KasperskyÐû²¼¶ñÒâÈí¼þÆÊÎö±¨¸æ£ºFarFariaÓ¦ÓõÄÊý¾Ý¿âй¶290ÍòÓû§ÐÅÏ¢

Ðû²¼Ê±¼ä 2021-09-30

΢Èí·¢Ã÷Ö¼ÔÚÇÔÈ¡AD FSÖÎÀíԱƾ֤µÄºóÃÅFoggyWeb


΢Èí·¢Ã÷Ö¼ÔÚÇÔÈ¡AD FSÖÎÀíԱƾ֤µÄºóÃÅFoggyWeb.jpg


΢ÈíÍþвÇ鱨ÖÐÐÄ(MSTIC)ÓÚ9ÔÂ27ÈÕÅû¶ÁËÖ¼ÔÚÇÔÈ¡Active DirectoryÁªºÏÉí·ÝÑé֤ЧÀÍ(AD FS)ÖÎÀíԱƾ֤µÄºóÃÅFoggyWeb ¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÓë¶íÂÞ˹Íâ¹úÇ鱨¾Ö(SVR)µÄºÚ¿ÍÍÅ»ïNobeliumÓйØ£¬£¬£¬£¬ÀÄÓÃÁËSAMLÁîÅÆ ¡£¡£¡£¡£¡£Ëü¿ÉÒÔΪ¹¥»÷Õß½ç˵µÄURIÉèÖÃHTTP¼àÌýÆ÷£¨ÕâЩURIÄ£ÄâÁËÄ¿µÄAD FSʹÓõÄÕýµ±URIµÄ½á¹¹£©£¬£¬£¬£¬À´¼àÌý·¢Ë͵½AD FSµÄHTTP GETºÍPOSTÇëÇ󣬣¬£¬£¬²¢×èµ²Óë×Ô½ç˵URIģʽƥÅäµÄHTTPÇëÇó ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.microsoft.com/security/blog/2021/09/27/foggyweb-targeted-nobelium-malware-leads-to-persistent-backdoor/



Ñо¿Ö°Ô±·¢Ã÷Õë¶Ô²¨À¼µÄÐÂAndroidÒøÐÐľÂíERMAC


Ñо¿Ö°Ô±·¢Ã÷Õë¶Ô²¨À¼µÄÐÂAndroidÒøÐÐľÂíERMAC.png


ºÉÀ¼Çå¾²¹«Ë¾ThreatFabric·¢Ã÷ÁËÒ»ÖÖÃûΪERMACµÄÐÂAndroidÒøÐÐľÂí ¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ»ùÓÚCerberus£¨ÆäÔ´´úÂëÒÑÓÚ2020Äê9ÔÂÔÚºÚ¿ÍÂÛ̳¹ûÕæ£©£¬£¬£¬£¬ÓëBlackRock±³ºóµÄÔËÓªÉÌÓÐ¹Ø ¡£¡£¡£¡£¡£ÓëCerberusÏà±È£¬£¬£¬£¬ERMACʹÓÃÁËBlowfish¼ÓÃÜËã·¨£¬£¬£¬£¬²¢ÇÒÔÚÓëC2µÄͨѶÖÐʹÓÃÁËAES-128-CBC¼ÓÃܼƻ® ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬ERMAC×Ô8ÔÂÏÂÑ®×îÏÈ»îÔ¾£¬£¬£¬£¬×îÏÈαװ³ÉGoogle Chrome£¬£¬£¬£¬Ö®ºó»¹Î±×°³Éαװ³É·À²¡¶¾¡¢ÒøÐкÍýÌå²¥·ÅÆ÷µÈÓ¦Ó㬣¬£¬£¬¿ÉÕë¶Ô378¸ö½ðÈÚÏà¹ØµÄÓ¦ÓóÌÐò ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.threatfabric.com/blogs/ermac-another-cerberus-reborn.html



QNAPÐû²¼¸üУ¬£¬£¬£¬ÐÞ¸´QVRÖÐ3¸öÑÏÖØµÄÏÂÁî×¢ÈëÎó²î


QNAPÐû²¼¸üУ¬£¬£¬£¬ÐÞ¸´QVRÖÐ3¸öÑÏÖØµÄÏÂÁî×¢ÈëÎó²î.png


NASÖÆÔìÉÌQNAPÔÚ9ÔÂ27ÈÕÐû²¼Çå¾²¸üУ¬£¬£¬£¬ÐÞ¸´ÁËÊÓÆµÖÎÀíϵͳQVRÖÐ3¸öÑÏÖØµÄÏÂÁî×¢ÈëÎó²î ¡£¡£¡£¡£¡£ÆäÖеÄÁ½¸öÎó²îCVSSÆÀ·ÖΪ9.8£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉʹÓÃÆäÔÚÄ¿µÄϵͳÉÏÖ´ÐÐÏÂÁ£¬£¬£¬´Ó¶øÍêÈ«¿ØÖÆ×°±¸ ¡£¡£¡£¡£¡£ÁíÍâÒ»¸öÎó²î×·×ÙΪCVE-2021-34349£¬£¬£¬£¬CVSSÆÀ·ÖΪ7.2£¬£¬£¬£¬ÓëÇ°ÃæÁ½¸öÎó²îµÄ²î±ðÊÇʹÓÃËùÐèµÄȨÏÞ²î±ð ¡£¡£¡£¡£¡£QNAPÖ¸³ö£¬£¬£¬£¬ÆäÖÐÁ½¸öÎó²î»¹Ó°ÏìÁ˲¿·ÖEOL×°±¸ ¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬Éв»ÇåÎúÕâЩÎó²îÊÇ·ñÒѱ»ÔÚҰʹÓÃÁË ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/qnap-fixes-critical-bugs-in-qvr-video-surveillance-solution/



FarFariaÓ¦ÓõÄÊý¾Ý¿âÉèÖùýʧй¶290Íò¸öÓû§µÄÐÅÏ¢


FarFariaÓ¦ÓõÄÊý¾Ý¿âÉèÖùýʧй¶290Íò¸öÓû§µÄÐÅÏ¢.png


Comparitech·¢Ã÷¶ùͯ¹ÊÊÂÊéÓ¦ÓÃFarFariaµÄMongoDBÊý¾Ý¿âÉèÖùýʧ£¬£¬£¬£¬Ð¹Â¶290Íò¸öÓû§µÄÐÅÏ¢ ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚ2021Äê8ÔÂ9ÈÕ·¢Ã÷¸ÃÎÊÌ⣬£¬£¬£¬Ö±µ½9ÔÂ27ÈÕ²ÅÅû¶³öÀ´ ¡£¡£¡£¡£¡£´Ë´Î×ܼÆÐ¹Â¶ÁË38GBµÄÊý¾Ý£¬£¬£¬£¬°üÀ¨µç×ÓÓʼþ¡¢Éí·ÝÑéÖ¤ÁîÅÆ¡¢ÃÜÂë¡¢µÇ¼ÐÅÏ¢ºÍÆäËüµÄÉ罻ýÌåÐÅÏ¢µÈ ¡£¡£¡£¡£¡£Éв»ÇåÎúÕâЩÊý¾ÝÊÇ·ñÒѱ»Ê¹Ó㬣¬£¬£¬¸ÃÊý¾Ý¿âÔÚÏÖÔÚÒѱ»±£»£»¤ÆðÀ´ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/storybooks-for-children-app-farfaria-exposed-data/



CISAºÍNSAÁªºÏÐû²¼ÓйØÑ¡ÔñºÍ¼Ó¹ÌVPNµÄÇå¾²Ö¸ÄÏ


CISAºÍNSAÁªºÏÐû²¼ÓйØÑ¡ÔñºÍ¼Ó¹ÌVPNµÄÇå¾²Ö¸ÄÏ.png


ÃÀ¹úCISAºÍNSAÔÚ9ÔÂ28ÈÕÁªºÏÐû²¼ÁËÓйØÑ¡ÔñºÍ¼Ó¹ÌVPNµÄÇå¾²Ö¸ÄÏ ¡£¡£¡£¡£¡£Ö¸ÄÏÖ¸³ö£¬£¬£¬£¬×éÖ¯Ó¦¸Ã´ÓÐÅÓþÓÅÒìµÄ¹©Ó¦ÉÌÄÇÀïÑ¡Ôñ²úÆ·£¬£¬£¬£¬ÓÉÓÚËûÃÇ»áÒÔ×î¿ìµÄËÙÂÊÐÞ¸´ÒÑÖªÎó²î ¡£¡£¡£¡£¡£Çå¾²»ú¹¹³Æ£¬£¬£¬£¬VPN×°±¸¿ÉÒÔÍøÂçÆ¾Ö¤¡¢ÓÃÀ´Ô¶³ÌÖ´ÐдúÂë¡¢Ï÷Èõ¼ÓÃÜÁ÷Á¿»á»°µÄ¼ÓÃÜ¡¢Ð®ÖƻỰÒÔ¼°¶ÁÈ¡Ãô¸ÐÐÅÏ¢£¬£¬£¬£¬½¨Òé×éÖ¯ÉèÖÃÇ¿¼ÓÃܺÍÉí·ÝÑéÖ¤¡¢½öÔËÐÐÐëÒªµÄ¹¦Ð§ÒÔ¼°±£»£»¤ºÍ¼à¿Ø¶ÔVPNµÄ»á¼û ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/09/28/cisa-and-nsa-release-guidance-selecting-and-hardening-vpns



KasperskyÐû²¼¶ñÒâÈí¼þBloodyStealerµÄÆÊÎö±¨¸æ


KasperskyÐû²¼¶ñÒâÈí¼þBloodyStealerµÄÆÊÎö±¨¸æ.png


KasperskyÔÚ9ÔÂ27ÈÕÐû²¼ÁËÓйضñÒâÈí¼þBloodyStealerµÄÆÊÎö±¨¸æ ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±3Ô·ÝÔÚ°µÍøÉÏ·¢Ã÷ÁËÓйضñÒâÈí¼þBloodyStealerµÄ¹ã¸æ£¬£¬£¬£¬¼ÛÇ®ÊÇ700¬²¼Ò»¸öÔ£¨Ô¼10ÃÀÔª£©»ò3000¬²¼Ò»´ÎÐÔ¹ºÖà ¡£¡£¡£¡£¡£Ëü¿ÉÒÔÇÔÈ¡¶à¸öÓÎϷƽ̨µÄÕÊ»§£¬£¬£¬£¬°üÀ¨Steam¡¢Epic Games Store ºÍEA Origin£¬£¬£¬£¬»¹¾ßÓÐÈÆ¹ýÇå¾²¼ì²âºÍ¶ñÒâÈí¼þÆÊÎöµÄ¹¦Ð§ ¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬×Ô¾õÏÖÒÔÀ´£¬£¬£¬£¬¸ÃľÂíÖ÷ÒªÓÃÀ´Õë¶ÔÅ·ÖÞ¡¢À­¶¡ÃÀÖÞºÍÑÇÌ«µØÇøµÄÓû§ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/bloodystealer-and-gaming-assets-for-sale/104319/