ÍøÐŰ졶»¥ÁªÍøµ¯´°ÐÅÏ¢ÍÆËÍ·þÎñÖÎÀí»®¶¨£¨Õ÷ÇóÒâ¼û¸å£©¡·
Ðû²¼Ê±¼ä 2022-03-07ÍøÐŰ졶»¥ÁªÍøµ¯´°ÐÅÏ¢ÍÆËÍ·þÎñÖÎÀí»®¶¨£¨Õ÷ÇóÒâ¼û¸å£©¡·
3ÔÂ2ÈÕ£¬¹ú¼Ò»¥ÁªÍøÐÅÏ¢°ì¹«ÊÒÐû²¼Á˹ØÓÚ¡¶»¥ÁªÍøµ¯´°ÐÅÏ¢ÍÆËÍ·þÎñÖÎÀí»®¶¨£¨Õ÷ÇóÒâ¼û¸å£©¡·¹ûÕæÕ÷ÇóÒâ¼ûµÄ֪ͨ¡£Í¨ÖªÖ¸³ö£¬Îª¹æ·¶»¥ÁªÍøµ¯´°ÐÅÏ¢ÍÆËÍ·þÎñ£¬Î¬»¤¹ú¼ÒÇå¾²ºÍ¹«¹²ÀûÒæ£¬Æ¾Ö¤¡¶ÖлªÈËÃñ¹²ºÍ¹úÍøÂçÇå¾²·¨¡·µÈÖ´ÂÉÀýÔòÖÆ¶©Á˱¾»®¶¨¡£ÔÚ¾³ÄÚÌṩ²Ù×÷ϵͳ¡¢ÖÕ¶Ë×°±¸¡¢Ó¦ÓÃÈí¼þ¡¢ÍøÕ¾µÈ·þÎñµÄ£¬¿ªÕ¹»¥ÁªÍøµ¯´°ÐÅÏ¢ÍÆËÍ·þÎñʱӦµ±×ñÊØ±¾»®¶¨¡£
http://www.cac.gov.cn/2022-03/02/c_1647826956995841.htm
Unit 42³Æ10Íò¶à¸öÊäÒº±ÃÒ×ÊܶàÄêǰµÄÊý¸öÎó²îÓ°Ïì
3ÔÂ2ÈÕ£¬Unit 42Ðû²¼±¨¸æ³ÆÆäÉó²éÁË200000¶à¸ö×°±¸£¬²¢·¢Ã÷ÆäÖÐ75%±£´æ¶àÄêǰµÄÎó²î¡£×îÆÕ±éµÄÊÇǶÈëʽװ±¸µÄVxWorksʵʱ²Ù×÷ϵͳ(RTOS)ÖеÄÄÚ´æËð»µÎó²î£¨CVE-2019-12255£¬CVSSÆÀ·Ö9.8£©£¬±£´æÓÚ52%µÄ²úÆ·ÖУ¨104000¶ą̀)£¬ÒÑÓÚ2019Äê7ÔÂ19ÈÕ±»ÐÞ¸´¡£±ðµÄ£¬Ñо¿Ö°Ô±»¹·¢Ã÷ÁËCVE-2020-12040¡¢CVE-2020-12045ºÍCVE-2020-12047µÈ¶à¸öÔÚ2019ÄêºÍ2020Äê¾Í±»Åû¶µÄÎó²î¡£
https://www.bleepingcomputer.com/news/security/over-100-000-medical-infusion-pumps-vulnerable-to-years-old-critical-bug/
Proofpoint·¢Ã÷ÐÂÒ»ÂÖ´¹ÂÚÔ˶¯Asylum Ambuscade
ProofpointÔÚ3ÔÂ1ÈÕ¹ûÕæÁËÐÂÒ»ÂÖ´¹ÂÚÔ˶¯Asylum AmbuscadeµÄÏêϸÐÅÏ¢¡£¸ÃÔ˶¯ÈëÇÖÁËÒ»¸öÎÚ¿ËÀ¼Îä×°²½¶ÓÔ±¹¤µÄÓʼþÕÊ»§£¬Ä¿µÄÊǼÓÈëÖÎÀíÎÚ¿ËÀ¼ÔÖÀèºóÇÚÊÂÇéµÄÖ°Ô±¡£´¹ÂÚÓʼþÀ´×Ôukr[.]net£¬°üÀ¨Ò»¸ö¶ñÒâºê¸½¼þ£¬Ö¼ÔÚ·Ö·¢¸öÃûΪSunSeedµÄ»ùÓÚLuaµÄ¶ñÒâÈí¼þ¡£Ñо¿Ö°Ô±·¢Ã÷¸ÃÔ˶¯Óë2021Äê7Ô°׶íÂÞ˹APT×éÖ¯GhostwriterÌᳫµÄ¹¥»÷ÏàËÆ£¬ÍƶÏÕâÁ½´Î¹¥»÷À´×Ôͳһ¹¥»÷Õß¡£
https://securityaffairs.co/wordpress/128594/apt/asylum-ambuscade-phishing-campaign-ukraine.html
Salt SecurityÐû²¼¹ØÓÚAPIÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ
3ÔÂ2ÈÕ£¬Salt SecurityÐû²¼Á˹ØÓÚAPIÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£±¨¸æÖ¸³ö£¬2021ÄêAPI¹¥»÷Á÷Á¿ÔöÌíÁË681%£¬¶øÕûÌåAPIÁ÷Á¿ÔöÌíÁË321%¡£¸ÃÑо¿¶ÔÀ´×Ô²î±ð¹æÄ£¹«Ë¾µÄ250ÃûÔ±¹¤µÄ¾ÙÐÐÊӲ죬·¢Ã÷34%µÄ¹«Ë¾È±·¦APIÇå¾²Õ½ÂÔ£¬83%ÊÜ·ÃÕß¶ÔËûÃǵÄÏÖÓÐAPI¹¦Ð§È±·¦ÐÅÐÄ£¬95%µÄÊÜ·ÃÕßÌåÏÖÔÚÈ¥ÄêÂÄÀú¹ýAPIÇå¾²ÊÂÎñ£¬85%µÄÊÜ·ÃÕßÖ¸³öÄ¿½ñµÄ¹¤¾ßÎÞ·¨ÓÐÓÃ×èÖ¹API¹¥»÷¡£
https://salt.security/press-releases/salt-security-state-of-api-security-report-reveals-api-attacks-increased-681-in-the-last-12-months?
BarracudaÐû²¼Log4ShellÎó²îʹÓÃÔ˶¯µÄÑо¿±¨¸æ
BarracudaÆÊÎöÁË×Ô2021Äê12ÔÂ10ÈÕÒÔÀ´¼ì²âµ½µÄ¹¥»÷ºÍpayload£¬²¢ÓÚ3ÔÂ2ÈÕÐû²¼ÁËLog4ShellÎó²îʹÓÃÔ˶¯µÄ±¨¸æ¡£±¨¸æÖ¸³ö£¬´ó´ó¶¼Ê¹ÓÃʵÑéÀ´×ÔÃÀ¹ú£¬Æä´ÎÊÇÈÕ±¾¡¢ÖÐÅ·ºÍ¶íÂÞ˹¡£Ñо¿Ö°Ô±·¢Ã÷Á˶à¸öʹÓøÃÎó²îµÄpayload£¬ÆäÖн©Ê¬ÍøÂçMirai¼°Æä±äÌåµÄÕ¼±È×î´ó£¬Æä´ÎΪBillGates malware(DDoS)¡¢Kinsing(¼ÓÃÜ¿ó¹¤)¡¢XMRig(¼ÓÃÜ¿ó¹¤)ºÍMuhstik(DDoS)¡£±¨¸æ»¹Ìá³öÓÐÓÃÌá·À´ËÀ๥»÷µÄ×î¼òÆÓÒªÁìÊǽ«Log4j¸üе½2.17.1»ò¸ü¸ß°æ±¾£¬²¢È·±£ËùÓÐWebÓ¦Óô¦ÓÚ×îÐÂ״̬¡£
https://blog.barracuda.com/2022/03/02/threat-spotlight-attacks-on-log4shell-vulnerabilities/
Ñо¿Ö°Ô±¹ûÕæLinuxÄÚºËÌáȨÎó²îCVE-2022-0492µÄϸ½Ú
Ñо¿Ö°Ô±ÔÚ3ÔÂ3ÈÕ¹ûÕæÁËLinuxÄÚºËÖеÄÌáȨÎó²î£¨CVE-2022-0492£©µÄϸ½Ú¡£ËüÊÇLinux¿ØÖÆ×é(cgroups)ÖеÄÒ»¸öÂß¼Îó²î£¬±£´æÓÚ/cgroup/cgroup-v1.cº¯ÊýÖеÄcgroup_release_agent_write¡£ÔÚijЩÇéÐÎÏ£¬Æä¿É±»ÓÃÀ´Í¨¹ýcgroups v1µÄrelease_agentÌØÕ÷ÌáÉýȨÏÞ£¬²¢ÈƹýÃû³Æ¿Õ¾àÀëÀë¡£ÏÖÔÚ£¬¸ÃÎó²î ÒÑÔÚ×îеÄLinux°æ±¾ÖÐÐÞ¸´£¬Ñо¿Ö°Ô±½¨ÒéËùÓÐÓû§Éý¼¶µ½×îа汾¡£
https://unit42.paloaltonetworks.com/cve-2022-0492-cgroups/
Çå¾²¹¤¾ß
BruteShark
ÍøÂçȡ֤ÆÊÎö¹¤¾ß (NFAT)£¬Ëü¶ÔÍøÂçÁ÷Á¿£¨Ö÷ÒªÊÇ PCAP Îļþ£©¾ÙÐÐÉî¶È´¦Öóͷ£ºÍ¼ì²é¡£
https://github.com/odedshimon/BruteShark/
Checkov
ÓÃÓÚ»ù´¡ÉèÊ©¼´´úÂëµÄ¾²Ì¬´úÂëÆÊÎö¹¤¾ß¡£
https://github.com/bridgecrewio/checkov
JNDI-Injection-Exploit
JNDI×¢ÈëʹÓù¤¾ß£¬ÌìÉúJNDIÁ´½Ó²¢Æô¶¯ºó¶ËÏà¹Ø·þÎñ£¬¿ÉÓÃÓÚFastjson¡¢JacksonµÈÏà¹ØÎó²îµÄÑéÖ¤¡£
https://github.com/welk1n/JNDI-Injection-Exploit
nrich v0.2
Ò»¸öÏÂÁîÐй¤¾ß£¬ÓÃÓÚ¿ìËÙÆÊÎöÎļþÖеÄËùÓÐ IP£¬²¢Éó²éÄÄЩ¾ßÓпª·Å¶Ë¿Ú/Îó²î¡£
fuzzuf
ÊÇÒ»¸ö´øÓÐ×Ô¼ºµÄ DSL µÄ fuzzing ¿ò¼Ü£¬Í¨¹ý¹¹½¨ fuzzing ÔÓïµÄ¹¹½¨¿éÀ´ÐÎòfuzzing Ñ»·¡£
https://securityonline.info/fuzzuf-fuzzing-unification-framework/
Çå¾²ÆÊÎö
΢ÈíÐû²¼ÊÊÓÃÓÚ Windows 11 µÄÐÂÓ¦ÓÃÇå¾²¹¦Ð§
https://news.softpedia.com/news/microsoft-announces-new-app-security-feature-for-windows-11-534974.shtml
¶íÂÞ˹º½Ìì¾Ö³ÆºÚ¿Í¹¥»÷ÎÀÐÇÊÇÒ»ÖÖÕ½ÕùÐÐΪ
https://www.bleepingcomputer.com/news/security/russian-space-agency-says-hacking-satellites-is-an-act-of-war/
¹¥»÷ÕßʹÓà Telegram ¾ÙÐÐÓë³åÍ»Ïà¹ØµÄÔ˶¯
https://blog.checkpoint.com/2022/03/02/telegram-becomes-a-digital-forefront-in-the-conflict/
Ó¢ÌØ¶ûµÄµÚ 12 ´ú Alder Lake ´¦Öóͷ£Æ÷²»°üÀ¨Î¢Èí Pluton
https://www.theregister.com/2022/03/02/microsoft_pluton_chip/
Anonymous¼°ÆäÁ¥Êô»ú¹¹¼ÌÐø¶Ô¶íÂÞ˹¾ÙÐй¥»÷
https://securityaffairs.co/wordpress/128576/hacktivism/anonymous-causes-damages-to-russia.html


¾©¹«Íø°²±¸11010802024551ºÅ