΢Èí°ä²¼2Ô·ݰ²È«¸üУ¬Ô̺¬3¸öÒѱ»ÀûÓõķì϶
°ä²¼¹¦·ò 2023-02-15
2ÔÂ14ÈÕ£¬Î¢Èí°ä²¼ÁË2023Äê2Եݲȫ¸üУ¬½¨¸´Ô̺¬3¸ö±»ÀûÓÃ0 dayÔÚÄÚµÄ77¸ö·ì϶¡£ÆäÖУ¬Òѱ»ÀûÓõķì϶±ðÀëΪWindowsͼÐÎ×é¼þÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2023-21823£©£¬¿ÉÓÃÀ´ÒÔSYSTEMȨÏÞÖ´ÐкÅÁMicrosoft Publisher°²È«Ö°ÄÜÈÆ¹ý·ì϶£¨CVE-2023-21715£©£¬ÌØÔìÎĵµ¿ÉÀûÓÃÆäÈÆ¹ýOfficeºêÕ½Êõ£»ÒÔ¼°WindowsͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶£¨CVE-2023-23376£©£¬¿ÉÓÃÀ´»ñµÃSYSTEMȨÏÞ¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-february-2023-patch-tuesday-fixes-3-exploited-zero-days-77-flaws/
2¡¢Cloudflare¼ì²âµ½Õë¶ÔÆä¿Í»§µÄ´ó¹æÄ£DDoS¹¥»÷
¾ÝýÌå2ÔÂ14ÈÕ±¨Â·£¬Cloudflare¼ì²âµ½ÊýÊ®´Î³¬´óÈÝÁ¿DDoS¹¥»÷¡£¸Ã¹«Ë¾°µÊ¾£¬´óÎÞÊý¹¥»÷µÄ·åÖµÔÚÿÃë50-70°ÙÍò¸öÒªÇó(rps)×óÓÒ£¬×î´ó·åÖµ³¬¹ý7100Íòrps£¬ÕâÊÇÆù½ñΪֹ×î´ó¹æÄ£µÄHTTP DDoS¹¥»÷¡£ÕâЩ¹¥»÷»ùÓÚHTTP/2£¬ÊÇʹÓÃÀ´×Ô¶à¸öÔÆÌṩÉ̵Ä30000¶à¸öIPµØÖ·Õë¶Ô¸÷ÀàÖ¸±êÌáÒéµÄ£¬Ô̺¬ÓÎÏ·ÌṩÉÌ¡¢ÔÆÍÆËãÆ½Ì¨¡¢¼ÓÃÜÇ®±Ò¹«Ë¾ºÍÍйÜÌṩÉÌ¡£ÔÚ´ÓǰµÄÒ»ÄêÀ×êÑÐÈËÔ±¿´µ½Á˸ü¶àÀ´×ÔÓÚÔÆÍÆË㹩¸øÉ̵Ĺ¥»÷¡£
https://thehackernews.com/2023/02/massive-http-ddos-attack-hits-record.html
3¡¢Phylum·¢ÏÖ451¸öÖ¼ÔÚ½Ù³Ö¼ÓÃÜÇ®±ÒÂòÂôµÄ¶ñÒâPyPI°ü
PhylumÔÚ2ÔÂ10ÈÕ³ÆÆä·¢ÏÖ451¸ö¶ñÒâPyPI°ü£¬Ö¼ÔÚͨ¹ý×°ÖöñÒâÀ©´ó½Ù³Ö»ùÓÚä¯ÀÀÆ÷µÄ¼ÓÃÜÇ®±ÒÂòÂô¡£ÕâÊÇ×î³õÓÚ2022Äê11Ô·¢ÏֵĻµÄÒ»Á¬£¬ÆäʱֻÓÐ27¸ö¶ñÒâPyPi°ü¡£ÔÚÕâ´Î»î¶¯Öб»·ÂÕÕµÄÊ¢ÐÐÈí¼þ°üÔ̺¬bitcoinlib¡¢ccxtºÍcryptocompareµÈ£¬Ã¿¸ö¶¼ÓÐ13µ½38¸ö°æ±¾£¬ÊÔͼ¸²¸Ç¿ÉÄܵĸ÷ÀàÃýÎóÀàÐÍ¡£ÎªÁËÈÆ¹ý¼ì²â£¬¹¥»÷ÕßʹÓÃËæ»úµÄ16λÖÐÎĺº×Ö×éºÏ×÷Ϊº¯ÊýºÍ±äÁ¿±êʶ·û¡£
https://blog.phylum.io/phylum-discovers-revived-crypto-wallet-address-replacement-attack
4¡¢Group-IBй©Æä½üÆÚÔâµ½À´×ÔTonto TeamÍÅ»ïµÄ¹¥»÷
Group-IBÓÚ2ÔÂ13ÈÕй©£¬Æä¼ì²â²¢×èÖ¹ÁËÀ´×ÔAPTÍÅ»ïTonto TeamµÄ¹¥»÷¡£¹¥»÷²úÉúÔÚ2022Äê6Ô£¬ÕâÊǵڶþ´ÎÕë¶ÔGroup-IBµÄ¹¥»÷£¬µÚÒ»´Î²úÉúÔÚ2021Äê3Ô¡£¹¥»÷ʼÓÚÒ»·â´¹µöÓʼþ£¬·Ö·¢ÁËʹÓÃRoyal Road Weaponizer´´½¨µÄ¶ñÒâMicrosoft OfficeÎĵµ¡£ÔÚ¹¥»÷ÆÚ¼ä£¬¹¥»÷Õß»¹ÀûÓÃÁËBisonal.DoubleTºóÃÅ¡£´Ë±í£¬×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸öеÄÏÂÔØ·¨Ê½TontoTeam.Downloader£¨±ðÃûQuickMute£©£¬ËüÖØÒªÕÆ¹Ü´ÓÔ¶³Ì·þÎñÆ÷¼ìË÷ÏÂÒ»½×¶ÎµÄ¶ñÒâÈí¼þ¡£
https://www.group-ib.com/blog/tonto-team/
5¡¢CheckPoint°ä²¼2023Äê1Ô·ÝÈ«ÇòÍþвָÊýµÄ»ã±¨
2ÔÂ13ÈÕ£¬Check Point°ä²¼2023Äê1Ô·ÝÈ«ÇòÍþвָÊýµÄ»ã±¨¡£QbotºÍLokibotÊÇÉϸöÔÂ×î³£¼ûµÄ¶ñÒâÈí¼þ£¬¶ÔÈ«Çò×éÖ¯µÄÓ°Ï쳬¹ýÁË6%£¬Æä´ÎÊÇAgentTesla£¬È«ÇòÓ°ÏìΪ5%¡£½ÌÓýºÍ×êÑÐÐÐÒµÒÀÈ»ÊÇÈ«ÇòÊܵ½¹¥»÷×îÑϳÁµÄÐÐÒµ£¬Æä´ÎÊǵ±¾Ö¾ü¶ÓÒÔ¼°Ò½ÁƱ£½¡ÐÐÒµ¡£×î³£±»ÀûÓõķì϶ΪWeb·þÎñÆ÷¶³öµÄGit´æ´¢¿âÐÅϢй¶ºÍHTTP±êÍ·Ô¶³Ì´úÂëÖ´Ðзì϶¡£×î³£¼ûµÄÒÆ¶¯¶ñÒâÈí¼þÊÇAnubis£¬Æä´ÎÊÇHiddadºÍAhMyth¡£
https://blog.checkpoint.com/2023/02/13/january-2023s-most-wanted-malware-infostealer-vidar-makes-a-return-while-earth-bogle-njrat-malware-campaign-strikes/
6¡¢Ahnlab°ä²¼¹ØÓÚDalbitÍŻ﹥»÷»î¶¯µÄ·ÖÎö»ã±¨
AhnlabÔÚ2ÔÂ13ÈÕ°ä²¼Á˹ØÓÚDalbitÍŻ﹥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£×Ô2022ÄêÒÔÀ´£¬¸ÃÍÅ»ïÒѶԺ«¹ú¹«Ë¾½øÐÐÁË50ÂŴι¥»÷£¬´óÎÞÊýÊÇÖÐÓ×Ð͹«Ë¾£¬Éæ¼°¼¼Êõ¡¢¹¤Òµ¡¢»¯¹¤¡¢¹¹ÖþºÍÆû³µµÈÐÐÒµµÄ×éÖ¯¡£¹¥»÷ÕßÊ×ÏÈͨ¹ýÀûÓ÷ì϶»ñµÃ½Ó¼ûȨÏÞ£¬³¢ÊÔʹÓÃWebShellµÈ¹¤¾ßÀ´½ÚÔìϵͳ¡£¶øºóÀûÓÃÍøÂçɨÃ蹤¾ßºÍÕË»§ÍµÇÔ¹¤¾ßµÈ½øÐÐÄÚ²¿¿úËźÍÇÔÊØÐÅÏ¢¡£×îÖÕ£¬¹¥»÷ÕßÔÚÇÔÈ¡ÁËËûÃÇÏëÒªµÄËùÓÐÐÅÏ¢ºó£¬»áʹÓÃBitLocker¼ÓÃÜijЩÇý¶¯Æ÷²¢Ë÷ÒªÊê½ð¡£
https://asec.ahnlab.com/en/47455/


¾©¹«Íø°²±¸11010802024551ºÅ