ÀÕË÷Èí¼þWannaCry³Áлع飬£¬£¬£¬£¬£¬£¬¹¥»÷»î¶¯¼¤Ôö53£¥£»£»£»£»£»£»£»Ó¡¶È¹¤Òµ·¢Õ¹¹«Ë¾MIDCϰȾSYNack£¬£¬£¬£¬£¬£¬£¬±»ÀÕË÷50ÒÚ¬±È

°ä²¼¹¦·ò 2021-04-01

1.ÀÕË÷Èí¼þWannaCry³Áлع飬£¬£¬£¬£¬£¬£¬¹¥»÷»î¶¯¼¤Ôö53£¥


1.jpg


Check Point·¢ÏÖÀÕË÷Èí¼þWannaCry³Áлع飬£¬£¬£¬£¬£¬£¬¹¥»÷»î¶¯¼¤Ôö53£¥¡£¡£¡£ ¡£¡£¡£¡£¡£´ÓǰµÄ°ëÄêÖУ¬£¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þ¹¥»÷»î¶¯Ôö³¤ÁË57£¥£¬£¬£¬£¬£¬£¬£¬È«Çò×ܹ²²úÉúÁË50000ÂŴι¥»÷³¢ÊÔ£¬£¬£¬£¬£¬£¬£¬ÆäÖдóÎÞÊýÕë¶Ôµ±¾Ö¡¢¾üÊ¡¢Ôì×÷Òµ¡¢ÒøÐкͽðÈÚ²¿ÃŵÄ×éÖ¯¡£¡£¡£ ¡£¡£¡£¡£¡£³ýÁËÕý³£ÀÕË÷Èí¼þ£¨ÃÔ¹¬¡¢RyukºÍREvilµÈ£©±í£¬£¬£¬£¬£¬£¬£¬Check Point»¹°ÑÎȵ½WannaCryÀÕË÷Èí¼þÔö³¤ÁË53£¥¡£¡£¡£ ¡£¡£¡£¡£¡£2021Äê3ÔÂÊܸöñÒâÈí¼þÓ°ÏìµÄ×éÖ¯ÊýÁ¿ÊÇ2020Äê10ÔµÄ40±¶£¬£¬£¬£¬£¬£¬£¬ÆäÐÂÑù±¾ÈÔÀûÓÃÁËEternalBlue·ì϶½øÐзַ¢£¬£¬£¬£¬£¬£¬£¬Ö»¹ÜÕë¶Ô¸Ã·ì϶µÄ²¹¶¡ÒѰ䲼³¬¹ý4Äê¡£¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-exchange-attacks-increase-while-wannacry-gets-a-restart/


2.Talos·¢ÏÖ¶à¸ö½«¶ñÒâÈí¼þ¼Ù×°³ÉÓÎÏ·±í¹ÒµÄ¹¥»÷»î¶¯


2.jpg


×êÑÐÈËÔ±³ÆÔÚ¶à¸ö»î¶¯Öз¢ÏÖÁËÁ˼¸¸ö¿´ÆðÀ´ÏñÓÎÏ·²¹¶¡¡¢µ÷ÕûÆ÷»òÅú¸ÄÆ÷µÄÓ×¹¤¾ß´øÓÐÍÌ͵ĶñÒâÈí¼þ¡£¡£¡£ ¡£¡£¡£¡£¡£´Ó2010ÄêÆðÍ·»îÔ¾µÄÉÌÓÃRAT XtremeRAT¾ÍÊÇÆäÖÐÖ®Ò»£¬£¬£¬£¬£¬£¬£¬¿ÉÓÃÀ´ÇÔÈ¡Îĵµ¡¢¼Í¼¼üÅÌÊäÈë¡¢²¶»ñÆÁÄ»½ØÍ¼¡¢Ê¹ÓÃÉãÏñÍ·»òÂó¿Ë·ç¼ÔìÒôƵÒÔ¼°Í¨¹ýÔ¶³ÌshellÓëÊܺ¦Õß»¥¶¯µÈ¡£¡£¡£ ¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹Ê¹ÓÃÁ˸´ÔӵĻùÓÚVisualBasicµÄ¼ÓÃÜÆ÷ºÍShellcodeÀ´×èÖ¹·ÖÎöºÍ¼ì²â£¬£¬£¬£¬£¬£¬£¬²¢°µ²ØÆäpayload¡£¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/malware-hidden-in-game-cheats-and-mods-used-to-target-gamers/


3.VMware½¨¸´vRealize OperationsÖеÄSSRFµÈ¶à¸ö·ì϶


3.jpg


VMware°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬ÒÔ½¨¸´VMware vRealize OperationsÖеĶà¸ö·ì϶¡£¡£¡£ ¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ×îΪÑϳÁµÄ·ì϶ÊÇvRealize Operations Manager APIÖеķþÎñÆ÷¶ËÒªÇóαÔì·ì϶£¨CVE-2021-21975£©£¬£¬£¬£¬£¬£¬£¬CVSSv3ÆÀ·ÖΪ8.6£¬£¬£¬£¬£¬£¬£¬Ô¶³Ìδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÎÞÐèÓëÓû§½»»¥¼´¿ÉÀûÓô˷ì϶À´ÇÔÈ¡ÖÎÀíÍ´´¦¡£¡£¡£ ¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬»¹½¨¸´ÁËËÁÒâÎļþдÈë·ì϶£¨CVE-2021-21983£©£¬£¬£¬£¬£¬£¬£¬CVSSv3ÆÀ·ÖΪ7.2£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓÃÆäÔڵײã¹â×Ó²Ù×÷ϵͳµÄËÁÒâµØÎ»Ð´ÈëÎļþ¡£¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116145/security/vmware-vrealize-operations-ssrf-flaw.html


4.IoTÉ豸ÉÌUbiquitiÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬Êý¾Ý¿âºÍÔ´´úÂëй¶


4.jpg


ÍøÂçÉ豸ºÍÎïÁªÍø£¨IoT£©É豸ÌṩÉÌUbiquitiÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬Êý¾Ý¿âºÍÔ´´úÂëй¶¡£¡£¡£ ¡£¡£¡£¡£¡£1ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾Åû¶ÆäµÚÈý·½ÔÆÌṩÉÌй¶ÁËÆä¿Í»§µÄÕÊ»§Í´´¦¡£¡£¡£ ¡£¡£¡£¡£¡£µ«½üÆÚ£¬£¬£¬£¬£¬£¬£¬ÄäÃûΪAdamµÄ¾Ù±¨Õßй©ÊÂÎñÔ¶±È¿´ÉÏÈ¥ÑϳÁµÃ¶à¡£¡£¡£ ¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»rootÖÎÀíԱȨÏÞ½Ó¼ûËùÓÐUbiquiti AWSÕÊ»§£¬£¬£¬£¬£¬£¬£¬Ô̺¬ËùÓÐS3Êý¾ÝͰ¡¢ÀûÓ÷¨Ê½ÈÕÖ¾¡¢Êý¾Ý¿âºÍÓû§Í´´¦£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Î±Ôìµ¥µãµÇ¼£¨SSO£©CookieºÍÔ¶³Ì½Ó¼ûËùÐèµÄÃÜÔ¿¡¢ÆëÈ«µÄÔ´´úÂë½ÚÔìÄÚÈݺÍÊðÃûÃÜÔ¿¡£¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://krebsonsecurity.com/2021/03/whistleblower-ubiquiti-breach-catastrophic/


5.Ó¡¶È¹¤Òµ·¢Õ¹¹«Ë¾MIDCϰȾSYNack£¬£¬£¬£¬£¬£¬£¬±»ÀÕË÷50ÒÚ¬±È


5.jpg


Ó¡¶ÈÃÏÂòµÄMaharashtra¹¤Òµ·¢Õ¹¹«Ë¾£¨MIDC£©µÄ·þÎñÆ÷ϰȾSYNack£¬£¬£¬£¬£¬£¬£¬±»ÀÕË÷50ÒÚ¬±È£¨Ô¼ºÏ6800ÍòÃÀÔª£©¡£¡£¡£ ¡£¡£¡£¡£¡£MIDC³Æ¹¥»÷²úÉúÔÚ3ÔÂ21ÈÕÖÜÈÕÁ賿2:30×óÓÒ£¬£¬£¬£¬£¬£¬£¬ÆäÊ×ÏÈÊÕµ½ÁËÀûÓ÷¨Ê½¹Ø¹ØµÄ¾¯±¨£¬£¬£¬£¬£¬£¬£¬¾­·ÖÎöÆäÔâµ½ÁËÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾Á¢¿Ì½«MIDCϵͳÓëÍøÂç¶Ï¿ªÒÔ¶ôÔ첡¶¾µÄ´«²¼¡£¡£¡£ ¡£¡£¡£¡£¡£Õâ´Î¹¥»÷Ó°ÏìÁËMIDCʹÓõÄÀûÓ÷¨Ê½ºÍÊý¾Ý¿â·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°²¿ÃĄ̊ʽ»ú£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°¸Ã¹«Ë¾Î»ÓÚ16¸öµØÓòµÄËùÓд¦Ê´¦¶¼ÒѹعØ¡£¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/03/midcs-server-hacked-threat-to-destroy.html


6.WatchGuard°ä²¼2020ÄêQ4¶ñÒâÈí¼þºÍÍøÂç¹¥»÷·ÖÎö»ã±¨


6.jpg


WatchGuard°ä²¼ÁË2020ÄêQ4¶ñÒâÈí¼þºÍÍøÂç¹¥»÷µÄ·ÖÎö»ã±¨¡£¡£¡£ ¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬£¬2020ÄêÎÞÎļþ¶ñÒâÈí¼þÊýÁ¿£¨fileless malware£©±È2019ÄêÔö³¤ÁË888£¥£¬£¬£¬£¬£¬£¬£¬ÖîÈçPowerSploitºÍCobaltStrikeÖ®ÀàµÄ¹¤¾ß°ü£¬£¬£¬£¬£¬£¬£¬¼´±ãÊܺ¦Õß¼ø±ð²¢É¾³ýÁËԭʼ¾ç±¾£¬£¬£¬£¬£¬£¬£¬ËüÃÇÈԿɳÖÐøÔËÐС£¡£¡£ ¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬¼ÓÃܿ󹤵ļìÕÉÁ¿±È2019ÄêÔö³¤ÁË25£¥ÒÔÉÏ£¬£¬£¬£¬£¬£¬£¬¶à´ï850ÖÖ±äÌ壬£¬£¬£¬£¬£¬£¬¶øÀÕË÷Èí¼þ¹¥»÷Á¿³Ê½µÂäÇ÷Ïò´Ó2019ÄêµÄ4131¸öpayload½µÂäµ½2152¸ö¡£¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.watchguard.com/wgrd-resource-center/security-report-q4-2020