ÍøÐŰìÐû²¼¡¶Î´³ÉÄêÈËÍøÂç± £»¤ÌõÀý£¨Õ÷ÇóÒâ¼û¸å£©¡·

Ðû²¼Ê±¼ä 2022-03-17

ÍøÐŰìÐû²¼¡¶Î´³ÉÄêÈËÍøÂç± £»¤ÌõÀý£¨Õ÷ÇóÒâ¼û¸å£©¡·


3ÔÂ14ÈÕ£¬¹ú¼Ò»¥ÁªÍøÐÅÏ¢°ì¹«ÊÒÐû²¼¹ØÓÚ¡¶Î´³ÉÄêÈËÍøÂç± £»¤ÌõÀý£¨Õ÷ÇóÒâ¼û¸å£©¡·ÔٴιûÈ»Õ÷ÇóÒâ¼ûµÄ֪ͨ¡£Îª± £»¤Î´³ÉÄêÈËÉíÐĽ¡¿µºÍÆäÔÚÍøÂç¿Õ¼äµÄºÏ·¨È¨Ò棬ǰÆÚÍøÐŰìÆð²ÝÁË¡¶Î´³ÉÄêÈËÍøÂç± £»¤ÌõÀý£¨Õ÷ÇóÒâ¼û¸å£©¡·¡£Ö®ºó£¬Æ¾¾ÝÐÂÐÞ¶©µÄ¡¶ÖлªÈËÃñ¹²ºÍ¹úδ³ÉÄêÈ˱ £»¤·¨¡·µÈÖ´·¨ºÍÉç»á¹«ÖÚ·´À¡Òâ¼û£¬¶Ô¸ÃÌõÀý½øÐÐÁËÐÞ¸ÄÍêÉÆ¡£ÌõÀýÖ¸³ö£¬ÍøÂç²úÎïºÍ·þÎñÌṩÕßÓ¦µ±½¨Á¢½¡È«·À×ÅÃÔÖÆ¶È£¬²»µÃÏòδ³ÉÄêÈËÌṩÓÕµ¼Æä×ÅÃԵIJúÎïºÍ·þÎñ¡£


http://www.cac.gov.cn/2022-03/14/c_1648865100662480.htm


QNAPͨ¸æ³ÆDirty Pipe©¶´»áÓ°ÏìÆä´ó²¿ÃÅNASÉ豸


Ó²¼þ¹©Ó¦ÉÌQNAPÔÚ3ÔÂ14ÈÕÐû²¼Í¨¸æ£¬³ÆÆä´ó²¿ÃÅÍøÂ總¼Ó´æ´¢(NAS)É豸¶¼Êܵ½Linux©¶´Dirty PipeµÄÓ°Ï졣ͨ¸æÖ¸³ö£¬Õâ¸ö©¶´Ö÷Òª»áÓ°ÏìÔËÐÐQTS 5.0.xºÍQuTS hero h5.0.xµÄÉ豸£¬¹¥»÷Õß¿ÉÒÔÀûÓÃÆä»ñµÃ¹ÜÀíԱȨÏÞ²¢×¢Èë¶ñÒâ´úÂë¡£ËäÈ»Õë¶ÔLinuxÄں˵IJ¹¶¡ÒÑÓÚÒ»ÖÜǰÐû²¼£¬µ«¸Ã¹«Ë¾½¨ÒéÓû§¹Ø±Õ·ÓÉÆ÷¶Ë¿Úת·¢¹¦Ð§²¢½ûÓÃQNAP NASµÄUPnP¹¦Ð§À´»º½â¸Ã©¶´£¬Ö±µ½QNAPÐû²¼×Ô¼ºµÄÄþ¾²¸üС£


https://www.bleepingcomputer.com/news/security/qnap-warns-severe-linux-bug-affects-most-of-its-nas-devices/


ÒÔÉ«ÁÐÔâµ½´ó¹æÄ£DDoS¹¥»÷£¬Õþ¸®»ú¹¹¶à¸öÍøÕ¾¹Ø±Õ


¾ÝýÌå3ÔÂ15ÈÕ±¨µÀ£¬ÒÔÉ«ÁÐÕþ¸®»ú¹¹µÄ¶à¸öÍøÕ¾ÔÚ±¾ÖÜÒ»Ôâµ½´ó¹æÄ£DDoS¹¥»÷¡£°üÂÞÎÀÉú²¿¡¢ÄÚÕþ²¿ºÍ˾·¨²¿ÔÚÄڵĶà¸ö²¿Î¯¶¼Êܵ½Á˹¥»÷µÄÓ°Ï죬×ÜÀí°ì¹«ÊÒµÄÍøÕ¾Ò²ÔÝʱ¹Ø±Õ¡£¸Ã¹ú¹ú·À»ú¹¹ºÍ¹ú¼ÒÍøÂç¾ÖÒÑÐû²¼½øÈë½ô¼±×´Ì¬£¬Ä¿Ç°ÕýÔÚÈ·¶¨¹¥»÷ÊÇ·ñ¶ÔÒÔÉ«ÁеÄÒªº¦»ù´¡ÉèÊ©Ôì³ÉÁËÉ˺¦¡£µ±µØÃ½Ì峯£¬´Ë´Î¹¥»÷¿ÉÄÜÀ´×ÔÓëÒÁÀÊÏà¹ØµÄ¹¥»÷Õß¡£¾ÝϤ£¬ÕâÊÇÓÐÊ·ÒÔÀ´Õë¶ÔÒÔÉ«ÁеÄ×î´ó¹æÄ£µÄ¹¥»÷»î¶¯¡£


https://securityaffairs.co/wordpress/129063/cyber-warfare-2/massive-ddos-attack-hit-israel.html


PandoraÍÅ»ïÉù³ÆÒÑÈëÇÖDENSO¹«Ë¾²¢ÇÔÈ¡1.4TBµÄÊý¾Ý


ýÌå3ÔÂ14Èճƣ¬DENSOÈÏ¿ÉÆäÔڵ¹úµÄ¼¯ÍŹ«Ë¾ÓÚ3ÔÂ10ÈÕÔâµ½ÈëÇÖ¡£DENSOÊÇÈ«Çò×î´óµÄÆû³µÁ㲿¼þÖÆÔìÉÌÖ®Ò»£¬¸Ã¹«Ë¾ÌåÏÖÔÚ¼ì²âµ½Î´¾­ÊÚȨµÄ·ÃÎʺó£¬Á¢¼´ÇжÏÁ˱»¹¥»÷É豸µÄÍøÂçÁ¬½Ó£¬ËùÓÐÉú²ú¹¤³§¶¼½«Õý³£ÔËÐУ¬Òò´ËÔ¤¼Æ´Ë´Îʼþ²»»áµ¼Ö¹©Ó¦Á´ÖжÏ¡£ÀÕË÷ÍÅ»ïPandoraÉù³Æ¶Ô´ËÊÂÂôÁ¦£¬²¢ÒÑ¿ªÊ¼Ð¹Â¶ÆäÇÔÈ¡µÄ1.4TBÎļþ£¬ÆäÐû²¼µÄÑù±¾Êý¾Ý°üÂ޲ɹº¶©µ¥¡¢¼¼ÊõÔ­ÀíͼºÍ±£ÃÜЭÒéµÈ¡£


https://www.zdnet.com/article/automotive-giant-denso-reveals-hack-pandora-ransomware-group-takes-credit/


ESETÐû²¼Õë¶ÔÎÚ¿ËÀ¼µÄжñÒâÈí¼þCaddyWiperµÄ³ÂËß


3ÔÂ15ÈÕ£¬ESETÐû²¼Õë¶ÔÎÚ¿ËÀ¼µÄжñÒâÈí¼þCaddyWiperµÄ·ÖÎö³ÂËß¡£ÕâÊÇÒ»¸öÊý¾Ý²Á³ý¶ñÒâÈí¼þ£¬ÓÚ±¾ÖÜÒ»ÉÏÎçÊ״α»·¢ÏÖ¡£Ñо¿ÈËÔ±ÔÚÒÑÔÚ¶à¸ö×éÖ¯µÄ¼¸Ê®¸öϵͳÉϼì²âµ½Ëü£¬±»ÓÃÀ´ÆÆ»µÁ¬½ÓÇý¶¯ÉϵÄÓû§Êý¾ÝºÍ·ÖÇøÐÅÏ¢¡£CaddyWiperÓëHermeticWiperºÍIsaacWiperµÄ´úÂëûÓÐÏàËÆÖ®´¦£¬µ«ÓÐÖ¤¾Ý±íÃ÷¹¥»÷ÕßÔÚÔÚ·Ö·¢¶ñÒâÈí¼þ֮ǰ¾ÍÉøÍ¸ÁËÄ¿±êµÄÍøÂç¡£


https://www.welivesecurity.com/2022/03/15/caddywiper-new-wiper-malware-discovered-ukraine/


OpenSSLÐû²¼Äþ¾²¸üУ¬ÐÞ¸´DoS©¶´CVE-2022-0778


¾Ý3ÔÂ15ÈÕ±¨µÀ£¬OpenSSLÐû²¼Äþ¾²¸üÐÂÒÔÐÞ¸´¾Ü¾ø·þÎñ(DoS)©¶´£¨CVE-2022-0778£©¡£¸Ã©¶´ÓÉGoogle Project ZeroÑо¿ÈËÔ±Tavis Ormandy·¢ÏÖ£¬Ô´ÓÚ½âÎöÖ¤Êéʱ¼ÆËãģƽ·½¸ùµÄBN_mod_sqrt()º¯ÊýÖдæÔÚÒ»¸ö´íÎ󣬿ÉÄܵ¼ÖÂËüÓÀÔ¶Ñ­»·¼ÆËã·ÇËØÊýÄ£¡£Ñо¿ÈËÔ±³Æ£¬¿ÉÒÔʹÓÃÎÞЧµÄÏÔʽÇúÏß²ÎÊýÖÆ×÷¸ñʽ´íÎóµÄÖ¤ÊéÀ´´¥·¢´Ë©¶´¡£¸Ã©¶´Ó°ÏìÁËOpenSSL°æ±¾ 1.0.2¡¢1.1.1ºÍ3.0£¬ÒÑͨ¹ýÐû²¼°æ±¾1.0.2zd¡¢1.1.1nºÍ3.0.2ÐÞ¸´¡£


https://securityaffairs.co/wordpress/129104/security/openssl-dos-vulnerability.html



Äþ¾²¹¤¾ß


CodeAnalysis


×ÛºÏÐԵĴúÂë·ÖÎöºÍÎÊÌâ¸ú×ÙÆ½Ì¨¡£


https://github.com/Tencent/CodeAnalysis


DomainAlerting


ÊÕ¼¯°üÂÞÒªº¦×ÖµÄ×¢²áµÄÐÂÓòÃû£¬²¢Ã¿ÈÕ¾¯±¨¡£


https://github.com/pixelbubble/DomainAlerting


NimPackt-v1


ÓÃÓÚ .NET ¿ÉÖ´ÐÐÎļþºÍԭʼ shellcode µÄ»ùÓÚ Nim µÄ´ò°ü·¨Ê½¡£


https://github.com/chvancooten/NimPackt-v1


PurplePanda


´Ó¹Ø×¢È¨Ï޵IJîÒìÔÆ/SaaS Ó¦Ó÷¨Ê½ÖлñÈ¡×ÊÔ´£¬ÒÔʶ±ðÔÆ/saas ÅäÖÃÖеÄȨÏÞÌáÉý·¾¶ºÍΣÏÕȨÏÞ¡£


https://github.com/carlospolop/PurplePanda



Äþ¾²·ÖÎö


Mozilla Firefox Òò´íÎóÐÅÏ¢ÎÊÌâ¶øÉ¾³ýÁ˶íÂÞ˹ËÑË÷ÌṩÉÌ


https://www.bleepingcomputer.com/news/software/mozilla-firefox-removes-russian-search-providers-over-misinformation-concerns/


Æ»¹ûÐû²¼ iOS 15.4£¬Óû§¿É´ø×Å¿ÚÕÖʹÓà Face ID


https://news.softpedia.com/news/apple-finally-releases-ios-15-4-face-id-with-a-mask-now-available-for-all-users-535039.shtml


΢ÈíΪ VirtualBox Óû§É¾³ýÁË Windows 11 ¸üÐÂÄ£¿é


https://www.bleepingcomputer.com/news/microsoft/microsoft-removes-windows-11-update-block-for-virtualbox-users/


ºÚ¿ÍÃé×¼¶íÂÞ˹ʯÓ͹«Ë¾µÄµÂ¹ú·Ö¹«Ë¾


https://securityaffairs.co/wordpress/129052/hacktivism/anonymous-hacked-german-subsidiary-rosneft.html


Ñо¿ÈËÔ±·¢ÏÖ½« Kwampirs Óë Shamoon APT ÁªÏµÆðÀ´µÄÐÂÖ¤¾Ý


https://thehackernews.com/2022/03/researchers-find-new-evidence-linking.html


ÓÃÓÚÔÚÎÚ¿ËÀ¼²¿Êð Cobalt Strike µÄÐé¼Ù·À²¡¶¾¸üÐÂ


https://www.bleepingcomputer.com/news/security/fake-antivirus-updates-used-to-deploy-cobalt-strike-in-ukraine/