GoogleÐû²¼½ô¼±¸üÐÂÐÞ¸´ChromeÖÐÒѱ»ÀûÓõÄ©¶´
Ðû²¼Ê±¼ä 2022-04-15GoogleÔÚ4ÔÂ14ÈÕÐû²¼½ô¼±¸üУ¬ÐÞ¸´Chrome V8 JavaScriptÒýÇæÖеÄÒ»¸öÀàÐÍ»ìÏý©¶´£¨CVE-2022-1364£©¡£GoogleÔÚÄþ¾²Í¨¸æÖÐÌåÏÖ£¬ÒѾ¼ì²âµ½ÀûÓÃÕâ¸öÁãÈÕ©¶´µÄ¹¥»÷£¬µ«Ëü²¢Î´ÌṩÓйØÕâЩ¹¥»÷µÄ¸ü¶àϸ½Ú¡£ËäÈ»ÀàÐÍ»ìÏý©¶´Í¨³£»áͨ¹ýÔ½½ç¶ÁÈ¡»òдÈëµ¼ÖÂä¯ÀÀÆ÷Í߽⣬µ«¹¥»÷ÕßÒ²¿ÉÒÔÀûÓÃËüÃÇÀ´Ö´ÐÐÈÎÒâ´úÂë¡£ÓÉÓÚ´Ë©¶´ÒÑÔÚ¹¥»÷Öб»»ý¼«ÀûÓã¬Ñо¿ÈËԱǿÁÒ½¨ÒéÓû§ÊÖ¶¯¼ì²éиüв¢ÖØÆôä¯ÀÀÆ÷Ó¦ÓøüС£
https://www.bleepingcomputer.com/news/security/google-chrome-emergency-update-fixes-zero-day-used-in-attacks/
2¡¢Ñо¿ÍŶӳÆн©Ê¬ÍøÂçFodchaÒÑѬȾÁè¼Ý6Íǫ̀É豸
ýÌå3ÔÂ14ÈÕ±¨µÀ£¬Ð½©Ê¬ÍøÂçFodchaÔÚ3ÔÂ29ÈÕÖÁ4ÔÂ10ÈÕÆÚ¼äÒÑѬȾÁè¼Ý62000̨É豸¡£FodchaʹÓÃÁ˱©Á¦Æƽ⹤¾ßCrazyfia£¬²¢ÀÄÓÃÁ˶à¸önday©¶´À´Ñ¬È¾ÐÂÉ豸£¬Éæ¼°Android£¨ADBµ÷ÊÔ·þÎñÆ÷ÖÐRCE£©¡¢GitLab£¨CVE-2021-22205£©ºÍRealtek Jungle SDK£¨CVE-2021-35394£©µÈ¡£ËüÿÌì¶Ô100¶à¸öÄ¿±ê½øÐÐDDoS¹¥»÷£¬×Ô1ÔÂÒÔÀ´Ò»Ö±Ê¹ÓÃfolded[.]in£¬Ö±µ½3ÔÂ19ÈÕ¸ÃÓò±»È¡µÞºó£¬ËüÇл»µ½ÁËfrenchxperts[.]cc¡£
https://www.bleepingcomputer.com/news/security/new-fodcha-ddos-botnet-targets-over-100-victims-every-day/
3¡¢VMware³ÆWorkspace ONE AccessÖÐCVE-2022-22954Òѱ»ÀûÓÃ
¾ÝýÌå4ÔÂ13ÈÕ±¨µÀ£¬VMware Workspace ONE AccessÖеÄ©¶´CVE-2022-22954Òѱ»ÔÚÒ°ÀûÓá£VMwareÔÚÄþ¾²×ÉѯÖÐÖ¸³ö£¬¹¥»÷Õß¿ÉÒÔͨ¹ý·þÎñÆ÷¶ËÄ£°å×¢Èëµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£±¾ÖÜ£¬¶à¸öÑо¿ÈËÔ±Ðû²¼Á˹ØÓڸ鶴µÄ©¶´ÀûÓã¬ÒÔ¼°ÖÁÉÙÒ»¸öPoC¡£Bad Packets¼ì²âµ½ÊÔͼÀûÓø鶴µÄ»î¶¯£¬ÆäpayloadÖÐʹÓõÄIPµØÖ·»¹ÔÚÆäËü¹¥»÷ÖÐÓÃÀ´·Ö·¢ºóÃÅTsunami¡£
https://thehackernews.com/2022/04/vmware-releases-patches-for-critical.html
4¡¢Î¢Èíǣͷ¹Ø±Õ½©Ê¬ÍøÂçZLoaderµÄÊýʮ̨C2·þÎñÆ÷
4ÔÂ13ÈÕ£¬Î¢ÈíµÄÊý×Ö·¸×ﲿÃÅ(DCU)Ðû²¼Òѵ·»Ù½©Ê¬ÍøÂçZLoader¡£´Ë´ÎÐж¯ÎªÆÚÊýÔÂÖ®¾Ã£¬ÁªºÏÁËÈ«Çò¶à¼ÒµçÐÅÌṩÉ̺ÍÍøÂçÄþ¾²¹«Ë¾¡£Î¢Èí»ñµÃ·¨ÔºÃüÁîºó¹Ø±ÕÁËZLoaderµÄ65¸öÓ²±àÂëÓò£¬ÒÔ¼°ÁíÍâ319¸öʹÓÃÓòÉú³ÉË㷨ע²áµÄÓò£¬ÔÚÊÓ²ìÖл¹È·¶¨Á˸öñÒâÈí¼þµÄ¿ª·¢ÕßÖ®Ò»Denis Malikov¡£ZLoaderÓÚ2015Äê8ÔÂÊ״α»·¢ÏÖ£¬Ö÷ÒªÕë¶ÔÃÀ¹ú¡¢Öйú¡¢Î÷Å·ºÍÈÕ±¾£¬×î½ü±»Ryuk¡¢Egregor¡¢DarkSideºÍBlackMatterµÈ¶à¸öÀÕË÷ÍÅ»ïÀ´·Ö·¢payload¡£
https://blogs.microsoft.com/on-the-issues/2022/04/13/zloader-botnet-disrupted-malware-ukraine/
5¡¢AethonÐÞ¸´Ó°ÏìÆäTUG»úÆ÷È˵Ä©¶´JekyllBot:5
¾Ý4ÔÂ14ÈÕ±¨µÀ£¬Ò½ÁÆÎïÁªÍøÄþ¾²¹«Ë¾Cynerio·¢ÏÖÁËAethon TUG»úÆ÷ÈËÖеÄ5¸ö©¶´¡£Aethon TUGÖÇÄÜ»úÆ÷ÈËÒѱ»È«ÇòÊý°Ù¼ÒҽԺʹÓã¬ÓÃÓÚÔËËÍÒ©Æ·ºÍά»¤ÓÃÆ·£¬²¢Ö´Ðмòµ¥µÄÈÎÎñ¡£ÕâЩ©¶´Í³³ÆΪJekyllBot:5£¬·Ö±ðÊÇCVE-2022-1066¡¢CVE-2022-26423¡¢CVE-2022-1070¡¢CVE-2022-1070¡¢CVE-2022-27494¡¢CVE-2022-1059¡£CISA³Æ£¬ÀÖ³ÉÀûÓÃÕâЩ©¶´¿ÉÄܻᵼÖ¾ܾø·þÎñ״̬£¬²¢¿ÉÍêÈ«¿ØÖÆ»úÆ÷ÈË»ò̻¶Ãô¸ÐÐÅÏ¢¡£Ä¿Ç°£¬AethonÒÑÐû²¼¹Ì¼þ¸üÐÂÐÞ¸´ÕâЩ©¶´¡£
https://securityaffairs.co/wordpress/130157/security/jekyllbot5-flaws-tug-autonomous-mobile-robots.html
6¡¢FortinetÐû²¼KeksecÍÅ»ïµÄÐÂEnemybotµÄ·ÖÎö³ÂËß
4ÔÂ12ÈÕ£¬FortinetÐû²¼Á˹ØÓÚKeksecÍÅ»ïʹÓõÄн©Ê¬ÍøÂçEnemybotµÄ·ÖÎö³ÂËß¡£EnemybotÖ÷ÒªÔ´×ÔGafgyt£¬µ«Ò²½è¼øÁËMiraiµÄ¼¸¸öÄ£¿é¡£Ëü¾ßÓÐ×Ö·û´®»ìÏý¹¦Ð§£¬¶øÆäC2·þÎñÆ÷Òþ²ØÔÚTor½ÚµãÖУ¬ÕâʹµÃɾ³ýËü±äµÃ¼«¾ßÌôÕ½ÐÔ¡£¸Ã¶ñÒâÈí¼þÖ÷ҪʹÓõÄ©¶´°üÂÞSeowon Intech SLC-130ºÍSLR-120S·ÓÉÆ÷ÖеÄRCE(CVE-2020-17456)¡¢D-Link DWR·ÓÉÆ÷ÖеÄRCE£¨CVE-2018-10823£©ÒÔ¼°iRZÒƶ¯Â·ÓÉÆ÷ÖеÄÈÎÒâcronjob×¢È멶´£¨CVE-2022-27226£©¡£
https://www.fortinet.com/blog/threat-research/enemybot-a-look-into-keksecs-latest-ddos-botnet