Windows KB5013943¸üпɵ¼ÖÂSophosɱ¶¾´¥·¢À¶ÆÁ

Ðû²¼Ê±¼ä 2022-05-18
1¡¢Windows KB5013943¸üпɵ¼ÖÂSophosɱ¶¾´¥·¢À¶ÆÁ


¾ÝýÌå5ÔÂ16ÈÕ±¨µÀ £¬£¬£¬£¬£¬£¬×°ÖÃKB5013943¸üкóµÄWindows 11ÉÏÔËÐÐSophos Homeɱ¶¾Èí¼þ»á´¥·¢À¶ÆÁËÀ»ú£¨BSOD£©ÎÊÌâ¡£¡£¡£¡£¡£¡£SophosÌåÏÖ £¬£¬£¬£¬£¬£¬Õâ¸öÎÊÌâÊÇÓÉÓÚSophos HomeʹÓõÄhmpalert.sys£¨ÓÖÃûHitManPro.Alert Support£©WindowsÇý¶¯³ÌÐòÒýÆðµÄ¡£¡£¡£¡£¡£¡£´ËÎÊÌâµÄÐÞ¸´³ÌÐò½«×Ô¶¯Ó¦ÓÃÓÚËùÓÐÊÜÓ°ÏìµÄϵͳ £¬£¬£¬£¬£¬£¬Óû§¿ÉÒÔÔÚC:\Windows\System32\driversÖмì²éhmpalert.sysµÄÏêϸÐÅÏ¢À´È·¶¨ÐÞ¸´³ÌÐòÊÇ·ñÒѱ»Ó¦Óᣡ£¡£¡£¡£¡£Î´¾ÙÐÐ×Ô¶¯ÐÞ¸´µÄÓû§ÐèÒªÖØÃüÃûhmpalert.sysÇý¶¯³ÌÐò»òÐ¶ÔØÓÐÎÊÌâµÄWindows¸üС£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/software/sophos-antivirus-driver-caused-bsods-after-windows-kb5013943-update/     


2¡¢NVIDIAÐû²¼¸üР£¬£¬£¬£¬£¬£¬ÐÞ¸´ÆäGPUÇý¶¯³ÌÐòÖеĶà¸öÎó²î


5ÔÂ16ÈÕ £¬£¬£¬£¬£¬£¬NVIDIAÐû²¼5Ô·ÝÇå¾²¸üР£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËÆäGPUÇý¶¯³ÌÐòÖеĶà¸öÎó²î¡£¡£¡£¡£¡£¡£´Ë´Î¸üÐÂÐÞ¸´ÁË¿ÉÄܵ¼Ö¾ܾøÐ§ÀÍ¡¢ÐÅϢй¶¡¢ÌØÈ¨ÌáÉý¡¢´úÂëÖ´ÐеȵÄÎó²î £¬£¬£¬£¬£¬£¬ÊÊÓÃÓÚÈí¼þ²úÆ·Tesla¡¢RTX/Quadro¡¢NVS¡¢StudioºÍGeForce £¬£¬£¬£¬£¬£¬º­¸ÇÇý¶¯·ÖÖ§R450¡¢R470ºÍR510¡£¡£¡£¡£¡£¡£ÆäÖнÏΪÑÏÖØµÄÎó²îÊÇCVE-2022-28181¡¢CVE-2022-28182¡¢CVE-2022-28183ºÍCVE-2022-28184 £¬£¬£¬£¬£¬£¬ËüÃǽöÐè½ÏµÍµÄȨÏÞÇÒÎÞÐèÓëÓû§½»»¥ £¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÆäÖ´ÐоßÓиü¸ßȨÏÞµÄÏÂÁî¡£¡£¡£¡£¡£¡£½¨ÒéËùÓÐÓû§¾¡¿ì×°ÖÃÒÑÐû²¼µÄ¸üС£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/nvidia-fixes-ten-vulnerabilities-in-windows-gpu-display-drivers/


3¡¢Malwarebytes·¢Ã÷Õë¶ÔµÂ¹úµÄ×Ô½ç˵PowerShell RAT


MalwarebytesÔÚ5ÔÂ16ÈÕÅû¶ÁËÕë¶ÔµÂ¹úµÄ×Ô½ç˵PowerShell RATµÄϸ½ÚÐÅÏ¢¡£¡£¡£¡£¡£¡£¹¥»÷Õß×¢²áÁËÒ»¸öµÂ¹úÓòÃûcollaboration-bw[.]de £¬£¬£¬£¬£¬£¬²¢¿Ë¡ÁËÕæÊµÍøÕ¾µÄÍâ¹Û¡£¡£¡£¡£¡£¡£ÍøÕ¾Ìṩһ¸öÃûΪ2022-Q2-Bedrohungslage-UkraineµÄÎļþ £¬£¬£¬£¬£¬£¬¾Ý³Æ°üÀ¨Á˹ØÓÚÎÚ¿ËÀ¼Ê±ÊƵÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¸ÃÎļþ»á´¥·¢Ò»¸öÔËÐÐBase64È¥»ìÏý³ÌÐòµÄPowerShell £¬£¬£¬£¬£¬£¬´Ó¶ø»ñÈ¡²¢Ö´ÐжñÒâ¾ç±¾¡£¡£¡£¡£¡£¡£×îÖÕ £¬£¬£¬£¬£¬£¬¸Ã¾ç±¾»áÏÂÔØÒ»¸ö.txtÐÎʽµÄRATºÍÒ»¸öͨ¹ýPowerShell×ÊÖúÆäÖ´ÐеÄ.cmdÎļþ¡£¡£¡£¡£¡£¡£


https://blog.malwarebytes.com/threat-intelligence/2022/05/custom-powershell-rat-targets-germans-seeking-information-about-the-ukraine-crisis/


4¡¢ÃÀ¹ú¹¤³Ì¹«Ë¾ParkerÔâµ½ÀÕË÷ÍÅ»ïContiµÄ¹¥»÷


¾Ý5ÔÂ16ÈÕ±¨µÀ £¬£¬£¬£¬£¬£¬ÃÀ¹ú¹¤³Ì¹«Ë¾Parker-Hannifin CorporationÔâµ½ÁËÀÕË÷ÍÅ»ïContiµÄ¹¥»÷¡£¡£¡£¡£¡£¡£ParkerרÃÅ´ÓÊÂÔ˶¯ºÍ¿ØÖÆÊÖÒÕ £¬£¬£¬£¬£¬£¬ÖØµã¹Ø×¢º½¿ÕҺѹװ±¸ £¬£¬£¬£¬£¬£¬ÊÕÈëΪ156ÒÚ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ £¬£¬£¬£¬£¬£¬¹¥»÷±¬·¢ÔÚ½ñÄê3ÔÂ11ÈÕÖÁ14ÈÕʱ´ú £¬£¬£¬£¬£¬£¬ËûÃÇÁ¬Ã¦Æô¶¯ÁËÊÂÎñÏìӦЭÒé £¬£¬£¬£¬£¬£¬²¢¹Ø±ÕÁ˲¿·Öϵͳ¡£¡£¡£¡£¡£¡£¾­ÓÉÊÓ²ì £¬£¬£¬£¬£¬£¬È·¶¨²¿·ÖÔ±¹¤µÄÐÅϢй¶ £¬£¬£¬£¬£¬£¬°üÀ¨ÐÕÃû¡¢Éç»áÇå¾²ºÅÂë(SSN)¡¢¼ÒÍ¥µØµã¡¢¼ÝʻִÕÕºÅÂë¡¢»¤ÕÕºÅÂë¡¢²ÆÎñÕË»§ÐÅÏ¢ºÍÕÊ»§ÃÜÂëµÈ¡£¡£¡£¡£¡£¡£ContiÔÚ4ÔÂ1ÈÕÉù³Æ¶Ô´ËÊÂÈÏÕæ £¬£¬£¬£¬£¬£¬²¢ÔÚ4ÔÂ20ÈÕÐû²¼ÁËÇÔÈ¡µÄ419 GBÊý¾Ý¡£¡£¡£¡£¡£¡£


https://www.infosecurity-magazine.com/news/parker-conti-ransomware/


5¡¢Kaspersky³Æ2022ÄêHTML¸½¼þÔÚ´¹ÂڻÖÐÒÀȻʢÐÐ


5ÔÂ16ÈÕ £¬£¬£¬£¬£¬£¬KasperskyÐû²¼±¨¸æ³Æ2022ÄêHTML¸½¼þÔÚ´¹ÂڻÖÐÒÀȻʢÐС£¡£¡£¡£¡£¡£¹¥»÷ÕßÖ÷ҪʹÓÃÁ½ÖÖÀàÐ͵ÄHTML¸½¼þ£º´øÓÐÖ¸ÏòαÔìÍøÕ¾Á´½ÓµÄHTMLÎļþ £¬£¬£¬£¬£¬£¬»òÒ»¸ö³ÉÊìµÄÍøÂç´¹ÂÚÒ³Ãæ¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö £¬£¬£¬£¬£¬£¬ÔÚ2022Äêǰ4¸öÔ £¬£¬£¬£¬£¬£¬¼ì²âµ½½ü200Íò·â°üÀ¨¶ñÒâHTML¸½¼þµÄµç×ÓÓʼþ £¬£¬£¬£¬£¬£¬ÔÚ3Ô·ݵִï·åÖµ £¬£¬£¬£¬£¬£¬¼ì²âµ½851000·â £¬£¬£¬£¬£¬£¬¶øÔÚ4Ô½µÖÁ387000´Î¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ £¬£¬£¬£¬£¬£¬´ËÀ๥»÷¿ÉÄÜÈÆ¹ýÇå¾²²úÆ·µÄ¼ì²â £¬£¬£¬£¬£¬£¬Òò´ËÓû§Ó¦¸ÃʼÖÕ½«HTML¸½¼þÊÓΪ¸ß¶È¿ÉÒɵÄ¡£¡£¡£¡£¡£¡£


https://securelist.com/html-attachments-in-phishing-e-mails/106481/


6¡¢Trend MicroÐû²¼¶ñÒâÈí¼þFacestealerµÄÆÊÎö±¨¸æ


Trend MicroÔÚ5ÔÂ16ÈÕÐû²¼Á˹ØÓÚ¶ñÒâÈí¼þFacestealerµÄÊÖÒÕÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£FacestealeÓÚ2021Äê7ÔÂÊ״α»·¢Ã÷ £¬£¬£¬£¬£¬£¬¿ÉÓÃÀ´ÇÔÈ¡Facebookƾ֤¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ £¬£¬£¬£¬£¬£¬×î½üµÄÊÓ²ìÔÚGoogle Play ÊÐËÁÖз¢Ã÷ÁË200¶à¸öFacestealerÓ¦ÓóÌÐò £¬£¬£¬£¬£¬£¬ÆäÖÐһЩÒѾ­×°ÖÃÁËÁè¼ÝÊ®Íò´Î¡£¡£¡£¡£¡£¡£ËüÃÇͨ³£Î±×°³É½¡ÉíºÍÕÕÆ¬±à¼­µÈÓ¦ÓóÌÐò £¬£¬£¬£¬£¬£¬ÈçDaily Fitness OL¡¢Enjoy Photo Editor¡¢Panorama CameraºÍPhoto Gaming PuzzleµÈ¡£¡£¡£¡£¡£¡£ÏÖÔÚ £¬£¬£¬£¬£¬£¬GoogleÒÑ´ÓÊÐËÁÖÐÒÆ³ýÁËÕâЩӦÓᣡ£¡£¡£¡£¡£


https://www.trendmicro.com/en_us/research/22/e/fake-mobile-apps-steal-facebook-credentials--crypto-related-keys.html