¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.08.09-2021.08.15£©
2021-08-16
Ò»¡¢ Íþвͨ¸æ
΢Èí8ÔÂÇå¾²¸üжà¸ö²úÆ·¸ßΣÎó²îͨ¸æ£¨CVE-2021-36936¡¢CVE-2021-36947¡¢CVE-2021-26424£©
¡¾Ðû²¼Ê±¼ä¡¿2021-08-1215:00:00GMT
¡¾¸ÅÊö¡¿
8ÔÂ11ÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½Î¢ÈíÐû²¼8ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË46¸öÇå¾²ÎÊÌâ£¬Éæ¼°Windows¡¢MicrosoftOffice¡¢ASP.NETCore¡¢MicrosoftVisualStudio¡¢AzureµÈÆÕ±éʹÓõIJúÆ·£¬ÆäÖаüÀ¨È¨ÏÞÌáÉý¡¢Ô¶³Ì´úÂëÖ´ÐеȸßΣÎó²îÀàÐÍ¡£±¾ÔÂ΢ÈíÔ¶ȸüÐÂÐÞ¸´µÄÎó²îÖУ¬ÑÏÖØË®Æ½ÎªÒªº¦£¨Critical£©µÄÎó²îÓÐ7¸ö£¬Ö÷Òª£¨Important£©Îó²îÓÐ39¸ö¡£ÆäÖÐÓÐ3¸öΪ0dayÎó²î£¬ÓÐ2¸öÎó²îÐÅÏ¢ÒÑÔÚÉÏÔÂÐû²¼£ºWindowsȨÏÞÌáÉýÎó²î£¨CVE-2021-36934£©WindowsPrintSpoolerÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-34481£©
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
WindowsPrintSpoolerÔ¶³Ì´úÂëÖ´ÐÐ0dayÎó²îͨ¸æ£¨CVE-2021-36958£©
¡¾Ðû²¼Ê±¼ä¡¿2021-08-1215:00:00GMT
¡¾¸ÅÊö¡¿
±±¾©Ê±¼ä8ÔÂ11ÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½Î¢ÈíÐû²¼8ÔÂÇå¾²¸üв¹¶¡£¬ÆäÖаüÀ¨ÁËÔÚ7ÔÂ16ÈÕ½ôÆÈÐû²¼µÄWindowsPrintSpoolerȨÏÞÌáÉýÎó²î£¨CVE-2021-34481£©£¬¶ÔÓ¦µÄ²¹¶¡±àºÅΪKB5005652£¬Î¢Èíͬʱ½«Îó²îÃû³ÆÐÞ¸ÄΪԶ³Ì´úÂëÖ´ÐС£µ±WindowsPrintSpooler·þÎñ²»×¼È·µØÖ´ÐÐÌØÈ¨Îļþ²Ù×÷ʱ£¬¹¥»÷ÕßʹÓôËÎó²î¿ÉÒÔʹÓÃSYSTEMȨÏÞÔËÐÐí§Òâ´úÂë¡£ÓÐÍâÑóÑо¿Ö°Ô±ÔÚ×°ÖÃÁË×îв¹¶¡µÄWindowsϵͳÉϾÙÐвâÊÔ£¬·¢Ã÷´Ë´Î¸üеÄCVE-2021-34481Çå¾²²¹¶¡ÎÞЧ£¬µ±Êܺ¦ÕßÅþÁ¬²¢×°Öù¥»÷Õß¿ØÖƵĴòÓ¡»úʱ£¬¿ÉÀֳɴ¥·¢´ËÎó²î
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
INFRAHALT£ºNicheStackTCP/IP¿ÍÕ»¶à¸ö¸ßΣÎó²îͨ¸æ£¨CVE-2020-25928¡¢CVE-2021-31226¡¢CVE-2020-25927£©
¡¾Ðû²¼Ê±¼ä¡¿2021-08-1114:00:00GMT
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬JFrogºÍForescoutµÄÑо¿Ö°Ô±Ðû²¼ÁËÒ»·ÝÍŽᱨ¸æ£¬¹ûÕæÅû¶ÁËÔÚNicheStackTCP/IP¿ÍÕ»Öз¢Ã÷µÄ14¸öÇå¾²Îó²î(ͳ³ÆÎªINFRA:HALT)£¬ÕâЩÎó²î¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС¢¾Ü¾ø·þÎñ¡¢ÐÅÏ¢×ß©¡¢TCPÓÕÆ»òDNS»º´æÖж¾¡£Ñо¿Ö°Ô±ÌåÏÖ£¬ÀÖ³ÉʹÓÃINFRA:HALTÎó²îµÄ¹¥»÷Õß¿ÉÄÜ»áÆÆËðÐÞ½¨ÎïµÄHVACϵͳ»ò½ÓÊÜÓÃÓÚÖÆÔìºÍÆäËüÒªº¦»ù´¡ÉèÊ©µÄ¿ØÖÆÆ÷£¬µ¼ÖÂOTºÍICS×°±¸ÀëÏß²¢±»Ð®ÖÆ£¬²¢ÇÒ¹¥»÷Õß¿ÉÒÔͨ¹ýÐ®ÖÆµÄ×°±¸Èö²¥¶ñÒâÈí¼þ¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. ¹¥»÷ÕßʹÓÃHive²¡¶¾ÀÕË÷Èí¼þ¹¥»÷¶à¼ÒÍâÑóÆóÒµ
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öHIVE²¡¶¾ÀÕË÷Èí¼þµÄÑù±¾£¬¸ÃÀÕË÷²¡¶¾Ñù±¾»á½«ÖÕ¶ËÉϵÄÎļþ¼ÓÃÜ£¬²¢ÁôÏÂÀÕË÷ÐÅÏ¢£¬ÇÒ¹¥»÷ÕßʹÓÃHIVEÀÕË÷²¡¶¾Ñù±¾ÔÚ¼ÓÃÜÎļþǰ¾ÙÐÐÊý¾ÝÇÔÈ¡£¬HiveÀÕË÷²¡¶¾½ÓÄÉAES+RSA¼ÓÃÜËã·¨£¬ÔÚÖ´Ðкó£¬Êܺ¦ÕßÖÕ¶ËÉϴ󲿷ÖÎļþ»á±»¼ÓÃܳÉ*.hiveµÄÎļþ¡£²¢ÇÒ»áÔÚÿһ¸öĿ¼ÏÂÁôÏÂÒ»¸öHOWTODECRYPTµÄÎı¾Îĵµ£¬Êܺ¦Õß¿ÉÆ¾Ö¤ÎĵµÖеÄÕ˺ÅÃÜÂëÉϰ¶ºÚ¿ÍÌṩµÄÍøÕ¾ºóÓÃÊê½ð»»È¡½âÃÜÃÜÔ¿¡£Æ¾Ö¤ÍâÑóýÌ屨µÀ£¬¼ÓÄôóÉÌÒµµØ²ú¹«Ë¾AltusGroupÕýÊÇÔâÊÜHiveÀÕË÷¹¥»÷µ¼ÖÂÊý¾Ýй¶¡£ÇÒ²»µ½Ò»¸öÔ£¬¸ÃÀÕË÷ÍÅ»ïÒÑÐû²¼Á˶à¼ÒÆóÒµµÄÊý¾ÝÐÅÏ¢¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMKy
2. ¹¥»÷ÕßʹÓÃGlowwormÇÔÌýÐéÄâ¾Û»áµÄÃô¸ÐÐÅÏ¢
¡¾¸ÅÊö¡¿
Ëæ×ÅÔ½À´Ô½¶àµÄӪҵͨ¹ýMicrosoftTeams¡¢Zoom¡¢SkypeµÈƽ̨£¬Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»ÖÖȫеÄÕë¶Ôµç×ÓͨѶ¹¥»÷ǰÑÔGlowworm£¬¹¥»÷Õß¿ÉʹÓÃGlowwormÇÔÌýZoomºÍÆäËûÐéÄâ¾Û»áµÄÃô¸Ð¶Ô»°£¬Ëü»á½«×°±¸¹¦ºÄÒýÆðµÄ×°±¸µçԴָʾµÆLEDÇ¿¶ÈµÄת±ä½«Æäת»»ÎªÒôƵ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMKv
3. ¶ÌÐÅÍøÂç´¹ÂÚÕ©ÆÍÅ»ïð³ä¾ÍÒµ»ú¹¹ÇÔÈ¡Óû§ÐÅÏ¢
¡¾¸ÅÊö¡¿
ÉÌҵίԱ»áÌåÏÖ£¬¶ÌÐÅÍøÂç´¹ÂÚÕ©ÆÍÅ»ïÕýÔÚð³ä¾ÍÒµºÍÀ͹¤»ú¹¹£¬ÓÕʹÓû§µã»÷¶ñÒâÁ´½Ó£¬ÕâЩ¶ñÒâÁ´½Ó³ÆÎªÍøÂç´¹ÂÚÎı¾£¬±»³ÆÎªÖØÐÂÌá½»»òÑé֤ʧҵ¾ÈÔ®½ðµÄ±í¸ñÁ´½Ó£¬¶ÌÐÅÖеĶñÒâÁ´½Ó½«Ä¿µÄÊܺ¦ÕßÒýÓÕÀàËÆ¾ÍÒµ»ú¹¹µÄÁ´½Ó¡£µ±Êܺ¦Õßµã»÷¶ñÒâÁ´½Óʱ£¬Õ©ÆÍÅ»ï»áÇÔȡСÎÒ˽¼ÒÐÅÏ¢£¬ÉõÖÁ¾ÈÔ®½ð¡£Ñо¿Ö°Ô±ÌåÏÖ£¬ÕâÐ©ÍøÂç´¹ÂÚ¹¥»÷½«ÔÚδÀ´¼¸¸öÔÂÄÚÒ»Á¬±£´æ£¬×è°ÆóÒµÊÂÇé¡£Òò´Ë£¬×éÖ¯±ØÐè¼ÌÐø¾ÍÉç»á¹¤³ÌÕ½ÂÔ¶ÔÔ±¹¤¾ÙÐÐÅàѵ£¬²¢ÎªÓû§½¨Éèʵʱ±¨¸æÍøÂç´¹ÂÚÐÂÎŵĻúÖÆ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMKt
4. LoakBitÀÕË÷Èí¼þÍÅ»ïÕë¶Ô°£ÉÕܹ«Ë¾¾ÙÐй¥»÷
¡¾¸ÅÊö¡¿
×Éѯ¹«Ë¾°£ÉÕÜ֤ʵ£¬ËüÊܵ½ÁËÀÕË÷Èí¼þÍÅ»ïLockBitµÄ¹¥»÷£¬ÔÚÆä°µÍøÖУ¬LockBitÉù³ÆÒѾÇÔÈ¡ÁËÁè¼Ý6TBµÄÊý¾Ý¿â£¬ÌṩÁ˰£ÉÕÜÊý¾Ý¿â³öÊÛ£¬²¢ÒªÇóÖ§¸¶5000ÍòÃÀÔª×÷ΪÊê½ð¡£¾ÝÊÂÎñ²¿³Æ£¬ÔÚÊê½ðÖ§¸¶µ¹¼ÆÊ±¿¢ÊÂʱ£¬×ß©վµãÏÔʾÁËÒ»¸öÃûΪW1µÄÎļþ¼Ð£¬ÆäÖаüÀ¨¾Ý³Æ´Ó¹«Ë¾ÇÔÈ¡µÄPDFÎĵµÜöÝÍ¡£²¢ÇÒLockBitÉù³ÆÒѾ»ñµÃ°£ÉÕÜÍøÂçµÄ»á¼ûȨÏÞ£¬²¢×¼±¸×ß©´Ó°£ÉÕÜ·þÎñÆ÷ÇÔÈ¡µÄÎļþ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlML0
5. StrongpityʹÓÃAndroid¶ñÒâÈí¼þ¹¥»÷ÐðÀûÑǵç×ÓÕþ¸®ÍøÕ¾
¡¾¸ÅÊö¡¿
StrongPityʹÓÃAndroid¶ñÒâÈí¼þ¹¥»÷ÐðÀûÑǵç×ÓÕþÎñÍøÕ¾£¬È»ºóÓÃľÂí°æ±¾Ìæ»»¹Ù·½Ó¦ÓóÌÐò£¬ËæºóʹÓøÃÓ¦ÓóÌÐò´ÓÊܺ¦ÕßµÄ×°±¸ÖÐÇÔÈ¡Îļþ¡£StrongPityͨ¹ýʹÓòî±ðµÄÖ¤Êé¶Ô¶ñÒâ°æ±¾µÄÓ¦ÓóÌÐò¾ÙÐÐÊðÃû£¬½«ÆäÖØÐ´ò°üÒÔʹÆä¿´ÆðÀ´ÏñÔʼ°æ±¾¡£Ëü»áµ÷½âÓ¦ÓóÌÐòÒÔÇëÇó¶ÔÊÜѬȾװ±¸µÄÌØÊâȨÏÞ£¬Ìí¼Ó¶ñÒâ×é¼þÒÔ´¥·¢Ñ¬È¾¡£¶ñÒâÈí¼þ¼ÌÐøÍ¨¹ýÏÂÁî¿ØÖÆ·þÎñÆ÷ͨѶ£¬½«¼ÓÃܵÄÓÐÓÃÔØºÉÉúÑĵ½AndroidĿ¼ÖУ¬È»ºó½âÃÜÎļþ¡£StrongPity´ÓÊܺ¦ÕßµÄ×°±¸ÍøÂçÊý¾Ý£¬ÀýÈçÒþ˽Êý¾ÝºÍÓйؿÉÓÃWi-FiÍøÂçµÄÐÅÏ¢¡£±¨¸æÖ¸³ö£¬ÔÚWindows°æ±¾ÖУ¬¹¥»÷ÕßʹÓÃÏàͬµÄÕ½ÂÔÖØÐ´ò°üÓ¦ÓóÌÐòµÄÔʼ°æÔÀ´Ñ¬È¾Êܺ¦Õß²¢ÇÔÈ¡Êý¾Ý¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMLp
6. ¹¥»÷ÕßʹÓÃWarzoneRAT¶ñÒâÈí¼þ¾ÙÐÐÓã²æÊ½ÍøÂç´¹ÂÚÔ˶¯
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷£¬¹¥»÷ÕßʹÓÃÊÜѬȾµÄWordPressÍøÕ¾£¬Ê¹ÓÃWarzoneRAT¶ñÒâÈí¼þ¾ÙÐÐеÄÓã²æÊ½ÍøÂç´¹ÂÚÔ˶¯¹¥»÷È«ÇòÖÆÔìÉÌ£¬ÐµÄÓã²æÊ½ÍøÂç´¹ÂÚÔ˶¯Ê¼ÓÚÒ»¼ÒλÓÚÓ¢¹úµÄÔÚÏßʳÎïÅäËÍ·þÎñÖÆÔìÉÌ£¬¹¥»÷Õ߸ø¸ÃÖÆÔìÉÌ´«ÈëÒ»·âαװ³É“FoodHub.co.uk”µÄ×Ô½ç˵µç×ÓÓʼþ£¬¿´ËÆÀ´×ÔÖÆÔìÉÌÕýµ±¿Í»§µÄÐéαµç×ÓÓʼþµØµã£¬µç×ÓÓʼþÕýÎİüÀ¨¶©µ¥ºÍÔËÊäÐÅÏ¢£¬ÒÔ¼°Ò»¸ö²É¹º¶©µ¥PowerPointÎļþ¡£ÍþвÐÐΪÕßͨ³£½«È«ÇòÖÆÔìÉÌºÍÆäËû¹©Ó¦ÉÌ×÷Ϊ¹¥»÷Ä¿µÄ£¬²»µ«ÊÇΪÁ˹¥»÷ËûÃÇ£¬²¢ÇÒÊÇΪÁËÇÔÈ¡µ½¸ÃÆóÒµ¿Í»§µÄÐÅÏ¢¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMLu
7. ¹¥»÷ÕßʹÓÃFlyTrap°²×¿¶ñÒâÈí¼þ¹¥»÷FacebookµÈÉ罻ýÌåÕÊ»§
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»ÖÖÃûΪFlyTrapµÄÐÂÐÍAndroidľÂí£¬¸ÃľÂíͨ¹ýµÚÈý·½Ó¦ÓÃÊÐËÁÖб»Ê¹ÓõÄÓ¦ÓᢲàÔØÓ¦Óúͱ»Ð®ÖƵÄFacebookÕÊ»§Èö²¥¸ø10,000¶àÃûÊܺ¦Õß¡£×Ô3ÔÂÒÔÀ´£¬¹¥»÷ÕßʹÓÃFlyTrap¶ñÒâÈí¼þͨ¹ýGooglePlayÊÐËÁºÍµÚÈý·½Ó¦ÓóÌÐòÊг¡·Ö·¢µÄ¶ñÒâÓ¦ÓóÌÐòÈö²¥µ½ÖÁÉÙ144¸ö¹ú¼Ò/µØÇø¡£FlyTrapʹÓÃJavaScript×¢Èëͨ¹ýµÇ¼ÔʼÕýµ±ÓòÀ´Ð®ÖÆFacebook»á»°£¬ÕâЩ±»Ð®ÖƵÄFacebook»á»°¿ÉÓÃÓÚÈö²¥¶ñÒâÈí¼þ£¬Í¨¹ýľÂíµÄÁ´½Ó£¬ÒÔ¼°Ê¹ÓÃÊܺ¦ÕߵĵØÀíλÖÃÏêϸÐÅÏ¢¾ÙÐÐÐû´«»òÐéαÐû´«Ô˶¯£¬²¢ÇÒ¾³£±»¹¥»÷ÕßÓÃÀ´½«¶ñÒâÈí¼þ´ÓÒ»¸öÊܺ¦ÕßÈö²¥µ½ÁíÒ»¸öÊܺ¦Õß¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMKO
8. ¹¥»÷ÕßÇÔÈ¡ÁË100ÍòÕÅÐÅÓÿ¨ÐÅÏ¢
¡¾¸ÅÊö¡¿
¹¥»÷Õßͨ¹ý¶àÖÖ·½·¨ÇÔÈ¡ÁË100ÍòÕÅÐÅÓÿ¨µÄÐÅÏ¢£¬ºÃ±ÈÏúÊÛµãË¢¿¨Æ÷¡¢ÒÔ¼°Õë¶ÔÍøÕ¾µÄMagecart¹¥»÷ºÍÐÅÏ¢ÇÔȡľÂíÊÇËûÃÇÇÔÊØÐÅÓÿ¨Êý¾ÝµÄÖ÷Òª¹¤¾ß¡£±¨µÀ³Æ£¬¹¥»÷ÕßÔÚCyber??sixgill¹«Ë¾¼à¿ØµÄµØÏÂÐÅÓÿ¨Êг¡ÉϳöÊÛÁËÁè¼Ý4500ÍòÕÅÐÅÓÿ¨ÐÅÏ¢¡£È»ºó£¬Ê¹ÓÃÕâЩÐÅÓÿ¨¾ÙÐÐÍøÉϹºÎ°üÀ¨¹ºÖÃÀñÎ│£¬µ«Í¨¹ýÕâЩÐÅÓÿ¨ÐÅÏ¢ºÜÄÑ×·²éµ½ËûÃǵÄÐÐ×Ù¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMKP
9. ºÚ¿ÍÔÚ¼ÓÃÜÇ®±ÒÇÀ½Ù°¸ÖÐÇÔÈ¡ÁËPolyNetwork¹«Ë¾6ÒÚÃÀÔª
¡¾¸ÅÊö¡¿
ÐÐÒµÁìÏȵÄÖÐÐÄ»¯½ðÈÚÆ½Ì¨DeFiÖ®Ò»PolyNetworkÒѳÉÎªÍøÂçÇÀ½ÙµÄÊܺ¦Õߣ¬»ùÓÚÇø¿éÁ´µÄDeFiÍøÂçÔâÊÜÁË×î´óµÄÊý×Ö×ʲú͵ÇÔÖ®Ò»£¬¹¥»÷ÕßÇÔÈ¡Á˸ù«Ë¾¼ÛÖµ6.11ÒÚÃÀÔªµÄ¼ÓÃÜÇ®±Ò¡£¾ÝPolyNetwork³Æ£¬À´×ÔBinanceChain¡¢PolygonºÍEthereumµÄ×ʲú±»µÁ²¢×ªÒƵ½Èý¸ö²î±ðµÄÇ®°ü¡£±ðµÄ£¬PolyNetworkÒѱ޲ßBinance¡¢OKEx¡¢HuobiGlobal¡¢Uniswap¡¢CirclePay¡¢TetherºÍBitGoµÈÊÜÓ°ÏìµÄÇø¿éÁ´ºÍ¼ÓÃÜÇ®±ÒÉúÒâËùÁ¬Ã¦Î´À´×Ô¹¥»÷ÕߵصãµÄÈκδú±ÒÁÐÈëºÚÃûµ¥¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlML1
10. Exchange·þÎñÆ÷Êܵ½ProxyShellµÄ×Ô¶¯¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷£¬Microsoft Exchange·þÎñÆ÷Êܵ½ProxyShellµÄ×Ô¶¯¹¥»÷£¬Exchange Serverºã¾ÃÒÔÀ´Ò»Ö±ÊǺڿ͵ÄÖ÷ҪĿµÄ£¬»¥ÁªÍøÉÏÓÐÁè¼Ý400,000̨Exchange·þÎñÆ÷ͨ¹ý¶Ë¿Ú443Êܵ½¹¥»÷¡£Í¨¹ýShodanɨÃè·¢Ã÷ÁË30,000¶à¸öÒ×Êܹ¥»÷µÄExchange·þÎñÆ÷£¬²¢ÇÒ˼Á¿µ½¿ÉÓÃÐÅÏ¢µÄÊýÄ¿¡£ÕâЩ¹¥»÷ʹÈκÎδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»·¢Ã÷Ã÷ÎÄÃÜÂ룬ÉõÖÁͨ¹ý¶Ë¿Ú 443 ÔÚMicrosoft Exchange ·þÎñÆ÷ÉÏÖ´ÐÐí§Òâ´úÂ룬¸Ã¶Ë¿ÚÓÉԼĪ 400,000 ̨ Exchange ·þÎñÆ÷̻¶ÔÚ Internet ÉÏ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMLv

AG¹«Ë¾ÔÆ







