΢Èí°ä²¼6Ô°²È«¸üн¨¸´FollinaÔÚÄÚµÄ55¸ö·ì϶

°ä²¼¹¦·ò 2022-06-15
1¡¢Î¢Èí°ä²¼6Ô·ݰ²È«¸üн¨¸´FollinaÔÚÄÚµÄ55¸ö·ì϶


6ÔÂ14ÈÕ£¬ £¬£¬£¬£¬Î¢Èí°ä²¼Á˱¾ÔµÄÖܶþ²¹¶¡£¬ £¬£¬£¬£¬×ܼƽ¨¸´ÁË55¸ö·ì϶¡£ ¡£¡£¡£¡£ÆäÖÐÔ̺¬12¸öÌáȨ·ì϶¡¢1°²È«Ö°ÄÜÈÆ¹ý·ì϶¡¢27¸öÔ¶³Ì´úÂëÖ´Ðзì϶¡¢11¸öÐÅϢй¶·ì϶¡¢3¸ö»Ø¾ø·þÎñ·ì϶ºÍ1¸öºýŪ·ì϶¡£ ¡£¡£¡£¡£ÆäÖÐ×îÑϳÁµÄÊÇWindows MSDTÖеķì϶Follina£¨CVE-2022-30190£©£¬ £¬£¬£¬£¬Òѱ»¶à¸ö¹¥»÷ÍÅ»ïÀûÓᣠ¡£¡£¡£¡£´Ë±í£¬ £¬£¬£¬£¬»¹½¨¸´ÁËWindows Hyper-VÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2022-30163£©¡¢WindowsÇáÁ¿¼¶Ä¿Â¼½Ó¼ûºÍ̸(LDAP)Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2022-30139£©ºÍWindowsÍøÂçÎļþϵͳԶ³Ì´úÂëÖ´Ðзì϶£¨CVE-2022-30136£©µÈ¡£ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2022-patch-tuesday-fixes-1-zero-day-55-flaws/


2¡¢AvastÔÚÒ°·¢ÏÖÈÔÔÚ¿ª·¢ÖеÄLinux rootkit Syslogk


6ÔÂ13ÈÕ£¬ £¬£¬£¬£¬AvastÅû¶ÁËÔÚÒ°·¢ÏÖµÄÒ»ÖÖÃûΪ¡°Syslogk¡±µÄÐÂLinux rootkitµÄ¼¼Êõϸ½Ú¡£ ¡£¡£¡£¡£Syslogk»ùÓÚ¿ªÔ´µÄLinuxÄÚºËrootkit Adore-Ng£¬ £¬£¬£¬£¬Ä¿Ç°ÈÔÔÚ¿ª·¢ÖÓ×£ ¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ Õë¶ÔLinuxÄÚºË3.x£¬ £¬£¬£¬£¬¿É°µ²ØÄ¿Â¼ºÍÍøÂçÁ÷Á¿£¬ £¬£¬£¬£¬²¢¼ÓÔØÒ»¸öÃûΪ¡°Rekoobe¡±µÄºóÃÅ¡£ ¡£¡£¡£¡£Õâ¸öºóÃÅÔÚÖ¸±êϵͳÖн«Ê¼ÖÕ´¦ÓÚÐÝÃß״̬£¬ £¬£¬£¬£¬Ö±µ½½Ó¹Üµ½À´×Ô¹¥»÷Õߵġ°magic packets¡±¡£ ¡£¡£¡£¡£ÆäÖØÒªÖ÷ÕÅÊÇΪ¹¥»÷ÕßÌṩָ±êÉ豸ÉϵÄÔ¶³Ìshell£¬ £¬£¬£¬£¬¿Éµ¼ÖÂÐÅϢй¶¡¢Êý¾Ýй¶¡¢Îļþ²Ù×÷ºÍÕÊ»§½Ù³ÖµÈ¡£ ¡£¡£¡£¡£


https://decoded.avast.io/davidalvarez/linux-threat-hunting-syslogk-a-kernel-rootkit-found-under-development-in-the-wild/


3¡¢ÃÀ¹úKaiser Permanente³Æ½ü7ÍòÈ˵ÄÐÅÏ¢±»·¸·¨½Ó¼û


¾ÝýÌå6ÔÂ13ÈÕ±¨Â·£¬ £¬£¬£¬£¬ÃÀ¹úÒ½ÁÆ»ú¹¹Kaiser Permanente³ÆÆäÔâµ½ÁËÍøÂç¹¥»÷¡£ ¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚÆä¹ÙÍøÉϰ䲼µÄ֪ͨй©£¬ £¬£¬£¬£¬2022Äê4ÔÂ5ÈÕ£¬ £¬£¬£¬£¬¹¥»÷ÕßÔÚδ¾­ÊÚȨµÄÇé¿öϽӼûÁËÆäÔ±¹¤µÄµç×ÓÓÊÏ䣬 £¬£¬£¬£¬ÆäÖÐÉæ¼°»¼ÕߵĽ¡È«ÐÅÏ¢£¨PHI£©¡£ ¡£¡£¡£¡£Kaiser PermanenteÓÚ6ÔÂ3ÈÕ֪ͨÊÜÓ°Ï컼Õߣ¬ £¬£¬£¬£¬²¢°µÊ¾Ð¹Â¶µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢²¡Àú±àºÅ¡¢·þÎñÈÕÆÚºÍ¼ì²âÁ˾ֵȡ£ ¡£¡£¡£¡£¸Ã¹«Ë¾Ìá½»¸øÃÀ¹úµ±¾ÖµÄ»ã±¨ÏÔʾ£¬ £¬£¬£¬£¬´ËÊÂÎñÒѵ¼ÖÂ69589È˵ÄPHIй¶¡£ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/kaiser-permanente-data-breach-exposes-health-data-of-69k-people/


4¡¢GaliumÀûÓÃÐÂRAT PingPull¹¥»÷Å·ÖÞ¡¢·ÇÖ޺Ͷ«ÄÏÑÇ


Unit 42ÔÚ6ÔÂ13ÈÕ¹«¿ªÁËAPTÍÅ»ïGaliumÕë¶ÔÅ·ÖÞ¡¢·ÇÖ޺Ͷ«ÄÏÑǵÄй¥»÷»î¶¯¡£ ¡£¡£¡£¡£Õâ´Î»î¶¯ÖØÒªÕë¶ÔµçÐÅ¡¢µ±¾ÖºÍ½ðÈÚ»ú¹¹£¬ £¬£¬£¬£¬ÀûÓÃÁËÒ»ÖÖÃûΪPingPullµÄÐÂRAT¡£ ¡£¡£¡£¡£PingPullÊÇ»ùÓÚVisual C++µÄ¶ñÒâÈí¼þ£¬ £¬£¬£¬£¬ËüÖ¼ÔÚΪ¹¥»÷ÕßÌṩÔÚÖ¸±êϵͳÖеķ´Ïòshell£¬ £¬£¬£¬£¬²¢Ö´ÐÐËÁÒâºÅÁî¡£ ¡£¡£¡£¡£Unit42¶ÔÈý¸öÓµÓÐÀàËÆÖ°Äܵķ֯ç±äÌå½øÐвÉÑù£¬ £¬£¬£¬£¬·¢ÏÖÕâЩ±äÌåʹÓÃÁË·ÖÆçµÄC2ͨѶºÍ̸£ºICMP¡¢HTTPSºÍTCP¡£ ¡£¡£¡£¡£×êÑÐÈËÔ±»¹·¢ÏÖÁËÓëGalliumÓйصĻù´¡ÉèÊ©Ô̺¬170¶à¸öIPµØÖ·£¬ £¬£¬£¬£¬ÓÐЩÄܹ»×·Òäµ½2020Äêµ×¡£ ¡£¡£¡£¡£


https://unit42.paloaltonetworks.com/pingpull-gallium/


5¡¢Confiant·¢ÏÖÇÔÈ¡Web3Ç®°ü×ʽðµÄSeaFlower»î¶¯


¾Ý6ÔÂ13ÈÕ±¨Â·£¬ £¬£¬£¬£¬Confiant·¢ÏÖÁËÕë¶ÔWeb3Ç®°üµÄSeaFlower»î¶¯¡£ ¡£¡£¡£¡£¸Ã»î¶¯ÓÚ½ñÄê3Ô³õ±»·¢ÏÖ£¬ £¬£¬£¬£¬Ò»Ö¹Øë¶ÔAndroidºÍiOSÓû§£¬ £¬£¬£¬£¬·ÂÕÕ¹Ù·½¼ÓÃÜÇ®±ÒÇ®°üÍøÕ¾£¬ £¬£¬£¬£¬²¢ÀûÓÃÁËSEO¼¼Êõ£¬ £¬£¬£¬£¬À´·Ö·¢ÇÔȡָ±ê×ʽðµÄºóÃÅÀûÓᣠ¡£¡£¡£¡£Ä¿Ç°£¬ £¬£¬£¬£¬SeaFlowerÖØÒªÊ¹ÓúóÃÅ´úÂëÅú¸ÄWeb3Ç®°ü£¬ £¬£¬£¬£¬²¢ÇÔÈ¡ÖÖ×ÓÃÜÂ루seed phrase£©¡£ ¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾£¬ £¬£¬£¬£¬¸Ã»î¶¯µÄÖ¸±êÀûÓÃÔ̺¬AndroidºÍiOS°æ±¾µÄCoinbase Wallet¡¢MetaMask¡¢TokenPocketºÍimToken¡£ ¡£¡£¡£¡£


https://thehackernews.com/2022/06/chinese-hackers-distribute-backdoored.html


6¡¢Î¢Èí°ä²¼¹ØÓÚÀÕË÷Èí¼þBlackCatµÄ¼¼Êõ·ÖÎö»ã±¨


΢ÈíÔÚ6ÔÂ13ÈÕ°ä²¼Á˹ØÓÚÀÕË÷Èí¼þBlackCat£¨Ò²³ÆALPHV£©µÄ·ÖÎö»ã±¨¡£ ¡£¡£¡£¡£BlackCatÓÚ2021Äê11Ô³õ´Î±»·¢ÏÖ£¬ £¬£¬£¬£¬ÊÇ×îÔçÓÃRust±àдµÄÀÕË÷Èí¼þÖ®Ò»£¬ £¬£¬£¬£¬Äܹ»¹¥»÷WindowsºÍLinuxÉ豸£¬ £¬£¬£¬£¬ÒÔ¼°VMWareÊ·ý¡£ ¡£¡£¡£¡£½üÆÚ£¬ £¬£¬£¬£¬×êÑÐÈËÔ±¹Û²ìµ½Ò»¸ö¹¥»÷ÕßÀûÓÃExchange·þÎñÆ÷·ì϶À´»ñµÃÖ¸±êÍøÂç½Ó¼û¡£ ¡£¡£¡£¡£´Ë±í£¬ £¬£¬£¬£¬ÖÁÉÙÓÐÁ½¸ö´ÓÊô×éÖ¯ÔÚÀûÓÃBlackCat: DEV-0237ºÍDEV-0504¡£ ¡£¡£¡£¡£Æ¾¾Ý΢ÈíµÄÊý¾Ý£¬ £¬£¬£¬£¬BlackCatÒÑÓ°ÏìÁË·ÇÖÞ¡¢ÃÀÖÞ¡¢ÑÇÖÞºÍÅ·Ö޵ĸ÷¸ö¹ú¶È²¢ÒýÆðÆ÷³Á¡£ ¡£¡£¡£¡£


https://www.microsoft.com/security/blog/2022/06/13/the-many-lives-of-blackcat-ransomware/