2Ô·ݸüе¼Ö²¿ÃÅWindows Server 2022Ðé¹¹»úÎÞ·¨Æô¶¯
°ä²¼¹¦·ò 2023-02-17
¾Ý2ÔÂ16ÈÕ±¨Â·£¬Î¢Èí°µÊ¾£¬²¿ÃÅWindows Server 2022Ðé¹¹»úÔÚ×°Öñ¾ÔµÄÖܶþ²¹¶¡ºó¿ÉÄÜÎÞ·¨Æô¶¯¡£´ËÎÊÌâ½öÓ°ÏìÆôÓÃÁ˰²È«Æô¶¯²¢ÔÚvSphere ESXi 6.7 U2/U3»òvSphere ESXi 7.0.xÉÏÔËÐеÄÐé¹¹»ú¡£VMwareºÍRedmondÔÚµ÷²é´ËÎÊÌ⣬¹ÌȻĿǰûÓн¨¸´·¨Ê½£¬µ«VMwareΪÊÜÓ°ÏìµÄÖÎÀíÔ±ÌṩÁ˶àÖÖ»º½â²½Öè¡£Òź¶µÄÊÇ£¬ÈôÊÇÒѾװÖÃÁ˱¾ÔµÄWindows Server 2022ÀÛ»ý¸üÐÂKB5022842£¬Ð¶ÔØËü²¢²»Äܽâ¾öÎÊÌâ¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-february-updates-break-some-windows-server-2022-vms/
2¡¢ÏÖ´úºÍÆðÑÇÍÆ³ö´¹Î£¸üн¨¸´Í¨¹ýUSBÊý¾ÝÏßµÁ³µµÄÎÊÌâ
ýÌå2ÔÂ15ÈÕ±¨Â·³Æ£¬Æû³µÔì×÷ÉÌÏÖ´úºÍÆðÑǶÔËûÃǵļ¸¿î³µÐÍÍÆ³ö´¹Î£Èí¼þ¸üУ¬ÒÔ½¨¸´Í¨¹ýUSBÊý¾ÝÏßµÁ³µµÄÎÊÌâ¡£×Ô2022Äê7ÔÂÒÔÀ´£¬TikTok³öÏÖÁËÒ»ÏîÌôÕ½£¬ÑÝʾÁËÈôºÎ²ðÏÂתÏòÖù¸Ç£¬Â¶³öÒ»¸öUSB-A²å²Û£¬ÓÃÓÚ¶Ì·µã»ðÆû³µ¡£ÕâÊÇÒ»¸öÂß¼·ì϶£¬ÔÊÐíÔ¿³×Æô¶¯ÏµÍ³Èƹý·ÀµÁÆ÷£¬¹¥»÷Õß¿ÉʹÓÃÈκÎUSBÊý¾ÝÏßÇ¿Ð줻îµã»ðÆø¸×À´Æô¶¯³µÁ¾¡£ÃÀ°î½»Í¨²¿³Æ£¬¸Ã·ì϶ӰÏìÁËÔ¼380ÍòÁ¾ÏÖ´úÆû³µºÍ450ÍòÁ¾ÆðÑÇÆû³µ¡£
https://www.bleepingcomputer.com/news/security/hyundai-kia-patch-bug-allowing-car-thefts-with-a-usb-cable/
3¡¢¼ÓÀû¸£ÄáÑDZ±ÖÝ´óѧÔâµ½AvosLockerÍÅ»ïµÄÀÕË÷¹¥»÷
2ÔÂ15ÈÕ±¨Â·£¬ÀÕË÷ÍÅ»ïAvosLockerÔÚÆäÍøÕ¾ÁгöÁ˼ÓÀû¸£ÄáÑDZ±ÖÝ´óѧ¡£¹¥»÷Õßй©£¬ÒÑÇÔÈ¡Ô̺¬ÐÕÃû¡¢Éç»á°²È«ºÅÂëºÍµç»°µÈÐÅÏ¢ÔÚÄÚµÄѧÉúµÇ¿ÆÊý¾Ý£¬ÒÔ¼°Éæ¼°ÐÕÃû¡¢»á°²È«ºÅÂë¡¢¹¤×ʺÍ˰ÎñµÈÐÅÏ¢µÄÔ±¹¤Êý¾Ý¡£»¹°ä²¼ÁË2022 W-2ѧԺԺ³¤¼æÊ×ϯִÐй١¢¸±Ôº³¤¼æÊ×ϯ²ÆÕþ¹ÙµÄÉêÃ÷ºÍÇóÖ°ÕßµÄÐÅÏ¢£¬×÷Ϊ¹¥»÷Ö¤¾Ý¡£¸ÃУÒÑÏò²¿ÃÅÖÎÀíÈËÔ±ºÍѧÉú·¢ËÍÕâ´ÎÊÂÎñµÄ֪ͨ£¬µ«ÊÇÆä¹ÙÍøÃ»ÓÐÈκθÉÓÚÍøÂç¹¥»÷µÄÐÅÏ¢¡£
https://www.databreaches.net/california-northstate-university-student-and-employee-data-stolen/
4¡¢×êÑÐÈËÔ±Åû¶ʩÄÍµÂµçÆø²¿ÃŲÙ×÷ϵͳÖÐÁ½¸ö·ì϶µÄϸ½Ú
¾Ý2ÔÂ15ÈÕ±¨Â·£¬×êÑÐÈËÔ±Åû¶ÁËÓ°ÏìSchneider Electric Modicon¿É±à³ÌÂß¼½ÚÔìÆ÷(PLC)UnityϵÁеÄÁ½¸ö·ì϶¡£±ðÀëΪÒì³£Çé¿ö²é³²»µ±·ì϶£¨CVE-2022-45788£©£¬¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐÓ×¢»Ø¾ø·þÎñ¡¢»úÃÜÐÔºÍÆëÈ«ÐÔÃÔʧ¡£ÒÔ¼°Éí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2022-45789£©£¬¿ÉÄܻᵼÖÂÔÚ½ÚÔìÆ÷ÉÏÖ´ÐÐδ¾ÊÚȨµÄModbusÖ°ÄÜ¡£ÕâÊÇForescout×·×ٵķì϶¼¯ÖÐICEFALLµÄÒ»²¿ÃÅ£¬¿ÉÓëÆäËû¹©¸øÉ̵ķì϶£¨ÈçCVE-2021-31886£©½áºÏʹÓã¬ÒÔʵÏÖOTÍøÂçÖеÄÉî¶ÈºáÏòÒÆ¶¯¡£
https://therecord.media/schneider-electric-modicon-vulnerabilities-forescout-icefall/
5¡¢Unit 42·¢ÏÖ¶àÆðÀûÓÃеÄMirai±äÌåV3G4µÄ¹¥»÷»î¶¯
2ÔÂ15ÈÕ£¬Unit 42Åû¶ÁËÐÂMirai±äÌåV3G4µÄ¹¥»÷»î¶¯¡£×Ô2022Äê7ÔÂÒÔÀ´£¬×êÑÐÈËÔ±¹Û²ìµ½ÈýÆðÀûÓÃMirai V3G4±äÌåµÄ»î¶¯¡£¹¥»÷ÕßÀûÓÃÁË13¸ö¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´Ðеķì϶£¬³É¹¦ÀûÓúó»á×Ô¶¯Ö´ÐÐwgetºÍcurl¹¤¾ß£¬´Ó¶ñÒâÈí¼þ»ù´¡ÉèÊ©ÏÂÔØMirai¿Í»§¶ËÑù±¾£¬¶øºóÖ´ÐÐÏÂÔØµÄbot¿Í»§¶Ë¡£´Ë±í£¬Unit 42ÒÔΪÕâÈýÆð¹¥»÷¶¼À´×Ôͳһ¸ö¹¥»÷Õߣ¬ÓÉÓÚÓ²±àÂëµÄC2ÓòÔ̺¬Ò»ÑùµÄ×Ö·û´®£¬shell¾ç±¾ÏÂÔØÀàËÆ£¬²¢ÇÒËùÓй¥»÷ÖÐʹÓõĽ©Ê¬ÍøÂç¿Í»§¶ËÓµÓÐÒ»ÑùµÄÖ°ÄÜ¡£
https://unit42.paloaltonetworks.com/mirai-variant-v3g4/
6¡¢Group-IB°ä²¼SideWinderÕë¶ÔÑÇÌ«µØÓò¹¥»÷µÄ»ã±¨
Group-IBÔÚ2ÔÂ15ÈÕ°ä²¼Á˹ØÓÚSideWinderÕë¶ÔÑÇÌ«µØÓò¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬ÔÚ2021Äê6ÔÂÖÁ2021Äê11ÔÂÆÚ¼ä£¬¹¥»÷ÕßÊÔͼÕë¶Ô°¢¸»º¹¡¢²»µ¤¡¢Ãåµé¡¢Äá²´¶ûºÍ˹ÀïÀ¼¿¨µÄ61¸öµ±¾Ö¡¢¾ü¶Ó¡¢·¨Âɲ¿ÃŵÈÓйØ×éÖ¯¡£¹¥»÷ʼÓÚÓã²æÊ½´¹µöÓʼþ£¬»áµ¼ÖÂÏÂÔØ¶ñÒâÎĵµ¡¢LNKÎļþ»ò¶ñÒâpayload¡£×êÑÐÈËÔ±»¹·¢ÏÖÁËÁ½¸öй¤¾ß£¬Ô¶³Ì½Ó¼ûľÂíSideWinder.RAT.bºÍÐÅÏ¢ÇÔÈ¡·¨Ê½SideWinder.StealerPy£¬ËüÃǶ¼Ê¹ÓÃTelegram½øÐÐͨѶ£¬¶ø²»ÊÇ´«Í³µÄC2¡£
https://www.group-ib.com/media-center/press-releases/sidewinder-apt-report/


¾©¹«Íø°²±¸11010802024551ºÅ