NCC·¢ÏÖClopÀûÓÃSolarWinds Serv-UÖÐRCEµÄ»î¶¯
°ä²¼¹¦·ò 2021-11-12ESET·¢ÏÖLazarusÀûÓõÁ°æµÄIDA Pro·Ö·¢¶ñÒâÈí¼þ

ESETÍŶÓÓÚ11ÔÂ10ÈÕ·¢ÏÖ³¯ÏʺڿÍÍÅ»ïLazarusÀûÓõÁ°æIDA Pro¹¥»÷°²È«×êÑÐÈËÔ±µÄ»î¶¯¡£¡£¡£¡£¡£¡£×êÑÐÈËԱͨ³£Ê¹ÓÃÄæÏò¹¤³ÌÀûÓÃIDA ProÀ´·ÖÎö·ì϶ºÍ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬¶øÕâ´Î·¢ÏÖµÄIDA Pro 7.5°æ±¾Ô̺¬ÁËÁ½¸öÃûΪidahelp.dllºÍwin_fw.dllµÄ¶ñÒâDLL¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬£¬win_fw.dll½«ÔÚWindows¹¤×÷µ÷¶È·¨Ê½Öд´½¨Ò»¸öй¤×÷£¬£¬£¬£¬£¬£¬£¬¸Ã¹¤×÷½«Æô¶¯idahelper.dll£¬£¬£¬£¬£¬£¬£¬¶øºóidahelper.dll½«Ïνӵ½devguardmap[.]orgÍøÕ¾²¢ÏÂÔØÔ¶³Ì½Ó¼ûľÂíNukeSpedµÄpayload¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/lazarus-hackers-target-researchers-with-trojanized-ida-pro/
ͳ³ÆÎªNUCLEUS:13µÄ¶à¸ö·ì϶ӰÏìÎ÷ÃÅ×ÓRTOS

ForescoutºÍMedigateµÄ×êÑÐÈËÔ±ÔÚ11ÔÂ9ÈÕÅû¶ÁËNucleusÖÐ13¸ö·ì϶µÄϸ½Ú¡£¡£¡£¡£¡£¡£NucleusÊÇÎ÷ÃÅ×ÓµÄʵʱ²Ù×÷ϵͳ(RTOS)£¬£¬£¬£¬£¬£¬£¬Í¨³£ÔËÐÐÔÚÒ½ÁÆÉ豸¡¢Æû³µ¡¢ÖÇÄÜÊÖ»ú¡¢ÎïÁªÍøÉ豸¡¢¹¤ÒµplcµÈÉ豸µÄƬÉÏϵͳ(SoC)¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶ͳ³ÆÎªNUCLEUS:13£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁËNucleus TCP/IP²Ö¿â¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬£¬×îÑϳÁµÄÊÇÓ°ÏìÁËFTP·þÎñÆ÷×é¼þµÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-31886£©£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬£¬£¬ÊÇÓÉÓÚ¶ÔUSERºÅÁ¶ÈµÄÑéÖ¤²»ÕýÈ·µ¼Öµġ£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/nucleus13-vulnerabilities-impact-siemens-medical-industrial-equipment/
SAP°ä²¼11Ô·ÝÖܶþ²¹¶¡£¬£¬£¬£¬£¬£¬£¬½¨¸´¶à¸ö°²È«·ì϶

SAPÔÚ11ÔÂ9ÈÕ°ä²¼Á˱¾ÔµÄÖܶþ²¹¶¡£¬£¬£¬£¬£¬£¬£¬½¨¸´Á˶à¸ö°²È«·ì϶¡£¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ×îÑϳÁµÄ·ì϶ÊÇABAPƽ̨ÄÚºËÖÐÓÉÓÚȱʧÊÚȨ²é³µ¼ÖµÄÌáȨ·ì϶£¨CVE-2021-40501£©£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.6¡£¡£¡£¡£¡£¡£°²È«¹«Ë¾Onapsis³Æ£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶Äܹ»Í¨¹ýRFCºÍHTTPͨѶӰÏìÆäËüϵͳµÄ¿ÉÐÅÏνӣ¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓÃÆäÔÚÆäËüϵͳÖÐÖ´ÐÐÌØ¶¨µÄÂß¼¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬»¹½¨¸´ÁËCommerceÖеÄÌáȨ·ì϶£¨CVE-2021-40502£©¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/sap-patches-critical-vulnerability-abap-platform-kernel
NCC·¢ÏÖClopÀûÓÃSolarWinds Serv-UÖÐRCEµÄ»î¶¯

NCC GroupÓÚ11ÔÂ8Èճƣ¬£¬£¬£¬£¬£¬£¬ÔÚ´Óǰ¼¸ÖÜÖÐÀÕË÷Èí¼þClopµÄϰȾÁ¿ÓÐËùÔö³¤£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ´óÎÞÊý¶¼ÀûÓÃÁË·ì϶CVE-2021-35211¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇServ-U Managed File TransferºÍServ-U Secure FTPÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬£¬£¬SolarWindsÔÚ2021Äê7Ô·ݰ䲼ÁË´¹Î£¸üн¨¸´¸Ã·ì϶£¬£¬£¬£¬£¬£¬£¬²¢³Æ½öÓ°ÏìÁËÆôÓÃSSHÖ°ÄܵĿͻ§¡£¡£¡£¡£¡£¡£ÔÚÕâ´Î»î¶¯ÖУ¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÃServ-UÌìÉúÁËÒ»¸öÓÉÆä½ÚÔìµÄ×Ó¹ý³Ì£¬£¬£¬£¬£¬£¬£¬²¢ÔÚÖ¸±êϵͳÉÏÖ´ÐкÅÁî¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://research.nccgroup.com/2021/11/08/ta505-exploits-solarwinds-serv-u-vulnerability-cve-2021-35211-for-initial-access/
µÂ¹úÒ½ÁÆÈí¼þ¹«Ë¾MedatixxÈ·ÈÏÆäÔâµ½ÀÕË÷¹¥»÷

Medatixx¹«Ë¾11ÔÂ9ÈÕÈ·ÈÏÆäÔÚÉÏÖÜÔâµ½ÁËÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£MedatixxÊÇÒ»¼ÒµÂ¹úµÄÒ½ÁÆÈí¼þ¹«Ë¾£¬£¬£¬£¬£¬£¬£¬ËüµÄ²úÆ·±»ÓÃÓÚ21000¶à¼ÒÒ½ÁÆ»ú¹¹¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾³Æ£¬£¬£¬£¬£¬£¬£¬¹¥»÷½öÓ°ÏìÁËËûÃǵÄÄÚ²¿ITϵͳ£¬£¬£¬£¬£¬£¬£¬Ã»ÓÐÓ°Ïì¿Í»§µÄPVS£¨Êµ¼ÊÖÎÀíϵͳ£©¡£¡£¡£¡£¡£¡£Ä¿Ç°ÉÐδȷ¶¨¹¥»÷ÕßÇÔÈ¡ÁËÄÄЩÊý¾Ý£¬£¬£¬£¬£¬£¬£¬µ«¿ÉÄÜÒѾ»ñÈ¡ÁËMedatixx¿Í»§µÄÃÜÂ룬£¬£¬£¬£¬£¬£¬Òò¶øMedatixx½¨Òé¿Í»§Á¢¿Ì¸ü¸ÄÆäÀûÓ÷¨Ê½µÄÃÜÂë¡£¡£¡£¡£¡£¡£¹«Ë¾ÈÔÔÚ¸´ÔÖУ¬£¬£¬£¬£¬£¬£¬½ØÖÁĿǰֻ¸´ÔÁËÓʼþºÍµç»°ÏµÍ³¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/medical-software-firm-urges-password-resets-after-ransomware-attack/
ACTIºÍPACT°ä²¼¹ØÓÚLyceum½üÆÚ»î¶¯µÄ·ÖÎö»ã±¨

11ÔÂ9ÈÕ£¬£¬£¬£¬£¬£¬£¬AccentureµÄACTIÍŶӺÍPrevailionµÄPACTÍŶӽáºÏ°ä²¼Á˹ØÓÚLyceum½üÆÚ»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬£¬ÒÁÀʺڿÍÍÅ»ïLyceumÖØÒª×¨Ò»ÓÚ¼äµý»î¶¯£¬£¬£¬£¬£¬£¬£¬ÔÚ2021Äê7ÔÂÖÁ10ÔÂÆÚ¼ä£¬£¬£¬£¬£¬£¬£¬Ôø¹¥»÷ÁËÒÔÉ«ÁÓעĦÂå¸ç¡¢Í»Äá˹ºÍÉ³ÌØ°¢À²®µÄISPºÍµçÐÅÔËÓªÉÌ£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°·ÇÖÞµÄ±í½»²¿(MFA)¡£¡£¡£¡£¡£¡£LyceumµÄ³õʼ¹¥»÷ý½éΪƾ֤Ìî³ä¹¥»÷ºÍ±©Á¦¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÔÚÈëÇֳɹ¦ºó»á×°ÖúóÃÅSharkºÍMilan£¨Í³³ÆÎªJames£©¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.accenture.com/us-en/blogs/cyber-defense/iran-based-lyceum-campaigns


¾©¹«Íø°²±¸11010802024551ºÅ