CISA°ä²¼ÓйØÔÚ½øÐеÄAPTÍøÂç»î¶¯µÄ¶´²ì»ã±¨£»Citrix³ÆºÚ¿ÍÀûÓÃDDoS¹¥»÷ÆäNetScaler ADCÉ豸

°ä²¼¹¦·ò 2020-12-25
1.CISA°ä²¼ÓйØÔÚ½øÐеÄAPTÍøÂç»î¶¯µÄ¶´²ì»ã±¨


1.jpg


CISA°ä²¼ÁËÓйØÔÚ½øÐеÄAPTÍøÂç»î¶¯µÄ¶´²ì»ã±¨ ¡£´Ë»ã±¨¿ÉΪ¸¨µ¼ÕßÌṩÓйØ×éÖ¯ÒÑÖª·çÏÕµÄÐÅÏ¢ÒÔ¼°×éÖ¯Äܹ»²ÉÈ¡µÄ´ëÊ©£¬ÒÔ±ãÓ¦¶ÔÕâЩÍþв ¡£CISA³ÆÒ»¸öAPT×éÖ¯Õë¶ÔSolarWinds OrionÈí¼þ¹©¸øÁ´£¬²¢ÀÄÓó£ÓõÄÉí·ÝÑéÖ¤»úÔì ¡£×éÖ¯Ó¦¸ÃÈ·¶¨ÊÇ·ñÊܵ½ÁËÓ°Ï죬ÈôÊÇÊܵ½Ó°ÏìÔòÐè½øÐÐÏìÓ¦ºÍ²¹¾È£¬·ÖÅä×ã¹»µÄ×ÊÔ´£¬×·Çó½øÒ»²½µÄÁìµ¼²¢ÔÚÏìÓ¦ºÍ²¹¾È¹ý³ÌÖÐά³Ö²Ù×÷°²È«ÐÔ ¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/12/23/cisa-releases-cisa-insights-and-creates-webpage-ongoing-apt-cyber


2.Kaspersky°ä²¼LazarusÕë¶ÔCOVID-19µý±¨µÄ·ÖÎö»ã±¨


2.png


Kaspersky°ä²¼ÓйغڿÍ×éÖ¯LazarusÕë¶ÔCOVID-19µý±¨µÄ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨ ¡£»ã±¨Ö¸³ö£¬LazarusÓÚ2020Äê9ÔÂ25ÈÕÈëÇÖÁËÒ»¼ÒÔìÒ©¹«Ë¾£¬²¢ÓÚ2020Äê10ÔÂ27ÈÕ¹¥»÷Á˵±¾ÖÎÀÉú²¿£¬²¢°Ü»µÁËÁ½Ì¨Windows·þÎñÆ÷ ¡£ÕâÁ½´Î¹¥»÷»î¶¯Ê¹ÓÃÁË·ÖÆçµÄÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½£¨TTP£©ÒÔ¼°¶ñÒâÈí¼þ¼¯Èº£¬µ«ÓÐÖ¤¾ÝÅú×¢¶¼ÓëLazarusÓйØ£¬²¢Ö¤Ã÷¸Ã×éÖ¯¶ÔÓëCOVID-19Óйصĵý±¨¸ÐÐËÖ ¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/lazarus-covets-covid-19-related-intelligence/99906/


3.6Ô±»½¨¸´µÄWindows·ì϶ÈԿɱ»ÀûÓã¬PoCÒѰ䲼


3.png


Google Project Zero·¢ÏÖ6Ô±»½¨¸´µÄWindows·ì϶ÈԿɱ»ÀûÓ㬲¢ÒѰ䲼PoC ¡£¸Ã·ì϶±»×·×ÙΪCVE-2020-0986£¬ÊÇWindowsÄÚºËÌØÈ¨ÌáÉý·ì϶£¬¹¥»÷Õß¿ÉÀûÓÃËÁÒâÖ¸ÕëµÄ½âÒýÓã¬À´½ÚÔì¡°src¡±ºÍ¡°dest¡±Ö¸ÕëÖ¸Ïòmemcpyº¯Êý ¡£¶øMicrosoftµÄ²¹¶¡·¨Ê½Ö»ÊǸü¸ÄÁËÖ¸ÏòÆ«ÒÆÁ¿µÄÖ¸Õ룬Òò¶øº¯ÊýµÄ²ÎÊýÒÀÈ»Äܹ»±»½ÚÔì ¡£×êÑÐÈËÔ±ÒѰ䲼ÁË´Ë·ì϶µÄPoC´úÂëÒÔ¼°ÈôºÎÕýÈ·ÔËÐеÄ×¢Ã÷ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/windows-zero-day-with-bad-patch-gets-new-public-exploit-code/


4.QNAP½¨¸´Ó°ÏìQTS¡¢QESºÍQuTS heroµÄ6¸öÑϳÁ·ì϶


4.png


QNAP°ä²¼°²È«¸üУ¬½¨¸´ÁËÓ°ÏìQTS¡¢QESºÍQuTS heroµÄ6¸öÑϳÁ·ì϶ ¡£Õâ´Î½¨¸´µÄ·ì϶±ðÀëΪQESÖд洢µÄ¿çÕ¾µã¾ç±¾·ì϶£¨CVE-2020-2503£©¡¢QESÖеľø¶Ôõè¾¶±éÀú·ì϶£¨CVE-2020-2504£©¡¢QESÖÐÔÊÐí¹¥»÷ÕßÌìÉúÃýÎóÐÂÎÅÀ´»ñÈ¡Ãô¸ÐÐÅÏ¢µÄ·ì϶£¨CVE-2020-2505£©¡¢QESÖеĺÅÁî×¢Èë·ì϶£¨CVE-2016-6903£©¡¢QESÖеÄÓ²±àÂëÃÜÂë·ì϶£¨CVE-2020-2499£©ÒÔ¼°QTSºÍQuTS heroÖеĺÅÁî×¢Èë·ì϶£¨CVE-2020-25847£© ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/qnap-fixes-high-severity-qts-qes-and-quts-hero-vulnerabilities/


5.21ButtonsµÄAWS´æ´¢Í°ÅäÖÃÃýÎóй¶Êý°ÙÍòÓû§µÄÊý¾Ý


5.png


21ButtonsµÄAWS´æ´¢Í°ÅäÖÃÃýÎó£¬Ð¹Â¶Êý°ÙÍòÓû§µÄÊý¾Ý ¡£21 ButtonsÊÇÖØÒªÃæÏòʱÉÐÐÐÒµµÄÉç½»ÍøÂ磬ÔÚAndroidƽ̨ÉϵÄÏÂÔØÁ¿³¬¹ý500Íò´Î ¡£Õâ´ÎÊÂÎñй¶Á˳¬¹ý5000Íò¸öÎļþ£¬ÆäÖÐÔ̺¬Óû§ÐÕÃû¡¢µØÖ·¡¢²ÆÕþÐÅÏ¢£¨ÀýÈçÒøÐÐÕʺš¢PayPalµç×ÓÓʼþµØÖ·¡¢ÕÕÆ¬ºÍÊÓÆµ£©ºÍ·¢Æ± ¡£Ä¿Ç°£¬Éв»Ã÷ÏÔÊÇ·ñÓкڿͽӼûÁ˹«¿ªµÄÊý¾Ý£¬Ò²²»Ã÷ÏÔÕâЩÊý¾ÝÊÇ·ñÒѵõ½±£»¤ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/fashion-marketplace-21-buttons-expose-users-data/


6.Citrix³ÆºÚ¿ÍÀûÓÃDDoS¹¥»÷ÆäNetScaler ADCÉ豸


6.png


Citrix³ÆºÚ¿ÍÀûÓÃDTLSÕë¶ÔNetScaler ADCÍøÂçÉ豸ÌáÒéDDoS¹¥»÷ ¡£×êÑÐÈËÔ±HofmannÓÚÉÏÖÜ·¢ÏÖÁ˵ÚÒ»´Î¹¥»÷»î¶¯£¬ºÚ¿ÍÒÔDTLS×÷ΪDDoS·Å´óÔØÌå ¡£ÔÚÒÔÍùµÄDDoS¹¥»÷ÖеķŴó±¶Êýͨ³£ÊÇԭʼ±¨ÎĵÄ4µ½5±¶£¬¶øÔÚÕâ´Î¹¥»÷»î¶¯ÖУ¬Citrix ADCÉ豸ÉϵÄDTLS±»·Å´óÁË35±¶£¬Ê¹Æä³ÉΪ×îÓÐÁ¦µÄDDoS·Å´óÔØÌåÖ®Ò» ¡£Ä¿Ç°£¬CitrixÌá³öÁËÁ½ÖÖһʱ½¨¸´¹æ»®£¬½ûÓÃCitrix ADC DTLS½Ó¿Ú£¬»òÇ¿ÔìÉ豸¶Ô´«ÈëµÄDTLSÏνӽøÐÐÉí·ÝÑéÖ¤ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/citrix-devices-are-being-abused-as-ddos-attack-vectors/