éÖ¯Õ¼ÓÐÓÉÁ½¸ö»ò¶à¸öÔÆÌṩÉ̵ķþÎñ×é³ÉµÄ¶àÔÆ»·¾³¡£¡£ ¡£¡£¡£¡£¡£¶àÔÆ»·¾³µÄ¸´ÔÓÐÔµ¼ÖÂÁ˺ܶàÌôÕ½£¬£¬£¬ £¬£¬£¬ £¬ £¬Ô̺¬Êý¾ÝµÄÒþÖԺͱ£»£»£»£»£»¤¡¢¶àÔÆ»·¾³ÖбØÒªµÄ¼¼Êõ¡¢½â¾ö¹æ»®ÕûºÏÒÔ¼°¿É¼ûÐԺͽÚÔìµÄ²»×ã¡£¡£ ¡£¡£¡£¡£¡£ÊµÏÖÔÆ°²È«µÄÖØÒªÖ¸±êÔ̺¬Ô¤·ÀÔÆÅäÖÃÃýÎó¡¢±£»£»£»£»£»¤ÒÑÔÚʹÓõÄÖØÒªÔÆÀûÓ÷¨Ê½¡¢ÊµÏÖ¼à¹ÜºÏ¹æºÍÕмܶñÒâÈí¼þ¡£¡£ ¡£¡£¡£¡£¡£


https://blog.checkpoint.com/2022/04/18/the-biggest-cloud-security-challenges-in-2022-check-point-software/


6¡¢Fortinet°ä²¼½üÆÚEmotet Maldoc·¢×÷Ç÷ÏòµÄ·ÖÎö»ã±¨


4ÔÂ18ÈÕ£¬£¬£¬ £¬£¬£¬ £¬ £¬Fortinet°ä²¼¹ØÓÚ½üÆÚEmotet·Ö·¢Maldoc»î¶¯µÄ·ÖÎö»ã±¨¡£¡£ ¡£¡£¡£¡£¡£´ËÂֻÆðÍ·ÓÚ2021Äê11ÔÂ16ÈÕ£¬£¬£¬ £¬£¬£¬ £¬ £¬Ê¹ÓÃÁË´¹µöÓʼþÓëÉç»á¹¤³Ì¹¥»÷Ïà½áºÏµÄ·½Ê½£¬£¬£¬ £¬£¬£¬ £¬ £¬À´ÓÕʹָ±ê×°ÖöñÒâÈí¼þ¡£¡£ ¡£¡£¡£¡£¡£ÕâЩ´¹µöÓʼþµÄÖ÷ÌâÐÐÖÐͨ³£ÖÐÔ̺¬¡°Re:¡±»ò¡°Fw:¡±£¬£¬£¬ £¬£¬£¬ £¬ £¬Ê¹Æä¿´ÆðÀ´Ô½·¢ºÏ·¨¡£¡£ ¡£¡£¡£¡£¡£×êÑÐÈËÔ±¼ì²âµ½ÁËÓë´Ë»î¶¯ÓйصÄ5¸ö·ÖÆçÑù±¾£¬£¬£¬ £¬£¬£¬ £¬ £¬ËüÃǵĺê´úÂëºÍÖ´ÐÐÁ÷³Ì´æÔÚ²î¾à¡£¡£ ¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬£¬ £¬ £¬¹¥»÷»î¶¯Ê¹ÓõĶñÒâExcelÎļþµÄÕ¼±ÈΪ93%£¬£¬£¬ £¬£¬£¬ £¬ £¬Ô¶¸ßÓÚ7%µÄ¶ñÒâWordÎĵµ¡£¡£ ¡£¡£¡£¡£¡£


https://www.fortinet.com/blog/threat-research/Trends-in-the-recent-emotet-maldoc-outbreak