CleafyÔÚGoogle Play·¢Ã÷αװ³É¶þάÂëÓ¦ÓõÄTeaBot

Ðû²¼Ê±¼ä 2022-03-04

CleafyÔÚGoogle Play·¢Ã÷αװ³É¶þάÂëÓ¦ÓõÄTeaBot


3ÔÂ1ÈÕ£¬£¬£¬£¬£¬£¬£¬CleafyÐû²¼±¨¸æ³ÆÆäÔÚGoogle PlayÊÐËÁÖз¢Ã÷ÁËÒøÐÐľÂíTeaBot¡£¡£ ¡£¡£¡£¸ÃľÂíαװ³É¶þάÂëÓ¦Óá°QR Code & Barcode ¨C Scanner¡±£¬£¬£¬£¬£¬£¬£¬Òѱ»ÏÂÔØÁè¼Ý10000´Î¡£¡£ ¡£¡£¡£Óë֮ǰ²î±ðµÄÊÇ£¬£¬£¬£¬£¬£¬£¬¸Ã±äÌåÕë¶ÔµÄÄ¿µÄÓ¦ÓÃÖÖÀàÔöÌí£¬£¬£¬£¬£¬£¬£¬ÏÖÒÑϯ¾íÁ˼ÒÍ¥ÒøÐÐÓ¦Óᢰü¹ÜÓ¦ÓúͼÓÃÜÇ®°üµÈÓ¦Óᣡ£ ¡£¡£¡£ÔÚ²»µ½Ò»ÄêµÄʱ¼äÀ£¬£¬£¬£¬£¬£¬TeaBotÕë¶ÔÄ¿µÄµÄÊýÄ¿ÔöÌíÁË500%ÒÔÉÏ£¬£¬£¬£¬£¬£¬£¬´Ó60¸öÔöÌíµ½400¶à¸ö¡£¡£ ¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬TeaBotÖ÷ÒªÃÀ¹úÓû§£¬£¬£¬£¬£¬£¬£¬½üÆÚ»¹ÐÂÔöÁ˶íÓ˹Âå·¥¿ËÓïºÍÖÐÎİ汾£¬£¬£¬£¬£¬£¬£¬ÕâÅú×¢¸Ã¶ñÒâÈí¼þÕýÔÚÃé׼ȫÇò¡£¡£ ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/teabot-malware-slips-back-into-google-play-store-to-target-us-users/


CloudSEK³ÆÕë¶ÔÓ¡¶ÈµÄ´¹ÂÚ¹¥»÷ÒÑÔì³ÉÉϰÙÍòÃÀÔªËðʧ


ÐÂ¼ÓÆÂÇå¾²¹«Ë¾CloudSEKÔÚ3ÔÂ1ÈÕÅû¶ÁËÕë¶ÔÓ¡¶ÈµÄ´¹ÂÚ¹¥»÷µÄϸ½ÚÐÅÏ¢¡£¡£ ¡£¡£¡£´Ë´Î¹¥»÷»î¶¯Éæ¼°200¶à¸ö´¹ÂÚÍøÕ¾£¬£¬£¬£¬£¬£¬£¬ÒԵ綯Æû³µÎªÓÕ¶ü£¬£¬£¬£¬£¬£¬£¬ÒÑÔì³É¸ß´ï1000000ÃÀÔªµÄËðʧ¡£¡£ ¡£¡£¡£Ó¡¶ÈÕþ¸®×î½üÍÆ³öÁËÐÂÕþ²ß£¬£¬£¬£¬£¬£¬£¬ÒÔÔö½ø¸Ã¹úµç¶¯Æû³µ£¨EV£©ÐÐÒµµÄÔöÌí¡£¡£ ¡£¡£¡£¹¥»÷Õßͨ¹ýʹÓÃGoogle Ads¡¢Ê¹ÓÃÏà¹ØÒªº¦×ÖÒÔ¼°Ä£ÄâRevoltºÍAtherµÈÆ·ÅÆÀ´ÓÕʹĿµÄ½øÈë´¹ÂÚÍøÕ¾£¬£¬£¬£¬£¬£¬£¬È»ºóÒªÇóËûÃÇÊäÈëСÎÒ˽¼ÒºÍÒøÐп¨ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬×îÖÕÇÔȡĿµÄµÄÕË»§×ʽ𡣡£ ¡£¡£¡£


https://cloudsek.com/whitepapers_reports/unearthing-the-million-dollar-scams-targeting-the-indian-electric-vehicle-industry-scams/


Malwarebytes·¢Ã÷Ö¼ÔÚÇÔȡ΢ÈíÓû§Æ¾Ö¤µÄ´¹Âڻ


3ÔÂ1ÈÕ£¬£¬£¬£¬£¬£¬£¬MalwarebytesÐû²¼Ò»·Ý±¨¸æ£¬£¬£¬£¬£¬£¬£¬ÏêÊöÁËÕë¶ÔMicrosoftÕÊ»§µÄ´¹Âڻ¡£¡£ ¡£¡£¡£¸Ã»î¶¯ÒÔ¡°MicrosoftÕÊ»§Òì³£µÇ¼»î¶¯¡±ÎªÖ÷Ì⣬£¬£¬£¬£¬£¬£¬Éù³Æ¼ì²âµ½À´×Ô¶íÂÞ˹/Ī˹¿ÆµÄÓû§¸Õ¸ÕÖØÐÂ×°±¸µÇ¼ÕÊ»§¡£¡£ ¡£¡£¡£µ±ÊÕ¼þÈ˵ã»÷´¹ÂÚÓʼþÖеġ°±¨¸æÓû§¡±ºó£¬£¬£¬£¬£¬£¬£¬±ã»áÏò¹¥»÷Õß·¢ËÍÒ»·â°üÀ¨Ô¤Ìî³äÐÂÎŵÄÓʼþ£¬£¬£¬£¬£¬£¬£¬Ö®ºó¿ÉÄܻᱻҪÇóÊäÈëµÇ¼ƾ֤ºÍÒøÐÐÐÅÏ¢µÈ¡£¡£ ¡£¡£¡£


https://blog.malwarebytes.com/scams/2022/03/unusual-sign-in-activity-mail-goes-phishing-for-microsoft-account-holders/


JFrogÐû²¼¹ØÓÚ¿ªÔ´¿âPJSIPÖÐ5¸öÄÚ´æËð»µÎó²îµÄ±¨¸æ


JFrogÔÚ3ÔÂ1ÈÕÐû²¼Á˹ØÓÚPJSIPÖÐ5¸öÄÚ´æËð»µÎó²îµÄ±¨¸æ¡£¡£ ¡£¡£¡£PJSIPÊÇÒ»¸ö¿ªÔ´¶àýÌåͨѶ¿â£¬£¬£¬£¬£¬£¬£¬ÌṩÁËIPµç»°Ó¦ÓÃʹÓõÄAPI¡£¡£ ¡£¡£¡£Îó²î°üÀ¨¿Éµ¼ÖµĴúÂëÖ´ÐеĿÍÕ»Òç³öÎó²î£¨CVE-2021-43299¡¢CVE-2021-43300ºÍCVE-2021-43301£©£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°¿Éµ¼Ö¾ܾøÐ§À͵ÄÔ½½ç¶ÁÈ¡Îó²î£¨CVE-2021-43302£©»ººÍ³åÇøÒç³öÎó²î£¨CVE-2021-43303£©¡£¡£ ¡£¡£¡£ÕâЩÎó²îÒÑͨ¹ý2ÔÂ24ÈÕÐû²¼µÄ²¹¶¡ÐÞ¸´¡£¡£ ¡£¡£¡£


https://jfrog.com/blog/jfrog-discloses-5-memory-corruption-vulnerabilities-in-pjsip-a-popular-multimedia-library/


GoogleÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ChromeÖеÄ28¸öÎó²î


GoogleÓÚ3ÔÂ1ÈÕÍÆ³öChrome 99£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁË28¸öÇå¾²Îó²î¡£¡£ ¡£¡£¡£ÆäÖнÏΪÑÏÖØµÄÎó²îÊÇANGLEÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2022-0789£©¡¢Cast UIÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2022-0790£©¡¢¶à¹¦Ð§¿òÖÐÊͷźóʹÓÃÎó²î£¨CVE-2022-0791£©¡¢Blink½á¹¹ÖеÄÀàÐÍ»ìÏýÎó²î£¨CVE-2022-0795£©ºÍANGLEÖÐÔ½½ç¶ÁÈ¡Îó²î£¨CVE-2022-0792£©µÈ¡£¡£ ¡£¡£¡£


https://www.cisa.gov/uscert/ncas/current-activity/2022/03/02/google-releases-security-updates-chrome


ESETÐû²¼IsaacWiperºÍHermeticWizardµÄÆÊÎö±¨¸æ


ESETÔÚ3ÔÂ1ÈÕÐû²¼ÁËIsaacWiperºÍHermeticWizardµÄÆÊÎö±¨¸æ¡£¡£ ¡£¡£¡£IsaacWipeÊÇÒ»¸öеÄWiper£¬£¬£¬£¬£¬£¬£¬±£´æÓÚûÓÐAuthenticodeÊðÃûµÄWindows DLL»òEXEÖУ¬£¬£¬£¬£¬£¬£¬×îÔçµÄPE±àÒëʱ¼ä´ÁÊÇ2021Äê10ÔÂ19¡£¡£ ¡£¡£¡£ÓÚ2ÔÂ24ÈÕÔÚÎÚ¿ËÀ¼Õþ¸®»ú¹¹µÄÍøÂçÖб»·¢Ã÷£¬£¬£¬£¬£¬£¬£¬ÉÐδȷ¶¨ÊÇ·ñÓëHermeticWiperÓйØÁª¡£¡£ ¡£¡£¡£HermeticWizardÊÇ×Ô½ç˵È䳿£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚͨ¹ýWMIºÍSMBÔÚÍâµØÍøÂçÖÐÈö²¥HermeticWiper¡£¡£ ¡£¡£¡£


https://www.welivesecurity.com/2022/03/01/isaacwiper-hermeticwizard-wiper-worm-targeting-ukraine/



Çå¾²¹¤¾ß


Searpy


ËÑË÷¹¤¾ß£¬£¬£¬£¬£¬£¬£¬¿ÉÓÃÓÚÊÕÂÞºÍËÝÔ´£¬£¬£¬£¬£¬£¬£¬Ö§³Öpy2ºÍpy3¡£¡£ ¡£¡£¡£


https://github.com/j3ers3/Searpy


CAPEv2


ÊÇÒ»¸ö¶ñÒâÈí¼þɳÏ䣬£¬£¬£¬£¬£¬£¬´Óí§Òâ¶ñÒâÈí¼þ¼Ò×åÖÐÌáÈ¡ÉèÖûò½âѹpayload¡£¡£ ¡£¡£¡£


https://github.com/kevoreilly/CAPEv2


S1EM


S1EM ÊÇÒ»¸ö´øÓÐ SIRP ºÍ Threat Intel µÄ SIEM£¬£¬£¬£¬£¬£¬£¬Ò»¸öÍêÕûµÄÊý¾Ý°ü²¶»ñ£¬£¬£¬£¬£¬£¬£¬¶àºÏÒ»¡£¡£ ¡£¡£¡£


https://github.com/V1D1AN/S1EM


WMEye


ΪʹÓà WMI ºÍÔ¶³Ì MSBuild Ö´ÐÐÖ´ÐкáÏòÒÆ¶¯¶ø¿ª·¢µÄʵÑéÐÔ¹¤¾ß¡£¡£ ¡£¡£¡£


https://github.com/pwn1sher/WMEye



Çå¾²ÆÊÎö


Æ»¹ûÐû²¼ iOS 15.4 Beta 5


https://news.softpedia.com/news/apple-releases-ios-15-4-beta-5-534963.shtml


΢ÈíΪÖÐСÆóÒµÍÆ³öеĶ˵ãÇå¾²½â¾ö¼Æ»®


https://www.bleepingcomputer.com/news/microsoft/microsoft-rolling-out-new-endpoint-security-solution-for-smbs/


ASEC·¢Ã÷αװ³ÉMSIµÄMagniber·Ö·¢»î¶¯


https://asec.ahnlab.com/en/32226/


΢Èí£ºLSASSÍ߽⵼ÖÂWindowsÓò¿ØÖÆÖØÊÓÆô


https://www.bleepingcomputer.com/news/microsoft/microsoft-windows-domain-controller-restarts-caused-by-lsass-crashes/


Reality Winner µÄ Twitter ÕË»§±»ºÚ¿Í¹¥»÷ÒÔÕë¶Ô¼ÇÕß


https://www.bleepingcomputer.com/news/security/reality-winners-twitter-account-was-hacked-to-target-journalists/


VoIPmonitor ¼à¿ØÈí¼þÖз¢Ã÷µÄÑÏÖØÇå¾²Îó²î


https://thehackernews.com/2022/03/critical-security-bugs-uncovered-in.html