ÍøÐŰ졶»¥ÁªÍøµ¯´°ÐÅÏ¢ÍÆËÍЧÀÍÖÎÀí»®¶¨£¨Õ÷ÇóÒâ¼û¸å£©¡·
Ðû²¼Ê±¼ä 2022-03-07ÍøÐŰ졶»¥ÁªÍøµ¯´°ÐÅÏ¢ÍÆËÍЧÀÍÖÎÀí»®¶¨£¨Õ÷ÇóÒâ¼û¸å£©¡·
3ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬¹ú¼Ò»¥ÁªÍøÐÅÏ¢°ì¹«ÊÒÐû²¼Á˹ØÓÚ¡¶»¥ÁªÍøµ¯´°ÐÅÏ¢ÍÆËÍЧÀÍÖÎÀí»®¶¨£¨Õ÷ÇóÒâ¼û¸å£©¡·¹ûÕæÕ÷ÇóÒâ¼ûµÄ֪ͨ¡£¡£¡£¡£¡£Í¨ÖªÖ¸³ö£¬£¬£¬£¬£¬£¬Îª¹æ·¶»¥ÁªÍøµ¯´°ÐÅÏ¢ÍÆËÍЧÀÍ£¬£¬£¬£¬£¬£¬Î¬»¤¹ú¼ÒÇå¾²ºÍ¹«¹²ÀûÒæ£¬£¬£¬£¬£¬£¬Æ¾Ö¤¡¶ÖлªÈËÃñ¹²ºÍ¹úÍøÂçÇå¾²·¨¡·µÈÖ´ÂÉÀýÔòÖÆ¶©Á˱¾»®¶¨¡£¡£¡£¡£¡£ÔÚ¾³ÄÚÌṩ²Ù×÷ϵͳ¡¢ÖÕ¶Ë×°±¸¡¢Ó¦ÓÃÈí¼þ¡¢ÍøÕ¾µÈЧÀ͵쬣¬£¬£¬£¬£¬¿ªÕ¹»¥ÁªÍøµ¯´°ÐÅÏ¢ÍÆËÍЧÀÍʱӦµ±×ñÊØ±¾»®¶¨¡£¡£¡£¡£¡£
http://www.cac.gov.cn/2022-03/02/c_1647826956995841.htm
Unit 42³Æ10Íò¶à¸öÊäÒº±ÃÒ×ÊܶàÄêǰµÄÊý¸öÎó²îÓ°Ïì
3ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬Unit 42Ðû²¼±¨¸æ³ÆÆäÉó²éÁË200000¶à¸ö×°±¸£¬£¬£¬£¬£¬£¬²¢·¢Ã÷ÆäÖÐ75%±£´æ¶àÄêǰµÄÎó²î¡£¡£¡£¡£¡£×îÆÕ±éµÄÊÇǶÈëʽװ±¸µÄVxWorksʵʱ²Ù×÷ϵͳ(RTOS)ÖеÄÄÚ´æËð»µÎó²î£¨CVE-2019-12255£¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö9.8£©£¬£¬£¬£¬£¬£¬±£´æÓÚ52%µÄ²úÆ·ÖУ¨104000¶ą̀)£¬£¬£¬£¬£¬£¬ÒÑÓÚ2019Äê7ÔÂ19ÈÕ±»ÐÞ¸´¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±»¹·¢Ã÷ÁËCVE-2020-12040¡¢CVE-2020-12045ºÍCVE-2020-12047µÈ¶à¸öÔÚ2019ÄêºÍ2020Äê¾Í±»Åû¶µÄÎó²î¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/over-100-000-medical-infusion-pumps-vulnerable-to-years-old-critical-bug/
Proofpoint·¢Ã÷ÐÂÒ»ÂÖ´¹ÂڻAsylum Ambuscade
ProofpointÔÚ3ÔÂ1ÈÕ¹ûÕæÁËÐÂÒ»ÂÖ´¹ÂڻAsylum AmbuscadeµÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¸Ã»î¶¯ÈëÇÖÁËÒ»¸öÎÚ¿ËÀ¼Îä×°²½¶ÓÔ±¹¤µÄÓʼþÕÊ»§£¬£¬£¬£¬£¬£¬Ä¿µÄÊǼÓÈëÖÎÀíÎÚ¿ËÀ¼ÔÖÀèºóÇÚÊÂÇéµÄÖ°Ô±¡£¡£¡£¡£¡£´¹ÂÚÓʼþÀ´×Ôukr[.]net£¬£¬£¬£¬£¬£¬°üÀ¨Ò»¸ö¶ñÒâºê¸½¼þ£¬£¬£¬£¬£¬£¬Ö¼ÔÚ·Ö·¢¸öÃûΪSunSeedµÄ»ùÓÚLuaµÄ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷¸Ã»î¶¯Óë2021Äê7Ô°׶íÂÞ˹APT×éÖ¯GhostwriterÌᳫµÄ¹¥»÷ÏàËÆ£¬£¬£¬£¬£¬£¬ÍƶÏÕâÁ½´Î¹¥»÷À´×Ôͳһ¹¥»÷Õß¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/128594/apt/asylum-ambuscade-phishing-campaign-ukraine.html
Salt SecurityÐû²¼¹ØÓÚAPIÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ
3ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬Salt SecurityÐû²¼Á˹ØÓÚAPIÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬2021ÄêAPI¹¥»÷Á÷Á¿ÔöÌíÁË681%£¬£¬£¬£¬£¬£¬¶øÕûÌåAPIÁ÷Á¿ÔöÌíÁË321%¡£¡£¡£¡£¡£¸ÃÑо¿¶ÔÀ´×Ô²î±ð¹æÄ£¹«Ë¾µÄ250ÃûÔ±¹¤µÄ¾ÙÐÐÊӲ죬£¬£¬£¬£¬£¬·¢Ã÷34%µÄ¹«Ë¾È±·¦APIÇå¾²Õ½ÂÔ£¬£¬£¬£¬£¬£¬83%ÊÜ·ÃÕß¶ÔËûÃǵÄÏÖÓÐAPI¹¦Ð§È±·¦ÐÅÐÄ£¬£¬£¬£¬£¬£¬95%µÄÊÜ·ÃÕßÌåÏÖÔÚÈ¥ÄêÂÄÀú¹ýAPIÇå¾²ÊÂÎñ£¬£¬£¬£¬£¬£¬85%µÄÊÜ·ÃÕßÖ¸³öÄ¿½ñµÄ¹¤¾ßÎÞ·¨ÓÐÓÃ×èÖ¹API¹¥»÷¡£¡£¡£¡£¡£
https://salt.security/press-releases/salt-security-state-of-api-security-report-reveals-api-attacks-increased-681-in-the-last-12-months?
BarracudaÐû²¼Log4ShellÎó²îʹÓûµÄÑо¿±¨¸æ
BarracudaÆÊÎöÁË×Ô2021Äê12ÔÂ10ÈÕÒÔÀ´¼ì²âµ½µÄ¹¥»÷ºÍpayload£¬£¬£¬£¬£¬£¬²¢ÓÚ3ÔÂ2ÈÕÐû²¼ÁËLog4ShellÎó²îʹÓûµÄ±¨¸æ¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬´ó´ó¶¼Ê¹ÓÃʵÑéÀ´×ÔÃÀ¹ú£¬£¬£¬£¬£¬£¬Æä´ÎÊÇÈÕ±¾¡¢ÖÐÅ·ºÍ¶íÂÞ˹¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷Á˶à¸öʹÓøÃÎó²îµÄpayload£¬£¬£¬£¬£¬£¬ÆäÖн©Ê¬ÍøÂçMirai¼°Æä±äÌåµÄÕ¼±È×î´ó£¬£¬£¬£¬£¬£¬Æä´ÎΪBillGates malware(DDoS)¡¢Kinsing(¼ÓÃÜ¿ó¹¤)¡¢XMRig(¼ÓÃÜ¿ó¹¤)ºÍMuhstik(DDoS)¡£¡£¡£¡£¡£±¨¸æ»¹Ìá³öÓÐÓÃÌá·À´ËÀ๥»÷µÄ×î¼òÆÓÒªÁìÊǽ«Log4j¸üе½2.17.1»ò¸ü¸ß°æ±¾£¬£¬£¬£¬£¬£¬²¢È·±£ËùÓÐWebÓ¦Óô¦ÓÚ×îÐÂ״̬¡£¡£¡£¡£¡£
https://blog.barracuda.com/2022/03/02/threat-spotlight-attacks-on-log4shell-vulnerabilities/
Ñо¿Ö°Ô±¹ûÕæLinuxÄÚºËÌáȨÎó²îCVE-2022-0492µÄϸ½Ú
Ñо¿Ö°Ô±ÔÚ3ÔÂ3ÈÕ¹ûÕæÁËLinuxÄÚºËÖеÄÌáȨÎó²î£¨CVE-2022-0492£©µÄϸ½Ú¡£¡£¡£¡£¡£ËüÊÇLinux¿ØÖÆ×é(cgroups)ÖеÄÒ»¸öÂß¼Îó²î£¬£¬£¬£¬£¬£¬±£´æÓÚ/cgroup/cgroup-v1.cº¯ÊýÖеÄcgroup_release_agent_write¡£¡£¡£¡£¡£ÔÚijЩÇéÐÎÏ£¬£¬£¬£¬£¬£¬Æä¿É±»ÓÃÀ´Í¨¹ýcgroups v1µÄrelease_agentÌØÕ÷ÌáÉýȨÏÞ£¬£¬£¬£¬£¬£¬²¢ÈƹýÃû³Æ¿Õ¾àÀëÀë¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬¸ÃÎó²î ÒÑÔÚ×îеÄLinux°æ±¾ÖÐÐÞ¸´£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±½¨ÒéËùÓÐÓû§Éý¼¶µ½×îа汾¡£¡£¡£¡£¡£
https://unit42.paloaltonetworks.com/cve-2022-0492-cgroups/
Çå¾²¹¤¾ß
BruteShark
ÍøÂçȡ֤ÆÊÎö¹¤¾ß (NFAT)£¬£¬£¬£¬£¬£¬Ëü¶ÔÍøÂçÁ÷Á¿£¨Ö÷ÒªÊÇ PCAP Îļþ£©¾ÙÐÐÉî¶È´¦Öóͷ£ºÍ¼ì²é¡£¡£¡£¡£¡£
https://github.com/odedshimon/BruteShark/
Checkov
ÓÃÓÚ»ù´¡ÉèÊ©¼´´úÂëµÄ¾²Ì¬´úÂëÆÊÎö¹¤¾ß¡£¡£¡£¡£¡£
https://github.com/bridgecrewio/checkov
JNDI-Injection-Exploit
JNDI×¢ÈëʹÓù¤¾ß£¬£¬£¬£¬£¬£¬ÌìÉúJNDIÁ´½Ó²¢Æô¶¯ºó¶ËÏà¹ØÐ§ÀÍ£¬£¬£¬£¬£¬£¬¿ÉÓÃÓÚFastjson¡¢JacksonµÈÏà¹ØÎó²îµÄÑéÖ¤¡£¡£¡£¡£¡£
https://github.com/welk1n/JNDI-Injection-Exploit
nrich v0.2
Ò»¸öÏÂÁîÐй¤¾ß£¬£¬£¬£¬£¬£¬ÓÃÓÚ¿ìËÙÆÊÎöÎļþÖеÄËùÓÐ IP£¬£¬£¬£¬£¬£¬²¢Éó²éÄÄЩ¾ßÓпª·Å¶Ë¿Ú/Îó²î¡£¡£¡£¡£¡£
fuzzuf
ÊÇÒ»¸ö´øÓÐ×Ô¼ºµÄ DSL µÄ fuzzing ¿ò¼Ü£¬£¬£¬£¬£¬£¬Í¨¹ý¹¹½¨ fuzzing ÔÓïµÄ¹¹½¨¿éÀ´ÐÎòfuzzing Ñ»·¡£¡£¡£¡£¡£
https://securityonline.info/fuzzuf-fuzzing-unification-framework/
Çå¾²ÆÊÎö
΢ÈíÐû²¼ÊÊÓÃÓÚ Windows 11 µÄÐÂÓ¦ÓÃÇå¾²¹¦Ð§
https://news.softpedia.com/news/microsoft-announces-new-app-security-feature-for-windows-11-534974.shtml
¶íÂÞ˹º½Ìì¾Ö³ÆºÚ¿Í¹¥»÷ÎÀÐÇÊÇÒ»ÖÖÕ½ÕùÐÐΪ
https://www.bleepingcomputer.com/news/security/russian-space-agency-says-hacking-satellites-is-an-act-of-war/
¹¥»÷ÕßʹÓà Telegram ¾ÙÐÐÓë³åÍ»Ïà¹ØµÄ»î¶¯
https://blog.checkpoint.com/2022/03/02/telegram-becomes-a-digital-forefront-in-the-conflict/
Ó¢ÌØ¶ûµÄµÚ 12 ´ú Alder Lake ´¦Öóͷ£Æ÷²»°üÀ¨Î¢Èí Pluton
https://www.theregister.com/2022/03/02/microsoft_pluton_chip/
Anonymous¼°ÆäÁ¥Êô»ú¹¹¼ÌÐø¶Ô¶íÂÞ˹¾ÙÐй¥»÷
https://securityaffairs.co/wordpress/128576/hacktivism/anonymous-causes-damages-to-russia.html