ÍøÐŰ졶»¥ÁªÍøµ¯´°ÐÅÏ¢ÍÆËÍЧÀÍÖÎÀí»®¶¨£¨Õ÷ÇóÒâ¼û¸å£©¡·

Ðû²¼Ê±¼ä 2022-03-07

ÍøÐŰ졶»¥ÁªÍøµ¯´°ÐÅÏ¢ÍÆËÍЧÀÍÖÎÀí»®¶¨£¨Õ÷ÇóÒâ¼û¸å£©¡·


3ÔÂ2ÈÕ£¬£¬ £¬£¬£¬ £¬¹ú¼Ò»¥ÁªÍøÐÅÏ¢°ì¹«ÊÒÐû²¼Á˹ØÓÚ¡¶»¥ÁªÍøµ¯´°ÐÅÏ¢ÍÆËÍЧÀÍÖÎÀí»®¶¨£¨Õ÷ÇóÒâ¼û¸å£©¡·¹ûÕæÕ÷ÇóÒâ¼ûµÄ֪ͨ ¡£¡£ ¡£¡£¡£Í¨ÖªÖ¸³ö£¬£¬ £¬£¬£¬ £¬Îª¹æ·¶»¥ÁªÍøµ¯´°ÐÅÏ¢ÍÆËÍЧÀÍ£¬£¬ £¬£¬£¬ £¬Î¬»¤¹ú¼ÒÇå¾²ºÍ¹«¹²ÀûÒæ£¬£¬ £¬£¬£¬ £¬Æ¾Ö¤¡¶ÖлªÈËÃñ¹²ºÍ¹úÍøÂçÇå¾²·¨¡·µÈÖ´ÂÉÀýÔòÖÆ¶©Á˱¾»®¶¨ ¡£¡£ ¡£¡£¡£ÔÚ¾³ÄÚÌṩ²Ù×÷ϵͳ¡¢ÖÕ¶Ë×°±¸¡¢Ó¦ÓÃÈí¼þ¡¢ÍøÕ¾µÈЧÀ͵Ä£¬£¬ £¬£¬£¬ £¬¿ªÕ¹»¥ÁªÍøµ¯´°ÐÅÏ¢ÍÆËÍЧÀÍʱӦµ±×ñÊØ±¾»®¶¨ ¡£¡£ ¡£¡£¡£


http://www.cac.gov.cn/2022-03/02/c_1647826956995841.htm


Unit 42³Æ10Íò¶à¸öÊäÒº±ÃÒ×ÊܶàÄêǰµÄÊý¸öÎó²îÓ°Ïì


3ÔÂ2ÈÕ£¬£¬ £¬£¬£¬ £¬Unit 42Ðû²¼±¨¸æ³ÆÆäÉó²éÁË200000¶à¸ö×°±¸£¬£¬ £¬£¬£¬ £¬²¢·¢Ã÷ÆäÖÐ75%±£´æ¶àÄêǰµÄÎó²î ¡£¡£ ¡£¡£¡£×îÆÕ±éµÄÊÇǶÈëʽװ±¸µÄVxWorksʵʱ²Ù×÷ϵͳ(RTOS)ÖеÄÄÚ´æËð»µÎó²î£¨CVE-2019-12255£¬£¬ £¬£¬£¬ £¬CVSSÆÀ·Ö9.8£©£¬£¬ £¬£¬£¬ £¬±£´æÓÚ52%µÄ²úÆ·ÖУ¨104000¶ą̀)£¬£¬ £¬£¬£¬ £¬ÒÑÓÚ2019Äê7ÔÂ19ÈÕ±»ÐÞ¸´ ¡£¡£ ¡£¡£¡£±ðµÄ£¬£¬ £¬£¬£¬ £¬Ñо¿Ö°Ô±»¹·¢Ã÷ÁËCVE-2020-12040¡¢CVE-2020-12045ºÍCVE-2020-12047µÈ¶à¸öÔÚ2019ÄêºÍ2020Äê¾Í±»Åû¶µÄÎó²î ¡£¡£ ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/over-100-000-medical-infusion-pumps-vulnerable-to-years-old-critical-bug/


Proofpoint·¢Ã÷ÐÂÒ»ÂÖ´¹ÂڻAsylum Ambuscade


ProofpointÔÚ3ÔÂ1ÈÕ¹ûÕæÁËÐÂÒ»ÂÖ´¹ÂڻAsylum AmbuscadeµÄÏêϸÐÅÏ¢ ¡£¡£ ¡£¡£¡£¸Ã»î¶¯ÈëÇÖÁËÒ»¸öÎÚ¿ËÀ¼Îä×°²½¶ÓÔ±¹¤µÄÓʼþÕÊ»§£¬£¬ £¬£¬£¬ £¬Ä¿µÄÊǼÓÈëÖÎÀíÎÚ¿ËÀ¼ÔÖÀèºóÇÚÊÂÇéµÄÖ°Ô± ¡£¡£ ¡£¡£¡£´¹ÂÚÓʼþÀ´×Ôukr[.]net£¬£¬ £¬£¬£¬ £¬°üÀ¨Ò»¸ö¶ñÒâºê¸½¼þ£¬£¬ £¬£¬£¬ £¬Ö¼ÔÚ·Ö·¢¸öÃûΪSunSeedµÄ»ùÓÚLuaµÄ¶ñÒâÈí¼þ ¡£¡£ ¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷¸Ã»î¶¯Óë2021Äê7Ô°׶íÂÞ˹APT×éÖ¯GhostwriterÌᳫµÄ¹¥»÷ÏàËÆ£¬£¬ £¬£¬£¬ £¬ÍƶÏÕâÁ½´Î¹¥»÷À´×Ôͳһ¹¥»÷Õß ¡£¡£ ¡£¡£¡£


https://securityaffairs.co/wordpress/128594/apt/asylum-ambuscade-phishing-campaign-ukraine.html


Salt SecurityÐû²¼¹ØÓÚAPIÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ


3ÔÂ2ÈÕ£¬£¬ £¬£¬£¬ £¬Salt SecurityÐû²¼Á˹ØÓÚAPIÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ ¡£¡£ ¡£¡£¡£±¨¸æÖ¸³ö£¬£¬ £¬£¬£¬ £¬2021ÄêAPI¹¥»÷Á÷Á¿ÔöÌíÁË681%£¬£¬ £¬£¬£¬ £¬¶øÕûÌåAPIÁ÷Á¿ÔöÌíÁË321% ¡£¡£ ¡£¡£¡£¸ÃÑо¿¶ÔÀ´×Ô²î±ð¹æÄ£¹«Ë¾µÄ250ÃûÔ±¹¤µÄ¾ÙÐÐÊӲ죬£¬ £¬£¬£¬ £¬·¢Ã÷34%µÄ¹«Ë¾È±·¦APIÇå¾²Õ½ÂÔ£¬£¬ £¬£¬£¬ £¬83%ÊÜ·ÃÕß¶ÔËûÃǵÄÏÖÓÐAPI¹¦Ð§È±·¦ÐÅÐÄ£¬£¬ £¬£¬£¬ £¬95%µÄÊÜ·ÃÕßÌåÏÖÔÚÈ¥ÄêÂÄÀú¹ýAPIÇå¾²ÊÂÎñ£¬£¬ £¬£¬£¬ £¬85%µÄÊÜ·ÃÕßÖ¸³öÄ¿½ñµÄ¹¤¾ßÎÞ·¨ÓÐÓÃ×èÖ¹API¹¥»÷ ¡£¡£ ¡£¡£¡£


https://salt.security/press-releases/salt-security-state-of-api-security-report-reveals-api-attacks-increased-681-in-the-last-12-months?


BarracudaÐû²¼Log4ShellÎó²îʹÓûµÄÑо¿±¨¸æ


BarracudaÆÊÎöÁË×Ô2021Äê12ÔÂ10ÈÕÒÔÀ´¼ì²âµ½µÄ¹¥»÷ºÍpayload£¬£¬ £¬£¬£¬ £¬²¢ÓÚ3ÔÂ2ÈÕÐû²¼ÁËLog4ShellÎó²îʹÓûµÄ±¨¸æ ¡£¡£ ¡£¡£¡£±¨¸æÖ¸³ö£¬£¬ £¬£¬£¬ £¬´ó´ó¶¼Ê¹ÓÃʵÑéÀ´×ÔÃÀ¹ú£¬£¬ £¬£¬£¬ £¬Æä´ÎÊÇÈÕ±¾¡¢ÖÐÅ·ºÍ¶íÂÞ˹ ¡£¡£ ¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷Á˶à¸öʹÓøÃÎó²îµÄpayload£¬£¬ £¬£¬£¬ £¬ÆäÖн©Ê¬ÍøÂçMirai¼°Æä±äÌåµÄÕ¼±È×î´ó£¬£¬ £¬£¬£¬ £¬Æä´ÎΪBillGates malware(DDoS)¡¢Kinsing(¼ÓÃÜ¿ó¹¤)¡¢XMRig(¼ÓÃÜ¿ó¹¤)ºÍMuhstik(DDoS) ¡£¡£ ¡£¡£¡£±¨¸æ»¹Ìá³öÓÐÓÃÌá·À´ËÀ๥»÷µÄ×î¼òÆÓÒªÁìÊǽ«Log4j¸üе½2.17.1»ò¸ü¸ß°æ±¾£¬£¬ £¬£¬£¬ £¬²¢È·±£ËùÓÐWebÓ¦Óô¦ÓÚ×îÐÂ״̬ ¡£¡£ ¡£¡£¡£


https://blog.barracuda.com/2022/03/02/threat-spotlight-attacks-on-log4shell-vulnerabilities/     


Ñо¿Ö°Ô±¹ûÕæLinuxÄÚºËÌáȨÎó²îCVE-2022-0492µÄϸ½Ú


Ñо¿Ö°Ô±ÔÚ3ÔÂ3ÈÕ¹ûÕæÁËLinuxÄÚºËÖеÄÌáȨÎó²î£¨CVE-2022-0492£©µÄϸ½Ú ¡£¡£ ¡£¡£¡£ËüÊÇLinux¿ØÖÆ×é(cgroups)ÖеÄÒ»¸öÂß¼­Îó²î£¬£¬ £¬£¬£¬ £¬±£´æÓÚ/cgroup/cgroup-v1.cº¯ÊýÖеÄcgroup_release_agent_write ¡£¡£ ¡£¡£¡£ÔÚijЩÇéÐÎÏ£¬£¬ £¬£¬£¬ £¬Æä¿É±»ÓÃÀ´Í¨¹ýcgroups v1µÄrelease_agentÌØÕ÷ÌáÉýȨÏÞ£¬£¬ £¬£¬£¬ £¬²¢ÈƹýÃû³Æ¿Õ¾àÀëÀë ¡£¡£ ¡£¡£¡£ÏÖÔÚ£¬£¬ £¬£¬£¬ £¬¸ÃÎó²î ÒÑÔÚ×îеÄLinux°æ±¾ÖÐÐÞ¸´£¬£¬ £¬£¬£¬ £¬Ñо¿Ö°Ô±½¨ÒéËùÓÐÓû§Éý¼¶µ½×îа汾 ¡£¡£ ¡£¡£¡£


https://unit42.paloaltonetworks.com/cve-2022-0492-cgroups/



Çå¾²¹¤¾ß


BruteShark


ÍøÂçȡ֤ÆÊÎö¹¤¾ß (NFAT)£¬£¬ £¬£¬£¬ £¬Ëü¶ÔÍøÂçÁ÷Á¿£¨Ö÷ÒªÊÇ PCAP Îļþ£©¾ÙÐÐÉî¶È´¦Öóͷ£ºÍ¼ì²é ¡£¡£ ¡£¡£¡£


https://github.com/odedshimon/BruteShark/


Checkov 


ÓÃÓÚ»ù´¡ÉèÊ©¼´´úÂëµÄ¾²Ì¬´úÂëÆÊÎö¹¤¾ß ¡£¡£ ¡£¡£¡£


https://github.com/bridgecrewio/checkov


JNDI-Injection-Exploit


JNDI×¢ÈëʹÓù¤¾ß£¬£¬ £¬£¬£¬ £¬ÌìÉúJNDIÁ´½Ó²¢Æô¶¯ºó¶ËÏà¹ØÐ§ÀÍ£¬£¬ £¬£¬£¬ £¬¿ÉÓÃÓÚFastjson¡¢JacksonµÈÏà¹ØÎó²îµÄÑéÖ¤ ¡£¡£ ¡£¡£¡£


https://github.com/welk1n/JNDI-Injection-Exploit



nrich v0.2


Ò»¸öÏÂÁîÐй¤¾ß£¬£¬ £¬£¬£¬ £¬ÓÃÓÚ¿ìËÙÆÊÎöÎļþÖеÄËùÓÐ IP£¬£¬ £¬£¬£¬ £¬²¢Éó²éÄÄЩ¾ßÓпª·Å¶Ë¿Ú/Îó²î ¡£¡£ ¡£¡£¡£


https://gitlab.com/shodan-public/nrich


fuzzuf


ÊÇÒ»¸ö´øÓÐ×Ô¼ºµÄ DSL µÄ fuzzing ¿ò¼Ü£¬£¬ £¬£¬£¬ £¬Í¨¹ý¹¹½¨ fuzzing Ô­ÓïµÄ¹¹½¨¿éÀ´ÐÎòfuzzing Ñ­»· ¡£¡£ ¡£¡£¡£


https://securityonline.info/fuzzuf-fuzzing-unification-framework/



Çå¾²ÆÊÎö


΢ÈíÐû²¼ÊÊÓÃÓÚ Windows 11 µÄÐÂÓ¦ÓÃÇå¾²¹¦Ð§


https://news.softpedia.com/news/microsoft-announces-new-app-security-feature-for-windows-11-534974.shtml



¶íÂÞ˹º½Ìì¾Ö³ÆºÚ¿Í¹¥»÷ÎÀÐÇÊÇÒ»ÖÖÕ½ÕùÐÐΪ


https://www.bleepingcomputer.com/news/security/russian-space-agency-says-hacking-satellites-is-an-act-of-war/



¹¥»÷ÕßʹÓà Telegram ¾ÙÐÐÓë³åÍ»Ïà¹ØµÄ»î¶¯


https://blog.checkpoint.com/2022/03/02/telegram-becomes-a-digital-forefront-in-the-conflict/



Ó¢ÌØ¶ûµÄµÚ 12 ´ú Alder Lake ´¦Öóͷ£Æ÷²»°üÀ¨Î¢Èí Pluton 


https://www.theregister.com/2022/03/02/microsoft_pluton_chip/



Anonymous¼°ÆäÁ¥Êô»ú¹¹¼ÌÐø¶Ô¶íÂÞ˹¾ÙÐй¥»÷


https://securityaffairs.co/wordpress/128576/hacktivism/anonymous-causes-damages-to-russia.html