΢ÈíÊÓ²ìDefender½«ºÏ·¨URLʶ±ðΪ¶ñÒâÁ´½ÓµÄÎÊÌâ
Ðû²¼Ê±¼ä 2023-03-311¡¢Î¢ÈíÊÓ²ìDefender½«ºÏ·¨URLʶ±ðΪ¶ñÒâÁ´½ÓµÄÎÊÌâ
¾ÝýÌå3ÔÂ29ÈÕ±¨µÀ£¬Î¢ÈíÔÚÊÓ²ìºÏ·¨URLÁ´½Ó±»Microsoft Defender·þÎñʶ±ðΪ¶ñÒâÁ´½ÓµÄÎÊÌâ¡£×ÔÎÊÌâ·ºÆðµÄÎå¸ö¶àСʱÒÔÀ´£¬Ò»Ð©¿Í»§ÒѾÊÕµ½ÁËÊýÊ®·â¾¯¸æÓʼþ¡£Î¢ÈíÌåÏÖ£¬¾¡¹Ü´æÔÚÎ󱨾¯±¨£¬µ«Óû§ÈÔÈ»Äܹ»·ÃÎʺϷ¨URL£¬ÆäÒ²ÔÚÊÓ²ì·þÎñµÄÄÄÒ»²¿ÃŶéÂ佫ºÏ·¨µÄURLʶ±ðΪ¶ñÒâ¡£3ÔÂ29ÈÕ15:08 EDT¸üÐÂÏÔʾ£¬Îó±¨ÎÊÌâÒÑͨ¹ý»Ö¸´×î½ü¶ÔSafeLinks¹¦Ð§µÄ¸üнâ¾ö¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-mistakenly-tagging-urls-as-malicious/
2¡¢Ñо¿ÈËÔ±·¢ÏÖÀûÓÃľÂí»¯3CX×ÀÃæÓ¦ÓõĹ©Ó¦Á´¹¥»÷
ýÌå3ÔÂ29ÈÕ±¨µÀ³Æ£¬Ñо¿ÈËÔ±Åû¶ÁËÀûÓÃľÂí»¯3CX×ÀÃæÓ¦ÓõĹ©Ó¦Á´¹¥»÷¡£3CXÊÇÒ»¼ÒVoIP IPBXÈí¼þ¿ª·¢¹«Ë¾£¬Æä3CX Phone System±»È«ÇòÁè¼Ý600000¼Ò¹«Ë¾Ê¹Óá£SentinelOne͸¶£¬Ä¾Âí»¯3CXDesktopAppÊǹ¥»÷Á´ÖеĵÚÒ»½×¶Î£¬Ëü´ÓGithubÖÐÌáÈ¡¸½¼ÓÁËbase64Êý¾ÝµÄICOÎļþ£¬²¢×îÖÕµ¼ÖµÚÈý½×¶ÎµÄÐÅÏ¢ÇÔÈ¡·¨Ê½DLL¡£3CX CEO Nick GaleaÌåÏÖ£¬ÆäʹÓõÄÉÏÓοâÒѱ»Ñ¬È¾£¬AndroidºÍiOS°æ±¾²»ÊÜÓ°Ïì¡£Ëû½¨ÒéËùÓÐÓû§Ð¶ÔØ×ÀÃæÓ¦Ó÷¨Ê½£¬×ª¶øʹÓÃPWA¿Í»§¶Ë¡£
https://www.bleepingcomputer.com/news/security/hackers-compromise-3cx-desktop-app-in-a-supply-chain-attack/
3¡¢GoogleÅû¶ÀûÓÃAndroidºÍiOSÖжà¸ö©¶´µÄ¹¥»÷»î¶¯
3ÔÂ29ÈÕ£¬GoogleÅû¶ÁË×î½ü·¢ÏÖµÄÁ½¸ö¹¥»÷»î¶¯£¬ÀûÓÃÁËAndroid¡¢iOSºÍChromeÖжà¸ö©¶´¡£µÚÒ»¸ö»î¶¯ÓÚ2022Äê11Ô±»·¢ÏÖ£¬ÀûÓÃÁËiOS WebKit RCE©¶´(CVE-2022-42856)ºÍChrome GPUɳÏäÈƹý©¶´(CVE-2022-4135)µÈ£¬Ö÷ÒªÕë¶ÔÒâ´óÀû¡¢ÂíÀ´Î÷ÑǺ͹þÈø¿Ë˹̹¡£2022Äê12Ô£¬Ñо¿ÈËÔ±·¢ÏÖÁ˵ڶþ¸ö»î¶¯£¬ÀûÓÃÁËCVE-2022-4262ºÍCVE-2023-0266µÈ©¶´£¬Õë¶Ô×îа汾µÄÈýÐÇä¯ÀÀÆ÷¡£Ëü½«À´×Ô°¢À²®ÁªºÏÇõ³¤¹ú(UAE)µÄÄ¿±êÖض¨Ïòµ½ÉÌÒµ¼äµýÈí¼þ¹©Ó¦ÉÌVariston¿ª·¢µÄHeliconia¿ò¼ÜÏàͬµÄµÇ½ҳÃ棬×îÖÕ°²×°Ò»¸ö»ùÓÚC++µÄAndroid¼äµýÈí¼þÌ×¼þ¡£
https://blog.google/threat-analysis-group/spyware-vendors-use-0-days-and-n-days-against-popular-platforms/
4¡¢Èí¼þ¹©Ó¦ÉÌNebuÒòй¶Լ200ÍòÓû§µÄÐÅÏ¢±»ÆðËß
3ÔÂ30ÈÕýÌå³Æ£¬Ô¼200ÍòºÉÀ¼¹«ÃñµÄÊý¾Ý±»Ð¹Â¶£¬É漰һЩʹÓÃNebuÈí¼þµÄÊг¡Ñо¿»ú¹¹¡£ÆäÖÐÒ»¼Ò»ú¹¹ÏÖ½«¸ÃÈí¼þ¹©Ó¦É̸æÉÏ·¨Í¥£¬Êг¡Ñо¿»ú¹¹BlauwÏ£Íûͨ¹ý·¨ÔºÇ¿ÖÆÒªÇóNebuÌṩ¸ü¶à¹ØÓÚй¶Ê¼þµÄÐÅÏ¢£¬°üÂÞÄÄЩÊý¾ÝÒѱ»Ð¹Â¶ÒÔ¼°Ê¼þÊÇÈçºÎ·¢Éú¡£¸ÃʼþÓ°ÏìÁËDe Vrienden van Amstel LIVE¡¢ºÉÀ¼¸ß¶û·òÁªºÏ»á£¨NGF£©¡¢ÔËÓªÉÌNSºÍ¹©Ó¦ÉÌVodafoneZiggoµÈ¡£ºÉÀ¼Êý¾Ý±£»¤¾Ö£¨AP£©ÌåÏÖ£¬²»ÅųýÓиü¶àµÄ¹«Ë¾ºÍ×éÖ¯Êܵ½Ó°Ïì¡£
https://www.nu.nl/tech/6257515/data-van-2-miljoen-nederlanders-gelekt-softwareleverancier-voor-rechter-gesleept.html
5¡¢Ó¡¶ÈÖÆÒ©¹«Ë¾Sun PharmaceuticalsÔâµ½ÀÕË÷¹¥»÷
¾Ý3ÔÂ30ÈÕ±¨µÀ£¬Ó¡¶È×î´óµÄÖÆÒ©¹«Ë¾Sun Pharmaceuticals͸¶ÆäÔâµ½ÀÕË÷¹¥»÷£¬¹«Ë¾Êý¾ÝºÍ¸öÈËÐÅÏ¢±»µÁ¡£ÕâÊÇÈ«ÇòµÚËÄ´óÌØÖÖ·ÂÖÆÒ©¹«Ë¾£¬2022ÄêÊÕÈë50ÒÚÃÀÔª¡£¸Ã¹«Ë¾ÌåÏÖ£¬Ò»¸öÀÕË÷ÍÅ»ïÒÑÉù³Æ¶ÔÕâÆðʼþÂôÁ¦£¬ËüûÓÐ͸¶¸ÃÍÅ»ïµÄÃû×Ö¡£µ«ÊÇ£¬ÀÕË÷ÍÅ»ïBlack CatÓÚ3ÔÂ24ÈÕÔÚÆäÍøÕ¾ÉÏÁгöÁ˸ù«Ë¾¡£¸Ã¹«Ë¾ÌåÏÖ£¬×÷ΪÏìÓ¦´ëÊ©Æä¸ôÀëÁËÍøÂç²¢Æô¶¯Á˻ָ´·¨Ê½£¬Òò´Ë¹«Ë¾µÄÒµÎñÔËÓªÊܵ½ÁËÓ°Ïì¡£
https://therecord.media/sun-pharma-india-ransomware-attack
6¡¢KasperskyÐû²¼2022ÄêµÄ½ðÈÚÐÐÒµÍþв̬ÊƵijÂËß
3ÔÂ29ÈÕ£¬KasperskyÐû²¼2022ÄêµÄ½ðÈÚÐÐÒµÍþв̬ÊƵijÂËß¡£2022Ä꣬½ðÈÚµöÓãÕ¼ËùÓеöÓã¹¥»÷µÄ36.3%¡£ÍøµêÆ·ÅÆÊÇ×îÊÜ»¶ÓµÄÓÕ¶ü£¬Õ¼µöÓãÍøÕ¾·ÃÎÊ´ÎÊýµÄ15.56%¡£ÊܽðÈÚ¶ñÒâÈí¼þÓ°ÏìµÄÓû§ÊýÁ¿±È2021ÄêϽµÁË14%¡£RamnitÊÇ×îÁ÷ÐеĶñÒâÈí¼þ¼Ò×壬ռ±ÈΪ34.4%£¬Æä´ÎÊÇZbot£¬Õ¼16.2%¡£Ôâµ½ÒøÐжñÒâÈí¼þ¹¥»÷µÄAndroidÓû§ÊýÁ¿±ÈÈ¥Äê¼õÉÙÁË55%¡£BianÓâÔ½Agent³ÉΪ×î»îÔ¾µÄÒƶ¯¶ñÒâÈí¼þ£¬Õ¼±È24.25%£¬¶øAgentΪ21.57%¡£
https://securelist.com/financial-cyberthreats-in-2022/109219/