ÀûÓÃGoogle Play·Ö·¢µÄÐÂľÂíXenomorphÕë¶ÔÅ·ÖÞµØÓò
Ðû²¼Ê±¼ä 2022-02-24ÀûÓÃGoogle Play·Ö·¢µÄÐÂľÂíXenomorphÕë¶ÔÅ·ÖÞµØÓò
¾ÝýÌå2ÔÂ21ÈÕ±¨µÀ£¬Äþ¾²¹«Ë¾ThreatFabric·¢ÏÖÁËеÄAndroidÒøÐÐľÂíXenomorph¡£¸ÃľÂíαװ³ÉÐÔÄÜÌáÉýÓ¦Ó÷¨Ê½£¨ÀýÈçFast Cleaner£©Í¨¹ýGoogle PlayÉ̵ê·Ö·¢£¬Òѱ»°²×°Áè¼Ý50000´Î¡£ËüĿǰÈÔ´¦ÓÚÔçÆÚ¿ª·¢½×¶Î£¬Ä¿±êÊÇÎ÷°àÑÀ¡¢ÆÏÌÑÑÀ¡¢Òâ´óÀûºÍ±ÈÀûʱµÈÅ·ÖÞ¹ú¼ÒµÄ56¼Ò½ðÈÚ»ú¹¹¡£Ñо¿ÈËÔ±»¹·¢ÏÖ¸ÃľÂíµÄ´úÂëÓëAlienÓÐËùÖØµþ£¬Õâ±íÃ÷¶þÕß´æÔÚijÖÖÁªÏµ£ºÒªÃ´XenomorphÊÇAlienµÄ¼ÌÈÎÕߣ¬ÒªÃ´XenomorphµÄ¿ª·¢ÈËÔ±Ò»Ö±ÔÚÑо¿Alien¡£
https://thehackernews.com/2022/02/xenomorph-android-banking.html
ÃÀ¹úMeyerÔâµ½ContiÀÕË÷¹¥»÷µ¼Ö´óÁ¿Ô±¹¤ÐÅϢй¶
¾Ý2ÔÂ21ÈÕ±¨µÀ£¬ÃÀ¹ú×î´óµÄ´¶¾ß¹«Ë¾MeyerÔâµ½ContiÀÕË÷¹¥»÷¡£¹¥»÷·¢ÉúÔÚ2021Äê10ÔÂ25ÈÕ£¬¼ì²âµ½¹¥»÷ºó¸Ã¹«Ë¾Á¢¼´Õ¹¿ªÊӲ죬²¢ÓÚ12ÔÂ1ÈÕÈ·¶¨MeyerÔ±¹¤µÄÐÅÏ¢¿ÉÄÜÒÑÔ⵽δ¾ÊÚȨµÄ·ÃÎÊ¡£Ñо¿ÈËÔ±ÔÚContiµÄÐÅÏ¢Ð¹Â¶ÍøÕ¾·¢ÏÖÒ»¸ö¿É×·Ëݵ½11ÔÂ7ÈÕµÄÁÐ±í£¬¾Ý³Æ°üÂÞÁËÔÚMeyerÇÔÈ¡µÄ2%µÄÊý¾Ý£¬µ«ÖÁ½ñÈÔδÐû²¼Ê£ÓàµÄ98%¡£MeyerÌåÏÖ½«ÎªÊÜÓ°ÏìµÄÔ±¹¤¼°Æä¼ÒÊôÌṩÁ½ÄêµÄÉí·Ý±£»¤·þÎñ¡£
https://www.bleepingcomputer.com/news/security/cookware-giant-meyer-discloses-cyberattack-that-impacted-employees/
Ahn Lab·¢ÏÖCryptBotбäÌåÀûÓõÁ°æÈí¼þÍøÕ¾Á÷´«
Ahn LabÔÚ2ÔÂ21ÈÕÐû²¼µÄÑо¿ÏÔʾ£¬CryptBotбäÌåÕýÔÚͨ¹ýµÁ°æÈí¼þÍøÕ¾½øÐÐÁ÷´«¡£CryptBotÊÇÒ»ÖÖWindowsÐÅÏ¢ÇÔÈ¡·¨Ê½£¬¿É´ÓÄ¿±êÇÔÈ¡ä¯ÀÀÆ÷ƾ¾Ý¡¢cookie¡¢¼ÓÃÜ»õ±ÒÇ®°üºÍÐÅÓÿ¨µÈÐÅÏ¢¡£¹¥»÷ÕßÀûÓÃÆÆ½âÈí¼þºÍÃÜÔ¿Éú³ÉÆ÷µÈÍøÕ¾·Ö·¢¶ñÒâÈí¼þ£¬²¢Í¨¹ýËÑË÷ÒýÇæÓÅ»¯½«ÕâÐ©ÍøÕ¾ÔڹȸèµÄËÑË÷½á¹ûÖÐÖö¥¡£´ËÍ⣬¸Ã°æ±¾±ÈÒÔÍùÓнϴóµÄ¸Ä¶¯£¬É¾³ýÁË·´É³ºÐ¹¦Ð§ºÍ±¸ÓÃC2µÈÈßÓàµÄ¹¦Ð§£¬²¢ÒÑ¿ÉÊÊÓÃÓÚËùÓÐChrome°æ±¾¡£
https://asec.ahnlab.com/en/31802/
KasperskyÐû²¼2021ÄêÒÆ¶¯¶ñÒâÈí¼þÌ¬ÊÆµÄ·ÖÎö³ÂËß
2ÔÂ21ÈÕ£¬KasperskyÐû²¼ÁË2021ÄêÒÆ¶¯¶ñÒâÈí¼þÌ¬ÊÆµÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬KasperskyÔÚ2021Äê×ܼƼì²âµ½3464756¸ö¶ñÒâ°²×°°ü¡¢97661¸öеÄÒÆ¶¯ÒøÐÐľÂíºÍ17372¸öеÄÒÆ¶¯ÀÕË÷Èí¼þ¡£ÊÜÒÆ¶¯¶ñÒâÈí¼þ¹¥»÷×î¶àµÄ¹ú¼ÒÊÇÒÁÀÊ£¬Æä´ÎÊÇÖйú¡¢É³Ìذ¢À²®ºÍ°¢¶û¼°ÀûÑÇ¡£¼ì²âµ½µÄ¶ñÒâÈí¼þÖÐ¹ã¸æÈí¼þ£¨42.42%£©µÄÕ¼±È×î´ó£¬Æä´ÎΪRiskToolÓ¦Ó÷¨Ê½£¨35.27%£©ºÍľÂí£¨8.86%£©¡£
https://securelist.com/mobile-malware-evolution-2021/105876/
Trend MicroÅû¶ÐµÄMac¶ñÒâÍÚ¿óÈí¼þµÄ¼¼Êõϸ½Ú
Trend MicroÔÚ2ÔÂ21ÈÕÅû¶ÁËÐÂMac¶ñÒâÍÚ¿óÈí¼þµÄ¼¼Êõϸ½Ú¡£¶ñÒâÈí¼þÑù±¾±»¼ì²âΪCoinminer.MacOS.MALXMR.H£¬ÓÚ2022Äê1Ô³õÊ״α»·¢ÏÖ£¬ÊÇÒ»¸öMach-OÎļþ¡£Ö´ÐÐʱ£¬ËüÀûÓÃAuthorizationExecuteWithPrivileges APIͨ¹ýÌáʾÓû§ÊäÈëÆ¾¾ÝÀ´ÌáÉýȨÏÞ¡£³ý´ËÖ®Í⣬¸ÃÑù±¾»¹Ê¹ÓÃÁËi2pd£¨ÓÖÃûI2PÊØ»¤·¨Ê½£©À´Òþ²ØÆäÍøÂçÁ÷Á¿£¬¶øÆäËüMac¶ñÒâÈí¼þͨ³£Ê¹ÓÃTor¡£
https://www.trendmicro.com/en_us/research/22/b/latest-mac-coinminer-utilizes-open-source-binaries-and-the-i2p-network.html
Ñо¿ÍŶӷ¢ÏÖÕë¶ÔMicrosoft SQLÊý¾Ý¿âµÄ¹¥»÷»î¶¯
ýÌå2ÔÂ21Èճƣ¬Ñо¿ÍŶӷ¢ÏÖÁËÕë¶ÔMicrosoft SQLÊý¾Ý¿âµÄ¹¥»÷»î¶¯¡£¹¥»÷ÕßÊ×ÏÈɨÃèTCP¶Ë¿Ú1433¿ª·ÅµÄ·þÎñ£¬È»ºóͨ¹ý±©Á¦ÆÆ½âºÍ×ֵ乥»÷À´ÆÆ½âÃÜÂë¡£Ò»µ©»ñµÃ¹ÜÀíÔ±ÕÊ»§µÄ·ÃÎÊȨÏÞ£¬¹¥»÷Õ߾ͻáÁ¢¼´°²×°Lemon Duck¡¢KingMinerºÍVollgarµÈ¶ñÒâ¿ó¹¤Èí¼þ¡£×îºó£¬ËûÃÇ»¹»áʹÓÃCobalt StrikeÔÚÊý¾Ý¿âÖн¨Á¢ºóÃÅ£¬ÒÔ±£³Ö³Ö¾ÃÐÔ²¢½øÐкáÏòÒÆ¶¯¡£
https://www.bleepingcomputer.com/news/security/vulnerable-microsoft-sql-servers-targeted-with-cobalt-strike/
Äþ¾²¹¤¾ß
coraza
golang ÆóÒµ¼¶ Web Ó¦Ó÷À»ðǽ¿ò¼Ü£¬Ö§³Ö Modsecurity µÄ seclang ÓïÑÔ£¬Óë OWASP Core Ruleset 100% ¼æÈÝ¡£
https://github.com/corazawaf/coraza
m3
ÒÆ¶¯¶ñÒâÈí¼þÄ£·Â¿ò¼Ü£¨¼ò³Æm3£©ÊÇÒ»¸ö¼òµ¥ÇÒ¿ÉÀ©Õ¹µÄ Android »úÆ÷ÈËÄ£Äâ¿ò¼Ü¡£
https://github.com/ThisIsLibra/m3/
SecureBank
°üÂÞËùÓÐ OWASP TOP 10 Äþ¾²Â©¶´µÄ½ðÈڿƼ¼Ó¦Ó÷¨Ê½¡£
https://ssrd.gitbook.io/securebank/
Talisman
¿É½«hook°²×°µ½´æ´¢¿â£¬ÒÔÈ·±£Ç±ÔÚµÄÃô¸ÐÐÅÏ¢²»»áÀ뿪¿ª·¢ÈËÔ±µÄÊÂÇéÕ¾¡£
https://github.com/thoughtworks/talisman#what-is-talisman
SharpCookieMonster
cookie-crimesÄ£¿éµÄÒ»¸ö Sharp ¶Ë¿Ú£¬Õâ¸ö C# ÏîÄ¿½«ÎªËùÓÐÕ¾µãת´¢ cookie¡£
https://github.com/m0rv4i/SharpCookieMonster
Äþ¾²·ÖÎö
ÕûÊýÒç³ö£ºËüÊÇÈçºÎ·¢ÉúµÄÒÔ¼°ÈçºÎÔ¤·À
https://www.welivesecurity.com/2022/02/21/integer-overflow-how-it-occur-can-be-prevented/
¹¥»÷ÕßÀûÓÃSMS PVA ·þÎñ½øÐжñÒâ»î¶¯
https://securityaffairs.co/wordpress/128242/cyber-crime/sms-pva-services.html
ÆÏÌÑÑÀÍþв³ÂËߣº2021 ÄêµÚËļ¾¶È
https://seguranca-informatica.pt/threat-report-portugal-q3-2021/
΢Èí¸üÐÂÁË Your Phone Ó¦Ó÷¨Ê½µÄÒ»Ïîй¦Ð§
https://news.softpedia.com/news/microsoft-announces-a-new-feature-for-the-your-phone-app-534911.shtml
CVE-2022-0290£ºChrome RenderFrameHostImplÊͷźóʹÓé¶´
https://packetstormsecurity.com/files/166080/GS20220221155706.tgz