Cado SecurityÌåÏÖ½©Ê¬ÍøÂçAbcbotÓëXantheÓйØÁª
Ðû²¼Ê±¼ä 2022-01-12΢ÈíÐû²¼1ÔÂÖܶþ²¹¶¡£¬ÐÞ¸´6¸ö0 dayÔÚÄÚµÄ97¸öÎó²î

1ÔÂ11ÈÕ£¬Î¢ÈíÐû²¼Á˽ñÄê¶ÈµÄÊ׸öÖܶþ²¹¶¡£¬×ܼÆÐÞ¸´97¸öÇå¾²Îó²î£¨²»°üÀ¨29¸öMicrosoft EdgeÎó²î£©¡£´Ë´ÎÐÞ¸´µÄ×îÑÏÖØµÄÊÇHTTPÐÒéÕ»Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2022-21907£©£¬CVSSÆÀ·ÖΪ9.8£¬¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâÊý¾Ý°üµ½Ä¿µÄ·þÎñÆ÷À´Ê¹ÓøÃÎó²î¡£±ðµÄ£¬¸üл¹ÐÞ¸´ÁË6¸ö0 day£¬°üÀ¨¿ªÔ´Curl¿âÖеÄRCE£¨CVE-2021-22947£©¡¢¿ªÔ´ Libarchive¿âÖеÄRCE£¨CVE-2021-36976£©ºÍÍâµØWindowsÇå¾²ÖÐÐÄAPIÖеÄRCE£¨CVE-2022-21874£©µÈ¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-january-2022-patch-tuesday-fixes-6-zero-days-97-flaws/
EDPSÒªÇóÅ·ÖÞÐ̾¯×é֯ɾ³ýÓë·¸·¨Ô˶¯Î޹صÄСÎÒ˽¼ÒÊý¾Ý
¾ÝýÌå1ÔÂ10ÈÕ±¨µÀ£¬Å·ÃËÊý¾Ý±£»¤î¿Ïµ»ú¹¹EDPSÏÂÁîÒªÇóÅ·ÖÞÐ̾¯×é֯ɾ³ýÓë·¸·¨Ô˶¯Î޹صÄСÎÒ˽¼ÒÊý¾Ý¡£Õþ¸®Ö¸³ö£¬ÔÚûÓÐÊý¾ÝÖ÷Ìå·ÖÀàµÄÇéÐÎÏ´洢´ó×ÚÊý¾Ý»á¶ÔСÎÒ˽¼ÒµÄ»ù±¾È¨Á¦×é³ÉΣº¦£¬Ï൱ÓÚ´ó¹æÄ£¼àÊÓ¡£¾Ý¡¶ÎÀ±¨¡·±¨µÀ£¬»º´æÖÁÉÙ°üÀ¨4 PB¡£EDPS»¹»®¶¨ÁËÁù¸öÔµı£´æÆÚ£¬ÒÔ¹ýÂ˺ÍÌáȡСÎÒ˽¼ÒÊý¾Ý£¬²¢¸øÓè¸Ã¿ç¾³Ö´·¨»ú¹¹Ò»ÄêµÄʱ¼äÀ´Éó²éÆäÊý¾Ý¿â¡£
https://thehackernews.com/2022/01/europol-ordered-to-delete-data-of.html
WordPressÐû²¼¸üУ¬ÐÞ¸´SQL×¢ÈëµÈ4¸öÇå¾²Îó²î
ýÌå1ÔÂ11ÈÕ±¨µÀ£¬WordPressÐû²¼¸üУ¬×ܼÆÐÞ¸´4¸öÇå¾²Îó²î¡£´Ë´ÎÐÞ¸´µÄÎó²î°üÀ¨SQL×¢ÈëÎó²î£¨CVE-2022-21661£©£¬¿Éͨ¹ýʹÓÃWP-QueryµÄ²å¼þºÍÖ÷ÌâʹÓã»XSSÎó²î£¨CVE-2022-21662£©£¬¿ÉÓÃÀ´Ö²ÈëºóÃÅ»òͨ¹ýÀÄÓÃpost slugÀ´¿ØÖÆÍøÕ¾£»SQL×¢ÈëÎó²î£¨CVE-2022-21664£©£¬¿Éͨ¹ýWP_Meta_QueryʹÓ㻹¤¾ß×¢ÈëÎó²î£¨CVE-2022-21663£©£¬ÐèÒªÈëÇÖÖÎÀíÔ±ÕÊ»§²Å»ªÊ¹Óá£
https://securityaffairs.co/wordpress/126556/security/wordpress-5-8-3.html
΢ÈíÅû¶macOSÎó²îpowerdir(CVE-2021-30970)ϸ½Ú
1ÔÂ10ÈÕ£¬Î¢ÈíÐû²¼¹ØÓÚmacOSÖеÄÎó²îpowerdir(CVE-2021-30970)µÄÆÊÎö±¨¸æ¡£Î¢ÈíÌåÏÖ£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÈÆ¹ý͸Ã÷¡¢Ô޳ɺͿØÖÆ(TCC)ÊÖÒÕÀ´»á¼ûÓû§µÄÊý¾Ý¡£Ñо¿Ö°Ô±·¢Ã÷£¬¿ÉÒÔͨ¹ý±à³ÌµÄ·½·¨¸Ä¶¯Ä¿µÄÓû§Ö÷Ŀ¼²¢Ö²ÈëαTCCÊý¾Ý¿â£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îƾ֤Óû§Êܱ£»¤µÄСÎÒ˽¼ÒÊý¾Ý²ß»®¹¥»÷¡£Î¢ÈíÍŶÓÔÚ2021Äê7ÔÂ15ÈÕ½«Îó²î±¨¸æ¸øApple¹«Ë¾£¬AppleÔÚ12ÔÂ13ÈÕÐû²¼µÄÇå¾²¸üÐÂÖÐÐÞ¸´¡£
https://www.microsoft.com/security/blog/2022/01/10/new-macos-vulnerability-powerdir-could-lead-to-unauthorized-user-data-access/
Cado SecurityÌåÏÖ½©Ê¬ÍøÂçAbcbotÓëXantheÓйØÁª
Cado SecurityÔÚ1ÔÂ10ÈÕÐû²¼µÄ±¨¸æÏÔʾ£¬½©Ê¬ÍøÂçAbcbotÓëXantheÓйØÁª¡£AbcbotÔÚ2021Äê11ÔÂÊ״α»¹ûÕæ£¬Æäʱ¹¥»÷ÁË»ªÎª¡¢ÌÚѶ¡¢°Ù¶ÈºÍ°¢ÀïÔÆµÈÔÆ·þÎñÌṩÉÌ¡£µ«Í¨¹ýËùÓÐÒÑÖªµÄIoCs£¬°üÀ¨IPµØµã¡¢urlºÍÑù±¾£¬·¢Ã÷AbcbotµÄ´úÂëºÍ»ù´¡ÉèÊ©ÓëÒ»¸öÃûΪXantheµÄ¼ÓÃÜÐ®ÖÆ¶ñÒâÈí¼þ¼Ò×åÓÐÖØµþ¡£Ñо¿ÍŶÓÒÔΪ¶þÕßÓÉͳһ¹¥»÷ÕßÈÏÕæ£¬²¢ÇÒËûÃÇÕý½«Ä¿µÄ´ÓÍÚ¿ó×ªÒÆµ½Óë½©Ê¬ÍøÂçÏà¹ØµÄÔ˶¯¡£
https://www.cadosecurity.com/abcbot-an-evolution-of-xanthe/
Check Point³Æ2021ÄêÍøÂç¹¥»÷Ô˶¯Í¬±ÈÔöÌí50%
1ÔÂ10ÈÕ£¬Check Point researchÐû²¼±¨¸æ³Æ2021ÄêÍøÂç¹¥»÷Ô˶¯Í¬±ÈÔöÌí50%¡£±¨¸æ»¹Ö¸³ö£¬ÔÚ2021ÄêµÚËÄÐò¶È£¬Ã¿¸ö×éÖ¯µÄÿÖÜÔâµ½µÄ¹¥»÷´ÎÊýµÖ´ïÀúÊ·×î¸ß£¬Æ½¾ùΪ925´Î¡£2021Ä꣬½ÌÓýºÍÑо¿ÐÐÒµÊÇÔâµ½¹¥»÷×î¶àµÄÐÐÒµ£¬Æ½¾ùÿÖÜ1605´Î¹¥»÷£¬Õâ±È2020ÄêÔöÌíÁË75%¡£°´µØÇø»®·Ö£¬·ÇÖÞÔâµ½¹¥»÷×î¶à£¬Æ½¾ùÿÖÜ1582´Î£¬±È2020ÄêÔöÌí13%£¬½ôËæØÊºóµÄÊÇÑÇÌ«µØÇø£¬Ã¿ÖÜÔâµ½1353´Î¹¥»÷£¨ÔöÌí25%£©¡£
https://blog.checkpoint.com/2022/01/10/check-point-research-cyber-attacks-increased-50-year-over-year/
Çå¾²¹¤¾ß
Mortar
MortarÄܹ»ÈƹýÏÖ´ú·´²¡¶¾²úÆ·ºÍÏȽøµÄXDR½â¾ö¼Æ»®£¬°üÀ¨Kaspersky¡¢ESETºÍMcafeeµÈ¡£
https://www.kitploit.com/2022/01/mortar-evasion-technique-to-defeat-and.html
RecoverPy
¿ÉÓÃÀ´»Ö¸´±»ÁýÕÖ»òɾ³ýµÄÊý¾Ý£¬ÏÖÔÚ½öÔÚLinuxϵͳÉÏ¿ÉÓá£
https://github.com/PabloLec/RecoverPy
Çå¾²ÆÊÎö
Linux Mint 20.3 Ðû²¼
Linux Mint Ðû²¼ÁË 20.3 °æ£¬´úºÅΪ¡°Una¡±£¬×÷Ϊºã¾ÃÖ§³Ö°æ±¾£¬²¢ÔÊÐíÔÚ 2025 ÄêÄê֮ǰÇå¾²¸üС£
https://www.bleepingcomputer.com/news/linux/linux-mint-203-released-promising-security-updates-until-2025/
ÀÕË÷Èí¼þAvosLocker Õë¶Ô VMware ESXi ·þÎñÆ÷
AvosLockerÔÚÆä×î½üµÄ¶ñÒâÈí¼þ±äÖÖÖÐÔöÌíÁË¶Ô Linux ϵͳµÄÖ§³Ö£¬ÌØÊâÊÇÕë¶Ô VMware ESXi ÐéÄâ»ú¡£
https://www.bleepingcomputer.com/news/security/linux-version-of-avoslocker-ransomware-targets-vmware-esxi-servers/


¾©¹«Íø°²±¸11010802024551ºÅ