ºê³ž(Acer)Ô¼160GBµÄÃô¸ÐÊý¾Ýй¶²¢ÔÚºÚ¿ÍÂÛ̳³öÊÛ

Ðû²¼Ê±¼ä 2023-03-08

1¡¢ºê³ž(Acer)Ô¼160GBµÄÃô¸ÐÊý¾Ýй¶²¢ÔÚºÚ¿ÍÂÛ̳³öÊÛ


¾ÝýÌå3ÔÂ6ÈÕ±¨µÀ£¬Öйų́Íå¿Æ¼¼¹«Ë¾ºê³ž(Acer Inc.)µÄ´óÁ¿Êý¾Ýй¶¡£¹¥»÷ÕßKernelwareÔÚÒ»¸öÁ÷ÐеĺڿÍÂÛ̳ÉϳöÊÛËûÃÇÉù³ÆÔÚ2023Äê2ÔÂÖÐÑ®´ÓAcerÇÔÈ¡µÄ160GBÊý¾Ý¡£¹¥»÷Õß͸¶±»µÁÊý¾Ý°üÂÞ¼¼ÊõÊֲᡢÈí¼þ¹¤¾ß¡¢ºó¶Ë»ù´¡ÉèÊ©ÏêϸÐÅÏ¢¡¢BIOSÓ³Ïñ¡¢ROMÎļþ¡¢ISOÎļþºÍÌæ»»Êý×Ö²úÎïÃÜÔ¿(RDPK)µÈ¡£×÷Ϊ¹¥»÷Ö¤¾Ý£¬¹¥»÷Õß¹ûÈ»ÁËAcer V206HQLÏÔʾÆÁµÄ¼¼ÊõʾÒâͼ¡¢Îĵµ¡¢BIOS½ç˵ºÍ»úÃÜÎĵµµÄÆÁÄ»½ØÍ¼¡£AcerÈ·ÈÏÆä¹©Î¬ÐÞ¼¼ÊõÈËԱʹÓõÄÎļþ·þÎñÆ÷±»ÈëÇÖ£¬µ«Êǿͻ§Êý¾Ý²¢Î´ÊÜÓ°Ïì¡£


https://www.hackread.com/acer-data-breach-hacker-sell-data/


2¡¢GoogleÐû²¼3Ô·ÝAndroid¸üУ¬×ܼÆÐÞ¸´60¸ö©¶´


¾Ý3ÔÂ7ÈÕ±¨µÀ£¬GoogleÐû²¼ÁË2023Äê3ÔµÄAndroidÄþ¾²¸üУ¬¹²ÐÞ¸´ÁË60¸ö©¶´£¬°üÂÞÁ½¸öÑÏÖØµÄRCE©¶´¡£´Ë´ÎÐÞ¸´µÄ©¶´Í¨¹ýÁ½¸ö¶ÀÁ¢µÄÄþ¾²²¹¶¡Ðû²¼£¬¼´2023-03-01ºÍ2023-03-05¡£Á½¸öRCE©¶´·Ö±ðΪCVE-2023-20951ºÍCVE-2023-20954£¬GoogleÒÑÒþ²Ø¹ØÓÚËüÃǵÄËùÓÐÐÅÏ¢£¬ÒÔ·ÀÖ¹¹¥»÷ÕßÔÚÓû§Ó¦ÓøüÐÂ֮ǰ½øÐй¥»÷¡£±¾ÔÂÐÞ¸´µÄ×îÑÏÖØµÄ©¶´ÊDZÕÔ´Qualcomm×é¼þÖеÄCVE-2022-33213ºÍCVE-2022-33256¡£


https://www.bleepingcomputer.com/news/security/android-march-2023-update-fixes-two-critical-code-execution-flaws/


3¡¢Î÷°àÑÀ°ÍÈûÂÞÄÇÕïËùÒ½ÔºÔâµ½Ransom HouseÀÕË÷¹¥»÷


ýÌå3ÔÂ6Èճƣ¬Î÷°àÑÀ°ÍÈûÂÞÄÇÕïËùÒ½Ôº(Hospital Clinic de Barcelona) Ôâµ½¹¥»÷¡£´Ë´Î¹¥»÷µ¼Ö¸ÃÖÐÐĵļÆËã»úϵͳ崻ú£¬150Ïî·Ç½ô¼±ÊÖÊõºÍ¶à´ï3000ÏÕß¼ì²é±»È¡Ïû£¬Ò½ÔºÕýÔÚ½«ÐµĽô¼±²¡Àý×ªÒÆµ½ÊÐÄÚÆäËûÒ½Ôº¡£µ±µØÒ»¼ÒÄþ¾²»ú¹¹Í¸Â¶£¬Õâ´Î¹¥»÷À´×ÔÀÕË÷ÍÅ»ïRansom House£¬ÀÕË÷Èí¼þѬȾÁËҽԺʵÑéÊÒ¡¢¼±ÕïÊÒºÍÈý¸öÖ÷ÒªÖÐÐĵÄÒ©·¿ÒÔ¼°¼¸¸öÍⲿÕïËùµÄ¼ÆËã»ú¡£Ä¿Ç°Éв»Çå³þϵͳºÎʱ¿É»Ö¸´Õý³£¡£


https://securityaffairs.com/143121/cyber-crime/hospital-clinic-de-barcelona-ransomware.html


4¡¢µÂ¹úºÍÎÚ¿ËÀ¼Ö´·¨²¿ÃÅ´þ²¶DoppelPaymerµÄºËÐijÉÔ±


3ÔÂ6ÈÕ±¨µÀ£¬Å·ÖÞÐ̾¯×éÖ¯Ðû²¼£¬µÂ¹úºÍÎÚ¿ËÀ¼µÄÖ´·¨²¿ÃÅ´þ²¶ÁËÀÕË÷ÍÅ»ïDoppelPaymerµÄÁ½ÃûºËÐijÉÔ±¡£´þ²¶Ðж¯·¢ÉúÔÚ2023Äê2ÔÂ28ÈÕ£¬Í»»÷ËѲéÁËÒ»ÃûµÂ¹ú¹úÃñµÄºâÓ²¢ÔÚÎÚ¿ËÀ¼¶¼Êлù¸¨ºÍ¹þ¶û¿Æ·ò½øÐÐÁ˹㷺ËѲé¡£µÂ¹úÕþ¸®ÈÏΪ£¬DoppelPaymer»î¶¯Éæ¼°5¸öºËÐijÉÔ±£¬ËûÃÇά»¤¹¥»÷»ù´¡ÉèÊ©¡¢Êý¾ÝÐ¹Â¶ÍøÕ¾¡¢´¦ÖÃ̸Åв¢½«·Ö·¢¶ñÒâÈí¼þ¡£Ö´·¨²¿ÃÅĿǰÒÑ·¢³ö´þ²¶ÁÔÚÈ«Çò·¶Î§ÄÚͨ¼©ÁíÍâ3ÃûÏÓÒÉÈË¡£


https://www.bleepingcomputer.com/news/security/core-doppelpaymer-ransomware-gang-members-targeted-in-europol-operation/


5¡¢SentinelOnÅû¶ÀûÓÃRemcos RATÕë¶Ô¶«Å·µÄµöÓã»î¶¯


3ÔÂ6ÈÕ£¬SentinelOnÅû¶ÁËÀûÓÃDBatLoader¼ÓÔØ·¨Ê½·Ö·¢Remcos RATµÄµöÓã»î¶¯£¬Ö÷ÒªÕë¶Ô¶«Å·»ú¹¹ºÍÆóÒµ¡£¹¥»÷ʼÓÚ°üÂÞ¼Ù·¢Æ±ºÍÕбêÎļþµÄµöÓãÓʼþ£¬°üÂÞDBatLoader¿ÉÖ´ÐÐÎļþµÄtar.lz´æµµ¡£µÚÒ»½×¶Îpayloadαװ³ÉOffice¡¢LibreOffice»òPDFÎĵµ£¬Æô¶¯ºó»á´Ó¹«¹²ÔÆ·þÎñÖлñÈ¡µÚ¶þ½×¶Îpayload¡£¼ÓÔØRemcos RAT֮ǰ£¬DBatLoader´´½¨²¢Ö´ÐÐWindowsÅú´¦Öýű¾£¬ÒÔÀûÓÃ2020Äê¼ÇÔØµÄWindows UACÈÆ¹ýÒªÁì¡£×îÖÕ£¬Í¨¹ý½ø³Ì×¢ÈëµÄ·½Ê½Ö´ÐÐRemcos¡£


https://www.sentinelone.com/blog/dbatloader-and-remcos-rat-sweep-eastern-europe/


6¡¢KasperskyÐû²¼2022ÄêH2¹¤Òµ×Ô¶¯»¯ÏµÍ³ÍþÐ²Ì¬ÊÆµÄ³ÂËß


3ÔÂ6ÈÕ£¬KasperskyÐû²¼2022ÄêH2¹¤Òµ×Ô¶¯»¯ÏµÍ³ÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬È«ÇòÊܵ½¹¥»÷µÄICS¼ÆËã»úµÄ°Ù·Ö±ÈΪ34.3%£¬ÂÔ¸ßÓÚ2022ÉϰëÄ꣨31.8%£©¡£Ö÷ÒªÍþвÀ´Ô´ÊÇ»¥ÁªÍø£¨19.9%£©¡¢µç×ÓÓʼþ¿Í»§¶Ë£¨6.4% £©ºÍ¿Éж³ýµÄÉ豸£¨3.8%£©¡£Êܵ½´ËÀ๥»÷×î¶àµÄµØÓòΪ·ÇÖÞºÍÖÐÑÇ£¬Õ¼±È40.1%¡£Î÷Å·ºÍ±±Å·ÊÇ×îÄþ¾²µÄµØÓò£¬·Ö±ðΪ14.2%ºÍ14.3%¡£KasperskyÔÚ2022ϰëÄêÔÚ¹¤Òµ×Ô¶¯»¯ÏµÍ³Éϼì²âµ½À´×Ô7684¸ö²îÒì¼Ò×åµÄ¶ñÒâÈí¼þ¡£   

 

https://securelist.com/threat-landscape-for-industrial-automation-systems-for-h2-2022/108958/