ÃÀ¹úµ·»ÙSandwormÔËÓªµÄ½©Ê¬ÍøÂçCyclops Blink

°ä²¼¹¦·ò 2022-04-11

ÃÀ¹úµ·»ÙSandwormÔËÓªµÄ½©Ê¬ÍøÂçCyclops Blink


¾ÝýÌå4ÔÂ6ÈÕ±¨Â· £¬ÃÀ¹úÒѵ·»ÙÓɶíÂÞ˹ºÚ¿Í×éÖ¯SandwormÔËÓªµÄ½©Ê¬ÍøÂçCyclops Blink¡£Sandworm´Ó2019Äê6ÔÂÆðͷʹÓøý©Ê¬ÍøÂç £¬ÖØÒªÖ¸±êÊÇWatchGuard Firebox·À»ðǽÉ豸ºÍ»ªË¶Â·ÓÉÆ÷¡£Õâ´Î·¨ÂÉÐж¯ÓÚ2022Äê3ÔÂ18ÈÕÆðÍ· £¬Ä¿Ç°ÒÑÔÚËùÓб»Ï°È¾µÄWatchguardÉ豸ÖÐɾ³ý¸Ã¶ñÒâÈí¼þ¡£WatchGuard°ä²¼Á˹ØÓÚ¸´Ô­±»Ï°È¾FireboxÉ豸µÄ×¢Ã÷ £¬»¹¿ª·¢ÁËÒ»Ì×Cyclops Blink¼ì²â¹¤¾ß £¬ÒÔ¼°Cyclops Blink 4²½Õï¶ÏºÍ½¨¸´´òËã¡£


https://securityaffairs.co/wordpress/129911/cyber-warfare-2/us-disrupts-cyclops-blink-botnet.html


VMware°ä²¼¸üР£¬½¨¸´Æä²úÆ·ÖеĶà¸ö°²È«·ì϶


4ÔÂ6ÈÕ £¬VMware°ä²¼°²È«¸üР£¬½¨¸´ÁËVMware Workspace ONE Access¡¢VMware Identity Manager (vIDM)ºÍvRealize Lifecycle ManagerµÈ²úÆ·ÖеÄ8¸ö·ì϶¡£ÆäÖÐÔ̺¬5¸ö½ÏΪÑϳÁµÄ·ì϶ £¬±ðÀëΪ·þÎñÆ÷¶ËÄ£°å×¢ÈëÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2022-22954 £¬CVSSÆÀ·Ö9.8£©¡¢OAuth2 ACSÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2022-22955ºÍCVE-2022-22956 £¬CVSSÆÀ·Ö9.8£©ÒÔ¼°JDBC×¢ÈëÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2022-22957ºÍCVE-2022-22958 £¬CVSSÆÀ·Ö9.1£©¡£


https://www.vmware.com/security/advisories/VMSA-2022-0011.html


Cybereason·¢ÏÖAridViperÕë¶ÔÒÔÉ«Áи߼¶¹ÙÔ±µÄ¼äµý»î¶¯


Cybereason NocturnusÍŶÓÔÚ4ÔÂ6ÈÕ°ä²¼»ã±¨ £¬ÏêÊöÁËAridViper£¨ÓÖ³ÆAPT-C-23£©µÄл¡£×êÑÐÈËÔ±½«Õâ´Î¼äµý»î¶¯¶¨ÃûΪOperation Bearded Barbie £¬Ëü¶Ô×¼ÒÔÉ«Áйú·À¡¢·¨Âɺʹ¹Î£·þÎñ²¿Ãŵĸ߼¶¹ÙÔ± £¬¼à¶½Æä»î¶¯²¢ÇÔÈ¡Êý¾Ý¡£¹¥»÷ÕßÀûÓÃÐéαµÄFacebookÕ˺ÅÓÕʹָ±êÏÂÔØÄ¾Âí £¬²¢Ê¹ÓÃÁËеĶñÒâÈí¼þBarb(ie) DownloaderºÍBarbWire Backdoor £¬ÒÔ¼°VolatileVenomбäÖÖ¡£ 


https://www.cybereason.com/blog/operation-bearded-barbie-apt-c-23-campaign-targeting-israeli-officials


3¸ö¶ñÒâAndroidÀûÓöÔ×¼ÂíÀ´Î÷ÑǵĶà¸ö½ðÈÚ»ú¹¹


4ÔÂ6ÈÕ £¬ESET°ä²¼Á˹ØÓÚ3¸ö¶ñÒâAndroidÀûÓõÄ×êÑл㱨¡£¸Ã»î¶¯×Ô2021Äê11ÔÂÆðÍ· £¬¹¥»÷Õßͨ¹ý¼ÙÒâMaid4u¡¢GrabmaidºÍMaria's CleaningµÈ7¸öºÏ·¨ÍøÕ¾ £¬ÓÕʹÓû§ÏÂÔØ¶ñÒâÀûÓà £¬ÕâЩÀûÓý«Ö¸±êÊÕµ½µÄËùÓжÌÐÅת·¢µ½¹¥»÷Õß £¬ÒÔÇÔÈ¡ÒøÐз¢Ë͵Ä2FA´úÂë¡£Õâ´Î»î¶¯ÖØÒªÕë¶ÔÂíÀ´Î÷ÑǵÄ8¼ÒÒøÐУºMaybank¡¢Affin Bank¡¢Public Bank Berhad¡¢CIMB bank¡¢BSN¡¢RHB¡¢Bank Islam MalaysiaºÍHong Leong Bank¡£


https://www.welivesecurity.com/2022/04/06/fake-eshops-prowl-banking-credentials-android-malware/


NB65Ðû³ÆÒÑÇÔÈ¡¶íÂÞ˹¹ã²¥¹«Ë¾VGTRKÔ¼800GBµÄÊý¾Ý


ýÌå4ÔÂ6ÈÕ±¨Â· £¬NB65(Network Battalion 65)Ðû³ÆÒÑÈëÇÖ¶íÂÞ˹µçÊӹ㲥¹«Ë¾VGTRK¡£NB65ÓëAnonymouÓйØÁª £¬VGTRKÊǶíÂÞ˹×î´óµÄýÌ幫˾ £¬ÔËÓª×Å5¸ö¹ú¶Èµç̨¡¢2¸ö¹ú¼ÊÍøÂç¡¢5¸ö¹ã²¥µç̨ºÍ80¶à¸öµØÓòµçÊÓºÍ¹ã²¥ÍøÂç¡£NB65ͨ¹ýDDoSecrets¹«¿ªÁËVGTRK 786.2 GBµÄÊý¾Ý £¬ÆäÖÐÔ̺¬4000¸öÎļþºÍ³¬¹ý900000·âµç×ÓÓʼþ¡£Anonymous»¹ÔÚ3ÔÂ26ÈÕй¶Á˶íÂÞ˹ÖÐÑëÒøÐÐ28GBµÄÊý¾Ý¡£


https://www.hackread.com/anonymous-affiliate-nb65-russia-broadcaster-data-breach/


Google PlayÖÐÀûÓÃSDKÍøÂçÐÅÏ¢µÄÀûÓÃÒÑ×°ÖÃ4500Íò´Î


¾Ý4ÔÂ7ÈÕ±¨Â· £¬AppCensus·¢ÏÖGoogle PlayÖеĶà¸öÀûÓÃͨ¹ýµÚÈý·½SDKÍøÂçÓû§Êý¾Ý¡£ÕâЩÀûÓÃÒÑ×°Öó¬¹ý4500Íò´Î £¬Ô̺¬Speed Camera RadarºÍAl-Moazin LiteµÈ £¬ÖØÒªÇÔÈ¡¼ôÌù°åÄÚÈÝ¡¢GPSÊý¾Ý¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë £¬ÒÔ¼°µ÷Ôì½âµ÷Æ÷·ÓÉÆ÷MACµØÖ·ºÍÍøÂçSSID¡£ÍøÂçµ½µÄÊý¾ÝÓÉSDK´«Êäµ½¡°mobile.measurelib.com¡± £¬¸ÃÓòÊôÓÚÒ»¼ÒÃûΪMeasurement SystemsµÄ°ÍÄÃÂí·ÖÎö¹«Ë¾ËùÓС£


https://www.bleepingcomputer.com/news/security/android-apps-with-45-million-installs-used-data-harvesting-sdk/




°²È«¹¤¾ß


Rip Raw


ÊÇÒ»¸öÓÃÓÚ·ÖÎöÊÜϰȾ Linux ϵͳÄÚ´æµÄÓ×¹¤¾ß¡£


https://github.com/cado-security/rip_raw


Grafiki


¹ØÓÚ Sysmon ºÍͼ±íµÄÍþв׷×Ù¹¤¾ß¡£


https://github.com/lucky-luk3/Grafiki/


Odin


Odin ÊÇ»ùÓÚLokiµÄÖÐÑë IoC ɨÃèÆ÷


https://github.com/Hamza-Megahed/odin




°²È«·ÖÎö


Windows 11 ÄÚ²¿°æ±¾ 22593 ÖеÄÒÑÖªÎÊÌâ


https://news.softpedia.com/news/known-issues-in-windows-11-build-22593-535182.shtml


Mozilla Firefox 99 ÏÖÒѿɹ©ÏÂÔØ


https://news.softpedia.com/news/mozilla-firefox-99-is-now-available-for-download-535180.shtml


΢Èí£º¶à¸ö .NET Framework °æ±¾½«ÓÚ 4 Ô EOL


https://www.bleepingcomputer.com/news/microsoft/microsoft-multiple-net-framework-versions-reach-end-of-life-in-april/


AMDÈ·ÈÏGPUÇý¶¯·¨Ê½ÃýÎóδ¾­Ðí¿É³¬ÆµCPU


https://www.bleepingcomputer.com/news/hardware/amd-confirms-gpu-driver-bug-overclocks-cpus-without-permission/


Atlassian Jira £¬Confluence ÖжÏÓ°ÏìÈ«ÇòÓû§


https://www.bleepingcomputer.com/news/technology/ongoing-atlassian-jira-confluence-outage-affects-customers-worldwide/


Palo Alto Networks ·À»ðǽ¡¢VPN ´æÔÚ OpenSSL ·ì϶


https://www.bleepingcomputer.com/news/security/palo-alto-networks-firewalls-vpns-vulnerable-to-openssl-bug/


FFDroiderÖ¼ÔÚÇÔÈ¡É罻ýÌåÖеÄÐÅÏ¢


https://www.zscaler.com/blogs/security-research/ffdroider-stealer-targeting-social-media-platform-users