NSOÀûÓÃiMessageÖеÄÐÂÁãµã»÷©¶´¹¥»÷°ÍÁÖ»îÔ¾ÈËÊ¿:F5Ðû²¼Äþ¾²¸üÐÂÐÞ¸´Æä¶à¿î²úÎï

Ðû²¼Ê±¼ä 2021-08-27

NSOÀûÓÃiMessageÖеÄÐÂÁãµã»÷©¶´¹¥»÷°ÍÁÖ»îÔ¾ÈËÊ¿


NSOÀûÓÃiMessageÖеÄÐÂÁãµã»÷©¶´¹¥»÷°ÍÁÖ»îÔ¾ÈËÊ¿.jpg


Citizen LabÓÚ2021Äê8ÔÂ24ÈÕÐû²¼ÁËÒ»ÏîÑо¿ £¬³ÆNSO GroupÀûÓÃiMessageÖÐеÄÁãµã»÷©¶´ÔÚÄ¿±êiPhoneÉϰ²×°¼äµýÈí¼þPegasus ¡£Ñо¿±íÃ÷ £¬´Ë´Î¹¥»÷ʼÓÚ2021Äê7Ô £¬Ö÷ÒªÕë¶Ô°ÍÁÖµÄ9¸ö»îÔ¾ÈËÊ¿£¨°üÂÞ°ÍÁÖÈËȨÖÐÐijÉÔ±¡¢WaadºÍAl WefaqµÈ£© ¡£Ôڴ˴λÖÐ £¬¹¥»÷ÕßÀûÓÃÁËÁ½¸öÁãµã»÷©¶´ £¬·Ö±ð³ÆÎª2020  KISMETºÍЩ¶´FORCEDENTRY ¡£Ä¿Ç°ÉÐδÓйØFORCEDENTRY©¶´µÄ¼¼Êõϸ½Ú £¬Ö÷ÒªÊÇÒòΪ¸Ã©¶´ÈÔδÐÞ¸´ ¡£ 


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/121415/malware/zero-click-exploit-nso.html


F5Ðû²¼Äþ¾²¸üР£¬ÐÞ¸´Æä¶à¿î²úÎïÖеĽü30¸öÄþ¾²Â©¶´


F5Ðû²¼Äþ¾²¸üÐÂ£¬ÐÞ¸´Æä¶à¿î²úÎïÖеĽü30¸öÄþ¾²Â©¶´.jpg


F5ÔÚ8ÔÂ24ÈÕÐû²¼ÁË8Ô·ÝÄþ¾²¸üР£¬ÐÞ¸´ÁËÆä¶à¿î²úÎïÖнü30¸ö©¶´ ¡£´Ë´ÎÐÞ¸´µÄ×îΪÑÏÖØµÄ©¶´ÊÇBIG-IP WAFºÍASMÁ÷Á¿¹ÜÀíÓû§½çÃæ(TMUI)ÉϵÄÌáȨ©¶´ £¬×·×ÙΪCVE-2021-23031 £¬ÆÀ·ÖΪ8.8 £¬µ«¶ÔÓÚʹÓÃÉ豸ģʽµÄÓû§À´Ëµ £¬ÆÀ·Ö½«Ìá¸ßµ½9.9 ¡£´ËÍâ £¬»¹ÓÐBIG-IPÖеÄÔ¶³ÌÃüÁîÖ´ÐЩ¶´£¨CVE-2021-23025£©¡¢BIG-IPºÍBIG-IQÖеÄCSRF©¶´£¨CVE-2021-23026£©ºÍTMUIÖеĻùÓÚDOMµÄXSS©¶´£¨CVE-2021-23027£©µÈ ¡£


Ô­ÎÄÁ´½Ó£º

https://support.f5.com/csp/article/K50974556


Ðé¼ÙµÄOpenSeaÖ§³ÖÆ­¾ÖÒþÄäÔÚDiscordÍøÂçÖй¥»÷Ä¿±ê


Ðé¼ÙµÄOpenSeaÖ§³ÖÆ­¾ÖÒþÄäÔÚDiscordÍøÂçÖй¥»÷Ä¿±ê.jpg


ÔÚ¹ýÈ¥µÄÒ»ÖÜÀï £¬Ðé¼ÙµÄOpenSeaÖ§³ÖÆ­¾ÖÒþÄäÔÚDiscordÍøÂçÖй¥»÷Ä¿±ê £¬Ö¼ÔÚÇÔÈ¡Óû§×ʽð ¡£µ±Óû§ÔÚÍøÉÏѰÇó×ÊÖúʱ £¬ÒþÄäÔÚDiscord·þÎñÆ÷ÉϵÄÕ©Æ­Õß±ã»á·¢ËÍ˽ÐÅÑûÇëÆä¼ÓÈëÐé¼ÙµÄOpenSeaÖ§³Ö·þÎñ ¡£Ö®ºó £¬Õ©Æ­Õß»áÒªÇóÄ¿±ê¿ªÆôÆÁÄ»¹²Ïí £¬²¢É¨Ãè¶þάÂëÒÔͬ²½MetaMaskÇ®°üÓëChromeÀ©Õ¹·¨Ê½ ¡£×îºó £¬Õ©Æ­Õß»áÓøöþάÂ뽫Ŀ±êÇ®°üÖеÄ×ʽð×ªÒÆ³öÀ´ ¡£    


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fake-opensea-support-staff-are-stealing-cryptowallets-and-nfts/


ÃÀ¹úСÕòPeterboroughÒò2´ÎBEC¹¥»÷Ëðʧ230ÍòÃÀÔª


ÃÀ¹úСÕòPeterboroughÒò2´ÎBEC¹¥»÷Ëðʧ230ÍòÃÀÔª.jpg


ÃÀ¹úк±²¼Ê²¶ûÖݵÄСÕòPeterboroughÒò2´ÎBEC¹¥»÷Ëðʧ230ÍòÃÀÔª ¡£¸ÃÕò¹ÙÔ±ÌåÏÖ £¬ËûÃÇÓÚ7ÔÂ26ÈÕÊ״η¢ÏÖ¹¥»÷»î¶¯ £¬ÆäʱConValÑ§Çø³ÆÆäûÓÐÊÕµ½Ã¿ÔÂ120ÍòÃÀÔªµÄתÕË ¡£ÔÚËæºóµÄÊÓ²ìÖÐ £¬ÓÖÓÚ8ÔÂ18ÈÕ·¢ÏÖÁËÁíÍâÁ½±Ê±»½Ù³ÖµÄ¿îÏî £¬ÕâЩ¿îÏîÔ­±¾Òª×ª¸øÇÅÁº¹¤³ÌµÄ³Ð°üÉÌBeckºÍBellucci ¡£¸ÃÕò±¾²ÆÕþÄê¶ÈµÄÔ¤ËãԼΪ1580ÍòÃÀÔª £¬´Ë´ÎµÄËðʧռÆäÄê¶ÈÔ¤ËãµÄ15% ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/cyberthieves-scam-new-hampshire/


ESET·¢ÏÖSparklingGoblin¹¥»÷ÃÀ¹úij¼ÆËã»úÁãÊÛ¹«Ë¾


ESET·¢ÏÖSparklingGoblin¹¥»÷ÃÀ¹úij¼ÆËã»úÁãÊÛ¹«Ë¾.jpg


˹Âå·¥¿ËÍøÂçÄþ¾²¹«Ë¾ESETÔÚ8ÔÂ24ÈÕ³ÆÆä·¢ÏÖÁËAPTÍÅ»ïSparklingGoblin¹¥»÷ÃÀ¹úij¼ÆËã»úÁãÊÛ¹«Ë¾µÄ»î¶¯ ¡£ÔÚ¹ýÈ¥µÄÒ»ÄêÖÐ £¬¸ÃÍŻ﹥»÷ÁËÊÀ½ç¸÷µØµÄ×éÖ¯ £¬°üÂÞ°ÍÁÖ¡¢¼ÓÄô󡢸ñ³¼ªÑÇ¡¢Ó¡¶È¡¢ÐÂ¼ÓÆÂ¡¢º«¹úºÍÃÀ¹úµÈ ¡£Ôڴ˴ι¥»÷ÖÐ £¬¸ÃÍÅ»ïʹÓÃÁËÒ»¸öеĺóÃÅSideWalk £¬Ëü¿ÉÒÔ¶¯Ì¬¼ÓÔØ´ÓÆäC&C·þÎñÆ÷·¢Ë͵ÄÌØ±ðÄ£¿é £¬²¢ÀûÓùȸèDocs×÷Ϊdead drop resolver ¡£Ñо¿ÈËÌåÏÖ £¬SideWalkºÜ¿ÉÄÜÊÇÓÉCROSSWALKµÄ¿ª·¢ÈËÔ±¿ª·¢µÄ £¬ÒòΪËüÃǹ²ÏíÁËÐí¶àÉè¼Æ½á¹¹ºÍʵÏÖϸ½Ú ¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/08/new-sidewalk-backdoor-targets-us-based.html


Unit 42Ðû²¼ÓйØ4¸öеÄÀÕË÷ÔËÓªÍÅ»ïµÄ·ÖÎö³ÂËß


Unit 42Ðû²¼ÓйØ4¸öеÄÀÕË÷ÔËÓªÍÅ»ïµÄ·ÖÎö³ÂËß.jpg


Unit 42ÔÚ2021Äê8ÔÂ24ÈÕÐû²¼ÁËÓйØ4¸öеÄÀÕË÷ÔËÓªÍÅ»ïµÄ·ÖÎö³ÂËß ¡£ÕâËĸöÀÕË÷ÍÅ»ï·Ö±ðΪ6ÔÂÏÂÑ®¿ªÊ¼ÔËÓªµÄAvosLocker RaaS £¬Ö÷ÒªÕë¶ÔÃÀ¹ú¡¢Ó¢¹ú¡¢°¢ÁªÇõ¡¢±ÈÀûʱ¡¢Î÷°àÑÀºÍÀè°ÍÄÛ £¬Êê½ð´Ó50000ÃÀÔªµ½75000ÃÀÔª²»µÈ£»6Ô¿ªÊ¼µÄHive Ransomware £¬Òѹ¥»÷ÁË28¸ö×éÖ¯£»7Ô¿ªÊ¼»îÔ¾µÄLinux°æ±¾HelloKitty £¬ÆäÊ×ѡĿ±êΪVMwareµÄESXi¹ÜÀí·¨Ê½£»ÒÔ¼°ÔÚ6Ô¾­¹ý¸ïеÄLockBit 2.0 £¬ÒѾ­¹¥»÷ÁË52¸ö×éÖ¯ ¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/emerging-ransomware-groups/