Ó¢ÃÀ°ÄÁªºÏÐû²¼2020Äê³£±»Ê¹ÓÃÎó²îµÄÇå¾²×Éѯ£»£»£»£»£»Ñо¿Ö°Ô±½«Åû¶Hyper-VÖдúÂëÖ´ÐÐÎó²îµÄÏêϸÐÅÏ¢

Ðû²¼Ê±¼ä 2021-07-30

1.Ó¢ÃÀ°ÄÁªºÏÐû²¼2020Äê³£±»Ê¹ÓÃÎó²îµÄÇå¾²×Éѯ


1.jpg


ÃÀ¹ú¡¢Ó¢¹úºÍ°Ä´óÀûÑÇÍøÂçÇå¾²»ú¹¹ÁªºÏÐû²¼Ò»·ÝÁªºÏÅû¶2020Äê³£±»Ê¹ÓÃÎó²î£¬ £¬£¬£¬¸Ã×Éѯ°üÀ¨Ã¿¸öÎó²îµÄÊÖÒÕϸ½Ú£¬ £¬£¬£¬ÀýÈçËðº¦Ö¸±ê(IoCs)ÒÔ¼°ÕâЩÎó²îµÄ»º½â²½·¥¡£¡£¡£¡£¡£¡£¡£¡£×Éѯָ³ö£¬ £¬£¬£¬2020Äê×î¾ßÕë¶ÔÐÔµÄËĸöÎó²îÓ°ÏìÁËÔ¶³ÌÊÂÇé¡¢vpn»ò»ùÓÚÔÆÊÖÒÕ¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²î°üÀ¨Microsoft ExchangeÖеÄCVE-2021-26855ºÍCVE-2021-26857µÈ¡¢Pulse SecureÖеÄCVE-2021-22893ºÍCVE-2021-22894µÈ£¬ £¬£¬£¬ÒÔ¼°VMwareÖеÄCVE-2021-21985µÈÎó²î¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/120644/hacking/top-routinely-flaws-exploited.html


2.ProofpointÅû¶ÒÁÀʺڿÍÕë¶Ô¹ú·À³Ð°üÉ̵Ĺ¥»÷»î¶¯


2.jpg


Çå¾²¹«Ë¾ProofpointÅû¶ÒÁÀʺڿÍÕë¶Ô¹ú·À³Ð°üÉ̵Ĺ¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£ÕâȺºÚ¿ÍʹÓÃÉ罻ýÌåÆ½Ì¨£¬ £¬£¬£¬ÌØÊâÊÇFacebook£¬ £¬£¬£¬ÇÔÈ¡º½¿Õ·ÀÎñ³Ð°üÉÌÔ±¹¤µÄµÇ¼ƾ֤¡£¡£¡£¡£¡£¡£¡£¡£ProofpointÑо¿Ö°Ô±Ö¸³ö£¬ £¬£¬£¬´Ë´Î¹¥»÷»î¶¯ÖÁÉÙÒ»Á¬ÁË18¸öÔ£¬ £¬£¬£¬ºÚ¿Íαװ³ÉÀ´×ÔÓ¢¹úÀûÎïÆÖµÄ½¡ÃÀ²Ù½ÌÁ·£¬ £¬£¬£¬Ä¿µÄÊÇÃÀ¹ú¡¢Ó¢¹úºÍÅ·ÖÞµÄԼĪ200Ãû¾üÊÂÖ°Ô±ÒÔ¼°º½¿Õº½ÌìºÍ³Ð°üÉÌ¡£¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬ £¬£¬£¬ÓÐÖ¤¾ÝÅú×¢´Ë´Î»î¶¯ÓëTA456Óйأ¨Ò²±»³ÆÎªTortoiseshell£©£¬ £¬£¬£¬¶ø¸ÃÍÅ»ïÓëÒÁÀʾüʲ¿·Ö¡°ÒÁ˹À¼¸ïÃüÎÀ¶Ó¡±(IRGC)¹ØÏµÇ×½ü¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/hackers-malware-aerospace-defense-contractor/


3.PKPLUGÍÅ»ïʹÓÃжñÒâÈí¼þTHORÕë¶Ô¶«ÄÏÑǵÄ×éÖ¯


3.jpg


Unit 42Ñо¿ÍŶӷ¢Ã÷ºÚ¿ÍÍÅ»ïPKPLUGʹÓÃжñÒâÈí¼þTHORÕëµÄ»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£PKPLUG(ÓÖÃûMustang Panda£©ÊÇÒ»¸öÌØ¹¤×éÖ¯£¬ £¬£¬£¬Ö÷ÒªÕë¶Ô¶«ÄÏÑǵÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£¡£THORΪ¶ñÒâÈí¼þPlugXµÄ±äÌ壬 £¬£¬£¬Æä×îÔç¿ÉÒÔ×·Ëݵ½2019Äê8Ô¡£¡£¡£¡£¡£¡£¡£¡£PKPLUGʹÓÃÁËÒ»ÖÖÃûΪ¡°living off the land¡±µÄÊÖÒÕÀ´Èƹý²¡¶¾¼ì²â²¢Ãé×¼Microsoft ExchangeЧÀÍÆ÷£¬ £¬£¬£¬Ê×ÏÈʹÓÃÕýµ±µÄ¿ÉÖ´ÐÐÎļþ£¬ £¬£¬£¬ÈçBITSAdmin£¬ £¬£¬£¬´ÓGitHub´æ´¢¿âÏÂÔØÒ»¸öÃûΪAro.datµÄÎÞº¦Îļþ¡£¡£¡£¡£¡£¡£¡£¡£Aro.datÒ»µ©±»¼ÓÔØµ½ÄÚ´æÖоÍ×îÏÈ×Ô¼º½â°ü£¬ £¬£¬£¬²¢×îÏÈÓëC2ЧÀÍÆ÷ͨѶ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/120636/malware/chinese-cyberspies-thor-rat.html


4.Ñо¿Ö°Ô±½«Åû¶Hyper-VÖдúÂëÖ´ÐÐÎó²îµÄÏêϸÐÅÏ¢


4.jpg


Ñо¿Ö°Ô±HarpazºÍHadarÍýÏëÔÚ8ÔÂ4ÈյĺÚñÇå¾²¾Û»áÉÏÏÈÈÝHyper-VÖдúÂëÖ´ÐÐÎó²î£¬ £¬£¬£¬ÒÔ¼°ÔõÑùʹÓÃÄÚ²¿Ä£ºý³ÌÐòhAFL1·¢Ã÷Õâ¸öÎó²î¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î¸ú×ÙΪCVE-2021-28476£¬ £¬£¬£¬ÆÀ·ÖΪ9.9£¬ £¬£¬£¬¿Éµ¼Ö¾ܾøÐ§ÀÍ»òÔÚÖ÷»úÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£ËüÔÚ2019Äê8ÔÂÊ״ηºÆð£¬ £¬£¬£¬²¢ÓÚ½ñÄê5ÔÂÊÕµ½Á˲¹¶¡¡£¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬ £¬£¬£¬ËäÈ»AzureЧÀͲ»»á·ºÆðÕâ¸öÎÊÌ⣬ £¬£¬£¬µ«Ò»Ð©ÍâµØHyper-V°²ÅÅÈÔÈ»ÈÝÒ×Êܵ½¹¥»÷£¬ £¬£¬£¬¶ø´ó×ÚÖÎÀíÔ±²¢Î´ÔÚ²¹¶¡Ðû²¼Ê±¾Í¸üÐÂWindowsϵͳ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/critical-microsoft-hyper-v-bug-could-haunt-orgs-for-a-long-time/


5.IBM SecurityÐû²¼2021ÄêÊý¾Ýй¶±¾Ç®µÄÆÊÎö±¨¸æ


5.jpg


IBM SecurityÐû²¼ÁË2021ÄêÊý¾Ýй¶±¾Ç®µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬ £¬£¬£¬±¨¸æÔ¤¼Æ£¬ £¬£¬£¬2021ÄêÆóÒµÔâÓöÒ»´Îµä·¶Êý¾Ýй¶Ê¹ʣ¨Éæ¼°1000-10ÍòÌõ¼Í¼£©µÄ±¾Ç®Îª424ÍòÃÀÔª£¬ £¬£¬£¬±È2020Äêºá¿ç10%¡£¡£¡£¡£¡£¡£¡£¡£¶ø¹ØÓÚÄÇЩÑÏÖØµÄʹÊ£¬ £¬£¬£¬¼ÈÓ°ÏìÁË5000ÍòÖÁ6500Íò¼Í¼µÄ¶¥¼¶ÆóÒµ¹«Ë¾£¬ £¬£¬£¬ÔòÐèÒªÖ§¸¶¸ü¸ßµÄ¼ÛÇ®¡ª¡ªÆ½¾ù񻮮·Ñ4.01ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¡£¡£IBM³Æ£¬ £¬£¬£¬½ÓÄÉ»ùÓÚÈ˹¤ÖÇÄÜ(AI)Ëã·¨¡¢»úеѧϰ¡¢ÆÊÎöºÍ¼ÓÃܵÄÇå¾²½â¾ö¼Æ»®µÄ¹«Ë¾¶¼½µµÍÁËDZÔÚÈëÇÖËðʧ£¬ £¬£¬£¬Æ½¾ùΪ¹«Ë¾½ÚÔ¼ÁË125Íòµ½149ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.ibm.com/security/data-breach


6.±±°®¶ûÀ¼DoH³ÆÆäCOVIDCert NIЧÀ͵ÄÓû§ÐÅÏ¢ÒÑй¶


6.jpg


±±°®¶ûÀ¼ÎÀÉú²¿(DoH)³ÆÆäCOVIDCert NIЧÀÍй¶²¿·ÖÓû§µÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£COVIDCert NIЧÀÍÖ÷ÒªÓÃÓÚΪ±±°®¶ûÀ¼µÄµÄ½ÓÖÖÕß½ÒÏþÈ·ÈÏÆäCOVID-19ÒßÃç½ÓÖÖ״̬µÄÊý×ÖÖ¤Ê飬 £¬£¬£¬¸Ã²¿·ÖÌåÏÖ£¬ £¬£¬£¬ÔÚijЩÇéÐÎϸÃЧÀÍ»áÏòһЩÓû§ÏÔʾÆäËûÓû§µÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ¸ÃЧÀ͵ÄÍøÕ¾covidcertni.nidirect.gov.ukºÍÒÆ¶¯Ó¦Óö¼´¦ÓڹرÕ״̬£¬ £¬£¬£¬¶ø±±°®¶ûÀ¼ÎÀÉú²¿ÕýÔÚÆð¾¢½â¾öÕâÒ»ÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/northern-ireland-suspends-vaccine-passport-system-after-data-leak/