¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.09.20-2021.09.26£©
2021-09-30
Ò»¡¢ Íþвͨ¸æ
º£¿µÍþÊÓ²úÆ·ÏÂÁî×¢ÈëÎó²î£¨CVE-2021-36260£©
¡¾Ðû²¼Ê±¼ä¡¿2021-09-22 13:00:00GMT
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½º£¿µÍþÊÓÐû²¼Ç徲ͨ¸æ£¬ÐÞ¸´Á˺£¿µÍþÊÓ²¿·Ö²úÆ·ÖеÄwebÄ£¿é±£´æµÄÒ»¸öÏÂÁî×¢ÈëÎó²î£¬ÓÉÓÚ¶ÔÊäÈë²ÎÊýУÑé²»³ä·Ö£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ý½á¹¹´øÓжñÒâÏÂÁîµÄ±¨ÎÄ·¢Ë͵½ÊÜÓ°Ïì×°±¸£¬¿ÉʵÏÖÔ¶³ÌÏÂÁîÖ´ÐС£
º£¿µÍþÊÓÊÇÒÔÊÓÆµÎª½¹µãµÄÖÇÄÜÎïÁªÍø½â¾ö¼Æ»®ºÍ´óÊý¾Ý·þÎñÌṩÉÌ£¬ÓªÒµ¾Û½¹ÓÚÖÇÄÜÎïÁªÍø¡¢´óÊý¾Ý·þÎñºÍÖÇ»ÛÓªÒµ£¬¹¹½¨¿ª·ÅÏàÖúÉú̬£¬Îª¹«¹²·þÎñÁìÓòÓû§¡¢ÆóÊÂÒµÓû§ºÍÖÐСÆóÒµÓû§Ìṩ·þÎñ£¬ÖÂÁ¦ÓÚÐÞ½¨ÔƱßÈںϡ¢ÎïÐÅÈںϡ¢ÊýÖÇÈںϵÄÖǻ۶¼»áºÍÊý×Ö»¯ÆóÒµ¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
l VMware vCenter Server ¶à¸ö¸ßΣÎó²îͨ¸æ£¨CVE-2021-22005£©
¡¾Ðû²¼Ê±¼ä¡¿2021-09-22 13:00:00GMT
¡¾¸ÅÊö¡¿
9ÔÂ22ÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½VMware ¹Ù·½Ðû²¼Ç徲ͨ¸æÅû¶ÁËVMware vCenter ServerÖеĶà¸öÎó²î£¬¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îÔì³ÉÐÅϢй¶¡¢È¨ÏÞÌáÉý¡¢Ô¶³Ì´úÂëÖ´Ðеȡ£ÏÖÔÚ¹Ù·½ÒѸüа汾ÐÞ¸´£¬ÇëÏà¹ØÓû§½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
vCenter ServerÊÇVMware¹«Ë¾µÄÒ»ÖÖ·þÎñÆ÷ÖÎÃ÷È·¾ö¼Æ»®£¬¿É×ÊÖúITÖÎÀíԱͨ¹ýµ¥¸ö¿ØÖÆÌ¨ÖÎÀíÆóÒµÇéÐÎÖеÄÐéÄâ»úºÍÐéÄ⻯Ö÷»ú¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. ¹¥»÷ÕßʹÓÃNumandoÐÂÐÍÒøÐÐľÂíÕë¶ÔÄ«Î÷¸çºÍÎ÷°àÑÀÓû§Ìᳫ¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»ÖÖÐ嵀 LATAM ÒøÐÐľÂí£¬±»ÃüÃûΪ Numando£¬ËüÀÄÓà YouTube¡¢Pastebin ºÍÆäËû¹«¹²Æ½Ì¨×÷Ϊ C2 »ù´¡ÉèÊ©²¢¾ÙÐÐÈö²¥¡£×¨¼Ò·¢Ã÷Á˹¥»÷ÕßʹÓÃNumando¶ñÒâÈí¼þÕë¶ÔÄ«Î÷¸çºÍÎ÷°àÑÀÓû§µÄÌᳫ¹¥»÷¡£ÓëÆäËûÀ¶¡ÃÀÖÞÒøÐÐľÂíÒ»Ñù£¬ËüÊÇÓà Delphi ±àдµÄ£¬²¢Ê¹ÓÃÐéαµÄÁýÕÖ´°¿ÚÀ´ÓÕÆÊܺ¦ÕßÌṩÃô¸ÐÐÅÏ¢¡£Ò»µ© Numando ×°ÖÃÔÚÄ¿µÄ»úеÉÏ£¬Ã¿µ±Êܺ¦Õß»á¼û½ðÈÚ×éÖ¯µÄÍøÕ¾²¢²¶»ñËûÃÇÌṩµÄƾ֤ʱ£¬Ëü¶¼»á½¨ÉèÐéαµÄÁýÕÖ´°¿Ú¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMSj
2. APT-C-36ÌØ¹¤×é֯ͨ¹ýαװ³É¸çÂ×±ÈÑÇÕþ¸®»ú¹¹ÏòÓû§Èö²¥ÐéαµÄµç×ÓÓʼþ
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»ÏîÕë¶ÔÄÏÃÀ×éÖ¯µÄÓã²æÊ½ÍøÂç´¹ÂÚÓʼþµÄÀ¬»øÓʼþÔ˶¯£¬ÕâЩ¹¥»÷¹éÒòÓÚÒ»ÖÖ±»³ÆÎªAPT-C-36µÄ¸ß¼¶Ò»Á¬Íþв×éÖ¯ (APT) £¬¸Ã×éÖ¯Ö÷Ҫͨ¹ýαװ³É¸çÂ×±ÈÑÇÕþ¸®»ú¹¹£¬Ïò¿Í»§·Ö·¢Ú²ÆÐԵĵç×ÓÓʼþ£¬µ±ÓʼþÊÕ¼þÈË·¿ªÓÕ¶ü PDF »ò Word ÎĵµÊ±£¬Ñ¬È¾Á´¾Í×îÏÈ£¬¸ÃÓʼþÉù³ÆÊÇÓëÆäÏà¹ØµÄ¿ÛѺÁî£¬ÒøÐÐÕÊ»§£¬È»ºóµ¥»÷´Ó URL Ëõ¶ÌÆ÷·þÎñÌìÉúµÄÁ´½Ó¡£APT-C-36 »áƾ֤λÖú͵ç×ÓÓʼþÊÕ¼þÈ˵IJÆÎñ״̬À´Ñ¡ÔñËûÃǵÄÄ¿µÄ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMSn
3. TeamT.NT½©Ê¬ÍøÂçÍŻ﹥»÷È«Çò¸÷µØµÄ×éÖ¯»ú¹¹
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»ÏîÃûΪChimaeraµÄÐÂÔ˶¯£¬ÕâÏîÔ˶¯ÓÉTeamT.NT½©Ê¬ÍøÂçÍÅ»ï¾ÙÐУ¬Ä¿µÄÊǹ¥»÷È«Çò¸÷µØµÄ×éÖ¯»ú¹¹¡£ÎªÁËÇÔȡȫÇò¸÷µØµÄ×éÖ¯»ú¹¹µÇ¼ƾ֤£¬TeamT.NTÔÚËûÃǵĹ¥»÷×°±¸¿âÖÐÌí¼ÓÁËÐí¶à¹¤¾ß£¬°üÀ¨shell¾ç±¾¡¢Òþ²ØÍÚ¿ó¡¢IRCºÍ¿ªÔ´Èí¼þµÈ¡£ËûÃÇÒ»Ö±ÔÚ¹¥»÷WindowsϵͳºÍÖÖÖÖLinux²Ù×÷ϵͳ£¬ÒÔ¼°AWS¡¢DockerºÍKubernetes£¬ÈËÃÇ×¢ÖØµ½ÆäÒÑÍùÒ²¹¥»÷¹ýMacOSϵͳ¡£È«ÇòÁè¼Ý5000¶àÀý¶ñÒâÈí¼þѬȾÊÂÎñ¹éÒòÓÚTeamTNT¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMSo
4. Ã÷ÄáËÕ´ïÖÝũҵ¹©Ó¦ÏàÖúÉçË®¾§¹ÈÔâÓöÀÕË÷Èí¼þ¹¥»÷
¡¾¸ÅÊö¡¿
Ã÷ÄáËÕ´ïÖÝũҵ¹©Ó¦ÏàÖúÉçË®¾§¹ÈÔâÓöÀÕË÷Èí¼þ¹¥»÷£¬¸ÃÏàÖúÉçΪ 2,500 ÃûÅ©ÃñºÍÉüÐóÉú²úÕßÌṩ·þÎñ£¬²¢ÓµÓÐ 260 ÃûÔ±¹¤¡£Õâ´Î¹¥»÷ÒѾѬȾÁËË®¾§¹ÈµÄÅÌËã»úϵͳ£¬ÑÏÖØÖÐÖ¹Á˹«Ë¾µÄÒ»Ñùƽ³£ÔËÓª£¬¸Ã¹«Ë¾ÒѾ¹Ø±ÕÁË IT ϵͳ£¬ÔÝÍ£ÁËËùÓÐʹÓà Visa.Mastercard ºÍ Discover ÐÅÓÿ¨µÄ¸¶¿î¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMSV
5. Turla×éÖ¯¹¥»÷°¢¸»º¹µÄÕþ¸®×éÖ¯ºÍ»ú¹¹
¡¾¸ÅÊö¡¿
Ò»¸öÓë¶íÂÞ˹ÓйØÁªµÄTurla ×éÖ¯Ò»Ö±ÒÔÕþ¸®×éÖ¯µÄϵͳΪĿµÄ£¬Í¨¹ýÔڸûú¹¹Éϰ²ÅŶñÒâÈí¼þ£¬ÒÔ¼á³ÖÔÚÊÜѬȾװ±¸Öеij¤ÆÚÐÔ£¬Ñо¿Ö°Ô±½«¶ñÒâÈí¼þ³ÆÎªTinyTurla£¬ÔÚÒÑÍùÁ½ÄêÖÐÒÑÕë¶ÔÃÀ¹úºÍµÂ¹úϵͳ°²ÅÅ¡£×î½ü£¬Turla ÔÚ°¢¸»º¹ÓÚ 8 Ô±»ËþÀû°àÕ¼Áì֮ǰ¾ÍʹÓÃÁ˸öñÒâÈí¼þÀ´¹¥»÷°¢¸»º¹µÄÕþ¸®×éÖ¯ºÍ»ú¹¹¡£ Turla ½«¶ñÒâÈí¼þαװ³ÉÒ»¸öÃûΪ“Windows ʱ¼ä·þÎñ”µÄÕýµ± Microsoft Îļþ£¬¸ÃÎļþÔÊÐí¶ñÒâ´úÂëÔÚºǫ́ÔËÐв¢ÓëÊÜѬȾÉè±¹ØÁ¬ÄÕýµ±Ó¦ÓóÌÐò»ìÏý¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMSS
6. ¹¥»÷ÕßʹÓÃÉÌÒµRATÓÕ¶ü¹¥»÷Õë¶ÔÓ¡¶ÈÕþ¸®Ö°Ô±Ìᳫ¹¥»÷
¡¾¸ÅÊö¡¿
Cisco Talos ×î½ü·¢Ã÷ÁËÒ»¸öÕë¶ÔÓ¡¶È´Î´ó½Õþ¸®¹ÍÔ±ºÍ¾üÊÂÖ°Ô±µÄ¶ñÒâÔ˶¯£¬ÆäÖÐÓÐÁ½¸öRAT ÓÕ¶üϵÁУ¬³ÆÎªNetwireRATºÍWarzoneRAT¡£¹¥»÷ÕßÏòÆäÓ¡¶ÈÕþ¸®Ö°Ô±·¢ËÍÁËÖÖÖÖÓÕ¶ü£¬Ö÷Ҫαװ³ÉÓëÓ¡¶ÈÕþ¸®»ù´¡ÉèÊ©ºÍ²Ù×÷Ïà¹ØµÄÖ¸ÄÏ£¬µ±Êܺ¦ÕßʹÓöñÒâÎĵµÏÂÔØºÍ¼ì²â¼ÓÔØ³ÌÐò£¬¼ÓÔØÆ÷ÈÏÕæÏÂÔØ»ò½âÃÜ×îÖÕµÄ RAT ¸ºÔز¢½«Æä°²ÅÅÔÚÊÜѬȾµÄ¶ËµãÉÏ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMT1
7. ¹¥»÷ÕßÇÔÈ¡ÁË1.06ÒÚÌ©¹úÓοÍ
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷£¬¹¥»÷ÕßÈëÇÖÁËÌ©¹úµÄElasticsearchÊý¾Ý¿â£¬²¢ÇÒÇÔÈ¡ÁË1.06ÒÚÌ©¹úÓοͣ¬ÇÔÈ¡µÄСÎÒ˽¼ÒÐÅÏ¢°üÀ¨ÂÃÐÐÕßµÄÈ«Ãû¡¢»¤ÕÕºÅÂë¡¢¾ÓÁôÉí·Ý¡¢µÖ´ïÌ©¹úµÄÈÕÆÚ¡¢ÒÆÃñÈë¾³¿¨ºÅÂëºÍǩ֤ÀàÐÍ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMSR
8. ¶íÂÞ˹µÄYandexÔâÊÜÊ·ÉÏ×î´óµÄDDOS¹¥»÷
¡¾¸ÅÊö¡¿
YandexÊǶíÂÞ˹µÄµÚÒ»´óËÑË÷ÒýÇæ£¬Ðí¶àÈ˻ὫÆä³ÆÎª¶íÂÞ˹µÄ“°Ù¶È”£¬ÒÔ¼°ÊǶíÂÞ˹×î´óµÄ»¥ÁªÍø·þÎñÌṩÉÌ£¬º¸ÇÁËËÑË÷ÒýÇæ¡¢µç×ÓÉÌÎñ¡¢µç×ÓÓʼþµÈ»¥ÁªÍøÓªÒµ£¬³ÆÖ®Îª¶íÂÞ˹µÄ“BAT”¡£ ¾ÝÍâý±¨µÀ£¬¿ËÈÕYandexÔâÊÜÁ˶íÂÞ˹»¥ÁªÍøÀúÊ·ÉÏ×î´óµÄDDoS¹¥»÷£¬¹¥»÷·åÖµµÖ´ïÁËÿÃë2180Íò´ÎÇëÇó¡£YandexÄÚ²¿ÈËÊ¿³Æ±¾´ÎDDoS¹¥»÷ÄÑÒÔ×èÖ¹£¬×èÖ¹±¾ÖÜÈÔÔÚ¼ÌÐøÔâÊܹ¥»÷¡£±¾´ÎDDoS¹¥»÷ÊÇÓÉÒ»¸öеĽ©Ê¬ÍøÂçÌᳫµÄ£¬¸Ã½©Ê¬ÍøÂç±»±ê¼ÇΪMéris£¬ÓÉԼĪ20¶àÍǫ̀װ±¸×é³É¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMSA
9. MarketronÔâµ½ Black Matter ÍÅ»ïÌᳫµÄÀÕË÷Èí¼þ¹¥»÷
¡¾¸ÅÊö¡¿
MarketronÊÇÒ»¼ÒΪýÌåÐÐÒµÌṩÆóÒµÊÕÈëºÍÖÎÃ÷È·¾ö¼Æ»®µÄ¹©Ó¦ÉÌ£¬Marketron Broadcast SolutionsÔâµ½ Black Matter ÍÅ»ïÌᳫµÄÀÕË÷Èí¼þ¹¥»÷£¬¸Ã¹¥»÷ÒÑϼÜÁ˸ÃÓªÏú¹«Ë¾µÄÐí¶à²úÆ·¡£´Ë´Î¹¥»÷Ö±½ÓÓ°ÏìÁ˸ù«Ë¾µÄ 6,000 ¼ÒýÌåÐÐÒµ¿Í»§£¬´ó²¿·Ö·þÎñÈÔ´¦ÓÚÀëÏß״̬¡£Õâ¸öÊý×ÖÒ»¶¨»áÔÚÏÂÓÎЧӦÖгÊÖ¸Êý¼¶ÔöÌí¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMSD
10. º½Ô˾ÞÍ·CMA CGMÔâÓö¹¥»÷ÕßÏ®»÷
¡¾¸ÅÊö¡¿
·¨¹úº½Ô˹«Ë¾CMA CGM³Æ£¬ÔÚÔâÊÜÀÕË÷Èí¼þ¹¥»÷µ¼ÖÂÆäϵͳÀëÏßÊýÌìºó£¬¸Ã¹«Ë¾ÔâÓöÊý¾Ýй¶½üÒ»Äê¡£ÔÚ¶Ô¼¯ÍÅ API µÄ¼à¿Ø²Ù×÷ʱ´ú£¬¼ì²âµ½ÓйØÓÐÏÞ¿Í»§ÐÅÏ¢£¨ÐÕÃû¡¢¹ÍÖ÷¡¢Ö°Î»¡¢µç×ÓÓʼþµØµãºÍµç»°ºÅÂ룩µÄÊý¾Ýй¶£¬´Ë´Î¹¥»÷µ¼ÖÂÆä IT ϵͳ̱»¾¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMSq

AG¹«Ë¾ÔÆ







