Akamai DNSÈ«Çò¹æÄ£ÖÐÖ¹£¬£¬£¬£¬£¬£¬£¬£¬SteamºÍAWSµÈÍøÕ¾Ì±»¾£»£»£»£»¶ñÒâÈí¼þXLoader¿ÉÔÚmacOSºÍWindowsÇÔÈ¡µÇ¼ÐÅÏ¢

Ðû²¼Ê±¼ä 2021-07-23
1.Akamai DNSÈ«Çò¹æÄ£ÄÚÖÐÖ¹£¬£¬£¬£¬£¬£¬£¬£¬SteamºÍAWSµÈÍøÕ¾Ì±»¾


1.jpg


±¾ÖÜËÄAkamai DNSÔÚÈ«Çò¹æÄ£ÄÚ±¬·¢Ð§ÀÍÖÐÖ¹£¬£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁËSteam¡¢PlayStation Network¡¢AWS¡¢ÑÇÂíÑ·¡¢¹È¸èºÍSalesforceµÈÍøÕ¾¡£¡£¡£¾­ÊӲ죬£¬£¬£¬£¬£¬£¬£¬´Ë´ÎÖÐÖ¹ÊÇÓÉÓÚEdge DNSЧÀÍÖеÄÎÊÌ⵼ֵġ£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ7ÔÂ22ÈÕ15:46UTC£¬£¬£¬£¬£¬£¬£¬£¬Ò»´ÎÈí¼þÉèÖøüе¼ÖÂÁËDNSϵͳÖзºÆð¹ýʧ£¬£¬£¬£¬£¬£¬£¬£¬ÖÐÖ¹Ò»Á¬Á˳¤´ïÒ»¸öСʱ£¬£¬£¬£¬£¬£¬£¬£¬ÔڻعöÈí¼þÉèÖøüк󣬣¬£¬£¬£¬£¬£¬£¬Ð§Àͻָ´ÁËÕý³£ÔËÐС£¡£¡£Akamai³ÆÆä¿ÉÒÔÈ·ÈÏÕâ²»ÊÇÕë¶ÔAkamaiƽ̨µÄÍøÂç¹¥»÷¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/akamai-dns-global-outage-takes-down-major-websites-online-services/


2.жñÒâÈí¼þXLoader¿ÉÔÚmacOSºÍWindowsÇÔÈ¡µÇ¼ÐÅÏ¢


2.jpg


Check PointÑо¿Ö°Ô±Åû¶Ð¶ñÒâÈí¼þXLoader¿ÉÔÚmacOSºÍWindowsÇÔÈ¡µÇ¼ÐÅÏ¢¡£¡£¡£XLoaderÔ´×ÔÕë¶ÔWindowsµÄÐÅÏ¢ÇÔÈ¡³ÌÐòFormbook£¬£¬£¬£¬£¬£¬£¬£¬ÓÚÈ¥Äê2ÔÂÊ״ηºÆð²¢Ô½À´Ô½ÊܽӴý£¬£¬£¬£¬£¬£¬£¬£¬ÊÇÒ»ÖÖûÓÐÒÀÀµÏîµÄ¿çƽ̨£¨WindowsºÍmacOS£©½©Ê¬ÍøÂç¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ»¹ºÜÊÇÁ®¼Û£¬£¬£¬£¬£¬£¬£¬£¬macOS°æ±¾½öÊÛ49ÃÀÔª¶øWindows°æ±¾59ÃÀÔª¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ2020Äê12ÔÂ1ÈÕÖÁ2021Äê6ÔÂ1ÈÕʱ´ú£¬£¬£¬£¬£¬£¬£¬£¬¼ì²âµ½ÁËÀ´×Ô69¸ö¹ú¼ÒºÍµØÇøµÄFormbook/XLoaderÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬ÆäÖд󲿷ÖÀ´×ÔÃÀ¹ú (53%)¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/xloader-malware-steals-logins-from-macos-and-windows-systems/


3.·¨¹úANSSIÅû¶APT31ʹÓüÒͥ·ÓÉÆ÷ÌᳫµÄÌØ¹¤»î¶¯


3.jpg


·¨¹ú¹ú¼ÒÍøÂçÇå¾²»ú¹¹ANSSIÅû¶APT31£¨»òZirconium£©Ê¹ÓüÒͥ·ÓÉÆ÷ÌᳫµÄÌØ¹¤»î¶¯¡£¡£¡£¸Ã»ú¹¹ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬´Ë´Î¹¥»÷×îÏÈÓÚ2021ÄêÍ·£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÏÖÔÚÈÔÔÚ¾ÙÐÐÖС£¡£¡£Ôڴ˴λÖУ¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÐ®ÖÆÁ˼Òͥ·ÓÉÆ÷ÒÔÉèÖÃÊÜѬȾװ±¸µÄÊðÀíÍøÂ磬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÒþ²ØÆäÕì̽ºÍ¹¥»÷»î¶¯¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬ANSSI»¹Ðû²¼ÁËÕâЩ¹¥»÷µÄÈëÇÖÖ¸±ê(IOC)Áбí£¬£¬£¬£¬£¬£¬£¬£¬²¢Ðû²¼Á˴˴ι¥»÷Öб»APT31Ð®ÖÆµÄ161¸öIPµØµãµÄÁбí¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/chinese-hacking-group-apt31-uses-mesh-of-home-routers-to-disguise-attacks/


4.2¸ö¶ñÒâNPM°üʹÓÃChromePass³ÌÐò´Óä¯ÀÀÆ÷ÇÔȡƾ֤


4.jpg


ReversingLabsÅû¶ÁË2¸ö¶ñÒâNPM°ü£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔʹÓÃChromePass³ÌÐò´Óä¯ÀÀÆ÷ÇÔȡƾ֤¡£¡£¡£ÕâÁ½¸öNPM°ü»®·ÖΪnodejs_net_serverºÍtemptesttempfile£¬£¬£¬£¬£¬£¬£¬£¬×ÜÏÂÔØÁ¿ÒÑÁè¼Ý2000´Î¡£¡£¡£ÆäÖÐǰÕß×Ô2019Äê2ÔÂÊ×´ÎÐû²¼ÒÔÀ´£¬£¬£¬£¬£¬£¬£¬£¬ÒѾ­ÓÉÁË12¸ö°æ±¾£¬£¬£¬£¬£¬£¬£¬£¬Æä¿ª·¢ÕßchrunleeËÆºõÒ²ÊÇGitHubÉϵĻîÔ¾¿ª·¢Ö°Ô±£»£»£»£»´ËºóÕßµÄÏà¹ØÐÅÏ¢ÔòÉٵöà¡£¡£¡£ReversingLabsÓÚ7ÔÂ2ÈÕÁªÏµÁËnpmÇå¾²ÍŶÓ£¬£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÕâÁ½¸öÈí¼þ°ü¶¼Òѱ»É¾³ý¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/npm-package-steals-chrome-passwords/168004/


5.CISAÔÚ±»¹¥»÷µÄPulse Secure×°±¸Öз¢Ã÷13¸ö¶ñÒâÑù±¾


5.jpg


ÃÀ¹úCISAÐû²¼¾¯±¨£¬£¬£¬£¬£¬£¬£¬£¬³ÆÔÚ±»¹¥»÷µÄPulse Secure×°±¸ÉÏ·¢Ã÷ÁË13¸ö¶ñÒâÈí¼þÑù±¾¡£¡£¡£×Ô2020Äê6ÔÂÒÔÀ´£¬£¬£¬£¬£¬£¬£¬£¬ÃÀ¹úÕþ¸®»ú¹¹¡¢Òªº¦»ù´¡ÉèÊ©ºÍ¸÷ÐÐÒµ¹«Ë¾µÄPulse Secure×°±¸Ò»Ö±Êǹ¥»÷ÕßµÄÄ¿µÄ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓöà¸öÎó²î£¨CVE-2019-11510¡¢CVE-2020-8260¡¢CVE-2020-8243ºÍCVE-2021-2289£©ÈëÇÖ²¢×°ÖÃwebshell¡£¡£¡£CISAÃãÀøÓû§ºÍÖÎÀíÔ±Éó²éÕâ13¸ö¶ñÒâÈí¼þµÄÆÊÎö±¨¸æ(MAR)£¬£¬£¬£¬£¬£¬£¬£¬Ïàʶ¹¥»÷ÕßµÄÊÖÒÕ¡¢Õ½ÂԺͳÌÐò(TTP)ÒÔ¼°ÈëÇÖÖ¸±ê(IOC)¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/07/21/malware-targeting-pulse-secure-devices


6.ºÚ¿Íbl4ckt0r³öÊÛÒâ´óÀûTicketClub 34ÍòÓû§ÐÅÏ¢


6.jpg


2021Äê7ÔÂ19ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿Íbl4ckt0rÔÚºÚ¿ÍÂÛ̳RaidForumsÉϳöÊÛTicketClubÁè¼Ý340957Óû§µÄÐÅÏ¢¡£¡£¡£TicketClubÊÇÒ»¼ÒÒâ´óÀû¹«Ë¾£¬£¬£¬£¬£¬£¬£¬£¬Ö÷ҪΪÏßϹºÎïÌṩÓÅ»Ýȯ£¬£¬£¬£¬£¬£¬£¬£¬ËûÃǵĿͻ§°üÀ¨ºº±¤Íõ¡¢Âóµ±ÀͺÍRainbow MagiclandµÈ¡£¡£¡£7ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾µÄÐí¶àÓû§±¨¸æ³ÆÍøÕ¾ÎÞ·¨»á¼û¡£¡£¡£ÖµµÃÒ»ÌáµÄÊÇ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚ2020Äê4ÔÂÒ²ÂÄÀú¹ýÀàËÆÊÂÎñ£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂ203859·â¿Í»§µÄµç×ÓÓʼþй¶¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/120406/data-breach/ticketclub-italy-data-leak.html