ʹÓÃGoogle Play·Ö·¢µÄÐÂľÂíXenomorphÕë¶ÔÅ·ÖÞµØÇø

Ðû²¼Ê±¼ä 2022-02-24

ʹÓÃGoogle Play·Ö·¢µÄÐÂľÂíXenomorphÕë¶ÔÅ·ÖÞµØÇø


¾ÝýÌå2ÔÂ21ÈÕ±¨µÀ£¬£¬£¬ £¬£¬£¬£¬Çå¾²¹«Ë¾ThreatFabric·¢Ã÷ÁËеÄAndroidÒøÐÐľÂíXenomorph¡£¡£¡£¡£¡£¡£¡£¸ÃľÂíαװ³ÉÐÔÄÜÌáÉýÓ¦ÓóÌÐò£¨ÀýÈçFast Cleaner£©Í¨¹ýGoogle PlayÊÐËÁ·Ö·¢£¬£¬£¬ £¬£¬£¬£¬Òѱ»×°ÖÃÁè¼Ý50000´Î¡£¡£¡£¡£¡£¡£¡£ËüÏÖÔÚÈÔ´¦ÓÚÔçÆÚ¿ª·¢½×¶Î£¬£¬£¬ £¬£¬£¬£¬Ä¿µÄÊÇÎ÷°àÑÀ¡¢ÆÏÌÑÑÀ¡¢Òâ´óÀûºÍ±ÈÀûʱµÈÅ·ÖÞ¹ú¼ÒµÄ56¼Ò½ðÈÚ»ú¹¹¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±»¹·¢Ã÷¸ÃľÂíµÄ´úÂëÓëAlienÓÐËùÖØµþ£¬£¬£¬ £¬£¬£¬£¬ÕâÅú×¢¶þÕß±£´æÄ³ÖÖÁªÏµ£ºÒªÃ´XenomorphÊÇAlienµÄ¼ÌÈÎÕߣ¬£¬£¬ £¬£¬£¬£¬ÒªÃ´XenomorphµÄ¿ª·¢Ö°Ô±Ò»Ö±ÔÚÑо¿Alien¡£¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2022/02/xenomorph-android-banking.html


ÃÀ¹úMeyerÔâµ½ContiÀÕË÷¹¥»÷µ¼Ö´ó×ÚÔ±¹¤ÐÅϢй¶


¾Ý2ÔÂ21ÈÕ±¨µÀ£¬£¬£¬ £¬£¬£¬£¬ÃÀ¹ú×î´óµÄ´¶¾ß¹«Ë¾MeyerÔâµ½ContiÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚ2021Äê10ÔÂ25ÈÕ£¬£¬£¬ £¬£¬£¬£¬¼ì²âµ½¹¥»÷ºó¸Ã¹«Ë¾Á¬Ã¦Õö¿ªÊӲ죬£¬£¬ £¬£¬£¬£¬²¢ÓÚ12ÔÂ1ÈÕÈ·¶¨MeyerÔ±¹¤µÄÐÅÏ¢¿ÉÄÜÒÑÔ⵽δ¾­ÊÚȨµÄ»á¼û¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚContiµÄÐÅÏ¢Ð¹Â¶ÍøÕ¾·¢Ã÷Ò»¸ö¿É×·Ëݵ½11ÔÂ7ÈÕµÄÁбí£¬£¬£¬ £¬£¬£¬£¬¾Ý³Æ°üÀ¨ÁËÔÚMeyerÇÔÈ¡µÄ2%µÄÊý¾Ý£¬£¬£¬ £¬£¬£¬£¬µ«ÖÁ½ñÈÔδÐû²¼Ê£ÓàµÄ98%¡£¡£¡£¡£¡£¡£¡£MeyerÌåÏÖ½«ÎªÊÜÓ°ÏìµÄÔ±¹¤¼°Æä¾ìÊôÌṩÁ½ÄêµÄÉí·Ý±£»£»£»¤Ð§ÀÍ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/cookware-giant-meyer-discloses-cyberattack-that-impacted-employees/


Ahn Lab·¢Ã÷CryptBotбäÌåʹÓõÁ°æÈí¼þÍøÕ¾Èö²¥


Ahn LabÔÚ2ÔÂ21ÈÕÐû²¼µÄÑо¿ÏÔʾ£¬£¬£¬ £¬£¬£¬£¬CryptBotбäÌåÕýÔÚͨ¹ýµÁ°æÈí¼þÍøÕ¾¾ÙÐÐÈö²¥¡£¡£¡£¡£¡£¡£¡£CryptBotÊÇÒ»ÖÖWindowsÐÅÏ¢ÇÔÈ¡³ÌÐò£¬£¬£¬ £¬£¬£¬£¬¿É´ÓÄ¿µÄÇÔÈ¡ä¯ÀÀÆ÷ƾ֤¡¢cookie¡¢¼ÓÃÜÇ®±ÒÇ®°üºÍÐÅÓÿ¨µÈÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÆÆ½âÈí¼þºÍÃÜÔ¿ÌìÉúÆ÷µÈÍøÕ¾·Ö·¢¶ñÒâÈí¼þ£¬£¬£¬ £¬£¬£¬£¬²¢Í¨¹ýËÑË÷ÒýÇæÓÅ»¯½«ÕâÐ©ÍøÕ¾ÔڹȸèµÄËÑË÷Ч¹ûÖÐÖö¥¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬£¬¸Ã°æ±¾±ÈÒÔÍùÓнϴóµÄ¸Ä¶¯£¬£¬£¬ £¬£¬£¬£¬É¾³ýÁË·´É³ºÐ¹¦Ð§ºÍ±¸ÓÃC2µÈÈßÓàµÄ¹¦Ð§£¬£¬£¬ £¬£¬£¬£¬²¢ÒÑ¿ÉÊÊÓÃÓÚËùÓÐChrome°æ±¾¡£¡£¡£¡£¡£¡£¡£


https://asec.ahnlab.com/en/31802/


KasperskyÐû²¼2021ÄêÒÆ¶¯¶ñÒâÈí¼þÌ¬ÊÆµÄÆÊÎö±¨¸æ


2ÔÂ21ÈÕ£¬£¬£¬ £¬£¬£¬£¬KasperskyÐû²¼ÁË2021ÄêÒÆ¶¯¶ñÒâÈí¼þÌ¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬ £¬£¬£¬£¬KasperskyÔÚ2021Äê×ܼƼì²âµ½3464756¸ö¶ñÒâ×°Öðü¡¢97661¸öеÄÒÆ¶¯ÒøÐÐľÂíºÍ17372¸öеÄÒÆ¶¯ÀÕË÷Èí¼þ¡£¡£¡£¡£¡£¡£¡£ÊÜÒÆ¶¯¶ñÒâÈí¼þ¹¥»÷×î¶àµÄ¹ú¼ÒÊÇÒÁÀÊ£¬£¬£¬ £¬£¬£¬£¬Æä´ÎÊÇÖйú¡¢É³Ìذ¢À­²®ºÍ°¢¶û¼°ÀûÑÇ¡£¡£¡£¡£¡£¡£¡£¼ì²âµ½µÄ¶ñÒâÈí¼þÖÐ¹ã¸æÈí¼þ£¨42.42%£©µÄÕ¼±È×î´ó£¬£¬£¬ £¬£¬£¬£¬Æä´ÎΪRiskToolÓ¦ÓóÌÐò£¨35.27%£©ºÍľÂí£¨8.86%£©¡£¡£¡£¡£¡£¡£¡£


https://securelist.com/mobile-malware-evolution-2021/105876/


Trend MicroÅû¶ÐµÄMac¶ñÒâÍÚ¿óÈí¼þµÄÊÖÒÕϸ½Ú


Trend MicroÔÚ2ÔÂ21ÈÕÅû¶ÁËÐÂMac¶ñÒâÍÚ¿óÈí¼þµÄÊÖÒÕϸ½Ú¡£¡£¡£¡£¡£¡£¡£¶ñÒâÈí¼þÑù±¾±»¼ì²âΪCoinminer.MacOS.MALXMR.H£¬£¬£¬ £¬£¬£¬£¬ÓÚ2022Äê1Ô³õÊ״α»·¢Ã÷£¬£¬£¬ £¬£¬£¬£¬ÊÇÒ»¸öMach-OÎļþ¡£¡£¡£¡£¡£¡£¡£Ö´ÐÐʱ£¬£¬£¬ £¬£¬£¬£¬ËüʹÓÃAuthorizationExecuteWithPrivileges APIͨ¹ýÌáÐÑÓû§ÊäÈëÆ¾Ö¤À´ÌáÉýȨÏÞ¡£¡£¡£¡£¡£¡£¡£³ý´ËÖ®Í⣬£¬£¬ £¬£¬£¬£¬¸ÃÑù±¾»¹Ê¹ÓÃÁËi2pd£¨ÓÖÃûI2PÊØ»¤³ÌÐò£©À´Òþ²ØÆäÍøÂçÁ÷Á¿£¬£¬£¬ £¬£¬£¬£¬¶øÆäËüMac¶ñÒâÈí¼þͨ³£Ê¹ÓÃTor¡£¡£¡£¡£¡£¡£¡£


https://www.trendmicro.com/en_us/research/22/b/latest-mac-coinminer-utilizes-open-source-binaries-and-the-i2p-network.html


Ñо¿ÍŶӷ¢Ã÷Õë¶ÔMicrosoft SQLÊý¾Ý¿âµÄ¹¥»÷»î¶¯


ýÌå2ÔÂ21Èճƣ¬£¬£¬ £¬£¬£¬£¬Ñо¿ÍŶӷ¢Ã÷ÁËÕë¶ÔMicrosoft SQLÊý¾Ý¿âµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏÈɨÃèTCP¶Ë¿Ú1433¿ª·ÅµÄЧÀÍ£¬£¬£¬ £¬£¬£¬£¬È»ºóͨ¹ý±©Á¦ÆÆ½âºÍ×ֵ乥»÷À´ÆÆ½âÃÜÂë¡£¡£¡£¡£¡£¡£¡£Ò»µ©»ñµÃÖÎÀíÔ±ÕÊ»§µÄ»á¼ûȨÏÞ£¬£¬£¬ £¬£¬£¬£¬¹¥»÷Õ߾ͻáÁ¬Ã¦×°ÖÃLemon Duck¡¢KingMinerºÍVollgarµÈ¶ñÒâ¿ó¹¤Èí¼þ¡£¡£¡£¡£¡£¡£¡£×îºó£¬£¬£¬ £¬£¬£¬£¬ËûÃÇ»¹»áʹÓÃCobalt StrikeÔÚÊý¾Ý¿âÖн¨ÉèºóÃÅ£¬£¬£¬ £¬£¬£¬£¬ÒÔ¼á³Ö³¤ÆÚÐÔ²¢¾ÙÐкáÏòÒÆ¶¯¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/vulnerable-microsoft-sql-servers-targeted-with-cobalt-strike/



Çå¾²¹¤¾ß


coraza


golang ÆóÒµ¼¶ Web Ó¦Ó÷À»ðǽ¿ò¼Ü£¬£¬£¬ £¬£¬£¬£¬Ö§³Ö Modsecurity µÄ seclang ÓïÑÔ£¬£¬£¬ £¬£¬£¬£¬Óë OWASP Core Ruleset 100% ¼æÈÝ¡£¡£¡£¡£¡£¡£¡£


https://github.com/corazawaf/coraza


m3


ÒÆ¶¯¶ñÒâÈí¼þÄ£Äâ¿ò¼Ü£¨¼ò³Æm3£©ÊÇÒ»¸ö¼òÆÓÇÒ¿ÉÀ©Õ¹µÄ Android »úеÈËÄ£Äâ¿ò¼Ü¡£¡£¡£¡£¡£¡£¡£


https://github.com/ThisIsLibra/m3/


SecureBank


°üÀ¨ËùÓÐ OWASP TOP 10 Çå¾²Îó²îµÄ½ðÈڿƼ¼Ó¦ÓóÌÐò¡£¡£¡£¡£¡£¡£¡£


https://ssrd.gitbook.io/securebank/


Talisman 


¿É½«hook×°Öõ½´æ´¢¿â£¬£¬£¬ £¬£¬£¬£¬ÒÔÈ·±£Ç±ÔÚµÄÃô¸ÐÐÅÏ¢²»»áÍÑÀ뿪·¢Ö°Ô±µÄÊÂÇéÕ¾¡£¡£¡£¡£¡£¡£¡£


https://github.com/thoughtworks/talisman#what-is-talisman


SharpCookieMonster


cookie-crimesÄ£¿£¿£¿£¿£¿£¿£¿éµÄÒ»¸ö Sharp ¶Ë¿Ú£¬£¬£¬ £¬£¬£¬£¬Õâ¸ö C# ÏîÄ¿½«ÎªËùÓÐÕ¾µãת´¢ cookie¡£¡£¡£¡£¡£¡£¡£


https://github.com/m0rv4i/SharpCookieMonster



Çå¾²ÆÊÎö


ÕûÊýÒç³ö£ºËüÊÇÔõÑù±¬·¢µÄÒÔ¼°ÔõÑùÔ¤·À


https://www.welivesecurity.com/2022/02/21/integer-overflow-how-it-occur-can-be-prevented/


¹¥»÷ÕßʹÓÃSMS PVA ЧÀ;ÙÐжñÒâ»î¶¯


https://securityaffairs.co/wordpress/128242/cyber-crime/sms-pva-services.html


ÆÏÌÑÑÀÍþв±¨¸æ£º2021 ÄêµÚËÄÐò¶È


https://seguranca-informatica.pt/threat-report-portugal-q3-2021/


΢Èí¸üÐÂÁË Your Phone Ó¦ÓóÌÐòµÄÒ»Ïîй¦Ð§


https://news.softpedia.com/news/microsoft-announces-a-new-feature-for-the-your-phone-app-534911.shtml


CVE-2022-0290£ºChrome RenderFrameHostImplÊͷźóʹÓÃÎó²î


https://packetstormsecurity.com/files/166080/GS20220221155706.tgz