NSOÀûÓÃiMessageÖеÄÐÂÁãµã»÷·ì϶¹¥»÷°ÍÁÖ»îÔ¾ÈËÊ¿:F5°ä²¼°²È«¸üн¨¸´Æä¶à¿î²úÆ·

°ä²¼¹¦·ò 2021-08-27

NSOÀûÓÃiMessageÖеÄÐÂÁãµã»÷·ì϶¹¥»÷°ÍÁÖ»îÔ¾ÈËÊ¿


NSOÀûÓÃiMessageÖеÄÐÂÁãµã»÷·ì϶¹¥»÷°ÍÁÖ»îÔ¾ÈËÊ¿.jpg


Citizen LabÓÚ2021Äê8ÔÂ24ÈÕ°ä²¼ÁËÒ»Ïî×êÑУ¬£¬£¬ £¬£¬£¬£¬³ÆNSO GroupÀûÓÃiMessageÖÐеÄÁãµã»÷·ì϶ÔÚÖ¸±êiPhoneÉÏ×°ÖüäµýÈí¼þPegasus¡£¡£¡£¡£¡£×êÑÐÅú×¢£¬£¬£¬ £¬£¬£¬£¬Õâ´Î¹¥»÷ʼÓÚ2021Äê7Ô£¬£¬£¬ £¬£¬£¬£¬ÖØÒªÕë¶Ô°ÍÁÖµÄ9¸ö»îÔ¾ÈËÊ¿£¨Ô̺¬°ÍÁÖÈËȨÖÐÐijÉÔ±¡¢WaadºÍAl WefaqµÈ£©¡£¡£¡£¡£¡£ÔÚÕâ´Î»î¶¯ÖУ¬£¬£¬ £¬£¬£¬£¬¹¥»÷ÕßÀûÓÃÁËÁ½¸öÁãµã»÷·ì϶£¬£¬£¬ £¬£¬£¬£¬±ðÀë³ÆÎª2020  KISMETºÍзì϶FORCEDENTRY¡£¡£¡£¡£¡£Ä¿Ç°ÉÐδÓйØFORCEDENTRY·ì϶µÄ¼¼Êõϸ½Ú£¬£¬£¬ £¬£¬£¬£¬ÖØÒªÊÇÓÉÓڸ÷ì϶ÈÔ佨¸´¡£¡£¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/121415/malware/zero-click-exploit-nso.html


F5°ä²¼°²È«¸üУ¬£¬£¬ £¬£¬£¬£¬½¨¸´Æä¶à¿î²úÆ·ÖеĽü30¸ö°²È«·ì϶


F5°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´Æä¶à¿î²úÆ·ÖеĽü30¸ö°²È«·ì϶.jpg


F5ÔÚ8ÔÂ24ÈÕ°ä²¼ÁË8Ô·ݰ²È«¸üУ¬£¬£¬ £¬£¬£¬£¬½¨¸´ÁËÆä¶à¿î²úÆ·Öнü30¸ö·ì϶¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ×îΪÑϳÁµÄ·ì϶ÊÇBIG-IP WAFºÍASMÁ÷Á¿ÖÎÀíÓû§½çÃæ(TMUI)ÉϵÄÌáȨ·ì϶£¬£¬£¬ £¬£¬£¬£¬×·×ÙΪCVE-2021-23031£¬£¬£¬ £¬£¬£¬£¬ÆÀ·ÖΪ8.8£¬£¬£¬ £¬£¬£¬£¬µ«¶ÔÓÚʹÓÃÉ豸ģʽµÄÓû§À´Ëµ£¬£¬£¬ £¬£¬£¬£¬ÆÀ·Ö½«Ìá¸ßµ½9.9¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬£¬£¬»¹ÓÐBIG-IPÖеÄÔ¶³ÌºÅÁîÖ´Ðзì϶£¨CVE-2021-23025£©¡¢BIG-IPºÍBIG-IQÖеÄCSRF·ì϶£¨CVE-2021-23026£©ºÍTMUIÖеĻùÓÚDOMµÄXSS·ì϶£¨CVE-2021-23027£©µÈ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://support.f5.com/csp/article/K50974556


ÐéαµÄOpenSeaÖ§³ÖȦÌ×ÒþÄäÔÚDiscordÍøÂçÖй¥»÷Ö¸±ê


ÐéαµÄOpenSeaÖ§³ÖȦÌ×ÒþÄäÔÚDiscordÍøÂçÖй¥»÷Ö¸±ê.jpg


ÔÚ´ÓǰµÄÒ»ÖÜÀ£¬£¬ £¬£¬£¬£¬ÐéαµÄOpenSeaÖ§³ÖȦÌ×ÒþÄäÔÚDiscordÍøÂçÖй¥»÷Ö¸±ê£¬£¬£¬ £¬£¬£¬£¬Ö¼ÔÚÇÔÈ¡Óû§×ʽ𡣡£¡£¡£¡£µ±Óû§ÔÚÍøÉÏ×·ÇóÔ®ÊÖʱ£¬£¬£¬ £¬£¬£¬£¬ÒþÄäÔÚDiscord·þÎñÆ÷ÉϵÄÚ¿Æ­Õß±ã»á·¢ËÍ˽ÐÅÔ¼ÇëÆä²ÎÓëÐéαµÄOpenSeaÖ§³Ö·þÎñ¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬ £¬£¬£¬£¬Ú¿Æ­Õß»áÒªÇóÖ¸±ê¿ªÆôÆÁÄ»¹²Ïí£¬£¬£¬ £¬£¬£¬£¬²¢É¨Ãè¶þάÂëÒÔͬ²½MetaMaskÇ®°üÓëChromeÀ©´ó·¨Ê½¡£¡£¡£¡£¡£×îºó£¬£¬£¬ £¬£¬£¬£¬Ú¿Æ­Õß»áÓøöþάÂ뽫ָ±êÇ®°üÖеÄ×ʽð×ªÒÆ³öÀ´¡£¡£¡£¡£¡£    


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fake-opensea-support-staff-are-stealing-cryptowallets-and-nfts/


ÃÀ¹úÓ×ÕòPeterboroughÒò2´ÎBEC¹¥»÷Ëðʧ230ÍòÃÀÔª


ÃÀ¹úÓ×ÕòPeterboroughÒò2´ÎBEC¹¥»÷Ëðʧ230ÍòÃÀÔª.jpg


ÃÀ¹úк±²¼Ê²¶ûÖݵÄÓ×ÕòPeterboroughÒò2´ÎBEC¹¥»÷Ëðʧ230ÍòÃÀÔª¡£¡£¡£¡£¡£¸ÃÕò¹ÙÔ±°µÊ¾£¬£¬£¬ £¬£¬£¬£¬ËûÃÇÓÚ7ÔÂ26ÈÕ³õ´Î·¢ÏÖ¹¥»÷»î¶¯£¬£¬£¬ £¬£¬£¬£¬ÆäʱConValÑ§Çø³ÆÆäûÓÐÊÕµ½Ã¿ÔÂ120ÍòÃÀÔªµÄתÕË¡£¡£¡£¡£¡£ÔÚËæºóµÄµ÷²éÖУ¬£¬£¬ £¬£¬£¬£¬ÓÖÓÚ8ÔÂ18ÈÕ·¢ÏÖÁËÁí±íÁ½±Ê±»½Ù³ÖµÄ¿î×Ó£¬£¬£¬ £¬£¬£¬£¬ÕâЩ¿î×ÓÕý±¾Òª×ª¸øÇÅÁº¹¤³ÌµÄ³Ð°üÉÌBeckºÍBellucci¡£¡£¡£¡£¡£¸ÃÕò±¾²ÆÕþÄê¶ÈµÄÔ¤ËãԼΪ1580ÍòÃÀÔª£¬£¬£¬ £¬£¬£¬£¬Õâ´ÎµÄËðʧռÆäÄê¶ÈÔ¤ËãµÄ15%¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/cyberthieves-scam-new-hampshire/


ESET·¢ÏÖSparklingGoblin¹¥»÷ÃÀ¹úÄ³ÍÆËã»úÁãÊÛ¹«Ë¾


ESET·¢ÏÖSparklingGoblin¹¥»÷ÃÀ¹úÄ³ÍÆËã»úÁãÊÛ¹«Ë¾.jpg


˹Âå·¥¿ËÍøÂ簲ȫ¹«Ë¾ESETÔÚ8ÔÂ24ÈÕ³ÆÆä·¢ÏÖÁËAPTÍÅ»ïSparklingGoblin¹¥»÷ÃÀ¹úÄ³ÍÆËã»úÁãÊÛ¹«Ë¾µÄ»î¶¯¡£¡£¡£¡£¡£ÔÚ´ÓǰµÄÒ»ÄêÖУ¬£¬£¬ £¬£¬£¬£¬¸ÃÍŻ﹥»÷ÁËÊÀ½ç¸÷µØµÄ×éÖ¯£¬£¬£¬ £¬£¬£¬£¬Ô̺¬°ÍÁÖ¡¢¼ÓÄô󡢸ñ³¼ªÑÇ¡¢Ó¡¶È¡¢ÐÂ¼ÓÆÂ¡¢º«¹úºÍÃÀ¹úµÈ¡£¡£¡£¡£¡£ÔÚÕâ´Î¹¥»÷ÖУ¬£¬£¬ £¬£¬£¬£¬¸ÃÍÅ»ïʹÓÃÁËÒ»¸öеĺóÃÅSideWalk£¬£¬£¬ £¬£¬£¬£¬ËüÄܹ»¶¯Ì¬¼ÓÔØ´ÓÆäC&C·þÎñÆ÷·¢Ë͵Ķî±íÄ£¿ £¿£¿£¿£¿é£¬£¬£¬ £¬£¬£¬£¬²¢ÀûÓùȸèDocs×÷Ϊdead drop resolver¡£¡£¡£¡£¡£×êÑÐÈ˰µÊ¾£¬£¬£¬ £¬£¬£¬£¬SideWalkºÜ¿ÉÄÜÊÇÓÉCROSSWALKµÄ¿ª·¢ÈËÔ±¿ª·¢µÄ£¬£¬£¬ £¬£¬£¬£¬ÓÉÓÚËüÃǹ²ÏíÁ˺ܶàÉè¼Æ½á¹¹ºÍʵÏÖϸ½Ú¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/08/new-sidewalk-backdoor-targets-us-based.html


Unit 42°ä²¼ÓйØ4¸öеÄÀÕË÷ÔËÓªÍÅ»ïµÄ·ÖÎö»ã±¨


Unit 42°ä²¼ÓйØ4¸öеÄÀÕË÷ÔËÓªÍÅ»ïµÄ·ÖÎö»ã±¨.jpg


Unit 42ÔÚ2021Äê8ÔÂ24ÈÕ°ä²¼ÁËÓйØ4¸öеÄÀÕË÷ÔËÓªÍÅ»ïµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£ÕâËĸöÀÕË÷ÍÅ»ï±ðÀëΪ6ÔÂÏÂÑ®ÆðÍ·ÔËÓªµÄAvosLocker RaaS£¬£¬£¬ £¬£¬£¬£¬ÖØÒªÕë¶ÔÃÀ¹ú¡¢Ó¢¹ú¡¢°¢ÁªÇõ¡¢±ÈÀûʱ¡¢Î÷°àÑÀºÍÀè°ÍÄÛ£¬£¬£¬ £¬£¬£¬£¬Êê½ð´Ó50000ÃÀÔªµ½75000ÃÀÔª²»µÈ£» £»£» £»£» £»6ÔÂÆðÍ·µÄHive Ransomware£¬£¬£¬ £¬£¬£¬£¬Òѹ¥»÷ÁË28¸ö×éÖ¯£» £»£» £»£» £»7ÔÂÆðÍ·»îÔ¾µÄLinux°æ±¾HelloKitty£¬£¬£¬ £¬£¬£¬£¬ÆäÊ×ѡָ±êΪVMwareµÄESXiÖÎÀí·¨Ê½£» £»£» £»£» £»ÒÔ¼°ÔÚ6Ô¾­¹ýˢеÄLockBit 2.0£¬£¬£¬ £¬£¬£¬£¬ÒѾ­¹¥»÷ÁË52¸ö×éÖ¯¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/emerging-ransomware-groups/