¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2022.01.10-2022.01.16£©
2022-01-17
Ò»¡¢ Íþвͨ¸æ
HTTPÐÒéÕ»Ô¶³Ì´úÂëÖ´ÐÐÎó²îͨ¸æ£¨CVE-2022-21907£©
¡¾Ðû²¼Ê±¼ä¡¿2022-01-14 15:00:00 GMT
¡¾¸ÅÊö¡¿
1ÔÂ12ÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½Î¢ÈíÐû²¼Ô¶ÈÇå¾²¸üУ¬ÆäÖÐÐÞ¸´ÁËÒ»¸öHTTPÐÒéÕ»Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2022-21907£©¡£ÓÉÓÚHTTPÐÒéÕ»£¨HTTP.sys£©ÖеÄHTTP Trailer Support¹¦Ð§±£´æ½çÏß¹ýʧ¿Éµ¼Ö»º³åÇøÒç³ö¡£Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýÏòWeb·þÎñÆ÷·¢ËÍÌØÖÆµÄHTTPÊý¾Ý°ü£¬´Ó¶øÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¸ÃÎó²î±»Î¢ÈíÌáÐÑΪ“¿ÉÈ䳿»¯”£¬ÎÞÐèÓû§½»»¥±ã¿Éͨ¹ýÍøÂç¾ÙÐÐ×ÔÎÒÈö²¥£¬CVSSÆÀ·ÖΪ9.8¡£ÏÖÔÚÒÑ·¢Ã÷¿ÉÔì³ÉÄ¿µÄÖ÷»úÀ¶ÆÁÍß½âµÄÎó²îʹÓ÷ºÆð£¬ÇëÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
Apache DubboÔ¶³Ì´úÂëÖ´ÐÐÎó²îͨ¸æ£¨CVE-2021-43297£©
¡¾Ðû²¼Ê±¼ä¡¿2022-01-13 11:00:00 GMT
¡¾¸ÅÊö¡¿
1ÔÂ12ÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²â·¢Ã÷ApacheÐû²¼Ç徲ͨ¸æ£¬ÐÞ¸´ÁËDubboÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-43297£©¡£ÓÉÓÚÔÚDubboµÄhessian-liteÖб£´æ·´ÐòÁл¯Îó²î£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚÄ¿µÄϵͳÉÏÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£´ó´ó¶¼ Dubbo Óû§Ä¬ÈÏʹÓà Hessian2×÷ΪÐòÁл¯/·´ÐòÁл¯ÐÒ飬ÔÚHessian ²¶»ñµ½Ò쳣ʱ£¬Hessian½«»á×¢ÏúһЩÓû§ÐÅÏ¢£¬Õâ¿ÉÄܻᵼÖÂÔ¶³ÌÏÂÁîÖ´ÐС£ÇëÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£ Apache Dubbo ÊÇÒ»¿î΢·þÎñ¿ª·¢¿ò¼Ü£¬ËüÌṩÁËRPCͨѶÓë΢·þÎñÖÎÀíÁ½´ó¸Åº¦ÄÜÁ¦¡£Ê¹Ó¦ÓÿÉͨ¹ý¸ßÐÔÄÜµÄ RPC ʵÏÖ·þÎñµÄÊä³öºÍÊäÈ빦Ч£¬¿ÉÒÔºÍ Spring ¿ò¼ÜÎ޷켯³É¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. SquirrelwaffleʹÓÃProxyShellºÍProxyLogonÌᳫµç×ÓÓʼþ¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±ÊÓ²ìÁË×î½ü±¬·¢ÔÚÖж«µÄ¼¸ÆðÓë Squirrelwaffle Ïà¹ØµÄ¹¥»÷ÊÂÎñ·¢Ã÷ËùÓй¥»÷¶¼Ô´×ÔÄÚ²¿°²ÅÅµÄ Microsoft Exchange ·þÎñÆ÷£¬ÕâЩ·þÎñÆ÷ËÆºõÈÝÒ×Êܵ½ ProxyLogon ºÍ ProxyShell µÄ¹¥»÷¡£¾ÆÊÎöºóÌåÏÖÈý¸öExchange·þÎñÆ÷ÉϵÄIISÈÕÖ¾Öж¼·¢Ã÷ÁËÎó²îCVE-2021-26855¡¢CVE-2021-34473ºÍCVE-2021-34523±»Ê¹Óõĺۼ££¬ProxyLogon(CVE-2021-26855)ºÍ ProxyShell(CVE-2021-34473ºÍ CVE-2021-34523) ¹¥»÷ÖÐʹÓÃÁËÏàͬµÄCVE¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNca
2. FIN7¼¯ÍŶÔʹÓÃBadUSB×°±¸µÄÃÀ¹ú¹«Ë¾Ìᳫ¹¥»÷
¡¾¸ÅÊö¡¿
Áª°îÊÓ²ì¾Ö (FBI) ÖÒÑÔÃÀ¹ú¹«Ë¾£¬FIN7 ÍøÂç·¸·¨¼¯ÍÅÕýÔÚʹÓÃBadUSB×°±¸Ãé×¼ÃÀ¹ú¹ú·À¹¤Òµ¡£²¢ÌåÏÖ¸ÃÍÅ»ïÕýÔÚʹÓôøÓÐLilyGO±ê¼ÇµÄÎäÆ÷»¯USB ×°±¸£¬ÕâЩװ±¸Í¨¹ýÃÀ¹úÓÊÕþ·þÎñºÍÍŽá°ü¹ü·þÎñ¹«Ë¾·¢Ë͸øÊܺ¦Õß¡£Ä¿µÄÓû§½«USBÄ´Ö¸Çý¶¯Æ÷²åÈëÅÌËã»úºó£¬»á´¥·¢BadUSB¹¥»÷£¬²¢ÇÒ×°±¸³äµ±¼üÅÌ£¨HID Emulator USB£©Ïòϵͳ·¢ËÍÏÂÁî¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNcb
3. еÄZloaderÔ˶¯Ê¹ÓÃ΢ÈíµÄÊðÃûÑéÖ¤¶ÔÓû§Ìᳫ¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷ZloaderÐÂÔ˶¯µÄÖ¤¾ÝÓÚ 2021 Äê 11 ÔÂÉÏÑ®×óÓÒÊ״ηºÆð£¬Ñ¬È¾Á´ÖаüÀ¨µÄÊÖÒÕ°üÀ¨Ê¹ÓÃÕýµ±Ô¶³ÌÖÎÀíÈí¼þ (RMM) ÒÔ»ñµÃ¶ÔÄ¿µÄÅÌËã»úµÄ³õʼ»á¼ûȨÏÞ¡£È»ºó£¬¶ñÒâÈí¼þʹÓÃ΢ÈíµÄÊý×ÖÊðÃûÑéÖ¤ÒªÁ콫ÆäÓÐÓÃÔØºÉ×¢ÈëÊðÃûϵͳ DLL ÖУ¬ÒÔ½øÒ»²½ÌÓ±ÜϵͳµÄ·ÀÓù¡£ÕâÒ»Ö¤¾ÝÅú×¢£¬Zloader Ô˶¯µÄ¿ª·¢ÕßÔÚ·ÀÓù¹æ±Ü·½Ãæ¾ÙÐÐÁËÐí¶àµü´ú£¬²¢ÇÒÈÔÔÚÿÖܸüÐÂËûÃǵÄÒªÁì¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNcw
4. ÓëÓ¡¶ÈÓйصĹ¥»÷ÕßPatchworkʹÓÃRagnatelaÌᳫ´¹ÂÚ¹¥»÷
¡¾¸ÅÊö¡¿
ÔÚ×î½üµÄÒ»´ÎÔ˶¯ÖУ¬Ò»ÃûÓëÓ¡¶ÈÓйصĹ¥»÷Õß±»×·×ÙΪ Patchwork£¨ÓÖÃû Dropping Elephant£©£¬ËûʹÓÃÁË BADNEWS ºóÃŵÄбäÌ壬³ÆÎª Ragnatela£¨Òâ´óÀûÓïÖеē֩ÖëÍø”£©£¬Patchwork С×éʹÓÃÎäÆ÷»¯µÄ RTF Îļþ¾ÙÐÐÁËÓã²æÊ½ÍøÂç´¹ÂÚÔ˶¯£¬ÒÔɾ³ý BADNEWS (Ragnatela) Ô¶³ÌÖÎÀíľÂí (RAT) µÄ±äÖÖ¡£¶ñÒâ RTF Îļþð³ä°Í»ù˹̹Õþ¸®²¢Ê¹Óà Microsoft ¹«Ê½±à¼Æ÷ÖеÄÎó²îÀ´×ª´ïºÍÖ´ÐÐ×îÖÕÓÐÓøºÔØ (RAT)¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNcu
5. ÔÚÏßÔ¤¶©·þÎñƽ̨FlexBooker´ó×ÚÓû§Êý¾ÝÔâй¶
¡¾¸ÅÊö¡¿
ƾ֤ÐÂÎųƣ¬ÔÚÏßÔ¤¶©·þÎñƽ̨ FlexBookerÅû¶Êý¾Ýй¶ÊÂÎñ£¬³¬370ÍòÕË»§Ôâµ½ºÚ¿ÍÈëÇÖ£¬±»µÁÊý¾ÝÐÅÏ¢ÔÚ°µÍø±»³öÊÛ¡£¶ø¹¥»÷±¬·¢ÔÚÊ¥µ®½ÚǰϦ£¬¸ÃÊÂÎñÓÉÒ»¸ö×Ô³ÆÎª Uawrongteam µÄ×éÖ¯Ìᳫ£¬ËûÃÇÐû²¼Á˰üÀ¨Éí·ÝÖ¤¡¢¼ÝÕÕ¡¢ÕÕÆ¬µÄµµ°¸ºÍÎļþÁ´½Ó¡£ÍþвÕßÉù³Æ±»µÁµÄÊý¾Ý¿â°üÀ¨¿Í»§ÐÅÏ¢£¬°üÀ¨ÐÕÃû¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂ롢ɢÁÐÃÜÂëºÍÃÜÂëÑΡ£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNcx
6. ¹¥»÷ÕßʹÓÃÐÂÐÍÀÕË÷Èí¼þNight SkyÕë¶ÔÆóÒµÌᳫ¹¥»÷
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬Çå¾²Ñо¿Ö°Ô±Ðû²¼ÖÒÑԳƣ¬Ò»¸öÃûΪ“Night Sky”µÄÐÂÐÍÀÕË÷Èí¼þÕýÔÙ»îÔ¾£¬ËüÒÔÆóÒµÍøÂçΪĿµÄ£¬²¢ÔÚË«ÖØÀÕË÷¹¥»÷ÖÐÇÔÈ¡Êý¾Ý¡£²¢ÇÒÔÚ¹¥»÷Ö®ºó£¬ÀÕË÷Èí¼þ»áÔÚÿ¸öÎļþ¼ÐÖа²ÅÅÒ»¸öÃûΪNightSkyReadMe.htaµÄÀÕË÷Ìõ×Ó£¬¸ÃÎļþÖеÄÐÅÏ¢°üÀ¨ÁªÏµµç×ÓÓʼþ£¬Êܺ¦ÕßÐÉÌÒ³ÃæµÄÓ²±àÂëÆ¾Ö¤£¬µÇ¼Rocket.ChatÒÔ±ã¾ÙÐÐÁªÏµµÄƾ֤¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNcy
7. ¹¥»÷ÕßʹÓÃSysJoker ºóÃŶñÒâÈí¼þ¶ÔWindows¡¢Linux ºÍmacOSÌᳫ¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±ÖÒÑÔ˵£¬Ò»ÖÖ¿ÉÄÜͨ¹ý¶ñÒâ npm °ü·Ö·¢µÄÈ«ÐÂ¶àÆ½Ì¨¶ñÒâÈí¼þÕýÔڵ͵÷Èö²¥£¬Linux ºÍ Mac °æ±¾ÔÚ VirusTotal ÖÐÍêȫδ±»¼ì²âµ½¡£¸ÃºóÃű»³ÆÎª SysJoker£¬ÓÃÓÚÔÚÄ¿µÄ»úеÉϽ¨Éè³õʼ»á¼ûȨÏÞ¡£×°Öúó£¬Ëü¿ÉÒÔÖ´ÐкóÐø´úÂëÒÔ¼°ÆäËûÏÂÁ¶ñÒâÐÐΪÕß¿ÉÒÔͨ¹ýÕâЩÏÂÁî¾ÙÐкóÐø¹¥»÷»òתÏò½øÒ»²½½øÈë¹«Ë¾ÍøÂç¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNcG
8. ¹¥»÷Õßͨ¹ý΢ÈíAzure¡¢AWSÔÆ·þÎñÈö²¥Ô¶³Ì»á¼ûľÂí
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷£¬×î½üÒ»ÏîʹÓù«¹²ÔÆ»ù´¡ÉèÊ©µÄÔ˶¯ÕýÔÚ°²ÅŵIJ»ÊÇÒ»¸ö£¬¶øÊÇÈý¸öÉÌÒµÔ¶³Ì»á¼ûľÂí (RAT)¡£Nanocore¡¢Netwire ºÍ AsyncRAT ÓÐÓøºÔØÕýÔÚ´Ó¹«¹²ÔÆÏµÍ³°²ÅÅ£¬ÕâÖÖÀÄÓÃÐÐΪʹ¹¥»÷ÕßÄܹ»Ê¹ÓðüÀ¨ Microsoft Azure ºÍ Amazon Web Services (AWS) ÔÚÄڵũӦÉÌÖÎÀíµÄÔÆ·þÎñ×ÊÔ´À´µÖ´ï¶ñÒâÄ¿µÄ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNcT
9. ¹¥»÷ÕßʹÓÃRedLineÐÅÏ¢ÇÔÈ¡Æ÷µÄбäÖÖÌᳫ¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷£¬RedLine ÐÅÏ¢ÇÔÈ¡Æ÷µÄбäÖÖÕýͨ¹ýµç×ÓÓʼþ¾ÙÐÐÈö²¥£¬ÒÔCOVID-19 Omicron ²¡Àý¼ÆÊýÆ÷Ó¦ÓóÌÐò×÷ΪÓÕ¶ü¡£RedLine µÄÄ¿µÄÊÇ´æ´¢ÔÚä¯ÀÀÆ÷ÉϵÄÓû§ÕË»§Æ¾Ö¤¡¢VPNÃÜÂë¡¢ÐÅÓÿ¨ÏêϸÐÅÏ¢¡¢cookies¡¢IMÄÚÈÝ¡¢FTPƾ֤¡¢¼ÓÃÜÇ®±ÒÇ®°üÊý¾ÝºÍϵͳÐÅÏ¢¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNcW
10. Ciox HealthµÄ´ó×Ú»¼ÕßÊý¾ÝÔâй¶
¡¾¸ÅÊö¡¿
ƾ֤×î½üµÄ Ciox Health ֪ͨ£¬Î´¾ÊÚȨµÄÈËÔÚ 2021 Äê 6 Ô 24 ÈÕÖÁ 7 Ô 2 ÈÕʱ´ú»á¼ûÁË Ciox Ô±¹¤µÄµç×ÓÓʼþÕÊ»§¡£¾Ý¸Ã¹«Ë¾³Æ£¬¹¥»÷Õß¿ÉÄÜÒÑʹÓøûá¼ûȨÏÞÏÂÔØÓëÊÜѬȾÕÊ»§Ïà¹ØµÄµç×ÓÓʼþºÍ¸½¼þ¡£ÕË»§ÐÅÏ¢ÓëÕ˵¥ÅÌÎʺͿͻ§·þÎñÇëÇóÏà¹Ø£¬Ëü¿ÉÄܰüÀ¨»¼ÕßÐÕÃû¡¢ÌṩÕßÐÕÃû¡¢³öÉúÈÕÆÚ¡¢·þÎñÈÕÆÚ¡¢¿µ½¡°ü¹ÜÐÅÏ¢¡¢ÁÙ´²ÐÅÏ¢»òÉç»á°ü¹Ü»ò¼ÝʻִÕÕºÅÂë¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNdb

AG¹«Ë¾ÔÆ







