ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ44ÖÜ
Ðû²¼Ê±¼ä 2021-11-01>±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
±¾Öܹ²ÊÕ¼Çå¾²Îó²î62¸ö£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApache Storm getTopologyHistoryЧÀÍSHELLÏÂÁî×¢ÈëÎó²î£»£»£»£»£»Microsoft Azure GridPro´úÂëÖ´ÐÐÎó²î£»£»£»£»£»Apple macOS bigsurÄں˴úÂëÖ´ÐÐÎó²î£»£»£»£»£»BillQuick Web SuiteSQL×¢ÈëÎó²î£»£»£»£»£»Penguin Aurora TV Box 41502δÊÚȨ»á¼ûÎó²î¡£¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇWizardUpdateбäÖÖͨ¹ýð³äÕýµ±Èí¼þÈÆ¹ý¼ì²â£»£»£»£»£»MicrosoftÐû²¼NOBELIUMÍŻ﹥»÷»î¶¯µÄÆÊÎö±¨¸æ£»£»£»£»£»EmsisoftÐû²¼Õë¶ÔÀÕË÷Èí¼þBlackMatterµÄ½âÃÜÆ÷£»£»£»£»£»Ñо¿ÍŶÓÅû¶APT×éÖ¯LazarusÌᳫµÄ¹©Ó¦Á´¹¥»÷µÄϸ½Ú£»£»£»£»£»ÒÁÀÊʯÓ͹«Ë¾NIOPDCÔâµ½¹¥»÷£¬£¬£¬£¬ÌìϼÓÓÍÕ¾ÔËÓªÖÐÖ¹¡£¡£¡£¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£¡£
>Ö÷ÒªÇå¾²Îó²îÁбí
1. Apache Storm getTopologyHistoryЧÀÍSHELLÏÂÁî×¢ÈëÎó²î
Apache Storm getTopologyHistoryЧÀͱ£´æSHELLÏÂÁî×¢ÈëÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿É×¢Èëí§Òâ´úÂë²¢ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐС£¡£¡£¡£¡£¡£¡£
https://lists.apache.org/thread.html/r5fe881f6ca883908b7a0f005d35115af49f43beea7a8b0915e377859%40%3Cuser.storm.apache.org%3E
2. Microsoft Azure GridPro´úÂëÖ´ÐÐÎó²î
Microsoft Azure GridProÇëÇóÖÎÀí±£´æÄ¿Â¼±éÀúÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://seclists.org/fulldisclosure/2021/Oct/33
3. Apple macOS bigsurÄں˴úÂëÖ´ÐÐÎó²î
Apple macOS bigsurÄں˱£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÍâµØ¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔÄÚºËÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://support.apple.com/zh-cn/HT212872
4. BillQuick Web SuiteSQL×¢ÈëÎó²î
Bqe Software BillQuick Web Suite±£´æSQL×¢ÈëÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄSQLÇëÇ󣬣¬£¬£¬²Ù×÷Êý¾Ý¿â£¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://www.huntress.com/blog/threat-advisory-hackers-are-exploiting-a-vulnerability-in-popular-billing-software-to-deploy-ransomware
5. Penguin Aurora TV Box 41502δÊÚȨ»á¼ûÎó²î
Penguin Aurora TV Box¶ÔÌØ¶¨Á´½Ó´¦Öóͷ£±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬Î´ÊÚȨ¿ØÖÆÏµÍ³¡£¡£¡£¡£¡£¡£¡£
https://www.cnvd.org.cn/flaw/show/2934166
>Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢WizardUpdateбäÖÖͨ¹ýð³äÕýµ±Èí¼þÈÆ¹ý¼ì²â
Ñо¿Ö°Ô±ÔÚ10ÔÂ22ÈÕÅû¶Á˶ñÒâÈí¼þWizardUpdate£¨ÓÖÃûUpdateAgent£©µÄбäÖÖ¡£¡£¡£¡£¡£¡£¡£WizardUpdate×î³õÓÚ2020Äê11Ô±»·¢Ã÷£¬£¬£¬£¬Ö÷ÒªÕë¶ÔmacOS¡£¡£¡£¡£¡£¡£¡£¸Ã±äÌ忪·¢ÁËÐµĹ¦Ð§£¬£¬£¬£¬ÀýÈçÀÄÓù«¹²ÔÆÀ´·Ö·¢¶ñÒâ¹ã¸æÈí¼þAdload£¬£¬£¬£¬²¢ÇÒ»¹ÄÜÈÆ¹ýAppleµÄÇå¾²¹¦Ð§Gatekeeper¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ËüʹÓÃÁË͵¶ÉʽÏÂÔØ£¨Drive-by downloads£©µÄ·½·¨¾ÙÐзַ¢£¬£¬£¬£¬Í¨¹ýð³äÕýµ±Èí¼þÀ´Èƹý¼ì²â£¬£¬£¬£¬Ñо¿Ö°Ô±ÉÐδ͸¶ÆäÄ£ÄâÁËÄÄЩÈí¼þ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/updateagent-malware-variant-macos-software/
2¡¢MicrosoftÐû²¼NOBELIUMÍŻ﹥»÷»î¶¯µÄÆÊÎö±¨¸æ
MicrosoftÍþвÇ鱨ÖÐÐÄÔÚ10ÔÂ25ÈÕÐû²¼Á˹ØÓÚNOBELIUMÍŻ﹥»÷»î¶¯µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£NOBELIUMÊÇ2020Äê12ÔÂÕë¶ÔSolarWindsµÄ¹©Ó¦Á´¹¥»÷µÄÄ»ºóºÚÊÖ£¬£¬£¬£¬×Ô2021Äê5ÔÂÒÔÀ´£¬£¬£¬£¬¸ÃÍÅ»ïÔÚÃÀ¹úºÍÅ·ÖÞÌᳫÁËÓÐÕë¶ÔÐԵũӦÁ´¹¥»÷¡£¡£¡£¡£¡£¡£¡£´Ë´Î»î¶¯²¢Î´Ê¹ÓÃÈκÎÎó²î£¬£¬£¬£¬¶øÊÇʹÓÃÃÜÂëÅçÉä¡¢ÁîÅÆÍµÇÔ¡¢APIÀÄÓúÍÓã²æÊ½ÍøÂç´¹ÂڵȶàÖÖÊÖÒÕÀ´ÇÔÌØÈ¨ÕÊ»§µÄƾ֤£¬£¬£¬£¬´Ó¶øÔÚÔÆÇéÐÎÖкáÏòÒÆ¶¯¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.microsoft.com/security/blog/2021/10/25/nobelium-targeting-delegated-administrative-privileges-to-facilitate-broader-attacks/
3¡¢EmsisoftÐû²¼Õë¶ÔÀÕË÷Èí¼þBlackMatterµÄ½âÃÜÆ÷
Çå¾²¹«Ë¾EmsisoftÔÚ10ÔÂ24ÈÕ¹ûÕæÁËÀÕË÷Èí¼þBlackMatterµÄ½âÃÜÆ÷¡£¡£¡£¡£¡£¡£¡£½ñÄêÔçЩʱ¼ä£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷BlackMatterÖб£´æÒ»¸ö¿ÉÓÃÓÚ»Ö¸´¼ÓÃÜÎļþÎó²î£¬£¬£¬£¬²¢ÇÒËûÃÇÔÚ֮ǰһֱûÓÐ͸¶¸ÃÎó²îµÄ±£´æ£¬£¬£¬£¬ÒÔ±ÜÃâ¸ÃÍÅ»ïÐÞ¸´Îó²î¡£¡£¡£¡£¡£¡£¡£²»ÐÒµÄÊÇ£¬£¬£¬£¬BlackMatterÔÚ9ÔÂβ·¢Ã÷²¢ÐÞ¸´Á˸ÃÎó²î£¬£¬£¬£¬Òò´ËÕâ¸ö½âÃÜÆ÷½öÄܽâÃÜ2021Äê7ÔÂÖÐÑ®ÖÁ9ÔÂÏÂѮ֮¼ä±»¼ÓÃܵÄÎļþ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/123736/security/blackmatter-decryptor-pat-victims.html
4¡¢Ñо¿ÍŶÓÅû¶APT×éÖ¯LazarusÌᳫµÄ¹©Ó¦Á´¹¥»÷µÄϸ½Ú
KasperskyÑо¿ÍŶÓÓÚ±¾ÖܶþÅû¶ÁËLazarusÔÚ½üÆÚÌᳫµÄ¹©Ó¦Á´¹¥»÷¡£¡£¡£¡£¡£¡£¡£APT×éÖ¯Lazarus×Ô2009ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬£¬Ê¹ÓÃMATA¹¥»÷¸÷¸öÐÐÒµµÄ×éÖ¯¡£¡£¡£¡£¡£¡£¡£Ôڴ˴λÖУ¬£¬£¬£¬¸ÃÍÅ»ïÓÚ5Ô¹¥»÷ÁËÀÍÑάÑǵÄIT¹©Ó¦ÉÌ£¬£¬£¬£¬ÓÖÔÚ6Ô·ÝʹÓúóÃÅBLINDINGCANµÄбäÌå¹¥»÷Á˺«¹úÖǿ⡣¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬×î½üµÄ»î¶¯Õ¹ÏÖÁËÁ½¸öÇ÷ÊÆ£ºLazarusÈÔÈ»¶Ô¹ú·ÀÐÐÒµ¸ÐÐËȤ£¬£¬£¬£¬²¢ÇÒ»¹Ï£Íûͨ¹ý¹©Ó¦Á´¹¥»÷À´À©Õ¹Æä¹¥»÷¹æÄ£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://usa.kaspersky.com/about/press-releases/2021_apt-actor-lazarus-attacks-defense-industry-develops-supply-chain-attack-capabilities
5¡¢ÒÁÀÊʯÓ͹«Ë¾NIOPDCÔâµ½¹¥»÷£¬£¬£¬£¬ÌìϼÓÓÍÕ¾ÔËÓªÖÐÖ¹
ÒÁÀʹúÓÐʯÓͲúÆ··ÖÏú¹«Ë¾(NIOPDC)ÔÚ10ÔÂ26ÈÕÔâµ½¹¥»÷¡£¡£¡£¡£¡£¡£¡£NIOPDCÔÚÒÁÀÊÌìϹæÄ£ÄÚÓµÓÐÁè¼Ý3500¸ö¼ÓÓÍÕ¾£¬£¬£¬£¬ÓÉÓÚÎÞ·¨Ö§¸¶Óöȣ¬£¬£¬£¬ÊÜÓ°ÏìµÄ¼ÓÓÍÕ¾ÔÚÔâµ½¹¥»÷ºóÁ¬Ã¦ÖÐÖ¹ÁËÔËÓª¡£¡£¡£¡£¡£¡£¡£Ðí¶à¼ÓÓÍÕ¾µÄ¹ã¸æÅÆÉ϶¼ÏÔʾ×Å¡°Khamenei£¡¼øºÚµ£±£ÍøÈ¼ÁÏÄØ£¿£¿£¿¡±ºÍ¡°Ãâ·ÑÆûÓÍ¡±µÄ×ÖÑù£¬£¬£¬£¬±ðµÄ£¬£¬£¬£¬¼ÓÓÍÕ¾µÄÆÁÄ»ÉÏÏÔʾ×Å¡°cyebrattack 64411¡±µÄ×ÖÑù£¬£¬£¬£¬ÆäÖÐ64411ÊǸùú×î¸ßÊ×ÄÔAyatollah Ali Khamenei°ì¹«Êҵĵ绰¡£¡£¡£¡£¡£¡£¡£Éв»È·¶¨¹¥»÷ÕßµÄÉí·Ý£¬£¬£¬£¬µ«ÒÁÀÊÕþ¸®ÍƶÏÕâÊÇÓɳðÊÓ¹ú¼ÒÌᳫµÄÍøÂç¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬¼ÓÓÍÕ¾µÄÔËÓªÒѻָ´¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/123824/hacking/iranian-gas-stations-incident.html