ÀÕË÷Èí¼þWannaCryÖØÐ»عé £¬¹¥»÷»î¶¯¼¤Ôö53£¥£»Ó¡¶È¹¤ÒµÉú³¤¹«Ë¾MIDCѬȾSYNack £¬±»ÀÕË÷50ÒÚ¬±È

Ðû²¼Ê±¼ä 2021-04-01

1.ÀÕË÷Èí¼þWannaCryÖØÐ»عé £¬¹¥»÷»î¶¯¼¤Ôö53£¥


1.jpg


Check Point·¢ÏÖÀÕË÷Èí¼þWannaCryÖØÐ»عé £¬¹¥»÷»î¶¯¼¤Ôö53£¥¡£¹ýÈ¥µÄ°ëÄêÖÐ £¬ÀÕË÷Èí¼þ¹¥»÷»î¶¯Ôö¼ÓÁË57£¥ £¬È«Çò×ܹ²·¢ÉúÁË50000¶à´Î¹¥»÷ʵÑé £¬ÆäÖдó¶àÊýÕë¶ÔÕþ¸®¡¢¾üÊ¡¢ÖÆÔìÒµ¡¢ÒøÐкͽðÈÚ²¿ÃŵÄ×éÖ¯¡£³ýÁËÕý³£ÀÕË÷Èí¼þ£¨ÃÔ¹¬¡¢RyukºÍREvilµÈ£©Íâ £¬Check Point»¹×¢Òâµ½WannaCryÀÕË÷Èí¼þÔö¼ÓÁË53£¥¡£2021Äê3ÔÂÊܸöñÒâÈí¼þÓ°ÏìµÄ×éÖ¯ÊýÁ¿ÊÇ2020Äê10ÔµÄ40±¶ £¬ÆäÐÂÑù±¾ÈÔÀûÓÃÁËEternalBlue©¶´½øÐзַ¢ £¬¾¡¹ÜÕë¶Ô¸Ã©¶´µÄ²¹¶¡ÒÑÐû²¼Áè¼Ý4Äê¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-exchange-attacks-increase-while-wannacry-gets-a-restart/


2.Talos·¢ÏÖ¶à¸ö½«¶ñÒâÈí¼þαװ³ÉÓÎÏ·Íâ¹ÒµÄ¹¥»÷»î¶¯


2.jpg


Ñо¿ÈËÔ±³ÆÔÚ¶à¸ö»î¶¯Öз¢ÏÖÁËÁ˼¸¸ö¿´ÆðÀ´ÏñÓÎÏ·²¹¶¡¡¢µ÷ÕûÆ÷»òÐÞ¸ÄÆ÷µÄС¹¤¾ß´øÓÐÄ£ºýµÄ¶ñÒâÈí¼þ¡£´Ó2010Ä꿪ʼ»îÔ¾µÄÉÌÓÃRAT XtremeRAT¾ÍÊÇÆäÖÐÖ®Ò» £¬¿ÉÓÃÀ´ÇÔÈ¡Îĵµ¡¢¼Ç¼¼üÅÌÊäÈë¡¢²¶×½ÆÁÄ»½ØÍ¼¡¢Ê¹ÓÃÉãÏñÍ·»òÂó¿Ë·çÂ¼ÖÆÒôƵÒÔ¼°Í¨¹ýÔ¶³ÌshellÓëÊܺ¦Õß»¥¶¯µÈ¡£´ËÍâ £¬¹¥»÷Õß»¹Ê¹ÓÃÁËÅÓ´óµÄ»ùÓÚVisualBasicµÄ¼ÓÃÜÆ÷ºÍShellcodeÀ´×èÖ¹·ÖÎöºÍ¼ì²â £¬²¢Òþ²ØÆäpayload¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/malware-hidden-in-game-cheats-and-mods-used-to-target-gamers/


3.VMwareÐÞ¸´vRealize OperationsÖеÄSSRFµÈ¶à¸ö©¶´


3.jpg


VMwareÐû²¼Äþ¾²¸üР£¬ÒÔÐÞ¸´VMware vRealize OperationsÖеĶà¸ö©¶´¡£´Ë´ÎÐÞ¸´µÄ×îΪÑÏÖØµÄ©¶´ÊÇvRealize Operations Manager APIÖеķþÎñÆ÷¶ËÇëÇóαÔì©¶´£¨CVE-2021-21975£© £¬CVSSv3ÆÀ·ÖΪ8.6 £¬Ô¶³Ìδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÎÞÐèÓëÓû§½»»¥¼´¿ÉÀûÓôË©¶´À´ÇÔÈ¡¹ÜÀíÆ¾¾Ý¡£´ËÍâ £¬»¹ÐÞ¸´ÁËÈÎÒâÎļþдÈë©¶´£¨CVE-2021-21983£© £¬CVSSv3ÆÀ·ÖΪ7.2 £¬¹¥»÷Õß¿ÉÀûÓÃÆäÔڵײã¹â×Ó²Ù×÷ϵͳµÄÈÎÒâλÖÃдÈëÎļþ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116145/security/vmware-vrealize-operations-ssrf-flaw.html


4.IoTÉ豸ÉÌUbiquitiÔâµ½¹¥»÷ £¬Êý¾Ý¿âºÍÔ´´úÂëй¶


4.jpg


ÍøÂçÉ豸ºÍÎïÁªÍø£¨IoT£©É豸ÌṩÉÌUbiquitiÔâµ½¹¥»÷ £¬Êý¾Ý¿âºÍÔ´´úÂëй¶¡£1ÔÂ11ÈÕ £¬¸Ã¹«Ë¾Åû¶ÆäµÚÈý·½ÔÆÌṩÉÌй¶ÁËÆä¿Í»§µÄÕÊ»§Æ¾¾Ý¡£µ«½üÆÚ £¬ÄäÃûΪAdamµÄ¾Ù±¨Õß͸¶Ê¼þÔ¶±È¿´ÉÏÈ¥ÑÏÖØµÃ¶à¡£¹¥»÷Õß¿ÉÒÔroot¹ÜÀíԱȨÏÞ·ÃÎÊËùÓÐUbiquiti AWSÕÊ»§ £¬°üÂÞËùÓÐS3Êý¾ÝͰ¡¢Ó¦Ó÷¨Ê½ÈÕÖ¾¡¢Êý¾Ý¿âºÍÓû§Æ¾¾Ý £¬ÒÔ¼°Î±Ôìµ¥µãµÇ¼£¨SSO£©CookieºÍÔ¶³Ì·ÃÎÊËùÐèµÄÃÜÔ¿¡¢ÍêÕûµÄÔ´´úÂë¿ØÖÆÄÚÈݺÍÇ©ÃûÃÜÔ¿¡£


Ô­ÎÄÁ´½Ó£º

https://krebsonsecurity.com/2021/03/whistleblower-ubiquiti-breach-catastrophic/


5.Ó¡¶È¹¤ÒµÉú³¤¹«Ë¾MIDCѬȾSYNack £¬±»ÀÕË÷50ÒÚ¬±È


5.jpg


Ó¡¶ÈÃÏÂòµÄMaharashtra¹¤ÒµÉú³¤¹«Ë¾£¨MIDC£©µÄ·þÎñÆ÷ѬȾSYNack £¬±»ÀÕË÷50ÒÚ¬±È£¨Ô¼ºÏ6800ÍòÃÀÔª£©¡£MIDC³Æ¹¥»÷·¢ÉúÔÚ3ÔÂ21ÈÕÖÜÈÕÁ賿2:30×óÓÒ £¬ÆäÊ×ÏÈÊÕµ½ÁËÓ¦Ó÷¨Ê½¹Ø±ÕµÄ¾¯±¨ £¬¾­·ÖÎöÆäÔâµ½ÁËÀÕË÷Èí¼þ¹¥»÷ £¬¸Ã¹«Ë¾Á¢¿Ì½«MIDCϵͳÓëÍøÂç¶Ï¿ªÒÔÍ£Ö¹²¡¶¾µÄÁ÷´«¡£´Ë´Î¹¥»÷Ó°ÏìÁËMIDCʹÓõÄÓ¦Ó÷¨Ê½ºÍÊý¾Ý¿â·þÎñÆ÷ £¬ÒÔ¼°²¿ÃĄ̊ʽ»ú £¬Ä¿Ç°¸Ã¹«Ë¾Î»ÓÚ16¸öµØÓòµÄËùÓзþÎñ´¦¶¼ÒѹرÕ¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/03/midcs-server-hacked-threat-to-destroy.html


6.WatchGuardÐû²¼2020ÄêQ4¶ñÒâÈí¼þºÍÍøÂç¹¥»÷·ÖÎö³ÂËß


6.jpg


WatchGuardÐû²¼ÁË2020ÄêQ4¶ñÒâÈí¼þºÍÍøÂç¹¥»÷µÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö £¬2020ÄêÎÞÎļþ¶ñÒâÈí¼þÊýÁ¿£¨fileless malware£©±È2019ÄêÔö¼ÓÁË888£¥ £¬ÖîÈçPowerSploitºÍCobaltStrikeÖ®ÀàµÄ¹¤¾ß°ü £¬¼´Ê¹Êܺ¦Õßʶ±ð²¢É¾³ýÁËԭʼ½Å±¾ £¬ËüÃÇÈԿɼÌÐøÔËÐС£´ËÍâ £¬¼ÓÃܿ󹤵ļìÕÉÁ¿±È2019ÄêÔö³¤ÁË25£¥ÒÔÉÏ £¬¶à´ï850ÖÖ±äÌå £¬¶øÀÕË÷Èí¼þ¹¥»÷Á¿³ÊϽµÇ÷ÊÆ´Ó2019ÄêµÄ4131¸öpayloadϽµµ½2152¸ö¡£


Ô­ÎÄÁ´½Ó£º

https://www.watchguard.com/wgrd-resource-center/security-report-q4-2020