KasperskyÐû²¼¶ñÒâÈí¼þ·ÖÎö³ÂËߣºFarFariaÓ¦ÓõÄÊý¾Ý¿âй¶290ÍòÓû§ÐÅÏ¢
Ðû²¼Ê±¼ä 2021-09-30΢Èí·¢ÏÖÖ¼ÔÚÇÔÈ¡AD FS¹ÜÀíԱƾ¾ÝµÄºóÃÅFoggyWeb
΢ÈíÍþвÇ鱨ÖÐÐÄ(MSTIC)ÓÚ9ÔÂ27ÈÕÅû¶ÁËÖ¼ÔÚÇÔÈ¡Active DirectoryÁªºÏÉí·ÝÑéÖ¤·þÎñ(AD FS)¹ÜÀíԱƾ¾ÝµÄºóÃÅFoggyWeb¡£¸Ã¶ñÒâÈí¼þÓë¶íÂÞ˹Íâ¹úÇ鱨¾Ö(SVR)µÄºÚ¿ÍÍÅ»ïNobeliumÓйأ¬ÀÄÓÃÁËSAMLÁîÅÆ¡£Ëü¿ÉÒÔΪ¹¥»÷Õß½ç˵µÄURIÅäÖÃHTTP¼àÌýÆ÷£¨ÕâЩURIÄ£·ÂÁËÄ¿±êAD FSʹÓõĺϷ¨URIµÄ½á¹¹£©£¬À´¼àÌý·¢Ë͵½AD FSµÄHTTP GETºÍPOSTÇëÇ󣬲¢À¹½ØÓë×Ô½ç˵URIģʽƥÅäµÄHTTPÇëÇó¡£
ÔÎÄÁ´½Ó£º
https://www.microsoft.com/security/blog/2021/09/27/foggyweb-targeted-nobelium-malware-leads-to-persistent-backdoor/
Ñо¿ÈËÔ±·¢ÏÖÕë¶Ô²¨À¼µÄÐÂAndroidÒøÐÐľÂíERMAC
ºÉÀ¼Äþ¾²¹«Ë¾ThreatFabric·¢ÏÖÁËÒ»ÖÖÃûΪERMACµÄÐÂAndroidÒøÐÐľÂí¡£¸Ã¶ñÒâÈí¼þ»ùÓÚCerberus£¨ÆäÔ´´úÂëÒÑÓÚ2020Äê9ÔÂÔÚºÚ¿ÍÂÛ̳¹ûÈ»£©£¬ÓëBlackRock±³ºóµÄÔËÓªÉÌÓйء£ÓëCerberusÏà±È£¬ERMACʹÓÃÁËBlowfish¼ÓÃÜËã·¨£¬¶øÇÒÔÚÓëC2µÄͨÐÅÖÐʹÓÃÁËAES-128-CBC¼ÓÃÜ·½°¸¡£Ñо¿ÈËÔ±³Æ£¬ERMAC×Ô8ÔÂÏÂÑ®¿ªÊ¼»îÔ¾£¬¿ªÊ¼Î±×°³ÉGoogle Chrome£¬Ö®ºó»¹Î±×°³Éαװ³É·À²¡¶¾¡¢ÒøÐкÍýÌå²¥·ÅÆ÷µÈÓ¦Ó㬿ÉÕë¶Ô378¸ö½ðÈÚÏà¹ØµÄÓ¦Ó÷¨Ê½¡£
ÔÎÄÁ´½Ó£º
https://www.threatfabric.com/blogs/ermac-another-cerberus-reborn.html
QNAPÐû²¼¸üУ¬ÐÞ¸´QVRÖÐ3¸öÑÏÖØµÄÃüÁî×¢Èë©¶´
NASÖÆÔìÉÌQNAPÔÚ9ÔÂ27ÈÕÐû²¼Äþ¾²¸üУ¬ÐÞ¸´ÁËÊÓÆµ¹ÜÀíϵͳQVRÖÐ3¸öÑÏÖØµÄÃüÁî×¢Èë©¶´¡£ÆäÖеÄÁ½¸ö©¶´CVSSÆÀ·ÖΪ9.8£¬Ô¶³Ì¹¥»÷Õß¿ÉÀûÓÃÆäÔÚÄ¿±êϵͳÉÏÖ´ÐÐÃüÁ´Ó¶øÍêÈ«¿ØÖÆÉ豸¡£ÁíÍâÒ»¸ö©¶´×·×ÙΪCVE-2021-34349£¬CVSSÆÀ·ÖΪ7.2£¬ÓëÇ°ÃæÁ½¸ö©¶´µÄ²îÒìÊÇÀûÓÃËùÐèµÄȨÏÞ²îÒì¡£QNAPÖ¸³ö£¬ÆäÖÐÁ½¸ö©¶´»¹Ó°ÏìÁ˲¿ÃÅEOLÉ豸¡£Ä¿Ç°£¬Éв»Çå³þÕâЩ©¶´ÊÇ·ñÒѱ»ÔÚÒ°ÀûÓÃÁË¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/qnap-fixes-critical-bugs-in-qvr-video-surveillance-solution/
FarFariaÓ¦ÓõÄÊý¾Ý¿âÅäÖôíÎóй¶290Íò¸öÓû§µÄÐÅÏ¢
Comparitech·¢ÏÖ¶ùͯ¹ÊÊÂÊéÓ¦ÓÃFarFariaµÄMongoDBÊý¾Ý¿âÅäÖôíÎó£¬Ð¹Â¶290Íò¸öÓû§µÄÐÅÏ¢¡£Ñо¿ÈËÔ±ÔÚ2021Äê8ÔÂ9ÈÕ·¢ÏÖ¸ÃÎÊÌ⣬ֱµ½9ÔÂ27ÈÕ²ÅÅû¶³öÀ´¡£´Ë´Î×ܼÆÐ¹Â¶ÁË38GBµÄÊý¾Ý£¬°üÂÞµç×ÓÓʼþ¡¢Éí·ÝÑéÖ¤ÁîÅÆ¡¢ÃÜÂë¡¢µÇ¼ÐÅÏ¢ºÍÆäËüµÄÉ罻ýÌåÐÅÏ¢µÈ¡£Éв»Çå³þÕâЩÊý¾ÝÊÇ·ñÒѱ»ÀûÓ㬸ÃÊý¾Ý¿âÔÚĿǰÒѱ»±£»¤ÆðÀ´¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/storybooks-for-children-app-farfaria-exposed-data/
CISAºÍNSAÁªºÏÐû²¼ÓйØÑ¡ÔñºÍ¼Ó¹ÌVPNµÄÄþ¾²Ö¸ÄÏ
ÃÀ¹úCISAºÍNSAÔÚ9ÔÂ28ÈÕÁªºÏÐû²¼ÁËÓйØÑ¡ÔñºÍ¼Ó¹ÌVPNµÄÄþ¾²Ö¸ÄÏ¡£Ö¸ÄÏÖ¸³ö£¬×éÖ¯Ó¦¸Ã´ÓÐÅÓþÁ¼ºÃµÄ¹©Ó¦ÉÌÄÇÀïÑ¡Ôñ²úÎÒòΪËûÃÇ»áÒÔ×î¿ìµÄËÙ¶ÈÐÞ¸´ÒÑ֪©¶´¡£Äþ¾²»ú¹¹³Æ£¬VPNÉ豸¿ÉÒÔÊÕ¼¯Æ¾Ö¤¡¢ÓÃÀ´Ô¶³ÌÖ´ÐдúÂë¡¢Ï÷Èõ¼ÓÃÜÁ÷Á¿»á»°µÄ¼ÓÃÜ¡¢½Ù³Ö»á»°ÒÔ¼°¶ÁÈ¡Ãô¸ÐÐÅÏ¢£¬½¨Òé×éÖ¯ÅäÖÃÇ¿¼ÓÃܺÍÉí·ÝÑéÖ¤¡¢½öÔËÐÐÐëÒªµÄ¹¦Ð§ÒÔ¼°±£»¤ºÍ¼à¿Ø¶ÔVPNµÄ·ÃÎÊ¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2021/09/28/cisa-and-nsa-release-guidance-selecting-and-hardening-vpns
KasperskyÐû²¼¶ñÒâÈí¼þBloodyStealerµÄ·ÖÎö³ÂËß
KasperskyÔÚ9ÔÂ27ÈÕÐû²¼ÁËÓйضñÒâÈí¼þBloodyStealerµÄ·ÖÎö³ÂËß¡£Ñо¿ÈËÔ±3Ô·ÝÔÚ°µÍøÉÏ·¢ÏÖÁËÓйضñÒâÈí¼þBloodyStealerµÄ¹ã¸æ£¬¼Û¸ñÊÇ700¬²¼Ò»¸öÔ£¨Ô¼10ÃÀÔª£©»ò3000¬²¼Ò»´ÎÐÔ¹ºÖá£Ëü¿ÉÒÔÇÔÈ¡¶à¸öÓÎϷƽ̨µÄÕÊ»§£¬°üÂÞSteam¡¢Epic Games Store ºÍEA Origin£¬»¹¾ßÓÐÈÆ¹ýÄþ¾²¼ì²âºÍ¶ñÒâÈí¼þ·ÖÎöµÄ¹¦Ð§¡£³ÂËßÖ¸³ö£¬×Ô·¢ÏÖÒÔÀ´£¬¸ÃľÂíÖ÷ÒªÓÃÀ´Õë¶ÔÅ·ÖÞ¡¢À¶¡ÃÀÖÞºÍÑÇÌ«µØÓòµÄÓû§¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/bloodystealer-and-gaming-assets-for-sale/104319/