¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.08.02-2021.08.08£©
2021-08-09
Ò»¡¢ Íþвͨ¸æ
LinuxKernelí§Òâ´úÂëÖ´ÐÐÎó²îͨ¸æ£¨CVE-2021-3490£©
¡¾Ðû²¼Ê±¼ä¡¿2021-08-0218:00:00GMT
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½ÓÐÑо¿Ö°Ô±¹ûÕæÅû¶ÁËeBPFÖеÄÒ»¸öí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-3490£©µÄϸ½ÚÐÅÏ¢ºÍPoC£¬²¢ÑÝʾʹÓôËÎó²îÔÚUbuntu20.10ºÍ21.04ÉÏʵÏÖÍâµØÈ¨ÏÞÌáÉý£¬¸ÃÎó²îÊÇÓÉÓÚLinuxÄÚºËÖа´Î»²Ù×÷£¨AND¡¢ORºÍXOR£©µÄeBPFALU32½çÏ߸ú×ÙûÓÐ׼ȷ¸üÐÂ32λ½çÏߣ¬Ôì³ÉLinuxÄÚºËÖеÄÔ½½ç¶ÁÈ¡ºÍдÈ룬´Ó¶øµ¼ÖÂí§Òâ´úÂëÖ´ÐС£¹Ù·½ÒÑÓÚ5ÔÂ11ºÅÐû²¼ÐÞ¸´°æ±¾£¬ÇëÏà¹ØÓû§ÊµÊ±½ÓÄɲ½·¥·À»¤¡£ExtendedBerkeleyPacketFilter£¨eBPF£©ÊÇÒ»ÖÖÄÚºËÊÖÒÕ£¨´ÓLinux4.x×îÏÈ£©£¬ÔÊÐí³ÌÐòÔËÐжøÎÞÐè¸Ä±äÄÚºËÔ´´úÂë»òÌí¼ÓÌØÁíÍâÄ£¿é¡£ËüÊÇLinuxÄÚºËÖеÄÒ»ÖÖÇáÁ¿¼¶µÄɳºÐÐéÄâ»ú£¨VM£©£¬¿ÉÒÔÔÚÆäÖÐÔËÐÐʹÓÃÌØ¶¨ÄÚºË×ÊÔ´µÄBPF×Ö½ÚÂë¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. ¹¥»÷ÕßʹÓÃÓã²æÊ½ÍøÂç´¹ÂÚÊÖÒÕÏòÓû§·Ö·¢µç×ÓÓʼþ¹¥»÷ÆóÒµÓû§
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±³Æ£¬¹¥»÷ÕßʹÓÃÓã²æÊ½ÍøÂç´¹ÂÚÊÖÒÕÏòÆóÒµÓû§´«Èëµç×ÓÓʼþ£¬Í¨¹ýʹÓÃÓòÃû·ÂðµÈ·½·¨¹¥»÷ÆóÒµÓû§£¬ËäÈ»ÍøÂç´¹ÂÚ¹¥»÷Ò»Ö±ÊÇÍøÂçÇå¾²ÁìÓòµÄ³£Ì¬£¬È»¶ø£¬ÇéÐÎÕýÔÚ±¬·¢×ª±ä£¬Ëæ×Ź¥»÷Õß´ÓÕë¶ÔСÎÒ˽¼ÒתÏòÒÔÆóÒµºÍ×é֯ΪĿµÄ£¬½ñÌìµÄÍøÂç´¹ÂÚ¹¥»÷±È1996Äê¡¢2006ÄêÉõÖÁ2016ÄêµÄ¹¥»÷ÒªÖØ´óµÃ¶à¡£
×î½üÓб¨µÀ³Æ£¬¹¥»÷ÕßÌᳫµÄÍøÂç´¹ÂÚÔ˶¯Ö÷ÒªÕë¶ÔÈ«Çò×ÔÈ»ÆøºÍʯÓÍ¡¢ÄÜÔ´¡¢Ã½Ìå¡¢ITºÍµç×ÓÐÐÒµµÄÆóÒµ£¬¹¥»÷Õßͨ¹ý¸øÕâЩÆóÒµ´«Èëµç×ÓÓʼþ£¬Ê¹ÓÃÁËÓÕÆºÍÓòÃû·ÂðµÈÊÖÒÕ£¬´«ÈëµÄµç×ÓÓʼþ¿´ÆðÀ´ÏñÊÇ´ÓÕæÊµ¹«Ë¾·¢Ë͵ġ£¹¥»÷Õß»¹Í¨¹ýÈ«ÐÄÖÆ×÷ÌØ¶¨Îı¾£¬°´Ãû³ÆÒýÓù«Ë¾¸ß¹Ü²¢°üÀ¨ÕæÊµµÄ¹«Ë¾µØµãºÍ¹«Ë¾»Õ±ê£¬´Ó¶ø±Ü¿ªÁË“¹Å°å”ÍøÂç´¹ÂÚÐÂÎŵÄÉ¢²¼Ê½·º»¯ÒªÁì¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMJO
2. ¹¥»÷Õß¹¥»÷Òâ´óÀûйڷÎÑ×ÒßÃçԤԼϵͳ
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±³Æ£¬ÔÚÒ½ÁƱ£½¡ÏµÍ³µÄÍøÂç¹¥»÷ÖУ¬¹¥»÷Õß¹¥»÷Òâ´óÀûÀÆë°ÂµØÇøµÄйÚÒßÃçԤԼϵͳ¡£ÏÖÔÚ£¬¸ÃµØÇøµÄFacebookÒ³ÃæÒѾ²»¿ÉÔËÐУ¬¹¥»÷ÕßÒѾ½ûÓÃÁ˸õØÇøÎÀÉú±£½¡»ú¹¹µÄϵͳ¡£¾Ý±¨µÀ£¬Òâ´óÀû³ýÁËÒßÃç½ÓÖÖԤԼϵͳÍ⣬ÉÐÓÐÐí¶àϵͳ¶¼Êܵ½Á˹¥»÷Õß¹¥»÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMJE
3. ¹¥»÷ÕßʹÓÃÀÕË÷Èí¼þ¹¥»÷ÃÀ¹úΣº¦Í¶×ʹ«Ë¾
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±³Æ£¬¹¥»÷Õß¹¥»÷ÁËÃÀ¹úΣº¦Í¶×ʹ«Ë¾AdvancedTechnologyVentures£¨ATV£©¡£ÒÔ¼°ÇÔÈ¡Á˹«Ë¾Í¶×ÊÕßµÄÊý¾ÝÐÅÏ¢¡£±¨µÀ³Æ£¬¹¥»÷ÕßÔÚÊý¾Ý¼ÓÃÜ֮ǰÇÔÈ¡ÁËÃÀ¹úΣº¦Í¶×ʹ«Ë¾´æ´¢ÔÚÁ½Ì¨·þÎñÆ÷ÉϵIJÆÎñÐÅÏ¢¡£2021Äê7ÔÂ9ÈÕ£¬¹«Ë¾´ÓÆäµÚÈý·½ÐÅÏ¢ÊÖÒÕÌṩÉÌ´¦»ñϤ£¬¹«Ë¾´æ´¢²ÆÎñ±¨¸æÐÅÏ¢µÄÁ½Ì¨ÏàͬµÄATV·þÎñÆ÷·ºÆðÒì³£Ô˶¯¡£¹«Ë¾ºÜ¿ìÈ·¶¨·þÎñÆ÷Òѱ»¹¥»÷Õß¹¥»÷¼ÓÃÜ¡£2021Äê7ÔÂ26ÈÕ£¬¹«Ë¾Ïàʶµ½ÓÐÖ¤¾ÝÅú×¢·þÎñÆ÷µÄÄÚÈÝÔ⵽δ¾ÊÚȨµÄ»á¼ûºÍй¶¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMJI
4. ¹¥»÷ÕßÉèÁ¢ºô½ÐÖÐÐÄÏòÓû§·Ö·¢¶ñÒâÈí¼þBazaLoader
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±³Æ£¬¹¥»÷Õßͨ¹ýÉèÁ¢ºô½ÐÖÐÐÄÏòÓû§·Ö·¢¶ñÒâÈí¼þ£¬3ÔÂ30ÈÕ£¬MalwareTrafficAnalysisÐû²¼Á˶ÔBazaCallºÅÂëµÄͨ»°Â¼Òô£¬ºô½ÐÖÐÐÄÔ±¹¤½«Êܺ¦ÕßÖ¸µ¼µ½Ò»¸öÍøÕ¾£¬ÔÚÄÇÀïÊܺ¦Õß±»Ö¸µ¼ÊäÈë¶©ÔĺÅÂë¡£CarrollºÍHackerдµÀ£¬¶©ÔĺŻòÆäËû±àºÅ¿É×÷ΪִÐк͸ú×ÙÔ˶¯µÄÖ°Ô±µÄ±êʶ·û¡£È»ºó£¬ºô½ÐÖÐÐÄÔ±¹¤½«Êܺ¦ÕßÖ¸µ¼µ½Ò»¸ö¿´ÆðÀ´ÏñÕýµ±ÆóÒµµÄÍøÕ¾¡£È»ºóָʾÊܺ¦ÕßÏÂÔØÎļþ£¬ÀýÈçExcelµç×Ó±í¸ñ¡£ÔÚÒôƵͨ»°ÖУ¬ÏÔʾÖÒÑÔºó»áÖ¸µ¼Óû§ÆôÓúꡣ×îÖÕ£¬Êܺ¦Õß±»¼û¸æËûÃǵĶ©ÔÄÒÑÀÖ³É×÷·Ï£¬µ«ÏÖʵÉÏ×°ÖÃÁËBazaLoader¶ñÒâÈí¼þ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMJu
5. ¶íÂÞ˹GRUÕë¶ÔÃÀ¹úºÍÈ«Çò×éÖ¯ÍøÂ籩Á¦¹¥»÷
¡¾¸ÅÊö¡¿
×î½ü£¬¶íÂÞ˹¾üÊÂÇ鱨»ú¹¹GRU¶ÔÃÀ¹úºÍÈ«Çò×éÖ¯Ìá³«ÍøÂ籩Á¦¹¥»÷¡£GRU×÷Ϊ¶íÂÞ˹µÄ¾üÊÂÇ鱨²¿·Ö£¬×Ô2019ÄêÒÔÀ´Ò»Ö±ÔÚ¾ÙÐÐÍøÂ籩Á¦¹¥»÷¡£Ëü¹¥»÷µÄÄ¿µÄÊÇÃÀ¹úºÍÈ«ÇòµÄÕþ¸®ºÍ˽Ӫ²¿·Ö¡£Ñо¿Ö°Ô±³Æ£¬¹¥»÷Õßͨ¹ýÌá½»´ó×ڵǼÐÅÏ¢À´ÇÖÈëÍøÂ磬µÇ¼ÐÅÏ¢°üÀ¨µç×ÓÓʼþºÍÆäËûÓÐÓõÄÕÊ»§Æ¾Ö¤£¬µ±¹¥»÷Õß¹¥»÷ÀÖ³Éʱ£¬ËûÃÇ»á»á¼ûÊܱ£»¤µÄÊý¾Ý£¬Êý¾Ý°üÀ¨×ÊÖúÍøÂç¹¥»÷ÕßÔÚÄ¿µÄʵÌåÄÚºáÏòÒÆ¶¯µÄƾ֤¡£ÀýÈ磬ƾ֤¿ÉÓÃÓÚ³õʼ»á¼û¡¢È¨ÏÞÌáÉý¡¢³¤ÆÚÐԺͷÀÓù¹æ±Ü¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMJA
6. ¹¥»÷Õß̫ͨ¹ý·¢ÍøÂç´¹ÂÚµç×ÓÓʼþ¹¥»÷WeTransferÎļþÍйÜϵͳ
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±³Æ£¬¹¥»÷ÕßʹÓÃÏòϵͳ·¢ËÍÍøÂç´¹ÂÚµç×ÓÓʼþ¹¥»÷WeTransferÎļþÍйÜϵͳ£¬´Ë¹¥»÷µÄÖ÷ҪĿµÄÊǼìË÷Êܺ¦ÕßµÄOffice365µç×ÓÓʼþƾ֤¡£¾ÊÓ²ì£¬ÍøÂç´¹ÂÚµç×ÓÓʼþËÆºõÊÇÓÉWeTransfer·¢Ë͵ģ¬ÓÉÓÚËüµÄ·¢¼þÈËÃû³ÆÎªWetransfer£¬ÎÊÌâΪ“Éó²éͨ¹ýWeTransfer·¢Ë͵ÄÎļþ”¡£ÕâÖÖÏàËÆÐÔ×ãÒÔÈÃÈËåÚÏëµ½ÕæÕýµÄWeTransferµç×ÓÓʼþ£¬²¢ÇÒºÜÈÝÒ×ÓÕÆÓû§¡£µç×ÓÓʼþÕýÎÄ»¹¶à´ÎÒýÓÃÄ¿µÄ×éÖ¯ÒÔʹÆä¿´ÆðÀ´Õýµ±¡£µç×ÓÓʼþÕýÎÄÏÔʾWeTransferÓëÊܺ¦Õß¹²ÏíÁËÁ½¸öÎļþ£¬²¢ÇÒÓÐÒ»¸öÁ´½Ó¿ÉÒÔÉó²éËüÃÇ¡£µ±Êܺ¦Õßµ¥»÷“Éó²éÎļþ”ʱ£¬¸ÃÁ´½Ó»á½«ËûÃÇÖ¸µ¼ÖÁÒ»¸ö¾Ý³ÆÊÇMicrosoftExcelµÄÍøÂç´¹ÂÚÒ³Ãæ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYTY
7. ¹¥»÷ÕßʹÓô¿Êý¾Ýй¶ģ×Óй¶¿Í»§Êý¾Ý
¡¾¸ÅÊö¡¿
¶íÓï×éÖ¯Conti¶Ô°®¶ûÀ¼ÎÀÉú·þÎñ»ú¹¹ÌᳫÀÕË÷Èí¼þ¹¥»÷£¬Í¬ÔÂDarkSide¶Ô×ܲ¿Î»ÓÚÃÀ¹úµÄColonialPipelineÒÔ¼°REvilÓÚ7Ô¶ÔÔ¶³ÌÖÎÀíÈí¼þ¹«Ë¾KaseyaÌᳫ¹¥»÷Ö®ºó£¬°ÝµÇÕþ¸®Ò»Ö±ÔÚ½ÓÄÉÐж¯£¬Ô½ÌáÒé¾¢µØÆÆËðÀÕË÷Èí¼þÉÌҵģʽ¡£°×¹¬»¹ºôÓõ¶íÂÞ˹Õþ¸®Ã»ÓжÔÔÚÆä¾³ÄÚÔ˶¯µÄ¾¯Ô±½ÓÄɸü¶à²½·¥£¬²¢ÍþÐ²ÒªÆÆËð´ËÀàÐж¯£¬³ý·ÇĪ˹¿Æ½ÓÄÉÐж¯¡£
±ðµÄ£¬“¹¥»÷ÕßÒ»Ö±ÔÚÃé×¼´¿Êý¾Ýй¶ģ×Ó£¬ÕâÊǹ¥»÷Õß×·²¶µÄÒ»¸öºÜºÃµÄÄ¿µÄ”McArdle˵¡£“ÁíÍ⣬'ÎÒÃÇ»á¸æËßÄúËùÓеĿͻ§ÎÒÃǼ´½«Ð¹Â¶ÄúµÄÊý¾Ý¡£'ÓÈÆäÊÇÔÚÊܵ½ÑÏ¿áî¿ÏµµÄÐÐÒµ£¬ÀýÈçÒ½ÁƱ£½¡»òÀàËÆÐÐÒµ£¬ÈôÊÇÄúÔâµ½ÆÆË𣬿ÉÄÜ»áËðʧһ´ó±ÊÇ®¡£”
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYUd
8. ¹¥»÷ÕßʹÓÃMicrosoftExchange·þÎñÆ÷¹¥»÷ÑÇÖÞµçÐŹ«Ë¾
¡¾¸ÅÊö¡¿
¹¥»÷ÕßʹÓÃMicrosoftExchange·þÎñÆ÷¹¥»÷ÑÇÖݵçÐŹ«Ë¾£¬²¢Ð¹Â¶ÁËÑÇÖݵçÐŹ«Ë¾Êý°ÙGBÊý¾Ý£¬ÒÔÍøÂç¿Í»§µÄÃô¸ÐͨѶ¡£
Cyber??easonÌåÏÖ£¬ÓëÆäËûÍøÂç¹¥»÷Ò»Ñù£¬ÕâЩAPTÔ˶¯Ê¹ÓÃÁËMicrosoftExchange·þÎñÆ÷ÖеÄȱÏÝÀ´»á¼ûÄ¿µÄÍøÂ磬Ȼºó¼ÌÐøÆÆËðÒªº¦×ʲúÐÅÏ¢£¬°üÀ¨¾ßÓÐÃô¸Ðºô½ÐÏêϸ¼Í¼Êý¾ÝµÄÓò¿ØÖÆÆ÷ºÍ¼Æ·Ñϵͳ¡£
ÕâЩ¹¥»÷Ö÷ÒªËðº¦ÁËÑÇÖÞµçÐŹ«Ë¾µÄÊý¾Ý£¬µ«ÕâЩ¹¥»÷¿ÉÄÜ»áÉìÕŵ½ÆäËûµØÇøµÄµçÐŹ«Ë¾£¬ÈôÊǹ¥»÷Õß¾öÒ齫ÆäÄ¿µÄ´ÓÌØ¹¤Ô˶¯¸ÄΪ×ÌÈÅ£¬ËûÃǽ«ÓÐÄÜÁ¦ÖÐÖ¹ÈκÎÊÜÓ°ÏìµçÐſͻ§µÄͨѶ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMJx
9. B2BÓªÏú¹«Ë¾Ð¹Â¶ÁËÃÀ¹úÈËÊýÒÔ°ÙÍòµÄÊý¾Ý
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±ÌåÏÖ£¬B2BÓªÏú¹«Ë¾OneMoreLeadÔÚÉèÖùýʧµÄElasticsearch·þÎñÆ÷ÉÏ̻¶Á˶à´ï1.26ÒÚÃÀ¹úÈ˵ÄÊý¾Ý¡£²¢Í¨ÖªÁËOneMoreLead¹©Ó¦ÉÌ£¬Ö®ºó¹©Ó¦É̶ÔÊý¾Ý¾ÙÐÐÁ˱£»¤¡£OneMoreLead½«ËùÓÐÐÅÏ¢´æ´¢ÔÚÒ»¸ö²»Çå¾²µÄÊý¾Ý¿âÖУ¬¸Ã¹«Ë¾Òѽ«ÆäÍêÈ«¿ª·Å¡£Òò´Ë£¬ÐÕÃû¡¢µç×ÓÓʼþµØµãºÍÊÂÇ鳡ºÏÐÅÏ¢»á̻¶¸øÈκÎÓµÓÐÍøÂçä¯ÀÀÆ÷µÄÈË¡£ÈôÊǹ¥»÷Õß·¢Ã÷ÁËÕâ¸öÊý¾Ý¿â£¬Ëü½«³ÉΪÖÖÖÖ·¸·¨Ô˶¯µÄ½ð¿ó£¬´Ó½ðÈÚڲƺÍÉí·Ý͵ÇÔ£¬µ½Õë¶ÔÃÀ¹ú¹«Ë¾ºÍÕþ¸®»ú¹¹µÄ´ó¹æÄ£ÍøÂç´¹ÂÚ¹¥»÷¡£”
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMJN
10. ¹¥»÷ÕßʹÓöñÒâÈí¼þLittleLooter¹¥»÷ÒÁÀÊË¢ÐÂÔ˶¯µÄÊܺ¦Õß
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±¼ÌÐø¸ú×ÙÒÉËÆÒÁÀÊÍþв×éÖ¯ITG18µÄ»ù´¡ÉèÊ©ºÍÔ˶¯¡£×Ô´ÓÓÚ2020Äê5ÔÂÊ״α¨¸æ¸Ã×éÖ¯ÒÔÀ´£¬·¢Ã÷ÁËÒ»¸ö¶ñÒ⹤¾ß£¬ÎÒÃǽ«ÆäÃüÃûΪAndroid¶ñÒâÈí¼þLittleLooter¡£LittleLooter½ö±»ÊӲ쵽±»ITG18ʹÓᣴÓ2020Äê8Ôµ½2021Äê5Ô£¬X-ForceÑо¿Ö°Ô±ÊӲ쵽ITG18ʹÓÃLittleLooter¶ñÒâÈí¼þ¹¥»÷ÁËÒÁÀÊË¢ÐÂÖ÷ÒåÔ˶¯µÄ¶àÃûÊܺ¦Õß¡£
X-ForceÑо¿Ö°Ô±·¢Ã÷ITG18´Ó2020ÄêÏÄÄ©µ½2021Äê´º¼¾Õë¶ÔÒÁÀÊСÎÒ˽¼Ò¹ûÕæ±¨¸æÁËËûÃǵÄOPSEC¹ýʧ£¬µ«ITG18¼ÌÐøÔÚ¿ª·Å·þÎñÆ÷ºÍ¿ª·ÅĿ¼Öб£´æ°üÀ¨Ð¹Â¶µÄÊܺ¦ÕßÐÅÏ¢µÄ´æµµÎļþ¡£X-ForceµÄÐÂÆÊÎöÏÔʾ£¬ITG18´ÓԼĪ20ÃûÓëÒÁÀÊË¢ÐÂÔ˶¯½áÃ˵ÄÈËÇÔÈ¡ÁËԼĪ120GBµÄÐÅÏ¢¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMJJ

AG¹«Ë¾ÔÆ







