΢Èí³ÆÊý°ÙÍò¸öAndroidÉ豸ԤװµÄÀûÓôæÔÚ¶à¸ö·ì϶

°ä²¼¹¦·ò 2022-05-30

1¡¢Î¢Èí³ÆÊý°ÙÍò¸öAndroidÉ豸ԤװµÄÀûÓôæÔÚ¶à¸ö·ì϶


΢ÈíÔÚ5ÔÂ27ÈÕ°ä²¼»ã±¨³Æ £¬£¬£¬£¬£¬£¬£¬£¬ÔÚÊý°ÙÍò¸öAndroidÉ豸ԤװµÄÀûÓôæÔÚ¶à¸öÑϳÁµÄ·ì϶¡£¡£¡£¡£¡£¾ÝϤ £¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±ÔÚmce SystemsµÄÒÆ¶¯¿ò¼ÜÖз¢ÏÖÁË4¸ö·ì϶ £¬£¬£¬£¬£¬£¬£¬£¬±ðÀëΪCVE-2021-42598¡¢CVE-2021-42599¡¢ CVE-2021-42600ºÍCVE-2021-42601 £¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖºÅÁî×¢ÈëºÍÌáȨµÈ¡£¡£¡£¡£¡£Æ¾¾Ýmce SystemsµÄ˵·¨ £¬£¬£¬£¬£¬£¬£¬£¬ÆäÖв¿ÃÅ·ì϶»¹Ó°ÏìÁËAndroidºÍiOSÉ豸ÉÏµÄÆäËüÀûÓᣡ£¡£¡£¡£ÊÜÓ°ÏìÀûÓÃÔÚGoogle PlayÉϺ±¼û°ÙÍò´ÎÏÂÔØÁ¿ £¬£¬£¬£¬£¬£¬£¬£¬×÷ΪϵͳÀûÓ÷¨Ê½Ô¤×°ÔÚ´ÓAT&TºÍTELUSµÈÔËÓªÉÌ´¦²É°ìµÄÉ豸ÉÏ¡£¡£¡£¡£¡£Ä¿Ç° £¬£¬£¬£¬£¬£¬£¬£¬ÕâЩ·ì϶Òѱ»½¨¸´¡£¡£¡£¡£¡£


https://www.microsoft.com/security/blog/2022/05/27/android-apps-with-millions-of-downloads-exposed-to-high-severity-vulnerabilities/


2¡¢ÐÂAndroidľÂíERMAC 2.0Äܹ»´Ó467¸öÀûÓÃÖÐÇÔÊØÐÅÏ¢


¾ÝýÌå5ÔÂ26ÈÕ±¨Â· £¬£¬£¬£¬£¬£¬£¬£¬AndroidÒøÐÐľÂíERMACÒÑÒѳöÏÖ2.0°æ±¾ £¬£¬£¬£¬£¬£¬£¬£¬Õë¶ÔµÄÖ¸±êÀûÓÃÊýÁ¿´Ó֮ǰµÄ378¸öÔö³¤µ½467¸ö¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÖ¼ÔÚÇÔȡָ±êµÄµÇ¼ʹ´¦²¢·¢Ë͸ø¹¥»÷Õß £¬£¬£¬£¬£¬£¬£¬£¬¶øºóÀûÓÃÇÔÈ¡µÄƾ֤À´½ÚÔìÖ¸±êµÄÒøÐкͼÓÃÜÇ®±ÒÕË»§ £¬£¬£¬£¬£¬£¬£¬£¬½øÐнðÈÚ»òÆäËü´ó¾ÖµÄڲƭ¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏֵĵÚÒ»¸öÀûÓÃÁËERMAC 2.0µÄ»î¶¯ÊÇÕë¶Ô²¨À¼µÄ £¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¼ÙÒâÁËÅ·ÖÞ±íÂô·þÎñBolt Food £¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýbolt-food[.]siteÍøÕ¾·Ö·¢¶ñÒâÈí¼þ¡£¡£¡£¡£¡£ÎªÔ¤·ÀAndroidľÂíϰȾ £¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±½¨ÒéÓû§¾¡Á¿Ô¤·À´ÓPlay StoreÒÔ±íÏÂÔØAPK¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-ermac-20-android-malware-steals-accounts-wallets-from-467-apps/


3¡¢ÀÕË÷ÍÅ»ïClop¾íÍÁ³ÁÀ´ £¬£¬£¬£¬£¬£¬£¬£¬½ö½ñÄê4Ô¾ÍÒѹ¥»÷21¸öÖ¸±ê


ýÌå5ÔÂ28ÈÕ³Æ £¬£¬£¬£¬£¬£¬£¬£¬ÀÕË÷ÍÅ»ïClopÔÚÈ¥Äê11ÔÂÖÁ½ñÄê2Ô¶ÌÔݵععØÊýÔÂºó £¬£¬£¬£¬£¬£¬£¬£¬ÓÖ¾íÍÁ³ÁÀ´¡£¡£¡£¡£¡£ÔÚ¹ú¼ÊÐ̾¯×é֯Эµ÷µÄ´úºÅΪOperation CycloneµÄ·¨ÂÉÐж¯Ö®ºó £¬£¬£¬£¬£¬£¬£¬£¬Clop²¿ÃÅ»ù´¡ÉèÊ©ÓÚ2021Äê6ÔÂ¹Ø¹Ø £¬£¬£¬£¬£¬£¬£¬£¬6¸ö³ÉÔ±±»²¶¡£¡£¡£¡£¡£NCC GroupµÄÊý¾ÝÏÔʾ £¬£¬£¬£¬£¬£¬£¬£¬4Ô·ÝClopÔÚÆäÍøÕ¾ÐÂÔöÁË21¸öÒѱ»¹¥»÷µÄÖ¸±ê £¬£¬£¬£¬£¬£¬£¬£¬ÆäÖØÒªÕë¶Ô¹¤ÒµÐÐÒµ £¬£¬£¬£¬£¬£¬£¬£¬Õ¼±ÈΪ45% £¬£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊǿƼ¼¹«Ë¾£¨27%£©¡£¡£¡£¡£¡£´Ë±í £¬£¬£¬£¬£¬£¬£¬£¬Lockbit 2.0ºÍContiÊÇ4Ô·Ý×î»îÔ¾µÄÍÅ»ï £¬£¬£¬£¬£¬£¬£¬£¬±ðÀë¹¥»÷ÁË103ºÍ45¸öÖ¸±ê¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/clop-ransomware-gang-is-back-hits-21-victims-in-a-single-month/


4¡¢GitHub¹«¿ª½ü10ÍòNPMÓû§Í´´¦µÄOAuthÁîÅÆ±»µÁµÄÐÅÏ¢


GitHubÔÚ5ÔÂ26ÈÕй© £¬£¬£¬£¬£¬£¬£¬£¬4ÔÂÖÐÑ®µÄ°²È«ÊÂÎñÖÐ £¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÃHerokuºÍTravis-CIµÄ±»µÁOAuthÀûÓõÄÁîÅÆÇÔÈ¡ÁËÔ¼100000¸önpmÕÊ»§µÄµÇ¼ÐÅÏ¢¡£¡£¡£¡£¡£×Ô4ÔÂ12ÈÕÔâµ½ÒÔÀ´ £¬£¬£¬£¬£¬£¬£¬£¬GitHubÒ»ÏòÔÚµ÷²éÕâ´Î¹¥»÷¶ÔnpmµÄÓ°Ïì £¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ½üÆÚ·¢ÏÖÁËеÄÐÅÏ¢¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓñ»µÁÁîÅÆÉý¼¶¶Ônpm»ù´¡ÉèÊ©µÄ½Ó¼ûȨÏÞ £¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÔÈ¡skimdb.npmjs.comµÄÊý¾Ý¿â±¸·ÝÖнØÖÁ2021Äê4ÔÂ7ÈÕµÄÊý¾Ý£¨Ô̺¬Ô¼10ÍònpmÓû§ÐÅÏ¢£©¡¢½ØÖÁ2022Äê4ÔÂ10ÈÕËùÓÐnpm˽ÓаüµÄÒѰ䲼°æ±¾Ãû³ÆºÍ°æ±¾ºÅ(semVer)µÄ´æµµ £¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Á½¸ö×éÖ¯µÄ²¿ÃÅ˽Óаü¡£¡£¡£¡£¡£


https://github.blog/2022-05-26-npm-security-update-oauth-tokens/


5¡¢°ÂµØÀû¿Ë¶÷¶ÙÖÝÔâµ½BlackCatµÄ¹¥»÷²¢±»ÀÕË÷500ÍòÃÀÔª


¾Ý5ÔÂ27ÈÕ±¨Â· £¬£¬£¬£¬£¬£¬£¬£¬°ÂµØÀû¿Ë¶÷¶ÙÖÝ£¨Carinthia£©Ôâµ½ÁËBlackCatµÄÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¹¥»÷²úÉúÔÚÉÏÖܶþ £¬£¬£¬£¬£¬£¬£¬£¬¸ÃÖݵ±¾Ö·þÎñµÄÔËÓª²úÉúÖÐ¶Ï £¬£¬£¬£¬£¬£¬£¬£¬²¢±»ÀÕË÷500ÍòÃÀÔª¡£¡£¡£¡£¡£¾Ý³Æ £¬£¬£¬£¬£¬£¬£¬£¬Êýǧ¸ö¹¤×÷Õ¾Òѱ»¼ÓÃÜ £¬£¬£¬£¬£¬£¬£¬£¬CarinthiaµÄ¹ÙÍøºÍÓʼþ·þÎñ´¦ÓÚÀëÏß״̬ £¬£¬£¬£¬£¬£¬£¬£¬µ±¾ÖÎÞ·¨Ç©·¢»¤ÕÕ»ò´¦Öý»Í¨·£¿£¿£¿£¿£¿£¿£¿ £¿î¡£¡£¡£¡£¡£¸ÃÖݽ²»°ÈËGerd Kurath°µÊ¾ £¬£¬£¬£¬£¬£¬£¬£¬ËûÃDz»»áÂú×ã¹¥»÷ÕßµÄÒªÇó £¬£¬£¬£¬£¬£¬£¬£¬BlackCatûÓдÓËûÃǵÄϵͳÖÐÇÔÈ¡ÈκÎÊý¾Ý £¬£¬£¬£¬£¬£¬£¬£¬¶øËûÃÇÄܹ»Óñ¸·Ý¸´Ô­É豸¡£¡£¡£¡£¡£´Ë±í £¬£¬£¬£¬£¬£¬£¬£¬ÔÚÊÜÓ°ÏìµÄ3000¸öϵͳÖÐ £¬£¬£¬£¬£¬£¬£¬£¬µÚÒ»ÅúϵͳԤ¼ÆÔÚ5ÔÂ27ÈտɳÁÐÂÆôÓᣡ£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/blackcat-alphv-ransomware-asks-5-million-to-unlock-austrian-state/


6¡¢Kaspersky°ä²¼2022ÄêQ1ÍøÂçÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨


5ÔÂ27ÈÕ £¬£¬£¬£¬£¬£¬£¬£¬Kaspersky°ä²¼ÁË2022ÄêµÚÒ»¼¾¶ÈÍøÂçÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£»ã±¨¸ÅÊöÁ˼¸´ÎÓÐÕë¶ÔÐԵĹ¥»÷ £¬£¬£¬£¬£¬£¬£¬£¬±ðÀëΪ¶ñÒâÈí¼þMoonBounce¹¥»÷UEFI¹Ì¼þ¡¢APT×éÖ¯BlueNoroff³ÖÐøÑ°ÕÒ¼ÓÃÜÇ®±Ò¡¢Roaming MantisÒѽ«¹¥»÷ÁìÓòÀ©´óµ½Å·ÖÞ¡¢ÓëÎÚ¿ËÀ¼Î£»£»£»£»£»£»úÓйصÄÍøÂç¹¥»÷ £¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°LazarusʹÓÃľÂí»¯DeFiÀûÓÃÀ´·Ö·¢¶ñÒâÈí¼þ¡£¡£¡£¡£¡£´Ë±í £¬£¬£¬£¬£¬£¬£¬£¬»ã±¨»¹Ô̺¬ÆäËüµÄ¶ñÒâÈí¼þ»î¶¯ £¬£¬£¬£¬£¬£¬£¬£¬ÈçNoreboot¼Ù×°iPhone³ÁÆô¡¢ÔÚICSÍøÂçÉÏѰÕÒ¹«Ë¾Æ¾Ö¤¡¢Lapsus$×éÈëÇÖOktaºÍÍøÂç´¹µö¹¤¾ß°üÊг¡¡£¡£¡£¡£¡£


https://securelist.com/it-threat-evolution-q1-2022/106513/