OutlookÓÊÏä¹ýÂËÆ÷³öÏÖÎÊÌâµ¼ÖÂÓû§ÊÕµ½´óÁ¿À¬»øÓʼþ

°ä²¼¹¦·ò 2023-02-21

1¡¢OutlookÓÊÏä¹ýÂËÆ÷³öÏÖÎÊÌâµ¼ÖÂÓû§ÊÕµ½´óÁ¿À¬»øÓʼþ


¾Ý2ÔÂ20ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬Ô½À´Ô½¶àµÄMicrosoftÓû§³ÆÆäOutlookÊÕ¼þÏäÔÚ´Óǰ¼¸Ó×ʱÄÚ±»À¬»øÓʼþ¸²Ã»¡£¡£¡£¡£¡£Ò»Î»Óû§Ëµ´ÓǰµÄ2Ó×ʱÄÚ£¬£¬£¬£¬£¬£¬ÆäÊÕ¼þÏäÊÕµ½ÁË36·âÀ¬»øÓʼþ¡£¡£¡£¡£¡£»£» £»£»£»£»£»¹ÓÐЧ»§·´Ó³£¬£¬£¬£¬£¬£¬ÔÚÀ¬»øÓʼþ¹ýÂËÆ÷ÖÐÉèÖá°½öÐÅÀµÀ´×ÔÎҵݲȫ·¢¼þÈ˺ÍÓòÁбíÒÔ¼°°²È«ÓʼþÁбíÖеĵØÖ·µÄµç×ÓÓʼþ¡±Ò²ÎÞ·¨½â¾ö´ËÎÊÌ⣬£¬£¬£¬£¬£¬ÕâÅú×¢Óʼþ·þÎñ¹ýÂËÆ÷¿ÉÄÜÒѱ»ÆëÈ«·ÛËé¡£¡£¡£¡£¡£Ö»¹ÜÓû§Í¶Ëß²»ÐÝ£¬£¬£¬£¬£¬£¬µ«Office·þÎñ×´Ì¬Ò³ÃæÈÔÏÔʾËùÓÐÕý³£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬Microsoft²¢Î´¶Ô´ËÊÂ×÷³ö»ØÓ¦¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-outlook-flooded-with-spam-due-to-broken-email-filters/


2¡¢Ó¡¶È»ð³µ¶©Æ±Æ½Ì¨RailYatriÔ¼3100ÍòÈËÐÅÏ¢ÔÚ°µÍø¹«¿ª


ýÌå2ÔÂ20Èճƣ¬£¬£¬£¬£¬£¬Ó¡¶È»ð³µ¶©Æ±Æ½Ì¨RailYatriÔâµ½ºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬31062673¸ö´î¿ÍµÄÐÅϢй¶¡£¡£¡£¡£¡£¹¥»÷²úÉúÔÚ2022Äê12Ô£¬£¬£¬£¬£¬£¬µ«±»µÁÊý¾ÝÖ±µ½´Ë¿Ì²Å±»Ð¹Â©µ½ºÚ¿ÍÂÛ̳BreachforumsÉÏ¡£¡£¡£¡£¡£ÔçÔÚ2020Äê2Ô£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸öÅäÖÃÃýÎóµÄElasticsearch·þÎñÆ÷ÊôÓÚRailYatri£¬£¬£¬£¬£¬£¬ÔÚÓ¡¶ÈCERT-InȾָºó¸Ã¹«Ë¾²ÅÉè·¨±£»£» £»£»£»£»£»¤ÆäÊý¾Ý¡£¡£¡£¡£¡£È»¶øÁ½Äêºó£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔٴβúÉúÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÒÔΪ£¬£¬£¬£¬£¬£¬RailYatri±¾Äܹ»Ô¤·ÀÕâ´ÎÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬ÈôÊÇËü´Óһ·ͷ¾ÍÖ´ÐÐÊʵ±µÄÍøÂ簲ȫսÊõ¡£¡£¡£¡£¡£


https://www.hackread.com/indian-ticketing-platform-railyatri-hacked/


3¡¢Earth KitsuneÍÅ»ïͨ¹ýË®¿Ó¹¥»÷·Ö·¢ÐµÄWhiskerSpy


2ÔÂ17ÈÕ£¬£¬£¬£¬£¬£¬Trend Micro³ÆÆä·¢ÏÖÁËEarth KitsuneÍÅ»ïͨ¹ýË®¿Ó¹¥»÷·Ö·¢WhiskerSpyµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£2022Äêµ×£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÒ»¸öÓ볯ÏÊÓйØ×éÖ¯µÄÍøÕ¾Ôâµ½ÈëÇÖ£¬£¬£¬£¬£¬£¬²¢±»´Û¸ÄÒÔ´«²¼¶ñÒâÈí¼þ¡£¡£¡£¡£¡£µ±½Ó¼ûÕßÔÚÍøÕ¾ÉÏÅÔ¹ÛÊÓÆµÊ±£¬£¬£¬£¬£¬£¬¹¥»÷Õß×¢ÈëµÄ¶ñÒâ¾ç±¾»áÏÔʾһÌõÐÂÎÅÌáÐÑ֪ͨËûÃÇÊÓÆµ±à½âÂëÆ÷ÃýÎ󣬣¬£¬£¬£¬£¬À´ÓÕʹËûÃÇÏÂÔØ²¢×°ÖÃľÂí»¯µÄ±à½âÂëÆ÷×°Ö÷¨Ê½¡£¡£¡£¡£¡£¸Ã×°Ö÷¨Ê½»á¼ÓÔØÒ»¸öеĺóÃÅWhiskerSpy¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬¸Ã»î¶¯Ê¹ÓõÄÓÆ¾ÃÐÔ¼¼ÊõÀÄÓÃÁËGoogle ChromeµÄ±¾»úÐÂÎÅ´«µÝÖ÷»ú£¬£¬£¬£¬£¬£¬²¢×°ÖÃÃûΪGoogle Chrome HelperµÄ¶ñÒâÀ©´ó¡£¡£¡£¡£¡£


https://www.trendmicro.com/en_us/research/23/b/earth-kitsune-delivers-new-whiskerspy-backdoor.html


4¡¢Check PointÅû¶Õë¶ÔÑÇÃÀÄáÑÇ×éÖ¯µÄÐÂÒ»ÂÖ¹¥»÷»î¶¯


Check PointÔÚ2ÔÂ16ÈÕÅû¶ÁË2022ËêĺÕë¶ÔÑÇÃÀÄáÑÇ×éÖ¯µÄÐÂÒ»ÂÖ¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬ÖØÒª·Ö·¢ºóÃÅOxtaRAT¡£¡£¡£¡£¡£OxtaRATÊÇÒ»ÖÖ»ùÓÚAutoItµÄÔ¶³Ì½Ó¼ûºÍ×ÀÃæ¼à¿Ø¹¤¾ß£¬£¬£¬£¬£¬£¬ËüÄܹ»´Ó±»Ï°È¾µÄÍÆËã»úÖÐËÑË÷ºÍй¶Îļþ¡¢´ÓÍøÂçÉãÏñÍ·ºÍ×ÀÃæÂ¼ÔìÊÓÆµ¡¢Ê¹ÓÃTightVNCÔ¶³Ì½ÚÔ챻ϰȾµÄÉ豸¡¢×°ÖÃweb shellºÍÖ´Ðж˿ÚɨÃèµÈ¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬£¬Óë¸ÃÍÅ»ï֮ǰµÄ»î¶¯Ïà±È£¬£¬£¬£¬£¬£¬2022Äê11ÔÂ×îлµÄϰȾÁ´²úÉúÁ˱䶯£¬£¬£¬£¬£¬£¬²ÉÈ¡ÁËÌá¸ß²Ù×÷°²È«ÐԵĴëÊ©£¬£¬£¬£¬£¬£¬ÒÔ¼°Ê¹ÓøĽøÇÔÈ¡Êý¾Ý·½Ê½µÄÐÂÖ°ÄÜ¡£¡£¡£¡£¡£


https://research.checkpoint.com/2023/operation-silent-watch-desktop-surveillance-in-azerbaijan-and-armenia/


5¡¢ºÚ¿ÍÀûÓÃľÂí°ç×°Ö÷¨Ê½Õë¶Ô¶«ÑǺͶ«ÄÏÑÇ´«²¼FatalRAT 


¾ÝESET 2ÔÂ16ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬ºÚ¿Íͨ¹ý¹È¸èËÑË÷Á˾ÖÖеÄÎóµ¼ÐÔ¸æ°×£¬£¬£¬£¬£¬£¬ÓÕʹָ±êÏÂÔØÄ¾Âí°ç×°Ö÷¨Ê½¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÔÚ2022Äê8ÔÂÖÁ2023Äê1Ô¹۲쵽ÕâЩ¹¥»÷£¬£¬£¬£¬£¬£¬µ«Æ¾¾ÝÒ£²âÊý¾Ý£¬£¬£¬£¬£¬£¬ÖÁÉÙ´Ó2022Äê5ÔÂ¾ÍÆðͷʹÓÃÏÈǰ°æ±¾µÄ×°Ö÷¨Ê½¡£¡£¡£¡£¡£¸Ã¹¥»÷ÖØÒªÕë¶Ô¶«ÄÏÑǺͶ«Ñǽ²ÖÐÎĵÄÈË£¬£¬£¬£¬£¬£¬Í¨¹ý´´½¨ÓëFirefox¡¢WhatsApp»òTelegramµÈÊ¢ÐÐÀûÓÃÒ»ÑùµÄÐéÎ±ÍøÕ¾£¬£¬£¬£¬£¬£¬·Ö·¢¶ñÒâÈí¼þFatalRAT¡£¡£¡£¡£¡£FatalRAT¿É²¶»ñ»÷¼ü¡¢¸ü¸ÄÖ¸±êµÄÆÁÄ»·Ö±æÂÊ¡¢ÏÂÔØºÍÖ´ÐÐÎļþµÈ£¬£¬£¬£¬£¬£¬ËüÓë2021Äê»ã±¨µÄ°æ±¾¼«¶ÈÀàËÆ¡£¡£¡£¡£¡£


https://www.welivesecurity.com/2023/02/16/these-arent-apps-youre-looking-for-fake-installers/


6¡¢Kaspersky°ä²¼¹ØÓÚ2022ÄêÀ¬»øÓʼþºÍ´¹µö»î¶¯µÄ»ã±¨


2ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬Kaspersky°ä²¼Á˹ØÓÚ2022ÄêÀ¬»øÓʼþºÍ´¹µö»î¶¯µÄ»ã±¨¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬ÔÚ2022Ä꣬£¬£¬£¬£¬£¬È«Çò48.63%µÄÓʼþÊÇÀ¬»øÓʼþ£¬£¬£¬£¬£¬£¬±ÈÉÏÒ»ÄêÔö³¤3.07¸ö°Ù·Öµã¡£¡£¡£¡£¡£À¬»øÓʼþ×î¶àµÄÔ·ÝÊÇ2Ô£¬£¬£¬£¬£¬£¬Õ¼±ÈΪ52.78%¡£¡£¡£¡£¡£¶à´ï29.82%µÄÀ¬»øÓʼþÀ´×Ô¶íÂÞ˹£¬£¬£¬£¬£¬£¬Æä´ÎÊǵ¹ú£¨29.82%£©¡£¡£¡£¡£¡£Ôâµ½´¹µö¹¥»÷×î¶àµÄ¹ú¶ÈÊÇÔ½ÄÏ(17.03%)£¬£¬£¬£¬£¬£¬Æä´ÎÊǰÄÃÅ£¨13.88%£©ºÍÂí´ï¼Ó˹¼Ó£¨12.04%£©¡£¡£¡£¡£¡£´óÎÞÊý´¹µöÒ³Ãæ¶¼ÍйÜÔÚCOMÓò£¨17.69%£©£¬£¬£¬£¬£¬£¬¶øºóÊÇXYZ(8.79%)¡£¡£¡£¡£¡£ÊÜ´ËÀ๥»÷×î¶àµÄÐÐҵΪ¿ìµÝ¹«Ë¾£¨27.38%£©£¬£¬£¬£¬£¬£¬ÔÚÏßÉ̵꣨15.56%£©ºÍÖ§¸¶ÏµÍ³£¨10.39%£©´ÎÖ®¡£¡£¡£¡£¡£


https://securelist.com/spam-phishing-scam-report-2022/108692/