AdobeÐÞ¸´Òѱ»ÀûÓõÄÊäÈëÑéÖ¤²»Íש¶´CVE-2022-24086

Ðû²¼Ê±¼ä 2022-02-16

AdobeÐÞ¸´Òѱ»ÀûÓõÄÊäÈëÑéÖ¤²»Íש¶´CVE-2022-24086


2ÔÂ13ÈÕ £¬AdobeÐû²¼½ô¼±¸üР£¬ÐÞ¸´Æä²úÎïCommerceºÍMagento Open SourceÖеÄ©¶´ ¡£ÕâÊÇÒ»¸öÊäÈëÑé֤©¶´ £¬×·×ÙΪCVE-2022-24086 £¬CVSSµÃ·ÖΪ9.8 ¡ £¿ÉÒÔ±»ÎäÆ÷»¯À´ÊµÏÖÈÎÒâ´úÂëÖ´ÐÐ £¬¾Ý³Æ¸Ã©¶´ÕýÔÚ±»¹ã·ºÀûÓà ¡£¸Ã©¶´Ó°ÏìÁËAdobe CommerceºÍMagento Open Source 2.4.3-p1¼°¸üÔç°æ±¾ £¬ÒÔ¼°2.3.7-p2¼°¸üÔç°æ±¾ ¡£


https://thehackernews.com/2022/02/critical-magento-0-day-vulnerability.html


¼ÓÖݵĴóѧOCCDÔâµ½ÀÕË÷¹¥»÷µ¼Ö·þÎñÖжÏÊ®¶àÌì


¾ÝýÌå2ÔÂ10ÈÕ±¨µÀ £¬¼ÓÖݵĴóѧOhlone Community College District(OCCD)ÒòÀÕË÷¹¥»÷·þÎñÖжÏÊ®¶àÌì ¡£¹¥»÷·¢ÉúÔÚ1ÔÂ20ÈÕ £¬µ¼ÖÂÔÚÏßѧÉúÍøÕ¾¹Ø±ÕÁË17Ìì £¬°Â¡ѧԺµÄµç»°Í¨ÐźÍÓʼþϵͳ¹Ø±ÕÁË10Ìì ¡£´ËÍâ £¬²¿ÃŽÌÖ°Ô±¹¤ºÍѧÉúµÄÐÅϢй¶ £¬Éæ¼°Éç»áÄþ¾²ºÅÂë¡¢¼ÝʻִÕÕºÅÂë¡¢ÒøÐÐÕË»§ÏêϸÐÅÏ¢¡¢Ñ§ÉúÖ¤ºÅÂë¡¢¿Î³Ì²¿ÊðºÍ½á¹ûµ¥µÈÐÅÏ¢ ¡£


https://www.infosecurity-magazine.com/news/californian-college-ransomware/


Uptycs·¢ÏÖÀûÓÃregsvr32·Ö·¢QbotºÍLokibotµÄ»î¶¯


UptycsÔÚ2ÔÂ9ÈÕÅû¶ÀûÓÃSquumbledoo¼¼Êõ·Ö·¢QbotºÍLokibotµÄ»î¶¯µÄϸ½Ú ¡£Squibldoo¼¼Êõ×Ô2017ÄêÒÔÀ´Ò»Ö±±»ÓÃÓÚ¶ñÒâÈí¼þ·Ö·¢»î¶¯ £¬Í¨¹ýʹÓÃregsvr32¼ÓÔØCOM½ÅÔ­À´Ö´ÐÐDLL ¡£´ËÒªÁì²»»á¸ü¸Ä×¢²á±í £¬¿ÉÓÃÀ´ÈƹýÓ¦Ó÷¨Ê½°×Ãûµ¥ ¡£Uptycs½üÆÚ¼ì²âµ½500¶à¸öʹÓÃregsvr32.exe×¢²á.ocxÎļþµÄÑù±¾ £¬ÆäÖÐ97%ÊôÓÚ¶ñÒâMicrosoft OfficeÎĵµ £¬Ö÷ÒªÊÇExcelÎļþ ¡£


https://www.bleepingcomputer.com/news/security/qbot-lokibot-malware-switch-back-to-windows-regsvr32-delivery/


KasperskyÐû²¼2021ÄêQ4 DDoS¹¥»÷µÄ·ÖÎö³ÂËß


KasperskyÔÚ2ÔÂ10ÈÕÐû²¼ÁË2021ÄêQ4 DDoS¹¥»÷µÄ·ÖÎö³ÂËß ¡£³ÂËßÖ¸³ö £¬ÔÚÕâÒ»¼¾¶ÈDDoS¹¥»÷ÊýÁ¿ÏÔÖøÔö³¤ £¬±ÈÉÏÒ»¼¾¶ÈÔö¼ÓÁË52% £¬±ÈÈ¥ÄêͬÆÚÔö¼ÓÁË4.5±¶ÒÔÉÏ £¬´´ÏÂÀúʷиß ¡£´ËÍâ £¬ÔÚµÚËļ¾¶È»¹·ºÆðÁ˼¸¸öÐ嵀 DDoS½©Ê¬ÍøÂç £¬°üÂÞAbcbotºÍEwDoorµÈ£»±¬³öÁ˺ųƽñÄê×îΣÏյĩ¶´Log4Shell £¬Mirai¡¢MuhstikºÍElknotµÈ½©Ê¬ÍøÂçÕýÊÔͼÀûÓôË©¶´£»Õë¶ÔVoIPÌṩÉ̵ÄDDoS¹¥»÷ÈÔÔÚ¼ÌÐø ¡£


https://securelist.com/ddos-attacks-in-q4-2021/105784/


ChainalysisÐû²¼2021ÄêÀÕË÷¹¥»÷»î¶¯µÄͳ¼Æ³ÂËß


2ÔÂ10ÈÕ £¬Çø¿éÁ´·ÖÎö¹«Ë¾ChainalysisÐû²¼Á˹ØÓÚ2021ÄêÀÕË÷¹¥»÷»î¶¯µÄͳ¼Æ³ÂËß ¡£³ÂËßÖ¸³ö £¬2021ÄêÔâµ½ÀÕË÷¹¥»÷µÄ×éÖ¯×ܼÆÖ§¸¶ÁË6.02ÒÚÃÀÔªµÄÊê½ð £¬ÓëÈ¥Ä꣨6.92ÒÚÃÀÔª£©Ïà±ÈÂÔÓÐϽµ ¡£ÆäÖÐContiµÄÕ¼±È×î´ó £¬ÊÕµ½ÁËÖÁÉÙ1.8ÒÚÃÀÔªÊê½ð ¡£Æ½¾ùÊê½ð½ð¶îÒ²ÓÐËùÔö¼Ó £¬2019ÄêΪ25000ÃÀÔª £¬2020Äêµ½´ï88000ÃÀÔª £¬¶ø2021ÄêÁè¼ÝÁË118000ÃÀÔª£»ÀÕË÷Èí¼þÊýÁ¿´Ó2019ÄêµÄ79ÖÖÔö³¤µ½2020ÄêµÄ119ÖÖ £¬²¢ÔÚ2021ÄêÔö³¤µ½140ÖÖ ¡£


https://blog.chainalysis.com/reports/2022-crypto-crime-report-preview-ransomware/


FBI³ÆBlackByteÒÑÈëÇÖÃÀ¹ú¶à¸öÒªº¦»ù´¡ÉèÊ©µÄ×éÖ¯


ýÌå2ÔÂ14ÈÕ±¨µÀ £¬ÃÀ¹úFBIºÍÌØÇÚ¾Ö(USSS)Ðû²¼ÁËÒ»·Ý¹ØÓÚBlackByteµÄÁªºÏÍøÂçÄþ¾²×ÊѶ ¡£¸Ã×ÊѶָ³ö £¬½ØÖÁ2021Äê11Ô £¬ÀÕË÷ÍÅ»ïBlackByteÒѾ­¹¥»÷ÁËÃÀ¹úµÄ¶à¸ö¹«Ë¾ £¬°üÂÞÖÁÉÙ3¸öÉæ¼°Òªº¦»ù´¡ÉèÊ©£¨Õþ¸®¡¢½ðÈÚÒÔ¼°Ê³Æ·ºÍũҵ£©µÄ×éÖ¯ ¡£BlackByteÊÇÒ»¸öRaaSÍÅ»ï £¬¸Ãͨ¸æµÄÖØµãÊÇÌṩÓÃÀ´¼ì²âºÍ·ÀÓùBlackByte¹¥»÷µÄIOC £¬»¹Ìá³öÁË¿ÉÒÔ×ÊÖú¹ÜÀíÔ±µÖÓùBlackByte¹¥»÷µÄ´ëÊ© ¡£


https://securityaffairs.co/wordpress/128013/malware/blackbyte-ransomware-breached-at-least-3-us-critical-infrastructure-organizations.html


Äþ¾²¹¤¾ß


modifyCertTemplate


Ö¼ÔÚ×ÊÖú²Ù×÷Ô±ÐÞ¸Ä ADCS Ö¤ÊéÄ£°å £¬ÒÔ±ã¿ÉÒÔÀûÓô´½¨µÄÒ×Êܹ¥»÷״̬½øÐÐȨÏÞÌáÉý ¡£


https://github.com/fortalice/modifyCertTemplate


Shhhloader 


ÊÇÒ»¸ö SysWhispers Shellcode ¼ÓÔØÆ÷ ¡£


https://github.com/icyguider/Shhhloader


RISKEN


Ò»¸öÄþ¾²²Ù×÷ƽ̨ £¬ÓÃÓÚÁ¬ÐøÊÕ¼¯ºÍ¼à¿ØÒþ²ØÔÚϵͳ»·¾³ÖеķçÏÕÐÅÏ¢ ¡£


https://docs.security-hub.jp/


Exrop 


×Ô¶¯ ROP Á´Éú³ÉÆ÷¹¤¾ß £¬Ëü¿ÉÒÔ´Ó¸ø¶¨µÄ¶þ½øÖÆÎļþºÍÔ¼Êø×Ô¶¯¹¹½¨Ð¡¹¤¾ßÁ´ ¡£


https://github.com/d4em0n/exrop


Get-RBCD-Threaded


ÔÚ Active Directory »·¾³Öз¢ÏÖ»ùÓÚ×ÊÔ´µÄÔ¼Êø¹¥»÷·¾¶µÄ¹¤¾ß ¡£


https://github.com/FatRodzianko/Get-RBCD-Threaded



Äþ¾²·ÖÎö


΢Èí³Æ¶à¸ö Visual Studio °æ±¾¼´½«¼´½«ÖÕÖ¹Ö§³Ö


https://news.softpedia.com/news/microsoft-warns-of-approaching-eol-for-several-visual-studio-versions-534867.shtml


΢ÈíÕýÔÚ¼Ó´ó´ÓÄÚ´æÖÐÇÔÈ¡ Windows ÃÜÂëµÄÄѶÈ


https://www.bleepingcomputer.com/news/microsoft/microsoft-is-making-it-harder-to-steal-windows-passwords-from-memory/


MOXA MXVIEW´æÔÚ¶à¸ö©¶´


https://www.claroty.com/2022/02/10/blog-research-securing-network-management-systems-moxa-mxview/


Twitter Òò¡°³öÁ˵ãÎÊÌ⡱¶øÖжÏ


https://www.bleepingcomputer.com/news/technology/twitter-is-down-with-something-went-wrong-errors/