µÂ¹úÊÖ»ú³§ÉÌGigasetÔâµ½¹©¸øÁ´¹¥»÷ £¬£¬£¬£¬£¬£¬ £¬¸üзþÎñÆ÷±»½Ù³Ö£» £»£»£»£»£»£»£»°²È«ÍŶÓÅû¶Õë¶ÔFortinet VPNµÄÐÂÀÕË÷Èí¼þCring

°ä²¼¹¦·ò 2021-04-09

1.µÂ¹úÊÖ»ú³§ÉÌGigasetÔâµ½¹©¸øÁ´¹¥»÷ £¬£¬£¬£¬£¬£¬ £¬¸üзþÎñÆ÷±»½Ù³Ö


1.jpg


µÂ¹úÊÖ»úÔì×÷ÉÌGigasetÔâµ½¹©¸øÁ´¹¥»÷ £¬£¬£¬£¬£¬£¬ £¬ÖÁÉÙÒ»¸ö¸üзþÎñÆ÷±»½Ù³ÖÓÃÀ´·Ö·¢¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£Gigaset AGµÄǰÉíΪÎ÷ÃÅ×Ó¼ÒÍ¥ºÍ°ì¹«ÊÒͨѶÉ豸¹«Ë¾ £¬£¬£¬£¬£¬£¬ £¬Ôì×÷DECTµç»° £¬£¬£¬£¬£¬£¬ £¬ÔÚ2018ÄêµÄÊÕÈëΪ2.8ÒÚÅ·Ôª¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷Õë¶ÔµÄÊÇGigasetÆìÏÂAndroidϵͳÖÇÄÜÊÖ»ú £¬£¬£¬£¬£¬£¬ £¬²úÉúÔÚ3ÔÂ27ÈÕ×óÓÒ £¬£¬£¬£¬£¬£¬ £¬Óû§·¢ÏÖÃûΪeasenfµÄδ֪ÀûÓÃÔÚ±»É¾³ýºó±ã»á×Ô¶¯³ÁÐÂ×°Öᣡ£¡£¡£¡£¡£¾ÝϤ £¬£¬£¬£¬£¬£¬ £¬easynfÊÇͨ¹ýÉ豸µÄϵͳ¸üÐÂÀûÓÃ×°ÖÃµÄ £¬£¬£¬£¬£¬£¬ £¬´Ë±í»¹·¢ÏÖÁËÆäËû¶ñÒâÀûÓà £¬£¬£¬£¬£¬£¬ £¬Ô̺¬gem¡¢smartºÍxiaoanµÈ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.com/2021/04/07/gigaset_supply_chain_malware_android_phones/


2.LazarusÍÅ»ïÀûÓÃжñÒâÈí¼þVyveva¹¥»÷ÄϷǵĻõÔ˹«Ë¾


2.jpg


³¯ÏʺڿÍ×éÖ¯LazarusʹÓÃÁËÐÂÐͶñÒâÈí¼þVyveva £¬£¬£¬£¬£¬£¬ £¬¶ÔÄÏ·ÇÒ»¼Ò»õÔËÎïÁ÷¹«Ë¾ÌáÒ鶨Ïò¹¥»÷¡£¡£¡£¡£¡£¡£ESET·¢ÏÖ £¬£¬£¬£¬£¬£¬ £¬Lazarus×î³õÊÇÔÚ2020Äê6ÔµĹ¥»÷ÖÐʹÓÃVyveva £¬£¬£¬£¬£¬£¬ £¬µ«ÔÚ2018Äê12ÔÂ֮ǰµÄ¹¥»÷ÖоÍÒ»ÏòÔÚ²¿ÊðËü¡£¡£¡£¡£¡£¡£VyvevaÓµÓкóÃÅÖ°ÄÜ £¬£¬£¬£¬£¬£¬ £¬¿ÉÖ´ÐÐËÁÒâ¶ñÒâ´úÂë²¢Ö§³Ö¹¦·ò´ÁºÅÁî¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖVyveva½öϰȾÁËÁ½Ì¨ÊôÓÚͳһ¼Ò»õÔ˹«Ë¾µÄ·þÎñÆ÷ £¬£¬£¬£¬£¬£¬ £¬²¢ÇÒÊdzõ´ÎÔÚÒ°±í±»ÀûÓà £¬£¬£¬£¬£¬£¬ £¬Òò¶ø´§Ä¦Æä¿ÉÄܻᱻÓÃÓÚÆäËûÓÐÕë¶ÔÐԵļäµý»î¶¯¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/north-korean-hackers-use-new-vyveva-malware-to-attack-freighters/


3.°²È«ÍŶÓÅû¶Õë¶ÔFortinet VPNµÄÐÂÀÕË÷Èí¼þCring


3.jpg


ÈðÊ¿µçÐŵÄCSIRTÍŶÓÅû¶ÁËÕë¶ÔFortinet VPNµÄÐÂÀÕË÷Èí¼þCring£¨Ò²³ÆÎªCrypt3r¡¢Vjiszy1lo¡¢GhostºÍPhantom£©¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÀûÓÃÁËFortiOSµÄSSL VPNÃÅ»§ÍøÕ¾µÄõè¾¶±éÀú·ì϶£¨CVE-2018-13379£© £¬£¬£¬£¬£¬£¬ £¬Õë¶ÔÅ·ÖÞÁйúµÄ¹¤Òµ¹«Ë¾¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÔÚ»ñµÃ³õʼ½Ó¼ûȨÏÞºó»áÏÂÔØ¶¨ÔìµÄMimikatzºÍCobaltStrike £¬£¬£¬£¬£¬£¬ £¬²¢Í¨¹ýʹÓúϷ¨µÄWindows CertUtilÖ¤ÊéÖÎÀíÆ÷ÈÆ¹ý°²È«Èí¼þ £¬£¬£¬£¬£¬£¬ £¬À´ÏÂÔØ²¢×°ÖÃÀÕË÷Èí¼þ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116480/cyber-crime/cring-ransomware-fortinet-vpn-flaw.html


4.VISA·¢ÏÖÀûÓÃWeb ShellÇÔÊØÐÅÓþ¿¨ÐÅÏ¢µÄÐÂÇ÷Ïò


4.jpg


È«ÇòÖ§¸¶´¦ÖÃÉÌVISA³Æ £¬£¬£¬£¬£¬£¬ £¬ÆäÖ§¸¶Ú²Æ­ÖжÏ(PFD)ÔÚ2020Äê·¢ÏÖÁËÒ»ÖÖÐÂÇ÷Ïò £¬£¬£¬£¬£¬£¬ £¬¼´Ô½À´Ô½¶àµÄeSkimming¹¥»÷ʹÓÃÁËweb shellÀ´´´½¨C2¡£¡£¡£¡£¡£¡£VISAµ÷²é·¢ÏÖ £¬£¬£¬£¬£¬£¬ £¬×ÔÈ¥ÄêÒÔÀ´ £¬£¬£¬£¬£¬£¬ £¬×°ÖÃÔÚ±»ÈëÇֵķþÎñÆ÷ÉϵÄWeb ShellÊýÁ¿ÏÕЩÔö³¤ÁËÒ»±¶ £¬£¬£¬£¬£¬£¬ £¬´Ó2020Äê8Ôµ½2021Äê1Ô £¬£¬£¬£¬£¬£¬ £¬¾ùÔÈÿÔ¿ɼì²âµ½14Íò¸ö´ËÀ๤¾ß¡£¡£¡£¡£¡£¡£´Ë±í £¬£¬£¬£¬£¬£¬ £¬VISA PFD³ÆÔÚ2020ÄêÖÁÉÙÓÐ45´ÎeSkimming¹¥»÷ʹÓÃÁËweb shell £¬£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÔÚÈëÇÖÔÚÏßÉ̵êµÄ·þÎñÆ÷ºó×°ÖúóÃŲ¢³ÉÁ¢C2·þÎñÆ÷ £¬£¬£¬£¬£¬£¬ £¬ÒÔÇÔÊØÐÅÓþ¿¨ÐÅÏ¢¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/visa-hackers-increasingly-using-web-shells-to-steal-credit-cards/


5.Group-IB·¢ÏÖÀûÓÃTelegramºÍGoogle FormsµÄ´¹µö»î¶¯


5.jpg


Group-IBµÄ×êÑÐÈËÔ±ÔÚ·ÖÎöÍøÂç´¹µö¹¤¾ß°üʱ·¢ÏÖ £¬£¬£¬£¬£¬£¬ £¬Ô½À´Ô½¶àµÄ¹¤¾ßÆðͷʹÓÃGoogle FormsºÍTelegramµÈºÏ·¨·þÎñÀ´ÍøÂçÓû§Êý¾Ý¡£¡£¡£¡£¡£¡£´ËÀ෽ʽ±»ÊÓΪ»ñÈ¡Êý¾ÝµÄ´úÌæ²½Öè £¬£¬£¬£¬£¬£¬ £¬Õ¼±ÈԼΪ6% £¬£¬£¬£¬£¬£¬ £¬²¢ÇÒÕâÒ»±ÈÀýÔÚ¶ÌÆÚÄÚ¿ÉÄÜ»áÔö³¤¡£¡£¡£¡£¡£¡£´Ë±í £¬£¬£¬£¬£¬£¬ £¬Group-IBÔÚÈ¥Äê·¢ÏÖÁËÕë¶Ô260¶à¸öÆ·ÅÆµÄÍøÂç´¹µö¹¤¾ß°ü £¬£¬£¬£¬£¬£¬ £¬ÖØÒªÕë¶ÔMicrosoft¡¢PayPal¡¢GoogleºÍYahooµÈÆ·ÅÆ¡£¡£¡£¡£¡£¡£¹¥»÷ÕßµÄÖØÒªÖ¸±êÊÇÔÚÏß·þÎñ£¨30.7£¥£©¡¢Æä´ÎÊǵç×ÓÓʼþ·þÎñ£¨22.8£¥£©ºÍ½ðÈÚ»ú¹¹£¨20£¥£©¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116459/cyber-crime/telegram-bots-google-forms-phishing.html


6.¶ñÒâÈí¼þFlixOnline¼Ù×°³ÉNetflixÀûÓÃÕë¶ÔWhatsApp


6.jpg


Check Point Research£¨CPR£©·¢ÏÖÃûΪFlixOnlineµÄAndroid¶ñÒâÈí¼þ¼Ù×°³ÉNetflixµÄÀûÓÃÕë¶ÔWhatsApp¡£¡£¡£¡£¡£¡£Ä¿Ç° £¬£¬£¬£¬£¬£¬ £¬GoogleÒѽ«¸Ã¶ñÒâÈí¼þ´ÓPlayÉ̵êÖÐɾ³ý¡£¡£¡£¡£¡£¡£Ò»µ©×°ÖÃFlixOnlineºó £¬£¬£¬£¬£¬£¬ £¬¸ÃÀûÓþͻáÒªÇ󸲸ǡ¢µç³ØÓÅ»¯ºöÂÔºÍ֪ͨȨÏÞ £¬£¬£¬£¬£¬£¬ £¬Ö¼ÔÚÌìÉúÓÃÓÚµÁȡʹ´¦µÄ¸²¸Ç´°¿Ú¡¢×èÖ¹É豸ÒòÓÅ»¯ÄܺĶø¹Ø¹ØÆä¹ý³Ì¡¢½Ó¼ûÀûÓÃ֪ͨ²¢ÖÎÀíºÍ»Ø¸´ÐÂÎÅ¡£¡£¡£¡£¡£¡£Ö®ºóÆðÍ·¼àÌýWhatsApp֪ͨ²¢×Ô¶¯»Ø¸´´«ÈëµÄÐÂÎÅ £¬£¬£¬£¬£¬£¬ £¬À´½«Êܺ¦Õß³Á¶¨Ïòµ½Î±ÔìµÄNetflixÍøÕ¾ £¬£¬£¬£¬£¬£¬ £¬ÇÔÈ¡ÆäÍ´´¦ºÍÐÅÓþ¿¨ÐÅÏ¢¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/new-android-malware-poses-as-netflix-to-hijack-whatsapp-sessions/