¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.09.13-2021.09.19£©
2021-09-22
Ò»¡¢ Íþвͨ¸æ
l Apache ShiroÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2021-41303£©
¡¾Ðû²¼Ê±¼ä¡¿2021-09-17 13:00:00GMT
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½Apache Shiro¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬ÐÞ¸´ÁËÒ»¸öеÄȨÏÞÈÆ¹ýÎó²î£¨CVE-2020-17523£©¡£µ±ÔÚSpring BootÖÐʹÓÃApache Shiroʱ£¬¹¥»÷Õß¿ÉÒÔ½á¹¹ÌØ¶¨µÄHTTPÇëÇóÈÆ¹ýÉí·ÝÑéÖ¤»á¼ûºǫ́¹¦Ð§£»ÇëÏà¹ØÓû§½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£Apache ShiroÊÇÒ»¸ö¹¦Ð§Ç¿Ê¢ÇÒÒ×ÓÚʹÓõÄJavaÇå¾²¿ò¼Ü£¬¹¦Ð§°üÀ¨Éí·ÝÑéÖ¤¡¢ÊÚȨ¡¢¼ÓÃܺͻỰÖÎÀí¡£Ê¹ÓÃShiroµÄAPI£¬¿ÉÒÔÇáËɵء¢¿ìËٵر£»¤ÈκÎÓ¦ÓóÌÐò£¬¹æÄ£´ÓСÐ͵ÄÒÆ¶¯Ó¦ÓóÌÐòµ½´óÐ͵ÄWebºÍÆóÒµÓ¦ÓóÌÐò¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. APT×é֯ʹÓÃSideWalk¶ñÒâÈí¼þÕë¶ÔÃÀ¹úÅÌËã»úÁãÊÛ¹«Ë¾Ìᳫ¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷ÁËAPT×é֯ʹÓÃSideWalk¶ñÒâÈí¼þÕë¶ÔÃÀ¹úÒ»¼ÒÅÌËã»úÁãÊÛ¹«Ë¾Ìᳫ¹¥»÷¡£¹¥»÷Õßͨ¹ýÈëÇÖ¹«Ë¾µÄMicrosoft Exchange »ò MySQL ·þÎñÆ÷£¬Ò»µ©ÔÚMicrosoft Exchange »ò MySQL Web ·þÎñÆ÷Éϰ²ÅÅ Web shell£¬¹¥»÷Õ߾ͻáÔÚÄ¿µÄÍøÂçÖкáÏòÈö²¥¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMQF
2. ºÚ¿ÍÇÔÈ¡FortinetÐéÄâרÓÃÍøÂç½ü50Íò¿Í»§µÄÕË»§ºÍÃÜÂë
¡¾¸ÅÊö¡¿
9ÔÂ8ÈÕ£¬Ò»ÃûÍøÂç¹¥»÷ÕßÇÔÈ¡Á˽ü50ÍòFortinet VPNµÇ¼ÃûºÍÃÜÂ룬ÓÉÓÚÐéÄâרÓÃÍøÂçÆ¾Ö¤¿ÉÄÜÔÊÐíÍþвÐÐΪÕß»á¼ûÍøÂçÖ´ÐÐÊý¾ÝÍâй¡¢×°ÖöñÒâÈí¼þºÍÖ´ÐÐÀÕË÷Èí¼þ¹¥»÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMPS
3. ºÚ¿ÍÇÔÈ¡ÁËÍŽá¹úÓû§µÄÊý¾Ý
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷£¬ºÚ¿Í¹¥»÷ÍŽá¹úµÄ»ù´¡ÉèÊ©£¬²¢ÇÒÇÔȡ͎á¹úÏµÍ³ÍøÂçÖеĴó×ÚÓû§Êý¾Ý£¬²¢ÇÒ½«ÇÔÈ¡µÄ´ó×ÚÐÅÏ¢³öÊÛ¸øÊÔͼÈëÇÖÍŽá¹úµÄÆäËûÍŻÒÔ½øÒ»²½ÍøÂçºã¾ÃÇ鱨¡£Ö®ºó£¬ºÚ¿ÍÊÔͼ»ñÈ¡¸ü¶àÓйØÍŽá¹úÅÌËã»úÍøÂç¼Ü¹¹µÄÐÅÏ¢£¬²¢ÈëÇÖÁË53¸öÍŽá¹úÕË»§£¬½«ÇÔÈ¡µÄÄÚÍøÕ˺źÍÃÜÂëÔÚ°µÍø³öÊÛ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMQV
4. ¹¥»÷ÕßʹÓÃBlackMatter ÀÕË÷Èí¼þ¹¥»÷¿Æ¼¼¾ÞÍ·°ÂÁÖ°Í˹
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷£¬Õë¶Ô¿Æ¼¼¾ÞÍ·°ÂÁÖ°Í˹µÄÀÕË÷Èí¼þ¹¥»÷Ô˶¯£¬¹¥»÷ÖÐʹÓÃBlackMatterÀÕË÷Èí¼þ£¬´Ë´Î¹¥»÷¶Ô°ÂÁÖ°Í˹µÄϵͳÔì³ÉÁËÆÕ±éÆÆË𣬵¼Ö°ÂÁÖ°Í˹×èÖ¹Á˿ͻ§µÄËùÓÐÎļþ´«Êä¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMRi
5. SextortionÀÕË÷Èí¼þÕ©ÆÕßʹÓÃÐéαµÄµç×ÓÓʼþ»ñÈ¡Êܺ¦Õß×°±¸µÄ»á¼ûȨÏÞ
¡¾¸ÅÊö¡¿
Sextortion ÊÇÒ»¸öͨ¹ýµç×ÓÓʼþ»òÈÎºÎÆäËûǰÑÔÀÕË÷Êܺ¦ÕßµÄȦÌ×ÍŻ²¢ÍþвҪ¹ûÕæÕÕÆ¬¡¢ÍøÒ³ä¯ÀÀÀúÊ·¼Í¼¡¢Ì¸Ìì¼Í¼µÈ˽ÈËÊý¾Ý¡£¸ÃÀÕË÷Èí¼þÕ©ÆÕßͨ¹ý·¢Ë͵ç×ÓÓʼþ»ñµÃ¶ÔÊܺ¦Õß×°±¸µÄ»á¼ûȨÏÞ£¬µ±Êܺ¦Õßµã»÷ÀÕË÷µç×ÓÓʼþʱ£¬Í¨¹ýµÇ¼µç×ÓÓʼþÔÚ×°±¸ÉÏ×°ÖÃÁËľÂí²¡¶¾¡£ÎªÁËʹÓʼþ¿´ÆðÀ´¸üÕæÊµ£¬¹¥»÷Õßͨ³£»á·¢ËÍÖ÷ÌâΪ“´ÓÄúµÄÕÊ»§¸¶¿î”µÄµç×ÓÓʼþ¡£È»ºóÉù³ÆÄúµÄÔ˶¯ÕýÔÚͨ¹ýÄúµÄ×°±¸£¨ÈçÏà»ú¡¢Âó¿Ë·çµÈ£©µÄ¿ØÖÆÆ÷±»¼Í¼¡£Êܺ¦ÕßÓÐ 48 СʱµÄʱ¼ä½« 1550 ÃÀÔª×ªÒÆµ½Æ×ӵıÈÌØ±ÒÇ®°ü£¬±êʶÈôÊÇûÓÐÏò±ÈÌØ±ÒµØµã¸¶¿î£¬ ¹¥»÷Õß»áÍþвÊܺ¦Õß¹ûÕæË½ÈËÊý¾Ý¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMQ1
6. Ì©¹úÉöÔàÒ½ÔºËÄÍòÃû»¼ÕßÊý¾Ý±»µÁ
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬Ñо¿Ö°Ô±·¢Ã÷£¬Ì©¹úÒ»ËùÉöÔàר¿ÆÒ½ÔºÏµÍ³ÔâÍøÂç¹¥»÷ÕßÈëÇÖ£¬µ¼Ö¸ÃÒ½Ôº»¼ÕßÊý¾Ý¿âÎÞ·¨»á¼û£¬Ëæºó£¬ÊÖÒÕÖ°Ô±ÔÚ¶Ôϵͳ¾ÙÐÐÁ˼ì²éÖ®ºó£¬·¢Ã÷ÓÐËÄÍò¶àÃû»¼ÕßµÄСÎÒ˽¼ÒÐÅÏ¢ºÍ²¡ÀýÐÅÏ¢±»ÍøÂç¹¥»÷Õß͵ȡ¡£´Ë´ÎÊý¾Ýй¶ÊÂÎñÆÆËðÁËÒ½ÔºµÄÊý¾Ýϵͳ£¬µ¼ÖÂÒ½ÉúÎÞ·¨Õý³£»á¼û»¼ÕßµÄX¹âµµ°¸ÐÅÏ¢¡£Ö®ºó£¬¹¥»÷ÕßÊÔͼͨ¹ýµç»°Ì¸ÅÐÀ´ÀÕË÷Ò½Ôº£¬ÒÔÏòÆäÖ§¸¶Êý¾ÝÊê½ð²¢Äûر»µÁµÄ»¼ÕßÊý¾Ý¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMRu
7. ¹¥»÷ÕßʹÓà maxtrilhaÒøÐÐľÂí¹¥»÷Å·ÖÞºÍÄÏÃÀÒøÐеĿͻ§
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±Åú×¢£¬·¢Ã÷ÁËÒ»ÖÖÃûΪ maxtrilhaµÄÐÂÒøÐÐľÂí£¬¸ÃÒøÐÐľÂíÕýÔÚÈö²¥£¬¹¥»÷Ä¿µÄÊÇÅ·ÖÞºÍÄÏÃÀÒøÐеĿͻ§£¬¹¥»÷ÕßÔÚÖ´ÐÐʱ´ú£¬Í¨¹ý¶ÌURL·¿ªÄ¿µÄÕýµ±Ò³Ã棬ÔÚÄ¿µÄ»úеÉϽ¨É賤ÆÚÐÔ£¬ËüʹÓà TinyURL ÔÚÏß·þÎñ£¬¸Ã·þÎñÔÚ¶ñÒâÈí¼þÖ´ÐÐʱ´úÓÉÊܺ¦ÕßÅÌËã»úÉÏ×°Öò¢¿ÉÓõÄĬÈÏ Web ä¯ÀÀÆ÷·¿ª¡£¶Ì URL Ö¸ÏòÓëÍøÂç´¹ÂÚÄ£°åÏà¹ØµÄÌØ¶¨Ò³ÃæÒÔÒýÓÕÊܺ¦Õß¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMR2
8. ÄÏ·Ç˾·¨²¿ºÍÏÜ·¨Éú³¤²¿Ôâµ½ÀÕË÷Èí¼þ¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±Åú×¢£¬ÄÏ·Ç˾·¨²¿ºÍÏÜ·¨Éú³¤²¿ÏµÍ³Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬¹¥»÷ÕßʹÓÃÀÕË÷Èí¼þ°üÀ¨¶ñÒ⸽¼þµÄÍøÂç´¹ÂÚµç×ÓÓʼþ»òͨ¹ý͵¶ÉʽÏÂÔØ¾ÙÐÐÈö²¥£¬ÏµÍ³±»¹¥»÷ºó£¬µ¼Ö¸ò¿·ÖÐÅÏ¢ÊÖÒÕϵͳÒÔ¼°µç×ÓÓʼþºÍ±£ÊͶàÏî·þÎṉ̃»¾£¬ÒÔ¼°ËùÓеÄÐÅϢϵͳ¼ÓÃÜ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMR4
9. AnonymousºÚ¿ÍÕûÌå¹¥»÷ÍøÂçÍйܷþÎñÌṩÉÌEpik
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±³Æ£¬AnonymousºÚ¿ÍÕûÌåÈëÇÖÁËÍøÂçÍйܷþÎñÌṩÉÌEpik£¬²¢ÇÔÈ¡Á˸ù«Ë¾180GBÓû§µÄÊý¾Ý¡¢×¢²á¡¢×ª·¢µÈÐÅÏ¢£¬²¢ÔÚ DDoSecrets ·ÇÓ¯Àû¾Ù±¨ÍøÕ¾ÉÏй¶¡£¾ÝºÚ¿Í³Æ£¬±»µÁÊý¾Ý°üÀ¨£ºÓòÃû¹ºÖã¬ÓòÃû×ªÒÆ£¬WHOISÀúÊ·£¬DNS¸ü¸Ä£¬µç×ÓÓʼþת·¢£¬Ö§¸¶ÀúÊ·£¬ÕË»§Æ¾Ö¤£¬Áè¼Ý500000¸ö˽ԿµÈÐÅÏ¢¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMRD
10. ¹¥»÷ÕßʹÓÃOperation Layover¶ñÒâÈí¼þ¹¥»÷º½¿Õº½ÌìºÍÂÃÓÎÐÐÒµ
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬Ñо¿Ö°Ô±·¢Ã÷£¬Ò»ÏîÓÐÕë¶ÔÐÔµÄÍøÂç´¹ÂÚÔ˶¯ÓÉÔÚÄáÈÕÀûÑÇ¿ªÕ¹ÓªÒµµÄ¹¥»÷Õß´ø¶¯Ìᳫ£¬Ä¿µÄÊǹ¥»÷º½¿Õº½ÌìºÍÂÃÓÎÐÐÒµ£¬´Ë´Î¹¥»÷Ô˶¯Ê¹Óà Operation Layover¶ñÒâÈí¼þ£¬Í¨¹ýÓã²æÊ½ÍøÂç´¹ÂÚµç×ÓÓʼþ·ÖÌáÒé¾¢¿ª·¢µÄ¼ÓÔØ³ÌÐò£¬È»ºóÌṩ RevengeRAT »ò AsyncRAT£¬¹¥»÷Õß½«¶à¸ö RAT ±àÖ¯µ½ËûÃǵÄÔ˶¯ÖУ¬½«»ù´¡ÉèÊ©ÓÃ×÷ Cyber??gate RAT¡¢AsyncRAT ºÍÅú´¦Öóͷ£ÎļþµÄÏÂÁîºÍ¿ØÖÆ (C2) ·þÎñÆ÷×÷Ϊ¶ñÒâÈí¼þÁ´µÄÒ»²¿·ÖÀ´ÏÂÔØºÍÖ´ÐÐÆäËû¶ñÒâÈí¼þ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMS9

AG¹«Ë¾ÔÆ







