΢Èí°ä²¼2Ô·ݰ²È«¸üР£¬£¬£¬ £¬£¬£¬£¬£¬Ô̺¬3¸öÒѱ»ÀûÓõķì϶

°ä²¼¹¦·ò 2023-02-15
1¡¢Î¢Èí°ä²¼2Ô·ݰ²È«¸üР£¬£¬£¬ £¬£¬£¬£¬£¬Ô̺¬3¸öÒѱ»ÀûÓõķì϶

      

2ÔÂ14ÈÕ £¬£¬£¬ £¬£¬£¬£¬£¬Î¢Èí°ä²¼ÁË2023Äê2Եݲȫ¸üР£¬£¬£¬ £¬£¬£¬£¬£¬½¨¸´Ô̺¬3¸ö±»ÀûÓÃ0 dayÔÚÄÚµÄ77¸ö·ì϶¡£¡£¡£¡£¡£ ¡£¡£ÆäÖÐ £¬£¬£¬ £¬£¬£¬£¬£¬Òѱ»ÀûÓõķì϶±ðÀëΪWindowsͼÐÎ×é¼þÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2023-21823£© £¬£¬£¬ £¬£¬£¬£¬£¬¿ÉÓÃÀ´ÒÔSYSTEMȨÏÞÖ´ÐкÅÁ£»£»£»£»£»Microsoft Publisher°²È«Ö°ÄÜÈÆ¹ý·ì϶£¨CVE-2023-21715£© £¬£¬£¬ £¬£¬£¬£¬£¬ÌØÔìÎĵµ¿ÉÀûÓÃÆäÈÆ¹ýOfficeºêÕ½Êõ£»£»£»£»£»£»ÒÔ¼°WindowsͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶£¨CVE-2023-23376£© £¬£¬£¬ £¬£¬£¬£¬£¬¿ÉÓÃÀ´»ñµÃSYSTEMȨÏÞ¡£¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-february-2023-patch-tuesday-fixes-3-exploited-zero-days-77-flaws/


2¡¢Cloudflare¼ì²âµ½Õë¶ÔÆä¿Í»§µÄ´ó¹æÄ£DDoS¹¥»÷

      

¾ÝýÌå2ÔÂ14ÈÕ±¨Â· £¬£¬£¬ £¬£¬£¬£¬£¬Cloudflare¼ì²âµ½ÊýÊ®´Î³¬´óÈÝÁ¿DDoS¹¥»÷¡£¡£¡£¡£¡£ ¡£¡£¸Ã¹«Ë¾°µÊ¾ £¬£¬£¬ £¬£¬£¬£¬£¬´óÎÞÊý¹¥»÷µÄ·åÖµÔÚÿÃë50-70°ÙÍò¸öÒªÇó(rps)×óÓÒ £¬£¬£¬ £¬£¬£¬£¬£¬×î´ó·åÖµ³¬¹ý7100Íòrps £¬£¬£¬ £¬£¬£¬£¬£¬ÕâÊÇÆù½ñΪֹ×î´ó¹æÄ£µÄHTTP DDoS¹¥»÷¡£¡£¡£¡£¡£ ¡£¡£ÕâЩ¹¥»÷»ùÓÚHTTP/2 £¬£¬£¬ £¬£¬£¬£¬£¬ÊÇʹÓÃÀ´×Ô¶à¸öÔÆÌṩÉ̵Ä30000¶à¸öIPµØÖ·Õë¶Ô¸÷ÀàÖ¸±êÌáÒéµÄ £¬£¬£¬ £¬£¬£¬£¬£¬Ô̺¬ÓÎÏ·ÌṩÉÌ¡¢ÔÆÍÆËãÆ½Ì¨¡¢¼ÓÃÜÇ®±Ò¹«Ë¾ºÍÍйÜÌṩÉÌ¡£¡£¡£¡£¡£ ¡£¡£ÔÚ´ÓǰµÄÒ»ÄêÀï £¬£¬£¬ £¬£¬£¬£¬£¬×êÑÐÈËÔ±¿´µ½Á˸ü¶àÀ´×ÔÓÚÔÆÍÆË㹩¸øÉ̵Ĺ¥»÷¡£¡£¡£¡£¡£ ¡£¡£


https://thehackernews.com/2023/02/massive-http-ddos-attack-hits-record.html


3¡¢Phylum·¢ÏÖ451¸öÖ¼ÔÚ½Ù³Ö¼ÓÃÜÇ®±ÒÂòÂôµÄ¶ñÒâPyPI°ü

      

PhylumÔÚ2ÔÂ10ÈÕ³ÆÆä·¢ÏÖ451¸ö¶ñÒâPyPI°ü £¬£¬£¬ £¬£¬£¬£¬£¬Ö¼ÔÚͨ¹ý×°ÖöñÒâÀ©´ó½Ù³Ö»ùÓÚä¯ÀÀÆ÷µÄ¼ÓÃÜÇ®±ÒÂòÂô¡£¡£¡£¡£¡£ ¡£¡£ÕâÊÇ×î³õÓÚ2022Äê11Ô·¢ÏֵĻµÄÒ»Á¬ £¬£¬£¬ £¬£¬£¬£¬£¬ÆäʱֻÓÐ27¸ö¶ñÒâPyPi°ü¡£¡£¡£¡£¡£ ¡£¡£ÔÚÕâ´Î»î¶¯Öб»·ÂÕÕµÄÊ¢ÐÐÈí¼þ°üÔ̺¬bitcoinlib¡¢ccxtºÍcryptocompareµÈ £¬£¬£¬ £¬£¬£¬£¬£¬Ã¿¸ö¶¼ÓÐ13µ½38¸ö°æ±¾ £¬£¬£¬ £¬£¬£¬£¬£¬ÊÔͼ¸²¸Ç¿ÉÄܵĸ÷ÀàÃýÎóÀàÐÍ¡£¡£¡£¡£¡£ ¡£¡£ÎªÁËÈÆ¹ý¼ì²â £¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃËæ»úµÄ16λÖÐÎĺº×Ö×éºÏ×÷Ϊº¯ÊýºÍ±äÁ¿±êʶ·û¡£¡£¡£¡£¡£ ¡£¡£


https://blog.phylum.io/phylum-discovers-revived-crypto-wallet-address-replacement-attack


4¡¢Group-IBй©Æä½üÆÚÔâµ½À´×ÔTonto TeamÍÅ»ïµÄ¹¥»÷

      

Group-IBÓÚ2ÔÂ13ÈÕй© £¬£¬£¬ £¬£¬£¬£¬£¬Æä¼ì²â²¢×èÖ¹ÁËÀ´×ÔAPTÍÅ»ïTonto TeamµÄ¹¥»÷¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷²úÉúÔÚ2022Äê6Ô £¬£¬£¬ £¬£¬£¬£¬£¬ÕâÊǵڶþ´ÎÕë¶ÔGroup-IBµÄ¹¥»÷ £¬£¬£¬ £¬£¬£¬£¬£¬µÚÒ»´Î²úÉúÔÚ2021Äê3Ô¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷ʼÓÚÒ»·â´¹µöÓʼþ £¬£¬£¬ £¬£¬£¬£¬£¬·Ö·¢ÁËʹÓÃRoyal Road Weaponizer´´½¨µÄ¶ñÒâMicrosoft OfficeÎĵµ¡£¡£¡£¡£¡£ ¡£¡£ÔÚ¹¥»÷ÆÚ¼ä £¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß»¹ÀûÓÃÁËBisonal.DoubleTºóÃÅ¡£¡£¡£¡£¡£ ¡£¡£´Ë±í £¬£¬£¬ £¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸öеÄÏÂÔØ·¨Ê½TontoTeam.Downloader£¨±ðÃûQuickMute£© £¬£¬£¬ £¬£¬£¬£¬£¬ËüÖØÒªÕÆ¹Ü´ÓÔ¶³Ì·þÎñÆ÷¼ìË÷ÏÂÒ»½×¶ÎµÄ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£ ¡£¡£


https://www.group-ib.com/blog/tonto-team/


5¡¢CheckPoint°ä²¼2023Äê1Ô·ÝÈ«ÇòÍþвָÊýµÄ»ã±¨

      

2ÔÂ13ÈÕ £¬£¬£¬ £¬£¬£¬£¬£¬Check Point°ä²¼2023Äê1Ô·ÝÈ«ÇòÍþвָÊýµÄ»ã±¨¡£¡£¡£¡£¡£ ¡£¡£QbotºÍLokibotÊÇÉϸöÔÂ×î³£¼ûµÄ¶ñÒâÈí¼þ £¬£¬£¬ £¬£¬£¬£¬£¬¶ÔÈ«Çò×éÖ¯µÄÓ°Ï쳬¹ýÁË6% £¬£¬£¬ £¬£¬£¬£¬£¬Æä´ÎÊÇAgentTesla £¬£¬£¬ £¬£¬£¬£¬£¬È«ÇòÓ°ÏìΪ5%¡£¡£¡£¡£¡£ ¡£¡£½ÌÓýºÍ×êÑÐÐÐÒµÒÀÈ»ÊÇÈ«ÇòÊܵ½¹¥»÷×îÑϳÁµÄÐÐÒµ £¬£¬£¬ £¬£¬£¬£¬£¬Æä´ÎÊǵ±¾Ö¾ü¶ÓÒÔ¼°Ò½ÁƱ£½¡ÐÐÒµ¡£¡£¡£¡£¡£ ¡£¡£×î³£±»ÀûÓõķì϶ΪWeb·þÎñÆ÷¶³öµÄGit´æ´¢¿âÐÅϢй¶ºÍHTTP±êÍ·Ô¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£ ¡£¡£×î³£¼ûµÄÒÆ¶¯¶ñÒâÈí¼þÊÇAnubis £¬£¬£¬ £¬£¬£¬£¬£¬Æä´ÎÊÇHiddadºÍAhMyth¡£¡£¡£¡£¡£ ¡£¡£


https://blog.checkpoint.com/2023/02/13/january-2023s-most-wanted-malware-infostealer-vidar-makes-a-return-while-earth-bogle-njrat-malware-campaign-strikes/


6¡¢Ahnlab°ä²¼¹ØÓÚDalbitÍŻ﹥»÷»î¶¯µÄ·ÖÎö»ã±¨

      

AhnlabÔÚ2ÔÂ13ÈÕ°ä²¼Á˹ØÓÚDalbitÍŻ﹥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£ ¡£¡£×Ô2022ÄêÒÔÀ´ £¬£¬£¬ £¬£¬£¬£¬£¬¸ÃÍÅ»ïÒѶԺ«¹ú¹«Ë¾½øÐÐÁË50ÂŴι¥»÷ £¬£¬£¬ £¬£¬£¬£¬£¬´óÎÞÊýÊÇÖÐÓ×Ð͹«Ë¾ £¬£¬£¬ £¬£¬£¬£¬£¬Éæ¼°¼¼Êõ¡¢¹¤Òµ¡¢»¯¹¤¡¢¹¹ÖþºÍÆû³µµÈÐÐÒµµÄ×éÖ¯¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßÊ×ÏÈͨ¹ýÀûÓ÷ì϶»ñµÃ½Ó¼ûȨÏÞ £¬£¬£¬ £¬£¬£¬£¬£¬³¢ÊÔʹÓÃWebShellµÈ¹¤¾ßÀ´½ÚÔìϵͳ¡£¡£¡£¡£¡£ ¡£¡£¶øºóÀûÓÃÍøÂçɨÃ蹤¾ßºÍÕË»§ÍµÇÔ¹¤¾ßµÈ½øÐÐÄÚ²¿¿úËźÍÇÔÊØÐÅÏ¢¡£¡£¡£¡£¡£ ¡£¡£×îÖÕ £¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÇÔÈ¡ÁËËûÃÇÏëÒªµÄËùÓÐÐÅÏ¢ºó £¬£¬£¬ £¬£¬£¬£¬£¬»áʹÓÃBitLocker¼ÓÃÜijЩÇý¶¯Æ÷²¢Ë÷ÒªÊê½ð¡£¡£¡£¡£¡£ ¡£¡£


https://asec.ahnlab.com/en/47455/