¹È¸è½¨¸´ChromeÖпªÊͺóʹÓ÷ì϶CVE-2022-0609

°ä²¼¹¦·ò 2022-02-17

¹È¸è½¨¸´ChromeÖпªÊͺóʹÓ÷ì϶CVE-2022-0609


2ÔÂ14ÈÕ£¬¹È¸è°ä²¼´¹Î£¸üУ¬½¨¸´ChromeÖеĶà¸ö°²È«·ì϶¡£Õâ´Î½¨¸´µÄ×îÑϳÁµÄ·ì϶ÊǶ¯»­×é¼þÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2022-0609£©£¬¿É±»ÓÃÀ´Ö´ÐÐËÁÒâ´úÂë»òÔÚä¯ÀÀÆ÷µÄɳÏäÖÐÌÓÒÝ¡£¹È¸è°µÊ¾ËûÃÇÒѾ­¼ì²âµ½ÀûÓÃÕâ¸öÁãÈÕ·ì϶µÄ¹¥»÷£¬µ«¸Ã¹«Ë¾²¢Î´·ÖÏíÓйع¥»÷»î¶¯µÄÆäËüÐÅÏ¢»ò¸Ã·ì϶µÄ¼¼Êõϸ½Ú¡£´Ë±í£¬¸üл¹½¨¸´ÁËWebstore APIÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2022-0605£©ºÍMojoÖеÄÕûÊýÒç¶Âí½Å£¨CVE-2022-0608£©µÈ·ì϶¡£


https://www.bleepingcomputer.com/news/security/google-chrome-emergency-update-fixes-zero-day-exploited-in-attacks/


ÎÚ¿ËÀ¼¶à¸ö¹Ù·½×éÖ¯µÄÍøÕ¾Ôâµ½´ó¹æÄ£DDoS¹¥»÷


ÎÚ¿ËÀ¼¶à¸ö¹Ù·½×éÖ¯µÄÍøÕ¾ÔÚ2ÔÂ15ÈÕÔâµ½ÁË´ó¹æÄ£DDoS¹¥»÷¡£¸Ã¹úµÄ2¸ö¹úÓÐÒøPrivatbank£¨ÎÚ¿ËÀ¼×î´óµÄÒøÐУ©ºÍOschadbank£¨¹ú¶È´¢ÐîÒøÐУ©´Ó±¾µØ¹¦·òÏÂÎç3µã×óÓÒÆðÍ·¹Ø¹ØÁË2¸öÓ×ʱ£¬ÔÚ5¸öÓ×ʱºó¸´Ô­Õý³£ÔËÐУ¬²¢°µÊ¾¿ÉÄÜ»áÔÙ´ÎÔâµ½¹¥»÷¡£´Ë±í£¬ÎÚ¿ËÀ¼¹ú·À²¿ºÍÎä×°¶ÓÁеÄÍøÕ¾ÒÀÈ»ÎÞ·¨½Ó¼û¡£ÎÚ¿ËÀ¼¹«¹²¹ã²¥µç̨µÄ×ÜÔì×÷ÈËDmitry Khorkin°µÊ¾µç̨ҲÔâµ½Á˹¥»÷£¬µ«ÆäÍøÕ¾²¢Î´Ì±»¾¡£


https://therecord.media/ddos-attacks-hit-websites-of-ukraines-state-banks-defense-ministry-and-armed-forces/


Î÷°àÑÀ¾¯·½µ·»Ù½ðÈÚÚ¿Æ­·¸×ïÍŻﲢ¿ÛÁô8¸öÏÓÒÉÈË


¾ÝýÌå2ÔÂ14ÈÕ±¨Â·£¬Î÷°àÑÀ¹ú¶È¾¯Ô±¾Ö£¨Polic¨ªa Nacional£©ÔÚÉÏÖܵ·»ÙÁËÒ»¸ö½ðÈÚÚ¿Æ­·¸×ïÍŻ¸ÃÍÅ»ïµÄ8Ãû³ÉÔ±±»²¶£¬12¸öÒøÐÐÕË»§±»¶³½á¡£¾ÝϤ£¬¸ÃÍÅ»ïµÄµÚһ·¹¥»÷ÊÂÎñ²úÉúÔÚ2021Äê3Ô£¬ËûÃÇÖØÒª¼Ù×°³ÉÒøÐÐºÍÆäËü×éÖ¯µÄ´ú±í£¬Ê¹Óô¹µö¹¥»÷ºÍSIM»¥»»¹¥»÷»ñȡָ±êµÄÓ×ÎҺͲÆÕþÐÅÏ¢£¬²¢´ÓËûÃǵÄÕË»§ÖÐÌáÈ¡×ʽð¡£½üÄêÀ´£¬SIM»¥»»ÒÑÑݱäΪһÖÖÈÕÒæÆÕ±éµÄÍøÂç·¸×ï´ó¾Ö£¬2021Äê12Ô£¬The Community³ÉÔ±ÒòÉæÏÓÊý°ÙÍòÃÀÔªµÄSIM¿¨»¥»»¹¥»÷±»¿ÛÁô¡£


https://thehackernews.com/2022/02/spanish-police-arrest-sim-swappers-who.html


Beetle Eye´æ´¢Í°ÅäÖÃÃýÎóÔ¼700ÍòÓû§µÄÐÅϢй¶


¾Ý2ÔÂ14Èյı¨Â·£¬Website Planet·¢ÏÖÃÀ¹úÓªÏú¹«Ë¾Beetle EyeÔ¼700ÍòÓû§µÄÐÅϢй¶¡£Beetle EyeÒòAWS S3´æ´¢Í°ÅäÖÃÃýÎó¶³öÁ˳¬¹ý6000¸öÎļþ£¬×ܼƳ¬¹ý1GBÊý¾Ý¡£Õâ´Îй¶ÁËÐÕÃû¡¢µØÖ·¡¢ÓÊÕþ±àÂëºÍµç»°ºÅÂëµÈÐÅÏ¢£¬ÊÜÓ°ÏìµÄÓû§´ó¶àÀ´×ÔÓÚÃÀ¹úºÍ¼ÓÄô󡣸ô洢ͰÓÚ2021Äê9ÔÂ9ÈÕ±»·¢ÏÖ£¬2022Äê2ÔÂ14ÈÕBeetle Eye»Ø¸´³ÆÃô¸ÐÎļþÒѱ»É¾³ý¡£


https://www.hackread.com/us-marketing-firm-data-exposed-database-mess-up/


ÈðÊ¿Æû³µ¾­ÏúÉÌEmil Frey³ÆÆäÔâµ½HiveµÄÀÕË÷¹¥»÷


ýÌå2ÔÂ14ÈÕ±¨Â·£¬ÈðÊ¿Æû³µ¾­ÏúÉÌEmil FreyÔâµ½HiveÀÕË÷¹¥»÷¡£ÕâÊÇÅ·ÖÞ×î´óµÄÆû³µ¾­ÏúÉÌÖ®Ò»£¬ÔÚ2020Äê´´ÔìÁË32.9ÒÚÃÀÔªµÄÏúÊÛ¶î¡£¸Ã¹«Ë¾ÓÚ2ÔÂ1Èճʴ˿ÌHiveµÄÒѱ»¹¥»÷Ö¸±êµÄÃûµ¥ÉÏ£¬²¢ÈÏ¿ÉËûÃÇÔÚ1Ô·ÝÔâµ½¹¥»÷¡£¸Ã¹«Ë¾½²»°È˳Æ£¬ÔÚ1ÔÂ11ÈÕµÄÊÂÎñ²úÉú¼¸Ììºó£¬¹«Ë¾¾ÍÒѸ´Ô­²¢³ÁÆôÁËóÒ׻¡£HiveÔÚ2021Äê¹¥»÷ÁËÖÁÉÙ28¸öÒ½ÁÆ»ú¹¹£¬»ñµÃÁËFBIµÄ³Áµã¹Ø×¢¡£


https://www.itsecurityguru.org/2022/02/14/major-car-dealer-suffers-ransomware-attack/


FortiGuard°ä²¼½üÆÚ·Ö·¢BitRATµÄ»î¶¯µÄ·ÖÎö»ã±¨


2ÔÂ14ÈÕ£¬FortiGuard Labs°ä²¼Á˹ØÓÚ·Ö·¢BitRATµÄ»î¶¯µÄ·ÖÎö»ã±¨¡£Õâ´Î»î¶¯Ê¹ÓÃÁËÃûΪ¡°NFT_Items.xlsm¡±µÄExcelµç×Ó±í¸ñ£¬¸ÃÎļþÓÐÁ½¸ö¹¤×÷²¾£¬ÆäÖÐÒ»¸öÊÇÏ£²®À´ÓïµÄ¡£¸Ã¶ñÒâÎļþÒÔ²»³É´úÌæ´ú±Ò(NFT)ÓйØÐÅϢΪµö¶ü£¬Ô̺¬Ò»¸ö¶ñÒâºê£¬¿ÉʹÓÃPowerShell¾ç±¾´ÓDiscordÏÂÔØÁíÒ»¸öÎļþNFTEXE.exe£¬×îÖÕ½«×°ÖÃÔ¶³Ì½Ó¼ûľÂíBitRAT¡£


https://www.fortinet.com/blog/threat-research/nft-lure-used-to-distribute-bitrat


°²È«¹¤¾ß


Droopescan


Ò»ÖÖ»ùÓÚ²å¼þµÄɨÃ跨ʽ£¬¿ÉÔ®ÊÖ°²È«×êÑÐÈËÔ±¼ø±ð¶à¸ö CMS µÄÎÊÌâ¡£


https://github.com/SamJoan/droopescan


AutoTimeliner


´ÓÒ×ʧÐÔÄÚ´æ×ª´¢ÖÐ×Ô¶¯Ìáȡȡ֤¹¦·òÏß¡£


https://github.com/andreafortuna/autotimeliner


truffleHog


ͨ¹ý git ´æ´¢¿âËÑË÷ÃÜÂ룬Éî¿ÌÍÚ¾òÌá½»º¹ÇàºÍ·ÖÖ§£¬Õâ¶ÔÓÚ·¢ÏÖÒâ±íÌá½»µÄÃÜÂ뼫¶ÈÓÐЧ¡£


https://github.com/trufflesecurity/truffleHog


WarFox


»ùÓÚÈí¼þµÄ HTTPS Ðűê Windows Ö²È뷨ʽ£¬ËüʹÓöà²ã´úÀíÍøÂç½øÐÐ C2 ͨѶ¡£


https://github.com/FULLSHADE/WarFox


Melody


ΪÍþвµý±¨¶ø¹¹½¨µÄͨÃ÷»¥ÁªÍø´«¸ÐÆ÷£¬¿ÉÏóÕ÷¸ÐÐËÖµÄÊý¾Ý°üÒÔ½øÇ°½øÒ»²½·ÖÎöºÍÍþв¼à¿Ø¡£


https://bonjourmalware.github.io/melody/



°²È«·ÖÎö


QNAP ΪһЩ²»ÊÜÖ§³ÖµÄ NAS É豸À©´ó¹Ø¼ü¸üÐÂ


https://www.bleepingcomputer.com/news/security/qnap-extends-critical-updates-for-some-unsupported-nas-devices/


Kali Linux 2022.1 °ä²¼£¬Ô̺¬ 6 ¸öй¤¾ß¡¢SSH ¿í·º¼æÈݵÈ


https://www.bleepingcomputer.com/news/security/kali-linux-20221-released-with-6-new-tools-ssh-wide-compat-and-more/


FTC ÖÒ¸æ VoIP ÌṩÉÌ£º·ÖÏí robocall ÐÅÏ¢»ò±»¸æ×´


https://www.bleepingcomputer.com/news/security/ftc-warns-voip-providers-share-your-robocall-info-or-get-sued/


KlaySwap Óû§ÔÚ BGP ½Ù³ÖºóËðʧ×ʽð


https://therecord.media/klayswap-crypto-users-lose-funds-after-bgp-hijack/


ÀûÓà Ghostbuster ¹¤¾ß½â³ýµ¯ÐÔ IP ÊÕÊÜ


https://blog.assetnote.io/2022/02/13/dangling-eips/