GoogleÐû²¼½ôÆÈ¸üÐÂÐÞ¸´ChromeÖÐÒѱ»Ê¹ÓõÄÎó²î

Ðû²¼Ê±¼ä 2022-04-15
1¡¢GoogleÐû²¼½ôÆÈ¸üÐÂÐÞ¸´ChromeÖÐÒѱ»Ê¹ÓõÄÎó²î


GoogleÔÚ4ÔÂ14ÈÕÐû²¼½ôÆÈ¸üР£¬£¬£¬£¬£¬£¬ÐÞ¸´Chrome V8 JavaScriptÒýÇæÖеÄÒ»¸öÀàÐÍ»ìÏýÎó²î£¨CVE-2022-1364£©¡£¡£¡£ ¡£¡£¡£¡£¡£GoogleÔÚÇ徲ͨ¸æÖÐÌåÏÖ £¬£¬£¬£¬£¬£¬ÒѾ­¼ì²âµ½Ê¹ÓÃÕâ¸öÁãÈÕÎó²îµÄ¹¥»÷ £¬£¬£¬£¬£¬£¬µ«Ëü²¢Î´ÌṩÓйØÕâЩ¹¥»÷µÄ¸ü¶àϸ½Ú¡£¡£¡£ ¡£¡£¡£¡£¡£ËäÈ»ÀàÐÍ»ìÏýÎó²îͨ³£»£»£»£»áͨ¹ýÔ½½ç¶ÁÈ¡»òдÈëµ¼ÖÂä¯ÀÀÆ÷Í߽⠣¬£¬£¬£¬£¬£¬µ«¹¥»÷ÕßÒ²¿ÉÒÔʹÓÃËüÃÇÀ´Ö´ÐÐí§Òâ´úÂë¡£¡£¡£ ¡£¡£¡£¡£¡£ÓÉÓÚ´ËÎó²îÒÑÔÚ¹¥»÷Öб»Æð¾¢Ê¹Óà £¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±Ç¿ÁÒ½¨ÒéÓû§ÊÖ¶¯¼ì²éиüв¢ÖØÆôä¯ÀÀÆ÷Ó¦ÓøüС£¡£¡£ ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/google-chrome-emergency-update-fixes-zero-day-used-in-attacks/


2¡¢Ñо¿ÍŶӳÆÐ½©Ê¬ÍøÂçFodchaÒÑѬȾÁè¼Ý6Íǫ̀װ±¸


ýÌå3ÔÂ14ÈÕ±¨µÀ £¬£¬£¬£¬£¬£¬Ð½©Ê¬ÍøÂçFodchaÔÚ3ÔÂ29ÈÕÖÁ4ÔÂ10ÈÕʱ´úÒÑѬȾÁè¼Ý62000̨װ±¸¡£¡£¡£ ¡£¡£¡£¡£¡£FodchaʹÓÃÁ˱©Á¦ÆÆ½â¹¤¾ßCrazyfia £¬£¬£¬£¬£¬£¬²¢ÀÄÓÃÁ˶à¸öndayÎó²îÀ´Ñ¬È¾ÐÂ×°±¸ £¬£¬£¬£¬£¬£¬Éæ¼°Android£¨ADBµ÷ÊÔЧÀÍÆ÷ÖÐRCE£©¡¢GitLab£¨CVE-2021-22205£©ºÍRealtek Jungle SDK£¨CVE-2021-35394£©µÈ¡£¡£¡£ ¡£¡£¡£¡£¡£ËüÌìÌì¶Ô100¶à¸öÄ¿µÄ¾ÙÐÐDDoS¹¥»÷ £¬£¬£¬£¬£¬£¬×Ô1ÔÂÒÔÀ´Ò»Ö±Ê¹ÓÃfolded[.]in £¬£¬£¬£¬£¬£¬Ö±µ½3ÔÂ19ÈÕ¸ÃÓò±»È¡µÞºó £¬£¬£¬£¬£¬£¬ËüÇл»µ½ÁËfrenchxperts[.]cc¡£¡£¡£ ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-fodcha-ddos-botnet-targets-over-100-victims-every-day/


3¡¢VMware³ÆWorkspace ONE AccessÖÐCVE-2022-22954Òѱ»Ê¹ÓÃ


¾ÝýÌå4ÔÂ13ÈÕ±¨µÀ £¬£¬£¬£¬£¬£¬VMware Workspace ONE AccessÖеÄÎó²îCVE-2022-22954Òѱ»ÔÚҰʹÓᣡ£¡£ ¡£¡£¡£¡£¡£VMwareÔÚÇå¾²×ÉѯÖÐÖ¸³ö £¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýЧÀÍÆ÷¶ËÄ£°å×¢Èëµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£ ¡£¡£¡£¡£¡£±¾ÖÜ £¬£¬£¬£¬£¬£¬¶à¸öÑо¿Ö°Ô±Ðû²¼Á˹ØÓÚ¸ÃÎó²îµÄÎó²îʹÓà £¬£¬£¬£¬£¬£¬ÒÔ¼°ÖÁÉÙÒ»¸öPoC¡£¡£¡£ ¡£¡£¡£¡£¡£Bad Packets¼ì²âµ½ÊÔͼʹÓøÃÎó²îµÄ»î¶¯ £¬£¬£¬£¬£¬£¬ÆäpayloadÖÐʹÓõÄIPµØµã»¹ÔÚÆäËü¹¥»÷ÖÐÓÃÀ´·Ö·¢ºóÃÅTsunami¡£¡£¡£ ¡£¡£¡£¡£¡£


https://thehackernews.com/2022/04/vmware-releases-patches-for-critical.html


4¡¢Î¢Èíǣͷ¹Ø±Õ½©Ê¬ÍøÂçZLoaderµÄÊýʮ̨C2ЧÀÍÆ÷


4ÔÂ13ÈÕ £¬£¬£¬£¬£¬£¬Î¢ÈíµÄÊý×Ö·¸·¨²¿·Ö(DCU)Ðû²¼Òѵ·»Ù½©Ê¬ÍøÂçZLoader¡£¡£¡£ ¡£¡£¡£¡£¡£´Ë´ÎÐж¯ÎªÆÚÊýÔÂÖ®¾Ã £¬£¬£¬£¬£¬£¬ÁªºÏÁËÈ«Çò¶à¼ÒµçÐÅÌṩÉ̺ÍÍøÂçÇå¾²¹«Ë¾¡£¡£¡£ ¡£¡£¡£¡£¡£Î¢Èí»ñµÃ·¨ÔºÏÂÁîºó¹Ø±ÕÁËZLoaderµÄ65¸öÓ²±àÂëÓò £¬£¬£¬£¬£¬£¬ÒÔ¼°ÁíÍâ319¸öʹÓÃÓòÌìÉúË㷨ע²áµÄÓò £¬£¬£¬£¬£¬£¬ÔÚÊÓ²ìÖл¹È·¶¨Á˸öñÒâÈí¼þµÄ¿ª·¢ÕßÖ®Ò»Denis Malikov¡£¡£¡£ ¡£¡£¡£¡£¡£ZLoaderÓÚ2015Äê8ÔÂÊ״α»·¢Ã÷ £¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹ú¡¢Öйú¡¢Î÷Å·ºÍÈÕ±¾ £¬£¬£¬£¬£¬£¬×î½ü±»Ryuk¡¢Egregor¡¢DarkSideºÍBlackMatterµÈ¶à¸öÀÕË÷ÍÅ»ïÀ´·Ö·¢payload¡£¡£¡£ ¡£¡£¡£¡£¡£


https://blogs.microsoft.com/on-the-issues/2022/04/13/zloader-botnet-disrupted-malware-ukraine/


5¡¢AethonÐÞ¸´Ó°ÏìÆäTUG»úеÈ˵ÄÎó²îJekyllBot:5


¾Ý4ÔÂ14ÈÕ±¨µÀ £¬£¬£¬£¬£¬£¬Ò½ÁÆÎïÁªÍøÇå¾²¹«Ë¾Cynerio·¢Ã÷ÁËAethon TUG»úеÈËÖеÄ5¸öÎó²î¡£¡£¡£ ¡£¡£¡£¡£¡£Aethon TUGÖÇÄÜ»úеÈËÒѱ»È«ÇòÊý°Ù¼ÒҽԺʹÓà £¬£¬£¬£¬£¬£¬ÓÃÓÚÔËËÍÒ©Æ·ºÍά»¤ÓÃÆ· £¬£¬£¬£¬£¬£¬²¢Ö´ÐмòÆÓµÄʹÃü¡£¡£¡£ ¡£¡£¡£¡£¡£ÕâЩÎó²îͳ³ÆÎªJekyllBot:5 £¬£¬£¬£¬£¬£¬»®·ÖÊÇCVE-2022-1066¡¢CVE-2022-26423¡¢CVE-2022-1070¡¢CVE-2022-1070¡¢CVE-2022-27494¡¢CVE-2022-1059¡£¡£¡£ ¡£¡£¡£¡£¡£CISA³Æ £¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓÃÕâЩÎó²î¿ÉÄܻᵼÖ¾ܾøÐ§ÀÍ״̬ £¬£¬£¬£¬£¬£¬²¢¿ÉÍêÈ«¿ØÖÆ»úеÈË»ò̻¶Ãô¸ÐÐÅÏ¢¡£¡£¡£ ¡£¡£¡£¡£¡£ÏÖÔÚ £¬£¬£¬£¬£¬£¬AethonÒÑÐû²¼¹Ì¼þ¸üÐÂÐÞ¸´ÕâЩÎó²î¡£¡£¡£ ¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/130157/security/jekyllbot5-flaws-tug-autonomous-mobile-robots.html


6¡¢FortinetÐû²¼KeksecÍÅ»ïµÄÐÂEnemybotµÄÆÊÎö±¨¸æ


4ÔÂ12ÈÕ £¬£¬£¬£¬£¬£¬FortinetÐû²¼Á˹ØÓÚKeksecÍÅ»ïʹÓõÄн©Ê¬ÍøÂçEnemybotµÄÆÊÎö±¨¸æ¡£¡£¡£ ¡£¡£¡£¡£¡£EnemybotÖ÷ÒªÔ´×ÔGafgyt £¬£¬£¬£¬£¬£¬µ«Ò²½è¼øÁËMiraiµÄ¼¸¸öÄ£¿£¿£¿£¿£¿£¿é¡£¡£¡£ ¡£¡£¡£¡£¡£Ëü¾ßÓÐ×Ö·û´®»ìÏý¹¦Ð§ £¬£¬£¬£¬£¬£¬¶øÆäC2ЧÀÍÆ÷Òþ²ØÔÚTor½ÚµãÖÐ £¬£¬£¬£¬£¬£¬ÕâʹµÃɾ³ýËü±äµÃ¼«¾ßÌôÕ½ÐÔ¡£¡£¡£ ¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÖ÷ҪʹÓõÄÎó²î°üÀ¨Seowon Intech SLC-130ºÍSLR-120S·ÓÉÆ÷ÖеÄRCE(CVE-2020-17456)¡¢D-Link DWR·ÓÉÆ÷ÖеÄRCE£¨CVE-2018-10823£©ÒÔ¼°iRZÒÆ¶¯Â·ÓÉÆ÷ÖеÄí§Òâcronjob×¢ÈëÎó²î£¨CVE-2022-27226£©¡£¡£¡£ ¡£¡£¡£¡£¡£


https://www.fortinet.com/blog/threat-research/enemybot-a-look-into-keksecs-latest-ddos-botnet