ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ44ÖÜ

Ðû²¼Ê±¼ä 2021-11-01

>±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


±¾Öܹ²ÊÕ¼Çå¾²Îó²î62¸ö £¬£¬£¬£¬£¬ £¬£¬ÖµµÃ¹Ø×¢µÄÊÇApache Storm getTopologyHistoryЧÀÍSHELLÏÂÁî×¢ÈëÎó²î £»£»£»£»Microsoft Azure GridPro´úÂëÖ´ÐÐÎó²î £»£»£»£»Apple macOS bigsurÄں˴úÂëÖ´ÐÐÎó²î £»£»£»£»BillQuick Web SuiteSQL×¢ÈëÎó²î £»£»£»£»Penguin Aurora TV Box 41502δÊÚȨ»á¼ûÎó²î¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇWizardUpdateбäÖÖͨ¹ýð³äÕýµ±Èí¼þÈÆ¹ý¼ì²â £»£»£»£»MicrosoftÐû²¼NOBELIUMÍŻ﹥»÷»î¶¯µÄÆÊÎö±¨¸æ £»£»£»£»EmsisoftÐû²¼Õë¶ÔÀÕË÷Èí¼þBlackMatterµÄ½âÃÜÆ÷ £»£»£»£»Ñо¿ÍŶÓÅû¶APT×éÖ¯LazarusÌᳫµÄ¹©Ó¦Á´¹¥»÷µÄϸ½Ú £»£»£»£»ÒÁÀÊʯÓ͹«Ë¾NIOPDCÔâµ½¹¥»÷ £¬£¬£¬£¬£¬ £¬£¬ÌìϼÓÓÍÕ¾ÔËÓªÖÐÖ¹¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö £¬£¬£¬£¬£¬ £¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£


>Ö÷ÒªÇå¾²Îó²îÁбí


1. Apache Storm getTopologyHistoryЧÀÍSHELLÏÂÁî×¢ÈëÎó²î


Apache Storm getTopologyHistoryЧÀͱ£´æSHELLÏÂÁî×¢ÈëÎó²î £¬£¬£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬£¬£¬ £¬£¬¿É×¢Èëí§Òâ´úÂë²¢ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐС£¡£¡£¡£


https://lists.apache.org/thread.html/r5fe881f6ca883908b7a0f005d35115af49f43beea7a8b0915e377859%40%3Cuser.storm.apache.org%3E


2. Microsoft Azure GridPro´úÂëÖ´ÐÐÎó²î


Microsoft Azure GridProÇëÇóÖÎÀí±£´æÄ¿Â¼±éÀúÎó²î £¬£¬£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬£¬£¬ £¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£


https://seclists.org/fulldisclosure/2021/Oct/33


3. Apple macOS bigsurÄں˴úÂëÖ´ÐÐÎó²î


Apple macOS bigsurÄں˱£´æÇå¾²Îó²î £¬£¬£¬£¬£¬ £¬£¬ÔÊÐíÍâµØ¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬£¬£¬ £¬£¬¿ÉÒÔÄÚºËÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£


https://support.apple.com/zh-cn/HT212872


4. BillQuick Web SuiteSQL×¢ÈëÎó²î


Bqe Software BillQuick Web Suite±£´æSQL×¢ÈëÎó²î £¬£¬£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄSQLÇëÇó £¬£¬£¬£¬£¬ £¬£¬²Ù×÷Êý¾Ý¿â £¬£¬£¬£¬£¬ £¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£


https://www.huntress.com/blog/threat-advisory-hackers-are-exploiting-a-vulnerability-in-popular-billing-software-to-deploy-ransomware


5. Penguin Aurora TV Box 41502δÊÚȨ»á¼ûÎó²î


Penguin Aurora TV Box¶ÔÌØ¶¨Á´½Ó´¦Öóͷ£±£´æÇå¾²Îó²î £¬£¬£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬£¬£¬ £¬£¬Î´ÊÚȨ¿ØÖÆÏµÍ³¡£¡£¡£¡£


https://www.cnvd.org.cn/flaw/show/2934166



 >Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢WizardUpdateбäÖÖͨ¹ýð³äÕýµ±Èí¼þÈÆ¹ý¼ì²â


Ñо¿Ö°Ô±ÔÚ10ÔÂ22ÈÕÅû¶Á˶ñÒâÈí¼þWizardUpdate£¨ÓÖÃûUpdateAgent£©µÄбäÖÖ¡£¡£¡£¡£WizardUpdate×î³õÓÚ2020Äê11Ô±»·¢Ã÷ £¬£¬£¬£¬£¬ £¬£¬Ö÷ÒªÕë¶ÔmacOS¡£¡£¡£¡£¸Ã±äÌ忪·¢ÁËÐµĹ¦Ð§ £¬£¬£¬£¬£¬ £¬£¬ÀýÈçÀÄÓù«¹²ÔÆÀ´·Ö·¢¶ñÒâ¹ã¸æÈí¼þAdload £¬£¬£¬£¬£¬ £¬£¬²¢ÇÒ»¹ÄÜÈÆ¹ýAppleµÄÇå¾²¹¦Ð§Gatekeeper¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬£¬ £¬£¬ËüʹÓÃÁË͵¶ÉʽÏÂÔØ£¨Drive-by downloads£©µÄ·½·¨¾ÙÐзַ¢ £¬£¬£¬£¬£¬ £¬£¬Í¨¹ýð³äÕýµ±Èí¼þÀ´Èƹý¼ì²â £¬£¬£¬£¬£¬ £¬£¬Ñо¿Ö°Ô±ÉÐδ͸¶ÆäÄ£ÄâÁËÄÄЩÈí¼þ¡£¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/updateagent-malware-variant-macos-software/


2¡¢MicrosoftÐû²¼NOBELIUMÍŻ﹥»÷»î¶¯µÄÆÊÎö±¨¸æ


MicrosoftÍþвÇ鱨ÖÐÐÄÔÚ10ÔÂ25ÈÕÐû²¼Á˹ØÓÚNOBELIUMÍŻ﹥»÷»î¶¯µÄÆÊÎö±¨¸æ¡£¡£¡£¡£NOBELIUMÊÇ2020Äê12ÔÂÕë¶ÔSolarWindsµÄ¹©Ó¦Á´¹¥»÷µÄÄ»ºóºÚÊÖ £¬£¬£¬£¬£¬ £¬£¬×Ô2021Äê5ÔÂÒÔÀ´ £¬£¬£¬£¬£¬ £¬£¬¸ÃÍÅ»ïÔÚÃÀ¹úºÍÅ·ÖÞÌᳫÁËÓÐÕë¶ÔÐԵũӦÁ´¹¥»÷¡£¡£¡£¡£´Ë´Î»î¶¯²¢Î´Ê¹ÓÃÈκÎÎó²î £¬£¬£¬£¬£¬ £¬£¬¶øÊÇʹÓÃÃÜÂëÅçÉä¡¢ÁîÅÆÍµÇÔ¡¢APIÀÄÓúÍÓã²æÊ½ÍøÂç´¹ÂڵȶàÖÖÊÖÒÕÀ´ÇÔÌØÈ¨ÕÊ»§µÄƾ֤ £¬£¬£¬£¬£¬ £¬£¬´Ó¶øÔÚÔÆÇéÐÎÖкáÏòÒÆ¶¯¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.microsoft.com/security/blog/2021/10/25/nobelium-targeting-delegated-administrative-privileges-to-facilitate-broader-attacks/


3¡¢EmsisoftÐû²¼Õë¶ÔÀÕË÷Èí¼þBlackMatterµÄ½âÃÜÆ÷


Çå¾²¹«Ë¾EmsisoftÔÚ10ÔÂ24ÈÕ¹ûÕæÁËÀÕË÷Èí¼þBlackMatterµÄ½âÃÜÆ÷¡£¡£¡£¡£½ñÄêÔçЩʱ¼ä £¬£¬£¬£¬£¬ £¬£¬Ñо¿Ö°Ô±·¢Ã÷BlackMatterÖб£´æÒ»¸ö¿ÉÓÃÓÚ»Ö¸´¼ÓÃÜÎļþÎó²î £¬£¬£¬£¬£¬ £¬£¬²¢ÇÒËûÃÇÔÚ֮ǰһֱûÓÐ͸¶¸ÃÎó²îµÄ±£´æ £¬£¬£¬£¬£¬ £¬£¬ÒÔ±ÜÃâ¸ÃÍÅ»ïÐÞ¸´Îó²î¡£¡£¡£¡£²»ÐÒµÄÊÇ £¬£¬£¬£¬£¬ £¬£¬BlackMatterÔÚ9ÔÂβ·¢Ã÷²¢ÐÞ¸´Á˸ÃÎó²î £¬£¬£¬£¬£¬ £¬£¬Òò´ËÕâ¸ö½âÃÜÆ÷½öÄܽâÃÜ2021Äê7ÔÂÖÐÑ®ÖÁ9ÔÂÏÂѮ֮¼ä±»¼ÓÃܵÄÎļþ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/123736/security/blackmatter-decryptor-pat-victims.html


4¡¢Ñо¿ÍŶÓÅû¶APT×éÖ¯LazarusÌᳫµÄ¹©Ó¦Á´¹¥»÷µÄϸ½Ú


KasperskyÑо¿ÍŶÓÓÚ±¾ÖܶþÅû¶ÁËLazarusÔÚ½üÆÚÌᳫµÄ¹©Ó¦Á´¹¥»÷¡£¡£¡£¡£APT×éÖ¯Lazarus×Ô2009ÄêÒÔÀ´Ò»Ö±»îÔ¾ £¬£¬£¬£¬£¬ £¬£¬Ê¹ÓÃMATA¹¥»÷¸÷¸öÐÐÒµµÄ×éÖ¯¡£¡£¡£¡£Ôڴ˴λÖÐ £¬£¬£¬£¬£¬ £¬£¬¸ÃÍÅ»ïÓÚ5Ô¹¥»÷ÁËÀ­ÍÑάÑǵÄIT¹©Ó¦ÉÌ £¬£¬£¬£¬£¬ £¬£¬ÓÖÔÚ6Ô·ÝʹÓúóÃÅBLINDINGCANµÄбäÌå¹¥»÷Á˺«¹úÖǿ⡣¡£¡£¡£Ñо¿Ö°Ô±³Æ £¬£¬£¬£¬£¬ £¬£¬×î½üµÄ»î¶¯Õ¹ÏÖÁËÁ½¸öÇ÷ÊÆ£ºLazarusÈÔÈ»¶Ô¹ú·ÀÐÐÒµ¸ÐÐËȤ £¬£¬£¬£¬£¬ £¬£¬²¢ÇÒ»¹Ï£Íûͨ¹ý¹©Ó¦Á´¹¥»÷À´À©Õ¹Æä¹¥»÷¹æÄ£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://usa.kaspersky.com/about/press-releases/2021_apt-actor-lazarus-attacks-defense-industry-develops-supply-chain-attack-capabilities


5¡¢ÒÁÀÊʯÓ͹«Ë¾NIOPDCÔâµ½¹¥»÷ £¬£¬£¬£¬£¬ £¬£¬ÌìϼÓÓÍÕ¾ÔËÓªÖÐÖ¹


ÒÁÀʹúÓÐʯÓͲúÆ··ÖÏú¹«Ë¾(NIOPDC)ÔÚ10ÔÂ26ÈÕÔâµ½¹¥»÷¡£¡£¡£¡£NIOPDCÔÚÒÁÀÊÌìϹæÄ£ÄÚÓµÓÐÁè¼Ý3500¸ö¼ÓÓÍÕ¾ £¬£¬£¬£¬£¬ £¬£¬ÓÉÓÚÎÞ·¨Ö§¸¶ÓÃ¶È £¬£¬£¬£¬£¬ £¬£¬ÊÜÓ°ÏìµÄ¼ÓÓÍÕ¾ÔÚÔâµ½¹¥»÷ºóÁ¬Ã¦ÖÐÖ¹ÁËÔËÓª¡£¡£¡£¡£Ðí¶à¼ÓÓÍÕ¾µÄ¹ã¸æÅÆÉ϶¼ÏÔʾ×Å¡°Khamenei£¡918²©ÌìÌÃȼÁÏÄØ£¿£¿£¿£¿¡±ºÍ¡°Ãâ·ÑÆûÓÍ¡±µÄ×ÖÑù £¬£¬£¬£¬£¬ £¬£¬±ðµÄ £¬£¬£¬£¬£¬ £¬£¬¼ÓÓÍÕ¾µÄÆÁÄ»ÉÏÏÔʾ×Å¡°cyebrattack 64411¡±µÄ×ÖÑù £¬£¬£¬£¬£¬ £¬£¬ÆäÖÐ64411ÊǸùú×î¸ßÊ×ÄÔAyatollah Ali Khamenei°ì¹«Êҵĵ绰¡£¡£¡£¡£Éв»È·¶¨¹¥»÷ÕßµÄÉí·Ý £¬£¬£¬£¬£¬ £¬£¬µ«ÒÁÀÊÕþ¸®ÍƶÏÕâÊÇÓɳðÊÓ¹ú¼ÒÌᳫµÄÍøÂç¹¥»÷»î¶¯¡£¡£¡£¡£ÏÖÔÚ £¬£¬£¬£¬£¬ £¬£¬¼ÓÓÍÕ¾µÄÔËÓªÒѻָ´¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/123824/hacking/iranian-gas-stations-incident.html