åÚÏëUEFI¹Ì¼þÇý¶¯³ÌÐòÖеÄÎó²îÓ°ÏìÉϰٿîÌõ¼Ç±¾µçÄÔ
Ðû²¼Ê±¼ä 2022-04-201¡¢åÚÏëUEFI¹Ì¼þÇý¶¯³ÌÐòÖеÄÎó²îÓ°ÏìÉϰٿîÌõ¼Ç±¾µçÄÔ
¾ÝýÌå4ÔÂ19ÈÕ±¨µÀ£¬ESETÑо¿Ö°Ô±·¢Ã÷Ó°ÏìåÚÏëÉϰٿîÌõ¼Ç±¾µçÄÔµÄ3¸öÎó²î¡£ÆäÖÐÁ½¸öÎó²î£¨CVE-2021-3971ºÍCVE-2021-3972£©¿ÉÓÃÀ´½ûÓöԴ洢UEFI¹Ì¼þµÄSPIÉÁ´æÐ¾Æ¬µÄ±£»¤£¬²¢¹Ø±ÕUEFIÇå¾²Æô¶¯¹¦Ð§£¬Ê¹¶ñÒâÈí¼þÔÚÏµÍ³ÖØÆôºóÈԿɱ£´æ¡£µÚÈý¸öÎó²î£¨CVE-2021-3970£©±£´æÓÚLenovoVariable SMI´¦Öóͷ£³ÌÐòÖУ¬¹¥»÷Õß¿ÉʹÓÃÆäÒÔÌáÉýµÄȨÏÞÖ´ÐÐí§Òâ´úÂë¡£ESETÓÚ2021Äê10ÔÂ11ÈÕÏòåÚÏ뱨¸æÕâЩÎó²î£¬åÚÏëÓÚ4ÔÂ12ÈÕÐû²¼²¹¶¡¡£
https://www.bleepingcomputer.com/news/security/lenovo-uefi-firmware-driver-bugs-affect-over-100-laptop-models/
2¡¢CISAºÍFBIÍŽáÐû²¼¹ØÓÚÇø¿éÁ´ÐÐÒµµÄÍøÂçÇå¾²×Éѯ
4ÔÂ18ÈÕ£¬ÃÀ¹úFBI¡¢CISAºÍ²ÆÎñ²¿ÍŽáÐû²¼Á˹ØÓÚÇø¿éÁ´ÐÐÒµµÄÍøÂçÇå¾²×Éѯ¡£¸Ã×Éѯָ³ö£¬³¯ÏÊAPT×éÖ¯LazarusÃé×¼Çø¿éÁ´ÊÖÒպͼÓÃÜÇ®±ÒÐÐÒµµÄÖÖÖÖ×éÖ¯£¬°üÀ¨¼ÓÃÜÇ®±ÒÉúÒâËù¡¢È¥ÖÐÐÄ»¯½ðÈÚ (DeFi) ÐæÅºÍ¼ÓÃÜÇ®±ÒÉÌÒµ¹«Ë¾µÈ¡£¹¥»÷ÕßʹÓÃÖÖÖÖͨѶƽ̨¶ÔÄ¿µÄ¾ÙÐÐÉç»á¹¤³Ì¹¥»÷£¬ÓÕʹÆäÔÚWindows»òmacOSϵͳÉÏÏÂÔØÄ¾Âí»¯µÄ¼ÓÃÜÇ®±ÒÓ¦Óã¬ÒÔÇÔȡ˽Կ»òÀÄÓÃÆäËüÎó²î¡£¸Ãͨ¸æÌṩÁË´ËÀàÔ˶¯Ïà¹ØµÄÕ½ÂÔ¡¢ÊÖÒպͳÌÐò(TTP)ºÍIOC£¬ÒÔ×ÊÖú×é֯ʶ±ð²¢µÖÓùÕë¶Ô¼ÓÃÜÇ®±ÒµÄÍøÂç¹¥»÷¡£
https://www.cisa.gov/uscert/ncas/alerts/aa22-108a
3¡¢CloudSEK·¢Ã÷ð³äWin11Éý¼¶·Ö·¢Inno StealerµÄÔ˶¯
ýÌå4ÔÂ18ÈÕ±¨µÀ£¬CloudSEK·¢Ã÷ð³äWin11Éý¼¶·Ö·¢Inno StealerµÄÔ˶¯¡£¸ÃÔ˶¯ÏÖÔںܻîÔ¾£¬Í¨¹ýËÑË÷Ч¹ûͶ¶¾À´ÍÆËÍð³äWindows 11ÍÆ¹ãÒ³ÃæµÄ´¹ÂÚÍøÕ¾¡£Ä¿µÄµã»÷Á¬Ã¦ÏÂÔØºó»á»ñµÃÒ»¸öISOÎļþ£¬ÆäÖаüÀ¨Inno StealerµÄ¼ÓÔØ³ÌÐò¡£Ð¶ñÒâÈí¼þÓÉÓÚʹÓÃÁËInno Setup Windows×°ÖóÌÐò¶øµÃÃû£¬ÓëÏÖÔÚÊ¢ÐÐµÄÆäËüÐÅÏ¢ÇÔÈ¡³ÌÐòµÄ´úÂëûÓÐÈκÎÏàËÆÖ®´¦£¬¿ÉÇÔÈ¡ä¯ÀÀÆ÷cookieºÍ´æ´¢µÄƾ֤¡¢¼ÓÃÜÇ®±ÒÇ®°üÖеÄÊý¾ÝÒÔ¼°ÎļþϵͳµÄÊý¾Ý¡£
https://www.bleepingcomputer.com/news/security/unofficial-windows-11-upgrade-installs-info-stealing-malware/
4¡¢Çå¾²¹«Ë¾PRODAFTÐû²¼ÀÕË÷Èí¼þPYSAµÄÉî¶ÈÆÊÎö±¨¸æ
4ÔÂ14ÈÕ£¬Çå¾²¹«Ë¾PRODAFTÐû²¼Á˹ØÓÚÀÕË÷Èí¼þPYSAµÄÉî¶ÈÆÊÎö±¨¸æ¡£PYSAÊÇMespinozaµÄ¼ÌÈÎÕߣ¬ÓÚ2019Äê12ÔÂÊ״α»·¢Ã÷£¬ÒѳÉΪ2021ÄêQ4¼ì²âµ½µÄµÚÈý´óÊ¢ÐÐÀÕË÷Èí¼þ£¬×Ô2020Äê9ÔÂÒÔÀ´Ð¹Â¶Á˶à´ï747¸ö±»¹¥»÷Ä¿µÄµÄÐÅÏ¢¡£PRODAFT·¢Ã÷ÁËPYSAµÄ¹ûÕæ.gitÎļþ¼Ð£¬ÆäÖÐÒ»¸ö³ÉÔ±ÊÇ¡°dodo@mail.pcc¡±£¬Æ¾Ö¤Ìá½»ÀúÊ·ÅжϴËÈËλÓÚÒ»¸öÏÄÁîʱ¹ú¼Ò¡£PYSAµÄ»ù´¡ÉèÊ©»¹°üÀ¨dockerizedÈÝÆ÷£¬É漰й¶·þÎñÆ÷¡¢Êý¾Ý¿âºÍÖÎÀí·þÎñÆ÷£¬ÒÔ¼°´æ´¢¼ÓÃÜÎļþµÄAmazon S3ÔÆ£¬×ܼÆ31.47TB¡£
https://thehackernews.com/2022/04/researchers-share-in-depth-analysis-of.html
5¡¢CheckPointÐû²¼2022ÄêÃæÁÙ×î´óµÄÔÆÇå¾²ÌôÕ½µÄ±¨¸æ
CheckPointÔÚ4ÔÂ18ÈÕÐû²¼ÁË2022ÄêÃæÁÙµÄ×î´óÔÆÇå¾²ÌôÕ½µÄ±¨¸æ¡£±¨¸æÖ¸³ö£¬Áè¼Ý98%µÄ×é֯ʹÓûùÓÚÔÆµÄ»ù´¡¼Ü¹¹£¬76%µÄ×éÖ¯ÓµÓÐÓÉÁ½¸ö»ò¶à¸öÔÆÌṩÉ̵ķþÎñ×é³ÉµÄ¶àÔÆÇéÐΡ£¶àÔÆÇéÐεÄÖØ´óÐÔµ¼ÖÂÁËÐí¶àÌôÕ½£¬°üÀ¨Êý¾ÝµÄÒþ˽ºÍ±£»¤¡¢¶àÔÆÇéÐÎÖÐÐëÒªµÄÊÖÒÕ¡¢½â¾ö¼Æ»®ÕûºÏÒÔ¼°¿É¼ûÐԺͿØÖƵÄȱ·¦¡£ÊµÏÖÔÆÇå¾²µÄÖ÷ҪĿµÄ°üÀ¨±ÜÃâÔÆÉèÖùýʧ¡¢±£»¤ÒÑÔÚʹÓõÄÖ÷ÒªÔÆÓ¦ÓóÌÐò¡¢ÊµÏÖî¿ÏµºÏ¹æºÍµÖÓù¶ñÒâÈí¼þ¡£
https://blog.checkpoint.com/2022/04/18/the-biggest-cloud-security-challenges-in-2022-check-point-software/
6¡¢FortinetÐû²¼½üÆÚEmotet Maldoc±¬·¢Ç÷ÊÆµÄÆÊÎö±¨¸æ
4ÔÂ18ÈÕ£¬FortinetÐû²¼¹ØÓÚ½üÆÚEmotet·Ö·¢MaldocÔ˶¯µÄÆÊÎö±¨¸æ¡£´ËÂÖÔ˶¯×îÏÈÓÚ2021Äê11ÔÂ16ÈÕ£¬Ê¹ÓÃÁË´¹ÂÚÓʼþÓëÉç»á¹¤³Ì¹¥»÷ÏàÍŽáµÄ·½·¨£¬À´ÓÕʹĿµÄ×°ÖöñÒâÈí¼þ¡£ÕâЩ´¹ÂÚÓʼþµÄÖ÷ÌâÐÐÖÐͨ³£ÖаüÀ¨¡°Re:¡±»ò¡°Fw:¡±£¬Ê¹Æä¿´ÆðÀ´Ô½·¢Õýµ±¡£Ñо¿Ö°Ô±¼ì²âµ½ÁËÓë´ËÔ˶¯Ïà¹ØµÄ5¸ö²î±ðÑù±¾£¬ËüÃǵĺê´úÂëºÍÖ´ÐÐÁ÷³Ì±£´æ²î±ð¡£±ðµÄ£¬¹¥»÷Ô˶¯Ê¹ÓõĶñÒâExcelÎļþµÄÕ¼±ÈΪ93%£¬Ô¶¸ßÓÚ7%µÄ¶ñÒâWordÎĵµ¡£
https://www.fortinet.com/blog/threat-research/Trends-in-the-recent-emotet-maldoc-outbreak


¾©¹«Íø°²±¸11010802024551ºÅ