Windows KB5013943¸üпɵ¼ÖÂSophosɱ¶¾´¥·¢À¶ÆÁ

Ðû²¼Ê±¼ä 2022-05-18
1¡¢Windows KB5013943¸üпɵ¼ÖÂSophosɱ¶¾´¥·¢À¶ÆÁ


¾ÝýÌå5ÔÂ16ÈÕ±¨µÀ£¬°²×°KB5013943¸üкóµÄWindows 11ÉÏÔËÐÐSophos Homeɱ¶¾Èí¼þ»á´¥·¢À¶ÆÁËÀ»ú£¨BSOD£©ÎÊÌâ¡£SophosÌåÏÖ£¬Õâ¸öÎÊÌâÊÇÓÉÓÚSophos HomeʹÓõÄhmpalert.sys£¨ÓÖÃûHitManPro.Alert Support£©WindowsÇý¶¯·¨Ê½ÒýÆðµÄ¡£´ËÎÊÌâµÄÐÞ¸´·¨Ê½½«×Ô¶¯Ó¦ÓÃÓÚËùÓÐÊÜÓ°ÏìµÄϵͳ£¬Óû§¿ÉÒÔÔÚC:\Windows\System32\driversÖмì²éhmpalert.sysµÄÏêϸÐÅÏ¢À´È·¶¨ÐÞ¸´·¨Ê½ÊÇ·ñÒѱ»Ó¦Óá£Î´½øÐÐ×Ô¶¯ÐÞ¸´µÄÓû§ÐèÒªÖØÃüÃûhmpalert.sysÇý¶¯·¨Ê½»òÐ¶ÔØÓÐÎÊÌâµÄWindows¸üС£


https://www.bleepingcomputer.com/news/software/sophos-antivirus-driver-caused-bsods-after-windows-kb5013943-update/     


2¡¢NVIDIAÐû²¼¸üУ¬ÐÞ¸´ÆäGPUÇý¶¯·¨Ê½ÖеĶà¸ö©¶´


5ÔÂ16ÈÕ£¬NVIDIAÐû²¼5Ô·ÝÄþ¾²¸üУ¬ÐÞ¸´ÁËÆäGPUÇý¶¯·¨Ê½ÖеĶà¸ö©¶´¡£´Ë´Î¸üÐÂÐÞ¸´ÁË¿ÉÄܵ¼Ö¾ܾø·þÎñ¡¢ÐÅϢй¶¡¢ÌØÈ¨ÌáÉý¡¢´úÂëÖ´ÐеȵÄ©¶´£¬ÊÊÓÃÓÚÈí¼þ²úÎïTesla¡¢RTX/Quadro¡¢NVS¡¢StudioºÍGeForce£¬º­¸ÇÇý¶¯·ÖÖ§R450¡¢R470ºÍR510¡£ÆäÖнÏΪÑÏÖØµÄ©¶´ÊÇCVE-2022-28181¡¢CVE-2022-28182¡¢CVE-2022-28183ºÍCVE-2022-28184£¬ËüÃǽöÐè½ÏµÍµÄȨÏÞÇÒÎÞÐèÓëÓû§½»»¥£¬¹¥»÷Õß¿ÉÀûÓÃÆäÖ´ÐоßÓиü¸ßȨÏÞµÄÃüÁî¡£½¨ÒéËùÓÐÓû§¾¡¿ì°²×°ÒÑÐû²¼µÄ¸üС£


https://www.bleepingcomputer.com/news/security/nvidia-fixes-ten-vulnerabilities-in-windows-gpu-display-drivers/


3¡¢Malwarebytes·¢ÏÖÕë¶ÔµÂ¹úµÄ×Ô½ç˵PowerShell RAT


MalwarebytesÔÚ5ÔÂ16ÈÕÅû¶ÁËÕë¶ÔµÂ¹úµÄ×Ô½ç˵PowerShell RATµÄϸ½ÚÐÅÏ¢¡£¹¥»÷Õß×¢²áÁËÒ»¸öµÂ¹úÓòÃûcollaboration-bw[.]de£¬²¢¿Ë¡ÁËÕæÊµÍøÕ¾µÄÍâ¹Û¡£ÍøÕ¾Ìṩһ¸öÃûΪ2022-Q2-Bedrohungslage-UkraineµÄÎļþ£¬¾Ý³Æ°üÂÞÁ˹ØÓÚÎÚ¿ËÀ¼¾ÖÊÆµÄÐÅÏ¢¡£¸ÃÎļþ»á´¥·¢Ò»¸öÔËÐÐBase64È¥»ìÏý·¨Ê½µÄPowerShell£¬´Ó¶ø»ñÈ¡²¢Ö´ÐжñÒâ½Å±¾¡£×îÖÕ£¬¸Ã½Å±¾»áÏÂÔØÒ»¸ö.txtÐÎʽµÄRATºÍÒ»¸öͨ¹ýPowerShell×ÊÖúÆäÖ´ÐеÄ.cmdÎļþ¡£


https://blog.malwarebytes.com/threat-intelligence/2022/05/custom-powershell-rat-targets-germans-seeking-information-about-the-ukraine-crisis/


4¡¢ÃÀ¹ú¹¤³Ì¹«Ë¾ParkerÔâµ½ÀÕË÷ÍÅ»ïContiµÄ¹¥»÷


¾Ý5ÔÂ16ÈÕ±¨µÀ£¬ÃÀ¹ú¹¤³Ì¹«Ë¾Parker-Hannifin CorporationÔâµ½ÁËÀÕË÷ÍÅ»ïContiµÄ¹¥»÷¡£ParkerרÃÅ´ÓÊÂÔ˶¯ºÍ¿ØÖƼ¼Êõ£¬ÖØµã¹Ø×¢º½¿ÕҺѹÉ豸£¬ÊÕÈëΪ156ÒÚ¡£¸Ã¹«Ë¾ÌåÏÖ£¬¹¥»÷·¢ÉúÔÚ½ñÄê3ÔÂ11ÈÕÖÁ14ÈÕÆÚ¼ä£¬ËûÃÇÁ¢¼´Æô¶¯ÁËʼþÏìӦЭÒ飬²¢¹Ø±ÕÁ˲¿ÃÅϵͳ¡£¾­¹ýÊӲ죬ȷ¶¨²¿ÃÅÔ±¹¤µÄÐÅϢй¶£¬°üÂÞÐÕÃû¡¢Éç»áÄþ¾²ºÅÂë(SSN)¡¢¼ÒÍ¥µØÖ·¡¢¼ÝʻִÕÕºÅÂë¡¢»¤ÕÕºÅÂë¡¢²ÆÕþÕË»§ÐÅÏ¢ºÍÕÊ»§ÃÜÂëµÈ¡£ContiÔÚ4ÔÂ1ÈÕÉù³Æ¶Ô´ËÊÂÂôÁ¦£¬²¢ÔÚ4ÔÂ20ÈÕÐû²¼ÁËÇÔÈ¡µÄ419 GBÊý¾Ý¡£


https://www.infosecurity-magazine.com/news/parker-conti-ransomware/


5¡¢Kaspersky³Æ2022ÄêHTML¸½¼þÔÚµöÓã»î¶¯ÖÐÒÀȻʢÐÐ


5ÔÂ16ÈÕ£¬KasperskyÐû²¼³ÂËß³Æ2022ÄêHTML¸½¼þÔÚµöÓã»î¶¯ÖÐÒÀȻʢÐС£¹¥»÷ÕßÖ÷ҪʹÓÃÁ½ÖÖÀàÐ͵ÄHTML¸½¼þ£º´øÓÐÖ¸ÏòαÔìÍøÕ¾Á´½ÓµÄHTMLÎļþ£¬»òÒ»¸ö³ÉÊìµÄÍøÂçµöÓãÒ³Ãæ¡£³ÂËßÖ¸³ö£¬ÔÚ2022Äêǰ4¸öÔ£¬¼ì²âµ½½ü200Íò·â°üÂÞ¶ñÒâHTML¸½¼þµÄµç×ÓÓʼþ£¬ÔÚ3Ô·ݵ½´ï·åÖµ£¬¼ì²âµ½851000·â£¬¶øÔÚ4Ô½µÖÁ387000´Î¡£Ñо¿ÈËÔ±ÌåÏÖ£¬´ËÀ๥»÷¿ÉÄÜÈÆ¹ýÄþ¾²²úÎïµÄ¼ì²â£¬Òò´ËÓû§Ó¦¸ÃʼÖÕ½«HTML¸½¼þÊÓΪ¸ß¶È¿ÉÒɵÄ¡£


https://securelist.com/html-attachments-in-phishing-e-mails/106481/


6¡¢Trend MicroÐû²¼¶ñÒâÈí¼þFacestealerµÄ·ÖÎö³ÂËß


Trend MicroÔÚ5ÔÂ16ÈÕÐû²¼Á˹ØÓÚ¶ñÒâÈí¼þFacestealerµÄ¼¼Êõ·ÖÎö³ÂËß¡£FacestealeÓÚ2021Äê7ÔÂÊ״α»·¢ÏÖ£¬¿ÉÓÃÀ´ÇÔÈ¡Facebookƾ¾Ý¡£Ñо¿ÈËÔ±ÌåÏÖ£¬×î½üµÄÊÓ²ìÔÚGoogle Play É̵êÖз¢ÏÖÁË200¶à¸öFacestealerÓ¦Ó÷¨Ê½£¬ÆäÖÐһЩÒѾ­°²×°ÁËÁè¼ÝÊ®Íò´Î¡£ËüÃÇͨ³£Î±×°³É½¡ÉíºÍÕÕÆ¬±à¼­µÈÓ¦Ó÷¨Ê½£¬ÈçDaily Fitness OL¡¢Enjoy Photo Editor¡¢Panorama CameraºÍPhoto Gaming PuzzleµÈ¡£Ä¿Ç°£¬GoogleÒÑ´ÓÉ̵êÖÐÒÆ³ýÁËÕâЩӦÓá£


https://www.trendmicro.com/en_us/research/22/e/fake-mobile-apps-steal-facebook-credentials--crypto-related-keys.html