еÄÀÕË÷ÔËÓªÍÅ»ïDeadBolt¹¥»÷È«ÇòµÄQNAP NAS×°±¸

Ðû²¼Ê±¼ä 2022-01-28

еÄÀÕË÷ÔËÓªÍÅ»ïDeadBolt¹¥»÷È«ÇòµÄQNAP NAS×°±¸


ýÌå1ÔÂ25ÈÕ±¨µÀ£¬£¬£¬£¬£¬ÐµÄÀÕË÷ÔËÓªÍÅ»ïDeadBoltÉù³ÆËûÃÇÕýÔÚʹÓÃ×°±¸Èí¼þÖеÄÁãÈÕÎó²î¹¥»÷È«ÇòQNAP NAS×°±¸¡£¡£¡£¡£¡£¹¥»÷×îÏÈÓÚ1ÔÂ25ÈÕ×îÏÈ£¬£¬£¬£¬£¬´ó×ÚQNAP×°±¸Òѱ»¼ÓÃܲ¢ÇÒÌí¼ÓÁË.deadboltÀ©Õ¹Ãû£¬£¬£¬£¬£¬Êê½ðΪ0.03±ÈÌØ±Ò£¨Ô¼1100ÃÀÔª£©¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬¸ÃÍŻﻹÌåÏÖQNAPÈôÊÇÖ§¸¶5¸ö±ÈÌØ±Ò¿ÉÒÔ»ñµÃ¹ØÓÚÁãÈÕÎó²îµÄËùÓÐÐÅÏ¢£¬£¬£¬£¬£¬Ö§¸¶50¸ö±ÈÌØ±Ò£¨Ô¼ºÏ185ÍòÃÀÔª£©¿ÉÒÔ»ñµÃÊÊÓÃÓÚËùÓÐQNAPÓû§µÄÖ÷½âÃÜÃÜÔ¿ºÍÎó²îÐÅÏ¢¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-deadbolt-ransomware-targets-qnap-devices-asks-50-btc-for-master-key/


µç×ÓÉ̳ÇSegwayÔÚMagecart¹¥»÷Öпͻ§ÐÅÏ¢±»µÁ


ýÌå1ÔÂ25ÈÕ±¨µÀ£¬£¬£¬£¬£¬SegwayµÄÔÚÏßÊÐËÁÔâµ½Magecart¹¥»÷£¬£¬£¬£¬£¬¿Í»§ÐÅÏ¢±»µÁ¡£¡£¡£¡£¡£Æ¾Ö¤urlscanioÊý¾ÝÆÊÎö£¬£¬£¬£¬£¬SegwayÍøÕ¾ (store.segway.com) ÖÁÉÙ´Ó1ÔÂ6ÈÕ¾ÍÒѾ­±»ÈëÇÖ£¬£¬£¬£¬£¬´Ë´Î»î¶¯¿ÉÄÜÓëMagecart Group 12ÓйØ£¬£¬£¬£¬£¬¸Ã×éÖ¯×Ô2019ÄêÒÔÀ´Ò»Ö±ÔÚÇÔÊØÐÅÓÿ¨ÐÅÏ¢¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÒÔΪ£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁËÍøÕ¾Ê¹ÓõÄMagento CMS»òÆä²å¼þÖеÄÎó²îÀ´×¢Èë¶ñÒâ´úÂë¡£¡£¡£¡£¡£×èÖ¹1ÔÂ25ÈÕ£¬£¬£¬£¬£¬ÇÔÊØÐÅÏ¢µÄ¶ñÒâ´úÂëÈÔ±£´æÓÚ¸ÃÍøÕ¾ÉÏ¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/127187/cyber-crime/segway-magecart-attack.html


LinuxÄÚºËÒç³öÎó²îCVE-2022-0185¿É´ÓÈÝÆ÷ÖÐÌÓÒÝ


ýÌå1ÔÂ25Èճƣ¬£¬£¬£¬£¬ LinuxÄÚºË×é¼þÖб£´æ»ùÓڶѵĻº³åÇøÒç³öÎó²î¡£¡£¡£¡£¡£¸ÃÎó²î×·×ÙΪCVE-2022-0185£¬£¬£¬£¬£¬¿Éµ¼ÖÂÔ½½çдÈë¡¢¾Ü¾øÐ§ÀͺÍí§Òâ´úÂëÖ´ÐУ¬£¬£¬£¬£¬¿ÉÓÃÀ´´ÓKubernetesµÄÈÝÆ÷ÖÐÌÓÒÝ£¬£¬£¬£¬£¬²¢»á¼ûÖ÷»úϵͳÉϵÄ×ÊÔ´¡£¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬£¬£¬¹¥»÷ÕßÐèҪʹÓ÷ÇÌØÈ¨Ãû³Æ¿Õ¼ä»òʹÓá°unshare¡±À´ÊäÈë¾ßÓÐCAP_SYS_ADMINȨÏÞµÄÃû³Æ¿Õ¼ä£¬£¬£¬£¬£¬²Å»ªÊ¹ÓøÃÎó²î¡£¡£¡£¡£¡£Ñо¿Ö°Ô±½¨Ò齫LinuxÄÚºËÉý¼¶µ½5.16.2»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/linux-kernel-bug-can-let-hackers-escape-kubernetes-containers/


AppleÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´Òѱ»ÔÚҰʹÓõÄÇå¾²Îó²î


1ÔÂ26ÈÕ£¬£¬£¬£¬£¬AppleÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´ÁËmacOSÖеÄ13¸öÎó²î£¬£¬£¬£¬£¬ÒÔ¼°iOS/iPadOSÖеÄ10¸öÎó²î¡£¡£¡£¡£¡£´Ë´Î¹²ÐÞ¸´ÁË2¸öÁãÈÕÎó²î£¬£¬£¬£¬£¬µÚÒ»¸öÊÇIOMobileFrameBufferÖеÄÄÚ´æËð»µÎó²î(CVE-2022-22587)£¬£¬£¬£¬£¬Ó°ÏìÁËiOS¡¢iPadOSºÍmacOS Monterey£¬£¬£¬£¬£¬Ê¹ÓôËÎó²î¿ÉÔÚÄ¿µÄ×°±¸ÉÏÒÔÄÚºËȨÏÞÖ´ÐÐí§Òâ´úÂ룻£»£»£»ÁíÒ»¸öÊÇWebKit StorageÖеÄÐÅϢй¶Îó²î£¨CVE-2022-22594£©¡£¡£¡£¡£¡£AppleÔÚͨ¸æÖгÆ£¬£¬£¬£¬£¬CVE-2022-22587¿ÉÄÜÒѱ»Æð¾¢Ê¹Óᣡ£¡£¡£¡£


https://threatpost.com/apple-zero-day-security-exploited/178040/


TrellixÐû²¼Õë¶ÔÎ÷ÑǵØÇøµÄÌØ¹¤»î¶¯µÄÆÊÎö±¨¸æ


1ÔÂ25ÈÕ£¬£¬£¬£¬£¬TrellixÐû²¼ÁËÕë¶ÔÎ÷ÑǵØÇø¹ú·ÀÐÐÒµµÄÌØ¹¤»î¶¯µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£´Ë´Î»î¶¯×îÔç×îÏÈÓÚ2021Äê6ÔÂ18ÈÕ£¬£¬£¬£¬£¬Ê¹ÓÃÁËMicrosoft OneDrive×÷ΪC2ЧÀÍÆ÷£¬£¬£¬£¬£¬²¢·ÖΪÁ˶à´ï6¸ö½×¶Î¡£¡£¡£¡£¡£Ñ¬È¾Á´Ê¼ÓÚ°üÀ¨MSHTMLÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2021-40444)Îó²îʹÓõÄExcelÎļþ£¬£¬£¬£¬£¬²¢Ê¹ÓÃÁËÃûΪGraphiteµÄ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£Trellix»ùÓÚÔ´´úÂëÒÔ¼°¹¥»÷Ö¸±êºÍÄ¿µÄµÄÏàËÆÐÔ£¬£¬£¬£¬£¬½«Õâ´Î¹¥»÷¹éÒòÓÚ¶íÂÞ˹µÄAPT28×éÖ¯¡£¡£¡£¡£¡£


https://www.trellix.com/en-gb/about/newsroom/stories/threat-labs/prime-ministers-office-compromised.html


Proofpoint·¢Ã÷DTPacker·Ö·¢¶à¸öRATºÍÐÅÏ¢ÇÔÈ¡³ÌÐò


ProofpointÔÚ1ÔÂ24ÈÕÐû²¼µÄ±¨¸æ¸ÅÊöÁ˶ñÒâÈí¼þDTPacker¡£¡£¡£¡£¡£ËüÊÇÒ»¸ö·ÖΪ2¸ö½×¶ÎµÄÉÌÆ·.NET´ò°ü³ÌÐò£¬£¬£¬£¬£¬ÆäpayloadʹÓÃÁ˰üÀ¨ÌÆÄɵÂÌØÀÊÆÕÐÕÃûµÄÀο¿ÃÜÂë¡£¡£¡£¡£¡£Proofpoint·¢Ã÷DTPacker·Ö·¢Á˶à¸öRATºÍÐÅÏ¢ÇÔÈ¡³ÌÐò£¬£¬£¬£¬£¬°üÀ¨Agent Tesla¡¢Ave Maria¡¢AsyncRATºÍFormBook£¬£¬£¬£¬£¬²¢Ê¹ÓöàÖÖ»ìÏýÊÖÒÕÀ´Èƹýɱ¶¾Èí¼þ¡¢É³ºÐºÍÊÖÒÕÆÊÎö¡£¡£¡£¡£¡£×Ô2020ÄêÒÔÀ´£¬£¬£¬£¬£¬DTPackerÓëÊýÊ®´Î¹¥»÷»î¶¯ºÍ¶à¸ö¹¥»÷ÍÅ»ïÏà¹Ø£¬£¬£¬£¬£¬ÆäÖаüÀ¨TA2536ºÍTA2715¡£¡£¡£¡£¡£


https://www.proofpoint.com/us/blog/threat-insight/dtpacker-net-packer-curious-password-1


Çå¾²¹¤¾ß


Yasso


ËѼ¯ÁËÐí¶àÊÊÓù¦Ð§£¬£¬£¬£¬£¬×÷Ϊ Intranet ¸¨ÖúÉøÍ¸¹¤¾ß¼¯Ðû²¼¡£¡£¡£¡£¡£


https://securityonline.info/yasso-intranet-assisted-penetration-toolset/


darvester


PoC Discord Óû§ºÍ¹«»áÐÅÏ¢ÍøÂ繤¾ß¡£¡£¡£¡£¡£


https://github.com/V3ntus/darvester


chronorace


¿ÉÒÔ׼ȷµØÖ´ÐÐ׼ʱ¾ºÕùÌõ¼þÒÔ¹æ±ÜÓ¦ÓóÌÐòÓªÒµÂß¼­µÄ¹¤¾ß¡£¡£¡£¡£¡£


https://github.com/Cache-Money/chronorace


dep-scan


ÍêÈ«¿ªÔ´µÄÇå¾²É󼯹¤¾ß£¬£¬£¬£¬£¬ÓÃÓÚ»ùÓÚÒÑÖªÎó²î¡¢½¨æÅºÍÔÊÐíÏÞÖÆµÄÏîÄ¿ÒÀÀµ¹ØÏµ¡£¡£¡£¡£¡£


https://github.com/AppThreat/dep-scan


Http Desync Guardian


ÆÊÎö HTTP ÇëÇóÒÔ×îС»¯ HTTP Òì²½¹¥»÷µÄΣº¦¡£¡£¡£¡£¡£


https://github.com/aws/http-desync-guardian


Çå¾²ÆÊÎö


Ó¢¹úNCSCÐû²¼ÓÃÀ´²éÕÒϵͳÖÐδÐÞ¸´Îó²îµÄNmap¾ç±¾


https://securityaffairs.co/wordpress/127181/hacking/uk-ncsc-scanning-made-easy-sme.html


Windows 11 KB5008353 ÀÛ»ý¸üÐÂÔ¤ÀÀÐû²¼


https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5008353-cumulative-update-preview-released/


VMware£ºÐÞ²¹ Horizon ЧÀÍÆ÷ÒÔµÖÓùÕýÔÚ¾ÙÐÐµÄ Log4j ¹¥»÷


https://www.bleepingcomputer.com/news/security/vmware-patch-horizon-servers-against-ongoing-log4j-attacks/


¶íÂÞ˹¾Ð²¶ºÚ¿Í×éÖ¯Infraud OrganizationµÄ³ÉÔ±


https://www.bleepingcomputer.com/news/security/russia-arrests-leader-of-infraud-organization-hacker-group/


ÐÂÄ«Î÷¸çÖÝÌá½»ÍøÂçÇå¾²·¨°¸


https://www.infosecurity-magazine.com/news/new-mexico-files-cybersecurity/


2021 ÄêÊ®´óÀÕË÷Èí¼þ¹¥»÷


https://www.cybereason.com/blog/ten-of-the-biggest-ransomware-attacks-of-2021