ÍøÐŰìÐû²¼¡¶Î´³ÉÄêÈËÍøÂç±£»£»£»£»£»£»¤ÌõÀý£¨Õ÷ÇóÒâ¼û¸å£©¡·
Ðû²¼Ê±¼ä 2022-03-17ÍøÐŰìÐû²¼¡¶Î´³ÉÄêÈËÍøÂç±£»£»£»£»£»£»¤ÌõÀý£¨Õ÷ÇóÒâ¼û¸å£©¡·
3ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬¹ú¼Ò»¥ÁªÍøÐÅÏ¢°ì¹«ÊÒÐû²¼¹ØÓÚ¡¶Î´³ÉÄêÈËÍøÂç±£»£»£»£»£»£»¤ÌõÀý£¨Õ÷ÇóÒâ¼û¸å£©¡·ÔٴιûÕæÕ÷ÇóÒâ¼ûµÄ֪ͨ¡£¡£¡£¡£¡£Îª±£»£»£»£»£»£»¤Î´³ÉÄêÈËÉíÐÄ¿µ½¡ºÍÆäÔÚÍøÂç¿Õ¼äµÄÕýµ±È¨Ò棬£¬£¬£¬£¬£¬Ç°ÆÚÍøÐŰìÆð²ÝÁË¡¶Î´³ÉÄêÈËÍøÂç±£»£»£»£»£»£»¤ÌõÀý£¨Õ÷ÇóÒâ¼û¸å£©¡·¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬Æ¾Ö¤ÐÂÐÞ¶©µÄ¡¶ÖлªÈËÃñ¹²ºÍ¹úδ³ÉÄêÈ˱£»£»£»£»£»£»¤·¨¡·µÈÖ´·¨ºÍÉç»á¹«ÖÚ·´ÏìÒâ¼û£¬£¬£¬£¬£¬£¬¶Ô¸ÃÌõÀý¾ÙÐÐÁËÐÞ¸ÄÍêÉÆ¡£¡£¡£¡£¡£ÌõÀýÖ¸³ö£¬£¬£¬£¬£¬£¬ÍøÂç²úÆ·ºÍЧÀÍÌṩÕßÓ¦µ±½¨É轡ȫ·À×ÅÃÔÖÆ¶È£¬£¬£¬£¬£¬£¬²»µÃÏòδ³ÉÄêÈËÌṩÓÕµ¼Æä×ÅÃԵIJúÆ·ºÍЧÀÍ¡£¡£¡£¡£¡£
http://www.cac.gov.cn/2022-03/14/c_1648865100662480.htm
QNAPͨ¸æ³ÆDirty PipeÎó²î»áÓ°ÏìÆä´ó²¿·ÖNAS×°±¸
Ó²¼þ¹©Ó¦ÉÌQNAPÔÚ3ÔÂ14ÈÕÐû²¼Í¨¸æ£¬£¬£¬£¬£¬£¬³ÆÆä´ó²¿·ÖÍøÂ總¼Ó´æ´¢(NAS)×°±¸¶¼Êܵ½LinuxÎó²îDirty PipeµÄÓ°Ïì¡£¡£¡£¡£¡£Í¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬Õâ¸öÎó²îÖ÷Òª»áÓ°ÏìÔËÐÐQTS 5.0.xºÍQuTS hero h5.0.xµÄ×°±¸£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÆä»ñµÃÖÎÀíԱȨÏÞ²¢×¢Èë¶ñÒâ´úÂë¡£¡£¡£¡£¡£ËäÈ»Õë¶ÔLinuxÄں˵IJ¹¶¡ÒÑÓÚÒ»ÖÜǰÐû²¼£¬£¬£¬£¬£¬£¬µ«¸Ã¹«Ë¾½¨ÒéÓû§¹Ø±Õ·ÓÉÆ÷¶Ë¿Úת·¢¹¦Ð§²¢½ûÓÃQNAP NASµÄUPnP¹¦Ð§À´»º½â¸ÃÎó²î£¬£¬£¬£¬£¬£¬Ö±µ½QNAPÐû²¼×Ô¼ºµÄÇå¾²¸üС£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/qnap-warns-severe-linux-bug-affects-most-of-its-nas-devices/
ÒÔÉ«ÁÐÔâµ½´ó¹æÄ£DDoS¹¥»÷£¬£¬£¬£¬£¬£¬Õþ¸®»ú¹¹¶à¸öÍøÕ¾¹Ø±Õ
¾ÝýÌå3ÔÂ15ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬ÒÔÉ«ÁÐÕþ¸®»ú¹¹µÄ¶à¸öÍøÕ¾ÔÚ±¾ÖÜÒ»Ôâµ½´ó¹æÄ£DDoS¹¥»÷¡£¡£¡£¡£¡£°üÀ¨ÎÀÉú²¿¡¢ÄÚÕþ²¿ºÍ˾·¨²¿ÔÚÄڵĶà¸ö²¿Î¯¶¼Êܵ½Á˹¥»÷µÄÓ°Ï죬£¬£¬£¬£¬£¬×ÜÀí°ì¹«ÊÒµÄÍøÕ¾Ò²ÔÝʱ¹Ø±Õ¡£¡£¡£¡£¡£¸Ã¹ú¹ú·À»ú¹¹ºÍ¹ú¼ÒÍøÂç¾ÖÒÑÐû²¼½øÈë½ôÆÈ״̬£¬£¬£¬£¬£¬£¬ÏÖÔÚÕýÔÚÈ·¶¨¹¥»÷ÊÇ·ñ¶ÔÒÔÉ«ÁеÄÒªº¦»ù´¡ÉèÊ©Ôì³ÉÁËΣÏÕ¡£¡£¡£¡£¡£ÍâµØÃ½Ì峯£¬£¬£¬£¬£¬£¬´Ë´Î¹¥»÷¿ÉÄÜÀ´×ÔÓëÒÁÀÊÏà¹ØµÄ¹¥»÷Õß¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬ÕâÊÇÓÐÊ·ÒÔÀ´Õë¶ÔÒÔÉ«ÁеÄ×î´ó¹æÄ£µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/129063/cyber-warfare-2/massive-ddos-attack-hit-israel.html
PandoraÍÅ»ïÉù³ÆÒÑÈëÇÖDENSO¹«Ë¾²¢ÇÔÈ¡1.4TBµÄÊý¾Ý
ýÌå3ÔÂ14Èճƣ¬£¬£¬£¬£¬£¬DENSOÈÏ¿ÉÆäÔڵ¹úµÄ¼¯ÍŹ«Ë¾ÓÚ3ÔÂ10ÈÕÔâµ½ÈëÇÖ¡£¡£¡£¡£¡£DENSOÊÇÈ«Çò×î´óµÄÆû³µÁ㲿¼þÖÆÔìÉÌÖ®Ò»£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÌåÏÖÔÚ¼ì²âµ½Î´¾ÊÚȨµÄ»á¼ûºó£¬£¬£¬£¬£¬£¬Á¬Ã¦ÇжÏÁ˱»¹¥»÷×°±¸µÄÍøÂçÅþÁ¬£¬£¬£¬£¬£¬£¬ËùÓÐÉú²ú¹¤³§¶¼½«Õý³£ÔËÐУ¬£¬£¬£¬£¬£¬Òò´ËÔ¤¼Æ´Ë´ÎÊÂÎñ²»»áµ¼Ö¹©Ó¦Á´ÖÐÖ¹¡£¡£¡£¡£¡£ÀÕË÷ÍÅ»ïPandoraÉù³Æ¶Ô´ËÊÂÈÏÕæ£¬£¬£¬£¬£¬£¬²¢ÒÑ×îÏÈй¶ÆäÇÔÈ¡µÄ1.4TBÎļþ£¬£¬£¬£¬£¬£¬ÆäÐû²¼µÄÑù±¾Êý¾Ý°üÀ¨²É¹º¶©µ¥¡¢ÊÖÒÕÔÀíͼºÍ±£ÃÜÐÒéµÈ¡£¡£¡£¡£¡£
https://www.zdnet.com/article/automotive-giant-denso-reveals-hack-pandora-ransomware-group-takes-credit/
ESETÐû²¼Õë¶ÔÎÚ¿ËÀ¼µÄжñÒâÈí¼þCaddyWiperµÄ±¨¸æ
3ÔÂ15ÈÕ£¬£¬£¬£¬£¬£¬ESETÐû²¼Õë¶ÔÎÚ¿ËÀ¼µÄжñÒâÈí¼þCaddyWiperµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£ÕâÊÇÒ»¸öÊý¾Ý²Á³ý¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬ÓÚ±¾ÖÜÒ»ÉÏÎçÊ״α»·¢Ã÷¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚÒÑÔÚ¶à¸ö×éÖ¯µÄ¼¸Ê®¸öϵͳÉϼì²âµ½Ëü£¬£¬£¬£¬£¬£¬±»ÓÃÀ´ÆÆËðÅþÁ¬Çý¶¯ÉϵÄÓû§Êý¾ÝºÍ·ÖÇøÐÅÏ¢¡£¡£¡£¡£¡£CaddyWiperÓëHermeticWiperºÍIsaacWiperµÄ´úÂëûÓÐÏàËÆÖ®´¦£¬£¬£¬£¬£¬£¬µ«ÓÐÖ¤¾ÝÅú×¢¹¥»÷ÕßÔÚÔÚ·Ö·¢¶ñÒâÈí¼þ֮ǰ¾ÍÉøÍ¸ÁËÄ¿µÄµÄÍøÂç¡£¡£¡£¡£¡£
https://www.welivesecurity.com/2022/03/15/caddywiper-new-wiper-malware-discovered-ukraine/
OpenSSLÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´DoSÎó²îCVE-2022-0778
¾Ý3ÔÂ15ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬OpenSSLÐû²¼Çå¾²¸üÐÂÒÔÐÞ¸´¾Ü¾øÐ§ÀÍ(DoS)Îó²î£¨CVE-2022-0778£©¡£¡£¡£¡£¡£¸ÃÎó²îÓÉGoogle Project ZeroÑо¿Ö°Ô±Tavis Ormandy·¢Ã÷£¬£¬£¬£¬£¬£¬Ô´ÓÚÆÊÎöÖ¤ÊéʱÅÌËãģƽ·½¸ùµÄBN_mod_sqrt()º¯ÊýÖб£´æÒ»¸ö¹ýʧ£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂËüÓÀÔ¶Ñ»·ÅÌËã·ÇËØÊýÄ£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬£¬£¬¿ÉÒÔʹÓÃÎÞЧµÄÏÔʽÇúÏß²ÎÊýÖÆ×÷ÃûÌùýʧµÄÖ¤ÊéÀ´´¥·¢´ËÎó²î¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁËOpenSSL°æ±¾ 1.0.2¡¢1.1.1ºÍ3.0£¬£¬£¬£¬£¬£¬ÒÑͨ¹ýÐû²¼°æ±¾1.0.2zd¡¢1.1.1nºÍ3.0.2ÐÞ¸´¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/129104/security/openssl-dos-vulnerability.html
Çå¾²¹¤¾ß
CodeAnalysis
×ÛºÏÐԵĴúÂëÆÊÎöºÍÎÊÌâ¸ú×ÙÆ½Ì¨¡£¡£¡£¡£¡£
https://github.com/Tencent/CodeAnalysis
DomainAlerting
ÍøÂç°üÀ¨Òªº¦×ÖµÄ×¢²áµÄÐÂÓòÃû£¬£¬£¬£¬£¬£¬²¢ÖðÈÕ¾¯±¨¡£¡£¡£¡£¡£
https://github.com/pixelbubble/DomainAlerting
NimPackt-v1
ÓÃÓÚ .NET ¿ÉÖ´ÐÐÎļþºÍÔʼ shellcode µÄ»ùÓÚ Nim µÄ´ò°ü³ÌÐò¡£¡£¡£¡£¡£
https://github.com/chvancooten/NimPackt-v1
PurplePanda
´Ó¹Ø×¢È¨Ï޵IJî±ðÔÆ/SaaS Ó¦ÓóÌÐòÖлñÈ¡×ÊÔ´£¬£¬£¬£¬£¬£¬ÒÔʶ±ðÔÆ/saas ÉèÖÃÖеÄȨÏÞÌáÉý·¾¶ºÍΣÏÕȨÏÞ¡£¡£¡£¡£¡£
https://github.com/carlospolop/PurplePanda
Çå¾²ÆÊÎö
Mozilla Firefox Òò¹ýʧÐÅÏ¢ÎÊÌâ¶øÉ¾³ýÁ˶íÂÞ˹ËÑË÷ÌṩÉÌ
https://www.bleepingcomputer.com/news/software/mozilla-firefox-removes-russian-search-providers-over-misinformation-concerns/
Æ»¹ûÐû²¼ iOS 15.4£¬£¬£¬£¬£¬£¬Óû§¿É´ø×Å¿ÚÕÖʹÓà Face ID
https://news.softpedia.com/news/apple-finally-releases-ios-15-4-face-id-with-a-mask-now-available-for-all-users-535039.shtml
΢ÈíΪ VirtualBox Óû§É¾³ýÁË Windows 11 ¸üÐÂÄ£¿£¿£¿£¿£¿£¿é
https://www.bleepingcomputer.com/news/microsoft/microsoft-removes-windows-11-update-block-for-virtualbox-users/
ºÚ¿ÍÃé×¼¶íÂÞ˹ʯÓ͹«Ë¾µÄµÂ¹ú·Ö¹«Ë¾
https://securityaffairs.co/wordpress/129052/hacktivism/anonymous-hacked-german-subsidiary-rosneft.html
Ñо¿Ö°Ô±·¢Ã÷½« Kwampirs Óë Shamoon APT ÁªÏµÆðÀ´µÄÐÂÖ¤¾Ý
https://thehackernews.com/2022/03/researchers-find-new-evidence-linking.html
ÓÃÓÚÔÚÎÚ¿ËÀ¼°²ÅÅ Cobalt Strike µÄÐéα·À²¡¶¾¸üÐÂ
https://www.bleepingcomputer.com/news/security/fake-antivirus-updates-used-to-deploy-cobalt-strike-in-ukraine/


¾©¹«Íø°²±¸11010802024551ºÅ