еÄÀÕË÷ÔËÓªÍÅ»ïDeadBolt¹¥»÷È«ÇòµÄQNAP NASÉ豸

Ðû²¼Ê±¼ä 2022-01-28

еÄÀÕË÷ÔËÓªÍÅ»ïDeadBolt¹¥»÷È«ÇòµÄQNAP NASÉ豸


ýÌå1ÔÂ25ÈÕ±¨µÀ£¬ÐµÄÀÕË÷ÔËÓªÍÅ»ïDeadBoltÉù³ÆËûÃÇÕýÔÚʹÓÃÉ豸Èí¼þÖеÄÁãÈÕ©¶´¹¥»÷È«ÇòQNAP NASÉ豸¡£¹¥»÷¿ªÊ¼ÓÚ1ÔÂ25ÈÕ¿ªÊ¼£¬´óÁ¿QNAPÉ豸Òѱ»¼ÓÃܶøÇÒÌí¼ÓÁË.deadboltÀ©Õ¹Ãû£¬Êê½ðΪ0.03±ÈÌØ±Ò£¨Ô¼1100ÃÀÔª£©¡£´ËÍ⣬¸ÃÍŻﻹÌåÏÖQNAPÈç¹ûÖ§¸¶5¸ö±ÈÌØ±Ò¿ÉÒÔ»ñµÃ¹ØÓÚÁãÈÕ©¶´µÄÈ«²¿ÐÅÏ¢£¬Ö§¸¶50¸ö±ÈÌØ±Ò£¨Ô¼ºÏ185ÍòÃÀÔª£©¿ÉÒÔ»ñµÃÊÊÓÃÓÚËùÓÐQNAPÓû§µÄÖ÷½âÃÜÃÜÔ¿ºÍ©¶´ÐÅÏ¢¡£


https://www.bleepingcomputer.com/news/security/new-deadbolt-ransomware-targets-qnap-devices-asks-50-btc-for-master-key/


µç×ÓÉ̳ÇSegwayÔÚMagecart¹¥»÷Öпͻ§ÐÅÏ¢±»µÁ


ýÌå1ÔÂ25ÈÕ±¨µÀ£¬SegwayµÄÔÚÏßÉ̵êÔâµ½Magecart¹¥»÷£¬¿Í»§ÐÅÏ¢±»µÁ¡£Æ¾¾ÝurlscanioÊý¾Ý·ÖÎö£¬SegwayÍøÕ¾ (store.segway.com) ÖÁÉÙ´Ó1ÔÂ6ÈÕ¾ÍÒѾ­±»ÈëÇÖ£¬´Ë´Î»î¶¯¿ÉÄÜÓëMagecart Group 12ÓйØ£¬¸Ã×éÖ¯×Ô2019ÄêÒÔÀ´Ò»Ö±ÔÚÇÔÈ¡ÐÅÓÿ¨ÐÅÏ¢¡£Ñо¿ÈËÔ±ÈÏΪ£¬¹¥»÷ÕßÀûÓÃÁËÍøÕ¾Ê¹ÓõÄMagento CMS»òÆä²å¼þÖеÄ©¶´À´×¢Èë¶ñÒâ´úÂë¡£½ØÖÁ1ÔÂ25ÈÕ£¬ÇÔÈ¡ÐÅÏ¢µÄ¶ñÒâ´úÂëÈÔ´æÔÚÓÚ¸ÃÍøÕ¾ÉÏ¡£


https://securityaffairs.co/wordpress/127187/cyber-crime/segway-magecart-attack.html


LinuxÄÚºËÒç³ö©¶´CVE-2022-0185¿É´ÓÈÝÆ÷ÖÐÌÓÒÝ


ýÌå1ÔÂ25Èճƣ¬ LinuxÄÚºË×é¼þÖдæÔÚ»ùÓڶѵĻº³åÇøÒç³ö©¶´¡£¸Ã©¶´×·×ÙΪCVE-2022-0185£¬¿Éµ¼ÖÂÔ½½çдÈë¡¢¾Ü¾ø·þÎñºÍÈÎÒâ´úÂëÖ´ÐУ¬¿ÉÓÃÀ´´ÓKubernetesµÄÈÝÆ÷ÖÐÌÓÒÝ£¬²¢·ÃÎÊÖ÷»úϵͳÉϵÄ×ÊÔ´¡£µ«ÊÇ£¬¹¥»÷ÕßÐèÒªÀûÓ÷ÇÌØÈ¨Ãû³Æ¿Õ¼ä»òʹÓá°unshare¡±À´ÊäÈë¾ßÓÐCAP_SYS_ADMINȨÏÞµÄÃû³Æ¿Õ¼ä£¬²ÅÆøÀûÓøÃ©¶´¡£Ñо¿ÈËÔ±½¨Ò齫LinuxÄÚºËÉý¼¶µ½5.16.2»ò¸ü¸ß°æ±¾¡£


https://www.bleepingcomputer.com/news/security/linux-kernel-bug-can-let-hackers-escape-kubernetes-containers/


AppleÐû²¼Äþ¾²¸üУ¬ÐÞ¸´Òѱ»ÔÚÒ°ÀûÓõÄÄþ¾²Â©¶´


1ÔÂ26ÈÕ£¬AppleÐû²¼Äþ¾²¸üУ¬ÐÞ¸´ÁËmacOSÖеÄ13¸ö©¶´£¬ÒÔ¼°iOS/iPadOSÖеÄ10¸ö©¶´¡£´Ë´Î¹²ÐÞ¸´ÁË2¸öÁãÈÕ©¶´£¬µÚÒ»¸öÊÇIOMobileFrameBufferÖеÄÄÚ´æËð»µÂ©¶´(CVE-2022-22587)£¬Ó°ÏìÁËiOS¡¢iPadOSºÍmacOS Monterey£¬ÀûÓôË©¶´¿ÉÔÚÄ¿±êÉ豸ÉÏÒÔÄÚºËȨÏÞÖ´ÐÐÈÎÒâ´úÂ룻ÁíÒ»¸öÊÇWebKit StorageÖеÄÐÅϢй¶©¶´£¨CVE-2022-22594£©¡£AppleÔÚͨ¸æÖгÆ£¬CVE-2022-22587¿ÉÄÜÒѱ»»ý¼«ÀûÓá£


https://threatpost.com/apple-zero-day-security-exploited/178040/


TrellixÐû²¼Õë¶ÔÎ÷ÑǵØÓòµÄ¼äµý»î¶¯µÄ·ÖÎö³ÂËß


1ÔÂ25ÈÕ£¬TrellixÐû²¼ÁËÕë¶ÔÎ÷ÑǵØÓò¹ú·ÀÐÐÒµµÄ¼äµý»î¶¯µÄ·ÖÎö³ÂËß¡£´Ë´Î»î¶¯×îÔ翪ʼÓÚ2021Äê6ÔÂ18ÈÕ£¬ÀûÓÃÁËMicrosoft OneDrive×÷ΪC2·þÎñÆ÷£¬²¢·ÖΪÁ˶à´ï6¸ö½×¶Î¡£Ñ¬È¾Á´Ê¼ÓÚ°üÂÞMSHTMLÔ¶³Ì´úÂëÖ´ÐЩ¶´(CVE-2021-40444)©¶´ÀûÓõÄExcelÎļþ£¬²¢Ê¹ÓÃÁËÃûΪGraphiteµÄ¶ñÒâÈí¼þ¡£Trellix»ùÓÚÔ´´úÂëÒÔ¼°¹¥»÷Ö¸±êºÍÄ¿±êµÄÏàËÆÐÔ£¬½«Õâ´Î¹¥»÷¹éÒòÓÚ¶íÂÞ˹µÄAPT28×éÖ¯¡£


https://www.trellix.com/en-gb/about/newsroom/stories/threat-labs/prime-ministers-office-compromised.html


Proofpoint·¢ÏÖDTPacker·Ö·¢¶à¸öRATºÍÐÅÏ¢ÇÔÈ¡·¨Ê½


ProofpointÔÚ1ÔÂ24ÈÕÐû²¼µÄ³ÂË߸ÅÊöÁ˶ñÒâÈí¼þDTPacker¡£ËüÊÇÒ»¸ö·ÖΪ2¸ö½×¶ÎµÄÉÌÆ·.NET´ò°ü·¨Ê½£¬ÆäpayloadʹÓÃÁ˰üÂÞÌÆÄɵÂÌØÀÊÆÕÐÕÃûµÄÀιÌÃÜÂë¡£Proofpoint·¢ÏÖDTPacker·Ö·¢Á˶à¸öRATºÍÐÅÏ¢ÇÔÈ¡·¨Ê½£¬°üÂÞAgent Tesla¡¢Ave Maria¡¢AsyncRATºÍFormBook£¬²¢Ê¹ÓöàÖÖ»ìÏý¼¼ÊõÀ´Èƹýɱ¶¾Èí¼þ¡¢É³ºÐºÍ¼¼Êõ·ÖÎö¡£×Ô2020ÄêÒÔÀ´£¬DTPackerÓëÊýÊ®´Î¹¥»÷»î¶¯ºÍ¶à¸ö¹¥»÷ÍÅ»ïÏà¹Ø£¬ÆäÖаüÂÞTA2536ºÍTA2715¡£


https://www.proofpoint.com/us/blog/threat-insight/dtpacker-net-packer-curious-password-1


Äþ¾²¹¤¾ß


Yasso


»ã¼¯ÁËÐí¶àʵÓù¦Ð§£¬×÷Ϊ Intranet ¸¨ÖúÉøÍ¸¹¤¾ß¼¯Ðû²¼¡£


https://securityonline.info/yasso-intranet-assisted-penetration-toolset/


darvester


PoC Discord Óû§ºÍ¹«»áÐÅÏ¢ÊÕ¼¯¹¤¾ß¡£


https://github.com/V3ntus/darvester


chronorace


¿ÉÒÔ׼ȷµØÖ´Ðж¨Ê±¾ºÕùÌõ¼þÒÔ¹æ±ÜÓ¦Ó÷¨Ê½ÒµÎñÂß¼­µÄ¹¤¾ß¡£


https://github.com/Cache-Money/chronorace


dep-scan


ÍêÈ«¿ªÔ´µÄÄþ¾²É󼯹¤¾ß£¬ÓÃÓÚ»ùÓÚÒÑ֪©¶´¡¢½¨ÒéºÍÐí¿ÉÏÞÖÆµÄÏîÄ¿ÒÀÀµ¹ØÏµ¡£


https://github.com/AppThreat/dep-scan


Http Desync Guardian


·ÖÎö HTTP ÇëÇóÒÔ×îС»¯ HTTP Òì²½¹¥»÷µÄ·çÏÕ¡£


https://github.com/aws/http-desync-guardian


Äþ¾²·ÖÎö


Ó¢¹úNCSCÐû²¼ÓÃÀ´²éÕÒϵͳÖÐδÐÞ¸´Â©¶´µÄNmap½Å±¾


https://securityaffairs.co/wordpress/127181/hacking/uk-ncsc-scanning-made-easy-sme.html


Windows 11 KB5008353 ÀÛ»ý¸üÐÂÔ¤ÀÀÐû²¼


https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5008353-cumulative-update-preview-released/


VMware£ºÐÞ²¹ Horizon ·þÎñÆ÷ÒÔµÖÓùÕýÔÚ½øÐÐµÄ Log4j ¹¥»÷


https://www.bleepingcomputer.com/news/security/vmware-patch-horizon-servers-against-ongoing-log4j-attacks/


¶íÂÞ˹´þ²¶ºÚ¿Í×éÖ¯Infraud OrganizationµÄ³ÉÔ±


https://www.bleepingcomputer.com/news/security/russia-arrests-leader-of-infraud-organization-hacker-group/


ÐÂÄ«Î÷¸çÖÝÌá½»ÍøÂçÄþ¾²·¨°¸


https://www.infosecurity-magazine.com/news/new-mexico-files-cybersecurity/


2021 ÄêÊ®´óÀÕË÷Èí¼þ¹¥»÷


https://www.cybereason.com/blog/ten-of-the-biggest-ransomware-attacks-of-2021