CleafyÔÚGoogle Play·¢Ã÷αװ³É¶þάÂëÓ¦ÓõÄTeaBot
Ðû²¼Ê±¼ä 2022-03-04CleafyÔÚGoogle Play·¢Ã÷αװ³É¶þάÂëÓ¦ÓõÄTeaBot
3ÔÂ1ÈÕ£¬£¬£¬£¬£¬CleafyÐû²¼±¨¸æ³ÆÆäÔÚGoogle PlayÊÐËÁÖз¢Ã÷ÁËÒøÐÐľÂíTeaBot¡£¡£¡£¡£¡£¸ÃľÂíαװ³É¶þάÂëÓ¦Óá°QR Code & Barcode ¨C Scanner¡±£¬£¬£¬£¬£¬Òѱ»ÏÂÔØÁè¼Ý10000´Î¡£¡£¡£¡£¡£Óë֮ǰ²î±ðµÄÊÇ£¬£¬£¬£¬£¬¸Ã±äÌåÕë¶ÔµÄÄ¿µÄÓ¦ÓÃÖÖÀàÔöÌí£¬£¬£¬£¬£¬ÏÖÒÑϯ¾íÁ˼ÒÍ¥ÒøÐÐÓ¦Óᢰü¹ÜÓ¦ÓúͼÓÃÜÇ®°üµÈÓ¦Óᣡ£¡£¡£¡£ÔÚ²»µ½Ò»ÄêµÄʱ¼äÀ£¬£¬£¬£¬TeaBotÕë¶ÔÄ¿µÄµÄÊýÄ¿ÔöÌíÁË500%ÒÔÉÏ£¬£¬£¬£¬£¬´Ó60¸öÔöÌíµ½400¶à¸ö¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬TeaBotÖ÷ÒªÃÀ¹úÓû§£¬£¬£¬£¬£¬½üÆÚ»¹ÐÂÔöÁ˶íÓ˹Âå·¥¿ËÓïºÍÖÐÎİ汾£¬£¬£¬£¬£¬ÕâÅú×¢¸Ã¶ñÒâÈí¼þÕýÔÚÃé׼ȫÇò¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/teabot-malware-slips-back-into-google-play-store-to-target-us-users/
CloudSEK³ÆÕë¶ÔÓ¡¶ÈµÄ´¹ÂÚ¹¥»÷ÒÑÔì³ÉÉϰÙÍòÃÀÔªËðʧ
ÐÂ¼ÓÆÂÇå¾²¹«Ë¾CloudSEKÔÚ3ÔÂ1ÈÕÅû¶ÁËÕë¶ÔÓ¡¶ÈµÄ´¹ÂÚ¹¥»÷µÄϸ½ÚÐÅÏ¢¡£¡£¡£¡£¡£´Ë´Î¹¥»÷»î¶¯Éæ¼°200¶à¸ö´¹ÂÚÍøÕ¾£¬£¬£¬£¬£¬ÒԵ綯Æû³µÎªÓÕ¶ü£¬£¬£¬£¬£¬ÒÑÔì³É¸ß´ï1000000ÃÀÔªµÄËðʧ¡£¡£¡£¡£¡£Ó¡¶ÈÕþ¸®×î½üÍÆ³öÁËÐÂÕþ²ß£¬£¬£¬£¬£¬ÒÔÔö½ø¸Ã¹úµç¶¯Æû³µ£¨EV£©ÐÐÒµµÄÔöÌí¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýʹÓÃGoogle Ads¡¢Ê¹ÓÃÏà¹ØÒªº¦×ÖÒÔ¼°Ä£ÄâRevoltºÍAtherµÈÆ·ÅÆÀ´ÓÕʹĿµÄ½øÈë´¹ÂÚÍøÕ¾£¬£¬£¬£¬£¬È»ºóÒªÇóËûÃÇÊäÈëСÎÒ˽¼ÒºÍÒøÐп¨ÐÅÏ¢£¬£¬£¬£¬£¬×îÖÕÇÔȡĿµÄµÄÕË»§×ʽ𡣡£¡£¡£¡£
https://cloudsek.com/whitepapers_reports/unearthing-the-million-dollar-scams-targeting-the-indian-electric-vehicle-industry-scams/
Malwarebytes·¢Ã÷Ö¼ÔÚÇÔȡ΢ÈíÓû§Æ¾Ö¤µÄ´¹Âڻ
3ÔÂ1ÈÕ£¬£¬£¬£¬£¬MalwarebytesÐû²¼Ò»·Ý±¨¸æ£¬£¬£¬£¬£¬ÏêÊöÁËÕë¶ÔMicrosoftÕÊ»§µÄ´¹Âڻ¡£¡£¡£¡£¡£¸Ã»î¶¯ÒÔ¡°MicrosoftÕÊ»§Òì³£µÇ¼»î¶¯¡±ÎªÖ÷Ì⣬£¬£¬£¬£¬Éù³Æ¼ì²âµ½À´×Ô¶íÂÞ˹/Ī˹¿ÆµÄÓû§¸Õ¸ÕÖØÐÂ×°±¸µÇ¼ÕÊ»§¡£¡£¡£¡£¡£µ±ÊÕ¼þÈ˵ã»÷´¹ÂÚÓʼþÖеġ°±¨¸æÓû§¡±ºó£¬£¬£¬£¬£¬±ã»áÏò¹¥»÷Õß·¢ËÍÒ»·â°üÀ¨Ô¤Ìî³äÐÂÎŵÄÓʼþ£¬£¬£¬£¬£¬Ö®ºó¿ÉÄܻᱻҪÇóÊäÈëµÇ¼ƾ֤ºÍÒøÐÐÐÅÏ¢µÈ¡£¡£¡£¡£¡£
https://blog.malwarebytes.com/scams/2022/03/unusual-sign-in-activity-mail-goes-phishing-for-microsoft-account-holders/
JFrogÐû²¼¹ØÓÚ¿ªÔ´¿âPJSIPÖÐ5¸öÄÚ´æËð»µÎó²îµÄ±¨¸æ
JFrogÔÚ3ÔÂ1ÈÕÐû²¼Á˹ØÓÚPJSIPÖÐ5¸öÄÚ´æËð»µÎó²îµÄ±¨¸æ¡£¡£¡£¡£¡£PJSIPÊÇÒ»¸ö¿ªÔ´¶àýÌåͨѶ¿â£¬£¬£¬£¬£¬ÌṩÁËIPµç»°Ó¦ÓÃʹÓõÄAPI¡£¡£¡£¡£¡£Îó²î°üÀ¨¿Éµ¼ÖµĴúÂëÖ´ÐеĿÍÕ»Òç³öÎó²î£¨CVE-2021-43299¡¢CVE-2021-43300ºÍCVE-2021-43301£©£¬£¬£¬£¬£¬ÒÔ¼°¿Éµ¼Ö¾ܾøÐ§À͵ÄÔ½½ç¶ÁÈ¡Îó²î£¨CVE-2021-43302£©»ººÍ³åÇøÒç³öÎó²î£¨CVE-2021-43303£©¡£¡£¡£¡£¡£ÕâЩÎó²îÒÑͨ¹ý2ÔÂ24ÈÕÐû²¼µÄ²¹¶¡ÐÞ¸´¡£¡£¡£¡£¡£
https://jfrog.com/blog/jfrog-discloses-5-memory-corruption-vulnerabilities-in-pjsip-a-popular-multimedia-library/
GoogleÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´ChromeÖеÄ28¸öÎó²î
GoogleÓÚ3ÔÂ1ÈÕÍÆ³öChrome 99£¬£¬£¬£¬£¬ÐÞ¸´ÁË28¸öÇå¾²Îó²î¡£¡£¡£¡£¡£ÆäÖнÏΪÑÏÖØµÄÎó²îÊÇANGLEÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2022-0789£©¡¢Cast UIÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2022-0790£©¡¢¶à¹¦Ð§¿òÖÐÊͷźóʹÓÃÎó²î£¨CVE-2022-0791£©¡¢Blink½á¹¹ÖеÄÀàÐÍ»ìÏýÎó²î£¨CVE-2022-0795£©ºÍANGLEÖÐÔ½½ç¶ÁÈ¡Îó²î£¨CVE-2022-0792£©µÈ¡£¡£¡£¡£¡£
https://www.cisa.gov/uscert/ncas/current-activity/2022/03/02/google-releases-security-updates-chrome
ESETÐû²¼IsaacWiperºÍHermeticWizardµÄÆÊÎö±¨¸æ
ESETÔÚ3ÔÂ1ÈÕÐû²¼ÁËIsaacWiperºÍHermeticWizardµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£IsaacWipeÊÇÒ»¸öеÄWiper£¬£¬£¬£¬£¬±£´æÓÚûÓÐAuthenticodeÊðÃûµÄWindows DLL»òEXEÖУ¬£¬£¬£¬£¬×îÔçµÄPE±àÒëʱ¼ä´ÁÊÇ2021Äê10ÔÂ19¡£¡£¡£¡£¡£ÓÚ2ÔÂ24ÈÕÔÚÎÚ¿ËÀ¼Õþ¸®»ú¹¹µÄÍøÂçÖб»·¢Ã÷£¬£¬£¬£¬£¬ÉÐδȷ¶¨ÊÇ·ñÓëHermeticWiperÓйØÁª¡£¡£¡£¡£¡£HermeticWizardÊÇ×Ô½ç˵È䳿£¬£¬£¬£¬£¬ÓÃÓÚͨ¹ýWMIºÍSMBÔÚÍâµØÍøÂçÖÐÈö²¥HermeticWiper¡£¡£¡£¡£¡£
https://www.welivesecurity.com/2022/03/01/isaacwiper-hermeticwizard-wiper-worm-targeting-ukraine/
Çå¾²¹¤¾ß
Searpy
ËÑË÷¹¤¾ß£¬£¬£¬£¬£¬¿ÉÓÃÓÚÊÕÂÞºÍËÝÔ´£¬£¬£¬£¬£¬Ö§³Öpy2ºÍpy3¡£¡£¡£¡£¡£
https://github.com/j3ers3/Searpy
CAPEv2
ÊÇÒ»¸ö¶ñÒâÈí¼þɳÏ䣬£¬£¬£¬£¬´Óí§Òâ¶ñÒâÈí¼þ¼Ò×åÖÐÌáÈ¡ÉèÖûò½âѹpayload¡£¡£¡£¡£¡£
https://github.com/kevoreilly/CAPEv2
S1EM
S1EM ÊÇÒ»¸ö´øÓÐ SIRP ºÍ Threat Intel µÄ SIEM£¬£¬£¬£¬£¬Ò»¸öÍêÕûµÄÊý¾Ý°ü²¶»ñ£¬£¬£¬£¬£¬¶àºÏÒ»¡£¡£¡£¡£¡£
https://github.com/V1D1AN/S1EM
WMEye
ΪʹÓà WMI ºÍÔ¶³Ì MSBuild Ö´ÐÐÖ´ÐкáÏòÒÆ¶¯¶ø¿ª·¢µÄʵÑéÐÔ¹¤¾ß¡£¡£¡£¡£¡£
https://github.com/pwn1sher/WMEye
Çå¾²ÆÊÎö
Æ»¹ûÐû²¼ iOS 15.4 Beta 5
https://news.softpedia.com/news/apple-releases-ios-15-4-beta-5-534963.shtml
΢ÈíΪÖÐСÆóÒµÍÆ³öеĶ˵ãÇå¾²½â¾ö¼Æ»®
https://www.bleepingcomputer.com/news/microsoft/microsoft-rolling-out-new-endpoint-security-solution-for-smbs/
ASEC·¢Ã÷αװ³ÉMSIµÄMagniber·Ö·¢»î¶¯
https://asec.ahnlab.com/en/32226/
΢Èí£ºLSASSÍ߽⵼ÖÂWindowsÓò¿ØÖÆÖØÊÓÆô
https://www.bleepingcomputer.com/news/microsoft/microsoft-windows-domain-controller-restarts-caused-by-lsass-crashes/
Reality Winner µÄ Twitter ÕË»§±»ºÚ¿Í¹¥»÷ÒÔÕë¶Ô¼ÇÕß
https://www.bleepingcomputer.com/news/security/reality-winners-twitter-account-was-hacked-to-target-journalists/
VoIPmonitor ¼à¿ØÈí¼þÖз¢Ã÷µÄÑÏÖØÇå¾²Îó²î
https://thehackernews.com/2022/03/critical-security-bugs-uncovered-in.html