¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.3.22-3.28£©
2021-03-29
Ò»¡¢ Íþвͨ¸æ
OpenSSL¾Ü¾ø·þÎñÓëÖ¤ÊéÈÆ¹ýÎó²î£¨CVE-2021-3449¡¢CVE-2021-3450£©
¡¾Ðû²¼Ê±¼ä¡¿2021-03-26 15:00:00 GMT
¡¾¸ÅÊö¡¿
2021Äê3ÔÂ26ÈÕ£¬AG¹«Ë¾¿Æ¼¼¼à²â·¢Ã÷OpenSSLÐû²¼Ç徲ͨ¸æ£¬ÐÞ¸´ÁËOpenSSL²úÆ·ÖеÄÒ»¸ö¾Ü¾ø·þÎñÎó²îºÍÒ»¸öÖ¤ÊéÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2021-3449/CVE-2021-3450£©¡£CVE-2021-3449£ºOpenSSL TLSv1.2 ĬÈÏ¿ªÆôµÄÖØÐÉÌÖб£´æÒ»´¦¿ÕÖ¸Õë½âÒýÓ㬹¥»÷Õßͨ¹ý´Ó¿Í»§¶Ë·¢ËͶñÒâµÄÖØÐÉÌClientHelloÐÂÎſɵ¼Ö·þÎñÆ÷Íß½âºÍ¾Ü¾ø·þÎñ¡£CVE-2021-3450£ºÔÚ¿ªÆôÁËX509_V_FLAG_X509_STRICT µÄ OpenSSL·þÎñÆ÷ÉÏ£¬ÓÉÓÚOpenSSL¶ÔX.509Ö¤ÊéÁ´µÄÑéÖ¤Âß¼Öб£´æÎÊÌ⣬µ¼ÖÂÊÜÓ°ÏìµÄϵͳ½ÓÊÜÓÉ·ÇCAÖ¤Êé»òÖ¤ÊéÁ´ÊðÃûµÄÓÐÓÃÖ¤Ê飬¹¥»÷Õß¿ÉÒÔ¾ÙÐÐÖÐÐÄÈË£¨MiTM£©¹¥»÷²¢»ñÈ¡Ãô¸ÐÐÅÏ¢¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. ̨ÍåÅÌËã»úÖÆÔìÉ̺곞ÔâÀÕË÷Èí¼þ¹¥»÷
¡¾¸ÅÊö¡¿
̨ÍåÅÌËã»úÖÆÔìÉ̺곞ÔâREvilÀÕË÷Èí¼þ×éÖ¯¹¥»÷£¬¹¥»÷ÕßÒªÇóÔÚ3ÔÂ28ÈÕ֮ǰ֧¸¶Ö§¸¶5000ÍòÃÀÔªµÄ¾Þ¶î×ʽ𣬲»È»½«Ð¹Â¶ÆäÉñÃØÊý¾Ý¡£¹¥»÷Õß¿ÉÄÜͨ¹ý΢ÈíExchangeÎó²îÈëÇÖºê³žÍøÂç¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.forbes.com/sites/leemathews/2021/03/21/acer-faced-with-ransom-up-to-100-million-after-hackers-breach-network/?sh=49d011ad750f
2. SilverFishÍøÂçÌØ¹¤×éÖ¯
¡¾¸ÅÊö¡¿
SilverFishÊÇÒ»¸ö¸ß¶ÈÖØ´óµÄÍøÂçÌØ¹¤×éÖ¯£¬Õë¶ÔÌìϸ÷µØµÄÖÁ¹«Ë¾ºÍ¹«¹²»ú¹¹£¬ÖصãÄ¿µÄΪŷÃ˺ÍÃÀ¹ú¡£SilverFish×éÖ¯ÓëSolarWinds¹¥»÷¡¢EvilCorp×éÖ¯ÒÔ¼°ÆäËûһЩ×ÅÃûµÄ¶ñÒâÈí¼þÔ˶¯ÓÐ×ÅÇ×½üµÄ¹ØÏµ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.prodaft.com/m/uploads/SilverFish_TLPWHITE.pdf
3. 5G½¹µãÍøÂçÇÐÆ¬Òò±£´æÇå¾²Îó²îÒ×ÔâÊÜDoS¹¥»÷
¡¾¸ÅÊö¡¿
Çå¾²Ñо¿Ö°Ô±·¢Ã÷ÁË5GÍøÂçÇÐÆ¬ºÍÐéÄâÍøÂ繦Ч¼Ü¹¹ÖеÄÒ»¸öÖ÷ÒªÎó²î£¬ÒÑ·¢Ã÷´ËÎó²îDZÔÚµØÔÊÐíÒÆ¶¯ÔËÓªÉÌÉϲî±ðÍøÂçÇÐÆ¬Ö®¼äµÄÊý¾Ý»á¼ûºÍ¾Ü¾ø·þÎñ£¨DoS£©¹¥»÷£¬´Ó¶øÊ¹ÆóÒµ¿Í»§ÈÝÒ×Êܵ½¶ñÒâÍøÂç¹¥»÷¡£ÊÜ´ËÎó²îÓ°Ïì×î´óµÄ¹ú¼ÒºÍµØÇø£¬°üÀ¨º«¹ú¡¢Ó¢¹ú¡¢µÂ¹úºÍÃÀ¹ú¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.hackread.com/5g-vulnerability-core-network-slicing-dos-attacks/
4. Purple Foxͨ¹ýÈ䳿¹¥»÷Windows·þÎñÆ÷
¡¾¸ÅÊö¡¿
2021Äê3ÔÂ23ÈÕ£¬Çå¾²Ñо¿Ö°Ô±·¢Ã÷Purple FoxÔöÌíÁËÈ䳿Èö²¥Ä£¿é£¬Í¨¹ýɨÃè¡¢¹¥»÷ÁªÍøµÄ Windows ϵͳ¾ÙÐÐѬȾÈö²¥¡£Óë´Ëͬʱ£¬¸üеÄPurple Fox»¹´øÓÐRootkitºÍºóÃŹ¦Ð§¡£Purple FoxÕë¶ÔWindowsϵͳ¾ÙÐÐÎó²îʹÓÃÌ×¼þµÄ¿ª·¢£¬ÔÚʹÓÃÄÚ´æÆÆËðºÍȨÏÞÌáÉýÎó²îºó£¬Í¨¹ýWebä¯ÀÀÆ÷ѬȾWindowsÓû§¡£2018Ä꣬Purple Fox£¨×Ϻü£©ÔÚҰѬȾÁè¼Ý 30000 ̨ÅÌËã»úºó±»Ê״η¢Ã÷¡£Purple Foxͨ¹ýÎó²îʹÓúʹ¹ÂÚÓʼþ¾ÙÐÐÈö²¥·Ö·¢£¬×ÔÉí»¹³äµ±ÆäËû¶ñÒâÈí¼þµÄ Downloader¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.guardicore.com/labs/purple-fox-rootkit-now-propagates-as-a-worm/
5. Facebook¸ú×ÙÕë¶ÔάÎá¶û×åÈ˵Ĺ¥»÷×éÖ¯
¡¾¸ÅÊö¡¿
Facebook¶ÔÓëÖйúÓÐÁªÏµµÄÍøÂçÌØ¹¤×é֯ʹÓõÄһϵÁÐÕÊ»§¾ÙÐÐÁ˸ú×Ù£¬¸Ã×éÖ¯±»³ÆÎªEarth Empusa »òEvil Eye£¬ÒÔÔÚÆÜÉíÔÚÖйú¾³ÍâµÄάÎá¶û×åÔ˶¯¼Ò¡¢¼ÇÕߺͳֲî±ðÕþ¼ûÕßʹÓõÄ×°±¸Éϰ²ÅżàÊÓ¶ñÒâÈí¼þ£¬¹¥»÷ÕßʹÓÃPoisonCarp»òINSOMNIAµÈÌØ¹¤Èí¼þ½«ÊôÓÚάÎá¶û×åÄ¿µÄµÄiOS×°±¸×÷Ϊ¹¥»÷Ä¿µÄ ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/115956/apt/facebook-china-apt-uyghur.html
6. Black KingdomÀÕË÷Èí¼þ¹¥»÷δÐÞ²¹µÄExchange·þÎñÆ÷
¡¾¸ÅÊö¡¿
½üÆÚÇå¾²Ñо¿×¨¼Ò·¢Ã÷Ò»ÖÖÐÂÀÕË÷Èí¼þBlack KingdomÕë¶Ôxchangeµç×ÓÓʼþ·þÎñÆ÷Ìᳫ¹¥»÷Ô˶¯¡£ÉÏÖÜ£¬Çå¾²¹«Ë¾RiskIQͳ¼ÆÈÔÓÐδÐÞ²¹Áè¼Ý45Íǫ̀ÍâµØExchange·þÎñÆ÷£¬²¢ÇÒ´ó´ó¶¼Î»ÓÚÃÀ¹ú¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.inforisktoday.com/black-kingdom-ransomware-hits-unpatched-exchange-servers-a-16258
7. Sierra WirelessÎïÁªÍø¹«Ë¾ÔâÀÕË÷Èí¼þ¹¥»÷
¡¾¸ÅÊö¡¿
ÉÏÖÜ£¬ÎïÁªÍø¹«Ë¾Sierra WirelessÅû¶ÁËÀÕË÷Èí¼þ¹¥»÷£¬¸Ã¹¥»÷ÓÚ2021Äê3ÔÂ20ÈÕÏ®»÷ÁËÆäÄÚ²¿ITϵͳ£¬²¢ÖÐÖ¹ÁËÆäÉú²ú¡£Sierra WirelessÊǼÓÄôó¿ç¹úÎÞÏßͨѶװ±¸Éè¼ÆÖ°Ô±ºÍÖÆÔìÉÌ£¬×ܲ¿Î»ÓÚ¼ÓÄôó²»Áе߸çÂ×±ÈÑÇÊ¡ÀïÊ¿Âú¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/115897/malware/sierra-wireless-ransomware.html
8. Hobby LobbyÁãÊÛÉÌ138GBÃô¸ÐÐÅÏ¢Ôâй¶
¡¾¸ÅÊö¡¿
¹¤ÒÕÆ·ÁãÊÛÉÌHobby LobbyÔâÊÜÁËÔÆ´æ´¢Í°µÄ¹ýʧÉèÖã¬Ì»Â¶ÁË138GBÃô¸ÐÐÅÏ¢£¬ÆäÖаüÀ¨¿Í»§ÐÕÃû¡¢²¿·ÖÖ§¸¶¿¨ÏêϸÐÅÏ¢¡¢µç»°ºÅÂ롢ͨѶµØµãºÍµç×ÓÓʼþµØµãµÈ¿Í»§ÏêϸÐÅÏ¢£¬»¹°üÀ¨¹«Ë¾Ó¦ÓóÌÐòµÄÔ´´úÂë¡¢Ô±¹¤ÐÕÃûºÍµç×ÓÓʼþµØµã¡£
¡¾²Î¿¼Á´½Ó¡¿
https://threatpost.com/hobby-lobby-customer-data-cloud-misconfiguration/164980/
9. BlackRock¶ñÒâÈí¼þαװ³ÉClubhouseÓ¦ÓÃÇÔÊØÐÅÏ¢
¡¾¸ÅÊö¡¿
BlackRock¶ñÒâÈí¼þαװ³ÉÒôƵ̸ÌìÓ¦ÓóÌÐòClubhouseµÄAndroid°æ±¾£¬Ö¼ÔÚÇÔÈ¡Êܺ¦ÕߵĵǼƾ֤¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.hackread.com/trojan-malware-blackrock-android-clubhouse-app/
10. ¼ÓÀû¸£ÄáÑÇÖÝ¿ØÖƾÖ(SCO)ÔâÍøÂç´¹ÂÚ¹¥»÷
¡¾¸ÅÊö¡¿
ÉÏÖܵÄÍøÂç´¹ÂÚ¹¥»÷ʹ¹¥»÷Õß¿ÉÒÔ»á¼û¼ÓÀû¸£ÄáÑÇÖÝ¿ØÖƾ֣¨SCO£©µÄµç×ÓÓʼþºÍÎļþ£¬ÈëÇÖÕßÇÔÈ¡Á˳ÉǧÉÏÍòÃûÖÝÊÂÇéÖ°Ô±µÄÉç»áÇå¾²ºÅÂëºÍÃô¸ÐÎļþ£¬²¢ÏòÖÁÉÙ9,000ÃûÆäËû¹¤È˼°ÆäÁªÏµÈË·¢ËÍÁËÕë¶ÔÐÔµÄÍøÂç´¹ÂÚÐÂÎÅ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://krebsonsecurity.com/2021/03/phish-leads-to-breach-at-calif-state-controller/

AG¹«Ë¾ÔÆ







