Cado SecurityÌåÏÖ½©Ê¬ÍøÂçAbcbotÓëXantheÓйØÁª

Ðû²¼Ê±¼ä 2022-01-12

΢ÈíÐû²¼1ÔÂÖܶþ²¹¶¡ £¬£¬£¬£¬£¬ £¬ÐÞ¸´6¸ö0 dayÔÚÄÚµÄ97¸öÎó²î


½ØÍ¼20220112121945.png


1ÔÂ11ÈÕ £¬£¬£¬£¬£¬ £¬Î¢ÈíÐû²¼Á˽ñÄê¶ÈµÄÊ׸öÖܶþ²¹¶¡ £¬£¬£¬£¬£¬ £¬×ܼÆÐÞ¸´97¸öÇå¾²Îó²î£¨²»°üÀ¨29¸öMicrosoft EdgeÎó²î£©¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄ×îÑÏÖØµÄÊÇHTTPЭÒéÕ»Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2022-21907£© £¬£¬£¬£¬£¬ £¬CVSSÆÀ·ÖΪ9.8 £¬£¬£¬£¬£¬ £¬¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâÊý¾Ý°üµ½Ä¿µÄЧÀÍÆ÷À´Ê¹ÓøÃÎó²î¡£¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬£¬ £¬¸üл¹ÐÞ¸´ÁË6¸ö0 day £¬£¬£¬£¬£¬ £¬°üÀ¨¿ªÔ´Curl¿âÖеÄRCE£¨CVE-2021-22947£©¡¢¿ªÔ´ Libarchive¿âÖеÄRCE£¨CVE-2021-36976£©ºÍÍâµØWindowsÇå¾²ÖÐÐÄAPIÖеÄRCE£¨CVE-2022-21874£©µÈ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-january-2022-patch-tuesday-fixes-6-zero-days-97-flaws/


EDPSÒªÇóÅ·ÖÞÐ̾¯×é֯ɾ³ýÓë·¸·¨»î¶¯Î޹صÄСÎÒ˽¼ÒÊý¾Ý


¾ÝýÌå1ÔÂ10ÈÕ±¨µÀ £¬£¬£¬£¬£¬ £¬Å·ÃËÊý¾Ý±£»£»£»£»¤î¿Ïµ»ú¹¹EDPSÏÂÁîÒªÇóÅ·ÖÞÐ̾¯×é֯ɾ³ýÓë·¸·¨»î¶¯Î޹صÄСÎÒ˽¼ÒÊý¾Ý¡£¡£¡£¡£¡£Õþ¸®Ö¸³ö £¬£¬£¬£¬£¬ £¬ÔÚûÓÐÊý¾ÝÖ÷Ìå·ÖÀàµÄÇéÐÎÏ´洢´ó×ÚÊý¾Ý»á¶ÔСÎÒ˽¼ÒµÄ»ù±¾È¨Á¦×é³ÉΣº¦ £¬£¬£¬£¬£¬ £¬Ï൱ÓÚ´ó¹æÄ£¼àÊÓ¡£¡£¡£¡£¡£¾Ý¡¶ÎÀ±¨¡·±¨µÀ £¬£¬£¬£¬£¬ £¬»º´æÖÁÉÙ°üÀ¨4 PB¡£¡£¡£¡£¡£EDPS»¹»®¶¨ÁËÁù¸öÔµı£´æÆÚ £¬£¬£¬£¬£¬ £¬ÒÔ¹ýÂ˺ÍÌáȡСÎÒ˽¼ÒÊý¾Ý £¬£¬£¬£¬£¬ £¬²¢¸øÓè¸Ã¿ç¾³Ö´·¨»ú¹¹Ò»ÄêµÄʱ¼äÀ´Éó²éÆäÊý¾Ý¿â¡£¡£¡£¡£¡£


https://thehackernews.com/2022/01/europol-ordered-to-delete-data-of.html


WordPressÐû²¼¸üР£¬£¬£¬£¬£¬ £¬ÐÞ¸´SQL×¢ÈëµÈ4¸öÇå¾²Îó²î


ýÌå1ÔÂ11ÈÕ±¨µÀ £¬£¬£¬£¬£¬ £¬WordPressÐû²¼¸üР£¬£¬£¬£¬£¬ £¬×ܼÆÐÞ¸´4¸öÇå¾²Îó²î¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄÎó²î°üÀ¨SQL×¢ÈëÎó²î£¨CVE-2022-21661£© £¬£¬£¬£¬£¬ £¬¿Éͨ¹ýʹÓÃWP-QueryµÄ²å¼þºÍÖ÷ÌâʹÓ㻣»£»£»XSSÎó²î£¨CVE-2022-21662£© £¬£¬£¬£¬£¬ £¬¿ÉÓÃÀ´Ö²ÈëºóÃÅ»òͨ¹ýÀÄÓÃpost slugÀ´¿ØÖÆÍøÕ¾£»£»£»£»SQL×¢ÈëÎó²î£¨CVE-2022-21664£© £¬£¬£¬£¬£¬ £¬¿Éͨ¹ýWP_Meta_QueryʹÓ㻣»£»£»¹¤¾ß×¢ÈëÎó²î£¨CVE-2022-21663£© £¬£¬£¬£¬£¬ £¬ÐèÒªÈëÇÖÖÎÀíÔ±ÕÊ»§²Å»ªÊ¹Óᣡ£¡£¡£¡£


https://securityaffairs.co/wordpress/126556/security/wordpress-5-8-3.html


΢ÈíÅû¶macOSÎó²îpowerdir(CVE-2021-30970)ϸ½Ú


1ÔÂ10ÈÕ £¬£¬£¬£¬£¬ £¬Î¢ÈíÐû²¼¹ØÓÚmacOSÖеÄÎó²îpowerdir(CVE-2021-30970)µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£Î¢ÈíÌåÏÖ £¬£¬£¬£¬£¬ £¬¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÈÆ¹ý͸Ã÷¡¢Ô޳ɺͿØÖÆ(TCC)ÊÖÒÕÀ´»á¼ûÓû§µÄÊý¾Ý¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷ £¬£¬£¬£¬£¬ £¬¿ÉÒÔͨ¹ý±à³ÌµÄ·½·¨¸Ä¶¯Ä¿µÄÓû§Ö÷Ŀ¼²¢Ö²ÈëαTCCÊý¾Ý¿â £¬£¬£¬£¬£¬ £¬¹¥»÷Õß¿ÉʹÓøÃÎó²îƾ֤Óû§Êܱ£»£»£»£»¤µÄСÎÒ˽¼ÒÊý¾Ý²ß»®¹¥»÷¡£¡£¡£¡£¡£Î¢ÈíÍŶÓÔÚ2021Äê7ÔÂ15ÈÕ½«Îó²î±¨¸æ¸øApple¹«Ë¾ £¬£¬£¬£¬£¬ £¬AppleÔÚ12ÔÂ13ÈÕÐû²¼µÄÇå¾²¸üÐÂÖÐÐÞ¸´¡£¡£¡£¡£¡£


https://www.microsoft.com/security/blog/2022/01/10/new-macos-vulnerability-powerdir-could-lead-to-unauthorized-user-data-access/


Cado SecurityÌåÏÖ½©Ê¬ÍøÂçAbcbotÓëXantheÓйØÁª


Cado SecurityÔÚ1ÔÂ10ÈÕÐû²¼µÄ±¨¸æÏÔʾ £¬£¬£¬£¬£¬ £¬½©Ê¬ÍøÂçAbcbotÓëXantheÓйØÁª¡£¡£¡£¡£¡£AbcbotÔÚ2021Äê11ÔÂÊ״α»¹ûÕæ £¬£¬£¬£¬£¬ £¬Æäʱ¹¥»÷ÁË»ªÎª¡¢ÌÚѶ¡¢°Ù¶ÈºÍ°¢ÀïÔÆµÈÔÆÐ§ÀÍÌṩÉÌ¡£¡£¡£¡£¡£µ«Í¨¹ýËùÓÐÒÑÖªµÄIoCs £¬£¬£¬£¬£¬ £¬°üÀ¨IPµØµã¡¢urlºÍÑù±¾ £¬£¬£¬£¬£¬ £¬·¢Ã÷AbcbotµÄ´úÂëºÍ»ù´¡ÉèÊ©ÓëÒ»¸öÃûΪXantheµÄ¼ÓÃÜÐ®ÖÆ¶ñÒâÈí¼þ¼Ò×åÓÐÖØµþ¡£¡£¡£¡£¡£Ñо¿ÍŶÓÒÔΪ¶þÕßÓÉͳһ¹¥»÷ÕßÈÏÕæ £¬£¬£¬£¬£¬ £¬²¢ÇÒËûÃÇÕý½«Ä¿µÄ´ÓÍÚ¿ó×ªÒÆµ½Óë½©Ê¬ÍøÂçÏà¹ØµÄ»î¶¯¡£¡£¡£¡£¡£


https://www.cadosecurity.com/abcbot-an-evolution-of-xanthe/


Check Point³Æ2021ÄêÍøÂç¹¥»÷»î¶¯Í¬±ÈÔöÌí50%


1ÔÂ10ÈÕ £¬£¬£¬£¬£¬ £¬Check Point researchÐû²¼±¨¸æ³Æ2021ÄêÍøÂç¹¥»÷»î¶¯Í¬±ÈÔöÌí50%¡£¡£¡£¡£¡£±¨¸æ»¹Ö¸³ö £¬£¬£¬£¬£¬ £¬ÔÚ2021ÄêµÚËÄÐò¶È £¬£¬£¬£¬£¬ £¬Ã¿¸ö×éÖ¯µÄÿÖÜÔâµ½µÄ¹¥»÷´ÎÊýµÖ´ïÀúÊ·×î¸ß £¬£¬£¬£¬£¬ £¬Æ½¾ùΪ925´Î¡£¡£¡£¡£¡£2021Äê £¬£¬£¬£¬£¬ £¬½ÌÓýºÍÑо¿ÐÐÒµÊÇÔâµ½¹¥»÷×î¶àµÄÐÐÒµ £¬£¬£¬£¬£¬ £¬Æ½¾ùÿÖÜ1605´Î¹¥»÷ £¬£¬£¬£¬£¬ £¬Õâ±È2020ÄêÔöÌíÁË75%¡£¡£¡£¡£¡£°´µØÇø»®·Ö £¬£¬£¬£¬£¬ £¬·ÇÖÞÔâµ½¹¥»÷×î¶à £¬£¬£¬£¬£¬ £¬Æ½¾ùÿÖÜ1582´Î £¬£¬£¬£¬£¬ £¬±È2020ÄêÔöÌí13% £¬£¬£¬£¬£¬ £¬½ôËæØÊºóµÄÊÇÑÇÌ«µØÇø £¬£¬£¬£¬£¬ £¬Ã¿ÖÜÔâµ½1353´Î¹¥»÷£¨ÔöÌí25%£©¡£¡£¡£¡£¡£


https://blog.checkpoint.com/2022/01/10/check-point-research-cyber-attacks-increased-50-year-over-year/


Çå¾²¹¤¾ß


Mortar 


MortarÄܹ»ÈƹýÏÖ´ú·´²¡¶¾²úÆ·ºÍÏȽøµÄXDR½â¾ö¼Æ»® £¬£¬£¬£¬£¬ £¬°üÀ¨Kaspersky¡¢ESETºÍMcafeeµÈ¡£¡£¡£¡£¡£


https://www.kitploit.com/2022/01/mortar-evasion-technique-to-defeat-and.html


RecoverPy


¿ÉÓÃÀ´»Ö¸´±»ÁýÕÖ»òɾ³ýµÄÊý¾Ý £¬£¬£¬£¬£¬ £¬ÏÖÔÚ½öÔÚLinuxϵͳÉÏ¿ÉÓᣡ£¡£¡£¡£


https://github.com/PabloLec/RecoverPy


Çå¾²ÆÊÎö


Linux Mint 20.3 Ðû²¼


Linux Mint Ðû²¼ÁË 20.3 °æ £¬£¬£¬£¬£¬ £¬´úºÅΪ¡°Una¡± £¬£¬£¬£¬£¬ £¬×÷Ϊºã¾ÃÖ§³Ö°æ±¾ £¬£¬£¬£¬£¬ £¬²¢ÔÊÐíÔÚ 2025 ÄêÄê֮ǰÇå¾²¸üС£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/linux/linux-mint-203-released-promising-security-updates-until-2025/


ÀÕË÷Èí¼þAvosLocker Õë¶Ô VMware ESXi ЧÀÍÆ÷


AvosLockerÔÚÆä×î½üµÄ¶ñÒâÈí¼þ±äÖÖÖÐÔöÌíÁË¶Ô Linux ϵͳµÄÖ§³Ö £¬£¬£¬£¬£¬ £¬ÌØÊâÊÇÕë¶Ô VMware ESXi ÐéÄâ»ú¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/linux-version-of-avoslocker-ransomware-targets-vmware-esxi-servers/