¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2022.02.07-2022.02.13£©
2022-02-16
Ò»¡¢ Íþвͨ¸æ
΢Èí2ÔÂÇå¾²¸üжà¸ö²úÆ·¸ßΣÎó²îͨ¸æ£¨CVE-2022-21984¡¢CVE-2022-22005¡¢CVE-2022-21999£©
¡¾Ðû²¼Ê±¼ä¡¿2022-02-09 18:00:00 GMT
¡¾¸ÅÊö¡¿
2ÔÂ9ÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½Î¢ÈíÐû²¼2ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË48¸öÇå¾²ÎÊÌâ£¬Éæ¼°Windows¡¢Microsoft Office¡¢Microsoft Dynamics¡¢AzureµÈÆÕ±éʹÓõIJúÆ·£¬ÆäÖаüÀ¨È¨ÏÞÌáÉý¡¢Ô¶³Ì´úÂëÖ´ÐеȸßΣÎó²îÀàÐÍ¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
SambaÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-44142£©
¡¾Ðû²¼Ê±¼ä¡¿2022-02-09 17:00:00 GMT
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½ÍøÉÏÅû¶SambaÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-44142£©£¬ÓÉÓÚSambaµÄvfs_fruitÄ£¿éĬÈÏÉèÖÃÏÂÔÊÐíͨ¹ýÀ©Õ¹ÎļþÊôÐÔ¾ÙÐÐÔ½½ç¶Ñ¶Áд¡£µ±smbdÆÊÎöEAÔªÊý¾Ýʱ£¬¶ÔÎļþÀ©Õ¹ÊôÐÔ¾ßÓÐд»á¼ûȨÏÞµÄÔ¶³Ì¹¥»÷Õߣ¨guestÕË»§»òδÊÚȨÓû§£©¿ÉʹÓÃsmbdµÄȨÏÞ(ͨ³£ÊÇroot)Ö´ÐÐí§Òâ´úÂë¡£ÏÖÔÚ´ËÎó²îÒÑÓÐÆÊÎöÎÄÕ¹ûÕæ£¬ÇëÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. ÎÖ´ï·áÆÏÌÑÑÀ¹«Ë¾µÄ·þÎñÒòÍøÂç¹¥»÷¶øÖÐÖ¹
¡¾±êÇ©¡¿ÆóÒµ
¡¾¸ÅÊö¡¿
ÎÖ´ï·á³ÉÎªÍøÂçÖÐÖ¹µÄÄ¿µÄ£¬¸ÃÍøÂçÖÐֹʼÓÚ 2022 Äê 2 Ô 7 ÈÕÍí£¬ÕâÊÇÒ»´ÎÖ¼ÔÚÔì³ÉË𺦺ÍÖÐÖ¹µÄÐîÒâºÍ¶ñÒâÍøÂç¹¥»÷µÄЧ¹û¡£Ò»µ©·¢Ã÷ÍøÂçÎÊÌâµÄµÚÒ»¸ö¼£Ïó£¬ÎÖ´ï·á¾ÍѸËÙ×ö³öÏìÓ¦ÒÔʶ±ð¡¢¿ØÖƺͻָ´·þÎñ¡£ÕâÖÖÇéÐÎÕýÔÚÓ°Ïì»ùÓÚÊý¾ÝÍøÂçµÄÓªÒµÌṩ£¬ÀýÈç4G/5GÍøÂç¡¢Àο¿ÓïÒô¡¢µçÊÓ¡¢¶ÌÐźÍÓïÒô/Êý×ÖÓ¦´ðÓªÒµ¡£Æ¾Ö¤ÎÖ´ï·áÆÏÌÑÑÀÊ×ϯִÐйٵÄ˵·¨£¬Õâ´ÎÏ®»÷Ó°ÏìÁËÊý°ÙÍòÈË¡¢ÆóÒµºÍ¹«¹²·þÎñ£¬Èç¾È»¤³µ·þÎñ¡¢Ïû·À²¿·ÖºÍÒ½Ôº¡£ËûÌåÏÖ£¬½ôÆÈ·þÎñÊǻָ´Í¨Ñ¶µÄÓÅÏÈÊÂÏî¡£Ëû¸æËß¼ÇÕߣ¬ÊÂÎñµÄÄ»ºóºÚÊÖ²¢Ã»ÓÐÒªÇóÊê½ð¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNgq
2. ¹¥»÷ÕßʹÓÃеÄNimbleMamba¶ñÒâÈí¼þ¹¥»÷Öж«Õþ¸®ºÍÆóÒµ
¡¾±êÇ©¡¿ÆóÒµ¡¢Õþ¸®
¡¾¸ÅÊö¡¿
×÷Ϊ“¸ß¶È¼¯ÖеÄÇé±¨ÍøÂçÔ˶¯”µÄÒ»²¿·Ö£¬Ò»¸öÓë°ÍÀÕ˹̹½áÃ˵ĺڿÍ×é֯ʹÓÃÒ»ÖÖÐÂÐͶñÒâÈí¼þÖ²ÈëÎïÀ´¹¥»÷Öж«Õþ¸®¡¢¹ú¼ÊÕþ²ßÖÇÄÒÍźÍÒ»¼Ò¹úÓк½¿Õ¹«Ë¾¡£Proofpoint Ñо¿Ö°Ô±µÄ·¢Ã÷Ïêϸ˵Ã÷Îú MoleRAT ×î½ü¶ÔÒ»¸öÖøÃûÇÒÓоݿɲéµÄ½²°¢À²®ÓïµÄÍøÂç×éÖ¯½ÓÄɵÄÐж¯£¬ÒÔ¼°ÕýÔÚ×°ÖõÄÒ»ÖÖÃûΪ“NimbleMamba”µÄÐÂÇé±¨ÍøÂçľÂí¡£ÎªÁËÑéÖ¤ËùÓÐÊÜѬȾµÄÈ˶¼ÔÚ TA402 µÄÄ¿µÄÇøÓòÄÚ£¬NimbleMamba ʹÓÃÁË»¤À¸¡£NimbleMamba ʹÓà Dropbox API À´¿ØÖƺÍÊý¾Ý×ß©¡£¸Ã¶ñÒâÈí¼þ»¹¾ßÓÐÐí¶àʹ×Ô¶¯»¯ºÍÈ˹¤ÆÊÎöÔ½·¢ÄÑÌâµÄ¹¦Ð§¡£ËüÒ»Ö±ÔÚ´´Á¢ÖУ¬Î¬»¤ÓÅÒ죬²¢ÊÊÊÊÓÃÓڸ߶ȼ¯ÖеÄÇé±¨ÍøÂçÍýÏë¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNg9
3. ¹¥»÷ÕßʹÓÃFritzFrog½©Ê¬ÍøÂç¹¥»÷Ò½ÁÆ¡¢½ÌÓýºÍÕþ¸®²¿·Ö
¡¾±êÇ©¡¿Ò½ÁÆ¡¢Õþ¸®
¡¾¸ÅÊö¡¿
FritzFrog ½©Ê¬ÍøÂçͨ¹ýÐ嵀 P2P Ô˶¯ÖØÐ·ºÆð£¬½öÔÚÒ»¸öÔÂÄÚÔöÌíÁË 10 ±¶¡£FritzFrog ÊÇ2020 Äê 1 Ô·¢Ã÷µÄµã¶Ôµã½©Ê¬ÍøÂç ¡£Ôڰ˸öÔµÄʱ¼äÀ¸Ã½©Ê¬ÍøÂçÀֳɹ¥»÷ÁËÖÁÉÙ 500 ̨Õþ¸®ºÍÆóÒµ SSH ·þÎñÆ÷¡£Óà Golang ±à³ÌÓïÑÔ±àдµÄ P2P ½©Ê¬ÍøÂçʵÖÊÉÏÊÇÈ¥ÖÐÐÄ»¯µÄ£¬Ëü½«ÊµÑ鱩Á¦ÆÆ½â·þÎñÆ÷¡¢ÔÆÊµÀýºÍÆäËû×°±¸——°üÀ¨Â·ÓÉÆ÷——ÔÚ»¥ÁªÍøÉÏ̻¶ÁËÈë¿Úµã¡£ÖÜËÄ£¬À´×ÔAkamai Threat LabsµÄÍøÂçÇå¾²Ñо¿Ö°Ô±ÌåÏÖ£¬Ö»¹ÜÔÚÉÏÒ»´Î¹¥»÷À˳±Ö®ºóÒѾÇå¾²ÏÂÀ´£¬µ«×Ô 12 ÔÂÒÔÀ´£¬½©Ê¬ÍøÂçÒÔÖ¸Êý¼¶µÄÔöÌíÔٴηºÆð¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNg8
4. ¶íÂÞ˹ APT ºÚ¿ÍʹÓà COVID-19 ÓÕ¶üÃé׼ŷÖÞÍâ½»¹Ù
¡¾±êÇ©¡¿Õþ¸®
¡¾¸ÅÊö¡¿
×÷Ϊ 2021 Äê 10 ÔÂºÍ 2021 Äê 11 ÔÂÌᳫµÄһϵÁÐÓã²æÊ½ÍøÂç´¹ÂÚÔ˶¯µÄÒ»²¿·Ö£¬±»³ÆÎª APT29 µÄÓë¶íÂÞ˹ÓйصÄÍþвÐÐΪÕßÕë¶ÔÅ·ÖÞÍ⽻ʹÍźÍÍâ½»²¿¡£Æ¾Ö¤Óë The Hacker News ¹²ÏíµÄ ESET µÄT3 2021 Íþв±¨¸æ£¬ÈëÇÖΪÔÚÊÜѬȾϵͳÉϰ²ÅÅ Cobalt Strike Beacon ÆÌƽÁËõè¾¶£¬ËæºóʹÓÃפ×ãµãͶ·ÅÁËÌØÁíÍâ¶ñÒâÈí¼þ£¬ÒÔÍøÂçÓйØÖ÷»úºÍÆäËû»úеµÄÐÅÏ¢¡£ÍøÂç¡£Óã²æÊ½ÍøÂç´¹ÂÚ¹¥»÷ʼÓÚð³äÒÁÀÊÍâ½»²¿µÄÒÔ COVID-19 ΪÖ÷ÌâµÄÍøÂç´¹ÂÚµç×ÓÓʼþ£¬ÆäÖаüÀ¨Ò»¸ö HTML ¸½¼þ£¬µ±·¿ª¸Ã¸½¼þʱ£¬»áÌáÐÑÊÕ¼þÈË·¿ª»òÉúÑÄ¿´ËÆ ISO ´ÅÅÌÓ³ÏñÎļþµÄÄÚÈÝ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNfN
5. Íâ½»²¿ÔâÓö“ÑÏÖØÍøÂçÇå¾²ÊÂÎñ”
¡¾±êÇ©¡¿Ò½ÁÆ¡¢Õþ¸®
¡¾¸ÅÊö¡¿
¹ûÕæÕбêÎļþÏÔʾӢÍâÑó½»²¿³ÉΪ“ÑÏÖØÍøÂçÇå¾²ÊÂÎñ”µÄÄ¿µÄ£¬µ«Ï¸½ÚÉÐδÅû¶¡£Íâ½»²¿ÔâÓöÁËÒ»ÆðÖØ´óµÄÍøÂçÇå¾²ÊÂÎñ£¬µ¼ÖÂÆäÍøÂçÇå¾²³Ð°üÉÌ BAE Systems Applied Intelligence ÒÔ“¼«Æä½ôÆÈµÄ·½·¨”»ñµÃÁËÌØÁíÍâÖ§³Ö¡£Stack ×îÏÈÅû¶ÁËÕâ´Î¹¥»÷µÄÐÂÎÅ£¬³ÆÕþ¸®Ö»ÊÇͨ¹ý¹ûÕæÕбêͨ¸æÅû¶ÁËÓ°ÏìÍâ½»¡¢Áª°îºÍÉú³¤°ì¹«ÊÒ (FCDO) µÄ“ÑÏÖØÍøÂçÇå¾²ÊÂÎñ”µÄ±£´æ¡£Ã»ÓйØÓÚ¹¥»÷±¬·¢µÄʱ¼ä¡¢¹¥»÷µÄÀàÐÍ¡¢Ôì³ÉµÄË𺦵ÈÐÅÏ¢£¬ÓÉÓÚϸ½ÚÉÐδ¹ûÕæÅû¶¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNfM
6. ¶íÂÞ˹APTÔöÇ¿ÎÚ¿ËÀ¼µÄ¶ñÒâÍøÂçÔ˶¯
¡¾±êÇ©¡¿Õþ¸®
¡¾¸ÅÊö¡¿
Ò»¸ö»îÔ¾Á˽üÊ®ÄêµÄ¶íÂÞ˹¸ß¼¶Ò»Á¬ÐÔÍþв×éÖ¯×î½üÔÚÎÚ¿ËÀ¼ÔöÇ¿Á˶ñÒâÍøÂç¹¥»÷Ô˶¯£¬ÕâÊǵØÔµÕþÖÎÖ÷ÒªÊ±ÊÆÔõÑù¾³£ÉìÕŵ½ÍøÂçÁìÓòµÄÁíÒ»¸öÀý×Ó¡£¹ØÓÚ×éÖ¯¶øÑÔ£¬ÕâЩ¹¥»÷ÌáÐÑËûÃÇΪʲôÐèÒªÇ×½ü¹Ø×¢Î»ÓڸõØÇøµÄϵͳ£¬²¢ÔÚËüÃdzÉΪĿµÄʱ½ÓÄɲ½·¥×èÖ¹Ë𺦡£Ñо¿Ö°Ô±ÉÏÖÜÐû²¼Á˹ØÓÚËûÃÇÊӲ쵽µÄÓë Actinium Ïà¹ØµÄ½üÆÚÍøÂçÌØ¹¤Ô˶¯µÄµ¥¶À±¨¸æ£¬±»ÒÔΪÓë¶íÂÞ˹Áª°îÇå¾²¾Ö£¨FSB£©Óйء£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNfy
7. ¹¥»÷ÕßʹÓÃÀÕË÷Èí¼þ¶ÔKronos Ransomware Ìᳫ¹¥»÷
¡¾±êÇ©¡¿ÆóÒµ
¡¾¸ÅÊö¡¿
12 Ô£¬ÈËÁ¦×ÊÔ´ÖÎÀíÆ½Ì¨ Ultimate Kronos Group (UKG) Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬6,632 Ãû Puma Ô±¹¤µÄÊý¾Ý±»µÁ¡£¿ÉÄÜ̻¶µÄÊý¾Ý°üÀ¨ÐÕÃû¡¢Éç»áÇå¾²ºÅÂëºÍÆäËûСÎÒ˽¼ÒÐÅÏ¢¡£¹¥»÷Ï®»÷ÁËÓÃÓÚÍйܶà¸öÔÆÓ¦ÓóÌÐòµÄ Kronos ˽ÓÐÔÆ·þÎñ£¬°üÀ¨ÒøÐе÷Àí½â¾ö¼Æ»®¡¢Ò½ÁƱ£½¡À©Õ¹¡¢UKG TeleStaff ºÍ UKG Workforce Central¡£Puma ÊǸù«Ë¾ÊÜÇå¾²Îó²îÓ°ÏìµÄ¿Í»§Ö®Ò»¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNfw
8. ACTINIUMºÚ¿Í×éÖ¯Õë¶ÔÕþ¸®¡¢¾ü¶ÓºÍ·ÇÕþ¸®×éÖ¯ÇÔÈ¡Ãô¸ÐÊý¾Ý
¡¾±êÇ©¡¿Õþ¸®
¡¾¸ÅÊö¡¿
Ò»¸öÃûΪ Gamaredon µÄÍøÂçÇå¾²ºÚ¿Í×éÖ¯ ÕýÔÚ½¨ÉèһϵÁÐÓã²æÊ½ÍøÂç´¹ÂÚµç×ÓÓʼþ¡£¿ÉÊÇ£¬ÔÚ×î½üµÄÊÂÎñÖУ¬ÒѾ¼ì²âµ½ ACTINIUM ºÚ¿Í×éÖ¯µÄÔËÓªÉÌÕýÔÚÕë¶ÔÒÔÏÂÎÚ¿ËÀ¼²¿·ÖÇÔÈ¡Ãô¸ÐÊý¾Ý£ºÕþ¸®¡¢¾ü¶Ó¡¢·ÇÕþ¸®×éÖ¯¡¢Ë¾·¨¡¢Ö´·¨¡£¸ÃÍþв×éÖ¯Ò»Á¬ÒÔÎÚ¿ËÀ¼ÊµÌåºÍÓëÎÚ¿ËÀ¼ÓйصÄËùÓÐÆäËû×é֯ΪĿµÄ¡£×Ô 2021 Äê 10 ÔÂÒÔÀ´£¬ºÚ¿Í×éÖ¯Ò»Ö±ÔÚÌᳫ´ËÀ๥»÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNfx
9. Swissport ÔâÓöÀÕË÷Èí¼þ¹¥»÷µ¼Öº½°àÑÓÎó
¡¾±êÇ©¡¿½»Í¨
¡¾¸ÅÊö¡¿
Swissport ÖÜÎåÔÚ Twitter ÉÏÖÒÑÔÆä IT »ù´¡ÉèÊ©Êܵ½ÁËÀÕË÷Èí¼þµÄ¹¥»÷£¬²¢¶Ô·þÎñ½»¸¶Ôì³ÉµÄÈκÎÓ°ÏìÌåÏÖǸÒâ¡£#Swissport µÄ IT Çå¾²ÊÂÎñ»ñµÃÁË¿ØÖÆ£¬ÊÜÓ°ÏìµÄ»ù´¡ÉèʩѸËÙÏÂÏß¡£ÊÖ¶¯½â¾öÒªÁì»ò±¸ÓÃϵͳʼÖÕÈ·±£²Ù×÷Çå¾²¡£ÏÖÔÚÕýÔÚ¾ÙÐÐÖÜÈ«µÄϵͳÕûÀíºÍ»Ö¸´¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNfz
10. Roaming Mantis SMSishing Ô˶¯Õë¶ÔÅ·ÖÞÌᳫ¹¥»÷
¡¾±êÇ©¡¿
¡¾¸ÅÊö¡¿
Roaming Mantis ÊÇÒ»ÖÖÆ¾Ö¤ÍµÇԺͶñÒâÈí¼þÔ˶¯£¬ËüʹÓà smishing ÒÔ APK ÎļþµÄÃûÌ÷ַ¢¶ñÒâ Android Ó¦ÓóÌÐò¡£Çå¾²Ñо¿Ô±µÄÊÓ²ì Åú×¢£¬Õâ´Î¹¥»÷µÄÄ¿µÄÊÇÑÇÖÞÓû§£¬Ê¹ÓÃÕë¶ÔÓ¢Óï¡¢º«Óï¡¢¼òÌåÖÐÎĺÍÈÕÓï¶¨ÖÆµÄÐéÎ±ÍøÕ¾¡£ÊÜÓ°Ïì×î´óµÄÓû§Î»ÓÚÃϼÓÀ¹ú¡¢ÈÕ±¾ºÍº«¹ú¡£ÏÖÔÚ£¬Roaming Mantis SMSÍøÂç´¹ÂÚÔ˶¯Õë¶ÔµÂ¹úºÍ·¨¹úµÄ Android ºÍ iPhone Óû§Ê¹ÓöñÒâÓ¦ÓóÌÐòºÍÍøÂç´¹ÂÚÒ³Ãæ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNfv

AG¹«Ë¾ÔÆ







