CleafyÔÚGoogle Play·¢ÏÖ¼Ù×°³É¶þάÂëÀûÓõÄTeaBot
°ä²¼¹¦·ò 2022-03-04CleafyÔÚGoogle Play·¢ÏÖ¼Ù×°³É¶þάÂëÀûÓõÄTeaBot
3ÔÂ1ÈÕ£¬Cleafy°ä²¼»ã±¨³ÆÆäÔÚGoogle PlayÉ̵êÖз¢ÏÖÁËÒøÐÐľÂíTeaBot¡£¸ÃľÂí¼Ù×°³É¶þάÂëÀûÓá°QR Code & Barcode ¨C Scanner¡±£¬Òѱ»ÏÂÔØ³¬¹ý10000´Î¡£Óë֮ǰ·ÖÆçµÄÊÇ£¬¸Ã±äÌåÕë¶ÔµÄÖ¸±êÀûÓÃÖÖÀàÔö³¤£¬ÏÖÒÑϯ¾íÁ˼ÒÍ¥ÒøÐÐÀûÓᢱ£ÏÕÀûÓúͼÓÃÜÇ®°üµÅצÓá£ÔÚ²»µ½Ò»ÄêµÄ¹¦·òÀTeaBotÕë¶ÔÖ¸±êµÄÊýÁ¿Ôö³¤ÁË500%ÒÔÉÏ£¬´Ó60¸öÔö³¤µ½400¶à¸ö¡£Ä¿Ç°£¬TeaBotÖØÒªÃÀ¹úÓû§£¬½üÆÚ»¹ÐÂÔöÁ˶íÓ˹Âå·¥¿ËÓïºÍÖÐÎİ汾£¬ÕâÅú×¢¸Ã¶ñÒâÈí¼þÔÚ¶Ô׼ȫÇò¡£
https://www.bleepingcomputer.com/news/security/teabot-malware-slips-back-into-google-play-store-to-target-us-users/
CloudSEK³ÆÕë¶ÔÓ¡¶ÈµÄ´¹µö¹¥»÷ÒÑÔì³ÉÉϰÙÍòÃÀÔªËðʧ
ÐÂ¼ÓÆÂ°²È«¹«Ë¾CloudSEKÔÚ3ÔÂ1ÈÕÅû¶ÁËÕë¶ÔÓ¡¶ÈµÄ´¹µö¹¥»÷µÄϸ½ÚÐÅÏ¢¡£Õâ´Î¹¥»÷»î¶¯Éæ¼°200¶à¸ö´¹µöÍøÕ¾£¬ÒԵ綯Æû³µÎªµö¶ü£¬ÒÑÔì³É¸ß´ï1000000ÃÀÔªµÄËðʧ¡£Ó¡¶Èµ±¾Ö×î½üÍÆ³öÁËÐÂÕþ²ß£¬ÒÔÍÆ½ø¸Ã¹úµç¶¯Æû³µ£¨EV£©ÐÐÒµµÄÔö³¤¡£¹¥»÷Õßͨ¹ýÀûÓÃGoogle Ads¡¢Ê¹ÓÃÓйعؼü×ÖÒÔ¼°·ÂÕÕRevoltºÍAtherµÈÆ·ÅÆÀ´ÓÕʹָ±ê½øÈë´¹µöÍøÕ¾£¬¶øºóÒªÇóËûÃÇÊäÈëÓ×ÎÒºÍÒøÐп¨ÐÅÏ¢£¬×îÖÕÇÔȡָ±êµÄÕË»§×ʽð¡£
https://cloudsek.com/whitepapers_reports/unearthing-the-million-dollar-scams-targeting-the-indian-electric-vehicle-industry-scams/
Malwarebytes·¢ÏÖÖ¼ÔÚÇÔȡ΢ÈíÓû§Í´´¦µÄ´¹µö»î¶¯
3ÔÂ1ÈÕ£¬Malwarebytes°ä²¼Ò»·Ý»ã±¨£¬ÏêÊöÁËÕë¶ÔMicrosoftÕÊ»§µÄ´¹µö»î¶¯¡£¸Ã»î¶¯ÒÔ¡°MicrosoftÕÊ»§Òì³£µÇ¼»î¶¯¡±ÎªÖ÷Ì⣬Ðû³Æ¼ì²âµ½À´×Ô¶íÂÞ˹/Ī˹¿ÆµÄÓû§¸Õ¸Õ´ÓÐÂÉ豸µÇ¼ÕÊ»§¡£µ±ÊÕ¼þÈ˵ã»÷´¹µöÓʼþÖеġ°»ã±¨Óû§¡±ºó£¬±ã»áÏò¹¥»÷Õß·¢ËÍÒ»·âÔ̺¬Ô¤Ìî³äÐÂÎŵÄÓʼþ£¬Ö®ºó¿ÉÄܻᱻҪÇóÊäÈëµÇ¼ƾ֤ºÍÒøÐÐÐÅÏ¢µÈ¡£
https://blog.malwarebytes.com/scams/2022/03/unusual-sign-in-activity-mail-goes-phishing-for-microsoft-account-holders/
JFrog°ä²¼¹ØÓÚ¿ªÔ´¿âPJSIPÖÐ5¸öÄÚ´æ°Ü»µ·ì϶µÄ»ã±¨
JFrogÔÚ3ÔÂ1ÈÕ°ä²¼Á˹ØÓÚPJSIPÖÐ5¸öÄÚ´æ°Ü»µ·ì϶µÄ»ã±¨¡£PJSIPÊÇÒ»¸ö¿ªÔ´¶àýÌåͨѶ¿â£¬ÌṩÁËIPµç»°ÀûÓÃʹÓõÄAPI¡£·ì϶Ô̺¬¿Éµ¼ÖµĴúÂëÖ´ÐеIJֿâÒç¶Âí½Å£¨CVE-2021-43299¡¢CVE-2021-43300ºÍCVE-2021-43301£©£¬ÒÔ¼°¿Éµ¼Ö»ؾø·þÎñµÄÔ½½ç¶ÁÈ¡·ì϶£¨CVE-2021-43302£©»ººÍ³åÇøÒç¶Âí½Å£¨CVE-2021-43303£©¡£ÕâЩ·ì϶ÒÑͨ¹ý2ÔÂ24ÈÕ°ä²¼µÄ²¹¶¡½¨¸´¡£
https://jfrog.com/blog/jfrog-discloses-5-memory-corruption-vulnerabilities-in-pjsip-a-popular-multimedia-library/
Google°ä²¼°²È«¸üУ¬½¨¸´ChromeÖеÄ28¸ö·ì϶
GoogleÓÚ3ÔÂ1ÈÕÍÆ³öChrome 99£¬½¨¸´ÁË28¸ö°²È«·ì϶¡£ÆäÖнÏΪÑϳÁµÄ·ì϶ÊÇANGLEÖеĶѻº³åÇøÒç¶Âí½Å£¨CVE-2022-0789£©¡¢Cast UIÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2022-0790£©¡¢¶àÖ°ÄÜ¿òÖпªÊͺóʹÓ÷ì϶£¨CVE-2022-0791£©¡¢Blink²¼¾ÖÖеÄÀàÐÍ»ìºÏ·ì϶£¨CVE-2022-0795£©ºÍANGLEÖÐÔ½½ç¶ÁÈ¡·ì϶£¨CVE-2022-0792£©µÈ¡£
https://www.cisa.gov/uscert/ncas/current-activity/2022/03/02/google-releases-security-updates-chrome
ESET°ä²¼IsaacWiperºÍHermeticWizardµÄ·ÖÎö»ã±¨
ESETÔÚ3ÔÂ1ÈÕ°ä²¼ÁËIsaacWiperºÍHermeticWizardµÄ·ÖÎö»ã±¨¡£IsaacWipeÊÇÒ»¸öеÄWiper£¬´æÔÚÓÚûÓÐAuthenticodeÊðÃûµÄWindows DLL»òEXEÖУ¬×îÔçµÄPE±àÒ빦·ò´ÁÊÇ2021Äê10ÔÂ19¡£ÓÚ2ÔÂ24ÈÕÔÚÎÚ¿ËÀ¼µ±¾Ö»ú¹¹µÄÍøÂçÖб»·¢ÏÖ£¬ÉÐδȷ¶¨ÊÇ·ñÓëHermeticWiperÓйØÁª¡£HermeticWizardÊÇ×Ô½ç˵È䳿£¬ÓÃÓÚͨ¹ýWMIºÍSMBÔÚ±¾µØÍøÂçÖд«²¼HermeticWiper¡£
https://www.welivesecurity.com/2022/03/01/isaacwiper-hermeticwizard-wiper-worm-targeting-ukraine/
°²È«¹¤¾ß
Searpy
ËÑË÷¹¤¾ß£¬¿ÉÓÃÓڲɼ¯ºÍËÝÔ´£¬Ö§³Öpy2ºÍpy3¡£
https://github.com/j3ers3/Searpy
CAPEv2
ÊÇÒ»¸ö¶ñÒâÈí¼þɳÏ䣬´ÓËÁÒâ¶ñÒâÈí¼þ¼Ò×åÖÐÌáÈ¡ÅäÖûò½âѹpayload¡£
https://github.com/kevoreilly/CAPEv2
S1EM
S1EM ÊÇÒ»¸ö´øÓÐ SIRP ºÍ Threat Intel µÄ SIEM£¬Ò»¸öÆëÈ«µÄÊý¾Ý°ü²¶»ñ£¬¶àºÏÒ»¡£
https://github.com/V1D1AN/S1EM
WMEye
ΪʹÓà WMI ºÍÔ¶³Ì MSBuild Ö´ÐÐÖ´ÐкáÏòÒÆ¶¯¶ø¿ª·¢µÄ³¢ÊÔÐÔ¹¤¾ß¡£
https://github.com/pwn1sher/WMEye
°²È«·ÖÎö
Æ»¹û°ä²¼ iOS 15.4 Beta 5
https://news.softpedia.com/news/apple-releases-ios-15-4-beta-5-534963.shtml
΢ÈíΪÖÐÓׯóÒµÍÆ³öеĶ˵㰲ȫ½â¾ö¹æ»®
https://www.bleepingcomputer.com/news/microsoft/microsoft-rolling-out-new-endpoint-security-solution-for-smbs/
ASEC·¢ÏÖ¼Ù×°³ÉMSIµÄMagniber·Ö·¢»î¶¯
https://asec.ahnlab.com/en/32226/
΢Èí£ºLSASS±ÀÀ£µ¼ÖÂWindowsÓò½ÚÔìÆ÷³ÁÆô
https://www.bleepingcomputer.com/news/microsoft/microsoft-windows-domain-controller-restarts-caused-by-lsass-crashes/
Reality Winner µÄ Twitter ÕË»§±»ºÚ¿Í¹¥»÷ÒÔÕë¶Ô¼ÇÕß
https://www.bleepingcomputer.com/news/security/reality-winners-twitter-account-was-hacked-to-target-journalists/
VoIPmonitor ¼à¿ØÈí¼þÖз¢ÏÖµÄÑϳÁ°²È«·ì϶
https://thehackernews.com/2022/03/critical-security-bugs-uncovered-in.html


¾©¹«Íø°²±¸11010802024551ºÅ