°ÍÎ÷³ÆÆä²ÆÕþ²¿ÃØÊé´¦µÄÄÚ²¿ÍøÂçÔâµ½ÀÕË÷Èí¼þ¹¥»÷:Fortinet FortiWeb WAF´æÔÚδÐÞ¸´µÄÃüÁî×¢Èë0day

Ðû²¼Ê±¼ä 2021-08-23

°ÍÎ÷³ÆÆä²ÆÕþ²¿ÃØÊé´¦µÄÄÚ²¿ÍøÂçÔâµ½ÀÕË÷Èí¼þ¹¥»÷


°ÍÎ÷³ÆÆä²ÆÕþ²¿ÃØÊé´¦µÄÄÚ²¿ÍøÂçÔâµ½ÀÕË÷Èí¼þ¹¥»÷.jpg


°ÍÎ÷Õþ¸®ÔÚÉÏÖÜÁùÍí¼ä͸¶£¬Æä²ÆÕþ²¿ÃØÊé´¦µÄÄÚ²¿ÍøÂçÔÚÖÜÎåÍíÉÏ£¨8ÔÂ13ÈÕ£©Ôâµ½ÁËÀÕË÷Èí¼þ¹¥»÷¡£°ÍÎ÷¾­¼Ã²¿Ðû²¼ÉùÃ÷³Æ£¬¾­¹ý¿ª¶ËÆÀ¹ÀÈ·¶¨¹ú¿âµÄϵͳ²¢Î´Êܵ½Ó°Ïì¡£8ÔÂ16ÈÕ£¬°ÍÎ÷Õþ¸®Óë°ÍÎ÷֤ȯ½»Ò×Ëù¾Í¸Ãʼþ·¢±íÁËÁªºÏÉùÃ÷£¬³Æ¾ÓÃñ¹ºÖðÍÎ÷Õþ¸®Õ®È¯µÄTesouro Diretoƽ̨ҲδÊܵ½Ó°Ïì¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/brazilian-government-discloses-national-treasury-ransomware-attack/



Cisco·¢ÏÖÕë¶ÔÄ«Î÷¸ç½ðÈÚ»ú¹¹µÄÐÂľÂíNeurevt


Cisco·¢ÏÖÕë¶ÔÄ«Î÷¸ç½ðÈÚ»ú¹¹µÄÐÂľÂíNeurevt.png


Cisco TalosÓÚ2021Äê6Ô¼ì²âµ½ÐÂNeurevtľÂí¡£¸Ã¶ñÒâÈí¼þ½«ºóÃźÍÐÅÏ¢ÇÔÈ¡·¨Ê½½áºÏÔÚÒ»Æð£¬Ö÷ÒªÕë¶ÔÄ«Î÷¸ç½ðÈÚ»ú¹¹µÄÓû§¡£¹¥»÷ÕßÒ»µ©ÀÖ³ÉѬȾĿ±êÉ豸£¬¾Í¿ÉÒÔ·ÃÎÊÄ¿±êϵͳ²¢ÐÞ¸ÄËûÃǵÄÉèÖÃÒÔÒþ²Ø×Ô¼º¡£¸ÃľÂí¿ÉÒÔͨ¹ý·ÃÎÊÊܺ¦ÕßµÄϵͳ·þÎñÁîÅÆÀ´ÌáȨ£¬´Ó¶ø·ÃÎʲÙ×÷ϵͳ¡¢Óû§ÕÊ»§ÐÅÏ¢¡¢ÒøÐÐÍøÕ¾Æ¾¾Ý¡¢½ØÈ¡ÆÁÄ»½ØÍ¼²¢·¢Ë͵½C2·þÎñÆ÷ÒÔÇÔȡĿ±êµÄÐÅÏ¢¡£ 


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2021/08/neurevt-trojan-takes-aim-at-mexican.html



Ñо¿ÍŶӷ¢ÏÖÕë¶ÔÈÕ±¾Ö¼ÔÚ·Ö·¢CinobiµÄ¶ñÒâ¹ã¸æ»î¶¯


Ñо¿ÍŶӷ¢ÏÖÕë¶ÔÈÕ±¾Ö¼ÔÚ·Ö·¢CinobiµÄ¶ñÒâ¹ã¸æ»î¶¯2.jpg


Ç÷ÊÆ¿Æ¼¼Ñо¿ÍŶÓÓÚÉÏÖÜÐû²¼ÁËÒ»Ïî·ÖÎö£¬½ÒʾÁ˺ڿÍÍÅ»ïWater KappaÕë¶ÔÈÕ±¾µÄ¶ñÒâ¹ã¸æ»î¶¯¡£¹¥»÷ÕßÊ×ÏÈʹÓÃÈÕ±¾¶¯»­ÓÎÏ·¡¢½±Àø»ý·ÖÓ¦ÓúÍÊÓÆµÁ÷·þÎñ·Ö·¢¶ñÒâ¹ã¸æ£¬×îÖÕ°²×°ÒøÐÐľÂíCinobi¡£Ñо¿ÈËÔ±·¢Ïִ˴λÖ÷ÒªÕë¶ÔʹÓÃInternet ExplorerÒÔÍâµÄä¯ÀÀÆ÷µÄÈÕ±¾Óû§£¬²¢Ö÷ÒªÇÔÈ¡ÈÕ±¾µÄ11¼Ò½ðÈÚ»ú¹¹µÄÓû§ÃûºÍÃÜÂ룬ÆäÖÐ3¼ÒÉæ¼°¼ÓÃÜ»õ±Ò½»Òס£


Ô­ÎÄÁ´½Ó£º

https://www.trendmicro.com/en_in/research/21/h/cinobi-banking-trojan-targets-users-of-cryptocurrency-exchanges-.html


ClearSky·¢ÏÖSiamesekittenÕë¶ÔÒÔÉ«Áеļäµý»î¶¯


ClearSky·¢ÏÖSiamesekittenÕë¶ÔÒÔÉ«Áеļäµý»î¶¯.png


ClearSkyµÄÑо¿ÈËÔ±ÔÚ8ÔÂ17ÈÕÅû¶ÁËÒÁÀÊAPT×éÖ¯SiamesekittenÕë¶ÔÒÔÉ«Áеļäµý»î¶¯¡£ClearSkyÓÚ2021Äê5Ô³õ¼ì²âµ½¸ÃÍÅ»ïÕë¶ÔÒÔÉ«ÁеÄÒ»¼ÒIT¹«Ë¾µÄµÚÒ»´Î¹¥»÷£¬²¢ÔÚ5ÔºÍ7ÔÂÓÖ¼ì²âµ½Á˶à´Î¹¥»÷¡£Ôڴ˴λÖУ¬ºÚ¿Íαװ³ÉChipPcºÍSoftware AGµÈÖªÃû¹«Ë¾µÄÈËÁ¦×ÊÔ´²¿Ô±¹¤£¬ÒÔÓÕÈ˵ÄְλÓÕʹĿ±ê½øÈëµöÓãÍøÒ³ÏÂÔØÔ¶³Ì·ÃÎÊľÂíDanBot¡£ÒòΪ´Ë´Î¹¥»÷Ö÷ÒªÕë¶ÔITºÍͨÐŹ«Ë¾£¬Òò´ËClearSkyÍÆ²âºÚ¿Í¿ÉÄÜÖ¼ÔÚ¶ÔËûÃǵĿͻ§Ìᳫ¹©Ó¦Á´¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.clearskysec.com/siamesekitten/


Fortinet FortiWeb WAF´æÔÚδÐÞ¸´µÄÃüÁî×¢Èë0day


Fortinet FortiWeb WAF´æÔÚδÐÞ¸´µÄÃüÁî×¢Èë0day.jpg


Fortinet FortiWeb WebÓ¦Ó÷¨Ê½·À»ðǽ(WAF)´æÔÚÃüÁî×¢Èë0day£¬¹¥»÷ÕßÀûÓøÃ©¶´¿ÉÒÔͨ¹ýSAML·þÎñÆ÷ÅäÖÃÒ³ÃæÒÔrootÓû§Éí·ÝÖ´ÐÐÈÎÒâÃüÁî¡£ËäÈ»¹¥»÷Õß±ØÐëͨ¹ýÁËÄ¿±êÉ豸¹ÜÀí½çÃæµÄÉí·ÝÑéÖ¤²ÅÆøÀûÓôË©¶´£¬µ«Èç¹ûÓëÆäËû©¶´£¨ÀýÈçÉí·ÝÑéÖ¤ÈÆ¹ý©¶´CVE-2020-29015£©½áºÏʹÓ㬿ÉÒÔÍêÈ«¿ØÖÆÄ¿±ê·þÎñÆ÷¡£FortinetÒѽ«¸Ã©¶´µÄÐÞ¸´¼Æ»®ÍƳٵ½8Ôµ×£¬Ñо¿ÈËÔ±½¨Ò齨Òé¹ÜÀíÔ±½ûÖ¹´Ó²»ÊÜÐÅÈεÄÍøÂç·ÃÎÊFortiWebÉ豸µÄ¹ÜÀí½çÃæÒÔ·ÀÖ¹´ËÀ๥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/121221/security/fortinet-fortiweb-os-command-injection.html


AdobeÐû²¼Äþ¾²¸üУ¬ÐÞ¸´Æä¶à¿î²úÎïÖеÄÄþ¾²Â©¶´


AdobeÐû²¼Äþ¾²¸üУ¬ÐÞ¸´Æä¶à¿î²úÎïÖеÄÄþ¾²Â©¶´.jpg


AdobeÓÚ8ÔÂ17ÈÕÐû²¼Äþ¾²¸üУ¬ÐÞ¸´ÁËAdobe Captivate¡¢XMP Toolkit SDK¡¢Photoshop¡¢BridgeºÍMedia EncoderÖеĶà¸öÄþ¾²Â©¶´¡£ÆäÖнÏΪÑÏÖØµÄÊÇAdobe XMP Toolkit SDKÖеÄÈÎÒâ´úÂëÖ´ÐЩ¶´£¨CVE-2021-36052ºÍCVE-2021-36064£©¡¢PhotoshopÖеÄÈÎÒâ´úÂëÖ´ÐЩ¶´£¨CVE-2021-36065ºÍCVE-2021-36066£©£¬ÒÔ¼°Adobe BridgeÖеÄÈÎÒâ´úÂëÖ´ÐЩ¶´£¨CVE-2021-36078µÈ£©µÈ©¶´¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/08/18/adobe-releases-multiple-security-updates