¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.10.18-2021.10.24£©
2021-10-25
Ò»¡¢ Íþвͨ¸æ
Oracleȫϵ²úÆ·10ÔÂÖ÷Òª²¹¶¡¸üÐÂͨ¸æ£¨CVE-2021-22931¡¢CVE-2021-3711¡¢CVE-2021-22926£©
¡¾Ðû²¼Ê±¼ä¡¿2021-10-21 10:00:00 GMT
¡¾¸ÅÊö¡¿
2021Äê10ÔÂ20ÈÕ£¬AG¹«Ë¾¿Æ¼¼¼à²â·¢Ã÷Oracle¹Ù·½Ðû²¼ÁË10ÔÂÖ÷Òª²¹¶¡¸üÐÂͨ¸æCPU£¨Critical Patch Update£©£¬´Ë´Î¹²ÐÞ¸´ÁË419¸ö²î±ðˮƽµÄÎó²î£¬´Ë´ÎÇå¾²¸üÐÂÉæ¼°Oracle MySQL¡¢Oracle Weblogic Server¡¢Oracle Java SE¡¢Oracle FusionMiddleware¡¢Oracle Retail ApplicationsµÈ¶à¸ö³£ÓòúÆ·¡£OracleÇ¿ÁÒ½¨Òé¿Í»§¾¡¿ìÓ¦ÓÃÒªº¦²¹¶¡¸üÐÂÐÞ¸´³ÌÐò£¬¶ÔÎó²î¾ÙÐÐÐÞ¸´¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. ¹¥»÷ÕßʹÓà Discord »ù´¡ÉèÊ©¾ÙÐжñÒâ¹¥»÷
¡¾¸ÅÊö¡¿
Check Point Research (CPR) ·¢Ã÷ÁËÒ»Öֶ๦Ч¶ñÒâÈí¼þ£¬Äܹ»½ØÈ¡ÆÁÄ»½ØÍ¼¡¢ÏÂÔØºÍÖ´ÐÐÆäËûÎļþÒÔ¼°Ö´ÐмüÅ̼ͼ——ËùÓÐÕâЩ¶¼ÊÇͨ¹ýʹÓà Discord µÄ½¹µã¹¦Ð§¡£Discord »úеÈ˹¦Ð§Ç¿Ê¢¡¢ÓѺÃÇÒºÜÊǽÚԼʱ¼ä¡£È»¶ø£¬ÄÜÁ¦Ô½´óÔðÈÎÒ²Ô½´ó£¬DiscordµÄbot¿ò¼ÜºÜÈÝÒ×±»¶ñÒâʹÓá£Ñо¿Ö°Ô±·¢Ã÷£¬ÆäÖÐDiscord Bot API ÊÇÒ»¸ö¼òÆÓµÄ Python ʵÏÖ£¬Ëü¼ò»¯ÁËÐ޸IJ¢Ëõ¶ÌÁË¿ª·¢Àú³Ì£¬¿ÉÒÔÇáËɵؽ«»úеÈËÄð³ÉÒ»¸ö¼òÆÓµÄÔ¶³Ì»á¼ûľÂíÀ´ÇÔÊØÐÅÏ¢¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMXw
2. ¹¥»÷ÕßÕë¶ÔÃÀ¹ú¾üÊ·ÀÎñ»ú¹¹¾ÙÐÐOffice 365ÌØ¹¤¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öÃûΪDEV-0343µÄÍøÂç×éÖ¯¹¥»÷ÁËÃÀ¹úºÍÒÔÉ«ÁеĹú·ÀÊÖÒÕ¹«Ë¾¡¢²¨Ë¹ÍåµÄÈë¾³¿Ú°¶ÒÔ¼°ÓëÖж«ÓйصÄÈ«Çòº£ÉÏÔËÊ乫˾¡£¸ÃÍþв×éÖ¯µÄ¹¥»÷·½·¨Ö÷ÒªÊǽÓÊÜ΢ÈíOffice 365ÕË»§¡£¹¥»÷ÕßËÆºõÒ»Ö±ÔÚ´ÓÊÂÍøÂçÌØ¹¤Ô˶¯£¬Í¬Ê±¸Ã×éÖ¯ÓëÒÁÀÊÓÐÁªÏµ£¬²¢ÇÒÍøÂç¹¥»÷ÕßÕýÔÚ¶ÔOffice 365ÕË»§¾ÙÐдóÃæ»ýµÄÃÜÂëÅçÈ÷¹¥»÷¡£ËüÊÇÒ»ÖÖÕë¶ÔÔÚÏßÕË»§Ê¹Óôó×ÚÓû§ÃûºÍһϵÁвî±ðÃÜÂë¾ÙÐй¥»÷µÄÀú³Ì£¬¹¥»÷ÕßÏ£ÍûÕÒµ½×¼È·µÄÃÜÂë²¢»ñµÃ¶ÔÊÜÃÜÂë±£»¤ÕË»§µÄ»á¼ûȨÏÞ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMXy
3. ºÚ¿ÍʹÓÃcookieÇÔÈ¡¶ñÒâÈí¼þÐ®ÖÆYouTube´´×÷ÕßµÄÕÊ»§
¡¾¸ÅÊö¡¿
ºÚ¿ÍʹÓÃÐéαµÄÏàÖúʱ»ú£¨¼´É±¶¾Èí¼þ¡¢VPN¡¢ÒôÀÖ²¥·ÅÆ÷¡¢ÕÕÆ¬±à¼»òÍøÂçÓÎÏ·µÄÑÝʾ£©Ð®ÖÆÁË YouTube ´´×÷ÕߵįµµÀ£¬Ò»µ©Ð®ÖÆÁËÆµµÀ£¬¹¥»÷ÕßҪô½«Æä³öÊÛ¸ø³ö¼Û×î¸ßµÄÈË£¬ÒªÃ´½«ÆäÓÃÓÚ¼ÓÃÜÇ®±ÒÕ©ÆÍýÏë¡£Ñо¿Ö°Ô±·¢Ã÷£¬¶ñÒâÈí¼þÔÚÉϰ¶Ò³ÃæÎ±×°³ÉÈí¼þÏÂÔØ URL£¬Í¨¹ýµç×ÓÓʼþ»ò Google Drive É쵀 PDF »ò°üÀ¨ÍøÂç´¹ÂÚÁ´½ÓµÄ Google Îĵµ·¢ËÍ¡£²¢È·¶¨ÁËԼĪ 15,000 ¸öÑÝÔ±ÕÊ»§£¬ÆäÖд󲿷ÖÊÇΪ´ËÔ˶¯½¨ÉèµÄ£¬»¹ÊӲ쵽£¬¹¥»÷Õß½«Ä¿µÄÍÆÏò WhatsApp¡¢Telegram »ò Discord µÈÐÂÎÅÓ¦ÓóÌÐò£¬ÓÉÓڹȸèÄܹ»Í¨¹ý Gmail ×èÖ¹ÍøÂç´¹ÂÚÍýÏ룬ÔËÐÐð³äÈí¼þºó£¬½«Ö´ÐÐ cookie ÇÔÈ¡¶ñÒâÈí¼þ¡£¶ñÒâÈí¼þ´ÓÊÜѬȾµÄ»úеÇÔÈ¡ä¯ÀÀÆ÷ cookie ²¢½«Æä·¢Ë͵½ C2 ·þÎñÆ÷¡£Ò»µ©ÔÚÄ¿µÄϵͳÉϽ»¸¶£¬¶ñÒâÈí¼þ¾Í»á±»ÓÃÀ´ÇÔÈ¡ËûÃÇµÄÆ¾Ö¤ºÍä¯ÀÀÆ÷ cookie£¬´Ó¶øÔÊÐí¹¥»÷ÕßÔÚת´ï cookie ¹¥»÷ÖÐÐ®ÖÆÊܺ¦ÕßµÄÕÊ»§¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMXv
4. ¹¥»÷ÕßʹÓÃTelegram BotÇÔÈ¡PayPalÕË»§×ʽð
¡¾¸ÅÊö¡¿
еÄÑо¿·¢Ã÷£¬ÍøÂç·¸·¨·Ö×ÓÕýÔÚʹÓÃTelegram»úеÈËÇÔȡһ´ÎÐÔÃÜÂëtoken£¨OTP£©²¢Í¨¹ýÒøÐкÍÔÚÏßÖ§¸¶ÏµÍ³£¨°üÀ¨PayPal¡¢Apple PayºÍGoogle Pay£©Ú²ÆÈºÖÚ¡£²¢ÌåÏÖÍþвÐÐΪÕßÕýÔÚʹÓÃTelegram»úеÈËºÍÆµµÀÒÔ¼°Ò»ÏµÁÐÕ½ÂÔÀ´»ñÈ¡ÕÊ»§ÐÅÏ¢£¬°üÀ¨ÖµçÊܺ¦Õß¡¢Ã°³äÒøÐкÍÕýµ±·þÎñµÈ£¬Í¬Ê±Í¨¹ýÉç»á¹¤³Ì£¬ÍþвÐÐΪÕß»¹ÓÕÆÈËÃÇͨ¹ýÒÆ¶¯×°±¸ÏòËûÃÇÌṩOTP»òÆäËûÑéÖ¤Â룬ȻºóÆ×ÓÓÃÕâЩ´úÂëÀ´ÆÈ¡Óû§ÕË»§ÖеÄ×ʽð¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMXm
5. ºê³žÒ»ÖÜÄÚÔâÓö¶þ´ÎÊý¾Ýй¶
¡¾¸ÅÊö¡¿
¿Æ¼¼¾ÞÍ·ºê³žÔÚÒ»ÖÜÄÚÔâµ½Á½´ÎºÚ¿Í¹¥»÷£¬Í³Ò»¸öÍþвÕß (Desorden) ×î³õÈëÇÖÁËÆäÔÚÓ¡¶ÈµÄһЩ·þÎñÆ÷£¬ÏÖÔÚËüÉù³ÆÒ²ÈëÇÖÁĘ̈ÍåµÄһЩϵͳ¡£¸ÃÊÂÎñÊÇÔÚÍþвÐÐΪÕßÔÚÒ»¸öµØÏÂÍøÂç·¸·¨ÂÛ̳ÉÏÐû²¼ÏúÊÛÁè¼Ý60 GBÊý¾ÝµÄ¹ã¸æºóÅû¶µÄ¡£¹¥»÷ÕßÏÖÔÚÉù³ÆÒÑÓÚ10Ô 15ÈÕÈëÇÖÁ˺곞̨ÍåµÄ·þÎñÆ÷£¬²¢ÇÔÈ¡ÁËÄÚ²¿Êý¾Ý£¬°üÀ¨Ô±¹¤ºÍ²úÆ·ÐÅÏ¢¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMXi
6. ¹¥»÷ÕßÔÚ¶ñÒâÔ˶¯ÖÐʹÓôó×ÚÉÌÆ·RAT¹¥»÷°¢¸»º¹ºÍÓ¡¶È
¡¾¸ÅÊö¡¿
Cisco Talos×î½ü·¢Ã÷ÁËÒ»¸öÍþвÐÐΪÕߣ¬ËüʹÓÃÕþÖκÍÕþ¸®ÎªÖ÷ÌâµÄ¶ñÒâÓòÀ´Õë¶ÔÓ¡¶ÈºÍ°¢¸»º¹µÄʵÌå¡£ÕâЩ¹¥»÷ʹÓà dcRAT ºÍ QuasarRAT for Windows£¬Í¨¹ýʹÓÃCVE-2017-11882£¨Microsoft Office ÖеÄÄÚ´æËð»µÎó²î£©ºÍ AndroidRAT µÄ¶ñÒâÎĵµÀ´¹¥»÷ÒÆ¶¯×°±¸¡£¹¥»÷Õß»¹ÔÚ¹¥»÷µÄ³õʼÕì̽½×¶ÎʹÓÃ×Ô½ç˵Îļþö¾ÙÆ÷ºÍѬȾÆ÷£¬È»ºóͨ¹ý°²ÅÅÖÖÖÖÉÌÆ· RAT£¨ÀýÈç DcRAT ºÍ QuasarRAT£©¾ÙÐй¥»÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMXl
7. ºÚ¿ÍÀÄÓÃÆ»¹û¹«Ë¾ÆóÒµÓ¦ÓóÌÐò͵ȡ140ÍòÃÀÔªµÄ¼ÓÃÜÇ®±Ò
¡¾¸ÅÊö¡¿
ºÚ¿ÍʹÓÃÉ罻ýÌå¡¢Ô¼»áÓ¦ÓóÌÐò¡¢¼ÓÃÜÇ®±ÒºÍÀÄÓÃÆ»¹û¹«Ë¾ÆóÒµ¿ª·¢ÕßÍýÏ룬´ÓºÁÎÞ½äÐĵÄÊܺ¦ÕßÄÇÀï͵ȡÁËÖÁÉÙ140ÍòÃÀÔª¡£ÆäÖÐÃûΪCryptoRomڲƵÄʵÑéÏ൱ֱ½Ó£¬ÔÚͨ¹ýÉ罻ýÌå»òÏÖÓÐÊý¾ÝÓ¦ÓóÌÐò»ñµÃÊܺ¦ÕßµÄÐÅÍкó£¬Óû§±»ÓÞŪµ½Ò»¸ö¿´ÆðÀ´ÏñÆ»¹ûÓ¦ÓÃÊÐËÁµÄÍøÕ¾£¬È»ºó±»¼û¸æÏÂÔØÒ»¸öÒÆ¶¯×°±¸ÖÎÀí³ÌÐò£¬×°ÖÃÒ»¸öÐ޸İæµÄ¼ÓÃÜÇ®±ÒÉúÒâËù£¬ÓÕʹÆäͶ×Ê£¬È»ºóÆ×ßÏÖ½ð¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMWU
8. ¹¥»÷Õßð³äDoT¾ÙÐÐÁËΪÆÚÁ½ÌìµÄ´¹ÂÚթƹ¥»÷
¡¾¸ÅÊö¡¿
ÍþвÕßÔÚΪÆÚÁ½ÌìµÄÍøÂç´¹ÂÚ¹¥»÷Ô˶¯ÖÐð³äÃÀ¹ú½»Í¨²¿£¨USDOT£©£¬ËûÃÇͨ¹ýʹÓöàÖÖÕ½ÂÔ£¬ÎªÁËʹ¹¥»÷Ô˶¯¿´ÆðÀ´¸üÕýµ±£¬ËûÃÇ»¹½¨ÉèÁËÐéαµÄÁª°îÍøÕ¾µÄÓòÃû£¬À´ÌÓ±ÜÇå¾²¼ì²â¡£Ñо¿Ö°Ô±¹²·¢Ã÷ÁË41·â´¹ÂÚÓʼþ£¬ÕâЩÓʼþ¶¼ÒÔ¹ú»á×î½üͨ¹ýµÄ1ÍòÒÚÃÀÔª»ù´¡ÉèÊ©¼Æ»®ÖеÄÏîĿͶ±êΪÓÕ¶ü¾ÙÐÐÕ©Æ¡£´Ë´Î¹¥»÷Ô˶¯Ö÷ÒªÒÔ¹¤³Ì¡¢ÄÜÔ´ºÍÐÞ½¨µÈÐÐÒµµÄ¹«Ë¾Îª¹¥»÷Ä¿µÄ£¬ÕâЩ¹«Ë¾¿ÉÄÜ»áÓëÃÀ¹ú½»Í¨²¿ÏàÖú£¬²¢ÏòDZÔÚµÄÊܺ¦Õß·¢ËÍթƵç×ÓÓʼþ£¬Ò»µ©½øÈëÕâ¸öð³äµÄÃÀ¹ú½»Í¨²¿ÍøÕ¾£¬Êܺ¦Õ߾ͻᱻԼÇëµã»÷Ò»¸ö "µã»÷ÕâÀïͶ±ê "°´Å¥£¬»¹»á·ºÆðÒ»¸ö´øÓÐ΢Èí±ê¼ÇºÍ "ÓÃÄãµÄµç×ÓÓʼþÌṩÉ̵Ǽ "ָʾµÄÆ¾Ö¤ÍøÂç±í¸ñ¡£µÚÒ»´ÎʵÑéÊäÈëÆ¾Ö¤Ê±»áÓöµ½ReCAPTCHAÑéÖ¤£¬Õýµ±ÍøÕ¾Ò»Ñùƽ³£»á½«Æä×÷ÎªÍøÕ¾µÄÇå¾²×é¼þ£¬È»¶ø£¬¹¥»÷ÕßÔÚÕâʱ¾ÍÒѾ»ñÈ¡ÁËÆ¾Ö¤£¬ÈôÊÇÊܺ¦ÕßµÚ¶þ´ÎʵÑéÊäÈëÖ¤Ê飬¾Í»á·ºÆðÒ»¸ö¹ýʧÐÅÏ¢£¬È»ºóËûÃǻᱻָµ¼µ½ÕæÕýµÄÃÀ¹ú½»Í¨²¿ÍøÕ¾£¬´¹ÂÚÕß¾³£½«ÕâÒ»²½×÷Ϊ×îºóÒ»²½À´¾ÙÐÐÖ´ÐС£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMX9
9. ºÚ¿ÍÇÔÈ¡Á˰¢¸ù͢ȫÌåÉú³ÝµÄÕþ¸®IDÊý¾Ý¿â
¡¾¸ÅÊö¡¿
Ò»ÃûºÚ¿ÍÈëÇÖÁ˰¢¸ùÍ¢Õþ¸®µÄITÍøÂ磬²¢ÇÔÈ¡Á˸ùúËùÓÐÉú³ÝµÄÉí·ÝÖ¤ÏêϸÐÅÏ¢£¬ÕâЩÊý¾ÝÏÖÔÚÕýÔÚ˽ÈËȦ×ÓÖгöÊÛ¡£ÉϸöÔ±¬·¢µÄºÚ¿Í¹¥»÷Ä¿µÄÊÇ RENAPER£¬Ëü´ú±í Registro Nacional de las Personas£¬·ÒëΪ National Registry of Persons¡£¸Ã»ú¹¹Êǰ¢¸ùÍ¢ÄÚÕþ²¿µÄÒ»¸öÖ÷Òª×é³É²¿·Ö£¬ÆäʹÃüÊÇÏòËùÓй«Ãñ·¢·Å¹úÃñÉí·ÝÖ¤£¬²¢½«ÕâЩÊý¾ÝÒÔÊý×ÖÃûÌô洢ΪÆäËûÕþ¸®»ú¹¹¿É»á¼ûµÄÊý¾Ý¿â£¬×÷Ϊ´ó´ó¶¼Õþ¸®ÅÌÎʵÄÖ§ÖùÓÃÓÚ¹«ÃñµÄСÎÒ˽¼ÒÐÅÏ¢¡£Æ¾Ö¤ºÚ¿ÍÔÚÏßÌṩµÄÑù±¾£¬ËûÃÇÏÖÔÚ¿ÉÒÔ»á¼ûµÄÐÅÏ¢°üÀ¨È«Ãû¡¢¼Òͥסַ¡¢³öÉúÈÕÆÚ¡¢ÐÔ±ðÐÅÏ¢¡¢Éí·Ý֤ǩ·¢ºÍµ½ÆÚÈÕÆÚ¡¢À͹¤Ê¶±ðÂë¡¢TrámiteºÅÂë¡¢¹«ÃñºÅÂëºÍÕþ¸®ÕÕÆ¬Éí·ÝÖ¤¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMX8
10. TeamTNTÔÚDocker HubÉϰ²ÅŶñÒâDocker¾µÏñ
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±×î½ü·¢Ã÷ÁËÒ»ÏîÔ˶¯£¬ÆäÖÐ TeamTNT Íþв¼ÓÈëÕß°²ÅÅÁË´øÓÐǶÈëʽ¾ç±¾µÄ¶ñÒâÈÝÆ÷Ó³Ïñ£¨ÍйÜÔÚ Docker Hub ÉÏ£©£¬ÒÔÏÂÔØ Zgrab ɨÃèÆ÷ ºÍ massscanner£¬»®·ÖÓÃÓÚºá·ùץȡºÍ¶Ë¿ÚɨÃèµÄÉøÍ¸²âÊÔ¹¤¾ß¡£Ê¹ÓöñÒâ Docker ¾µÏñÖеÄɨÃ蹤¾ß£¬ÍþвÐÐΪÕßʵÑéɨÃèÊܺ¦Õß×ÓÍøÖеĸü¶àÄ¿µÄ²¢Ö´ÐнøÒ»²½µÄ¶ñÒâÔ˶¯¡£ÆäÖз¸·¨ÍÅ»ï¼ÌÐø½« Docker Hub¡¢GitHub ºÍÆäËû°üÀ¨°üÀ¨¶ñÒâ¾ç±¾ºÍ¹¤¾ßµÄÈÝÆ÷Ó³ÏñºÍÈí¼þ×é¼þµÄ¹²Ïí´æ´¢¿â×÷ΪĿµÄ¡£ËûÃÇͨ³£Ö¼ÔÚÈö²¥ coinminer ¶ñÒâÈí¼þ£¬Ð®ÖÆÊܺ¦ÕßµÄÅÌËã»ú×ÊÔ´À´ÍÚ¾ò¼ÓÃÜÇ®±Ò¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMX5

AG¹«Ë¾ÔÆ







