Cisco·¢ÏÖÀûÓÃÓòÃûǰÖü¼ÊõÃé×¼ÃåµéÕþ¸®µÄ¹¥»÷»î¶¯
Ðû²¼Ê±¼ä 2021-11-19Cisco·¢ÏÖÀûÓÃÓòÃûǰÖü¼ÊõÃé×¼ÃåµéÕþ¸®µÄ¹¥»÷»î¶¯
Cisco TalosÔÚ11ÔÂ16ÈÕÅû¶ÁËÀûÓÃеÄÒþ²Ø¼¼ÊõÈÆ¹ý¼ì²âµÄ¹¥»÷»î¶¯¡£´Ë´Î»î¶¯×î³õ·¢ÏÖÓÚ½ñÄê9Ô·ݣ¬ÀûÓÃÁËÒ»ÖÖÃûΪÓòÃûǰÖõļ¼ÊõÀ´Òþ²ØC2¡£´ËÍ⣬¹¥»÷Õß»¹ÀûÓÃÁ˺Ϸ¨µÄ¹¤¾ßCobalt Strik£¬µ±BeaconÆô¶¯Ê±½«ÎªÍйÜÔÚCloudflareµÄºÏ·¨ÓòÌá½»DNSÇëÇó£¬È»ºóÐ޸ĺóÐøµÄHTTPsÇëÇóÍ·£¬ÒÔָʾCDN½«Á÷Á¿Öض¨Ïòµ½¹¥»÷Õß¿ØÖƵÄÖ÷»ú¡£»î¶¯ÖÐʹÓõĺϷ¨ÓòÃûΪÃåµéÊý×ÖÐÂÎŵÄmdn[.]gov[.]mm¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2021/11/attackers-use-domain-fronting-technique.html
ESET·¢ÏÖÒÔÉ«ÁÐCandiruÕë¶ÔÓ¢¹úºÍÖж«µÄË®¿Ó¹¥»÷
11ÔÂ16ÈÕ£¬ESETµÄÑо¿ÈËÔ±³ÆÒÔÉ«ÁеļäµýÈí¼þCandiruÓëÕë¶ÔÓ¢¹úºÍÖж«µÄË®¿Ó¹¥»÷Óйء£CandiruÒÑÓÚ±¾Ô±»ÃÀ¹úÉÌÎñ²¿ÁÐÈë¶ñÒâÍøÂç»î¶¯×éÖ¯Ãûµ¥¡£´Ë´Î»î¶¯´óÖ·ÖΪÁ½²¨£¬µÚÒ»²¨¿ªÊ¼ÓÚ2020Äê3Ô£¬ÓÚ2020Äê8Ô½áÊø£¬µÚ¶þ²¨¹¥»÷¿ªÊ¼ÓÚ2021Äê1Ô¿ªÊ¼£¬Ò»Ö±Á¬Ðøµ½2021Äê8ÔÂÉÏÑ®£¬¹¥»÷ÁËÓ¢¹ú¡¢Ò²ÃÅ¡¢ÒÁÀÊ¡¢ÐðÀûÑÇ¡¢É³Ìذ¢À²®¡¢Òâ´óÀûºÍÄϷǵȵØÓòµÄ×éÖ¯¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/11/israels-candiru-spyware-found-linked-to.html
еĵöÓã»î¶¯Ã°³äTikTokÔ±¹¤ÒÔɾ³ýÕ˺ÅÀ´ÍþвÓû§
Abnormal SecurityÔÚ11ÔÂ17ÈÕ·¢ÏÖÕë¶ÔTikTokÓû§µÄÐÂÒ»ÂÖµöÓã»î¶¯¡£¹¥»÷Õßð³äTikTokÔ±¹¤£¬¾¯¸æÄ¿±êÒòÆäÉæÏÓÎ¥·´Æ½Ì¨Ìõ¿î¶ø½«Á¢¼´É¾³ýÕÊ»§¡£Ö®ºó£¬Óû§»á±»Öض¨Ïòµ½Ò»¸öWhatsAppÁÄÌìÊÒ£¬²¢±»ÒªÇóÌá¹©ÖØÖÃÕÊ»§ÃÜÂëËùÐèµÄÓʼþµØÖ·¡¢µç»°ºÅÂëºÍÒ»´ÎÐÔ´úÂ롣ĿǰÉв»Çå³þ¹¥»÷ÕßµÄÄ¿µÄÊÇʲô£¬»òÐíÖ¼ÔÚ½Ó¹ÜÕË»§»òÀÕË÷¡£´Ë´Î»î¶¯µÄÁ½¸ö·åÖµ·Ö±ðÔÚ10ÔÂ2ÈÕºÍ11ÔÂ1ÈÕ£¬Òò´ËÑо¿ÈËÔ±ÍÆ²âÏÂÒ»Âֻ¿ÉÄÜ»áÔÚ¼¸Öܺó¿ªÊ¼¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/tiktok-phishing-threatens-to-delete-influencers-accounts/
ÐÂÀÕË÷ÔËÓªÍÅ»ïMementoÀûÓÃvCenterÖеÄRCE©¶´
SophosÓÚ11ÔÂ18ÈÕÅû¶ÁËÀÕË÷ÔËÓªÍÅ»ïMementoµÄл¡£¹¥»÷ÕßÀûÓÃÁËVMware vCenter Server WebÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-21971£©£¬CVSSÆÀ·ÖΪ9.8¡£¹¥»÷Õß¿ÉÀûÓøÃ©¶´·ÃÎÊTCP/IP¶Ë¿Ú443£¬²¢ÒÔ¹ÜÀíԱȨÏÞÖ´ÐÐÃüÁÆä²¹¶¡ÒÑÓÚ2Ô·ÝÐû²¼¡£´Ë´Î»î¶¯¿ªÊ¼ÓÚÉϸöÔ£¬¹¥»÷ÕßÊ×ÏÈÀûÓÃvCenterÖеÄ©¶´´ÓÄ¿±ê·þÎñÆ÷ÇÔÈ¡¹ÜÀíÆ¾¾Ý£¬È»ºóʹÓÃRDP over SSHºáÏòÒÆ¶¯£¬²¢Ê×´ÎÔÚ¹¥»÷ÖÐʹÓÃÁËWinRARÀ´Ñ¹ËõÎļþ²¢¶ÔÆä½øÐмÓÃÜ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-memento-ransomware-switches-to-winrar-after-failing-at-encryption/
CISAÐû²¼2021ÄêÍøÂçÄþ¾²Ê¼þºÍ©¶´µÄÓ¦¼±ÏìÓ¦Ö¸ÄÏ
11ÔÂ16ÈÕ£¬ÃÀ¹úCISAÐû²¼ÁË2021ÄêÍøÂçÄþ¾²Ê¼þºÍ©¶´µÄÓ¦¼±ÏìÓ¦Ö¸ÄÏ¡£¸ÃÖ¸ÄÏΪÁª°îÎÄÖ°ÐÐÕþ²¿ÃÅ£¨FCEB£©»ú¹¹ÌṩÁËÓÃÓڹ滮ºÍ¿ªÕ¹ÍøÂçÄþ¾²Ê¼þºÍ©¶´ÏìÓ¦»î¶¯µÄ²Ù×÷·¨Ê½£¬²¢Í¨¹ý¾ö²ßÊ÷Ïêϸ˵Ã÷ÁËʼþºÍ©¶´ÏìÓ¦µÄÿ¸ö²½Öè¡£CISAÃãÀøÒªº¦»ù´¡ÉèÊ©Ïà¹Ø×éÖ¯£¬ÖÝ¡¢µØ·½µÄÕþ¸®×éÖ¯ÒÔ¼°Ë½Óª×éÖ¯ÀûÓøÃÖ¸ÄϽøÐÐÉó²é£¬ÒÔ¶ÔÆä×ÔÉíµÄ©¶´ºÍʼþÏìӦʵ¼ù½øÐлù×¼²âÊÔ¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2021/11/16/new-federal-government-cybersecurity-incident-and-vulnerability
KasperskyÐû²¼2022ÄêAPT¹¥»÷ÍþÐ²Ì¬ÊÆµÄÔ¤²â³ÂËß
KasperskyÓÚ11ÔÂ17ÈÕÐû²¼ÁË2022ÄêAPT¹¥»÷ÍþÐ²Ì¬ÊÆµÄÔ¤²â³ÂËß¡£³ÂËßÖ¸³ö£¬APT×éÖ¯½«´ÓÆäËû¹¥»÷ÕßÄÇÀﹺÖóõÊ¼ÍøÂç·ÃÎÊȨÏÞ£»¸ü¶à¹ú¼Ò½«Ö´·¨ÆðËß×÷ΪÆäÍøÂçÕ½ÂÔµÄÒ»²¿ÃÅ£»¶ÔÍøÂçÉ豸µÄÕë¶ÔÐÔ¹¥»÷Ôö¼Ó£»5G©¶´¼´½«·ºÆð£»¹¥»÷Õß½«¼ÌÐøÀûÓÃCOVID-19Ö÷Ìâ£»ÒÆ¶¯É豸½«Êܵ½¹ã·º¹¥»÷£»¹©Ó¦Á´¹¥»÷µÄÊýÁ¿½«Ôö¼Ó£»¼ÌÐøÀûÓÃWFH£»METAµØÓò£¬ÓÈÆäÊÇ·ÇÖÞµÄAPT»î¶¯½«Ôö¼Ó¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/advanced-threat-predictions-for-2022/104870/