¹¥»÷ÕßʹÓÃαװ³ÉTelegramµÄ¶ñÒâÈí¼þ·Ö·¢Purple Fox
Ðû²¼Ê±¼ä 2022-01-06¹ú¼ÒÍøÐŰìµÈ13¸ö²¿·ÖÐÞ¶©Ðû²¼¡¶ÍøÂçÇå¾²Éó²é²½·¥¡·

1ÔÂ4ÈÕ£¬£¬£¬£¬£¬£¬£¬¹ú¼Ò»¥ÁªÍøÐÅÏ¢°ì¹«ÊÒµÈ13¸ö²¿·ÖÐÞ¶©Ðû²¼¡¶ÍøÂçÇå¾²Éó²é²½·¥¡·¡£¡£¡£¡£¡£¡£¡£¸Ã²½·¥¹²23Ìõ£¬£¬£¬£¬£¬£¬£¬ÔÚ2021Äê11ÔÂ16ÈÕ¹ú¼Ò»¥ÁªÍøÐÅÏ¢°ì¹«ÊÒ2021ÄêµÚ20´ÎÊÒÎñ¾Û»áÉóÒéͨ¹ý£¬£¬£¬£¬£¬£¬£¬×Ô2022Äê2ÔÂ15ÈÕÆðÊ©ÐС£¡£¡£¡£¡£¡£¡£¸Ã²½·¥»®¶¨ÕÆÎÕÁè¼Ý100ÍòÓû§Ð¡ÎÒ˽¼ÒÐÅÏ¢µÄÍøÂçÆ½Ì¨ÔËÓªÕ߸°ÍâÑóÉÏÊУ¬£¬£¬£¬£¬£¬£¬±ØÐèÏòÍøÂçÇå¾²ÉóºË°ì¹«ÊÒÉê±¨ÍøÂçÇå¾²Éó²é¡£¡£¡£¡£¡£¡£¡£ÈÏÕæÈ˳ƣ¬£¬£¬£¬£¬£¬£¬´Ë¾ÙÊÇΪ½øÒ»²½°ü¹ÜÍøÂçÇå¾²ºÍÊý¾ÝÇå¾²£¬£¬£¬£¬£¬£¬£¬Î¬»¤¹ú¼ÒÇå¾²¡£¡£¡£¡£¡£¡£¡£
http://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm
¹¥»÷ÕßʹÓÃαװ³ÉTelegramµÄ¶ñÒâÈí¼þ·Ö·¢Purple Fox
Minerva LabsÔÚ1ÔÂ3ÈÕÐû²¼µÄ±¨¸æÅû¶½üÆÚ·Ö·¢Purple FoxµÄ»î¶¯Ï¸½Ú¡£¡£¡£¡£¡£¡£¡£´Ë´Î»î¶¯Ê¹ÓÃÃûΪTelegram Desktop.exeµÄ±àÒëºóµÄAutoIt¾ç±¾£¬£¬£¬£¬£¬£¬£¬Ëü»á×°ÖÃ2¸öÎļþ£ºÕýµ±µÄTelegram×°ÖóÌÐòºÍ¶ñÒâÏÂÔØ³ÌÐò(TextInputh.exe)¡£¡£¡£¡£¡£¡£¡£TextInputh.exe½«ÏÂÔØÒ»ÏµÁжñÒâÎļþÀ´×èÖ¹360 AVÀú³ÌÆô¶¯£¬£¬£¬£¬£¬£¬£¬ÔÚÈ·¶¨ÇéÐÎÇå¾²ºóÅþÁ¬C2£¬£¬£¬£¬£¬£¬£¬ÒÔ.msiÎļþµÄÐÎʽÏÂÔØPurple Fox¡£¡£¡£¡£¡£¡£¡£
https://blog.minerva-labs.com/malicious-telegram-installer-drops-purple-fox-rootkit
Broward HealthϵͳÐÂÎó²îÔì³É130¶àÍò»¼ÕßÐÅϢй¶
¾ÝýÌå1ÔÂ4ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬Broward HealthÒÑй¶Áè¼Ý130Íò»¼ÕßÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÕâÊÇÃÀ¹úTop 10µÄ¹«¹²Ò½ÁÆÏµÍ³£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚı»®×Å30¶à¸öÒ½ÁÆ»ú¹¹¡£¡£¡£¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚ2021Äê10ÔÂ15ÈÕ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÈëÇÖÁËÒ½ÔºµÄÍøÂç²¢»á¼û»¼ÕßÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¸Ã»ú¹¹ÓÚ10ÔÂ19ÈÕ·¢Ã÷Çå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬²¢ÏòµØ·½Õþ¸®±¨¸æ¡£¡£¡£¡£¡£¡£¡£¾ÊӲ죬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÊÇͨ¹ýÈëÇÖÆäµÚÈý·½Ò½ÁÆÌṩÉ̽øÈëÍøÂç¡£¡£¡£¡£¡£¡£¡£¸ÃÒ½Ôº½«ÎªÊÜÓ°ÏìÓû§ÌṩΪÆÚÁ½ÄêµÄÉí·ÝµÁÓüì²âºÍ±£»£»£»£»£»£»¤Ð§À͵ĻáÔ±×ʸñ¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/126285/data-breach/broward-health-data-breach.html
SEGA EuropeµÄAWS´æ´¢Í°ÉèÖùýʧ£¬£¬£¬£¬£¬£¬£¬¿É»á¼ûÃÜÔ¿µÈÐÅÏ¢
Çå¾²¹«Ë¾VPN Overview 12ÔÂ30ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬SEGA EuropeµÄAWS´æ´¢Í°ÉèÖùýʧµ¼ÖÂÐÅÏ¢×ß©¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ´æ´¢Í°°üÀ¨¿ÉÓÃÀ´»á¼ûSEGA EuropeµÄ¶à¸öÔÆÐ§À͵ÄAWSÃÜÔ¿£¬£¬£¬£¬£¬£¬£¬SNS֪ͨÐÐÁУ¬£¬£¬£¬£¬£¬£¬ÒÔ¼°´ó×ÚÓû§ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬ËûÃÇÄܹ»ÉÏ´«Îļþ¡¢Ö´Ðо籾¡¢¸ü¸ÄÏÖÓÐÍøÒ³²¢¸Ä¶¯SEGAÓòµÄÉèÖ㬣¬£¬£¬£¬£¬£¬ÏÖÔÚûÓм£ÏóÅú×¢¹¥»÷ÕßÒÑ»á¼ûÊý¾Ý»òʹÓÃÉÏÊöÎó²î¡£¡£¡£¡£¡£¡£¡£
https://vpnoverview.com/news/sega-europe-security-report/
Invezz³Æ½ü10ÄêÖмÓÃÜÇå¾²Îó²îµÄÊýÄ¿ÒÑÔöÌí850%
¾ÝýÌå1ÔÂ2ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬InvezzÐû²¼µÄ±¨¸æÏÔʾ½ü10ÄêÖмÓÃÜÇå¾²Îó²îµÄÊýÄ¿ÒÑÔöÌí850%¡£¡£¡£¡£¡£¡£¡£¾ÝÔ¤¼Æ£¬£¬£¬£¬£¬£¬£¬2011Äê1ÔÂÖÁ2021Äê12Ô£¬£¬£¬£¬£¬£¬£¬±»µÁµÄ¼ÓÃÜÇ®±Ò½ð¶î´ï121ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¡£ÆäÖÐËðʧ½ð¶îÔö·ù×î´óµÄÊÇ2016ÄêÖÁ2017Ä꣬£¬£¬£¬£¬£¬£¬ÔöÌí180%£»£»£»£»£»£»Òò¼ÓÃܹ¥»÷¶øµ¼ÖµÄËðʧ×î¸ßµÄÊÇ2021Ä꣬£¬£¬£¬£¬£¬£¬´ï42.5ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¡£Ê¹ÓüÓÃܽ»Á÷Ç徲ϵͳÖеÄÎó²îÊÇ×î³£¼ûµÄÕ½ÂÔ£¬£¬£¬£¬£¬£¬£¬×î³£Ôâµ½´ËÀ๥»÷µÄ¹ú¼ÒÊÇÈÕ±¾¡¢º«¹ú¡¢ÃÀ¹ú¡¢Ó¢¹úºÍÖйú¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/126216/cyber-crime/crypto-security-breaches-2011-2021.html
MicrosoftÐû²¼½ôÆÈ¸üÐÂÐÞ¸´Windows ServerÖеĹýʧ
¾Ý±¨µÀ£¬£¬£¬£¬£¬£¬£¬MicrosoftÒÑÓÚ1ÔÂ4ÈÕÐû²¼´øÍâ(OOB)¸üС£¡£¡£¡£¡£¡£¡£´Ë´Î¸üн«ÐÞ¸´Windows Server 2019ºÍWindows Server 2012 R2µÄºÚÆÁ¡¢µÇ¼»ºÂý»òÆÕ±é»ºÂýµÄÎÊÌ⣬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÎÞ·¨Ê¹ÓÃÔ¶³Ì×ÀÃæ»á¼ûЧÀÍÆ÷»òЧÀÍÆ÷×èÖ¹ÏìÓ¦µÄÎÊÌâ¡£¡£¡£¡£¡£¡£¡£ÕâЩ¸üв»¿É´ÓWindows¸üлñµÃ£¬£¬£¬£¬£¬£¬£¬Ò²²»»á×Ô¶¯×°Öᣡ£¡£¡£¡£¡£¡£MicrosoftÉÐδÐû²¼ÆäËü°æ±¾µÄ¸üУ¬£¬£¬£¬£¬£¬£¬Ô¤¼Æ½«ÔÚδÀ´¼¸ÌìÄÚÌṩ½â¾ö¼Æ»®¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/microsoft/emergency-windows-server-update-fixes-remote-desktop-issues/
Çå¾²¹¤¾ß
Haveged
¸Ã¹¤¾ßµÄÄ¿µÄÊÇÌṩһ¸ö¼òÆÓÒ×ÓõIJ»¿ÉÕ¹ÍûËæ»úÊýÌìÉúÆ÷£¬£¬£¬£¬£¬£¬£¬»ùÓÚ HAVEGE Ëã·¨¡£¡£¡£¡£¡£¡£¡£
https://wiki.archlinux.org/title/Haveged
rustpad
ÓÃRust±àдµÄ¹Å°åpadbusterµÄ¶àÏ̼߳ÌÐøÕߣ¬£¬£¬£¬£¬£¬£¬Ê¹Óà Padding Oracle Îó²î¡£¡£¡£¡£¡£¡£¡£
https://github.com/Kibouo/rustpad/
Çå¾²ÆÊÎö
ÔõÑùʹÓø´ÖÆÕ³ÌùÈëÇÖ
¸´ÖÆÎı¾ºóµÄĩβÉÐÓÐÒ»¸ö»»Ðзû£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂËüÔÚÕ³Ìùµ½LinuxÖն˺óÁ¬Ã¦Ö´ÐС£¡£¡£¡£¡£¡£¡£
https://www.wizer-training.com/blog/copy-paste
ʹÓõç´ÅÐźžÙÐлìÏý¶ñÒâÈí¼þµÄ·ÖÀà
ʹÓÃIoT×°±¸µÄµç´Å³¡ÐźÅ×÷ΪÅÔ·À´ÍøÂçÕë¶ÔÖ²ÈëϵͳµÄ²î±ðÀàÐͶñÒâÈí¼þµÄ׼ȷÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
https://dl.acm.org/doi/10.1145/3485832.3485894


¾©¹«Íø°²±¸11010802024551ºÅ