ÃÀ¹ú×ÜͳǩÊ𡶸ÄÉÆ¹ú¼ÒÍøÂçÄþ¾²µÄÐÐÕþÃüÁî¡·£»Cisco¸üÐÂÐÞ¸´AnyConnect VPNÖдæÔÚ6¸öÔµÄ0day

Ðû²¼Ê±¼ä 2021-05-14

1.ÃÀ¹ú×ÜͳǩÊ𡶸ÄÉÆ¹ú¼ÒÍøÂçÄþ¾²µÄÐÐÕþÃüÁî¡·


1.jpg


ÃÀ¹ú×ÜͳÓÚ±¾ÖÜÈý£¨2021Äê5ÔÂ12ÈÕ£©Ç©ÊðÁË¡¶¸ÄÉÆ¹ú¼ÒÍøÂçÄþ¾²µÄÐÐÕþÃüÁî¡· ¡£¸ÃÐÐÕþÃüÁîÊǼ̽ñÄêÖÚ¶àÕë¶ÔÃÀ¹úµÄÍøÂç¹¥»÷Ö®ºó°ä²¼µÄ £¬°üÂÞ12ÔµÄSolarWinds¹©Ó¦Á´¹¥»÷ÒÔ¼°×î½üµÄÕë¶ÔColonial PipelineµÄDarkSideÀÕË÷Èí¼þ¹¥»÷ ¡£¸ÃÃüÁîÖ¼ÔÚÏÖ´ú»¯Áª°îÕþ¸®»ù´¡ÉèÊ©µÄÍøÂçÄþ¾²·ÀÓù´ëÊ©¡¢´´½¨³ß¶È»¯µÄʼþÏìÓ¦ÊֲᲢ¼ÓÇ¿·þÎñÌṩÉÌÓëÖ´·¨²¿ÃÅÖ®¼äµÄÏàͬ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/biden-issues-executive-order-to-increase-us-cybersecurity-defenses/


2.Cisco¸üÐÂÐÞ¸´AnyConnect VPNÖдæÔÚ6¸öÔµÄ0day


2.jpg


˼¿ÆÐû²¼Äþ¾²¸üР£¬ÐÞ¸´ÁËÔÚAnyConnect VPNÖÐÒÑ´æÔÚ6¸öÔÂÖ®¾ÃµÄ0day £¬²¢ÌṩÁ˹ûÈ»¿ÉÓõĿ´·¨Ñé֤©¶´ÀûÓôúÂë ¡£CiscoÓÚ2020Äê11ÔÂÅû¶Á˸é¶´£¨CVE-2020-3556£© £¬ µ«Ö»ÌṩÁË»º½â´ëÊ©²¢Î´Ðû²¼Äþ¾²¸üР¡£¸Ã©¶´´æÔÚÓÚAnyConnectµÄ½ø³Ì¼äͨÐÅ£¨IPC£© £¬ÔÊÐí¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÖ´ÐжñÒâ½Å±¾ ¡£ÏÖÔÚ £¬ÏÈǰÐû²¼µÄ»º½â´ëÊ©ÈÔÈ»¿ÉÓà £¬ÎÞ·¨Á¢¼´°²×°Äþ¾²¸üеĿͻ§¿ÉÒÔͨ¹ýÇл»×Ô¶¯¸üй¦Ð§À´»º½â´Ë©¶´ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/cisco-fixes-6-month-old-anyconnect-vpn-zero-day-with-exploit-code/


3.ÍÁ¶úÆä¿ÆÄáÑÇÊÐÕþ¸®Ôâµ½¹¥»÷ £¬100Íò¾ÓÃñµÄÐÅϢй¶


3.jpg


ÍÁ¶úÆä¿ÆÄáÑÇÊÐÕþ¸®µÄÍøÂçÔâµ½¹¥»÷ £¬100Íò¾ÓÃñµÄÐÅϢй¶ ¡£¿ÆÄáÑÇÊÇÍÁ¶úÆä¿ÆÄáÑÇÊ¡µÄÊ׸® £¬¶¼ÊÐÈË¿ÚÁè¼Ý100Íò £¬ÊÇÍÁ¶úÆä×Ú½Ì×îÊØ¾ÉµÄ¶àÊý»áÖ®Ò» ¡£Ä³ÊÐÕþ¹ÙԱ֤ʵÁ˴˴ι¥»÷ £¬µ«²¢Î´Í¸Â¶Æä¹æÄ£ £¬S?zc¨¹±¨Ö½Ôò³Æ £¬Ô¼ÓÐ100ÍòÈ˵ÄIDºÍÆäËû¸öÈËÐÅÏ¢ÒѾ­Ð¹Â¶ £¬Ö÷񻃾¼°ÄÇЩÏòÊÐÕþÕþ¸®·¢Ë͹ýÓʼþµÄÈË ¡£Ä¿Ç° £¬ÃûΪMaxim GorkiµÄµÄºÚ¿ÍÒÑÔÚ°µÍøÉϹûÈ»ÁËÕâЩÐÅÏ¢ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.dailysabah.com/turkey/investigations/cyberattack-steals-info-of-one-million-in-turkeys-konya


4.΢ÈíÅû¶Õë¶Ôº½¿Õº½ÌìÐÐÒµµÄÓã²æÊ½ÍøÂçµöÓã»î¶¯


4.jpg


΢ÈíÅû¶½üÆÚÕë¶Ôº½¿Õº½ÌìºÍÂÃÓÎÐÐÒµµÄÓã²æÊ½ÍøÂçµöÓã»î¶¯ ¡£´Ë´Î¹¥»÷ÖÐ £¬ºÚ¿Íαװ³Éº½¿Õ¡¢ÂÃÓκͻõÔ˹«Ë¾ £¬Ê¹ÓÃÁËеļÓÔØ·¨Ê½Snip3 £¬ÔÚÄ¿±êϵͳÖа²×°Revenge RAT¡¢AsyncRAT¡¢Agent TeslaºÍNetWire RATµÈpayload ¡£ÎªÁËÈÆ¹ý¼ì²â £¬Snip3»¹Ê¹ÓÃÁ˹¥»÷ÊÖ¶Î £¬°üÂÞ£ºÓÃ'remotesigned'²ÎÊýÖ´ÐÐPowerShell´úÂ룻ʹÓÃPastebinºÍtop4top½øÐзֶΣ»ÔËÐеÄʱºòÔÚÖն˱àÒëRunPE¼ÓÔØ·¨Ê½ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-threat-actors-target-aviation-orgs-with-new-malware/


5.Ñо¿ÈËÔ±ÑÝʾÈçºÎʹÓÃÆ»¹ûFind My networkÇÔÈ¡ÐÅÏ¢


5.jpg


Ñо¿ÈËÔ±Fabian Br?unleinÑÝʾÁËÈçºÎʹÓÃÆ»¹ûµÄFind My network¹¦Ð§ÇÔÈ¡ÐÅÏ¢ ¡£¸Ã¹¦Ð§Ö÷ÒªÓÃÓÚ²éÕÒiOSºÍmacOSÉ豸 £¬ÒÔ¼°×î½üµÄAirTagºÍÆäËûÌ×¼þ ¡£Br?unleinʹÓûùÓÚopenhaystackµÄ¹Ì¼þµÄESP32΢¿ØÖÆÆ÷À´¹ã²¥Ò»¸öÓ²±àÂëµÄȱʡÏûÏ¢ £¬²¢ÔÚÆä´®ÐнӿÚÉÏÕìÌýÐÂÊý¾Ý ¡£ËÄÖÜÆôÓÃÁ˸ù¦Ð§µÄÉ豸½«½ÓÊÕÕâЩÐźŠ£¬²¢×ª·¢µ½Æ»¹ûµÄ·þÎñÆ÷ ¡£µ«ÊÇÈç¹ûÏëÒª¼ì²ìÕâЩ´«ÊäÐÅÏ¢ £¬»¹Ðè°²×°OpenHaystack²¢ÔËÐÐBr?unlein´´½¨µÄmacOSÓ¦ÓÃDataFetcher ¡£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.com/2021/05/12/apples_find_network/


6.Unit42Ðû²¼ÓйØDarkSideÀÕË÷ÍÅ»ïµÄ·ÖÎö³ÂËß


6.jpg


Unit42Ðû²¼ÁËÓйØDarkSideÀÕË÷ÍÅ»ïµÄ·ÖÎö³ÂËß ¡£DarkSideÊÇÊÀ½çÉÏ×îÖªÃûµÄºÚ¿Í×éÖ¯Ö®Ò» £¬½üÆÚÕë¶ÔÃÀ¹úÒ»¼ÒÖ÷ÒªµÄ¹ÜµÀ¹«Ë¾½øÐÐÁ˹¥»÷ ¡£ÓëÆäËûÀÕË÷Èí¼þÍÅ»ïÒ»Ñù £¬DarkSide×î½üÒ²½ÓÄÉÁËÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©Ä£ÐÍ ¡£¸ÃÍÅ»ïʹÓõŤ¾ß°üÂÞ£ººÏ·¨µÄÔ¶³Ì¼àÊӺ͹ÜÀí£¨RMM£©¹¤¾ß £¬ÀýÈçAnyDeskºÍTeamViewer£»ÃÜÂë¹ÜÀíÓ¦Óà £¬ÀýÈçDashlaneºÍLastPass£»Æ¾Ö¤ÇÔÈ¡¹¤¾ßMimikatzµÈ¹¤¾ß ¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/darkside-ransomware/