¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180717

°ä²¼¹¦·ò 2018-07-17

¡¾Íþвµý±¨¡¿×êÑÐÍŶӷ¢ÏÖ¶íÂÞ˹·¸×ïÍÅ»ïAPT28µÄй¥»÷»î¶¯


CSE Cybsec Z-Lab°²È«×êÑÐÈËÔ±·¢ÏÖ¶íÂÞ˹·¸×ïÍÅ»ïAPT28µÄй¥»÷»î¶¯¡£6Ô·Ý×êÑÐÈËÔ±·¢ÏÖһЩжñÒâÈí¼þÑù±¾£¬·ÖÎöÅú×¢ËüÃÇÊÇAPT28ʹÓõĺóÃÅX-AgentµÄбäÖÖ£¬¸Ã±äÖÖÊÇÒ»¸öWindows°æ±¾µÄ±äÖÖ£¬ÖØÒªÓÃÓÚÕë¶ÔÒâ´óÀû¾ü¹¤ÆóÒµMarina Militare¡£×êÑÐÈËÔ±½«APT28µÄÕâ´ÎÍøÂç¼äµý»î¶¯³ÆÎªÂÞÂí¼ÙÈջ¡£¸ü¶à¾ßÌåÐÅÏ¢£¨Ô̺¬IoCºÍYara¹æ¶¨£©Çë½Ó¼ûÒÔÏÂÁ´½Ó¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/74460/apt/operation-roman-holiday-apt28.html


¡¾Íþвµý±¨¡¿¾Ý±¨Â·¶íÂÞ˹ÔÚÊÀ½ç±­ÆÚ¼äÔâµ½Ô¼2500Íò´ÎÍøÂç¹¥»÷


Ī˹¿ÆÊ±±¨±¨Â·³Æ£¬¶íÂÞ˹×ÜͳÆÕ¾©¸ß¶ÈÔÞÑïÁ˸ùúµÄÍøÂ簲ȫÊýÃÅ£¬¸Ã²¿ÃÅÔÚÊÀ½ç±­ÆÚ¼ä¹²×èÖ¹ÁËÔ¼2500Íò´ÎÍøÂç¹¥»÷ºÍÆäËü·¸×ï»î¶¯£¬È·±£Á˽ÇÖðµÄ°²È«¡£FireEyeÄÏÅ·¼¼Êõ×ܼàDavid Grout°µÊ¾¹ÌÈ»ÕâÒ»Êý×ֺܸߣ¬µ«²¢²»³öºõÒâÁÏ¡£ÕâЩ¹¥»÷¿ÉÄÜÔ̺¬ÔÚ½ÇÖðǰ¼¸ÖÜ¾ÍÆðÍ·µÄÍøÂç´¹µö¹¥»÷£¬ÀýÈçÁ®¼Û»úƱ¡¢Ó®µÃ¶íÂÞ˹֮ÂÃÒÔ¼°ÓëÊÀ½ç±­Ö÷ÌâÓйصĴÙÏú»î¶¯£¨Èç¹ú¶È¶ÓÇòÒ£©µÈ¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/russia-fends-off-25-million-world/


¡¾Íþвµý±¨¡¿FBIͳ¼Æ³ÆBECÚ¿Æ­»î¶¯¹²µ¼Ö³¬¹ý120ÒÚÃÀÔªµÄËðʧ


ƾ¾ÝFBIÉÏÖܰ䲼µÄÒ»·Ýµ÷Ñл㱨£¬ÓÉBECºÍEACÚ¿Æ­»î¶¯µ¼ÖµÄËðʧ³¬¹ý120ÒÚÃÀÔª¡£¸Ã»ã±¨»ùÓÚFBIÏÂÊôµÄ»¥ÁªÍø·¸×ïͶËßÖÐÐÄIC3ÒÔ¼°¹ú¼Ê·¨ÂÉ»ú¹¹ºÍ½ðÈÚ»ú¹¹ÔÚ2013Äê10ÔÂÖÁ2018Äê5ÔÂÆÚ¼äÍøÂçµÄÊý¾Ý¡£ÔÚ´ËÆÚ¼ä£¬È«Çò¹²ÓÐ7.8Íò¶àÆðÓйØÍ¶Ëߣ¬ÆäÖг¬¹ý4.1ÍòÆð²úÉúÔÚÃÀ¹ú¡£Êܺ¦µÄÓ×ÎÒ¼°ÆóÒµµÄËðʧ¿ÉÄܸߴï125ÒÚÃÀÔª¡£Ïà±È֮ϣ¬FBI֮ǰµÄ»ã±¨£¨º­¸Ç2013Äê10ÔÂÖÁ2016Äê12Ô£©³ÆÈ«Çò¹²²úÉúÔ¼4ÍòÆðÊÂÎñ£¬Ëðʧ×ܶîΪ53ÒÚÃÀÔª¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/bec-scam-losses-top-12-billion-fbi


¡¾°²È«·ì϶¡¿×êÑÐÈËÔ±³ÆÊýÍǫ̀´ó»ªDVRµÄµÇ¼ÃÜÂë±»ZoomEyeÊÕ¼


NewSky SecurityµÄ°²È«×êÑÐÔ±Ankit Anubhav·¢ÏÖÊýÍǫ̀´ó»ªDVRµÄµÇ¼ÃÜÂë±»ZoomEyeÊÕ¼¡£´ó»ªDVRÖдæÔÚ·ì϶£¨CVE-2013-6117£©£¬¹ÌÈ»½¨¸´²¹¶¡ÒѰ䲼¶àÄ꣬µ«ÈÔÓдóÁ¿É豸ûÓнøÐиüС£¸Ã·ì϶ÔÊÐíÔ¶³Ì¹¥»÷ÕßÈÆ¹ýÉí·ÝÑéÖ¤²¢»ñÈ¡Ãô¸ÐÊý¾Ý£¬Ô̺¬Óû§ÃûºÍÃÜÂëµÈ¡£ZoomEye»º´æÁËɨÃèÕâЩÉ豸µÄ¶Ë¿Úʱ·µ»ØµÄµÇ¼ÃÜÂë¡£Anubhav³ÆÔ¼ÓÐ1.5Íò¸ö´ó»ªDVRʹÓÃÈõÃÜÂëadmin£¬Áí±í³¬¹ý1.3Íò¸öÉ豸ʹÓÃÈõÃÜÂë123456¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/passwords-for-tens-of-thousands-of-dahua-devices-cached-in-iot-search-engine/


¡¾°²È«·ì϶¡¿×êÑÐÍŶӰ䲼¹ØÓÚDHCP¿Í»§¶Ë·ì϶£¨CVE-2018-1111£©µÄ·ÖÎö»ã±¨


Paloalto NetworksµÄUnit42×êÑÐÍŶӰ䲼¹ØÓÚDHCP¿Í»§¶ËÈí¼þ°üÖеĺÅÁî×¢Èë·ì϶£¨CVE-2018-1111£©µÄ·ÖÎö»ã±¨¡£¸Ã·ì϶´æÔÚÓÚ¶à¸öRed Hat Linux°æ±¾µÄDHCP¿Í»§¶ËÈí¼þ°üµÄNetworkManager¾ç±¾ÖС£¹¥»÷Õß¿Éͨ¹ý¶ñÒâDHCP·þÎñÆ÷»ò±¾µØ¶ñÒâDHCPÏìÓ¦°üÀ´ÀûÓø÷ì϶£¬´Ó¶øÒÔrootȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£¸Ã·ì϶µÄPoCÓÚ2018Äê5ÔÂ16ÈÕ±»¹«¿ª°ä²¼¡£Ë¼¿¼µ½NetworkManager±»Ê¹ÓÃµÄ¿í·ºÐÔ£¬½¨ÒéÓû§¾¡¿ì½øÐиüС£

 

Ô­ÎÄÁ´½Ó£ºhttps://researchcenter.paloaltonetworks.com/2018/07/unit42-analysis-dhcp-client-script-code-execution-vulnerability-cve-2018-1111/


¡¾¶ñÒâÈí¼þ¡¿×êÑÐÍŶӷ¢ÏÖÀÕË÷Èí¼þMagniberÔÚÑÇÖÞÀ©´óÆä¹¥»÷ÁìÓò


Malwarebytes Labs×êÑÐÍŶӷ¢ÏÖÀÕË÷Èí¼þMagniberÀ©´óÁËÆä¹¥»÷ÁìÓò£¬´ÓÖ»Õë¶Ôº«¹úµ½Õë¶Ô¸ü¶àÖÐÎÄ£¨Öйú¡¢ÐÂ¼ÓÆÂ£©ºÍÂíÀ´ÓÂíÀ´Î÷ÑÇ¡¢ÎÄÀ³£©µÄÓû§¡£×êÑÐÈËÔ±»¹³Æ¸Ã¶ñÒâÈí¼þµÄÔ´´úÂë´Ë¿ÌÖÊÁ¿¸ü¸ß£¬ÀûÓöàÖÖ»ìºÏ¼¼Êõ²¢ÇÒ²»ÔÙÒÀÀµÓÚC&C»òÓ²±àÂëÃÜÔ¿À´ÊµÏÔìä¼ÓÃÜ·¨Ê½¡£ÐµÄMagniber¹¥»÷»î¶¯ÀûÓÃIE·ì϶£¨CVE-2018-8174£©½øÐзַ¢¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://blog.malwarebytes.com/threat-analysis/2018/07/magniber-ransomware-improves-expands-within-asia/