ÍøÐŰ졶»¥ÁªÍøµ¯´°ÐÅÏ¢ÍÆËÍ·þÎñ¹ÜÀí¹æ¶¨£¨Õ÷ÇóÒâ¼û¸å£©¡·

Ðû²¼Ê±¼ä 2022-03-07

ÍøÐŰ졶»¥ÁªÍøµ¯´°ÐÅÏ¢ÍÆËÍ·þÎñ¹ÜÀí¹æ¶¨£¨Õ÷ÇóÒâ¼û¸å£©¡·


3ÔÂ2ÈÕ£¬¹ú¼Ò»¥ÁªÍøÐÅÏ¢°ì¹«ÊÒÐû²¼Á˹ØÓÚ¡¶»¥ÁªÍøµ¯´°ÐÅÏ¢ÍÆËÍ·þÎñ¹ÜÀí¹æ¶¨£¨Õ÷ÇóÒâ¼û¸å£©¡·¹ûÈ»Õ÷ÇóÒâ¼ûµÄ֪ͨ ¡£Í¨ÖªÖ¸³ö£¬Îª¹æ·¶»¥ÁªÍøµ¯´°ÐÅÏ¢ÍÆËÍ·þÎñ£¬Î¬»¤¹ú¼ÒÄþ¾²ºÍ¹«¹²ÀûÒæ£¬Æ¾¾Ý¡¶ÖлªÈËÃñ¹²ºÍ¹úÍøÂçÄþ¾²·¨¡·µÈÖ´·¨¹æÔòÖÆ¶¨Á˱¾¹æ¶¨ ¡£ÔÚ¾³ÄÚÌṩ²Ù×÷ϵͳ¡¢ÖÕ¶ËÉ豸¡¢Ó¦ÓÃÈí¼þ¡¢ÍøÕ¾µÈ·þÎñµÄ£¬¿ªÕ¹»¥ÁªÍøµ¯´°ÐÅÏ¢ÍÆËÍ·þÎñʱӦµ±×ñÊØ±¾¹æ¶¨ ¡£


http://www.cac.gov.cn/2022-03/02/c_1647826956995841.htm


Unit 42³Æ10Íò¶à¸öÊäÒº±ÃÒ×ÊܶàÄêǰµÄÊý¸ö©¶´Ó°Ïì


3ÔÂ2ÈÕ£¬Unit 42Ðû²¼³ÂËß³ÆÆäÉó²éÁË200000¶à¸öÉ豸£¬²¢·¢ÏÖÆäÖÐ75%´æÔÚ¶àÄêǰµÄ©¶´ ¡£×îÆÕ±éµÄÊÇǶÈëʽÉ豸µÄVxWorksʵʱ²Ù×÷ϵͳ(RTOS)ÖеÄÄÚ´æËð»µÂ©¶´£¨CVE-2019-12255£¬CVSSÆÀ·Ö9.8£©£¬´æÔÚÓÚ52%µÄ²úÎïÖУ¨104000¶ą̀)£¬ÒÑÓÚ2019Äê7ÔÂ19ÈÕ±»ÐÞ¸´ ¡£´ËÍ⣬Ñо¿ÈËÔ±»¹·¢ÏÖÁËCVE-2020-12040¡¢CVE-2020-12045ºÍCVE-2020-12047µÈ¶à¸öÔÚ2019ÄêºÍ2020Äê¾Í±»Åû¶µÄ©¶´ ¡£


https://www.bleepingcomputer.com/news/security/over-100-000-medical-infusion-pumps-vulnerable-to-years-old-critical-bug/


Proofpoint·¢ÏÖÐÂÒ»ÂÖµöÓã»î¶¯Asylum Ambuscade


ProofpointÔÚ3ÔÂ1ÈÕ¹ûÈ»ÁËÐÂÒ»ÂÖµöÓã»î¶¯Asylum AmbuscadeµÄÏêϸÐÅÏ¢ ¡£¸Ã»î¶¯ÈëÇÖÁËÒ»¸öÎÚ¿ËÀ¼Îä×°¶ÓÎéÔ±¹¤µÄÓʼþÕÊ»§£¬Ä¿±êÊǼÓÈë¹ÜÀíÎÚ¿ËÀ¼ÄÑÃñºóÇÚÊÂÇéµÄÈËÔ± ¡£µöÓãÓʼþÀ´×Ôukr[.]net£¬°üÂÞÒ»¸ö¶ñÒâºê¸½¼þ£¬Ö¼ÔÚ·Ö·¢¸öÃûΪSunSeedµÄ»ùÓÚLuaµÄ¶ñÒâÈí¼þ ¡£Ñо¿ÈËÔ±·¢ÏָûÓë2021Äê7Ô°׶íÂÞ˹APT×éÖ¯GhostwriterÌᳫµÄ¹¥»÷ÏàËÆ£¬ÍƶÏÕâÁ½´Î¹¥»÷À´×Ôͬһ¹¥»÷Õß ¡£


https://securityaffairs.co/wordpress/128594/apt/asylum-ambuscade-phishing-campaign-ukraine.html


Salt SecurityÐû²¼¹ØÓÚAPIÄþ¾²Ì¬ÊƵķÖÎö³ÂËß


3ÔÂ2ÈÕ£¬Salt SecurityÐû²¼Á˹ØÓÚAPIÄþ¾²Ì¬ÊƵķÖÎö³ÂËß ¡£³ÂËßÖ¸³ö£¬2021ÄêAPI¹¥»÷Á÷Á¿Ôö³¤ÁË681%£¬¶øÕûÌåAPIÁ÷Á¿Ôö³¤ÁË321% ¡£¸ÃÑо¿¶ÔÀ´×Ô²îÒì¹æÄ£¹«Ë¾µÄ250ÃûÔ±¹¤µÄ½øÐÐÊӲ죬·¢ÏÖ34%µÄ¹«Ë¾È±·¦APIÄþ¾²¼ÆÄ±£¬83%ÊÜ·ÃÕß¶ÔËûÃǵÄÏÖÓÐAPI¹¦Ð§È±·¦ÐÅÐÄ£¬95%µÄÊÜ·ÃÕßÌåÏÖÔÚÈ¥Äê¾­Àú¹ýAPIÄþ¾²Ê¼þ£¬85%µÄÊÜ·ÃÕßÖ¸³öµ±Ç°µÄ¹¤¾ßÎÞ·¨ÓÐЧ×èÖ¹API¹¥»÷ ¡£


https://salt.security/press-releases/salt-security-state-of-api-security-report-reveals-api-attacks-increased-681-in-the-last-12-months?


BarracudaÐû²¼Log4Shell©¶´ÀûÓûµÄÑо¿³ÂËß


Barracuda·ÖÎöÁË×Ô2021Äê12ÔÂ10ÈÕÒÔÀ´¼ì²âµ½µÄ¹¥»÷ºÍpayload£¬²¢ÓÚ3ÔÂ2ÈÕÐû²¼ÁËLog4Shell©¶´ÀûÓûµÄ³ÂËß ¡£³ÂËßÖ¸³ö£¬´ó¶àÊýÀûÓÃʵÑéÀ´×ÔÃÀ¹ú£¬Æä´ÎÊÇÈÕ±¾¡¢ÖÐÅ·ºÍ¶íÂÞ˹ ¡£Ñо¿ÈËÔ±·¢ÏÖÁ˶à¸öÀûÓøÃ©¶´µÄpayload£¬ÆäÖн©Ê¬ÍøÂçMirai¼°Æä±äÌåµÄÕ¼±È×î´ó£¬Æä´ÎΪBillGates malware(DDoS)¡¢Kinsing(¼ÓÃÜ¿ó¹¤)¡¢XMRig(¼ÓÃÜ¿ó¹¤)ºÍMuhstik(DDoS) ¡£³ÂËß»¹Ìá³öÓÐЧ·À·¶´ËÀ๥»÷µÄ×î¼òµ¥ÒªÁìÊǽ«Log4j¸üе½2.17.1»ò¸ü¸ß°æ±¾£¬²¢È·±£ËùÓÐWebÓ¦Óô¦ÓÚ×îÐÂ״̬ ¡£


https://blog.barracuda.com/2022/03/02/threat-spotlight-attacks-on-log4shell-vulnerabilities/     


Ñо¿ÈËÔ±¹ûÈ»LinuxÄÚºËÌáȨ©¶´CVE-2022-0492µÄϸ½Ú


Ñо¿ÈËÔ±ÔÚ3ÔÂ3ÈÕ¹ûÈ»ÁËLinuxÄÚºËÖеÄÌáȨ©¶´£¨CVE-2022-0492£©µÄϸ½Ú ¡£ËüÊÇLinux¿ØÖÆ×é(cgroups)ÖеÄÒ»¸öÂß¼­Â©¶´£¬´æÔÚÓÚ/cgroup/cgroup-v1.cº¯ÊýÖеÄcgroup_release_agent_write ¡£ÔÚijЩÇé¿öÏ£¬Æä¿É±»ÓÃÀ´Í¨¹ýcgroups v1µÄrelease_agentÌØÐÔÌáÉýȨÏÞ£¬²¢ÈƹýÃû³Æ¿Õ¼ä¸ôÀë ¡£Ä¿Ç°£¬¸Ã©¶´ ÒÑÔÚ×îеÄLinux°æ±¾ÖÐÐÞ¸´£¬Ñо¿ÈËÔ±½¨ÒéËùÓÐÓû§Éý¼¶µ½×îа汾 ¡£


https://unit42.paloaltonetworks.com/cve-2022-0492-cgroups/



Äþ¾²¹¤¾ß


BruteShark


ÍøÂçȡ֤·ÖÎö¹¤¾ß (NFAT)£¬Ëü¶ÔÍøÂçÁ÷Á¿£¨Ö÷ÒªÊÇ PCAP Îļþ£©½øÐÐÉî¶È´¦Öúͼì²é ¡£


https://github.com/odedshimon/BruteShark/


Checkov 


ÓÃÓÚ»ù´¡ÉèÊ©¼´´úÂëµÄ¾²Ì¬´úÂë·ÖÎö¹¤¾ß ¡£


https://github.com/bridgecrewio/checkov


JNDI-Injection-Exploit


JNDI×¢ÈëÀûÓù¤¾ß£¬Éú³ÉJNDIÁ´½Ó²¢Æô¶¯ºó¶ËÏà¹Ø·þÎñ£¬¿ÉÓÃÓÚFastjson¡¢JacksonµÈÏà¹ØÂ©¶´µÄÑéÖ¤ ¡£


https://github.com/welk1n/JNDI-Injection-Exploit



nrich v0.2


Ò»¸öÃüÁîÐй¤¾ß£¬ÓÃÓÚ¿ìËÙ·ÖÎöÎļþÖеÄËùÓÐ IP£¬²¢¼ì²ìÄÄЩ¾ßÓпª·Å¶Ë¿Ú/©¶´ ¡£


https://gitlab.com/shodan-public/nrich


fuzzuf


ÊÇÒ»¸ö´øÓÐ×Ô¼ºµÄ DSL µÄ fuzzing ¿ò¼Ü£¬Í¨¹ý¹¹½¨ fuzzing Ô­ÓïµÄ¹¹½¨¿éÀ´ÃèÊöfuzzing Ñ­»· ¡£


https://securityonline.info/fuzzuf-fuzzing-unification-framework/



Äþ¾²·ÖÎö


΢ÈíÐû²¼ÊÊÓÃÓÚ Windows 11 µÄÐÂÓ¦ÓÃÄþ¾²¹¦Ð§


https://news.softpedia.com/news/microsoft-announces-new-app-security-feature-for-windows-11-534974.shtml



¶íÂÞ˹º½Ìì¾Ö³ÆºÚ¿Í¹¥»÷ÎÀÐÇÊÇÒ»ÖÖÕ½ÕùÐÐΪ


https://www.bleepingcomputer.com/news/security/russian-space-agency-says-hacking-satellites-is-an-act-of-war/



¹¥»÷ÕßÀûÓà Telegram ½øÐÐÓë³åÍ»Ïà¹ØµÄ»î¶¯


https://blog.checkpoint.com/2022/03/02/telegram-becomes-a-digital-forefront-in-the-conflict/



Ó¢ÌØ¶ûµÄµÚ 12 ´ú Alder Lake ´¦ÖÃÆ÷²»°üÂÞ΢Èí Pluton 


https://www.theregister.com/2022/03/02/microsoft_pluton_chip/



Anonymous¼°ÆäÁ¥Êô»ú¹¹¼ÌÐø¶Ô¶íÂÞ˹½øÐй¥»÷


https://securityaffairs.co/wordpress/128576/hacktivism/anonymous-causes-damages-to-russia.html