¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180717
°ä²¼¹¦·ò 2018-07-17¡¾Íþвµý±¨¡¿×êÑÐÍŶӷ¢ÏÖ¶íÂÞ˹·¸×ïÍÅ»ïAPT28µÄй¥»÷»î¶¯
CSE Cybsec Z-Lab°²È«×êÑÐÈËÔ±·¢ÏÖ¶íÂÞ˹·¸×ïÍÅ»ïAPT28µÄй¥»÷»î¶¯¡£6Ô·Ý×êÑÐÈËÔ±·¢ÏÖһЩжñÒâÈí¼þÑù±¾£¬·ÖÎöÅú×¢ËüÃÇÊÇAPT28ʹÓõĺóÃÅX-AgentµÄбäÖÖ£¬¸Ã±äÖÖÊÇÒ»¸öWindows°æ±¾µÄ±äÖÖ£¬ÖØÒªÓÃÓÚÕë¶ÔÒâ´óÀû¾ü¹¤ÆóÒµMarina Militare¡£×êÑÐÈËÔ±½«APT28µÄÕâ´ÎÍøÂç¼äµý»î¶¯³ÆÎªÂÞÂí¼ÙÈջ¡£¸ü¶à¾ßÌåÐÅÏ¢£¨Ô̺¬IoCºÍYara¹æ¶¨£©Çë½Ó¼ûÒÔÏÂÁ´½Ó¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/74460/apt/operation-roman-holiday-apt28.html
¡¾Íþвµý±¨¡¿¾Ý±¨Â·¶íÂÞ˹ÔÚÊÀ½ç±ÆÚ¼äÔâµ½Ô¼2500Íò´ÎÍøÂç¹¥»÷
Ī˹¿ÆÊ±±¨±¨Â·³Æ£¬¶íÂÞ˹×ÜͳÆÕ¾©¸ß¶ÈÔÞÑïÁ˸ùúµÄÍøÂ簲ȫÊýÃÅ£¬¸Ã²¿ÃÅÔÚÊÀ½ç±ÆÚ¼ä¹²×èÖ¹ÁËÔ¼2500Íò´ÎÍøÂç¹¥»÷ºÍÆäËü·¸×ï»î¶¯£¬È·±£Á˽ÇÖðµÄ°²È«¡£FireEyeÄÏÅ·¼¼Êõ×ܼàDavid Grout°µÊ¾¹ÌÈ»ÕâÒ»Êý×ֺܸߣ¬µ«²¢²»³öºõÒâÁÏ¡£ÕâЩ¹¥»÷¿ÉÄÜÔ̺¬ÔÚ½ÇÖðǰ¼¸ÖÜ¾ÍÆðÍ·µÄÍøÂç´¹µö¹¥»÷£¬ÀýÈçÁ®¼Û»úƱ¡¢Ó®µÃ¶íÂÞ˹֮ÂÃÒÔ¼°ÓëÊÀ½ç±Ö÷ÌâÓйصĴÙÏú»î¶¯£¨Èç¹ú¶È¶ÓÇòÒ£©µÈ¡£
ÔÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/russia-fends-off-25-million-world/
¡¾Íþвµý±¨¡¿FBIͳ¼Æ³ÆBECڿƻ¹²µ¼Ö³¬¹ý120ÒÚÃÀÔªµÄËðʧ
ƾ¾ÝFBIÉÏÖܰ䲼µÄÒ»·Ýµ÷Ñл㱨£¬ÓÉBECºÍEACڿƻµ¼ÖµÄËðʧ³¬¹ý120ÒÚÃÀÔª¡£¸Ã»ã±¨»ùÓÚFBIÏÂÊôµÄ»¥ÁªÍø·¸×ïͶËßÖÐÐÄIC3ÒÔ¼°¹ú¼Ê·¨ÂÉ»ú¹¹ºÍ½ðÈÚ»ú¹¹ÔÚ2013Äê10ÔÂÖÁ2018Äê5ÔÂÆÚ¼äÍøÂçµÄÊý¾Ý¡£ÔÚ´ËÆÚ¼ä£¬È«Çò¹²ÓÐ7.8Íò¶àÆðÓйØÍ¶Ëߣ¬ÆäÖг¬¹ý4.1ÍòÆð²úÉúÔÚÃÀ¹ú¡£Êܺ¦µÄÓ×ÎÒ¼°ÆóÒµµÄËðʧ¿ÉÄܸߴï125ÒÚÃÀÔª¡£Ïà±È֮ϣ¬FBI֮ǰµÄ»ã±¨£¨º¸Ç2013Äê10ÔÂÖÁ2016Äê12Ô£©³ÆÈ«Çò¹²²úÉúÔ¼4ÍòÆðÊÂÎñ£¬Ëðʧ×ܶîΪ53ÒÚÃÀÔª¡£
ÔÎÄÁ´½Ó£ºhttps://www.securityweek.com/bec-scam-losses-top-12-billion-fbi
¡¾°²È«·ì϶¡¿×êÑÐÈËÔ±³ÆÊýÍǫ̀´ó»ªDVRµÄµÇ¼ÃÜÂë±»ZoomEyeÊÕ¼
NewSky SecurityµÄ°²È«×êÑÐÔ±Ankit Anubhav·¢ÏÖÊýÍǫ̀´ó»ªDVRµÄµÇ¼ÃÜÂë±»ZoomEyeÊÕ¼¡£´ó»ªDVRÖдæÔÚ·ì϶£¨CVE-2013-6117£©£¬¹ÌÈ»½¨¸´²¹¶¡ÒѰ䲼¶àÄ꣬µ«ÈÔÓдóÁ¿É豸ûÓнøÐиüС£¸Ã·ì϶ÔÊÐíÔ¶³Ì¹¥»÷ÕßÈÆ¹ýÉí·ÝÑéÖ¤²¢»ñÈ¡Ãô¸ÐÊý¾Ý£¬Ô̺¬Óû§ÃûºÍÃÜÂëµÈ¡£ZoomEye»º´æÁËɨÃèÕâЩÉ豸µÄ¶Ë¿Úʱ·µ»ØµÄµÇ¼ÃÜÂë¡£Anubhav³ÆÔ¼ÓÐ1.5Íò¸ö´ó»ªDVRʹÓÃÈõÃÜÂëadmin£¬Áí±í³¬¹ý1.3Íò¸öÉ豸ʹÓÃÈõÃÜÂë123456¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/passwords-for-tens-of-thousands-of-dahua-devices-cached-in-iot-search-engine/
¡¾°²È«·ì϶¡¿×êÑÐÍŶӰ䲼¹ØÓÚDHCP¿Í»§¶Ë·ì϶£¨CVE-2018-1111£©µÄ·ÖÎö»ã±¨
Paloalto NetworksµÄUnit42×êÑÐÍŶӰ䲼¹ØÓÚDHCP¿Í»§¶ËÈí¼þ°üÖеĺÅÁî×¢Èë·ì϶£¨CVE-2018-1111£©µÄ·ÖÎö»ã±¨¡£¸Ã·ì϶´æÔÚÓÚ¶à¸öRed Hat Linux°æ±¾µÄDHCP¿Í»§¶ËÈí¼þ°üµÄNetworkManager¾ç±¾ÖС£¹¥»÷Õß¿Éͨ¹ý¶ñÒâDHCP·þÎñÆ÷»ò±¾µØ¶ñÒâDHCPÏìÓ¦°üÀ´ÀûÓø÷ì϶£¬´Ó¶øÒÔrootȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£¸Ã·ì϶µÄPoCÓÚ2018Äê5ÔÂ16ÈÕ±»¹«¿ª°ä²¼¡£Ë¼¿¼µ½NetworkManager±»Ê¹ÓÃµÄ¿í·ºÐÔ£¬½¨ÒéÓû§¾¡¿ì½øÐиüС£
ÔÎÄÁ´½Ó£ºhttps://researchcenter.paloaltonetworks.com/2018/07/unit42-analysis-dhcp-client-script-code-execution-vulnerability-cve-2018-1111/
¡¾¶ñÒâÈí¼þ¡¿×êÑÐÍŶӷ¢ÏÖÀÕË÷Èí¼þMagniberÔÚÑÇÖÞÀ©´óÆä¹¥»÷ÁìÓò
Malwarebytes Labs×êÑÐÍŶӷ¢ÏÖÀÕË÷Èí¼þMagniberÀ©´óÁËÆä¹¥»÷ÁìÓò£¬´ÓÖ»Õë¶Ôº«¹úµ½Õë¶Ô¸ü¶àÖÐÎÄ£¨Öйú¡¢ÐÂ¼ÓÆÂ£©ºÍÂíÀ´ÓÂíÀ´Î÷ÑÇ¡¢ÎÄÀ³£©µÄÓû§¡£×êÑÐÈËÔ±»¹³Æ¸Ã¶ñÒâÈí¼þµÄÔ´´úÂë´Ë¿ÌÖÊÁ¿¸ü¸ß£¬ÀûÓöàÖÖ»ìºÏ¼¼Êõ²¢ÇÒ²»ÔÙÒÀÀµÓÚC&C»òÓ²±àÂëÃÜÔ¿À´ÊµÏÔìä¼ÓÃÜ·¨Ê½¡£ÐµÄMagniber¹¥»÷»î¶¯ÀûÓÃIE·ì϶£¨CVE-2018-8174£©½øÐзַ¢¡£
ÔÎÄÁ´½Ó£ºhttps://blog.malwarebytes.com/threat-analysis/2018/07/magniber-ransomware-improves-expands-within-asia/


¾©¹«Íø°²±¸11010802024551ºÅ