¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.06.14-2021.06.20£©
2021-06-21
Ò»¡¢ ÈÈÃÅ×ÊѶ
1. Cosmolog KozmetikÊý¾Ýй¶£ºÊýÊ®Íò¿Í»§Êܵ½Ó°Ïì
¡¾¸ÅÊö¡¿
Cosmolog KozmetikÊÇÒ»¼ÒÍÁ¶úÆäÔÚÏßÁãÊÛÉÌ£¬ÔÚÏÕЩËùÓÐÖ÷ÒªµÄÍÁ¶úÆäµç×ÓÉÌÎñƽ̨ÉÏÔËÓª£¬°üÀ¨Trendyol¡¢HepsiburadaºÍUnishop¡£ËüÃǹé¸ñÇп˷¿Æ×È÷µÙ¿ËËùÓС£¸Ã¹«Ë¾Ö÷Ҫı»®»¤·ôÆ·ºÍÏãË®µÈÃÀÈݲúÆ·µÄÏúÊÛºÍÔËÊä¡£ËûÃÇ»¹ÒÔ“Marketlog”µÄÃûÒåÏúÊÛÆäËûÉÌÆ·
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYLA
2. ¼«¿ÍС¶Óͨ¹ýVishing¹¥»÷ÈÆ¹ýµç×ÓÓʼþÇå¾²±£»¤£¬¹¥»÷25K¸öÓÊÏä
¡¾¸ÅÊö¡¿
×î½ü£¬ÒÔ¼«¿ÍС¶ÓºÍŵ¶Ùɱ¶¾Èí¼þΪÑÚ»¤µÄÕʵ¥ºÍÊÖÒÕÖ§³Ö“vishing”¹¥»÷Àֳɵػ÷ÖÐÁË25000¸öÓÊÏ䣬ËÑË÷Êܺ¦ÕßµÄÐÅÓÿ¨ÐÅÏ¢¡£
Vishing£¨ÓïÒôÍøÂç´¹ÂÚµÄËõд£©Í¨³£°üÀ¨Í¨¹ýµç»°ÇÔÈ¡Êܺ¦ÕßµÄСÎÒ˽¼ÒÐÅÏ¢»òÁôÏÂÚ²ÆÐÔµÄÓïÒôÐÅÏ¢¡£ÔÚÕâÖÖÇéÐÎÏ£¬Õ½ÂÔ°üÀ¨Í¨¹ýµç×ÓÓʼþ·¢Ëͼٶ©µ¥ÊÕÌõ£¬È»ºó°üÀ¨µç»°ºÅÂ룬ÒԱ㓴¦Öóͷ£¶©µ¥ÍË»õ”
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYLz
3. ÔÚAPTÔ˶¯Öз¢Ã÷ÁËÐ嵀 "Victory "ºóÃÅ
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±Ëµ£¬ÎÒÃÇ·¢Ã÷ÁËÒ»¸öÕýÔÚÉñÃØ¾ÙÐеļàÊÓÐж¯£¬ÆäÄ¿µÄÊÇʹÓÃÒ»¸öÒÔǰ´Óδ¼û¹ýµÄ¶ñÒâÈí¼þÀ´¹¥»÷Ò»¸ö¶«ÄÏÑǹú¼ÒµÄÕþ¸®¡£
¾ÝCheck PointÑо¿¹«Ë¾³Æ£¬¸Ã¹¥»÷ͨ¹ý·¢Ë͸½¼ÓÁ˶ñÒâµÄWordÎĵµµÄÓã²æÊ½´¹ÂÚÓʼþ£¬À´»ñµÃϵͳµÄ³õʼ»á¼ûȨÏÞ£¬Í¬Ê±Ò²»áʹÓÃÒÑÖªµÄ΢ÈíOfficeÇå¾²Îó²î¡£Ñо¿Ö°Ô±Ëµ£¬×îÖµµÃ×¢ÖØµÄÊÇ£¬ÎÒÃÇ·¢Ã÷ÁËÒ»¸öеĺóÃÅÎļþ£¬Õâ¸öAPT×éÖ¯ÈýÄêÀ´Ò»Ö±ÔÚ¿ª·¢Õâ¸öºóÃÅ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYLD
4. UNC2465ÍøÂç·¸·¨¼¯ÍŶÔÑëÊÓ¹©Ó¦ÉÌÌᳫ¹©Ó¦Á´¹¥»÷
¡¾¸ÅÊö¡¿
MandiantÑо¿Ö°Ô±·¢Ã÷£¬±»×·×ÙΪUNC2465µÄ DARKSIDE ÀÕË÷ÍÅ»ïµÄÒ»¸ö·ÖÖ§¶ÔCCTV¹©Ó¦É̾ÙÐÐÁ˹©Ó¦Á´¹¥»÷¡£UNC2465 ±»ÒÔΪÊÇ DARKSIDE ¼¯ÍŵÄÖ÷ÒªÁ¥Êô×éÖ¯Ö®Ò»£¬Óë FireEye/Mandiant ¸ú×ÙµÄÆäËûÁ¥ÊôÍÅ»ïÒ»Æð£¬³ÆÎª UNC2628 ºÍ UNC2659¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYLr
5. 11ÒÚ¿Í»§µÄCVS¿µ½¡¼Í¼±»ÆØ¹â
¡¾¸ÅÊö¡¿
Áè¼Ý10ÒÚÌõCVS¿µ½¡¿Í»§µÄ¼Í¼±»ÁôÔÚÒ»¸öµÚÈý·½£¬Î´Í¸Â¶ÐÕÃûµÄ¹©Ó¦É̵ÄÊý¾Ý¿âÖЗ—̻¶£¬ÎÞ±£»¤£¬¿ÉÔÚÏß»á¼û¡£Ñо¿Ö°Ô±Ëµ£¬ËùÆØ¹âµÄÊý¾Ýµã¿ÉÒÔ´®ÔÚÒ»Æð£¬½¨ÉèÒ»¸ö¼«ÆäСÎÒ˽¼Ò»¯µÄ¿ìÕÕ¡£
Çå¾²Ñо¿Ô±Ò®ÀûÃ×·¸£ÀÕ£¨Jeremiah Fowler£©ÖÜËÄÔÚÍøÕ¾ÉϵÄһƪÎÄÕÂÖÐ˵£º »»¾ä»°Ëµ£¬Õâ¿ÉÄÜÊÇ»ùÓÚÔÆ´æ´¢µÄÓÖÒ»ÆðÂþÒçµÄÎóÉèÖÃÊÂÎñ£¬´Ó¶øµ¼ÖÂÄÚ²¿ÍøÂçÉÏÃô¸ÐÊý¾ÝµÄй¶¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYLC
6. Cyberium¶ñÒâÈí¼þÍйÜÓò±»ÓÃÓÚ¶à¸öMirai±äÌåÔ˶¯
¡¾¸ÅÊö¡¿
ÔÚ3ÔÂ⣬ATÍâÐÇÈËʵÑéÊÒÊӲ쵽£¬Õë¶ÔTendaÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©Îó²î CVE-2020-10987 µÄ¿ª·¢ÊµÑ鼤Ôö¡£ATÍâÐÇÈËʵÑéÊÒÐû²¼µÄÆÊÎö±¨¸æÐ´µÀ£ºÔÚ¼¸¸öСʱÄÚ£¬ÔÚ´ó×Ú¿Í»§ÖÐÊӲ쵽ÁËÕâÒ»·åÖµ¡£´ËÎó²î¿ÉÒÔͨ¹ýÇëÇóµÄURL¾ÙÐÐʶ±ð£¬ÆäÖаüÀ¨½«ÓÐÓÃÔØºÉ·ÖÅɸøÒ×Êܹ¥»÷²ÎÊý"×°±¸Ãû³Æ"µÄ"setUsbUnload"¡£´ËÓÐÓÃÔØºÉ°üÀ¨½«Ö´Ðз¾¶¸ü¸ÄΪÔÝʱλÖᢴӶñÒâÈí¼þÍйÜÒ³Ãæ»ñÈ¡Îļþ¡¢ÌṩִÐÐȨÏÞ²¢Ö´ÐÐËüµÄÂß¼¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYLn
7. ParadiseÀÕË÷Èí¼þÔ´´úÂë±»¹ûÕæ£¬¹¥»÷Õ߿ɾÙÐГ˽È˶¨ÖÆ”
¡¾¸ÅÊö¡¿
2017Äê9Ô£¬ParadiseÀÕË÷Èí¼þÊ״α»·¢Ã÷£¬Æäͨ¹ý°üÀ¨¶ñÒâIQY¸½¼þµÄ´¹ÂÚÓʼþÌᳫ¹¥»÷£¬ÕâЩ¸½¼þÏÂÔØ²¢×°ÖÃÁËÀÕË÷Èí¼þ¡£
Ö®ºó£¬¸ÃÀÕË÷Èí¼þÓÖÐû²¼Á˶à¸ö°æ±¾£¬ÓÉÓÚ×î³õµÄ°æ±¾Öк¬ÓÐȱÏÝ£¬Òò´ËÑо¿Ö°Ô±¶ÔÆä¾ÙÐÐÑо¿²¢Ðû²¼ÁËParadiseµÄ½âÃÜÆ÷¡£
È»¶ø£¬Ð°汾µÄParadise½«¼ÓÃÜÒªÁì¸ü¸ÄΪRSA£¬Õâ¾ÍʹÔÏȵĽâÃÜÆ÷“ʧЧ”ÁË£¬ÎļþÎÞ·¨ÔÙ±»Ã⺬»ìÃÜ¡£
½¨Éè×î³õ°æ±¾ParadiseÀÕË÷Èí¼þ½âÃÜÆ÷µÄMichael GillespieÌåÏÖ£¬ÏÖÒÑÐû²¼µÄParadise°æ±¾°üÀ¨£º
Paradise——½âÃÜÆ÷¿ÉÊÊÓõÄ×î³õ°æ±¾¡£
Paradise .NET——Ò»¸ö.NET°æ±¾£¬Ëü½«¼ÓÃÜË㷨ת»»ÎªÊ¹ÓÃRSA¼ÓÃÜ¡£
Paradise B29——Ò»¸ö±äÌ壬ֻ¶ÔÎļþµÄ×îºó¾ÙÐмÓÃÜ¡£
²»ÐÒµÄÊÇ£¬´Ë´Î±»Ðû²¼Ô´´úÂëµÄÊÇ.NET°æ±¾µÄParadise£¬ËüʹÓÃRSA¼ÓÃÜÎÞ·¨±»½âÃÜÆ÷ÆÆ½â¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYLl
8. ÆÏÌÑÑÀ±¬·¢ÒøÐÐÍøÂç´¹ÂÚÊÂÎñ£¬¹¥»÷ÕßʹÓùȸèµÄ¿ª·ÅÖØ¶¨Ïòʧ°ÜÀ´×èÖ¹±»·¢Ã÷
¡¾¸ÅÊö¡¿
×Ô2021Äê6ÔÂ13ÈÕÐÇÆÚÈÕ¿¢ÊÂÒÔÀ´£¬·¸·¨·Ö×ÓÕýͨ¹ýµç×ÓÓʼþÈö²¥ÐÂÒ»ÂÖð³äǧÄêBCPʵÌåµÄÍøÂç´¹ÂÚÀ˳±¡£×î½üµÄÕâÒ»Ô˶¯Ê¹ÓÃÁËGoogleÕýµ±ÏµÍ³µÄһϵÁÐÖØ¶¨Ïò£¬ÒÔ±ÜÃâÍøÂç¼à¿ØÏµÍ³¡¢·À»ðǽ¡¢SIEMÉõÖÁ¶ñÒâÈí¼þ¼ì²âϵͳ£¨Èç·À²¡¶¾ºÍEDR£©¶Ô¶ñÒâÍøÕ¾¾ÙÐмì²â¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYL9
9. ¡¾Ç徲ͷÌõ¡¿Ï®»÷ÃÀ¹úºËÎäÆ÷³Ð°üÉÌ£¬REvilÀÕË÷Èí¼þÔÙÏÂÊÖ
¡¾¸ÅÊö¡¿
¼Ìºê³ž(acer)¡¢Æ»¹û¹©Ó¦ÉÌ»·Ðñµç×Ó¡¢ÈÕ±¾¸»Ê¿¡¢È«Çò×î´óÈâÖÆÆ·¹©Ó¦ÉÌJBSµÈ¹«Ë¾ºó£¬ÃÀ¹úºËÎ乩ӦÉÌSol Oriens¹«Ë¾³ÉΪÁËREvilÀÕË÷²¡¶¾“µ¶”ϵÄÓÖÒ»¸öÊܺ¦Õß¡£
ÉÏÖÜÎåÓÐÐÂÎÅÅû¶£¬ÃÀ¹úÄÜÔ´²¿(DOE)·Ö°üÉÌÓë¹ú¼ÒºËÇå¾²¾Ö(NNSA)ÏàÖú¿ª·¢ºËÎäϵͳµÄSol Oriens¹«Ë¾ÔÚ5ÔÂÔâÓöÀÕË÷²¡¶¾¹¥»÷£¬¶øÄ»ºóÕæÐ×¾ÍÊÇÎÛÃûÕÑÖøµÄÀÕË÷Èí¼þÍÅ»ïREvil¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYL8
10. ¹«¹²Æû³µ¹©Ó¦ÉÌй¶ÁË330ÍòÃû³µÖ÷µÄÊý¾Ý
¡¾¸ÅÊö¡¿
¹«¹²Æû³µÃÀ¹ú¹«Ë¾£¨Volkswagen America£©ÉÏÖÜÌåÏÖ£¬¹«¹²Æû³µµÄÒ»¼Ò¹©Ó¦É̽«ÆäÒ»¸öϵͳ¿ª·ÅÁ˽üÁ½Ä̻꣬¶ÁË330Íò¿Í»§µÄСÎÒ˽¼ÒÊý¾Ý£¬ÕâЩ¿Í»§ÏÕЩ¶¼ÊǸù«Ë¾ºÀ»ªÆ·ÅÆAudisµÄËùÓÐÕß»òÓÐÒâÓµÓÐÕß¡£
¹«¹²Æû³µÔÚÖÂÃåÒòÖÝ˾·¨²¿³¤µÄÒ»·âÐÅÖгƣ¬ÕâÆðÎ¥¹æÊÂÎñ±¬·¢ÔÚ2019Äê8ÔÂÖÁ2021Äê5ÔÂÖ®¼ä£¬TechCrunch¼ÇÕßÔú¿Ë·»ÝËþ¿Ë£¨Zack Whittaker£©Ê×ÏÈ·¢Ã÷ÁËÕâ·âÐÅ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYKS

AG¹«Ë¾ÔÆ







