ºê³ž(Acer)Ô¼160GBµÄÃô¸ÐÊý¾Ýй¶²¢ÔÚºÚ¿ÍÂÛ̳ÏúÊÛ

°ä²¼¹¦·ò 2023-03-08

1¡¢ºê³ž(Acer)Ô¼160GBµÄÃô¸ÐÊý¾Ýй¶²¢ÔÚºÚ¿ÍÂÛ̳ÏúÊÛ


¾ÝýÌå3ÔÂ6ÈÕ±¨Â·£¬ £¬£¬ £¬£¬£¬Öйų́Íå¿Æ¼¼¹«Ë¾ºê³ž(Acer Inc.)µÄ´óÁ¿Êý¾Ýй¶¡£¡£¡£¡£¡£¡£¹¥»÷ÕßKernelwareÔÚÒ»¸öÊ¢ÐеĺڿÍÂÛ̳ÉÏÏúÊÛËûÃÇÐû³ÆÔÚ2023Äê2ÔÂÖÐÑ®´ÓAcerÇÔÈ¡µÄ160GBÊý¾Ý¡£¡£¡£¡£¡£¡£¹¥»÷Õßй©±»µÁÊý¾ÝÔ̺¬¼¼ÊõÊֲᡢÈí¼þ¹¤¾ß¡¢ºó¶Ë»ù´¡ÉèÊ©¾ßÌåÐÅÏ¢¡¢BIOSÓ³Ïñ¡¢ROMÎļþ¡¢ISOÎļþºÍ´úÌæÊý×Ö²úÆ·ÃÜÔ¿(RDPK)µÈ¡£¡£¡£¡£¡£¡£×÷Ϊ¹¥»÷Ö¤¾Ý£¬ £¬£¬ £¬£¬£¬¹¥»÷Õß¹«¿ªÁËAcer V206HQLÏÔʾÆÁµÄ¼¼ÊõʾÒâͼ¡¢Îĵµ¡¢BIOS½ç˵ºÍ»úÃÜÎĵµµÄÆÁÄ»½ØÍ¼¡£¡£¡£¡£¡£¡£AcerÈ·ÈÏÆä¹©Î¬½¨¼¼ÊõÈËԱʹÓõÄÎļþ·þÎñÆ÷±»ÈëÇÖ£¬ £¬£¬ £¬£¬£¬µ«Êǿͻ§Êý¾Ý²¢Î´ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£


https://www.hackread.com/acer-data-breach-hacker-sell-data/


2¡¢Google°ä²¼3Ô·ÝAndroid¸üУ¬ £¬£¬ £¬£¬£¬×ܼƽ¨¸´60¸ö·ì϶


¾Ý3ÔÂ7ÈÕ±¨Â·£¬ £¬£¬ £¬£¬£¬Google°ä²¼ÁË2023Äê3ÔµÄAndroid°²È«¸üУ¬ £¬£¬ £¬£¬£¬¹²½¨¸´ÁË60¸ö·ì϶£¬ £¬£¬ £¬£¬£¬Ô̺¬Á½¸öÑϳÁµÄRCE·ì϶¡£¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ·ì϶ͨ¹ýÁ½¸ö¶ÀÁ¢µÄ°²È«²¹¶¡°ä²¼£¬ £¬£¬ £¬£¬£¬¼´2023-03-01ºÍ2023-03-05¡£¡£¡£¡£¡£¡£Á½¸öRCE·ì϶±ðÀëΪCVE-2023-20951ºÍCVE-2023-20954£¬ £¬£¬ £¬£¬£¬GoogleÒѰµ²Ø¹ØÓÚËüÃǵÄËùÓÐÐÅÏ¢£¬ £¬£¬ £¬£¬£¬ÒÔÔ¤·À¹¥»÷ÕßÔÚÓû§ÀûÓøüÐÂ֮ǰ½øÐй¥»÷¡£¡£¡£¡£¡£¡£±¾Ô½¨¸´µÄ×îÑϳÁµÄ·ì϶ÊǹØÔ´Qualcomm×é¼þÖеÄCVE-2022-33213ºÍCVE-2022-33256¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/android-march-2023-update-fixes-two-critical-code-execution-flaws/


3¡¢Î÷°àÑÀ°ÍÈûÂÞÄÇÕïËùÒ½ÔºÔâµ½Ransom HouseÀÕË÷¹¥»÷


ýÌå3ÔÂ6Èճƣ¬ £¬£¬ £¬£¬£¬Î÷°àÑÀ°ÍÈûÂÞÄÇÕïËùÒ½Ôº(Hospital Clinic de Barcelona) Ôâµ½¹¥»÷¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷µ¼Ö¸ÃÖÐÐĵÄÍÆËã»úϵͳ崻ú£¬ £¬£¬ £¬£¬£¬150Ïî·Ç´¹Î£ÊÖÊõºÍ¶à´ï3000ÏÕ߲鳭±»È¡µÞ£¬ £¬£¬ £¬£¬£¬Ò½ÔºÔÚ½«ÐµĴ¹Î£²¡Àý×ªÒÆµ½ÊÐÄÚÆäËûÒ½Ôº¡£¡£¡£¡£¡£¡£±¾µØÒ»¼Ò°²È«»ú¹¹Ð¹Â©£¬ £¬£¬ £¬£¬£¬Õâ´Î¹¥»÷À´×ÔÀÕË÷ÍÅ»ïRansom House£¬ £¬£¬ £¬£¬£¬ÀÕË÷Èí¼þϰȾÁËÒ½Ôº³¢ÊÔÊÒ¡¢¼¹ØïÊÒºÍÈý¸öÖØÒªÖÐÐĵÄÒ©·¿ÒÔ¼°¼¸¸ö±í²¿ÕïËùµÄÍÆËã»ú¡£¡£¡£¡£¡£¡£Ä¿Ç°Éв»Ã÷ÏÔϵͳºÎʱ¿É¸´Ô­Õý³£¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/143121/cyber-crime/hospital-clinic-de-barcelona-ransomware.html


4¡¢µÂ¹úºÍÎÚ¿ËÀ¼·¨Âɲ¿ÃÅ¿ÛÁôDoppelPaymerµÄÖ÷Ìâ³ÉÔ±


3ÔÂ6ÈÕ±¨Â·£¬ £¬£¬ £¬£¬£¬Å·ÖÞÐ̾¯×éÖ¯°ä·¢£¬ £¬£¬ £¬£¬£¬µÂ¹úºÍÎÚ¿ËÀ¼µÄ·¨Âɲ¿ÃÅ¿ÛÁôÁËÀÕË÷ÍÅ»ïDoppelPaymerµÄÁ½ÃûÖ÷Ìâ³ÉÔ±¡£¡£¡£¡£¡£¡£¿ÛÁôÐж¯²úÉúÔÚ2023Äê2ÔÂ28ÈÕ£¬ £¬£¬ £¬£¬£¬Í»»÷ËѲéÁËÒ»ÃûµÂ¹ú¹úÃñµÄ·¿ÎÝ£¬ £¬£¬ £¬£¬£¬²¢ÔÚÎÚ¿ËÀ¼³ÇÊлù¸¨ºÍ¹þ¶û¿Æ·ò½øÐÐÁË¿í·ºËѲ顣¡£¡£¡£¡£¡£µÂ¹úµ±¾ÖÒÔΪ£¬ £¬£¬ £¬£¬£¬DoppelPaymer»î¶¯Éæ¼°5¸öÖ÷Ìâ³ÉÔ±£¬ £¬£¬ £¬£¬£¬ËûÃÇÊØ»¤¹¥»÷»ù´¡ÉèÊ©¡¢Êý¾ÝÐ¹Â¶ÍøÕ¾¡¢´¦Öý»Éæ²¢½«·Ö·¢¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£·¨Âɲ¿ÃÅĿǰÒÑ·¢³ö¿ÛÁôÁ £¬£¬ £¬£¬£¬ÔÚÈ«ÇòÁìÓòÄÚͨ¼©Áí±í3ÃûÏÓÒÉÈË¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/core-doppelpaymer-ransomware-gang-members-targeted-in-europol-operation/


5¡¢SentinelOnÅû¶ÀûÓÃRemcos RATÕë¶Ô¶«Å·µÄ´¹µö»î¶¯


3ÔÂ6ÈÕ£¬ £¬£¬ £¬£¬£¬SentinelOnÅû¶ÁËÀûÓÃDBatLoader¼ÓÔØ·¨Ê½·Ö·¢Remcos RATµÄ´¹µö»î¶¯£¬ £¬£¬ £¬£¬£¬ÖØÒªÕë¶Ô¶«Å·»ú¹¹ºÍÆóÒµ¡£¡£¡£¡£¡£¡£¹¥»÷ʼÓÚÔ̺¬¼Ù·¢Æ±ºÍÕбêÎļþµÄ´¹µöÓʼþ£¬ £¬£¬ £¬£¬£¬Ô̺¬DBatLoader¿ÉÖ´ÐÐÎļþµÄtar.lz´æµµ¡£¡£¡£¡£¡£¡£µÚÒ»½×¶Îpayload¼Ù×°³ÉOffice¡¢LibreOffice»òPDFÎĵµ£¬ £¬£¬ £¬£¬£¬Æô¶¯ºó»á´Ó¹«¹²ÔÆ·þÎñÖлñÈ¡µÚ¶þ½×¶Îpayload¡£¡£¡£¡£¡£¡£¼ÓÔØRemcos RAT֮ǰ£¬ £¬£¬ £¬£¬£¬DBatLoader´´½¨²¢Ö´ÐÐWindowsÅú´¦Öþ籾£¬ £¬£¬ £¬£¬£¬ÒÔÀûÓÃ2020Äê¼Í¼µÄWindows UACÈÆ¹ý²½Öè¡£¡£¡£¡£¡£¡£×îÖÕ£¬ £¬£¬ £¬£¬£¬Í¨¹ý¹ý³Ì×¢ÈëµÄ·½Ê½Ö´ÐÐRemcos¡£¡£¡£¡£¡£¡£


https://www.sentinelone.com/blog/dbatloader-and-remcos-rat-sweep-eastern-europe/


6¡¢Kaspersky°ä²¼2022ÄêH2¹¤Òµ×Ô¶¯»¯ÏµÍ³ÍþÐ²Ì¬ÊÆµÄ»ã±¨


3ÔÂ6ÈÕ£¬ £¬£¬ £¬£¬£¬Kaspersky°ä²¼2022ÄêH2¹¤Òµ×Ô¶¯»¯ÏµÍ³ÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬ £¬£¬ £¬£¬£¬È«ÇòÊܵ½¹¥»÷µÄICSÍÆËã»úµÄ°Ù·Ö±ÈΪ34.3%£¬ £¬£¬ £¬£¬£¬ÂÔ¸ßÓÚ2022ÉϰëÄ꣨31.8%£©¡£¡£¡£¡£¡£¡£ÖØÒªÍþвÆðÔ´ÊÇ»¥ÁªÍø£¨19.9%£©¡¢µç×ÓÓʼþ¿Í»§¶Ë£¨6.4% £©ºÍ¿Éж³ýµÄÉ豸£¨3.8%£©¡£¡£¡£¡£¡£¡£Êܵ½´ËÀ๥»÷×î¶àµÄµØÓòΪ·ÇÖÞºÍÖÐÑÇ£¬ £¬£¬ £¬£¬£¬Õ¼±È40.1%¡£¡£¡£¡£¡£¡£Î÷Å·ºÍ±±Å·ÊÇ×ȫµÄµØÓò£¬ £¬£¬ £¬£¬£¬±ðÀëΪ14.2%ºÍ14.3%¡£¡£¡£¡£¡£¡£KasperskyÔÚ2022ϰëÄêÔÚ¹¤Òµ×Ô¶¯»¯ÏµÍ³Éϼì²âµ½À´×Ô7684¸ö·ÖÆç¼Ò×åµÄ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£   

 

https://securelist.com/threat-landscape-for-industrial-automation-systems-for-h2-2022/108958/