ÁªÏëÐÞ¸´ÆäÌõ¼Ç±¾µÄUEFI¹Ì¼þÖЩ¶´£¬Ó°Ïì70¶à¿îÐͺÅ

Ðû²¼Ê±¼ä 2022-07-14
1¡¢ÁªÏëÐÞ¸´ÆäÌõ¼Ç±¾µÄUEFI¹Ì¼þÖЩ¶´£¬Ó°Ïì70¶à¿îÐͺÅ

      

¾Ý7ÔÂ13ÈÕ±¨µÀ£¬ÁªÏëÐÞ¸´ÁËÆäÌõ¼Ç±¾µçÄÔµÄUEFI¹Ì¼þÖеÄÈý¸ö»º³åÇøÒç³ö©¶´¡£ÕâЩ©¶´·Ö±ðΪReadyBootDxeÇý¶¯·¨Ê½ÖеĻº³åÇøÒç³ö©¶´£¨CVE-2022-1890£©ÒÔ¼°SystemLoadDefaultDxeÇý¶¯·¨Ê½ÖеĻº³åÇøÒç³ö£¨CVE-2022-1891ºÍCVE-2022-1892£©¡£ESETÑо¿ÈËÔ±½âÊͳÆ£¬ÕâЩ©¶´ÊÇÓÉÓÚͨ±¨¸øUEFIÔËÐÐʱ·þÎñº¯ÊýGetVariableµÄDataSize²ÎÊýÑéÖ¤²»³äʵµ¼ÖµÄ£¬¿É±»ÓÃÀ´ÔÚÆ½Ì¨Æô¶¯µÄÔçÆÚ½×¶ÎʵÏÖÈÎÒâ´úÂëÖ´ÐУ¬²¢½Ù³Ö²Ù×÷ϵͳִÐÐÁ÷³ÌÒÔ¼°½ûÓÃÒ»Ð©ÖØÒªµÄÄþ¾²¹¦Ð§¡£


https://www.bleepingcomputer.com/news/security/new-uefi-firmware-flaws-impact-over-70-lenovo-laptop-models/


2¡¢Á¢ÌÕÍðÄÜÔ´¹«Ë¾Ignitis GroupÔâµ½´ó¹æÄ£DDoS¹¥»÷

      

¾ÝýÌå7ÔÂ12ÈÕ±¨µÀ£¬Á¢ÌÕÍðÄÜÔ´¹«Ë¾Ignitis GroupÔâµ½Á˽üÊ®ÄêÀ´×î´ó¹æÄ£µÄÍøÂç¹¥»÷¡£ÉÏÖÜÁù£¬Õë¶Ô¸Ã¹«Ë¾µÄDDoS¹¥»÷µ¼ÖÂÆäÊý×Ö·þÎñºÍÍøÕ¾ÒòÖжϡ£IgnitisÔÚ7ÔÂ9ÈÕ·¢Ìû£¬ËüÒѾ­Äܹ»¹ÜÀíºÍÏÞÖÆ¹¥»÷¶ÔÆäϵͳµÄÓ°Ï죬¶øÇÒûÓз¢ÏÖÈκÎÎ¥¹æÐÐΪ£¬È»¶ø£¬¹¥»÷ÈÔÔÚ½øÐÐÖС£ºÚ¿ÍÍÅ»ïKillnetÔÚÆäTelegramÖÐÌåÏÖ£¬¶Ô´Ë´Î¹¥»÷ʼþÂôÁ¦¡£Á¢ÌÕÍð¹ú·À²¿¸±²¿³¤ÔÚ·¢±í½²»°Ê±¾¯¸æ³Æ£¬²»Òª¹ý¶È¹Ø×¢´ËÀàÍøÂç¹¥»÷¡£


https://www.infosecurity-magazine.com/news/lithuanian-energy-ddos-attack/


3¡¢È¥ÖÐÐÄ»¯½»Ò×ËùUniswapÔâµ½µöÓã¹¥»÷Ëðʧ800ÍòÃÀÔª

      

¾ÝCheck Point 7ÔÂ12ÈÕ±¨µÀ£¬È¥ÖÐÐÄ»¯¼ÓÃÜ»õ±Ò½»Ò×ËùUniswapÔâµ½µöÓã¹¥»÷£¬Ëðʧ¸ß´ï800ÍòÃÀÔª£¨7500 ETH£©¡£¸ÃʼþÓÚÖÜÒ»Ê×´ÎÆØ¹â£¬BinanceµÄCEOÔÚTwitterÉÏ·¢ÎijÆ£¬ÔÚETHÇø¿éÁ´Éϼì²âµ½Uniswap V3µÄDZÔÚ©¶´¡£UniswapÊ×´´ÈËHayden Adams֤ʵÕâÊÇÒ»´ÎµöÓã¹¥»÷£¬ÓëЭÒé×Ô¼ºÎ޹ء£¹¥»÷ÕßÏòUniswapÓû§¿ÕͶÁ˶ñÒâ´ú±Ò£¬½«ËûÃÇÓÕµ¼ÖÁÒ»¸öµöÓãÍøÕ¾£¬È»ºó´ÓÄ¿±êµÄÇ®°üÖÐÇÔÈ¡×ʽ𡣠


https://blog.checkpoint.com/2022/07/12/8-million-dollars-stolen-in-a-uniswap-phishing-attack/


4¡¢Aerojet RocketdyneÒòÎ¥·´ÍøÂçÄþ¾²¹æÔòÖ§¸¶900ÍòÃÀÔª

      

ýÌå7ÔÂ12Èճƣ¬º½¿Õº½ÌìºÍ¹ú·À¹«Ë¾Aerojet RocketdyneÒÑͬÒâÖ§¸¶900ÍòÃÀÔª£¬À´ºÍ½â¶ÔÓÚÆäÎ¥·´ÍøÂçÄþ¾²¹æÔòµÄËßËÏ¡£¸Ã¹«Ë¾µÄǰԱ¹¤Æ¾¾Ý¡¶Ðé¼ÙË÷Åâ·¨¡·Ïò·¨ÔºÌáÆðËßËÏ£¬ÌåÏÖËûÔÚ¹«Ë¾µ£ÈÎÍøÂçÄþ¾²¡¢ºÏ¹æºÍ¿ØÖƸ߼¶×ܼàʱ£¬¸Ã¹«Ë¾ÔÊÐíÌṩ1000ÍòÖÁ1500ÍòÃÀÔªµÄÔ¤ËãÒÔ¼°5ÖÁ10ÃûÔ±¹¤ºÍ25Ãû³Ð°üÉÌ£¬ÒÔÌá¸ß¼ÆËã»úÄþ¾²ÐÔ¡£µ«ÊÂÇéÆÚ¼ä£¬Ëû·¢Ïָù«Ë¾Ã»ÓÐÂú×ãÓë¹ú·À²¿¡¢NASA»òÆäËüÕþ¸®»ú¹¹Ç©¶©ºÏͬµÄÍøÂçÄþ¾²ÒªÇó¡£AerojetµÄ·¢ÑÔÈ˾ܾøÔںͽâЭÒéÖÐÈÏ¿ÉÓÐ×²¢¾Ü¾øÖÃÆÀ¡£


https://therecord.media/rocket-maker-agrees-to-pay-9-million-to-settle-allegations-of-cybersecurity-violations/


5¡¢Î¢Èí³Æ×ÔÈ¥Äê9ÔÂAiTMµöÓã»î¶¯Òѹ¥»÷Áè¼Ý10000¸ö×éÖ¯

      

7ÔÂ12ÈÕ£¬Î¢ÈíÐû²¼µÄ×îгÂË߳ƣ¬¹¥»÷ÕßʹÓÃAiTMµöÓãÍøÕ¾×÷Ϊ½øÒ»²½½ðÈÚÆÛÕ©µÄÇÐÈëµã¡£³ÂËßÖ¸³ö£¬Ò»¸ö´ó¹æÄ£µÄµöÓã»î¶¯Ê¹ÓÃÖмäÈË£¨AiTM£©µöÓãÍøÕ¾ÇÔÈ¡ÃÜÂë¡¢½Ù³ÖÓû§µÄµÇ¼»á»°²¢Ìø¹ýÈÏÖ¤¹ý³Ì£¬¼´Ê¹Óû§ÒÑÆôÓöàÒòËØÈÏÖ¤£¨MFA£©¡£È»ºó£¬¹¥»÷Õß»áʹÓÃÇÔÈ¡µÄƾ¾ÝºÍ»á»°cookie·ÃÎÊÄ¿±ê»§µÄÓÊÏ䣬²¢¶ÔÆäËüÄ¿±êÖ´ÐÐBEC¹¥»÷¡£Í³¼ÆÊý¾ÝÏÔʾ£¬´Ó2021Äê9Ô¿ªÊ¼£¬AiTMµöÓã»î¶¯ÒÑÕë¶ÔÁË10000¶à¸ö×éÖ¯¡£


https://www.microsoft.com/security/blog/2022/07/12/from-cookie-theft-to-bec-attackers-use-aitm-phishing-sites-as-entry-point-to-further-financial-fraud/


6¡¢Unit42Ðû²¼ChromeLoader¶ñÒâÈí¼þ»î¶¯µÄ·ÖÎö³ÂËß

      

Unit42ÔÚ7ÔÂ12ÈÕÐû²¼Á˹ØÓÚChromeLoader¶ñÒâÈí¼þ»î¶¯µÄ·ÖÎö³ÂËß¡£³ÂËß½éÉÜÁËChromeLoaderµÄ¶à¸ö±äÌ壬ÆäÖеÚÒ»¸öWindows±äÖÖÓÚ½ñÄê1ÔÂÊ״α»·¢ÏÖ£¬macOS°æ±¾ÓÚ3Ô·ݷºÆð£¬µ«Ñо¿ÈËÔ±³Æ£¬×îÔçÉæ¼°¸Ã¶ñÒâÈí¼þµÄ¹¥»÷¿ÉÒÔ×·Ëݵ½2021Äê12Ô¡£ChromeLoaderÖ÷ÒªÓÃÓÚä¯ÀÀÆ÷½Ù³ÖºÍadware»î¶¯£¬ÒÔISO»òDMGÎļþÏÂÔØµÄÐÎʽ·Ö·¢¡£¿ª·¢ÕßûÓÐʹÓÃWindows¿ÉÖ´ÐÐÎļþ(.exe)»ò¶¯Ì¬Á´½Ó¿â(.dll)µÈ´«Í³¶ñÒâÈí¼þ£¬¶øÊÇʹÓÃä¯ÀÀÆ÷À©Õ¹×÷Ϊ×îÖÕpayload¡£


https://unit42.paloaltonetworks.com/chromeloader-malware/