¹È¸èÐÞ¸´ChromeÖÐÊͷźóʹÓÃÎó²îCVE-2022-0609

Ðû²¼Ê±¼ä 2022-02-17

¹È¸èÐÞ¸´ChromeÖÐÊͷźóʹÓÃÎó²îCVE-2022-0609


2ÔÂ14ÈÕ £¬£¬£¬£¬£¬ £¬£¬¹È¸èÐû²¼½ôÆÈ¸üР£¬£¬£¬£¬£¬ £¬£¬ÐÞ¸´ChromeÖеĶà¸öÇå¾²Îó²î¡£¡£ ¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄ×îÑÏÖØµÄÎó²îÊǶ¯»­×é¼þÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2022-0609£© £¬£¬£¬£¬£¬ £¬£¬¿É±»ÓÃÀ´Ö´ÐÐí§Òâ´úÂë»òÔÚä¯ÀÀÆ÷µÄɳÏäÖÐÌÓÒÝ¡£¡£ ¡£¡£¡£¡£¹È¸èÌåÏÖËûÃÇÒѾ­¼ì²âµ½Ê¹ÓÃÕâ¸öÁãÈÕÎó²îµÄ¹¥»÷ £¬£¬£¬£¬£¬ £¬£¬µ«¸Ã¹«Ë¾²¢Î´·ÖÏíÓйع¥»÷»î¶¯µÄÆäËüÐÅÏ¢»ò¸ÃÎó²îµÄÊÖÒÕϸ½Ú¡£¡£ ¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬£¬ £¬£¬¸üл¹ÐÞ¸´ÁËWebstore APIÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2022-0605£©ºÍMojoÖеÄÕûÊýÒç³öÎó²î£¨CVE-2022-0608£©µÈÎó²î¡£¡£ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/google-chrome-emergency-update-fixes-zero-day-exploited-in-attacks/


ÎÚ¿ËÀ¼¶à¸ö¹Ù·½×éÖ¯µÄÍøÕ¾Ôâµ½´ó¹æÄ£DDoS¹¥»÷


ÎÚ¿ËÀ¼¶à¸ö¹Ù·½×éÖ¯µÄÍøÕ¾ÔÚ2ÔÂ15ÈÕÔâµ½ÁË´ó¹æÄ£DDoS¹¥»÷¡£¡£ ¡£¡£¡£¡£¸Ã¹úµÄ2¸ö¹úÓÐÒøPrivatbank£¨ÎÚ¿ËÀ¼×î´óµÄÒøÐУ©ºÍOschadbank£¨¹ú¼Ò´¢±¸ÒøÐУ©´ÓÍâµØÊ±¼äÏÂÖç3µã×óÓÒ×îÏȹرÕÁË2¸öСʱ £¬£¬£¬£¬£¬ £¬£¬ÔÚ5¸öСʱºó»Ö¸´Õý³£ÔËÐÐ £¬£¬£¬£¬£¬ £¬£¬²¢ÌåÏÖ¿ÉÄÜ»áÔÙ´ÎÔâµ½¹¥»÷¡£¡£ ¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬£¬ £¬£¬ÎÚ¿ËÀ¼¹ú·À²¿ºÍÎä×°²½¶ÓµÄÍøÕ¾ÈÔÈ»ÎÞ·¨»á¼û¡£¡£ ¡£¡£¡£¡£ÎÚ¿ËÀ¼¹«¹²¹ã²¥µç̨µÄ×ÜÖÆ×÷ÈËDmitry KhorkinÌåÏÖµç̨ҲÔâµ½Á˹¥»÷ £¬£¬£¬£¬£¬ £¬£¬µ«ÆäÍøÕ¾²¢Î´Ì±»¾¡£¡£ ¡£¡£¡£¡£


https://therecord.media/ddos-attacks-hit-websites-of-ukraines-state-banks-defense-ministry-and-armed-forces/


Î÷°àÑÀ¾¯·½µ·»Ù½ðÈÚÕ©Æ­·¸·¨ÍŻﲢ¾Ð²¶8¸öÏÓÒÉÈË


¾ÝýÌå2ÔÂ14ÈÕ±¨µÀ £¬£¬£¬£¬£¬ £¬£¬Î÷°àÑÀ¹ú¼Ò¾¯Ô±¾Ö£¨Polic¨ªa Nacional£©ÔÚÉÏÖܵ·»ÙÁËÒ»¸ö½ðÈÚÕ©Æ­·¸·¨ÍŻ¡£ ¡£¡£¡£¡£¸ÃÍÅ»ïµÄ8Ãû³ÉÔ±±»²¶ £¬£¬£¬£¬£¬ £¬£¬12¸öÒøÐÐÕË»§±»¶³½á¡£¡£ ¡£¡£¡£¡£¾ÝϤ £¬£¬£¬£¬£¬ £¬£¬¸ÃÍÅ»ïµÄµÚÒ»Æð¹¥»÷ÊÂÎñ±¬·¢ÔÚ2021Äê3Ô £¬£¬£¬£¬£¬ £¬£¬ËûÃÇÖ÷Ҫαװ³ÉÒøÐÐºÍÆäËü×éÖ¯µÄ´ú±í £¬£¬£¬£¬£¬ £¬£¬Ê¹Óô¹ÂÚ¹¥»÷ºÍSIM½»Á÷¹¥»÷»ñȡĿµÄµÄСÎÒ˽¼ÒºÍ²ÆÎñÐÅÏ¢ £¬£¬£¬£¬£¬ £¬£¬²¢´ÓËûÃǵÄÕË»§ÖÐÌáÈ¡×ʽ𡣡£ ¡£¡£¡£¡£½üÄêÀ´ £¬£¬£¬£¬£¬ £¬£¬SIM½»Á÷ÒÑÑݱäΪһÖÖÈÕÒæÆÕ±éµÄÍøÂç·¸·¨ÐÎʽ £¬£¬£¬£¬£¬ £¬£¬2021Äê12Ô £¬£¬£¬£¬£¬ £¬£¬The Community³ÉÔ±ÒòÉæÏÓÊý°ÙÍòÃÀÔªµÄSIM¿¨½»Á÷¹¥»÷±»¾Ð²¶¡£¡£ ¡£¡£¡£¡£


https://thehackernews.com/2022/02/spanish-police-arrest-sim-swappers-who.html


Beetle Eye´æ´¢Í°ÉèÖùýʧԼ700ÍòÓû§µÄÐÅϢй¶


¾Ý2ÔÂ14Èյı¨µÀ £¬£¬£¬£¬£¬ £¬£¬Website Planet·¢Ã÷ÃÀ¹úÓªÏú¹«Ë¾Beetle EyeÔ¼700ÍòÓû§µÄÐÅϢй¶¡£¡£ ¡£¡£¡£¡£Beetle EyeÒòAWS S3´æ´¢Í°ÉèÖùýʧ̻¶ÁËÁè¼Ý6000¸öÎļþ £¬£¬£¬£¬£¬ £¬£¬×ܼÆÁè¼Ý1GBÊý¾Ý¡£¡£ ¡£¡£¡£¡£´Ë´Îй¶ÁËÐÕÃû¡¢µØµã¡¢ÓÊÕþ±àÂëºÍµç»°ºÅÂëµÈÐÅÏ¢ £¬£¬£¬£¬£¬ £¬£¬ÊÜÓ°ÏìµÄÓû§´ó¶àÀ´×ÔÓÚÃÀ¹úºÍ¼ÓÄô󡣡£ ¡£¡£¡£¡£¸Ã´æ´¢Í°ÓÚ2021Äê9ÔÂ9ÈÕ±»·¢Ã÷ £¬£¬£¬£¬£¬ £¬£¬2022Äê2ÔÂ14ÈÕBeetle Eye»Ø¸´³ÆÃô¸ÐÎļþÒѱ»É¾³ý¡£¡£ ¡£¡£¡£¡£


https://www.hackread.com/us-marketing-firm-data-exposed-database-mess-up/


ÈðÊ¿Æû³µ¾­ÏúÉÌEmil Frey³ÆÆäÔâµ½HiveµÄÀÕË÷¹¥»÷


ýÌå2ÔÂ14ÈÕ±¨µÀ £¬£¬£¬£¬£¬ £¬£¬ÈðÊ¿Æû³µ¾­ÏúÉÌEmil FreyÔâµ½HiveÀÕË÷¹¥»÷¡£¡£ ¡£¡£¡£¡£ÕâÊÇÅ·ÖÞ×î´óµÄÆû³µ¾­ÏúÉÌÖ®Ò» £¬£¬£¬£¬£¬ £¬£¬ÔÚ2020Äê´´Á¢ÁË32.9ÒÚÃÀÔªµÄÏúÊÛ¶î¡£¡£ ¡£¡£¡£¡£¸Ã¹«Ë¾ÓÚ2ÔÂ1ÈÕ·ºÆðÔÚHiveµÄÒѱ»¹¥»÷Ä¿µÄµÄÃûµ¥ÉÏ £¬£¬£¬£¬£¬ £¬£¬²¢ÈÏ¿ÉËûÃÇÔÚ1Ô·ÝÔâµ½¹¥»÷¡£¡£ ¡£¡£¡£¡£¸Ã¹«Ë¾½²»°ÈË³Æ £¬£¬£¬£¬£¬ £¬£¬ÔÚ1ÔÂ11ÈÕµÄÊÂÎñ±¬·¢¼¸Ììºó £¬£¬£¬£¬£¬ £¬£¬¹«Ë¾¾ÍÒѻָ´²¢ÖØÆôÁËÉÌÒµ»î¶¯¡£¡£ ¡£¡£¡£¡£HiveÔÚ2021Äê¹¥»÷ÁËÖÁÉÙ28¸öÒ½ÁÆ»ú¹¹ £¬£¬£¬£¬£¬ £¬£¬»ñµÃÁËFBIµÄÖØµã¹Ø×¢¡£¡£ ¡£¡£¡£¡£


https://www.itsecurityguru.org/2022/02/14/major-car-dealer-suffers-ransomware-attack/


FortiGuardÐû²¼½üÆÚ·Ö·¢BitRATµÄ»î¶¯µÄÆÊÎö±¨¸æ


2ÔÂ14ÈÕ £¬£¬£¬£¬£¬ £¬£¬FortiGuard LabsÐû²¼Á˹ØÓÚ·Ö·¢BitRATµÄ»î¶¯µÄÆÊÎö±¨¸æ¡£¡£ ¡£¡£¡£¡£´Ë´Î»î¶¯Ê¹ÓÃÁËÃûΪ¡°NFT_Items.xlsm¡±µÄExcelµç×Ó±í¸ñ £¬£¬£¬£¬£¬ £¬£¬¸ÃÎļþÓÐÁ½¸öÊÂÇé²¾ £¬£¬£¬£¬£¬ £¬£¬ÆäÖÐÒ»¸öÊÇÏ£²®À´ÓïµÄ¡£¡£ ¡£¡£¡£¡£¸Ã¶ñÒâÎļþÒÔ²»¿ÉÌæ»»´ú±Ò(NFT)Ïà¹ØÐÅϢΪÓÕ¶ü £¬£¬£¬£¬£¬ £¬£¬°üÀ¨Ò»¸ö¶ñÒâºê £¬£¬£¬£¬£¬ £¬£¬¿ÉʹÓÃPowerShell¾ç±¾´ÓDiscordÏÂÔØÁíÒ»¸öÎļþNFTEXE.exe £¬£¬£¬£¬£¬ £¬£¬×îÖÕ½«×°ÖÃÔ¶³Ì»á¼ûľÂíBitRAT¡£¡£ ¡£¡£¡£¡£


https://www.fortinet.com/blog/threat-research/nft-lure-used-to-distribute-bitrat


Çå¾²¹¤¾ß


Droopescan


Ò»ÖÖ»ùÓÚ²å¼þµÄɨÃè³ÌÐò £¬£¬£¬£¬£¬ £¬£¬¿É×ÊÖúÇå¾²Ñо¿Ö°Ô±Ê¶±ð¶à¸ö CMS µÄÎÊÌâ¡£¡£ ¡£¡£¡£¡£


https://github.com/SamJoan/droopescan


AutoTimeliner


´ÓÒ×ʧÐÔÄÚ´æ×ª´¢ÖÐ×Ô¶¯Ìáȡȡ֤ʱ¼äÏß¡£¡£ ¡£¡£¡£¡£


https://github.com/andreafortuna/autotimeliner


truffleHog


ͨ¹ý git ´æ´¢¿âËÑË÷ÃÜÂë £¬£¬£¬£¬£¬ £¬£¬ÉîÈëÍÚ¾òÌá½»ÀúÊ·ºÍ·ÖÖ§ £¬£¬£¬£¬£¬ £¬£¬Õâ¹ØÓÚ·¢Ã÷ÒâÍâÌá½»µÄÃÜÂëºÜÊÇÓÐÓᣡ£ ¡£¡£¡£¡£


https://github.com/trufflesecurity/truffleHog


WarFox


»ùÓÚÈí¼þµÄ HTTPS Ðűê Windows Ö²Èë³ÌÐò £¬£¬£¬£¬£¬ £¬£¬ËüʹÓöà²ãÊðÀíÍøÂç¾ÙÐÐ C2 ͨѶ¡£¡£ ¡£¡£¡£¡£


https://github.com/FULLSHADE/WarFox


Melody


ΪÍþвÇ鱨¶ø¹¹½¨µÄ͸Ã÷»¥ÁªÍø´«¸ÐÆ÷ £¬£¬£¬£¬£¬ £¬£¬¿É±ê¼Ç¸ÐÐËȤµÄÊý¾Ý°üÒÔ¾ÙÐнøÒ»²½ÆÊÎöºÍÍþв¼à¿Ø¡£¡£ ¡£¡£¡£¡£


https://bonjourmalware.github.io/melody/



Çå¾²ÆÊÎö


QNAP ΪһЩ²»ÊÜÖ§³ÖµÄ NAS ×°±¸À©Õ¹Òªº¦¸üÐÂ


https://www.bleepingcomputer.com/news/security/qnap-extends-critical-updates-for-some-unsupported-nas-devices/


Kali Linux 2022.1 Ðû²¼ £¬£¬£¬£¬£¬ £¬£¬°üÀ¨ 6 ¸öй¤¾ß¡¢SSH ÆÕ±é¼æÈݵÈ


https://www.bleepingcomputer.com/news/security/kali-linux-20221-released-with-6-new-tools-ssh-wide-compat-and-more/


FTC ÖÒÑÔ VoIP ÌṩÉÌ£º·ÖÏí robocall ÐÅÏ¢»ò±»ÆðËß


https://www.bleepingcomputer.com/news/security/ftc-warns-voip-providers-share-your-robocall-info-or-get-sued/


KlaySwap Óû§ÔÚ BGP Ð®ÖÆºóËðʧ×ʽð


https://therecord.media/klayswap-crypto-users-lose-funds-after-bgp-hijack/


ʹÓà Ghostbuster ¹¤¾ßÏû³ýµ¯ÐÔ IP ½ÓÊÜ


https://blog.assetnote.io/2022/02/13/dangling-eips/