¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.08.23-2021.08.29£©
2021-08-30
Ò»¡¢ Íþвͨ¸æ
AtlassianConfluenceÔ¶³Ì´úÂëÖ´ÐÐÎó²îͨ¸æ£¨CVE-2021-26084£©
¡¾Ðû²¼Ê±¼ä¡¿2021-08-2619:00:00GMT
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½Atlassian¹Ù·½Ðû²¼ÁËConfluenceServerWebworkOGNL×¢ÈëÎó²î£¨CVE-2021-26084£©µÄÇ徲ͨ¸æ£¬Ô¶³Ì¹¥»÷ÕßÔÚ¾ÓÉÉí·ÝÑéÖ¤»òÔÚÌØ¶¨ÇéÐÎÏÂδ¾Éí·ÝÑéÖ¤µÄÇéÐÎÏ£¬¿É½á¹¹OGNL±í´ïʽ¾ÙÐÐ×¢È룬ʵÏÖÔÚConfluenceServer»òDataCenterÉÏÖ´ÐÐí§Òâ´úÂ룬CVSSÆÀ·ÖΪ9.8¡£ÇëÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£AtlassianConfluenceÊÇAtlassian¹«Ë¾³öÆ·µÄרҵwiki³ÌÐò¡£Ëü¿ÉÒÔ×÷Ϊһ¸ö֪ʶÖÎÀíµÄ¹¤¾ß£¬Í¨¹ýËüÄܹ»ÊµÏÖÍŶӳÉÔ±Ö®¼äµÄÐ×÷ºÍ֪ʶ¹²Ïí¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
XStream¶à¸ö¸ßΣÎó²îͨ¸æ£¨CVE-2021-39141¡¢CVE-2021-39144¡¢CVE-2021-39139£©
¡¾Ðû²¼Ê±¼ä¡¿2021-08-2315:00:00GMT
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬AG¹«Ë¾¿Æ¼¼¼à²âµ½XStream¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬¹ûÕæÁËXStreamÖеÄ14¸öÇå¾²Îó²î£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îÔì³É¾Ü¾ø·þÎñ¡¢SSRF¡¢Ô¶³ÌÖ´ÐÐí§Òâ´úÂë¡£XStreamÊÇÒ»¸öJava¹¤¾ßºÍXMLÏ໥ת»»µÄ¹¤¾ß£¬ÔÚ½«JavaBeanÐòÁл¯¡¢»ò½«XMLÎļþ·´ÐòÁл¯Ê±£¬Ëü²»ÐèÒªÆäËü¸¨ÖúÀàºÍÓ³ÉäÎļþ£¬ÕâʹµÃXMLÐòÁл¯²»ÔÙ·±Ëö¡£CVE-2021-39140:¹¥»÷Õß¿ÉÒÔʹÓÃÒÑ´¦Öóͷ£µÄÊäÈëÁ÷²¢Ìæ»»»ò×¢È빤¾ß£¬Õâ»áµ¼ÖÂÒ»¸öÎÞÐÝÖ¹µÄÑ»·£¬´Ó¶øÔì³É¾Ü¾ø·þÎñ¹¥»÷¡£CVE-2021-39144:¹¥»÷Õß¿ÉÒÔ²Ù×÷ÒÑ´¦Öóͷ£µÄÊäÈëÁ÷²¢Ìæ»»»ò×¢È빤¾ß£¬´Ó¶øÔÚ·þÎñÆ÷ÉÏÔ¶³ÌÖ´ÐÐÏÂÁî¡£CVE-2021-39139¡¢CVE-2021-39141¡¢CVE-2021-39145¡¢CVE-2021-39146¡¢CVE-2021-39147¡¢CVE-2021-39148¡¢CVE-2021-39149¡¢CVE-2021-39151¡¢CVE-2021-39153¡¢CVE-2021-39154£º¹¥»÷Õß¿ÉÒÔʹÓÃÒÑ´¦Öóͷ£µÄÊäÈëÁ÷²¢Ìæ»»»ò×¢È빤¾ß£¬´Ó¶øÖ´ÐдÓÔ¶³Ì·þÎñÆ÷¼ÓÔØµÄí§Òâ´úÂë¡£CVE-2021-39150¡¢CVE-2021-39152£º¹¥»÷Õß¿ÉÒÔʹÓÃÒÑ´¦Öóͷ£µÄÊäÈëÁ÷²¢Ìæ»»»ò×¢È빤¾ß£¬´Ó¶øÊµÏÖ·þÎñ¶ËÇëÇóαÔì¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. ShinyHunters×éÖ¯ÇÔÈ¡½ÌÓý¡¢Õþ¸®ºÍ¾üÊÂʵÌåµÄÃô¸ÐÐÅÏ¢
¡¾¸ÅÊö¡¿
ShinyHuntersÊÇÒ»¸öÍøÂç·¸·¨µØÏÂ×éÖ¯£¬Ñо¿Ö°Ô±Åú×¢£¬¸Ã×éÖ¯Ö÷ÒªÔÚRaidÂÛ̳ÉÏÔË×÷£¬½«½ÌÓý¡¢Õþ¸®ºÍ¾üÊÂʵÌåÖ°Ô±×÷Ϊ¹¥»÷µÄÄ¿µÄ£¬ÒÔÇÔÈ¡¹«Ë¾ÓÐÓõÄOAuthÁîÅÆÐÅÏ¢£¬Ê¹ÓÃÁîÅÆÐÅÏ¢ÆÆËð¹«Ë¾µÄÔÆ»ù´¡ÉèÊ©²¢ÈƹýÈκÎÒòËØÉí·ÝÑéÖ¤»úÖÆ¡£ÕâЩƾ֤»òAPIÃÜÔ¿¡¢ÁîÅÆÐÅÏ¢Ëæºó±»ÀÄÓÃÒÔ»á¼ûÊý¾Ý¿â²¢ÍøÂçÃô¸ÐÐÅÏ¢ÒÔתÊÛIJÀû»òÔÚºÚ¿ÍÂÛ̳ÉÏÃâ·ÑÐû²¼¡£¹¥»÷Õß×ܹ²ÇÔÈ¡ÁËÁè¼Ý112Íò¸öÊôÓÚ±ê×¼ÆÕ¶û100Ö¸Êý×éÖ¯¡¢½ÌÓý¡¢Õþ¸®ºÍ¾üÊÂʵÌåµÄΨһµç×ÓÓʼþµØµã¡£ShinyHunters×éÖ¯×îÏÈÒÔ20ÍòÃÀÔªµÄÆð¼Û³öÊ۾ݳưüÀ¨7000ÍòAT&T¿Í»§Ð¡ÎÒ˽¼ÒÐÅÏ¢µÄÊý¾Ý¿â£¬Ö»¹ÜÕâ¼ÒÃÀ¹úµçÐÅÌṩÉÌ·ñ¶¨ÆäϵͳÔâµ½ÆÆËð¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMMV
2. °ÍÎ÷°Ù»õ´ò°ç¹«Ë¾LojasRenner±»ÀÕË÷Èí¼þÍÅ»ïRansomExxennerÏ®»÷
¡¾¸ÅÊö¡¿
°ÍÎ÷×î´óµÄ´ò°ç¹«Ë¾LojasRennerÔâÓöÀÕË÷Èí¼þÍÅ»ïRansomExx¹¥»÷£¬Ó°ÏìÁË´ò°ç¹«Ë¾µÄIT»ù´¡ÉèÊ©¡£RansomExxennerÀÕË÷Èí¼þÍÅ»ïÈëÇÖÁ˰ÍÎ÷°Ù»õ´ò°ç¹«Ë¾µÄÍøÂç²¢¶ÔÔ±¹¤ºÍ¿Í»§Ð¡ÎÒ˽¼ÒÃô¸ÐÊý¾Ý¾ÙÐÐÁ˸´ÖÆ»ò¼ÓÃÜ£¬È»ºóÒÔÔÚÍøÉÏÐû²¼Òþ˽Êý¾ÝΪҪЮ£¬ÏòÊܺ¦·½Ë÷Òª10ÒÚÃÀÔªÊê½ð£¬¾Ý°ÍÎ÷ÐÂÎÅýÌ屨µÀ£¬¸Ã¹«Ë¾Òò´Ë´ÎÏ®»÷±»ÆÈ¹Ø±ÕÁËÌìÏÂËùÓÐʵÌåµê¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMLN
3. ŵ»ùÑÇ×Ó¹«Ë¾SACWirelessÔâµ½ContiÀÕË÷Èí¼þÍŻ﹥»÷
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬Åµ»ùÑÇ×Ó¹«Ë¾SACWirelessÔâÓöContiÀÕË÷Èí¼þÍŻﱩÁ¦¹¥»÷£¬ContiÀÕË÷Èí¼þÍÅ»ïͨ¹ý°²ÅÅÁËÓÐÓÃÔØºÉ²¢¼ÓÃÜÁËÎÞÏßϵͳ֮ºó£¬»ñµÃÁËŵ»ùÑÇ×Ó¹«Ë¾ÏµÍ³µÄ»á¼ûȨÏÞ£¬ÀÖ³ÉÈëÇָù«Ë¾ÍøÂ磬½«¶ñÒâÎļþÉÏ´«µ½ÆäÔÆ´æ´¢£¬È»ºó°²ÅÅÁËÀÕË÷Èí¼þÀ´¼ÓÃÜŵ»ùÑÇ×Ó¹«Ë¾ÏµÍ³ÉϵÄÎļþ£¬ÇÔÈ¡Á˸ù«Ë¾ÏÖÈκÍÈ¥Ö°Ô±¹¤µÄ250GBСÎÒ˽¼ÒÐÅÏ¢¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMNA
4. ºÚ¿Íͨ¹ý¸Ä¶¯PCÖÆÔìÉ̵ĸüÐÂÈí¼þ¹¥»÷»ªË¶µçÄÔ
¡¾¸ÅÊö¡¿
±¨µÀ³Æ£¬ºÚ¿Íͨ¹ý¸Ä¶¯PCÖÆÔìÉ̵ĸüÐÂÈí¼þ¹¥»÷Êý°ÙÍǫ̀»ªË¶µçÄÔ£¬ÎªÁË·¢¶¯¹¥»÷£¬ºÚ¿Íͨ¹ý“liveupdate01s.asus.com”ºÍ“liveupdate01.asus.com”ÉøÍ¸²¢Ìṩ»ªË¶×Ô¼ºµÄ¹Ù·½·þÎñÆ÷ÉϵĶñÒâ¸üУ¬ËûÃÇ»¹Ïë·¨ÓÓASUSTekComputerInc.”ϵÄÕýµ±Èí¼þÖ¤ÊéÇ©ÊðÁËËûÃǵĶñÒâ¸üС£Æ¾Ö¤ÎÒÃǵÄͳ¼ÆÊý¾Ý£¬Áè¼Ý57,000Ãû¿¨°Í˹»ùÓû§ÔÚij¸öʱ¼äµãÏÂÔØ²¢×°ÖÃÁ˺óÃŰ汾µÄ»ªË¶µÄ¸üÐÂÈí¼þ£¬²¢ÇÒ¿ÉÄÜÓ°ÏìÈ«ÇòÁè¼ÝÒ»°ÙÍòÓû§¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMNy
5. OnePercentGroup×é֯ʹÓÃCobaltStrikeÀÕË÷Èí¼þ¹¥»÷ÃÀ¹ú¹«Ë¾
¡¾¸ÅÊö¡¿
OnePercentGroup×é֯ʹÓÃCobaltStrikeÀÕË÷Èí¼þ¶ÔÃÀ¹ú¹«Ë¾Ìᳫ¹¥»÷£¬Í¨¹ýÍøÂç´¹ÂÚÓʼþ¹¥»÷¹«Ë¾¿Í»§£¬½«IcedIDÒøÐÐľÂíÓÐÓÃÔØºÉͶ·Åµ½Ä¿µÄϵͳÉÏ£¬È»ºóÔÚÊÜѬȾµÄϵͳÉÏͶ·ÅºÍ×°ÖÃCobaltStrikeÀÕË÷Èí¼þ£¬²¢ÔÚ¹«Ë¾ÏµÍ³ÍøÂçÖкáÏòÒÆ¶¯¡£¾ÝÊӲ죬һµ©ÀÕË÷Èí¼þÀֳɰ²ÅÅ£¬¸Ã×éÖ¯¾Í»áÇÔÈ¡µ½ÃÀ¹ú¹«Ë¾ÏµÍ³¿Í»§µÄÎļþ£¬OnePercent×éÖ¯¶ÔÇÔÈ¡µ½µÄÎļþ¾ÙÐмÓÃܲ¢ÔÚÆäÎļþÃûºó¸½¼ÓÒ»¸öËæ»úµÄ°Ë×Ö·ûÀ©Õ¹Ãû£¬²¢Ìí¼ÓΨһÃüÃûµÄÊê½ð˵Ã÷£¬Í¨¹ýÑó´Ð·ÓÉÆ÷ÍøÂçºÍclearnetÐû²¼±»µÁÊý¾Ý£¬ÒªÐ®Êܺ¦ÕßÒÔÐéÄâÇ®±ÒÖ§¸¶Êê½ð¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMNp
6. ViceSociety×éÖ¯ÇÔÈ¡ÂÞ¶ûסÃñµÄÎļþºÍСÎÒ˽¼ÒÃô¸ÐÐÅÏ¢
¡¾¸ÅÊö¡¿
ViceSociety×éÖ¯¹¥»÷µÄÄ¿µÄÊǹ«Á¢Ñ§ÇøºÍ½ÌÓý»ú¹¹£¬ËüʵÑéË«ÖØÀÕË÷ģʽ£¬¸Ã×éÖ¯ÇÔÈ¡ÁËÈÕÄÚÍߺþÅÏÈðʿСÕòÂÞ¶û6,200ÃûסÃñǧÕ××Ö½ÚµÄÊý¾ÝÎļþºÍСÎÒ˽¼ÒÏêϸÐÅÏ¢£¬Ð¹Â¶µÄÊý¾Ý°üÀ¨·ÇÈðÊ¿¹úÃñµÄÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢Éç»áÇå¾²ºÅÂëºÍ¾ÓÁôÔÊÐíÐÅÏ¢£¬Ñ§Ð£¼Í¼ÒÔ¼°Ñ¬È¾Covid-19µÄ¶ùͯµÄÐÅÏ¢£¬²¢ÔÚ×éÖ¯ÄÚ²¿µÄÊý¾Ýй¶վµãÉÏÐû²¼´ÓÊܺ¦ÕßÄÇÀïÇÔÈ¡µÄÊý¾Ý¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMNR
7. SparklingGoblin×é֯ʹÓÃSideWalkÀÕË÷Èí¼þ¹¥»÷ÃÀ¹úµçÄÔÁãÊÛ¹«Ë¾
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷£¬Ò»¼ÒλÓÚÃÀ¹úµÄµçÄÔÁãÊÛ¹«Ë¾³ÉΪSparklingGoblin×éÖ¯¹¥»÷µÄÄ¿µÄ£¬SparklingGoblin×éÖ¯Ö÷ÒªÒÔרÃÅÕë¶Ô¶«ÑǺͶ«ÄÏÑÇʵÌåµÄÍøÂç¹¥»÷¶øÖøÃû¡£¸Ã×é֯ʹÓÃSideWalk¶ñÒâÈí¼þ½«¶ñÒâ´úÂë×¢Èëµ½¹«Ë¾Õýµ±³ÌÐò£¬²¢Ê¹ÓÃWindowsϵͳÉÏ.NET¼ÓÔØÆ÷°²ÅŶñÒâÈí¼þ£¬¸Ã¼ÓÔØÆ÷ÈÏÕæ´Ó¹«Ë¾ÏµÍ³´ÅÅÌÉ϶ÁÈ¡¼ÓÃܵĴúÂ룬¶ÔÆä¾ÙÐнâÃÜ£¬²¢Ê¹ÓÃÀú³ÌÊÖÒÕ½«Æä×¢ÈëÕýµ±Àú³Ì£¬Ê¹ÓÃCloudflare×÷ΪC&C·þÎñÆ÷£¬È»ºóSideWalkÓëC&C·þÎñÆ÷½¨ÉèͨѶ£¬Ê¹ÓÃGoogle Docs×÷ΪËÀÑ»·ÆÊÎöÆ÷£¬¶ñÒâÈí¼þ´ÓGoogle DocsÎĵµÖмìË÷¼ÓÃܵÄIPµØµã¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMNQ
8. ¹¥»÷ÕßʹÓÃMirai½©Ê¬ÍøÂç¶ÔCloudflare½ðÈÚ¿Í»§¾ÙÐÐDDOS¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷ÁËÓÐÊ·ÒÔÀ´×î´óµÄDDOS¹¥»÷£¬¹¥»÷ÕßʹÓÃMirai½©Ê¬ÍøÂç¶ÔCloudflare½ðÈÚÁìÓòµÄ¿Í»§¾ÙÐÐDDOS¹¥»÷£¬Í¨¹ýʹÓý©Ê¬ÍøÂçÔÚ¶Ìʱ¼äÄÚÄܱ¬·¢´ó×ڵĹ¥»÷Á÷Á¿£¬¹¥»÷Á÷Á¿À´×ÔÈ«Çò125¸ö¹ú¼Ò/µØÇøµÄ20,000¶à¸ö»úеÈË£¬Æ¾Ö¤»úеÈ˵ÄÔ´IPµØµã£¬ÏÕЩ15%µÄ¹¥»÷À´×ÔÓ¡¶ÈÄáÎ÷ÑÇ£¬ÁíÍâ17%À´×ÔÓ¡¶ÈºÍ°ÍÎ÷¡£¹¥»÷ÕßÊÔͼͨ¹ýʹÓöà¸öÂþÑÜʽλÖõÄÐéαÇëÇóÈ÷þÎñ±äµÃÔÆÔÆÃ¦ÂµÒÔÖÂÓÚ±ÀÀ£»ò×èÖ¹£¬´Ó¶ø¹¥»÷Cloudflare½ðÈÚ¿Í»§µÄÍøÕ¾£¬×èÖ¹¿Í»§Ê¹Ó÷þÎñ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMMS
9. ¹¥»÷ÕßʹÓÃSharePoint¹²ÏíÎļþ¹¥»÷Office365
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷£¬¹¥»÷ÕßÔÚÍøÂç´¹ÂÚÔ˶¯ÖÐʹÓÃSharePoint¹²ÏíÎļþ×÷ΪÓÕ¶ü¾ÙÐй¥»÷£¬´Ë´Î¹¥»÷Ô˶¯µÄÄ¿µÄÊÇOffice365£¬ÆäÄ¿µÄÊÇÆÈ¡Êܺ¦ÕßµÄÖ¤Ê飬¹¥»÷Õßͨ¹ý·¢Ë͵ç×ÓÓʼþ²¢ÔÚÐÅÏ¢ÖÐαÔìÁËÄ¿µÄÓû§ÃûµÄ·¢¼þÈ˵صã×÷ΪÓÕ¶ü£¬Õâ·âµç×ÓÓʼþÌáÐÑÊÕ¼þÈËÓÐÒ»¸ö¹²ÏíÎļþÇëÇó£¬ÕâСÎÒ˽¼Ò¿ÉÄÜÊÇËûÃǵÄͬÊ£¬²¢ÔÚÎļþÖаüÀ¨ÁËÒ»¸öÍøÂç´¹ÂÚÒ³ÃæµÄÁ´½Ó¡£Ñо¿Ö°Ô±Ö¸³ö£¬ÎªÁËʹÐżþÏÔµÃÔ½·¢ÕæÊµ¿ÉÐÅ£¬Ìý˵¸ÃÎļþ»¹°üÀ¨ÁËijÖÖÕýµ±ÀàÐ͵ÄÓªÒµÄÚÈÝ£¬ÈçÔ±¹¤±¨¸æ¡¢½±½ð»ò¼ÛÇ®Çåµ¥¡£ÈôÊÇÓû§µã»÷Õâ¸ö¶ñÒâÓʼþ£¬×îÖջᱻָµ¼µ½Ò»¸ö´¹ÂÚÒ³Ãæ£¬Ò³ÃæÒªÇóËûÃÇÓÃ×Ô¼ºµÄÕýµ±Æ¾Ö¤µÇ¼Office365¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMO7
10. ·ÆÂɱöÈËȨͬÃË¿¨ÀÅÁ̹KarapatanÔâÊÜÁËÑÏÖØµÄDDOS¹¥»÷
¡¾¸ÅÊö¡¿
·ÆÂɱöÈËȨͬÃË¿¨ÀÅÁ̹KarapatanÔâÊÜÁËÑÏÖØÇÒÒ»Á¬µÄDDoS¹¥»÷£¬Õâ´Î¹¥»÷ÊÇÔÚÕë¶ÔýÌåBulatlatºÍAltermidyaµÄDDoS¹¥»÷À˳±±¬·¢½öÒ»¸öÔÂÖ®ºó±¬·¢µÄ£¬DDoS¹¥»÷±¬·¢ÔÚÓÉKarapatanÅäºÏÖ÷ÀíµÄÔÚÏßÍŽáÔ˶¯StopTheKillingsPHʱ´ú£¬Õâ´Î¹¥»÷ÊÇͨ¹ýÂþÑÜÔÚ¶íÂÞ˹¡¢ÎÚ¿ËÀ¼¡¢Ó¡¶ÈÄáÎ÷ÑǺÍÖйúµÄ30,000¸ö»úеÈËÊðÀíµÄ¡£¹¥»÷Õß¶à´ÎÐÞ¸ÄÁ˹¥»÷Õ½ÂÔ£¬Õâ±ê¼Ç×ÅÌìϸ÷µØµÄÈËȨ×éÖ¯ºÍÌᳫÕߺôÓõ×èÖ¹·ÆÂɱöµÄɱ¾¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMO9

AG¹«Ë¾ÔÆ







