΢ÈíÅû¶LinuxÖÐͳ³ÆÎªNimbuspwnµÄ2¸öÌáȨ·ì϶µÄÏêÇé
°ä²¼¹¦·ò 2022-04-28΢ÈíÔÚ4ÔÂ26ÈÕÅû¶ÁËLinuxÖÐÒ»×éÃûΪNimbuspwnµÄ·ì϶µÄÏêÇé¡£¡£¡£¡£¡£¡£·ì϶±ðÀëΪĿ¼±éÀú·ì϶(CVE-2022-29799)¡¢·ûºÅÁ´½Ó¾ºÕùÒÔ¼°Time-of-check-time-of-use(TOCTOU)¾ºÕùǰÌá·ì϶(CVE-2022-29800)£¬£¬£¬£¬£¬£¬£¬£¬¿É±»±¾µØ¹¥»÷ÕßÓÃÀ´ÌáÉýȨÏÞ£¬£¬£¬£¬£¬£¬£¬£¬×°ÖúóÃźÍÀÕË÷Èí¼þµÈ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£ËüÃÇ´æÔÚÓÚsystemd×é¼þnetworkd-dispatcherÖУ¬£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»¸öÓÃÓÚÍøÂçÖÎÀíÆ÷ϵͳ·þÎñµÄÊØ»¤·¨Ê½¡£¡£¡£¡£¡£¡£
https://www.microsoft.com/security/blog/2022/04/26/microsoft-finds-new-elevation-of-privilege-linux-vulnerability-nimbuspwn/
2¡¢Google½¨¸´VirusTotalÖеÄRCE·ì϶CVE-2021-22204
ýÌå4ÔÂ26ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬GoogleÒѽ¨¸´VirusTotalƽ̨ÖеÄRCE·ì϶£¨CVE-2021-22204£©¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇExifTool¶ÔDjVuÎļþ´¦Öò»µ±µ¼Öµģ¬£¬£¬£¬£¬£¬£¬£¬¿É±»¹¥»÷ÕßÓÃÀ´±øÆ÷»¯VirusTotalƽ̨£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚʹÓÃɱ¶¾ÒýÇæµÄµÚÈý·½É³ºÐÉÏʵÏÖÔ¶³Ì´úÂëÖ´ÐÓ×£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÌáÐÑ£¬£¬£¬£¬£¬£¬£¬£¬·ì϶²¢²»Ó°ÏìVirusTotal£¬£¬£¬£¬£¬£¬£¬£¬´úÂëÖ´Ðв»´æÔÚÓÚÆ½Ì¨×ÔÉí£¬£¬£¬£¬£¬£¬£¬£¬¶øÊÇÔÚ·ÖÎöºÍÖ´ÐÐÑù±¾µÄµÚÈý·½É¨Ãèϵͳ¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÓÚ2021Äê4Ô±»Åû¶£¬£¬£¬£¬£¬£¬£¬£¬ÓÚ2021Äê5Ô±»½ÓÊÜ£¬£¬£¬£¬£¬£¬£¬£¬¶ø²¹¶¡Óڰ˸öÔºóµÄ2022Äê1Ô°䲼¡£¡£¡£¡£¡£¡£
https://www.hackread.com/critical-rce-vulnerability-google-virustotal/
3¡¢StormousÍÅ»ïÐû³ÆÒÑÇÔÈ¡ÊʿڿÉÀÖ¹«Ë¾161 GBµÄÊý¾Ý
¾Ý4ÔÂ26ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬ÀÕË÷ÍÅ»ïStormousÐû³ÆÒÑÇÔÈ¡ÊʿڿÉÀÖ¹«Ë¾³¬¹ý161 GBµÄÊý¾Ý¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ÁгöÁË´ýÊÛÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬²¢ÏòÊʿڿÉÀÖ¹«Ë¾ÀÕË÷1.65±ÈÌØ±Ò£¨Ô¼ºÏ64000ÃÀÔª£©¡£¡£¡£¡£¡£¡£Ð¹Â¶Êý¾ÝÔ̺¬Ñ¹ËõÎĵµ¡¢µç×ÓÓʼþºÍÃÜÂëµÄÎı¾Îļþ¡¢ÕÊ»§ºÍ¸¶¿îÓйØZIPÎĵµµÈ¡£¡£¡£¡£¡£¡£ÕâÊÇStormousÍÅ»ïµÚÒ»´Î¹«¿ª±»µÁÊý¾Ý¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£ÊʿڿÉÀÖ¹«Ë¾°µÊ¾ÖªÏ¤ÓëÆäÓйصÄÍøÂç¹¥»÷µÄ±¨Â·ºó£¬£¬£¬£¬£¬£¬£¬£¬ÔÚµ÷²é´ËÊÂÎñ¡£¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/130614/cyber-crime/stormous-ransomware-hit-coca-cola.html
4¡¢Hive0117¼ÙÒâ¶íÂÞ˹·¨Âɲ¿ÃŶԶ«Å·¹ú¶È½øÐд¹µö¹¥»÷
ýÌå4ÔÂ27Èճƣ¬£¬£¬£¬£¬£¬£¬£¬IBMµÄX-ForceÍŶӷ¢ÏÖ½üÆÚÕë¶Ô¶«Å·¹ú¶ÈµÄ´¹µö¹¥»÷¡£¡£¡£¡£¡£¡£Õâ´Î´¹µö»î¶¯ÆðÍ·ÓÚ2022Äê2Ô£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚ·Ö·¢ÃûΪDarkWatchmanµÄÎÞÎļþ¶ñÒâÈí¼þ±äÖÖ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¼ÙÒâ¶íÂÞ˹µÄ·¨Âɲ¿ÃÅ£¬£¬£¬£¬£¬£¬£¬£¬ÊÕ¼þÈËÊÇÁ¢ÌÕÍð¡¢°®É³ÄáÑǺͶíÂÞ˹µÄµçÕÛ·þÎñÌṩÉ̺͹¤Òµ¹«Ë¾¡£¡£¡£¡£¡£¡£´¹µöÓʼþÀ´×Ô˾·¨²¿µÄÕæÊµµØÖ·£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈç¡°mail@r77[.]fssprus[.]ru¡±£¬£¬£¬£¬£¬£¬£¬£¬ÕýÎÄ»¹´øÓÐÕæÊµµÄ±êÖ¾¡£¡£¡£¡£¡£¡£Ëù¸½µÄZIPÎļþÔ̺¬×°ÖÃDarkWatchmanµÄ¿ÉÖ´ÐÐÎļþ£¬£¬£¬£¬£¬£¬£¬£¬ºÍ¼ÓÃܵļüÅ̼ͼ·¨Ê½¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/russian-govt-impersonators-target-telcos-in-phishing-attacks/
5¡¢Secureworks³ÆConti±³ºóÍÅ»ïGold UlrickµÄ»î¶¯¼¤Ôö
ýÌå4ÔÂ26Èճƣ¬£¬£¬£¬£¬£¬£¬£¬¹ÌÈ»ÀÕË÷Èí¼þContiÔÚ²»¾Ãǰ²úÉúÁËÊý¾Ýй©ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬£¬µ«Æä±³ºóÍÅ»ïGold UlrickµÄ¹¥»÷ÈÔÔÚ³ÖÐø¡£¡£¡£¡£¡£¡£ContiÊý¾ÝÐ¹Â¶ÍøÕ¾ÔÚ2021Äê¾ùÔÈÿÔÂÁгö43¸ö±»¹¥»÷Ö¸±ê£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ11Ô´ﵽ·åÖµ£¬£¬£¬£¬£¬£¬£¬£¬Îª95¸ö¡£¡£¡£¡£¡£¡£2022Äê2ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬@ContiLeaks¹«¿ªÁËGOLD ULRICKµÄÊý¾ÝºÍͨѶ£¬£¬£¬£¬£¬£¬£¬£¬µ«3Ô·ݱ»¹¥»÷Ö¸±êµÄÊýÁ¿¼¤Ôö£¬£¬£¬£¬£¬£¬£¬£¬½ö´ÎÓÚÈ¥Äê11ÔµķåÖµ¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïµÄ³ÉÔ±¡°Jordan Conti¡±°µÊ¾Êý¾Ýй¶¶ÔÆäÓ°ÏìºÜÓ×£¬£¬£¬£¬£¬£¬£¬£¬ÆäÍøÕ¾ÔÚ4ÔµÄǰËÄÌì¾ÍÔö³¤ÁË11¸ö±»¹¥»÷Ö¸±ê¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2022/04/gold-ulrick-hackers-still-in-action.html
6¡¢Kaspersky°ä²¼2022ÄêQ1 DDoS¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨
2ÔÂ25ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Kaspersky°ä²¼2022ÄêQ1 DDoS¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬£¬£¬2022ÄêµÚÒ»¼¾¶ÈµÄDDoS¸ñ¾ÖÊܵ½¶íÂÞ˹ºÍÎÚ¿ËÀ¼Ö®¼ä³ÖÐøÃ¬¶ÜµÄÓ°Ïì¡£¡£¡£¡£¡£¡£KasperskyÔÚµÚÒ»¼¾¶È×ܹ²¼ì²âµ½ 91052´ÎDDoS¹¥»÷£»£»£»£»£»44.34%µÄ¹¥»÷Õë¶ÔÃÀ¹ú£¬£¬£¬£¬£¬£¬£¬£¬Õ¼ËùÓй¥»÷µÄ45.02%¡£¡£¡£¡£¡£¡££»£»£»£»£»×î¶àµÄDDoS¹¥»÷(16.35%)²úÉúÔÚÖÜÈÕ£»£»£»£»£»´óÎÞÊý¹¥»÷£¨94.95%£©³ÖÐø²»µ½4Ó×ʱ£¬£¬£¬£¬£¬£¬£¬£¬×µÄ¹¥»÷³ÖÐøÁË549Ó×ʱ£»£»£»£»£»53.64%µÄ¹¥»÷ÊÇUDPºé·º£»£»£»£»£»55.53%µÄC&C·þÎñÆ÷λÓÚÃÀ¹ú¡£¡£¡£¡£¡£¡£
https://securelist.com/ddos-attacks-in-q1-2022/106358/


¾©¹«Íø°²±¸11010802024551ºÅ