ÁªÏëUEFI¹Ì¼þÇý¶¯·¨Ê½ÖеÄ©¶´Ó°ÏìÉϰٿîÌõ¼Ç±¾µçÄÔ

Ðû²¼Ê±¼ä 2022-04-20

1¡¢ÁªÏëUEFI¹Ì¼þÇý¶¯·¨Ê½ÖеÄ©¶´Ó°ÏìÉϰٿîÌõ¼Ç±¾µçÄÔ


¾ÝýÌå4ÔÂ19ÈÕ±¨µÀ £¬ESETÑо¿ÈËÔ±·¢ÏÖÓ°ÏìÁªÏëÉϰٿîÌõ¼Ç±¾µçÄÔµÄ3¸ö©¶´¡£ÆäÖÐÁ½¸ö©¶´£¨CVE-2021-3971ºÍCVE-2021-3972£©¿ÉÓÃÀ´½ûÓöԴ洢UEFI¹Ì¼þµÄSPIÉÁ´æÐ¾Æ¬µÄ±£»¤ £¬²¢¹Ø±ÕUEFIÄþ¾²Æô¶¯¹¦Ð§ £¬Ê¹¶ñÒâÈí¼þÔÚÏµÍ³ÖØÆôºóÈÔ¿É´æÔÚ¡£µÚÈý¸ö©¶´£¨CVE-2021-3970£©´æÔÚÓÚLenovoVariable SMI´¦Ö÷¨Ê½ÖÐ £¬¹¥»÷Õß¿ÉÀûÓÃÆäÒÔÌáÉýµÄȨÏÞÖ´ÐÐÈÎÒâ´úÂë¡£ESETÓÚ2021Äê10ÔÂ11ÈÕÏòÁªÏë³ÂËßÕâЩ©¶´ £¬ÁªÏëÓÚ4ÔÂ12ÈÕÐû²¼²¹¶¡¡£


https://www.bleepingcomputer.com/news/security/lenovo-uefi-firmware-driver-bugs-affect-over-100-laptop-models/


2¡¢CISAºÍFBIÁªºÏÐû²¼¹ØÓÚÇø¿éÁ´ÐÐÒµµÄÍøÂçÄþ¾²×Éѯ


4ÔÂ18ÈÕ £¬ÃÀ¹úFBI¡¢CISAºÍ²ÆÕþ²¿ÁªºÏÐû²¼Á˹ØÓÚÇø¿éÁ´ÐÐÒµµÄÍøÂçÄþ¾²×Éѯ¡£¸Ã×Éѯָ³ö £¬³¯ÏÊAPT×éÖ¯LazarusÃé×¼Çø¿éÁ´¼¼ÊõºÍ¼ÓÃÜ»õ±ÒÐÐÒµµÄÖÖÖÖ×éÖ¯ £¬°üÂÞ¼ÓÃÜ»õ±Ò½»Ò×Ëù¡¢È¥ÖÐÐÄ»¯½ðÈÚ (DeFi) ЭÒéºÍ¼ÓÃÜ»õ±ÒóÒ×¹«Ë¾µÈ¡£¹¥»÷ÕßʹÓÃÖÖÖÖͨÐÅÆ½Ì¨¶ÔÄ¿±ê½øÐÐÉç»á¹¤³Ì¹¥»÷ £¬ÓÕʹÆäÔÚWindows»òmacOSϵͳÉÏÏÂÔØÄ¾Âí»¯µÄ¼ÓÃÜ»õ±ÒÓ¦Óà £¬ÒÔÇÔȡ˽Կ»òÀÄÓÃÆäËü©¶´¡£¸Ãͨ¸æÌṩÁË´ËÀà»î¶¯Ïà¹ØµÄ¼ÆÄ±¡¢¼¼ÊõºÍ·¨Ê½(TTP)ºÍIOC £¬ÒÔ×ÊÖú×é֯ʶ±ð²¢µÖÓùÕë¶Ô¼ÓÃÜ»õ±ÒµÄÍøÂç¹¥»÷¡£


https://www.cisa.gov/uscert/ncas/alerts/aa22-108a


3¡¢CloudSEK·¢ÏÖð³äWin11Éý¼¶·Ö·¢Inno StealerµÄ»î¶¯


ýÌå4ÔÂ18ÈÕ±¨µÀ £¬CloudSEK·¢ÏÖð³äWin11Éý¼¶·Ö·¢Inno StealerµÄ»î¶¯¡£¸Ã»î¶¯Ä¿Ç°ºÜ»îÔ¾ £¬Í¨¹ýËÑË÷½á¹ûͶ¶¾À´ÍÆËÍð³äWindows 11ÍÆ¹ãÒ³ÃæµÄµöÓãÍøÕ¾¡£Ä¿±êµã»÷Á¢¼´ÏÂÔØºó»áµÃµ½Ò»¸öISOÎļþ £¬ÆäÖаüÂÞInno StealerµÄ¼ÓÔØ·¨Ê½¡£Ð¶ñÒâÈí¼þÒòΪʹÓÃÁËInno Setup Windows°²×°·¨Ê½¶øµÃÃû £¬ÓëĿǰÁ÷ÐÐµÄÆäËüÐÅÏ¢ÇÔÈ¡·¨Ê½µÄ´úÂëûÓÐÈκÎÏàËÆÖ®´¦ £¬¿ÉÇÔÈ¡ä¯ÀÀÆ÷cookieºÍ´æ´¢µÄƾ¾Ý¡¢¼ÓÃÜ»õ±ÒÇ®°üÖеÄÊý¾ÝÒÔ¼°ÎļþϵͳµÄÊý¾Ý¡£


https://www.bleepingcomputer.com/news/security/unofficial-windows-11-upgrade-installs-info-stealing-malware/


4¡¢Äþ¾²¹«Ë¾PRODAFTÐû²¼ÀÕË÷Èí¼þPYSAµÄÉî¶È·ÖÎö³ÂËß


4ÔÂ14ÈÕ £¬Äþ¾²¹«Ë¾PRODAFTÐû²¼Á˹ØÓÚÀÕË÷Èí¼þPYSAµÄÉî¶È·ÖÎö³ÂËß¡£PYSAÊÇMespinozaµÄ¼ÌÈÎÕß £¬ÓÚ2019Äê12ÔÂÊ״α»·¢ÏÖ £¬ÒѳÉΪ2021ÄêQ4¼ì²âµ½µÄµÚÈý´óÁ÷ÐÐÀÕË÷Èí¼þ £¬×Ô2020Äê9ÔÂÒÔÀ´Ð¹Â¶Á˶à´ï747¸ö±»¹¥»÷Ä¿±êµÄÐÅÏ¢¡£PRODAFT·¢ÏÖÁËPYSAµÄ¹ûÈ».gitÎļþ¼Ð £¬ÆäÖÐÒ»¸ö³ÉÔ±ÊÇ¡°dodo@mail.pcc¡± £¬Æ¾¾ÝÌá½»ÀúÊ·ÅжϴËÈËλÓÚÒ»¸öÏÄÁîʱ¹ú¼Ò¡£PYSAµÄ»ù´¡ÉèÊ©»¹°üÂÞdockerizedÈÝÆ÷ £¬É漰й¶·þÎñÆ÷¡¢Êý¾Ý¿âºÍ¹ÜÀí·þÎñÆ÷ £¬ÒÔ¼°´æ´¢¼ÓÃÜÎļþµÄAmazon S3ÔÆ £¬×ܼÆ31.47TB¡£


https://thehackernews.com/2022/04/researchers-share-in-depth-analysis-of.html 


5¡¢CheckPointÐû²¼2022ÄêÃæÁÙ×î´óµÄÔÆÄþ¾²ÌôÕ½µÄ³ÂËß


CheckPointÔÚ4ÔÂ18ÈÕÐû²¼ÁË2022ÄêÃæÁÙµÄ×î´óÔÆÄþ¾²ÌôÕ½µÄ³ÂËß¡£³ÂËßÖ¸³ö £¬Áè¼Ý98%µÄ×é֯ʹÓûùÓÚÔÆµÄ»ù´¡¼Ü¹¹ £¬76%µÄ×éÖ¯ÓµÓÐÓÉÁ½¸ö»ò¶à¸öÔÆÌṩÉ̵ķþÎñ×é³ÉµÄ¶àÔÆ»·¾³¡£¶àÔÆ»·¾³µÄÅÓ´óÐÔµ¼ÖÂÁËÐí¶àÌôÕ½ £¬°üÂÞÊý¾ÝµÄÒþ˽ºÍ±£»¤¡¢¶àÔÆ»·¾³ÖÐÐëÒªµÄ¼¼ÄÜ¡¢½â¾ö·½°¸ÕûºÏÒÔ¼°¿É¼ûÐԺͿØÖƵÄȱ·¦¡£ÊµÏÖÔÆÄþ¾²µÄÖ÷ҪĿ±ê°üÂÞ·ÀÖ¹ÔÆÅäÖôíÎó¡¢±£»¤ÒÑÔÚʹÓõÄÖ÷ÒªÔÆÓ¦Ó÷¨Ê½¡¢ÊµÏÖ¼à¹ÜºÏ¹æºÍµÖÓù¶ñÒâÈí¼þ¡£


https://blog.checkpoint.com/2022/04/18/the-biggest-cloud-security-challenges-in-2022-check-point-software/


6¡¢FortinetÐû²¼½üÆÚEmotet Maldoc·¢×÷Ç÷ÊÆµÄ·ÖÎö³ÂËß


4ÔÂ18ÈÕ £¬FortinetÐû²¼¹ØÓÚ½üÆÚEmotet·Ö·¢Maldoc»î¶¯µÄ·ÖÎö³ÂËß¡£´ËÂֻ¿ªÊ¼ÓÚ2021Äê11ÔÂ16ÈÕ £¬Ê¹ÓÃÁ˵öÓãÓʼþÓëÉç»á¹¤³Ì¹¥»÷Ïà½áºÏµÄ·½Ê½ £¬À´ÓÕʹĿ±ê°²×°¶ñÒâÈí¼þ¡£ÕâЩµöÓãÓʼþµÄÖ÷ÌâÐÐÖÐͨ³£ÖаüÂÞ¡°Re:¡±»ò¡°Fw:¡± £¬Ê¹Æä¿´ÆðÀ´Ô½·¢ºÏ·¨¡£Ñо¿ÈËÔ±¼ì²âµ½ÁËÓë´Ë»î¶¯Ïà¹ØµÄ5¸ö²îÒìÑù±¾ £¬ËüÃǵĺê´úÂëºÍÖ´ÐÐÁ÷³Ì´æÔÚ²îÒì¡£´ËÍâ £¬¹¥»÷»î¶¯Ê¹ÓõĶñÒâExcelÎļþµÄÕ¼±ÈΪ93% £¬Ô¶¸ßÓÚ7%µÄ¶ñÒâWordÎĵµ¡£


https://www.fortinet.com/blog/threat-research/Trends-in-the-recent-emotet-maldoc-outbreak