Crystal Valley Farm CoopÔâµ½ÀÕË÷Èí¼þ¹¥»÷£ºAppleÐû²¼¶à¿î²úÎï©¶´
Ðû²¼Ê±¼ä 2021-09-24VMwareÐÞ¸´vCenter ServerÖÐÑÏÖØµÄÎļþÉÏ´«Â©¶´
VMwareÓÚ±¾ÖܶþÐû²¼Äþ¾²¸üУ¬ÐÞ¸´vCenter ServerºÍCloud FoundationÖеÄ19¸ö©¶´¡£ÆäÖÐ×îΪÑÏÖØµÄÊÇvCenter ServerÖеÄÈÎÒâÎļþÉÏ´«Â©¶´(CVE-2021-22005)£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÍøÂç·ÃÎʶ˿Ú443µÄÉÏ´«ÌØÖÆÎļþÀ´Ö´ÐдúÂë¡£´ËÍ⣬»¹ÐÞ¸´Á˵±µØÌáȨ©¶´£¨CVE-2021-21991£©¡¢·´ÏòÊðÀíÈÆ¹ý©¶´£¨CVE-2021-22006£©¡¢API¶Ëµã©¶´£¨CVE-2021-22011£©ºÍAPIÐÅϢй¶©¶´£¨CVE-2021-22012£©µÈ¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/09/vmware-warns-of-critical-file-upload.html
AppleÐû²¼Äþ¾²¸üУ¬ÐÞ¸´¶à¿î²úÎïÖеÄRCEµÈ©¶´
AppleÓÚ9ÔÂ20ÈÕÐû²¼Äþ¾²¸üУ¬ÐÞ¸´ÁËSafari 15¡¢Xcode 13¡¢tvOS 15¡¢watchOS 8¡¢iOS 15¡¢iPadOS 15ºÍiTunes 12.12ÖеĶà¸ö©¶´¡£ÆäÖаüÂÞSafari 15ÖеÄÄÚ´æË𻵵¼ÖµÄÈÎÒâ´úÂëÖ´ÐЩ¶´£¨CVE-2021-30846ºÍCVE-2021-30851µÈ£©¡¢tvOS 15ÖеÄDoS©¶´£¨CVE-2013-0340£©ºÍɳºÐÈÆ¹ý©¶´£¨CVE-2021-30854£©£¬ÒÔ¼°iOS 15ºÍiPadOS 15ÖеĴúÂëÖ´ÐЩ¶´£¨CVE-2021-30837ºÍCVE-2021-30811£©µÈ¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2021/09/21/apple-releases-security-updates-multiple-products
¶íÂÞ˹APT×éÖ¯TurlaÀûÓÃкóÃŹ¥»÷ÃÀ¡¢µÂºÍ°¢¸»º¹
Cisco TalosÔÚ9ÔÂ21ÈÕÅû¶Á˶íÂÞ˹APT×éÖ¯TurlaÀûÓÃкóÃÅTinyTurla¹¥»÷ÃÀ¡¢µÂºÍ°¢¸»º¹µÄ»î¶¯¡£Turla×Ô2004ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬¹¥»÷ÁËÖж«¡¢ÑÇÖÞ¡¢Å·ÖÞ¡¢±±ÃÀºÍÄÏÃÀµÈµØÓòµÄÄ¿±ê¡£Ñо¿ÈËԱͨ¹ýÒ£²â·¢ÏÖÁ˺óÃÅ£¬µ«Éв»Çå³þÆäÈ·Çеݲװ·½Ê½£¬½öÖªµÀ¹¥»÷ÕßʹÓÃ.batÎļþÁ÷´«ºóÃÅ¡£¸ÃºóÃÅαװ³ÉMicrosoft DLL£¬²¢ÃüÃûΪw64time.dll£¬¿ÉÉÏ´«ºÍÖ´ÐÐÎļþ¡¢´´½¨×ÓÁ÷³ÌºÍÇÔÈ¡Êý¾ÝµÈ¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2021/09/tinyturla.html
DeFiƽ̨pNetwork³ÆÆäÔâµ½¹¥»÷ËðʧÁè¼Ý1200ÍòÃÀÔª
DeFiƽ̨pNetworkÔÚ9ÔÂ19ÈÕÐû²¼Twitter³ÆÆäÔâµ½¹¥»÷£¬ËðʧÁè¼Ý1200ÍòÃÀÔª¡£¸Ãƽ̨³Æ£¬¹¥»÷ÕßÀûÓÃÆä´úÂë¿âÖеÄ©¶´¹¥»÷ÁËpBTC-on-BSC £¬²¢ÇÔÈ¡ÁË277¸öBTC¡£pNetwork»¹ÌåÏÖ£¬Èç¹û¹¥»÷ÕßÄÜÍ˻ر»µÁ×ʽð£¬ËûÃÇÔ¸Ö§¸¶×ܽð¶îµÄ12.5%£¨150ÍòÃÀÔª£©×÷ΪÉͽð¡£9ÔÂ22ÈÕ£¬¸ÃÍŶÓÐû²¼ÁËÓйش˴ι¥»÷ʼþµÄÊÓ²ì³ÂËß¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/hacker-steals-12m-from-defi/
ÃÀ¹úCrystal Valley Farm CoopÔâµ½ÀÕË÷Èí¼þ¹¥»÷
Crystal Valley Farm CoopÔÚ9ÔÂ21ÈÕ͸¶ÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬³ÉΪ±¾Öܵڶþ¸öÔâµ½¹¥»÷µÄũҵºÏ×÷Éç¡£¹¥»÷·¢ÉúÔÚÉÏÖÜÈÕ£¨9ÔÂ19ÈÕ£©£¬ÆäÖ§¸¶ÏµÍ³Êܵ½Ó°Ï죬ÎÞ·¨Ê¹ÓÃVisa¡¢MastercardºÍDiscoverÐÅÓÿ¨¸¶¿î¡£½ØÖÁ±¾ÖÜÈýÏÂÎç¸Ã¹«Ë¾µÄÍøÕ¾ÈÔ´¦ÓڹرÕ״̬£¬Ä¿Ç°Éв»Çå³þ´Ë´Î¹¥»÷±³ºóµÄÀÕË÷ÔËÓªÍŻ±¾ÖÜÒ»£¬NEW CooperativeÔøÔâµ½BlackMatter¹¥»÷£¬²¢±»ÀÕË÷590ÍòÃÀÔª¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/second-farming-cooperative-shut-down-by-ransomware-this-week/
Recorded FutureÐû²¼TAG-28¹¥»÷Ó¡¶ÈµÄ·ÖÎö³ÂËß
Recorded FutureÓÚ9ÔÂ21ÈÕÐû²¼Á˹ØÓÚTAG-28¹¥»÷Ó¡¶ÈµÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬TAG-28¿ÉÄÜÓëÕë¶ÔÓ¡¶ÈýÌ弯ÍÅBennett Coleman And Co Ltd(BCCL£¬ÓÖ³ÆÊ±´ú¼¯ÍÅ£©¡¢Ó¡¶ÈÉí·Ýʶ±ð»ú¹¹UIDAIºÍÖÐÑë°î¾¯²ì¾ÖµÄ¹¥»÷»î¶¯Óйء£´ËÍ⣬Óë2020ÄêÏà±È£¬2021ÄêÕë¶ÔÓ¡¶È×éÖ¯µÄÒÉËÆÓɹú¼Ò×ÊÖúµÄ¹¥»÷»î¶¯Ôö¼ÓÁË261%£¬¶ø¸ÃÊý¾Ý´Ó2019ÄêÖÁ2020ÄêÔö¼ÓÁË120%¡£
ÔÎÄÁ´½Ó£º
https://www.recordedfuture.com/china-linked-tag-28-targets-indias-the-times-group/