Ó¢ÃÀ°Ä½áºÏ°ä²¼2020Äê³£±»ÀûÓ÷ì϶µÄ°²È«Õ÷ѯ£»×êÑÐÈËÔ±½«Åû¶Hyper-VÖдúÂëÖ´Ðзì϶µÄ¾ßÌåÐÅÏ¢
°ä²¼¹¦·ò 2021-07-301.Ó¢ÃÀ°Ä½áºÏ°ä²¼2020Äê³£±»ÀûÓ÷ì϶µÄ°²È«Õ÷ѯ

ÃÀ¹ú¡¢Ó¢¹úºÍ°Ä´óÀûÑÇÍøÂ簲ȫ»ú¹¹½áºÏ°ä²¼Ò»·Ý½áºÏÅû¶2020Äê³£±»ÀûÓ÷ì϶£¬¸ÃÕ÷ѯÔ̺¬Ã¿¸ö·ì϶µÄ¼¼Êõϸ½Ú£¬ÀýÈçÇÖº¦Ö¸±ê(IoCs)ÒÔ¼°ÕâЩ·ì϶µÄ»º½â´ëÊ©¡£Õ÷ѯָ³ö£¬2020Äê×î¾ßÕë¶ÔÐÔµÄËĸö·ì϶ӰÏìÁËÔ¶³Ì¹¤×÷¡¢vpn»ò»ùÓÚÔÆ¼¼Êõ¡£ÕâЩ·ì϶Ô̺¬Microsoft ExchangeÖеÄCVE-2021-26855ºÍCVE-2021-26857µÈ¡¢Pulse SecureÖеÄCVE-2021-22893ºÍCVE-2021-22894µÈ£¬ÒÔ¼°VMwareÖеÄCVE-2021-21985µÈ·ì϶¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/120644/hacking/top-routinely-flaws-exploited.html
2.ProofpointÅû¶ÒÁÀʺڿÍÕë¶Ô¹ú·À³Ð°üÉ̵Ĺ¥»÷»î¶¯

°²È«¹«Ë¾ProofpointÅû¶ÒÁÀʺڿÍÕë¶Ô¹ú·À³Ð°üÉ̵Ĺ¥»÷»î¶¯¡£ÕâȺºÚ¿ÍÀûÓÃÉ罻ýÌåÆ½Ì¨£¬³ö¸ñÊÇFacebook£¬ÇÔÈ¡º½¿Õ·ÀÎñ³Ð°üÉÌÔ±¹¤µÄµÇ¼ƾ֤¡£Proofpoint×êÑÐÈËÔ±Ö¸³ö£¬Õâ´Î¹¥»÷»î¶¯ÖÁÉÙ³ÖÐøÁË18¸öÔ£¬ºÚ¿Í¼Ù×°³ÉÀ´×ÔÓ¢¹úÀûÎïÆÖµÄ½¡ÃÀ²Ù¶ÍÁ·£¬Ö¸±êÊÇÃÀ¹ú¡¢Ó¢¹úºÍÅ·ÖÞµÄԼĪ200Ãû¾üÊÂÈËÔ±ÒÔ¼°º½¿Õº½ÌìºÍ³Ð°üÉÌ¡£Ä¿Ç°£¬ÓÐÖ¤¾ÝÅú×¢Õâ´Î»î¶¯ÓëTA456Óйأ¨Ò²±»³ÆÎªTortoiseshell£©£¬¶ø¸ÃÍÅ»ïÓëÒÁÀʾüʲ¿ÃÅ¡°ÒÁ˹À¼¸ïÃüÎÀ¶Ó¡±(IRGC)¹ØÏµÇ×êÇ¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/hackers-malware-aerospace-defense-contractor/
3.PKPLUGÍÅ»ïÀûÓÃжñÒâÈí¼þTHORÕë¶Ô¶«ÄÏÑǵÄ×éÖ¯

Unit 42×êÑÐÍŶӷ¢ÏÖºÚ¿ÍÍÅ»ïPKPLUGÀûÓÃжñÒâÈí¼þTHORÕëµÄ»î¶¯¡£PKPLUG(±ðÃûMustang Panda£©ÊÇÒ»¸ö¼äµý×éÖ¯£¬ÖØÒªÕë¶Ô¶«ÄÏÑǵÄÖ¸±ê¡£THORΪ¶ñÒâÈí¼þPlugXµÄ±äÌ壬Æä×îÔçÄܹ»×·Òäµ½2019Äê8Ô¡£PKPLUGʹÓÃÁËÒ»ÖÖÃûΪ¡°living off the land¡±µÄ¼¼ÊõÀ´Èƹý²¡¶¾¼ì²â²¢¶Ô×¼Microsoft Exchange·þÎñÆ÷£¬Ê×ÏÈÀûÓúϷ¨µÄ¿ÉÖ´ÐÐÎļþ£¬ÈçBITSAdmin£¬´ÓGitHub´æ´¢¿âÏÂÔØÒ»¸öÃûΪAro.datµÄÎÞº¦Îļþ¡£Aro.datÒ»µ©±»¼ÓÔØµ½ÄÚ´æÖÐ¾ÍÆðÍ·×Ô¼º½â°ü£¬²¢ÆðÍ·ÓëC2·þÎñÆ÷ͨѶ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/120636/malware/chinese-cyberspies-thor-rat.html
4.×êÑÐÈËÔ±½«Åû¶Hyper-VÖдúÂëÖ´Ðзì϶µÄ¾ßÌåÐÅÏ¢

×êÑÐÈËÔ±HarpazºÍHadar´òËãÔÚ8ÔÂ4ÈյĺÚñ°²È«»áÒéÉϽéÉÜHyper-VÖдúÂëÖ´Ðзì϶£¬ÒÔ¼°ÈôºÎʹÓÃÄÚ²¿ÍÌÍ·¨Ê½hAFL1·¢ÏÖÕâ¸ö·ì϶¡£¸Ã·ì϶¸ú×ÙΪCVE-2021-28476£¬ÆÀ·ÖΪ9.9£¬¿Éµ¼Ö»ؾø·þÎñ»òÔÚÖ÷»úÉÏÖ´ÐÐËÁÒâ´úÂë¡£ËüÔÚ2019Äê8Ô³õ´Î³öÏÖ£¬²¢ÓÚ½ñÄê5ÔÂÊÕµ½Á˲¹¶¡¡£×êÑÐÈËÔ±³Æ£¬¹ÌÈ»Azure·þÎñ²»»á³öÏÖÕâ¸öÎÊÌ⣬µ«Ò»Ð©±¾µØHyper-V²¿ÊðÒÀÈ»ÈÝÒ×Êܵ½¹¥»÷£¬¶ø´óÁ¿ÖÎÀíÔ±²¢Î´ÔÚ²¹¶¡°ä²¼Ê±¾Í¸üÐÂWindowsϵͳ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/critical-microsoft-hyper-v-bug-could-haunt-orgs-for-a-long-time/
5.IBM Security°ä²¼2021ÄêÊý¾Ýй¶³É±¾µÄ·ÖÎö»ã±¨

IBM Security°ä²¼ÁË2021ÄêÊý¾Ýй¶³É±¾µÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬»ã±¨¹À¼Æ£¬2021ÄêÆóÒµÔâ·êÒ»´ÎµäÐÍÊý¾Ýй¶±äÂÒ£¨Éæ¼°1000-10Íò±Ê¼Í¼£©µÄ³É±¾Îª424ÍòÃÀÔª£¬±È2020ÄêÓâÔ½10%¡£¶ø¶ÔÓÚÄÇЩÑϳÁµÄ±äÂÒ£¬¼Å×°ÏìÁË5000ÍòÖÁ6500Íò¼Í¼µÄ¶¥¼¶ÆóÒµ¹«Ë¾£¬Ôò±ØÒªÖ§³ö¸ü¸ßµÄ¼ÛÖµ¡ª¡ª¾ùÔÈ񻮮·Ñ4.01ÒÚÃÀÔª¡£IBM³Æ£¬Ñ¡È¡»ùÓÚÈËΪÖÇÄÜ(AI)Ëã·¨¡¢»úе½ø½¨¡¢·ÖÎöºÍ¼ÓÃܵݲȫ½â¾ö¹æ»®µÄ¹«Ë¾¶¼½µµÍÁËDZÔÚÈëÇÖËðʧ£¬¾ùÔÈΪ¹«Ë¾½Ú¼óÁË125Íòµ½149ÍòÃÀÔª¡£
ÔÎÄÁ´½Ó£º
https://www.ibm.com/security/data-breach
6.±±°®¶ûÀ¼DoH³ÆÆäCOVIDCert NI·þÎñµÄÓû§ÐÅÏ¢ÒÑй¶

±±°®¶ûÀ¼ÎÀÉú²¿(DoH)³ÆÆäCOVIDCert NI·þÎñй¶²¿ÃÅÓû§µÄÐÅÏ¢¡£COVIDCert NI·þÎñÖØÒªÓÃÓÚΪ±±°®¶ûÀ¼µÄµÄ½ÓÖÖÕßÐû¸æÈ·ÈÏÆäCOVID-19ÒßÃç½ÓÖÖ״̬µÄÊý×ÖÖ¤Ê飬¸Ã²¿ÃŰµÊ¾£¬ÔÚijЩÇé¿öϸ÷þÎñ»áÏòһЩÓû§ÏÔʾÆäËûÓû§µÄÊý¾Ý¡£Ä¿Ç°¸Ã·þÎñµÄÍøÕ¾covidcertni.nidirect.gov.ukºÍÒÆ¶¯ÀûÓö¼´¦ÓڹعØ×´Ì¬£¬¶ø±±°®¶ûÀ¼ÎÀÉú²¿ÔÚÖÂÁ¦½â¾öÕâÒ»ÎÊÌâ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/northern-ireland-suspends-vaccine-passport-system-after-data-leak/


¾©¹«Íø°²±¸11010802024551ºÅ