åÚÏ뽨¸´Æä±Ê¼Ç±¾µÄUEFI¹Ì¼þÖзì϶£¬£¬£¬£¬£¬Ó°Ïì70¶à¿îÐͺÅ
°ä²¼¹¦·ò 2022-07-14
¾Ý7ÔÂ13ÈÕ±¨Â·£¬£¬£¬£¬£¬åÚÏ뽨¸´ÁËÆä±Ê¼Ç±¾µçÄÔµÄUEFI¹Ì¼þÖеÄÈý¸ö»º³åÇøÒç¶Âí½Å¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶±ðÀëΪReadyBootDxeÇý¶¯·¨Ê½ÖеĻº³åÇøÒç¶Âí½Å£¨CVE-2022-1890£©ÒÔ¼°SystemLoadDefaultDxeÇý¶¯·¨Ê½ÖеĻº³åÇøÒç³ö£¨CVE-2022-1891ºÍCVE-2022-1892£©¡£¡£¡£¡£¡£¡£ESET×êÑÐÈËÔ±Ú¹Êͳƣ¬£¬£¬£¬£¬ÕâЩ·ì϶ÊÇÓÉÓÚ´«µÝ¸øUEFIÔËÐÐʱ·þÎñº¯ÊýGetVariableµÄDataSize²ÎÊýÑéÖ¤²»³ä·Öµ¼Öµģ¬£¬£¬£¬£¬¿É±»ÓÃÀ´ÔÚÆ½Ì¨Æô¶¯µÄÔçÆÚ½×¶ÎʵÏÖËÁÒâ´úÂëÖ´ÐУ¬£¬£¬£¬£¬²¢½Ù³Ö²Ù×÷ϵͳִÐÐÁ÷³ÌÒÔ¼°½ûÓÃһЩ³ÁÒªµÄ°²È«Ö°ÄÜ¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-uefi-firmware-flaws-impact-over-70-lenovo-laptop-models/
2¡¢Á¢ÌÕÍðÄÜÔ´¹«Ë¾Ignitis GroupÔâµ½´ó¹æÄ£DDoS¹¥»÷
¾ÝýÌå7ÔÂ12ÈÕ±¨Â·£¬£¬£¬£¬£¬Á¢ÌÕÍðÄÜÔ´¹«Ë¾Ignitis GroupÔâµ½Á˽üÊ®ÄêÀ´×î´ó¹æÄ£µÄÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£ÉÏÖÜÁù£¬£¬£¬£¬£¬Õë¶Ô¸Ã¹«Ë¾µÄDDoS¹¥»÷µ¼ÖÂÆäÊý×Ö·þÎñºÍÍøÕ¾ÒòÖжϡ£¡£¡£¡£¡£¡£IgnitisÔÚ7ÔÂ9ÈÕ·¢Ìû£¬£¬£¬£¬£¬ËüÒѾ¿ÉÄÜÖÎÀíºÍÏ޶ȹ¥»÷¶ÔÆäϵͳµÄÓ°Ï죬£¬£¬£¬£¬²¢ÇÒûÓз¢ÏÖÈκÎÎ¥¹æÐÐΪ£¬£¬£¬£¬£¬È»¶ø£¬£¬£¬£¬£¬¹¥»÷ÈÔÔÚ½øÐÐÖÓ×£¡£¡£¡£¡£¡£ºÚ¿ÍÍÅ»ïKillnetÔÚÆäTelegramÖаµÊ¾£¬£¬£¬£¬£¬¶ÔÕâ´Î¹¥»÷ÊÂÎñÕÆ¹Ü¡£¡£¡£¡£¡£¡£Á¢ÌÕÍð¹ú·À²¿¸±²¿³¤ÔÚ°ä·¢½²»°Ê±ÖÒ¸æ³Æ£¬£¬£¬£¬£¬²»Òª¹ý¶È¹Ø×¢´ËÀàÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£
https://www.infosecurity-magazine.com/news/lithuanian-energy-ddos-attack/
3¡¢È¥ÖÐÐÄ»¯ÂòÂôËùUniswapÔâµ½´¹µö¹¥»÷Ëðʧ800ÍòÃÀÔª
¾ÝCheck Point 7ÔÂ12ÈÕ±¨Â·£¬£¬£¬£¬£¬È¥ÖÐÐÄ»¯¼ÓÃÜÇ®±ÒÂòÂôËùUniswapÔâµ½´¹µö¹¥»÷£¬£¬£¬£¬£¬Ëðʧ¸ß´ï800ÍòÃÀÔª£¨7500 ETH£©¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñÓÚÖÜÒ»³õ´ÎÆØ¹â£¬£¬£¬£¬£¬BinanceµÄCEOÔÚTwitterÉÏ·¢Îijƣ¬£¬£¬£¬£¬ÔÚETHÇø¿éÁ´Éϼì²âµ½Uniswap V3µÄDZÔÚ·ì϶¡£¡£¡£¡£¡£¡£UniswapÊ×´´ÈËHayden Adams֤ʵÕâÊÇÒ»´Î´¹µö¹¥»÷£¬£¬£¬£¬£¬ÓëºÍ̸×ÔÉíÎ޹ء£¡£¡£¡£¡£¡£¹¥»÷ÕßÏòUniswapÓû§¿ÕͶÁ˶ñÒâ´ú±Ò£¬£¬£¬£¬£¬½«ËûÃÇÓÕµ¼ÖÁÒ»¸ö´¹µöÍøÕ¾£¬£¬£¬£¬£¬¶øºó´ÓÖ¸±êµÄÇ®°üÖÐÇÔÈ¡×ʽ𡣡£¡£¡£¡£¡£
https://blog.checkpoint.com/2022/07/12/8-million-dollars-stolen-in-a-uniswap-phishing-attack/
4¡¢Aerojet RocketdyneÒòÎ¥·´ÍøÂ簲ȫÂÉÀýÖ§¸¶900ÍòÃÀÔª
ýÌå7ÔÂ12Èճƣ¬£¬£¬£¬£¬º½¿Õº½ÌìºÍ¹ú·À¹«Ë¾Aerojet RocketdyneÒÑÔÞ³ÉÖ§¸¶900ÍòÃÀÔª£¬£¬£¬£¬£¬À´ºÍ½â¶ÔÓÚÆäÎ¥·´ÍøÂ簲ȫÂÉÀýµÄËßËÏ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾µÄǰԱ¹¤Æ¾¾Ý¡¶ÐéαË÷Åâ·¨¡·Ïò·¨ÔºÌá¸æ×´ËÏ£¬£¬£¬£¬£¬°µÊ¾ËûÔÚ¹«Ë¾µ£ÈÎÍøÂ簲ȫ¡¢ºÏ¹æºÍ½ÚÔì¸ß¼¶×ܼàʱ£¬£¬£¬£¬£¬¸Ã¹«Ë¾³ÐŵÌṩ1000ÍòÖÁ1500ÍòÃÀÔªµÄÔ¤ËãÒÔ¼°5ÖÁ10ÃûÔ±¹¤ºÍ25Ãû³Ð°üÉÌ£¬£¬£¬£¬£¬ÒÔÌá¸ßÍÆËã»ú°²È«ÐÔ¡£¡£¡£¡£¡£¡£µ«¹¤×÷ÆÚ¼ä£¬£¬£¬£¬£¬Ëû·¢Ïָù«Ë¾Ã»ÓÐÂú×ãÓë¹ú·À²¿¡¢NASA»òÆäËüµ±¾Ö»ú¹¹Ç©¶¨ºÏͬµÄÍøÂ簲ȫҪÇ󡣡£¡£¡£¡£¡£AerojetµÄ½²»°È˻ؾøÔںͽâºÍ̸ÖÐÈÏ¿ÉÓÐ×£¬£¬£¬£¬²¢»Ø¾øÖÃÆÀ¡£¡£¡£¡£¡£¡£
https://therecord.media/rocket-maker-agrees-to-pay-9-million-to-settle-allegations-of-cybersecurity-violations/
5¡¢Î¢Èí³Æ×ÔÈ¥Äê9ÔÂAiTM´¹µö»î¶¯Òѹ¥»÷³¬¹ý10000¸ö×éÖ¯
7ÔÂ12ÈÕ£¬£¬£¬£¬£¬Î¢Èí°ä²¼µÄ×îл㱨³Æ£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃAiTM´¹µöÍøÕ¾×÷Ϊ½øÒ»²½½ðÈÚڲƵÄÇÐÈëµã¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬Ò»¸ö´ó¹æÄ£µÄ´¹µö»î¶¯Ê¹ÓÃÖÐÑëÈË£¨AiTM£©´¹µöÍøÕ¾ÇÔÈ¡ÃÜÂë¡¢½Ù³ÖÓû§µÄµÇ¼»á»°²¢Ìø¹ýÈÏÖ¤¹ý³Ì£¬£¬£¬£¬£¬¼´±ãÓû§ÒÑÆôÓöà³É·ÖÈÏÖ¤£¨MFA£©¡£¡£¡£¡£¡£¡£¶øºó£¬£¬£¬£¬£¬¹¥»÷Õß»áʹÓÃÇÔÈ¡µÄÍ´´¦ºÍ»á»°cookie½Ó¼ûÖ¸±ê»§µÄÓÊÏ䣬£¬£¬£¬£¬²¢¶ÔÆäËüÖ¸±êÖ´ÐÐBEC¹¥»÷¡£¡£¡£¡£¡£¡£Í³¼ÆÊý¾ÝÏÔʾ£¬£¬£¬£¬£¬´Ó2021Äê9ÔÂÆðÍ·£¬£¬£¬£¬£¬AiTM´¹µö»î¶¯ÒÑÕë¶ÔÁË10000¶à¸ö×éÖ¯¡£¡£¡£¡£¡£¡£
https://www.microsoft.com/security/blog/2022/07/12/from-cookie-theft-to-bec-attackers-use-aitm-phishing-sites-as-entry-point-to-further-financial-fraud/
6¡¢Unit42°ä²¼ChromeLoader¶ñÒâÈí¼þ»î¶¯µÄ·ÖÎö»ã±¨
Unit42ÔÚ7ÔÂ12ÈÕ°ä²¼Á˹ØÓÚChromeLoader¶ñÒâÈí¼þ»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£»ã±¨½éÉÜÁËChromeLoaderµÄ¶à¸ö±äÌ壬£¬£¬£¬£¬ÆäÖеÚÒ»¸öWindows±äÖÖÓÚ½ñÄê1Ô³õ´Î±»·¢ÏÖ£¬£¬£¬£¬£¬macOS°æ±¾ÓÚ3Ô·ݳöÏÖ£¬£¬£¬£¬£¬µ«×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬×îÔçÉæ¼°¸Ã¶ñÒâÈí¼þµÄ¹¥»÷Äܹ»×·Òäµ½2021Äê12Ô¡£¡£¡£¡£¡£¡£ChromeLoaderÖØÒªÓÃÓÚä¯ÀÀÆ÷½Ù³ÖºÍadware»î¶¯£¬£¬£¬£¬£¬ÒÔISO»òDMGÎļþÏÂÔØµÄ´ó¾Ö·Ö·¢¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿ª·¢ÕßûÓÐʹÓÃWindows¿ÉÖ´ÐÐÎļþ(.exe)»ò¶¯Ì¬Á´½Ó¿â(.dll)µÈ´«Í³¶ñÒâÈí¼þ£¬£¬£¬£¬£¬¶øÊÇʹÓÃä¯ÀÀÆ÷À©´ó×÷Ϊ×îÖÕpayload¡£¡£¡£¡£¡£¡£
https://unit42.paloaltonetworks.com/chromeloader-malware/


¾©¹«Íø°²±¸11010802024551ºÅ