΢ÈíÐû²¼7Ô·ÝÄþ¾²¸üУ¬×ܼÆÐÞ¸´84¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2022-07-13
1¡¢Î¢ÈíÐû²¼7Ô·ÝÄþ¾²¸üУ¬×ܼÆÐÞ¸´84¸öÄþ¾²Â©¶´

      

7ÔÂ12ÈÕ£¬Î¢ÈíÐû²¼7Ô·ݵÄÖܶþ²¹¶¡£¬ÐÞ¸´Á˰üÂÞÒ»¸öÒѱ»ÀûÓõÄ0 dayÔÚÄÚµÄ84¸ö©¶´¡£´Ë´ÎÐÞ¸´ÁË52¸öÌáȨ©¶´¡¢4¸öÄþ¾²¹¦Ð§Èƹý©¶´¡¢12¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´¡¢11¸öÐÅϢй¶©¶´ºÍ5¸ö¾Ü¾ø·þÎñ©¶´¡£ÆäÖУ¬Òѱ»ÔÚÒ°ÀûÓõÄ©¶´ÊÇWindows CSRSSȨÏÞÌáÉý©¶´£¨CVE-2022-22047£©£¬Î¢Èí½âÊͳÆÀÖ³ÉÀûÓôË©¶´¿É»ñµÃϵͳȨÏÞ¡£´ËÍ⣬ÐÞ¸´µÄ½ÏΪÑÏÖØµÄ©¶´°üÂÞWindowsͼÐÎ×é¼þÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2022-30221£©ºÍWindows ÍøÂçÎļþϵͳԶ³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2022-22029£©µÈ¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2022-patch-tuesday-fixes-exploited-zero-day-84-flaws/


2¡¢ÐÂÀÕË÷Èí¼þHavanaCryptαװ³ÉGoogleÈí¼þ¸üÐÂÀ´·Ö·¢

     

Trend MicroÔÚ7ÔÂ6ÈÕÅû¶ÁËÐÂÀÕË÷Èí¼þHavanaCryptµÄ·Ö·¢»î¶¯¡£Ôڴ˴λÖУ¬¶ñÒâÈí¼þαװ³ÉGoogleÈí¼þ¸üÐÂÓ¦Ó÷¨Ê½£¬²¢Ê¹ÓÃMicrosoftÍøÂçÍйܷþÎñIPµØÖ·×÷ΪÆäC2·þÎñÆ÷À´ÈƹýÄþ¾²¼ì²â¡£´ËÍ⣬Ñо¿ÈËÔ±·¢ÏÖ£¬ÀÕË÷Èí¼þÔÚ¼ÓÃÜÆÚ¼äʹÓÃÀ´×Ô¿ªÔ´ÃÜÔ¿¹ÜÀíÆ÷KeePass Password Safe´úÂ룬²¢Ê¹ÓÃÃûΪ¡°QueueUserWorkItem¡±µÄ.Netº¯ÊýÀ´¼ÓËÙ¼ÓÃÜ¡£Trend MicroÖ¸³ö£¬HavanaCrypt¿ÉÄÜÈÔ´¦ÓÚ¿ª·¢½×¶Î£¬ÒòΪËü²»»áÔÚ±»Ñ¬È¾µÄϵͳÉÏÁôÏÂÊê½ð¼Ç¼¡£


https://www.trendmicro.com/en_us/research/22/g/brand-new-havanacrypt-ransomware-poses-as-google-software-update.html


3¡¢Anubis NetworksÔٴλع飬Õë¶Ô°ÍÎ÷ºÍÆÏÌÑÑÀµöÓã¹¥»÷ 

      

¾ÝSeguran?a Inform¨¢ticaÔÚ7ÔÂ10ÈÕ±¨µÀ£¬Anubis NetworkÒÑ´ø×ÅеÄC2·þÎñÆ÷»Ø¹é¡£´Ë´Î»î¶¯×Ô2022Äê3Ô¿ªÊ¼£¬Ö÷ÒªÕë¶Ô°ÍÎ÷ºÍÆÏÌÑÑÀµÄ»¥ÁªÍøÓû§¡£¸Ã»î¶¯ÓÉÈý¸öÒªº¦µÄ²¿ÃÅ×é³É£ºÔÚÒ°Á÷´«Ðé¼ÙµÇÂ¼Ò³ÃæµÄ½»¸¶¹¤¾ß£¬Í¨³£Í¨¹ý¶ÌÐź͵öÓãµç×ÓÓʼþ½øÐУ»ÍйÜÔÚÔÆ·þÎñÆ÷ÉϵĶñÒâµÇÂ¼Ò³Ãæ£¬ÓÉÓëÕæÊµÏµÍ³·Ç³£ÏàËÆµÄÓû§½çÃæºÍ½á¹¹×é³É£»Ò»¸ö¿ØÖƺó¶Ë£¬±»¹¥»÷ÕßÓÃÓÚ¹ÜÀíÄ¿±êÓû§µÄÏêϸÐÅÏ¢¡£


https://seguranca-informatica.pt/anubis-networks-is-back-with-new-c2-server/#.Ys0jP3ZBxPa


4¡¢Ó¢¹ú½ðÈÚ·þÎñ¹«Ë¾Aon½ü15Íò¸ö±±ÃÀ¿Í»§µÄ¸öÈËÐÅϢй¶

      

¾ÝýÌå7ÔÂ8ÈÕ±¨µÀ£¬Ó¢¹ú¿ç¹ú½ðÈÚ·þÎñ¹«Ë¾âù°²£¨Aon£©145889¸ö±±ÃÀ¿Í»§µÄÐÅϢй¶¡£¸Ã¹«Ë¾ÌåÏÖ£¬´Ó2020Äê12ÔÂ29ÈÕµ½2022Äê2ÔÂ26ÈÕ£¬ºÚ¿ÍÔÚ²îÒìʱ¼äÄÚÈëÇÖÁËÆäϵͳ¡£ÊÜÓ°ÏìµÄÐÅÏ¢°üÂÞ¼ÝÕÕºÅÂë¡¢Éç»áÄþ¾²ºÅÂëºÍ¸£Àû¹ÒºÅÐÅÏ¢µÈ¡£AonÉù³ÆÒѽÓÄÉ´ëʩȷÈÏδ¾­ÊÚȨµÄµÚÈý·½²»ÔÙÓÐȨ·ÃÎÊÊý¾Ý£¬ÇÒÐÅÏ¢²¢Î´±»ÀÄÓá£ÓÉÓÚÊý¾Ýй¶Ê¼þ£¬AonÃæÁÙÖÁÉÙÁ½Æð¼¯ÌåËßËÏ¡£´ËÍ⣬¸Ã¹«Ë¾ÎªÊÜÓ°ÏìµÄ¿Í»§ÌṩÁË24¸öÔµÄÉí·Ý±£»¤·þÎñ¡£


https://www.infosecurity-magazine.com/news/aon-hack-sensitive-information/


5¡¢Resecurity³ÆÀÕË÷ÍÅ»ïALPHVÒªÇóµÄÊê½ðÒÑ´ï250ÍòÃÀÔª

     

¾Ý7ÔÂ10ÈÕ±¨µÀ£¬ÀÕË÷ÍÅ»ïALPHV£¨ÓÖÃûBlackCat£©ÒªÇóµÄÊê½ðÒÑ´ï250ÍòÃÀÔª¡£ALPHVÖÁÉÙ´ÓÈ¥Äê11Ô¾ͿªÊ¼ÔËÓªÁË£¬Ëü¿ªÊ¼ÒªÇó250ÍòÃÀÔªºÍ½Ó½üÒ»°ëµÄÕÛ¿Û£¬ÒÔ¼¤ÀøÄ¿±ê¾¡¿ì¸¶Êê½ð£¬Áô¸øÄ¿±êµÄÖ§¸¶Ê±¼äÔÚ5-7Ìì²»µÈ¡£ResecurityÌåÏÖ£¬×Ô2020ÄêÒÔÀ´£¬Æ½¾ùÀÕË÷Êê½ð¶îÔö¼ÓÁË82%£¬ÖÁ2021ÄêÉϰëÄêΪ570000ÃÀÔª£¬µ½´ïÀúʷиߣ¬È»ºóµ½2022Ä꼸ºõ·­ÁËÒ»·¬¡£×îÐÂÔ¤²âÊǵ½2031Ä꣬ȫÇòÀÕË÷»î¶¯½«µ½´ï2650ÒÚÃÀÔª£¬¶ÔÈ«ÇòÆóÒµÔì³ÉµÄ×ÜËðʧ½«µ½´ï10.5ÍòÒÚÃÀÔª¡£


https://resecurity.com/blog/article/blackcat-aka-alphv-ransomware-is-increasing-stakes-up-to-25m-in-demands


6¡¢KasperskyÐû²¼ÓйػùÓÚÎı¾µÄÆÛÕ©»î¶¯µÄ·ÖÎö³ÂËß

      

7ÔÂ11ÈÕ£¬KasperskyÐû²¼ÁËÓйػùÓÚÎı¾µÄÆÛÕ©»î¶¯µÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬»ùÓÚÎı¾µÄÆÛÕ©¿ÉÒÔ·ÖΪ¼¸ÖÖÀàÐÍ£ºÔ¼»áÕ©Æ­¡¢419Õ©Æ­¡¢ÇÃÕ©ÀÕË÷ºÍÓïÒôÍøÂçµöÓã¡£ÆäÖУ¬Ô¼»áÕ©Æ­ÊÇ×î²»³£¼ûµÄÀàÐÍ£¬´Ó2022Äê3Ôµ½6Ô£¬¼ì²âµ½49536Ìõ´ËÀàÏûÏ¢£»419Õ©Æ­ÊÇ×î¹ÅÀϵÄÀàÐÍÖ®Ò»£¬Í¨³£ÊǼÙðµÄÂÉʦ¼û¸æÄ¿±êÒѹʵÄÇׯÝÒѽ«¾Þ¶î²Æ¸»ÒÅÔù¸øËûÃÇ£¬Ã¿Ô»á¼ì²âµ½ÊýÊ®ÍòÌõ´ËÀàÏûÏ¢£»ÇÃÕ©ÀÕË÷µÄÓʼþÒª±ÈÆäËüÀàÐͶàµÃ¶à£¬´Ó3Ôµ½6ÔÂÓÐÁè¼Ý1200ÍòÌõÀÕË÷ÐÅÏ¢£»3Ôµ½6Ô£¬Ñо¿ÈËÔ±¼ì²âµ½347141·âÓïÒôµöÓãÓʼþ¡£


https://securelist.com/mail-text-scam/106926/