AppleÐû²¼½ôÆÈ¸üУ¬ £¬£¬£¬£¬£¬£¬ÐÞ¸´2¸öÒѱ»Ê¹ÓõÄÁãÈÕÎó²î

Ðû²¼Ê±¼ä 2022-04-02

AppleÐû²¼½ôÆÈ¸üУ¬ £¬£¬£¬£¬£¬£¬ÐÞ¸´2¸öÒѱ»Ê¹ÓõÄÁãÈÕÎó²î


3ÔÂ31ÈÕ£¬ £¬£¬£¬£¬£¬£¬AppleÐû²¼½ôÆÈ¸üУ¬ £¬£¬£¬£¬£¬£¬ÐÞ¸´iPhone¡¢iPadºÍMacÖÐ2¸öÒѱ»Ê¹ÓõÄÁãÈÕÎó²î¡£ ¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄÎó²î»®·ÖÎªÓ¢ÌØ¶ûÏÔ¿¨Çý¶¯³ÌÐòÖеÄÔ½½çдÈëÎó²î(CVE-2022-22674)£¬ £¬£¬£¬£¬£¬£¬¿ÉÓÃÀ´¶ÁÈ¡ÄÚºËÄڴ棻£»£»£»£»£»ÒÔ¼°AppleAVDýÌå½âÂëÆ÷ÖеÄÔ½½ç¶ÁÈ¡Îó²î(CVE-2022-22675)£¬ £¬£¬£¬£¬£¬£¬¿É±»ÓÃÀ´ÒÔÄÚºËȨÏÞÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£¡£¡£¡£¡£AppleÌåÏÖÕâЩÎó²î¿ÉÄÜÒѱ»Æð¾¢Ê¹Ó㬠£¬£¬£¬£¬£¬£¬ÏÖÒÑͨ¹ýË¢ÐÂÊäÈëÑéÖ¤ºÍ½çÏß¼ì²é£¬ £¬£¬£¬£¬£¬£¬ÔÚiOS 15.4.1¡¢iPadOS 15.4.1ºÍmacOS Monterey 12.3.1ÖÐÐÞ¸´¡£ ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/apple-emergency-update-fixes-zero-days-used-to-hack-iphones-macs/



QNAP³ÆÆä²¿·ÖNAS×°±¸±£´æDoSÎó²îCVE-2022-0778 


      ¾ÝýÌå3ÔÂ30ÈÕ±¨µÀ£¬ £¬£¬£¬£¬£¬£¬QNAPÔÚ±¾ÖܶþÐû²¼Í¨¸æ³Æ£¬ £¬£¬£¬£¬£¬£¬Æä´ó²¿·ÖNAS×°±¸¶¼Êܵ½OpenSSLÖеÄDoSÎó²îµÄÓ°Ïì¡£ ¡£¡£¡£¡£¡£¡£¡£ÕâÊÇÒ»¸öÎÞÏÞÑ­»·Îó²î£¨CVE-2022-0778£©£¬ £¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓú󹥻÷Õß¿ÉÖ´ÐоܾøÐ§À͹¥»÷¡£ ¡£¡£¡£¡£¡£¡£¡£Í¨¸æÖ¸³ö£¬ £¬£¬£¬£¬£¬£¬¸ÃÎó²îÓÚÁ½ÖÜǰ±»¹ûÕæ²¢Ðû²¼Á˲¹¶¡£ ¡£¡£¡£¡£¡£¡£¡£¬ £¬£¬£¬£¬£¬£¬µ«QNAPÌåÏÖ£¬ £¬£¬£¬£¬£¬£¬Æä¿Í»§»¹ÐèÆÚ´ýÆä¹«Ë¾Ðû²¼×Ô¼ºµÄÇå¾²¸üС£ ¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬ £¬£¬£¬£¬£¬£¬OpenSSLÍÅ¶Ó³ÆÆäÉÐδ·¢Ã÷×Ô¶¯Ê¹ÓøÃÎó²îµÄ»î¶¯£¬ £¬£¬£¬£¬£¬£¬µ«Òâ´óÀûCSIRT¼ì²âµ½ËüÒѱ»ÔÚҰʹÓᣠ¡£¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2022/03/qnap-warns-of-openssl-infinite-loop.html



Sentinel·¢Ã÷HiveʹÓÃеÄIPfuscation¿ÉÈÆ¹ý¼ì²â


3ÔÂ29ÈÕ£¬ £¬£¬£¬£¬£¬£¬SentinelÐû²¼±¨¸æ³ÆHiveʹÓÃÐÂÊÖÒÕIPfuscationÈÆ¹ý¼ì²â¡£ ¡£¡£¡£¡£¡£¡£¡£»£»£»£»£»£»ìÏýÊÖÒÕIPfuscationÉæ¼°IPv4µØµãºÍһϵÁеÄת»»²¢×îÖÕÏÂÔØCobalt Strike beacon¡£ ¡£¡£¡£¡£¡£¡£¡£¼ì²âµ½µÄÑù±¾ÊÇ64λWindows PEÎļþ£¬ £¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨Ò»¸ö»ìÏýµÄpayload£¬ £¬£¬£¬£¬£¬£¬ÓÃÓÚÌá¹©ÌØÁíÍâÖ²Èë³ÌÐò¡£ ¡£¡£¡£¡£¡£¡£¡£»£»£»£»£»£»ìÏýµÄpayloadαװ³ÉÒ»¸öASCII IPv4µØµãÊý×飬 £¬£¬£¬£¬£¬£¬±»×ª´ï¸øRtlIpv4StringToAddressAº¯Êý£¬ £¬£¬£¬£¬£¬£¬¸Ãº¯Êý»á½«ASCII IP×Ö·û´®×ª»»Îª¶þ½øÖÆ£¬ £¬£¬£¬£¬£¬£¬ÕâЩ¶þ½øÖÆ¿ÉÒÔ×é³ÉÒ»¸öshellcode¿é¡£ ¡£¡£¡£¡£¡£¡£¡£


https://www.sentinelone.com/blog/hive-ransomware-deploys-novel-ipfuscation-technique/



FBIµÄEagle SweepÐж¯Òѵ·»ÙÈ«Çò¶à¸öBEC¹¥»÷ÍÅ»ï


ýÌå3ÔÂ30ÈÕ±¨µÀ£¬ £¬£¬£¬£¬£¬£¬ FBIºÍ¹ú¼ÊÖ´·¨»ú¹¹µÄÁªºÏÐж¯ÒѾ­µ·»ÙÁ˶à¸öÉÌÒµµç×ÓÓʼþй¶(BEC)ÍŻ ¡£¡£¡£¡£¡£¡£¡£ÕâÏîÃûΪEagle SweepµÄÐж¯Ò»Á¬ÁËÈý¸öÔ£¬ £¬£¬£¬£¬£¬£¬´Ó2021Äê9ÔÂ×îÏÈ£¬ £¬£¬£¬£¬£¬£¬ÔÚÃÀ¹ú¡¢ÄáÈÕÀûÑÇ¡¢ÄÏ·Ç¡¢¼íÆÒÕ¯ºÍ¼ÓÄôó¾Ð²¶ÁË65ÃûÏÓÒÉÈË¡£ ¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤FBI IC3Ðû²¼µÄ2021Äê·¸·¨±¨¸æ£¬ £¬£¬£¬£¬£¬£¬BECÕ©Æ­Ôì³ÉµÄ¾­¼ÃËðʧ¸ß´ï24ÒÚÃÀÔª¡£ ¡£¡£¡£¡£¡£¡£¡£FBI³Æ£¬ £¬£¬£¬£¬£¬£¬ËûÃǾв¶µÄÏÓÒÉÈ˹¥»÷ÁËÃÀ¹ú500¶à¼Ò¹«Ë¾£¬ £¬£¬£¬£¬£¬£¬²¢Ôì³ÉÖÁÉÙ51000000ÃÀÔªµÄËðʧ¡£ ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/legal/fbi-disrupts-bec-cybercrime-gangs-targeting-victims-worldwide/


ViasatÅû¶ÆäÎÀÐÇЧÀÍKA-SATÔâµ½¹¥»÷µÄÏêϸÐÅÏ¢


¾Ý3ÔÂ30ÈÕ±¨µÀ£¬ £¬£¬£¬£¬£¬£¬ÃÀ¹úÎÀÐÇͨѶÌṩÉÌViasat¹ûÕæÁ˹ØÓÚ2ÔÂ24ÈÕÆäÎÀÐÇ¿í´øÐ§ÀÍKA-SATÍøÂç¹¥»÷µÄÊÂÎñ±¨¸æ¡£ ¡£¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñµ¼ÖÂÖÐÅ·ºÍ¶«Å·µÄÎÀÐÇЧÀÍÖÐÖ¹£¬ £¬£¬£¬£¬£¬£¬»¹ÖÐÖ¹ÁËÓÃÓÚ¿ØÖƵ¹úÔ¼5800̨·çÁ¦ÎÐÂÖ»úµÄµ÷ÖÆ½âµ÷Æ÷¡£ ¡£¡£¡£¡£¡£¡£¡£¾­ÊӲ죬 £¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýÉèÖùýʧµÄVPN×°±¸ÈëÇÖÆäÖÎÀíϵͳ£¬ £¬£¬£¬£¬£¬£¬²¢ÏòÓû§µÄ×°±¸·¢ËÍÏÂÁ £¬£¬£¬£¬£¬£¬µ¼ÖÂÊýÍòµ÷ÖÆ½âµ÷Æ÷´ÓKA-SATÍøÂçÖеôÏß¡£ ¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬ £¬£¬£¬£¬£¬£¬ViasatÒѾ­·¢³ö½ü3Íǫ̀µ÷ÖÆ½âµ÷Æ÷£¬ £¬£¬£¬£¬£¬£¬ÒÔ×ÊÖú¿Í»§ÖØÐÂÁªÍø¡£ ¡£¡£¡£¡£¡£¡£¡£ 


https://www.bleepingcomputer.com/news/security/viasat-shares-details-on-ka-sat-satellite-service-cyberattack/



Ñо¿Ö°Ô±ÑÝʾ¿ÉÔ¶³ÌÖÐÖ¹Æû³µ³äµçµÄBrokenwire¹¥»÷


ýÌå3ÔÂ30Èճƣ¬ £¬£¬£¬£¬£¬£¬Ó¢¹úÅ£½ò´óѧºÍÈðÊ¿Armasuisse»ú¹¹µÄÑо¿Ö°Ô±·¢Ã÷ÁËÒ»ÖÖÐµĹ¥»÷ÒªÁìBrokenwire¡£ ¡£¡£¡£¡£¡£¡£¡£BrokenwireÊÇÕë¶Ô×éºÏ³äµçϵͳ(CCS)µÄ¹¥»÷£¬ £¬£¬£¬£¬£¬£¬¶øCCSÊǵ綯Æû³µÖÐʹÓÃ×îÆÕ±éµÄÖ±Á÷¿ìËÙ³äµçÊÖÒÕÖ®Ò»¡£ ¡£¡£¡£¡£¡£¡£¡£ÕâÖÖ¹¥»÷»áÖÐÖ¹³µÁ¾ºÍ³äµçÆ÷Ö®¼äÐëÒªµÄ¿ØÖÆÍ¨Ñ¶£¬ £¬£¬£¬£¬£¬£¬µ¼Ö³äµçÀú³ÌÖÐÖ¹¡£ ¡£¡£¡£¡£¡£¡£¡£¾ÝÔ¤¼Æ£¬ £¬£¬£¬£¬£¬£¬È«ÇòÔ¼ÓÐ1200ÍòÁ¾µç¶¯Æû³µ£¬ £¬£¬£¬£¬£¬£¬ÆäÖд󲿷ÖÊÜ´ËÀ๥»÷Ó°Ïì¡£ ¡£¡£¡£¡£¡£¡£¡£³ýµç¶¯Æû³µÍ⣬ £¬£¬£¬£¬£¬£¬Brokenwire»¹»áÓ°Ïìµç¶¯´¬²°¡¢·É»úºÍÖØÐͳµÁ¾µÈ¡£ ¡£¡£¡£¡£¡£¡£¡£


https://www.brokenwire.fail/




Çå¾²¹¤¾ß


CVE-2022-27254µÄPoC


±¾ÌïÔ¶³ÌÎÞÔ¿³×ϵͳÎó²î(CVE-2022-27254)µÄ PoC¡£ ¡£¡£¡£¡£¡£¡£¡£


https://github.com/nonamecoder/CVE-2022-27254


casper-fs


×Ô½ç˵µÄ Linux ÄÚºËÄ£¿£¿£¿£¿éÌìÉúÆ÷£¬ £¬£¬£¬£¬£¬£¬ÓÃÓÚʹÓÃ×ÊÔ´À´±£»£»£»£»£»£»¤»òÒþ²Ø×Ô½ç˵ÎļþÁбí¡£ ¡£¡£¡£¡£¡£¡£¡£


https://github.com/CoolerVoid/casper-fs


hcltm


ÌṩһÖÖ DevOps ÓÅÏȵÄÒªÁìÀ´¼Í¼ϵͳÍþвģ×Ó¡£ ¡£¡£¡£¡£¡£¡£¡£


https://github.com/xntrik/hcltm



Çå¾²ÆÊÎö


Hive ÀÕË÷ÍŻ﹥»÷¼ÓÖÝPartnership HealthPlan


https://therecord.media/hive-ransomware-shuts-down-california-health-care-organization/


΢ÈíÕýïÔÌ­ IE£¬ £¬£¬£¬£¬£¬£¬ÍýÏëÔÚ 6 Ô 15 ÈÕ³¹µ×¹Ø±Õ


https://news.softpedia.com/news/android-could-at-one-point-be-able-to-detect-bluetooth-trackers-natively-535135.shtml


Mozilla ½«Ðû²¼Thunderbird °æ±¾ 102


https://news.softpedia.com/news/mozilla-thunderbird-will-receive-a-major-update-with-version-102-535131.shtml


Infosecurity Europe Ðû²¼ 2022 Äê»î¶¯µÄÑݽ²Õß


https://www.infosecurity-magazine.com/news/infosecurity-europe-keynote/


Ò»¸ö¼òÆÓµÄ±àÂë¹ýʧ¿ÉÒÔÆÆËðÂí×Ô´ïµÄ»¥ÁªÏµÍ³


https://www.bleepingcomputer.com/news/security/mazda-infotainment-crash-shows-how-fragile-car-security-really-is/