FacebookͬÒâÖ§¸¶9ǧÍòÃÀÔª½â¾ö³¤´ï10ÄêµÄÇÖ·¸Òþ˽°¸

Ðû²¼Ê±¼ä 2022-02-18

FacebookͬÒâÖ§¸¶9ǧÍòÃÀÔª½â¾ö³¤´ï10ÄêµÄÇÖ·¸Òþ˽°¸


¾ÝýÌå2ÔÂ15ÈÕ±¨µÀ £¬Meta PlatformsÒÑͬÒâÖ§¸¶9000ÍòÃÀÔª £¬ÒÔ½â¾ö¸Ã¹«Ë¾Ê¹ÓÃcookieÀ´¸ú×ÙFacebookÓû§»¥ÁªÍø»î¶¯µÄËßËÏ¡£ÕâÆð°¸¼þ³¤´ïÊ®ÄêÖ®¾Ã £¬ÔÚ2012Äê±»Ìá³ö £¬Ö÷ÒªÎ§ÈÆFacebookʹÓÃרÓеġ°Like¡±°´¼üÀ´¸ú×ÙÓû§·ÃÎʵÚÈý·½ÍøÕ¾Ê± £¬Î¥·´ÁËÇÔÌý·¨¡£¾Ý³Æ £¬ËûÃÇ»¹½«ÕâЩä¯ÀÀ¼Ç¼±à¼­³É¸öÈË×ÊÁÏ £¬²¢³öÊÛ¸ø¹ã¸æÉÌ¡£Ò»Äêǰ £¬MetaÔøÒòÎ¥·´ÁËÒÁÀûŵÒÁÖÝÉúÎïʶ±ðÐÅÏ¢Òþ˽·¨(BIPA) £¬±»ÀÕÁîÖ§¸¶6.5ÒÚÃÀÔª¡£


https://thehackernews.com/2022/02/facebook-agrees-to-pay-90-million-to.html


»¥ÁªÍøÐ­»áISOCµÄ´æ´¢¿âÅäÖôíÎóÊýÍòÓû§µÄÐÅϢй¶


ClarioÑо¿ÈËÔ±ÔÚ2ÔÂ15ÈÕÖ¸³ö £¬¹ú¼Ê»¥ÁªÍøÐ­»áISOCÊýÍòÓû§µÄÐÅϢй¶¡£Clario³ÆËûÃÇÓÚ2021Äê12ÔÂ8ÈÕ·¢ÏÖÒ»¸öδÊܱ£»¤µÄMicrosoft Azure blob´æ´¢¿â £¬¸Ã´æ´¢¿â°üÂÞÊý°ÙÍò¸öÎļþ £¬Éæ¼°ISOC³ÉÔ±µÄÐÕÃû¡¢×¡Ö·¡¢ÓʼþµØÖ·¡¢ÐԱ𡢵ǼÏêϸÐÅÏ¢ºÍÃÜÂëµÈ¡£12ÔÂ15ÈÕ £¬ISOCÌåÏÖ¸ÃʼþÊÇÓÉÓÚÆä¹ÜÀíϵͳÌṩÉÌÅäÖôíÎóµ¼Ö嵀 £¬ÇÒÊӲ췢ÏÖ²¢Î´ÓÐÈκÎÊý¾Ý±»¶ñÒâ·ÃÎÊ¡£


https://www.infosecurity-magazine.com/news/internet-society-data-leaked/


BlackCat³ÆÆäÒÑÈëÇÖSwissport²¢ÇÔÈ¡1.6TBµÄÊý¾Ý


¾Ý2ÔÂ15ÈÕ±¨µÀ £¬BlackCatÉù³Æ¶ÔSwissportµÄ¹¥»÷ÂôÁ¦¡£¾ÝµÂ¹úýÌåSpiegel³Æ £¬¹¥»÷·¢ÉúÔÚ2ÔÂ3ÈÕÔçÉÏ6µã £¬Æäʱµ¼Ö¶à¼Üº½°àÑÓÎó £¬¶ÔÆäÔËÓª·¢ÉúÁËÑÏÖØÓ°Ïì¡£BlackCatÒѹûÈ»ÔÚÀÕË÷¹¥»÷ÆÚ¼äÇÔÈ¡µÄÊý¾ÝÑù±¾ £¬²¢ÌåÏÖÓÐ1.6TBµÄÊý¾Ý¿É¹©³öÊÛ¡£Ð¹Â¶Êý¾Ý°üÂÞÉÌÒµÎļþ¡¢ÄÉ˰É걨µ¥¡¢»¤ÕÕ¡¢¸öÈËÉí·ÝÖ¤¡¢ÓʼþµØÖ·ºÍµç»°ºÅÂëµÈ¡£


https://securityaffairs.co/wordpress/128039/cyber-crime/blackcat-swissport-ransomware-attack.html


Proofpoint·¢ÏÖTA2541Õë¶Ôº½¿ÕºÍÔËÊäÐÐÒµµÄ¹¥»÷»î¶¯


Äþ¾²¹«Ë¾ProofpointÓÚ2ÔÂ15ÈÕÅû¶ÁËTA2541µÄ¹¥»÷»î¶¯µÄϸ½Ú¡£TA2541×Ô2017ÄêÒÔÀ´Ò»Ö±»îÔ¾ £¬Õë¶Ôº½¿Õ¡¢º½Ìì¡¢ÔËÊä¡¢ÖÆÔìºÍ¹ú·ÀÐÐÒµµÄ×éÖ¯¡£Ëüͨ³£ÒÀ¿¿Microsoft Word ÎĵµÀ´·Ö·¢RAT £¬½üÆÚ¿ªÊ¼Ê¹ÓÃÍйÜÔÚGoogle DriveµÈÔÆ·þÎñµÄÁ´½Ó¡£´ËÍâ £¬¸ÃÍŻﲻʹÓÃ×Ô½ç˵¶ñÒâÈí¼þ £¬Æ«°®ÓÚAsyncRAT¡¢NetWire¡¢WSH RATºÍParallax¡£Ä¿Ç°»î¶¯ÖÐʹÓõĶñÒâÈí¼þ¶¼¿ÉÓÃÓÚÊÕ¼¯ÐÅÏ¢ £¬µ«¹¥»÷ÕßµÄ×îÖÕÄ¿±êÈÔδ¿ÉÖª¡£


https://www.bleepingcomputer.com/news/security/unskilled-hacker-linked-to-years-of-attacks-on-aviation-transport-sectors/


Unit 42Ðû²¼¹ØÓÚEmotetÐÂÒ»ÂÖ¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß


2ÔÂ15ÈÕ £¬Unit 42Ðû²¼Á˹ØÓÚEmotetÐÂÒ»ÂÖ¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö £¬ÔçÔÚ2021Äê12ÔÂ21ÈÕ £¬Ñо¿ÈËÔ±¾ÍÊӲ쵽¶ñÒâÈí¼þ¼Ò×åEmotetµÄÐÂѬȾҪÁì¡£ÐµĹ¥»÷»î¶¯Í¨¹ýµç×ÓÓʼþ·Ö·¢Ò»¸öExcelÎļþ £¬¸ÃÎĵµ°üÂÞÒ»¸ö»ìÏýµÄExcel 4.0ºê¡£¼¤»îºêºó £¬Ëü»áÏÂÔØ²¢Ö´ÐÐÒ»¸öHTMLÓ¦Ó÷¨Ê½ £¬¸ÃÓ¦Ó÷¨Ê½»áÏÂÔØÁ½¸ö½×¶ÎµÄPowerShellÒÔÏÂÔØ²¢Ö´ÐÐ×îÖÕµÄEmotet payload¡£


https://unit42.paloaltonetworks.com/new-emotet-infection-method/


Check Point³ÆTrickbotÒѹ¥»÷60¼Ò´óÐ͹«Ë¾


Check Point ResearchÔÚ2ÔÂ16ÈÕÐû²¼³ÂËß³ÆTrickbotÒѱ»ÓÃÓÚ¹¥»÷60¼Ò´óÐ͹«Ë¾¡£TrickbotÊÇÒ»ÖÖÅÓ´óÇҶ๦ЧµÄ¶ñÒâÈí¼þ £¬¾ßÓÐ20¶à¸ö¿É°´ÐèÏÂÔØºÍÖ´ÐеÄÄ£¿é¡£TrickBotµÄÄ¿±ê°üÂÞÑÇÂíÑ·¡¢ÃÀ¹úÔËͨ¡¢Ä¦¸ù´óͨ¡¢Î¢Èí¡¢º£¾üÁª°îÐÅÓúÏ×÷Éç¡¢PayPal¡¢RBC¡¢ÑÅ»¢µÈÖªÃû¹«Ë¾¡£´ËÍâ £¬CPR³Æ¹¥»÷ÕßµÄÄ¿±ê²¢²»ÊÇÕâЩ¹«Ë¾¶øÊÇËûÃǵĿͻ§¡£³ÂËß»¹ÖصãÃèÊöÁË3¸öÒªº¦Ä£¿éinjectDll¡¢tabDllºÍpwgrabc £¬ÒÔ¼°TrickbotµÄ·´·ÖÎö¼¼Êõ¡£


https://research.checkpoint.com/2022/a-modern-ninja-evasive-trickbot-attacks-customers-of-60-high-profile-companies/



Äþ¾²¹¤¾ß


SafeDNS


ÃæÏò MSP µÄ»ùÓÚÔÆµÄ Internet Äþ¾²ºÍ Web ¹ýÂ˽â¾ö·½°¸¡£


https://thehackernews.com/2022/02/safedns-cloud-based-internet-security.html


F5 Distributed Cloud Services


F5 ÍÆ³öÁËÒ»¸öеÄÈí¼þ¼´·þÎñ (SaaS) ƽ̨ £¬Ö¼ÔÚ¼ò»¯¹«Ë¾µÄ·ÖÖ§Äþ¾²½â¾ö·½°¸¡£


https://www.zdnet.com/article/f5-launches-new-saas-app-security-cloud-edge-computing-platform/


Shellcodetester


¸Ã¹¤¾ß²âÊÔÉú³ÉµÄ ShellCodes¡£


https://github.com/helviojunior/shellcodetester


Flare-Qdb


ÃüÁîÐкͿɱàд½Å±¾µÄ»ùÓÚ Python µÄ¹¤¾ß £¬ÓÃÓÚÆÀ¹ÀºÍ²Ù×÷±¾»ú·¨Ê½×´Ì¬¡£


https://github.com/mandiant/flare-qdb


365Inspect


ͨ¹ý±àд¿É×Ô¶¯¶Ô Microsoft Office 365 »·¾³½øÐÐÄþ¾²ÆÀ¹ÀµÄ PowerShell ½Å±¾ £¬½øÒ»²½Á˽â O365 Äþ¾²×´Ì¬¡£


https://github.com/soteria-security/365Inspect



Äþ¾²·ÖÎö


CVE-2021-44521£ºApache Cassandra ÖÐ RCE ©¶´


https://thehackernews.com/2022/02/high-severity-rce-security-bug-reported.html


Squirrelwaffle¹¥»÷δÐÞ¸´µÄ Exchange ·þÎñÆ÷


https://news.sophos.com/en-us/2022/02/15/vulnerable-exchange-server-hit-by-squirrelwaffle-and-financial-fraud/


Windows 10 KB5010415 ¸üÐÂÐû²¼


https://www.bleepingcomputer.com/news/microsoft/windows-10-kb5010415-update-released-with-35-bug-fixes-improvements/


CISA Ðû²¼Í¨¸æ½¨Òé×éÖ¯ÐÞ¸´»ý¼«ÀûÓÃµÄ Chrome¡¢Magento ©¶´


https://www.bleepingcomputer.com/news/security/cisa-tells-federal-agencies-to-patch-actively-exploited-chrome-magento-bugs/


¹È¸èΪ Linux ÄÚºËºÍ GKE 0dayÌṩ 91,000 ÃÀÔªµÄ½±Àø


https://www.securityweek.com/google-offering-91000-rewards-linux-kernel-gke-zero-days


ÊÊÓÃÓÚ Windows 11 µÄ Android Ó¦Ó÷¨Ê½ÒÑÔÚÃÀ¹úÉÏÏß


https://www.bleepingcomputer.com/news/microsoft/windows-11s-android-apps-feature-now-available-in-the-us/