¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.10.11-2021.10.17£©
2021-10-19
Ò»¡¢ Íþвͨ¸æ
΢Èí10ÔÂÇå¾²¸üжà¸ö²úÆ·¸ßΣÎó²î£¨CVE-2021-40461¡¢CVE-2021-38672¡¢CVE-2021-40449£©
¡¾Ðû²¼Ê±¼ä¡¿2021-10-13 18:00:00 GMT
¡¾¸ÅÊö¡¿
10ÔÂ13ÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½Î¢ÈíÐû²¼10ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË81¸öÇå¾²ÎÊÌâ£¬Éæ¼°Windows¡¢Microsoft Office¡¢Microsoft Visual Studio¡¢Exchange ServerµÈÆÕ±éʹÓõIJúÆ·£¬ÆäÖаüÀ¨È¨ÏÞÌáÉý¡¢Ô¶³Ì´úÂëÖ´ÐеȸßΣÎó²îÀàÐÍ¡£±¾ÔÂ΢ÈíÔ¶ȸüÐÂÐÞ¸´µÄÎó²îÖУ¬ÑÏÖØË®Æ½ÎªÒªº¦£¨Critical£©µÄÎó²îÓÐ3¸ö£¬Ö÷Òª£¨Important£©Îó²îÓÐ70¸ö£¬ÆäÖаüÀ¨4¸ö0dayÎó²î£ºWin32k ȨÏÞÌáÉýÎó²î£¨CVE-2021-40449£©¡¢Windows DNS Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-40469£©¡¢Windows Kernel ȨÏÞÌáÉýÎó²î£¨CVE-2021-41335£©ºÍWindows AppContainer ·À»ðǽ¹æÔòÇå¾²¹¦Ð§ÈƹýÎó²î£¨CVE-2021-41338£©¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. Mykings½©Ê¬ÍøÂçͨ¹ýÍÚ¿óÔ˶¯ÖÁÉÙ׬Ǯ2470ÍòÃÀÔª
¡¾¸ÅÊö¡¿
¾ÝÑо¿±¨¸æÏÔʾ£¬ÌìÌìÔ¼ÓÐ4700¸öÐÂϵͳ±»½©Ê¬ÍøÂçѬȾ¡£MyKingsÒ²±»³ÆÎªSmominru»òXaxmen£¬Ö÷Òª¾ÙÐмÓÃÜÇ®±ÒÍÚ¿óÔ˶¯£¬Í¨³£Ãé׼δʵʱÐÞ²¹µÄϵͳ£¬ËüʹÓöàÖÖ·½·¨¾ÙÐÐÈö²¥£¬ÈçÏòÊܺ¦ÕßµÄÊìÈË·¢ËÍËÀÃûΪ“ÕÕÆ¬”ʵΪ¶ñÒâÈí¼þµÄ¾ßÓÐÒÉ»óÐÔµÄ.rar»ò.zipÎļþ£¬ÔÙÈçÔÚÊ¢ÐиèÊÖÌ©Àշ˹Íþ·òÌØ£¨Taylor Swift£©µÄ Jpeg ͼÏñÄÚÒþ²Ø¶ñÒâ.exe¡£ÔÚÀÖ³ÉѬȾºó£¬Mykings»á½ÓÄɶàÖÖ·½·¨¾ÙÐг¤ÆÚ»¯ÊµÏÖºã¾ÃפÁô£¬È磺ÕûÀíÆäËûľÂí¡¢Ð¶ÔØÉ±¶¾Èí¼þ¡¢¹Ø±Õϵͳ×Ô¸üС¢¹Ø±ÕWindows Defender¡¢×èÖ¹139¡¢445µÈ¶Ë¿ÚÅþÁ¬¡¢Ìí¼Ó×¢²á±íÆô¶¯ÏîµÈÓë´ËͬʱÐÂѬȾµÄ×°±¸Ò²»á³ÉΪ¹¥»÷ÆäËûϵͳµÄÌø°å¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMWr
2. ¹¥»÷ÕßʹÓÃÐÂÐÍÑÖÂÞÍõÀÕË÷Èí¼þ¸ß¶ÈÕë¶ÔÐÔ¹¥»÷´óÐÍÆóÒµ
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»ÖÖеÄÀÕË÷Èí¼þ£¬³ÆÎª Yanluowang£¬ÓÃÓÚ¶ÔÆóÒµ¾ÙÐи߶ÈÕë¶ÔÐԵĹ¥»÷¡£Í¬Ê±×¢Öص½Ê¹ÓÃÕýµ±µÄ AdFind ÏÂÁîÐÐ Active Directory ÅÌÎʹ¤¾ß£¬¸Ã¹¤¾ß¾³£±»ÀÕË÷Èí¼þÔËÓªÉÌÀÄÓÃ×÷ΪÕì̽¹¤¾ß¡£¹¥»÷ÕßÔÚ°²Åŵ½ÊÜѬȾװ±¸Ö®Ç°£¬¹¥»÷Õß»áÏÈÆô¶¯Ò»¸ö¶ñÒ⹤¾ß£¬¸Ã¹¤¾ßÏÈͨ¹ý½¨ÉèÒ»¸ö .txt Îļþ£¬ÆäÖаüÀ¨ÒªÔÚÏÂÁîÐÐÖмì²éµÄÔ¶³Ì»úеÊý£¬ÔÙʹÓà Windows Management Instrumentation (WMI) »ñÈ¡ÔÚ .txt ÎļþÖÐÁгöµÄÔ¶³ÌÅÌËã»úÉÏÔËÐеÄÀú³ÌÁÐ±í£¬×îºó½«ËùÓÐÀú³ÌºÍÔ¶³Ì»úеÃû³Æ¼Í¼µ½ processes.txt¡£¹¥»÷ÕßÔÚ°²ÅÅÑÏÂåÍøÀÕË÷Èí¼þºó£¬Ëü½«×èÖ¹ÖÎÀí³ÌÐòÐéÄâ»ú£¬¿¢ÊÂÉÏÊö¹¤¾ß£¨°üÀ¨ SQL ºÍ±¸·Ý½â¾ö¼Æ»® Veeam£©¼Í¼µÄËùÓÐÀú³Ì£¬È»ºó¶ÔÎļþ¾ÙÐмÓÃÜ¡£ÀÕË÷Èí¼þ½« .yanluowang À©Õ¹Ãû¸½¼Óµ½¼ÓÃÜÎļþµÄÎļþÃû½ø¶øÊµÑé¹¥»÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMWn
3. »ªÎªÔƳÉΪ¼ÓÃÜÇ®±ÒÍÚ¿ó¶ñÒâÈí¼þµÄÐÂÄ¿µÄ
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±×î½ü×¢ÖØµ½Ò»ÖÖÈ«Ð嵀 Linux ¶ñÒâÈí¼þ¹¥»÷£¬ËüÕë¶ÔÏà¶Ô½ÏеÄÔÆ·þÎñÌṩÉÌ (CSP) ¾ÙÐмÓÃÜÇ®±ÒÍÚ¾ò¶ñÒâÈí¼þºÍ¼ÓÃÜÐ®ÖÆ¹¥»÷¡£¹¥»÷Õ߻ᰲÅÅ´úÂëÀ´É¾³ýÖ÷Òª±£´æÓÚ»ªÎªÔÆÖеÄÓ¦ÓóÌÐòºÍ·þÎñ¡£ÏêϸÀ´Ëµ£¬¶ñÒâ´úÂë»á½ûÓà hostguard ·þÎñ£¬ÕâÊÇÒ»¸ö“¼ì²âÇå¾²ÎÊÌâ¡¢±£»¤ÏµÍ³²¢¼à¿ØÊðÀ픵ĻªÎªÔÆ Linux ÊðÀíÀú³Ì¡£¶ñÒâ´úÂ뻹°üÀ¨cloudResetPwdUpdateAgent£¬ÕâÊÇÒ»¸ö¿ªÔ´²å¼þÊðÀí£¬ÔÊÐí»ªÎªÔÆÓû§ÖØÖõ¯ÐÔÔÆ·þÎñ£¨ECS£©ÊµÀýµÄÃÜÂ룬¸ÃʵÀýĬÈÏ×°ÖÃÔÚ¹«¹²¾µÏñÉÏ¡£ÓÉÓÚ¹¥»÷ÕßÔÚÆä shell ¾ç±¾Öб£´æÕâÁ½Ïî·þÎñ£¬ÎÒÃÇ¿ÉÒÔ¼ÙÉèËûÃÇרÃÅÕë¶Ô»ªÎªÔÆÄÚµÄÒ×Êܹ¥»÷µÄ ECS ʵÀý¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMWp
4. ¹¥»÷ÕßÓÃÊýѧ·ûºÅÈÆ¹ý·´´¹ÂÚ¼ì²â¾ÙÐй¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±Ñо¿Ö°Ô±ÌåÏÖ×÷ΪһÖÖ¹ÅÀϵÄÍøÂç¹¥»÷ÊֶΣ¬´¹ÂÚÓʼþÊÇÆóÒµºÍСÎÒ˽¼Ò×î³£Óö¼ûµÄÍøÂçÍþв֮һ£¬ÃæÁÙÈÕ񾮵·¢µÄ´¹ÂÚÓʼþ¹¥»÷£¬²»ÉÙÆóÒµ×îÏȰ²ÅÅÖÖÖÖ·´´¹ÂÚÓʼþµÄ¹¤¾ßÏ¢Õù¾ö¼Æ»®£¬¶ø¹¥»÷ÕßÃÇÔòÊÇÏ뾡²½·¥À´¹æ±ÜÕâЩ·´´¹ÂÚÓʼþ¼ì²â¡£¿ËÈÕ£¬Ñо¿Ö°Ô±·¢Ã÷ij´¹ÂÚÓʼþ×é֯ʹÓÃÊý×Ö·ûºÅÀ´×ÌÈÅ·´´¹ÂÚÓʼþ¼ì²â£¬ËüµÄ½¹µãÊÇʹÓÃÖÖÖÖÊý×Ö·ûºÅÌæ»»¹«Ë¾logo»òÃû×ÖÖеÄ×Öĸ£¬µÖ´ï“ÓÕÆ”·´´¹ÂÚÓʼþ»ò·´À¬»øÓʼþ²úÆ·µÄÄ¿µÄ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMWA
5. BlackTech×é֯ʹÓöñÒâÈí¼þGh0stTimes¶Ô·þÎñÆ÷¾ÙÐй¥»÷
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬Ñо¿Ö°Ô±·¢Ã÷ÁËBlackTech¿ÉÄÜʹÓõĶñÒâÈí¼þGh0stTimes£¬BlackTechÊÇÒ»¸öÍøÂçÌØ¹¤×éÖ¯£¬ÔÚ2018Äêǰºó¶ÔÈÕ±¾Ìᳫ¹¥»÷Ô˶¯¡£Ñо¿Ö°Ô±Í¬Ê±ÔÚÊÜGh0stTimesѬȾµÄ·þÎñÆ÷ÉÏ»¹·¢Ã÷ÁËÆäËû¶ñÒâÈí¼þ£¬ÈçÏÂÔØÆ÷¡¢ºóÃųÌÐò¡¢ELF BifroseºÍ¹¥»÷¹¤¾ß¡£ÕâЩ¹¤¾ß¿ÉÄÜ»áÒ²±»BlackTech×é֯ʹÓá£Ñо¿Ö°Ô±´Ë´ÎµÄÑо¿ËµÃ÷BlackTech¹¥»÷×éÖ¯ÒÀÈ»»îÔ¾£¬ÇÒʹÓÃÁ˸ü¶àµÄ¹¤¾ß¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMWc
6. ¹¥»÷ÕßʹÓÃÀÕË÷Èí¼þ¹¥»÷°ÂÁÖ°Í˹ÅÌËã»úϵͳ
¡¾¸ÅÊö¡¿
Ò½ÁÆÊÖÒÕ¾ÞÍ·°ÂÁÖ°Í˹ÔÚÍøÂç¹¥»÷ºó±»ÆÈ¹Ø±ÕÆäÔÚÃÀ¹ú£¨ÃÀ¹ú¡¢¼ÓÄôóºÍÀ¶¡ÃÀÖÞ£©µÄÅÌËã»úÍøÂ磬¹«Ë¾Ã»ÓÐ͸¶ËüÔâÊܵĹ¥»÷ÀàÐÍ£¬µ«ÇéÐÎÅú×¢¿ÉÄÜÊÇÀÕË÷Èí¼þ¹¥»÷¡£9 Ô£¬°ÂÁÖ°Í˹½ÒÏþÉùÃ÷£¬Ðû²¼ÆäÅ·ÖÞ¡¢Öж«ºÍ·ÇÖÞÅÌËã»úÍøÂçÔâµ½ÀÕË÷Èí¼þ¹¥»÷¡£ÔÚÊÜѬȾϵͳÉÏ·¢Ã÷µÄÊê½ðƱ¾ÝÉù³Æ¸Ã¹«Ë¾Êܵ½BlackMatter ÀÕË÷Èí¼þ×éÖ¯µÄ¹¥»÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMWa
7. ÃÀ¹ú¿üË¹ÌØÕï¶Ï¹«Ë¾ÈÏ¿É35ÍòÃû»¼ÕßÒ½ÁÆ×ÊÁϱ»Ð¹Â¶
¡¾¸ÅÊö¡¿
¿üË¹ÌØÕï¶Ï¹«Ë¾ÏòÃÀ¹ú֤ȯÉúÒâίԱ»á(SEC)ת´ï³Æ£¬¹«Ë¾ÆìÏÂÉúÓýÕïËùReproSourceÔÚ°ËÔ·ÝÔâµ½ÁËÀÕË÷Èí¼þ¹¥»÷£¬Ô¼ 350,000 Ãû»¼ÕߵĴó×Ú¿µ½¡ÐÅÏ¢ºÍ²ÆÎñÐÅÏ¢Ôâµ½×ß©£¬²¿·Ö»¼ÕßµÄÉç»áÇå¾²ºÅÂ루ssn)ºÍÐÅÓÿ¨ºÅÂëÒ²Ôâµ½×ß©¡£¹¥»÷ʱ´ú»¹Ð¹Â¶ÁËÓû§´ó×Ú¿µ½¡ÐÅÏ¢£¬°üÀ¨ CPT ´úÂë¡¢Õï¶Ï´úÂë¡¢²âÊÔÉêÇëºÍЧ¹û¡¢²âÊÔ±¨¸æºÍ²¡Ê·ÐÅÏ¢¡¢¿µ½¡°ü¹Ü»òÕûÌåÍýÏëʶÓÖÃû³ÆºÍ±àºÅÒÔ¼°Ð¡ÎÒ˽¼Ò»òÓÉСÎÒ˽¼ÒÌṩµÄÆäËûÐÅÏ¢ÖÎÁÆÒ½Ê¦¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMWd
8. ΢Èí»÷ÍËÁËÕë¶ÔAzure¿Í»§µÄ´´¼Í¼µÄ2.4 Tbps DDoS¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿ÕßÌåÏÖÆä Azure ÔÆÆ½Ì¨ÔÚ 8 ÔµÄ×îºóÒ»ÖÜ»º½âÁËÕë¶ÔÅ·ÖÞδǩ×Ö¿Í»§µÄ 2.4 Tbps ÂþÑÜʽ¾Ü¾ø·þÎñ (DDoS) ¹¥»÷£¬Áè¼ÝÁËÑÇÂíÑ·ÍøÂç·þÎñÔÚ 2020 Äê 2 ÔÂ×èÖ¹µÄ2.3 Tbps ¹¥»÷¡£DDoS¹¥»÷Êǹ¥»÷ÕßʹÓà UDP ÐÒéµÄÎÞÅþÁ¬ÌØÕ÷ºÍÓÕÆÐÔÇëÇó£¬Óôó×ÚÊý¾Ý°üÑÍûĿµÄ·þÎñÆ÷»òÍøÂ磬Ôì³ÉÖÐÖ¹»òäÖȾ·þÎñÆ÷¼°ÆäÖܱ߻ù´¡ÉèÊ©²»¿ÉÓá£Ìý˵Õâ´Î¹¥»÷Ô´×ÔÒ»¸öÓÉԼĪ 70,000 ̨ÊÜѬȾװ±¸×é³ÉµÄ½©Ê¬ÍøÂ磬ÕâЩװ±¸Ö÷ҪλÓÚÑÇÌ«µØÇø£¬ÀýÈçÂíÀ´Î÷ÑÇ¡¢Ô½ÄÏ¡¢Ì¨Íå¡¢ÈÕ±¾ºÍÖйú£¬ÒÔ¼°ÃÀ¹úµÈ¹ú¼Ò¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMVV
9. ÓëÒÁÀÊÓйصÄDEV-0343 APTÄ¿µÄÊÇÃÀ¹úºÍÒÔÉ«Áйú·ÀÊÖÒÕ¹«Ë¾
¡¾¸ÅÊö¡¿
Microsoft ÍþвÇ鱨ÖÐÐÄ (MSTIC) ºÍ Microsoft Êý×ÖÇå¾²²¿·Ö (DSU) µÄÑо¿Ö°Ô±·¢Ã÷ÁËÒ»¸ö¸ú×ÙΪ DEV-0343 µÄ¶ñÒâÔ˶¯¼¯Èº£¬DEV-0343 ÊÇ Microsoft ÍþвÇ鱨ÖÐÐÄ (MSTIC) Ê×´ÎÊӲ쵽²¢ÓÚ 2021 Äê 7 ÔÂÏÂÑ®×îÏȸú×ÙµÄÐÂÔ˶¯¼¯Èº¡£MSTIC ÊӲ쵽 DEV-0343 ¶Ô 250 ¶à¸ö Office 365 ×â»§¾ÙÐÐÁËÆÕ±éµÄÃÜÂëÅçÈ÷£¬¹¥»÷ÖØµãÊÇÃÀ¹úºÍÒÔÉ«Áйú·ÀÊÖÒÕ¹«Ë¾¡¢²¨Ë¹ÍåÈë¾³¿Ú°¶»òÔÚÖж«¿ªÕ¹ÓªÒµµÄÈ«Çòº£ÉÏÔËÊ乫˾¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMW9
10. ÈÕ±¾¿ç¹ú¹«ÔâÀÕË÷Èí¼þ¹¥»÷£¬±»ÀÕË÷700ÍòÃÀ½ðÊê½ð
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬ÈÕ±¾¿ç¹ú¹«Ë¾JVCKenwoodÔâµ½ÁËConti ÀÕË÷Èí¼þ¹¥»÷£¬¹¥»÷ÕßÉù³ÆÇÔÈ¡ÁË1.7TBµÄÊý¾Ý£¬²¢ÀÕË÷700 ÍòÃÀÔªµÄÊê½ð¡£JVCKenwood ÊÇÒ»¼Ò×ܲ¿Î»ÓÚÈÕ±¾µÄ¿ç¹úµç×Ó¹«Ë¾£¬ÓµÓÐ 16,956 ÃûÔ±¹¤£¬2021 ÄêµÄÊÕÈëΪ 24.5 ÒÚÃÀÔª¡£¸Ã¹«Ë¾ÒÔÆä JVC¡¢Kenwood ºÍ Victor Æ·ÅÆ¶øÖøÃû£¬ÕâÐ©Æ·ÅÆÉú²úÆû³µºÍ¼ÒÍ¥ÒôƵװ±¸¡¢Ò½ÁƱ£½¡ºÍÎÞÏßµç×°±¸¡¢×¨ÒµºÍ³µÔØÉãÏñÍ·ÒÔ¼°±ãЯʽ·¢µçÕ¾¡£JVCKenwoodÌåÏÖ£¬ÆäÔÚÅ·ÖÞµÄÏúÊÛ¹«Ë¾µÄ·þÎñÆ÷ÓÚ9ÔÂ22ÈÕÔâµ½ÆÆË𣬹¥»÷Õß¿ÉÄÜÔÚ¹¥»÷ʱ´ú»á¼ûÁËÊý¾Ý¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMVK

AG¹«Ë¾ÔÆ







