åÚÏëUEFI¹Ì¼þÇý¶¯³ÌÐòÖеÄÎó²îÓ°ÏìÉϰٿîÌõ¼Ç±¾µçÄÔ

Ðû²¼Ê±¼ä 2022-04-20

1¡¢åÚÏëUEFI¹Ì¼þÇý¶¯³ÌÐòÖеÄÎó²îÓ°ÏìÉϰٿîÌõ¼Ç±¾µçÄÔ


¾ÝýÌå4ÔÂ19ÈÕ±¨µÀ£¬£¬£¬ £¬£¬£¬£¬ESETÑо¿Ö°Ô±·¢Ã÷Ó°ÏìåÚÏëÉϰٿîÌõ¼Ç±¾µçÄÔµÄ3¸öÎó²î¡£¡£ ¡£¡£ÆäÖÐÁ½¸öÎó²î£¨CVE-2021-3971ºÍCVE-2021-3972£©¿ÉÓÃÀ´½ûÓöԴ洢UEFI¹Ì¼þµÄSPIÉÁ´æÐ¾Æ¬µÄ± £»£» £» £»£»¤£¬£¬£¬ £¬£¬£¬£¬²¢¹Ø±ÕUEFIÇå¾²Æô¶¯¹¦Ð§£¬£¬£¬ £¬£¬£¬£¬Ê¹¶ñÒâÈí¼þÔÚÏµÍ³ÖØÆôºóÈԿɱ£´æ¡£¡£ ¡£¡£µÚÈý¸öÎó²î£¨CVE-2021-3970£©±£´æÓÚLenovoVariable SMI´¦Öóͷ£³ÌÐòÖУ¬£¬£¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÆäÒÔÌáÉýµÄȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£ ¡£¡£ESETÓÚ2021Äê10ÔÂ11ÈÕÏòåÚÏ뱨¸æÕâЩÎó²î£¬£¬£¬ £¬£¬£¬£¬åÚÏëÓÚ4ÔÂ12ÈÕÐû²¼²¹¶¡¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/lenovo-uefi-firmware-driver-bugs-affect-over-100-laptop-models/


2¡¢CISAºÍFBIÁªºÏÐû²¼¹ØÓÚÇø¿éÁ´ÐÐÒµµÄÍøÂçÇå¾²×Éѯ


4ÔÂ18ÈÕ£¬£¬£¬ £¬£¬£¬£¬ÃÀ¹úFBI¡¢CISAºÍ²ÆÎñ²¿ÁªºÏÐû²¼Á˹ØÓÚÇø¿éÁ´ÐÐÒµµÄÍøÂçÇå¾²×Éѯ¡£¡£ ¡£¡£¸Ã×Éѯָ³ö£¬£¬£¬ £¬£¬£¬£¬³¯ÏÊAPT×éÖ¯LazarusÃé×¼Çø¿éÁ´ÊÖÒպͼÓÃÜÇ®±ÒÐÐÒµµÄÖÖÖÖ×éÖ¯£¬£¬£¬ £¬£¬£¬£¬°üÀ¨¼ÓÃÜÇ®±ÒÉúÒâËù¡¢È¥ÖÐÐÄ»¯½ðÈÚ (DeFi) ЭæÅºÍ¼ÓÃÜÇ®±ÒÉÌÒµ¹«Ë¾µÈ¡£¡£ ¡£¡£¹¥»÷ÕßʹÓÃÖÖÖÖͨѶƽ̨¶ÔÄ¿µÄ¾ÙÐÐÉç»á¹¤³Ì¹¥»÷£¬£¬£¬ £¬£¬£¬£¬ÓÕʹÆäÔÚWindows»òmacOSϵͳÉÏÏÂÔØÄ¾Âí»¯µÄ¼ÓÃÜÇ®±ÒÓ¦Ó㬣¬£¬ £¬£¬£¬£¬ÒÔÇÔȡ˽Կ»òÀÄÓÃÆäËüÎó²î¡£¡£ ¡£¡£¸Ãͨ¸æÌṩÁË´ËÀà»î¶¯Ïà¹ØµÄÕ½ÂÔ¡¢ÊÖÒպͳÌÐò(TTP)ºÍIOC£¬£¬£¬ £¬£¬£¬£¬ÒÔ×ÊÖú×é֯ʶ±ð²¢µÖÓùÕë¶Ô¼ÓÃÜÇ®±ÒµÄÍøÂç¹¥»÷¡£¡£ ¡£¡£


https://www.cisa.gov/uscert/ncas/alerts/aa22-108a


3¡¢CloudSEK·¢Ã÷ð³äWin11Éý¼¶·Ö·¢Inno StealerµÄ»î¶¯


ýÌå4ÔÂ18ÈÕ±¨µÀ£¬£¬£¬ £¬£¬£¬£¬CloudSEK·¢Ã÷ð³äWin11Éý¼¶·Ö·¢Inno StealerµÄ»î¶¯¡£¡£ ¡£¡£¸Ã»î¶¯ÏÖÔںܻîÔ¾£¬£¬£¬ £¬£¬£¬£¬Í¨¹ýËÑË÷Ч¹ûͶ¶¾À´ÍÆËÍð³äWindows 11ÍÆ¹ãÒ³ÃæµÄ´¹ÂÚÍøÕ¾¡£¡£ ¡£¡£Ä¿µÄµã»÷Á¬Ã¦ÏÂÔØºó»á»ñµÃÒ»¸öISOÎļþ£¬£¬£¬ £¬£¬£¬£¬ÆäÖаüÀ¨Inno StealerµÄ¼ÓÔØ³ÌÐò¡£¡£ ¡£¡£Ð¶ñÒâÈí¼þÓÉÓÚʹÓÃÁËInno Setup Windows×°ÖóÌÐò¶øµÃÃû£¬£¬£¬ £¬£¬£¬£¬ÓëÏÖÔÚÊ¢ÐÐµÄÆäËüÐÅÏ¢ÇÔÈ¡³ÌÐòµÄ´úÂëûÓÐÈκÎÏàËÆÖ®´¦£¬£¬£¬ £¬£¬£¬£¬¿ÉÇÔÈ¡ä¯ÀÀÆ÷cookieºÍ´æ´¢µÄƾ֤¡¢¼ÓÃÜÇ®±ÒÇ®°üÖеÄÊý¾ÝÒÔ¼°ÎļþϵͳµÄÊý¾Ý¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/unofficial-windows-11-upgrade-installs-info-stealing-malware/


4¡¢Çå¾²¹«Ë¾PRODAFTÐû²¼ÀÕË÷Èí¼þPYSAµÄÉî¶ÈÆÊÎö±¨¸æ


4ÔÂ14ÈÕ£¬£¬£¬ £¬£¬£¬£¬Çå¾²¹«Ë¾PRODAFTÐû²¼Á˹ØÓÚÀÕË÷Èí¼þPYSAµÄÉî¶ÈÆÊÎö±¨¸æ¡£¡£ ¡£¡£PYSAÊÇMespinozaµÄ¼ÌÈÎÕߣ¬£¬£¬ £¬£¬£¬£¬ÓÚ2019Äê12ÔÂÊ״α»·¢Ã÷£¬£¬£¬ £¬£¬£¬£¬ÒѳÉΪ2021ÄêQ4¼ì²âµ½µÄµÚÈý´óÊ¢ÐÐÀÕË÷Èí¼þ£¬£¬£¬ £¬£¬£¬£¬×Ô2020Äê9ÔÂÒÔÀ´Ð¹Â¶Á˶à´ï747¸ö±»¹¥»÷Ä¿µÄµÄÐÅÏ¢¡£¡£ ¡£¡£PRODAFT·¢Ã÷ÁËPYSAµÄ¹ûÕæ.gitÎļþ¼Ð£¬£¬£¬ £¬£¬£¬£¬ÆäÖÐÒ»¸ö³ÉÔ±ÊÇ¡°dodo@mail.pcc¡±£¬£¬£¬ £¬£¬£¬£¬Æ¾Ö¤Ìá½»ÀúÊ·ÅжϴËÈËλÓÚÒ»¸öÏÄÁîʱ¹ú¼Ò¡£¡£ ¡£¡£PYSAµÄ»ù´¡ÉèÊ©»¹°üÀ¨dockerizedÈÝÆ÷£¬£¬£¬ £¬£¬£¬£¬É漰й¶ЧÀÍÆ÷¡¢Êý¾Ý¿âºÍÖÎÀíЧÀÍÆ÷£¬£¬£¬ £¬£¬£¬£¬ÒÔ¼°´æ´¢¼ÓÃÜÎļþµÄAmazon S3ÔÆ£¬£¬£¬ £¬£¬£¬£¬×ܼÆ31.47TB¡£¡£ ¡£¡£


https://thehackernews.com/2022/04/researchers-share-in-depth-analysis-of.html 


5¡¢CheckPointÐû²¼2022ÄêÃæÁÙ×î´óµÄÔÆÇå¾²ÌôÕ½µÄ±¨¸æ


CheckPointÔÚ4ÔÂ18ÈÕÐû²¼ÁË2022ÄêÃæÁÙµÄ×î´óÔÆÇå¾²ÌôÕ½µÄ±¨¸æ¡£¡£ ¡£¡£±¨¸æÖ¸³ö£¬£¬£¬ £¬£¬£¬£¬Áè¼Ý98%µÄ×é֯ʹÓûùÓÚÔÆµÄ»ù´¡¼Ü¹¹£¬£¬£¬ £¬£¬£¬£¬76%µÄ×éÖ¯ÓµÓÐÓÉÁ½¸ö»ò¶à¸öÔÆÌṩÉ̵ÄЧÀÍ×é³ÉµÄ¶àÔÆÇéÐΡ£¡£ ¡£¡£¶àÔÆÇéÐεÄÖØ´óÐÔµ¼ÖÂÁËÐí¶àÌôÕ½£¬£¬£¬ £¬£¬£¬£¬°üÀ¨Êý¾ÝµÄÒþ˽ºÍ± £»£» £» £»£»¤¡¢¶àÔÆÇéÐÎÖÐÐëÒªµÄÊÖÒÕ¡¢½â¾ö¼Æ»®ÕûºÏÒÔ¼°¿É¼ûÐԺͿØÖƵÄȱ·¦¡£¡£ ¡£¡£ÊµÏÖÔÆÇå¾²µÄÖ÷ҪĿµÄ°üÀ¨±ÜÃâÔÆÉèÖùýʧ¡¢± £»£» £» £»£»¤ÒÑÔÚʹÓõÄÖ÷ÒªÔÆÓ¦ÓóÌÐò¡¢ÊµÏÖî¿ÏµºÏ¹æºÍµÖÓù¶ñÒâÈí¼þ¡£¡£ ¡£¡£


https://blog.checkpoint.com/2022/04/18/the-biggest-cloud-security-challenges-in-2022-check-point-software/


6¡¢FortinetÐû²¼½üÆÚEmotet Maldoc±¬·¢Ç÷ÊÆµÄÆÊÎö±¨¸æ


4ÔÂ18ÈÕ£¬£¬£¬ £¬£¬£¬£¬FortinetÐû²¼¹ØÓÚ½üÆÚEmotet·Ö·¢Maldoc»î¶¯µÄÆÊÎö±¨¸æ¡£¡£ ¡£¡£´ËÂֻ×îÏÈÓÚ2021Äê11ÔÂ16ÈÕ£¬£¬£¬ £¬£¬£¬£¬Ê¹ÓÃÁË´¹ÂÚÓʼþÓëÉç»á¹¤³Ì¹¥»÷ÏàÁ¬ÏµµÄ·½·¨£¬£¬£¬ £¬£¬£¬£¬À´ÓÕʹĿµÄ×°ÖöñÒâÈí¼þ¡£¡£ ¡£¡£ÕâЩ´¹ÂÚÓʼþµÄÖ÷ÌâÐÐÖÐͨ³£ÖаüÀ¨¡°Re:¡±»ò¡°Fw:¡±£¬£¬£¬ £¬£¬£¬£¬Ê¹Æä¿´ÆðÀ´Ô½·¢Õýµ±¡£¡£ ¡£¡£Ñо¿Ö°Ô±¼ì²âµ½ÁËÓë´Ë»î¶¯Ïà¹ØµÄ5¸ö²î±ðÑù±¾£¬£¬£¬ £¬£¬£¬£¬ËüÃǵĺê´úÂëºÍÖ´ÐÐÁ÷³Ì±£´æ²î±ð¡£¡£ ¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬£¬¹¥»÷»î¶¯Ê¹ÓõĶñÒâExcelÎļþµÄÕ¼±ÈΪ93%£¬£¬£¬ £¬£¬£¬£¬Ô¶¸ßÓÚ7%µÄ¶ñÒâWordÎĵµ¡£¡£ ¡£¡£


https://www.fortinet.com/blog/threat-research/Trends-in-the-recent-emotet-maldoc-outbreak