¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.3.1-3.7£©
2021-03-08
Ò»¡¢ Íþвͨ¸æ
΢ÈíExchange¶à¸ö¸ßΣÎó²î
¡¾Ðû²¼Ê±¼ä¡¿2021-03-03 09:00:00 GMT
¡¾¸ÅÊö¡¿
2021Äê3ÔÂ2ÈÕ£¬AG¹«Ë¾¿Æ¼¼¼à²âµ½Î¢ÈíÐû²¼Exchange ServerµÄ½ôÆÈÇå¾²¸üУ¬ÐÞ¸´ÁË7¸öÏà¹ØÎó²î£¬Exchange·þÎñ¶ËÇëÇóαÔìÎó²î£¨CVE-2021-26855£©£ºÎ´¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»½á¹¹HTTPÇëÇóɨÃèÄÚÍø²¢Í¨¹ýExchange Server¾ÙÐÐÉí·ÝÑéÖ¤¡£Exchange·´ÐòÁл¯Îó²î£¨CVE-202126857£©£º¾ßÓÐÖÎÀíԱȨÏ޵Ĺ¥»÷Õß¿ÉÒÔÔÚExchange·þÎñÆ÷ÉÏÒÔSYSTEMÉí·ÝÔËÐÐí§Òâ´úÂë¡£Exchangeí§ÒâÎļþдÈëÎó²î£¨CVE-2021-26858/CVE-2021-27065£©£º¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔʹÓÃÎó²î½«ÎļþдÈë·þÎñÆ÷ÉϵÄí§ÒâĿ¼£¬¿ÉÍŽáCVE-2021-26855¾ÙÐÐ×éºÏ¹¥»÷¡£¼°3¸öExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-26412/CVE-2021-26854/CVE-2021-27078£©¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
Apache Tomcat Session·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î£¨CVE-2021-25329£©
¡¾Ðû²¼Ê±¼ä¡¿2021-03-02 15:00:00 GMT
¡¾¸ÅÊö¡¿
2021Äê3ÔÂ1ÈÕ£¬AG¹«Ë¾¿Æ¼¼¼à²âµ½ApacheÈí¼þ»ù½ð»áÐû²¼Ç徲ͨ¸æ£¬ÐÞ¸´ÁËÒ»¸öͨ¹ý»á»°³¤ÆÚÐÔ¾ÙÐÐRCEµÄÎó²î£¬´ËÎó²îΪCVE-2020-9484µÄ²¹¶¡Èƹý£¬ÈôÊÇʹÓÃÁËTomcatµÄsession³¤ÆÚ»¯¹¦Ð§£¬²»Çå¾²µÄÉèÖý«µ¼Ö¹¥»÷Õß¿ÉÒÔ·¢ËͶñÒâÇëÇóÖ´ÐÐí§Òâ´úÂë¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. HAFNIUM×éÖ¯Õë¶ÔÓÐÁãÈÕÎó²îʹÓõÄExchange Server
¡¾¸ÅÊö¡¿
MicrosoftÒѼì²âµ½¶à¸öÁãÈÕÎó²î£¬¿ÉÓÃÓÚÔÚÓÐÏÞÇÒÓÐÕë¶ÔÐԵĹ¥»÷ÖжÔMicrosoft Exchange ServerµÄÍâµØ°æ±¾¾ÙÐй¥»÷¡£ÔÚÊӲ쵽µÄ¹¥»÷ÖУ¬ÍþвÐж¯ÕßʹÓÃÕâЩÎó²î»á¼ûÁËÍâµØExchange·þÎñÆ÷£¬´Ó¶ø¿ÉÒÔ»á¼ûµç×ÓÓʼþÕÊ»§£¬²¢ÔÊÐí×°ÖÃÆäËû¶ñÒâÈí¼þÒÔÔö½ø¶ÔÊܺ¦ÕßÇéÐεĺã¾Ã»á¼û¡£´Ë´ÎÔ˶¯¹é¹¦ÓÚHAFNIUM£¬¸Ã×éÖ¯Ö÷ÒªÕë¶ÔÃÀ¹ú¶à¸öÐÐÒµµÄʵÌ壬°üÀ¨Ñ¬È¾²¡Ñо¿Ö°Ô±¡¢×´Ê¦ÊÂÎñËù¡¢¸ßµÈ½ÌÓý»ú¹¹¡¢¹ú·À³Ð°üÉÌ¡¢Õþ²ßÖÇÄÒÍźͷÇÕþ¸®×éÖ¯¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/
2. ¾«×¼¶ÌÐÅ´¹ÂÚÆµ·¢£¬ÒÑÓжà¸öÒøÐÐÓû§ÖÐÕÐ
¡¾¸ÅÊö¡¿
2021Äê1ÔÂÖÁ½ñ£¬AG¹«Ë¾¿Æ¼¼Ó¦¼±ÏìÓ¦ÍŶӼà²âµ½Ìì϶à¸öÊ¡·Ý·ºÆð¶àÆð·ÂÃ°ÒøÐÐÓòÃûµÄ¶ÌÐÅ´¹ÂÚÊÂÎñ£¬ÆäÖд¹Âھ籾¡¢¹¥»÷ÊÖ·¨¼°´¹ÂÚÍøÕ¾Ò³Ãæ¾ù¸ß¶ÈÏàËÆ£¬¿É»ù±¾È·ÈÏÊÇͳһºÚ²úÍÅ»ïËùΪ¡£´¹ÂÚ¶ÌÐųÆÊܺ¦ÕßÊÖ»úÒøÐм´½«ÓâÆÚ»òÕË»§±»¶³½á£¬²¢¸½´ø·ÂðµÄ´¹ÂÚÍøÕ¾ÓòÃû¡£´¹ÂÚÍøÕ¾ÓëÄ¿µÄÊÖ»úÒøÐеǼ½çÃæ¸ß¶ÈÏàËÆ£¬²¢ÓÕµ¼Óû§ÊäÈëÉí·ÝÖ¤ºÅ¡¢ÊÖ»úºÅ¡¢ÊÖ»úÒøÐеǼÃÜÂë¡¢¶ÌÐÅÑéÖ¤Âë¡¢ÉúÒâÃÜÂëµÈÃô¸ÐÐÅÏ¢¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
3. ÒÔÀ¶¾üÊӽǸú×ÙºÍÆÊÎöCANVAS¹¥»÷¿ò¼Üй¶ÊÂÎñ
¡¾¸ÅÊö¡¿
3ÔÂ3ÈÕ£¬AG¹«Ë¾¿Æ¼¼Ñо¿ÍŶÓÔÚ¶ÔÍøÂçÇå¾²ÊÂÎñÓßÇé¼à¿ØÖз¢Ã÷ÖøÃûµÄÉÌÒµÉøÍ¸¿ò¼ÜCANVASϵͳԴ´úÂ뱬·¢Ð¹Â¶£¬AG¹«Ë¾¿Æ¼¼M01NÀ¶¾üÑо¿ÍŶӵÚһʱ¼ä¶Ô¸ÃÊÂÎñ¾ÙÐÐÁ˸ú×Ù£¬¿ìËÙÆÊÎöÁËCANVASµÄ¹¥»÷¿ò¼Ü¡¢ËùÉæ¼°µÄÎó²îºÍÊÖÒÕϸ½Ú¡£
¡¾²Î¿¼Á´½Ó¡¿
https://mp.weixin.qq.com/s/eQ-KDMoirOwx-pFxUcNjtQ
4. Å£½ò´óѧCOVID-19ʵÑéÊÒ±»ºÚ¿Í¹¥»÷
¡¾¸ÅÊö¡¿
Å£½ò´óѧÑо¿ÉúÎïѧҪÁìÒÔ¶Ô¿¹COVID-19µÄʵÑéÊÒÒѳÉΪºÚ¿Í¾ÙÐÐÍøÂç¹¥»÷Ô˶¯µÄÄ¿µÄ¡£Å£½ò´óѧ½²»°ÈË֤ʵ£¬±»ºÚ¿ÍÈëÇֵĸÃÉúÎïʵÑéÊÒϵͳ²»°üÀ¨Èκλ¼ÕßÊý¾Ý£¬²¢ÇÒ²»ÇÖÕ¼»¼ÕßµÄÉñÃØÐÔ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.welivesecurity.com/2021/02/26/oxford-university-covid19-laboratory-hack/
5. GenuGate·À»ðǽҪº¦Éí·ÝÈÆ¹ýÎó²îÒÑÐÞ¸´
¡¾¸ÅÊö¡¿
×ܲ¿Î»Óڵ¹úµÄÍøÂçÇå¾²¹«Ë¾GenuaÒÑÕë¶ÔGenuGate·À»ðǽÖеÄÑÏÖØÈ±ÏÝѸËÙ¾ÙÐÐÁËÐÞ¸´¡£ÈôÊÇʹÓôËÎó²î£¬ÔòÍâµØ¹¥»÷Õß¿ÉÄÜ»áÈÆ¹ýÉí·ÝÑéÖ¤²½·¥£¬²¢ÒÔ×î¸ß¼¶±ðµÄÌØÈ¨µÇ¼µ½¹«Ë¾ÄÚ²¿ÍøÂç¡£
¡¾²Î¿¼Á´½Ó¡¿
https://threatpost.com/firewall-critical-security-flaw/164347/
6. PrismHRÔâÀÕË÷Èí¼þ¹¥»÷
¡¾¸ÅÊö¡¿
PrismHRÊÇÒ»¼ÒÒÔ×ÊÖú80,000¶à¼ÒСÐÍÆóÒµÖÎÀíÈËΪ¡¢¸£ÀûºÍÈËÁ¦×ÊÔ´µÄ¹«Ë¾£¬¸Ã¹«Ë¾¿ËÈÕÔâÊÜÁËÒ»Á¬µÄÀÕË÷Èí¼þ¹¥»÷£¬ÑÏÖØÓ°Ïì¶àÏîÓªÒµÕý³£¾ÙÐС£
¡¾²Î¿¼Á´½Ó¡¿
https://krebsonsecurity.com/2021/03/payroll-hr-giant-prismhr-hit-by-ransomware/
7. RyukÀÕË÷Èí¼þа汾¿É¾ÙÐÐÈ䳿״µÄ×ÔÎÒÈö²¥
¡¾¸ÅÊö¡¿
RyukÀÕË÷Èí¼þа汾Äܹ»ÔÚÍâµØÍøÂçÖÐͨ¹ýSMB¹²ÏíºÍ¶Ë¿ÚɨÃè¾ÙÐÐ×ÔÎÒ¸´ÖÆ£¬²¢¶ÁÈ¡ÊÜѬȾװ±¸µÄµØµãÆÊÎöÐÒ飨ARP£©±í£¬¸Ã±í´æ´¢ÁËÓëÅÌËã»úͨѶµÄÈκÎÍøÂç×°±¸µÄIPµØµãºÍMACµØµã¡£
¡¾²Î¿¼Á´½Ó¡¿
https://threatpost.com/ryuk-ransomware-worming-self-propagation/164412/
8. ͨÓÃÒ½ÁÆ·þÎñ¹«Ë¾(UHS)Ôâ¹¥»÷ºóÃæÁÙ¾Þ¶îËðʧ
¡¾¸ÅÊö¡¿
ÔÚ2020Äê9ÔÂ-10ÔÂʱ´úÕë¶ÔͨÓÃÒ½ÁÆ·þÎñ¹«Ë¾£¨UHS£©µÄÍøÂç¹¥»÷ÊÂÎñʹ¸Ã¹«Ë¾ÔâÊÜÁ˸ߴï6700ÍòÃÀÔªµÄËðʧ£¬¸Ã¹«Ë¾ÊÇÃÀ¹ú×î´óµÄÒ½ÁÆÖÎÀí¹«Ë¾Ö®Ò»£¬±¨µÀÖ¸³ö¸Ã´ÎÍøÂç¹¥»÷µÄ×ï¿ý×ï¿ýÊÇRyukÀÕË÷Èí¼þ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://threatpost.com/post-cyberattack-universal-health-services-faces-67m-in-losses/164424/
9. ClopÀÕË÷Èí¼þÍÅ»ïй¶´ÓÍøÂçÇå¾²¹«Ë¾QualysÇÔÈ¡µÄÊý¾Ý
¡¾¸ÅÊö¡¿
ClopÀÕË÷Èí¼þÍÅ»ïʹÓÃÁËAccellion FTA·þÎñÆ÷ÖеÄÁãÈÕÎó²îÇÔÈ¡ÍøÂçÇå¾²¹«Ë¾QualysµÄÊý¾Ý£¬²¢ÔÚÆäй¶վµãÉϹ²ÏíÁ˱»µÁÎļþµÄ½ØÍ¼ÐÅÏ¢£¬Ð¹Â¶µÄÊý¾Ý°üÀ¨·¢Æ±¡¢²É¹º¶©µ¥¡¢Ë°µ¥ºÍɨÃ豨¸æµÈ£¬Êܵ½Í¬Ñù¹¥»÷µÄÉÐÓÐÐÂÄÏÍþ¶ûÊ¿ÖݵÄÔËÊ乫˾ºÍÅӰ͵Ϲ«Ë¾¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/115250/data-breach/qualys-clop-ransomware.html
10. 2100ÍòÃâ·ÑVPNÓû§Êý¾ÝÔâй¶
¡¾¸ÅÊö¡¿
Áè¼Ý2100ÍòÒÆ¶¯VPNÓ¦ÓóÌÐòÓû§µÄÏêϸƾ֤ÔÚÍøÉϳöÊÛ£¬Êý¾Ý°üÀ¨µç×ÓÓʼþµØµã¡¢Ëæ»úÌìÉúµÄÃÜÂë×Ö·û´®¡¢¸¶¿îÐÅÏ¢ÒÔ¼°ÊôÓÚÈý¸öVPNÓ¦ÓóÌÐò£¨SuperVPN¡¢GeckoVPNºÍChatVPN£©Óû§µÄ×°±¸ID¡£
¡¾²Î¿¼Á´½Ó¡¿
https://blog.malwarebytes.com/cybercrime/privacy/2021/03/21-million-free-vpn-users-data-exposed/

AG¹«Ë¾ÔÆ







