KasperskyÐû²¼¶ñÒâÈí¼þ·ÖÎö³ÂËߣºFarFariaÓ¦ÓõÄÊý¾Ý¿âй¶290ÍòÓû§ÐÅÏ¢

Ðû²¼Ê±¼ä 2021-09-30

΢Èí·¢ÏÖÖ¼ÔÚÇÔÈ¡AD FS¹ÜÀíԱƾ¾ÝµÄºóÃÅFoggyWeb


΢Èí·¢ÏÖÖ¼ÔÚÇÔÈ¡AD FS¹ÜÀíԱƾ¾ÝµÄºóÃÅFoggyWeb.jpg


΢ÈíÍþвÇ鱨ÖÐÐÄ(MSTIC)ÓÚ9ÔÂ27ÈÕÅû¶ÁËÖ¼ÔÚÇÔÈ¡Active DirectoryÁªºÏÉí·ÝÑéÖ¤·þÎñ(AD FS)¹ÜÀíԱƾ¾ÝµÄºóÃÅFoggyWeb¡£¸Ã¶ñÒâÈí¼þÓë¶íÂÞ˹Íâ¹úÇ鱨¾Ö(SVR)µÄºÚ¿ÍÍÅ»ïNobeliumÓйØ £¬ÀÄÓÃÁËSAMLÁîÅÆ¡£Ëü¿ÉÒÔΪ¹¥»÷Õß½ç˵µÄURIÅäÖÃHTTP¼àÌýÆ÷£¨ÕâЩURIÄ£·ÂÁËÄ¿±êAD FSʹÓõĺϷ¨URIµÄ½á¹¹£© £¬À´¼àÌý·¢Ë͵½AD FSµÄHTTP GETºÍPOSTÇëÇó £¬²¢À¹½ØÓë×Ô½ç˵URIģʽƥÅäµÄHTTPÇëÇó¡£


Ô­ÎÄÁ´½Ó£º

https://www.microsoft.com/security/blog/2021/09/27/foggyweb-targeted-nobelium-malware-leads-to-persistent-backdoor/



Ñо¿ÈËÔ±·¢ÏÖÕë¶Ô²¨À¼µÄÐÂAndroidÒøÐÐľÂíERMAC


Ñо¿ÈËÔ±·¢ÏÖÕë¶Ô²¨À¼µÄÐÂAndroidÒøÐÐľÂíERMAC.png


ºÉÀ¼Äþ¾²¹«Ë¾ThreatFabric·¢ÏÖÁËÒ»ÖÖÃûΪERMACµÄÐÂAndroidÒøÐÐľÂí¡£¸Ã¶ñÒâÈí¼þ»ùÓÚCerberus£¨ÆäÔ´´úÂëÒÑÓÚ2020Äê9ÔÂÔÚºÚ¿ÍÂÛ̳¹ûÈ»£© £¬ÓëBlackRock±³ºóµÄÔËÓªÉÌÓйØ¡£ÓëCerberusÏà±È £¬ERMACʹÓÃÁËBlowfish¼ÓÃÜËã·¨ £¬¶øÇÒÔÚÓëC2µÄͨÐÅÖÐʹÓÃÁËAES-128-CBC¼ÓÃÜ·½°¸¡£Ñо¿ÈËÔ±³Æ £¬ERMAC×Ô8ÔÂÏÂÑ®¿ªÊ¼»îÔ¾ £¬¿ªÊ¼Î±×°³ÉGoogle Chrome £¬Ö®ºó»¹Î±×°³Éαװ³É·À²¡¶¾¡¢ÒøÐкÍýÌå²¥·ÅÆ÷µÈÓ¦Óà £¬¿ÉÕë¶Ô378¸ö½ðÈÚÏà¹ØµÄÓ¦Ó÷¨Ê½¡£


Ô­ÎÄÁ´½Ó£º

https://www.threatfabric.com/blogs/ermac-another-cerberus-reborn.html



QNAPÐû²¼¸üР£¬ÐÞ¸´QVRÖÐ3¸öÑÏÖØµÄÃüÁî×¢Èë©¶´


QNAPÐû²¼¸üÐÂ£¬ÐÞ¸´QVRÖÐ3¸öÑÏÖØµÄÃüÁî×¢Èë©¶´.png


NASÖÆÔìÉÌQNAPÔÚ9ÔÂ27ÈÕÐû²¼Äþ¾²¸üР£¬ÐÞ¸´ÁËÊÓÆµ¹ÜÀíϵͳQVRÖÐ3¸öÑÏÖØµÄÃüÁî×¢Èë©¶´¡£ÆäÖеÄÁ½¸ö©¶´CVSSÆÀ·ÖΪ9.8 £¬Ô¶³Ì¹¥»÷Õß¿ÉÀûÓÃÆäÔÚÄ¿±êϵͳÉÏÖ´ÐÐÃüÁî £¬´Ó¶øÍêÈ«¿ØÖÆÉ豸¡£ÁíÍâÒ»¸ö©¶´×·×ÙΪCVE-2021-34349 £¬CVSSÆÀ·ÖΪ7.2 £¬ÓëÇ°ÃæÁ½¸ö©¶´µÄ²îÒìÊÇÀûÓÃËùÐèµÄȨÏÞ²îÒì¡£QNAPÖ¸³ö £¬ÆäÖÐÁ½¸ö©¶´»¹Ó°ÏìÁ˲¿ÃÅEOLÉ豸¡£Ä¿Ç° £¬Éв»Çå³þÕâЩ©¶´ÊÇ·ñÒѱ»ÔÚÒ°ÀûÓÃÁË¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/qnap-fixes-critical-bugs-in-qvr-video-surveillance-solution/



FarFariaÓ¦ÓõÄÊý¾Ý¿âÅäÖôíÎóй¶290Íò¸öÓû§µÄÐÅÏ¢


FarFariaÓ¦ÓõÄÊý¾Ý¿âÅäÖôíÎóй¶290Íò¸öÓû§µÄÐÅÏ¢.png


Comparitech·¢ÏÖ¶ùͯ¹ÊÊÂÊéÓ¦ÓÃFarFariaµÄMongoDBÊý¾Ý¿âÅäÖôíÎó £¬Ð¹Â¶290Íò¸öÓû§µÄÐÅÏ¢¡£Ñо¿ÈËÔ±ÔÚ2021Äê8ÔÂ9ÈÕ·¢ÏÖ¸ÃÎÊÌâ £¬Ö±µ½9ÔÂ27ÈÕ²ÅÅû¶³öÀ´¡£´Ë´Î×ܼÆÐ¹Â¶ÁË38GBµÄÊý¾Ý £¬°üÂÞµç×ÓÓʼþ¡¢Éí·ÝÑéÖ¤ÁîÅÆ¡¢ÃÜÂë¡¢µÇ¼ÐÅÏ¢ºÍÆäËüµÄÉ罻ýÌåÐÅÏ¢µÈ¡£Éв»Çå³þÕâЩÊý¾ÝÊÇ·ñÒѱ»ÀûÓà £¬¸ÃÊý¾Ý¿âÔÚĿǰÒѱ»±£»¤ÆðÀ´¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/storybooks-for-children-app-farfaria-exposed-data/



CISAºÍNSAÁªºÏÐû²¼ÓйØÑ¡ÔñºÍ¼Ó¹ÌVPNµÄÄþ¾²Ö¸ÄÏ


CISAºÍNSAÁªºÏÐû²¼ÓйØÑ¡ÔñºÍ¼Ó¹ÌVPNµÄÄþ¾²Ö¸ÄÏ.png


ÃÀ¹úCISAºÍNSAÔÚ9ÔÂ28ÈÕÁªºÏÐû²¼ÁËÓйØÑ¡ÔñºÍ¼Ó¹ÌVPNµÄÄþ¾²Ö¸ÄÏ¡£Ö¸ÄÏÖ¸³ö £¬×éÖ¯Ó¦¸Ã´ÓÐÅÓþÁ¼ºÃµÄ¹©Ó¦ÉÌÄÇÀïÑ¡Ôñ²úÎï £¬ÒòΪËûÃÇ»áÒÔ×î¿ìµÄËÙ¶ÈÐÞ¸´ÒÑ֪©¶´¡£Äþ¾²»ú¹¹³Æ £¬VPNÉ豸¿ÉÒÔÊÕ¼¯Æ¾Ö¤¡¢ÓÃÀ´Ô¶³ÌÖ´ÐдúÂë¡¢Ï÷Èõ¼ÓÃÜÁ÷Á¿»á»°µÄ¼ÓÃÜ¡¢½Ù³Ö»á»°ÒÔ¼°¶ÁÈ¡Ãô¸ÐÐÅÏ¢ £¬½¨Òé×éÖ¯ÅäÖÃÇ¿¼ÓÃܺÍÉí·ÝÑéÖ¤¡¢½öÔËÐÐÐëÒªµÄ¹¦Ð§ÒÔ¼°±£»¤ºÍ¼à¿Ø¶ÔVPNµÄ·ÃÎÊ¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/09/28/cisa-and-nsa-release-guidance-selecting-and-hardening-vpns



KasperskyÐû²¼¶ñÒâÈí¼þBloodyStealerµÄ·ÖÎö³ÂËß


KasperskyÐû²¼¶ñÒâÈí¼þBloodyStealerµÄ·ÖÎö³ÂËß.png


KasperskyÔÚ9ÔÂ27ÈÕÐû²¼ÁËÓйضñÒâÈí¼þBloodyStealerµÄ·ÖÎö³ÂËß¡£Ñо¿ÈËÔ±3Ô·ÝÔÚ°µÍøÉÏ·¢ÏÖÁËÓйضñÒâÈí¼þBloodyStealerµÄ¹ã¸æ £¬¼Û¸ñÊÇ700¬²¼Ò»¸öÔ£¨Ô¼10ÃÀÔª£©»ò3000¬²¼Ò»´ÎÐÔ¹ºÖá£Ëü¿ÉÒÔÇÔÈ¡¶à¸öÓÎϷƽ̨µÄÕÊ»§ £¬°üÂÞSteam¡¢Epic Games Store ºÍEA Origin £¬»¹¾ßÓÐÈÆ¹ýÄþ¾²¼ì²âºÍ¶ñÒâÈí¼þ·ÖÎöµÄ¹¦Ð§¡£³ÂËßÖ¸³ö £¬×Ô·¢ÏÖÒÔÀ´ £¬¸ÃľÂíÖ÷ÒªÓÃÀ´Õë¶ÔÅ·ÖÞ¡¢À­¶¡ÃÀÖÞºÍÑÇÌ«µØÓòµÄÓû§¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/bloodystealer-and-gaming-assets-for-sale/104319/