×êÑÐÈËÔ±¼ì²âµ½241¸ö¶ñÒânpmºÍPyPI°ü·Ö·¢ÍÚ¿óÈí¼þ

°ä²¼¹¦·ò 2022-08-22
1¡¢×êÑÐÈËÔ±¼ì²âµ½241¸ö¶ñÒânpmºÍPyPI°ü·Ö·¢ÍÚ¿óÈí¼þ

      

¾ÝýÌå8ÔÂ19ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬ÉÏÖÜÒÑ·¢ÏÖÁËÖÁÉÙ241¸ö¶ñÒâµÄPyPIºÍnpm°ü£¬£¬£¬£¬£¬£¬ÕâЩ°ü»áÔÚϰȾLinuxÉ豸ºó»á×°ÖöñÒâÍÚ¿óÈí¼þ¡£¡£¡£¡£¡£¡£¡£ÉÏÖÜÈý£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±¹«¿ªÁËÔÚPyPIÉÏ·¢ÏÖµÄ33¸öÏîÄ¿£¬£¬£¬£¬£¬£¬¿ÉÔÚϰȾϵͳºóÆô¶¯¿ªÔ´ÃÅÂÞ±Ò¼ÓÃÜ¿ó¹¤XMRig¡£¡£¡£¡£¡£¡£¡£ÔÚÕâЩ°ü±»É¾³ýºó£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±ÓÖ·¢ÏÖÁËÁíÒ»×éÓµÓÐÒ»ÑùpayloadµÄ22¸ö°ü¡£¡£¡£¡£¡£¡£¡£SonatypeÔÚ8ÔÂ19ÈÕÅû¶ÁË186¸önpmÓòÃûÇÀ×¢¶ñÒâ°ü£¬£¬£¬£¬£¬£¬ËüÃǾùÀ´×ÔÄäÃûÕÊ»§17b4a931£¬£¬£¬£¬£¬£¬·ÂÕÕÁ˳£ÓõÄhttp-errors JavaScript¿â¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËԱƾ¾Ý¼¼ÊõÖ¸±ê´§¶È£¬£¬£¬£¬£¬£¬Õâ241¸ö¶ñÒâ°üÓÉͳһ¹¥»÷Õß°ä²¼¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/241-npm-and-pypi-packages-caught-dropping-linux-cryptominers/


2¡¢ÐÂľÂíGrandoreiroÖØÒªÕë¶ÔÄ«Î÷¸çºÍÎ÷°àÑÀµÈ¹ú¶È

      

8ÔÂ18ÈÕ£¬£¬£¬£¬£¬£¬Zscaler ThreatLabzÅû¶ÁËÐÂľÂíGrandoreiroÕë¶ÔÄ«Î÷¸çºÍÎ÷°àÑÀµÈ¹ú¶ÈµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÖÁÉÙ×Ô2017ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬£¬£¬£¬£¬£¬Õâ´Î¹¥»÷ÓÚ2022Äê6ÔÂÆðÍ·£¬£¬£¬£¬£¬£¬²¢ÇÒĿǰÈÔÔÚ½øÐÐÖС£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¼Ù×°³ÉÀ´×ÔÄ«Î÷¸ç×ܼì²ì³¤°ì¹«ÊÒ»òÎ÷°àÑÀ¹«¹²²¿£¬£¬£¬£¬£¬£¬×îÖÕpayloadÀûÓôÓASUSTEKÍ·´µÄÖ¤ÊéÊðÃû£¬£¬£¬£¬£¬£¬Í¨¹ý¶þ½øÔìÌî³äµÄ²½Ö轫´óÓ×ÅòÕ͵½400MB£¬£¬£¬£¬£¬£¬À´ÈƹýɳÏä·ÖÎö¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬×îеÄGrandoreiro±äÌåÐÂÔöÁËʹÓÃDGA½øÐÐC2ͨѶµÄÖ°ÄÜ£¬£¬£¬£¬£¬£¬ÕâʹµÃ·¢ÏÖ¶ñÒâÈí¼þµÄ»ù´¡ÉèÊ©²¢½«Æä²ð³ý±äµÃ¸üÄÑ¡£¡£¡£¡£¡£¡£¡£


https://www.zscaler.com/blogs/security-research/grandoreiro-banking-trojan-new-ttps-targeting-various-industry-verticals


3¡¢WPÍøÕ¾±»ÈëÇÖºóÏÔʾαÔìCloudflare¾¯±¨²¢×°ÖöñÒâÈí¼þ

      

8ÔÂ18ÈÕ£¬£¬£¬£¬£¬£¬Sucuri³ÆWordPressÍøÕ¾±»ÈëÇÖºó»áÏÔʾαÔìµÄCloudflare DDoS±£»£»£»£»£»£»£»£»¤Ò³Ã棬£¬£¬£¬£¬£¬À´·Ö·¢¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬¹¥»÷Õß»áÈëÇÖÖ¸±êWordPressÍøÕ¾²¢Ö²ÈëÒ»¸ö»ìºÏµÄJavaScript payload£¬£¬£¬£¬£¬£¬Ëü¿ÉÏÔʾһ¸öαÔìµÄCloudflare DDoS±£»£»£»£»£»£»£»£»¤½çÃæ¡£¡£¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬Ö¸±ê»á±»ÒªÇóÏÂÔØÎļþsecurity_install.iso£¬£¬£¬£¬£¬£¬Æä±»ÃèÊöÎªÈÆ¹ýDDoSÑéÖ¤ËùÐèµÄ¹¤¾ß¡£¡£¡£¡£¡£¡£¡£´ò¿ª¸ÃÎļþ»á¿´µ½security_install.exe£¬£¬£¬£¬£¬£¬Ö´ÐиÃEXEÎļþ½«×°ÖöñÒâÈí¼þNetSupport RATºÍRaccoon Stealer¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/wordpress-sites-hacked-with-fake-cloudflare-ddos-alerts-pushing-malware/


4¡¢Proofpoint·¢ÏÖTA558¹¥»÷À­¶¡ÃÀÖ޾ƵêºÍÓÎÀÀÐÐÒµ

      

ProofpointÔÚ8ÔÂ18ÈÕ°ä²¼Á˹ØÓÚºÚ¿ÍÍÅ»ïTA558µÄ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£TA558¿ÉÄÜÊÇÒ»¸ö³öÓÚ¾­¼Ã¶¯»úµÄÓ×ÐͺڿÍÍŻ£¬£¬£¬£¬£¬×Ô2018ÄêÒÔÀ´ÆðÍ·»îÔ¾£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔλÓÚÀ­¶¡ÃÀÖÞµØÓòµÄ¾ÆµêºÍÓÎÀÀÐÐÒµ£¬£¬£¬£¬£¬£¬ÓÐʱҲ»áÕë¶ÔÎ÷Å·ºÍ±±ÃÀµØÓò¡£¡£¡£¡£¡£¡£¡£×î½üµÄ»î¶¯ÖУ¬£¬£¬£¬£¬£¬¹¥»÷Õß´ÓÀûÓÃÔ̺¬ºêµÄMicrosoft Office¸½¼þ£¬£¬£¬£¬£¬£¬×ª¶øÊ¹ÓÃURLºÍISOÎļþÀ´ÊµÏÖ³õʼϰȾ£¬£¬£¬£¬£¬£¬´Ë¾Ù¿ÉÄÜÊǶÔ΢Èí¾ö¶¨Ä¬ÈÏ×èÖ¹´ÓÍøÂçÏÂÔØÎļþÖеĺê×ö³öµÄ»ØÓ¦¡£¡£¡£¡£¡£¡£¡£


https://www.proofpoint.com/us/blog/threat-insight/reservations-requested-ta558-targets-hospitality-and-travel


5¡¢°®É³ÄáÑǵ±¾ÖÐû³ÆÒÑ×èÖ¹KillnetÍÅ»ï¶ÔÆäµÄDDoS¹¥»÷

      

¾Ý8ÔÂ19ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬°®É³ÄáÑǵ±¾ÖÐû³Æ×Ô2007ÄêÒÔÀ´×îÑϳÁµÄDDoS¹¥»÷¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷¼ÈÕë¶Ô¹«¹²»ú¹¹£¬£¬£¬£¬£¬£¬Ò²Õë¶Ô˽Ӫ¹«Ë¾£¬£¬£¬£¬£¬£¬ºÚ¿Í×éÖ¯KillnetÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬µÐÔÖÊ×ϯÐÅÏ¢¹Ù±ç²µÁ˸Ã×éÖ¯¹ØÓÚ200¶à¸öÍøÕ¾Òѱ»²é·âµÄ˵·¨£¬£¬£¬£¬£¬£¬²¢°µÊ¾E-EstoniaÒÑÆô¶¯²¢ÔËÐУ¬£¬£¬£¬£¬£¬·þÎñûÓÐÖжÏ¡£¡£¡£¡£¡£¡£¡£°®É³ÄáÑÇÍÆËã»úÓ¦¼±ÏìÓ¦Ó××éй©£¬£¬£¬£¬£¬£¬Ô̺¬¾¯Ô±ºÍµ±¾ÖÔÚÄڵĴ¦Ëùµ±¾ÖµÄÍøÕ¾ÒÔ¼°Ò»¼ÒÎïÁ÷¹«Ë¾Ôâµ½¹¥»÷¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/134560/cyber-warfare-2/estonia-blocked-cyberattacks-killnet.html 


6¡¢MicrosoftÅû¶ChromeOS×é¼þÖÐÄÚ´æ°Ü»µ·ì϶µÄϸ½Ú

      

MicrosoftÔÚ8ÔÂ19ÈÕ°ä²¼Á˹ØÓÚChromeOS×é¼þÖÐÄÚ´æ°Ü»µ·ì϶µÄ¼¼Êõ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶׷×ÙΪCVE-2022-2587£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬£¬¿É±»ÓÃÀ´Ö´ÐÐDoS£¬£¬£¬£¬£¬£¬»òÕßÔÚ¼«¶ËÇé¿öÏÂÖ´ÐÐÔ¶³Ì´úÂë¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶´æÔÚÓÚGoogle ChromeÒôƵ·þÎñÆ÷£¬£¬£¬£¬£¬£¬¿É±»Ô¶³Ì¹¥»÷Õßͨ¹ýÌØÔìµÄÒôƵԪÊý¾ÝÀûÓᣡ£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬¸Ã·ì϶Òѱ»½¨¸´£¬£¬£¬£¬£¬£¬ÉÐδ±»ÔÚÒ°ÀûÓᣡ£¡£¡£¡£¡£¡£


https://www.microsoft.com/security/blog/2022/08/19/uncovering-a-chromeos-remote-memory-corruption-vulnerability/