AppleÆðËßNSO Group¼°Æäĸ¹«Ë¾ÓÃPegasus¼àÊÓiOSÓû§
Ðû²¼Ê±¼ä 2021-11-25AppGalleryÖжà¿îÓÎÏ·Ó¦ÓôæÔÚľÂí£¬ÒÑѬȾ900¶àÍòÉ豸
11ÔÂ23ÈÕ£¬Dr. WebµÄÑо¿ÈËÔ±Åû¶»ªÎªÓ¦ÓÃÉ̵êAppGalleryÖеÄ190¿îÓÎÏ·ÖдæÔÚľÂíAndroid.Cynos.7.origin£¬ÒѰ²×°Ô¼9300000´Î¡£¸ÃľÂíÊǶñÒâÈí¼þCynosµÄ±äÌ壬ּÔÚÊÕ¼¯Óû§µÄÐÅÏ¢¡£ÕâЩÓÎÏ·Ö÷ҪʹÓöíÓï¡¢ÖÐÎĺÍÓ¢ÓÆäÖÐÓÎÏ·¡°¿ìµã¶ãÆðÀ´¡±µÄÏÂÔØÁ¿¸ß´ï2000000´Î¡£Ñо¿ÈËÔ±³Æ£¬¸ÃľÂí¿É·¢ËͺÍÀ¹½Ø¶ÌÐÅ¡¢ÏÂÔØºÍÆô¶¯ÆäËüÄ£¿é£¬ÒÔ¼°ÏÂÔØºÍ°²×°ÆäËûÓ¦Óá£Ä¿Ç°£¬»ªÎª¹«Ë¾Òѽ«ÕâЩÓÎϷϼܡ£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/124927/malware/android-cynos-7-origin-trojan-infections.html
BIO-ISAC³Æ¹¥»÷ÕßÀûÓÃÐÂTardigradeÃé×¼ÉúÎïÖÆÔìÐÐÒµ
ÉúÎï¾¼ÃÐÅÏ¢¹²ÏíºÍ·ÖÎöÖÐÐÄ(BIO-ISAC)ÔÚ11ÔÂ23ÈÕÐû²¼¹ØÓÚÀûÓÃTardigradeµÄ¹¥»÷»î¶¯µÄ¾¯±¨¡£×Ô2021Äê´º¼¾ÒÔÀ´£¬¹¥»÷Õß¿ªÊ¼ÀûÓôË×Ô½ç˵¶ñÒâÈí¼þ¹¥»÷ÉúÎïÖÆÔìÐÐÒµµÄ¹«Ë¾¡£Ñо¿ÈËÔ±³Æ£¬ÕâÊÇSmokeLoaderµÄ±äÌ壬Ö÷Ҫͨ¹ýµöÓã»î¶¯»òUÅ̽øÐзַ¢¡£ÒòΪËü¿ÉÒÔ´ÓÄÚ´æÖÐÖØÐ±àÒë¼ÓÔØ·¨Ê½£¬Òò´Ë²»»áÁôÏÂÏàͬµÄÇ©Ãû£¬Õâʹʶ±ð¡¢¸ú×ÙºÍɾ³ý±äµÃÔ½·¢À§ÄÑ¡£´ËÍ⣬¸Ã±äÌå¿ÉÒÔ×ÔÖ÷ÔËÐУ¬ÉõÖÁÎÞÐèC2Á¬½Ó¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hackers-target-biomanufacturing-with-stealthy-tardigrade-malware/
AppleÆðËßNSO Group¼°Æäĸ¹«Ë¾ÓÃPegasus¼àÊÓiOSÓû§
Apple¹«Ë¾ÔÚ11ÔÂ23ÈÕ¶ÔNSO Group¼°Æäĸ¹«Ë¾Q Cyber TechnologiesÌáÆðËßËÏ£¬Ö¸ÔðÆäÀûÓÃPegasus·Ç·¨¼àÊÓiOSÓû§¡£PegasusÊÇÒ»ÖÖ¾üʼ¶¼äµýÈí¼þ£¬Í¨³£»áÀûÓÃÁãµã»÷©¶´À´Ñ¬È¾Ä¿±êÉ豸£¬AppleÔÚËßËÏÖÐÌØ±ðÌá¼°ÆäÀûÓÃiMessageÖеÄ©¶´FORCEDENTRY¹¥»÷9¸ö°ÍÁÖÈËÊ¿¡£Apple¹«Ë¾³ÆËûÃǵÄÄ¿µÄÊÇÓÀ¾ÃµØ½ûÖ¹NSO GroupʹÓÃÈκÎAppleÈí¼þ¡¢·þÎñ»òÉ豸¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/11/apple-sues-israels-nso-group-for-spying.html
Ñо¿ÍŶÓչʾÈçºÎÀûÓôòÓ¡»úµÄ3ÖÖ¹¥»÷ģʽPrintjack
Òâ´óÀûÑо¿ÍŶÓչʾͳ³ÆÎªPrintjackµÄ3ÖÖй¥»÷ģʽ£¬¿ÉÀûÓôòÓ¡»úÔì³ÉÑÏÖØµÄºó¹û¡£Ö÷ÒªÀûÓÃShodanɨÃèTCP¶Ë¿Ú9100¿ª·ÅµÄÉ豸£¬ÆäÖе¹ú¡¢¶íÂÞ˹¡¢·¨¹ú¡¢ºÉÀ¼ºÍÓ¢¹úµÄ̻¶É豸×î¶à¡£µÚÒ»ÖÖ¹¥»÷ÊÇÀûÓÃCVE-2014-3741µÈ©¶´£¬¿ØÖÆ´òÓ¡»úÌᳫDDoS¹¥»÷£»µÚ¶þÖÖÊÇÖ½ÕÅDoS¹¥»÷£¬Ëüͨ¹ý·¢ËÍÖØ¸´µÄ´òÓ¡ÈÎÎñÀ´ºÄ¾¡Ä¿±êÉ豸ÖеÄËùÓÐÖ½ÕÅ£»×îÑÏÖØµÄÊÇÀûÓÃÆä½øÐÐÖмäÈ˹¥»÷£¬²¢ÇÔÈ¡´òÓ¡µÄÄÚÈÝ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/researchers-warn-of-severe-risks-from-printjack-printer-attacks/
°ëµ¼Ì幫˾MediaTekÐÞ¸´ÆäоƬÖеĶà¸öÄþ¾²Â©¶´
Check PointÔÚ11ÔÂ24ÈÕÅû¶ÁËÖйų́Í幫˾Áª·¢¿Æ£¨MediaTek£©²úÎïÖÐ4¸ö©¶´µÄϸ½Ú¡£MediaTekÊÇÈ«Çò×î´óµÄ°ëµ¼Ì幫˾֮һ£¬½ØÖÁ2021ÄêµÚ¶þ¼¾¶È£¬43%µÄÖÇÄÜÊÖ»ú¶¼½ÓÄÉÁËÁª·¢¿ÆÏµÍ³Ð¾Æ¬ (SoC) £¬°üÂÞСÃס¢Oppo¡¢RealmeºÍVivoµÈ¡£Ä¿Ç°£¬MediaTekÒÑÔÚ10Ô·ÝÄþ¾²¸üÐÂÖÐÐÞ¸´ÁËÆäÖеÄ3¸öÔ½½çдÈëºÍµ±µØÌáȨ©¶´£¨CVE-2021-0661¡¢CVE-2021-0662ºÍCVE-2021-0663£©£¬²¢Ô¤¼ÆÔÚ12ÔÂÄþ¾²¸üÐÂÖÐÐÞ¸´µÚ4¸ö©¶´£¨CVE-2021-0673£©¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/mediatek-eavesdropping-bug-impacts-30-percent-of-all-android-smartphones/
KasperskyÐû²¼2022ÄêICSºÍ¹¤ÒµÐÐÒµÍþвµÄÔ¤²â³ÂËß
KasperskyÓÚ11ÔÂ23ÈÕÐû²¼ÁË2022ÄêICSºÍ¹¤ÒµÐÐÒµÍþвµÄÔ¤²â³ÂËß¡£³ÂËßÖ¸³ö£¬ÔÚδÀ´¹¥»÷Õß¿ÉÄÜ»á¼õÉÙÿ´Î¹¥»÷µÄÄ¿±êÊýÁ¿£¬Ëõ¶Ì¶ñÒâÈí¼þµÄÉúÃüÖÜÆÚ²¢×î´óÏ޶ȵؼõÉÙ¶ñÒâ»ù´¡ÉèÊ©µÄʹÓᣴËÍ⣬³ÂËßÌåÏÖÒÔϹ¥»÷¼ÆÄ±ºÍ¼¼ÊõÎÞÒɽ«ÔÚÀ´Äê±»»ý¼«ÀûÓ㺵öÓã¹¥»÷¡¢½«Ó²¼þÖеÄÒÑ֪©¶´×÷ÎªÉøÍ¸Ã½½é¡¢ÀûÓòÙ×÷ϵͳ×é¼þºÍIT²úÎïÖеÄÁãÈÕ©¶´¡¢ÈëÇÖÓòÃû×¢²áÉ̺ÍÈÏÖ¤»ú¹¹ÒÔ¼°Õë¶Ô¹©Ó¦É̵Ĺ¥»÷¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/threats-to-ics-and-industrial-enterprises-in-2022/104957/