NSOʹÓÃiMessageÖеÄÐÂÁãµã»÷Îó²î¹¥»÷°ÍÁÖ»îÔ¾ÈËÊ¿:F5Ðû²¼Çå¾²¸üÐÂÐÞ¸´Æä¶à¿î²úÆ·

Ðû²¼Ê±¼ä 2021-08-27

NSOʹÓÃiMessageÖеÄÐÂÁãµã»÷Îó²î¹¥»÷°ÍÁÖ»îÔ¾ÈËÊ¿


NSOʹÓÃiMessageÖеÄÐÂÁãµã»÷Îó²î¹¥»÷°ÍÁÖ»îÔ¾ÈËÊ¿.jpg


Citizen LabÓÚ2021Äê8ÔÂ24ÈÕÐû²¼ÁËÒ»ÏîÑо¿£¬ £¬£¬£¬£¬£¬³ÆNSO GroupʹÓÃiMessageÖÐеÄÁãµã»÷Îó²îÔÚÄ¿µÄiPhoneÉÏ×°ÖÃÌØ¹¤Èí¼þPegasus¡£¡£¡£¡£¡£¡£Ñо¿Åú×¢£¬ £¬£¬£¬£¬£¬´Ë´Î¹¥»÷ʼÓÚ2021Äê7Ô£¬ £¬£¬£¬£¬£¬Ö÷ÒªÕë¶Ô°ÍÁÖµÄ9¸ö»îÔ¾ÈËÊ¿£¨°üÀ¨°ÍÁÖÈËȨÖÐÐijÉÔ±¡¢WaadºÍAl WefaqµÈ£©¡£¡£¡£¡£¡£¡£Ôڴ˴λÖУ¬ £¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁËÁ½¸öÁãµã»÷Îó²î£¬ £¬£¬£¬£¬£¬»®·Ö³ÆÎª2020  KISMETºÍÐÂÎó²îFORCEDENTRY¡£¡£¡£¡£¡£¡£ÏÖÔÚÉÐδÓйØFORCEDENTRYÎó²îµÄÊÖÒÕϸ½Ú£¬ £¬£¬£¬£¬£¬Ö÷ÒªÊÇÓÉÓÚ¸ÃÎó²îÈÔδÐÞ¸´¡£¡£¡£¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/121415/malware/zero-click-exploit-nso.html


F5Ðû²¼Çå¾²¸üУ¬ £¬£¬£¬£¬£¬ÐÞ¸´Æä¶à¿î²úÆ·ÖеĽü30¸öÇå¾²Îó²î


F5Ðû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´Æä¶à¿î²úÆ·ÖеĽü30¸öÇå¾²Îó²î.jpg


F5ÔÚ8ÔÂ24ÈÕÐû²¼ÁË8Ô·ÝÇå¾²¸üУ¬ £¬£¬£¬£¬£¬ÐÞ¸´ÁËÆä¶à¿î²úÆ·Öнü30¸öÎó²î¡£¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄ×îΪÑÏÖØµÄÎó²îÊÇBIG-IP WAFºÍASMÁ÷Á¿ÖÎÀíÓû§½çÃæ(TMUI)ÉϵÄÌáȨÎó²î£¬ £¬£¬£¬£¬£¬×·×ÙΪCVE-2021-23031£¬ £¬£¬£¬£¬£¬ÆÀ·ÖΪ8.8£¬ £¬£¬£¬£¬£¬µ«¹ØÓÚʹÓÃ×°±¸Ä£Ê½µÄÓû§À´Ëµ£¬ £¬£¬£¬£¬£¬ÆÀ·Ö½«Ìá¸ßµ½9.9¡£¡£¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬£¬£¬ÉÐÓÐBIG-IPÖеÄÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨CVE-2021-23025£©¡¢BIG-IPºÍBIG-IQÖеÄCSRFÎó²î£¨CVE-2021-23026£©ºÍTMUIÖеĻùÓÚDOMµÄXSSÎó²î£¨CVE-2021-23027£©µÈ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://support.f5.com/csp/article/K50974556


ÐéαµÄOpenSeaÖ§³ÖȦÌ×ÒþÄäÔÚDiscordÍøÂçÖй¥»÷Ä¿µÄ


ÐéαµÄOpenSeaÖ§³ÖȦÌ×ÒþÄäÔÚDiscordÍøÂçÖй¥»÷Ä¿µÄ.jpg


ÔÚÒÑÍùµÄÒ»ÖÜÀ £¬£¬£¬£¬£¬ÐéαµÄOpenSeaÖ§³ÖȦÌ×ÒþÄäÔÚDiscordÍøÂçÖй¥»÷Ä¿µÄ£¬ £¬£¬£¬£¬£¬Ö¼ÔÚÇÔÈ¡Óû§×ʽ𡣡£¡£¡£¡£¡£µ±Óû§ÔÚÍøÉÏ×·Çó×ÊÖúʱ£¬ £¬£¬£¬£¬£¬ÒþÄäÔÚDiscordЧÀÍÆ÷ÉϵÄÕ©Æ­Õß±ã»á·¢ËÍ˽ÐÅÔ¼ÇëÆä¼ÓÈëÐéαµÄOpenSeaÖ§³ÖЧÀÍ¡£¡£¡£¡£¡£¡£Ö®ºó£¬ £¬£¬£¬£¬£¬Õ©Æ­Õß»áÒªÇóÄ¿µÄ¿ªÆôÆÁÄ»¹²Ïí£¬ £¬£¬£¬£¬£¬²¢É¨Ãè¶þάÂëÒÔͬ²½MetaMaskÇ®°üÓëChromeÀ©Õ¹³ÌÐò¡£¡£¡£¡£¡£¡£×îºó£¬ £¬£¬£¬£¬£¬Õ©Æ­Õß»áÓøöþάÂ뽫ĿµÄÇ®°üÖеÄ×ʽð×ªÒÆ³öÀ´¡£¡£¡£¡£¡£¡£    


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fake-opensea-support-staff-are-stealing-cryptowallets-and-nfts/


ÃÀ¹úСÕòPeterboroughÒò2´ÎBEC¹¥»÷Ëðʧ230ÍòÃÀÔª


ÃÀ¹úСÕòPeterboroughÒò2´ÎBEC¹¥»÷Ëðʧ230ÍòÃÀÔª.jpg


ÃÀ¹úк±²¼Ê²¶ûÖݵÄСÕòPeterboroughÒò2´ÎBEC¹¥»÷Ëðʧ230ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¸ÃÕò¹ÙÔ±ÌåÏÖ£¬ £¬£¬£¬£¬£¬ËûÃÇÓÚ7ÔÂ26ÈÕÊ״η¢Ã÷¹¥»÷»î¶¯£¬ £¬£¬£¬£¬£¬ÆäʱConValÑ§Çø³ÆÆäûÓÐÊÕµ½Ã¿ÔÂ120ÍòÃÀÔªµÄתÕË¡£¡£¡£¡£¡£¡£ÔÚËæºóµÄÊÓ²ìÖУ¬ £¬£¬£¬£¬£¬ÓÖÓÚ8ÔÂ18ÈÕ·¢Ã÷ÁËÁíÍâÁ½±Ê±»Ð®ÖƵĿî×Ó£¬ £¬£¬£¬£¬£¬ÕâЩ¿î×ÓÔ­±¾Òª×ª¸øÇÅÁº¹¤³ÌµÄ³Ð°üÉÌBeckºÍBellucci¡£¡£¡£¡£¡£¡£¸ÃÕò±¾²ÆÎñÄê¶ÈµÄÔ¤ËãԼΪ1580ÍòÃÀÔª£¬ £¬£¬£¬£¬£¬´Ë´ÎµÄËðʧռÆäÄê¶ÈÔ¤ËãµÄ15%¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/cyberthieves-scam-new-hampshire/


ESET·¢Ã÷SparklingGoblin¹¥»÷ÃÀ¹úijÅÌËã»úÁãÊÛ¹«Ë¾


ESET·¢Ã÷SparklingGoblin¹¥»÷ÃÀ¹úijÅÌËã»úÁãÊÛ¹«Ë¾.jpg


˹Âå·¥¿ËÍøÂçÇå¾²¹«Ë¾ESETÔÚ8ÔÂ24ÈÕ³ÆÆä·¢Ã÷ÁËAPTÍÅ»ïSparklingGoblin¹¥»÷ÃÀ¹úijÅÌËã»úÁãÊÛ¹«Ë¾µÄ»î¶¯¡£¡£¡£¡£¡£¡£ÔÚÒÑÍùµÄÒ»ÄêÖУ¬ £¬£¬£¬£¬£¬¸ÃÍŻ﹥»÷ÁËÌìϸ÷µØµÄ×éÖ¯£¬ £¬£¬£¬£¬£¬°üÀ¨°ÍÁÖ¡¢¼ÓÄô󡢸ñ³¼ªÑÇ¡¢Ó¡¶È¡¢ÐÂ¼ÓÆÂ¡¢º«¹úºÍÃÀ¹úµÈ¡£¡£¡£¡£¡£¡£Ôڴ˴ι¥»÷ÖУ¬ £¬£¬£¬£¬£¬¸ÃÍÅ»ïʹÓÃÁËÒ»¸öеĺóÃÅSideWalk£¬ £¬£¬£¬£¬£¬Ëü¿ÉÒÔ¶¯Ì¬¼ÓÔØ´ÓÆäC&CЧÀÍÆ÷·¢Ë͵ÄÌØÊâÄ £¿£¿£¿£¿£¿é£¬ £¬£¬£¬£¬£¬²¢Ê¹ÓùȸèDocs×÷Ϊdead drop resolver¡£¡£¡£¡£¡£¡£Ñо¿ÈËÌåÏÖ£¬ £¬£¬£¬£¬£¬SideWalkºÜ¿ÉÄÜÊÇÓÉCROSSWALKµÄ¿ª·¢Ö°Ô±¿ª·¢µÄ£¬ £¬£¬£¬£¬£¬ÓÉÓÚËüÃǹ²ÏíÁËÐí¶àÉè¼Æ½á¹¹ºÍʵÏÖϸ½Ú¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/08/new-sidewalk-backdoor-targets-us-based.html


Unit 42Ðû²¼ÓйØ4¸öеÄÀÕË÷ÔËÓªÍÅ»ïµÄÆÊÎö±¨¸æ


Unit 42Ðû²¼ÓйØ4¸öеÄÀÕË÷ÔËÓªÍÅ»ïµÄÆÊÎö±¨¸æ.jpg


Unit 42ÔÚ2021Äê8ÔÂ24ÈÕÐû²¼ÁËÓйØ4¸öеÄÀÕË÷ÔËÓªÍÅ»ïµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£ÕâËĸöÀÕË÷ÍŻﻮ·ÖΪ6ÔÂÏÂÑ®×îÏÈÔËÓªµÄAvosLocker RaaS£¬ £¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹ú¡¢Ó¢¹ú¡¢°¢ÁªÇõ¡¢±ÈÀûʱ¡¢Î÷°àÑÀºÍÀè°ÍÄÛ£¬ £¬£¬£¬£¬£¬Êê½ð´Ó50000ÃÀÔªµ½75000ÃÀÔª²»µÈ £»£»£»6ÔÂ×îÏȵÄHive Ransomware£¬ £¬£¬£¬£¬£¬Òѹ¥»÷ÁË28¸ö×éÖ¯ £»£»£»7ÔÂ×îÏÈ»îÔ¾µÄLinux°æ±¾HelloKitty£¬ £¬£¬£¬£¬£¬ÆäÊ×ѡĿµÄΪVMwareµÄESXiÖÎÀí³ÌÐò £»£»£»ÒÔ¼°ÔÚ6Ô¾­ÓÉˢеÄLockBit 2.0£¬ £¬£¬£¬£¬£¬ÒѾ­¹¥»÷ÁË52¸ö×éÖ¯¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/emerging-ransomware-groups/