Microsoft DefenderÎ󱨣¬½«Chrome¸üÐÂÏóÕ÷Ϊ¿ÉÒÉ

°ä²¼¹¦·ò 2022-04-22

1¡¢Microsoft DefenderÎ󱨣¬½«Chrome¸üÐÂÏóÕ÷Ϊ¿ÉÒÉ


¾ÝýÌå4ÔÂ20ÈÕ±¨Â·£¬Microsoft Defender½«Í¨¹ýGoogle UpdateÌá½»µÄChrome¸üÐÂÏóÕ÷Ϊ¿ÉÒɻ¡£Óû§»ã±¨£¬ÆäÊÕµ½µÄ¾¯±¨³Æ¡°Éæ¼°Ö´ÐкͷÀÓùÈÆ¹ýµÄ¶à½×¶ÎÊÂÎñ¡±¡£MicrosoftÔÚ·þÎñ²¼¸æÖÐй©£¬ÕâÊÇÎó±¨ÎÊÌ⣬¶ø·Ç´æÔÚ¶ñÒâ»î¶¯¡£Ô¼ÄªÒ»¸ö°ëÓ×ʱºó£¬Îó±¨ÎÊÌâµÃµ½½â¾ö£¬·þÎñÒ²ÒѸ´Ô­¡£ÔÚ´ÓǰÁ½ÄêÖУ¬Defender²úÉú¹ýÂÅ´ÎÎó±¨ÎÊÌ⣬ÀýÈçOOffice¸üÐÂÔø±»¼ì²âΪÀÕË÷Èí¼þ»î¶¯¡£


https://www.bleepingcomputer.com/news/security/microsoft-defender-flags-google-chrome-updates-as-suspicious/


2¡¢¸ßͨºÍÁª·¢¿ÆÐ¾Æ¬ÖеĶà¸ö·ì϶ӰÏìÊý°ÙÍòAndroidÊÖ»ú


Check Point ResearchÔÚ4ÔÂ21ÈÕÅû¶Á˸ßͨºÍÁª·¢¿ÆÐ¾Æ¬µÄÒôƵ½âÂëÆ÷ÖеÄ3¸ö·ì϶¡£Apple Lossless Audio Codec(ALAC)ÊÇÓÃÓÚÎÞËðÒôƵѹËõµÄÒôƵ±àÂëÌåʽ£¬AppleÓÚ2011Ä꽫Æä¿ªÔ´£¬ÕâÁ½¼ÒоƬ¹«Ë¾ÔÚÆäÒôƵ½âÂëÆ÷ÖÐʹÓÃÁË´æÔÚ·ì϶µÄALAC´úÂë¡£·ì϶±ðÀëΪÊäÈëÑéÖ¤²»µ±µ¼ÖÂÐÅϢй¶·ì϶£¨CVE-2021-0674£©¡¢Ô½½çдÈëµ¼ÖµÄÌáȨ·ì϶£¨CVE-2021-0675£©ºÍÄÚ´æ½Ó¼û·ì϶£¨CVE-2021-30351£©£¬¿É±»¹¥»÷ÕßÓÃÀ´Ô¶³Ì½Ó¼ûÉ豸µÄýÌåºÍÒôƵ¶Ô»°¡£Ä¿Ç°£¬·ì϶¾ùÒѱ»½¨¸´¡£


https://blog.checkpoint.com/2022/04/21/largest-mobile-chipset-manufacturers-used-vulnerable-audio-decoder-2-3-of-android-users-privacy-around-the-world-were-at-risk/


3¡¢¼ÓÄô󺽿չ«Ë¾SunwingÔâµ½ÍøÂç¹¥»÷µ¼Öº½°àÑÓÎó


¾Ý4ÔÂ20ÈÕ±¨Â·£¬¼ÓÄô󺽿չ«Ë¾Sunwing Airlines IncÔâµ½ÍøÂç¹¥»÷¡£´ÓÉÏÖÜÈÕÏÂÎçÆðÍ·£¬¸Ã¹«Ë¾ÓÉÓÚ¼¼ÊõÎÊÌâµ¼Öº½°àÑÓÎ󡣸ù«Ë¾µÄCEO Mark Williamsй©£¬ÆäÓÃÓÚ½â¾öÊÖÐøºÍµÇ»úµÄϵͳÔâµ½¹¥»÷¡£±¾Öܶþ£¬¸Ãº½¿Õ¹«Ë¾ÔÚTwitterÉϰµÊ¾£¬ËûÃÇÔÚÊÖ¶¯ÎªËùÓк½°à½â¾öµÇ»úÊÖÐø¡£Sunwing Airlines°µÊ¾£¬Ô¤¼ÆÑÓÎóÎÊÌâÒÀÈ»»á³ÖÐø£¬Ä¿Ç°Éв»Ã÷ÏÔºÎʱ»á¸´Ô­Õý³£ÔËÓª¡£


https://www.infosecurity-magazine.com/news/cyberattackers-hit-sunwing-airlines/


4¡¢FBI´¹Î£¹«¸æ³ÆBlackCatÒÑÈëÇÖÈ«Çò³¬¹ý60¸ö×éÖ¯


ýÌå4ÔÂ21Èճƣ¬FBIºÍCISA½áºÏ°ä²¼ÁËTLP:WHITE´¹Î£¹«¸æ¡£¹«¸æÖ¸³ö£¬Black Cat£¨Ò²³ÆALPHV£©ÔÚ2021Äê11ÔÂÖÁ2022Äê3ÔÂÆÚ¼äÈëÇÖÁËÈ«Çò³¬¹ý60¸ö×éÖ¯¡£FBIÇ¿µ÷ÁËÆäÔÚµ÷²éÆÚ¼ä·¢ÏÖµÄÀÕË÷Èí¼þ±äÖÖËùʹÓõÄÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½(TTP)ÒÔ¼°ÓëÆäÓйصÄIOC¡£FBI °µÊ¾£¬ÕâÊǵÚÒ»¸ö³É¹¦Ê¹ÓÃRUSTµÄÀÕË÷ÍŻËüµÄºÜ¶àÍŻﶼÓëDarkside/BlackmatterÓйØÁª£¬ÕâÅú×¢ËûÃÇÕ¼ÓÐ¿í·ºµÄÍøÂçºÍÀÕË÷Èí¼þÔËÓª¾­Ñé¡£¸Ã»ú¹¹»¹³Æ£¬²»½¨Òé±»¹¥»÷µÄ×éÖ¯ÏòBlackCatÖ§¸¶Êê½ð¡£


https://www.bleepingcomputer.com/news/security/fbi-blackcat-ransomware-breached-at-least-60-entities-worldwide/


5¡¢Google°ä²¼¹ØÓÚ2021ÄêÔÚÒ°ÀûÓÃ0-dayµÄ»ØÊ׻㱨


4ÔÂ19ÈÕ£¬Google Project Zero°ä²¼Á˹ØÓÚ2021ÄêÔÚÒ°ÀûÓÃ0-dayµÄ»ØÊ׻㱨¡£Google½«2021Äê³ÆÎª¡°ÔÚÒ°ÀûÓÃ0-day´´¼Í¼µÄÒ»Äꡱ£¬ÓÉÓÚÆäÔÚÕâÒ»ÄêÖмì²â²¢Åû¶ÁË58¸ö·ì϶£¬¶ø2020Äê½ö¼ì²âµ½25¸ö¡£ÕâЩ·ì϶ÖÐ×î¶àµÄ´æÔÚÓÚChromiumƽ̨(14¸ö)£¬Æä´ÎÊÇWindows(10¸ö)ºÍAndroid(7¸ö)£»39¸öÊÇÄÚ´æ°Ü»µ·ì϶£¬ÖØÒªÊÇÓÉ¿ªÊͺóʹÓÃ(17¸ö)¡¢Ô½½ç¶Áд(6¸ö)¡¢»º³åÇøÒç³ö(4¸ö)ºÍÕûÊýÒç³ö(4¸ö£©µ¼Ö¡£


https://googleprojectzero.blogspot.com/2022/04/the-more-you-know-more-you-know-you.html


6¡¢Symantec°ä²¼Shuckworm½üÆÚ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨


4ÔÂ20ÈÕ£¬Symantec°ä²¼ÁËShuckworm(ÓÖ³ÆGamaredon£©½üÆÚ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¸ÃÍÅ»ï×Ô2014Äê³õ´Î³öÏÖÒÔÀ´£¬ÒѶÔÎÚ¿ËÀ¼µÄ1500¸ö×éÖ¯½øÐÐÁ˳¬¹ý5000´Î¹¥»÷¡£½üÆÚµÄ¹¥»÷ʹÓÃÁË4ÖÖ·ÖÆçµÄPterodo±äÌ壬ÿ¸ö¶¼Óë·ÖÆçµÄC2·þÎñÆ÷µØÖ·½øÐÐͨѶ¡£ÔÚÕâЩ±äÌåÖУ¬¹¥»÷Õß¶¼Ê¹ÓÃÁËÍÌ͵ÄVBS droppers£¬Ôö³¤´òË㹤×÷£¬¶øºó´ÓC2»ñÈ¡ÆäËûÄ£¿é¡£´Ë±í£¬Shuckworm»¹Ê¹ÓÃÁËÔ¶³Ì½Ó¼û¹¤¾ßUltraVNC £¬ÒÔ¼°ÓÃÓÚ´¦ÖÃDLLÄ£¿é¹ý³ÌµÄMicrosoft Process Explorer¡£


https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/shuckworm-intense-campaign-ukraine