¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.05.10-2021.05.16£©
2021-05-17
Ò»¡¢ Íþвͨ¸æ
HTTP ÐÒéÕ»Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-31166£©
¡¾Ðû²¼Ê±¼ä¡¿2021-05-12 16:00:00 GMT
¡¾¸ÅÊö¡¿
5 Ô 12 ÈÕ£¬AG¹«Ë¾¿Æ¼¼¼à²âµ½Î¢Èí¹Ù·½Ðû²¼ 5 ÔÂÇå¾²¸üв¹¶¡£¬ÆäÖÐÐÞ¸´ÁËÒ»¸ö HTTP ÐÒéÕ»Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-31166£©£¬¸ÃÎó²î±£´æÓÚ HTTP ÐÒéÕ»(http.sys) µÄ´¦Öóͷ£³ÌÐòÖУ¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿Éͨ¹ýÏòÄ¿µÄÖ÷»ú·¢ËÍÌØÖÆÊý¾Ý°üÀ´¾ÙÐÐʹÓ㬴ӶøÔÚÄ¿µÄϵͳÉÏÒÔÄÚºËÉí·ÝÖ´ÐÐí§Òâ´úÂë¡£CVSS ÆÀ·ÖΪ 9.8£¬Î¢ÈíÌåÏÖ´ËÎó²î¿ÉÓÃÓÚÈä³æÊ½´«¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
΢Èí 2021Äê5ÔÂÇå¾²¸üжà¸ö²úÆ·¸ßΣÎó²î
¡¾Ðû²¼Ê±¼ä¡¿2021-05-12 16:00:00 GMT
¡¾¸ÅÊö¡¿
5 Ô 12 ÈÕ£¬Î¢ÈíÐû²¼ 5 ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË 55 ¸öÇå¾²Îó²î£¬Éæ¼° Windows¡¢Microsoft Office¡¢Exchange Server¡¢Visual Studio Code¡¢Internet Explorer µÈÆÕ±éʹÓõIJúÆ·£¬ÆäÖаüÀ¨Ô¶³Ì´úÂëÖ´ÐкÍȨÏÞÌáÉýµÈ¸ßΣÎó²îÀàÐÍ¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. ´ÓÓÍÆø¹ÜµÀ¹«Ë¾±»ÀÕË÷£¬ÆÊÎöDARKSIDEÀà×éÖ¯¶ÔÒªº¦ÐÅÏ¢»ù´¡ÉèÊ©µÄÓ°Ïì¼°Ó¦¶Ô²½·¥
¡¾¸ÅÊö¡¿
ÍâµØÊ±¼ä5ÔÂ7ÈÕ£¬ÃÀ¹ú×î´óµÄȼÓ͹ܵÀÔËÓªÉÌColonial PipelineÒòÊܵ½ÀÕË÷Èí¼þ¹¥»÷±»ÆÈ¹Ø±ÕÁËÆäÃÀ¹ú¶«²¿Ñغ£¸÷Öݹ©Ó͵ÄÒªº¦È¼ÓÍÍøÂç¡£´Ë´ÎÀÕË÷¹¥»÷ʹÃÀ¹úÈý¸öÇøÓòÊܵ½Á˶ÏÓ͵ÄÓ°Ï죬¹²Éæ¼°17¸öÖÝ¡£5ÔÂ9ÈÕ£¬Áª°îÆû³µÔËÊäÇå¾²ÖÎÀí¾Ö£¨FMCSA£©Ðû²¼ÇøÓò½ôÆÈ״̬ÉùÃ÷£¬·Å¿íÁË17¸öÖݺ͸çÂ×±ÈÑÇÌØÇø¶ÔЯ´øÆûÓÍ¡¢²ñÓÍ¡¢ÅçÆøÈ¼ÁÏºÍÆäËû¾«Á¶Ê¯ÓͲúÆ·ÔËÊä˾»úµÄ·þÎñʱ¼ä»®¶¨¡£ÔÊÐíËûÃÇÌØÊâ»ò¸üÎÞаµÄÊÂÇéʱ¼ä£¬ÒÔ¼õÇá¹ÜµÀÖÐÖ¹µ¼ÖÂÓйØÈ¼ÁÏǷȱµÄÓ°Ïì¡£BBC³Æ¶à¸öÐÂÎÅȪԴ֤ʵ£¬ÊÇÒ»¸öÃûΪDarkSideµÄÍøÂç·¸·¨ÍÅ»ï¾ÙÐÐÁË´Ë´ÎÀÕË÷¹¥»÷¡£¸ÃÍÅ»ïÔÚÖÜËÄÈëÇÖÁËColonialµÄÍøÂ磬²¢ÇÔÈ¡Á˽ü100GBµÄÊý¾Ý£¬ÒÔÍþвÈôÊDz»ÔÚÖÜÎåǰ֧¸¶Êê½ð»á½«Æä×ß©µ½»¥ÁªÍø¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYGg
2. ICEDIDÕë¶Ô½ðÈÚ»ú¹¹µÄ×îÐÂÔ˶¯
¡¾¸ÅÊö¡¿
ǰ¶Îʱ¼ä£¬AG¹«Ë¾¿Æ¼¼·üӰʵÑéÊÒ²¶»ñµ½Ò»ÅúÏàËÆ¶ÈÊ®·Ö¿¿½üµÄÑù±¾¡£ÎÒÃǶÔÕâÅúÑù±¾¾ÙÐÐÁËÒ»Á¬¸ú×Ù£¬²¢¾ÙÐÐÁËÖÜÈ«µÄÆÊÎö£¬·¢Ã÷ÆäΪICEDID×îÐÂÔ˶¯£¬±¾´ÎÔ˶¯Öй¥»÷Õßй¹ÁËÒ»ÖÖ¶ñÒâÈí¼þ¼ÓÔØÆ÷Gziploader¡£¸ÃÀàÑù±¾ÔÚ2021Äê3ÔÂÖÐÑ®×îÏÈ´ó×Ú»îÔ¾£¬Ñù±¾ÊýÄ¿Öڶ࣬Ö÷Ҫͨ¹ýÀ¬»øÓʼþ»ò´¹ÂÚÓʼþµÄ·½·¨¾ÙÐÐÈö²¥¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYGg
3. Operation TunnelSnakeʹÓúóÞÙÐÐÌØ¹¤Ô˶¯
¡¾¸ÅÊö¡¿
Operation TunnelSnake¸ß¼¶Ò»Á¬ÍþвÔ˶¯ÕýÔÚ¾ÙÐÐÖУ¬¸ÃÔ˶¯Ê¹ÓÃÒ»¸öÃûΪMoriyaµÄWindows rootkit°²ÅÅÒ»¸ö±»¶¯ºóÃÅÀ´¼àÊÓÊܺ¦Õߣ¬ÔÚÊܺ¦×éÖ¯ÄÚ²¿ÃæÏò¹«ÖڵķþÎñÆ÷ÉÏ¿ªÕ¹µÄÔ˶¯ÊÇΪÁ˼àÊÓÍøÂçÁ÷Á¿£¬²¢ÏòÊÜÓ°ÏìµÄÖ÷»ú·¢ËÍÏÂÁî¡£¾Ý¿¨°Í˹»ù±¨µÀ£¬¹¥»÷ÕßʹÓõÄÊÇÌØÈ¨Ö²ÈëÎÕâЩֲÈëÎïͨ³£±»ÓÃ×÷Çý¶¯³ÌÐò¡£Moriya Rootkit×î³õÓÚ2019Äê10ÔºÍ2020Äê5ÔÂÔÚÑÇÖ޺ͷÇÖÞµÄÇøÓòÍâ½»×éÖ¯ÍøÂçÉϱ»·¢Ã÷¡£Ñо¿Ö°Ô±Ëµ£¬ÕâЩѬȾÔÚÄ¿µÄÍøÂçÖÐÒ»Á¬Á˼¸¸öÔ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYFY
4. BabukÀÕË÷Èí¼þÍÅ»ïй¶»ªÊ¢¶Ù¾¯·½Êý¾Ý
¡¾¸ÅÊö¡¿
×î½üÓÉBabukÀÕË÷Èí¼þÍÅ»ïй¶µÄÎļþ°üÀ¨26GBµÄ¼Í¼£¬Ð¹Â¶µÄÊý¾ÝÀ´×Ô»ªÊ¢¶Ù¾¯Ô±¾Ö£¬¸Ã¾¯¾ÖÔ¸ÒâÖ§¸¶10ÍòÃÀÔªÒѱÜÃâ±»µÁÊý¾Ýй¶£¬Î´Öª×ãBabukÀÕË÷Èí¼þÍÅ»ïÒªÇóµÄ400ÍòÃÀÔªÊê½ð¡£BabukÀÕË÷Èí¼þÍÅ»ï´Ó¸Ã²¿·ÖµÄÍøÂçÖÐÇÔÈ¡Á˽ü250 GBµÄδ¼ÓÃÜÎļþ£¬¸ÃÊý¾Ý¿â°üÀ¨Ç鱨¼ò±¨¡¢ÊӲ챨¸æ¡¢¼ÍÂÉ´¦·ÖºÍ¾Ð²¶Êý¾Ý¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYG0
5. Android¶ñÒâÈí¼þð³äChromeÓ¦ÓÃÈö²¥²¡¶¾
¡¾¸ÅÊö¡¿
Õë¶ÔAndroid×°±¸µÄ¹¥»÷»á×ÔÎÒÈö²¥£¬²¢¿ÉÄÜÔì³ÉһϵÁÐË𺦡£ÔÚÒÑÍù¼¸ÖÜÄÚ£¬Ò»¸öð³äChromeÓ¦ÓõÄÐÂAndroid¶ñÒâÈí¼þÒѾÉìÕŵ½ÊýÊ®ÍòÈË¡£Õâ¿î¶ñÒâÓ¦ÓóÌÐò±»ÓÃ×÷Ò»³¡ÖØ´óÍøÂç¹¥»÷Ô˶¯µÄÒ»²¿·Ö£¬ÍþвÐÐΪÕß´ÓÊÜѬȾװ±¸Ã¿ÖÜ·¢ËÍÁè¼Ý2,000ÌõµÄSMSÐÂÎÅ£¬Ö¼ÔÚʹÓÃÒÆ¶¯ÍøÂç´¹ÂÚÇÔȡСÎÒ˽¼Ò¸ÐÃôÐÅÏ¢ºÍƾ֤¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/ruT9
6. ºÚ¿ÍÕë¶ÔʹÓÃAdobe ReaderµÄWindowsÓû§
¡¾¸ÅÊö¡¿
Adobe 2021Äê5ÔµÄÇå¾²¸üÐÂÔÚExperience Manager¡¢InDesign¡¢Illustrator¡¢InCopy¡¢Adobe Genuine Service¡¢AcrobatºÍReader¡¢Magento¡¢Creative Cloud Desktop¡¢Media Encoder¡¢MediumºÍAnimateÖÐÖÁÉÙ½â¾öÁË43¸öCVE¡£ÉÏÊöȱÏÝÖеÄ5¸öÊÇͨ¹ýZDI³ÌÐò±¨¸æµÄ¡£ÆäÖÐÒ»¸öÎÊÌâ±»×·×ÙΪCVE-2021-28550£¬ËüÊÇÒ»¸öÓ°ÏìAdobe Reader for WindowsµÄÃâ·ÑʹÓúóÄÚ´æËð»µÈ±ÏÝ£¬¸ÃȱÏÝÒÑÔÚÓÐÏ޵Ĺ¥»÷Öб»ÆÕ±éʹÓá£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYFL
7. AvaddonÀÕË÷Èí¼þ¹¥»÷ÔöÌí
¡¾¸ÅÊö¡¿
¾ÝÁª°îÊÓ²ì¾ÖFBIºÍ°Ä´óÀûÑÇÍøÂçÇå¾²ÖÐÐÄACSC³Æ£¬¹¥»÷ÕßÕýÔÚʹÓÃAvaddonÀÕË÷Èí¼þ¹¥»÷ÃÀ¹ú¡¢°Ä´óÀûÑÇºÍÆäËûµØ·½µÄ²î±ð×éÖ¯¡£ÕâЩ»ú¹¹ÖÒÑÔ˵£¬ÕýÔÚ¾ÙÐеÄÔ˶¯Õë¶ÔÖÆÔìÉÌ¡¢º½¿Õ¹«Ë¾¡¢Ò½ÁƱ£½¡»ú¹¹ºÍÆäËû»ú¹¹¡£AvaddonÀÕË÷Èí¼þ×î³õÊÇÔÚ¶íÓïºÚ¿ÍÂÛ̳ÉÏ×÷ΪһÖÖÀÕË÷Èí¼þ¼´·þÎñ²úÆ·¾ÙÐÐÍÆ¹ãµÄ£¬Ëæºó±»ÓÃÓÚÍøÂç·¸·¨Ô˶¯£¬¸ÃÀÕË÷Èí¼þͨ¹ýÍøÂç´¹ÂںͶñÒâÀ¬»øÓʼþÔ˶¯¾ÙÐÐÈö²¥£¬ÕâЩÔ˶¯ÌṩÁ˶ñÒâµÄJavaScriptÎļþ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYFM
8. WallStreetBetsÂÛ̳³ÉÔ±Òò¼ÓÃÜÇ®±ÒÕ©ÆËðʧ200ÍòÃÀÔª
¡¾¸ÅÊö¡¿
WallStreetBets (WSB)ÂÛ̳µÄ²¿·Ö³ÉÔ±³ÉΪ¼ÓÃÜÇ®±ÒÕ©ÆÔ˶¯µÄÊܺ¦Õߣ¬ÍþвÐÐΪÕßÓÕʹ¹ºÖÃÒ»ÖÖ³ÆÎªWSB FinanceµÄÐÂÐͼÓÃÜÇ®±Ò´ú±Ò£¬ÒªÇó½«Binance Coins£¨³ÆÎªBNB£©»òÒÔÌ«±Ò·¢ËÍÖÁÖ¸¶¨¼ÓÃÜÇ®±ÒÇ®°ü£¬È»ºóÓëTelegramÉϵē´ú±Ò»úеÈË”ÁªÏµ£¬ÎüÊÕWSB Finance£¬½ÓÏÂÀ´ÔÚTelegramÉϸæËßÒѾ»ã¿îµÄÈË£¬ÓÉÓÚ»úеÈËÎÊÌ⣬ÐèÒªÔٴλã³öÏàͬµÄ½ð¶î£¬²»È»½«»áʧȥ×î³õµÄͶ×Ê ¡£´Ë´ÎÕ©ÆÔ˶¯ÊÇһЩÓû§ÔâÊÜ200ÃÀÔªµÄËðʧ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/ruSN
9. ¶ñÒâÀ¬»øÓʼþÔ˶¯Ê¹ÓÃHancitorÏÂÔØCubaÀÕË÷Èí¼þ
¡¾¸ÅÊö¡¿
ÍþвÐÐΪÕßÕýÆð¾¢Ê¹ÓÃHancitorÀ´°²ÅÅCubaÀÕË÷Èí¼þ£¬´Ó¶øÆðÔ´½øÈëÄ¿µÄÍøÂ磬һµ©Êܺ¦ÕßµÄ×°±¸±»ÀÖ³ÉÈëÇÖ£¬ÈôÊÇÊê½ðÒªÇóûÓлñµÃÖª×㣬¾Í»áʹÓÃCubaÀÕË÷Èí¼þרÃŵÄÊý¾ÝÐ¹Â¶ÍøÕ¾Ðû²¼±»Ð¹Â¶µÄÊý¾Ý¡£¹Å°ÍÀÕË÷Èí¼þÖÁÉÙ´Ó2020Äê1ÔÂÆð¾Í×îÏÈ»îÔ¾£¬ÆäÔËÓªÉÌÓµÓÐDLSÍøÕ¾£¬ËûÃÇÔÚ¸ÃÍøÕ¾ÉÏÐû²¼Á˾ܾøÖ§¸¶Êê½ðµÄÊܺ¦ÕßµÄÃô¸ÐÊý¾Ý£¬Ö÷ÒªÀ´×Ô×Ôº½¿Õ¡¢½ðÈÚ¡¢½ÌÓýºÍÖÆÔìÒµ¹«Ë¾µÄÃô¸ÐÐÅÏ¢¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/ruSP
10. XcodeGhost¶ñÒâÈí¼þÓ°Ïì1.28ÒÚiOSÓû§
¡¾¸ÅÊö¡¿
×Ô2015ÄêÒÔÀ´Ò»Ö±»îÔ¾µÄÎÛÃûÕÑÖøµÄXcodeGhost¶ñÒâÈí¼þ´ó¹æÄ£Ñ¬È¾ÒÑÓ°ÏìÁË1.28ÒÚiOSÓû§¡£´ó¹æÄ£ºÚ¿ÍÈëÇÖÊÇÓÉÓÚApp StoreÖÐÌṩÁË4000¸ö¶ñÒâÓ¦ÓóÌÐò£¬Ð§¹û·¢Ã÷ÕâЩӦÓóÌÐò°üÀ¨XCodeGhost¶ñÒâÈí¼þ¡£ÍþвÐÐΪÕßʹÓÃXcodeGhostÀ´½ÓÊÜÊܺ¦ÕßµÄÒÆ¶¯×°±¸£¬Äܹ»ÇÔȡƾ֤¡¢Ð®ÖÆÓû§µÄÁ÷Á¿²¢ÇÔÈ¡iCloudÃÜÂë¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/ruTc

AG¹«Ë¾ÔÆ







