¹¥»÷ÕßÀûÓÃαװ³ÉTelegramµÄ¶ñÒâÈí¼þ·Ö·¢Purple Fox

Ðû²¼Ê±¼ä 2022-01-06

¹ú¼ÒÍøÐŰìµÈ13¸ö²¿ÃÅÐÞ¶©Ðû²¼¡¶ÍøÂçÄþ¾²Éó²é´ëÊ©¡·


¹ú¼ÒÍøÐŰìµÈ13¸ö²¿ÃÅÐÞ¶©Ðû²¼¡¶ÍøÂçÄþ¾²Éó²é´ëÊ©¡·.png


1ÔÂ4ÈÕ£¬¹ú¼Ò»¥ÁªÍøÐÅÏ¢°ì¹«ÊÒµÈ13¸ö²¿ÃÅÐÞ¶©Ðû²¼¡¶ÍøÂçÄþ¾²Éó²é´ëÊ©¡·¡£¸Ã´ëÊ©¹²23Ìõ£¬ÔÚ2021Äê11ÔÂ16ÈÕ¹ú¼Ò»¥ÁªÍøÐÅÏ¢°ì¹«ÊÒ2021ÄêµÚ20´ÎÊÒÎñ»áÒéÉóÒéͨ¹ý£¬×Ô2022Äê2ÔÂ15ÈÕÆðÊ©ÐС£¸Ã´ëÊ©¹æ¶¨ÕÆÎÕÁè¼Ý100ÍòÓû§¸öÈËÐÅÏ¢µÄÍøÂçÆ½Ì¨ÔËÓªÕ߸°¹úÍâÉÏÊУ¬±ØÐëÏòÍøÂçÄþ¾²ÉóºË°ì¹«ÊÒÉê±¨ÍøÂçÄþ¾²Éó²é¡£ÂôÁ¦È˳Æ£¬´Ë¾ÙÊÇΪ½øÒ»²½±£ÕÏÍøÂçÄþ¾²ºÍÊý¾ÝÄþ¾²£¬Î¬»¤¹ú¼ÒÄþ¾²¡£


http://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm


¹¥»÷ÕßÀûÓÃαװ³ÉTelegramµÄ¶ñÒâÈí¼þ·Ö·¢Purple Fox


Minerva LabsÔÚ1ÔÂ3ÈÕÐû²¼µÄ³ÂËßÅû¶½üÆÚ·Ö·¢Purple FoxµÄ»î¶¯Ï¸½Ú¡£´Ë´Î»î¶¯ÀûÓÃÃûΪTelegram Desktop.exeµÄ±àÒëºóµÄAutoIt½Å±¾£¬Ëü»á°²×°2¸öÎļþ£ººÏ·¨µÄTelegram°²×°·¨Ê½ºÍ¶ñÒâÏÂÔØ·¨Ê½(TextInputh.exe)¡£TextInputh.exe½«ÏÂÔØÒ»ÏµÁжñÒâÎļþÀ´×èÖ¹360 AV½ø³ÌÆô¶¯£¬ÔÚÈ·¶¨»·¾³Äþ¾²ºóÁ¬½ÓC2£¬ÒÔ.msiÎļþµÄÐÎʽÏÂÔØPurple Fox¡£


https://blog.minerva-labs.com/malicious-telegram-installer-drops-purple-fox-rootkit


Broward HealthϵͳЩ¶´Ôì³É130¶àÍò»¼ÕßÐÅϢй¶


¾ÝýÌå1ÔÂ4ÈÕ±¨µÀ£¬Broward HealthÒÑй¶Áè¼Ý130Íò»¼ÕßÐÅÏ¢¡£ÕâÊÇÃÀ¹úTop 10µÄ¹«¹²Ò½ÁÆÏµÍ³£¬Ä¿Ç°¾­Óª×Å30¶à¸öÒ½ÁÆ»ú¹¹¡£¹¥»÷·¢ÉúÔÚ2021Äê10ÔÂ15ÈÕ£¬¹¥»÷ÕßÈëÇÖÁËÒ½ÔºµÄÍøÂç²¢·ÃÎÊ»¼ÕßÊý¾Ý¡£¸Ã»ú¹¹ÓÚ10ÔÂ19ÈÕ·¢ÏÖÄþ¾²Â©¶´£¬²¢ÏòµØ·½Õþ¸®³ÂËß¡£¾­ÊӲ죬¹¥»÷ÕßÊÇͨ¹ýÈëÇÖÆäµÚÈý·½Ò½ÁÆÌṩÉ̽øÈëÍøÂç¡£¸ÃÒ½Ôº½«ÎªÊÜÓ°ÏìÓû§ÌṩΪÆÚÁ½ÄêµÄÉí·ÝµÁÓüì²âºÍ±£»¤·þÎñµÄ»áÔ±×ʸñ¡£


https://securityaffairs.co/wordpress/126285/data-breach/broward-health-data-breach.html


SEGA EuropeµÄAWS´æ´¢Í°ÅäÖôíÎ󣬿ɷÃÎÊÃÜÔ¿µÈÐÅÏ¢


Äþ¾²¹«Ë¾VPN Overview 12ÔÂ30ÈÕ±¨µÀ£¬SEGA EuropeµÄAWS´æ´¢Í°ÅäÖôíÎóµ¼ÖÂÐÅϢй©¡£ÊÜÓ°ÏìµÄ´æ´¢Í°°üÂÞ¿ÉÓÃÀ´·ÃÎÊSEGA EuropeµÄ¶à¸öÔÆ·þÎñµÄAWSÃÜÔ¿£¬SNS֪ͨÐÐÁУ¬ÒÔ¼°´óÁ¿Óû§ÐÅÏ¢¡£Ñо¿ÈËÔ±ÌåÏÖ£¬ËûÃÇÄܹ»ÉÏ´«Îļþ¡¢Ö´Ðнű¾¡¢¸ü¸ÄÏÖÓÐÍøÒ³²¢¸Ä¶¯SEGAÓòµÄÅäÖã¬Ä¿Ç°Ã»Óм£Ïó±íÃ÷¹¥»÷ÕßÒÑ·ÃÎÊÊý¾Ý»òÀûÓÃÉÏÊö©¶´¡£


https://vpnoverview.com/news/sega-europe-security-report/


Invezz³Æ½ü10ÄêÖмÓÃÜÄþ¾²Â©¶´µÄÊýÁ¿ÒÑÔö¼Ó850%


¾ÝýÌå1ÔÂ2ÈÕ±¨µÀ£¬InvezzÐû²¼µÄ³ÂËßÏÔʾ½ü10ÄêÖмÓÃÜÄþ¾²Â©¶´µÄÊýÁ¿ÒÑÔö¼Ó850%¡£¾ÝÔ¤¼Æ£¬2011Äê1ÔÂÖÁ2021Äê12Ô£¬±»µÁµÄ¼ÓÃÜ»õ±Ò½ð¶î´ï121ÒÚÃÀÔª¡£ÆäÖÐËðʧ½ð¶îÔö·ù×î´óµÄÊÇ2016ÄêÖÁ2017Ä꣬Ôö³¤180%£»Òò¼ÓÃܹ¥»÷¶øµ¼ÖµÄËðʧ×î¸ßµÄÊÇ2021Ä꣬´ï42.5ÒÚÃÀÔª¡£ÀûÓüÓÃܽ»»»Äþ¾²ÏµÍ³ÖеÄ©¶´ÊÇ×î³£¼ûµÄ¼ÆÄ±£¬×î³£Ôâµ½´ËÀ๥»÷µÄ¹ú¼ÒÊÇÈÕ±¾¡¢º«¹ú¡¢ÃÀ¹ú¡¢Ó¢¹úºÍÖйú¡£


https://securityaffairs.co/wordpress/126216/cyber-crime/crypto-security-breaches-2011-2021.html


MicrosoftÐû²¼½ô¼±¸üÐÂÐÞ¸´Windows ServerÖеĴíÎó


¾Ý±¨µÀ£¬MicrosoftÒÑÓÚ1ÔÂ4ÈÕÐû²¼´øÍâ(OOB)¸üС£´Ë´Î¸üн«ÐÞ¸´Windows Server 2019ºÍWindows Server 2012 R2µÄºÚÆÁ¡¢µÇ¼»ºÂý»òÆÕ±é»ºÂýµÄÎÊÌ⣬ÒÔ¼°ÎÞ·¨Ê¹ÓÃÔ¶³Ì×ÀÃæ·ÃÎÊ·þÎñÆ÷»ò·þÎñÆ÷Í£Ö¹ÏìÓ¦µÄÎÊÌâ¡£ÕâЩ¸üв»ÄÜ´ÓWindows¸üлñµÃ£¬Ò²²»»á×Ô¶¯°²×°¡£MicrosoftÉÐδÐû²¼ÆäËü°æ±¾µÄ¸üУ¬Ô¤¼Æ½«ÔÚδÀ´¼¸ÌìÄÚÌṩ½â¾ö·½°¸¡£


https://www.bleepingcomputer.com/news/microsoft/emergency-windows-server-update-fixes-remote-desktop-issues/


Äþ¾²¹¤¾ß


Haveged


¸Ã¹¤¾ßµÄÄ¿µÄÊÇÌṩһ¸ö¼òµ¥Ò×ÓõIJ»ÐÐÔ¤²âËæ»úÊýÉú³ÉÆ÷£¬»ùÓÚ HAVEGE Ëã·¨¡£


https://wiki.archlinux.org/title/Haveged


rustpad


ÓÃRust±àдµÄ´«Í³padbusterµÄ¶àÏ̼̳߳ÐÕߣ¬ÀûÓà Padding Oracle ©¶´¡£


https://github.com/Kibouo/rustpad/


Äþ¾²·ÖÎö


ÈçºÎÀûÓø´ÖÆÕ³ÌùÈëÇÖ


¸´ÖÆÎı¾ºóµÄĩβ»¹ÓÐÒ»¸ö»»Ðзû£¬¿Éµ¼ÖÂËüÔÚÕ³Ìùµ½LinuxÖն˺óÁ¢¼´Ö´ÐС£


https://www.wizer-training.com/blog/copy-paste


ÀûÓõç´ÅÐźŽøÐлìÏý¶ñÒâÈí¼þµÄ·ÖÀà


ÀûÓÃIoTÉ豸µÄµç´Å³¡ÐźÅ×÷ΪÅÔ·À´ÊÕ¼¯Õë¶ÔÖ²ÈëϵͳµÄ²îÒìÀàÐͶñÒâÈí¼þµÄ¾«È·ÐÅÏ¢¡£


https://dl.acm.org/doi/10.1145/3485832.3485894