Cisco·¢ÏÖÀûÓÃÓòÃûǰÖü¼ÊõÃé×¼ÃåµéÕþ¸®µÄ¹¥»÷»î¶¯

Ðû²¼Ê±¼ä 2021-11-19

Cisco·¢ÏÖÀûÓÃÓòÃûǰÖü¼ÊõÃé×¼ÃåµéÕþ¸®µÄ¹¥»÷»î¶¯


Cisco·¢ÏÖÀûÓÃÓòÃûǰÖü¼ÊõÃé×¼ÃåµéÕþ¸®µÄ¹¥»÷»î¶¯.png


Cisco TalosÔÚ11ÔÂ16ÈÕÅû¶ÁËÀûÓÃеÄÒþ²Ø¼¼ÊõÈÆ¹ý¼ì²âµÄ¹¥»÷»î¶¯¡£´Ë´Î»î¶¯×î³õ·¢ÏÖÓÚ½ñÄê9Ô·Ý£¬ÀûÓÃÁËÒ»ÖÖÃûΪÓòÃûǰÖõļ¼ÊõÀ´Òþ²ØC2¡£´ËÍ⣬¹¥»÷Õß»¹ÀûÓÃÁ˺Ϸ¨µÄ¹¤¾ßCobalt Strik£¬µ±BeaconÆô¶¯Ê±½«ÎªÍйÜÔÚCloudflareµÄºÏ·¨ÓòÌá½»DNSÇëÇó£¬È»ºóÐ޸ĺóÐøµÄHTTPsÇëÇóÍ·£¬ÒÔָʾCDN½«Á÷Á¿Öض¨Ïòµ½¹¥»÷Õß¿ØÖƵÄÖ÷»ú¡ £»î¶¯ÖÐʹÓõĺϷ¨ÓòÃûΪÃåµéÊý×ÖÐÂÎŵÄmdn[.]gov[.]mm¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2021/11/attackers-use-domain-fronting-technique.html


ESET·¢ÏÖÒÔÉ«ÁÐCandiruÕë¶ÔÓ¢¹úºÍÖж«µÄË®¿Ó¹¥»÷


ESET·¢ÏÖÒÔÉ«ÁÐCandiruÕë¶ÔÓ¢¹úºÍÖж«µÄË®¿Ó¹¥»÷.png


11ÔÂ16ÈÕ£¬ESETµÄÑо¿ÈËÔ±³ÆÒÔÉ«ÁеļäµýÈí¼þCandiruÓëÕë¶ÔÓ¢¹úºÍÖж«µÄË®¿Ó¹¥»÷ÓйØ¡£CandiruÒÑÓÚ±¾Ô±»ÃÀ¹úÉÌÎñ²¿ÁÐÈë¶ñÒâÍøÂç»î¶¯×éÖ¯Ãûµ¥¡£´Ë´Î»î¶¯´óÖ·ÖΪÁ½²¨£¬µÚÒ»²¨¿ªÊ¼ÓÚ2020Äê3Ô£¬ÓÚ2020Äê8Ô½áÊø£¬µÚ¶þ²¨¹¥»÷¿ªÊ¼ÓÚ2021Äê1Ô¿ªÊ¼£¬Ò»Ö±Á¬Ðøµ½2021Äê8ÔÂÉÏÑ®£¬¹¥»÷ÁËÓ¢¹ú¡¢Ò²ÃÅ¡¢ÒÁÀÊ¡¢ÐðÀûÑÇ¡¢É³Ìذ¢À­²®¡¢Òâ´óÀûºÍÄϷǵȵØÓòµÄ×éÖ¯¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/11/israels-candiru-spyware-found-linked-to.html


еĵöÓã»î¶¯Ã°³äTikTokÔ±¹¤ÒÔɾ³ýÕ˺ÅÀ´ÍþвÓû§


еĵöÓã»î¶¯Ã°³äTikTokÔ±¹¤ÒÔɾ³ýÕ˺ÅÀ´ÍþвÓû§.png


Abnormal SecurityÔÚ11ÔÂ17ÈÕ·¢ÏÖÕë¶ÔTikTokÓû§µÄÐÂÒ»ÂÖµöÓã»î¶¯¡£¹¥»÷Õßð³äTikTokÔ±¹¤£¬¾¯¸æÄ¿±êÒòÆäÉæÏÓÎ¥·´Æ½Ì¨Ìõ¿î¶ø½«Á¢¼´É¾³ýÕÊ»§¡£Ö®ºó£¬Óû§»á±»Öض¨Ïòµ½Ò»¸öWhatsAppÁÄÌìÊÒ£¬²¢±»ÒªÇóÌá¹©ÖØÖÃÕÊ»§ÃÜÂëËùÐèµÄÓʼþµØÖ·¡¢µç»°ºÅÂëºÍÒ»´ÎÐÔ´úÂ롣ĿǰÉв»Çå³þ¹¥»÷ÕßµÄÄ¿µÄÊÇʲô£¬»òÐíÖ¼ÔÚ½Ó¹ÜÕË»§»òÀÕË÷¡£´Ë´Î»î¶¯µÄÁ½¸ö·åÖµ·Ö±ðÔÚ10ÔÂ2ÈÕºÍ11ÔÂ1ÈÕ£¬Òò´ËÑо¿ÈËÔ±ÍÆ²âÏÂÒ»Âֻ¿ÉÄÜ»áÔÚ¼¸Öܺó¿ªÊ¼¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/tiktok-phishing-threatens-to-delete-influencers-accounts/


ÐÂÀÕË÷ÔËÓªÍÅ»ïMementoÀûÓÃvCenterÖеÄRCE©¶´


ÐÂÀÕË÷ÔËÓªÍÅ»ïMementoÀûÓÃvCenterÖеÄRCE©¶´.png


SophosÓÚ11ÔÂ18ÈÕÅû¶ÁËÀÕË÷ÔËÓªÍÅ»ïMementoµÄл¡£¹¥»÷ÕßÀûÓÃÁËVMware vCenter Server WebÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-21971£©£¬CVSSÆÀ·ÖΪ9.8¡£¹¥»÷Õß¿ÉÀûÓøÃ©¶´·ÃÎÊTCP/IP¶Ë¿Ú443£¬²¢ÒÔ¹ÜÀíԱȨÏÞÖ´ÐÐÃüÁÆä²¹¶¡ÒÑÓÚ2Ô·ÝÐû²¼¡£´Ë´Î»î¶¯¿ªÊ¼ÓÚÉϸöÔ£¬¹¥»÷ÕßÊ×ÏÈÀûÓÃvCenterÖеÄ©¶´´ÓÄ¿±ê·þÎñÆ÷ÇÔÈ¡¹ÜÀíÆ¾¾Ý£¬È»ºóʹÓÃRDP over SSHºáÏòÒÆ¶¯£¬²¢Ê×´ÎÔÚ¹¥»÷ÖÐʹÓÃÁËWinRARÀ´Ñ¹ËõÎļþ²¢¶ÔÆä½øÐмÓÃÜ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-memento-ransomware-switches-to-winrar-after-failing-at-encryption/


CISAÐû²¼2021ÄêÍøÂçÄþ¾²Ê¼þºÍ©¶´µÄÓ¦¼±ÏìÓ¦Ö¸ÄÏ


CISAÐû²¼2021ÄêÍøÂçÄþ¾²Ê¼þºÍ©¶´µÄÓ¦¼±ÏìÓ¦Ö¸ÄÏ.png


11ÔÂ16ÈÕ£¬ÃÀ¹úCISAÐû²¼ÁË2021ÄêÍøÂçÄþ¾²Ê¼þºÍ©¶´µÄÓ¦¼±ÏìÓ¦Ö¸ÄÏ¡£¸ÃÖ¸ÄÏΪÁª°îÎÄÖ°ÐÐÕþ²¿ÃÅ£¨FCEB£©»ú¹¹ÌṩÁËÓÃÓڹ滮ºÍ¿ªÕ¹ÍøÂçÄþ¾²Ê¼þºÍ©¶´ÏìÓ¦»î¶¯µÄ²Ù×÷·¨Ê½£¬²¢Í¨¹ý¾ö²ßÊ÷Ïêϸ˵Ã÷ÁËʼþºÍ©¶´ÏìÓ¦µÄÿ¸ö²½Öè¡£CISAÃãÀøÒªº¦»ù´¡ÉèÊ©Ïà¹Ø×éÖ¯£¬ÖÝ¡¢µØ·½µÄÕþ¸®×éÖ¯ÒÔ¼°Ë½Óª×éÖ¯ÀûÓøÃÖ¸ÄϽøÐÐÉó²é£¬ÒÔ¶ÔÆä×ÔÉíµÄ©¶´ºÍʼþÏìӦʵ¼ù½øÐлù×¼²âÊÔ¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/11/16/new-federal-government-cybersecurity-incident-and-vulnerability


KasperskyÐû²¼2022ÄêAPT¹¥»÷ÍþÐ²Ì¬ÊÆµÄÔ¤²â³ÂËß


KasperskyÐû²¼2022ÄêAPT¹¥»÷ÍþÐ²Ì¬ÊÆµÄÔ¤²â³ÂËß.png


KasperskyÓÚ11ÔÂ17ÈÕÐû²¼ÁË2022ÄêAPT¹¥»÷ÍþÐ²Ì¬ÊÆµÄÔ¤²â³ÂËß¡£³ÂËßÖ¸³ö£¬APT×éÖ¯½«´ÓÆäËû¹¥»÷ÕßÄÇÀﹺÖóõÊ¼ÍøÂç·ÃÎÊȨÏÞ £»¸ü¶à¹ú¼Ò½«Ö´·¨ÆðËß×÷ΪÆäÍøÂçÕ½ÂÔµÄÒ»²¿ÃÅ £»¶ÔÍøÂçÉ豸µÄÕë¶ÔÐÔ¹¥»÷Ôö¼Ó £»5G©¶´¼´½«·ºÆð £»¹¥»÷Õß½«¼ÌÐøÀûÓÃCOVID-19Ö÷Ìâ £»Òƶ¯É豸½«Êܵ½¹ã·º¹¥»÷ £»¹©Ó¦Á´¹¥»÷µÄÊýÁ¿½«Ôö¼Ó £»¼ÌÐøÀûÓÃWFH £»METAµØÓò£¬ÓÈÆäÊÇ·ÇÖÞµÄAPT»î¶¯½«Ôö¼Ó¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/advanced-threat-predictions-for-2022/104870/