GreyNoiseÔÚÒ°·¢ÏÖÀûÓÃZyxelÖзì϶µÄ¹¥»÷»î¶¯£»ºÚ¿ÍÀûÓÃÐéαµÄÌØÀÊÆÕ³óÎÅÊÓÆµ´«²¼QNode RAT
°ä²¼¹¦·ò 2021-01-08
ÍøÂ簲ȫ¹«Ë¾GreyNoiseÔÚÒ°·¢ÏÖÀûÓÃZyxelÖзì϶£¨CVE-2020-29583£©µÄ¹¥»÷»î¶¯¡£¸Ã·ì϶ÓëZyxelÖÐÓ²±àÂëµÄºóÃÅÕÊ»§zyfwpÓйأ¬¹¥»÷ÕßÄܹ»ÀûÓÃÀ´ÊÕÊÜÍøÂçÉ豸¡£GreyNoise¼ì²âµ½Èý¸ö·ÖÆçµÄIPµØÖ·ÔÚɨÃèSSHÉ豸£¬²¢³¢ÊÔʹÓÃZyxelºóÃŵǼ¡£µ«ÊÇÕâЩ¹¥»÷Õß²¢Ã»ÓÐרÃÅÕë¶ÔZyxelÉ豸£¬¶øÊÇɨÃèInternetÉÏËùÓÐÔÚÔËÐеÄSSH¡£ÆäÖÐÒ»¸ö¹¥»÷ÕßʹÓÃÁËCobalt StrikeµÄÄÚÖÃSSH¿Í»§¶ËÀ´Ö´ÐÐɨÃ裬ּÔÚÈÆ¹ý¼ì²â¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hackers-start-exploiting-the-new-backdoor-in-zyxel-devices/
2.ºÚ¿ÍÀûÓÃÐéαµÄÌØÀÊÆÕ³óÎÅÊÓÆµ´«²¼QNode RAT

Cybesecurity×êÑÐÈËÔ±·¢ÏÖºÚ¿ÍÀûÓÃÐéαµÄÌØÀÊÆÕ³óÎÅÊÓÆµ´«²¼¶ñÒâÈí¼þQNode¡£ÔÚÕâ´Î¹¥»÷»î¶¯ÖУ¬¹¥»÷Õß·¢ËÍÒÔ¡°GOOD LOAN OFFER !!¡±ÎªÖ÷ÌâµÄÓʼþ£¬²¢¸½ÓÐÒ»¸öÃûΪTRUMP_SEX_SCANDAL_VIDEOµÄJAR¶ñÒâÎļþÎļþÒÔ×°ÖÃQNode RAT¡£QRATÊǵäÐ͵ÄÔ¶³Ì½Ó¼ûľÂí£¬ÓµÓлñȡϵͳÐÅÏ¢¡¢Ö´ÐÐÎļþ²Ù×÷ÒÔ¼°´ÓGoogle ChromeºÍFirefoxµÅצÓÃÖлñȡʹ´¦µÄÖ°ÄÜ¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/01/hackers-using-fake-trumps-scandal-video.html
3.ÃÀ¹ú˾·¨²¿³ÆºÚ¿ÍÈëÇÔìäMicrosoft O365Óʼþ·þÎñÆ÷

ÃÀ¹ú˾·¨²¿£¨DoJ£©³ÆSolarWinds¹©¸øÁ´¹¥»÷µÄºÚ¿ÍÈëÇÔìäMicrosoft O365Óʼþ·þÎñÆ÷£¬²¢½Ó¼ûÁË3450×óÓÒ¸öÓÊÏäÕË»§¡£¸Ã²¿ÃųƺڿͽӼûµÄO365ÓÊÏäÊýÁ¿½öÔÚ3£¥×óÓÒ£¬²¢ÇÒÆä»úÃÜϵͳ²¢Î´Êܵ½Ó°Ïì¡£½ØÖÁĿǰ£¬Êܵ½Ó°ÏìµÄ»ú¹¹Ô̺¬²ÆÕþ²¿¡¢¹úÎñÔº¡¢NTIA¡¢¹úÁ¢ÎÀÉú×êÑÐÔºCISA¡¢ÄÜÔ´²¿¡¢¹ú¶ÈºË°²È«¾ÖºÍºÓɽ°²È«ÊýµÈ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/solarwinds-hackers-had-access-to-over-3-000-us-doj-email-accounts/
4.TalosÅû¶SoftMaker OfficeÖеĴúÂëÖ´Ðзì϶

Cisco TalosÅû¶ÁËSoftMaker OfficeÖеĴúÂëÖ´Ðзì϶¡£µÂ¹úÈí¼þ¿ª·¢ÉÌSoftMaker Software GmbHΪÓ×ÎÒºÍÆóÒµÌṩ°ì¹«Èí¼þÌ×¼þ£¬¸Ã·ì϶ӰÏìÁËÆäÎÄ×Ö´¦ÖÃÖ°ÄÜ×é¼þTextMaker¡£Õâ´Î·¢Ïֵķì϶±ðÀëΪ·ûºÅÀ©´ó·ì϶£¨CVE-2020-13544£©£¬µ¼ÖÂÎĵµ½âÎöÆ÷¶ÔÓÃÓÚÖÕֹѻ·µÄ³¤¶È½øÐзûºÅÀ©´ó£»Îĵµ½âÎöÖ°ÄÜÖеÄÊðÃûת»»·ì϶£¨CVE-2020-13545£©£»ÕûÊýÒç¶Âí½Å£¨CVE-2020-13546£©£¬µ¼ÖÂÀûÓÃÔÚ»º³åÇø±í²¿Ð´ÈëÊý¾Ý¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/softmaker-office-vulnerabilities-allow-code-execution-malicious-documents
5.MoFo°ä²¼2020ÄêÊý¾Ýй¶ËßËϵĻØÊ׻㱨

MoFo°ä²¼2020ÄêÊý¾Ýй¶ËßËϵĻØÊ׻㱨¡£»ã±¨Ö¸³ö£¬2020ÄêÊý¾Ýй¶µÄÊýÁ¿Ôö³¤ÁË270£¥¡£¸Ã»ã±¨Í³¼ÆÁËÈ¥ÄêµÄ25¸ö³Á´óÊý¾Ýй¶¼¯ÌåËßËϰ¸¼þ£¬·¢´Ë¿ÌԼĪ15£¥µÄ³Á´óÊý¾Ýй¶°¸¼þÖÐÔ¸æÊǹÍÔ±£¬ÆäËûÇé¿öÏ£¬Ô¸æÊǽӼû±»¸æ¸¶¿îƽ̨µÄ¿Í»§¡¢»¼Õß¡¢Óû§¡¢ÕÊ»§³ÖÓÐÈË»òÓ×ÎÒ¡£´Ë±í£¬¸Ã»ã±¨Ô¤²â£¬2020Ä갲ȫÊÂÎñÊýÁ¿µÄ´ó·ùÔö³¤½«µ¼ÖÂ2021Äê²úÉú¸ü¶àµÄÊý¾Ýй¶ËßËϰ¸¼þ¡£
ÔÎÄÁ´½Ó£º
https://www.mofo.com/resources/insights/210104-data-breach-litigation-2020.html
6.еÄÅÔ·¹¥»÷Äܹ»´ÓGoogle TitanÖи´Ô¼ÓÃÜÃÜÔ¿

·¨¹ú×êÑÐÈËÔ±·¢ÏÖеÄÅÔ·¹¥»÷Äܹ»´ÓGoogle TitanÖи´Ô¼ÓÃÜÃÜÔ¿¡£¸Ã·ì϶£¨CVE-2021-3011£©´æÔÚÓÚGoogle TitanºÍYubiKeyÓ²¼þ°²È«ÃÜÔ¿µÄоƬÖУ¬¿É±»ÓÃÀ´¸´ÔÓ²¼þ°²È«ÃÜÔ¿ËùʹÓõļÓÃÜÃÜÔ¿¡£¹¥»÷ÕßÒ»µ©»ñµÃ¼ÓÃÜÃÜÔ¿£¬¼´ECDSA ˽Կ£¬±ãÄܹ»¿Ë¡Titan¡¢YubiKeyºÍÆäËûÃÜÔ¿£¬ÒÔÈÆ¹ý2FA·¨Ê½¡£µ«ÊÇ´ËÀ๥»÷²»ÄÜͨ¹ýInternet»ò±¾µØÍøÂçÔ¶³Ì½øÐУ¬¶øÊDZØÒª¶Ô°²È«ÃÜÔ¿½øÐÐÎïÀí½Ó¼û¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/new-side-channel-attack-can-recover-encryption-keys-from-google-titan-security-keys/


¾©¹«Íø°²±¸11010802024551ºÅ