2Ô·ݸüе¼Ö²¿ÃÅWindows Server 2022ÐéÄâ»úÎÞ·¨Æô¶¯
Ðû²¼Ê±¼ä 2023-02-17
¾Ý2ÔÂ16ÈÕ±¨µÀ£¬Î¢ÈíÌåÏÖ£¬²¿ÃÅWindows Server 2022ÐéÄâ»úÔÚ°²×°±¾ÔµÄÖܶþ²¹¶¡ºó¿ÉÄÜÎÞ·¨Æô¶¯¡£´ËÎÊÌâ½öÓ°ÏìÆôÓÃÁËÄþ¾²Æô¶¯²¢ÔÚvSphere ESXi 6.7 U2/U3»òvSphere ESXi 7.0.xÉÏÔËÐеÄÐéÄâ»ú¡£VMwareºÍRedmondÕýÔÚÊÓ²ì´ËÎÊÌ⣬ËäȻĿǰûÓÐÐÞ¸´·¨Ê½£¬µ«VMwareΪÊÜÓ°ÏìµÄ¹ÜÀíÔ±ÌṩÁ˶àÖÖ»º½âÒªÁì¡£Òź¶µÄÊÇ£¬Èç¹ûÒѾ°²×°Á˱¾ÔµÄWindows Server 2022ÀÛ»ý¸üÐÂKB5022842£¬Ð¶ÔØËü²¢²»Äܽâ¾öÎÊÌâ¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-february-updates-break-some-windows-server-2022-vms/
2¡¢ÏÖ´úºÍÆðÑÇÍƳö½ô¼±¸üÐÂÐÞ¸´Í¨¹ýUSBÊý¾ÝÏßµÁ³µµÄÎÊÌâ
ýÌå2ÔÂ15ÈÕ±¨µÀ³Æ£¬Æû³µÖÆÔìÉÌÏÖ´úºÍÆðÑǶÔËûÃǵļ¸¿î³µÐÍÍƳö½ô¼±Èí¼þ¸üУ¬ÒÔÐÞ¸´Í¨¹ýUSBÊý¾ÝÏßµÁ³µµÄÎÊÌâ¡£×Ô2022Äê7ÔÂÒÔÀ´£¬TikTok·ºÆðÁËÒ»ÏîÌôÕ½£¬ÑÝʾÁËÈçºÎ²ðÏÂתÏòÖù¸Ç£¬Â¶³öÒ»¸öUSB-A²å²Û£¬ÓÃÓڶ̷·ÙÉÕÆû³µ¡£ÕâÊÇÒ»¸öÂ߼©¶´£¬ÔÊÐíÔ¿³×Æô¶¯ÏµÍ³Èƹý·ÀµÁÆ÷£¬¹¥»÷Õß¿ÉʹÓÃÈκÎUSBÊý¾ÝÏßÇ¿Ð줻î·ÙÉÕÆø¸×À´Æô¶¯³µÁ¾¡£ÃÀ¹ú½»Í¨²¿³Æ£¬¸Ã©¶´Ó°ÏìÁËÔ¼380ÍòÁ¾ÏÖ´úÆû³µºÍ450ÍòÁ¾ÆðÑÇÆû³µ¡£
https://www.bleepingcomputer.com/news/security/hyundai-kia-patch-bug-allowing-car-thefts-with-a-usb-cable/
3¡¢¼ÓÀû¸£ÄáÑDZ±ÖÝ´óѧÔâµ½AvosLockerÍÅ»ïµÄÀÕË÷¹¥»÷
2ÔÂ15ÈÕ±¨µÀ£¬ÀÕË÷ÍÅ»ïAvosLockerÔÚÆäÍøÕ¾ÁгöÁ˼ÓÀû¸£ÄáÑDZ±ÖÝ´óѧ¡£¹¥»÷Õß͸¶£¬ÒÑÇÔÈ¡°üÂÞÐÕÃû¡¢Éç»áÄþ¾²ºÅÂëºÍµç»°µÈÐÅÏ¢ÔÚÄÚµÄѧÉú¼ȡÊý¾Ý£¬ÒÔ¼°Éæ¼°ÐÕÃû¡¢»áÄþ¾²ºÅÂë¡¢ÈËΪºÍË°ÎñµÈÐÅÏ¢µÄÔ±¹¤Êý¾Ý¡£»¹Ðû²¼ÁË2022 W-2ѧԺԺ³¤¼æÊ×ϯִÐй١¢¸±Ôº³¤¼æÊ×ϯ²ÆÕþ¹ÙµÄÉùÃ÷ºÍÇóÖ°ÕßµÄÐÅÏ¢£¬×÷Ϊ¹¥»÷Ö¤¾Ý¡£¸ÃУÒÑÏò²¿ÃŹÜÀíÈËÔ±ºÍѧÉú·¢ËÍ´Ë´ÎʼþµÄ֪ͨ£¬µ«ÊÇÆä¹ÙÍøûÓÐÈκιØÓÚÍøÂç¹¥»÷µÄÐÅÏ¢¡£
https://www.databreaches.net/california-northstate-university-student-and-employee-data-stolen/
4¡¢Ñо¿ÈËÔ±Åû¶ʩÄ͵µçÆø²¿ÃŲÙ×÷ϵͳÖÐÁ½¸ö©¶´µÄϸ½Ú
¾Ý2ÔÂ15ÈÕ±¨µÀ£¬Ñо¿ÈËÔ±Åû¶ÁËÓ°ÏìSchneider Electric Modicon¿É±à³ÌÂß¼¿ØÖÆÆ÷(PLC)UnityϵÁеÄÁ½¸ö©¶´¡£·Ö±ðΪÒì³£Çé¿ö¼ì²é²»Íש¶´£¨CVE-2022-45788£©£¬¿Éµ¼ÖÂÈÎÒâ´úÂëÖ´ÐС¢¾Ü¾ø·þÎñ¡¢»úÃÜÐÔºÍÍêÕûÐÔ¶ªÊ§¡£ÒÔ¼°Éí·ÝÑéÖ¤Èƹý©¶´£¨CVE-2022-45789£©£¬¿ÉÄܻᵼÖÂÔÚ¿ØÖÆÆ÷ÉÏÖ´ÐÐδ¾ÊÚȨµÄModbus¹¦Ð§¡£ÕâÊÇForescout×·×ٵĩ¶´¼¯ºÏICEFALLµÄÒ»²¿ÃÅ£¬¿ÉÓëÆäËû¹©Ó¦É̵Ä©¶´£¨ÈçCVE-2021-31886£©½áºÏʹÓã¬ÒÔʵÏÖOTÍøÂçÖеÄÉî¶ÈºáÏòÒƶ¯¡£
https://therecord.media/schneider-electric-modicon-vulnerabilities-forescout-icefall/
5¡¢Unit 42·¢ÏÖ¶àÆðÀûÓÃеÄMirai±äÌåV3G4µÄ¹¥»÷»î¶¯
2ÔÂ15ÈÕ£¬Unit 42Åû¶ÁËÐÂMirai±äÌåV3G4µÄ¹¥»÷»î¶¯¡£×Ô2022Äê7ÔÂÒÔÀ´£¬Ñо¿ÈËÔ±ÊӲ쵽ÈýÆðÀûÓÃMirai V3G4±äÌåµÄ»î¶¯¡£¹¥»÷ÕßÀûÓÃÁË13¸ö¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐеÄ©¶´£¬ÀÖ³ÉÀûÓúó»á×Ô¶¯Ö´ÐÐwgetºÍcurl¹¤¾ß£¬´Ó¶ñÒâÈí¼þ»ù´¡ÉèÊ©ÏÂÔØMirai¿Í»§¶ËÑù±¾£¬È»ºóÖ´ÐÐÏÂÔصÄbot¿Í»§¶Ë¡£´ËÍ⣬Unit 42ÈÏΪÕâÈýÆð¹¥»÷¶¼À´×Ôͬһ¸ö¹¥»÷Õߣ¬ÒòΪӲ±àÂëµÄC2Óò°üÂÞÏàͬµÄ×Ö·û´®£¬shell½Å±¾ÏÂÔØÏàËÆ£¬¶øÇÒËùÓй¥»÷ÖÐʹÓõĽ©Ê¬ÍøÂç¿Í»§¶Ë¾ßÓÐÏàͬµÄ¹¦Ð§¡£
https://unit42.paloaltonetworks.com/mirai-variant-v3g4/
6¡¢Group-IBÐû²¼SideWinderÕë¶ÔÑÇÌ«µØÓò¹¥»÷µÄ³ÂËß
Group-IBÔÚ2ÔÂ15ÈÕÐû²¼Á˹ØÓÚSideWinderÕë¶ÔÑÇÌ«µØÓò¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬ÔÚ2021Äê6ÔÂÖÁ2021Äê11ÔÂÆڼ䣬¹¥»÷ÕßÊÔͼÕë¶Ô°¢¸»º¹¡¢²»µ¤¡¢Ãåµé¡¢Äá²´¶ûºÍ˹ÀïÀ¼¿¨µÄ61¸öÕþ¸®¡¢¾ü¶Ó¡¢Ö´·¨²¿ÃŵÈÏà¹Ø×éÖ¯¡£¹¥»÷ʼÓÚÓã²æʽµöÓãÓʼþ£¬»áµ¼ÖÂÏÂÔضñÒâÎĵµ¡¢LNKÎļþ»ò¶ñÒâpayload¡£Ñо¿ÈËÔ±»¹·¢ÏÖÁËÁ½¸öй¤¾ß£¬Ô¶³Ì·ÃÎÊľÂíSideWinder.RAT.bºÍÐÅÏ¢ÇÔÈ¡·¨Ê½SideWinder.StealerPy£¬ËüÃǶ¼Ê¹ÓÃTelegram½øÐÐͨÐÅ£¬¶ø²»ÊÇ´«Í³µÄC2¡£
https://www.group-ib.com/media-center/press-releases/sidewinder-apt-report/