ÃÀ¹úµ·»ÙSandwormÔËÓªµÄ½©Ê¬ÍøÂçCyclops Blink

Ðû²¼Ê±¼ä 2022-04-11

ÃÀ¹úµ·»ÙSandwormÔËÓªµÄ½©Ê¬ÍøÂçCyclops Blink


¾ÝýÌå4ÔÂ6ÈÕ±¨µÀ£¬£¬£¬ÃÀ¹úÒѵ·»ÙÓɶíÂÞ˹ºÚ¿Í×éÖ¯SandwormÔËÓªµÄ½©Ê¬ÍøÂçCyclops Blink¡£¡£¡£¡£Sandworm´Ó2019Äê6ÔÂ×îÏÈʹÓøý©Ê¬ÍøÂ磬£¬£¬Ö÷ҪĿµÄÊÇWatchGuard Firebox·À»ðǽװ±¸ºÍ»ªË¶Â·ÓÉÆ÷¡£¡£¡£¡£´Ë´ÎÖ´·¨Ðж¯ÓÚ2022Äê3ÔÂ18ÈÕ×îÏÈ£¬£¬£¬ÏÖÔÚÒÑÔÚËùÓб»Ñ¬È¾µÄWatchguard×°±¸ÖÐɾ³ý¸Ã¶ñÒâÈí¼þ¡£¡£¡£¡£WatchGuardÐû²¼Á˹ØÓÚ»Ö¸´±»Ñ¬È¾Firebox×°±¸µÄ˵Ã÷£¬£¬£¬»¹¿ª·¢ÁËÒ»Ì×Cyclops Blink¼ì²â¹¤¾ß£¬£¬£¬ÒÔ¼°Cyclops Blink 4²½Õï¶ÏºÍÐÞ¸´ÍýÏë¡£¡£¡£¡£


https://securityaffairs.co/wordpress/129911/cyber-warfare-2/us-disrupts-cyclops-blink-botnet.html


VMwareÐû²¼¸üУ¬£¬£¬ÐÞ¸´Æä²úÆ·ÖеĶà¸öÇå¾²Îó²î


4ÔÂ6ÈÕ£¬£¬£¬VMwareÐû²¼Çå¾²¸üУ¬£¬£¬ÐÞ¸´ÁËVMware Workspace ONE Access¡¢VMware Identity Manager (vIDM)ºÍvRealize Lifecycle ManagerµÈ²úÆ·ÖеÄ8¸öÎó²î¡£¡£¡£¡£ÆäÖаüÀ¨5¸ö½ÏΪÑÏÖØµÄÎó²î£¬£¬£¬»®·ÖΪЧÀÍÆ÷¶ËÄ£°å×¢ÈëÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2022-22954£¬£¬£¬CVSSÆÀ·Ö9.8£©¡¢OAuth2 ACSÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2022-22955ºÍCVE-2022-22956£¬£¬£¬CVSSÆÀ·Ö9.8£©ÒÔ¼°JDBC×¢ÈëÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2022-22957ºÍCVE-2022-22958£¬£¬£¬CVSSÆÀ·Ö9.1£©¡£¡£¡£¡£


https://www.vmware.com/security/advisories/VMSA-2022-0011.html


Cybereason·¢Ã÷AridViperÕë¶ÔÒÔÉ«Áи߼¶¹ÙÔ±µÄÌØ¹¤»î¶¯


Cybereason NocturnusÍŶÓÔÚ4ÔÂ6ÈÕÐû²¼±¨¸æ£¬£¬£¬ÏêÊöÁËAridViper£¨ÓÖ³ÆAPT-C-23£©µÄл¡£¡£¡£¡£Ñо¿Ö°Ô±½«´Ë´ÎÌØ¹¤»î¶¯ÃüÃûΪOperation Bearded Barbie£¬£¬£¬ËüÃé×¼ÒÔÉ«Áйú·À¡¢Ö´·¨ºÍ½ôÆÈЧÀͲ¿·ÖµÄ¸ß¼¶¹ÙÔ±£¬£¬£¬¼àÊÓÆä»î¶¯²¢ÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÐéαµÄFacebookÕ˺ÅÓÕʹĿµÄÏÂÔØÄ¾Âí£¬£¬£¬²¢Ê¹ÓÃÁËеĶñÒâÈí¼þBarb(ie) DownloaderºÍBarbWire Backdoor£¬£¬£¬ÒÔ¼°VolatileVenomбäÖÖ¡£¡£¡£¡£ 


https://www.cybereason.com/blog/operation-bearded-barbie-apt-c-23-campaign-targeting-israeli-officials


3¸ö¶ñÒâAndroidÓ¦ÓÃÃé×¼ÂíÀ´Î÷ÑǵĶà¸ö½ðÈÚ»ú¹¹


4ÔÂ6ÈÕ£¬£¬£¬ESETÐû²¼Á˹ØÓÚ3¸ö¶ñÒâAndroidÓ¦ÓõÄÑо¿±¨¸æ¡£¡£¡£¡£¸Ã»î¶¯×Ô2021Äê11ÔÂ×îÏÈ£¬£¬£¬¹¥»÷Õßͨ¹ýð³äMaid4u¡¢GrabmaidºÍMaria's CleaningµÈ7¸öÕýµ±ÍøÕ¾£¬£¬£¬ÓÕʹÓû§ÏÂÔØ¶ñÒâÓ¦Ó㬣¬£¬ÕâЩӦÓý«Ä¿µÄÊÕµ½µÄËùÓжÌÐÅת·¢µ½¹¥»÷Õߣ¬£¬£¬ÒÔÇÔÈ¡ÒøÐз¢Ë͵Ä2FA´úÂë¡£¡£¡£¡£´Ë´Î»î¶¯Ö÷ÒªÕë¶ÔÂíÀ´Î÷ÑǵÄ8¼ÒÒøÐУºMaybank¡¢Affin Bank¡¢Public Bank Berhad¡¢CIMB bank¡¢BSN¡¢RHB¡¢Bank Islam MalaysiaºÍHong Leong Bank¡£¡£¡£¡£


https://www.welivesecurity.com/2022/04/06/fake-eshops-prowl-banking-credentials-android-malware/


NB65Éù³ÆÒÑÇÔÈ¡¶íÂÞ˹¹ã²¥¹«Ë¾VGTRKÔ¼800GBµÄÊý¾Ý


ýÌå4ÔÂ6ÈÕ±¨µÀ£¬£¬£¬NB65(Network Battalion 65)Éù³ÆÒÑÈëÇÖ¶íÂÞ˹µçÊӹ㲥¹«Ë¾VGTRK¡£¡£¡£¡£NB65ÓëAnonymouÓйØÁª£¬£¬£¬VGTRKÊǶíÂÞ˹×î´óµÄýÌ幫˾£¬£¬£¬ÔËÓª×Å5¸ö¹ú¼Òµç̨¡¢2¸ö¹ú¼ÊÍøÂç¡¢5¸ö¹ã²¥µç̨ºÍ80¶à¸öµØÇøµçÊÓºÍ¹ã²¥ÍøÂç¡£¡£¡£¡£NB65ͨ¹ýDDoSecrets¹ûÕæÁËVGTRK 786.2 GBµÄÊý¾Ý£¬£¬£¬ÆäÖаüÀ¨4000¸öÎļþºÍÁè¼Ý900000·âµç×ÓÓʼþ¡£¡£¡£¡£Anonymous»¹ÔÚ3ÔÂ26ÈÕй¶Á˶íÂÞ˹ÖÐÑëÒøÐÐ28GBµÄÊý¾Ý¡£¡£¡£¡£


https://www.hackread.com/anonymous-affiliate-nb65-russia-broadcaster-data-breach/


Google PlayÖÐʹÓÃSDKÍøÂçÐÅÏ¢µÄÓ¦ÓÃÒÑ×°ÖÃ4500Íò´Î


¾Ý4ÔÂ7ÈÕ±¨µÀ£¬£¬£¬AppCensus·¢Ã÷Google PlayÖеĶà¸öÓ¦ÓÃͨ¹ýµÚÈý·½SDKÍøÂçÓû§Êý¾Ý¡£¡£¡£¡£ÕâЩӦÓÃÒÑ×°ÖÃÁè¼Ý4500Íò´Î£¬£¬£¬°üÀ¨Speed Camera RadarºÍAl-Moazin LiteµÈ£¬£¬£¬Ö÷ÒªÇÔÈ¡¼ôÌù°åÄÚÈÝ¡¢GPSÊý¾Ý¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂ룬£¬£¬ÒÔ¼°µ÷ÖÆ½âµ÷Æ÷·ÓÉÆ÷MACµØµãºÍÍøÂçSSID¡£¡£¡£¡£ÍøÂçµ½µÄÊý¾ÝÓÉSDK´«Êäµ½¡°mobile.measurelib.com¡±£¬£¬£¬¸ÃÓòÊôÓÚÒ»¼ÒÃûΪMeasurement SystemsµÄ°ÍÄÃÂíÆÊÎö¹«Ë¾ËùÓС£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/android-apps-with-45-million-installs-used-data-harvesting-sdk/




Çå¾²¹¤¾ß


Rip Raw


ÊÇÒ»¸öÓÃÓÚÆÊÎöÊÜѬȾ Linux ϵͳÄÚ´æµÄС¹¤¾ß¡£¡£¡£¡£


https://github.com/cado-security/rip_raw


Grafiki


¹ØÓÚ Sysmon ºÍͼ±íµÄÍþв׷×Ù¹¤¾ß¡£¡£¡£¡£


https://github.com/lucky-luk3/Grafiki/


Odin


Odin ÊÇ»ùÓÚLokiµÄÖÐÑë IoC ɨÃèÆ÷


https://github.com/Hamza-Megahed/odin




Çå¾²ÆÊÎö


Windows 11 ÄÚ²¿°æ±¾ 22593 ÖеÄÒÑÖªÎÊÌâ


https://news.softpedia.com/news/known-issues-in-windows-11-build-22593-535182.shtml


Mozilla Firefox 99 ÏÖÒѿɹ©ÏÂÔØ


https://news.softpedia.com/news/mozilla-firefox-99-is-now-available-for-download-535180.shtml


΢Èí£º¶à¸ö .NET Framework °æ±¾½«ÓÚ 4 Ô EOL


https://www.bleepingcomputer.com/news/microsoft/microsoft-multiple-net-framework-versions-reach-end-of-life-in-april/


AMDÈ·ÈÏGPUÇý¶¯³ÌÐò¹ýʧδ¾­ÔÊÐí³¬ÆµCPU


https://www.bleepingcomputer.com/news/hardware/amd-confirms-gpu-driver-bug-overclocks-cpus-without-permission/


Atlassian Jira£¬£¬£¬Confluence ÖÐÖ¹Ó°ÏìÈ«ÇòÓû§


https://www.bleepingcomputer.com/news/technology/ongoing-atlassian-jira-confluence-outage-affects-customers-worldwide/


Palo Alto Networks ·À»ðǽ¡¢VPN ±£´æ OpenSSL Îó²î


https://www.bleepingcomputer.com/news/security/palo-alto-networks-firewalls-vpns-vulnerable-to-openssl-bug/


FFDroiderÖ¼ÔÚÇÔÈ¡É罻ýÌåÖеÄÐÅÏ¢


https://www.zscaler.com/blogs/security-research/ffdroider-stealer-targeting-social-media-platform-users