KasperskyÐû²¼¶ñÒâÈí¼þÆÊÎö±¨¸æ£ºFarFariaÓ¦ÓõÄÊý¾Ý¿âй¶290ÍòÓû§ÐÅÏ¢

Ðû²¼Ê±¼ä 2021-09-30

΢Èí·¢Ã÷Ö¼ÔÚÇÔÈ¡AD FSÖÎÀíԱƾ֤µÄºóÃÅFoggyWeb


΢Èí·¢Ã÷Ö¼ÔÚÇÔÈ¡AD FSÖÎÀíԱƾ֤µÄºóÃÅFoggyWeb.jpg


΢ÈíÍþвÇ鱨ÖÐÐÄ(MSTIC)ÓÚ9ÔÂ27ÈÕÅû¶ÁËÖ¼ÔÚÇÔÈ¡Active DirectoryÁªºÏÉí·ÝÑé֤ЧÀÍ(AD FS)ÖÎÀíԱƾ֤µÄºóÃÅFoggyWeb¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÓë¶íÂÞ˹Íâ¹úÇ鱨¾Ö(SVR)µÄºÚ¿ÍÍÅ»ïNobeliumÓйØ£¬ £¬ £¬£¬ÀÄÓÃÁËSAMLÁîÅÆ¡£¡£¡£¡£¡£Ëü¿ÉÒÔΪ¹¥»÷Õß½ç˵µÄURIÉèÖÃHTTP¼àÌýÆ÷£¨ÕâЩURIÄ£ÄâÁËÄ¿µÄAD FSʹÓõÄÕýµ±URIµÄ½á¹¹£©£¬ £¬ £¬£¬À´¼àÌý·¢Ë͵½AD FSµÄHTTP GETºÍPOSTÇëÇó£¬ £¬ £¬£¬²¢×èµ²Óë×Ô½ç˵URIģʽƥÅäµÄHTTPÇëÇ󡣡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.microsoft.com/security/blog/2021/09/27/foggyweb-targeted-nobelium-malware-leads-to-persistent-backdoor/



Ñо¿Ö°Ô±·¢Ã÷Õë¶Ô²¨À¼µÄÐÂAndroidÒøÐÐľÂíERMAC


Ñо¿Ö°Ô±·¢Ã÷Õë¶Ô²¨À¼µÄÐÂAndroidÒøÐÐľÂíERMAC.png


ºÉÀ¼Çå¾²¹«Ë¾ThreatFabric·¢Ã÷ÁËÒ»ÖÖÃûΪERMACµÄÐÂAndroidÒøÐÐľÂí¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ»ùÓÚCerberus£¨ÆäÔ´´úÂëÒÑÓÚ2020Äê9ÔÂÔÚºÚ¿ÍÂÛ̳¹ûÕæ£©£¬ £¬ £¬£¬ÓëBlackRock±³ºóµÄÔËÓªÉÌÓйء£¡£¡£¡£¡£ÓëCerberusÏà±È£¬ £¬ £¬£¬ERMACʹÓÃÁËBlowfish¼ÓÃÜËã·¨£¬ £¬ £¬£¬²¢ÇÒÔÚÓëC2µÄͨѶÖÐʹÓÃÁËAES-128-CBC¼ÓÃܼƻ®¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬ £¬ £¬£¬ERMAC×Ô8ÔÂÏÂÑ®×îÏÈ»îÔ¾£¬ £¬ £¬£¬×îÏÈαװ³ÉGoogle Chrome£¬ £¬ £¬£¬Ö®ºó»¹Î±×°³Éαװ³É·À²¡¶¾¡¢ÒøÐкÍýÌå²¥·ÅÆ÷µÈÓ¦Ó㬠£¬ £¬£¬¿ÉÕë¶Ô378¸ö½ðÈÚÏà¹ØµÄÓ¦ÓóÌÐò¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.threatfabric.com/blogs/ermac-another-cerberus-reborn.html



QNAPÐû²¼¸üУ¬ £¬ £¬£¬ÐÞ¸´QVRÖÐ3¸öÑÏÖØµÄÏÂÁî×¢ÈëÎó²î


QNAPÐû²¼¸üУ¬£¬£¬£¬ÐÞ¸´QVRÖÐ3¸öÑÏÖØµÄÏÂÁî×¢ÈëÎó²î.png


NASÖÆÔìÉÌQNAPÔÚ9ÔÂ27ÈÕÐû²¼Çå¾²¸üУ¬ £¬ £¬£¬ÐÞ¸´ÁËÊÓÆµÖÎÀíϵͳQVRÖÐ3¸öÑÏÖØµÄÏÂÁî×¢ÈëÎó²î¡£¡£¡£¡£¡£ÆäÖеÄÁ½¸öÎó²îCVSSÆÀ·ÖΪ9.8£¬ £¬ £¬£¬Ô¶³Ì¹¥»÷Õß¿ÉʹÓÃÆäÔÚÄ¿µÄϵͳÉÏÖ´ÐÐÏÂÁ £¬ £¬£¬´Ó¶øÍêÈ«¿ØÖÆ×°±¸¡£¡£¡£¡£¡£ÁíÍâÒ»¸öÎó²î×·×ÙΪCVE-2021-34349£¬ £¬ £¬£¬CVSSÆÀ·ÖΪ7.2£¬ £¬ £¬£¬ÓëÇ°ÃæÁ½¸öÎó²îµÄ²î±ðÊÇʹÓÃËùÐèµÄȨÏÞ²î±ð¡£¡£¡£¡£¡£QNAPÖ¸³ö£¬ £¬ £¬£¬ÆäÖÐÁ½¸öÎó²î»¹Ó°ÏìÁ˲¿·ÖEOL×°±¸¡£¡£¡£¡£¡£ÏÖÔÚ£¬ £¬ £¬£¬Éв»ÇåÎúÕâЩÎó²îÊÇ·ñÒѱ»ÔÚҰʹÓÃÁË¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/qnap-fixes-critical-bugs-in-qvr-video-surveillance-solution/



FarFariaÓ¦ÓõÄÊý¾Ý¿âÉèÖùýʧй¶290Íò¸öÓû§µÄÐÅÏ¢


FarFariaÓ¦ÓõÄÊý¾Ý¿âÉèÖùýʧй¶290Íò¸öÓû§µÄÐÅÏ¢.png


Comparitech·¢Ã÷¶ùͯ¹ÊÊÂÊéÓ¦ÓÃFarFariaµÄMongoDBÊý¾Ý¿âÉèÖùýʧ£¬ £¬ £¬£¬Ð¹Â¶290Íò¸öÓû§µÄÐÅÏ¢¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚ2021Äê8ÔÂ9ÈÕ·¢Ã÷¸ÃÎÊÌ⣬ £¬ £¬£¬Ö±µ½9ÔÂ27ÈÕ²ÅÅû¶³öÀ´¡£¡£¡£¡£¡£´Ë´Î×ܼÆÐ¹Â¶ÁË38GBµÄÊý¾Ý£¬ £¬ £¬£¬°üÀ¨µç×ÓÓʼþ¡¢Éí·ÝÑéÖ¤ÁîÅÆ¡¢ÃÜÂë¡¢µÇ¼ÐÅÏ¢ºÍÆäËüµÄÉ罻ýÌåÐÅÏ¢µÈ¡£¡£¡£¡£¡£Éв»ÇåÎúÕâЩÊý¾ÝÊÇ·ñÒѱ»Ê¹Ó㬠£¬ £¬£¬¸ÃÊý¾Ý¿âÔÚÏÖÔÚÒѱ»±£»£»£»¤ÆðÀ´¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/storybooks-for-children-app-farfaria-exposed-data/



CISAºÍNSAÁªºÏÐû²¼ÓйØÑ¡ÔñºÍ¼Ó¹ÌVPNµÄÇå¾²Ö¸ÄÏ


CISAºÍNSAÁªºÏÐû²¼ÓйØÑ¡ÔñºÍ¼Ó¹ÌVPNµÄÇå¾²Ö¸ÄÏ.png


ÃÀ¹úCISAºÍNSAÔÚ9ÔÂ28ÈÕÁªºÏÐû²¼ÁËÓйØÑ¡ÔñºÍ¼Ó¹ÌVPNµÄÇå¾²Ö¸ÄÏ¡£¡£¡£¡£¡£Ö¸ÄÏÖ¸³ö£¬ £¬ £¬£¬×éÖ¯Ó¦¸Ã´ÓÐÅÓþÓÅÒìµÄ¹©Ó¦ÉÌÄÇÀïÑ¡Ôñ²úÆ·£¬ £¬ £¬£¬ÓÉÓÚËûÃÇ»áÒÔ×î¿ìµÄËÙÂÊÐÞ¸´ÒÑÖªÎó²î¡£¡£¡£¡£¡£Çå¾²»ú¹¹³Æ£¬ £¬ £¬£¬VPN×°±¸¿ÉÒÔÍøÂçÆ¾Ö¤¡¢ÓÃÀ´Ô¶³ÌÖ´ÐдúÂë¡¢Ï÷Èõ¼ÓÃÜÁ÷Á¿»á»°µÄ¼ÓÃÜ¡¢Ð®ÖƻỰÒÔ¼°¶ÁÈ¡Ãô¸ÐÐÅÏ¢£¬ £¬ £¬£¬½¨Òé×éÖ¯ÉèÖÃÇ¿¼ÓÃܺÍÉí·ÝÑéÖ¤¡¢½öÔËÐÐÐëÒªµÄ¹¦Ð§ÒÔ¼°±£»£»£»¤ºÍ¼à¿Ø¶ÔVPNµÄ»á¼û¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/09/28/cisa-and-nsa-release-guidance-selecting-and-hardening-vpns



KasperskyÐû²¼¶ñÒâÈí¼þBloodyStealerµÄÆÊÎö±¨¸æ


KasperskyÐû²¼¶ñÒâÈí¼þBloodyStealerµÄÆÊÎö±¨¸æ.png


KasperskyÔÚ9ÔÂ27ÈÕÐû²¼ÁËÓйضñÒâÈí¼þBloodyStealerµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±3Ô·ÝÔÚ°µÍøÉÏ·¢Ã÷ÁËÓйضñÒâÈí¼þBloodyStealerµÄ¹ã¸æ£¬ £¬ £¬£¬¼ÛÇ®ÊÇ700¬²¼Ò»¸öÔ£¨Ô¼10ÃÀÔª£©»ò3000¬²¼Ò»´ÎÐÔ¹ºÖᣡ£¡£¡£¡£Ëü¿ÉÒÔÇÔÈ¡¶à¸öÓÎϷƽ̨µÄÕÊ»§£¬ £¬ £¬£¬°üÀ¨Steam¡¢Epic Games Store ºÍEA Origin£¬ £¬ £¬£¬»¹¾ßÓÐÈÆ¹ýÇå¾²¼ì²âºÍ¶ñÒâÈí¼þÆÊÎöµÄ¹¦Ð§¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬ £¬ £¬£¬×Ô¾õÏÖÒÔÀ´£¬ £¬ £¬£¬¸ÃľÂíÖ÷ÒªÓÃÀ´Õë¶ÔÅ·ÖÞ¡¢À­¶¡ÃÀÖÞºÍÑÇÌ«µØÇøµÄÓû§¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/bloodystealer-and-gaming-assets-for-sale/104319/