ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ44ÖÜ
Ðû²¼Ê±¼ä 2021-11-01>±¾ÖÜÇ徲̬ÊÆ×ÛÊö
±¾Öܹ²ÊÕ¼Çå¾²Îó²î62¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇApache Storm getTopologyHistory·þÎñSHELLÏÂÁî×¢ÈëÎó²î£»Microsoft Azure GridPro´úÂëÖ´ÐÐÎó²î£»Apple macOS bigsurÄں˴úÂëÖ´ÐÐÎó²î£»BillQuick Web SuiteSQL×¢ÈëÎó²î£»Penguin Aurora TV Box 41502δÊÚȨ»á¼ûÎó²î¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇWizardUpdateбäÖÖͨ¹ýð³äÕýµ±Èí¼þÈƹý¼ì²â£»MicrosoftÐû²¼NOBELIUMÍŻ﹥»÷Ô˶¯µÄÆÊÎö±¨¸æ£»EmsisoftÐû²¼Õë¶ÔÀÕË÷Èí¼þBlackMatterµÄ½âÃÜÆ÷£»Ñо¿ÍŶÓÅû¶APT×éÖ¯LazarusÌᳫµÄ¹©Ó¦Á´¹¥»÷µÄϸ½Ú£»ÒÁÀÊʯÓ͹«Ë¾NIOPDCÔâµ½¹¥»÷£¬ÌìϼÓÓÍÕ¾ÔËÓªÖÐÖ¹¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£
>Ö÷ÒªÇå¾²Îó²îÁбí
1. Apache Storm getTopologyHistory·þÎñSHELLÏÂÁî×¢ÈëÎó²î
Apache Storm getTopologyHistory·þÎñ±£´æSHELLÏÂÁî×¢ÈëÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿É×¢Èëí§Òâ´úÂë²¢ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐС£
https://lists.apache.org/thread.html/r5fe881f6ca883908b7a0f005d35115af49f43beea7a8b0915e377859%40%3Cuser.storm.apache.org%3E
2. Microsoft Azure GridPro´úÂëÖ´ÐÐÎó²î
Microsoft Azure GridProÇëÇóÖÎÀí±£´æĿ¼±éÀúÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://seclists.org/fulldisclosure/2021/Oct/33
3. Apple macOS bigsurÄں˴úÂëÖ´ÐÐÎó²î
Apple macOS bigsurÄں˱£´æÇå¾²Îó²î£¬ÔÊÐíÍâµØ¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÄÚºËÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://support.apple.com/zh-cn/HT212872
4. BillQuick Web SuiteSQL×¢ÈëÎó²î
Bqe Software BillQuick Web Suite±£´æSQL×¢ÈëÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄSQLÇëÇ󣬲Ù×÷Êý¾Ý¿â£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐí§Òâ´úÂë¡£
https://www.huntress.com/blog/threat-advisory-hackers-are-exploiting-a-vulnerability-in-popular-billing-software-to-deploy-ransomware
5. Penguin Aurora TV Box 41502δÊÚȨ»á¼ûÎó²î
Penguin Aurora TV Box¶ÔÌض¨Á´½Ó´¦Öóͷ£±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬Î´ÊÚȨ¿ØÖÆϵͳ¡£
https://www.cnvd.org.cn/flaw/show/2934166
>Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢WizardUpdateбäÖÖͨ¹ýð³äÕýµ±Èí¼þÈƹý¼ì²â
Ñо¿Ö°Ô±ÔÚ10ÔÂ22ÈÕÅû¶Á˶ñÒâÈí¼þWizardUpdate£¨ÓÖÃûUpdateAgent£©µÄбäÖÖ¡£WizardUpdate×î³õÓÚ2020Äê11Ô±»·¢Ã÷£¬Ö÷ÒªÕë¶ÔmacOS¡£¸Ã±äÌ忪·¢ÁËÐµĹ¦Ð§£¬ÀýÈçÀÄÓù«¹²ÔÆÀ´·Ö·¢¶ñÒâ¹ã¸æÈí¼þAdload£¬²¢ÇÒ»¹ÄÜÈƹýAppleµÄÇå¾²¹¦Ð§Gatekeeper¡£±ðµÄ£¬ËüʹÓÃÁË͵¶ÉʽÏÂÔØ£¨Drive-by downloads£©µÄ·½·¨¾ÙÐзַ¢£¬Í¨¹ýð³äÕýµ±Èí¼þÀ´Èƹý¼ì²â£¬Ñо¿Ö°Ô±ÉÐδ͸¶ÆäÄ£ÄâÁËÄÄЩÈí¼þ¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/updateagent-malware-variant-macos-software/
2¡¢MicrosoftÐû²¼NOBELIUMÍŻ﹥»÷Ô˶¯µÄÆÊÎö±¨¸æ
MicrosoftÍþвÇ鱨ÖÐÐÄÔÚ10ÔÂ25ÈÕÐû²¼Á˹ØÓÚNOBELIUMÍŻ﹥»÷Ô˶¯µÄÆÊÎö±¨¸æ¡£NOBELIUMÊÇ2020Äê12ÔÂÕë¶ÔSolarWindsµÄ¹©Ó¦Á´¹¥»÷µÄÄ»ºóºÚÊÖ£¬×Ô2021Äê5ÔÂÒÔÀ´£¬¸ÃÍÅ»ïÔÚÃÀ¹úºÍÅ·ÖÞÌᳫÁËÓÐÕë¶ÔÐԵĹ©Ó¦Á´¹¥»÷¡£´Ë´ÎÔ˶¯²¢Î´Ê¹ÓÃÈκÎÎó²î£¬¶øÊÇʹÓÃÃÜÂëÅçÉä¡¢ÁîÅÆ͵ÇÔ¡¢APIÀÄÓúÍÓã²æʽÍøÂç´¹ÂڵȶàÖÖÊÖÒÕÀ´ÇÔÌØȨÕÊ»§µÄƾ֤£¬´Ó¶øÔÚÔÆÇéÐÎÖкáÏòÒƶ¯¡£
ÔÎÄÁ´½Ó£º
https://www.microsoft.com/security/blog/2021/10/25/nobelium-targeting-delegated-administrative-privileges-to-facilitate-broader-attacks/
3¡¢EmsisoftÐû²¼Õë¶ÔÀÕË÷Èí¼þBlackMatterµÄ½âÃÜÆ÷
Çå¾²¹«Ë¾EmsisoftÔÚ10ÔÂ24ÈÕ¹ûÕæÁËÀÕË÷Èí¼þBlackMatterµÄ½âÃÜÆ÷¡£½ñÄêÔçЩʱ¼ä£¬Ñо¿Ö°Ô±·¢Ã÷BlackMatterÖб£´æÒ»¸ö¿ÉÓÃÓÚ»Ö¸´¼ÓÃÜÎļþÎó²î£¬²¢ÇÒËûÃÇÔÚ֮ǰһֱûÓÐ͸¶¸ÃÎó²îµÄ±£´æ£¬ÒÔ±ÜÃâ¸ÃÍÅ»ïÐÞ¸´Îó²î¡£²»ÐÒµÄÊÇ£¬BlackMatterÔÚ9ÔÂβ·¢Ã÷²¢ÐÞ¸´Á˸ÃÎó²î£¬Òò´ËÕâ¸ö½âÃÜÆ÷½öÄܽâÃÜ2021Äê7ÔÂÖÐÑ®ÖÁ9ÔÂÏÂѮ֮¼ä±»¼ÓÃܵÄÎļþ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/123736/security/blackmatter-decryptor-pat-victims.html
4¡¢Ñо¿ÍŶÓÅû¶APT×éÖ¯LazarusÌᳫµÄ¹©Ó¦Á´¹¥»÷µÄϸ½Ú
KasperskyÑо¿ÍŶÓÓÚ±¾ÖܶþÅû¶ÁËLazarusÔÚ½üÆÚÌᳫµÄ¹©Ó¦Á´¹¥»÷¡£APT×éÖ¯Lazarus×Ô2009ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬Ê¹ÓÃMATA¹¥»÷¸÷¸öÐÐÒµµÄ×éÖ¯¡£ÔÚ´Ë´ÎÔ˶¯ÖУ¬¸ÃÍÅ»ïÓÚ5Ô¹¥»÷ÁËÀÍÑάÑǵÄIT¹©Ó¦ÉÌ£¬ÓÖÔÚ6Ô·ÝʹÓúóÃÅBLINDINGCANµÄбäÌå¹¥»÷Á˺«¹úÖÇ¿â¡£Ñо¿Ö°Ô±³Æ£¬×î½üµÄÔ˶¯Õ¹ÏÖÁËÁ½¸öÇ÷ÊÆ£ºLazarusÈÔÈ»¶Ô¹ú·ÀÐÐÒµ¸ÐÐËȤ£¬²¢ÇÒ»¹Ï£Íûͨ¹ý¹©Ó¦Á´¹¥»÷À´À©Õ¹Æä¹¥»÷¹æÄ£¡£
ÔÎÄÁ´½Ó£º
https://usa.kaspersky.com/about/press-releases/2021_apt-actor-lazarus-attacks-defense-industry-develops-supply-chain-attack-capabilities
5¡¢ÒÁÀÊʯÓ͹«Ë¾NIOPDCÔâµ½¹¥»÷£¬ÌìϼÓÓÍÕ¾ÔËÓªÖÐÖ¹
ÒÁÀʹúÓÐʯÓͲúÆ··ÖÏú¹«Ë¾(NIOPDC)ÔÚ10ÔÂ26ÈÕÔâµ½¹¥»÷¡£NIOPDCÔÚÒÁÀÊÌìϹæÄ£ÄÚÓµÓÐÁè¼Ý3500¸ö¼ÓÓÍÕ¾£¬ÓÉÓÚÎÞ·¨Ö§¸¶Óöȣ¬ÊÜÓ°ÏìµÄ¼ÓÓÍÕ¾ÔÚÔâµ½¹¥»÷ºóÁ¬Ã¦ÖÐÖ¹ÁËÔËÓª¡£Ðí¶à¼ÓÓÍÕ¾µÄ¹ã¸æÅÆÉ϶¼ÏÔʾ×Å¡°Khamenei£¡ÎÒÃǵÄȼÁÏÄØ£¿¡±ºÍ¡°Ãâ·ÑÆûÓÍ¡±µÄ×ÖÑù£¬±ðµÄ£¬¼ÓÓÍÕ¾µÄÆÁÄ»ÉÏÏÔʾ×Å¡°cyebrattack 64411¡±µÄ×ÖÑù£¬ÆäÖÐ64411ÊǸùú×î¸ßÊ×ÄÔAyatollah Ali Khamenei°ì¹«Êҵĵ绰¡£Éв»È·¶¨¹¥»÷ÕßµÄÉí·Ý£¬µ«ÒÁÀÊÕþ¸®ÍƶÏÕâÊÇÓɳðÊÓ¹ú¼ÒÌᳫµÄÍøÂç¹¥»÷Ô˶¯¡£ÏÖÔÚ£¬¼ÓÓÍÕ¾µÄÔËÓªÒѻָ´¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/123824/hacking/iranian-gas-stations-incident.html