¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.3.15-3.21£©
2021-03-22
Ò»¡¢ Íþвͨ¸æ
Apache Solrí§ÒâÎļþ¶ÁÈ¡ÓëSSRFÎó²î
¡¾Ðû²¼Ê±¼ä¡¿2021-03-18 16:00:00 GMT
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬AG¹«Ë¾¿Æ¼¼¼à²âµ½ÍøÉÏÅû¶ÁË ApacheSolr µÄÎļþ¶ÁÈ¡Óë SSRF Îó²î£¬ÓÉÓÚ Apache Solr ĬÈÏ×°ÖÃʱ먦ÆôÉí·ÝÑéÖ¤£¬µ¼ÖÂδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉʹÓà Config API ·¿ª requestDispatcher.requestParsers.enableRemoteStreaming ¿ª¹Ø£¬´Ó¶øÊ¹ÓÃÎó²î¾ÙÐÐÎļþ¶ÁÈ¡¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
GitLabÔ¶³Ì´úÂëÖ´ÐÐÎó²î
¡¾Ðû²¼Ê±¼ä¡¿2021-03-18 16:00:00 GMT
¡¾¸ÅÊö¡¿
2021Äê 3 Ô 18 ÈÕ£¬AG¹«Ë¾¿Æ¼¼¼à²âµ½ GitLab ¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬ÐÞ¸´Á˱£´æÓÚÉçÇø°æ(CE)ºÍÆóÒµ °æ(EE)ÖÐµÄ ´úÂëÖ´ÐÐÎó²î£¬CVSS ÆÀ·ÖΪ 9.9¡£Î´ÊÚȨµ«¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýʹÓÃ¿É¿ØµÄ markdown äÖȾѡÏ½á¹¹¶ñÒâÇëÇó´Ó¶øÔÚ·þÎñÆ÷ÉÏÖ´ÐÐí§Òâ´úÂë¡£ GitLab ÊÇÒ»¸öÓÃÓÚ¿ÍÕ»ÖÎÀíϵͳµÄ¿ªÔ´ÏîÄ¿£¬Ê¹Óà Git ×÷Ϊ´úÂëÖÎÀí¹¤¾ß£¬¿Éͨ¹ý Web ½çÃæ»á¼û¹ûÕæ»ò˽ÈËÏîÄ¿¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
XStream ¶à¸ö¸ßΣÎó²î
¡¾Ðû²¼Ê±¼ä¡¿2021-03-16 16:00:00 GMT
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬AG¹«Ë¾¿Æ¼¼¼à²âµ½XStream¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬¹ûÕæÁËXStreamÖеÄ11¸öÇå¾²Îó²î£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îÔì³É¾Ü¾ø·þÎñ¡¢SSRF¡¢É¾³ýí§ÒâÎļþ¡¢Ô¶³ÌÖ´ÐÐí§Òâ´úÂë¡£XStreamÊÇÒ»¸öJava¹¤¾ßºÍXMLÏ໥ת»»µÄ¹¤¾ß£¬ÔÚ½«JavaBeanÐòÁл¯¡¢»ò½«XMLÎļþ·´ÐòÁл¯Ê±£¬Ëü²»ÐèÒªÆäËü¸¨ÖúÀàºÍÓ³ÉäÎļþ£¬ÕâʹµÃXMLÐòÁл¯²»ÔÙ·±Ëö¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. Õë¶ÔµçÐŹ«Ë¾ÍøÂç¹¥»÷ÒÔÇÔÈ¡5GÉñÃØ
¡¾¸ÅÊö¡¿
OperationsDiànxùnÊÇÒ»ÆðÕë¶ÔµçÐŹ«Ë¾µÄÍøÂçÌØ¹¤Ô˶¯£¬ÒÔÇÔÈ¡Óë5GÊÖÒÕÏà¹ØµÄÃô¸ÐÊý¾ÝºÍÉÌÒµÉñÃØÎªÄ¿µÄ£¬Ìᳫ´Ë´Î¹¥»÷Ô˶¯µÄÍþв×éÖ¯ÒÉËÆÓëÖйúÓйء£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/115693/apt/chinese-hackers-5g.html
2. Ê©Ä͵ÂÖÇÄܵç±íÄڴ滺³åÇøÎó²î
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬AG¹«Ë¾¿Æ¼¼¼à²âµ½Ê©Ä͵ÂÐû²¼Í¨¸æÅû¶ÁËÖÇÄܵç±íµÄÁ½¸ö»º´æÇøÒç³öÎó²î£¬CVE-2021-22714ΪÕûÊýÒç³öÎó²î£¬¹¥»÷ÕßÄܹ»Æ¾Ö¤ÏµÍ³½á¹¹Ê¹Óòî±ðʹÓ÷½·¨Ïò×°±¸·¢ËÍÌØÖÆµÄTCPÊý¾Ý°ü£¬Ôì³ÉÄ¿µÄµç±íÖØÆô»òÔ¶³Ì´úÂëÖ´ÐУ¬CVSSÆÀ·ÖΪ9.8¡£CVE-2021-22713ÊÇÓÉÓÚ¶ÔÄڴ滺³åÇøÄÚ²Ù×÷µÄ²»µ±ÏÞÖÆÔì³ÉµÄ£¬¹¥»÷Õß¿ÉʹÓôËÎó²îÇ¿ÖÆµç±íÖØÆô£¬CVSSÆÀ·ÖΪ7.5¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.claroty.com/2021/03/09/blog-research-schneider-electric-smart-meter-vulnerabilities/
3. ZHtrap½©Ê¬ÍøÂçͨ¹ýÃÛ¹ÞÀ´²éÕÒ¸ü¶àÊܺ¦Õß
¡¾¸ÅÊö¡¿
Ò»ÖÖеĻùÓÚMiraiµÄ½©Ê¬ÍøÂ磬±»³ÆÎªZHtrap£¬¸Ã½©Ê¬ÍøÂçʵÏÖʹÓÃÃÛ¹ÞÀ´²éÕÒ¸ü¶àÊܺ¦Õß¡£ZHtrap½©Ê¬ÍøÂçʹÓÃËĸöÎó²î¾ÙÐÐÈö²¥£¬Ö÷ÒªÓÃÓÚ¾ÙÐÐDDoS¹¥»÷ºÍɨÃèÔ˶¯£¬Í¬Ê±¼¯³ÉÁËһЩºóÃŹ¦Ð§¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/115684/cyber-crime/zhtrap-botnet-honeypot.html
4. ÍøÂç·¸·¨·Ö×ÓÀÄÓÃWSH-RAT
¡¾¸ÅÊö¡¿
×î½üÑо¿Ö°Ô±·¢Ã÷ÌØÊâ¾ßÓдú±íÐԵĹ¥»÷Ô˶¯£¬Ê¹ÓÃWSH-RATÌ×¼þÆÊÎöÁËÒ»ÌõѬȾÁ´£¬¸ÃÌ×¼þÊÇÔÚµØÏ³öÊÛµÄÍêÕûµÄÔ¶³ÌÖÎÀí¹¤¾ß£¬¾³£±»·¸·¨·Ö×ÓÀÄÓ㬺óÕßÒÀÀµÏֳɵÄÌ×¼þ¾ÙÐй¥ÊÆ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://yoroi.company/research/threatening-within-budget-how-wsh-rat-is-abused-by-cyber-crooks/
5. BleachGapÀÕË÷Èí¼þͨ¹ýUÅÌÈö²¥
¡¾¸ÅÊö¡¿
½üÆÚÑо¿Ö°Ô±²¶»ñµ½Ò»Ö־߱¸¿ÉÒÆ¶¯½éÖÊÈö²¥¹¦Ð§µÄBleachGapÀÕË÷Èí¼þ¡£¸ÃÀÕË÷Èí¼þ×îÔç·ºÆðÓÚ2021Äê2Ô£¬ÏÖÔÚÒѵü´ú¶à¸ö°æ±¾¡£BleachGapÀÕË÷Èí¼þ¾ß±¸Ìí¼Ó×ÔÆô¶¯¡¢Ìí¼ÓÍýÏëʹÃü¡¢¸ÄдMBR¡¢Ê¹¼üÅ̰´¼üʧЧ¡¢Í¨¹ý¿ÉÒÆ¶¯½éÖÊÈö²¥µÈ¶àÏЧ£¬½ÓÄÉ“AES-256”¶Ô³Æ¼ÓÃÜËã·¨¼ÓÃÜÎļþ£¬ÔÚÒÑÖªÃÜÔ¿µÄÇéÐÎÏ¿ɿìËÙ½âÃÜ¡£ÏÖÔÚ£¬ÀÕË÷Èí¼þµÄ¹¦Ð§ÒѾ²»¾ÖÏÞÓÚ¼ÓÃÜÎļþ£¬×îÏÈʵÑéͨ¹ý¿ÉÒÆ¶¯½éÖʵķ½·¨ºáÏòÈö²¥£¬Óû§ÐèʵʱÕë¶Ô´ËÀ๥»÷ÊÖ¶Î×öºÃÓÐÓÃÌá·À²½·¥¡£
¡¾²Î¿¼Á´½Ó¡¿
https://mp.weixin.qq.com/s?__biz=MjM5MTA3Nzk4MQ==&mid=2650182226&idx=1&sn=498d62a3072401ee1501ba6836df63db&chksm=beb9316089ceb876e59f608074780f0b359152d47ed76801191d87481d609189dad2c1f3ca8b#rd
6. OVHÊý¾ÝÖÐÐÄ»ðÔÖÓ°ÏìAPTÍþв×éÖ¯
¡¾¸ÅÊö¡¿
È«Çò×î´óµÄÍйܷþÎñÌṩÉÌÖ®Ò»OVHÉÏÖÜÔâÊÜ»ðÔÖ£¬´Ý»ÙÁËÆäλÓÚË¹ÌØÀ˹±¤µÄÊý¾ÝÖÐÐÄ¡£¿¨°Í˹»ùʵÑéÊÒÈ«ÇòÑо¿ºÍÆÊÎöÍŶӣ¨GReAT£©Í¸Â¶£¬ÓÉÓÚC2·þÎñÆ÷ÍÑ»ú£¬ÖÖÖÖÍþв¼ÓÈëÕßʹÓõÄ140̨OVH·þÎñÆ÷ÖÐÓÐ36£¥´¦ÓÚÍÑ»ú״̬£¬ÆäÖаüÀ¨Charming Kitten¡¢APT39¡¢BahamutºÍOceanLotus×éÖ¯¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/115559/apt/ovh-fire-apt-impact.html
7. DearCryÀÕË÷Èí¼þ
¡¾¸ÅÊö¡¿
ÉÏÖÜ£¬Microsoft±¨¸æ³Æ¹¥»÷ÕßʹÓÃËĸöÁãÈÕÎó²îÀ´ÆÆËðExchange Mail Server ¡£Ö»¹ÜMicrosoftÒÑÐû²¼²¹¶¡£¬µ«¹¥»÷ÕßÈÔÔÚͨ¹ý¶ñÒ⹤¾ß¡¢¶ñÒâÈí¼þºÍÊý¾Ýй¶¹¥»÷Ò×Êܹ¥»÷µÄMicrosoft Exchange Server°æ±¾¡£±ðµÄ£¬MicrosoftÒѾȷÈϱ£´æÊ¹ÓÃÕâЩÎó²îµÄÀÕË÷Èí¼þ±äÖÖ£¬¸Ã±äÖÖ±»³ÆÎªDearCry¡£DearCryÀÕË÷Èí¼þÒѾ±»·¢Ã÷ʹÓÃMicrosoft Exchange ServerµÄProxyLogonÎó²î¾ÙÐгõʼ»á¼û£¬Õë¶ÔÃÀ¹ú¡¢¼ÓÄôóºÍ°Ä´óÀûÑǵØÇøµÄÓû§¡£
¡¾²Î¿¼Á´½Ó¡¿
https://unit42.paloaltonetworks.com/dearcry-ransomware/
8. й¥»÷ʹÓÃαÔìͼ±êÀ´Èö²¥NanoCoreľÂí
¡¾¸ÅÊö¡¿
Ò»¸öеĶñÒâÀ¬»øÓʼþÔ˶¯ÕýÔÚ½«NanoCoreÔ¶³Ì»á¼ûľÂí×÷Ϊ¶ñÒâAdobeͼ±êÀ´Ñ¬È¾ÆäÊܺ¦Õß¡£NanoCore RAT£¨Ò²³ÆÎªNancrat£©×Ô2013ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬¸Ã¶ñÒâÈí¼þÖ¼ÔÚÇÔÈ¡PCÉϵÄÐÅÏ¢£¬ÀýÈçÃÜÂëºÍµç×ÓÓʼþ£»Ëü»¹Äܹ»»á¼û¡¢Ð޸ĺͻñÈ¡PCÉÏÈκÎÎļþµÄ¸±±¾£¬²¢¼¤»îÍøÂçÉãÏñÍ·ÒÔ¼àÊÓÊܺ¦Õߣ¬²¢¼Í¼»÷¼ü¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.inforisktoday.com/new-attack-uses-fake-icon-to-deliver-trojan-a-16179
9. ÃÀ¹úÔËÊäÖÎÀíÈí¼þ¹«Ë¾µÄÃô¸ÐÊý¾ÝÔÚÏß̻¶
¡¾¸ÅÊö¡¿
ÃÀ¹úÔËÊäÖÎÀíÈí¼þ¹«Ë¾×ܼÆ103 GBÃô¸ÐÊý¾ÝÔâй¶£¬ÕâЩÊý¾ÝÀ´×Ô»ùÓÚNew JersyµÄDescartes Aljex Software £¬ÓÉÓÚÉèÖùýʧµÄAWS S3´æ´¢Í°¶øÌ»Â¶£¬¸Ã´æ´¢Í°²»Çå¾²ÇÒÈÝÒ×Êܵ½ÈëÇÖ¡£ÕâÒâζ×Å£¬×ÝȻûÓÐÊÚȨµÄÓû§Ò²¿ÉÄܽöͨ¹ýÊäÈë׼ȷµÄURL¼´¿É»á¼û´æ´¢Í°¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨¹«Ë¾Ô±¹¤¡¢ÏúÊÛ´ú±íºÍµÚÈý·½ÔËÓªÉÌÊÂÇéÖ°Ô±µÄÏêϸСÎÒ˽¼ÒÐÅÏ¢¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.hackread.com/shipping-management-software-firm-data-online/

AG¹«Ë¾ÔÆ







