΢ÈíÐÞ¸´AzureÖпɻá¼ûÆäËû¿Í»§Êý¾ÝµÄÎó²îAutoWarp

Ðû²¼Ê±¼ä 2022-03-10

΢ÈíÐÞ¸´AzureÖпɻá¼ûÆäËû¿Í»§Êý¾ÝµÄÎó²îAutoWarp


¾ÝýÌå3ÔÂ7ÈÕ±¨µÀ£¬£¬£¬£¬MicrosoftÒÑÐÞ¸´ÆäAzure×Ô¶¯»¯Ð§ÀÍÖеÄÎó²îAutoWarp¡£¡£ ¡£¡£Azure¿ÉÌṩÁ÷³Ì×Ô¶¯»¯¡¢ÉèÖÃÖÎÀíºÍ¸üÐÂÖÎÀí¹¦Ð§£¬£¬£¬£¬Ã¿¸öÍýÏë×÷ÒµÔÚAzure¿Í»§µÄɳÏäÄÚÔËÐС£¡£ ¡£¡£Ê¹ÓøÃÎó²î£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ´ÓÖÎÀíÆäËûÓû§É³ÏäµÄÄÚ²¿Ð§ÀÍÆ÷ÇÔÈ¡Azure¿Í»§µÄÍйÜÉí·ÝÑéÖ¤ÁîÅÆ£¬£¬£¬£¬À´ÍêÈ«¿ØÖÆÆäÕÊ»§¡£¡£ ¡£¡£12ÔÂ10ÈÕ£¬£¬£¬£¬Î¢Èíͨ¹ý×èÖ¹¶ÔËùÓÐɳÏäµÄÈÏÖ¤ÁîÅÆ»á¼û(³ýÁ˾ßÓÐÕýµ±»á¼ûȨµÄɳÏ䣩ÐÞ¸´ÁË´ËÎó²î¡£¡£ ¡£¡£


https://thehackernews.com/2022/03/microsoft-azure-autowarp-bug-could-have.html


»ÝÆÕÐÞ¸´Ó°ÏìÆäÊý°ÙÍǫ̀װ±¸µÄ16¸öUEFI¹Ì¼þÎó²î


BinarlyÔÚ3ÔÂ8ÈÕ¹ûÕæÁËÔÚ»ÝÆÕÆóÒµ×°±¸Öз¢Ã÷µÄ16¸öÐÂÎó²î¡£¡£ ¡£¡£ÕâЩÎó²î±£´æÓÚͳһ¿ÉÀ©Õ¹¹Ì¼þ½Ó¿Ú(UEFI)¹Ì¼þÖУ¬£¬£¬£¬¿É±»ÓÃÀ´»ñÈ¡¸ü¸ßȨÏÞ²¢ÔÚ×°±¸ÉÏ×°ÖöñÒâÈí¼þ£¬£¬£¬£¬ÈƹýÇå¾²Èí¼þµÄ¼ì²â¡£¡£ ¡£¡£ÆäÖнÏΪÑÏÖØµÄÊÇÌáȨÎó²î£¨CVE-2021-23932£©¡¢µ¼ÖÂí§Òâ´úÂëÖ´ÐеĶѻº³åÇøÒç³öÎó²î£¨CVE-2021-23924£©ºÍµ¼ÖÂí§Òâ´úÂëÖ´ÐеÄÄÚ´æËð»µÎó²î£¨CVE-2021-23928£©¡£¡£ ¡£¡£ÏÖÔÚ£¬£¬£¬£¬»ÝÆÕÒÑÐÞ¸´ÕâЩÎó²î¡£¡£ ¡£¡£


https://thehackernews.com/2022/03/new-16-high-severity-uefi-firmware.html


FBI³ÆRagnar LockerÒÑÈëÇÖÃÀ¹ú52¸öÒªº¦»ù´¡ÉèÊ©µÄ»ú¹¹


3ÔÂ7ÈÕ£¬£¬£¬£¬ÃÀ¹úFBIÓëÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾ÖÁªºÏÐû²¼ÁËÒ»·ÝTLP:WHITEͨ¸æ¡£¡£ ¡£¡£¸Ã»ú¹¹Ö¸³ö£¬£¬£¬£¬×èÖ¹2022Äê1Ô£¬£¬£¬£¬ÒÑÓÐ10¸öÒªº¦»ù´¡ÉèÊ©ÁìÓòµÄÖÁÉÙ52¸ö»ú¹¹Ôâµ½ÁËRagnarLockerÀÕË÷Èí¼þµÄ¹¥»÷£¬£¬£¬£¬Éæ¼°ÖÆÔì¡¢ÄÜÔ´¡¢½ðÈÚЧÀÍ¡¢Õþ¸®ºÍÐÅÏ¢ÊÖÒÕµÈÐÐÒµ¡£¡£ ¡£¡£Í¨¸æ×ÅÖØÓÚÌṩÓÃÀ´¼ì²âºÍ×èÖ¹Ragnar Locker¹¥»÷µÄÈëÇÖÖ¸±ê(IOC)£¬£¬£¬£¬»¹¹ûÕæÁË·ÀÓù´ËÀ๥»÷µÄ»º½â²½·¥¡£¡£ ¡£¡£FBI±Þ²ß±»¹¥»÷µÄ×éÖ¯Á¬Ã¦Éϱ¨´ËÀàÊÂÎñ£¬£¬£¬£¬²»ÃãÀøÖ§¸¶Êê½ð¡£¡£ ¡£¡£


https://www.documentcloud.org/documents/21397387-ragnarlocker-ransomware-indicators-of-compromise


¼ÓÄôóPressReader³ÆÕýÔÚ»Ö¸´ÒòÍøÂç¹¥»÷ÖÐÖ¹µÄÔËÓª


ýÌå3ÔÂ7ÈÕ±¨µÀ£¬£¬£¬£¬¼ÓÄôóPressReader³ÆÆäÕýÔÚÆð¾¢»Ö¸´ÒòÍøÂç¹¥»÷ÖÐÖ¹µÄÔËÓª¡£¡£ ¡£¡£PressReaderÊÇÈ«Çò×î´óµÄÊý×Ö±¨Ö½ºÍÔÓÖ¾·ÖÏúÉÌ£¬£¬£¬£¬×ÔÉÏÖÜËÄ×îÏÈ·ºÆðÍøÂçÖÐÖ¹£¬£¬£¬£¬ÆäBranded EditionsÍøÕ¾¡¢Ó¦ÓóÌÐòºÍPressReaderÍøÕ¾Êܵ½Ó°Ïì¡£¡£ ¡£¡£ÖÜÎåÍíÉÏ£¬£¬£¬£¬¸Ã¹«Ë¾È·ÈÏ´Ë´ÎÖÐÖ¹ÊÇÒ»ÆðÍøÂçÇå¾²ÊÂÎñ¡£¡£ ¡£¡£PressReaderÔÚ3ÔÂ6ÈÕÐû²¼Óû§¸üУ¬£¬£¬£¬³ÆÆäÍŶÓÕýÔÚÆð¾¢»Ö¸´ÔËÓª£¬£¬£¬£¬ÏÖÒÑÄܹ»´¦Öóͷ£ºÍÐû²¼Ä¿½ñµÄ±¨Ö½ºÍÔÓÖ¾¡£¡£ ¡£¡£


https://www.infosecurity-magazine.com/news/pressreader-suffers-cyber-attack/


ÂÞÂíÄáÑǵļÓÓÍÕ¾RompetrolÔâµ½À´×ÔHiveµÄÀÕË÷¹¥»÷


3ÔÂ7ÈÕ£¬£¬£¬£¬ÂÞÂíÄáÑǵÄʯÓ͹©Ó¦ÉÌRompetrol³ÆÆäÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬¹«Ë¾¹ÙÍøºÍ¼ÓÓÍÕ¾µÄFill&GoЧÀͱ»ÆÈ¹Ø±Õ¡£¡£ ¡£¡£RompetrolÊÇKMG InternationalµÄ×Ó¹«Ë¾£¬£¬£¬£¬Ò²ÊÇÂÞÂíÄáÑÇ×î´óµÄÁ¶Óͳ§Petromidia NavodariµÄÔËÓªÉÌ£¬£¬£¬£¬¸ÃÁ¶Óͳ§µÄÄê¼Ó¹¤ÄÜÁ¦Áè¼Ý500Íò¶Ö¡£¡£ ¡£¡£¾ÝϤ£¬£¬£¬£¬´Ë´Î¹¥»÷µÄÄ»ºóºÚÊÖÊÇHive£¬£¬£¬£¬¸ÃÍÅ»ïÌá³öÁË200ÍòÃÀÔªµÄÊê½ðÒªÇ󡣡£ ¡£¡£HiveÏÖÔÚºÜÊÇ»£»£»£»îÔ¾ºÍ¼¤½ø£¬£¬£¬£¬×Ô2021Äê6ÔÂÏÂÑ®ÆØ¹âÒÔÀ´£¬£¬£¬£¬Æ½¾ùÌìÌì¹¥»÷3¼Ò¹«Ë¾¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/rompetrol-gas-station-network-hit-by-hive-ransomware/


Ñо¿ÍŶÓÅû¶AxedaÖÐͳ³ÆÎªAccess:7µÄÒ»×éÎó²îµÄÏêÇé


¾Ý3ÔÂ8ÈÕ±¨µÀ£¬£¬£¬£¬ForescoutÑо¿ÍŶӷ¢Ã÷ÁËPTC AxedaÖеÄ7¸öÎó²îAccess:7¡£¡£ ¡£¡£Axeda¿Éͨ¹ýÍâµØ°²ÅŵÄÊðÀí£¬£¬£¬£¬ÌṩÀ´×ÔÍøÂçÉÏÎïÁªÍø×°±¸µÄÒ£²âÊý¾ÝºÍÔ¶³ÌЧÀÍ£¬£¬£¬£¬Ö÷ÒªÓÃÓÚÒ½ÁƱ£½¡ÐÐÒµ¡£¡£ ¡£¡£´Ë´ÎÅû¶µÄ×îÑÏÖØµÄÊÇ3¸ö´úÂëÖ´ÐÐÎó²îCVE-2022-25251¡¢CVE-2022-25246ºÍCVE-2022-25247£¬£¬£¬£¬CVSSÆÀ·Ö»®·ÖΪ9.4¡¢9.8ºÍ9.8¡£¡£ ¡£¡£ForescoutÚ¹ÊÍ˵£¬£¬£¬£¬¾ÍÒ½ÁÆ×°±¸¶øÑÔ£¬£¬£¬£¬×ÝÈ»ÊDz»Ì«ÑÏÖØµÄÎó²îÒ²»á±¬·¢ÖØ´óÓ°Ïì¡£¡£ ¡£¡£ÏÖÔÚ£¬£¬£¬£¬AxedaÒÑÐÞ¸´ÁËËùÓеÄAccess:7Îó²î¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/access-7-vulnerabilities-impact-medical-and-iot-devices/



Çå¾²¹¤¾ß


GO/NET Scanner


´øÓÐ Arp ·¢Ã÷ºÍ×Ô¼ºµÄÆÊÎöÆ÷µÄ Golang ÍøÂçɨÃè³ÌÐò¡£¡£ ¡£¡£


https://github.com/luijait/GONET-Scanner


GraphQL Cop 


ÊÇÒ»¸öСÐÍ Python ÊÊÓóÌÐò£¬£¬£¬£¬ÓÃÓÚÕë¶ÔGraphQL API ÔËÐг£¼ûµÄÇå¾²²âÊÔ¡£¡£ ¡£¡£


https://github.com/dolevf/graphql-cop


FastFuzz Chrome Extension


´øÓÐ chrome À©Õ¹µÄ¿ìËÙfuzzingÍøÕ¾¡£¡£ ¡£¡£


https://github.com/tismayil/fastfuz-chrome-ext


s3sec


ÓÃÀ´²âÊÔ AWS S3 ´æ´¢Í°µÄ¶Á/д/ɾ³ý»á¼û¡£¡£ ¡£¡£


https://github.com/0xmoot/s3sec


zkar


ÊÇÒ»¸öÓà Go ʵÏÖµÄ JavaÐòÁл¯Ð­ÒéÆÊÎö¹¤¾ß£¬£¬£¬£¬ÈÔÔÚ¿ª·¢ÖС£¡£ ¡£¡£


https://github.com/phith0n/zkar



Çå¾²ÆÊÎö


Coinbase ×èÖ¹ÁËÁè¼Ý 25,000 ¸öÓë¶íÂÞ˹Ïà¹ØµÄ¼ÓÃܵصã


https://www.bleepingcomputer.com/news/security/coinbase-blocks-over-25-000-russian-linked-crypto-addresses/


FBI£ºÕþ¸®¹ÙÔ±ÔÚ´ó×ÚÀÕË÷»î¶¯Öб»Ã°³ä


https://www.bleepingcomputer.com/news/security/fbi-govt-officials-impersonated-in-widespread-extortion-schemes/


¶íÂÞ˹·Å¿íµÁ°æÈí¼þÔÊÐí¹æÔò


https://www.bleepingcomputer.com/news/government/piracy-ok-russia-to-ease-software-licensing-rules-after-sanctions/


ÏàʶºÚ¿ÍÔõÑùÕì̽


https://thehackernews.com/2022/03/understanding-how-hackers-recon.html


ÔõÑùͨ¹ý Alexa µÄÓïÒôÈëÇÖ Alexa


https://www.schneier.com/blog/archives/2022/03/hacking-alexa-through-alexas-speech.html