ÔËÓªÉÌUkrtelecom³ÆÆä½¹µã»ù´¡ÉèÊ©Ôâµ½´ó¹æÄ£¹¥»÷
Ðû²¼Ê±¼ä 2022-03-31ÔËÓªÉÌUkrtelecom³ÆÆä½¹µã»ù´¡ÉèÊ©Ôâµ½´ó¹æÄ£¹¥»÷
¾ÝýÌå3ÔÂ29ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬ÎÚ¿ËÀ¼Ö÷ÒªµÄÔËÓªÉÌUkrtelecomÔâµ½ÁË´ó¹æÄ£µÄÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬Ôì³ÉÁËÑÏÖØµÄÍøÂçÖÐÖ¹¡£¡£¡£¡£¡£¡£Æ¾Ö¤»¥ÁªÍø¼à¿ØÐ§ÀÍNetBlockµÄÊý¾Ý£¬£¬£¬£¬£¬£¬ÊµÊ±ÍøÂçÊý¾ÝÏÔʾÅþÁ¬ÐÔϽµµ½Õý³£Ë®Æ½µÄ13%¡£¡£¡£¡£¡£¡£ÎÚ¿ËÀ¼SSSCIPÌåÏÖ£¬£¬£¬£¬£¬£¬ºÚ¿Í¹¥»÷ÁËUkrtelecomµÄIT»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬ËûÃÇÒÑÀֳɵÖÓù´Ë´Î¹¥»÷¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬ÎªÁ˱£»£»£»£»£»¤Æä»ù´¡ÉèÊ©²¢¼ÌÐøÎªÎÚ¿ËÀ¼Îä×°²½¶ÓºÍÆäËû¾üÊÂ×éÖ¯ºÍ¿Í»§ÌṩЧÀÍ£¬£¬£¬£¬£¬£¬UkrtelecomÔÝʱÏÞÖÆÁË´ó´ó¶¼Ë½ÈËºÍÆóÒµ¿Í»§µÄЧÀÍ¡£¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/129585/cyber-warfare-2/ukraine-cyberattack-ukrtelecom.html
΢ÈíÐÞ¸´Windows 11 SMBºÍDirectXÖеÄBSODÎÊÌâ
ýÌå3ÔÂ28ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬MicrosoftÐû²¼ÁËÊÊÓÃÓÚWindows 11µÄ¿ÉÑ¡KB5011563ÀÛ»ý¸üС£¡£¡£¡£¡£¡£´Ë´Î¸üÐÂÖ÷ÒªÐÞ¸´ÁË2¸öÀ¶ÆÁËÀ»ú(BSOD)ÎÊÌ⣬£¬£¬£¬£¬£¬°üÀ¨DirectXÄÚºË×é¼þÖеÄ×èÖ¹¹ýʧ£¨0xD1£¬£¬£¬£¬£¬£¬DRIVER_IRQL_NOT_LESS_OR_EQUAL£©ºÍSMBЧÀÍÆ÷£¨srv2.sys£©ÖеÄ×èÖ¹¹ýʧ0x1E¡£¡£¡£¡£¡£¡£´Ë´Î¸üл¹ÔöÌíÁËÐí¶àÐµĹ¦Ð§£¬£¬£¬£¬£¬£¬ÀýÓÌÈçʱÏÔʾ×î¶àÈý¸ö¸ßÓÅÏȼ¶Toast֪ͨ¡£¡£¡£¡£¡£¡£Óû§¿ÉÒÔÔÚÉèÖÃÖÐÊÖ¶¯¼ì²é¸üУ¬£¬£¬£¬£¬£¬»ò´ÓMicrosoft¸üÐÂĿ¼ÊÖ¶¯ÏÂÔØ²¢×°Öô˸üС£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5011563-update-fixes-smb-directx-blue-screens/
ÎÚ¿ËÀ¼µÄ¶à¸öÍøÕ¾Ôâµ½À´×ÔÊý°Ù¸öÍøÕ¾µÄDDoS¹¥»÷
¾Ý3ÔÂ28ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬MalwareHunterTeam·¢Ã÷ÁËÒ»¸ö¶ñÒâ¾ç±¾¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÒÑʹÓÃWordPressÖеÄÎó²îÈëÇÖÁËÉϰٸöÍøÕ¾£¬£¬£¬£¬£¬£¬È»ºó²åÈë¸Ã¶ñÒâ¾ç±¾¶ÔÎÚ¿ËÀ¼µÄÍøÕ¾Ö´ÐÐDDoS¹¥»÷£¬£¬£¬£¬£¬£¬Éæ¼°ÎÚ¿ËÀ¼Õþ¸®»ú¹¹¡¢ÖÇÄÒÍÅ¡¢¹ú·À¾üÕÐļºÍ½ðÈÚµÈÏà¹ØÍøÕ¾¡£¡£¡£¡£¡£¡£Õâ¸öJavaScript¾ç±¾½«Ç¿ÖƱ»ÈëÇÖµÄä¯ÀÀÆ÷¶ÔÁгöµÄ¶àÓÐÍøÕ¾Ö´ÐÐHTTP GETÇëÇ󣬣¬£¬£¬£¬£¬Ò»´Î²»Áè¼Ý1000¸ö²¢·¢ÅþÁ¬¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬¶ÔÄ¿µÄÍøÕ¾µÄÿ¸öÇëÇó¶¼½«Ê¹ÓÃÒ»¸öËæ»úÅÌÎÊ×Ö·û´®£¬£¬£¬£¬£¬£¬ÕâÑùÇëÇó¾Í²»»áͨ¹ý»º´æÐ§ÀÍ£¨ÈçCloudflare£©ÌṩЧÀÍ£¬£¬£¬£¬£¬£¬¶øÊÇÖ±½ÓÓɱ»¹¥»÷µÄЧÀÍÆ÷ÎüÊÕ¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/hacked-wordpress-sites-force-visitors-to-ddos-ukrainian-targets/
MinervaÐû²¼¹ØÓÚÀÕË÷Èí¼þSunCryptµÄÆÊÎö±¨¸æ
3ÔÂ28ÈÕ£¬£¬£¬£¬£¬£¬Minerva LabsÐû²¼¹ØÓÚÀÕË÷Èí¼þSunCryptµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£SunCryptÊÇRaaSÍŻ£¬£¬£¬£¬£¬ÓÚ2019Äê10ÔÂÊ״ηºÆð£¬£¬£¬£¬£¬£¬ÊÇ×îÔçʹÓÃÈýÖØÀÕË÷Õ½ÂÔµÄ×éÖ¯Ö®Ò»¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬´Ë2022 SunCrypt±äÖÖÔöÌíÁËÐí¶àÐµĹ¦Ð§£¬£¬£¬£¬£¬£¬°üÀ¨ÖÕÖ¹Àú³Ì¡¢×èֹЧÀͲ¢É¨³ýÀÕË÷Èí¼þÖ´Ðеĺۼ£¡£¡£¡£¡£¡£¡£¸ÃÀÕË÷Èí¼þ»¹Ê¹ÓÃÒ»¸öwinlogon.exe»á¼ûÁîÅÆ£¬£¬£¬£¬£¬£¬²¢Í¨¹ýʹÓÃSetThreadToken APIŲÓý«ÆäÉèÖÃΪÆäÖ÷Ï̡߳£¡£¡£¡£¡£¡£
https://blog.minerva-labs.com/suncrypt-ransomware-gains-new-abilities-in-2022
Rapid7Ðû²¼¹ØÓÚ2021ÄêÇå¾²Îó²îÌ¬ÊÆµÄÆÊÎö±¨¸æ
3ÔÂ28ÈÕ£¬£¬£¬£¬£¬£¬Rapid7Ðû²¼ÁËÆä×îеÄÎó²îÌ¬ÊÆÆÊÎö±¨¸æ£¬£¬£¬£¬£¬£¬Ñо¿ÁË2021Äê×îÏÔÖøµÄÇå¾²Îó²îºÍÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£2021ÄêµÄÍþвÖУ¬£¬£¬£¬£¬£¬Áè¼Ý50%µÄʼÓÚÁãÈÕÎó²î¡£¡£¡£¡£¡£¡£¸Ã±¨¸æÑо¿ÁË50¸öÎó²î£¬£¬£¬£¬£¬£¬ÆäÖÐÓÐ43¸öÒѱ»Ê¹Ó㬣¬£¬£¬£¬£¬½üÒ»°ëÊÇÔÚÐÞ¸´Ö®Ç°±»ÓÃÓÚÁãÈÕ¹¥»÷¡£¡£¡£¡£¡£¡£ÓÃ×÷ÁãÈÕ¹¥»÷µÄÎó²îÊýÄ¿±È2020ÄêÔöÌíÁË100%£¬£¬£¬£¬£¬£¬ÇÒʹÓÃµÄÆ½¾ùʱ¼ä´Ó2020ÄêµÄ42ÌìϽµµ½2021ÄêµÄ12Ì죻£»£»£»£»66%µÄÎó²î±»¹éÀàΪÆÕ±éÍþв£¬£¬£¬£¬£¬£¬ÆäÖÐ60%ÒÔÉϱ»ÓÃÓÚÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£
https://www.rapid7.com/info/2021-vulnerability-intelligence-report/
CISAÓëÄÜÔ´²¿ÁªºÏÐû²¼Õë¶ÔUPS×°±¸µÄ¹¥»÷µÄ×Éѯ
3ÔÂ29ÈÕ£¬£¬£¬£¬£¬£¬ÃÀ¹úCISAÓëÄÜÔ´²¿ÁªºÏÐû²¼ÁËÕë¶Ô²»ÖÐÖ¹µçÔ´(UPS)×°±¸µÄ¹¥»÷µÄÇå¾²×Éѯ¡£¡£¡£¡£¡£¡£Í¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬ÕâЩ»ú¹¹·¢Ã÷¹¥»÷Õßͨ³£Í¨¹ýδ¸ü¸ÄµÄĬÈÏÓû§ÃûºÍÃÜÂëÀ´»á¼ûÖÖÖÖÁªÍøµÄUPS×°±¸,×éÖ¯¿ÉÒÔͨ¹ý´Ó»¥ÁªÍøÉÑþ³ØýÖÎÀí½Ó¿ÚÀ´»º½â¶ÔÆäUPS×°±¸µÄ¹¥»÷¡£¡£¡£¡£¡£¡£CISAºÍDOE»¹ÌṩÁËÆäËüµÄ»º½â²½·¥£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨²éÕÒ×éÖ¯ÍøÂçÉϵÄËùÓÐUPSºÍÆäËüÓ¦¼±µçԴϵͳ£¬£¬£¬£¬£¬£¬²¢È·±£ËüÃÇÎÞ·¨Í¨¹ýInternet»á¼û¡£¡£¡£¡£¡£¡£
https://www.cisa.gov/uscert/ncas/current-activity/2022/03/29/mitigating-attacks-against-uninterruptable-power-supply-devices
Çå¾²¹¤¾ß
Gitcolombo
OSINT ¹¤¾ß£¬£¬£¬£¬£¬£¬ÓÃÓÚ´Ó git ´æ´¢¿âÖÐÌáÈ¡ÓйØÖ°Ô±µÄÐÅÏ¢¡£¡£¡£¡£¡£¡£
https://github.com/soxoj/gitcolombo
ScheduleRunner
AC# ¹¤¾ß£¬£¬£¬£¬£¬£¬¿É¸üÎÞаµØ×Ô½ç˵ÍýÏëʹÃü£¬£¬£¬£¬£¬£¬ÒÔʵÏÖºì¶Ó²Ù×÷Öеij¤ÆÚÐԺͺáÏòÒÆ¶¯¡£¡£¡£¡£¡£¡£
https://github.com/netero1010/ScheduleRunner
phantun
Ò»¸öÇáÁ¿¼¶ºÍ¿ìËÙµÄ UDP µ½ TCP »ìÏýÆ÷¡£¡£¡£¡£¡£¡£
https://github.com/dndx/phantun/
Çå¾²ÆÊÎö
AnonymousºÚ¿ÍÈëÇÖ 2 ¼Ò¶íÂÞ˹¹¤Òµ¹«Ë¾£¬£¬£¬£¬£¬£¬Ð¹Â¶ 112GB Êý¾Ý
https://www.hackread.com/anonymous-hack-russian-industrial-firms-data-leak/
Ð嵀 Windows Çå¾²¹¦Ð§¿É×èÖ¹Ò×Êܹ¥»÷µÄÇý¶¯³ÌÐò
https://www.bleepingcomputer.com/news/microsoft/new-windows-security-feature-blocks-vulnerable-drivers/
¶íÂÞ˹Òò×°±¸Ç·È±¶øÃæÁÙ»¥ÁªÍøÖÐÖ¹
https://www.bleepingcomputer.com/news/technology/russia-facing-internet-outages-due-to-equipment-shortage/
΢ÈíΪ AMD Çý¶¯µÄ Surface Laptop 4 Ðû²¼¹Ì¼þ¸üÐÂ
https://news.softpedia.com/news/microsoft-releases-firmware-update-for-amd-powered-surface-laptop-4-535118.shtml
Trend MicroÅû¶Purple Fox½üÆÚ¹¥»÷»î¶¯µÄϸ½ÚÐÅÏ¢
https://www.trendmicro.com/en_us/research/22/c/purple-fox-uses-new-arrival-vector-and-improves-malware-arsenal.html


¾©¹«Íø°²±¸11010802024551ºÅ