Cisco·¢ÏÖÀûÓÃÓòÃûǰÖü¼Êõ¶Ô×¼Ãåµéµ±¾ÖµÄ¹¥»÷»î¶¯

°ä²¼¹¦·ò 2021-11-19

Cisco·¢ÏÖÀûÓÃÓòÃûǰÖü¼Êõ¶Ô×¼Ãåµéµ±¾ÖµÄ¹¥»÷»î¶¯


Cisco·¢ÏÖÀûÓÃÓòÃûǰÖü¼Êõ¶Ô×¼Ãåµéµ±¾ÖµÄ¹¥»÷»î¶¯.png


Cisco TalosÔÚ11ÔÂ16ÈÕÅû¶ÁËÀûÓÃÐµİµ²Ø¼¼ÊõÈÆ¹ý¼ì²âµÄ¹¥»÷»î¶¯ ¡£Õâ´Î»î¶¯×î³õ·¢ÏÖÓÚ½ñÄê9Ô·Ý£¬ÀûÓÃÁËÒ»ÖÖÃûΪÓòÃûǰÖõļ¼ÊõÀ´°µ²ØC2 ¡£´Ë±í£¬¹¥»÷Õß»¹ÀûÓÃÁ˺Ϸ¨µÄ¹¤¾ßCobalt Strik£¬µ±BeaconÆô¶¯Ê±½«ÎªÍйÜÔÚCloudflareµÄºÏ·¨ÓòÌá½»DNSÒªÇ󣬶øºóÅú¸ÄºóÐøµÄHTTPsÒªÇóÍ·£¬ÒÔÅúʾCDN½«Á÷Á¿³Á¶¨Ïòµ½¹¥»÷Õß½ÚÔìµÄÖ÷»ú ¡ £»î¶¯ÖÐʹÓõĺϷ¨ÓòÃûΪÃåµéÊý×ÖÐÂÎŵÄmdn[.]gov[.]mm ¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2021/11/attackers-use-domain-fronting-technique.html


ESET·¢ÏÖÒÔÉ«ÁÐCandiruÕë¶ÔÓ¢¹úºÍÖж«µÄË®¿Ó¹¥»÷


ESET·¢ÏÖÒÔÉ«ÁÐCandiruÕë¶ÔÓ¢¹úºÍÖж«µÄË®¿Ó¹¥»÷.png


11ÔÂ16ÈÕ£¬ESETµÄ×êÑÐÈËÔ±³ÆÒÔÉ«ÁеļäµýÈí¼þCandiruÓëÕë¶ÔÓ¢¹úºÍÖж«µÄË®¿Ó¹¥»÷ÓйØ ¡£CandiruÒÑÓÚ±¾Ô±»ÃÀ¹úÉÌÎñ²¿ÁÐÈë¶ñÒâÍøÂç»î¶¯×éÖ¯Ãûµ¥ ¡£Õâ´Î»î¶¯´óÌå·ÖΪÁ½²¨£¬µÚÒ»²¨ÆðÍ·ÓÚ2020Äê3Ô£¬ÓÚ2020Äê8ÔÂʵÏÖ£¬µÚ¶þ²¨¹¥»÷ÆðÍ·ÓÚ2021Äê1ÔÂÆðÍ·£¬Ò»Ïò³ÖÐøµ½2021Äê8ÔÂÉÏÑ®£¬¹¥»÷ÁËÓ¢¹ú¡¢Ò²ÃÅ¡¢ÒÁÀÊ¡¢ÐðÀûÑÇ¡¢É³Ìذ¢À­²®¡¢Òâ´óÀûºÍÄϷǵȵØÓòµÄ×éÖ¯ ¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/11/israels-candiru-spyware-found-linked-to.html


еĴ¹µö»î¶¯¼ÙÒâTikTokÔ±¹¤ÒÔɾ³ýÕ˺ÅÀ´ÍþвÓû§


еĴ¹µö»î¶¯¼ÙÒâTikTokÔ±¹¤ÒÔɾ³ýÕ˺ÅÀ´ÍþвÓû§.png


Abnormal SecurityÔÚ11ÔÂ17ÈÕ·¢ÏÖÕë¶ÔTikTokÓû§µÄÐÂÒ»ÂÖ´¹µö»î¶¯ ¡£¹¥»÷Õß¼ÙÒâTikTokÔ±¹¤£¬ÖÒ¸æÖ¸±êÒòÆäÉæÏÓÎ¥·´Æ½Ì¨Ìõ¿î¶ø½«µ±¼´É¾³ýÕÊ»§ ¡£Ö®ºó£¬Óû§»á±»³Á¶¨Ïòµ½Ò»¸öWhatsApp̸ÌìÊÒ£¬²¢±»ÒªÇóÌṩ³ÁÖÃÕÊ»§ÃÜÂëËùÐèµÄÓʼþµØÖ·¡¢µç»°ºÅÂëºÍÒ»´ÎÐÔ´úÂë ¡£Ä¿Ç°Éв»Ã÷ÏÔ¹¥»÷ÕßµÄÖ÷ÕÅÊÇʲô£¬»òÐíÖ¼ÔÚÊÕÊÜÕË»§»òÀÕË÷ ¡£Õâ´Î»î¶¯µÄÁ½¸ö·åÖµ±ðÀëÔÚ10ÔÂ2ÈÕºÍ11ÔÂ1ÈÕ£¬Òò¶ø×êÑÐÈËÔ±´§Ä¦ÏÂÒ»Âֻ¿ÉÄÜ»áÔÚ¼¸ÖܺóÆðÍ· ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/tiktok-phishing-threatens-to-delete-influencers-accounts/


ÐÂÀÕË÷ÔËÓªÍÅ»ïMementoÀûÓÃvCenterÖеÄRCE·ì϶


ÐÂÀÕË÷ÔËÓªÍÅ»ïMementoÀûÓÃvCenterÖеÄRCE·ì϶.png


SophosÓÚ11ÔÂ18ÈÕÅû¶ÁËÀÕË÷ÔËÓªÍÅ»ïMementoµÄл ¡£¹¥»÷ÕßÀûÓÃÁËVMware vCenter Server WebÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-21971£©£¬CVSSÆÀ·ÖΪ9.8 ¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶½Ó¼ûTCP/IP¶Ë¿Ú443£¬²¢ÒÔÖÎÀíԱȨÏÞÖ´ÐкÅÁÆä²¹¶¡ÒÑÓÚ2Ô·ݰ䲼 ¡£Õâ´Î»î¶¯ÆðÍ·ÓÚÉϸöÔ£¬¹¥»÷ÕßÊ×ÏÈÀûÓÃvCenterÖеķì϶´ÓÖ¸±ê·þÎñÆ÷ÇÔÈ¡ÖÎÀíÍ´´¦£¬¶øºóʹÓÃRDP over SSHºáÏòÒÆ¶¯£¬²¢³õ´ÎÔÚ¹¥»÷ÖÐʹÓÃÁËWinRARÀ´Ñ¹ËõÎļþ²¢¶ÔÆä½øÐмÓÃÜ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-memento-ransomware-switches-to-winrar-after-failing-at-encryption/


CISA°ä²¼2021ÄêÍøÂ簲ȫÊÂÎñºÍ·ì϶µÄÓ¦¼±ÏìÓ¦Ö¸ÄÏ


CISA°ä²¼2021ÄêÍøÂ簲ȫÊÂÎñºÍ·ì϶µÄÓ¦¼±ÏìÓ¦Ö¸ÄÏ.png


11ÔÂ16ÈÕ£¬ÃÀ¹úCISA°ä²¼ÁË2021ÄêÍøÂ簲ȫÊÂÎñºÍ·ì϶µÄÓ¦¼±ÏìÓ¦Ö¸ÄÏ ¡£¸ÃÖ¸ÄÏΪÁª¹úÎÄÖ°ÐÐÕþ²¿ÃÅ£¨FCEB£©»ú¹¹ÌṩÁËÓÃÓڹ滮ºÍ·¢Õ¹ÍøÂ簲ȫÊÂÎñºÍ·ì϶ÏìÓ¦»î¶¯µÄ²Ù×÷·¨Ê½£¬²¢Í¨¹ý¾ö²ßÊ÷¾ßÌå˵ÁËÈ»ÊÂÎñºÍ·ì϶ÏìÓ¦µÄÿ¸ö²½Öè ¡£CISA¼¤Àø¹Ø¼ü»ù´¡ÉèÊ©ÓйØ×éÖ¯£¬ÖÝ¡¢´¦ËùÈ·µ±¾Ö×éÖ¯ÒÔ¼°Ë½Óª×éÖ¯ÀûÓøÃÖ¸ÄϽøÐÐÉó²é£¬ÒÔ¶ÔÆä×ÔÉíµÄ·ì϶ºÍÊÂÎñÏìӦʵ¼Ê½øÐлù×¼²âÊÔ ¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/11/16/new-federal-government-cybersecurity-incident-and-vulnerability


Kaspersky°ä²¼2022ÄêAPT¹¥»÷ÍþÐ²Ì¬ÊÆµÄÔ¤²â»ã±¨


Kaspersky°ä²¼2022ÄêAPT¹¥»÷ÍþÐ²Ì¬ÊÆµÄÔ¤²â»ã±¨.png


KasperskyÓÚ11ÔÂ17ÈÕ°ä²¼ÁË2022ÄêAPT¹¥»÷ÍþÐ²Ì¬ÊÆµÄÔ¤²â»ã±¨ ¡£»ã±¨Ö¸³ö£¬APT×éÖ¯½«´ÓÆäËû¹¥»÷ÕßÄÇÀï²É°ì³õÊ¼ÍøÂç½Ó¼ûȨÏÞ £»¸ü¶à¹ú¶È½«Ë¾·¨¸æ×´×÷ΪÆäÍøÂçÕ½ÊõµÄÒ»²¿ÃÅ £»¶ÔÍøÂçÉ豸µÄÕë¶ÔÐÔ¹¥»÷Ôö³¤ £»5G·ì϶¼´½«³öÏÖ £»¹¥»÷Õß½«³ÖÐøÀûÓÃCOVID-19Ö÷Ìâ £»Òƶ¯É豸½«Êܵ½¿í·º¹¥»÷ £»¹©¸øÁ´¹¥»÷µÄÊýÁ¿½«Ôö³¤ £»³ÖÐøÀûÓÃWFH £»METAµØÓò£¬ÓÈÆä³¤¶ÌÖÞµÄAPT»î¶¯½«Ôö³¤ ¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/advanced-threat-predictions-for-2022/104870/