ʹÓÃGoogle Play·Ö·¢µÄÐÂľÂíXenomorphÕë¶ÔÅ·ÖÞµØÇø

Ðû²¼Ê±¼ä 2022-02-24

ʹÓÃGoogle Play·Ö·¢µÄÐÂľÂíXenomorphÕë¶ÔÅ·ÖÞµØÇø


¾ÝýÌå2ÔÂ21ÈÕ±¨µÀ£¬£¬£¬Çå¾²¹«Ë¾ThreatFabric·¢Ã÷ÁËеÄAndroidÒøÐÐľÂíXenomorph¡£¡£ ¡£¡£¸ÃľÂíαװ³ÉÐÔÄÜÌáÉýÓ¦ÓóÌÐò£¨ÀýÈçFast Cleaner£©Í¨¹ýGoogle PlayÊÐËÁ·Ö·¢£¬£¬£¬Òѱ»×°ÖÃÁè¼Ý50000´Î¡£¡£ ¡£¡£ËüÏÖÔÚÈÔ´¦ÓÚÔçÆÚ¿ª·¢½×¶Î£¬£¬£¬Ä¿µÄÊÇÎ÷°àÑÀ¡¢ÆÏÌÑÑÀ¡¢Òâ´óÀûºÍ±ÈÀûʱµÈÅ·ÖÞ¹ú¼ÒµÄ56¼Ò½ðÈÚ»ú¹¹¡£¡£ ¡£¡£Ñо¿Ö°Ô±»¹·¢Ã÷¸ÃľÂíµÄ´úÂëÓëAlienÓÐËùÖØµþ£¬£¬£¬ÕâÅú×¢¶þÕß±£´æÄ³ÖÖÁªÏµ£ºÒªÃ´XenomorphÊÇAlienµÄ¼ÌÈÎÕߣ¬£¬£¬ÒªÃ´XenomorphµÄ¿ª·¢Ö°Ô±Ò»Ö±ÔÚÑо¿Alien¡£¡£ ¡£¡£


https://thehackernews.com/2022/02/xenomorph-android-banking.html


ÃÀ¹úMeyerÔâµ½ContiÀÕË÷¹¥»÷µ¼Ö´ó×ÚÔ±¹¤ÐÅϢй¶


¾Ý2ÔÂ21ÈÕ±¨µÀ£¬£¬£¬ÃÀ¹ú×î´óµÄ´¶¾ß¹«Ë¾MeyerÔâµ½ContiÀÕË÷¹¥»÷¡£¡£ ¡£¡£¹¥»÷±¬·¢ÔÚ2021Äê10ÔÂ25ÈÕ£¬£¬£¬¼ì²âµ½¹¥»÷ºó¸Ã¹«Ë¾Á¬Ã¦Õö¿ªÊӲ죬£¬£¬²¢ÓÚ12ÔÂ1ÈÕÈ·¶¨MeyerÔ±¹¤µÄÐÅÏ¢¿ÉÄÜÒÑÔ⵽δ¾­ÊÚȨµÄ»á¼û¡£¡£ ¡£¡£Ñо¿Ö°Ô±ÔÚContiµÄÐÅÏ¢Ð¹Â¶ÍøÕ¾·¢Ã÷Ò»¸ö¿É×·Ëݵ½11ÔÂ7ÈÕµÄÁбí£¬£¬£¬¾Ý³Æ°üÀ¨ÁËÔÚMeyerÇÔÈ¡µÄ2%µÄÊý¾Ý£¬£¬£¬µ«ÖÁ½ñÈÔδÐû²¼Ê£ÓàµÄ98%¡£¡£ ¡£¡£MeyerÌåÏÖ½«ÎªÊÜÓ°ÏìµÄÔ±¹¤¼°Æä¾ìÊôÌṩÁ½ÄêµÄÉí·Ý±£»£»£»¤Ð§ÀÍ¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/cookware-giant-meyer-discloses-cyberattack-that-impacted-employees/


Ahn Lab·¢Ã÷CryptBotбäÌåʹÓõÁ°æÈí¼þÍøÕ¾Èö²¥


Ahn LabÔÚ2ÔÂ21ÈÕÐû²¼µÄÑо¿ÏÔʾ£¬£¬£¬CryptBotбäÌåÕýÔÚͨ¹ýµÁ°æÈí¼þÍøÕ¾¾ÙÐÐÈö²¥¡£¡£ ¡£¡£CryptBotÊÇÒ»ÖÖWindowsÐÅÏ¢ÇÔÈ¡³ÌÐò£¬£¬£¬¿É´ÓÄ¿µÄÇÔÈ¡ä¯ÀÀÆ÷ƾ֤¡¢cookie¡¢¼ÓÃÜÇ®±ÒÇ®°üºÍÐÅÓÿ¨µÈÐÅÏ¢¡£¡£ ¡£¡£¹¥»÷ÕßʹÓÃÆÆ½âÈí¼þºÍÃÜÔ¿ÌìÉúÆ÷µÈÍøÕ¾·Ö·¢¶ñÒâÈí¼þ£¬£¬£¬²¢Í¨¹ýËÑË÷ÒýÇæÓÅ»¯½«ÕâÐ©ÍøÕ¾ÔڹȸèµÄËÑË÷Ч¹ûÖÐÖö¥¡£¡£ ¡£¡£±ðµÄ£¬£¬£¬¸Ã°æ±¾±ÈÒÔÍùÓнϴóµÄ¸Ä¶¯£¬£¬£¬É¾³ýÁË·´É³ºÐ¹¦Ð§ºÍ±¸ÓÃC2µÈÈßÓàµÄ¹¦Ð§£¬£¬£¬²¢ÒÑ¿ÉÊÊÓÃÓÚËùÓÐChrome°æ±¾¡£¡£ ¡£¡£


https://asec.ahnlab.com/en/31802/


KasperskyÐû²¼2021ÄêÒÆ¶¯¶ñÒâÈí¼þÌ¬ÊÆµÄÆÊÎö±¨¸æ


2ÔÂ21ÈÕ£¬£¬£¬KasperskyÐû²¼ÁË2021ÄêÒÆ¶¯¶ñÒâÈí¼þÌ¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£ ¡£¡£±¨¸æÖ¸³ö£¬£¬£¬KasperskyÔÚ2021Äê×ܼƼì²âµ½3464756¸ö¶ñÒâ×°Öðü¡¢97661¸öеÄÒÆ¶¯ÒøÐÐľÂíºÍ17372¸öеÄÒÆ¶¯ÀÕË÷Èí¼þ¡£¡£ ¡£¡£ÊÜÒÆ¶¯¶ñÒâÈí¼þ¹¥»÷×î¶àµÄ¹ú¼ÒÊÇÒÁÀÊ£¬£¬£¬Æä´ÎÊÇÖйú¡¢É³Ìذ¢À­²®ºÍ°¢¶û¼°ÀûÑÇ¡£¡£ ¡£¡£¼ì²âµ½µÄ¶ñÒâÈí¼þÖÐ¹ã¸æÈí¼þ£¨42.42%£©µÄÕ¼±È×î´ó£¬£¬£¬Æä´ÎΪRiskToolÓ¦ÓóÌÐò£¨35.27%£©ºÍľÂí£¨8.86%£©¡£¡£ ¡£¡£


https://securelist.com/mobile-malware-evolution-2021/105876/


Trend MicroÅû¶ÐµÄMac¶ñÒâÍÚ¿óÈí¼þµÄÊÖÒÕϸ½Ú


Trend MicroÔÚ2ÔÂ21ÈÕÅû¶ÁËÐÂMac¶ñÒâÍÚ¿óÈí¼þµÄÊÖÒÕϸ½Ú¡£¡£ ¡£¡£¶ñÒâÈí¼þÑù±¾±»¼ì²âΪCoinminer.MacOS.MALXMR.H£¬£¬£¬ÓÚ2022Äê1Ô³õÊ״α»·¢Ã÷£¬£¬£¬ÊÇÒ»¸öMach-OÎļþ¡£¡£ ¡£¡£Ö´ÐÐʱ£¬£¬£¬ËüʹÓÃAuthorizationExecuteWithPrivileges APIͨ¹ýÌáÐÑÓû§ÊäÈëÆ¾Ö¤À´ÌáÉýȨÏÞ¡£¡£ ¡£¡£³ý´ËÖ®Í⣬£¬£¬¸ÃÑù±¾»¹Ê¹ÓÃÁËi2pd£¨ÓÖÃûI2PÊØ»¤³ÌÐò£©À´Òþ²ØÆäÍøÂçÁ÷Á¿£¬£¬£¬¶øÆäËüMac¶ñÒâÈí¼þͨ³£Ê¹ÓÃTor¡£¡£ ¡£¡£


https://www.trendmicro.com/en_us/research/22/b/latest-mac-coinminer-utilizes-open-source-binaries-and-the-i2p-network.html


Ñо¿ÍŶӷ¢Ã÷Õë¶ÔMicrosoft SQLÊý¾Ý¿âµÄ¹¥»÷»î¶¯


ýÌå2ÔÂ21Èճƣ¬£¬£¬Ñо¿ÍŶӷ¢Ã÷ÁËÕë¶ÔMicrosoft SQLÊý¾Ý¿âµÄ¹¥»÷»î¶¯¡£¡£ ¡£¡£¹¥»÷ÕßÊ×ÏÈɨÃèTCP¶Ë¿Ú1433¿ª·ÅµÄЧÀÍ£¬£¬£¬È»ºóͨ¹ý±©Á¦ÆÆ½âºÍ×ֵ乥»÷À´ÆÆ½âÃÜÂë¡£¡£ ¡£¡£Ò»µ©»ñµÃÖÎÀíÔ±ÕÊ»§µÄ»á¼ûȨÏÞ£¬£¬£¬¹¥»÷Õ߾ͻáÁ¬Ã¦×°ÖÃLemon Duck¡¢KingMinerºÍVollgarµÈ¶ñÒâ¿ó¹¤Èí¼þ¡£¡£ ¡£¡£×îºó£¬£¬£¬ËûÃÇ»¹»áʹÓÃCobalt StrikeÔÚÊý¾Ý¿âÖн¨ÉèºóÃÅ£¬£¬£¬ÒÔ¼á³Ö³¤ÆÚÐÔ²¢¾ÙÐкáÏòÒÆ¶¯¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/vulnerable-microsoft-sql-servers-targeted-with-cobalt-strike/



Çå¾²¹¤¾ß


coraza


golang ÆóÒµ¼¶ Web Ó¦Ó÷À»ðǽ¿ò¼Ü£¬£¬£¬Ö§³Ö Modsecurity µÄ seclang ÓïÑÔ£¬£¬£¬Óë OWASP Core Ruleset 100% ¼æÈÝ¡£¡£ ¡£¡£


https://github.com/corazawaf/coraza


m3


ÒÆ¶¯¶ñÒâÈí¼þÄ£Äâ¿ò¼Ü£¨¼ò³Æm3£©ÊÇÒ»¸ö¼òÆÓÇÒ¿ÉÀ©Õ¹µÄ Android »úеÈËÄ£Äâ¿ò¼Ü¡£¡£ ¡£¡£


https://github.com/ThisIsLibra/m3/


SecureBank


°üÀ¨ËùÓÐ OWASP TOP 10 Çå¾²Îó²îµÄ½ðÈڿƼ¼Ó¦ÓóÌÐò¡£¡£ ¡£¡£


https://ssrd.gitbook.io/securebank/


Talisman 


¿É½«hook×°Öõ½´æ´¢¿â£¬£¬£¬ÒÔÈ·±£Ç±ÔÚµÄÃô¸ÐÐÅÏ¢²»»áÍÑÀ뿪·¢Ö°Ô±µÄÊÂÇéÕ¾¡£¡£ ¡£¡£


https://github.com/thoughtworks/talisman#what-is-talisman


SharpCookieMonster


cookie-crimesÄ£¿£¿£¿£¿éµÄÒ»¸ö Sharp ¶Ë¿Ú£¬£¬£¬Õâ¸ö C# ÏîÄ¿½«ÎªËùÓÐÕ¾µãת´¢ cookie¡£¡£ ¡£¡£


https://github.com/m0rv4i/SharpCookieMonster



Çå¾²ÆÊÎö


ÕûÊýÒç³ö£ºËüÊÇÔõÑù±¬·¢µÄÒÔ¼°ÔõÑùÔ¤·À


https://www.welivesecurity.com/2022/02/21/integer-overflow-how-it-occur-can-be-prevented/


¹¥»÷ÕßʹÓÃSMS PVA ЧÀ;ÙÐжñÒâ»î¶¯


https://securityaffairs.co/wordpress/128242/cyber-crime/sms-pva-services.html


ÆÏÌÑÑÀÍþв±¨¸æ£º2021 ÄêµÚËÄÐò¶È


https://seguranca-informatica.pt/threat-report-portugal-q3-2021/


΢Èí¸üÐÂÁË Your Phone Ó¦ÓóÌÐòµÄÒ»Ïîй¦Ð§


https://news.softpedia.com/news/microsoft-announces-a-new-feature-for-the-your-phone-app-534911.shtml


CVE-2022-0290£ºChrome RenderFrameHostImplÊͷźóʹÓÃÎó²î


https://packetstormsecurity.com/files/166080/GS20220221155706.tgz