Âóµ±ÀÍÒòй¶487Íò¹Ë¿ÍµÄÊý¾Ý±»º«¹ú·£¿î6.96ÒÚº«Ôª
°ä²¼¹¦·ò 2023-03-241¡¢Âóµ±ÀÍÒòй¶487Íò¹Ë¿ÍµÄÊý¾Ý±»º«¹ú·£¿î6.96ÒÚº«Ôª
¾ÝýÌå3ÔÂ22ÈÕ±¨Â·£¬Âóµ±Àͺ«¹ú¹«Ë¾ÒòÊý¾ÝÖÎÀí²»Ñϵ¼ÖÂ487Íò¹Ë¿ÍµÄÓ×ÎÒÊý¾Ýй¶£¬±»·£¿î6.96ÒÚº«Ôª£¨Ô¼ºÏ532110ÃÀÔª£©¡£Æ¾¾Ýµ÷²éÁ˾֣¬Âóµ±ÀÍûÓнøÐгä·ÖµÄ½Ó¼û½ÚÔ죬ʹµÃÔ̺¬Æä²ÍÌüºÍÂóµ±ÀͿͻ§µÄÓ×ÎÒÊý¾ÝµÄ±¸·ÝÎļþÄܹ»Í¨¹ýÎļþ¹²ÏíºÍ̸½øÐнӼû¡£Á˾֣¬ºÚ¿ÍÈëÇÖ²¢Ð¹Â¶Á˳¬¹ý487Íò¿Í»§µÄÓ×ÎÒÊý¾Ý¡£´Ë±í£¬¸Ã¹«Ë¾»¹±»·¢ÏÖûÓÐÏú»ÙÊý¾Ý±£ÁôÆÚÒѹýµÄ766846Ãû¹Ë¿ÍµÄÊý¾Ý£¬²¢ÇÒ³Ù³ÙûÓÐÏòµ±¾ÖºÍ¹Ë¿Í´«µÝÊý¾Ýй¶µÄÇé¿ö¡£
https://en.yna.co.kr/view/AEN20230322007100315
2¡¢Cleafy·¢ÏÖеÄAndroidľÂíNexusÖØÒªÊ¹ÓÃATO¹¥»÷
CleafyÔÚ3ÔÂ21ÈÕ³ÆÆä·¢ÏÖÁËÒ»¸öÐÂAndroidÒøÐÐľÂíNexus£¬Òѱ»¶à¸öÍÅ»ïÓÃÀ´¹¥»÷450ÖÖ½ðÈÚÀûÓá£Nexus¿Éͨ¹ý¶ñÒâÈí¼þ¼´·þÎñ(MaaS)»ñµÃ£¬ÓµÓжÔÒøÐÐÍøÕ¾ºÍ¼ÓÃÜÇ®±Ò·þÎñÖ´ÐÐATO¹¥»÷µÄËùÓÐÖØÒªÖ°ÄÜ£¬ÀýÈçÆ¾Ö¤ÇÔÈ¡ºÍSMSÀ¹½Ø¡£×êÑÐÈËÔ±ÒÔΪ£¬Ö»¹ÜÓжà¸ö»î¶¯Ê¹ÓÃÁËNexusľÂí£¬µ«ËüÈÔ´¦ÓÚÔçÆÚ¿ª·¢½×¶Î¡£NexusÆëÂúÊÇÖØÐÂÆðÍ·±àдµÄ£¬µ«×êÑз¢ÏÖËüºÍSOVAľÂíÖ®¼äÓÐÀàËÆÖ®´¦¡£
https://www.cleafy.com/cleafy-labs/nexus-a-new-android-botnet
3¡¢KimsukyÍÅ»ïÀûÓÃChromeÀ©´óÇÔȡָ±êµÄGmailÓʼþ
¾Ý3ÔÂ22ÈÕ±¨Â·£¬µÂ¹úºÍº«¹úµ±¾ÖµÄ½áºÏ°²È«Õ÷ѯ³Æ£¬KimsukyʹÓÃChromeÀ©´ó·¨Ê½ÇÔȡָ±êµÄGmailµç×ÓÓʼþ¡£¹¥»÷ʼÓÚÒ»·âÓã²æÊ½´¹µöÓʼþ£¬ÓÕʹָ±ê×°ÖöñÒâChromeÀ©´ó·¨Ê½¡£À©´óÃûΪ¡°AF¡±£¬Ö»Óе±Óû§ÔÚä¯ÀÀÆ÷µÄµØÖ·À¸ÖÐÊäÈë¡°(chrome|edge| brave)://extensions¡±Ê±£¬ÄÜÁ¦ÔÚÀ©´óÁбíÖп´µ½¡£Ò»µ©Ö¸±êͨ¹ý±»Ï°È¾µÄä¯ÀÀÆ÷½Ó¼ûGmail£¬À©´ó·¨Ê½¾Í»á×Ô¶¯¼¤»îÀ´À¹½ØºÍÇÔȡָ±êµÄµç×ÓÓʼþ¡£
https://www.bleepingcomputer.com/news/security/north-korean-hackers-using-chrome-extensions-to-steal-gmail-emails/
4¡¢Cisco°ä²¼Õë¶ÔNetgear Orbi·ÓÉÆ÷Öзì϶µÄPoC
ýÌå3ÔÂ22Èճƣ¬Cisco Talos°ä²¼ÁËÕë¶ÔNetgear Orbi 750ϵÁзÓÉÆ÷ºÍÀ©´óÎÀÐÇÖеķì϶°ä²¼ÁËPoC¡£µÚÒ»¸öPoCÕë¶ÔµÄÊǽӼû½ÚÔìÖ°ÄÜÖеĺÅÁîÖ´Ðзì϶£¨CVE-2022-37337£©£¬¿Éͨ¹ýÌØÔìµÄHTTPÒªÇóÔÚÉ豸ÉÏÖ´ÐÐËÁÒâºÅÁîÀ´ÀûÓÃÖÎÀí½ÚÔį̀¡£ÁíÒ»¸öÕë¶Ô·ÓÉÆ÷telnet·þÎñÖеÄÔ¶³ÌºÅÁîÖ´Ðзì϶£¨CVE-2022-38452£©£¬¸Ã·ì϶µÄÀûÓñØÒªÓÐЧµÄÍ´´¦ºÍMACµØÖ·¡£NetgearÓÚ1ÔÂ19ÈÕ°ä²¼¹Ì¼þ°æ±¾4.6.14.3½¨¸´ÁËÕâЩ·ì϶¡£
https://securityaffairs.com/143863/hacking/netgear-orbi-routers-flaws.html
5¡¢SentinelLabsÅû¶Õë¶ÔÖж«µçÐŹ«Ë¾µÄ¹¥»÷»î¶¯
SentinelLabsÔÚ3ÔÂ23ÈÕÅû¶ÁËÕë¶ÔÖж«µçÐŹ«Ë¾µÄ¹¥»÷»î¶¯£¬ËüÓëOperation Soft Cell»î¶¯µÄ¹¥»÷ÍÅ»ïÓйء£³õʼ¹¥»÷Éæ¼°ÈëÇÖÃæÏò»¥ÁªÍøµÄExchange·þÎñÆ÷£¬ÒÔ×°ÖÃÖ´ÐкÅÁîµÄwebshells¡£×Ô½ç˵ʹ´¦ÇÔÈ¡¶ñÒâÈí¼þµÄ×°ÖÃÊÇÕâһлµÄÖ÷Ì⣬ËüÔÚ¹ØÔ´¹¤¾ßÉÏÖ´ÐÐÁËһϵÁжÔMimikatz½øÐÐÅú¸ÄµÄ¶ñÒâÈí¼þ¡£¶ñÒâÈí¼þµÄÒ»¸öÌØ¶¨Ñù±¾£¨¶¨ÃûΪmim221£©»¹ÓµÓÐÉý¼¶µÄ·´¼ì²âÖ°ÄÜ¡£»î¶¯µÄ¹éÒòÉв»Ã÷È·£¬µ«¿ÉÄÜÓëGalliumºÍAPT41ÓйØÏµ¡£
https://www.sentinelone.com/labs/operation-tainted-love-chinese-apts-target-telcos-in-new-attacks/
6¡¢ENISA°ä²¼¹ØÓÚÅ·Ã˽»Í¨³©ÒµÍøÂçÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨
3ÔÂ21ÈÕ£¬ENISA°ä²¼Á˹ØÓÚÅ·Ã˽»Í¨³©ÒµÍøÂçÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¸Ã»ã±¨º¸ÇÁË2021Äê1ÔÂÖÁ2022Äê10Ôº½¿Õ¡¢º£ÔË¡¢Ìú·ºÍ¹«Â·ÔËÊäÐÐÒµ²úÉúµÄ°²È«ÊÂÎñ¡£Ó°ÏìÔËÊäÐÐÒµµÄÖØÒªÍþвÔ̺¬ÀÕË÷¹¥»÷¡¢Êý¾ÝÓйØÍþв¡¢¶ñÒâÈí¼þ¡¢DoS/DDoSºÍRDoS¹¥»÷¡¢´¹µö¹¥»÷ÒÔ¼°¹©¸øÁ´¹¥»÷¡£ÀÕË÷¹¥»÷ÒѳÉΪ2022Äê¸ÃÐÐÒµ×î͹ÆðµÄÍþв£¬¹¥»÷´ÎÊýÏÕЩ·ÁËÒ»·¬£¬´Ó2021ÄêµÄ13%ÉÏÉýµ½2022ÄêµÄ25%¡£¶ø¶ñÒâÈí¼þ´Ó11%½µÂäµ½6%£¬Êý¾Ýй¶´Ó21%½µÂäµ½9%¡£
https://www.enisa.europa.eu/publications/enisa-transport-threat-landscape


¾©¹«Íø°²±¸11010802024551ºÅ