ºê³ž(Acer)Ô¼160GBµÄÃô¸ÐÊý¾Ýй¶²¢ÔÚºÚ¿ÍÂÛ̳ÏúÊÛ

°ä²¼¹¦·ò 2023-03-08

1¡¢ºê³ž(Acer)Ô¼160GBµÄÃô¸ÐÊý¾Ýй¶²¢ÔÚºÚ¿ÍÂÛ̳ÏúÊÛ


¾ÝýÌå3ÔÂ6ÈÕ±¨Â·£¬Öйų́Íå¿Æ¼¼¹«Ë¾ºê³ž(Acer Inc.)µÄ´óÁ¿Êý¾Ýй¶¡£¹¥»÷ÕßKernelwareÔÚÒ»¸öÊ¢ÐеĺڿÍÂÛ̳ÉÏÏúÊÛËûÃÇÐû³ÆÔÚ2023Äê2ÔÂÖÐÑ®´ÓAcerÇÔÈ¡µÄ160GBÊý¾Ý¡£¹¥»÷Õßй©±»µÁÊý¾ÝÔ̺¬¼¼ÊõÊֲᡢÈí¼þ¹¤¾ß¡¢ºó¶Ë»ù´¡ÉèÊ©¾ßÌåÐÅÏ¢¡¢BIOSÓ³Ïñ¡¢ROMÎļþ¡¢ISOÎļþºÍ´úÌæÊý×Ö²úÆ·ÃÜÔ¿(RDPK)µÈ¡£×÷Ϊ¹¥»÷Ö¤¾Ý£¬¹¥»÷Õß¹«¿ªÁËAcer V206HQLÏÔʾÆÁµÄ¼¼ÊõʾÒâͼ¡¢Îĵµ¡¢BIOS½ç˵ºÍ»úÃÜÎĵµµÄÆÁÄ»½ØÍ¼¡£AcerÈ·ÈÏÆä¹©Î¬½¨¼¼ÊõÈËԱʹÓõÄÎļþ·þÎñÆ÷±»ÈëÇÖ£¬µ«Êǿͻ§Êý¾Ý²¢Î´ÊÜÓ°Ïì¡£


https://www.hackread.com/acer-data-breach-hacker-sell-data/


2¡¢Google°ä²¼3Ô·ÝAndroid¸üУ¬×ܼƽ¨¸´60¸ö·ì϶


¾Ý3ÔÂ7ÈÕ±¨Â·£¬Google°ä²¼ÁË2023Äê3ÔµÄAndroid°²È«¸üУ¬¹²½¨¸´ÁË60¸ö·ì϶£¬Ô̺¬Á½¸öÑϳÁµÄRCE·ì϶¡£Õâ´Î½¨¸´µÄ·ì϶ͨ¹ýÁ½¸ö¶ÀÁ¢µÄ°²È«²¹¶¡°ä²¼£¬¼´2023-03-01ºÍ2023-03-05¡£Á½¸öRCE·ì϶±ðÀëΪCVE-2023-20951ºÍCVE-2023-20954£¬GoogleÒѰµ²Ø¹ØÓÚËüÃǵÄËùÓÐÐÅÏ¢£¬ÒÔÔ¤·À¹¥»÷ÕßÔÚÓû§ÀûÓøüÐÂ֮ǰ½øÐй¥»÷¡£±¾Ô½¨¸´µÄ×îÑϳÁµÄ·ì϶ÊǹØÔ´Qualcomm×é¼þÖеÄCVE-2022-33213ºÍCVE-2022-33256¡£


https://www.bleepingcomputer.com/news/security/android-march-2023-update-fixes-two-critical-code-execution-flaws/


3¡¢Î÷°àÑÀ°ÍÈûÂÞÄÇÕïËùÒ½ÔºÔâµ½Ransom HouseÀÕË÷¹¥»÷


ýÌå3ÔÂ6Èճƣ¬Î÷°àÑÀ°ÍÈûÂÞÄÇÕïËùÒ½Ôº(Hospital Clinic de Barcelona) Ôâµ½¹¥»÷¡£Õâ´Î¹¥»÷µ¼Ö¸ÃÖÐÐĵÄÍÆËã»úϵͳ崻ú£¬150Ïî·Ç´¹Î£ÊÖÊõºÍ¶à´ï3000ÏÕ߲鳭±»È¡µÞ£¬Ò½ÔºÔÚ½«ÐµĴ¹Î£²¡Àý×ªÒÆµ½ÊÐÄÚÆäËûÒ½Ôº¡£±¾µØÒ»¼Ò°²È«»ú¹¹Ð¹Â©£¬Õâ´Î¹¥»÷À´×ÔÀÕË÷ÍÅ»ïRansom House£¬ÀÕË÷Èí¼þϰȾÁËÒ½Ôº³¢ÊÔÊÒ¡¢¼¹ØïÊÒºÍÈý¸öÖØÒªÖÐÐĵÄÒ©·¿ÒÔ¼°¼¸¸ö±í²¿ÕïËùµÄÍÆËã»ú¡£Ä¿Ç°Éв»Ã÷ÏÔϵͳºÎʱ¿É¸´Ô­Õý³£¡£


https://securityaffairs.com/143121/cyber-crime/hospital-clinic-de-barcelona-ransomware.html


4¡¢µÂ¹úºÍÎÚ¿ËÀ¼·¨Âɲ¿ÃÅ¿ÛÁôDoppelPaymerµÄÖ÷Ìâ³ÉÔ±


3ÔÂ6ÈÕ±¨Â·£¬Å·ÖÞÐ̾¯×éÖ¯°ä·¢£¬µÂ¹úºÍÎÚ¿ËÀ¼µÄ·¨Âɲ¿ÃÅ¿ÛÁôÁËÀÕË÷ÍÅ»ïDoppelPaymerµÄÁ½ÃûÖ÷Ìâ³ÉÔ±¡£¿ÛÁôÐж¯²úÉúÔÚ2023Äê2ÔÂ28ÈÕ£¬Í»»÷ËѲéÁËÒ»ÃûµÂ¹ú¹úÃñµÄ·¿ÎÝ£¬²¢ÔÚÎÚ¿ËÀ¼³ÇÊлù¸¨ºÍ¹þ¶û¿Æ·ò½øÐÐÁË¿í·ºËѲé¡£µÂ¹úµ±¾ÖÒÔΪ£¬DoppelPaymer»î¶¯Éæ¼°5¸öÖ÷Ìâ³ÉÔ±£¬ËûÃÇÊØ»¤¹¥»÷»ù´¡ÉèÊ©¡¢Êý¾ÝÐ¹Â¶ÍøÕ¾¡¢´¦Öý»Éæ²¢½«·Ö·¢¶ñÒâÈí¼þ¡£·¨Âɲ¿ÃÅĿǰÒÑ·¢³ö¿ÛÁôÁÔÚÈ«ÇòÁìÓòÄÚͨ¼©Áí±í3ÃûÏÓÒÉÈË¡£


https://www.bleepingcomputer.com/news/security/core-doppelpaymer-ransomware-gang-members-targeted-in-europol-operation/


5¡¢SentinelOnÅû¶ÀûÓÃRemcos RATÕë¶Ô¶«Å·µÄ´¹µö»î¶¯


3ÔÂ6ÈÕ£¬SentinelOnÅû¶ÁËÀûÓÃDBatLoader¼ÓÔØ·¨Ê½·Ö·¢Remcos RATµÄ´¹µö»î¶¯£¬ÖØÒªÕë¶Ô¶«Å·»ú¹¹ºÍÆóÒµ¡£¹¥»÷ʼÓÚÔ̺¬¼Ù·¢Æ±ºÍÕбêÎļþµÄ´¹µöÓʼþ£¬Ô̺¬DBatLoader¿ÉÖ´ÐÐÎļþµÄtar.lz´æµµ¡£µÚÒ»½×¶Îpayload¼Ù×°³ÉOffice¡¢LibreOffice»òPDFÎĵµ£¬Æô¶¯ºó»á´Ó¹«¹²ÔÆ·þÎñÖлñÈ¡µÚ¶þ½×¶Îpayload¡£¼ÓÔØRemcos RAT֮ǰ£¬DBatLoader´´½¨²¢Ö´ÐÐWindowsÅú´¦Öþ籾£¬ÒÔÀûÓÃ2020Äê¼Í¼µÄWindows UACÈÆ¹ý²½Öè¡£×îÖÕ£¬Í¨¹ý¹ý³Ì×¢ÈëµÄ·½Ê½Ö´ÐÐRemcos¡£


https://www.sentinelone.com/blog/dbatloader-and-remcos-rat-sweep-eastern-europe/


6¡¢Kaspersky°ä²¼2022ÄêH2¹¤Òµ×Ô¶¯»¯ÏµÍ³ÍþÐ²Ì¬ÊÆµÄ»ã±¨


3ÔÂ6ÈÕ£¬Kaspersky°ä²¼2022ÄêH2¹¤Òµ×Ô¶¯»¯ÏµÍ³ÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬È«ÇòÊܵ½¹¥»÷µÄICSÍÆËã»úµÄ°Ù·Ö±ÈΪ34.3%£¬ÂÔ¸ßÓÚ2022ÉϰëÄ꣨31.8%£©¡£ÖØÒªÍþвÆðÔ´ÊÇ»¥ÁªÍø£¨19.9%£©¡¢µç×ÓÓʼþ¿Í»§¶Ë£¨6.4% £©ºÍ¿Éж³ýµÄÉ豸£¨3.8%£©¡£Êܵ½´ËÀ๥»÷×î¶àµÄµØÓòΪ·ÇÖÞºÍÖÐÑÇ£¬Õ¼±È40.1%¡£Î÷Å·ºÍ±±Å·ÊÇ×ȫµÄµØÓò£¬±ðÀëΪ14.2%ºÍ14.3%¡£KasperskyÔÚ2022ϰëÄêÔÚ¹¤Òµ×Ô¶¯»¯ÏµÍ³Éϼì²âµ½À´×Ô7684¸ö·ÖÆç¼Ò×åµÄ¶ñÒâÈí¼þ¡£   

 

https://securelist.com/threat-landscape-for-industrial-automation-systems-for-h2-2022/108958/