Eclypsium·¢ÏÖ3¸ö½Ó¿Ú¿ÉÈÆ¹ýUEFIµÄÄþ¾²Òýµ¼¹¦Ð§

Ðû²¼Ê±¼ä 2022-08-15
1¡¢Eclypsium·¢ÏÖ3¸ö½Ó¿Ú¿ÉÈÆ¹ýUEFIµÄÄþ¾²Òýµ¼¹¦Ð§

      

¾Ý8ÔÂ12ÈÕ±¨µÀ£¬EclypsiumÔÚ3¸öµÚÈý·½Í³Ò»¿ÉÀ©Õ¹¹Ì¼þ½Ó¿Ú(UEFI)Òýµ¼¼ÓÔØ·¨Ê½Öз¢ÏÖÁËÄþ¾²¹¦Ð§Èƹý©¶´£¬¿ÉÓÃÀ´ÈƹýUEFIÄþ¾²Òýµ¼¹¦Ð§ ¡£ÕâÊÇÓÉMicrosoftÇ©ÃûºÍÑéÖ¤µÄÌØ¶¨¹©Ó¦É̵ÄÒýµ¼¼ÓÔØ·¨Ê½£¬·Ö±ðΪEurosoftÒýµ¼¼ÓÔØ·¨Ê½(CVE-2022-34301)¡¢New Horizon Data Systems IncÒýµ¼¼ÓÔØ·¨Ê½(CVE-2022-34302)ºÍCrypto ProÒýµ¼¼ÓÔØ·¨Ê½(CVE-20220-34303) ¡£¹¥»÷Õß¿ÉÒÔÀûÓÃÕâЩ©¶´ÔÚÄ¿±êÉϽ¨Á¢³Ö¾ÃÐÔ£¬¶ø²»»áÒòÎªÖØÐ°²×°ÏµÍ³±»É¾³ý£¬Î¢ÈíÒÑͨ¹ýÉÏÖÜÐû²¼µÄÖܶþ²¹¶¡½øÐÐÐÞ¸´ ¡£


https://thehackernews.com/2022/08/researchers-uncover-uefi-secure-boot.html


2¡¢¹È¸èÒòÊÕ¼¯AndroidλÖÃÊý¾Ý±»°Ä´óÀûÑÇ·£¿î6000ÍòÃÀÔª

      

¾ÝýÌå8ÔÂ13ÈÕ±¨µÀ£¬¹È¸è±»°Ä´óÀûÑǾºÕùÓëÏû·ÑÕßίԱ»á(ACCC)·£¿î6000ÍòÃÀÔª£¬ÒòΪÆäÔÚ2017Äê1ÔÂÖÁ2018Äê12ÔÂÊÕ¼¯ºÍʹÓðĴóÀûÑÇAndroidÓû§µÄλÖÃÊý¾Ý ¡£¸Ã»ú¹¹ÌåÏÖ£¬¼´Ê¹Óû§ÔÚÉ豸ÉèÖÃÖнûÓÃÁËλÖÃÀúÊ·¼Ç¼£¬µ«¹È¸èÈÔÔÚ¸ú×ÙÆäÓû§µÄAndroidÊÖ»ú ¡£Óû§±»Îóµ¼²¢ÈÏΪ¸ÃÉèÖÿɽûÓÃλÖøú×Ù£¬µ«Êµ¼ÊÉÏÁíÒ»¸öĬÈÏ´ò¿ªµÄWeb & App ActivityÕÊ»§ÉèÖÿÉÓÃÀ´ÊÕ¼¯¡¢´æ´¢ºÍʹÓøöÈËλÖÃÊý¾Ý ¡£ACCCÔ¤¼Æ£¬ÓÐÁè¼Ý130Íò°Ä´óÀûÑǾÓÃñµÄÊܵ½Ó°Ïì ¡£


https://www.bleepingcomputer.com/news/google/google-fined-60-million-over-android-location-data-collection/


3¡¢KillnetÉù³Æ¶ÔLockheed MartinÔâµ½µÄDDoS¹¥»÷ÂôÁ¦

      

ýÌå8ÔÂ13ÈÕ±¨µÀ£¬ºÚ¿ÍÍÅ»ïKillnetÉù³Æ¶Ôº½¿Õº½ÌìºÍ¹ú·À¹«Ë¾Âå¿ËÏ£µÂÂí¶ ¡£¨Lockheed Martin£©Ôâµ½µÄDDoS¹¥»÷ÂôÁ¦ ¡£¸ÃÍÅ»ï×Ô3ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬Ôø¶ÔÒâ´óÀû¡¢ÂÞÂíÄáÑÇ¡¢Ä¦¶û¶àÍß¡¢½Ý¿Ë¹²ºÍ¹ú¡¢Á¢ÌÕÍð¡¢Å²ÍþºÍÀ­ÍÑάÑǵȹú¼Ò½øÐÐDDoS¹¥»÷ ¡£´ËÍ⣬Ëü»¹ÔÚTelegramÉÏÐû²¼ÁËÒ»¶ÎÊÓÆµ£¬Éù³ÆÇÔÈ¡Á˸ù«Ë¾Ô±¹¤µÄ¸öÈËÐÅÏ¢£¬°üÂÞÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂëºÍÕÕÆ¬µÈ ¡£Ä¿Ç°£¬Lockheed Martin²¢Î´¶Ô´ËÊÂ×ö³ö»Ø¸´ ¡£


https://securityaffairs.co/wordpress/134341/hacking/killnet-lockheed-martin.html


4¡¢Lucky Mouseͨ¹ýľÂí»¯MiMi·Ö·¢ºóÃÅrshellºÍHyperBro

      

¾ÝýÌå8ÔÂ13Èճƣ¬SEKOIAºÍTrend MicroÅû¶ÁËLucky MouseÀûÓÃľÂí»¯¿çƽ̨¼´Ê±Í¨Ñ¶Ó¦Ó÷¨Ê½MiMi·Ö·¢ºóÃŵĻ ¡£SEKOIA·¢ÏÖ×Ô½ñÄê5ÔÂ26ÈÕ£¬¸ÃÓ¦ÓõÄmacOS°æ±¾2.3.0±»¸Ä¶¯²¢Ö²ÈëÁ˶ñÒâJavaScript´úÂ룬Õâ¿ÉÄÜÊǵÚÒ»¸öÊÜѬȾµÄmacOS±äÌå ¡£TrendMicro·¢ÏÖÁËÀûÓÃrshellÕë¶ÔLinuxºÍÀûÓÃHyperBroÕë¶ÔWindowsµÄ¾ÉµÄľÂí»¯MiMi£¬×îÔçµÄLinux rshellÑù±¾·ºÆðÔÚ2021Äê6Ô ¡£


https://thehackernews.com/2022/08/chinese-hackers-backdoored-mimi-chat.html


5¡¢CISAºÍFBI¹ûÈ»ÀÕË÷Èí¼þZeppelinµÄTTPµÈÏêϸÐÅÏ¢

      

8ÔÂ11ÈÕ£¬CISAºÍFBIÐû²¼Á˹ØÓÚÀÕË÷Èí¼þZeppelinµÄÁªºÏÍøÂçÄþ¾²×Éѯ(CSA) ¡£ZeppelinÊÇ»ùÓÚDelphiµÄVega¶ñÒâÈí¼þ¼Ò×åµÄÑÜÉú²úÎ×÷ΪRaaS£¬´Ó2019Äêµ½2022Äê6Ô±»ÓÃÀ´¹¥»÷ÁË´óÁ¿µÄµÄÆóÒµºÍÒªº¦»ù´¡ÉèÊ©£¬°üÂÞ¹ú·À³Ð°üÉÌ¡¢½ÌÓý»ú¹¹¡¢ÖÆÔìÉ̺ͼ¼Êõ¹«Ë¾£¬ÌرðÊÇÒ½ÁÆÐÐÒµµÄ×éÖ¯ ¡£¸Ã×Éѯ»¹½Ò¶Á˸ÃÀÕË÷Èí¼þµÄ¼ÆÄ±¡¢¼¼ÊõºÍ·¨Ê½(TTP)ÒÔ¼°Í×Эָ±ê(IOC)£¬À´×ÊÖúÄþ¾²ÈËÔ±¼ì²âºÍ·ÀÓù´ËÀ๥»÷ ¡£


https://www.cisa.gov/uscert/ncas/alerts/aa22-223a


6¡¢ÂíÀ´Î÷ÑÇÖ§¸¶Íø¹ØÆ½Ì¨iPay88µÄÓû§Ö§¸¶¿¨ÐÅϢй¶

      

ýÌå8ÔÂ11Èճƣ¬ÂíÀ´Î÷ÑÇÖ§¸¶Íø¹ØÆ½Ì¨iPay88µÄÓû§µÄÖ§¸¶¿¨ÐÅÏ¢¿ÉÄÜй¶ ¡£iPay88ÊÇÂíÀ´Î÷ÑÇ×î´óµÄÖ§¸¶Íø¹ØÆ½Ì¨Ö®Ò»£¬Îª¸ÃµØÓòµÄÖÚ¶àÉ̼ÒÌṩPOS½â¾ö·½°¸ ¡£¸Ã¹«Ë¾Ðû²¼ÉùÃ÷³ÆÆäÔÚ5ÔÂ31ÈÕ·¢ÏÖÁËй¶Ê¼þ²¢¿ªÊ¼ÊӲ죬×Ô7ÔÂ20ÈÕÒÔÀ´Ã»Óз¢ÏÖ½øÒ»²½µÄ¿ÉÒɻ ¡£Ä¿Ç°£¬ÂíÀ´Î÷Ñǹú¼ÒÒøÐУ¨BNM£©ÒÑָʾ¸÷ÒøÐÐÁ¢¼´Í¨ÖªÊÜÓ°ÏìµÄ³Ö¿¨ÈË£¬ÒÔ½øÒ»²½±£»¤ËûÃÇÃâÔâÕ©Æ­»òδ¾­ÊÚȨµÄ½»Ò×·çÏÕ ¡£


https://soyacincau.com/2022/08/11/ipay88-cybersecurity-incident-card-data-compromised-xrs/