°²×°WindowsÄþ¾²Æô¶¯DBXµÄÄþ¾²¸üÐÂʱ¿ÉÄÜ·ºÆð´íÎó

Ðû²¼Ê±¼ä 2022-08-16
1¡¢°²×°WindowsÄþ¾²Æô¶¯DBXµÄÄþ¾²¸üÐÂʱ¿ÉÄÜ·ºÆð´íÎó

      

¾Ý8ÔÂ15ÈÕ±¨µÀ£¬Î¢ÈíÌåÏÖ£¬µ±Óû§ÔÚĿǰ֧³ÖµÄ²Ù×÷ϵͳºÍÆóÒµ¼¶·þÎñÆ÷Éϰ²×°Windows KB5012170Äþ¾²¸üÐÂʱ£¬¿ÉÄ᷺ܻÆð0x800f0922´íÎó¡£KB5012170¸üÐÂÊÇÄþ¾²Æô¶¯DBXµÄÄþ¾²¸üУ¬¸Ã´æ´¢¿â°üÂÞͳһ¿ÉÀ©Õ¹¹Ì¼þ½Ó¿Ú(UEFI)Òýµ¼¼ÓÔØ·¨Ê½µÄÈ¡ÏûÇ©Ãû¡£ÉÏÖÜ£¬EclypsiumÔøÅû¶ÁË3¸öµÚÈý·½Òýµ¼¼ÓÔØ·¨Ê½ÖÐÈÆ¹ýÄþ¾²Æô¶¯µÄ©¶´¡£Î¢ÈíÖ¸³ö£¬¿ÉÒÔ½«UEFI¸üе½¹©Ó¦ÉÌÌṩµÄ×îаæÔ­À´»º½â¸ÃÎÊÌ⣬²¢½¨ÒéÖ»ÓÐÔÚÈ·±£É豸ÔËÐÐÁ˹©Ó¦ÉÌÌṩµÄÎÞ©¶´µÄÒýµ¼¼ÓÔØ·¨Ê½°æ±¾Ö®ºóÔÙ¸üÐÂDBX¡£


https://www.bleepingcomputer.com/news/security/windows-kb5012170-secure-boot-dbx-update-may-fail-with-0x800f0922-error/


2¡¢AndroidÒøÐÐľÂíSOVA»Ø¹éÐÂÔöÀÕË÷Èí¼þµÈ¹¦Ð§

      

¾ÝCleafy 8ÔÂ11ÈÕÅû¶£¬AndroidÒøÐÐľÂíSOVA¾íÍÁÖØÀ´²¢ÐÂÔö¶àÖÖ¹¦Ð§¡£2022Äê7Ô£¬SOVA¶ñÒâÈí¼þÐû²¼Á˵Ú4¸ö°æ±¾£¬ÆäÄ¿±êÓ¦Ó÷¨Ê½Ôö¼Óµ½200¸ö£¬²¢ÐÂÔöVNC¹¦Ð§ÓÃÓÚÉè±¹ØÁ¬ÄÆÛÕ©¡£Ö®ºó£¬Ñо¿ÈËÔ±»¹·¢ÏÖÁËSOVA v5µÄÔçÆÚ°æ±¾£¬Ëü½øÐÐÁË´óÁ¿´úÂë¸ïв¢Ìí¼ÓÀÕË÷Èí¼þÄ£¿éµÈй¦Ð§£¬¸ÃÄ£¿éʹÓÃAES¼ÓÃÜÀ´Ëø¶¨±»Ñ¬È¾É豸ÖеÄËùÓÐÎļþ£¬²¢¸½¼ÓÀ©Õ¹Ãû.enc¡£Ä¿Ç°£¬µÚ5°æ»¹Ã»ÓнøÐй㷺Á÷´«£¬ÇÒ¸ÃÔçÆÚÑù±¾ÖÐȱÉÙVNCÄ£¿é£¬ËùÒÔÕâ¸ö°æ±¾ºÜ¿ÉÄÜÈÔÔÚ¿ª·¢ÖС£


https://www.cleafy.com/cleafy-labs/sova-malware-is-back-and-is-evolving-rapidly


3¡¢CybleɨÃè·¢ÏÖÁè¼Ý9000̨ÔÚÍøÉÏ̻¶µÄVNC·þÎñÆ÷

      

¾Ý8ÔÂ14ÈÕ±¨µÀ£¬CybleÑо¿ÈËÔ±·¢ÏÖÁËÖÁÉÙ9000̨̻¶µÄVNC£¨ÐéÄâÍøÂç¼ÆË㣩·þÎñÆ÷£¬ÎÞÐèÉí·ÝÑéÖ¤¼´¿É·ÃÎʺÍʹÓá£ÕâЩ̻¶µÄʵÀý¿É±»¹¥»÷ÕßÓÃÀ´·ÃÎÊÄÚ²¿ÍøÂ磬´ó¶àÊýλÓÚÈðµä¡¢ÃÀ¹ú¡¢Î÷°àÑÀºÍ°ÍÎ÷µÈ¹ú¡£ÎªÁ˽⹥»÷Õß¹¥»÷VNC·þÎñÆ÷µÄƵÂÊ£¬Cyble¼à¿ØÁ˶ÔVNCµÄĬÈ϶˿Ú5900µÄ¹¥»÷£¬·¢ÏÖÒ»¸öÔÂÄÚÓÐÁè¼Ý600Íò¸öÇëÇó¡£´ËÍ⣬ºÚ¿ÍÂÛ̳¶Ô̻¶»òÆÆ½âµÄVNC·ÃÎʵÄÐèÇóÒ²ºÜ¸ß£¬¹¥»÷Õß¿ÉÀÄÓÃVNC½øÐжñÒâ²Ù×÷£¬Èç´ò¿ªÎĵµ¡¢ÏÂÔØÎļþºÍÖ´ÐÐÈÎÒâÃüÁîµÈ¡£


https://www.bleepingcomputer.com/news/security/over-9-000-vnc-servers-exposed-online-without-a-password/


4¡¢·ÒÀ¼Òé»áµÄÍøÕ¾ÔÚÔâµ½¾Ü¾ø·þÎñ¹¥»÷ºóÔÝʱ¹Ø±Õ

      

¾ÝýÌå8ÔÂ12ÈÕ±¨µÀ£¬·ÒÀ¼Òé»áµÄÍøÕ¾ÒòÔâµ½¹¥»÷ÔÝʱ¹Ø±Õ¡£·ÒÀ¼Òé»áÔÚTwitterÉÏ·¢±íÉùÃ÷³Æ£¬ÉÏÖܶþÏÂÎç2µã30·Ö×óÓÒ£¬Òé»áµÄÍâ²¿ÍøÕ¾Ôâµ½Á˾ܾø·þÎñ¹¥»÷£¬Òé»á¡¢·þÎñÌṩÉ̺ÍÍøÂçÄþ¾²ÖÐÐĽÓÄÉÁËÏìÓ¦´ëÊ©À´ÏÞÖÆ¹¥»÷¡£Òé»áÔÚÉÏÖÜÈý·¢ÎijÆ£¬¸ÃÍøÕ¾ÒÑÓÚÖܶþÍíÉϻָ´Õý³£¡£¾ÝϤ£¬Õë¶ÔÒé»áµÄ¹¥»÷·¢ÉúÔڰݵÇÇ©ÊðÖ§³Ö·ÒÀ¼ºÍÈðµä¼ÓÈë±±Ô¼µÄÎļþµÄͬһÌì¡£


https://www.databreaches.net/finlands-parliament-hit-with-cyberattack-following-us-move-to-admit-the-country-to-nato/


5¡¢ÐµÄPyPI°üsecretslib¿ÉÔÚLinuxÉϰ²×°¼ÓÃÜ¿ó¹¤

      

SonatypeÔÚ8ÔÂ11ÈÕ³ÆÆä·¢ÏÖÁËÒ»¸öеÄPyPI°üsecretslib£¬¿ÉÔÚLinuxÉϰ²×°¼ÓÃܿ󹤡£¸Ã¶ñÒâÈí¼þÓÚ2022Äê8ÔÂ6ÈÕÐû²¼£¬±»ÃèÊöÎªÊ¹ÃØÃÜÆ¥ÅäºÍÑéÖ¤±äµÃÈÝÒ×£¬ÔÚɾ³ýǰ±»ÒÑÏÂÔØ93´Î¡£Ëü»áÔÚLinuxÄÚ´æÖУ¨Ö±½Ó´ÓRAM£©ÔËÐÐMonero(XMR)¿ó¹¤£¬ÕâÖÖ¼¼ÊõÖ÷ÒªÓÉÎÞÎļþ¶ñÒâÈí¼þºÍ¼ÓÃÜ·¨Ê½Ê¹ÓᣴËÍ⣬¸Ã¶ñÒâ»î¶¯¼¸ºõûÓÐÁôÏÂÈκÎ×ã¼££¬²¢ÀûÓÃÁËÃÀ¹úÄÜÔ´²¿×ÊÖúµÄʵÑéÊÒ(ANL.gov)µÄÈí¼þ¹¤³ÌʦµÄÉí·ÝºÍÁªÏµÐÅÏ¢À´Ôö¼Ó¿ÉÐŶÈ¡£


https://blog.sonatype.com/pypi-package-secretslib-drops-fileless-linux-malware-to-mine-monero


6¡¢KELAÐû²¼2022ÄêµÚ¶þ¼¾¶ÈÀÕË÷Èí¼þÌ¬ÊÆµÄ·ÖÎö³ÂËß

      

8ÔÂ11ÈÕ£¬ÍøÂçÇ鱨¹«Ë¾KELAÐû²¼Á˹ØÓÚÀÕË÷Èí¼þµÄ·ÖÎö³ÂËß¡£ÀÕË÷ÍŻﲻͣÉú³¤²¢Íþв×ÅÊÀ½ç¸÷µØµÄ×éÖ¯£¬¾¡¹Ü²¿ÃÅÍÅ»ïÔÚ2022ÄêQ2¼õÉÙ»òÍ£Ö¹Á˻£¬µ«ÏñBlack BastaÕâÑùµÄÐÂÍŻﷺÆð²¢¼ÌÐøÀÕË÷Ç®²Æ¡£2022ÄêQ2ÀÕË÷¹¥»÷»î¶¯¼õÉÙÁË7%£¬Æ½¾ùÿ¸öÔ¼ì²âµ½216´Î¹¥»÷£»×î»îÔ¾µÄÀÕË÷ÍÅ»ïÊÇLockBit¡¢Black Basta¡¢Alphv¡¢ContiºÍVice Society£¬¶¼Òѹ¥»÷Áè¼Ý40¸öÄ¿±ê£»ÀÕË÷¹¥»÷ÕßÖ÷ÒªÕë¶ÔµÄÊÇÖÆÔìÒµºÍ¹¤Òµ¡£


https://ke-la.com/wp-content/uploads/2022/08/KELA-RESEARCH_Ransomware-Victims-and-Network-Access-Sales_Q2-2022.pdf