ÃÀ¹úCISAÐû²¼2022ÄêÃâ·ÑÍøÂçÄþ¾²¹¤¾ßºÍ·þÎñÇåµ¥
Ðû²¼Ê±¼ä 2022-02-22ÃÀ¹úCISAÐû²¼2022ÄêÃâ·ÑÍøÂçÄþ¾²¹¤¾ßºÍ·þÎñÇåµ¥
2ÔÂ18ÈÕ£¬ÃÀ¹úCISAÌåÀý²¢Ðû²¼ÁË2022ÄêÃâ·ÑÍøÂçÄþ¾²¹¤¾ßºÍ·þÎñÇåµ¥£¬Ö¼ÔÚ×ÊÖú×éÖ¯Äܹ»ÓÐЧ»º½â¡¢¼ì²âºÍÏìÓ¦¶ñÒâ¹¥»÷¡£¸ÃÇåµ¥µÄ×ÊÔ´ÖÐÐİüÂÞCISAÌṩµÄ101Ïî·þÎñ¡¢¿ªÔ´·¨Ê½ÒÔ¼°ÆäËü×éÖ¯ÌṩµÄ¹¤¾ß¡£´ËÍ⣬¸Ã»ú¹¹»¹ÍƳöÁËרÃŵÄÍøÕ¾£¬ÓÃÀ´¼Ç¼Òѱ»ÀûÓõÄ©¶´¡¢¡°Ò쳣ΣÏÕ¡±µÄÄþ¾²·¨Ê½¡¢µÖÓùÀÕË÷Èí¼þµÄÖ¸ÄÏÒÔ¼°ÆäËüÍþв¡£
https://www.cisa.gov/uscert/ncas/current-activity/2022/02/18/cisa-compiles-free-cybersecurity-services-and-tools-network
WordPress UpdraftPlusÈÎÒâÎļþÏÂÔØCVE-2022-0633
¾ÝýÌå2ÔÂ19ÈÕ±¨µÀ£¬WordPressµÄ²å¼þUpdraftPlusÖдæÔÚÈÎÒâÎļþÏÂÔØÂ©¶´£¨CVE-2022-0633£©¡£µÍȨÏÞÓû§¿ÉÀûÓÃÆäÀ´ÏÂÔØÍøÕ¾µÄ×îб¸·Ý£¬ÀÖ³ÉÀûÓú󣬹¥»÷Õ߿ɷÃÎÊÄ¿±êÍøÕ¾Êý¾Ý¿âÖеÄÌØÈ¨ÐÅÏ¢£¬ÈçÓû§ÃûºÍÃÜÂë¡£¸Ã©¶´´æÔÚÓÚUpdraftPlus°æ±¾1.16.7ÖÁ1.22.2ÖУ¬Ä¿Ç°£¬WordPressÒÑÔÚ300¶àÍò¸öÊÜÓ°ÏìµÄÍøÕ¾ÖÐÇ¿ÖÆ°²×°ÁËUpdraftPlus²¹¶¡¡£
https://securityaffairs.co/wordpress/128170/hacking/updraftplus-forced-update.html
ÒÁÀÊTunnelVisionÀûÓÃLog4Shell©¶´¹¥»÷Öж«ºÍÃÀ¹ú
SentinelLabsÔÚ2ÔÂ17ÈÕÐû²¼³ÂËߣ¬¸ÅÊöÁËÒÁÀÊAPT×éÖ¯TunnelVisionÕë¶ÔÖж«ºÍÃÀ¹úµÄ¹¥»÷»î¶¯¡£TunnelVision»î¶¯µÄÌØµãÊǸü¶àµØÀûÓÃ1 day©¶´£¬ÀýÈçFortinet FortiOS(CVE-2018-13379)¡¢Microsoft Exchange(ProxyShell)ºÍLog4Shell©¶´¡£´ËÍ⣬¸ÃÍÅ»ï·Ç³£ÒÀÀµËíµÀ¹¤¾ß£¬Ëü×î³£ÓõÄÊÇ¿ìËÙ·´ÏòÊðÀí¿Í»§¶Ë(FRPC)ºÍPlink¡£Ñо¿ÈËÔ±»¹Åû¶Á˸ÃÍÅ»ïÀûÓÃLog4Shell¹¥»÷VMware Horizon·þÎñÆ÷µÄ¼¼Êõϸ½Ú¡£
https://www.bleepingcomputer.com/news/security/iranian-hackers-target-vmware-horizon-servers-with-log4j-exploits/
Avanan³Æ¹¥»÷ÕßÀûÓÃTeamsÕë¶ÔýÌåÐÐÒµ·Ö·¢¶ñÒâÈí¼þ
2ÔÂ17ÈÕ£¬AvananÐû²¼³ÂË߳ƹ¥»÷ÕßÀûÓÃTeamsÕë¶ÔýÌåÐÐÒµ·Ö·¢¶ñÒâÈí¼þ¡£Ëæ×ÅMicrosoft TeamsÔ½À´Ô½ÊÜ»¶Ó£¨Ã¿Ô»îÔ¾Óû§Ô¼Îª2.7ÒÚ£©£¬¸ü¶àµÄ¹¥»÷Õß¿ªÊ¼½«ÆäÓÃ×÷¹¥»÷ý½é¡£ÕâЩ¹¥»÷¿ªÊ¼ÓÚ2022Äê1Ô£¬´ÓÏÖÓÐÊý¾ÝÀ´¿´´ó¶àÊý¹¥»÷·¢ÉúÔÚÃÀ¹úÎå´óºþµØÓò£¬Ö÷ÒªÕë¶Ôµ±µØÃ½Ìå»ú¹¹¡£¾ÝϤ£¬¹¥»÷Õß»áÔÚÁÄÌìÖзַ¢¿ÉÖ´ÐÐÎļþ¡°User Centric¡±²¢ÓÕʹÓû§ÔËÐÐËü¡£Ò»µ©Ö´ÐУ¬¶ñÒâÈí¼þ»á½«Êý¾ÝдÈëϵͳע²á±í¡¢°²×°DLL²¢ÔÚWindowsÉϽ¨Á¢³Ö¾ÃÐÔ¡£
https://www.avanan.com/blog/hackers-attach-malicious-.exe-files-to-teams-conversations
ASEC·¢ÏÖPseudoManuscryptÕë¶Ôº«¹úµÄ¹¥»÷»î¶¯
ASECÔÚ2ÔÂ18ÈÕ±¨µÀ³Æ£¬×Ô2021Äê5ÔÂÒÔÀ´£¬º«¹úµÄÐí¶àWindowsÉ豸¶¼³ÉΪÁËPseudoManuscryptµÄÄ¿±ê¡£¶ñÒâÈí¼þαװ³ÉÀàËÆÓÚCryptbotµÄ°²×°·¨Ê½£¬ÇÒµ±Óû§ËÑË÷CrackºÍKeygenµÈÈí¼þÏà¹ØµÄ·Ç·¨Ó¦ÓÃʱ£¬Ëü»¹»áͨ¹ýËÑË÷Ò³ÃæÊ×Ò³µÄ¶ñÒâÍøÕ¾½øÐзַ¢¡£¸Ã»î¶¯Ä¿Ç°ÈÔÔÚ½øÐÐÖУ¬¸Ã¹úÿÌìÆ½¾ùÈÔÓÐ30¶ą̀µçÄÔ±»Ñ¬È¾¡£¸Ã¶ñÒâÈí¼þÓÚ2021Äê12ÔÂÊ״α»·¢ÏÖ£¬Ñ¬È¾ÁËÈ«Çò195¸ö¹ú¼ÒµÄ35000¶ą̀µçÄÔ¡£
https://asec.ahnlab.com/en/31683/
Element VapeÔâµ½Magecart¹¥»÷Óû§ÐÅÓÿ¨ÐÅϢй¶
ýÌå2ÔÂ18Èճƣ¬´óÐ͵ç×ÓÑÌÍøÉÏÉ̵êElement VapeÔâµ½Magecart¹¥»÷¡£Ñо¿ÈËÔ±·¢ÏÖ£¬ÍøÕ¾µÄ¶à¸öÍøÒ³´æÔÚÒ»¶Îbase64±àÂë½Å±¾£¬½âÂëºó·¢ÏÖËü»áÔÚµÚÈý·½ÍøÕ¾ÏÂÔØÒ»¸öJavaScriptÎļþ£¬Ö¼ÔÚµ±Óû§½áÕËʱÊÕ¼¯ÆäÖ§¸¶¿¨ºÍÕ˵¥ÐÅÏ¢£¬È»ºó½«ÐÅϢͨ¹ýTelegram·¢Ë͸ø¹¥»÷Õß¡£Ä¿Ç°Éв»Çå³þ¸Ã¶ñÒâ½Å±¾´æÔڶ೤ʱ¼ä£¬µ«Element VapeÏÖÒÑÐÞ¸´´ËÎÊÌâ¡£
https://www.bleepingcomputer.com/news/security/popular-e-cigarette-store-was-compromised-to-steal-credit-cards/
Äþ¾²¹¤¾ß
Njsscan
ÓïÒå¸ÐÖª SAST ¹¤¾ß£¬¿ÉÒÔÔÚ Node.js Ó¦Ó÷¨Ê½ÖÐÕÒµ½²»Äþ¾²µÄ´úÂëģʽ¡£
https://github.com/ajinabraham/njsscan
Snaffler
ÊÇÒ»¸ö¹©ÉøÍ¸²âÊÔÕßʹÓõŤ¾ß¡£
https://github.com/SnaffCon/Snaffler
KrbRelay
ÖмÌKerberosƱ֤µÄΨһ¹«¹²¹¤¾ßºÍΨһÓà C# ±àдµÄÖм̿ò¼Ü¡£
https://securityonline.info/krbrelay-relaying-kerberos-tickets/
Zircolite
Zircolite ÊÇÓà Python 3 ±àдµÄ¶ÀÁ¢¹¤¾ß£¬ÔÚ MS Windows EVTX£¨EVTX ºÍ JSON ¸ñʽ£©ÉÏʹÓÃSIGMA¹æÔò¡£
https://github.com/wagga40/Zircolite
presshell
¿ÉÓÃÀ´ÔÚ wordpress ·þÎñÆ÷ÉÏÖ´ÐÐ shell ÃüÁî¡£
https://github.com/scheatkode/presshell
Äþ¾²·ÖÎö
Google Drive ½« macOS µÄ¡°.DS_Store¡±Îļþ±ê־ΪÇÖ·¸°æÈ¨
https://www.bleepingcomputer.com/news/security/google-drive-flags-macos-ds-store-files-for-copyright-violation/
Windows 11 µÄÐÂÈÎÎñ¹ÜÀíÆ÷
https://www.bleepingcomputer.com/news/microsoft/closer-look-at-windows-11s-new-task-manager/
NSA Ðû²¼Ñ¡ÔñÇ¿ Cisco ÃÜÂëÀàÐ͵ÄÖ¸ÄÏ
https://www.darkreading.com/vulnerabilities-threats/nsa-issues-guidance-for-selecting-strong-cisco-password-types
Ó¢ÌØ¶ûÈí¼þºÍ¹Ì¼þ¸üв¹¶¡ 18 ¸ßÑÏÖØÐÔ©¶´
https://www.securityweek.com/intel-software-and-firmware-updates-patch-18-high-severity-vulnerabilities
CISA¾¯¸æÕë¶ÔÃÀ¹úÒªº¦»ù´¡ÉèÊ©µÄÍþв
https://www.cisa.gov/uscert/ncas/current-activity/2022/02/18/cisa-insights-foreign-influence-operations-targeting-critical
΢ÈíÐû²¼Îª Windows Server Azure ÐéÄâ»úÌṩÈȲ¹¶¡
https://www.bleepingcomputer.com/news/microsoft/microsoft-announces-hotpatching-for-windows-server-azure-vms/