Cisco·¢ÏÖÀûÓÃÓòÃûǰÖü¼Êõ¶Ô×¼Ãåµéµ±¾ÖµÄ¹¥»÷»î¶¯
°ä²¼¹¦·ò 2021-11-19Cisco·¢ÏÖÀûÓÃÓòÃûǰÖü¼Êõ¶Ô×¼Ãåµéµ±¾ÖµÄ¹¥»÷»î¶¯

Cisco TalosÔÚ11ÔÂ16ÈÕÅû¶ÁËÀûÓÃÐµİµ²Ø¼¼ÊõÈÆ¹ý¼ì²âµÄ¹¥»÷»î¶¯¡£Õâ´Î»î¶¯×î³õ·¢ÏÖÓÚ½ñÄê9Ô·ݣ¬ÀûÓÃÁËÒ»ÖÖÃûΪÓòÃûǰÖõļ¼ÊõÀ´°µ²ØC2¡£´Ë±í£¬¹¥»÷Õß»¹ÀûÓÃÁ˺Ϸ¨µÄ¹¤¾ßCobalt Strik£¬µ±BeaconÆô¶¯Ê±½«ÎªÍйÜÔÚCloudflareµÄºÏ·¨ÓòÌá½»DNSÒªÇ󣬶øºóÅú¸ÄºóÐøµÄHTTPsÒªÇóÍ·£¬ÒÔÅúʾCDN½«Á÷Á¿³Á¶¨Ïòµ½¹¥»÷Õß½ÚÔìµÄÖ÷»ú¡£»î¶¯ÖÐʹÓõĺϷ¨ÓòÃûΪÃåµéÊý×ÖÐÂÎŵÄmdn[.]gov[.]mm¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2021/11/attackers-use-domain-fronting-technique.html
ESET·¢ÏÖÒÔÉ«ÁÐCandiruÕë¶ÔÓ¢¹úºÍÖж«µÄË®¿Ó¹¥»÷

11ÔÂ16ÈÕ£¬ESETµÄ×êÑÐÈËÔ±³ÆÒÔÉ«ÁеļäµýÈí¼þCandiruÓëÕë¶ÔÓ¢¹úºÍÖж«µÄË®¿Ó¹¥»÷Óйء£CandiruÒÑÓÚ±¾Ô±»ÃÀ¹úÉÌÎñ²¿ÁÐÈë¶ñÒâÍøÂç»î¶¯×éÖ¯Ãûµ¥¡£Õâ´Î»î¶¯´óÌå·ÖΪÁ½²¨£¬µÚÒ»²¨ÆðÍ·ÓÚ2020Äê3Ô£¬ÓÚ2020Äê8ÔÂʵÏÖ£¬µÚ¶þ²¨¹¥»÷ÆðÍ·ÓÚ2021Äê1ÔÂÆðÍ·£¬Ò»Ïò³ÖÐøµ½2021Äê8ÔÂÉÏÑ®£¬¹¥»÷ÁËÓ¢¹ú¡¢Ò²ÃÅ¡¢ÒÁÀÊ¡¢ÐðÀûÑÇ¡¢É³Ìذ¢À²®¡¢Òâ´óÀûºÍÄϷǵȵØÓòµÄ×éÖ¯¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/11/israels-candiru-spyware-found-linked-to.html
еĴ¹µö»î¶¯¼ÙÒâTikTokÔ±¹¤ÒÔɾ³ýÕ˺ÅÀ´ÍþвÓû§

Abnormal SecurityÔÚ11ÔÂ17ÈÕ·¢ÏÖÕë¶ÔTikTokÓû§µÄÐÂÒ»ÂÖ´¹µö»î¶¯¡£¹¥»÷Õß¼ÙÒâTikTokÔ±¹¤£¬ÖÒ¸æÖ¸±êÒòÆäÉæÏÓÎ¥·´Æ½Ì¨Ìõ¿î¶ø½«µ±¼´É¾³ýÕÊ»§¡£Ö®ºó£¬Óû§»á±»³Á¶¨Ïòµ½Ò»¸öWhatsApp̸ÌìÊÒ£¬²¢±»ÒªÇóÌṩ³ÁÖÃÕÊ»§ÃÜÂëËùÐèµÄÓʼþµØÖ·¡¢µç»°ºÅÂëºÍÒ»´ÎÐÔ´úÂ롣ĿǰÉв»Ã÷ÏÔ¹¥»÷ÕßµÄÖ÷ÕÅÊÇʲô£¬»òÐíÖ¼ÔÚÊÕÊÜÕË»§»òÀÕË÷¡£Õâ´Î»î¶¯µÄÁ½¸ö·åÖµ±ðÀëÔÚ10ÔÂ2ÈÕºÍ11ÔÂ1ÈÕ£¬Òò¶ø×êÑÐÈËÔ±´§Ä¦ÏÂÒ»Âֻ¿ÉÄÜ»áÔÚ¼¸ÖܺóÆðÍ·¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/tiktok-phishing-threatens-to-delete-influencers-accounts/
ÐÂÀÕË÷ÔËÓªÍÅ»ïMementoÀûÓÃvCenterÖеÄRCE·ì϶

SophosÓÚ11ÔÂ18ÈÕÅû¶ÁËÀÕË÷ÔËÓªÍÅ»ïMementoµÄл¡£¹¥»÷ÕßÀûÓÃÁËVMware vCenter Server WebÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-21971£©£¬CVSSÆÀ·ÖΪ9.8¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶½Ó¼ûTCP/IP¶Ë¿Ú443£¬²¢ÒÔÖÎÀíԱȨÏÞÖ´ÐкÅÁÆä²¹¶¡ÒÑÓÚ2Ô·ݰ䲼¡£Õâ´Î»î¶¯ÆðÍ·ÓÚÉϸöÔ£¬¹¥»÷ÕßÊ×ÏÈÀûÓÃvCenterÖеķì϶´ÓÖ¸±ê·þÎñÆ÷ÇÔÈ¡ÖÎÀíÍ´´¦£¬¶øºóʹÓÃRDP over SSHºáÏòÒÆ¶¯£¬²¢³õ´ÎÔÚ¹¥»÷ÖÐʹÓÃÁËWinRARÀ´Ñ¹ËõÎļþ²¢¶ÔÆä½øÐмÓÃÜ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-memento-ransomware-switches-to-winrar-after-failing-at-encryption/
CISA°ä²¼2021ÄêÍøÂ簲ȫÊÂÎñºÍ·ì϶µÄÓ¦¼±ÏìÓ¦Ö¸ÄÏ

11ÔÂ16ÈÕ£¬ÃÀ¹úCISA°ä²¼ÁË2021ÄêÍøÂ簲ȫÊÂÎñºÍ·ì϶µÄÓ¦¼±ÏìÓ¦Ö¸ÄÏ¡£¸ÃÖ¸ÄÏΪÁª¹úÎÄÖ°ÐÐÕþ²¿ÃÅ£¨FCEB£©»ú¹¹ÌṩÁËÓÃÓڹ滮ºÍ·¢Õ¹ÍøÂ簲ȫÊÂÎñºÍ·ì϶ÏìÓ¦»î¶¯µÄ²Ù×÷·¨Ê½£¬²¢Í¨¹ý¾ö²ßÊ÷¾ßÌå˵ÁËÈ»ÊÂÎñºÍ·ì϶ÏìÓ¦µÄÿ¸ö²½Öè¡£CISA¼¤Àø¹Ø¼ü»ù´¡ÉèÊ©ÓйØ×éÖ¯£¬ÖÝ¡¢´¦ËùÈ·µ±¾Ö×éÖ¯ÒÔ¼°Ë½Óª×éÖ¯ÀûÓøÃÖ¸ÄϽøÐÐÉó²é£¬ÒÔ¶ÔÆä×ÔÉíµÄ·ì϶ºÍÊÂÎñÏìӦʵ¼Ê½øÐлù×¼²âÊÔ¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2021/11/16/new-federal-government-cybersecurity-incident-and-vulnerability
Kaspersky°ä²¼2022ÄêAPT¹¥»÷ÍþÐ²Ì¬ÊÆµÄÔ¤²â»ã±¨

KasperskyÓÚ11ÔÂ17ÈÕ°ä²¼ÁË2022ÄêAPT¹¥»÷ÍþÐ²Ì¬ÊÆµÄÔ¤²â»ã±¨¡£»ã±¨Ö¸³ö£¬APT×éÖ¯½«´ÓÆäËû¹¥»÷ÕßÄÇÀï²É°ì³õÊ¼ÍøÂç½Ó¼ûȨÏÞ£»¸ü¶à¹ú¶È½«Ë¾·¨¸æ×´×÷ΪÆäÍøÂçÕ½ÊõµÄÒ»²¿ÃÅ£»¶ÔÍøÂçÉ豸µÄÕë¶ÔÐÔ¹¥»÷Ôö³¤£»5G·ì϶¼´½«³öÏÖ£»¹¥»÷Õß½«³ÖÐøÀûÓÃCOVID-19Ö÷Ìâ£»ÒÆ¶¯É豸½«Êܵ½¿í·º¹¥»÷£»¹©¸øÁ´¹¥»÷µÄÊýÁ¿½«Ôö³¤£»³ÖÐøÀûÓÃWFH£»METAµØÓò£¬ÓÈÆä³¤¶ÌÖÞµÄAPT»î¶¯½«Ôö³¤¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/advanced-threat-predictions-for-2022/104870/


¾©¹«Íø°²±¸11010802024551ºÅ