AppleÐû²¼¸üУ¬ÐÞ¸´AppleAVDÖÐÒѱ»ÀûÓõÄ©¶´

Ðû²¼Ê±¼ä 2022-05-17
1¡¢AppleÐû²¼¸üУ¬ÐÞ¸´AppleAVDÖÐÒѱ»ÀûÓõÄ©¶´


5ÔÂ16ÈÕ£¬AppleÐû²¼½ô¼±¸üУ¬ÐÞ¸´Ó°ÏìÁËMacºÍApple WatchµÄ0 day¡£ÕâÊÇ´æÔÚÓÚAppleAVDÖеÄÔ½½çдÈ멶´£¨CVE-2022-22675£©£¬¿É±»ÓÃÀ´Ê¹ÓÃÄÚºËȨÏÞÖ´ÐÐÈÎÒâ´úÂë¡£AppleµÄͨ¸æÌåÏÖ£¬¸Ã©¶´¿ÉÄÜÒѱ»»ý¼«ÀûÓã¬ÒѾ­Í¨¹ý¸ïнçÏÞ¼ì²éÀ´ÐÞ¸´¡£ÕâÊÇApple¹«Ë¾ÔÚ2022ÄêÐÞ¸´µÄµÚ6¸ö0 day£¬Ö®Ç°»¹ÐÞ¸´ÁËCVE-2022-22587¡¢CVE-2022-22594ºÍCVE-2022-22620µÈ©¶´¡£


https://securityaffairs.co/wordpress/131346/security/apple-sixth-zero-day-2022.html


2¡¢Ñо¿ÈËÔ±·¢ÏÖLinuxºóÃÅBPFdoor¿ÉÈƹýµ±µØ·À»ðǽ


¾ÝýÌå5ÔÂ12ÈÕ±¨µÀ£¬Ñо¿ÈËÔ±ÔÚ½üÆÚ·¢ÏÖÁËÒ»ÖÖÃûΪBPFdoorµÄLinux/Unix ºóÃÅ£¬ÎåÄê¶àÀ´Ò»Ö±Ã»Óб»·¢ÏÖ¡£¸ÃºóÃÅÖ÷ÒªÕë¶ÔLinuxºÍSolarisϵͳ£¬¹¥»÷ÕßÀûÓÃÆä¿ÉÒÔÈƹýµ±µØ·À»ðǽ£¬Ô¶³ÌÁ¬½Óµ½Linux shellÒÔ»ñµÃ¶ÔÄ¿±êÉ豸µÄÍêÈ«·ÃÎÊȨÏÞ¡£Ñо¿ÈËÔ±ÔÚÃÀ¹ú¡¢º«¹ú¡¢ÖйúÏã¸Û¡¢ÍÁ¶úÆä¡¢Ó¡¶È¡¢Ô½ÄϺÍÃåµéµÈµØÓò·¢ÏÖÁËBPFdoorµÄ»î¶¯£¬²¢¼ì²âµ½ÁË11̨Speedtest·þÎñÆ÷ÒÑѬȾBPFdoor£¬Éв»Çå³þËüÃÇÊÇÈçºÎ±»ÈëÇֵġ£


https://www.bleepingcomputer.com/news/security/bpfdoor-stealthy-linux-malware-bypasses-firewalls-for-remote-access/    


3¡¢Fortinet·¢ÏÖÒÁÀÊAPT34Õë¶ÔÔ¼µ©µÄµöÓã¹¥»÷»î¶¯


FortinetÔÚ5ÔÂ11ÈÕÅû¶ÁËÒÁÀÊAPT34£¨ÓÖ³ÆOilrig£©½üÆÚµÄÓã²æʽµöÓã»î¶¯µÄÏêÇé¡£´Ë´Î»î¶¯Ö÷ÒªÕë¶ÔÔ¼µ©µÄÍâ½»¹ÙÔ±£¬Î±×°³Éͬһ»ú¹¹µÄIT²¿ÃŵÄͬÊ·¢Ë͵öÓãÓʼþ¡£ÓʼþÖеĶñÒâExcel¸½¼þÖаüÂÞVBAºê´úÂ룬ּÔÚ´´½¨Ò»¸ö¶ñÒâ¿ÉÖ´ÐÐÎļþ¡¢Ò»¸öÅäÖÃÎļþºÍÒ»¸öÇ©ÃûÇҽྻµÄDLL¡£¶ñÒâÈí¼þʹÓÃDGA¹¤¾ßÓëC2×ÓÓò½øÐÐͨÐÅ£¬ÇһÖÐʹÓõÄһЩÓòÊÔͼαװ³É°¢Ë¹Àû¿µ¡¢»ã·áÒøÐкÍ˼¿ÆµÈÖªÃû¹«Ë¾¡£


https://www.fortinet.com/blog/threat-research/please-confirm-you-received-our-apt


4¡¢¼ÙðµÄPixelmon NFTÍøÕ¾»á·Ö·¢Ð¶ñÒâÈí¼þVidar


ýÌå5ÔÂ15Èճƣ¬Ò»¸ö¼ÙðµÄPixelmon NFTÍøÕ¾»á·Ö·¢ÇÔȡƾ¾ÝµÄжñÒâÈí¼þVidar¡£¹¥»÷Õ߸´ÖÆÁ˺Ϸ¨µÄpixelmon.clubÍøÕ¾£¬²¢ÔÚpixelmon[.]pwÉÏ´´½¨ÁËαÔìµÄÍøÕ¾¡£¸ÃÍøÕ¾»á·Ö·¢Îļþsetup.zip£¬ÆäÖаüÂÞÒ»¸öWindows¿ì½Ý·½Ê½Îļþsetup.lnk£¬Ëü½«Ö´ÐÐPowerShellÃüÁîÒÔ´Ópixelmon[.]pwÏÂÔØsystem32.hta¡£¾­¹ý²âÊÔ£¬System32.hta»áÏÂÔØVidar¡£Vidar»á´Óä¯ÀÀÆ÷ºÍÓ¦Ó÷¨Ê½ÖÐÇÔÈ¡ÃÜÂ룬²¢ÔÚ¼ÆËã»úÉÏËÑË÷Ìض¨Ãû³ÆµÄÎļþ£¬·¢Ë͸ø¹¥»÷Õß¡£


https://www.bleepingcomputer.com/news/security/fake-pixelmon-nft-site-infects-you-with-password-stealing-malware/


5¡¢¶íÂÞ˹¶à¸ö×éÖ¯µÄÐÅÏ¢Êý¾ÝÒѱ»¹ûÈ»ÔÚDDoSecrets


¾Ý5ÔÂ14ÈÕ±¨µÀ£¬AnonymousÌᳫµÄOpRussia»î¶¯ÔÚ½üÒ»ÖÜÓÖÈëÇÖÁ˶íÂÞ˹µÄ¶à¸ö×éÖ¯¡£¹¥»÷Õßͨ¹ýDDoSecrets¹ûÈ»Á˱»µÁÊý¾Ý£¬ÆäÖаüÂÞ£ºSOCAR EnergoresourceµÄ130 GB£¬°üÂÞ½ü116500·âÓʼþ£»°¢ÇÕ˹¿ËÊÐÕþ¸®µÄ8.5 GB£¬°üÂÞ7000¶à·âÓʼþ£»¶íÂÞ˹Áª°îÓæÒµºÍº£ÑóÑо¿Ëù¼«µØ·Ö²¿466 GBµÄÓʼþ£»JSC UMMCµÄ¿Ú°¶ºÍÌú·ÏîÄ¿·þÎñµÄ106 GB£¬ÆäÖаüÂÞ½ü77500·âÓʼþ¡£


https://securityaffairs.co/wordpress/131264/hacktivism/anonymous-oprussia-updates.html


6¡¢CybleÐû²¼¹ØÓÚ¶ñÒâÈí¼þ¹¤¾ß°üEternityµÄ·ÖÎö³ÂËß


5ÔÂ12ÈÕ£¬CybleÐû²¼Á˹ØÓÚ¶ñÒâÈí¼þ¹¤¾ß°üEternityµÄ·ÖÎö³ÂËß¡£ÕâÊÇÒ»¸öеĶñÒâÈí¼þ¼´·þÎñ£¨MaaS£©£¬¿ÉÓÃÀ´Æ¾¾ÝËù½øÐеĹ¥»÷ʹÓòîÒìµÄÄ £¿é½øÐж¨ÖÆ£¬°üÂÞÐÅÏ¢ÇÔÈ¡·¨Ê½¡¢ÍÚ¿óÈí¼þ¡¢clipper¡¢ÀÕË÷Èí¼þ¡¢Èä³æÒÔ¼°DDoS bot¡£ÆäÖÐÊÛ¼Û260ÃÀÔªÒ»ÄêµÄÐÅÏ¢ÇÔÈ¡Èí¼þ¿ÉÇÔÈ¡20¶à¸öä¯ÀÀÆ÷ÖеÄÊý¾Ý£»×î°º¹óµÄÊÇ490ÃÀÔªEternityÀÕË÷Èí¼þÄ £¿é£¬¾Ý³ÆÊÇFUD£¨ÍêÈ«ÎÞ·¨¼ì²âµ½£©µÄ¡£Ñо¿ÈËÔ±ÌåÏÖ£¬ÒѾ­ÔÚÒ°¼ì²âµ½¸Ã¶ñÒâÈí¼þµÄÑù±¾µÄÁ÷´«ºÍʹÓá£


https://blog.cyble.com/2022/05/12/a-closer-look-at-eternity-malware/