12ÔÂWindows Server¸üе¼ÖÂHyper-VÐé¹¹»ú´´½¨³öÏÖBug

°ä²¼¹¦·ò 2022-12-16
1¡¢12ÔÂWindows Server¸üе¼ÖÂHyper-VÐé¹¹»ú´´½¨³öÏÖBug

      

¾Ý12ÔÂ14ÈÕ±¨Â·£¬ £¬ £¬£¬£¬Î¢Èí°µÊ¾£¬ £¬ £¬£¬£¬12Ô·ݵÄWindows Server¸üлᵼÖÂÔÚ²¿ÃÅHyper-VÖ÷»úÉÏ´´½¨ÐÂÐé¹¹»úʱ´¥·¢ÃýÎ󡣡£¡£¡£¡£¡£¡£Õâ¸öÎÊÌâÖ»Ó°Ï쵽ʹÓÃϵͳÖÐÐÄÐé¹¹»úÖÎÀíÆ÷£¨SCVMM£©ÖÎÀíµÄSDN»·¾³ÖеÄWindows Server/AzStack HCIÖ÷»ú¡£¡£¡£¡£¡£¡£¡£Î¢ÈíΪÊÜÓ°ÏìÓû§ÌṩÁË»º½â·¨×Ó£¬ £¬ £¬£¬£¬ÔÚPowerShell´°¿ÚÔËÐÐÒ»×éºÅÁ £¬ £¬£¬£¬»òʹÓÃרÓýÅÕý±¾ÅúÁ¿²¿Êð½â¾ö²½Öè¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬ £¬ £¬£¬£¬¸Ã¹«Ë¾ÔÚ½¨¸´ÎÊÌ⣬ £¬ £¬£¬£¬²¢½«ÔÚ½«À´µÄ°æ±¾ÖÐÌṩ¸üС£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-december-windows-server-updates-break-hyper-v-vm-creation/


2¡¢ÊÀ½ç±­°ë¾öÈüÆÚ¼äFuboTV±»¹¥»÷Óû§ÎÞ·¨½Ó¼ûÁ÷ýÌå·þÎñ

      

ýÌå12ÔÂ15Èճƣ¬ £¬ £¬£¬£¬±¾ÖÜÈýµ±FuboTVÓû§³ï±¸ÅÔ¹ÛÊÀ½ç±­·¨¹úÓëĦÂå¸çÖ®¼äµÄ°ë¾öÈüʱ£¬ £¬ £¬£¬£¬·¢ÏÖËûÃÇÎÞ·¨µÇ¼Á÷ýÌå·þÎñ¡£¡£¡£¡£¡£¡£¡£ËûÃÇÔÚ³¢ÊԵǼʱÊÕµ½CB_ERR_OPENÃýÎóÌáÐÑ£¬ £¬ £¬£¬£¬ÏÔʾ¡°ff: downstream not available¡±¡£¡£¡£¡£¡£¡£¡£FuboTVºÜ¿ì·¢ÎijÆËûÃÇÔÚ½â¾öÕâ¸öÎÊÌ⣬ £¬ £¬£¬£¬²¢½¨ÒéÓû§Í¨¹ýFOXÅÔ¹Û½ÇÖ𡣡£¡£¡£¡£¡£¡£15ÈÕ£¬ £¬ £¬£¬£¬FuboTVÈ·ÈÏÖжÏÊÇÓÉÓÚÍøÂç¹¥»÷µ¼Öµģ¬ £¬ £¬£¬£¬ËûÃÇĿǰÔÚµ÷²éºÍÓ¦¶ÔÕâÒ»ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£FuboTV δй©¹¥»÷ϸ½Ú£¬ £¬ £¬£¬£¬µ«°µÊ¾´ø¿í²»¼°²¢Î´µ¼ÖÂÖжϣ¬ £¬ £¬£¬£¬Åú×¢Õâ²»ÊÇDDoS¹¥»÷£¬ £¬ £¬£¬£¬¹¥»÷ºÜ¿ÉÄÜÊǶÔËûÃǵÄÍøÂç»ò·þÎñÆ÷µÄ·ÛËé¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/fubotv-says-world-cup-streaming-outage-caused-by-a-cyberattack/


3¡¢ESETÅû¶MirrorFaceÕë¶ÔÈÕ±¾µ±¾Ö»ú¹¹µÄ´¹µö¹¥»÷ÏêÇé

     

 ESETÓÚ12ÔÂ14ÈÕÅû¶ÁËMirrorFaceÕë¶ÔÈÕ±¾µ±¾Ö»ú¹¹µÄ´¹µö¹¥»÷»î¶¯Operation LiberalFace¡£¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯ÆðÍ·ÓÚ2022Äê6Ôµף¬ £¬ £¬£¬£¬¼Ù×°³ÉÀ´×ÔÌØ¶¨ÈÕ±¾Õþµ³¹«¹Ø²¿ÃŵĹٷ½Í¨Ñ¶£¬ £¬ £¬£¬£¬¶½´ÙÊÕ¼þÈËÔÚ×Ô¼ºµÄÉ罻ýÌå×ÊÁÏÖзÖÏí¸½¼þÖеÄÊÓÆµ¡£¡£¡£¡£¡£¡£¡£¸½¼þÊÇÒ»¸ö×Ô½âѹµÄWinRARѹËõ°ü£¬ £¬ £¬£¬£¬´ò¿ª¾Í»áÆðͷϰȾLODEINFO¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹Ê¹ÓÃÁËÒ»¸öÐÂµÄÆ¾Ö¤ÇÔÈ¡·¨Ê½MirrorStealer£¬ £¬ £¬£¬£¬Ëü¿É´Ó¶à¸öÀûÓÃÖÐÇÔȡƾ֤£¬ £¬ £¬£¬£¬Ô̺¬ä¯ÀÀÆ÷ºÍµç×ÓÓʼþ¿Í»§¶Ë¡£¡£¡£¡£¡£¡£¡£


https://www.welivesecurity.com/2022/12/14/unmasking-mirrorface-operation-liberalface-targeting-japanese-political-entities/


4¡¢ºÚ¿ÍÔÚ¶à¸ö¿ªÔ´´æ´¢¿âÉÏ´«³¬¹ý14Íò¸öÔ̺¬´¹µöÁ´½ÓµÄ°ü

      

¾ÝýÌå12ÔÂ14ÈÕ±¨Â·£¬ £¬ £¬£¬£¬×êÑÐÈËÔ±·¢ÏÖͳһ¸ö¹¥»÷ÕßÏòNuGet¡¢NPMºÍPyPiÉÏ´«ÁË144294¸ö°ü¡£¡£¡£¡£¡£¡£¡£µ÷²é½ÒʾÁËÒ»ÖÖÐµĹ¥»÷ý½é£¬ £¬ £¬£¬£¬¹¥»÷ÕßʹÓÃÔ̺¬´¹µö¹¥»÷Á´½ÓµÄÈí¼þ°üÏò¿ªÔ´Éú̬ϵͳ·¢ËÍÀ¬»øÓʼþ¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾£¬ £¬ £¬£¬£¬ËùÓаüºÍÓйØÓû§ÕÊ»§ºÜ¿ÉÄÜÊÇʹÓÃ×Ô¶¯»¯´´½¨µÄ£¬ £¬ £¬£¬£¬ÕâЩ°üʹÓÃÁËÀàËÆµÄÏîÄ¿ÃèÊöºÍ×Ô¶¯ÌìÉúµÄÃû³Æ¡£¡£¡£¡£¡£¡£¡£¸Ã´¹µö»î¶¯Á´½Óµ½90¸öÓòÉϵÄ65000¶à¸öΨһURL£¬ £¬ £¬£¬£¬Ã¿¸öÓòÔÚ·ÖÆçõè¾¶Ï´´½¨Á˶à¸ö´¹µöÍøÒ³¡£¡£¡£¡£¡£¡£¡£


https://checkmarx.com/blog/how-140k-nuget-npm-and-pypi-packages-were-used-to-spread-phishing-links/


5¡¢Cisco½üÆÚ·¢ÏÖʹÓÃÐÂÐÍHTML×ß˽¼¼Êõ·Ö·¢QBotµÄ»î¶¯

      

Cisco TalosÔÚ12ÔÂ13ÈÕ³ÆÆä·¢ÏÖÁËʹÓÿÉËõ·ÅʸÁ¿Í¼ÐÎ(SVG)ͼÏñµÄÐÂHTML×ß˽¼¼Êõ¡£¡£¡£¡£¡£¡£¡£ÕâÖÖ¹¥»÷ÊÇͨ¹ýº¬ÓÐJavaScriptµÄǶÈëʽSVGÎļþ½øÐеģ¬ £¬ £¬£¬£¬ÕâЩÎļþ³ÁÐÂ×éºÏ³ÉÒ»¸öBase64±àÂëµÄQBot¶ñÒâÈí¼þ×°Ö÷¨Ê½£¬ £¬ £¬£¬£¬Í¨¹ýÖ¸±êµÄä¯ÀÀÆ÷×Ô¶¯ÏÂÔØ¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ¶ñÒâÈí¼þpayloadÊÇÖ±½ÓÔÚÖ¸±êÖй¹½¨µÄ£¬ £¬ £¬£¬£¬¶ø²»ÊÇͨ¹ýÍøÂç´«ÊäµÄ£¬ £¬ £¬£¬£¬Òò¶øÕâÖÖHTML×ß˽¼¼ÊõÄܹ»ÈƹýÖ¼ÔÚ¹ýÂË´«ÊäÖеĶñÒâÄÚÈݵݲȫ¼ì²â¡£¡£¡£¡£¡£¡£¡£ÎªÕмÜHTML×ß˽¹¥»÷£¬ £¬ £¬£¬£¬¿É×èÖ¹¶ÔÏÂÔØÄÚÈÝÖ´ÐÐJavaScript»òVBScript¡£¡£¡£¡£¡£¡£¡£


https://blog.talosintelligence.com/html-smugglers-turn-to-svg-images/


6¡¢Cybereason°ä²¼¹ØÓÚÀÕË÷Èí¼þRoyalµÄ¼¼Êõ·ÖÎö»ã±¨

      

12ÔÂ14ÈÕ£¬ £¬ £¬£¬£¬Cybereason°ä²¼Á˹ØÓÚÀÕË÷Èí¼þRoyalµÄ¼¼Êõ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£RoyalÓÚ2022ËêÊ׳öÏÖ£¬ £¬ £¬£¬£¬²¢×ÔÄêÖÐÒÔÀ´ÊÆÍ·Ç¿¾¢¡£¡£¡£¡£¡£¡£¡£¸Ã»ã±¨Ö¸³ö£¬ £¬ £¬£¬£¬RoyalÀ©´óÁ˲¿ÃżÓÃܵĸÅÏ룬 £¬ £¬£¬£¬ÕâÒâζ×ÅËüÄܹ»¼ÓÃÜÔ¤ÏÈÈ·¶¨µÄ²¿ÃÅÎļþÄÚÈÝ£¬ £¬ £¬£¬£¬²¢»ùÓڽýݵİٷֱȽ«Æä²¿ÃżÓÃÜ£¬ £¬ £¬£¬£¬Ìá¸ßÁË·´ÀÕË÷Èí¼þ½â¾ö¹æ»®µÄ¼ì²âÄѶÈ£»£»£»£»£» £»Ê¹Óöà¸öÏß³ÌÀ´¼Ó¿ì¼ÓÃܹý³Ì£»£»£»£»£» £»ÔÚÈ«ÇòÁìÓòÄÚ»îÔ¾£¬ £¬ £¬£¬£¬Ã»ÓÐʹÓÃRaaS£¬ £¬ £¬£¬£¬Ò²Ã»ÓÐÕë¶ÔÌØ¶¨ÐÐÒµ»òµØÓò£»£»£»£»£» £»Æä×î³õÒÔ·ÖÆçµÄ·½Ê½Æô¶¯ºÍ×°Öᣡ£¡£¡£¡£¡£¡£


https://www.cybereason.com/blog/royal-ransomware-analysis