ÐÂÀÕË÷Èí¼þGoodWillÒªÇóÖ¸±êʵÏÖÈýÏîÉç»á¾ÈÖú»î¶¯

°ä²¼¹¦·ò 2022-05-31

1¡¢ÐÂÀÕË÷Èí¼þGoodWillÒªÇóÖ¸±êʵÏÖÈýÏîÉç»á¾ÈÖú»î¶¯


¾Ý5ÔÂ29ÈÕ±¨Â·£¬£¬£¬£¬£¬ £¬£¬CloudSEKÅû¶ÁËÒ»ÖÖÃûΪGoodWillµÄÐÂÀÕË÷Èí¼þ¡£¡£¡£¡£¡£¸ÃÀÕË÷Èí¼þÓÚ2022Äê3Ô³õ´Î±»·¢ÏÖ£¬£¬£¬£¬£¬ £¬£¬ÓÉ.NET±àд£¬£¬£¬£¬£¬ £¬£¬Ê¹ÓÃAESËã·¨½øÐмÓÃÜ£¬£¬£¬£¬£¬ £¬£¬²¢Í¨¹ýÐÝÃß722.45ÃëÀ´×ÌÈŶ¯Ì¬·ÖÎö¡£¡£¡£¡£¡£Ëü²»ÊdzöÓÚ¾­¼Ã¶¯»úµÄÀÕË÷»î¶¯£¬£¬£¬£¬£¬ £¬£¬ÆäÊê½ð¼Í¼עÃ÷£¬£¬£¬£¬£¬ £¬£¬ÒªÇóÖ¸±ê½øÐÐÈýÏîÉç»á¾ÈÖú»î¶¯ÄÜÁ¦»ñµÃ½âÃܹ¤¾ß£¬£¬£¬£¬£¬ £¬£¬Ô̺¬ÏòÎ޼ҿɹéÕß¾èÔùÐÂÒ·þºÍ̺×Ó£¬£¬£¬£¬£¬ £¬£¬ÒÔ¼°´øÎå¸öÇîÀ§¶ùͯȥ³Ô·¹µÈ¡£¡£¡£¡£¡£Ö®ºó»¹ÒªÇóÖ¸±êÒÔÆÁÄ»½ØÍ¼ºÍ×ÔÅĵĴó¾Ö¼Í¼»î¶¯£¬£¬£¬£¬£¬ £¬£¬²¢°ä²¼ÔÚËûÃǵÄÉ罻ýÌåÉÏ¡£¡£¡£¡£¡£¹¥»÷ÕßÉí·ÝÉв»Ã÷È·£¬£¬£¬£¬£¬ £¬£¬µ«Í¨¹ý¶ÈÎö·¢ÏÖÔËÓªÈËÔ±À´×ÔÓ¡¶È¡£¡£¡£¡£¡£


https://thehackernews.com/2022/05/new-goodwill-ransomware-forces-victims.html


2¡¢EnemyBotµÄ±äÌåÐÂÔöVMwareºÍF5 BIG-IPµÈ·ì϶


AT&T Alien LabsÔÚ5ÔÂ26ÈÕ°ä²¼µÄÒ»·Ý»ã±¨Ö¸³ö£¬£¬£¬£¬£¬ £¬£¬EnemyBotµÄ×îбäÌåÔ̺¬24¸ö·ì϶¡£¡£¡£¡£¡£ÆäÖдóÎÞÊý¶¼ÊÇÑϳÁµÄ·ì϶£¬£¬£¬£¬£¬ £¬£¬Óм¸¸öÉõÖÁûÓÐCVE±àºÅ£¬£¬£¬£¬£¬ £¬£¬ÕâʹµÃ·ÀÓù±äµÃÔ½·¢ÄÑÌâ¡£¡£¡£¡£¡£¸Ã±äÌåÔ̺¬VMwareÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2022-22954£©¡¢SpringÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2022-22947£©ºÍF5 BIG-IPµÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2022-1388£©¡£¡£¡£¡£¡£EnemyBot±³ºóµÄÍÅ»ïKeksecÈÔÔÚ»ý¼«¿ª·¢¸Ã¶ñÒâÈí¼þ£¬£¬£¬£¬£¬ £¬£¬¸ÃÍŻﻹռÓÐTsunami¡¢Gafgyt¡¢DarkHTTP¡¢DarkIRCºÍNecro¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ £¬£¬AT&T³ÆEnemyBotµÄÔ´´úÂëÒѾ­¹«¿ª£¬£¬£¬£¬£¬ £¬£¬ÈκÎÈ˶¼Äܹ»ÀûÓÃËü¡£¡£¡£¡£¡£


https://cybersecurity.att.com/blogs/labs-research/rapidly-evolving-iot-malware-enemybot-now-targeting-content-management-system-servers


3¡¢×êÑÐÈËÔ±ÑÝʾÈôºÎÀûÓõç´ÅÐźÅÔ¶³Ì½ÚÔì´¥ÃþÆÁ


¾ÝýÌå5ÔÂ27ÈÕ±¨Â·£¬£¬£¬£¬£¬ £¬£¬×êÑÐÈËÔ±·¢ÏÖÒ»ÖÖÐµĹ¥»÷·½Ê½GhostTouch£¬£¬£¬£¬£¬ £¬£¬¿ÉÀûÓõç´ÅÐźÅÔ¶³Ì½ÚÔì´¥ÃþÆÁ¡£¡£¡£¡£¡£ÆäÖ÷Ìâ˼ÏëÊÇÀûÓõç´ÅÐźÅÀ´Ö´Ðиù»ùµÄ´¥Ãþ²Ù×÷£¬£¬£¬£¬£¬ £¬£¬ÀýÈçÇáÇúͻ¬¶¯µ½´¥ÃþÆÁ£¬£¬£¬£¬£¬ £¬£¬Ö¼ÔÚÊÕÊÜÔ¶³Ì½ÚÔìºÍ²Ù¿Øµ×²ãÉ豸¡£¡£¡£¡£¡£ÕâÖÖ¹¥»÷¿ÉÔÚ40ºÁÃ׵ľàÀëÄÚ²ûÑï×÷Ó㬣¬£¬£¬£¬ £¬£¬Æä¹Ø¼üÔÚÓÚµçÈÝʽ´¥ÃþÆÁ¶Ôµç´Å×ÌÈÅ£¨EMI£©µÄÃô¸ÐÐÔ£¬£¬£¬£¬£¬ £¬£¬ÀûÓÃËü½«µç´ÅÐźÅ×¢ÈëÄÚÖÃÓÚ´¥ÃþÆÁÖеÄͨÃ÷µç¼«¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬ £¬£¬ÈËÃÇ¿ÉÄܻὫÖÇÄÜÊÖ»úÃæ³¯Ï·ÅÔÚ×À×ÓÉÏ£¬£¬£¬£¬£¬ £¬£¬¹¥»÷Õß¾ÍÄܹ»½«¹¥»÷É豸ǶÈë×ÀÃæÏ£¬£¬£¬£¬£¬ £¬£¬ÌáÒéÔ¶³Ì¹¥»÷¡£¡£¡£¡£¡£


https://thehackernews.com/2022/05/attackers-can-use-electromagnetic.html


4¡¢¹ú¼ÊÐ̾¯×éÖ¯ÒÑ¿ÛÁôÈýÃûʹÓÃRAT½øÐнðÈÚ·¸×ïµÄÏÓÒÉÈË


ýÌå5ÔÂ30Èճƣ¬£¬£¬£¬£¬ £¬£¬¹ú¼ÊÐ̾¯×éÖ¯ÒÑ¿ÛÁôÈýÃûÄáÈÕÀûÑǵÄÍøÂç·¸×ïÏÓÒÉÈË¡£¡£¡£¡£¡£Õâ´ÎÐж¯´úºÅΪKiller Bee£¬£¬£¬£¬£¬ £¬£¬Óɹú¼ÊÐ̾¯×é֯ǣͷ£¬£¬£¬£¬£¬ £¬£¬¶«ÄÏÑÇ11¹úµÄ·¨ÂÉ»ú¹¹Ð­Öú¡£¡£¡£¡£¡£¸ÃÍÅ»ïÉæÏÓʹÓÃÔ¶³Ì½Ó¼ûľÂíAgent Tesla´Û¸Ä½ðÈÚÂòÂô²¢ÇÔÈ¡ÕË»§Æ¾Ö¤£¬£¬£¬£¬£¬ £¬£¬Ö¸±êÔ̺¬Öж«¡¢±±·ÇºÍ¶«ÄÏÑǵĴóÐÍÆóÒµ×éÖ¯ºÍÓÍÆø¹«Ë¾¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬ £¬£¬·¨ÂÉ»ú¹¹²¢Î´Ð¹Â©Æä´ÓÖ¸±ê×éÖ¯ÄÇÀïÇÔÈ¡Á˼¸¶àÇ®¡£¡£¡£¡£¡£ÉÏÖÜ£¬£¬£¬£¬£¬ £¬£¬¹ú¼ÊÐ̾¯×éÖ¯µÄÁíÒ»¸ö´úºÅΪDelilahµÄÐж¯ÖпÛÁôÁËSilverTerrierÍÅ»ïµÄÍ·×Ó¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/three-nigerians-arrested-for-malware-assisted-financial-crimes/


5¡¢FBI³Æ¹¥»÷ÕßÔÚ°µÍøÉÏÏúÊÛÃÀ¹ú¸ßУµÄÍøÂç½Ó¼ûÍ´´¦


FBIÔÚ5ÔÂ26ÈÕ°ä²¼µÄµÄ¹«¸æ³Æ£¬£¬£¬£¬£¬ £¬£¬ÃÀ¹ú¸ßУµÄÍøÂç½Ó¼ûƾ֤ºÍVPN½Ó¼ûȨÏÞÔÚ°µÍøÉÏÏúÊÛ¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓÃÓã²æÊ½´¹µö¹¥»÷ºÍÀÕË÷¹¥»÷µÈÕ½ÊõÀ´ÍøÂçÆ¾Ö¤£¬£¬£¬£¬£¬ £¬£¬¶øºó½«»ñµÃµÄƾ֤°ä²¼ÔÚ¶íÂÞ˹µÄºÚ¿ÍÂÛ̳ÉÏ£¬£¬£¬£¬£¬ £¬£¬ÒÔ¼¸ÃÀÔªµ½¼¸Ç§ÃÀÔª²»µÈµÄ¼ÛÖµÏúÊÛ¡£¡£¡£¡£¡£¸Ã»ú¹¹³Æ£¬£¬£¬£¬£¬ £¬£¬¹¥»÷Õß¿ÉÀûÓÃÕâЩµÇ¼ÐÅÏ¢½øÐб©Á¦×²¿â¹¥»÷£¬£¬£¬£¬£¬ £¬£¬¿ÉÓâÔ½·ÖÆçµÄÕË»§¡¢ÍøÕ¾ºÍ·þÎñÈëÇÖÖ¸±ê£¬£¬£¬£¬£¬ £¬£¬²¢½¨Òéͨ¹ýÏÞ¶ÈÕÊ»§µÄʹÓõØÎ»ºÍÆôÓñ¾µØÉ豸ʹ´¦±£»£»£»£»£»£»£»¤»úÔìÀ´Ï÷¼õÍ´´¦Ð¹Â¶¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/fbi-warns-of-hackers-selling-credentials-for-us-college-networks/


6¡¢Kaspersky°ä²¼2022ÄêQ1ÒÆ¶¯¶ñÒâÈí¼þÌ¬ÊÆµÄ·ÖÎö»ã±¨


5ÔÂ27ÈÕ£¬£¬£¬£¬£¬ £¬£¬Kaspersky°ä²¼ÁË2022ÄêµÚÒ»¼¾¶ÈÒÆ¶¯¶ñÒâÈí¼þÌ¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬ £¬£¬ÔÚµÚÒ»¼¾¶È¹²¼ì²âµ½516617¸ö¶ñÒâ×°Öðü£¬£¬£¬£¬£¬ £¬£¬±ÈÉÏÒ»¼¾¶ÈÏ÷¼õ79448¸ö£¬£¬£¬£¬£¬ £¬£¬ÆäÖÐ53947¸öÓëÊÖ»úÒøÐÐľÂíÓйأ¬£¬£¬£¬£¬ £¬£¬1942¸öÊÇÒÆ¶¯ÀÕË÷Èí¼þ¡£¡£¡£¡£¡£ÔÚ¼ì²âµ½µÄËùÓÐÍþвÖУ¬£¬£¬£¬£¬ £¬£¬Õ¼±È×î´óµÄÊÇRiskToolÀûÓ÷¨Ê½£¨48.75%£©£¬£¬£¬£¬£¬ £¬£¬Æä´ÎÊǸæ°×Èí¼þÀûÓã¨16.92%£©¡£¡£¡£¡£¡£ÖØÒªµÄÒÆ¶¯¶ñÒâÈí¼þ·¨Ê½ÊÇDangerousObject.Multi.Generic (Õ¼±È20.45%)£¬£¬£¬£¬£¬ £¬£¬Æä´ÎÊÇTrojan.AndroidOS.Fakemoney.d£¨10.73%£©ºÍTrojan-SMS.AndroidOS.Fakeapp.d£¨7.82 £©¡£¡£¡£¡£¡£


https://securelist.com/it-threat-evolution-in-q1-2022-mobile-statistics/106589/