ʹÓÃGoogle Play·Ö·¢µÄÐÂľÂíXenomorphÕë¶ÔÅ·ÖÞµØÇø

Ðû²¼Ê±¼ä 2022-02-24

ʹÓÃGoogle Play·Ö·¢µÄÐÂľÂíXenomorphÕë¶ÔÅ·ÖÞµØÇø


¾ÝýÌå2ÔÂ21ÈÕ±¨µÀ£¬£¬£¬£¬£¬Çå¾²¹«Ë¾ThreatFabric·¢Ã÷ÁËеÄAndroidÒøÐÐľÂíXenomorph ¡£¡£¡£¡£¸ÃľÂíαװ³ÉÐÔÄÜÌáÉýÓ¦ÓóÌÐò£¨ÀýÈçFast Cleaner£©Í¨¹ýGoogle PlayÊÐËÁ·Ö·¢£¬£¬£¬£¬£¬Òѱ»×°ÖÃÁè¼Ý50000´Î ¡£¡£¡£¡£ËüÏÖÔÚÈÔ´¦ÓÚÔçÆÚ¿ª·¢½×¶Î£¬£¬£¬£¬£¬Ä¿µÄÊÇÎ÷°àÑÀ¡¢ÆÏÌÑÑÀ¡¢Òâ´óÀûºÍ±ÈÀûʱµÈÅ·ÖÞ¹ú¼ÒµÄ56¼Ò½ðÈÚ»ú¹¹ ¡£¡£¡£¡£Ñо¿Ö°Ô±»¹·¢Ã÷¸ÃľÂíµÄ´úÂëÓëAlienÓÐËùÖØµþ£¬£¬£¬£¬£¬ÕâÅú×¢¶þÕß±£´æÄ³ÖÖÁªÏµ£ºÒªÃ´XenomorphÊÇAlienµÄ¼ÌÈÎÕߣ¬£¬£¬£¬£¬ÒªÃ´XenomorphµÄ¿ª·¢Ö°Ô±Ò»Ö±ÔÚÑо¿Alien ¡£¡£¡£¡£


https://thehackernews.com/2022/02/xenomorph-android-banking.html


ÃÀ¹úMeyerÔâµ½ContiÀÕË÷¹¥»÷µ¼Ö´ó×ÚÔ±¹¤ÐÅϢй¶


¾Ý2ÔÂ21ÈÕ±¨µÀ£¬£¬£¬£¬£¬ÃÀ¹ú×î´óµÄ´¶¾ß¹«Ë¾MeyerÔâµ½ContiÀÕË÷¹¥»÷ ¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚ2021Äê10ÔÂ25ÈÕ£¬£¬£¬£¬£¬¼ì²âµ½¹¥»÷ºó¸Ã¹«Ë¾Á¬Ã¦Õö¿ªÊӲ죬£¬£¬£¬£¬²¢ÓÚ12ÔÂ1ÈÕÈ·¶¨MeyerÔ±¹¤µÄÐÅÏ¢¿ÉÄÜÒÑÔ⵽δ¾­ÊÚȨµÄ»á¼û ¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚContiµÄÐÅÏ¢Ð¹Â¶ÍøÕ¾·¢Ã÷Ò»¸ö¿É×·Ëݵ½11ÔÂ7ÈÕµÄÁбí£¬£¬£¬£¬£¬¾Ý³Æ°üÀ¨ÁËÔÚMeyerÇÔÈ¡µÄ2%µÄÊý¾Ý£¬£¬£¬£¬£¬µ«ÖÁ½ñÈÔδÐû²¼Ê£ÓàµÄ98% ¡£¡£¡£¡£MeyerÌåÏÖ½«ÎªÊÜÓ°ÏìµÄÔ±¹¤¼°Æä¾ìÊôÌṩÁ½ÄêµÄÉí·Ý±£»£»£»¤Ð§ÀÍ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/cookware-giant-meyer-discloses-cyberattack-that-impacted-employees/


Ahn Lab·¢Ã÷CryptBotбäÌåʹÓõÁ°æÈí¼þÍøÕ¾Èö²¥


Ahn LabÔÚ2ÔÂ21ÈÕÐû²¼µÄÑо¿ÏÔʾ£¬£¬£¬£¬£¬CryptBotбäÌåÕýÔÚͨ¹ýµÁ°æÈí¼þÍøÕ¾¾ÙÐÐÈö²¥ ¡£¡£¡£¡£CryptBotÊÇÒ»ÖÖWindowsÐÅÏ¢ÇÔÈ¡³ÌÐò£¬£¬£¬£¬£¬¿É´ÓÄ¿µÄÇÔÈ¡ä¯ÀÀÆ÷ƾ֤¡¢cookie¡¢¼ÓÃÜÇ®±ÒÇ®°üºÍÐÅÓÿ¨µÈÐÅÏ¢ ¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÆÆ½âÈí¼þºÍÃÜÔ¿ÌìÉúÆ÷µÈÍøÕ¾·Ö·¢¶ñÒâÈí¼þ£¬£¬£¬£¬£¬²¢Í¨¹ýËÑË÷ÒýÇæÓÅ»¯½«ÕâÐ©ÍøÕ¾ÔڹȸèµÄËÑË÷Ч¹ûÖÐÖö¥ ¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬¸Ã°æ±¾±ÈÒÔÍùÓнϴóµÄ¸Ä¶¯£¬£¬£¬£¬£¬É¾³ýÁË·´É³ºÐ¹¦Ð§ºÍ±¸ÓÃC2µÈÈßÓàµÄ¹¦Ð§£¬£¬£¬£¬£¬²¢ÒÑ¿ÉÊÊÓÃÓÚËùÓÐChrome°æ±¾ ¡£¡£¡£¡£


https://asec.ahnlab.com/en/31802/


KasperskyÐû²¼2021ÄêÒÆ¶¯¶ñÒâÈí¼þÌ¬ÊÆµÄÆÊÎö±¨¸æ


2ÔÂ21ÈÕ£¬£¬£¬£¬£¬KasperskyÐû²¼ÁË2021ÄêÒÆ¶¯¶ñÒâÈí¼þÌ¬ÊÆµÄÆÊÎö±¨¸æ ¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬KasperskyÔÚ2021Äê×ܼƼì²âµ½3464756¸ö¶ñÒâ×°Öðü¡¢97661¸öеÄÒÆ¶¯ÒøÐÐľÂíºÍ17372¸öеÄÒÆ¶¯ÀÕË÷Èí¼þ ¡£¡£¡£¡£ÊÜÒÆ¶¯¶ñÒâÈí¼þ¹¥»÷×î¶àµÄ¹ú¼ÒÊÇÒÁÀÊ£¬£¬£¬£¬£¬Æä´ÎÊÇÖйú¡¢É³Ìذ¢À­²®ºÍ°¢¶û¼°ÀûÑÇ ¡£¡£¡£¡£¼ì²âµ½µÄ¶ñÒâÈí¼þÖÐ¹ã¸æÈí¼þ£¨42.42%£©µÄÕ¼±È×î´ó£¬£¬£¬£¬£¬Æä´ÎΪRiskToolÓ¦ÓóÌÐò£¨35.27%£©ºÍľÂí£¨8.86%£© ¡£¡£¡£¡£


https://securelist.com/mobile-malware-evolution-2021/105876/


Trend MicroÅû¶ÐµÄMac¶ñÒâÍÚ¿óÈí¼þµÄÊÖÒÕϸ½Ú


Trend MicroÔÚ2ÔÂ21ÈÕÅû¶ÁËÐÂMac¶ñÒâÍÚ¿óÈí¼þµÄÊÖÒÕϸ½Ú ¡£¡£¡£¡£¶ñÒâÈí¼þÑù±¾±»¼ì²âΪCoinminer.MacOS.MALXMR.H£¬£¬£¬£¬£¬ÓÚ2022Äê1Ô³õÊ״α»·¢Ã÷£¬£¬£¬£¬£¬ÊÇÒ»¸öMach-OÎļþ ¡£¡£¡£¡£Ö´ÐÐʱ£¬£¬£¬£¬£¬ËüʹÓÃAuthorizationExecuteWithPrivileges APIͨ¹ýÌáÐÑÓû§ÊäÈëÆ¾Ö¤À´ÌáÉýȨÏÞ ¡£¡£¡£¡£³ý´ËÖ®Í⣬£¬£¬£¬£¬¸ÃÑù±¾»¹Ê¹ÓÃÁËi2pd£¨ÓÖÃûI2PÊØ»¤³ÌÐò£©À´Òþ²ØÆäÍøÂçÁ÷Á¿£¬£¬£¬£¬£¬¶øÆäËüMac¶ñÒâÈí¼þͨ³£Ê¹ÓÃTor ¡£¡£¡£¡£


https://www.trendmicro.com/en_us/research/22/b/latest-mac-coinminer-utilizes-open-source-binaries-and-the-i2p-network.html


Ñо¿ÍŶӷ¢Ã÷Õë¶ÔMicrosoft SQLÊý¾Ý¿âµÄ¹¥»÷»î¶¯


ýÌå2ÔÂ21Èճƣ¬£¬£¬£¬£¬Ñо¿ÍŶӷ¢Ã÷ÁËÕë¶ÔMicrosoft SQLÊý¾Ý¿âµÄ¹¥»÷»î¶¯ ¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏÈɨÃèTCP¶Ë¿Ú1433¿ª·ÅµÄЧÀÍ£¬£¬£¬£¬£¬È»ºóͨ¹ý±©Á¦ÆÆ½âºÍ×ֵ乥»÷À´ÆÆ½âÃÜÂë ¡£¡£¡£¡£Ò»µ©»ñµÃÖÎÀíÔ±ÕÊ»§µÄ»á¼ûȨÏÞ£¬£¬£¬£¬£¬¹¥»÷Õ߾ͻáÁ¬Ã¦×°ÖÃLemon Duck¡¢KingMinerºÍVollgarµÈ¶ñÒâ¿ó¹¤Èí¼þ ¡£¡£¡£¡£×îºó£¬£¬£¬£¬£¬ËûÃÇ»¹»áʹÓÃCobalt StrikeÔÚÊý¾Ý¿âÖн¨ÉèºóÃÅ£¬£¬£¬£¬£¬ÒÔ¼á³Ö³¤ÆÚÐÔ²¢¾ÙÐкáÏòÒÆ¶¯ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/vulnerable-microsoft-sql-servers-targeted-with-cobalt-strike/



Çå¾²¹¤¾ß


coraza


golang ÆóÒµ¼¶ Web Ó¦Ó÷À»ðǽ¿ò¼Ü£¬£¬£¬£¬£¬Ö§³Ö Modsecurity µÄ seclang ÓïÑÔ£¬£¬£¬£¬£¬Óë OWASP Core Ruleset 100% ¼æÈÝ ¡£¡£¡£¡£


https://github.com/corazawaf/coraza


m3


ÒÆ¶¯¶ñÒâÈí¼þÄ£Äâ¿ò¼Ü£¨¼ò³Æm3£©ÊÇÒ»¸ö¼òÆÓÇÒ¿ÉÀ©Õ¹µÄ Android »úеÈËÄ£Äâ¿ò¼Ü ¡£¡£¡£¡£


https://github.com/ThisIsLibra/m3/


SecureBank


°üÀ¨ËùÓÐ OWASP TOP 10 Çå¾²Îó²îµÄ½ðÈڿƼ¼Ó¦ÓóÌÐò ¡£¡£¡£¡£


https://ssrd.gitbook.io/securebank/


Talisman 


¿É½«hook×°Öõ½´æ´¢¿â£¬£¬£¬£¬£¬ÒÔÈ·±£Ç±ÔÚµÄÃô¸ÐÐÅÏ¢²»»áÍÑÀ뿪·¢Ö°Ô±µÄÊÂÇéÕ¾ ¡£¡£¡£¡£


https://github.com/thoughtworks/talisman#what-is-talisman


SharpCookieMonster


cookie-crimesÄ£¿£¿ £¿ £¿£¿£¿éµÄÒ»¸ö Sharp ¶Ë¿Ú£¬£¬£¬£¬£¬Õâ¸ö C# ÏîÄ¿½«ÎªËùÓÐÕ¾µãת´¢ cookie ¡£¡£¡£¡£


https://github.com/m0rv4i/SharpCookieMonster



Çå¾²ÆÊÎö


ÕûÊýÒç³ö£ºËüÊÇÔõÑù±¬·¢µÄÒÔ¼°ÔõÑùÔ¤·À


https://www.welivesecurity.com/2022/02/21/integer-overflow-how-it-occur-can-be-prevented/


¹¥»÷ÕßʹÓÃSMS PVA ЧÀ;ÙÐжñÒâ»î¶¯


https://securityaffairs.co/wordpress/128242/cyber-crime/sms-pva-services.html


ÆÏÌÑÑÀÍþв±¨¸æ£º2021 ÄêµÚËÄÐò¶È


https://seguranca-informatica.pt/threat-report-portugal-q3-2021/


΢Èí¸üÐÂÁË Your Phone Ó¦ÓóÌÐòµÄÒ»Ïîй¦Ð§


https://news.softpedia.com/news/microsoft-announces-a-new-feature-for-the-your-phone-app-534911.shtml


CVE-2022-0290£ºChrome RenderFrameHostImplÊͷźóʹÓÃÎó²î


https://packetstormsecurity.com/files/166080/GS20220221155706.tgz