CleafyÔÚGoogle Play·¢Ã÷αװ³É¶þάÂëÓ¦ÓõÄTeaBot
Ðû²¼Ê±¼ä 2022-03-04CleafyÔÚGoogle Play·¢Ã÷αװ³É¶þάÂëÓ¦ÓõÄTeaBot
3ÔÂ1ÈÕ£¬£¬£¬£¬CleafyÐû²¼±¨¸æ³ÆÆäÔÚGoogle PlayÊÐËÁÖз¢Ã÷ÁËÒøÐÐľÂíTeaBot¡£¡£¡£¡£¡£¡£¸ÃľÂíαװ³É¶þάÂëÓ¦Óá°QR Code & Barcode ¨C Scanner¡±£¬£¬£¬£¬Òѱ»ÏÂÔØÁè¼Ý10000´Î¡£¡£¡£¡£¡£¡£Óë֮ǰ²î±ðµÄÊÇ£¬£¬£¬£¬¸Ã±äÌåÕë¶ÔµÄÄ¿µÄÓ¦ÓÃÖÖÀàÔöÌí£¬£¬£¬£¬ÏÖÒÑϯ¾íÁ˼ÒÍ¥ÒøÐÐÓ¦Óᢰü¹ÜÓ¦ÓúͼÓÃÜÇ®°üµÈÓ¦Óᣡ£¡£¡£¡£¡£ÔÚ²»µ½Ò»ÄêµÄʱ¼äÀ£¬£¬£¬TeaBotÕë¶ÔÄ¿µÄµÄÊýÄ¿ÔöÌíÁË500%ÒÔÉÏ£¬£¬£¬£¬´Ó60¸öÔöÌíµ½400¶à¸ö¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬TeaBotÖ÷ÒªÃÀ¹úÓû§£¬£¬£¬£¬½üÆÚ»¹ÐÂÔöÁ˶íÓ˹Âå·¥¿ËÓïºÍÖÐÎİ汾£¬£¬£¬£¬ÕâÅú×¢¸Ã¶ñÒâÈí¼þÕýÔÚÃé׼ȫÇò¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/teabot-malware-slips-back-into-google-play-store-to-target-us-users/
CloudSEK³ÆÕë¶ÔÓ¡¶ÈµÄ´¹ÂÚ¹¥»÷ÒÑÔì³ÉÉϰÙÍòÃÀÔªËðʧ
ÐÂ¼ÓÆÂÇå¾²¹«Ë¾CloudSEKÔÚ3ÔÂ1ÈÕÅû¶ÁËÕë¶ÔÓ¡¶ÈµÄ´¹ÂÚ¹¥»÷µÄϸ½ÚÐÅÏ¢¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷»î¶¯Éæ¼°200¶à¸ö´¹ÂÚÍøÕ¾£¬£¬£¬£¬ÒԵ綯Æû³µÎªÓÕ¶ü£¬£¬£¬£¬ÒÑÔì³É¸ß´ï1000000ÃÀÔªµÄËðʧ¡£¡£¡£¡£¡£¡£Ó¡¶ÈÕþ¸®×î½üÍÆ³öÁËÐÂÕþ²ß£¬£¬£¬£¬ÒÔÔö½ø¸Ã¹úµç¶¯Æû³µ£¨EV£©ÐÐÒµµÄÔöÌí¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýʹÓÃGoogle Ads¡¢Ê¹ÓÃÏà¹ØÒªº¦×ÖÒÔ¼°Ä£ÄâRevoltºÍAtherµÈÆ·ÅÆÀ´ÓÕʹĿµÄ½øÈë´¹ÂÚÍøÕ¾£¬£¬£¬£¬È»ºóÒªÇóËûÃÇÊäÈëСÎÒ˽¼ÒºÍÒøÐп¨ÐÅÏ¢£¬£¬£¬£¬×îÖÕÇÔȡĿµÄµÄÕË»§×ʽ𡣡£¡£¡£¡£¡£
https://cloudsek.com/whitepapers_reports/unearthing-the-million-dollar-scams-targeting-the-indian-electric-vehicle-industry-scams/
Malwarebytes·¢Ã÷Ö¼ÔÚÇÔȡ΢ÈíÓû§Æ¾Ö¤µÄ´¹Âڻ
3ÔÂ1ÈÕ£¬£¬£¬£¬MalwarebytesÐû²¼Ò»·Ý±¨¸æ£¬£¬£¬£¬ÏêÊöÁËÕë¶ÔMicrosoftÕÊ»§µÄ´¹Âڻ¡£¡£¡£¡£¡£¡£¸Ã»î¶¯ÒÔ¡°MicrosoftÕÊ»§Òì³£µÇ¼»î¶¯¡±ÎªÖ÷Ì⣬£¬£¬£¬Éù³Æ¼ì²âµ½À´×Ô¶íÂÞ˹/Ī˹¿ÆµÄÓû§¸Õ¸ÕÖØÐÂ×°±¸µÇ¼ÕÊ»§¡£¡£¡£¡£¡£¡£µ±ÊÕ¼þÈ˵ã»÷´¹ÂÚÓʼþÖеġ°±¨¸æÓû§¡±ºó£¬£¬£¬£¬±ã»áÏò¹¥»÷Õß·¢ËÍÒ»·â°üÀ¨Ô¤Ìî³äÐÂÎŵÄÓʼþ£¬£¬£¬£¬Ö®ºó¿ÉÄܻᱻҪÇóÊäÈëµÇ¼ƾ֤ºÍÒøÐÐÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£
https://blog.malwarebytes.com/scams/2022/03/unusual-sign-in-activity-mail-goes-phishing-for-microsoft-account-holders/
JFrogÐû²¼¹ØÓÚ¿ªÔ´¿âPJSIPÖÐ5¸öÄÚ´æËð»µÎó²îµÄ±¨¸æ
JFrogÔÚ3ÔÂ1ÈÕÐû²¼Á˹ØÓÚPJSIPÖÐ5¸öÄÚ´æËð»µÎó²îµÄ±¨¸æ¡£¡£¡£¡£¡£¡£PJSIPÊÇÒ»¸ö¿ªÔ´¶àýÌåͨѶ¿â£¬£¬£¬£¬ÌṩÁËIPµç»°Ó¦ÓÃʹÓõÄAPI¡£¡£¡£¡£¡£¡£Îó²î°üÀ¨¿Éµ¼ÖµĴúÂëÖ´ÐеĿÍÕ»Òç³öÎó²î£¨CVE-2021-43299¡¢CVE-2021-43300ºÍCVE-2021-43301£©£¬£¬£¬£¬ÒÔ¼°¿Éµ¼Ö¾ܾøÐ§À͵ÄÔ½½ç¶ÁÈ¡Îó²î£¨CVE-2021-43302£©»ººÍ³åÇøÒç³öÎó²î£¨CVE-2021-43303£©¡£¡£¡£¡£¡£¡£ÕâЩÎó²îÒÑͨ¹ý2ÔÂ24ÈÕÐû²¼µÄ²¹¶¡ÐÞ¸´¡£¡£¡£¡£¡£¡£
https://jfrog.com/blog/jfrog-discloses-5-memory-corruption-vulnerabilities-in-pjsip-a-popular-multimedia-library/
GoogleÐû²¼Çå¾²¸üУ¬£¬£¬£¬ÐÞ¸´ChromeÖеÄ28¸öÎó²î
GoogleÓÚ3ÔÂ1ÈÕÍÆ³öChrome 99£¬£¬£¬£¬ÐÞ¸´ÁË28¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£ÆäÖнÏΪÑÏÖØµÄÎó²îÊÇANGLEÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2022-0789£©¡¢Cast UIÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2022-0790£©¡¢¶à¹¦Ð§¿òÖÐÊͷźóʹÓÃÎó²î£¨CVE-2022-0791£©¡¢Blink½á¹¹ÖеÄÀàÐÍ»ìÏýÎó²î£¨CVE-2022-0795£©ºÍANGLEÖÐÔ½½ç¶ÁÈ¡Îó²î£¨CVE-2022-0792£©µÈ¡£¡£¡£¡£¡£¡£
https://www.cisa.gov/uscert/ncas/current-activity/2022/03/02/google-releases-security-updates-chrome
ESETÐû²¼IsaacWiperºÍHermeticWizardµÄÆÊÎö±¨¸æ
ESETÔÚ3ÔÂ1ÈÕÐû²¼ÁËIsaacWiperºÍHermeticWizardµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£IsaacWipeÊÇÒ»¸öеÄWiper£¬£¬£¬£¬±£´æÓÚûÓÐAuthenticodeÊðÃûµÄWindows DLL»òEXEÖУ¬£¬£¬£¬×îÔçµÄPE±àÒëʱ¼ä´ÁÊÇ2021Äê10ÔÂ19¡£¡£¡£¡£¡£¡£ÓÚ2ÔÂ24ÈÕÔÚÎÚ¿ËÀ¼Õþ¸®»ú¹¹µÄÍøÂçÖб»·¢Ã÷£¬£¬£¬£¬ÉÐδȷ¶¨ÊÇ·ñÓëHermeticWiperÓйØÁª¡£¡£¡£¡£¡£¡£HermeticWizardÊÇ×Ô½ç˵È䳿£¬£¬£¬£¬ÓÃÓÚͨ¹ýWMIºÍSMBÔÚÍâµØÍøÂçÖÐÈö²¥HermeticWiper¡£¡£¡£¡£¡£¡£
https://www.welivesecurity.com/2022/03/01/isaacwiper-hermeticwizard-wiper-worm-targeting-ukraine/
Çå¾²¹¤¾ß
Searpy
ËÑË÷¹¤¾ß£¬£¬£¬£¬¿ÉÓÃÓÚÊÕÂÞºÍËÝÔ´£¬£¬£¬£¬Ö§³Öpy2ºÍpy3¡£¡£¡£¡£¡£¡£
https://github.com/j3ers3/Searpy
CAPEv2
ÊÇÒ»¸ö¶ñÒâÈí¼þɳÏ䣬£¬£¬£¬´Óí§Òâ¶ñÒâÈí¼þ¼Ò×åÖÐÌáÈ¡ÉèÖûò½âѹpayload¡£¡£¡£¡£¡£¡£
https://github.com/kevoreilly/CAPEv2
S1EM
S1EM ÊÇÒ»¸ö´øÓÐ SIRP ºÍ Threat Intel µÄ SIEM£¬£¬£¬£¬Ò»¸öÍêÕûµÄÊý¾Ý°ü²¶»ñ£¬£¬£¬£¬¶àºÏÒ»¡£¡£¡£¡£¡£¡£
https://github.com/V1D1AN/S1EM
WMEye
ΪʹÓà WMI ºÍÔ¶³Ì MSBuild Ö´ÐÐÖ´ÐкáÏòÒÆ¶¯¶ø¿ª·¢µÄʵÑéÐÔ¹¤¾ß¡£¡£¡£¡£¡£¡£
https://github.com/pwn1sher/WMEye
Çå¾²ÆÊÎö
Æ»¹ûÐû²¼ iOS 15.4 Beta 5
https://news.softpedia.com/news/apple-releases-ios-15-4-beta-5-534963.shtml
΢ÈíΪÖÐСÆóÒµÍÆ³öеĶ˵ãÇå¾²½â¾ö¼Æ»®
https://www.bleepingcomputer.com/news/microsoft/microsoft-rolling-out-new-endpoint-security-solution-for-smbs/
ASEC·¢Ã÷αװ³ÉMSIµÄMagniber·Ö·¢»î¶¯
https://asec.ahnlab.com/en/32226/
΢Èí£ºLSASSÍ߽⵼ÖÂWindowsÓò¿ØÖÆÖØÊÓÆô
https://www.bleepingcomputer.com/news/microsoft/microsoft-windows-domain-controller-restarts-caused-by-lsass-crashes/
Reality Winner µÄ Twitter ÕË»§±»ºÚ¿Í¹¥»÷ÒÔÕë¶Ô¼ÇÕß
https://www.bleepingcomputer.com/news/security/reality-winners-twitter-account-was-hacked-to-target-journalists/
VoIPmonitor ¼à¿ØÈí¼þÖз¢Ã÷µÄÑÏÖØÇå¾²Îó²î
https://thehackernews.com/2022/03/critical-security-bugs-uncovered-in.html