Kaspersky°ä²¼¶ñÒâÈí¼þ·ÖÎö»ã±¨£ºFarFariaÀûÓõÄÊý¾Ý¿âй¶290ÍòÓû§ÐÅÏ¢

°ä²¼¹¦·ò 2021-09-30

΢Èí·¢ÏÖÖ¼ÔÚÇÔÈ¡AD FSÖÎÀíԱʹ´¦µÄºóÃÅFoggyWeb


΢Èí·¢ÏÖÖ¼ÔÚÇÔÈ¡AD FSÖÎÀíԱʹ´¦µÄºóÃÅFoggyWeb.jpg


΢ÈíÍþвµý±¨ÖÐÐÄ(MSTIC)ÓÚ9ÔÂ27ÈÕÅû¶ÁËÖ¼ÔÚÇÔÈ¡Active DirectoryÁª³ÆÉí·ÝÑéÖ¤·þÎñ(AD FS)ÖÎÀíԱʹ´¦µÄºóÃÅFoggyWeb¡£¸Ã¶ñÒâÈí¼þÓë¶íÂÞ˹±í¹úµý±¨¾Ö(SVR)µÄºÚ¿ÍÍÅ»ïNobeliumÓйØ£¬ÀÄÓÃÁËSAMLÁîÅÆ¡£Ëü¿ÉÒÔΪ¹¥»÷Õß½ç˵µÄURIÅäÖÃHTTP¼àÌýÆ÷£¨ÕâЩURI·ÂÕÕÁËÖ¸±êAD FSʹÓõĺϷ¨URIµÄ½á¹¹£©£¬À´¼àÌý·¢Ë͵½AD FSµÄHTTP GETºÍPOSTÒªÇ󣬲¢À¹½ØÓë×Ô½ç˵URIģʽƥÅäµÄHTTPÒªÇó¡£


Ô­ÎÄÁ´½Ó£º

https://www.microsoft.com/security/blog/2021/09/27/foggyweb-targeted-nobelium-malware-leads-to-persistent-backdoor/



×êÑÐÈËÔ±·¢ÏÖÕë¶Ô²¨À¼µÄÐÂAndroidÒøÐÐľÂíERMAC


×êÑÐÈËÔ±·¢ÏÖÕë¶Ô²¨À¼µÄÐÂAndroidÒøÐÐľÂíERMAC.png


ºÉÀ¼°²È«¹«Ë¾ThreatFabric·¢ÏÖÁËÒ»ÖÖÃûΪERMACµÄÐÂAndroidÒøÐÐľÂí¡£¸Ã¶ñÒâÈí¼þ»ùÓÚCerberus£¨ÆäÔ´´úÂëÒÑÓÚ2020Äê9ÔÂÔÚºÚ¿ÍÂÛ̳¹«¿ª£©£¬ÓëBlackRock±³ºóµÄÔËÓªÉÌÓйØ¡£ÓëCerberusÏà±È£¬ERMACʹÓÃÁËBlowfish¼ÓÃÜËã·¨£¬²¢ÇÒÔÚÓëC2µÄͨѶÖÐʹÓÃÁËAES-128-CBC¼ÓÃܹ滮¡£×êÑÐÈËÔ±³Æ£¬ERMAC×Ô8ÔÂÏÂÑ®ÆðÍ·»îÔ¾£¬ÆðÍ·¼Ù×°³ÉGoogle Chrome£¬Ö®ºó»¹¼Ù×°³É¼Ù×°³É·À²¡¶¾¡¢ÒøÐкÍýÌå²¥·ÅÆ÷µÅצÓ㬿ÉÕë¶Ô378¸ö½ðÈÚÓйصÄÀûÓ÷¨Ê½¡£


Ô­ÎÄÁ´½Ó£º

https://www.threatfabric.com/blogs/ermac-another-cerberus-reborn.html



QNAP°ä²¼¸üУ¬½¨¸´QVRÖÐ3¸öÑϳÁµÄºÅÁî×¢Èë·ì϶


QNAP°ä²¼¸üУ¬½¨¸´QVRÖÐ3¸öÑϳÁµÄºÅÁî×¢Èë·ì϶.png


NASÔì×÷ÉÌQNAPÔÚ9ÔÂ27ÈÕ°ä²¼°²È«¸üУ¬½¨¸´ÁËÊÓÆµÖÎÀíϵͳQVRÖÐ3¸öÑϳÁµÄºÅÁî×¢Èë·ì϶¡£ÆäÖеÄÁ½¸ö·ì϶CVSSÆÀ·ÖΪ9.8£¬Ô¶³Ì¹¥»÷Õß¿ÉÀûÓÃÆäÔÚÖ¸±êϵͳÉÏÖ´ÐкÅÁ´Ó¶øÆëÈ«½ÚÔìÉ豸¡£Áí±íÒ»¸ö·ì϶׷×ÙΪCVE-2021-34349£¬CVSSÆÀ·ÖΪ7.2£¬ÓëÇ°ÃæÁ½¸ö·ì϶µÄ²î¾àÊÇÀûÓÃËùÐèµÄȨÏÞ·ÖÆç¡£QNAPÖ¸³ö£¬ÆäÖÐÁ½¸ö·ì϶»¹Ó°ÏìÁ˲¿ÃÅEOLÉ豸¡£Ä¿Ç°£¬Éв»Ã÷ÏÔÕâЩ·ì϶ÊÇ·ñÒѱ»ÔÚÒ°ÀûÓÃÁË¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/qnap-fixes-critical-bugs-in-qvr-video-surveillance-solution/



FarFariaÀûÓõÄÊý¾Ý¿âÅäÖÃÃýÎóй¶290Íò¸öÓû§µÄÐÅÏ¢


FarFariaÀûÓõÄÊý¾Ý¿âÅäÖÃÃýÎóй¶290Íò¸öÓû§µÄÐÅÏ¢.png


Comparitech·¢ÏÖ¶ùͯ¹ÊÊÂÊéÀûÓÃFarFariaµÄMongoDBÊý¾Ý¿âÅäÖÃÃýÎó£¬Ð¹Â¶290Íò¸öÓû§µÄÐÅÏ¢¡£×êÑÐÈËÔ±ÔÚ2021Äê8ÔÂ9ÈÕ·¢ÏÖ¸ÃÎÊÌ⣬ֱµ½9ÔÂ27ÈÕ²ÅÅû¶³öÀ´¡£Õâ´Î×ܼÆÐ¹Â¶ÁË38GBµÄÊý¾Ý£¬Ô̺¬µç×ÓÓʼþ¡¢Éí·ÝÑéÖ¤ÁîÅÆ¡¢ÃÜÂë¡¢µÇ¼ÐÅÏ¢ºÍÆäËüµÄÉ罻ýÌåÐÅÏ¢µÈ¡£Éв»Ã÷ÏÔÕâЩÊý¾ÝÊÇ·ñÒѱ»ÀûÓ㬸ÃÊý¾Ý¿âÔÚĿǰÒѱ»±£»¤ÆðÀ´¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/storybooks-for-children-app-farfaria-exposed-data/



CISAºÍNSA½áºÏ°ä²¼ÓйØÑ¡ÔñºÍ¼Ó¹ÌVPNµÄ°²È«Ö¸ÄÏ


CISAºÍNSA½áºÏ°ä²¼ÓйØÑ¡ÔñºÍ¼Ó¹ÌVPNµÄ°²È«Ö¸ÄÏ.png


ÃÀ¹úCISAºÍNSAÔÚ9ÔÂ28ÈÕ½áºÏ°ä²¼ÁËÓйØÑ¡ÔñºÍ¼Ó¹ÌVPNµÄ°²È«Ö¸ÄÏ¡£Ö¸ÄÏÖ¸³ö£¬×éÖ¯Ó¦¸Ã´ÓŵÑÔÓÅÁ¼µÄ¹©¸øÉÌÄÇÀïÑ¡Ôñ²úÆ·£¬ÓÉÓÚËûÃÇ»áÒÔ×î¿ìµÄ¿ìÂʽ¨¸´ÒÑÖª·ì϶¡£°²È«»ú¹¹³Æ£¬VPNÉ豸Äܹ»ÍøÂçÆ¾Ö¤¡¢ÓÃÀ´Ô¶³ÌÖ´ÐдúÂë¡¢¼õÈõ¼ÓÃÜÁ÷Á¿»á»°µÄ¼ÓÃÜ¡¢½Ù³Ö»á»°ÒÔ¼°¶ÁÈ¡Ãô¸ÐÐÅÏ¢£¬½¨Òé×éÖ¯ÅäÖÃÇ¿¼ÓÃܺÍÉí·ÝÑéÖ¤¡¢½öÔËÐбØÒªµÄÖ°ÄÜÒÔ¼°±£»¤ºÍ¼à¿Ø¶ÔVPNµÄ½Ó¼û¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/09/28/cisa-and-nsa-release-guidance-selecting-and-hardening-vpns



Kaspersky°ä²¼¶ñÒâÈí¼þBloodyStealerµÄ·ÖÎö»ã±¨


Kaspersky°ä²¼¶ñÒâÈí¼þBloodyStealerµÄ·ÖÎö»ã±¨.png


KasperskyÔÚ9ÔÂ27ÈÕ°ä²¼ÁËÓйضñÒâÈí¼þBloodyStealerµÄ·ÖÎö»ã±¨¡£×êÑÐÈËÔ±3Ô·ÝÔÚ°µÍøÉÏ·¢ÏÖÁËÓйضñÒâÈí¼þBloodyStealerµÄ¸æ°×£¬¼ÛÖµÊÇ700¬²¼Ò»¸öÔ£¨Ô¼10ÃÀÔª£©»ò3000¬²¼Ò»´ÎÐԲɰì¡£ËüÄܹ»ÇÔÈ¡¶à¸öÓÎϷƽ̨µÄÕÊ»§£¬Ô̺¬Steam¡¢Epic Games Store ºÍEA Origin£¬»¹ÓµÓÐÈÆ¹ý°²È«¼ì²âºÍ¶ñÒâÈí¼þ·ÖÎöµÄÖ°ÄÜ¡£»ã±¨Ö¸³ö£¬×Ô¾õÏÖÒÔÀ´£¬¸ÃľÂíÖØÒªÓÃÀ´Õë¶ÔÅ·ÖÞ¡¢À­¶¡ÃÀÖÞºÍÑÇÌ«µØÓòµÄÓû§¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/bloodystealer-and-gaming-assets-for-sale/104319/