ʹÓÃGoogle Play·Ö·¢µÄÐÂľÂíXenomorphÕë¶ÔÅ·ÖÞµØÇø
Ðû²¼Ê±¼ä 2022-02-24ʹÓÃGoogle Play·Ö·¢µÄÐÂľÂíXenomorphÕë¶ÔÅ·ÖÞµØÇø
¾ÝýÌå2ÔÂ21ÈÕ±¨µÀ£¬£¬£¬£¬£¬Çå¾²¹«Ë¾ThreatFabric·¢Ã÷ÁËеÄAndroidÒøÐÐľÂíXenomorph¡£¡£¡£¡£¸ÃľÂíαװ³ÉÐÔÄÜÌáÉýÓ¦ÓóÌÐò£¨ÀýÈçFast Cleaner£©Í¨¹ýGoogle PlayÊÐËÁ·Ö·¢£¬£¬£¬£¬£¬Òѱ»×°ÖÃÁè¼Ý50000´Î¡£¡£¡£¡£ËüÏÖÔÚÈÔ´¦ÓÚÔçÆÚ¿ª·¢½×¶Î£¬£¬£¬£¬£¬Ä¿µÄÊÇÎ÷°àÑÀ¡¢ÆÏÌÑÑÀ¡¢Òâ´óÀûºÍ±ÈÀûʱµÈÅ·ÖÞ¹ú¼ÒµÄ56¼Ò½ðÈÚ»ú¹¹¡£¡£¡£¡£Ñо¿Ö°Ô±»¹·¢Ã÷¸ÃľÂíµÄ´úÂëÓëAlienÓÐËùÖØµþ£¬£¬£¬£¬£¬ÕâÅú×¢¶þÕß±£´æÄ³ÖÖÁªÏµ£ºÒªÃ´XenomorphÊÇAlienµÄ¼ÌÈÎÕߣ¬£¬£¬£¬£¬ÒªÃ´XenomorphµÄ¿ª·¢Ö°Ô±Ò»Ö±ÔÚÑо¿Alien¡£¡£¡£¡£
https://thehackernews.com/2022/02/xenomorph-android-banking.html
ÃÀ¹úMeyerÔâµ½ContiÀÕË÷¹¥»÷µ¼Ö´ó×ÚÔ±¹¤ÐÅϢй¶
¾Ý2ÔÂ21ÈÕ±¨µÀ£¬£¬£¬£¬£¬ÃÀ¹ú×î´óµÄ´¶¾ß¹«Ë¾MeyerÔâµ½ContiÀÕË÷¹¥»÷¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚ2021Äê10ÔÂ25ÈÕ£¬£¬£¬£¬£¬¼ì²âµ½¹¥»÷ºó¸Ã¹«Ë¾Á¬Ã¦Õö¿ªÊӲ죬£¬£¬£¬£¬²¢ÓÚ12ÔÂ1ÈÕÈ·¶¨MeyerÔ±¹¤µÄÐÅÏ¢¿ÉÄÜÒÑÔ⵽δ¾ÊÚȨµÄ»á¼û¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚContiµÄÐÅÏ¢Ð¹Â¶ÍøÕ¾·¢Ã÷Ò»¸ö¿É×·Ëݵ½11ÔÂ7ÈÕµÄÁÐ±í£¬£¬£¬£¬£¬¾Ý³Æ°üÀ¨ÁËÔÚMeyerÇÔÈ¡µÄ2%µÄÊý¾Ý£¬£¬£¬£¬£¬µ«ÖÁ½ñÈÔδÐû²¼Ê£ÓàµÄ98%¡£¡£¡£¡£MeyerÌåÏÖ½«ÎªÊÜÓ°ÏìµÄÔ±¹¤¼°Æä¾ìÊôÌṩÁ½ÄêµÄÉí·Ý±£»£»£»¤Ð§ÀÍ¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/cookware-giant-meyer-discloses-cyberattack-that-impacted-employees/
Ahn Lab·¢Ã÷CryptBotбäÌåʹÓõÁ°æÈí¼þÍøÕ¾Èö²¥
Ahn LabÔÚ2ÔÂ21ÈÕÐû²¼µÄÑо¿ÏÔʾ£¬£¬£¬£¬£¬CryptBotбäÌåÕýÔÚͨ¹ýµÁ°æÈí¼þÍøÕ¾¾ÙÐÐÈö²¥¡£¡£¡£¡£CryptBotÊÇÒ»ÖÖWindowsÐÅÏ¢ÇÔÈ¡³ÌÐò£¬£¬£¬£¬£¬¿É´ÓÄ¿µÄÇÔÈ¡ä¯ÀÀÆ÷ƾ֤¡¢cookie¡¢¼ÓÃÜÇ®±ÒÇ®°üºÍÐÅÓÿ¨µÈÐÅÏ¢¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÆÆ½âÈí¼þºÍÃÜÔ¿ÌìÉúÆ÷µÈÍøÕ¾·Ö·¢¶ñÒâÈí¼þ£¬£¬£¬£¬£¬²¢Í¨¹ýËÑË÷ÒýÇæÓÅ»¯½«ÕâÐ©ÍøÕ¾ÔڹȸèµÄËÑË÷Ч¹ûÖÐÖö¥¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬¸Ã°æ±¾±ÈÒÔÍùÓнϴóµÄ¸Ä¶¯£¬£¬£¬£¬£¬É¾³ýÁË·´É³ºÐ¹¦Ð§ºÍ±¸ÓÃC2µÈÈßÓàµÄ¹¦Ð§£¬£¬£¬£¬£¬²¢ÒÑ¿ÉÊÊÓÃÓÚËùÓÐChrome°æ±¾¡£¡£¡£¡£
https://asec.ahnlab.com/en/31802/
KasperskyÐû²¼2021ÄêÒÆ¶¯¶ñÒâÈí¼þÌ¬ÊÆµÄÆÊÎö±¨¸æ
2ÔÂ21ÈÕ£¬£¬£¬£¬£¬KasperskyÐû²¼ÁË2021ÄêÒÆ¶¯¶ñÒâÈí¼þÌ¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬KasperskyÔÚ2021Äê×ܼƼì²âµ½3464756¸ö¶ñÒâ×°Öðü¡¢97661¸öеÄÒÆ¶¯ÒøÐÐľÂíºÍ17372¸öеÄÒÆ¶¯ÀÕË÷Èí¼þ¡£¡£¡£¡£ÊÜÒÆ¶¯¶ñÒâÈí¼þ¹¥»÷×î¶àµÄ¹ú¼ÒÊÇÒÁÀÊ£¬£¬£¬£¬£¬Æä´ÎÊÇÖйú¡¢É³Ìذ¢À²®ºÍ°¢¶û¼°ÀûÑÇ¡£¡£¡£¡£¼ì²âµ½µÄ¶ñÒâÈí¼þÖÐ¹ã¸æÈí¼þ£¨42.42%£©µÄÕ¼±È×î´ó£¬£¬£¬£¬£¬Æä´ÎΪRiskToolÓ¦ÓóÌÐò£¨35.27%£©ºÍľÂí£¨8.86%£©¡£¡£¡£¡£
https://securelist.com/mobile-malware-evolution-2021/105876/
Trend MicroÅû¶ÐµÄMac¶ñÒâÍÚ¿óÈí¼þµÄÊÖÒÕϸ½Ú
Trend MicroÔÚ2ÔÂ21ÈÕÅû¶ÁËÐÂMac¶ñÒâÍÚ¿óÈí¼þµÄÊÖÒÕϸ½Ú¡£¡£¡£¡£¶ñÒâÈí¼þÑù±¾±»¼ì²âΪCoinminer.MacOS.MALXMR.H£¬£¬£¬£¬£¬ÓÚ2022Äê1Ô³õÊ״α»·¢Ã÷£¬£¬£¬£¬£¬ÊÇÒ»¸öMach-OÎļþ¡£¡£¡£¡£Ö´ÐÐʱ£¬£¬£¬£¬£¬ËüʹÓÃAuthorizationExecuteWithPrivileges APIͨ¹ýÌáÐÑÓû§ÊäÈëÆ¾Ö¤À´ÌáÉýȨÏÞ¡£¡£¡£¡£³ý´ËÖ®Í⣬£¬£¬£¬£¬¸ÃÑù±¾»¹Ê¹ÓÃÁËi2pd£¨ÓÖÃûI2PÊØ»¤³ÌÐò£©À´Òþ²ØÆäÍøÂçÁ÷Á¿£¬£¬£¬£¬£¬¶øÆäËüMac¶ñÒâÈí¼þͨ³£Ê¹ÓÃTor¡£¡£¡£¡£
https://www.trendmicro.com/en_us/research/22/b/latest-mac-coinminer-utilizes-open-source-binaries-and-the-i2p-network.html
Ñо¿ÍŶӷ¢Ã÷Õë¶ÔMicrosoft SQLÊý¾Ý¿âµÄ¹¥»÷»î¶¯
ýÌå2ÔÂ21Èճƣ¬£¬£¬£¬£¬Ñо¿ÍŶӷ¢Ã÷ÁËÕë¶ÔMicrosoft SQLÊý¾Ý¿âµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏÈɨÃèTCP¶Ë¿Ú1433¿ª·ÅµÄЧÀÍ£¬£¬£¬£¬£¬È»ºóͨ¹ý±©Á¦ÆÆ½âºÍ×ֵ乥»÷À´ÆÆ½âÃÜÂë¡£¡£¡£¡£Ò»µ©»ñµÃÖÎÀíÔ±ÕÊ»§µÄ»á¼ûȨÏÞ£¬£¬£¬£¬£¬¹¥»÷Õ߾ͻáÁ¬Ã¦×°ÖÃLemon Duck¡¢KingMinerºÍVollgarµÈ¶ñÒâ¿ó¹¤Èí¼þ¡£¡£¡£¡£×îºó£¬£¬£¬£¬£¬ËûÃÇ»¹»áʹÓÃCobalt StrikeÔÚÊý¾Ý¿âÖн¨ÉèºóÃÅ£¬£¬£¬£¬£¬ÒÔ¼á³Ö³¤ÆÚÐÔ²¢¾ÙÐкáÏòÒÆ¶¯¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/vulnerable-microsoft-sql-servers-targeted-with-cobalt-strike/
Çå¾²¹¤¾ß
coraza
golang ÆóÒµ¼¶ Web Ó¦Ó÷À»ðǽ¿ò¼Ü£¬£¬£¬£¬£¬Ö§³Ö Modsecurity µÄ seclang ÓïÑÔ£¬£¬£¬£¬£¬Óë OWASP Core Ruleset 100% ¼æÈÝ¡£¡£¡£¡£
https://github.com/corazawaf/coraza
m3
ÒÆ¶¯¶ñÒâÈí¼þÄ£Äâ¿ò¼Ü£¨¼ò³Æm3£©ÊÇÒ»¸ö¼òÆÓÇÒ¿ÉÀ©Õ¹µÄ Android »úеÈËÄ£Äâ¿ò¼Ü¡£¡£¡£¡£
https://github.com/ThisIsLibra/m3/
SecureBank
°üÀ¨ËùÓÐ OWASP TOP 10 Çå¾²Îó²îµÄ½ðÈڿƼ¼Ó¦ÓóÌÐò¡£¡£¡£¡£
https://ssrd.gitbook.io/securebank/
Talisman
¿É½«hook×°Öõ½´æ´¢¿â£¬£¬£¬£¬£¬ÒÔÈ·±£Ç±ÔÚµÄÃô¸ÐÐÅÏ¢²»»áÍÑÀ뿪·¢Ö°Ô±µÄÊÂÇéÕ¾¡£¡£¡£¡£
https://github.com/thoughtworks/talisman#what-is-talisman
SharpCookieMonster
cookie-crimesÄ£¿£¿£¿£¿£¿£¿éµÄÒ»¸ö Sharp ¶Ë¿Ú£¬£¬£¬£¬£¬Õâ¸ö C# ÏîÄ¿½«ÎªËùÓÐÕ¾µãת´¢ cookie¡£¡£¡£¡£
https://github.com/m0rv4i/SharpCookieMonster
Çå¾²ÆÊÎö
ÕûÊýÒç³ö£ºËüÊÇÔõÑù±¬·¢µÄÒÔ¼°ÔõÑùÔ¤·À
https://www.welivesecurity.com/2022/02/21/integer-overflow-how-it-occur-can-be-prevented/
¹¥»÷ÕßʹÓÃSMS PVA ЧÀ;ÙÐжñÒâ»î¶¯
https://securityaffairs.co/wordpress/128242/cyber-crime/sms-pva-services.html
ÆÏÌÑÑÀÍþв±¨¸æ£º2021 ÄêµÚËÄÐò¶È
https://seguranca-informatica.pt/threat-report-portugal-q3-2021/
΢Èí¸üÐÂÁË Your Phone Ó¦ÓóÌÐòµÄÒ»Ïîй¦Ð§
https://news.softpedia.com/news/microsoft-announces-a-new-feature-for-the-your-phone-app-534911.shtml
CVE-2022-0290£ºChrome RenderFrameHostImplÊͷźóʹÓÃÎó²î
https://packetstormsecurity.com/files/166080/GS20220221155706.tgz