΢Èí°ä²¼7Ô·ݰ²È«¸üУ¬×ܼƽ¨¸´84¸ö°²È«·ì϶
°ä²¼¹¦·ò 2022-07-13
7ÔÂ12ÈÕ£¬Î¢Èí°ä²¼7Ô·ݵÄÖܶþ²¹¶¡£¬½¨¸´ÁËÔ̺¬Ò»¸öÒѱ»ÀûÓõÄ0 dayÔÚÄÚµÄ84¸ö·ì϶¡£Õâ´Î½¨¸´ÁË52¸öÌáȨ·ì϶¡¢4¸ö°²È«Ö°ÄÜÈÆ¹ý·ì϶¡¢12¸öÔ¶³Ì´úÂëÖ´Ðзì϶¡¢11¸öÐÅϢй¶·ì϶ºÍ5¸ö»Ø¾ø·þÎñ·ì϶¡£ÆäÖУ¬Òѱ»ÔÚÒ°ÀûÓõķì϶ÊÇWindows CSRSSȨÏÞÌáÉý·ì϶£¨CVE-2022-22047£©£¬Î¢ÈíÚ¹ÊͳƳɹ¦ÀûÓô˷ì϶¿É»ñµÃϵͳȨÏÞ¡£´Ë±í£¬½¨¸´µÄ½ÏΪÑϳÁµÄ·ì϶Ô̺¬WindowsͼÐÎ×é¼þÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2022-30221£©ºÍWindows ÍøÂçÎļþϵͳԶ³Ì´úÂëÖ´Ðзì϶£¨CVE-2022-22029£©µÈ¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2022-patch-tuesday-fixes-exploited-zero-day-84-flaws/
2¡¢ÐÂÀÕË÷Èí¼þHavanaCrypt¼Ù×°³ÉGoogleÈí¼þ¸üÐÂÀ´·Ö·¢
Trend MicroÔÚ7ÔÂ6ÈÕÅû¶ÁËÐÂÀÕË÷Èí¼þHavanaCryptµÄ·Ö·¢»î¶¯¡£ÔÚÕâ´Î»î¶¯ÖУ¬¶ñÒâÈí¼þ¼Ù×°³ÉGoogleÈí¼þ¸üÐÂÀûÓ÷¨Ê½£¬²¢Ê¹ÓÃMicrosoftÍøÂçÍйܷþÎñIPµØÖ·×÷ΪÆäC2·þÎñÆ÷À´Èƹý°²È«¼ì²â¡£´Ë±í£¬×êÑÐÈËÔ±·¢ÏÖ£¬ÀÕË÷Èí¼þÔÚ¼ÓÃÜÆÚ¼äʹÓÃÀ´×Ô¿ªÔ´ÃÜÔ¿ÖÎÀíÆ÷KeePass Password Safe´úÂ룬²¢Ê¹ÓÃÃûΪ¡°QueueUserWorkItem¡±µÄ.Netº¯ÊýÀ´¼Ó¿ì¼ÓÃÜ¡£Trend MicroÖ¸³ö£¬HavanaCrypt¿ÉÄÜÈÔ´¦ÓÚ¿ª·¢½×¶Î£¬ÓÉÓÚËü²»»áÔÚ±»Ï°È¾µÄϵͳÉÏÁôÏÂÊê½ð¼Í¼¡£
https://www.trendmicro.com/en_us/research/22/g/brand-new-havanacrypt-ransomware-poses-as-google-software-update.html
3¡¢Anubis NetworksÔٴλع飬Õë¶Ô°ÍÎ÷ºÍÆÏÌÑÑÀ´¹µö¹¥»÷
¾ÝSeguran?a Inform¨¢ticaÔÚ7ÔÂ10ÈÕ±¨Â·£¬Anubis NetworkÒÑ´ø×ÅеÄC2·þÎñÆ÷»Ø¹é¡£Õâ´Î»î¶¯×Ô2022Äê3ÔÂÆðÍ·£¬ÖØÒªÕë¶Ô°ÍÎ÷ºÍÆÏÌÑÑÀµÄ»¥ÁªÍøÓû§¡£¸Ã»î¶¯ÓÉÈý¸ö¹Ø¼üµÄ²¿ÃÅ×é³É£ºÔÚÒ°´«²¼ÐéαµÇÂ¼Ò³ÃæµÄ½»¸¶¹¤¾ß£¬Í¨³£Í¨¹ý¶ÌÐźʹ¹µöµç×ÓÓʼþ½øÐУ»ÍйÜÔÚÔÆ·þÎñÆ÷ÉϵĶñÒâµÇÂ¼Ò³Ãæ£¬ÓÉÓëÕæÊµÏµÍ³¼«¶ÈÀàËÆµÄÓû§½çÃæºÍ²¼¾Ö×é³É£»Ò»¸ö½ÚÔìºó¶Ë£¬±»¹¥»÷ÕßÓÃÓÚÖÎÀíÖ¸±êÓû§µÄ¾ßÌåÐÅÏ¢¡£
https://seguranca-informatica.pt/anubis-networks-is-back-with-new-c2-server/#.Ys0jP3ZBxPa
4¡¢Ó¢¹ú½ðÈÚ·þÎñ¹«Ë¾Aon½ü15Íò¸ö±±ÃÀ¿Í»§µÄÓ×ÎÒÐÅϢй¶
¾ÝýÌå7ÔÂ8ÈÕ±¨Â·£¬Ó¢¹ú¿ç¹ú½ðÈÚ·þÎñ¹«Ë¾âù°²£¨Aon£©145889¸ö±±ÃÀ¿Í»§µÄÐÅϢй¶¡£¸Ã¹«Ë¾°µÊ¾£¬´Ó2020Äê12ÔÂ29ÈÕµ½2022Äê2ÔÂ26ÈÕ£¬ºÚ¿ÍÔÚ·ÖÆç¹¦·òÄÚÈëÇÖÁËÆäϵͳ¡£ÊÜÓ°ÏìµÄÐÅÏ¢Ô̺¬¼ÝÕÕºÅÂë¡¢Éç»á°²È«ºÅÂëºÍ¸£ÀûµÇ¼ÇÐÅÏ¢µÈ¡£AonÐû³ÆÒѲÉÈ¡´ëʩȷÈÏδ¾ÊÚȨµÄµÚÈý·½²»ÔÙÓÐȨ½Ó¼ûÊý¾Ý£¬ÇÒÐÅÏ¢²¢Î´±»ÀÄÓá£ÓÉÓÚÊý¾Ýй¶ÊÂÎñ£¬AonÃæ¶ÔÖÁÉÙÁ½Æð¼¯ÌåËßËÏ¡£´Ë±í£¬¸Ã¹«Ë¾ÎªÊÜÓ°ÏìµÄ¿Í»§ÌṩÁË24¸öÔµÄÉí·Ý±£»¤·þÎñ¡£
https://www.infosecurity-magazine.com/news/aon-hack-sensitive-information/
5¡¢Resecurity³ÆÀÕË÷ÍÅ»ïALPHVÒªÇóµÄÊê½ðÒÑ´ï250ÍòÃÀÔª
¾Ý7ÔÂ10ÈÕ±¨Â·£¬ÀÕË÷ÍÅ»ïALPHV£¨±ðÃûBlackCat£©ÒªÇóµÄÊê½ðÒÑ´ï250ÍòÃÀÔª¡£ALPHVÖÁÉÙ´ÓÈ¥Äê11ÔÂ¾ÍÆðÍ·ÔËÓªÁË£¬ËüÆðÍ·ÒªÇó250ÍòÃÀÔªºÍ¿¿½üÒ»°ëµÄÕÛ¿Û£¬ÒÔ¼¤ÀøÖ¸±ê¾¡¿ì¸¶Êê½ð£¬Áô¸øÖ¸±êµÄÖ§¸¶¹¦·òÔÚ5-7Ìì²»µÈ¡£Resecurity°µÊ¾£¬×Ô2020ÄêÒÔÀ´£¬¾ùÔÈÀÕË÷Êê½ð¶îÔö³¤ÁË82%£¬ÖÁ2021ÄêÉϰëÄêΪ570000ÃÀÔª£¬´ïµ½º¹Çàиߣ¬¶øºóµ½2022ÄêÏÕЩ·ÁËÒ»·¬¡£×îÐÂÔ¤²âÊǵ½2031Ä꣬ȫÇòÀÕË÷»î¶¯½«´ïµ½2650ÒÚÃÀÔª£¬¶ÔÈ«ÇòÆóÒµÔì³ÉµÄ×ÜËðʧ½«´ïµ½10.5ÍòÒÚÃÀÔª¡£
https://resecurity.com/blog/article/blackcat-aka-alphv-ransomware-is-increasing-stakes-up-to-25m-in-demands
6¡¢Kaspersky°ä²¼ÓйػùÓÚÎı¾µÄڲƻµÄ·ÖÎö»ã±¨
7ÔÂ11ÈÕ£¬Kaspersky°ä²¼ÁËÓйػùÓÚÎı¾µÄڲƻµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬»ùÓÚÎı¾µÄÚ²ÆÄܹ»·ÖΪ¼¸ÖÖÀàÐÍ£ºÔ¼»áÚ¿Æ¡¢419Ú¿Æ¡¢Ú²ÆÀÕË÷ºÍÓïÒôÍøÂç´¹µö¡£ÆäÖУ¬Ô¼»áÚ¿ÆÊÇ×î²»³£¼ûµÄÀàÐÍ£¬´Ó2022Äê3Ôµ½6Ô£¬¼ì²âµ½49536Ìõ´ËÀàÐÂÎÅ£»419Ú¿ÆÊÇ×î¹ÅÀϵÄÀàÐÍÖ®Ò»£¬Í¨³£ÊǼÙðµÄÂÉʦ·î¸æÖ¸±êÒѹʵÄÇׯÝÒѽ«¾Þ¶î²Æ¸»ÒÅÔù¸øËûÃÇ£¬Ã¿Ô»á¼ì²âµ½ÊýÊ®ÍòÌõ´ËÀàÐÂÎÅ£»Ú²ÆÀÕË÷µÄÓʼþÒª±ÈÆäËüÀàÐͶàµÃ¶à£¬´Ó3Ôµ½6ÔÂÓг¬¹ý1200ÍòÌõÀÕË÷ÐÅÏ¢£»3Ôµ½6Ô£¬×êÑÐÈËÔ±¼ì²âµ½347141·âÓïÒô´¹µöÓʼþ¡£
https://securelist.com/mail-text-scam/106926/


¾©¹«Íø°²±¸11010802024551ºÅ