NCC·¢ÏÖClopÀûÓÃSolarWinds Serv-UÖÐRCEµÄ»î¶¯
Ðû²¼Ê±¼ä 2021-11-12ESET·¢ÏÖLazarusÀûÓõÁ°æµÄIDA Pro·Ö·¢¶ñÒâÈí¼þ
ESETÍŶÓÓÚ11ÔÂ10ÈÕ·¢ÏÖ³¯ÏʺڿÍÍÅ»ïLazarusÀûÓõÁ°æIDA Pro¹¥»÷Äþ¾²Ñо¿ÈËÔ±µÄ»î¶¯¡£Ñо¿ÈËԱͨ³£Ê¹ÓÃÄæÏò¹¤³ÌÓ¦ÓÃIDA ProÀ´·ÖÎö©¶´ºÍ¶ñÒâÈí¼þ£¬¶ø´Ë´Î·¢ÏÖµÄIDA Pro 7.5°æ±¾°üÂÞÁËÁ½¸öÃûΪidahelp.dllºÍwin_fw.dllµÄ¶ñÒâDLL¡£ÆäÖУ¬win_fw.dll½«ÔÚWindowsÈÎÎñµ÷Öη¨Ê½Öд´½¨Ò»¸öÐÂÈÎÎñ£¬¸ÃÈÎÎñ½«Æô¶¯idahelper.dll£¬È»ºóidahelper.dll½«Á¬½Óµ½devguardmap[.]orgÍøÕ¾²¢ÏÂÔØÔ¶³Ì·ÃÎÊľÂíNukeSpedµÄpayload¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/lazarus-hackers-target-researchers-with-trojanized-ida-pro/
ͳ³ÆÎªNUCLEUS:13µÄ¶à¸ö©¶´Ó°ÏìÎ÷ÃÅ×ÓRTOS
ForescoutºÍMedigateµÄÑо¿ÈËÔ±ÔÚ11ÔÂ9ÈÕÅû¶ÁËNucleusÖÐ13¸ö©¶´µÄϸ½Ú¡£NucleusÊÇÎ÷ÃÅ×ÓµÄʵʱ²Ù×÷ϵͳ(RTOS)£¬Í¨³£ÔËÐÐÔÚÒ½ÁÆÉ豸¡¢Æû³µ¡¢ÖÇÄÜÊÖ»ú¡¢ÎïÁªÍøÉ豸¡¢¹¤ÒµplcµÈÉ豸µÄƬÉÏϵͳ(SoC)¡£ÕâЩ©¶´Í³³ÆÎªNUCLEUS:13£¬Ó°ÏìÁËNucleus TCP/IP¶ÑÕ»¡£ÆäÖУ¬×îÑÏÖØµÄÊÇÓ°ÏìÁËFTP·þÎñÆ÷×é¼þµÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-31886£©£¬CVSSÆÀ·ÖΪ9.8£¬ÊÇÓÉÓÚ¶ÔUSERÃüÁ¶ÈµÄÑéÖ¤²»ÕýÈ·µ¼Öµġ£
ÔÎÄÁ´½Ó£º
https://therecord.media/nucleus13-vulnerabilities-impact-siemens-medical-industrial-equipment/
SAPÐû²¼11Ô·ÝÖܶþ²¹¶¡£¬ÐÞ¸´¶à¸öÄþ¾²Â©¶´
SAPÔÚ11ÔÂ9ÈÕÐû²¼Á˱¾ÔµÄÖܶþ²¹¶¡£¬ÐÞ¸´Á˶à¸öÄþ¾²Â©¶´¡£´Ë´ÎÐÞ¸´µÄ×îÑÏÖØµÄ©¶´ÊÇABAPƽ̨ÄÚºËÖÐÓÉÓÚȱʧÊÚȨ¼ì²éµ¼ÖµÄÌáȨ©¶´£¨CVE-2021-40501£©£¬CVSSÆÀ·ÖΪ9.6¡£Äþ¾²¹«Ë¾Onapsis³Æ£¬¸Ã©¶´¿ÉÒÔͨ¹ýRFCºÍHTTPͨÐÅÓ°ÏìÆäËüϵͳµÄ¿ÉÐÅÁ¬½Ó£¬¹¥»÷Õß¿ÉÀûÓÃÆäÔÚÆäËüϵͳÖÐÖ´ÐÐÌØ¶¨µÄÂß¼¡£´ËÍ⣬»¹ÐÞ¸´ÁËCommerceÖеÄÌáȨ©¶´£¨CVE-2021-40502£©¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/sap-patches-critical-vulnerability-abap-platform-kernel
NCC·¢ÏÖClopÀûÓÃSolarWinds Serv-UÖÐRCEµÄ»î¶¯
NCC GroupÓÚ11ÔÂ8Èճƣ¬ÔÚ¹ýÈ¥¼¸ÖÜÖÐÀÕË÷Èí¼þClopµÄѬȾÁ¿ÓÐËùÔö¼Ó£¬¶øÇÒ´ó¶àÊý¶¼ÀûÓÃÁË©¶´CVE-2021-35211¡£¸Ã©¶´ÊÇServ-U Managed File TransferºÍServ-U Secure FTPÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬SolarWindsÔÚ2021Äê7Ô·ÝÐû²¼Á˽ô¼±¸üÐÂÐÞ¸´¸Ã©¶´£¬²¢³Æ½öÓ°ÏìÁËÆôÓÃSSH¹¦Ð§µÄ¿Í»§¡£Ôڴ˴λÖУ¬¹¥»÷ÕßÀûÓÃServ-UÉú³ÉÁËÒ»¸öÓÉÆä¿ØÖÆµÄ×Ó½ø³Ì£¬²¢ÔÚÄ¿±êϵͳÉÏÖ´ÐÐÃüÁî¡£
ÔÎÄÁ´½Ó£º
https://research.nccgroup.com/2021/11/08/ta505-exploits-solarwinds-serv-u-vulnerability-cve-2021-35211-for-initial-access/
µÂ¹úÒ½ÁÆÈí¼þ¹«Ë¾MedatixxÈ·ÈÏÆäÔâµ½ÀÕË÷¹¥»÷
Medatixx¹«Ë¾11ÔÂ9ÈÕÈ·ÈÏÆäÔÚÉÏÖÜÔâµ½ÁËÀÕË÷¹¥»÷¡£MedatixxÊÇÒ»¼ÒµÂ¹úµÄÒ½ÁÆÈí¼þ¹«Ë¾£¬ËüµÄ²úÎï±»ÓÃÓÚ21000¶à¼ÒÒ½ÁÆ»ú¹¹¡£¸Ã¹«Ë¾³Æ£¬¹¥»÷½öÓ°ÏìÁËËûÃǵÄÄÚ²¿ITϵͳ£¬Ã»ÓÐÓ°Ïì¿Í»§µÄPVS£¨Êµ¼ù¹ÜÀíϵͳ£©¡£Ä¿Ç°ÉÐδȷ¶¨¹¥»÷ÕßÇÔÈ¡ÁËÄÄЩÊý¾Ý£¬µ«¿ÉÄÜÒѾ»ñÈ¡ÁËMedatixx¿Í»§µÄÃÜÂ룬Òò´ËMedatixx½¨Òé¿Í»§Á¢¿Ì¸ü¸ÄÆäÓ¦Ó÷¨Ê½µÄÃÜÂë¡£¹«Ë¾ÈÔÔÚ»Ö¸´ÖУ¬½ØÖÁĿǰֻ»Ö¸´ÁËÓʼþºÍµç»°ÏµÍ³¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/medical-software-firm-urges-password-resets-after-ransomware-attack/
ACTIºÍPACTÐû²¼¹ØÓÚLyceum½üÆÚ»î¶¯µÄ·ÖÎö³ÂËß
11ÔÂ9ÈÕ£¬AccentureµÄACTIÍŶӺÍPrevailionµÄPACTÍŶÓÁªºÏÐû²¼Á˹ØÓÚLyceum½üÆÚ»î¶¯µÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬ÒÁÀʺڿÍÍÅ»ïLyceumÖ÷ҪרעÓÚ¼äµý»î¶¯£¬ÔÚ2021Äê7ÔÂÖÁ10ÔÂÆÚ¼ä£¬Ôø¹¥»÷ÁËÒÔÉ«ÁС¢Ä¦Âå¸ç¡¢Í»Äá˹ºÍÉ³ÌØ°¢À²®µÄISPºÍµçÐÅÔËÓªÉÌ£¬ÒÔ¼°·ÇÖÞµÄÍâ½»²¿(MFA)¡£LyceumµÄ³õʼ¹¥»÷ý½éΪƾ֤Ìî³ä¹¥»÷ºÍ±©Á¦¹¥»÷£¬ÔÚÈëÇÖÀֳɺó»á°²×°ºóÃÅSharkºÍMilan£¨Í³³ÆÎªJames£©¡£
ÔÎÄÁ´½Ó£º
https://www.accenture.com/us-en/blogs/cyber-defense/iran-based-lyceum-campaigns