΢ÈíÅû¶LinuxÖÐͳ³ÆÎªNimbuspwnµÄ2¸öÌáȨ©¶´µÄÏêÇé

Ðû²¼Ê±¼ä 2022-04-28
1¡¢Î¢ÈíÅû¶LinuxÖÐͳ³ÆÎªNimbuspwnµÄ2¸öÌáȨ©¶´µÄÏêÇé

΢ÈíÔÚ4ÔÂ26ÈÕÅû¶ÁËLinuxÖÐÒ»×éÃûΪNimbuspwnµÄ©¶´µÄÏêÇ顣©¶´·Ö±ðΪĿ¼±éÀú©¶´(CVE-2022-29799)¡¢·ûºÅÁ´½Ó¾ºÕùÒÔ¼°Time-of-check-time-of-use(TOCTOU)¾ºÕùÌõ¼þ©¶´(CVE-2022-29800)£¬¿É±»µ±µØ¹¥»÷ÕßÓÃÀ´ÌáÉýȨÏÞ£¬°²×°ºóÃźÍÀÕË÷Èí¼þµÈ¶ñÒâÈí¼þ¡£ËüÃÇ´æÔÚÓÚsystemd×é¼þnetworkd-dispatcherÖУ¬ÕâÊÇÒ»¸öÓÃÓÚÍøÂç¹ÜÀíÆ÷ϵͳ·þÎñµÄÊØ»¤·¨Ê½¡£


https://www.microsoft.com/security/blog/2022/04/26/microsoft-finds-new-elevation-of-privilege-linux-vulnerability-nimbuspwn/


2¡¢GoogleÐÞ¸´VirusTotalÖеÄRCE©¶´CVE-2021-22204


ýÌå4ÔÂ26ÈÕ±¨µÀ£¬GoogleÒÑÐÞ¸´VirusTotalƽ̨ÖеÄRCE©¶´£¨CVE-2021-22204£©¡£¸Ã©¶´ÊÇExifTool¶ÔDjVuÎļþ´¦Öò»Í×µ¼ÖµÄ£¬¿É±»¹¥»÷ÕßÓÃÀ´ÎäÆ÷»¯VirusTotalƽ̨£¬²¢ÔÚʹÓÃɱ¶¾ÒýÇæµÄµÚÈý·½É³ºÐÉÏʵÏÖÔ¶³Ì´úÂëÖ´ÐС£Ñо¿ÈËÔ±ÌáÐÑ£¬Â©¶´²¢²»Ó°ÏìVirusTotal£¬´úÂëÖ´Ðв»´æÔÚÓÚÆ½Ì¨×Ô¼º£¬¶øÊÇÔÚ·ÖÎöºÍÖ´ÐÐÑù±¾µÄµÚÈý·½É¨Ãèϵͳ¡£¸Ã©¶´ÓÚ2021Äê4Ô±»Åû¶£¬ÓÚ2021Äê5Ô±»½ÓÊÜ£¬¶ø²¹¶¡Óڰ˸öÔºóµÄ2022Äê1ÔÂÐû²¼¡£


https://www.hackread.com/critical-rce-vulnerability-google-virustotal/


3¡¢StormousÍÅ»ïÉù³ÆÒÑÇÔÈ¡¿É¿Ú¿ÉÀÖ¹«Ë¾161 GBµÄÊý¾Ý


¾Ý4ÔÂ26ÈÕ±¨µÀ£¬ÀÕË÷ÍÅ»ïStormousÉù³ÆÒÑÇÔÈ¡¿É¿Ú¿ÉÀÖ¹«Ë¾Áè¼Ý161 GBµÄÊý¾Ý¡£¹¥»÷ÕßÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ÁгöÁË´ýÊÛÊý¾Ý£¬²¢Ïò¿É¿Ú¿ÉÀÖ¹«Ë¾ÀÕË÷1.65±ÈÌØ±Ò£¨Ô¼ºÏ64000ÃÀÔª£©¡£Ð¹Â¶Êý¾Ý°üÂÞѹËõÎĵµ¡¢µç×ÓÓʼþºÍÃÜÂëµÄÎı¾Îļþ¡¢ÕÊ»§ºÍ¸¶¿îÏà¹ØZIPÎĵµµÈ¡£ÕâÊÇStormousÍÅ»ïµÚÒ»´Î¹ûÈ»±»µÁÊý¾Ý¡£¿É¿Ú¿ÉÀÖ¹«Ë¾ÌåÏÖ֪ϤÓëÆäÏà¹ØµÄÍøÂç¹¥»÷µÄ±¨µÀºó£¬ÕýÔÚÊÓ²ì´Ëʼþ¡£


https://securityaffairs.co/wordpress/130614/cyber-crime/stormous-ransomware-hit-coca-cola.html


4¡¢Hive0117ð³ä¶íÂÞ˹ִ·¨²¿ÃŶԶ«Å·¹ú¼Ò½øÐеöÓã¹¥»÷


ýÌå4ÔÂ27Èճƣ¬IBMµÄX-ForceÍŶӷ¢ÏÖ½üÆÚÕë¶Ô¶«Å·¹ú¼ÒµÄµöÓã¹¥»÷¡£´Ë´ÎµöÓã»î¶¯¿ªÊ¼ÓÚ2022Äê2Ô£¬Ö¼ÔÚ·Ö·¢ÃûΪDarkWatchmanµÄÎÞÎļþ¶ñÒâÈí¼þ±äÖÖ¡£¹¥»÷Õßð³ä¶íÂÞ˹µÄÖ´·¨²¿ÃÅ£¬ÊÕ¼þÈËÊÇÁ¢ÌÕÍð¡¢°®É³ÄáÑǺͶíÂÞ˹µÄµçÐÅ·þÎñÌṩÉ̺͹¤Òµ¹«Ë¾¡£µöÓãÓʼþÀ´×Ô˾·¨²¿µÄÕæÊµµØÖ·£¬ÀýÈç¡°mail@r77[.]fssprus[.]ru¡±£¬ÕýÎÄ»¹´øÓÐÕæÊµµÄ±êÖ¾¡£Ëù¸½µÄZIPÎļþ°üÂÞ°²×°DarkWatchmanµÄ¿ÉÖ´ÐÐÎļþ£¬ºÍ¼ÓÃܵļüÅ̼Ǽ·¨Ê½¡£


https://www.bleepingcomputer.com/news/security/russian-govt-impersonators-target-telcos-in-phishing-attacks/


5¡¢Secureworks³ÆConti±³ºóÍÅ»ïGold UlrickµÄ»î¶¯¼¤Ôö


ýÌå4ÔÂ26Èճƣ¬ËäÈ»ÀÕË÷Èí¼þContiÔÚ²»¾Ãǰ·¢ÉúÁËÊý¾Ýй©Ê¼þ£¬µ«Æä±³ºóÍÅ»ïGold UlrickµÄ¹¥»÷ÈÔÔÚ¼ÌÐø¡£ContiÊý¾ÝÐ¹Â¶ÍøÕ¾ÔÚ2021ÄêÆ½¾ùÿÔÂÁгö43¸ö±»¹¥»÷Ä¿±ê£¬ÔÚ11Ôµ½´ï·åÖµ£¬Îª95¸ö¡£2022Äê2ÔÂ27ÈÕ£¬@ContiLeaks¹ûÈ»ÁËGOLD ULRICKµÄÊý¾ÝºÍͨÐÅ£¬µ«3Ô·ݱ»¹¥»÷Ä¿±êµÄÊýÁ¿¼¤Ôö£¬½ö´ÎÓÚÈ¥Äê11ÔµķåÖµ¡£¸ÃÍÅ»ïµÄ³ÉÔ±¡°Jordan Conti¡±ÌåÏÖÊý¾Ýй¶¶ÔÆäÓ°ÏìºÜС£¬ÆäÍøÕ¾ÔÚ4ÔµÄǰËÄÌì¾ÍÌí¼ÓÁË11¸ö±»¹¥»÷Ä¿±ê¡£


https://thehackernews.com/2022/04/gold-ulrick-hackers-still-in-action.html


6¡¢KasperskyÐû²¼2022ÄêQ1 DDoS¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß


2ÔÂ25ÈÕ£¬KasperskyÐû²¼2022ÄêQ1 DDoS¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬2022ÄêµÚÒ»¼¾¶ÈµÄDDoS¸ñʽÊܵ½¶íÂÞ˹ºÍÎÚ¿ËÀ¼Ö®¼äÁ¬Ðø³åÍ»µÄÓ°Ïì¡£KasperskyÔÚµÚÒ»¼¾¶È×ܹ²¼ì²âµ½ 91052´ÎDDoS¹¥»÷£»44.34%µÄ¹¥»÷Õë¶ÔÃÀ¹ú£¬Õ¼ËùÓй¥»÷µÄ45.02%¡££»×î¶àµÄDDoS¹¥»÷(16.35%)·¢ÉúÔÚÖÜÈÕ£»´ó¶àÊý¹¥»÷£¨94.95%£©Á¬Ðø²»µ½4Сʱ£¬×µÄ¹¥»÷Á¬ÐøÁË549Сʱ£»53.64%µÄ¹¥»÷ÊÇUDPºé·º£»55.53%µÄC&C·þÎñÆ÷λÓÚÃÀ¹ú¡£


https://securelist.com/ddos-attacks-in-q1-2022/106358/