¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.12.06-2021.12.12£©
2021-12-13
Ò»¡¢ Íþвͨ¸æ
Apache Log4j2 Ô¶³Ì´úÂëÖ´ÐÐÎó²î´¦Öóͷ£ÊÖ²á
¡¾Ðû²¼Ê±¼ä¡¿2021-12-10 14:00:00 GMT
¡¾¸ÅÊö¡¿
12 Ô 9 ÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½ÍøÉÏÅû¶Apache Log4j2Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¬ÓÉÓÚ Apache Log4j2 ijЩ¹¦Ð§±£´æµÝ¹éÆÊÎö¹¦Ð§£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ý·¢ËÍÌØÊâ½á¹¹µÄÊý¾ÝÇëÇó°ü£¬¿ÉÔÚÄ¿µÄ·þÎñÆ÷ÉÏÖ´ÐÐí§Òâ´úÂë¡£Îó²î PoC ÒÑÔÚÍøÉϹûÕæ£¬Ä¬ÈÏÉèÖü´¿É¾ÙÐÐʹÓ㬸ÃÎó²îÓ°Ïì¹æÄ£¼«¹ã£¬½¨ÒéÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐÐÅŲéÓë·À»¤¡£Apache Log4j2ÊÇÒ»¿î¿ªÔ´µÄJavaÈÕÖ¾¿ò¼Ü£¬±»ÆÕ±éµØÓ¦ÓÃÔÚÖÐÐļþ¡¢¿ª·¢¿ò¼ÜÓëWebÓ¦ÓÃÖУ¬ÓÃÀ´¼Í¼ÈÕÖ¾ÐÅÏ¢¡£AG¹«Ë¾¿Æ¼¼ÒÑÀֳɸ´ÏÖ´ËÎó²î¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
ºÚ¿ÍʹÓÿªÔ´´úÂëÆ½Ì¨ SonarQube Îó²îй¶¶à¼Òµ¥Î»Ô´Âë
¡¾Ðû²¼Ê±¼ä¡¿2021-12-10 14:00:00 GMT
¡¾¸ÅÊö¡¿
2021 Äê 10 ÔÂÒÔÀ´£¬AG¹«Ë¾¿Æ¼¼CERT¼à²â·¢Ã÷¾³ÍâºÚ¿Í×éÖ¯AgainstTheWest£¨¼ò³Æ“ATW”£©Õë¶Ô̻¶ÔÚ¹«ÍøÉϵÄSonarQubeƽ̨¾ÙÐй¥»÷£¬ÇÔÈ¡ÁËÎÒ¹ú¶à¼ÒÆóÒµµ¥Î»ÐÅϢϵͳԴ´úÂ룬²¢ÔÚÍâÑóºÚ¿ÍÂÛ̳RaidForumsÉϾÙÐв»·¨ÊÛÂô¡£10ÔÂ14ÈÕ£¬ATW ÔÚ RaidForumsÉÏ·¢Ìû³ÆÒªÐ¹Â¶ÎÒ¹úÄ³ÒøÐÐϵͳԴ´úÂ룬²¢ÔÚÒÔºóÒ»¶Îʱ¼äÄÚÒ»Á¬·¢Ìûй¶¡¢ÊÛÂôÎÒ¹ú¶à¼ÒÖ÷Òªµ¥Î»Ô´´úÂëÊý¾ÝÐÅÏ¢¡£¾ÑÐÅÐÆÊÎöÖª£¬ATW ºÚ¿Í×éÖ¯¹¥»÷µÄµ¥Î»Éæ¼°½ðÈÚ¡¢ÔËÓªÉÌ¡¢½»Í¨¡¢»¥ÁªÍø¡¢½ÌÓý¡¢Õþ¸®µÈÐÐÒµ¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. ºÚ¿ÍʹÓÃйڱäÒ첡¶¾Ïò±±ÃÀ´óѧÌᳫ¹¥»÷
¡¾¸ÅÊö¡¿
Ëæ×ÅйڱäÒ첡ÖêOmicronµÄ·ºÆð£¬Ñо¿Ö°Ô±ÒѾÊӲ쵽ÁËʹÓÃOmicron²¡¶¾×÷ΪÓÕ¶üµÄÍøÂç´¹ÂÚÔ˶¯¡£¹¥»÷Õßͨ¹ýαÔìµÄ´óѧµÇ¼ÃÅ»§£¬ÇÔÈ¡Óû§µÄ Office 365 ƾ֤¡£´Ë´ÎÔ˶¯µÄÖ÷ҪĿµÄΪ±±ÃÀ´óѧ¡£²¢ÇÒÔÚijЩÔ˶¯ÖУ¬¹¥»÷Õß»¹½¨ÉèÁËÓÕÆDUO MFAÒ³ÃæµÄµÇÂ¼Ò³Ãæ£¬ÊÔͼÇÔÈ¡¶àÒòËØÉí·ÝÑéÖ¤(MFA)ƾ֤¡£Êܺ¦ÕßÔÚαÔìµÄµÇÂ¼Ò³ÃæÉÏÊäÈëÆ¾Ö¤ºó£¬»á±»ÒªÇóÊäÈëÊÖ»ú¶ÌÐÅÊÕµ½µÄÑéÖ¤Â룬¹¥»÷Õß¿ÉÒÔʹÓÃÑéÖ¤ÂëÀ´½Ó»á¼Æ»§¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN7K
2. ¹¥»÷ÕßʹÓÃoom_reaper¹¥»÷QNAP NAS ×°±¸
¡¾¸ÅÊö¡¿
̨Í幩ӦÉÌQNAPÖÒÑÔ¿Í»§£¬¹¥»÷Õß½«ËûÃǵÄNAS×°±¸Óë¼ÓÃÜÇ®±Ò¿óÊÂÇéΪĿµÄ¡£ÔÚÆÆËð×°±¸ºó£¬¿ó¹¤½«½¨ÉèÒ»¸öÃûΪ [oom_reaper] µÄÐÂÀú³Ì£¬ÔÊÐí¹¥»÷ÕßÍÚ¾ò±ÈÌØ±Ò¡£Ò»µ© NAS ±»Ñ¬È¾£¬CPUʹÓÃÂÊ»á±äµÃÒì³£¸ß£¬ÆäÖÐÃûΪ“[oom_reaper]”µÄÀú³Ì¿ÉÄÜ»áÕ¼ÓÃ×ÜCPUʹÓÃÂʵÄ50%×óÓÒ¡£Õâ¸öÀú³ÌÄ£ÄâÁËÒ»¸öÄÚºËÀú³Ì£¬µ«ËüµÄPIDͨ³£´óÓÚ1000¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN7i
3. ¶«ÑǺڿÍ×éÖ¯BlackTechÕë¶Ô½ðÈÚ¡¢½ÌÓýµÈÐÐÒµÕö¿ª¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±¼à²âµ½¶«ÑǺڿÍ×éÖ¯BlackTech½üÆÚ¹¥»÷Ô˶¯ÆµÈÔ£¬¹¥»÷Ä¿µÄ°üÀ¨ÖйúµØÇøµÄ»¥ÁªÍø½ðÈÚ¡¢»¥ÁªÍø½ÌÓýµÈÐÐÒµ¡£Æ¾Ö¤½üÆÚ²¶»ñµÄBlackTech×é֯ʹÓõĺóÃÅľÂí£¬Ñо¿Ö°Ô±»¹·¢Ã÷¸Ã×éÖ¯µÄÎäÆ÷¿âÔÚÒ»Á¬¸»ºñºÍת±ä£¬ÔÚWindowsƽ̨ÉÏʹÓÃÓÉGh0stÔ´ÂëÐ޸ĶøÀ´µÄºóÃÅľÂí£¬ÔÚLinuxƽ̨ÉÏʹÓÃBifroseºóÃÅľÂí£¬´ó¶¼É±¶¾ÒýÇæ½ÏÄѲéɱ¡£ÁíÍâÔÚLinuxƽ̨»¹Ê¹ÓÃPython±àд´ò°üµÄºóÃÅľÂí¡£¶øÔÚIT×ʲú·½Ã棬BlackTech×éÖ¯ÒÀ¾É±£´æÁË֮ǰµÄÌØµã£¬¼´¾³£×âÓÃÖйú¡¢ÈÕ±¾µÈµØµÄ·þÎñÆ÷×÷ΪC&C·þÎñÆ÷£¬ÔÚ½üÆÚ¹¥»÷Ô˶¯ÖÐÒ²¸´ÓÃÁ˲¿·ÖÔÚ¹ýÍù¹¥»÷Ô˶¯ÖÐʹÓõÄ×ʲú¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN7J
4. NobeliumʹÓÃCeeloader×Ô½ç˵¶ñÒâÈí¼þ¶ÔÈ«Çò×éÖ¯Ìᳫ¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷Óë¶íÂÞ˹ÓÐ¹ØµÄ Nobelium APT ×éÖ¯ÕýÔÚʹÓÃÒ»ÖÖÃûΪCeeloaderµÄÐÂÐÍ×Ô½ç˵¶ñÒâÈí¼þ¹¥»÷È«Çò×éÖ¯¡£Nobelium ÍøÂçÌØ¹¤ÕýÔÚʹÓÃÒ»ÖÖеÄ×Ô½ç˵ÏÂÔØÆ÷£¬¸ÃÏÂÔØÆ÷±»Ñо¿Ö°Ô±¸ú×ÙΪ CEELOADER¡£APT¾ÙÐеĶà´Î¹©Ó¦Á´¹¥»÷£¬¹¥»÷Õ߯ÆËðÁË·þÎñÌṩÉÌ£¬²¢Ê¹ÓÃÊôÓÚ±»ºÚÌṩÉ̵ÄÌØÈ¨»á¼ûºÍƾ֤À´Ãé×¼ËûÃǵĿͻ§¡£²¢ÇÒÖÁÉÙÔÚÒ»¸öʵÀýÖз¢Ã÷£¬¹¥»÷Õßʶ±ð²¢ÆÆËðÁËÒ»¸öÍâµØVPNÕÊ»§£¬²¢Ê¹ÓøÃVPNÕÊ»§¾ÙÐÐÕì̽²¢½øÒ»²½»á¼ûÊܺ¦ CSP ÇéÐÎÖеÄÄÚ²¿×ÊÔ´£¬×îÖÕµ¼ÖÂÄÚ²¿ÓòÕÊ»§Ôâµ½ÆÆËð¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN76
5. ¹¥»÷ÕßʹÓÃNginRAT ¶ñÒâÈí¼þ¹¥»÷Òþ²ØÔÚ Nginx ·þÎñÆ÷Éϵĵç×ÓÊÐËÁ
¡¾¸ÅÊö¡¿
Çå¾²¹«Ë¾µÄÑо¿Ö°Ô±×î½ü·¢Ã÷ÁËÒ»¸öÐ嵀 Linux Ô¶³Ì»á¼ûľÂí (RAT)£¬¸ú×ÙΪCronRAT£¬ËüÓÚ2ÔÂ31ÈÕÒþ²ØÔÚLinuxʹÃüµ÷Àíϵͳ (cron) ÖС£CronRAT ÓÃÓÚÕë¶ÔÔÚÏßÊÐËÁÍøÂçÊÐËÁµÄMagecart¹¥»÷£¬²¢Ê¹¹¥»÷ÕßÄܹ»Í¨¹ýÔÚLinux·þÎñÆ÷Éϰ²ÅÅÔÚÏßÖ§¸¶Æ²È¡Æ÷À´ÇÔÊØÐÅÓÿ¨Êý¾Ý¡£ÔÚÊӲ챱ÃÀºÍÅ·ÖÞµÄ CronRAT ѬȾʱ£¬Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»ÖÖÃûΪ NginRAT µÄжñÒâÈí¼þ£¬Ëü¿ÉÒÔÈÆ¹ýÇå¾²½â¾ö¼Æ»®Òþ²ØÔÚNginx·þÎñÆ÷ÉÏ¡£Óë CronRAT Ò»Ñù£¬NginRAT Ò²×÷Ϊ“·þÎñÆ÷¶Ë Magecart”ÊÂÇ飬Ëü½«×ÔÉí×¢Èëµ½ Nginx Àú³ÌÖС£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN6E
6. ¹¥»÷ÕßʹÓÃKMSPico¶ñÒâÈí¼þÇÔÈ¡WindowsÓû§µÄ¼ÓÃÜÇ®±ÒÇ®°ü
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷Ï£ÍûÔÚ²»Ê¹ÓÃÊý×ÖÔÊÐíÖ¤»ò²úÆ·ÃÜÔ¿µÄÇéÐÎϼ¤»îWindowsµÄÓû§Õý³ÉΪÊÜѬȾµÄ×°ÖóÌÐòµÄÄ¿µÄ£¬ÒÔ°²ÅÅÖ¼ÔÚÂÓ¶á¼ÓÃÜÇ®±ÒÇ®°üÖÐµÄÆ¾Ö¤ºÍÆäËûÐÅÏ¢µÄ¶ñÒâÈí¼þ¡£¸Ã¶ñÒâÈí¼þ±»³ÆÎª“ CryptBot ”£¬ÊÇÒ»ÖÖÐÅÏ¢ÇÔÈ¡³ÌÐò£¬Äܹ»»ñÈ¡ä¯ÀÀÆ÷¡¢¼ÓÃÜÇ®±ÒÇ®°ü¡¢ä¯ÀÀÆ÷ cookie¡¢ÐÅÓÿ¨µÄƾ֤£¬²¢´ÓÊÜѬȾµÄϵͳÖв¶»ñÆÁÄ»½ØÍ¼¡£Í¨¹ýÆÆ½âÈí¼þ°²ÅÅ£¬×îÐµĹ¥»÷Éæ¼°Î±×°³É KMSPico µÄ¶ñÒâÈí¼þ¡£¶øKMSPico ÊÇÒ»Öַǹٷ½¹¤¾ß£¬ÓÃÓÚÔÚûÓÐÏÖʵӵÓÐÔÊÐíÖ¤ÃÜÔ¿µÄÇéÐÎϲ»·¨¼¤»îµÁ°æÈí¼þ£¨Èç Microsoft Windows ºÍ Office Ì×¼þ£©µÄËùÓй¦Ð§¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN6R
7. Apache KafkaÔÆ¼¯ÈºÌ»Â¶ÖÁ¹«Ë¾Ãô¸ÐÊý¾Ý
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±ÌåÏÖ£¬KafdropÊÇApache KafkaµÄÖÎÀí½Ó¿Ú£¬Apache Kafka ÊÇÒ»¸ö¿ªÔ´µÄÔÆÔÉúƽ̨£¬ÓÃÓÚÍøÂç¡¢ÆÊÎö¡¢´æ´¢ºÍÖÎÀíÊý¾ÝÁ÷¡£µ«ÓÉÓÚKafdropʵÀýÉèÖùýʧ£¬Ò»Ð©ÌìÏÂÉÏ×î´óµÄ¹«Ë¾ÒѾ̻¶ÁË´ó×ÚÀ´×ÔÔÆµÄÃô¸ÐÐÅÏ¢¡£Ëü×Ô¶¯ÅþÁ¬ºÍÓ³ÉäÏÖÓÐµÄ Kafka ¼¯Èº£¬ÔÊÐíÓû§ÖÎÀíÖ÷Ì⽨ÉèºÍɾ³ý£¬ÒÔ¼°“Ïàʶ¼¯ÈºµÄÍØÆËºÍ½á¹¹£¬ÉîÈëÏàʶÖ÷»ú¡¢Ö÷Ìâ¡¢·ÖÇøºÍÏûºÄÕß¡£Ëü»¹ÔÊÐíÄú´ÓËùÓÐÖ÷ÌâºÍ·ÖÇøÖвÉÑùºÍÏÂÔØÊµÊ±Êý¾Ý£¬³äµ±Õýµ±µÄKafka ÏûºÄÕß¡£²¢ÇÒ¼¯ÈºÌ»Â¶Á˿ͻ§Êý¾Ý¡¢ÉúÒâ¡¢Ò½ÁƼͼºÍÄÚ²¿Ï½µµÍ÷Á¿£¬»¹Ì»Â¶ÁËʵʱÁ÷Á¿£¬Ð¹Â¶ÉñÃØ¡¢Éí·ÝÑéÖ¤ÁîÅÆºÍÆäËû»á¼ûÏêϸÐÅÏ¢£¬ÔÊÐíºÚ¿ÍÉøÍ¸µ½¹«Ë¾ÔÚ AWS¡¢IBM¡¢Oracle ºÍÆäËû¹«Ë¾ÉϵÄÔÆÔ˶¯¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN79
8. ¹¥»÷ÕßʹÓÃÔ¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷ConfluenceºÍGitLab·þÎñÆ÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷Ò»¸öÀÕË÷Èí¼þ×é֯ʹÓÃ×î½üÅû¶µÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨ CVE-2021-26084 ºÍ CVE-2021-22205 £©À´»á¼ûδÐÞ²¹µÄ ConfluenceºÍ GitLab·þÎñÆ÷£¬¼ÓÃÜËûÃǵÄÎļþ£¬È»ºóÒªÇó·þÎñÆ÷ËùÓÐÕßÖ§¸¶Êê½ðÒÔ»Ö¸´ËûÃǵÄÊý¾Ý¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN7y
9. ÍøÂçºÚ¿ÍÕýʹÓÃÐéα¹ã¸æÀ´Èö²¥¶ñÒâ³ÌÐò
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷ÁËһϵÁжñÒâ¹ã¸æÔ˶¯£¬Ê¹ÓÃÊ¢ÐÐÓ¦ÓúÍÓÎÏ·µÄÐéαװÖóÌÐò×÷ΪÓÕ¶ü£¬ÓÕʹÓû§ÏÂÔØÐµĺóÃųÌÐòºÍδ¼Í¼µÄ¶ñÒâGoogle ChromeÀ©Õ¹³ÌÐò¡£×¨¼ÒÊӲ쵽 2019 Äêµ×ºÍ 2020 ÄêÍ·µÄ¼äЪÐÔÔ˶¯¡£¸Ã×éÖ¯ÓÚ 2021 Äê 4 ÔÂÖØÐ·ºÆð£¬¶ñÒâ¹ã¸æÔ˶¯Õë¶Ô¼ÓÄôó¡¢ÃÀ¹ú¡¢°Ä´óÀûÑÇ¡¢Òâ´óÀû¡¢Î÷°àÑÀºÍŲÍþ¡£ Ñо¿Ö°Ô±½«ÕâЩÔ˶¯¹éÒòÓÚÒ»¸ö±»×·×ÙΪ“magnat”µÄδ֪¹¥»÷Õß¡£×¨¼Ò×¢ÖØµ½£¬¾Ý±¨µÀ¸Ã×éÖ¯ÕýÔÚ¸üжñÒâÈí¼þϵÁС£MagnatExtension αװ³ÉGoogleµÄÇå¾²ä¯ÀÀ£¬ÔÊÐí¹¥»÷ÕßÇÔÈ¡±íµ¥Êý¾Ý¡¢ÍøÂç cookie²¢ÔÚÊܺ¦ÕßµÄϵͳÉÏÖ´ÐÐí§Òâ JavaScript ´úÂë¡£À©Õ¹Ê¹ÓõÄC2µØµãÊÇÓ²±àÂëµÄ£¬Ëü¿ÉÒÔÓÉÄ¿½ñµÄC2ʹÓø½¼ÓC2ÓòµÄÁбí¾ÙÐиüС£¹¥»÷Õß»¹ÎªC2ʵÑéÁËÒ»ÖÖ±¸·Ý»úÖÆ£¬ÔÊÐí´Ó Twitter ËÑË÷“#aquamamba2019”»ò“#ololo2019”µÈÖ÷Ìâ±êÇ©ÖлñÈ¡Ð嵀 C2 µØµã¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN6T
10. ¹¥»÷ÕßʹÓÃеÄXS-LeaksÎó²î¹¥»÷ Web ä¯ÀÀÆ÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷ÁË 14 ÖÖÐÂÐÍ¿çÕ¾µãÊý¾Ýй¶¹¥»÷£¬¹¥»÷ÁËÐí¶àÏÖ´úÍøÂçä¯ÀÀÆ÷£¬°üÀ¨ Tor ä¯ÀÀÆ÷¡¢Mozilla Firefox¡¢Google Chrome¡¢Microsoft Edge¡¢Apple Safari ºÍ Opera µÈ¡£×¨¼Ò½«ÕâЩä¯ÀÀÆ÷Îó²îͳ³ÆÎª“XS-Leaks”£¬Ê¹¶ñÒâÍøÕ¾Äܹ»ÔÚ»á¼ûÕßÔÚÄ¿µÄ²»ÖªÇéµÄÇéÐÎÏÂÔÚºǫ́ÓëÆäËûÍøÕ¾½»»¥Ê±´Ó»á¼ûÕßÄÇÀïÍøÂçСÎÒ˽¼ÒÊý¾Ý¡£¹¥»÷ÕßʹÓÃXS-LeaksÈÆ¹ýÁËËùνµÄͬԴսÂÔ£¬¶øÍ¬Ô´Õ½ÂÔµÄÄ¿µÄÊDZÜÃâÐÅÏ¢´ÓÊÜÐÅÍеÄÍøÕ¾±»µÁ¡£ÔÚXS-Leaks µÄÇéÐÎÏ£¬¹¥»÷ÕßÈÔÈ»¿ÉÒÔʶ±ðÍøÕ¾µÄ¸öÌåСϸ½Ú¡£ÈôÊÇÕâЩϸ½ÚÓëСÎÒ˽¼ÒÊý¾ÝÏà¹ØÁª£¬ÕâЩÊý¾Ý¿ÉÄÜ»áй¶¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN6U

AG¹«Ë¾ÔÆ







