Cisco·¢ÏÖÀûÓÃÓòÃûǰÖü¼Êõ¶Ô×¼Ãåµéµ±¾ÖµÄ¹¥»÷»î¶¯

°ä²¼¹¦·ò 2021-11-19

Cisco·¢ÏÖÀûÓÃÓòÃûǰÖü¼Êõ¶Ô×¼Ãåµéµ±¾ÖµÄ¹¥»÷»î¶¯


Cisco·¢ÏÖÀûÓÃÓòÃûǰÖü¼Êõ¶Ô×¼Ãåµéµ±¾ÖµÄ¹¥»÷»î¶¯.png


Cisco TalosÔÚ11ÔÂ16ÈÕÅû¶ÁËÀûÓÃÐµİµ²Ø¼¼ÊõÈÆ¹ý¼ì²âµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯×î³õ·¢ÏÖÓÚ½ñÄê9Ô·Ý£¬£¬£¬£¬£¬£¬£¬ÀûÓÃÁËÒ»ÖÖÃûΪÓòÃûǰÖõļ¼ÊõÀ´°µ²ØC2¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹ÀûÓÃÁ˺Ϸ¨µÄ¹¤¾ßCobalt Strik£¬£¬£¬£¬£¬£¬£¬µ±BeaconÆô¶¯Ê±½«ÎªÍйÜÔÚCloudflareµÄºÏ·¨ÓòÌá½»DNSÒªÇ󣬣¬£¬£¬£¬£¬£¬¶øºóÅú¸ÄºóÐøµÄHTTPsÒªÇóÍ·£¬£¬£¬£¬£¬£¬£¬ÒÔÅúʾCDN½«Á÷Á¿³Á¶¨Ïòµ½¹¥»÷Õß½ÚÔìµÄÖ÷»ú¡£¡£¡£¡£¡£¡£»£»£»£»£»î¶¯ÖÐʹÓõĺϷ¨ÓòÃûΪÃåµéÊý×ÖÐÂÎŵÄmdn[.]gov[.]mm¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2021/11/attackers-use-domain-fronting-technique.html


ESET·¢ÏÖÒÔÉ«ÁÐCandiruÕë¶ÔÓ¢¹úºÍÖж«µÄË®¿Ó¹¥»÷


ESET·¢ÏÖÒÔÉ«ÁÐCandiruÕë¶ÔÓ¢¹úºÍÖж«µÄË®¿Ó¹¥»÷.png


11ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬£¬ESETµÄ×êÑÐÈËÔ±³ÆÒÔÉ«ÁеļäµýÈí¼þCandiruÓëÕë¶ÔÓ¢¹úºÍÖж«µÄË®¿Ó¹¥»÷ÓйØ¡£¡£¡£¡£¡£¡£CandiruÒÑÓÚ±¾Ô±»ÃÀ¹úÉÌÎñ²¿ÁÐÈë¶ñÒâÍøÂç»î¶¯×éÖ¯Ãûµ¥¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯´óÌå·ÖΪÁ½²¨£¬£¬£¬£¬£¬£¬£¬µÚÒ»²¨ÆðÍ·ÓÚ2020Äê3Ô£¬£¬£¬£¬£¬£¬£¬ÓÚ2020Äê8ÔÂʵÏÖ£¬£¬£¬£¬£¬£¬£¬µÚ¶þ²¨¹¥»÷ÆðÍ·ÓÚ2021Äê1ÔÂÆðÍ·£¬£¬£¬£¬£¬£¬£¬Ò»Ïò³ÖÐøµ½2021Äê8ÔÂÉÏÑ®£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÁËÓ¢¹ú¡¢Ò²ÃÅ¡¢ÒÁÀÊ¡¢ÐðÀûÑÇ¡¢É³Ìذ¢À­²®¡¢Òâ´óÀûºÍÄϷǵȵØÓòµÄ×éÖ¯¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/11/israels-candiru-spyware-found-linked-to.html


еĴ¹µö»î¶¯¼ÙÒâTikTokÔ±¹¤ÒÔɾ³ýÕ˺ÅÀ´ÍþвÓû§


еĴ¹µö»î¶¯¼ÙÒâTikTokÔ±¹¤ÒÔɾ³ýÕ˺ÅÀ´ÍþвÓû§.png


Abnormal SecurityÔÚ11ÔÂ17ÈÕ·¢ÏÖÕë¶ÔTikTokÓû§µÄÐÂÒ»ÂÖ´¹µö»î¶¯¡£¡£¡£¡£¡£¡£¹¥»÷Õß¼ÙÒâTikTokÔ±¹¤£¬£¬£¬£¬£¬£¬£¬ÖÒ¸æÖ¸±êÒòÆäÉæÏÓÎ¥·´Æ½Ì¨Ìõ¿î¶ø½«Á¢¼´É¾³ýÕÊ»§¡£¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬£¬Óû§»á±»³Á¶¨Ïòµ½Ò»¸öWhatsApp̸ÌìÊÒ£¬£¬£¬£¬£¬£¬£¬²¢±»ÒªÇóÌṩ³ÁÖÃÕÊ»§ÃÜÂëËùÐèµÄÓʼþµØÖ·¡¢µç»°ºÅÂëºÍÒ»´ÎÐÔ´úÂë¡£¡£¡£¡£¡£¡£Ä¿Ç°Éв»Ã÷ÏÔ¹¥»÷ÕßµÄÖ÷ÕÅÊÇʲô£¬£¬£¬£¬£¬£¬£¬»òÐíÖ¼ÔÚÊÕÊÜÕË»§»òÀÕË÷¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯µÄÁ½¸ö·åÖµ±ðÀëÔÚ10ÔÂ2ÈÕºÍ11ÔÂ1ÈÕ£¬£¬£¬£¬£¬£¬£¬Òò¶ø×êÑÐÈËÔ±´§Ä¦ÏÂÒ»Âֻ¿ÉÄÜ»áÔÚ¼¸ÖܺóÆðÍ·¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/tiktok-phishing-threatens-to-delete-influencers-accounts/


ÐÂÀÕË÷ÔËÓªÍÅ»ïMementoÀûÓÃvCenterÖеÄRCE·ì϶


ÐÂÀÕË÷ÔËÓªÍÅ»ïMementoÀûÓÃvCenterÖеÄRCE·ì϶.png


SophosÓÚ11ÔÂ18ÈÕÅû¶ÁËÀÕË÷ÔËÓªÍÅ»ïMementoµÄл¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓÃÁËVMware vCenter Server WebÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-21971£©£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.8¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶½Ó¼ûTCP/IP¶Ë¿Ú443£¬£¬£¬£¬£¬£¬£¬²¢ÒÔÖÎÀíԱȨÏÞÖ´ÐкÅÁ£¬£¬£¬£¬£¬£¬Æä²¹¶¡ÒÑÓÚ2Ô·ݰ䲼¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯ÆðÍ·ÓÚÉϸöÔ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÊ×ÏÈÀûÓÃvCenterÖеķì϶´ÓÖ¸±ê·þÎñÆ÷ÇÔÈ¡ÖÎÀíÍ´´¦£¬£¬£¬£¬£¬£¬£¬¶øºóʹÓÃRDP over SSHºáÏòÒÆ¶¯£¬£¬£¬£¬£¬£¬£¬²¢³õ´ÎÔÚ¹¥»÷ÖÐʹÓÃÁËWinRARÀ´Ñ¹ËõÎļþ²¢¶ÔÆä½øÐмÓÃÜ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-memento-ransomware-switches-to-winrar-after-failing-at-encryption/


CISA°ä²¼2021ÄêÍøÂ簲ȫÊÂÎñºÍ·ì϶µÄÓ¦¼±ÏìÓ¦Ö¸ÄÏ


CISA°ä²¼2021ÄêÍøÂ簲ȫÊÂÎñºÍ·ì϶µÄÓ¦¼±ÏìÓ¦Ö¸ÄÏ.png


11ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬£¬ÃÀ¹úCISA°ä²¼ÁË2021ÄêÍøÂ簲ȫÊÂÎñºÍ·ì϶µÄÓ¦¼±ÏìÓ¦Ö¸ÄÏ¡£¡£¡£¡£¡£¡£¸ÃÖ¸ÄÏΪÁª¹úÎÄÖ°ÐÐÕþ²¿ÃÅ£¨FCEB£©»ú¹¹ÌṩÁËÓÃÓڹ滮ºÍ·¢Õ¹ÍøÂ簲ȫÊÂÎñºÍ·ì϶ÏìÓ¦»î¶¯µÄ²Ù×÷·¨Ê½£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ý¾ö²ßÊ÷¾ßÌå˵ÁËÈ»ÊÂÎñºÍ·ì϶ÏìÓ¦µÄÿ¸ö²½Öè¡£¡£¡£¡£¡£¡£CISA¼¤Àø¹Ø¼ü»ù´¡ÉèÊ©ÓйØ×éÖ¯£¬£¬£¬£¬£¬£¬£¬ÖÝ¡¢´¦ËùÈ·µ±¾Ö×éÖ¯ÒÔ¼°Ë½Óª×éÖ¯ÀûÓøÃÖ¸ÄϽøÐÐÉó²é£¬£¬£¬£¬£¬£¬£¬ÒÔ¶ÔÆä×ÔÉíµÄ·ì϶ºÍÊÂÎñÏìӦʵ¼Ê½øÐлù×¼²âÊÔ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/11/16/new-federal-government-cybersecurity-incident-and-vulnerability


Kaspersky°ä²¼2022ÄêAPT¹¥»÷ÍþÐ²Ì¬ÊÆµÄÔ¤²â»ã±¨


Kaspersky°ä²¼2022ÄêAPT¹¥»÷ÍþÐ²Ì¬ÊÆµÄÔ¤²â»ã±¨.png


KasperskyÓÚ11ÔÂ17ÈÕ°ä²¼ÁË2022ÄêAPT¹¥»÷ÍþÐ²Ì¬ÊÆµÄÔ¤²â»ã±¨¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬£¬APT×éÖ¯½«´ÓÆäËû¹¥»÷ÕßÄÇÀï²É°ì³õÊ¼ÍøÂç½Ó¼ûȨÏÞ£»£»£»£»£»¸ü¶à¹ú¶È½«Ë¾·¨¸æ×´×÷ΪÆäÍøÂçÕ½ÊõµÄÒ»²¿ÃÅ£»£»£»£»£»¶ÔÍøÂçÉ豸µÄÕë¶ÔÐÔ¹¥»÷Ôö³¤£»£»£»£»£»5G·ì϶¼´½«³öÏÖ£»£»£»£»£»¹¥»÷Õß½«³ÖÐøÀûÓÃCOVID-19Ö÷Ì⣻£»£»£»£»Òƶ¯É豸½«Êܵ½¿í·º¹¥»÷£»£»£»£»£»¹©¸øÁ´¹¥»÷µÄÊýÁ¿½«Ôö³¤£»£»£»£»£»³ÖÐøÀûÓÃWFH£»£»£»£»£»METAµØÓò£¬£¬£¬£¬£¬£¬£¬ÓÈÆä³¤¶ÌÖÞµÄAPT»î¶¯½«Ôö³¤¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/advanced-threat-predictions-for-2022/104870/