¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.12.27-2022.01.02£©
2022-01-04
Ò»¡¢ ÈÈÃÅ×ÊѶ
1. ¹¥»÷ÕßÕë¶Ô HTTP/2 ÐÒéÌᳫHTTP Desync¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±ÏÈÈÝÁ˹¥»÷ÕßÊÇʹÓÃÎó²îÌᳫHTTP Desync¹¥»÷µÄ£¬Ä¿µÄ¶¼ÊÇһЩ×ÅÃûÍøÕ¾£¬ÕâЩÎó²îͨ¹ýÐ®ÖÆ¿Í»§¶Ë¡¢Ä¾Âí»¯»º´æ¡¢ÉÐÓÐÇÔȡƾ֤À´Ìᳫ¹¥»÷¡£²¢ÌåÏÖͨ¹ýÖØ¶¨Ïò JavaScript °üÀ¨£¬ËûÃÇ¿ÉÒÔÖ´ÐжñÒâ JavaScript À´ÆÆËð Netflix ÕÊ»§£¬²¢ÇÔÈ¡ÃÜÂëºÍÐÅÓÿ¨ºÅ¡£Í¨¹ýÑ»·ÔËÐÐÕâÖÖ¹¥»÷£¬¿ÉÒÔÔÚûÓÐÓû§½»»¥µÄÇéÐÎÏÂÖð½¥¹¥»÷ÍøÕ¾µÄËùÓлîÔ¾Óû§£¬ÕâÖÖÑÏÖØË®Æ½ÊÇÇëÇó×ß˽µÄµä·¶ÌåÏÖ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNaj
2. ¹¥»÷ÕßʹÓÃTelegram ÇÔÈ¡¼ÓÃÜÇ®°üƾ֤
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷£¬¹¥»÷ÕßʹÓà Telegram ¾ä±ú“Smokes Night”À´Èö²¥¶ñÒâµÄ Echelon ÐÅÏ¢ÇÔÈ¡³ÌÐò£¬¸Ã³ÌÐòÇÔÈ¡¼ÓÃÜÇ®±ÒºÍÆäËûÓû§ÕÊ»§µÄƾ֤¡£²¢ÌåÏÖ ÔÚ¸ÃÔ˶¯ÖÐʹÓõĶñÒâÈí¼þÖ¼ÔÚ´Ó¶à¸öÐÂÎÅת´ïºÍÎļþ¹²ÏíÆ½Ì¨ÇÔȡƾ֤£¬°üÀ¨ Discord¡¢Edge¡¢FileZilla¡¢OpenVPN¡¢Outlook ÉõÖÁ Telegram ×Ô¼º£¬ÒÔ¼°Ðí¶à¼ÓÃÜÇ®±ÒÇ®°ü£¬°üÀ¨ AtomicWallet¡¢BitcoinCore¡¢ByteCoin ¡¢³ö°£¼°¼Ç¡¢Jaxx ºÍÃÅÂÞ±Ò¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNa9
3. ºÚ¿ÍÈÆ¹ý×î½üÐÞ²¹µÄMS Office BugÀ´ÌṩFormbook¶ñÒâÈí¼þ
¡¾¸ÅÊö¡¿
Çå¾²¹«Ë¾µÄר¼Ò·¢Ã÷ÁËÒ»ÖÖеĽâ¾öÒªÁìÎó²î£¬ºÚ¿Íͨ¹ý¸ÃÎó²îʹÓÃ×î½üÐÞ²¹µÄ Microsoft Office Îó²î£¬¶øÎÞÐèʹÓúêÀ´×ª´ï Formbook ¶ñÒâÈí¼þ¡£¸ÃÎó²îÔÊÐí¹¥»÷ÕßÖ´Ðжà¸öí§Òâ´úÂëºÍÏÂÁî¡£²¢ÌåÏÖÔÚ Word ÎĵµÖУ¬¸ÃÎó²îʹÓÃÒ»ÖÖ»úÖÆÏÂÔØ¼ÓÔØÁË PowerShell µÄ Microsoft Îļþ¹ñ (CAB) RAR ´æµµ£¬È»ºóËûÃÇʹÓÃËüÏÂÔØ¶ñÒâ¸ºÔØ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNa8
4. ·¨¹ú Inetum ¼¯ÍÅÔâµ½ÀÕË÷Èí¼þ¹¥»÷
¡¾¸ÅÊö¡¿
¾Ý±¨µÀ£¬×ܲ¿Î»ÓÚ·¨¹úµÄ IT ·þÎñÌṩÉÌ Inetum Group ÓÚ 2021 Äê 12 Ô 19 ÈÕÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬ÔÚÒ»¶¨Ë®Æ½ÉÏÈÅÂÒÁËÆä²¿·ÖÒªº¦ÓªÒµ£¬²¢¸ø²¿·Ö¿Í»§´øÀ´ÁËδ±ã¡£¾³õ³ÌÐò²éÏÔÊ¾Éæ¼° BlackCat ÀÕË÷Èí¼þ£¬Ò²³ÆÎª Noberus ºÍ Alphv¡£Í¬Ê±ÍøÂçÇå¾²Ñо¿Ö°Ô±ÌåÏÖ£¬¹¥»÷ÕßÒÔÓà RUST ±à³ÌÓïÑÔ±àдµÄ BlackCat ÒÔ Vmware ¼ÓÔØµÄÐéÄâ»úºÍÖÎÀí³ÌÐòΪĿµÄ£¬¿ÉÒÔÁ¬Ã¦Èö²¥µ½ÆäËûÔÚ Windows ºÍ Linux ÉÏÔËÐеÄÊÂÇéÕ¾ºÍÍøÂç¡£ALPHV ¿ÉÒÔ½ÓÄÉË«ÖØÀÕË÷Õ½ÂÔ£¬Í¨¹ýÏò¿Í»§¡¢ÏàÖúͬ°éºÍÔ±¹¤Í¸Â¶¹¥»÷ϸ½ÚºÍЧ¹ûÀ´ÍþвÆäËðº¦ÉÌÒµ¿Õ¼äÐÎÏóµÄÊܺ¦Õß¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNap
5. ¹¥»÷ÕßʹÓÃPseudoManuscryptÌØ¹¤Èí¼þÕë¶ÔÊýǧ¼ÆµÄ¹¤ÒµÏµÍ³Ìᳫ¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±×·×ÙÁËеÄÌØ¹¤Èí¼þ——±»³ÆÎª“PseudoManuscrypt”£¬ÓÉÓÚËüÀàËÆÓÚLazarus¸ß¼¶Ò»Á¬Íþв(APT)×éÖ¯µÄ“Manuscrypt”¶ñÒâÈí¼þ——½ö½ñÄêÒ»Äê¾ÍѬȾÁË195¸ö¹ú¼Ò/µØÇøµÄ35,000¶ą̀ÅÌËã»ú¡£Manuscrypt£¬ÓÖÃûNukeSped£¬ÊÇһϵÁжñÒâÈí¼þ¹¤¾ß£¬ÒÑÍùÔø±»ÓÃÓÚÌØ¹¤Ô˶¯¡£ÆäÖÐÒ»¸öÀý×ÓÊÇ2Ô·ÝÓëLazarusÏà¹ØµÄÓã²æÊ½ÍøÂç´¹ÂÚÔ˶¯£¬¸ÃÔ˶¯Ê¹ÓÃManuscrypt¶ñÒâÈí¼þ¼Ò×åµÄ“ThreatNeedle”¹¤¾ß¼¯ÈºÀ´¹¥»÷¹ú·À¹«Ë¾¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNaq
6. ¹¥»÷ÕßʹÓÃÐ嵀 Android ÒøÐжñÒâÈí¼þ¶Ô°ÍÎ÷µÄ Itaú Unibanco ÒøÐÐÌᳫ¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±ÆÊÎöÁËÒ»ÖÖеÄAndroidÒøÐжñÒâÈí¼þ£¬¸Ã¶ñÒâÈí¼þÕë¶Ô°ÍÎ÷µÄ Itaú Unibanco£¬¸Ã¶ñÒâÈí¼þͨ¹ýÐéαµÄGoogle Play ÊÐËÁÒ³Ãæ¾ÙÐÐÈö²¥£¬ÕâÐ©Ò³ÃæÒÔ“ sincronizador.apk ”µÄÃûÒåÍйܶñÒâÓ¦ÓóÌÐò¡£²¢ÌåÏÖ¶ñÒâÓ¦ÓóÌÐòͨ³£Î±×°³ÉÕýµ±Ó¦ÓóÌÐòÀ´ÓÕÆÓû§×°ÖÃËüÃÇ£¬²¢ÊÔͼÔÚÊܺ¦Õß²»ÖªÇéµÄÇéÐÎϾÙÐÐÚ²ÆÐÔ½ðÈÚÉúÒâ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNao
7. ¹¥»÷ÕßÔÚÐ嵀 BLISTER ¶ñÒâÈí¼þ¼ÓÔØ³ÌÐòÖÐʹÓÃÓÐÓõĴúÂëÊðÃûÖ¤ÊéÌᳫ¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±Ð·¢Ã÷µÄ BLISTER ¶ñÒâÈí¼þ¼ÓÔØ³ÌÐòʹÓÃÓÐÓõĴúÂëÊðÃûÖ¤ÊéÀ´Ìӱܼì²â¡£²¢ÇÒÕâÖÖжñÒâÈí¼þ±³ºóµÄ¹¥»÷ÕßʹÓÃÓÐÓõĴúÂëÊðÃûÖ¤ÊéÀ´Ç©Êð¶ñÒâÈí¼þ¡£ÕâÖÖÕ½ÂÔÓÐÖúÓÚÍþв²»±»²ì¾õ£¬ÕâÒ²ÊÊÓÃÓÚ BLISTER ¶ñÒâÈí¼þ¡£¹¥»÷Õß¿ÉÒÔÇÔÈ¡Õýµ±µÄ´úÂëÊðÃûÖ¤Ê飬Ҳ¿ÉÒÔÖ±½Ó»òͨ¹ýǰ̨¹«Ë¾´ÓÖ¤Êé½ÒÏþ»ú¹¹¹ºÖ᣾ßÓÐÓÐÓôúÂëÊðÃûÖ¤ÊéµÄ¿ÉÖ´ÐÐÎļþµÄÉó²éˮƽͨ³£µÍÓÚδÊðÃûµÄ¿ÉÖ´ÐÐÎļþ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNaD
8. ¹¥»÷ÕßʹÓà Docker API ¹ýʧÉèÖÃÌᳫÍÚ¿ó¹¥»÷
¡¾¸ÅÊö¡¿
×Ô 2019 ÄêÒÔÀ´£¬¼ÓÃÜÇ®±ÒÍÚ¿óÔ˶¯±³ºóµÄºÚ¿ÍÒ»Ö±Ïë·¨×èÖ¹±»·¢Ã÷¡£Ñо¿Ö°Ô±ÌåÏÖ£¬ÕâЩ¹¥»÷ʹÓÃÁ˹ýʧÉèÖÃµÄ Docker API£¬Ê¹ËûÃÇÄܹ»½øÈëÍøÂç²¢×îÖÕÔÚÊÜѬȾÖ÷»úÉÏÉèÖúóÃÅÀ´ÍÚ¾ò¼ÓÃÜÇ®±Ò¡£ÕâÖÖ¹¥»÷ÊÖÒÕÊÇ»ùÓھ籾µÄ£¬±»³ÆÎª“Autom”£¬ÓÉÓÚËüʹÓÃÁË“autom.sh”Îļþ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNaP
9. ¹¥»÷Õß¶ÔÔÚÏßÃÜÂëÖÎÀíÆ÷LastPassÓû§Ìᳫײ¿â¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷¹¥»÷Õß¶ÔÔÚÏßÃÜÂëÖÎÀíÆ÷LastPassÓû§¾ÙÐÐÁË´ó¹æÄ£µÄײ¿â¹¥»÷£¬ÊÔͼ»á¼ûËûÃǵÄÔÆÍйÜÃÜÂë¿â¡£Ðí¶àLastPass Óû§ÌåÏÖ£¬ËûÃÇÊÕµ½µç×ÓÓʼþÖÒÑÔ£¬Æä´óÒâÊÇ“ÓÐÈËʵÑéʹÓÃÄúµÄÖ÷ÃÜÂëÔÚ´ÓδʹÓõÄ×°±¸ºÍλÖÃÉϵǼÄúµÄÕË»§£¬LastPass ×èÖ¹ÁËÕâ´ÎµÇ¼ÇëÇó£¬ÇëÄúÔÙ´ÎÈ·ÈÏÊÇÄúÔڵǼÂð?”¡£ÔÚÏßÃÜÂëÖÎÀíÆ÷Ö÷ÃÜÂëÓÐй¶µÄΣº¦£¬Óй¥»÷Õß(ÍâÑóIPÓû§)ÊÔͼ»á¼û¡¢µÁÓÃËûÃǵÄÕË»§¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNaU
10. ¹¥»÷ÕßʹÓÃRedLine ¶ñÒâÈí¼þ¹¥»÷ä¯ÀÀÆ÷ÒÔÇÔÈ¡Óû§ÃÜÂë
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷Ò»ÖÖÃûΪ RedLine µÄÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þÕë¶Ô Chrome¡¢Opera »ò Microsoft Edge µÈä¯ÀÀÆ÷¡£Redline Stealer ÊÇÒ»¸öÐÅÏ¢ÇÔÈ¡Æ÷£¬ËüÍøÂçÉúÑÄÔÚÍøÂçä¯ÀÀÆ÷ÖеÄÕÊ»§Æ¾Ö¤£¬ËüÓÚ 2020 Äê 3 ÔÂÊ״ηºÆðÔÚ¶íÂÞ˹°µÍøÉÏ¡£RedLine µÄÄ¿µÄÊÇËùÓлùÓÚ Chromium µÄ Web ä¯ÀÀÆ÷Éϱ£´æµÄÃûΪ“µÇ¼Êý¾Ý”µÄÎļþ¡£Õâ»ù±¾ÉÏ´ú±íÁËÒ»¸öÓÃÓÚÆ¾Ö¤´æ´¢£¨Óû§ÃûºÍÃÜÂ룩ĿµÄµÄ SQLite Êý¾Ý¿â¡£×ÝÈ»Óû§²»Ñ¡Ôñ½«Æäƾ֤´æ´¢ÔÚä¯ÀÀÆ÷ÖУ¬ÃÜÂëÖÎÀíϵͳÈÔ»áÌí¼ÓÒ»¸öÌõÄ¿£¬Ö¸³ö¸ÃÍøÕ¾Òѱ»“ÁÐÈëºÚÃûµ¥”¡£×ÝÈ»ºÚ¿ÍÎÞ·¨»á¼û“ÁÐÈëºÚÃûµ¥”ÕÊ»§µÄÃÜÂ룬ÕâÒ²½«ÌåÏÖËûÃDZ£´æ´ËÀàÕÊ»§£¬ÕâÒâζ×ÅËûÃÇ¿ÉÒÔ¾öÒéÖ´ÐÐÉç»á¹¤³Ì/ÍøÂç´¹ÂÚ¹¥»÷»òƾ֤Ìî³ä¹¥»÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNaS

AG¹«Ë¾ÔÆ







