FacebookÔÞ³ÉÖ§¸¶9ÍòÍòÃÀÔª½â¾ö³¤´ï10ÄêµÄÇÖÕ¼Òþ˽°¸

Ðû²¼Ê±¼ä 2022-02-18

FacebookÔÞ³ÉÖ§¸¶9ÍòÍòÃÀÔª½â¾ö³¤´ï10ÄêµÄÇÖÕ¼Òþ˽°¸


¾ÝýÌå2ÔÂ15ÈÕ±¨µÀ £¬£¬£¬£¬£¬£¬Meta PlatformsÒÑÔÞ³ÉÖ§¸¶9000ÍòÃÀÔª £¬£¬£¬£¬£¬£¬ÒÔ½â¾ö¸Ã¹«Ë¾Ê¹ÓÃcookieÀ´¸ú×ÙFacebookÓû§»¥ÁªÍø»î¶¯µÄËßËÏ¡£¡£ ¡£¡£ÕâÆð°¸¼þ³¤´ïÊ®ÄêÖ®¾Ã £¬£¬£¬£¬£¬£¬ÔÚ2012Äê±»Ìá³ö £¬£¬£¬£¬£¬£¬Ö÷ÒªÎ§ÈÆFacebookʹÓÃרÓеġ°Like¡±°´¼üÀ´¸ú×ÙÓû§»á¼ûµÚÈý·½ÍøÕ¾Ê± £¬£¬£¬£¬£¬£¬Î¥·´ÁËÇÔÌý·¨¡£¡£ ¡£¡£¾Ý³Æ £¬£¬£¬£¬£¬£¬ËûÃÇ»¹½«ÕâЩä¯ÀÀ¼Í¼±à¼­³ÉСÎÒ˽¼Ò×ÊÁÏ £¬£¬£¬£¬£¬£¬²¢³öÊÛ¸ø¹ã¸æÉÌ¡£¡£ ¡£¡£Ò»Äêǰ £¬£¬£¬£¬£¬£¬MetaÔøÒòÎ¥·´ÁËÒÁÀûŵÒÁÖÝÉúÎïʶ±ðÐÅÏ¢Òþ˽·¨(BIPA) £¬£¬£¬£¬£¬£¬±»ÆÈÁîÖ§¸¶6.5ÒÚÃÀÔª¡£¡£ ¡£¡£


https://thehackernews.com/2022/02/facebook-agrees-to-pay-90-million-to.html


»¥ÁªÍøÐ­»áISOCµÄ´æ´¢¿âÉèÖùýʧÊýÍòÓû§µÄÐÅϢй¶


ClarioÑо¿Ö°Ô±ÔÚ2ÔÂ15ÈÕÖ¸³ö £¬£¬£¬£¬£¬£¬¹ú¼Ê»¥ÁªÍøÐ­»áISOCÊýÍòÓû§µÄÐÅϢй¶¡£¡£ ¡£¡£Clario³ÆËûÃÇÓÚ2021Äê12ÔÂ8ÈÕ·¢Ã÷Ò»¸öδÊܱ£»£»£»£»£»¤µÄMicrosoft Azure blob´æ´¢¿â £¬£¬£¬£¬£¬£¬¸Ã´æ´¢¿â°üÀ¨Êý°ÙÍò¸öÎļþ £¬£¬£¬£¬£¬£¬Éæ¼°ISOC³ÉÔ±µÄÐÕÃû¡¢×¡Ö·¡¢ÓʼþµØµã¡¢ÐԱ𡢵ǼÏêϸÐÅÏ¢ºÍÃÜÂëµÈ¡£¡£ ¡£¡£12ÔÂ15ÈÕ £¬£¬£¬£¬£¬£¬ISOCÌåÏÖ¸ÃÊÂÎñÊÇÓÉÓÚÆäÖÎÀíϵͳÌṩÉÌÉèÖùýʧµ¼Ö嵀 £¬£¬£¬£¬£¬£¬ÇÒÊӲ췢Ã÷²¢Î´ÓÐÈκÎÊý¾Ý±»¶ñÒâ»á¼û¡£¡£ ¡£¡£


https://www.infosecurity-magazine.com/news/internet-society-data-leaked/


BlackCat³ÆÆäÒÑÈëÇÖSwissport²¢ÇÔÈ¡1.6TBµÄÊý¾Ý


¾Ý2ÔÂ15ÈÕ±¨µÀ £¬£¬£¬£¬£¬£¬BlackCatÉù³Æ¶ÔSwissportµÄ¹¥»÷ÈÏÕæ¡£¡£ ¡£¡£¾ÝµÂ¹úýÌåSpiegel³Æ £¬£¬£¬£¬£¬£¬¹¥»÷±¬·¢ÔÚ2ÔÂ3ÈÕÔçÉÏ6µã £¬£¬£¬£¬£¬£¬Æäʱµ¼Ö¶à¼Üº½°àÑÓÎó £¬£¬£¬£¬£¬£¬¶ÔÆäÔËÓª±¬·¢ÁËÑÏÖØÓ°Ïì¡£¡£ ¡£¡£BlackCatÒѹûÕæÔÚÀÕË÷¹¥»÷ʱ´úÇÔÈ¡µÄÊý¾ÝÑù±¾ £¬£¬£¬£¬£¬£¬²¢ÌåÏÖÓÐ1.6TBµÄÊý¾Ý¿É¹©³öÊÛ¡£¡£ ¡£¡£Ð¹Â¶Êý¾Ý°üÀ¨ÉÌÒµÎļþ¡¢ÄÉ˰É걨µ¥¡¢»¤ÕÕ¡¢Ð¡ÎÒ˽¼ÒÉí·ÝÖ¤¡¢ÓʼþµØµãºÍµç»°ºÅÂëµÈ¡£¡£ ¡£¡£


https://securityaffairs.co/wordpress/128039/cyber-crime/blackcat-swissport-ransomware-attack.html


Proofpoint·¢Ã÷TA2541Õë¶Ôº½¿ÕºÍÔËÊäÐÐÒµµÄ¹¥»÷»î¶¯


Çå¾²¹«Ë¾ProofpointÓÚ2ÔÂ15ÈÕÅû¶ÁËTA2541µÄ¹¥»÷»î¶¯µÄϸ½Ú¡£¡£ ¡£¡£TA2541×Ô2017ÄêÒÔÀ´Ò»Ö±»îÔ¾ £¬£¬£¬£¬£¬£¬Õë¶Ôº½¿Õ¡¢º½Ìì¡¢ÔËÊä¡¢ÖÆÔìºÍ¹ú·ÀÐÐÒµµÄ×éÖ¯¡£¡£ ¡£¡£Ëüͨ³£ÒÀÀµMicrosoft Word ÎĵµÀ´·Ö·¢RAT £¬£¬£¬£¬£¬£¬½üÆÚ×îÏÈʹÓÃÍйÜÔÚGoogle DriveµÈÔÆÐ§À͵ÄÁ´½Ó¡£¡£ ¡£¡£±ðµÄ £¬£¬£¬£¬£¬£¬¸ÃÍŻﲻʹÓÃ×Ô½ç˵¶ñÒâÈí¼þ £¬£¬£¬£¬£¬£¬Æ«ÐÒÓÚAsyncRAT¡¢NetWire¡¢WSH RATºÍParallax¡£¡£ ¡£¡£ÏÖÔڻÖÐʹÓõĶñÒâÈí¼þ¶¼¿ÉÓÃÓÚÍøÂçÐÅÏ¢ £¬£¬£¬£¬£¬£¬µ«¹¥»÷ÕßµÄ×îÖÕÄ¿µÄÈÔδ¿ÉÖª¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/unskilled-hacker-linked-to-years-of-attacks-on-aviation-transport-sectors/


Unit 42Ðû²¼¹ØÓÚEmotetÐÂÒ»ÂÖ¹¥»÷»î¶¯µÄÆÊÎö±¨¸æ


2ÔÂ15ÈÕ £¬£¬£¬£¬£¬£¬Unit 42Ðû²¼Á˹ØÓÚEmotetÐÂÒ»ÂÖ¹¥»÷»î¶¯µÄÆÊÎö±¨¸æ¡£¡£ ¡£¡£±¨¸æÖ¸³ö £¬£¬£¬£¬£¬£¬ÔçÔÚ2021Äê12ÔÂ21ÈÕ £¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±¾ÍÊӲ쵽¶ñÒâÈí¼þ¼Ò×åEmotetµÄÐÂѬȾҪÁì¡£¡£ ¡£¡£ÐµĹ¥»÷»î¶¯Í¨¹ýµç×ÓÓʼþ·Ö·¢Ò»¸öExcelÎļþ £¬£¬£¬£¬£¬£¬¸ÃÎĵµ°üÀ¨Ò»¸ö»ìÏýµÄExcel 4.0ºê¡£¡£ ¡£¡£¼¤»îºêºó £¬£¬£¬£¬£¬£¬Ëü»áÏÂÔØ²¢Ö´ÐÐÒ»¸öHTMLÓ¦ÓóÌÐò £¬£¬£¬£¬£¬£¬¸ÃÓ¦ÓóÌÐò»áÏÂÔØÁ½¸ö½×¶ÎµÄPowerShellÒÔÏÂÔØ²¢Ö´ÐÐ×îÖÕµÄEmotet payload¡£¡£ ¡£¡£


https://unit42.paloaltonetworks.com/new-emotet-infection-method/


Check Point³ÆTrickbotÒѹ¥»÷60¼Ò´óÐ͹«Ë¾


Check Point ResearchÔÚ2ÔÂ16ÈÕÐû²¼±¨¸æ³ÆTrickbotÒѱ»ÓÃÓÚ¹¥»÷60¼Ò´óÐ͹«Ë¾¡£¡£ ¡£¡£TrickbotÊÇÒ»ÖÖÖØ´óÇҶ๦ЧµÄ¶ñÒâÈí¼þ £¬£¬£¬£¬£¬£¬¾ßÓÐ20¶à¸ö¿É°´ÐèÏÂÔØºÍÖ´ÐеÄÄ£¿£¿£¿£¿£¿£¿£¿£¿é¡£¡£ ¡£¡£TrickBotµÄÄ¿µÄ°üÀ¨ÑÇÂíÑ·¡¢ÃÀ¹úÔËͨ¡¢Ä¦¸ù´óͨ¡¢Î¢Èí¡¢Ë®Ê¦Áª°îÐÅÓÃÏàÖúÉç¡¢PayPal¡¢RBC¡¢ÑÅ»¢µÈ×ÅÃû¹«Ë¾¡£¡£ ¡£¡£±ðµÄ £¬£¬£¬£¬£¬£¬CPR³Æ¹¥»÷ÕßµÄÄ¿µÄ²¢²»ÊÇÕâЩ¹«Ë¾¶øÊÇËûÃǵĿͻ§¡£¡£ ¡£¡£±¨¸æ»¹ÖصãÐÎòÁË3¸öÒªº¦Ä£¿£¿£¿£¿£¿£¿£¿£¿éinjectDll¡¢tabDllºÍpwgrabc £¬£¬£¬£¬£¬£¬ÒÔ¼°TrickbotµÄ·´ÆÊÎöÊÖÒÕ¡£¡£ ¡£¡£


https://research.checkpoint.com/2022/a-modern-ninja-evasive-trickbot-attacks-customers-of-60-high-profile-companies/



Çå¾²¹¤¾ß


SafeDNS


ÃæÏò MSP µÄ»ùÓÚÔÆµÄ Internet Çå¾²ºÍ Web ¹ýÂ˽â¾ö¼Æ»®¡£¡£ ¡£¡£


https://thehackernews.com/2022/02/safedns-cloud-based-internet-security.html


F5 Distributed Cloud Services


F5 ÍÆ³öÁËÒ»¸öеÄÈí¼þ¼´Ð§ÀÍ (SaaS) ƽ̨ £¬£¬£¬£¬£¬£¬Ö¼ÔÚ¼ò»¯¹«Ë¾µÄ·ÖÖ§Çå¾²½â¾ö¼Æ»®¡£¡£ ¡£¡£


https://www.zdnet.com/article/f5-launches-new-saas-app-security-cloud-edge-computing-platform/


Shellcodetester


¸Ã¹¤¾ß²âÊÔÌìÉúµÄ ShellCodes¡£¡£ ¡£¡£


https://github.com/helviojunior/shellcodetester


Flare-Qdb


ÏÂÁîÐкͿɱàд¾ç±¾µÄ»ùÓÚ Python µÄ¹¤¾ß £¬£¬£¬£¬£¬£¬ÓÃÓÚÆÀ¹ÀºÍ²Ù×÷±¾»ú³ÌÐò״̬¡£¡£ ¡£¡£


https://github.com/mandiant/flare-qdb


365Inspect


ͨ¹ý±àд¿É×Ô¶¯¶Ô Microsoft Office 365 ÇéÐξÙÐÐÇå¾²ÆÀ¹ÀµÄ PowerShell ¾ç±¾ £¬£¬£¬£¬£¬£¬½øÒ»²½Ïàʶ O365 Ç徲״̬¡£¡£ ¡£¡£


https://github.com/soteria-security/365Inspect



Çå¾²ÆÊÎö


CVE-2021-44521£ºApache Cassandra ÖÐ RCE Îó²î


https://thehackernews.com/2022/02/high-severity-rce-security-bug-reported.html


Squirrelwaffle¹¥»÷δÐÞ¸´µÄ Exchange ЧÀÍÆ÷


https://news.sophos.com/en-us/2022/02/15/vulnerable-exchange-server-hit-by-squirrelwaffle-and-financial-fraud/


Windows 10 KB5010415 ¸üÐÂÐû²¼


https://www.bleepingcomputer.com/news/microsoft/windows-10-kb5010415-update-released-with-35-bug-fixes-improvements/


CISA Ðû²¼Í¨¸æ½¨Òé×éÖ¯ÐÞ¸´Æð¾¢Ê¹ÓÃµÄ Chrome¡¢Magento Îó²î


https://www.bleepingcomputer.com/news/security/cisa-tells-federal-agencies-to-patch-actively-exploited-chrome-magento-bugs/


¹È¸èΪ Linux ÄÚºËºÍ GKE 0dayÌṩ 91,000 ÃÀÔªµÄ½±Àø


https://www.securityweek.com/google-offering-91000-rewards-linux-kernel-gke-zero-days


ÊÊÓÃÓÚ Windows 11 µÄ Android Ó¦ÓóÌÐòÒÑÔÚÃÀ¹úÉÏÏß


https://www.bleepingcomputer.com/news/microsoft/windows-11s-android-apps-feature-now-available-in-the-us/