¶íÂÞ˹FSBÀֳɵ·»ÙÀÕË÷ÍÅ»ïREvil²¢´þ²¶Æä14Ãû³ÉÔ±

Ðû²¼Ê±¼ä 2022-01-18

¶íÂÞ˹FSBÀֳɵ·»ÙÀÕË÷ÍÅ»ïREvil²¢´þ²¶Æä14Ãû³ÉÔ±


¶íÂÞ˹FSBÀֳɵ·»ÙÀÕË÷ÍÅ»ïREvil²¢´þ²¶Æä14Ãû³ÉÔ±.png


¾ÝýÌå1ÔÂ4ÈÕ±¨µÀ £¬¶íÂÞ˹Áª°îÄþ¾²¾ÖFSBÒÑÀֳɵ·»ÙÀÕË÷ÍÅ»ïREvil¡£REvilÊÇÈ¥Äê×î»îÔ¾µÄÀÕË÷ÍÅ»ïÖ®Ò» £¬Ôø¹¥»÷ÁËJBSºÍKaseya¡£¾Ý³ÆÕâÊÇÓ¦ÃÀ¹úÕþ¸®ÒªÇó½øÐеÄͻϮÐж¯ £¬Ö´·¨»ú¹¹ËѲéÁËĪ˹¿ÆºÍÊ¥±ËµÃ±¤µÈ¶¼ÊеÄ25¸öËùÔÚ £¬²¢´þ²¶ÁË14ÃûÍÅ»ï³ÉÔ± £¬ÆäÖÐ1È˼ÓÈëÁË2021Äê5ÔÂÕë¶ÔColonial PipelineµÄ¹¥»÷ £¬ÕâÔÙ´Î֤ʵÁËREvilÓëDarkSideÓйØÁª ¡£´ËÍâ £¬FSB»¹²é»ñÁËÁè¼Ý4.26ÒÚ¬²¼ £¬ÒÔ¼°ÓÃÓÚ·¸×ï»î¶¯µÄ¼ÆËã»ú¡¢¼ÓÃÜÇ®°üºÍ20Á¾Æû³µ¡£


https://threatpost.com/russian-security-revil-ransomware/177660/


ÎÚ¿ËÀ¼µÄ70¶à¸ö¹Ù·½ÍøÕ¾Í¬Ê±Ôâµ½´ó¹æÄ£¹¥»÷


1ÔÂ14ÈÕ £¬ÎÚ¿ËÀ¼Õþ¸®ÔËÓªµÄÁè¼Ý70¸öÍøÕ¾ÀëÏßÊýСʱ¡£ÕâËÆºõÊÇÔ´ÓÚÒ»³¡´ó¹æÄ£µÄÐ­Í¬ÍøÂç¹¥»÷ £¬¸Ã¹úÖ´·¨²¿ÃÅÌåÏÖ¿ÉÄÜÓë¶íÂÞ˹ÓйØ¡£ÎÚ¿ËÀ¼CERTÉù³ÆÕâЩ¹¥»÷¿ÉÄÜÀûÓÃÁËLaravel-based October CMSÖеÄ©¶´(CVE-2021-32648) £¬Õë¶ÔÎÚ¿ËÀ¼ÄÚ¸ó¡¢½ÌÓý¡¢Å©Òµ¡¢ÄÜÔ´¡¢ÍËÎé¾üÈËÊÂÎñºÍ»·¾³²¿µÈ¶à¸ö²¿ÃŵÄÍøÕ¾¡£´Ë´Î¹¥»÷»î¶¯½öÔÚ±»ÈëÇÖÍøÕ¾µÄÖ÷Ò³ÉÏÐû²¼ÁËÌôÐÆÐÔÐÅÏ¢ £¬²¢ÎÞ¸öÈËÊý¾Ýй¶µÄÇé¿ö¡£


https://thehackernews.com/2022/01/massive-cyber-attack-knocks-down.html


È«Çò×î´óÐÅÓÿ¨½»Ò×°µÍøÊг¡UniCCÐû²¼½«Í£Ö¹ÔËÓª


ýÌå1ÔÂ15ÈÕ±¨µÀ £¬È«Çò×î´óµÄÐÅÓÿ¨ºÍ½è¼Ç¿¨ÐÅÏ¢½»Ò×°µÍøÊг¡UniCCÐû²¼½«Í£Ö¹ÔËÓª¡£¸ÃÍøÕ¾ÓÚ2013ÄêÍÆ³ö £¬¾ÝÔ¤¼ÆÍ¨¹ý¸Ãƽ̨½»Ò׵ļÓÃÜ»õ±ÒԼΪ3.58ÒÚÃÀÔª £¬1ÔÂ·ÝÆäÊг¡·Ý¶îµ½´ïÁË30%¡£UniCC¹ÜÀíÔ±ÔÚÐû²¼¹Ø±ÕÏûÏ¢ºó¸ø»áÔ±Áô³öÁË10Ììʱ¼äÀ´Ïû·ÑÓà¶î £¬²¢ÌåÏÖÕâÊÇËûÃÇ×ö³öµÄ¾ö¶¨ £¬²»Òª½øÐÐÒõıÂÛ¡£´ËÍâ £¬½ü¼¸¸öÔÂÓжà¸ö°µÍøÊг¡¹Ø±Õ £¬°üÂÞWhite House Market£¨10Ô£©¡¢Cannazon£¨11Ô£©¡¢Torrez£¨12Ô£©ºÍMonopoly Market£¨1Ô³õ£©¡£


https://securityaffairs.co/wordpress/126757/cyber-crime/unicc-shutting-down.html


ÀÕË÷Èí¼þQlocker»Ø¹é £¬ÔÙ´ÎÃé׼ȫÇòµÄQNAP NASÉ豸


¾ÝýÌå1ÔÂ15ÈÕ³Æ £¬ÀÕË÷Èí¼þQlocker»Ø¹é £¬²¢ÔÙ´ÎÃé׼ȫÇòµÄQNAPÍøÂ總¼Ó´æ´¢(NAS)É豸¡£´ËǰQlockerÔøÔÚ4ÔÂ19ÈÕ¿ªÊ¼´ó¹æÄ£¹¥»÷QNAP¿Í»§ £¬²¢Ê¹ÓÃ7-zip¼ÓÃÜÊý¾Ý¡£ÐµÄÀÕË÷»î¶¯Ê¼ÓÚ1ÔÂ6ÈÕ £¬Ëü»áÔÚ±»ÈëÇÖÉ豸ÉÏÁôÏÂÃûΪ!!!READ_ME.txtµÄÊê½ð¼Ç¼ £¬ÆäÖдó²¿ÃÅÄ¿±ê±»ÒªÇóÖ§¸¶0.02µ½0.03±ÈÌØ±Ò¡£Õâ²¢²»ÊÇΨһÕë¶ÔQNAP NASµÄÀÕË÷Èí¼þ £¬×ÔÊ¥µ®½Ú¿ªÊ¼ £¬ech0raixÕë¶ÔÆäµÄ¹¥»÷»î¶¯¼¤Ôö¡£


https://www.bleepingcomputer.com/news/security/qlocker-ransomware-returns-to-target-qnap-nas-devices-worldwide/


¹ú·À³Ð°üÉÌHensoldt³ÆÆäÓ¢¹ú×Ó¹«Ë¾ÒÑѬȾLorenz


¾Ý1ÔÂ14Èյı¨µÀ³Æ £¬µÂ¹ú¹ú·À³Ð°üÉÌHensoldtÈÏ¿ÉÆäÓ¢¹ú×Ó¹«Ë¾ÒÑѬȾÀÕË÷Èí¼þLorenz¡£Lorenz×Ô4Ô¿ªÊ¼»îÔ¾ £¬Êê½ðÒªÇóΪ500000µ½700000ÃÀÔªÖ®¼ä¡£2021Äê12ÔÂ17ÈÕ £¬LorenzÉù³ÆÒѹ¥»÷Hensoldt £¬²¢ÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ÒÔÃÜÂë±£»¤ÎļþµÄÐÎʽÐû²¼ÁË95%µÄ±»µÁÎļþ¡£¸Ã¹«Ë¾ÔÚÉÏÖÜÈ·ÈÏÆäÔâµ½¹¥»÷ £¬µ«Ö»ÓÐÓ¢¹ú×Ó¹«Ë¾µÄ²¿ÃÅÒÆ¶¯É豸Êܵ½ÁËÓ°Ïì¡£


https://securityaffairs.co/wordpress/126738/malware/lorenz-ransomware-hit-hensoldt.html


eNomÊý¾ÝÖÐÐÄÇ¨ÒÆ·¢Éú´íÎóµ¼Ö·þÎñÔÝʱÖжÏ


1ÔÂ16ÈÕ £¬ÍøÂçÍйܷþÎñÉÌeNomµÄÊý¾ÝÖÐÐÄÇ¨ÒÆ·ºÆð´íÎó £¬µ¼Ö·þÎñÔÝʱÖжÏ¡£²¿ÃÅÓû§³ÂËß³ÆÎÞ·¨ÔÙ·ÃÎÊÍøÕ¾ºÍÓÊÏä £¬»¹ÓÐÓû§ÌåÏÖÆäGmailÏÔʾÒòΪeNomÕýÔÚ½øÐÐÊý¾ÝÖÐÐÄÇ¨ÒÆ £¬DNSÎÞ·¨Õý³£ÊÂÇé¡£¾­¹ýÊÓ²ì £¬¸Ã¹«Ë¾·¢ÏÖÓòÃû½âÎöÎÊÌâÓ°ÏìÁËÊý°Ù¸öÓòÃû £¬ÊÜÎÊÌâÓ°ÏìÓû§ÎÞ·¨¸ü¸ÄNameServers £¬ËûÃÇËùÄÜ×öµÄ¾ÍÊÇÆÚ´ýÇ¨ÒÆÍê³É¡£


https://www.bleepingcomputer.com/news/security/enom-data-center-migration-mistakenly-knocks-sites-offline/


Äþ¾²¹¤¾ß


PasteMonitor


ץȡ Pastebin API ÒÔÊÕ¼¯Ã¿ÈÕÕ³Ìù £¬ÉèÖÃwordlist²¢ÔÚÆ¥Åäʱͨ¹ýµç×ÓÓʼþ½ÓÊÕ¾¯±¨¡£


https://github.com/pixelbubble/PasteMonitor


ipsourcebypass


´Ë Python ½Å±¾¿ÉÓÃÓÚÈÆ¹ýʹÓà HTTP ±êÍ·µÄ IP Ô´ÏÞÖÆ¡£


https://github.com/p0dalirius/ipsourcebypass


elfloader


elfloader ÊÇÒ»¸ö³¬¼¶¼òµ¥µÄ ELF Îļþ¼ÓÔØÆ÷ £¬ËüÉú³ÉELFÔÚÄÚ´æÖÐµÄÆ½ÃæÌåÏÖ¡£


https://github.com/gamozolabs/elfloader


Äþ¾²·ÖÎö


ÓÉÓÚÆúÓÃSGX £¬ÐµÄÓ¢ÌØ¶ûоƬ½«ÎÞ·¨²¥·ÅÀ¶¹â¹âÅÌ


µÚ12´úÓ¢ÌØ¶û¿áî£11000ºÍ12000´¦ÖÃÆ÷È¡ÏûÁ˶ÔSGX£¨Èí¼þ±£»¤À©Õ¹£©µÄÖ§³Ö £¬µ¼ÖÂPCÎÞ·¨²¥·Å4K·Ö±æÂʵÄÀ¶¹â¹âÅÌ¡£


https://www.bleepingcomputer.com/news/security/new-intel-chips-wont-play-blu-ray-disks-due-to-sgx-deprecation/


CVE-2021-45039£ºÔ¶³Ì´úÂëÖ´ÐЩ¶´


UniviewרÓÐЭÒé¼àÌýUDP¶Ë¿Ú7788µÄ©¶´ÔÊÐíÔ¶³Ìδ¾­Éí·ÝÑéÖ¤µÄÀûÓûº³åÇøÒç³ö©¶´ £¬¿É»ñµÃ¶ÔÉ豸µÄroot·ÃÎÊȨ¡£


https://ssd-disclosure.com/ssd-advisory-uniview-preauth-rce/