Cisco·¢ÏÖÀûÓÃÓòÃûǰÖü¼ÊõÃé×¼ÃåµéÕþ¸®µÄ¹¥»÷»î¶¯

Ðû²¼Ê±¼ä 2021-11-19

Cisco·¢ÏÖÀûÓÃÓòÃûǰÖü¼ÊõÃé×¼ÃåµéÕþ¸®µÄ¹¥»÷»î¶¯


Cisco·¢ÏÖÀûÓÃÓòÃûǰÖü¼ÊõÃé×¼ÃåµéÕþ¸®µÄ¹¥»÷»î¶¯.png


Cisco TalosÔÚ11ÔÂ16ÈÕÅû¶ÁËÀûÓÃеÄÒþ²Ø¼¼ÊõÈÆ¹ý¼ì²âµÄ¹¥»÷»î¶¯¡£´Ë´Î»î¶¯×î³õ·¢ÏÖÓÚ½ñÄê9Ô·Ý £¬ÀûÓÃÁËÒ»ÖÖÃûΪÓòÃûǰÖõļ¼ÊõÀ´Òþ²ØC2¡£´ËÍâ £¬¹¥»÷Õß»¹ÀûÓÃÁ˺Ϸ¨µÄ¹¤¾ßCobalt Strik £¬µ±BeaconÆô¶¯Ê±½«ÎªÍйÜÔÚCloudflareµÄºÏ·¨ÓòÌá½»DNSÇëÇó £¬È»ºóÐ޸ĺóÐøµÄHTTPsÇëÇóÍ· £¬ÒÔָʾCDN½«Á÷Á¿Öض¨Ïòµ½¹¥»÷Õß¿ØÖƵÄÖ÷»ú¡£»î¶¯ÖÐʹÓõĺϷ¨ÓòÃûΪÃåµéÊý×ÖÐÂÎŵÄmdn[.]gov[.]mm¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2021/11/attackers-use-domain-fronting-technique.html


ESET·¢ÏÖÒÔÉ«ÁÐCandiruÕë¶ÔÓ¢¹úºÍÖж«µÄË®¿Ó¹¥»÷


ESET·¢ÏÖÒÔÉ«ÁÐCandiruÕë¶ÔÓ¢¹úºÍÖж«µÄË®¿Ó¹¥»÷.png


11ÔÂ16ÈÕ £¬ESETµÄÑо¿ÈËÔ±³ÆÒÔÉ«ÁеļäµýÈí¼þCandiruÓëÕë¶ÔÓ¢¹úºÍÖж«µÄË®¿Ó¹¥»÷ÓйØ¡£CandiruÒÑÓÚ±¾Ô±»ÃÀ¹úÉÌÎñ²¿ÁÐÈë¶ñÒâÍøÂç»î¶¯×éÖ¯Ãûµ¥¡£´Ë´Î»î¶¯´óÖ·ÖΪÁ½²¨ £¬µÚÒ»²¨¿ªÊ¼ÓÚ2020Äê3Ô £¬ÓÚ2020Äê8Ô½áÊø £¬µÚ¶þ²¨¹¥»÷¿ªÊ¼ÓÚ2021Äê1Ô¿ªÊ¼ £¬Ò»Ö±Á¬Ðøµ½2021Äê8ÔÂÉÏÑ® £¬¹¥»÷ÁËÓ¢¹ú¡¢Ò²ÃÅ¡¢ÒÁÀÊ¡¢ÐðÀûÑÇ¡¢É³Ìذ¢À­²®¡¢Òâ´óÀûºÍÄϷǵȵØÓòµÄ×éÖ¯¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/11/israels-candiru-spyware-found-linked-to.html


еĵöÓã»î¶¯Ã°³äTikTokÔ±¹¤ÒÔɾ³ýÕ˺ÅÀ´ÍþвÓû§


еĵöÓã»î¶¯Ã°³äTikTokÔ±¹¤ÒÔɾ³ýÕ˺ÅÀ´ÍþвÓû§.png


Abnormal SecurityÔÚ11ÔÂ17ÈÕ·¢ÏÖÕë¶ÔTikTokÓû§µÄÐÂÒ»ÂÖµöÓã»î¶¯¡£¹¥»÷Õßð³äTikTokÔ±¹¤ £¬¾¯¸æÄ¿±êÒòÆäÉæÏÓÎ¥·´Æ½Ì¨Ìõ¿î¶ø½«Á¢¼´É¾³ýÕÊ»§¡£Ö®ºó £¬Óû§»á±»Öض¨Ïòµ½Ò»¸öWhatsAppÁÄÌìÊÒ £¬²¢±»ÒªÇóÌá¹©ÖØÖÃÕÊ»§ÃÜÂëËùÐèµÄÓʼþµØÖ·¡¢µç»°ºÅÂëºÍÒ»´ÎÐÔ´úÂ롣ĿǰÉв»Çå³þ¹¥»÷ÕßµÄÄ¿µÄÊÇʲô £¬»òÐíÖ¼ÔÚ½Ó¹ÜÕË»§»òÀÕË÷¡£´Ë´Î»î¶¯µÄÁ½¸ö·åÖµ·Ö±ðÔÚ10ÔÂ2ÈÕºÍ11ÔÂ1ÈÕ £¬Òò´ËÑо¿ÈËÔ±ÍÆ²âÏÂÒ»Âֻ¿ÉÄÜ»áÔÚ¼¸Öܺó¿ªÊ¼¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/tiktok-phishing-threatens-to-delete-influencers-accounts/


ÐÂÀÕË÷ÔËÓªÍÅ»ïMementoÀûÓÃvCenterÖеÄRCE©¶´


ÐÂÀÕË÷ÔËÓªÍÅ»ïMementoÀûÓÃvCenterÖеÄRCE©¶´.png


SophosÓÚ11ÔÂ18ÈÕÅû¶ÁËÀÕË÷ÔËÓªÍÅ»ïMementoµÄл¡£¹¥»÷ÕßÀûÓÃÁËVMware vCenter Server WebÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-21971£© £¬CVSSÆÀ·ÖΪ9.8¡£¹¥»÷Õß¿ÉÀûÓøÃ©¶´·ÃÎÊTCP/IP¶Ë¿Ú443 £¬²¢ÒÔ¹ÜÀíԱȨÏÞÖ´ÐÐÃüÁî £¬Æä²¹¶¡ÒÑÓÚ2Ô·ÝÐû²¼¡£´Ë´Î»î¶¯¿ªÊ¼ÓÚÉϸöÔ £¬¹¥»÷ÕßÊ×ÏÈÀûÓÃvCenterÖеÄ©¶´´ÓÄ¿±ê·þÎñÆ÷ÇÔÈ¡¹ÜÀíÆ¾¾Ý £¬È»ºóʹÓÃRDP over SSHºáÏòÒÆ¶¯ £¬²¢Ê×´ÎÔÚ¹¥»÷ÖÐʹÓÃÁËWinRARÀ´Ñ¹ËõÎļþ²¢¶ÔÆä½øÐмÓÃÜ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-memento-ransomware-switches-to-winrar-after-failing-at-encryption/


CISAÐû²¼2021ÄêÍøÂçÄþ¾²Ê¼þºÍ©¶´µÄÓ¦¼±ÏìÓ¦Ö¸ÄÏ


CISAÐû²¼2021ÄêÍøÂçÄþ¾²Ê¼þºÍ©¶´µÄÓ¦¼±ÏìÓ¦Ö¸ÄÏ.png


11ÔÂ16ÈÕ £¬ÃÀ¹úCISAÐû²¼ÁË2021ÄêÍøÂçÄþ¾²Ê¼þºÍ©¶´µÄÓ¦¼±ÏìÓ¦Ö¸ÄÏ¡£¸ÃÖ¸ÄÏΪÁª°îÎÄÖ°ÐÐÕþ²¿ÃÅ£¨FCEB£©»ú¹¹ÌṩÁËÓÃÓڹ滮ºÍ¿ªÕ¹ÍøÂçÄþ¾²Ê¼þºÍ©¶´ÏìÓ¦»î¶¯µÄ²Ù×÷·¨Ê½ £¬²¢Í¨¹ý¾ö²ßÊ÷Ïêϸ˵Ã÷ÁËʼþºÍ©¶´ÏìÓ¦µÄÿ¸ö²½Öè¡£CISAÃãÀøÒªº¦»ù´¡ÉèÊ©Ïà¹Ø×éÖ¯ £¬ÖÝ¡¢µØ·½µÄÕþ¸®×éÖ¯ÒÔ¼°Ë½Óª×éÖ¯ÀûÓøÃÖ¸ÄϽøÐÐÉó²é £¬ÒÔ¶ÔÆä×ÔÉíµÄ©¶´ºÍʼþÏìӦʵ¼ù½øÐлù×¼²âÊÔ¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/11/16/new-federal-government-cybersecurity-incident-and-vulnerability


KasperskyÐû²¼2022ÄêAPT¹¥»÷ÍþÐ²Ì¬ÊÆµÄÔ¤²â³ÂËß


KasperskyÐû²¼2022ÄêAPT¹¥»÷ÍþÐ²Ì¬ÊÆµÄÔ¤²â³ÂËß.png


KasperskyÓÚ11ÔÂ17ÈÕÐû²¼ÁË2022ÄêAPT¹¥»÷ÍþÐ²Ì¬ÊÆµÄÔ¤²â³ÂËß¡£³ÂËßÖ¸³ö £¬APT×éÖ¯½«´ÓÆäËû¹¥»÷ÕßÄÇÀﹺÖóõÊ¼ÍøÂç·ÃÎÊȨÏÞ£»¸ü¶à¹ú¼Ò½«Ö´·¨ÆðËß×÷ΪÆäÍøÂçÕ½ÂÔµÄÒ»²¿ÃÅ£»¶ÔÍøÂçÉ豸µÄÕë¶ÔÐÔ¹¥»÷Ôö¼Ó£»5G©¶´¼´½«·ºÆð£»¹¥»÷Õß½«¼ÌÐøÀûÓÃCOVID-19Ö÷Ì⣻Òƶ¯É豸½«Êܵ½¹ã·º¹¥»÷£»¹©Ó¦Á´¹¥»÷µÄÊýÁ¿½«Ôö¼Ó£»¼ÌÐøÀûÓÃWFH£»METAµØÓò £¬ÓÈÆäÊÇ·ÇÖÞµÄAPT»î¶¯½«Ôö¼Ó¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/advanced-threat-predictions-for-2022/104870/