Ñо¿ÍŶÓÅû¶ÒÑ´æÔÚ¶àÄêµÄLinuxºóÃÅRotaJakiro£»Î¢ÈíÅû¶IoTºÍOTÉ豸ÖеÄ25¸öRCE©¶´BadAlloc
Ðû²¼Ê±¼ä 2021-04-301.Ñо¿ÍŶÓÅû¶ÒÑ´æÔÚ¶àÄêµÄLinuxºóÃÅRotaJakiro
Ñо¿ÍŶÓÅû¶×Ô2018ÄêÒÔÀ´¾Í´æÔÚµÄLinuxºóÃÅRotaJakiro£¬Ö¼ÔÚ´ÓÊÜѬȾµÄÉ豸ÖÐÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£RotaJakiroÖ®ËùÒÔµÃÃû£¬ÊÇÒòΪËüʹÓÃÁËÂÖ»»¼ÓÃÜ£¬¶øÇÒÔÚrootÕÊ»§ºÍ·ÇrootÕÊ»§ÖÐÖ´ÐÐʱÓÐËù²îÒì¡£´ËÍ⣬ÆäʹÓÃÁ˶àÖÖ¼ÓÃÜËã·¨£¬°üÂÞÓÃÓÚ¶ÔÑù±¾ÖеÄ×ÊÔ´ÐÅÏ¢½øÐмÓÃܵÄAESËã·¨£¬ÒÔ¼°ÓÃÓÚC2ͨÐŵÄAES¡¢XOR¡¢ROTATE¼ÓÃܺÍZLIBѹËõ£¬Ö¼ÔÚ¾¡¿ÉÄÜÒþ±ÎµØÔËÐС£¾ßÓÐÇÔÈ¡Éè±¸Ö¸ÎÆ¡¢ÎļþºÍ²å¼þ¹ÜÀí£¨²éѯ¡¢ÏÂÔØºÍɾ³ý£©ºÍÖ´ÐÐÌØ¶¨²å¼þµÄ¹¦Ð§¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/117332/breaking-news/rotajakiro-linux-backdoor.html
2.Naikon APTÔÚÕë¶Ô¶«ÄÏÑǾüÊÂ×éÖ¯µÄ¹¥»÷ÖÐʹÓÃкóÃÅNebulae
Bitdefender·¢ÏÖ£¬APT×éÖ¯NaikonÔÚÕë¶Ô¶«ÄÏÑǾüÊÂ×éÖ¯µÄ¹¥»÷»î¶¯ÖÐʹÓÃÁËкóÃÅNebulae¡£¸Ã×éÖ¯×Ô2010ÄêÒÔÀ´¿ªÊ¼»îÔ¾£¬Ö÷ÒªÕë¶Ô·ÆÂɱö¡¢ÂíÀ´Î÷ÑÇ¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢ÐÂ¼ÓÆÂºÍÌ©¹úµÄÕþ¸®ºÍ¾üÊÂ×éÖ¯¡£ÔÚ½üÆÚµÄ»î¶¯ÖУ¨2019Äê6ÔÂÖÁ2021Äê3Ô£©£¬NaikonÀûÓÃÁ˺Ϸ¨Èí¼þ¼ÓÔØNebulaeÀ´ÊµÏÖ³Ö¾ÃÐÔ£¬¸ÃºóÃÅ¿ÉÒÔÊÕ¼¯ÏµÍ³ÐÅÏ¢¡¢ÀûÓÃÎļþºÍÎļþ¼Ð¡¢´ÓC2ÏÂÔØÎļþÒÔ¼°Ö´ÐС¢Áгö»òÖÕÖ¹ÊÜѬȾÉè±¹ØÁ¬Ä½ø³Ì¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/117321/apt/naikon-apt-nebulae-backdoor.html
3.΢ÈíÅû¶IoTºÍOTÉ豸ÖеÄ25¸öRCE©¶´BadAlloc
΢ÈíÄþ¾²Ñо¿ÈËÔ±ÔÚÎïÁªÍø£¨IoT£©É豸ºÍÔËÓª¼¼Êõ£¨OT£©¹¤ÒµÏµÍ³Öз¢ÏÖÁË25¸öÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©Â©¶´£¬±»Í³³ÆÎªBadAlloc¡£ÕâЩ©¶´ÊÇÓÉÓÚÕûÊýÒç³ö»ò»·ÈƵ¼Öµģ¬ÒòΪÄÚ´æ·ÖÅ书ЧÖÐûÓнøÐÐÊäÈëÑéÖ¤£¬¹¥»÷Õß¿ÉÒÔÀûÓøù¦Ð§À´½øÐжÑÒç³ö£¬´Ó¶øÔÚÄ¿±êÉ豸ÉÏÖ´ÐжñÒâ´úÂë¡£ÕâЩ©¶´Ö÷ÒªÓ°ÏìÁËÏû·ÑÕß¡¢Ò½Áƺ͹¤ÒµµÄÍøÂ磬CISA½¨Òé×éÖ¯Ó¦ÓÿÉÓõũӦÉ̸üС¢¾¡Á¿¼õÉÙÏµÍ³ÍøÂçµÄ̻¶¡¢½«¿ØÖÆÏµÍ³µÄÍøÂçºÍÔ¶³ÌÉ豸ÖÃÓÚ·À»ðǽ֮ºó²¢ÓëÒµÎñÍøÂç¸ôÀëÒÔ¼°Ê¹ÓÃVPN½øÐÐÔ¶³Ì·ÃÎÊ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-finds-critical-code-execution-bugs-in-iot-ot-devices/
4.ºÚ¿ÍÂÛ̳OGUsersÔâµ½µÚËĴι¥»÷£¬ÆäÊý¾Ý¿â±»³öÊÛ
Äþ¾²¹«Ë¾KELA³ÆOGUsersÒÑÈ·ÈÏÆäÔâµ½¹¥»÷£¬ÕâÊÇÆäÁ½ÄêÄÚÔâµ½µÄµÚËÄ´ÎÈëÇÖ¡£OGUsersÊÇÒ»¸öºÚ¿ÍÂÛ̳£¬Ö÷Òª³öÊÛͨ¹ýSIM½»»»¹¥»÷¡¢Æ¾¾ÝÌî³ä¹¥»÷µÈ·½Ê½µÃµ½µÄÉ罻ýÌåÕÊ»§¡£¾ÝϤ£¬¹¥»÷·¢ÉúÔÚ2021Äê4ÔÂ11ÈÕ£¬ºÚ¿Í½«Web ShellÉÏ´«µ½ÁËOGUsersµÄ·þÎñÆ÷£¬²¢ÔÚ°µÍøÒÔ3000ÃÀÔªµÄ¼Û¸ñ³öÊÛÆäÊý¾Ý¿â£¬ÆäÖаüÂÞÔ¼350000¸ö»áÔ±µÄÓû§¼Ç¼ºÍ˽ÈËÏûÏ¢¡£ÔçÔÚÔÚ2019Äê5Ô¡¢2020Äê4ÔºÍ2020Äê11Ô£¬OGUsersÔâµ½ÁË3´Î¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/fourth-times-a-charm-ogusers-hacking-forum-hacked-again/
5.GoogleÄþ¾²¸üУ¬ÐÞ¸´Chrome V8ÖеĴúÂëÖ´ÐЩ¶´
GoogleÐû²¼Äþ¾²¸üУ¬ÐÞ¸´ÁËChrome V8ÖеĴúÂëÖ´ÐЩ¶´¡£¸Ã©¶´±»×·×ÙΪ£¬Î»ÓÚä¯ÀÀÆ÷ʹÓõÄV8 JavaScriptÒýÇæÖУ¬ÊÇÓÉÓÚÊý¾ÝÑéÖ¤²»×ãµ¼Öµġ£½«ÆäÓëɳºÐÌÓÒÝ©¶´½áºÏʹÓÿÉÒÔÔÚ²Ù×÷ϵͳÉÏÖ´ÐжñÒâ´úÂ룬ÓëÒѱ»ÐÞ¸´µÄCVE-2020-16040ºÍCVE-2020-15965©¶´Ïà¹Ø¡£´ËÍ⣬´Ë´Î¸üл¹ÐÞ¸´ÁËANGLE×é¼þÖеĶѻº³åÇøÒç³ö©¶´£¨CVE-2021-21233£©ºÍV8×é¼þÖеÄÀàÐÍ»ìÏý©¶´£¨CVE-2021-21230£©µÈÆäËü8¸ö©¶´¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/google-chrome-v8-bug-remote-code-execution/165662/
6.Ó¢¹úÌúÂ·ÍøÕ¾MerseyrailѬȾLockbit£¬¿Í»§ÐÅϢй¶
Merseyrail³ÆÆäÔâµ½LockbitÀÕË÷Èí¼þ¹¥»÷£¬Óʼþϵͳ±»ÆÆ»µ¡£MerseyrailÊÇÓ¢¹úµÄÌúÂ·ÍøÕ¾£¬ÎªÓ¢¸ñÀ¼ÀûÎïÆÖÊеØÓòµÄ68¸ö³µÕ¾Ìṩ»ð³µ·þÎñ¡£¹¥»÷ÕßÓÚ4ÔÂ18ÈÕÐû²¼Óʼþ£¬¼û¸æ¸Ã¹«Ë¾Óйش˴εĹ¥»÷ʼþ£¬²¢Éù³ÆÆäÒÑÇÔÈ¡ÁËÔ±¹¤ºÍ¿Í»§µÄÐÅÏ¢¡£Í¬Ê±£¬¸ÃÓʼþÒ²±»·¢Ë͸øÁËÓ¢¹úµÄ¼¸¼Ò±¨ÉçºÍMerseyrailµÄÔ±¹¤£¬ÒÔÏò¹«Ë¾Ê©¼ÓѹÁ¦£¬ÆÈʹÆäÖ§¸¶Êê½ð¡£MerseyrailÒÑÉϱ¨¸øÓ¢¹úÕþ¸®£¬²¢ÕýÔÚÖ´·¨²¿ÃŵÄÐÖú϶ԸÃʼþÕ¹¿ªÊӲ졣
ÔÎÄÁ´½Ó£º
https://news-block.com/uks-merseyrail-rail-network-likely-to-be-hit-by-lockbit-ransomware/