Apple°ä²¼¸üУ¬£¬ £¬£¬£¬½¨¸´AppleAVDÖÐÒѱ»ÀûÓõķì϶

°ä²¼¹¦·ò 2022-05-17
1¡¢Apple°ä²¼¸üУ¬£¬ £¬£¬£¬½¨¸´AppleAVDÖÐÒѱ»ÀûÓõķì϶


5ÔÂ16ÈÕ£¬£¬ £¬£¬£¬Apple°ä²¼´¹Î£¸üУ¬£¬ £¬£¬£¬½¨¸´Ó°ÏìÁËMacºÍApple WatchµÄ0 day¡£¡£¡£¡£¡£¡£¡£ÕâÊÇ´æÔÚÓÚAppleAVDÖеÄÔ½½çдÈë·ì϶£¨CVE-2022-22675£©£¬£¬ £¬£¬£¬¿É±»ÓÃÀ´Ê¹ÓÃÄÚºËȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£AppleµÄ²¼¸æ°µÊ¾£¬£¬ £¬£¬£¬¸Ã·ì϶¿ÉÄÜÒѱ»»ý¼«ÀûÓ㬣¬ £¬£¬£¬ÒѾ­Í¨¹ý¸Ä½øÌìǵ²é³­À´½¨¸´¡£¡£¡£¡£¡£¡£¡£ÕâÊÇApple¹«Ë¾ÔÚ2022Ä꽨¸´µÄµÚ6¸ö0 day£¬£¬ £¬£¬£¬Ö®Ç°»¹½¨¸´ÁËCVE-2022-22587¡¢CVE-2022-22594ºÍCVE-2022-22620µÈ·ì϶¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/131346/security/apple-sixth-zero-day-2022.html


2¡¢×êÑÐÈËÔ±·¢ÏÖLinuxºóÃÅBPFdoor¿ÉÈÆ¹ý±¾µØ·À»ðǽ


¾ÝýÌå5ÔÂ12ÈÕ±¨Â·£¬£¬ £¬£¬£¬×êÑÐÈËÔ±ÔÚ½üÆÚ·¢ÏÖÁËÒ»ÖÖÃûΪBPFdoorµÄLinux/Unix ºóÃÅ£¬£¬ £¬£¬£¬ÎåÄê¶àÀ´Ò»ÏòûÓб»·¢ÏÖ¡£¡£¡£¡£¡£¡£¡£¸ÃºóÃÅÖØÒªÕë¶ÔLinuxºÍSolarisϵͳ£¬£¬ £¬£¬£¬¹¥»÷ÕßÀûÓÃÆäÄܹ»Èƹý±¾µØ·À»ðǽ£¬£¬ £¬£¬£¬Ô¶³ÌÏνӵ½Linux shellÒÔ»ñµÃ¶ÔÖ¸±êÉ豸µÄÆëÈ«½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÔÚÃÀ¹ú¡¢º«¹ú¡¢ÖйúÏã¸Û¡¢ÍÁ¶úÆä¡¢Ó¡¶È¡¢Ô½ÄϺÍÃåµéµÈµØÓò·¢ÏÖÁËBPFdoorµÄ»î¶¯£¬£¬ £¬£¬£¬²¢¼ì²âµ½ÁË11̨Speedtest·þÎñÆ÷ÒÑϰȾBPFdoor£¬£¬ £¬£¬£¬Éв»Ã÷ÏÔËüÃÇÊÇÈôºÎ±»ÈëÇֵġ£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/bpfdoor-stealthy-linux-malware-bypasses-firewalls-for-remote-access/    


3¡¢Fortinet·¢ÏÖÒÁÀÊAPT34Õë¶ÔÔ¼µ©µÄ´¹µö¹¥»÷»î¶¯


FortinetÔÚ5ÔÂ11ÈÕÅû¶ÁËÒÁÀÊAPT34£¨ÓÖ³ÆOilrig£©½üÆÚµÄÓã²æÊ½´¹µö»î¶¯µÄÏêÇé¡£¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯ÖØÒªÕë¶ÔÔ¼µ©µÄ±í½»¹ÙÔ±£¬£¬ £¬£¬£¬¼Ù×°³Éͳһ»ú¹¹µÄIT²¿ÃŵÄͬÊ·¢ËÍ´¹µöÓʼþ¡£¡£¡£¡£¡£¡£¡£ÓʼþÖеĶñÒâExcel¸½¼þÖÐÔ̺¬VBAºê´úÂ룬£¬ £¬£¬£¬Ö¼ÔÚ´´½¨Ò»¸ö¶ñÒâ¿ÉÖ´ÐÐÎļþ¡¢Ò»¸öÅäÖÃÎļþºÍÒ»¸öÊðÃûÇҸɾ»µÄDLL¡£¡£¡£¡£¡£¡£¡£¶ñÒâÈí¼þʹÓÃDGA¹¤¾ßÓëC2×ÓÓò½øÐÐͨѶ£¬£¬ £¬£¬£¬ÇһÖÐʹÓõÄһЩÓòÊÔͼ¼Ù×°³É°¢Ë¹Àû¿µ¡¢»ã·áÒøÐкÍ˼¿ÆµÈ³ÛÃû¹«Ë¾¡£¡£¡£¡£¡£¡£¡£


https://www.fortinet.com/blog/threat-research/please-confirm-you-received-our-apt


4¡¢¼ÙðµÄPixelmon NFTÍøÕ¾»á·Ö·¢Ð¶ñÒâÈí¼þVidar


ýÌå5ÔÂ15Èճƣ¬£¬ £¬£¬£¬Ò»¸ö¼ÙðµÄPixelmon NFTÍøÕ¾»á·Ö·¢ÇÔȡʹ´¦µÄжñÒâÈí¼þVidar¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õ߸´ÔìÁ˺Ϸ¨µÄpixelmon.clubÍøÕ¾£¬£¬ £¬£¬£¬²¢ÔÚpixelmon[.]pwÉÏ´´½¨ÁËαÔìµÄÍøÕ¾¡£¡£¡£¡£¡£¡£¡£¸ÃÍøÕ¾»á·Ö·¢Îļþsetup.zip£¬£¬ £¬£¬£¬ÆäÖÐÔ̺¬Ò»¸öWindows¿ì½Ý·½Ê½Îļþsetup.lnk£¬£¬ £¬£¬£¬Ëü½«Ö´ÐÐPowerShellºÅÁîÒÔ´Ópixelmon[.]pwÏÂÔØsystem32.hta¡£¡£¡£¡£¡£¡£¡£¾­¹ý²âÊÔ£¬£¬ £¬£¬£¬System32.hta»áÏÂÔØVidar¡£¡£¡£¡£¡£¡£¡£Vidar»á´Óä¯ÀÀÆ÷ºÍÀûÓ÷¨Ê½ÖÐÇÔÈ¡ÃÜÂ룬£¬ £¬£¬£¬²¢ÔÚÍÆËã»úÉÏËÑË÷ÌØ¶¨Ãû³ÆµÄÎļþ£¬£¬ £¬£¬£¬·¢Ë͸ø¹¥»÷Õß¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/fake-pixelmon-nft-site-infects-you-with-password-stealing-malware/


5¡¢¶íÂÞ˹¶à¸ö×éÖ¯µÄÐÅÏ¢Êý¾ÝÒѱ»¹«¿ªÔÚDDoSecrets


¾Ý5ÔÂ14ÈÕ±¨Â·£¬£¬ £¬£¬£¬AnonymousÌáÒéµÄOpRussia»î¶¯ÔÚ½üÒ»ÖÜÓÖÈëÇÖÁ˶íÂÞ˹µÄ¶à¸ö×éÖ¯¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýDDoSecrets¹«¿ªÁ˱»µÁÊý¾Ý£¬£¬ £¬£¬£¬ÆäÖÐÔ̺¬£ºSOCAR EnergoresourceµÄ130 GB£¬£¬ £¬£¬£¬Ô̺¬½ü116500·âÓʼþ£»£»£»£»£»°¢ÇÕ˹¿ËÊе±¾ÖµÄ8.5 GB£¬£¬ £¬£¬£¬Ô̺¬7000¶à·âÓʼþ£»£»£»£»£»¶íÂÞ˹Áª¹úÓæÒµºÍº£Ñó×êÑÐËù¼«µØ·Ö²¿466 GBµÄÓʼþ£»£»£»£»£»JSC UMMCµÄ¸Û¿ÚºÍÌú·ÏîÄ¿·þÎñµÄ106 GB£¬£¬ £¬£¬£¬ÆäÖÐÔ̺¬½ü77500·âÓʼþ¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/131264/hacktivism/anonymous-oprussia-updates.html


6¡¢Cyble°ä²¼¹ØÓÚ¶ñÒâÈí¼þ¹¤¾ß°üEternityµÄ·ÖÎö»ã±¨


5ÔÂ12ÈÕ£¬£¬ £¬£¬£¬Cyble°ä²¼Á˹ØÓÚ¶ñÒâÈí¼þ¹¤¾ß°üEternityµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£ÕâÊÇÒ»¸öеĶñÒâÈí¼þ¼´·þÎñ£¨MaaS£©£¬£¬ £¬£¬£¬¿ÉÓÃÀ´Æ¾¾ÝËù½øÐеĹ¥»÷ʹÓÃ·ÖÆçµÄÄ£¿£¿£¿£¿£¿£¿£¿£¿é½øÐж¨Ô죬£¬ £¬£¬£¬Ô̺¬ÐÅÏ¢ÇÔÈ¡·¨Ê½¡¢ÍÚ¿óÈí¼þ¡¢clipper¡¢ÀÕË÷Èí¼þ¡¢È䳿ÒÔ¼°DDoS bot¡£¡£¡£¡£¡£¡£¡£ÆäÖÐÊÛ¼Û260ÃÀÔªÒ»ÄêµÄÐÅÏ¢ÇÔÈ¡Èí¼þ¿ÉÇÔÈ¡20¶à¸öä¯ÀÀÆ÷ÖеÄÊý¾Ý£»£»£»£»£»×î°º¹óµÄÊÇ490ÃÀÔªEternityÀÕË÷Èí¼þÄ£¿£¿£¿£¿£¿£¿£¿£¿é£¬£¬ £¬£¬£¬¾Ý³ÆÊÇFUD£¨ÆëÈ«ÎÞ·¨¼ì²âµ½£©µÄ¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾£¬£¬ £¬£¬£¬ÒѾ­ÔÚÒ°¼ì²âµ½¸Ã¶ñÒâÈí¼þµÄÑù±¾µÄ´«²¼ºÍʹÓᣡ£¡£¡£¡£¡£¡£


https://blog.cyble.com/2022/05/12/a-closer-look-at-eternity-malware/