΢Èí³ÆÊý°ÙÍò¸öAndroidÉ豸ԤװµÄÓ¦ÓôæÔÚ¶à¸ö©¶´

Ðû²¼Ê±¼ä 2022-05-30

1¡¢Î¢Èí³ÆÊý°ÙÍò¸öAndroidÉ豸ԤװµÄÓ¦ÓôæÔÚ¶à¸ö©¶´


΢ÈíÔÚ5ÔÂ27ÈÕÐû²¼³ÂË߳ƣ¬ÔÚÊý°ÙÍò¸öAndroidÉ豸ԤװµÄÓ¦ÓôæÔÚ¶à¸öÑÏÖØµÄ©¶´¡£¾ÝϤ£¬Ñо¿ÈËÔ±ÔÚmce SystemsµÄÒÆ¶¯¿ò¼ÜÖз¢ÏÖÁË4¸ö©¶´£¬·Ö±ðΪCVE-2021-42598¡¢CVE-2021-42599¡¢ CVE-2021-42600ºÍCVE-2021-42601£¬¿Éµ¼ÖÂÃüÁî×¢ÈëºÍÌáȨµÈ¡£Æ¾¾Ýmce SystemsµÄ˵·¨£¬ÆäÖв¿ÃÅ©¶´»¹Ó°ÏìÁËAndroidºÍiOSÉè±¹ØÁ¬ÄÆäËüÓ¦Óá£ÊÜÓ°ÏìÓ¦ÓÃÔÚGoogle PlayÉÏÓÐÊý°ÙÍò´ÎÏÂÔØÁ¿£¬×÷ΪϵͳӦÓ÷¨Ê½Ô¤×°ÔÚ´ÓAT&TºÍTELUSµÈÔËÓªÉÌ´¦¹ºÖõÄÉ豸ÉÏ¡£Ä¿Ç°£¬ÕâЩ©¶´Òѱ»ÐÞ¸´¡£


https://www.microsoft.com/security/blog/2022/05/27/android-apps-with-millions-of-downloads-exposed-to-high-severity-vulnerabilities/


2¡¢ÐÂAndroidľÂíERMAC 2.0¿ÉÒÔ´Ó467¸öÓ¦ÓÃÖÐÇÔÈ¡ÐÅÏ¢


¾ÝýÌå5ÔÂ26ÈÕ±¨µÀ£¬AndroidÒøÐÐľÂíERMACÒÑÒÑ·ºÆð2.0°æ±¾£¬Õë¶ÔµÄÄ¿±êÓ¦ÓÃÊýÁ¿´Ó֮ǰµÄ378¸öÔö¼Óµ½467¸ö¡£¸Ã¶ñÒâÈí¼þÖ¼ÔÚÇÔȡĿ±êµÄµÇ¼ƾ¾Ý²¢·¢Ë͸ø¹¥»÷Õߣ¬È»ºóÀûÓÃÇÔÈ¡µÄƾ֤À´¿ØÖÆÄ¿±êµÄÒøÐкͼÓÃÜ»õ±ÒÕË»§£¬½øÐнðÈÚ»òÆäËüÐÎʽµÄÆÛÕ©¡£Ñо¿ÈËÔ±·¢ÏֵĵÚÒ»¸öÀûÓÃÁËERMAC 2.0µÄ»î¶¯ÊÇÕë¶Ô²¨À¼µÄ£¬¹¥»÷Õßð³äÁËÅ·ÖÞÍâÂô·þÎñBolt Food£¬Í¨¹ýbolt-food[.]siteÍøÕ¾·Ö·¢¶ñÒâÈí¼þ¡£Îª·ÀÖ¹AndroidľÂíѬȾ£¬Ñо¿ÈËÔ±½¨ÒéÓû§¾¡Á¿ÖÆÖ¹´ÓPlay StoreÒÔÍâÏÂÔØAPK¡£


https://www.bleepingcomputer.com/news/security/new-ermac-20-android-malware-steals-accounts-wallets-from-467-apps/


3¡¢ÀÕË÷ÍÅ»ïClop¾íÍÁÖØÀ´£¬½ö½ñÄê4Ô¾ÍÒѹ¥»÷21¸öÄ¿±ê


ýÌå5ÔÂ28Èճƣ¬ÀÕË÷ÍÅ»ïClopÔÚÈ¥Äê11ÔÂÖÁ½ñÄê2Ô¶ÌÔݵعرÕÊýÔºó£¬ÓÖ¾íÍÁÖØÀ´¡£ÔÚ¹ú¼ÊÐ̾¯×é֯Эµ÷µÄ´úºÅΪOperation CycloneµÄÖ´·¨Ðж¯Ö®ºó£¬Clop²¿ÃÅ»ù´¡ÉèÊ©ÓÚ2021Äê6Ô¹رÕ£¬6¸ö³ÉÔ±±»²¶¡£NCC GroupµÄÊý¾ÝÏÔʾ£¬4Ô·ÝClopÔÚÆäÍøÕ¾ÐÂÔöÁË21¸öÒѱ»¹¥»÷µÄÄ¿±ê£¬ÆäÖ÷ÒªÕë¶Ô¹¤ÒµÐÐÒµ£¬Õ¼±ÈΪ45%£¬Æä´ÎÊǿƼ¼¹«Ë¾£¨27%£©¡£´ËÍ⣬Lockbit 2.0ºÍContiÊÇ4Ô·Ý×î»îÔ¾µÄÍŻ·Ö±ð¹¥»÷ÁË103ºÍ45¸öÄ¿±ê¡£


https://www.bleepingcomputer.com/news/security/clop-ransomware-gang-is-back-hits-21-victims-in-a-single-month/


4¡¢GitHub¹ûÈ»½ü10ÍòNPMÓû§Æ¾¾ÝµÄOAuthÁîÅÆ±»µÁµÄÐÅÏ¢


GitHubÔÚ5ÔÂ26ÈÕ͸¶£¬4ÔÂÖÐÑ®µÄÄþ¾²Ê¼þÖУ¬¹¥»÷ÕßÀûÓÃHerokuºÍTravis-CIµÄ±»µÁOAuthÓ¦ÓõÄÁîÅÆÇÔÈ¡ÁËÔ¼100000¸önpmÕÊ»§µÄµÇ¼ÐÅÏ¢¡£×Ô4ÔÂ12ÈÕÔâµ½ÒÔÀ´£¬GitHubÒ»Ö±ÔÚÊÓ²ìÕâ´Î¹¥»÷¶ÔnpmµÄÓ°Ï죬²¢ÔÚ½üÆÚ·¢ÏÖÁËеÄÐÅÏ¢¡£¹¥»÷Õß¿ÉÀûÓñ»µÁÁîÅÆÉý¼¶¶Ônpm»ù´¡ÉèÊ©µÄ·ÃÎÊȨÏÞ£¬²¢ÇÔÈ¡skimdb.npmjs.comµÄÊý¾Ý¿â±¸·ÝÖнØÖÁ2021Äê4ÔÂ7ÈÕµÄÊý¾Ý£¨°üÂÞÔ¼10ÍònpmÓû§ÐÅÏ¢£©¡¢½ØÖÁ2022Äê4ÔÂ10ÈÕËùÓÐnpm˽ÓаüµÄÒÑÐû²¼°æ±¾Ãû³ÆºÍ°æ±¾ºÅ(semVer)µÄ´æµµ£¬ÒÔ¼°Á½¸ö×éÖ¯µÄ²¿ÃÅ˽Óаü¡£


https://github.blog/2022-05-26-npm-security-update-oauth-tokens/


5¡¢°ÂµØÀû¿Ë¶÷¶ÙÖÝÔâµ½BlackCatµÄ¹¥»÷²¢±»ÀÕË÷500ÍòÃÀÔª


¾Ý5ÔÂ27ÈÕ±¨µÀ£¬°ÂµØÀû¿Ë¶÷¶ÙÖÝ£¨Carinthia£©Ôâµ½ÁËBlackCatµÄÀÕË÷¹¥»÷¡£¹¥»÷·¢ÉúÔÚÉÏÖܶþ£¬¸ÃÖÝÕþ¸®·þÎñµÄÔËÓª·¢ÉúÖжÏ£¬²¢±»ÀÕË÷500ÍòÃÀÔª¡£¾Ý³Æ£¬Êýǧ¸öÊÂÇéÕ¾Òѱ»¼ÓÃÜ£¬CarinthiaµÄ¹ÙÍøºÍÓʼþ·þÎñ´¦ÓÚÀëÏß״̬£¬Õþ¸®ÎÞ·¨Ç©·¢»¤ÕÕ»ò´¦Öý»Í¨·£¿î¡£¸ÃÖÝ·¢ÑÔÈËGerd KurathÌåÏÖ£¬ËûÃDz»»áÂú×ã¹¥»÷ÕßµÄÒªÇó£¬BlackCatûÓдÓËûÃǵÄϵͳÖÐÇÔÈ¡ÈκÎÊý¾Ý£¬¶øËûÃÇ¿ÉÒÔÓñ¸·Ý»Ö¸´É豸¡£´ËÍ⣬ÔÚÊÜÓ°ÏìµÄ3000¸öϵͳÖУ¬µÚÒ»ÅúϵͳԤ¼ÆÔÚ5ÔÂ27ÈÕ¿ÉÖØÐÂÆôÓá£


https://www.bleepingcomputer.com/news/security/blackcat-alphv-ransomware-asks-5-million-to-unlock-austrian-state/


6¡¢KasperskyÐû²¼2022ÄêQ1ÍøÂçÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß


5ÔÂ27ÈÕ£¬KasperskyÐû²¼ÁË2022ÄêµÚÒ»¼¾¶ÈÍøÂçÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß¡£³ÂË߸ÅÊöÁ˼¸´ÎÓÐÕë¶ÔÐԵĹ¥»÷£¬·Ö±ðΪ¶ñÒâÈí¼þMoonBounce¹¥»÷UEFI¹Ì¼þ¡¢APT×éÖ¯BlueNoroff¼ÌÐøÑ°ÕÒ¼ÓÃÜ»õ±Ò¡¢Roaming MantisÒѽ«¹¥»÷·¶Î§À©Õ¹µ½Å·ÖÞ¡¢ÓëÎÚ¿ËÀ¼Î£»úÓйصÄÍøÂç¹¥»÷£¬ÒÔ¼°LazarusʹÓÃľÂí»¯DeFiÓ¦ÓÃÀ´·Ö·¢¶ñÒâÈí¼þ¡£´ËÍ⣬³ÂËß»¹°üÂÞÆäËüµÄ¶ñÒâÈí¼þ»î¶¯£¬ÈçNoreboot¼Ù×°iPhoneÖØÆô¡¢ÔÚICSÍøÂçÉÏѰÕÒ¹«Ë¾Æ¾Ö¤¡¢Lapsus$×éÈëÇÖOktaºÍÍøÂçµöÓ㹤¾ß°üÊг¡¡£


https://securelist.com/it-threat-evolution-q1-2022/106513/