¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180928

Ðû²¼Ê±¼ä 2018-09-28

¡¾¶ñÒâÈí¼þ¡¿TalosÑо¿ÍŶӷ¢Ã÷¶ñÒâÈí¼þVPNFilterÐÂÔö7¸ö¹¦Ð§Ä£¿£¿£¿£¿£¿é


˼¿ÆTalosÑо¿ÍŶÓÅû¶¶ñÒâÈí¼þVPNFilterµÄ7¸öÐÂÄ£¿£¿£¿£¿£¿éµÄÊÖÒÕϸ½ÚÐÅÏ¢¡£¡£ÕâЩÄ£¿£¿£¿£¿£¿éΪVPNFilterÔöÌíÁ˶à¸öÖ÷Òª¹¦Ð§£¬£¬£¬£¬£¬£¬°üÀ¨Ó³ÉäÍøÂçÍØÆË²¢Ñ¬È¾ÆäËü×°±¸¡¢»ìÏýºÍ¼ÓÃܶñÒâÁ÷Á¿¡¢Êý¾ÝÉøÂ©¡¢ÓëC&CͨѶ¡¢É¨ÃèÍøÂçÖеÄDZÔÚÄ¿µÄÒÔ¼°¹¹½¨ÂþÑÜʽÊðÀíÍøÂçµÈ¡£¡£Ñо¿Ö°Ô±»¹·¢Ã÷ÎÚ¿ËÀ¼µÄMikroTik×°±¸³ÉΪÆäÖ÷ÒªµÄ¹¥»÷Ä¿µÄ¡£¡£


https://blog.talosintelligence.com/2018/09/vpnfilter-part-3.html


¡¾¶ñÒâÈí¼þ¡¿ESETÑо¿ÍŶӷ¢Ã÷Ê׸öÔÚÒ°ÍâʹÓõÄUEFI Rootkit LoJax


ESETÑо¿ÍŶӷ¢Ã÷Ê׸öÔÚÒ°ÍâʹÓõÄUEFI rootkit£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ±»ÃüÃûΪLoJax¡£¡£LoJax±»·¸·¨ÍÅ»ïAPT28ÓÃÓÚÕë¶Ô°Í¶û¸ÉµØÇøÒÔ¼°ÖÐÅ·ºÍ¶«Å·µÄÕþ¸®»ú¹¹¡£¡£LoJax±»ÊµÏÖΪUEFI/BIOSÄ£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬Ê¹µÃÆä¿ÉÒÔÔÚÖØÐÂ×°ÖòÙ×÷ϵͳÒÔ¼°Ìæ»»Ó²Å̺óÒÀ¾É±£´æ¡£¡£É¾³ý¸Ã¶ñÒâÈí¼þµÄΨһҪÁìÊÇÖØË¢UEFI¹Ì¼þ¡£¡£Í¨¹ýÆôÓÃÇå¾²ÆôÄîÍ·ÖÆÒ²¿ÉÒÔ±ÜÃâLoJaxѬȾ¡£¡£


https://www.bleepingcomputer.com/news/security/apt28-uses-lojax-first-uefi-rootkit-seen-in-the-wild/


¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±·¢Ã÷IoT½©Ê¬ÍøÂç×½ÃÔ²Ø×îÏÈÕë¶ÔAndroid×°±¸


ƾ֤BitDefenderµÄб¨¸æ£¬£¬£¬£¬£¬£¬ÎïÁªÍø½©Ê¬ÍøÂç×½ÃԲأ¨HNS£©µÄ×îÐÂÑù±¾×îÏÈÕë¶ÔÆôÓÃÁËÎÞÏßµ÷ÊÔ¹¦Ð§£¨ADB£©µÄAndroid×°±¸¡£¡£ÕâÒ»¸Ä±äʹµÃ×½ÃÔ²ØÑ¬È¾µÄ×°±¸×ÜÊýÐÂÔöÁË4Íò£¬£¬£¬£¬£¬£¬ÆäÖд󲿷ÖλÓÚÖйų́ÍåºÍº«¹úµÈµØÇø¡£¡£BitDefenderÌåÏÖ¿ÉÒԿ϶¨µÄÊÇ£¬£¬£¬£¬£¬£¬²»µ«ÊÇÔËÐÐAndroidϵͳµÄÖÇÄÜÊÖ»úÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬ÆäËüÖÇÄܵçÊÓ¡¢DVRÒÔ¼°ÏÕЩÈÎºÎÆôÓÃÁËADB¹¦Ð§µÄ×°±¸¶¼»áÊܵ½Ó°Ïì¡£¡£ÏÖÔڸý©Ê¬ÍøÂçµÄÕæÕýÄ¿µÄÈÔȻδ֪¡£¡£


https://labs.bitdefender.com/2018/09/hide-and-seek-iot-botnet-learns-new-tricks-uses-adb-over-internet-to-exploit-thousands-of-android-devices/


¡¾ÍþвÇ鱨¡¿AvastÑо¿ÍŶӷ¢Ã÷еÄÎïÁªÍø½©Ê¬ÍøÂçTorii


AvastÑо¿ÍŶÓÐû²¼¹ØÓÚÐÂÎïÁªÍø½©Ê¬ÍøÂçToriiµÄÆÊÎö±¨¸æ¡£¡£Torii×Ô2017Äê12ÔÂÆðÒ»Ö±»îÔ¾£¬£¬£¬£¬£¬£¬Ëü¿ÉÒÔѬȾ¶àÖÖCPU¼Ü¹¹µÄ×°±¸£¬£¬£¬£¬£¬£¬ÈçMIPS¡¢ARM¡¢x86¡¢x64¡¢PowerPCºÍSuperHµÈ¡£¡£ToriiÊÇ×ÔVPNFilterºÍ×½ÃÔ²ØÒÔÀ´µÄµÚÈý¸öʵÏÖÁ˳¤ÆÚÐÔµÄÎïÁªÍø½©Ê¬ÍøÂ磬£¬£¬£¬£¬£¬ÕâÒâζ×ÅËü¿ÉÒÔÔÚ×°±¸ÖØÆôºó¼ÌÐøÔËÐС£¡£½«×°±¸¹Ì¼þµÄÉèÖÃÖØÖÃΪĬÈϳö³§ÉèÖÿÉÄÜ¿ÉÒÔɾ³ýËü¡£¡£


https://blog.avast.com/new-torii-botnet-threat-research


¡¾Îó²î²¹¶¡¡¿Ë¼¿ÆÐû²¼Cisco IOSºÍIOS XEµÄ°ëÄê¶ÈÇ徲ת´ï£¬£¬£¬£¬£¬£¬¹²ÐÞ¸´13¸öÎó²î


9ÔÂ26ÈÕ˼¿ÆÐû²¼Cisco IOSºÍIOS XEÈí¼þµÄ°ëÄê¶ÈÇ徲ת´ï£¬£¬£¬£¬£¬£¬¹²ÐÞ¸´13¸öÇå¾²Îó²î¡£¡£Ë¼¿ÆÔÚÿÄêµÄ3ÔºÍ9ÔµĵÚËĸöÐÇÆÚÈý¶¼»áÐû²¼ÆäCisco IOSºÍIOS XEÈí¼þµÄ°ëÄê¶ÈÇ徲ת´ï¡£¡£±¾´Îת´ïÖÐÐÞ¸´µÄ13¸öÎó²îµÄÇå¾²ÆÀ¼¶£¨SIR£©¶¼Îª¸ß£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓÃÕâЩÎó²î½«»áµ¼ÖÂÌáȨ»ò¾Ü¾øÐ§ÀÍ¡£¡£ÏêϸÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£


https://tools.cisco.com/security/center/viewErp.x?alertId=ERP-69981


¡¾Çå¾²²¥±¨¡¿Å̹ÅÍŶÓÀÖ³ÉÔÚÔËÐÐiOS 12µÄiPhone XSÉÏÔ½Óü


ƾ֤Çå¾²Ñо¿Ö°Ô±Min(Spark) ZhengµÄÍÆÎÄ£¬£¬£¬£¬£¬£¬Å̹ÅÍŶÓÀÖ³ÉÔÚÔËÐÐiOS 12µÄiPhone XSÉÏÔ½Óü¡£¡£Ñо¿Ö°Ô±Í¸Â¶Ô½ÓüµÄÊÂÇéÔ­ÀíÊÇÈÆ¹ýA12·ÂÉúоƬÖÐʵÑéµÄPAC·À»¤¹¦Ð§¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬ÓÉÓÚiPhone XSµÄÓ²¼þÓëiPhone XS MaxºÜÊÇÏàËÆ£¬£¬£¬£¬£¬£¬Òò´Ë¸ÃÔ½ÓüÒªÁìÒ²ÊÊÓÃÓÚiPhone XS Max¡£¡£ÏÖÔÚÉв»ÇåÎú¸ÃÍŶÓÊÇ·ñ»áÏò¹«ÖÚÐû²¼ÆäÔ½ÓüÒªÁì¡£¡£


https://thehackernews.com/2018/09/ios12-iphone-jailbreak-exploit.html



¡¾ÈËÉú¾ÍÊDz©¼¯ÍÅADLabÕûÀíÐû²¼¡¿