ÃÀ¹ú×ÜͳǩÊ𡶸ÄÉÆ¹ú¼ÒÍøÂçÇå¾²µÄÐÐÕþÏÂÁî¡·£»£»£»£»£»Cisco¸üÐÂÐÞ¸´AnyConnect VPNÖб£´æ6¸öÔµÄ0day

Ðû²¼Ê±¼ä 2021-05-14

1.ÃÀ¹ú×ÜͳǩÊ𡶸ÄÉÆ¹ú¼ÒÍøÂçÇå¾²µÄÐÐÕþÏÂÁî¡·


1.jpg


ÃÀ¹ú×ÜͳÓÚ±¾ÖÜÈý£¨2021Äê5ÔÂ12ÈÕ£©Ç©ÊðÁË¡¶¸ÄÉÆ¹ú¼ÒÍøÂçÇå¾²µÄÐÐÕþÏÂÁî¡·¡£¡£¡£¡£¡£¸ÃÐÐÕþÏÂÁîÊǼ̽ñÄêÖÚ¶àÕë¶ÔÃÀ¹úµÄÍøÂç¹¥»÷Ö®ºó¹«²¼µÄ£¬£¬£¬£¬£¬£¬°üÀ¨12ÔµÄSolarWinds¹©Ó¦Á´¹¥»÷ÒÔ¼°×î½üµÄÕë¶ÔColonial PipelineµÄDarkSideÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¡£¸ÃÏÂÁîÖ¼ÔÚÏÖ´ú»¯Áª°îÕþ¸®»ù´¡ÉèÊ©µÄÍøÂçÇå¾²·ÀÓù²½·¥¡¢½¨Éè±ê×¼»¯µÄÊÂÎñÏìÓ¦ÊֲᲢÔöǿЧÀÍÌṩÉÌÓëÖ´·¨²¿·ÖÖ®¼äµÄÏàͬ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/biden-issues-executive-order-to-increase-us-cybersecurity-defenses/


2.Cisco¸üÐÂÐÞ¸´AnyConnect VPNÖб£´æ6¸öÔµÄ0day


2.jpg


˼¿ÆÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËÔÚAnyConnect VPNÖÐÒѱ£´æ6¸öÔÂÖ®¾ÃµÄ0day£¬£¬£¬£¬£¬£¬²¢ÌṩÁ˹ûÕæ¿ÉÓõĿ´·¨ÑéÖ¤Îó²îʹÓôúÂë¡£¡£¡£¡£¡£CiscoÓÚ2020Äê11ÔÂÅû¶Á˸ÃÎó²î£¨CVE-2020-3556£©£¬£¬£¬£¬£¬£¬ µ«Ö»ÌṩÁË»º½â²½·¥²¢Î´Ðû²¼Çå¾²¸üС£¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚAnyConnectµÄÀú³Ì¼äͨѶ£¨IPC£©£¬£¬£¬£¬£¬£¬ÔÊÐí¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÖ´ÐжñÒâ¾ç±¾¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬ÏÈǰÐû²¼µÄ»º½â²½·¥ÈÔÈ»¿ÉÓ㬣¬£¬£¬£¬£¬ÎÞ·¨Á¬Ã¦×°ÖÃÇå¾²¸üеĿͻ§¿ÉÒÔͨ¹ýÇл»×Ô¶¯¸üй¦Ð§À´»º½â´ËÎó²î¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/cisco-fixes-6-month-old-anyconnect-vpn-zero-day-with-exploit-code/


3.ÍÁ¶úÆä¿ÆÄáÑÇÊÐÕþ¸®Ôâµ½¹¥»÷£¬£¬£¬£¬£¬£¬100ÍòסÃñµÄÐÅϢй¶


3.jpg


ÍÁ¶úÆä¿ÆÄáÑÇÊÐÕþ¸®µÄÍøÂçÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬100ÍòסÃñµÄÐÅϢй¶¡£¡£¡£¡£¡ £¿£¿£¿£¿£¿£¿£¿£¿ÆÄáÑÇÊÇÍÁ¶úÆä¿ÆÄáÑÇÊ¡µÄÊ׸®£¬£¬£¬£¬£¬£¬¶¼»áÉú³ÝÁè¼Ý100Íò£¬£¬£¬£¬£¬£¬ÊÇÍÁ¶úÆä×Ú½Ì×îÊØ¾ÉµÄ´ó¶¼»áÖ®Ò»¡£¡£¡£¡£¡£Ä³ÊÐÕþ¹ÙԱ֤ʵÁ˴˴ι¥»÷£¬£¬£¬£¬£¬£¬µ«²¢Î´Í¸Â¶Æä¹æÄ££¬£¬£¬£¬£¬£¬S?zc¨¹±¨Ö½Ôò³Æ£¬£¬£¬£¬£¬£¬Ô¼ÓÐ100ÍòÈ˵ÄIDºÍÆäËûСÎÒ˽¼ÒÐÅÏ¢ÒѾ­Ð¹Â¶£¬£¬£¬£¬£¬£¬Ö÷񻃾¼°ÄÇЩÏòÊÐÕþÕþ¸®·¢Ë͹ýÓʼþµÄÈË¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬ÃûΪMaxim GorkiµÄµÄºÚ¿ÍÒÑÔÚ°µÍøÉϹûÕæÁËÕâЩÐÅÏ¢¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.dailysabah.com/turkey/investigations/cyberattack-steals-info-of-one-million-in-turkeys-konya


4.΢ÈíÅû¶Õë¶Ôº½¿Õº½ÌìÐÐÒµµÄÓã²æÊ½ÍøÂç´¹Âڻ


4.jpg


΢ÈíÅû¶½üÆÚÕë¶Ôº½¿Õº½ÌìºÍÂÃÓÎÐÐÒµµÄÓã²æÊ½ÍøÂç´¹Âڻ¡£¡£¡£¡£¡£´Ë´Î¹¥»÷ÖУ¬£¬£¬£¬£¬£¬ºÚ¿Íαװ³Éº½¿Õ¡¢ÂÃÓκͻõÔ˹«Ë¾£¬£¬£¬£¬£¬£¬Ê¹ÓÃÁËеļÓÔØ³ÌÐòSnip3£¬£¬£¬£¬£¬£¬ÔÚÄ¿µÄϵͳÖÐ×°ÖÃRevenge RAT¡¢AsyncRAT¡¢Agent TeslaºÍNetWire RATµÈpayload¡£¡£¡£¡£¡£ÎªÁËÈÆ¹ý¼ì²â£¬£¬£¬£¬£¬£¬Snip3»¹Ê¹ÓÃÁ˹¥»÷ÊֶΣ¬£¬£¬£¬£¬£¬°üÀ¨£ºÓÃ'remotesigned'²ÎÊýÖ´ÐÐPowerShell´úÂ룻£»£»£»£»Ê¹ÓÃPastebinºÍtop4top¾ÙÐзֶΣ»£»£»£»£»ÔËÐеÄʱ¼äÔÚÖն˱àÒëRunPE¼ÓÔØ³ÌÐò¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-threat-actors-target-aviation-orgs-with-new-malware/


5.Ñо¿Ö°Ô±ÑÝʾÔõÑùʹÓÃÆ»¹ûFind My networkÇÔÊØÐÅÏ¢


5.jpg


Ñо¿Ö°Ô±Fabian Br?unleinÑÝʾÁËÔõÑùʹÓÃÆ»¹ûµÄFind My network¹¦Ð§ÇÔÊØÐÅÏ¢¡£¡£¡£¡£¡£¸Ã¹¦Ð§Ö÷ÒªÓÃÓÚ²éÕÒiOSºÍmacOS×°±¸£¬£¬£¬£¬£¬£¬ÒÔ¼°×î½üµÄAirTagºÍÆäËûÌ×¼þ¡£¡£¡£¡£¡£Br?unleinʹÓûùÓÚopenhaystackµÄ¹Ì¼þµÄESP32΢¿ØÖÆÆ÷À´¹ã²¥Ò»¸öÓ²±àÂëµÄȱʡÐÂÎÅ£¬£¬£¬£¬£¬£¬²¢ÔÚÆä´®ÐнӿÚÉÏÕìÌýÐÂÊý¾Ý¡£¡£¡£¡£¡£ÖÜΧÆôÓÃÁ˸ù¦Ð§µÄ×°±¸½«ÎüÊÕÕâЩÐźÅ£¬£¬£¬£¬£¬£¬²¢×ª·¢µ½Æ»¹ûµÄЧÀÍÆ÷¡£¡£¡£¡£¡£¿ÉÊÇÈôÊÇÏëÒªÉó²éÕâЩ´«ÊäÐÅÏ¢£¬£¬£¬£¬£¬£¬»¹Ðè×°ÖÃOpenHaystack²¢ÔËÐÐBr?unlein½¨ÉèµÄmacOSÓ¦ÓÃDataFetcher¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.com/2021/05/12/apples_find_network/


6.Unit42Ðû²¼ÓйØDarkSideÀÕË÷ÍÅ»ïµÄÆÊÎö±¨¸æ


6.jpg


Unit42Ðû²¼ÁËÓйØDarkSideÀÕË÷ÍÅ»ïµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£DarkSideÊÇÌìÏÂÉÏ×î×ÅÃûµÄºÚ¿Í×éÖ¯Ö®Ò»£¬£¬£¬£¬£¬£¬½üÆÚÕë¶ÔÃÀ¹úÒ»¼ÒÖ÷ÒªµÄ¹ÜµÀ¹«Ë¾¾ÙÐÐÁ˹¥»÷¡£¡£¡£¡£¡£ÓëÆäËûÀÕË÷Èí¼þÍÅ»ïÒ»Ñù£¬£¬£¬£¬£¬£¬DarkSide×î½üÒ²½ÓÄÉÁËÀÕË÷Èí¼þ¼´Ð§ÀÍ£¨RaaS£©Ä£×Ó¡£¡£¡£¡£¡£¸ÃÍÅ»ïʹÓõŤ¾ß°üÀ¨£ºÕýµ±µÄÔ¶³Ì¼àÊÓºÍÖÎÀí£¨RMM£©¹¤¾ß£¬£¬£¬£¬£¬£¬ÀýÈçAnyDeskºÍTeamViewer£»£»£»£»£»ÃÜÂëÖÎÀíÓ¦Ó㬣¬£¬£¬£¬£¬ÀýÈçDashlaneºÍLastPass£»£»£»£»£»Æ¾Ö¤ÇÔÈ¡¹¤¾ßMimikatzµÈ¹¤¾ß¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/darkside-ransomware/