FireEye³ÆÕë¶ÔAccellion FTAµÄ¹¥»÷ÓëFIN11ÓйØ£»£»£»£»£»£»ÎÚ¿ËÀ¼³ÆÆäÕþ¸®µÄ¶à¸öÍøÕ¾Ôâµ½À´×Ô¶íÂÞ˹µÄ¹¥»÷

Ðû²¼Ê±¼ä 2021-02-24

1.FireEye³ÆÕë¶ÔAccellion FTAµÄ¹¥»÷ÓëFIN11ÓйØ


1.jpg


Çå¾²¹«Ë¾FireEye³Æ£¬£¬£¬£¬ £¬£¬2020Äê12Ôµ½2021Äê1ÔÂÖ®¼äʹÓÃAccellion FTAЧÀÍÆ÷ÖÐ0dayµÄ¹¥»÷»î¶¯ÓëFIN11Óйأ¬£¬£¬£¬ £¬£¬²¨¼°ÁËÈ«ÇòÔ¼100¼Ò¹«Ë¾ ¡£¡£¡£¡£ºÚ¿ÍÖ÷ҪʹÓÃÁËËĸöÎó²îÀ´¹¥»÷FTAЧÀÍÆ÷£¬£¬£¬£¬ £¬£¬²¢×°ÖÃÁËÒ»¸öÃûΪDEWMODEµÄWeb Shell£¬£¬£¬£¬ £¬£¬À´ÏÂÔØÊܺ¦ÕßFTA×°±¸ÉÏ´æ´¢µÄÎļþ ¡£¡£¡£¡£ÊÜÓ°ÏìµÄ¹«Ë¾ºÍ×éÖ¯°üÀ¨Fugro¡¢Danaher¡¢Singtel¡¢Jones¡¢ÐÂÎ÷À¼´¢±¸ÒøÐкͰĴóÀûÑÇ֤ȯºÍͶ×ÊίԱ»á£¨ASIC£©µÈ ¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬£¬ºÚ¿ÍÔÚClopµÄÊý¾ÝÐ¹Â¶ÍøÕ¾ÉÏÁгöÁ˲¿·Ö¹«Ë¾£¬£¬£¬£¬ £¬£¬ÒÔڲƭÀÕË÷ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/attacks-targeting-accellion-product-linked-fin11-cybercrime-group


2.Áè¼Ý1500¸öPowerhouse VPN¿É±»ÓÃÓÚ´ó¹æÄ£DDoS¹¥»÷


2.png


Ñо¿Ö°Ô±Phenomite·¢Ã÷Ô¼ÓÐ1520̨Powerhouse VPN¿É±»ÓÃÓÚ´ó¹æÄ£DDoS¹¥»÷£¬£¬£¬£¬ £¬£¬Ö÷ҪλÓÚÓ¢¹ú¡¢Î¬Ò²ÄɺÍÏã¸Û ¡£¡£¡£¡£Phenomite³ÆÕâ¸öеÄDDoSʸÁ¿ÊÇÔËÐÐÔÚPowerhouse VPNЧÀÍÆ÷µÄUDP¶Ë¿Ú20811ÉϵÄδ֪µÄЧÀÍ£¬£¬£¬£¬ £¬£¬¹¥»÷Õß¿ÉÒÔÓÃÒ»¸ö×Ö½ÚµÄÇëÇópingÕâ¸ö¶Ë¿Ú£¬£¬£¬£¬ £¬£¬Ð§ÀÍͨ³£»£»£»£»£»£»áÓøߴïԭʼÊý¾Ý°ü40±¶µÄÊý¾Ý°üÀ´ÏìÓ¦ ¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬£¬ÕâÖÖDDoS¹¥»÷ǰÑÔÒѱ»ÔÚҰʹÓ㬣¬£¬£¬ £¬£¬ÆäÖÐһЩ¹¥»÷ËÙÂʸߴï22 Gbps ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/powerhouse-vpn-products-can-be-abused-for-large-scale-ddos-attacks/


3.ÎÚ¿ËÀ¼³ÆÆäÕþ¸®µÄ¶à¸öÍøÕ¾Ôâµ½À´×Ô¶íÂÞ˹µÄ¹¥»÷


3.png


ÎÚ¿ËÀ¼¹ú¼ÒÇå¾²Óë·ÀÓùίԱ»á£¨NSDC£©³Æ×Ô2ÔÂ18ÈÕÒÔÀ´£¬£¬£¬£¬ £¬£¬¸Ã¹úÕþ¸®µÄ¶à¸öÍøÕ¾Ôâµ½ÁËÀ´×Ô¶íÂÞ˹µÄDDoS¹¥»÷ ¡£¡£¡£¡£NCCCÖ¸³ö£¬£¬£¬£¬ £¬£¬ÕâЩDDoS¹¥»÷µÄ¹æÄ£ºÜ´ó£¬£¬£¬£¬ £¬£¬²¢ÇÒÃé×¼Á˹ú·ÀºÍÇå¾²ÁìÓòµÄÕþ¸®ÍøÕ¾£¬£¬£¬£¬ £¬£¬Ö÷ÒªÕë¶ÔÎÚ¿ËÀ¼Çå¾²¾Ö¡¢ÎÚ¿ËÀ¼¹ú¼ÒÇå¾²ºÍ¹ú·ÀίԱ»áµÄÍøÕ¾ÒÔ¼°ÆäËû¹ú¼Ò»ú¹¹ºÍÕ½ÂÔÆóÒµµÄÍøÕ¾ ¡£¡£¡£¡£NCCCÊÓ²ìºóÌåÏÖ£¬£¬£¬£¬ £¬£¬ºÚ¿ÍÊ×ÏÈÏòÎÚ¿ËÀ¼Õþ¸®Ð§ÀÍÆ÷ÉÏÖ²ÈëжñÒâÈí¼þÀ´½«ÆäÌí¼Óµ½½©Ê¬ÍøÂçÖУ¬£¬£¬£¬ £¬£¬ÒÔÓÃÓÚÕë¶ÔÎÚ¿ËÀ¼ÆäËûÍøÕ¾µÄ½øÒ»²½DDoS¹¥»÷ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ukraine-ddos-attacks-on-govt-sites-originated-from-russia/


4.̸ÌìÓ¦ÓÃClubhouse±£´æÎó²î£¬£¬£¬£¬ £¬£¬ÊµÊ±ÒôƵ¿É±»ÇÔÈ¡


4.png


̸ÌìÊÒÓ¦ÓóÌÐòClubhouse±£´æÎó²î£¬£¬£¬£¬ £¬£¬Óû§µÄʵʱÒôƵ¿É±»ÇÔÈ¡ ¡£¡£¡£¡£ÔÚ±¾ÖÜÄ©£¬£¬£¬£¬ £¬£¬Ò»¸öδ֪ºÚ¿ÍÇÔÈ¡Á˶à¸öClubhouse·¿¼äµÄÒôƵ²¢´«Êäµ½ÁËËûÃÇ×Ô¼ºµÄµÚÈý·½ÍøÕ¾ÖÐ ¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬ £¬£¬¸ÃºÚ¿Í¿ÉÄÜʹÓÃJavaScript¿ª·¢¹¤¾ß°ü´î½¨ÁËÆ½Ì¨£¬£¬£¬£¬ £¬£¬ÈÆ¿ªÁËClubhouseµÄÐÅÏ¢¼ÓÃÜ»úÖÆÀ´ÇÔÈ¡Êý¾Ý ¡£¡£¡£¡£Îª´Ë£¬£¬£¬£¬ £¬£¬¸Ã¹«Ë¾ÓÀÊÀեȡÁ˸úڿ͵ÄÕÊ»§£¬£¬£¬£¬ £¬£¬²¢°²ÅÅÁËеķÀ»¤²½·¥ÒÔ±ÜÃâδÀ´Ôٴα¬·¢ÀàËÆµÄ¹¥»÷ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/114891/digital-id/clubhouse-privacy-issues.html


5.VMwareÐû²¼Çå¾²¸üУ¬£¬£¬£¬ £¬£¬ÐÞ¸´vCenterÖеÄRCEÎó²î


5.png


VMwareÐû²¼Çå¾²¸üУ¬£¬£¬£¬ £¬£¬ÐÞ¸´ÁËvCenter ServerÐéÄâ»ù´¡¼Ü¹¹ÖÎÀíÆ½Ì¨ÖеÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©Îó²î ¡£¡£¡£¡£¸ÃÎó²î±»×·×ÙΪCVE-2021-21972£¬£¬£¬£¬ £¬£¬CVSSv3»ù±¾µÃ·ÖΪ9.8£¬£¬£¬£¬ £¬£¬Î»ÓÚvSphere Client£¨HTML5£©ÖУ¬£¬£¬£¬ £¬£¬¾ßÓжԶ˿Ú443µÄÍøÂç»á¼ûȨÏÞ¹¥»÷Õß¿ÉÄÜ»áʹÓøÃÎó²îÔÚÍйÜvCenter ServerµÄϵͳÉÏÒÔ²»ÊÜÏÞÖÆµÄȨÏÞÖ´ÐÐÏÂÁî ¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬£¬ÊÜÓ°ÏìµÄvRealize Operations²å¼þ±£´æÓÚËùÓÐĬÈÏ×°ÖÃÖÐ ¡£¡£¡£¡£ÓÉÓÚ´ËÇå¾²Îó²îµÄÑÏÖØÐÔ£¬£¬£¬£¬ £¬£¬VMwareÇ¿ÁÒ½¨ÒéÓû§¾¡¿ìÉý¼¶ ¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/vmware-fixes-critical-rce-bug-in-all-default-vcenter-installs/


6.CrowdStrikeÐû²¼2021ÄêÈ«ÇòÍþÐ²Ì¬ÊÆµÄÕ¹Íû±¨¸æ


6.png


CrowdStrikeÐû²¼ÁË2021ÄêÈ«ÇòÍþÐ²Ì¬ÊÆµÄÕ¹Íû±¨¸æ ¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬ £¬£¬¹©Ó¦Á´¹¥»÷¡¢ÀÕË÷Èí¼þ¡¢Êý¾ÝÀÕË÷ºÍÃñ×åÍþв±ÈÒÔÍùÈκÎʱ¼ä¶¼Ô½·¢¸»ºñ£»£»£»£»£»£»eCrime¹¥»÷£¨Í¨¹ýÊÖ¶¯²Ù×÷£©Õ¼ËùÓÐÈëÇÖµÄ79£¥£¬£¬£¬£¬ £¬£¬¶ø¹©Ó¦Á´³ÉÎªÍøÂç·¸·¨µÄÒ»¸öÊ¢ÐеÄÔØÌ壬£¬£¬£¬ £¬£¬ÓÉÓÚËüÔÊÐí¹¥»÷Õß´ÓÒ»´ÎÈëÇÖÖÐÈö²¥¶à¸öÏÂÓÎÄ¿µÄ ¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬£¬¸Ã±¨¸æ»¹ÖصãÏÈÈÝÁËÃñ×åÖ÷ÒåºÚ¿ÍÔõÑùÉøÍ¸ÍøÂç²¢ÇÔÈ¡ÓмÛÖµµÄÊý¾ÝÒÔ×·ÇóCOVID-19ÒßÃçÑо¿Ð§¹û ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.crowdstrike.com/blog/global-threat-report-foreword-2021/