×°ÖÃWindowsÇå¾²Æô¶¯DBXµÄÇå¾²¸üÐÂʱ¿ÉÄÜ·ºÆð¹ýʧ
Ðû²¼Ê±¼ä 2022-08-16
¾Ý8ÔÂ15ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬Î¢ÈíÌåÏÖ£¬£¬£¬£¬£¬£¬µ±Óû§ÔÚÏÖÔÚÖ§³ÖµÄ²Ù×÷ϵͳºÍÆóÒµ¼¶Ð§ÀÍÆ÷ÉÏ×°ÖÃWindows KB5012170Çå¾²¸üÐÂʱ£¬£¬£¬£¬£¬£¬¿ÉÄ᷺ܻÆð0x800f0922¹ýʧ¡£¡£¡£¡£KB5012170¸üÐÂÊÇÇå¾²Æô¶¯DBXµÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬¸Ã´æ´¢¿â°üÀ¨Í³Ò»¿ÉÀ©Õ¹¹Ì¼þ½Ó¿Ú(UEFI)Ö¸µ¼¼ÓÔØ³ÌÐòµÄ×÷·ÏÊðÃû¡£¡£¡£¡£ÉÏÖÜ£¬£¬£¬£¬£¬£¬EclypsiumÔøÅû¶ÁË3¸öµÚÈý·½Ö¸µ¼¼ÓÔØ³ÌÐòÖÐÈÆ¹ýÇå¾²Æô¶¯µÄÎó²î¡£¡£¡£¡£Î¢ÈíÖ¸³ö£¬£¬£¬£¬£¬£¬¿ÉÒÔ½«UEFI¸üе½¹©Ó¦ÉÌÌṩµÄ×îаæÔÀ´»º½â¸ÃÎÊÌ⣬£¬£¬£¬£¬£¬²¢½¨ÒéÖ»ÓÐÔÚÈ·±£×°±¸ÔËÐÐÁ˹©Ó¦ÉÌÌṩµÄÎÞÎó²îµÄÖ¸µ¼¼ÓÔØ³ÌÐò°æ±¾Ö®ºóÔÙ¸üÐÂDBX¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/windows-kb5012170-secure-boot-dbx-update-may-fail-with-0x800f0922-error/
2¡¢AndroidÒøÐÐľÂíSOVA»Ø¹éÐÂÔöÀÕË÷Èí¼þµÈ¹¦Ð§
¾ÝCleafy 8ÔÂ11ÈÕÅû¶£¬£¬£¬£¬£¬£¬AndroidÒøÐÐľÂíSOVA¾íÍÁÖØÀ´²¢ÐÂÔö¶àÖÖ¹¦Ð§¡£¡£¡£¡£2022Äê7Ô£¬£¬£¬£¬£¬£¬SOVA¶ñÒâÈí¼þÐû²¼Á˵Ú4¸ö°æ±¾£¬£¬£¬£¬£¬£¬ÆäÄ¿µÄÓ¦ÓóÌÐòÔöÌíµ½200¸ö£¬£¬£¬£¬£¬£¬²¢ÐÂÔöVNC¹¦Ð§ÓÃÓÚÉè±¹ØÁ¬Äڲơ£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±»¹·¢Ã÷ÁËSOVA v5µÄÔçÆÚ°æ±¾£¬£¬£¬£¬£¬£¬Ëü¾ÙÐÐÁË´ó×Ú´úÂëˢв¢Ìí¼ÓÀÕË÷Èí¼þÄ£¿£¿£¿éµÈй¦Ð§£¬£¬£¬£¬£¬£¬¸ÃÄ£¿£¿£¿éʹÓÃAES¼ÓÃÜÀ´Ëø¶¨±»Ñ¬È¾×°±¸ÖеÄËùÓÐÎļþ£¬£¬£¬£¬£¬£¬²¢¸½¼ÓÀ©Õ¹Ãû.enc¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬µÚ5°æ»¹Ã»ÓоÙÐÐÆÕ±éÈö²¥£¬£¬£¬£¬£¬£¬ÇÒ¸ÃÔçÆÚÑù±¾ÖÐȱÉÙVNCÄ£¿£¿£¿é£¬£¬£¬£¬£¬£¬ÒÔÊÇÕâ¸ö°æ±¾ºÜ¿ÉÄÜÈÔÔÚ¿ª·¢ÖС£¡£¡£¡£
https://www.cleafy.com/cleafy-labs/sova-malware-is-back-and-is-evolving-rapidly
3¡¢CybleɨÃè·¢Ã÷Áè¼Ý9000̨ÔÚÍøÉÏ̻¶µÄVNCЧÀÍÆ÷
¾Ý8ÔÂ14ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬CybleÑо¿Ö°Ô±·¢Ã÷ÁËÖÁÉÙ9000̨̻¶µÄVNC£¨ÐéÄâÍøÂçÅÌË㣩ЧÀÍÆ÷£¬£¬£¬£¬£¬£¬ÎÞÐèÉí·ÝÑéÖ¤¼´¿É»á¼ûºÍʹÓᣡ£¡£¡£ÕâЩ̻¶µÄʵÀý¿É±»¹¥»÷ÕßÓÃÀ´»á¼ûÄÚ²¿ÍøÂ磬£¬£¬£¬£¬£¬´ó´ó¶¼Î»ÓÚÈðµä¡¢ÃÀ¹ú¡¢Î÷°àÑÀºÍ°ÍÎ÷µÈ¹ú¡£¡£¡£¡£ÎªÏàʶ¹¥»÷Õß¹¥»÷VNCЧÀÍÆ÷µÄƵÂÊ£¬£¬£¬£¬£¬£¬Cyble¼à¿ØÁ˶ÔVNCµÄĬÈ϶˿Ú5900µÄ¹¥»÷£¬£¬£¬£¬£¬£¬·¢Ã÷Ò»¸öÔÂÄÚÓÐÁè¼Ý600Íò¸öÇëÇ󡣡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬ºÚ¿ÍÂÛ̳¶Ô̻¶»òÆÆ½âµÄVNC»á¼ûµÄÐèÇóÒ²ºÜ¸ß£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀÄÓÃVNC¾ÙÐжñÒâ²Ù×÷£¬£¬£¬£¬£¬£¬Èç·¿ªÎĵµ¡¢ÏÂÔØÎļþºÍÖ´ÐÐí§ÒâÏÂÁîµÈ¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/over-9-000-vnc-servers-exposed-online-without-a-password/
4¡¢·ÒÀ¼Òé»áµÄÍøÕ¾ÔÚÔâµ½¾Ü¾øÐ§À͹¥»÷ºóÔÝʱ¹Ø±Õ
¾ÝýÌå8ÔÂ12ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬·ÒÀ¼Òé»áµÄÍøÕ¾ÒòÔâµ½¹¥»÷ÔÝʱ¹Ø±Õ¡£¡£¡£¡£·ÒÀ¼Òé»áÔÚTwitterÉϽÒÏþÉùÃ÷³Æ£¬£¬£¬£¬£¬£¬ÉÏÖܶþÏÂÖç2µã30·Ö×óÓÒ£¬£¬£¬£¬£¬£¬Òé»áµÄÍâ²¿ÍøÕ¾Ôâµ½Á˾ܾøÐ§À͹¥»÷£¬£¬£¬£¬£¬£¬Òé»á¡¢Ð§ÀÍÌṩÉ̺ÍÍøÂçÇå¾²ÖÐÐĽÓÄÉÁËÏìÓ¦²½·¥À´ÏÞÖÆ¹¥»÷¡£¡£¡£¡£Òé»áÔÚÉÏÖÜÈý·¢Îijƣ¬£¬£¬£¬£¬£¬¸ÃÍøÕ¾ÒÑÓÚÖܶþÍíÉϻָ´Õý³£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬Õë¶ÔÒé»áµÄ¹¥»÷±¬·¢ÔڰݵÇÇ©ÊðÖ§³Ö·ÒÀ¼ºÍÈðµä¼ÓÈë±±Ô¼µÄÎļþµÄͳһÌì¡£¡£¡£¡£
https://www.databreaches.net/finlands-parliament-hit-with-cyberattack-following-us-move-to-admit-the-country-to-nato/
5¡¢ÐµÄPyPI°üsecretslib¿ÉÔÚLinuxÉÏ×°ÖüÓÃÜ¿ó¹¤
SonatypeÔÚ8ÔÂ11ÈÕ³ÆÆä·¢Ã÷ÁËÒ»¸öеÄPyPI°üsecretslib£¬£¬£¬£¬£¬£¬¿ÉÔÚLinuxÉÏ×°ÖüÓÃܿ󹤡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÓÚ2022Äê8ÔÂ6ÈÕÐû²¼£¬£¬£¬£¬£¬£¬±»ÐÎòΪʹÉñÃØÆ¥ÅäºÍÑéÖ¤±äµÃÈÝÒ×£¬£¬£¬£¬£¬£¬ÔÚɾ³ýǰ±»ÒÑÏÂÔØ93´Î¡£¡£¡£¡£Ëü»áÔÚLinuxÄÚ´æÖУ¨Ö±½Ó´ÓRAM£©ÔËÐÐMonero(XMR)¿ó¹¤£¬£¬£¬£¬£¬£¬ÕâÖÖÊÖÒÕÖ÷ÒªÓÉÎÞÎļþ¶ñÒâÈí¼þºÍ¼ÓÃܳÌÐòʹÓᣡ£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâ»î¶¯ÏÕЩûÓÐÁôÏÂÈκÎ×ã¼££¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃÁËÃÀ¹úÄÜÔ´²¿×ÊÖúµÄʵÑéÊÒ(ANL.gov)µÄÈí¼þ¹¤³ÌʦµÄÉí·ÝºÍÁªÏµÐÅÏ¢À´ÔöÌí¿ÉÐŶȡ£¡£¡£¡£
https://blog.sonatype.com/pypi-package-secretslib-drops-fileless-linux-malware-to-mine-monero
6¡¢KELAÐû²¼2022ÄêµÚ¶þ¼¾¶ÈÀÕË÷Èí¼þÌ¬ÊÆµÄÆÊÎö±¨¸æ
8ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬ÍøÂçÇ鱨¹«Ë¾KELAÐû²¼Á˹ØÓÚÀÕË÷Èí¼þµÄÆÊÎö±¨¸æ¡£¡£¡£¡£ÀÕË÷ÍÅ»ïÒ»Ö±Éú³¤²¢Íþв×ÅÌìϸ÷µØµÄ×éÖ¯£¬£¬£¬£¬£¬£¬Ö»¹Ü²¿·ÖÍÅ»ïÔÚ2022ÄêQ2ïÔÌ»ò×èÖ¹Á˻£¬£¬£¬£¬£¬£¬µ«ÏñBlack BastaÕâÑùµÄÐÂÍŻﷺÆð²¢¼ÌÐøÀÕË÷Ç®²Æ¡£¡£¡£¡£2022ÄêQ2ÀÕË÷¹¥»÷»î¶¯ïÔÌÁË7%£¬£¬£¬£¬£¬£¬Æ½¾ùÿ¸öÔ¼ì²âµ½216´Î¹¥»÷£»£»£»£»×î»îÔ¾µÄÀÕË÷ÍÅ»ïÊÇLockBit¡¢Black Basta¡¢Alphv¡¢ContiºÍVice Society£¬£¬£¬£¬£¬£¬¶¼Òѹ¥»÷Áè¼Ý40¸öÄ¿µÄ£»£»£»£»ÀÕË÷¹¥»÷ÕßÖ÷ÒªÕë¶ÔµÄÊÇÖÆÔìÒµºÍ¹¤Òµ¡£¡£¡£¡£
https://ke-la.com/wp-content/uploads/2022/08/KELA-RESEARCH_Ransomware-Victims-and-Network-Access-Sales_Q2-2022.pdf


¾©¹«Íø°²±¸11010802024551ºÅ