KasperskyÐû²¼¶ñÒâÈí¼þÆÊÎö±¨¸æ£ºFarFariaÓ¦ÓõÄÊý¾Ý¿âй¶290ÍòÓû§ÐÅÏ¢
Ðû²¼Ê±¼ä 2021-09-30΢Èí·¢Ã÷Ö¼ÔÚÇÔÈ¡AD FSÖÎÀíԱƾ֤µÄºóÃÅFoggyWeb
΢ÈíÍþвÇ鱨ÖÐÐÄ(MSTIC)ÓÚ9ÔÂ27ÈÕÅû¶ÁËÖ¼ÔÚÇÔÈ¡Active DirectoryÁªºÏÉí·ÝÑé֤ЧÀÍ(AD FS)ÖÎÀíԱƾ֤µÄºóÃÅFoggyWeb¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÓë¶íÂÞ˹Íâ¹úÇ鱨¾Ö(SVR)µÄºÚ¿ÍÍÅ»ïNobeliumÓйأ¬£¬£¬£¬£¬£¬ÀÄÓÃÁËSAMLÁîÅÆ¡£¡£¡£¡£¡£Ëü¿ÉÒÔΪ¹¥»÷Õß½ç˵µÄURIÉèÖÃHTTP¼àÌýÆ÷£¨ÕâЩURIÄ£ÄâÁËÄ¿µÄAD FSʹÓõÄÕýµ±URIµÄ½á¹¹£©£¬£¬£¬£¬£¬£¬À´¼àÌý·¢Ë͵½AD FSµÄHTTP GETºÍPOSTÇëÇ󣬣¬£¬£¬£¬£¬²¢×èµ²Óë×Ô½ç˵URIģʽƥÅäµÄHTTPÇëÇ󡣡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.microsoft.com/security/blog/2021/09/27/foggyweb-targeted-nobelium-malware-leads-to-persistent-backdoor/
Ñо¿Ö°Ô±·¢Ã÷Õë¶Ô²¨À¼µÄÐÂAndroidÒøÐÐľÂíERMAC
ºÉÀ¼Çå¾²¹«Ë¾ThreatFabric·¢Ã÷ÁËÒ»ÖÖÃûΪERMACµÄÐÂAndroidÒøÐÐľÂí¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ»ùÓÚCerberus£¨ÆäÔ´´úÂëÒÑÓÚ2020Äê9ÔÂÔÚºÚ¿ÍÂÛ̳¹ûÕæ£©£¬£¬£¬£¬£¬£¬ÓëBlackRock±³ºóµÄÔËÓªÉÌÓйء£¡£¡£¡£¡£ÓëCerberusÏà±È£¬£¬£¬£¬£¬£¬ERMACʹÓÃÁËBlowfish¼ÓÃÜËã·¨£¬£¬£¬£¬£¬£¬²¢ÇÒÔÚÓëC2µÄͨѶÖÐʹÓÃÁËAES-128-CBC¼ÓÃܼƻ®¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬£¬£¬ERMAC×Ô8ÔÂÏÂÑ®×îÏÈ»îÔ¾£¬£¬£¬£¬£¬£¬×îÏÈαװ³ÉGoogle Chrome£¬£¬£¬£¬£¬£¬Ö®ºó»¹Î±×°³Éαװ³É·À²¡¶¾¡¢ÒøÐкÍýÌå²¥·ÅÆ÷µÈÓ¦Ó㬣¬£¬£¬£¬£¬¿ÉÕë¶Ô378¸ö½ðÈÚÏà¹ØµÄÓ¦ÓóÌÐò¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.threatfabric.com/blogs/ermac-another-cerberus-reborn.html
QNAPÐû²¼¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´QVRÖÐ3¸öÑÏÖØµÄÏÂÁî×¢ÈëÎó²î
NASÖÆÔìÉÌQNAPÔÚ9ÔÂ27ÈÕÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËÊÓÆµÖÎÀíϵͳQVRÖÐ3¸öÑÏÖØµÄÏÂÁî×¢ÈëÎó²î¡£¡£¡£¡£¡£ÆäÖеÄÁ½¸öÎó²îCVSSÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉʹÓÃÆäÔÚÄ¿µÄϵͳÉÏÖ´ÐÐÏÂÁ£¬£¬£¬£¬£¬´Ó¶øÍêÈ«¿ØÖÆ×°±¸¡£¡£¡£¡£¡£ÁíÍâÒ»¸öÎó²î×·×ÙΪCVE-2021-34349£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ7.2£¬£¬£¬£¬£¬£¬ÓëÇ°ÃæÁ½¸öÎó²îµÄ²î±ðÊÇʹÓÃËùÐèµÄȨÏÞ²î±ð¡£¡£¡£¡£¡£QNAPÖ¸³ö£¬£¬£¬£¬£¬£¬ÆäÖÐÁ½¸öÎó²î»¹Ó°ÏìÁ˲¿·ÖEOL×°±¸¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬Éв»ÇåÎúÕâЩÎó²îÊÇ·ñÒѱ»ÔÚҰʹÓÃÁË¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/qnap-fixes-critical-bugs-in-qvr-video-surveillance-solution/
FarFariaÓ¦ÓõÄÊý¾Ý¿âÉèÖùýʧй¶290Íò¸öÓû§µÄÐÅÏ¢
Comparitech·¢Ã÷¶ùͯ¹ÊÊÂÊéÓ¦ÓÃFarFariaµÄMongoDBÊý¾Ý¿âÉèÖùýʧ£¬£¬£¬£¬£¬£¬Ð¹Â¶290Íò¸öÓû§µÄÐÅÏ¢¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚ2021Äê8ÔÂ9ÈÕ·¢Ã÷¸ÃÎÊÌ⣬£¬£¬£¬£¬£¬Ö±µ½9ÔÂ27ÈÕ²ÅÅû¶³öÀ´¡£¡£¡£¡£¡£´Ë´Î×ܼÆÐ¹Â¶ÁË38GBµÄÊý¾Ý£¬£¬£¬£¬£¬£¬°üÀ¨µç×ÓÓʼþ¡¢Éí·ÝÑéÖ¤ÁîÅÆ¡¢ÃÜÂë¡¢µÇ¼ÐÅÏ¢ºÍÆäËüµÄÉ罻ýÌåÐÅÏ¢µÈ¡£¡£¡£¡£¡£Éв»ÇåÎúÕâЩÊý¾ÝÊÇ·ñÒѱ»Ê¹Ó㬣¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âÔÚÏÖÔÚÒѱ»±£»£»¤ÆðÀ´¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/storybooks-for-children-app-farfaria-exposed-data/
CISAºÍNSAÁªºÏÐû²¼ÓйØÑ¡ÔñºÍ¼Ó¹ÌVPNµÄÇå¾²Ö¸ÄÏ
ÃÀ¹úCISAºÍNSAÔÚ9ÔÂ28ÈÕÁªºÏÐû²¼ÁËÓйØÑ¡ÔñºÍ¼Ó¹ÌVPNµÄÇå¾²Ö¸ÄÏ¡£¡£¡£¡£¡£Ö¸ÄÏÖ¸³ö£¬£¬£¬£¬£¬£¬×éÖ¯Ó¦¸Ã´ÓÐÅÓþÓÅÒìµÄ¹©Ó¦ÉÌÄÇÀïÑ¡Ôñ²úÆ·£¬£¬£¬£¬£¬£¬ÓÉÓÚËûÃÇ»áÒÔ×î¿ìµÄËÙÂÊÐÞ¸´ÒÑÖªÎó²î¡£¡£¡£¡£¡£Çå¾²»ú¹¹³Æ£¬£¬£¬£¬£¬£¬VPN×°±¸¿ÉÒÔÍøÂçÆ¾Ö¤¡¢ÓÃÀ´Ô¶³ÌÖ´ÐдúÂë¡¢Ï÷Èõ¼ÓÃÜÁ÷Á¿»á»°µÄ¼ÓÃÜ¡¢Ð®ÖƻỰÒÔ¼°¶ÁÈ¡Ãô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬½¨Òé×éÖ¯ÉèÖÃÇ¿¼ÓÃܺÍÉí·ÝÑéÖ¤¡¢½öÔËÐÐÐëÒªµÄ¹¦Ð§ÒÔ¼°±£»£»¤ºÍ¼à¿Ø¶ÔVPNµÄ»á¼û¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2021/09/28/cisa-and-nsa-release-guidance-selecting-and-hardening-vpns
KasperskyÐû²¼¶ñÒâÈí¼þBloodyStealerµÄÆÊÎö±¨¸æ
KasperskyÔÚ9ÔÂ27ÈÕÐû²¼ÁËÓйضñÒâÈí¼þBloodyStealerµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±3Ô·ÝÔÚ°µÍøÉÏ·¢Ã÷ÁËÓйضñÒâÈí¼þBloodyStealerµÄ¹ã¸æ£¬£¬£¬£¬£¬£¬¼ÛÇ®ÊÇ700¬²¼Ò»¸öÔ£¨Ô¼10ÃÀÔª£©»ò3000¬²¼Ò»´ÎÐÔ¹ºÖᣡ£¡£¡£¡£Ëü¿ÉÒÔÇÔÈ¡¶à¸öÓÎϷƽ̨µÄÕÊ»§£¬£¬£¬£¬£¬£¬°üÀ¨Steam¡¢Epic Games Store ºÍEA Origin£¬£¬£¬£¬£¬£¬»¹¾ßÓÐÈÆ¹ýÇå¾²¼ì²âºÍ¶ñÒâÈí¼þÆÊÎöµÄ¹¦Ð§¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬×Ô¾õÏÖÒÔÀ´£¬£¬£¬£¬£¬£¬¸ÃľÂíÖ÷ÒªÓÃÀ´Õë¶ÔÅ·ÖÞ¡¢À¶¡ÃÀÖÞºÍÑÇÌ«µØÇøµÄÓû§¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/bloodystealer-and-gaming-assets-for-sale/104319/