ÁªÏëUEFI¹Ì¼þÇý¶¯·¨Ê½ÖеÄ©¶´Ó°ÏìÉϰٿîÌõ¼Ç±¾µçÄÔ
Ðû²¼Ê±¼ä 2022-04-201¡¢ÁªÏëUEFI¹Ì¼þÇý¶¯·¨Ê½ÖеÄ©¶´Ó°ÏìÉϰٿîÌõ¼Ç±¾µçÄÔ
¾ÝýÌå4ÔÂ19ÈÕ±¨µÀ£¬ESETÑо¿ÈËÔ±·¢ÏÖÓ°ÏìÁªÏëÉϰٿîÌõ¼Ç±¾µçÄÔµÄ3¸ö©¶´¡£ÆäÖÐÁ½¸ö©¶´£¨CVE-2021-3971ºÍCVE-2021-3972£©¿ÉÓÃÀ´½ûÓöԴ洢UEFI¹Ì¼þµÄSPIÉÁ´æÐ¾Æ¬µÄ±£»¤£¬²¢¹Ø±ÕUEFIÄþ¾²Æô¶¯¹¦Ð§£¬Ê¹¶ñÒâÈí¼þÔÚÏµÍ³ÖØÆôºóÈÔ¿É´æÔÚ¡£µÚÈý¸ö©¶´£¨CVE-2021-3970£©´æÔÚÓÚLenovoVariable SMI´¦Ö÷¨Ê½ÖУ¬¹¥»÷Õß¿ÉÀûÓÃÆäÒÔÌáÉýµÄȨÏÞÖ´ÐÐÈÎÒâ´úÂë¡£ESETÓÚ2021Äê10ÔÂ11ÈÕÏòÁªÏë³ÂËßÕâЩ©¶´£¬ÁªÏëÓÚ4ÔÂ12ÈÕÐû²¼²¹¶¡¡£
https://www.bleepingcomputer.com/news/security/lenovo-uefi-firmware-driver-bugs-affect-over-100-laptop-models/
2¡¢CISAºÍFBIÁªºÏÐû²¼¹ØÓÚÇø¿éÁ´ÐÐÒµµÄÍøÂçÄþ¾²×Éѯ
4ÔÂ18ÈÕ£¬ÃÀ¹úFBI¡¢CISAºÍ²ÆÕþ²¿ÁªºÏÐû²¼Á˹ØÓÚÇø¿éÁ´ÐÐÒµµÄÍøÂçÄþ¾²×Éѯ¡£¸Ã×Éѯָ³ö£¬³¯ÏÊAPT×éÖ¯LazarusÃé×¼Çø¿éÁ´¼¼ÊõºÍ¼ÓÃÜ»õ±ÒÐÐÒµµÄÖÖÖÖ×éÖ¯£¬°üÂÞ¼ÓÃÜ»õ±Ò½»Ò×Ëù¡¢È¥ÖÐÐÄ»¯½ðÈÚ (DeFi) ÐÒéºÍ¼ÓÃÜ»õ±ÒóÒ×¹«Ë¾µÈ¡£¹¥»÷ÕßʹÓÃÖÖÖÖͨÐÅÆ½Ì¨¶ÔÄ¿±ê½øÐÐÉç»á¹¤³Ì¹¥»÷£¬ÓÕʹÆäÔÚWindows»òmacOSϵͳÉÏÏÂÔØÄ¾Âí»¯µÄ¼ÓÃÜ»õ±ÒÓ¦Óã¬ÒÔÇÔȡ˽Կ»òÀÄÓÃÆäËü©¶´¡£¸Ãͨ¸æÌṩÁË´ËÀà»î¶¯Ïà¹ØµÄ¼ÆÄ±¡¢¼¼ÊõºÍ·¨Ê½(TTP)ºÍIOC£¬ÒÔ×ÊÖú×é֯ʶ±ð²¢µÖÓùÕë¶Ô¼ÓÃÜ»õ±ÒµÄÍøÂç¹¥»÷¡£
https://www.cisa.gov/uscert/ncas/alerts/aa22-108a
3¡¢CloudSEK·¢ÏÖð³äWin11Éý¼¶·Ö·¢Inno StealerµÄ»î¶¯
ýÌå4ÔÂ18ÈÕ±¨µÀ£¬CloudSEK·¢ÏÖð³äWin11Éý¼¶·Ö·¢Inno StealerµÄ»î¶¯¡£¸Ã»î¶¯Ä¿Ç°ºÜ»îÔ¾£¬Í¨¹ýËÑË÷½á¹ûͶ¶¾À´ÍÆËÍð³äWindows 11ÍÆ¹ãÒ³ÃæµÄµöÓãÍøÕ¾¡£Ä¿±êµã»÷Á¢¼´ÏÂÔØºó»áµÃµ½Ò»¸öISOÎļþ£¬ÆäÖаüÂÞInno StealerµÄ¼ÓÔØ·¨Ê½¡£Ð¶ñÒâÈí¼þÒòΪʹÓÃÁËInno Setup Windows°²×°·¨Ê½¶øµÃÃû£¬ÓëĿǰÁ÷ÐÐµÄÆäËüÐÅÏ¢ÇÔÈ¡·¨Ê½µÄ´úÂëûÓÐÈκÎÏàËÆÖ®´¦£¬¿ÉÇÔÈ¡ä¯ÀÀÆ÷cookieºÍ´æ´¢µÄƾ¾Ý¡¢¼ÓÃÜ»õ±ÒÇ®°üÖеÄÊý¾ÝÒÔ¼°ÎļþϵͳµÄÊý¾Ý¡£
https://www.bleepingcomputer.com/news/security/unofficial-windows-11-upgrade-installs-info-stealing-malware/
4¡¢Äþ¾²¹«Ë¾PRODAFTÐû²¼ÀÕË÷Èí¼þPYSAµÄÉî¶È·ÖÎö³ÂËß
4ÔÂ14ÈÕ£¬Äþ¾²¹«Ë¾PRODAFTÐû²¼Á˹ØÓÚÀÕË÷Èí¼þPYSAµÄÉî¶È·ÖÎö³ÂËß¡£PYSAÊÇMespinozaµÄ¼ÌÈÎÕߣ¬ÓÚ2019Äê12ÔÂÊ״α»·¢ÏÖ£¬ÒѳÉΪ2021ÄêQ4¼ì²âµ½µÄµÚÈý´óÁ÷ÐÐÀÕË÷Èí¼þ£¬×Ô2020Äê9ÔÂÒÔÀ´Ð¹Â¶Á˶à´ï747¸ö±»¹¥»÷Ä¿±êµÄÐÅÏ¢¡£PRODAFT·¢ÏÖÁËPYSAµÄ¹ûÈ».gitÎļþ¼Ð£¬ÆäÖÐÒ»¸ö³ÉÔ±ÊÇ¡°dodo@mail.pcc¡±£¬Æ¾¾ÝÌá½»ÀúÊ·ÅжϴËÈËλÓÚÒ»¸öÏÄÁîʱ¹ú¼Ò¡£PYSAµÄ»ù´¡ÉèÊ©»¹°üÂÞdockerizedÈÝÆ÷£¬É漰й¶·þÎñÆ÷¡¢Êý¾Ý¿âºÍ¹ÜÀí·þÎñÆ÷£¬ÒÔ¼°´æ´¢¼ÓÃÜÎļþµÄAmazon S3ÔÆ£¬×ܼÆ31.47TB¡£
https://thehackernews.com/2022/04/researchers-share-in-depth-analysis-of.html
5¡¢CheckPointÐû²¼2022ÄêÃæÁÙ×î´óµÄÔÆÄþ¾²ÌôÕ½µÄ³ÂËß
CheckPointÔÚ4ÔÂ18ÈÕÐû²¼ÁË2022ÄêÃæÁÙµÄ×î´óÔÆÄþ¾²ÌôÕ½µÄ³ÂËß¡£³ÂËßÖ¸³ö£¬Áè¼Ý98%µÄ×é֯ʹÓûùÓÚÔÆµÄ»ù´¡¼Ü¹¹£¬76%µÄ×éÖ¯ÓµÓÐÓÉÁ½¸ö»ò¶à¸öÔÆÌṩÉ̵ķþÎñ×é³ÉµÄ¶àÔÆ»·¾³¡£¶àÔÆ»·¾³µÄÅÓ´óÐÔµ¼ÖÂÁËÐí¶àÌôÕ½£¬°üÂÞÊý¾ÝµÄÒþ˽ºÍ±£»¤¡¢¶àÔÆ»·¾³ÖÐÐëÒªµÄ¼¼ÄÜ¡¢½â¾ö·½°¸ÕûºÏÒÔ¼°¿É¼ûÐԺͿØÖƵÄȱ·¦¡£ÊµÏÖÔÆÄþ¾²µÄÖ÷ҪĿ±ê°üÂÞ·ÀÖ¹ÔÆÅäÖôíÎó¡¢±£»¤ÒÑÔÚʹÓõÄÖ÷ÒªÔÆÓ¦Ó÷¨Ê½¡¢ÊµÏÖ¼à¹ÜºÏ¹æºÍµÖÓù¶ñÒâÈí¼þ¡£
https://blog.checkpoint.com/2022/04/18/the-biggest-cloud-security-challenges-in-2022-check-point-software/
6¡¢FortinetÐû²¼½üÆÚEmotet Maldoc·¢×÷Ç÷ÊÆµÄ·ÖÎö³ÂËß
4ÔÂ18ÈÕ£¬FortinetÐû²¼¹ØÓÚ½üÆÚEmotet·Ö·¢Maldoc»î¶¯µÄ·ÖÎö³ÂËß¡£´ËÂֻ¿ªÊ¼ÓÚ2021Äê11ÔÂ16ÈÕ£¬Ê¹ÓÃÁ˵öÓãÓʼþÓëÉç»á¹¤³Ì¹¥»÷Ïà½áºÏµÄ·½Ê½£¬À´ÓÕʹĿ±ê°²×°¶ñÒâÈí¼þ¡£ÕâЩµöÓãÓʼþµÄÖ÷ÌâÐÐÖÐͨ³£ÖаüÂÞ¡°Re:¡±»ò¡°Fw:¡±£¬Ê¹Æä¿´ÆðÀ´Ô½·¢ºÏ·¨¡£Ñо¿ÈËÔ±¼ì²âµ½ÁËÓë´Ë»î¶¯Ïà¹ØµÄ5¸ö²îÒìÑù±¾£¬ËüÃǵĺê´úÂëºÍÖ´ÐÐÁ÷³Ì´æÔÚ²îÒì¡£´ËÍ⣬¹¥»÷»î¶¯Ê¹ÓõĶñÒâExcelÎļþµÄÕ¼±ÈΪ93%£¬Ô¶¸ßÓÚ7%µÄ¶ñÒâWordÎĵµ¡£
https://www.fortinet.com/blog/threat-research/Trends-in-the-recent-emotet-maldoc-outbreak