¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.05.24-2021.05.30£©
2021-06-01
Ò»¡¢ Íþвͨ¸æ
VMware VCenter Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î
¡¾Ðû²¼Ê±¼ä¡¿2021-05-26 22:00:00 GMT
¡¾¸ÅÊö¡¿
2021 Äê 5 Ô 26 ÈÕ£¬AG¹«Ë¾¿Æ¼¼ CERT ¼à²âµ½ VMware ¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬ÐÞ¸´ÁË VMware vCenter Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-21985£©ºÍ vCenter Server ²å¼þÖеÄÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2021-21986£©£»ÓÉÓÚ vCenter Server ÖеIJå¼þ Virtual SAN Health Check ȱÉÙÊäÈëÑéÖ¤£¬Í¨¹ý 443 ¶Ë¿Ú»á¼û vSphere Client(HTML5)µÄ¹¥»÷Õߣ¬¿ÉÒÔ½á¹¹ÌØÊâµÄÊý¾Ý°üÔÚÄ¿µÄÖ÷»úÉÏÖ´ÐÐí§Òâ´úÂë¡£ÎÞÂÛÊÇ·ñʹÓà vSAN£¬vCenter Server ¶¼»áĬÈÏÆôÓøÃÊÜÓ°ÏìµÄ²å¼þ£¬CVSS ÆÀ·ÖΪ 9.8£¬ÇëÏà¹ØÓû§½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
Nginx DNS ÆÊÎö³ÌÐòÎó²î
¡¾Ðû²¼Ê±¼ä¡¿2021-05-26 22:00:00 GMT
¡¾¸ÅÊö¡¿
2021 Äê 5 Ô 26 ÈÕ£¬AG¹«Ë¾¿Æ¼¼ CERT ¼à²âµ½ Nginx Ðû²¼Ç徲ͨ¸æ£¬ÐÞ¸´ÁË nginx ÆÊÎöÆ÷ÖеÄÒ»¸ö DNS ÆÊÎö³ÌÐòÎó²î£¨CVE-2021-23017£©£¬ÓÉÓÚ ngx_resolver_copy()´¦Öóͷ£ DNS ÏìӦʱ±£´æ¹ýʧ £¬µ±nginx ÉèÖÃÎļþÖÐʹÓÃÁË“ resolver”Ö¸Áîʱ£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Î±ÔìÀ´×ÔDNS ·þÎñÆ÷µÄ UDP Êý¾Ý°ü£¬½á¹¹ÌØÖÆµÄ DNS ÏìÓ¦µ¼Ö 1 ×Ö½ÚÄÚ´æÁýÕÖ£¬´Ó¶øÔì³É¾Ü¾ø·þÎñ»òí§Òâ´úÂëÖ´ÐС£ÏÖÔÚÒÑÓÐϸ½ÚÐÅÏ¢Åû¶£¬ÇëÏà¹ØÓû§½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. REvil·çÔÆÔÙÆð£¬APTʽÀÕË÷±¬·¢
¡¾¸ÅÊö¡¿
2021Äê5Ô£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½REvil/SodinokibiÀÕË÷¼Ò×åµÄ¶àÆðÔ˶¯£¬REvilΪRansomware Evil£¨ÓÖ³ÆSodinokibi£©µÄËõд£¬ÊÇÒ»¸ö˽ÈËÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©×éÖ¯¡£ÓÚ2019Äê4ÔÂÊ״α»·¢Ã÷£¬ÔÚÒ»ÄêÄÚ¾ÍÒѱ»ÓÃÓÚһЩ×ÅÃûÍøÂç¹¥»÷£¬2019Äê8ÔµÄPerCSoft¹¥»÷£¬2020Äê1ÔµÄTravelexÀÕË÷Èí¼þ¹¥»÷£¬¼°2020Äê1ÔµÄGedia Automotive¹¥»÷µÈÊÂÎñ¡£½üÆÚ£¬¸Ã×éÖ¯ÈëÇÖÁËÆ»¹û¹«Ë¾µÄ¹©Ó¦ÉÌ£¬²¢ÇÔÈ¡ÁËÆ»¹û¹«Ë¾¼´½«ÍƳöµÄ²úÆ·ÉñÃØÔÀíͼ¡£´ó¶¼ÍøÂçÇ徲ר¼ÒÒÔΪ£¬REvilÊÇÒÔǰһ¸öÎÛÃûÕÑÖøµ«ÒÑÇýÖðµÄºÚ¿ÍÍÅ»ïGandCrabµÄ·ÖÖ§¡£¸ÃÍÆ²âÔ´ÓÚREvilÔÚGandCrab×èÖ¹ÔËÓªºóÁ¬Ã¦×îÏÈÔ˶¯£¬ÇÒ¶þÕßʹÓõÄÀÕË÷Èí¼þ±£´æ´ó×Ú¹²Ïí´úÂë¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYIS
2. ÒôÏì×°±¸¾ÞÍ·BoseÔâÀÕË÷Èí¼þ¹¥»÷
¡¾¸ÅÊö¡¿
Bose͸¶£¬2021Äê3ÔÂÉÏÑ®ËûÃÇÂÄÀúÁËÒ»³¡ÍøÂç¹¥»÷£¬ÆÆËðÁËһЩITϵͳ£¬²¢ÓÚ2021Äê4ÔÂ29ÈÕÈ·¶¨ÍøÂç¹¥»÷µÄÕØÊÂÕß¿ÉÄÜ»á¼ûÁËÉÙÁ¿ÄÚ²¿µç×Ó±í¸ñ£¬ÆäÖаüÀ¨ÈËÁ¦×ÊÔ´²¿·Öά»¤µÄÖÎÀíÐÅÏ¢¡£Æäʱһµ©·¢Ã÷¹¥»÷£¬BoseÆô¶¯ÁËÐëÒªµÄÊÂÎñÏìÓ¦ÐÒ飬°üÀ¨ÆäÊÖÒÕÍŶÓÒÔ±ÜÃâ¶ñÒâÈí¼þ½øÒ»²½Èö²¥£¬²¢ÔöÇ¿¶Ôδ¾ÊÚȨµÄÔ˶¯µÄ·ÀÓù¡£ÊÜ´Ë´ÎÍøÂç¹¥»÷Ó°ÏìµÄÊý¾Ý°üÀ¨Éç»áÇå¾²ºÅÂë¡¢Ô±¹¤ÐÕÃûºÍн³êÊý¾Ý¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYHY
3. Ó¡¶È×î´óº½¿Õ¹«Ë¾450ÍòÃûÂÿÍÐÅϢй¶
¡¾¸ÅÊö¡¿
2021Äê2Ô£¬Ó¡¶È×î´óº½¿Õ¹«Ë¾—Ó¡¶Èº½¿Õ¹«Ë¾£¨Air India£©µÄÂÿͷþÎñϵͳÌṩÉÌSITAÔâÓöºÚ¿Í¹¥»÷¡£Á½¸öÔºó£¬Ó¡¶Èº½¿Õ¹«Ë¾Åû¶£¬Ô¼450ÍòÂÿ͵ÄÐÅÏ¢Ôâй¶¡£Ó¡¶Èº½¿Õ¹«Ë¾³Æ£¬´Ë´Îй¶µÄÊý¾Ý¹æÄ£ÊÇ2011Äê8ÔÂÖÁ2021Äê2ÔÂʱ´ú¹ÒºÅµÄÂÿÍÊý¾Ý£¬Ð¹Â¶ÐÅÏ¢°üÀ¨ÐÕÃû¡¢ÐÅÓÿ¨Õʺ𢻤ÕÕ¡¢³öÉúÈÕÆÚ¡¢ÁªÏµÐÅÏ¢¡¢»úƱÐÅÏ¢¡¢ÐÇ¿ÕͬÃËÐÅÏ¢ÒÔ¼°Ó¡¶Èº½¿Õ³£ÓοÍÐÅÏ¢¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYHF
4. TeamTNT×éÖ¯Õë¶ÔKubernetes¼¯Èº¾ÙÐÐÈä³æÊ½¹¥»÷
¡¾¸ÅÊö¡¿
ÒÔÔÆÅÌËãÎªÖØµãµÄÃÜÂëÐ®ÖÆÍŶÓTeamTNT¾ÙÐÐÁËÈ䳿״¹¥»÷£¬¿ç¶à¸öKubernetesȺ¼¯ÆÆËðÁËԼĪ50,000¸öIP¡£TeamTNT ÊÇÒ»¸öרעÓÚÔÆµÄ¼ÓÃÜÐ®ÖÆ×éÖ¯£¬ËûÃǾ³£Õë¶ÔÊÜѬȾµÄÔÆÏµÍ³É쵀 Amazon Web Services ƾ֤ÎļþÀ´ÍÚ¾ò¼ÓÃÜÇ®±Ò Monero¡£Óɹȸ迪·¢ºÍÖ§³ÖµÄKubernetesÊǽÓÄÉ×îÆÕ±éµÄÈÝÆ÷±àÅÅÆ½Ì¨Ö®Ò»£¬ÓÃÓÚ×Ô¶¯»¯°²ÅÅ¡¢À©Õ¹ºÍÖÎÀíÈÝÆ÷»¯µÄÓ¦ÓóÌÐò¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYI7
5. ÃÀ°ü¹Ü¾ÞÍ·CNAÖ§¸¶4000ÍòÃÀÔªÀÕË÷Êê½ð
¡¾¸ÅÊö¡¿
ÃÀ¹ú×î´óµÄ°ü¹Ü¹«Ë¾Ö®Ò»CNA FinancialÒѾÏòÀÕË÷Èí¼þ×éÖ¯Ö§¸¶ÁË4000ÍòÃÀÔªµÄÊê½ð£¬Ôµ¹ÊÔÓÉÊǸù«Ë¾µÄITϵͳ±»ÀÕË÷Èí¼þËø¶¨£¬¹¥»÷Õß»¹ÇÔÈ¡ÁËÊý¾Ý¡£¾ÝϤ£¬¹¥»÷CNAµÄÀÕË÷Èí¼þ×éÖ¯PhoenixʹÓõÄÊÇEvil Corp±àдµÄHadesÀÕË÷Èí¼þµÄ±äÌå—Phoenix Locker¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYI8
6. StrRATαװ³ÉÀÕË÷Èí¼þ
¡¾¸ÅÊö¡¿
΢ÈíÖÒÑÔÒ»³¡ÐµÄÀ¬»øÓʼþÔ˶¯Ê¹ÓûùÓÚjavaµÄStrRAT¶ñÒâÈí¼þµÄ¸üбäÌ壬¸Ã¶ñÒâÈí¼þ½«×Ô¼ºÎ±×°³ÉÀÕË÷Èí¼þѬȾ£¬ÇÔÈ¡ÉñÃØÊý¾Ý£¬Ö»¹ÜËüÏÖʵÉϲ¢²»¼ÓÃÜÊý¾Ý¡£Í¬Ê±ÕâÖÖÔ¶³Ì»á¼ûľÂíÒòÆäÀàËÆÀÕË÷Èí¼þµÄÐÐΪ¶øÎÛÃûÕÑÖø£¬Ëü»á½«ÎļþÀ©Õ¹Ãû.crimson¸½¼Óµ½ÎļþÖУ¬È´²î³ØÎļþ¾ÙÐмÓÃÜ£¬¸ÃÀ©Õ¹Ãû¿ÉÒÔ±ÜÃâÓû§Ë«»÷·¿ªÎļþ£¬Ê¹¹¥»÷ÕßÄܹ»¾ÙÐпìËÙ¶ø¼òÆÓµÄÀÕË÷ʵÑ飬µ«Î¢ÈíÖ¸³ö£¬Óû§¿ÉÒÔɾ³ý¸ÃÀ©Õ¹ÃûÀ´»Ö¸´ËûÃǵÄÎļþ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYHJ
7. Æ»¹ûÐÞ²¹ÁËMacOSÖÐÔÊÐí͵ÅÄÆÁÄ»µÄÁãÈÕÎó²î
¡¾¸ÅÊö¡¿
Æ»¹ûÒѾÐÞ²¹ÁË macOS ÖеÄÒ»¸öÑÏÖØ¹ýʧ£¬¸Ã¹ýʧ¿É±»Ê¹ÓÃÀ´½ØÈ¡Ä³ÈËÅÌËã»úµÄÆÁÄ»½ØÍ¼£¬²¢ÔÚ¸ÃÈ˲»ÖªÇéµÄÇéÐÎϲ¶»ñËûÃÇÔÚÓ¦ÓóÌÐò»òÊÓÆµ¾Û»áÖеÄÔ˶¯Í¼Ïñ¡£Ñо¿Ö°Ô±ÌåÏÖ£¬ËûÃÇ·¢Ã÷ XCSSET ÌØ¹¤Èí¼þÕýÔÚʹÓøÃÎó²î£¬¸ú×ÙΪCVE-2021-30713£¬×¨ÃÅÓÃÓÚÔÚ²»ÐèÒªÌØÊâȨÏÞµÄÇéÐÎϽØÈ¡Óû§×ÀÃæµÄÆÁÄ»½ØÍ¼ £¬¸ÃÎó²îͨ¹ýÈÆ¹ý͸Ã÷Ô޳ɺͿØÖÆ£¨TCC£©¿ò¼Ü¶øÆð×÷Ó㬸ÿò¼Ü¿ØÖÆÓ¦ÓóÌÐò¿ÉÒÔ»á¼ûµÄ×ÊÔ´£¬ÀýÈçÊÚÓèÊÓÆµÐ×÷Èí¼þ¶ÔÍøÂçÉãÏñÍ·ºÍÂó¿Ë·çµÄ»á¼ûȨÏÞ£¬ÒÔ±ã¼ÓÈëÐéÄâ¾Û»á¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYHV
8. Agrius ×é֯ʹÓôÅÅ̲Á³ýÆ÷¹¥»÷ÒÔÉ«ÁÐ
¡¾¸ÅÊö¡¿
Apostle ÊÇÒ»ÖÖÆæÒìÇÒǰËùδ¼ûµÄ´ÅÅ̲Á³ý¶ñÒâÈí¼þ£¬Î±×°³ÉÀÕË÷Èí¼þ£¬¶ÔÒÔÉ«ÁеIJî±ðÄ¿µÄ·¢¶¯ÆÆËðÐÔ¹¥»÷£¬Ö÷ÒªÕë¶ÔÍøÂç»ù´¡ÉèÊ©¡£´Ë´Î¹¥»÷Ô˶¯ÓÉAgrius ºÚ¿Í×éÖ¯Ìᳫ£¬¸Ã×éÖ¯ÊÇÓëÒÁÀÊÕþ¸®Óйصģ¬Í¨³£Ê¹Óö¨ÖƵŤ¾ß¼¯ºÍÏֳɵÄÇå¾²Èí¼þÀ´°²ÅŶ¨ÖƵIJÁ³ýÆ÷¼æÀÕË÷Èí¼þ»òÆÆËðÐԵIJÁ³ýÆ÷±äÌ壬Ö÷ÒªÖØµãÊÇÊý¾ÝÆÆËðºÍÍøÂçÌØ¹¤Ô˶¯¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYHU
9. BazaLoaderαװ³ÉÓ°Ï·Á÷ýÌå·þÎñ
¡¾¸ÅÊö¡¿
BravoMoviesÍøÕ¾µÄ¹¦Ð§°üÀ¨Î±ÔìµÄÓ°Ï·º£±¨ºÍ´øÓÐFAQ³£¼ûÎÊÌâ½â´ð¡¢ÒÔ¼°¿ÉÓÃÀ´“×÷·Ï”ÕâÏî·þÎñµÄExcelµç×Ó±í¸ñ£¬µ«ËüÏÂÔØµÄÖ»ÊǶñÒâÈí¼þBazaLoader¡£BazaLoader ÊÇÒ»ÖÖ¼ÓÔØ³ÌÐò£¬ÓÃÓÚ°²ÅÅÀÕË÷Èí¼þ»òÆäËûÀàÐ͵ĶñÒâÈí¼þ£¬²¢´ÓÊܺ¦ÏµÍ³ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£BravoMovies Ô˶¯Ê¹ÓÃÈ«ÐÄÉè¼ÆµÄѬȾÁ´£¬Óë BazaLoader Á¥Êô»ú¹¹¼á³ÖÒ»Ö£¬ÕâЩÁ¥Êô»ú¹¹ÓÕʹÊܺ¦ÕßÌø¹ý¶à¸öȦÌ×ÒÔ´¥·¢¶ñÒâÈí¼þ¸ºÔØ£¬ÍþвÐÐΪÕß´ÓÒ»·âµç×ÓÓʼþ×îÏÈ£¬¸æËßÊÕ¼þÈ˳ý·Ç×÷·ÏËûÃǶԷþÎñµÄ¶©ÔÄ£¬²»È»ËûÃǵÄÐÅÓÿ¨½«±»ÊÕÈ¡Óöȣ¬ÕâÊÇËûÃÇ´ÓδǩÊð¹ýµÄ¶©ÔÄ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYI2

AG¹«Ë¾ÔÆ







