ÀÕË÷ÍÅ»ïLapsus$Éù³ÆÒÑ´ÓÈýÐǵç×ÓÇÔÈ¡190GBµÄÊý¾Ý

Ðû²¼Ê±¼ä 2022-03-08

ÀÕË÷ÍÅ»ïLapsus$Éù³ÆÒÑ´ÓÈýÐǵç×ÓÇÔÈ¡190GBµÄÊý¾Ý


3ÔÂ4ÈÕ£¬ÀÕË÷ÍÅ»ïLapsus$Ðû²¼Ò»·ÝÉùÃ÷£¬³ÆÆäÒÑ´ÓÈýÐǵç×ÓÇÔÈ¡190GBµÄÊý¾Ý¡£¸ÃÍŻォÇÔÈ¡µ½µÄÊý¾Ý²ð·ÖΪÈý¸öѹËõÎļþ£¬·Ö±ðΪ£ºÓйØSecurity/Defense/Knox/Bootloader/TrustedAppsµÈÏîÄ¿µÄÔ´´úÂëºÍÏà¹ØÊý¾Ý£»ÓйØÉ豸Äþ¾²ºÍ¼ÓÃܵÄÔ´´úÂëºÍÏà¹ØÊý¾Ý£»À´×ÔÈýÐÇGithubµÄÖÖÖÖ´æ´¢¿â£¬ÈçÒÆ¶¯·ÀÓù¹¤³Ì¡¢ÈýÐÇÕÊ»§ºó¶Ë¡¢ÈýÐÇͨÐÐÖ¤ºó¶Ë/ǰ¶ËºÍSES¡£Éв»Çå³þLapsus$ÊÇ·ñÁªÏµÁËÈýÐÇË÷ÒªÊê½ð£¬ÈýÐÇҲδ¶Ô´ËÊÂ×÷³ö»ØÓ¦¡£


https://securityaffairs.co/wordpress/128712/cyber-crime/samsung-electronics-lapsus-ransomware.html


Ñо¿ÈËÔ±·¢ÏÖ¶à¸ö¶ñÒâÈí¼þÀûÓÃй¶µÄNVIDIAÖ¤ÊéÇ©Ãû


¾ÝýÌå3ÔÂ5ÈÕ±¨µÀ£¬¹¥»÷ÕßÕýÔÚʹÓñ»µÁµÄNVIDIAÖ¤Êé¶Ô¶ñÒâÈí¼þ½øÐÐÇ©Ãû¡£NVIDIAÔÚÉÏÖÜÔâµ½¹¥»÷£¬ÀÕË÷ÍÅ»ïLapsus$ÇÔÈ¡²¢Ð¹Â¶Á˸ù«Ë¾1TBµÄÊý¾Ý¡£ÆäÖаüÂÞ2¸ö´úÂëÇ©ÃûÖ¤Ê飬NVIDIAµÄ¿ª·¢ÈËԱʹÓÃËüÃÇÀ´Ç©ÃûÇý¶¯·¨Ê½ºÍ¿ÉÖ´ÐÐÎļþ¡£Æ¾¾ÝÉÏ´«µ½VirusTotalÑù±¾£¬Ñо¿ÈËÔ±·¢ÏÖÕâЩ֤Êé±»ÓÃÓÚ¶à¸ö¶ñÒâÈí¼þºÍºÚ¿Í¹¤¾ßµÄÇ©Ãû£¬ÀýÈçCobalt Strike¡¢Mimikatz¡¢Quasar¡¢ÒÔ¼°¶àÖÖºóÃźÍľÂíµÈ¡£


https://www.bleepingcomputer.com/news/security/malware-now-using-nvidias-stolen-code-signing-certificates/


SharkBotαװ³Éɱ¶¾Èí¼þͨ¹ýGoogle PlayÉ̵ê·Ö·¢


3ÔÂ3ÈÕ£¬NCC GroupÅû¶Á˶ñÒâÈí¼þSharkBotµÄ·Ö·¢»î¶¯µÄϸ½ÚÐÅÏ¢¡£Ôڴ˴λÖУ¬SharkBotαװ³É¾ßÓÐϵͳÇåÀí¹¦Ð§µÄɱ¶¾Èí¼þ£¬Í¨¹ýAndroidÓ¦ÓÃÉ̳ÇGoogle Play Store½øÐзַ¢¡£¸Ã¶ñÒâÈí¼þÓÚ2021Äê10ÔÂÓÉCleafyÊ״η¢ÏÖ£¬ÓëÆäËüÒøÐÐľÂíµÄÇø±ðÊÇ¿ÉÒÔͨ¹ý×Ô¶¯×ªÕËϵͳ(ATS)½øÐÐתÕË¡£´ËÍ⣬Ëü»¹¿ÉÒÔͨ¹ýͨ¹ý¡°×Ô¶¯»Ø¸´¡±¹¦Ð§£¬Ö±½Ó´ÓC2ÏÂÔØ¾ßÓÐATS¹¦Ð§µÄSharkBot²¢×Ô¶¯°²×°ÔÚÄ¿±êÉ豸ÉÏ¡£


https://research.nccgroup.com/2022/03/03/sharkbot-a-new-generation-android-banking-trojan-being-distributed-on-google-play-store/


Imperva³ÆÆäÒѵÖÓù¸ß´ï250ÍòRPSµÄÀÕË÷DDoS¹¥»÷»î¶¯


Äþ¾²¹«Ë¾ImpervaÔÚ3ÔÂ4ÈÕÌåÏÖ£¬Ëü×î½üµÖÓùÁ˸ߴïÿÃë250Íò´ÎÇëÇó(RPS)µÄÀÕË÷DDoS¹¥»÷»î¶¯¡£¹¥»÷µÄÖ÷ÒªÀ´Ô´ÊÇÓ¡¶ÈÄáÎ÷ÑÇ£¬Æä´ÎÊÇÃÀ¹ú¡¢Öйú¡¢°ÍÎ÷ºÍÓ¡¶ÈµÈ¡£¹¥»÷Õß×Ô³ÆÊÇREvil£¬Éв»Çå³þÕâÊÇÕæµÄREvilÍŻﻹÊÇðÃû¶¥ÌæÕߣ¬ImpervaÊÕ¼¯µÄÖ¤¾Ý±íÃ÷´Ë´ÎDDoS¹¥»÷Ô´×Ô½©Ê¬ÍøÂçM¨¥ris¡£´ËÍ⣬±»¹¥»÷µÄ×éÖ¯ÔÚ¹¥»÷ÆÚ¼äÊÕµ½Á˶à·ÝÊê½ð֪ͨ¡£


https://thehackernews.com/2022/03/imperva-thwarts-25-million-rps-ransom.html


AvastÐû²¼Õë¶ÔÀÕË÷Èí¼þHermeticRansomµÄÃâ·Ñ½âÃÜÆ÷


ýÌå3ÔÂ3ÈÕ±¨µÀ£¬Äþ¾²¹«Ë¾AvastÐû²¼ÁË×Ô2ÔÂ23ÈÕ¿ªÊ¼¹¥»÷ÎÚ¿ËÀ¼µÄÀÕË÷Èí¼þHermeticRansomµÄÃâ·Ñ½âÃÜÆ÷¡£Ö®Ç°£¬CrowdstrikeµÄÑо¿ÈËÔ±·¢ÏÖÆä¼ÓÃܹý³ÌÖдæÔÚÒ»¸öÂß¼­Â©¶´£¬¿É±»ÓÃÀ´ÆÆ½â¼ÓÃÜ¡£×¨¼ÒÍÆ²â£¬¿ª·¢ÈËÔ±ÔÚ²âÊÔÀÕË÷Èí¼þµÄ·½ÃæÍ¶ÈëµÄ¾«Á¦ÓÐÏÞ£¬¿ÉÄÜÊÇÒòΪ¼ÓÃܲ¢²»ÊÇÆä×îÖÕÄ¿±ê¡£Avast»¹Ðû²¼ÁËÀûÓýâÃÜÆ÷»Ö¸´Êý¾ÝµÄÏêϸ˵Ã÷¡£


https://securityaffairs.co/wordpress/128652/breaking-news/free-decryptor-hermeticransom-ukraine.html


MozillaÐû²¼Äþ¾²¸üÐÂÐÞ¸´FirefoxÖÐ2¸öÒѱ»ÀûÓõÄ0day


¾Ý3ÔÂ6Èյı¨µÀ£¬Mozilla Firefox 97.0.2ÐÞ¸´ÁË2¸öÒѱ»»ý¼«ÀûÓõÄÁãÈÕ©¶´¡£Õâ2¸ö©¶´·Ö±ðΪXSLT²ÎÊý´¦ÖÃÖеÄÊͷźóʹÓé¶´£¨CVE-2022-26485£©£¬ÒÔ¼°WebGPU IPC¿ò¼ÜÖеÄÊͷźóʹÓé¶´£¨CVE-2022-26486£©¡£MozillaûÓйûÈ»¹¥»÷ÕßÊÇÈçºÎÀûÓÃÕâЩ©¶´µÄ£¬µ«ºÜ¿ÉÄÜÊÇͨ¹ý½«FirefoxÓû§Öض¨Ïòµ½¶ñÒâÍøÒ³À´Íê³ÉµÄ¡£ÓÉÓÚÕâЩ©¶´µÄÑÏÖØÐÔ¼°ÆäÕý±»ÀûÓã¬Ñо¿ÈËÔ±½¨ÒéËùÓÐÓû§Á¢¼´°²×°¸üС£


https://www.bleepingcomputer.com/news/security/mozilla-firefox-9702-fixes-two-actively-exploited-zero-day-bugs/



Äþ¾²¹¤¾ß


Osmedeus


½ø¹¥ÐÔÄþ¾²µÄÊÂÇéÁ÷ÒýÇæ¡£


https://github.com/j3ssie/osmedeus



PyShell


¶àƽ̨Python WebShell£¬¿ÉÔÚ Web ·þÎñÆ÷ÉÏ»ñµÃÀàËÆ shell µÄ½çÃæÒÔ½øÐÐÔ¶³Ì·ÃÎÊ¡£


https://github.com/JoelGMSec/PyShell



Authz0


×Ô¶¯ÊÚȨ²âÊÔ¹¤¾ß£¬¿ÉÒÔÆ¾¾Ý URL ºÍ Roles ºÍ Credentials ʶ±ðδ¾­ÊÚȨµÄ·ÃÎÊ¡£


https://github.com/hahwul/authz0



patching


¸ÃÏîÄ¿À©Õ¹ÁËÁ÷ÐеÄIDA Pro·´»ã±à·¨Ê½£¬ÒÔ´´½¨¸üÇ¿´óµÄ½»»¥Ê½¶þ½øÖÆÐÞ²¹ÊÂÇéÁ÷³Ì£¬Ö¼ÔÚʵÏÖ¿ìËÙµü´ú¡£


https://github.com/gaasedelen/patching



shfz


»ùÓÚ TypeScript ³¡¾°µÄ Web Ó¦Ó÷¨Ê½Ä£ºý²âÊÔ¿ò¼Ü¡£


https://github.com/shfz/shfz



Äþ¾²·ÖÎö


¶íÂÞ˹¹ûÈ» 17,000 ¸ö IP µÄÃûµ¥£¬¾Ý³ÆÊǶíÂÞ˹×éÖ¯DDOS


https://www.bleepingcomputer.com/news/security/russia-shares-list-of-17-000-ips-allegedly-ddosing-russian-orgs/


ÎÚ¿ËÀ¼¼ÓÈë±±Ô¼Ç鱨¹²ÏíÍøÂç·ÀÓùÖÐÐÄ


https://www.bleepingcomputer.com/news/government/ukraine-to-join-nato-intel-sharing-cyberdefense-hub/


Ñо¿ÈËÔ±¶Ø´Ù²»ÒªÔÚÍøÂçä¯ÀÀÆ÷ÖÐÇ¿ÖÆÊ¹Óò»Äþ¾²µÄÖ¤Êé


https://www.bleepingcomputer.com/news/security/experts-urge-eu-not-to-force-insecure-certificates-in-web-browsers/


¶íÂÞ˹½ûÖ¹·ÃÎÊ Facebook¡¢Twitter¡¢Íâ¹úÐÂÎÅýÌå


https://www.bleepingcomputer.com/news/technology/russia-blocks-access-to-facebook-twitter-foreign-news-outlets/


ÃÀ¹ú²ÎÒéԺͨ¹ýÍøÂçÄþ¾²·¨°¸ÒÔ¼ÓǿҪº¦»ù´¡ÉèÊ©Äþ¾²


https://thehackernews.com/2022/03/us-senate-passes-cybersecurity-bill-to.html