Ó¢ÃÀ°Ä½áºÏ°ä²¼2020Äê³£±»ÀûÓ÷ì϶µÄ°²È«Õ÷ѯ£»£»£»£»£»£»×êÑÐÈËÔ±½«Åû¶Hyper-VÖдúÂëÖ´Ðзì϶µÄ¾ßÌåÐÅÏ¢
°ä²¼¹¦·ò 2021-07-301.Ó¢ÃÀ°Ä½áºÏ°ä²¼2020Äê³£±»ÀûÓ÷ì϶µÄ°²È«Õ÷ѯ

ÃÀ¹ú¡¢Ó¢¹úºÍ°Ä´óÀûÑÇÍøÂ簲ȫ»ú¹¹½áºÏ°ä²¼Ò»·Ý½áºÏÅû¶2020Äê³£±»ÀûÓ÷ì϶£¬£¬£¬£¬£¬¸ÃÕ÷ѯÔ̺¬Ã¿¸ö·ì϶µÄ¼¼Êõϸ½Ú£¬£¬£¬£¬£¬ÀýÈçÇÖº¦Ö¸±ê(IoCs)ÒÔ¼°ÕâЩ·ì϶µÄ»º½â´ëÊ©¡£¡£¡£¡£¡£¡£¡£Õ÷ѯָ³ö£¬£¬£¬£¬£¬2020Äê×î¾ßÕë¶ÔÐÔµÄËĸö·ì϶ӰÏìÁËÔ¶³Ì¹¤×÷¡¢vpn»ò»ùÓÚÔÆ¼¼Êõ¡£¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶Ô̺¬Microsoft ExchangeÖеÄCVE-2021-26855ºÍCVE-2021-26857µÈ¡¢Pulse SecureÖеÄCVE-2021-22893ºÍCVE-2021-22894µÈ£¬£¬£¬£¬£¬ÒÔ¼°VMwareÖеÄCVE-2021-21985µÈ·ì϶¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/120644/hacking/top-routinely-flaws-exploited.html
2.ProofpointÅû¶ÒÁÀʺڿÍÕë¶Ô¹ú·À³Ð°üÉ̵Ĺ¥»÷»î¶¯

°²È«¹«Ë¾ProofpointÅû¶ÒÁÀʺڿÍÕë¶Ô¹ú·À³Ð°üÉ̵Ĺ¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£ÕâȺºÚ¿ÍÀûÓÃÉ罻ýÌåÆ½Ì¨£¬£¬£¬£¬£¬³ö¸ñÊÇFacebook£¬£¬£¬£¬£¬ÇÔÈ¡º½¿Õ·ÀÎñ³Ð°üÉÌÔ±¹¤µÄµÇ¼ƾ֤¡£¡£¡£¡£¡£¡£¡£Proofpoint×êÑÐÈËÔ±Ö¸³ö£¬£¬£¬£¬£¬Õâ´Î¹¥»÷»î¶¯ÖÁÉÙ³ÖÐøÁË18¸öÔ£¬£¬£¬£¬£¬ºÚ¿Í¼Ù×°³ÉÀ´×ÔÓ¢¹úÀûÎïÆÖµÄ½¡ÃÀ²Ù¶ÍÁ·£¬£¬£¬£¬£¬Ö¸±êÊÇÃÀ¹ú¡¢Ó¢¹úºÍÅ·ÖÞµÄԼĪ200Ãû¾üÊÂÈËÔ±ÒÔ¼°º½¿Õº½ÌìºÍ³Ð°üÉÌ¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬ÓÐÖ¤¾ÝÅú×¢Õâ´Î»î¶¯ÓëTA456Óйأ¨Ò²±»³ÆÎªTortoiseshell£©£¬£¬£¬£¬£¬¶ø¸ÃÍÅ»ïÓëÒÁÀʾüʲ¿ÃÅ¡°ÒÁ˹À¼¸ïÃüÎÀ¶Ó¡±(IRGC)¹ØÏµÇ×êÇ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/hackers-malware-aerospace-defense-contractor/
3.PKPLUGÍÅ»ïÀûÓÃжñÒâÈí¼þTHORÕë¶Ô¶«ÄÏÑǵÄ×éÖ¯

Unit 42×êÑÐÍŶӷ¢ÏÖºÚ¿ÍÍÅ»ïPKPLUGÀûÓÃжñÒâÈí¼þTHORÕëµÄ»î¶¯¡£¡£¡£¡£¡£¡£¡£PKPLUG(±ðÃûMustang Panda£©ÊÇÒ»¸ö¼äµý×éÖ¯£¬£¬£¬£¬£¬ÖØÒªÕë¶Ô¶«ÄÏÑǵÄÖ¸±ê¡£¡£¡£¡£¡£¡£¡£THORΪ¶ñÒâÈí¼þPlugXµÄ±äÌ壬£¬£¬£¬£¬Æä×îÔçÄܹ»×·Òäµ½2019Äê8Ô¡£¡£¡£¡£¡£¡£¡£PKPLUGʹÓÃÁËÒ»ÖÖÃûΪ¡°living off the land¡±µÄ¼¼ÊõÀ´Èƹý²¡¶¾¼ì²â²¢¶Ô×¼Microsoft Exchange·þÎñÆ÷£¬£¬£¬£¬£¬Ê×ÏÈÀûÓúϷ¨µÄ¿ÉÖ´ÐÐÎļþ£¬£¬£¬£¬£¬ÈçBITSAdmin£¬£¬£¬£¬£¬´ÓGitHub´æ´¢¿âÏÂÔØÒ»¸öÃûΪAro.datµÄÎÞº¦Îļþ¡£¡£¡£¡£¡£¡£¡£Aro.datÒ»µ©±»¼ÓÔØµ½ÄÚ´æÖÐ¾ÍÆðÍ·×Ô¼º½â°ü£¬£¬£¬£¬£¬²¢ÆðÍ·ÓëC2·þÎñÆ÷ͨѶ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/120636/malware/chinese-cyberspies-thor-rat.html
4.×êÑÐÈËÔ±½«Åû¶Hyper-VÖдúÂëÖ´Ðзì϶µÄ¾ßÌåÐÅÏ¢

×êÑÐÈËÔ±HarpazºÍHadar´òËãÔÚ8ÔÂ4ÈյĺÚñ°²È«»áÒéÉϽéÉÜHyper-VÖдúÂëÖ´Ðзì϶£¬£¬£¬£¬£¬ÒÔ¼°ÈôºÎʹÓÃÄÚ²¿ÍÌÍ·¨Ê½hAFL1·¢ÏÖÕâ¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶¸ú×ÙΪCVE-2021-28476£¬£¬£¬£¬£¬ÆÀ·ÖΪ9.9£¬£¬£¬£¬£¬¿Éµ¼Ö»ؾø·þÎñ»òÔÚÖ÷»úÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£ËüÔÚ2019Äê8Ô³õ´Î³öÏÖ£¬£¬£¬£¬£¬²¢ÓÚ½ñÄê5ÔÂÊÕµ½Á˲¹¶¡¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬¹ÌÈ»Azure·þÎñ²»»á³öÏÖÕâ¸öÎÊÌ⣬£¬£¬£¬£¬µ«Ò»Ð©±¾µØHyper-V²¿ÊðÒÀÈ»ÈÝÒ×Êܵ½¹¥»÷£¬£¬£¬£¬£¬¶ø´óÁ¿ÖÎÀíÔ±²¢Î´ÔÚ²¹¶¡°ä²¼Ê±¾Í¸üÐÂWindowsϵͳ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/critical-microsoft-hyper-v-bug-could-haunt-orgs-for-a-long-time/
5.IBM Security°ä²¼2021ÄêÊý¾Ýй¶³É±¾µÄ·ÖÎö»ã±¨

IBM Security°ä²¼ÁË2021ÄêÊý¾Ýй¶³É±¾µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬»ã±¨¹À¼Æ£¬£¬£¬£¬£¬2021ÄêÆóÒµÔâ·êÒ»´ÎµäÐÍÊý¾Ýй¶±äÂÒ£¨Éæ¼°1000-10Íò±Ê¼Í¼£©µÄ³É±¾Îª424ÍòÃÀÔª£¬£¬£¬£¬£¬±È2020ÄêÓâÔ½10%¡£¡£¡£¡£¡£¡£¡£¶ø¶ÔÓÚÄÇЩÑϳÁµÄ±äÂÒ£¬£¬£¬£¬£¬¼Å×°ÏìÁË5000ÍòÖÁ6500Íò¼Í¼µÄ¶¥¼¶ÆóÒµ¹«Ë¾£¬£¬£¬£¬£¬Ôò±ØÒªÖ§³ö¸ü¸ßµÄ¼ÛÖµ¡ª¡ª¾ùÔÈ񻮮·Ñ4.01ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¡£IBM³Æ£¬£¬£¬£¬£¬Ñ¡È¡»ùÓÚÈËΪÖÇÄÜ(AI)Ëã·¨¡¢»úе½ø½¨¡¢·ÖÎöºÍ¼ÓÃܵݲȫ½â¾ö¹æ»®µÄ¹«Ë¾¶¼½µµÍÁËDZÔÚÈëÇÖËðʧ£¬£¬£¬£¬£¬¾ùÔÈΪ¹«Ë¾½Ú¼óÁË125Íòµ½149ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.ibm.com/security/data-breach
6.±±°®¶ûÀ¼DoH³ÆÆäCOVIDCert NI·þÎñµÄÓû§ÐÅÏ¢ÒÑй¶

±±°®¶ûÀ¼ÎÀÉú²¿(DoH)³ÆÆäCOVIDCert NI·þÎñй¶²¿ÃÅÓû§µÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£COVIDCert NI·þÎñÖØÒªÓÃÓÚΪ±±°®¶ûÀ¼µÄµÄ½ÓÖÖÕßÐû¸æÈ·ÈÏÆäCOVID-19ÒßÃç½ÓÖÖ״̬µÄÊý×ÖÖ¤Ê飬£¬£¬£¬£¬¸Ã²¿ÃŰµÊ¾£¬£¬£¬£¬£¬ÔÚijЩÇé¿öϸ÷þÎñ»áÏòһЩÓû§ÏÔʾÆäËûÓû§µÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°¸Ã·þÎñµÄÍøÕ¾covidcertni.nidirect.gov.ukºÍÒÆ¶¯ÀûÓö¼´¦ÓڹعØ×´Ì¬£¬£¬£¬£¬£¬¶ø±±°®¶ûÀ¼ÎÀÉú²¿ÔÚÖÂÁ¦½â¾öÕâÒ»ÎÊÌâ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/northern-ireland-suspends-vaccine-passport-system-after-data-leak/


¾©¹«Íø°²±¸11010802024551ºÅ