Kaspersky·¢ÏÖ¶à¸ö¶ÌÖÜÆÚµÄ¼äµý»î¶¯Õë¶Ô¹¤¿ØÐÐÒµ
°ä²¼¹¦·ò 2022-01-25Kaspersky·¢ÏÖ¶à¸ö¶ÌÖÜÆÚµÄ¼äµý»î¶¯Õë¶Ô¹¤¿ØÐÐÒµ
1ÔÂ9ÈÕ£¬Kaspersky°ä²¼»ã±¨Åû¶¶à¸öÕë¶Ô¹¤¿ØÐÐÒµµÄ¼äµý»î¶¯¡£ÕâЩ»î¶¯Ê¹ÓÃÏֳɵļäµýÈí¼þ¹¤¾ß£¬Ô̺¬AgentTesla¡¢HawkEye¡¢Noon/Formbook¡¢Masslogger¡¢Snake KeyloggerºÍLokibotµÈ¡£Kaspersky³ÆÕâЩ¹¥»÷³ÆÎª¡°anomalous¡±£¬ÓÉÓÚÓ봫ͳµÄ¼äµý¹¥»÷Ïà±È£¬ËüÃǵÄÐÔÃüÖÜÆÚ¼«¶È¶ÌÔÝ£¬´óÎÞÊý´ËÀ๥»÷»á³ÖÐøÊýÔÂÉõÖÁÊýÄ꣬¶øÕâЩ»î¶¯Ô¼Îª25Ìì¡£
https://securelist.com/hunt-for-corporate-credentials-on-ics-networks/105545/
McAfee½¨¸´AgentÈí¼þÖеÄÌáȨ·ì϶CVE-2022-0166
ýÌå1ÔÂ21ÈÕ±¨Â·£¬McAfee£¨ÏÖΪTrellix£©Òѽ¨¸´ÌáȨ·ì϶£¨CVE-2022-0166£©¡£¸Ã·ì϶λÓÚWindows°æ±¾µÄMcAfee AgentÈí¼þÖУ¬Èí¼þÔÚ¹¹½¨¹ý³ÌÖÐʹÓÃopenssl.cnf½«OPENSSLDIR±äÁ¿Ö¸¶¨Îª×°ÖÃĿ¼ÖеÄ×ÓĿ¼£¬µÍȨÏÞÓû§Äܹ»ÀûÓø÷ì϶´´½¨×ÓĿ¼²¢Ê¹ÓÃSystemȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£¸Ã¹«Ë¾ÓÚ1ÔÂ18ÈÕ°ä²¼ÁËMcAfee Agent 5.7.5½¨¸´´Ë·ì϶¡£
https://securityaffairs.co/wordpress/127044/security/mcafee-agent-code-execution-flaw.html
Rust½¨¸´¿Éɾ³ýÎļþºÍĿ¼µÄ·ì϶CVE-2022-21658
Rust°²È«ÏìÓ¦¹¤×÷×é(WG)ÔÚ1ÔÂ20ÈÕ°ä²¼µÄ²¼¸æÖаµÊ¾£¬Æä²úÆ·´æÔÚÒ»¸öÑϳÁµÄ·ì϶¡£·ì϶±»×·×ÙΪCVE-2022-21658£¬CVSSÆÀ·ÖΪ7.3£¬Ó°ÏìÁËRust 1.0.0µ½Rust 1.58.0°æ±¾¡£¸Ã·ì϶ԴÓڳ߶ȿ⺯Êýstd::fs::remove_dir_allÈÝÒ×Êܵ½ÆôÓ÷ûºÅÁ´½Ó¸ú×ٵľºÕùǰÌáµÄÓ°Ï죬¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶ÓÕÊ¹ÌØÈ¨·¨Ê½É¾³ýÆäÎÞ·¨½Ó¼û»òɾ³ýµÄÎļþºÍĿ¼¡£¸ÃÍŶÓÔÚÉÏÖܰ䲼µÄRust 1.58.1°æ±¾Öн¨¸´ÁË´Ë·ì϶¡£
https://thehackernews.com/2022/01/high-severity-rust-programming-bug.html
Fortinet·¢ÏÖ¼ÙÒ⺽Ô˹«Ë¾·Ö·¢STRRATµÄ´¹µö»î¶¯
FortinetÔÚ1ÔÂ20ÈÕ¹«¿ªÁËÖ¼ÔÚ·Ö·¢Ô¶³Ì½Ó¼ûľÂíSTRRATµÄ´¹µö»î¶¯¡£Õâ´Î»î¶¯¼ÙÒ⺽Ô˹«Ë¾ÂíÊ¿»ùº½Ô˹«Ë¾£¨Maersk Shipping£©£¬Ê¹ÓÃÒÔ×°ÔË¡¢½»»õÈÕÆÚ¸ü¸Ä»ò²É°ì֪ͨµÄ´¹µöÓʼþ£¬µ±Ö¸±ê´ò¿ªÓʼþÖеĸ½¼þºó¾Í»áÔËÐжñÒâºê²¢×°ÖÃSTRRAT¡£STRRATÄܹ»ÇÔȡָ±êµÄÐÅÏ¢£¬»òÕß½øÐмٵÄÀÕË÷¹¥»÷£¨ÔÚ¹¥»÷ÖÐûÓÐÎļþ±»¼ÓÃÜ£©¡£´Ë±í£¬¹¥»÷ÕßʹÓÃÁËAllatori¹¤¾ß¶ÔÈí¼þ°ü½øÐÐÁË»ìºÏ£¬ÒÔÈÆ¹ý°²È«²úÆ·µÄ¼ì²â¡£
https://www.bleepingcomputer.com/news/security/phishing-impersonates-shipping-giant-maersk-to-push-strrat-malware/
Check Point°ä²¼2021ÄêÍøÂç¹¥»÷»î¶¯µÄ»ØÊ׻㱨
1ÔÂ21ÈÕ£¬Check Point°ä²¼ÁË2021ÄêÍøÂç¹¥»÷»î¶¯µÄ»ØÊ׻㱨¡£×ÜÌå¶øÑÔ£¬Óë2020ÄêÏà±È£¬2021Äê×é֯ÿÖÜÔâÓöµÄ¹¥»÷´ÎÊýÔö³¤ÁË50%¡£Õë¶ÔTOP 16ÐÐÒµµÄ¹¥»÷¾ùÔÈÔö³¤ÁË55%£¬ÆäÖнÌÓýºÍ×êÑв¿ÃÅÊÇÊܹ¥»÷×î¶àµÄÐÐÒµ£¬¾ùÔÈÿÖÜÔâµ½1605´Î¹¥»÷£¨Ôö³¤75%£©£¬Æä´ÎΪµ±¾ÖºÍ¾ü¶Ó£¨1136´Î£¬Ôö³¤47%£©ÒÔ¼°Í¨Ñ¶ÐÐÒµ£¨1079´Î£¬Ôö³¤51%£©£»Õë¶ÔÈí¼þ¹©¸øÉ̹¥»÷´ÎÊýµÄÔö·ù×î´ó£¬Í¬±ÈÔö³¤ÁË146%¡£
https://blog.checkpoint.com/2022/01/21/2022-security-report-software-vendors-saw-146-increase-in-cyber-attacks-in-2021-marking-largest-year-on-year-growth/
Cleafy½üÆÚ·¢ÏÖAndroid¶ñÒâÈí¼þBRATAµÄбäÌå
¾ÝýÌå1ÔÂ24ÈÕ±¨Â·£¬Cleafy³ÆAndroid¶ñÒâÈí¼þBRATAÔÚÆäбäÌåÖÐÔö³¤¶à¸öÖ°ÄÜ¡£BRATAÊÇÒ»¿îÖØÒªÕë¶Ô°ÍÎ÷Óû§µÄAndroid RAT£¬ÔÚ2019Äê³õ´Î±»Kaspersky·¢ÏÖ¡£¸Ã±äÌå´Ë¿ÌÖØÒªÕë¶ÔÓ¢¹ú¡¢²¨À¼¡¢Òâ´óÀû¡¢Î÷°àÑÀ¡¢ÖйúºÍÀ¶¡ÃÀÖ޵ĵç×ÓÒøÐеÄÓû§£¬ÐÂÔöÁ˼üÅ̼ͼְÄÜ¡¢GPS ¸ú×ÙÖ°ÄÜ£¬Äܹ»Ö´Ðгö³§³ÁÖÃÒԶϸùËùÓжñÒâ»î¶¯µÄºÛ¼££¬»¹Ôö³¤ÁËÄܹ»Ö§³ÖHTTPºÍWebSocketsµÄÐÂC2ͨѶͨ·¡£
https://www.bleepingcomputer.com/news/security/android-malware-brata-wipes-your-device-after-stealing-data/
°²È«¹¤¾ß
CFRipper
»ùÓÚ Python µÄ¿âºÍ CLI °²È«·ÖÎöÆ÷£¬ÓÃ×÷ AWS CloudFormation °²È«É¨ÃèºÍÉ󼯹¤¾ß¡£
https://github.com/Skyscanner/cfripper
TokenUniverse
ʹÓýӼûÁîÅÆºÍ Windows °²È«Õ½ÊõµÄ¸ß¼¶¹¤¾ß¡£
https://github.com/diversenok/TokenUniverse
Registry Spy
Ãâ·ÑµÄ¿ªÔ´¿çƽ̨ Windows ×¢²á±í²é¿´Æ÷¡£
https://github.com/andyjsmith/Registry-Spy
SysmonSimulator
ÓÃC˵»°´´½¨µÄ¿ªÔ´ Windows ÊÂÎñ·ÂÕÕʵÓ÷¨Ê½£¬¿ÉÓÃÓÚ·ÂÕÕ´óÎÞÊýʹÓà WINAPI µÄ¹¥»÷¡£
https://github.com/ScarredMonk/SysmonSimulator
HazProne
ÔÆÉøÈë²âÊÔ¿ò¼Ü£¬ÓÃÓÚÉøÈë²âÊÔ·ì϶¡£
https://github.com/stafordtituss/HazProne
°²È«·ÖÎö
΢ÈíĬÈϽûÓÃExcel 4.0ºêÀ´×èÖ¹¶ñÒâÈí¼þ
https://www.bleepingcomputer.com/news/microsoft/microsoft-disables-excel-40-macros-by-default-to-block-malware/
SonicWall ΪÏÝÈë³ÁÆôÑ»·µÄ·À»ðǽ¹²ÏíÌṩһʱ½¨¸´
https://www.bleepingcomputer.com/news/technology/sonicwall-shares-temp-fix-for-firewalls-stuck-in-reboot-loop/
΢ÈíÁгöÁËÒªÔ¤·ÀµÄ Windows 10 ×éÕ½Êõ
https://www.bleepingcomputer.com/news/microsoft/microsoft-lists-the-windows-10-group-policies-to-avoid/
ProtonMail ÒýÈëÁËÒ»¸öеĵç×ÓÓʼþ¸ú×ÙÆ÷×èֹϵͳ
https://www.bleepingcomputer.com/news/security/protonmail-introduces-a-new-email-tracker-blocking-system/
F5 ½¨¸´ÁË BIG-IP¡¢BIG-IQ ºÍ NGINX ²úÆ·ÖÐµÄ 25 ¸öȱµã
https://securityaffairs.co/wordpress/127097/security/f5-big-ip-flaws.html


¾©¹«Íø°²±¸11010802024551ºÅ