¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180928

Ðû²¼Ê±¼ä 2018-09-28

¡¾¶ñÒâÈí¼þ¡¿TalosÑо¿ÍŶӷ¢Ã÷¶ñÒâÈí¼þVPNFilterÐÂÔö7¸ö¹¦Ð§Ä£¿£¿£¿£¿£¿£¿£¿é


˼¿ÆTalosÑо¿ÍŶÓÅû¶¶ñÒâÈí¼þVPNFilterµÄ7¸öÐÂÄ£¿£¿£¿£¿£¿£¿£¿éµÄÊÖÒÕϸ½ÚÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÕâЩģ¿£¿£¿£¿£¿£¿£¿éΪVPNFilterÔöÌíÁ˶à¸öÖ÷Òª¹¦Ð§£¬£¬£¬£¬°üÀ¨Ó³ÉäÍøÂçÍØÆË²¢Ñ¬È¾ÆäËü×°±¸¡¢»ìÏýºÍ¼ÓÃܶñÒâÁ÷Á¿¡¢Êý¾ÝÉøÂ©¡¢ÓëC&CͨѶ¡¢É¨ÃèÍøÂçÖеÄDZÔÚÄ¿µÄÒÔ¼°¹¹½¨ÂþÑÜʽÊðÀíÍøÂçµÈ¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±»¹·¢Ã÷ÎÚ¿ËÀ¼µÄMikroTik×°±¸³ÉΪÆäÖ÷ÒªµÄ¹¥»÷Ä¿µÄ¡£¡£¡£¡£¡£¡£¡£


https://blog.talosintelligence.com/2018/09/vpnfilter-part-3.html


¡¾¶ñÒâÈí¼þ¡¿ESETÑо¿ÍŶӷ¢Ã÷Ê׸öÔÚÒ°ÍâʹÓõÄUEFI Rootkit LoJax


ESETÑо¿ÍŶӷ¢Ã÷Ê׸öÔÚÒ°ÍâʹÓõÄUEFI rootkit£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ±»ÃüÃûΪLoJax¡£¡£¡£¡£¡£¡£¡£LoJax±»·¸·¨ÍÅ»ïAPT28ÓÃÓÚÕë¶Ô°Í¶û¸ÉµØÇøÒÔ¼°ÖÐÅ·ºÍ¶«Å·µÄÕþ¸®»ú¹¹¡£¡£¡£¡£¡£¡£¡£LoJax±»ÊµÏÖΪUEFI/BIOSÄ£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬Ê¹µÃÆä¿ÉÒÔÔÚÖØÐÂ×°ÖòÙ×÷ϵͳÒÔ¼°Ìæ»»Ó²Å̺óÒÀ¾É±£´æ¡£¡£¡£¡£¡£¡£¡£É¾³ý¸Ã¶ñÒâÈí¼þµÄΨһҪÁìÊÇÖØË¢UEFI¹Ì¼þ¡£¡£¡£¡£¡£¡£¡£Í¨¹ýÆôÓÃÇå¾²ÆôÄîÍ·ÖÆÒ²¿ÉÒÔ±ÜÃâLoJaxѬȾ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/apt28-uses-lojax-first-uefi-rootkit-seen-in-the-wild/


¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±·¢Ã÷IoT½©Ê¬ÍøÂç×½ÃÔ²Ø×îÏÈÕë¶ÔAndroid×°±¸


ƾ֤BitDefenderµÄб¨¸æ£¬£¬£¬£¬ÎïÁªÍø½©Ê¬ÍøÂç×½ÃԲأ¨HNS£©µÄ×îÐÂÑù±¾×îÏÈÕë¶ÔÆôÓÃÁËÎÞÏßµ÷ÊÔ¹¦Ð§£¨ADB£©µÄAndroid×°±¸¡£¡£¡£¡£¡£¡£¡£ÕâÒ»¸Ä±äʹµÃ×½ÃÔ²ØÑ¬È¾µÄ×°±¸×ÜÊýÐÂÔöÁË4Íò£¬£¬£¬£¬ÆäÖд󲿷ÖλÓÚÖйų́ÍåºÍº«¹úµÈµØÇø¡£¡£¡£¡£¡£¡£¡£BitDefenderÌåÏÖ¿ÉÒԿ϶¨µÄÊÇ£¬£¬£¬£¬²»µ«ÊÇÔËÐÐAndroidϵͳµÄÖÇÄÜÊÖ»úÊܵ½Ó°Ï죬£¬£¬£¬ÆäËüÖÇÄܵçÊÓ¡¢DVRÒÔ¼°ÏÕЩÈÎºÎÆôÓÃÁËADB¹¦Ð§µÄ×°±¸¶¼»áÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£ÏÖÔڸý©Ê¬ÍøÂçµÄÕæÕýÄ¿µÄÈÔȻδ֪¡£¡£¡£¡£¡£¡£¡£


https://labs.bitdefender.com/2018/09/hide-and-seek-iot-botnet-learns-new-tricks-uses-adb-over-internet-to-exploit-thousands-of-android-devices/


¡¾ÍþвÇ鱨¡¿AvastÑо¿ÍŶӷ¢Ã÷еÄÎïÁªÍø½©Ê¬ÍøÂçTorii


AvastÑо¿ÍŶÓÐû²¼¹ØÓÚÐÂÎïÁªÍø½©Ê¬ÍøÂçToriiµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£Torii×Ô2017Äê12ÔÂÆðÒ»Ö±»îÔ¾£¬£¬£¬£¬Ëü¿ÉÒÔѬȾ¶àÖÖCPU¼Ü¹¹µÄ×°±¸£¬£¬£¬£¬ÈçMIPS¡¢ARM¡¢x86¡¢x64¡¢PowerPCºÍSuperHµÈ¡£¡£¡£¡£¡£¡£¡£ToriiÊÇ×ÔVPNFilterºÍ×½ÃÔ²ØÒÔÀ´µÄµÚÈý¸öʵÏÖÁ˳¤ÆÚÐÔµÄÎïÁªÍø½©Ê¬ÍøÂ磬£¬£¬£¬ÕâÒâζ×ÅËü¿ÉÒÔÔÚ×°±¸ÖØÆôºó¼ÌÐøÔËÐС£¡£¡£¡£¡£¡£¡£½«×°±¸¹Ì¼þµÄÉèÖÃÖØÖÃΪĬÈϳö³§ÉèÖÿÉÄÜ¿ÉÒÔɾ³ýËü¡£¡£¡£¡£¡£¡£¡£


https://blog.avast.com/new-torii-botnet-threat-research


¡¾Îó²î²¹¶¡¡¿Ë¼¿ÆÐû²¼Cisco IOSºÍIOS XEµÄ°ëÄê¶ÈÇ徲ת´ï£¬£¬£¬£¬¹²ÐÞ¸´13¸öÎó²î


9ÔÂ26ÈÕ˼¿ÆÐû²¼Cisco IOSºÍIOS XEÈí¼þµÄ°ëÄê¶ÈÇ徲ת´ï£¬£¬£¬£¬¹²ÐÞ¸´13¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£Ë¼¿ÆÔÚÿÄêµÄ3ÔºÍ9ÔµĵÚËĸöÐÇÆÚÈý¶¼»áÐû²¼ÆäCisco IOSºÍIOS XEÈí¼þµÄ°ëÄê¶ÈÇ徲ת´ï¡£¡£¡£¡£¡£¡£¡£±¾´Îת´ïÖÐÐÞ¸´µÄ13¸öÎó²îµÄÇå¾²ÆÀ¼¶£¨SIR£©¶¼Îª¸ß£¬£¬£¬£¬ÀÖ³ÉʹÓÃÕâЩÎó²î½«»áµ¼ÖÂÌáȨ»ò¾Ü¾øÐ§ÀÍ¡£¡£¡£¡£¡£¡£¡£ÏêϸÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£¡£


https://tools.cisco.com/security/center/viewErp.x?alertId=ERP-69981


¡¾Çå¾²²¥±¨¡¿Å̹ÅÍŶÓÀÖ³ÉÔÚÔËÐÐiOS 12µÄiPhone XSÉÏÔ½Óü


ƾ֤Çå¾²Ñо¿Ö°Ô±Min(Spark) ZhengµÄÍÆÎÄ£¬£¬£¬£¬Å̹ÅÍŶÓÀÖ³ÉÔÚÔËÐÐiOS 12µÄiPhone XSÉÏÔ½Óü¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Í¸Â¶Ô½ÓüµÄÊÂÇéÔ­ÀíÊÇÈÆ¹ýA12·ÂÉúоƬÖÐʵÑéµÄPAC·À»¤¹¦Ð§¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ÓÉÓÚiPhone XSµÄÓ²¼þÓëiPhone XS MaxºÜÊÇÏàËÆ£¬£¬£¬£¬Òò´Ë¸ÃÔ½ÓüÒªÁìÒ²ÊÊÓÃÓÚiPhone XS Max¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎú¸ÃÍŶÓÊÇ·ñ»áÏò¹«ÖÚÐû²¼ÆäÔ½ÓüÒªÁì¡£¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2018/09/ios12-iphone-jailbreak-exploit.html



¡¾¼øºÚµ£±£Íø¼¯ÍÅADLabÕûÀíÐû²¼¡¿