10¸ö×î³£¼ûµÄAndroidÒøÐÐľÂíµÄÏÂÔØÁ¿³¬¹ý10ÒÚ´Î
°ä²¼¹¦·ò 2022-06-08¾ÝýÌå6ÔÂ6ÈÕ±¨Â·£¬Zimperium·ÖÎöÁË2022ÄêÉϰëÄêµÄAndroidÍþв£¬·¢ÏÖÁË10¸ö×î¶à²úµÄAndroidÒøÐÐľÂíµÄÀÛ¼ÆÏÂÔØÁ¿³¬¹ý10.1ÒڴΡ£ÕâЩľÂíÕë¶ÔGoogle Play storeÖеÄ639¿î½ðÈÚÀûÓ÷¨Ê½£¬ÆäÖдó²¿ÃÅÊôÓÚÃÀ¹ú£¨121¸ö£©£¬Æä´ÎÊÇÓ¢¹ú£¨55¸ö£©ºÍÒâ´óÀû£¨43¸ö£©¡£½öTeaBot¾ÍÕë¶Ô410¸öÀûÓã¬ÆäËüľÂí»¹Ô̺¬Octo(Exobot)¡¢BianLian¡¢Coper¡¢EventBot¡¢FluBot(Cabassous)¡¢Medusa¡¢SharkBotºÍXenomorph¡£
https://thehackernews.com/2022/06/10-most-prolific-banking-trojans.html
2¡¢ÃÀ¹úÒ½ÁÆ·þÎñÌṩÉÌShieldsÔ¼200Íò»¼ÕßµÄÐÅϢй¶
ýÌå6ÔÂ7Èճƣ¬Shields Health Care Group(Shields)Ôâµ½ÍøÂç¹¥»÷£¬Ð¹Â¶ÁËÔ¼200Íò¸ö»¼ÕßµÄÐÅÏ¢¡£ShieldsÊÇÂíÈøÖîÈûÖݵÄÒ½ÁÆ·þÎñÌṩÉÌ£¬×¨ÃÅ´ÓÊÂMRIºÍPET/CTÕï¶Ï³ÉÏñ¡¢·ÅÉäÖ×ÁöѧºÍÃÅÕïÊÖÊõ·þÎñ¡£¸Ã¹«Ë¾ÔÚ½ñÄê3ÔÂ28ÈÕ·¢ÏÖÁ˹¥»÷£¬¾¹ý¶ÔÈÕÖ¾ÎļþµÄ²é³£¬È·¶¨¹¥»÷ÕßÔÚ3ÔÂ7ÈÕÖÁ3ÔÂ21ÈÕÆÚ¼äÄܹ»½Ó¼ûShieldsµÄϵͳ¡£Õâ´ÎÊÂÎñ¿ÉÄÜй¶ÁË»¼ÕßÐÕÃû¡¢Éç»á°²È«ºÅÂë¡¢Õï¶Ï¡¢Õ˵¥ÐÅÏ¢¡¢±£ÏÕÐÅÏ¢ºÍÒ½ÖÎÐÅÏ¢µÈ¡£
https://www.bleepingcomputer.com/news/security/shields-health-care-group-data-breach-affects-2-million-patients/
3¡¢×êÑÐÍŶӽüÆÚ·¢ÏÖÕë¶ÔÅ·ÃÀÈ·µ±¾Ö»ú¹¹µÄ´¹µö»î¶¯
6ÔÂ6ÈÕ£¬Proofpointй©ŷÃÀ¶à¸öµ±¾Ö»ú¹¹Ôâµ½ÁË´¹µö¹¥»÷¡£Õâ´Î»î¶¯Ê¹ÓÃÁ˶ñÒâµÄ¸»Îı¾Ìåʽ(RTF)Îĵµ£¬ÒÔ¼Óн³ÐŵÓÕʹԱ¹¤´ò¿ªµö¶üÎļþ£¬¶øºó½«×°ÖÃÒ»¸öPowershell¾ç±¾×÷Ϊ×îÖÕpayload¡£´Ë±í£¬¹¥»÷ÕßÀûÓõݲȫ·ì϶׷×ÙΪCVE-2022-30190£¬ÊÇMicrosoft WindowsÖ§³ÖÕï¶Ï¹¤¾ß(MSDT)Ô¶³Ì´úÂëÖ´Ðзì϶£¨Follina£©¡£×êÑÐÈËÔ±°µÊ¾£¬Æ¾¾Ý¶ÔPowershellµÄ·ÖÎö£¬ÒÉ»óÕⳡÐж¯ÊÇÓë¹ú¶È½áÃ˵Ĺ¥»÷ÕßËùΪ£¬µ«Ä¿Ç°Ã»Óн«Æä¹éÒòÓÚÈκÎÍŻ
https://www.bleepingcomputer.com/news/security/windows-zero-day-exploited-in-us-local-govt-phishing-attacks/
4¡¢Òâ´óÀû°ÍÀÕĪÊÐÔâµ½¹¥»÷Ó°ÏìËùÓе±¾ÖÍøÕ¾ºÍ¹«¹²·þÎñ
¾Ý6ÔÂ6ÈÕ±¨Â·£¬Òâ´óÀûÄϲ¿µÄ°ÍÀÕĪÊÐÔÚÉÏÖÜÎåÔâµ½ÍøÂç¹¥»÷£¬Óйز¿ÃÅÔÚ´ÓǰµÄÈýÌìÄÚÒ»ÏòÔÚ³¢ÊÔ¸´Ôϵͳ£¬µ«ËùÓзþÎñ¡¢¹«¹²ÍøÕ¾ºÍÔÚÏßÃÅ»§ÈÔ´¦ÓÚÀëÏß״̬¡£°ÍÀÕĪÊÇÒâ´óÀûÈ˶¡µÚÎå´ó³ÇÊУ¬¸ÃµØÓòÿÄ껹ÓÐ230ÍòÓο͵½·Ã£¬Õâ´ÎÊÂÎñ¶ÔÆäÔËÓªºÍ·þÎñÔì³ÉÁ˾޴óÓ°Ïì¡£¾Ý±¾µØÃ½Ì屨·£¬ÊÜÓ°ÏìµÄϵͳÔ̺¬¹«¹²ÊÓÆµ¼à¿ØÖÎÀí¡¢Êо¯Ô±Ðж¯ÖÐÐÄÒÔ¼°Êе±¾ÖµÄËùÓзþÎñ¡£Ö»¹ÜºÜ¿ìÓÐÈ˽«·æÃ¢Ö¸ÏòKillnet£¬ÓÉÓÚÒâ´óÀû×î½üÊÕµ½Á˸ÃÍÅ»ïµÄÍþв£¬µ«¶Ô°ÍÀÕεÄÔâµ½µÄ¹¥»÷´øÓÐÀÕË÷¹¥»÷µÄ¼£Ï󣬶ø·ÇDDoS¹¥»÷¡£
https://www.bleepingcomputer.com/news/security/italian-city-of-palermo-shuts-down-all-systems-to-fend-off-cyberattack/
5¡¢CheckpointÅû¶ĦÍÐÂÞÀÓõÄUnisocоƬÖзì϶µÄÏêÇé
CheckpointÔÚ6ÔÂ2ÈÕ°ä²¼»ã±¨£¬Åû¶ÁËΪĦÍÐÂÞÀMoto G20¡¢E30ºÍE40ÖÇÄÜÊÖ»úÌṩ¶¯Á¦µÄUnisoc Tiger T700оƬÖеÄÒ»¸öÑϳÁµÄ·ì϶¡£ÔÚÕâÏî×êÑÐÖУ¬CPR¶ÔUnisoc»ù´ø½øÐÐÁ˼±¾ç·ÖÎö£¬ÒÔѰÕÒÄܹ»Ô¶³Ì¹¥»÷UnisocÉ豸µÄ²½Öè¡£×êÑÐÈËÔ±ÔÚ¶ÔLTEºÍ̸ջ½øÐÐÄæÏò¹¤³Ìʱ£¬·¢ÏÖÁËÒ»¸ö¿ÉÓÃÓڻؾøµ÷Ôì½âµ÷Æ÷·þÎñºÍ×èֹͨѶµÄ·ì϶¡£¸Ã·ì϶CVSSÆÀ·ÖΪ9.4£¬UnisocÒÑÓÚ½ñÄê5ÔÂ¶ÔÆä½øÐн¨¸´¡£´Ë±í£¬GoogleҲȷÈÏËûÃǽ«ÔÚ¼´½«°ä²¼µÄAndroid¸üÐÂÖа䲼²¹¶¡¡£
https://www.infosecurity-magazine.com/news/vulnerability-in-motorolas-unisoc/
6¡¢NCC Group°ä²¼Black BastaÓйØTTPµÄ·ÖÎö»ã±¨
6ÔÂ6ÈÕ£¬NCC GroupµÄ»ã±¨½ÒʾÁËÀÕË÷Èí¼þBlack BastaʹÓõÄһЩTTP¡£Black BastÓÚ½ñÄê4Ô³õ´Î¹«¿ª£¬Ëü´Ë¿ÌÓëQBot³ÉÁ¢ÁËеĺÏ×÷¹ØÏµ£¬Í¨¹ý±»ÈëÇÖµÄÍøÂç½øÐкáÏò´«²¼¡£»ã±¨Ö¸³ö£¬QbotÊǹ¥»÷ÕßÓÃÀ´Î¬³ÔìäÔÚÍøÂçÉϵĴæÔÚµÄÖØÒª²½Ö裬¹¥»÷¹ý³Ì»¹Ê¹ÓÃÁËCobalt Strike beacons£¬²¢ÇÒ»á½ûÓÃWindows DefenderÀ´Èƹý°²È«¼ì²â¡£Áí±í£¬QakbotÄܹ»¼±¾ç½øÈë±»¹¥»÷µÄÍøÂ磬µ«ÀÕË÷Èí¼þµÄpayload²»»áµ±¼´±»ÏÂÔØ£¬Òò¶øÔÚ¿àÄѵ½À´Ö®Ç°£¬·ÀÓùÕßÈÎÈ»ÓлúÓö¡£
https://research.nccgroup.com/2022/06/06/shining-the-light-on-black-basta/


¾©¹«Íø°²±¸11010802024551ºÅ