¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2022.02.21-2022.02.27£©
2022-02-28
Ò»¡¢ ÈÈÃÅ×ÊѶ
1. ÍøÂç¹¥»÷ÕßʹÓÃDocuSignÇÔÈ¡Microsoft OutlookµÇ¼ÐÅÏ¢
¡¾±êÇ©¡¿ÆóÒµ
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷£¬Õë¶Ô“λÓÚ±±ÃÀµÄÒ»¼Ò´óÐÍ¡¢¹ûÕæÉúÒâµÄ×ÛºÏÖ§¸¶½â¾ö¼Æ»®¹«Ë¾”µÄÖØ´óÍøÂç´¹ÂÚÔ˶¯Ê¹ÓÃDocuSignºÍÊÜѬȾµÄµÚÈý·½µç×ÓÓʼþÓòÀ´Èƹýµç×ÓÓʼþÇå¾²²½·¥¡£¶ø¸ÃÔ˶¯ÔÚ¹«Ë¾ÖÜΧɢ²¼¿´ËÆÎÞº¦µÄµç×ÓÓʼþ£¬ÊµÔòÄ¿µÄÊÇÇÔȡ΢ÈíµÄµÇ¼ƾ֤¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNiG
2. ¹¥»÷ÕßʹÓÃÀÕË÷Èí¼þ¹¥»÷»ªË¶×Ó¹«Ë¾ASUSTOR
¡¾±êÇ©¡¿ÆóÒµ
¡¾¸ÅÊö¡¿
¿ËÈÕ»ªË¶ÆìÏÂ×Ó¹«Ë¾»ªÜ¿¿Æ¼¼£¨Asustor£©µÄÍøÂ總¼Ó´æ´¢£¨NAS£©ÔâÓöÁËÀÕË÷¹¥»÷¡£´Ë´ÎÀÕË÷¹¥»÷²¨¼°È«ÇòÖÚ¶àÓû§£¬²¢ÔÚASUSTORÂÛ̳ÉÏÒýÆðÀ´ÆÕ±éÌÖÂÛ¡£Ñо¿Ö°Ô±ÌåÏÖÓëÉϸöÔÂQNAP NAS×°±¸±»ÀÕË÷¹¥»÷ÏàÀàËÆ£¬Á½´Î¹¥»÷¾ùÊÇDeadBoltÀÕË÷Èí¼þËùΪ£¬ËùÓÐÎļþ¶¼±»¼ÓÁË.deadbolt ÎļþÀ©Õ¹Ãû¡£ASUSTOR µÇÂ¼Ò³ÃæÒ²±»Ò»ÕÅÊý¾ÝÀÕË÷֪ͨȡ´ú£¬ÒªÇóÓû§Ö§0.03¸ö±ÈÌØ±Ò£¬ÕÛºÏÈËÃñ±ÒÔ¼Æßǧ¶àÔª¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNiI
3. ¹¥»÷Õßͨ¹ý΢Èí¹Ù·½ÊÐËÁµÄÓÎÏ·Ó¦ÓóÌÐò·Ö·¢Electron Bot жñÒâÈí¼þ¿ØÖÆÉ罻ýÌåÕÊ»§
¡¾±êÇ©¡¿É罻ýÌå
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±¼ì²âµ½Ò»ÖÖÃûΪ Electron Bot µÄжñÒâÈí¼þ£¬¸Ã¶ñÒâÈí¼þÒÑѬȾȫÇò 5,000 ¶ą̀ÔËÄîͷе¡£²¢ÌåÏÖÔÚ“Temple Run”»ò“Subway Surfer”µÈÈÈÃÅÓÎÏ··¢Ã÷±£´æ¸Ã¶ñÒâÈí¼þ£¬¹¥»÷Õß¿ÉÒÔʹÓÃ×°ÖõĶñÒâÈí¼þ×÷ΪºóÃÅ£¬ÒÔÍêÈ«¿ØÖÆÊܺ¦ÕߵĻúе£¬¶ø´ó´ó¶¼Êܺ¦ÕßÀ´×ÔÈðµä¡¢±£¼ÓÀûÑÇ¡¢¶íÂÞ˹¡¢°ÙĽ´óºÍÎ÷°àÑÀ¡£Electron ÊÇÒ»¸öʹÓà Web ¾ç±¾¹¹½¨¿çƽ̨×ÀÃæÓ¦ÓóÌÐòµÄ¿ò¼Ü¡£¸Ã¿ò¼ÜÍŽáÁË Chromium äÖȾÒýÇæºÍ Node.js ÔËÐÐʱ£¬Ê¹Æä¾ß±¸ÓÉJavaScriptµÈ¾ç±¾¿ØÖƵÄä¯ÀÀÆ÷¹¦Ð§£¬ÎªÁË×èÖ¹±»¼ì²âµ½£¬´ó´ó¶¼¿ØÖƶñÒâÈí¼þµÄ¾ç±¾¶¼ÊÇÔÚÔËÐÐʱ´Ó¹¥»÷ÕߵķþÎñÆ÷¶¯Ì¬¼ÓÔØµÄ¡£Õâʹ¹¥»÷ÕßÄܹ»ÔÚÈκθø×¼Ê±¼äÐ޸ĶñÒâÈí¼þµÄÓÐÓøºÔز¢¸ü¸Ä»úеÈ˵ÄÐÐΪ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNiH
4. ¹¥»÷ÕßʹÓÃDridex ¶ñÒâÈí¼þÔÚ±»ºÚÅÌËã»úÉϰ²ÅÅìØÀÕË÷Èí¼þ
¡¾±êÇ©¡¿ÆóÒµ¡¢Õþ¸®
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±ÔÚDridexͨÓöñÒâÈí¼þºÍÒ»ÖÖÏÊΪÈËÖªµÄÀÕË÷Èí¼þEntropyÖ®¼ä·¢Ã÷ÁËÏàËÆÖ®´¦£¬²¢ÌåÏÖËüµÄÏàËÆÖ®´¦ÔÚÓÚÓÃÓÚÒþ²ØÀÕË÷Èí¼þ´úÂëµÄÈí¼þ´ò°ü³ÌÐò£¬ÓÃÓÚ²éÕҺͻìÏýÏÂÁAPI ŲÓ㩵ĶñÒâÈí¼þ×Ó³ÌÐò£¬ÒÔ¼°ÓÃÓÚ½âÃܼÓÃÜÎı¾µÄ×Ó³ÌÐò¡£¶øÑо¿Ö°Ô±ÊÇÔÚÕë¶ÔÒ»¼Òδǩ×ÖýÌ幫˾ºÍÒ»¼ÒµØÇøÕþ¸®»ú¹¹µÄÁ½ÆðÎÞ¹ØÊÂÎñÖ®ºó£¬·¢Ã÷ÁËÕâЩÅäºÏµã¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNis
5. ¹¥»÷ÕßʹÓÃWiper¶ñÒâÈí¼þ¶ÔÒÁÀʹ㲥¹«Ë¾IRIBÌᳫ¹¥»÷
¡¾±êÇ©¡¿Õþ¸®¡¢ÆóÒµ
¡¾¸ÅÊö¡¿
ÒÁÀʹú¼ÒýÌ幫˾ÒÁÀÊÒÁ˹À¼¹²ºÍ¹ú¹ã²¥¹«Ë¾ (IRIB) ÔÚ 2022 Äê 1 ÔÂÏÂÑ®Ôâµ½Á˲Á³ý¶ñÒâÈí¼þµÄ¹¥»÷¡£ÊÓ²ì´Ë´Î¹¥»÷µÄÑо¿Ö°Ô±±¨¸æ³Æ£¬¹¥»÷ÕßʹÓòÁ³ý¶ñÒâÈí¼þÆÆËð¸ÃÖÝµÄ¹ã²¥ÍøÂç£¬ÆÆËðµçÊÓºÍ¹ã²¥ÍøÂç¡£ÔÚÊÓ²ìÀú³ÌÖÐÑо¿Ö°Ô±·¢Ã÷ÁËÁ½¸öÏàͬµÄ.NET Ñù±¾£¬ÃûΪmsdskint.exe£¬ÓÃÓÚ²Á³ýÊÜѬȾÉè±¹ØÁ¬ÄÎļþ¡¢Çý¶¯Æ÷ºÍMBR£¬Ê¹ËüÃÇÎÞ·¨Ê¹Óᣲ¢ÌåÏָöñÒâÈí¼þ»¹¾ßÓÐɨ³ýWindowsÊÂÎñÈÕÖ¾¡¢É¾³ý±¸·Ý¡¢ÖÕÖ¹Àú³ÌºÍ¸ü¸ÄÓû§ÃÜÂëµÄÄÜÁ¦¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNip
6. ¶ùͯÉÝ³ÞÆ·´ò°çµêMelijoe 200GB¿Í»§Êý¾ÝÔâй¶
¡¾±êÇ©¡¿ÆóÒµ
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±³Æ£¬ÓÉÓÚÆäÖÐÒ»¸öÉèÖùýʧµÄ Amazon S3 ´æ´¢Í°£¬¸Ã¹«Ë¾Ì»Â¶Á˰üÀ¨½ü 200 Íò¸öÎļþµÄ¸ß´ï200 GBµÄÊý¾Ý¡£¸üÔã¸âµÄÊÇ£¬´æ´¢Í°ÔÚûÓÐÈκÎÃÜÂë»òÇå¾²Éí·ÝÑéÖ¤µÄÇéÐÎϱ»¹ûÕæ»á¼û£¬ÕâÒâζ×ÅÈκÎÖªµÀÔõÑù²éÕÒÉèÖùýʧµÄÊý¾Ý¿âµÄÈ˶¼¿ÉÒÔ»á¼ûÊý¾Ý¡£¾ÓɶÔÕâЩÊý¾Ý¼¯µÄ½øÒ»²½ÆÊÎö·¢Ã÷ÒÔÏÂÃô¸ÐÐÅÏ¢±»Ð¹Â¶£ºÐԱ𡢳öÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢Õʵ¥µØµã¡¢Ö§¸¶·½·¨¼°º¢×ÓµÄÈ«Ãû¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNi9
7. ¹¥»÷ÕßʹÓÃXenomorph ¶ñÒâÈí¼þÇÔÈ¡Android ×°±¸µÄ²ÆÎñÐÅÏ¢
¡¾±êÇ©¡¿½ðÈÚ
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷Áè¼Ý50,000 ̨ Android ×°±¸Ñ¬È¾ÁËÒ»ÖÖÃûΪXenomorph µÄÐÂÐÍÒøÐÐľÂí£¬¸ÃľÂíͨ¹ýGoogle PlayÊÐËÁÈö²¥ÒÔÇÔÈ¡²ÆÎñÐÅÏ¢¡£Ñо¿Ö°Ô±ÌåÏÖ Xenomorph ÌØÂåÒÁľÂíͨ¹ýͨÓÃÐÔÄÜÌáÉýÓ¦ÓóÌÐò£¨Èç“Fast Cleaner”£©½øÈëÁËGoogle PlayÊÐËÁ£¬¶øXenomorph ÕâÑùµÄÒøÐÐľÂíÖ¼ÔÚÇÔÈ¡Ãô¸ÐµÄÒøÐÐÏêϸÐÅÏ¢¡¢¿ØÖÆÕË»§²¢Ìᳫδ¾ÊÚȨµÄÉúÒ⣬²¢½«±»µÁÊý¾Ý³öÊÛ¸øÇ±ÔÚÂò¼Ò¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNi8
8. ÎÚ¿ËÀ¼ÔÚÓë¶íÂÞ˹Ö÷ÒªÊ±ÊÆÖÐÔâÊÜÍøÂç¹¥»÷
¡¾±êÇ©¡¿½ðÈÚ¡¢Õþ¸®
¡¾¸ÅÊö¡¿
ÎÚ¿ËÀ¼¹ú·À²¿ÖܶþÌåÏÖ£¬ÓÉÓÚÓë¶íÂÞ˹µÄÖ÷ÒªÊ±ÊÆ¼Ó¾ç£¬ÒÔ¼°µ£ÐÄĪ˹¿Æ¿ÉÄܶԸùú½ÓÄɼ¤¾ÙÐж¯£¬°üÀ¨Ç±ÔڵĵØÃæÈëÇÖ£¬ËüÔâµ½ÁËÍøÂç¹¥»÷¡£±ðµÄ£¬¾ÝÁ¥ÊôÓÚÎÄ»¯ºÍÐÅÏ¢Õþ²ß²¿µÄÎÚ¿ËÀ¼Õ½ÂÔͨѶºÍÐÅÏ¢Çå¾²ÖÐÐijƣ¬ÖÁÉÙÓÐÁ½¼ÒÎÚ¿ËÀ¼ÒøÐкÍһЩ ATM »úʧȥÁËÅþÁ¬¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNhW
9. ÒÁÀʺڿÍʹÓà Log4jÎó²î°²ÅÅÀÕË÷Èí¼þ¹¥»÷VMware Horizon·þÎñÆ÷
¡¾±êÇ©¡¿²»Çø·ÖÐÐÒµ
¡¾¸ÅÊö¡¿
ÓëÒÁÀÊÕþ¸®½áÃ˵Ĺ¥»÷ÕßÕýÔÚÆð¾¢Ê¹ÓÃÖÚËùÖÜÖªµÄLog4j Îó²î£¬ÓÃÀÕË÷Èí¼þѬȾδÐÞ²¹µÄ VMware Horizon ·þÎñÆ÷¡£Ñо¿Ö°Ô±ÌåÏÖÓë Log4ShellÒ»ÆðÊӲ쵽µÄÉÐÓÐʹÓà Fortinet FortiOS ·¾¶±éÀúÎó²î ( CVE-2018-13379 ) ºÍ Microsoft Exchange ProxyShellÎó²îÀ´»ñµÃ¶ÔÄ¿µÄÍøÂçµÄ³õʼ»á¼ûȨÏÞÒÔ¾ÙÐкóÆÚʹÓá£TunnelVision ¹¥»÷ÕßÒ»Ö±ÔÚÆð¾¢Ê¹ÓøÃÎó²îÀ´ÔËÐжñÒâ PowerShell ÏÂÁî¡¢°²ÅźóÃÅ¡¢½¨ÉèºóÃÅÓû§¡¢»ñȡƾ֤²¢Ö´ÐкáÏòÒÆ¶¯¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNhK
10. ºÚ¿ÍÒÔ¹©Ó¦Á´¹¥»÷̨Íå½ðÈÚÉÌÒµ²¿·Ö
¡¾±êÇ©¡¿½ðÈÚ
¡¾¸ÅÊö¡¿
̨ÍåÇå¾²¹«Ë¾·¢Ã÷ÉøÍ¸Ô˶¯£¬´úºÅΪ“»º´æÐÜèÐж¯”£¬Ê¹ÓÃÔŲ́ÍåÊг¡Õ¼ÓÐÂÊÁè¼Ý80%µÄÎÞÃû֤ȯÈí¼þµÄÍøÒ³ÖÎÀí½çÃæÖеÄÒ»¸öÎó²î£¬Ê¹ÓøÃÎó²î°²ÅÅÒ»¸öÍøÒ³Íâ¿Ç£¬×÷ΪֲÈëµÄ¹ÜµÀ¡£ÊÜѬȾϵͳÉϵÄQuasar RATÖ¼ÔÚÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¶øQuasar RAT ÊÇÓà .NET ±àдµÄ¹ûÕæ¿ÉÓõĿªÔ´Ô¶³Ì»á¼ûľÂí (RAT)¡£ËüµÄ¹¦Ð§°üÀ¨²¶»ñÆÁÄ»½ØÍ¼¡¢Â¼ÖÆÍøÂçÉãÏñÍ·¡¢±à¼×¢²á±í¡¢¼üÅ̼ͼºÍÇÔÈ¡ÃÜÂë¡£±ðµÄ£¬¹¥»÷»¹Ê¹ÓÃÃûΪ wenshushu.cn µÄÖйúÔÆÎļþ¹²Ïí·þÎñÏÂÔØ¸¨Öú¹¤¾ß¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNic

AG¹«Ë¾ÔÆ







