¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.10.04-2021.10.10£©
2021-10-14
Ò»¡¢ ÈÈÃÅ×ÊѶ
1. ¹¥»÷ÕßʹÓÃÀÕË÷Èí¼þ¶ÔSpringhillÒ½ÁÆÖÐÐľÙÐй¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷£¬SpringhillÒ½ÁÆÖÐÐÄÔâÀÕË÷Èí¼þ¹¥»÷£¬µ¼Ö¸ÃÒ½ÁÆÖÐÐIJ¿·Öµç×Ó×°±¸ÒÑʧЧ£¬ÒÔ¼°µ¼ÖÂijӤ¶ù²»ÐÒÀëÊÀ£¬¸ÃĸÇ×¶ÔÒ½ÁÆÖÐÐÄÌáÆðËßËÏ£¬ÒÔΪҽÁÆÖÐÐÄÓ¦¶Ô´ËÊÂÎñÈÏÕæ¡£µ«ÓÉÓÚϵͳ·ºÆð¹ÊÕÏÒ½»¤Ö°Ô±¼à²â²»µ½Ó¤¶ùµÄ״̬£¬´ý·¢Ã÷ÎÊÌâºó£¬Ó¤¶ùÒÑ·ºÆðÁËÑÏÖØµÄÄÔËðÉË£¬ÔÚÒ»Á¬¹©Ñõ¾Å¸öÔºóÈ¥ÊÀ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMVE
2. ¿ç¹ú¹¤³Ì¾Þͷΰ¶û¼¯ÍÅWeir GroupÔâÊÜÀÕË÷Èí¼þÍŻ﹥»÷
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬ËÕ¸ñÀ¼¿ç¹ú¹¤³Ì¾Þͷΰ¶û¼¯ÍÅ£¨Weir Group£©ÔâÊܵ½ÀÕË÷Èí¼þ¹¥»÷¡£¸ÃÀÕË÷ÊÂÎñµ¼ÖÂÆä·¢»õ¡¢ÖÆÔìºÍ¹¤³ÌÖÐÖ¹£¬ÒÔ¼°µ¼Ö¼ä½ÓÓöȽÓÄÉȱ·¦ºÍÊÕÈëÑÓÆÚ5000ÍòÓ¢°÷¡£Î°¶û¼¯ÍÅÊÇÈ«Çò×ÅÃû¿óÒµ¡¢Ê¯ÓÍ×ÔÈ»ÆøºÍµçÁ¦»ù´¡ÉèÊ©¹¤³Ì½â¾ö¼Æ»®µÄÌṩÕߣ¬ÔÚÈ«Çò50¶à¸ö¹ú¼ÒÓµÓÐ1.15ÍòÃûÔ±¹¤¡£¹ØÓÚ´Ë´ÎÀÕË÷ÊÂÎñ£¬Î°¶û·½ÃæÌåÏÖ£º“ΰ¶ûÍøÂçÇ徲ϵͳ£¬¶ÔÍþв×ö³öÁË¿ìËÙ·´Ó¦£¬²¢½ÓÄÉÁËÇ¿ÓÐÁ¦µÄ±£»¤²½·¥——Õâ°üÀ¨¸ôÀëºÍ¹Ø±ÕITϵͳ£¬ÌØÊâÊǸôÀëºÍ¹Ø±Õ½¹µãÆóÒµ×ÊÔ´ÍýÏë (ERP)ºÍ¹¤³ÌÓ¦ÓóÌÐò¡£”
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMVs
3. ¹è¹ÈΣº¦Í¶×ʹ«Ë¾Ð¹Â¶ÁË“ÉúÒâÁ÷”Êý¾Ý
¡¾¸ÅÊö¡¿
Ò»¼Ò¹è¹ÈΣº¦Í¶×ʹ«Ë¾ÔËӪ׎«Í¶×ÊÕßÓëÊ×´´¹«Ë¾ÁªÏµÆðÀ´µÄÅä¶Ô·þÎñ£¬Ì»Â¶ÁË 6GB µÄÊý¾Ý£¬°üÀ¨ÓëͶ×ÊÕߺÍÊ×´´¹«Ë¾ÓйصÄÉúÒâÁ÷ÐÅÏ¢¡£ÕâЩÊý¾ÝÊôÓÚ Plug and Play Ventures£¬¸Ã¹«Ë¾×ܲ¿Î»ÓÚ¼ÓÀû¸£ÄáÑÇÖÝÉ£Äáά¶û£¬²¢ÔÚÌìϸ÷µØÉèÓзþÎñ´¦¡£¼´²å¼´ÓÃ×ÊÖúÊ×´´¹«Ë¾Æð²½£¬²¢½«ÕâЩ¹«Ë¾ÓëͶ×ÊÕßÏàÆ¥Åä¡£¸Ã¹«Ë¾ÌåÏÖ£¬ËüÊÜÒæÓÚ¶Ô PayPal ºÍ Dropbox µÄÔçÆÚͶ×Ê¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMV9
4. ¹¥»÷ÕßʹÓÃCoinbaseÎó²îÇÔÈ¡Óû§×ʽð
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷£¬¹¥»÷ÕßʹÓüÓÃÜÇ®±ÒÉúÒâËù Coinbase ʵÑéµÄ»ùÓÚ SMS µÄË«ÒòËØÉí·ÝÑéÖ¤ (2FA) ϵͳÖеÄÎó²î´Ó 6,000 ¶à¸öÓû§ÄÇÀïÇÔÈ¡×Ê½ð¡£Æ¾Ö¤Ìá½»¸øÃÀ¹úÖÝÉó²é³¤°ì¹«ÊÒµÄÊý¾Ýй¶֪ͨÐÅ£¬¹¥»÷ÕßÖªµÀËûÃǵÄÓû§ÃûºÍÃÜÂëÒÔ¼°ÓëÕÊ»§Ïà¹ØµÄµç»°ºÅÂ룬Äܹ»Èƹý»ùÓÚ SMS µÄÉí·ÝÑéÖ¤ÇÔÈ¡×ʽð¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMV8
5. ÄäÃûÈËʿй¶ÁËTwitchµÄÔ´´úÂëºÍÊý¾Ý
¡¾¸ÅÊö¡¿
ÄäÃû 4chan Óû§ÔÚ 4chan ÂÛ̳ÉÏÐû²¼ÁËÒ»¸ö 128GB ÎļþµÄ torrent Á´½Ó£¬Ð¹Â¶µÄµµ°¸°üÀ¨´Ó 6,000 ¸öÄÚ²¿ Twitch Git ´æ´¢¿âÇÔÈ¡µÄÃô¸ÐÊý¾Ý¡£The Record µÄר¼ÒÏÂÔØ²¢ÆÊÎöÁËÊý¾ÝÒÔÑéÖ¤ÆäÕæÊµÐÔ£¬È·ÈÏй¶µÄÄÚÈݰüÀ¨Æ½Ì¨µÄÓû§Éí·ÝºÍÉí·ÝÑéÖ¤»úÖÆÒÔ¼°Æä¶¥¼¶Á÷ýÌåµÄÖ§¸¶¼Æ»®¡£Ê¢ÐеÄÊÓÆµÁ÷ƽ̨֤ʵÁËÇå¾²Îó²î£¬²¢ÕýÔÚ¶ÔÆä¾ÙÐÐÊÓ²ìÒÔÈ·¶¨ÊÂÎñµÄÑÏÖØË®Æ½¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMV7
6. APT28×éÖ¯Õë¶Ô14000ÃûGmailÓû§Ìᳫ¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öAPT28ÍøÂç´¹ÂÚÔ˶¯£¬Ä¿µÄÊÇ¿ç¶à¸öÆóÒµµÄԼĪ 14,000 Ãû Gmail Óû§£¬¸Ã×éÖ¯ÔÚ¶íÂÞ˹×ÜÕÕÁϲ¿Ö÷ÒªÇ鱨¾Ö (GRU) µÚ 85 Ö÷ÒªÌØÊâ·þÎñÖÐÐÄ (GTsSS) µÄ¾üÊÂͳһ 26165 Ö®ÍâÔË×÷¡£Google ½¨Òé ΪÊÂÇéºÍСÎÒ˽¼Òµç×ÓÓʼþ×¢²á ¸ß¼¶±£»¤ÍýÏ룬¸ÃÍýÏë±£»¤¾ßÓи߶ȿɼûÐÔºÍÃô¸ÐÐÅÏ¢µÄÓû§£¬ÕâЩÓû§ÃæÁÙÓÐÕë¶ÔÐÔµÄÔÚÏß¹¥»÷µÄΣº¦¡£¸Ã¹«Ë¾»á×Ô¶¯Ë¢ÐÂÆä·þÎñÒÔµÖÓùµ±½ñÆÕ±éµÄÍþв¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMVe
7. ÀÕË÷ÍÅ»ïʹÓà Python ¾ç±¾¼ÓÃÜ VMware ESXi ·þÎñÆ÷
¡¾¸ÅÊö¡¿
ÀÕË÷Èí¼þÍÅ»ïʹÓÃ×Ô½ç˵ Python ½ÅÔÀ´¹¥»÷ VMware ESXi ²¢¼ÓÃÜ·þÎñÆ÷ÉÏÍйܵÄËùÓÐÐéÄâ»ú¡£ÈëÇÖÕßͨ¹ýµÇ¼ÔÚÓòÖÎÀíÔ±µÇ¼µÄ×°±¸ÉÏÔËÐÐµÄ TeamViewer ÕÊ»§À´»á¼ûÍøÂ硣Ȼºó¹¥»÷ÕßʹÓà Advanced IP Scanner ɨÃèÍøÂç¶Ëʶ±ðÆäËûÄ¿µÄ£¬È»ºóʹÓÃÃûΪ Bitvis µÄ SSH ¿Í»§¶ËµÇ¼µ½ ESXi ·þÎñÆ÷¡£ÔÚÕâÖÖÇéÐÎÏ£¬Êܺ¦×éÖ¯µÄ IT ÖÎÀíÔ±Èà SSH ESXi Shell ·þÎñΪ¹¥»÷Õß·¿ªÁË´óÃÅ£¬ÀÕË÷Èí¼þ²Ù×÷ÕßÈ»ºóÖ´ÐÐÒ»¸öϸСµÄ Python ¾ç±¾ (6kb) À´¼ÓÃÜ·þÎñÆ÷ÉÏÍйܵÄÐéÄâ»úµÄËùÓÐÐéÄâ´ÅÅÌºÍ VM ÉèÖÃÎļþ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMV1
8. ¹¥»÷ÕßʹÓÃ0dayÎó²î¹¥»÷¶íÂÞ˹¶à¸ö×éÖ¯
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬Ñо¿Ö°Ô±·¢Ã÷£¬ÃÀ¹ú¿Ú°¶Ö®Ò»µÄÐÝ˹¶ÙÔâµ½¹¥»÷ÕßÍøÂç¹¥»÷£¬Æ¾Ö¤ÃÀ¹ú»ú¹¹µÄ˵·¨£¬ÒÔΪÕâ´Î¹¥»÷ÊÇÓÉʹÓÃZohoÓû§Éí·ÝÑé֤װ±¸ÖеÄÁãÈÕÎó²îµÄ“¹¥»÷ÕߔʵÑéµÄ¡£ÃÀ¹úÁª°îÊÓ²ì¾Ö¡¢CISA ºÍº£°¶¾¯ÎÀ¶ÓÍøÂç˾Á Ðû²¼ÍŽáͨ¸æ£¬ÖÒÑÔAPT ×éÖ¯ÕýÔÚÆð¾¢Ê¹ÓÃADSelfService Plus Èí¼þ£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÈí¼þÀ´°²ÅÅ webshel??l£¬Õâʹ¹¥»÷ÕßÄܹ»¾ÙÐкóʹÓÃÔ˶¯£¬ÀýÈçÆÆËðÖÎÀíԱƾ֤¡¢¾ÙÐкáÏòÒÆ¶¯ÒÔ¼°Ð¹Â¶×¢²á±íÉèÖõ¥Î»ºÍ Active Directory Îļþ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMTX
9. ÃÀ¹úýÌ弯ÍÅCMGÔâµ½ÀÕË÷Èí¼þÍŻ﹥»÷
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬Ñо¿Ö°Ô±·¢Ã÷£¬ÃÀ¹úýÌ弯ÍÅCMGÔâµ½ÀÕË÷Èí¼þÍŻ﹥»÷£¬µ¼ÖµçÊÓÖ±²¥ºÍ¹ã²¥Á÷ÖÐÖ¹¡£CMGÁ¬Ã¦ÔÚÖ´·¨²¿·ÖµÄÖ§³ÖÏÂÕö¿ªÊӲ죬»¹Ô¼ÇëÁËÁìÏȵÄÍøÂçÇ徲ר¼ÒÀ´È·¶¨¹¥»÷µÄˮƽ¡£¸Ã¹«Ë¾Ö¤Êµ£¬ËüûÓÐÖ§¸¶Êê½ð¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMVu
10. Ó¡µÚ°²ÄÉÖÝ2¼ÒÒ½ÔºÔâÓöÍøÂç¹¥»÷
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬Ñо¿Ö°Ô±·¢Ã÷£¬Ó¡µÚ°²ÄÉÖÝ2¼ÒÒ½ÔºÔâÓöÍøÂç¹¥»÷£¬»®·ÖÊǸ»À¼¿ËÁÖµÄÔ¼º²Ñ·¼ÍÄ½¡ÖÐÐĺÍλÓÚÎ÷ĦԼ 40 Ó¢ÀïÍâµÄÊ©ÄÚ¿ËÒ½ÁÆÖÐÐÄ£¬µ¼ÖÂÒ½ÔºµÄITϵͳÍ߽⣬ÅÌËã»úÍøÂçÒѱ»½ûÓã¬ËùÓеÄITϵͳ´¦ÓÚÍ£»ú״̬£¬Á½¼ÒÒ½Ôº¶¼²»µÃ²»×ªÒÆ»¼Õß»òÍÆ³ÙÔñÆÚÊÖÊõ£¬ ÒÔ¼°´Ë´Î¹¥»÷£¬µ¼Ö²¿·Ö»¼ÕߺÍÔ±¹¤Êý¾Ýй¶£¬ÆäÖÐһЩÊý¾ÝØÊºó±»ºÚ¿ÍÐû²¼µ½°µÍøÉÏ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMV4

AG¹«Ë¾ÔÆ







