ÃÀ¹ú×ÜͳǩÊ𡶸ÄÉƹú¼ÒÍøÂçÄþ¾²µÄÐÐÕþÃüÁî¡·£»Cisco¸üÐÂÐÞ¸´AnyConnect VPNÖдæÔÚ6¸öÔµÄ0day
Ðû²¼Ê±¼ä 2021-05-141.ÃÀ¹ú×ÜͳǩÊ𡶸ÄÉƹú¼ÒÍøÂçÄþ¾²µÄÐÐÕþÃüÁî¡·
ÃÀ¹ú×ÜͳÓÚ±¾ÖÜÈý£¨2021Äê5ÔÂ12ÈÕ£©Ç©ÊðÁË¡¶¸ÄÉƹú¼ÒÍøÂçÄþ¾²µÄÐÐÕþÃüÁî¡·¡£¸ÃÐÐÕþÃüÁîÊǼ̽ñÄêÖÚ¶àÕë¶ÔÃÀ¹úµÄÍøÂç¹¥»÷Ö®ºó°ä²¼µÄ£¬°üÂÞ12ÔµÄSolarWinds¹©Ó¦Á´¹¥»÷ÒÔ¼°×î½üµÄÕë¶ÔColonial PipelineµÄDarkSideÀÕË÷Èí¼þ¹¥»÷¡£¸ÃÃüÁîÖ¼ÔÚÏÖ´ú»¯Áª°îÕþ¸®»ù´¡ÉèÊ©µÄÍøÂçÄþ¾²·ÀÓù´ëÊ©¡¢´´½¨³ß¶È»¯µÄʼþÏìÓ¦ÊֲᲢ¼ÓÇ¿·þÎñÌṩÉÌÓëÖ´·¨²¿ÃÅÖ®¼äµÄÏàͬ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/biden-issues-executive-order-to-increase-us-cybersecurity-defenses/
2.Cisco¸üÐÂÐÞ¸´AnyConnect VPNÖдæÔÚ6¸öÔµÄ0day
˼¿ÆÐû²¼Äþ¾²¸üУ¬ÐÞ¸´ÁËÔÚAnyConnect VPNÖÐÒÑ´æÔÚ6¸öÔÂÖ®¾ÃµÄ0day£¬²¢ÌṩÁ˹ûÈ»¿ÉÓõĿ´·¨Ñé֤©¶´ÀûÓôúÂë¡£CiscoÓÚ2020Äê11ÔÂÅû¶Á˸鶴£¨CVE-2020-3556£©£¬ µ«Ö»ÌṩÁË»º½â´ëÊ©²¢Î´Ðû²¼Äþ¾²¸üС£¸Ã©¶´´æÔÚÓÚAnyConnectµÄ½ø³Ì¼äͨÐÅ£¨IPC£©£¬ÔÊÐí¾¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÖ´ÐжñÒâ½Å±¾¡£ÏÖÔÚ£¬ÏÈÇ°Ðû²¼µÄ»º½â´ëÊ©ÈÔÈ»¿ÉÓã¬ÎÞ·¨Á¢¼´°²×°Äþ¾²¸üеĿͻ§¿ÉÒÔͨ¹ýÇл»×Ô¶¯¸üй¦Ð§À´»º½â´Ë©¶´¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/cisco-fixes-6-month-old-anyconnect-vpn-zero-day-with-exploit-code/
3.ÍÁ¶úÆä¿ÆÄáÑÇÊÐÕþ¸®Ôâµ½¹¥»÷£¬100Íò¾ÓÃñµÄÐÅϢй¶
ÍÁ¶úÆä¿ÆÄáÑÇÊÐÕþ¸®µÄÍøÂçÔâµ½¹¥»÷£¬100Íò¾ÓÃñµÄÐÅϢй¶¡£¿ÆÄáÑÇÊÇÍÁ¶úÆä¿ÆÄáÑÇÊ¡µÄÊ׸®£¬¶¼ÊÐÈË¿ÚÁè¼Ý100Íò£¬ÊÇÍÁ¶úÆä×Ú½Ì×îÊؾɵĶàÊý»áÖ®Ò»¡£Ä³ÊÐÕþ¹ÙԱ֤ʵÁ˴˴ι¥»÷£¬µ«²¢Î´Í¸Â¶Æä¹æÄ££¬S?zc¨¹±¨Ö½Ôò³Æ£¬Ô¼ÓÐ100ÍòÈ˵ÄIDºÍÆäËû¸öÈËÐÅÏ¢ÒѾй¶£¬Ö÷ÒªÉæ¼°ÄÇЩÏòÊÐÕþÕþ¸®·¢Ë͹ýÓʼþµÄÈË¡£Ä¿Ç°£¬ÃûΪMaxim GorkiµÄµÄºÚ¿ÍÒÑÔÚ°µÍøÉϹûÈ»ÁËÕâЩÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.dailysabah.com/turkey/investigations/cyberattack-steals-info-of-one-million-in-turkeys-konya
4.΢ÈíÅû¶Õë¶Ôº½¿Õº½ÌìÐÐÒµµÄÓã²æʽÍøÂçµöÓã»î¶¯
΢ÈíÅû¶½üÆÚÕë¶Ôº½¿Õº½ÌìºÍÂÃÓÎÐÐÒµµÄÓã²æʽÍøÂçµöÓã»î¶¯¡£´Ë´Î¹¥»÷ÖУ¬ºÚ¿Íαװ³Éº½¿Õ¡¢ÂÃÓκͻõÔ˹«Ë¾£¬Ê¹ÓÃÁËеļÓÔØ·¨Ê½Snip3£¬ÔÚÄ¿±êϵͳÖа²×°Revenge RAT¡¢AsyncRAT¡¢Agent TeslaºÍNetWire RATµÈpayload¡£ÎªÁËÈƹý¼ì²â£¬Snip3»¹Ê¹ÓÃÁ˹¥»÷ÊֶΣ¬°üÂÞ£ºÓÃ'remotesigned'²ÎÊýÖ´ÐÐPowerShell´úÂ룻ʹÓÃPastebinºÍtop4top½øÐзֶΣ»ÔËÐеÄʱºòÔÚÖն˱àÒëRunPE¼ÓÔØ·¨Ê½¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-threat-actors-target-aviation-orgs-with-new-malware/
5.Ñо¿ÈËÔ±ÑÝʾÈçºÎʹÓÃÆ»¹ûFind My networkÇÔÈ¡ÐÅÏ¢
Ñо¿ÈËÔ±Fabian Br?unleinÑÝʾÁËÈçºÎʹÓÃÆ»¹ûµÄFind My network¹¦Ð§ÇÔÈ¡ÐÅÏ¢¡£¸Ã¹¦Ð§Ö÷ÒªÓÃÓÚ²éÕÒiOSºÍmacOSÉ豸£¬ÒÔ¼°×î½üµÄAirTagºÍÆäËûÌ×¼þ¡£Br?unleinʹÓûùÓÚopenhaystackµÄ¹Ì¼þµÄESP32΢¿ØÖÆÆ÷À´¹ã²¥Ò»¸öÓ²±àÂëµÄȱʡÏûÏ¢£¬²¢ÔÚÆä´®ÐнӿÚÉÏÕìÌýÐÂÊý¾Ý¡£ËÄÖÜÆôÓÃÁ˸ù¦Ð§µÄÉ豸½«½ÓÊÕÕâЩÐźţ¬²¢×ª·¢µ½Æ»¹ûµÄ·þÎñÆ÷¡£µ«ÊÇÈç¹ûÏëÒª¼ì²ìÕâЩ´«ÊäÐÅÏ¢£¬»¹Ðè°²×°OpenHaystack²¢ÔËÐÐBr?unlein´´½¨µÄmacOSÓ¦ÓÃDataFetcher¡£
ÔÎÄÁ´½Ó£º
https://www.theregister.com/2021/05/12/apples_find_network/
6.Unit42Ðû²¼ÓйØDarkSideÀÕË÷ÍÅ»ïµÄ·ÖÎö³ÂËß
Unit42Ðû²¼ÁËÓйØDarkSideÀÕË÷ÍÅ»ïµÄ·ÖÎö³ÂËß¡£DarkSideÊÇÊÀ½çÉÏ×îÖªÃûµÄºÚ¿Í×éÖ¯Ö®Ò»£¬½üÆÚÕë¶ÔÃÀ¹úÒ»¼ÒÖ÷ÒªµÄ¹ÜµÀ¹«Ë¾½øÐÐÁ˹¥»÷¡£ÓëÆäËûÀÕË÷Èí¼þÍÅ»ïÒ»Ñù£¬DarkSide×î½üÒ²½ÓÄÉÁËÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©Ä£ÐÍ¡£¸ÃÍÅ»ïʹÓõŤ¾ß°üÂÞ£ººÏ·¨µÄÔ¶³Ì¼àÊӺ͹ÜÀí£¨RMM£©¹¤¾ß£¬ÀýÈçAnyDeskºÍTeamViewer£»ÃÜÂë¹ÜÀíÓ¦Óã¬ÀýÈçDashlaneºÍLastPass£»Æ¾Ö¤ÇÔÈ¡¹¤¾ßMimikatzµÈ¹¤¾ß¡£
ÔÎÄÁ´½Ó£º
https://unit42.paloaltonetworks.com/darkside-ransomware/