JFrog·¢ÏÖ200¶à¸öÕë¶ÔAzure¿ª·¢ÈËÔ±µÄ¶ñÒâNPM°ü

Ðû²¼Ê±¼ä 2022-03-28

JFrog·¢ÏÖ200¶à¸öÕë¶ÔAzure¿ª·¢ÈËÔ±µÄ¶ñÒâNPM°ü


JFrogÔÚ3ÔÂ23ÈÕÐû²¼³ÂË߳ƣ¬·¢ÏÖÁËÖÁÉÙ218¸öÖ¼ÔÚÇÔÈ¡¸öÈËÉí·ÝÐÅÏ¢µÄ¶ñÒâNPM°ü¡£ÕâÊÇÕë¶ÔAzure¿ª·¢ÈËÔ±µÄ´ó¹æÄ£¹©Ó¦Á´¹¥»÷£¬¹¥»÷ÕßÀûÓÃÁËÓòÃû·ÂðµÄ¹¥»÷·½Ê½£¬²¢Ê¹ÓÃ×Ô¶¯½Å±¾´´½¨ÕÊ»§²¢ÉÏ´«¶ñÒâ°ü£¬ÒÔÑÚ¸ÇÕâЩ¶ñÒâ°ü¶¼À´×Ôͬһ¿ª·¢ÕßµÄÊÂʵ¡£´ËÀàNPM°üÒ»µ©±»°²×°ºó£¬¾Í»áÊÕ¼¯ÓйØÓû§µ±Ç°ÊÂÇéĿ¼£¬ÒÔ¼°ÓëÍøÂç½Ó¿ÚºÍDNS·þÎñÆ÷Ïà¹ØµÄIPµØÖ·µÄÐÅÏ¢£¬²¢½«ÕâЩÊý¾Ý·¢Ë͵½Ó²±àÂëµÄÔ¶³Ì·þÎñÆ÷¡£Ä¿Ç°£¬ÕâЩ¶ñÒâNPM°üÒѱ»É¾³ý¡£


https://thehackernews.com/2022/03/over-200-malicious-npm-packages-caught.html


΢Èí¸üе¼ÖÂWindows Server 2019µÄDNS½âÎöʧ°Ü


¾ÝýÌå3ÔÂ24ÈÕ±¨µÀ£¬ÔÚ°²×°2022Äê1ÔÂ25ÈÕÐû²¼µÄ¸üÐÂ(KB5009616)ºó£¬Windows Server 2019µÄDNS½âÎö¿ÉÄ᷺ܻÆðÎÊÌâ¡£ÕâÊÇDNS´æ¸ùÇøÓòÎÞ·¨ÕýÈ·¼ÓÔØµ¼ÖµÄ£¬¿ÉÄÜ´¥·¢´ËDNS½âÎöÎÊÌâµÄÁíÍâÁ½¸öWindows¸üÐÂÊÇKB5010427£¨2ÔÂ15ÈÕÐû²¼£©ºÍKB5011551£¨3ÔÂ22ÈÕÐû²¼£©¡£Ä¿Ç°£¬MicrosoftÒÑͨ¹ýÒÑÖªÎÊÌâ»Ø¹ö(KIR)¹¦Ð§ÐÞ¸´ÁË´ËÎÊÌâ¡£ÒªÐÞ¸´´ËÎÊÌ⣬¹ÜÀíÔ±»¹Ðè°²×°ºÍÅäÖÃÁ½¸ö×鼯ı¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-recent-windows-server-updates-cause-dns-issues/


VMwareÐû²¼¸üУ¬ÐÞ¸´ÆäCarbon BlackÖеÄ2¸ö©¶´


3ÔÂ23ÈÕ£¬VMwareÐû²¼Á˸üУ¬ÐÞ¸´Ó°ÏìÆäCarbon Black App Controlƽ̨µÄ2¸ö©¶´¡£Carbon BlackÊÇÓ¦Ó÷¨Ê½¿ØÖƽâ¾ö·½°¸£¬´Ë´ÎÐÞ¸´µÄ©¶´·Ö±ðΪÃüÁî×¢Èë©¶´£¨CVE-2022-22951£©£¬¿ÉÓÉÓÚÊäÈëÑéÖ¤²»Í×¶øµ¼ÖÂÔ¶³ÌÖ´ÐдúÂë £»ÒÔ¼°ÎļþÉÏ´«Â©¶´£¨CVE-2022-22952£©£¬¹¥»÷Õß¿ÉÉÏ´«ÌØÖÆÎļþÀ´Ö´ÐÐÈÎÒâ´úÂë¡£ÕâЩ©¶´µÄCVSSÆÀ·Ö¾ùΪ9.1£¬µ«ÀÖ³ÉÀûÓÃËüÃǵÄǰÌáÊǾßÓйÜÀíÔ±»ò¸ü¸ßȨÏÞ¡£


https://thehackernews.com/2022/03/vmware-issues-patches-for-critical.html


ÎÚ¿ËÀ¼CERT-UAÐû²¼¹ØÓÚDoubleZero¹¥»÷»î¶¯µÄ¾¯±¨


ýÌå3ÔÂ23ÈÕ±¨µÀ£¬ÎÚ¿ËÀ¼CERT-UAÔÚ½üÆÚÐû²¼ÁËÒ»·Ýͨ¸æ£¬¾¯¸æDoubleZeroÕë¶ÔÎÚ¿ËÀ¼×éÖ¯µÄ¹¥»÷¡£Í¨¸æÖ¸³öÓÚ3ÔÂ17ÈÕÊ״η¢Ïֻ£¬¹¥»÷ÕßʹÓÃÓã²æÊ½µöÓã¹¥»÷·Ö·¢¶ñÒâÈí¼þ¡£µöÓãÓʼþ°üÂÞÒ»¸ö»ìÏýµÄ.NET·¨Ê½£¬±»ÃüÃûΪDoubleZero£¬ÊÇΪÁËÆÆ»µÄ¿±êϵͳ¶ø¿ª·¢µÄ¡£DoubleZero wipeʹÓÃÁË2ÖÖ¼¼Êõ£¬Ê¹ÓÃ4096×Ö½ÚÁýÕÖÆäÄÚÈÝ£¨Ê¹ÓÃFileStream.Write£©£¬»òʹÓÃAPIµ÷ÓÃNtFileOpenºÍNtFsControlFile(code:FSCTL_SET_ZERO_DATA)£¬×îºó»¹»áɾ³ýWindows×¢²á±íHKCU¡¢HKU¡¢HKLMºÍHKLM\BCD¡£


https://securityaffairs.co/wordpress/129417/malware/doublezero-wiper-hit-ukraine.html


¹¥»÷ÕßÀûÓÃαװµÄÆÆ½âRATµÈ¶ñÒâÈí¼þÇÔȡĿ±êµÄÐÅÏ¢


¾Ý2ÔÂ23ÈÕ±¨µÀ£¬¶à¸öÄþ¾²ÍŶӷ¢ÏÖÁËÀûÓÃαÔìµÄ¶ñÒâÈí¼þ¹¥»÷ºÚ¿ÍµÄ»î¶¯¡£ASECÔÚRussia black hatµÈºÚ¿ÍÂÛ̳ÉÏ·¢ÏÖαװ³ÉÆÆ½â°æBitRATºÍQuasar RATµÄÇÔÈ¡·¨Ê½£¬Ä¿±êÔÚµã»÷ÓÕ¶üÁ´½Óºó»á±»Öض¨Ïòµ½Ò»¸öAnonfilesÒ³Ãæ£¬È»ºó»áÏÂÔØ¶ñÒâÈí¼þClipBanker¡£Cyble·¢ÏÖÁËÉù³ÆÊÇÌṩһ¸öÔÂÃâ·ÑAvD Crypto StealerµÄ»î¶¯£¬Ä¿±êÔÚÏÂÔØËùνµÄ¶ñÒâÈí¼þ¹¹½¨Æ÷²¢Æô¶¯ÃûΪ¡°Payload.exe¡±µÄÎļþºó£¬»áѬȾÕë¶ÔEthereumµÈµÄclipper¶ñÒâÈí¼þ¡£¸Ã»î¶¯ÒѽٳÖÁË422±Ê½»Òײ¢ÇÔÈ¡ÁË1.3±ÈÌØ±Ò£¨Ô¼54000ÃÀÔª£©¡£


https://www.bleepingcomputer.com/news/security/hackers-steal-from-hackers-by-pushing-fake-malware-on-forums/


VolexityÐû²¼ÐÂGimmickÃé×¼macOSÓû§µÄ·ÖÎö³ÂËß


3ÔÂ22ÈÕ£¬Äþ¾²¹«Ë¾VolexityÐû²¼ÁËжñÒâÈí¼þGimmickÃé×¼macOSÓû§µÄ·ÖÎö³ÂËß¡£´Ë´Î»î¶¯¿ªÊ¼ÓÚ2021Äêµ×£¬À´×ÔÓÚStorm CloudÍŻ¸ÃmacOS±äÌåÖ÷ҪʹÓÃObjective C±àд£¬¶øWindows°æ±¾Ê¹ÓÃÁË.NETºÍDelphi¡£Àֳɰ²×°ºó£¬Gimmick¿ÉÒÔ×÷ÎªÊØ»¤·¨Ê½Æô¶¯£¬Ò²¿ÉÒÔÒÔ¶¨ÖÆÓ¦Ó÷¨Ê½µÄÐÎʽÆô¶¯£¬²¢±»ÅäÖÃΪ½öÔÚÊÂÇéÈÕÓëC2½øÐÐͨÐÅ¡£´ËÍ⣬Ëü»¹¾ßÓÐ×ÔÎÒÐ¶ÔØ¹¦Ð§£¬¿ÉÒÔ½«×Ô¼º´ÓÄ¿±êÉ豸ÉÏɾ³ý¡£


https://www.volexity.com/blog/2022/03/22/storm-cloud-on-the-horizon-gimmick-malware-strikes-at-macos/




Äþ¾²¹¤¾ß


catalyst


ÊÇÒ»¸ö SOAR ϵͳ£¬¿É×Ô¶¯»¯¾¯±¨´¦ÖúÍʼþÏìÓ¦Á÷³Ì¡£


https://catalyst-soar.com/


Auto-Elevate


ÇÔÈ¡²¢Ä£ÄâÆä½ø³Ì TOKEN£¬²¢Ê¹Óñ»µÁÁîÅÆÉú³ÉÒ»¸öÐ嵀 SYSTEM ¼¶½ø³Ì


https://github.com/FULLSHADE/Auto-Elevate


ICMP-TransferTools


ÊÇÒ»×é½Å±¾£¬Ö¼ÔÚÔÚÊÜÏÞÍøÂç»·¾³Öн«ÎļþÒÆÈëºÍÒÆ³ö Windows Ö÷»ú¡£


https://github.com/icyguider/ICMP-TransferTools


HTTP Smuggling Calculator


ͨ¹ý×Ô¶¯ÖÆ×÷ HTTP ÇëÇóÀ´Ö´ÐÐ CL.TE ºÍ TE.CL HTTP ÇëÇó×ß˽¹¥»÷¡£


https://github.com/kleiton0x00/HTTP-Smuggling-Calculator




Äþ¾²·ÖÎö


FBI£º2021 ÄêÒòÍøÂç·¸×ïËðʧ 69 ÒÚÃÀÔª


https://therecord.media/fbi-6-9-billion-lost-through-internet-crimes-in-2021/


ÃÀ¹úÆðËß¶íÂÞ˹Igor DekhtyarchukÔËÓª°µÍøÂÛ̳ 


https://www.bleepingcomputer.com/news/security/fbi-adds-russian-cybercrime-market-owner-to-most-wanted-list/


¶íÂÞ˹½ûÓùȸèÐÂÎÅ


https://www.bleepingcomputer.com/news/technology/russia-bans-google-news-for-unreliable-info-on-war-in-ukraine/


Microsoft PowerToys ÖÐ¶Ï Outlook PDF Ô¤ÀÀ


https://www.bleepingcomputer.com/news/microsoft/microsoft-powertoys-breaks-outlook-pdf-preview/


΢ÈíÐÞ¸´Á˵¼Ö Windows À¶ÆÁµÄÀ¶ÑÀÎÊÌâ


https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-bluetooth-issue-causing-windows-blue-screens/


Anonymous Ìᳫ´ó¹æÄ£µÄ¡°Ó¡Ë¢¹¥»÷¡±


https://www.hackread.com/anonymous-hacks-unsecured-printers-message-russia/