¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180928
Ðû²¼Ê±¼ä 2018-09-28¡¾¶ñÒâÈí¼þ¡¿TalosÑо¿ÍŶӷ¢Ã÷¶ñÒâÈí¼þVPNFilterÐÂÔö7¸ö¹¦Ð§Ä£¿é
˼¿ÆTalosÑо¿ÍŶÓÅû¶¶ñÒâÈí¼þVPNFilterµÄ7¸öÐÂÄ£¿éµÄÊÖÒÕϸ½ÚÐÅÏ¢¡£ÕâЩģ¿éΪVPNFilterÔöÌíÁ˶à¸öÖ÷Òª¹¦Ð§£¬°üÀ¨Ó³ÉäÍøÂçÍØÆË²¢Ñ¬È¾ÆäËü×°±¸¡¢»ìÏýºÍ¼ÓÃܶñÒâÁ÷Á¿¡¢Êý¾ÝÉøÂ©¡¢ÓëC&CͨѶ¡¢É¨ÃèÍøÂçÖеÄDZÔÚÄ¿µÄÒÔ¼°¹¹½¨ÂþÑÜʽÊðÀíÍøÂçµÈ¡£Ñо¿Ö°Ô±»¹·¢Ã÷ÎÚ¿ËÀ¼µÄMikroTik×°±¸³ÉΪÆäÖ÷ÒªµÄ¹¥»÷Ä¿µÄ¡£
https://blog.talosintelligence.com/2018/09/vpnfilter-part-3.html
¡¾¶ñÒâÈí¼þ¡¿ESETÑо¿ÍŶӷ¢Ã÷Ê׸öÔÚÒ°ÍâʹÓõÄUEFI Rootkit LoJax
ESETÑо¿ÍŶӷ¢Ã÷Ê׸öÔÚÒ°ÍâʹÓõÄUEFI rootkit£¬¸Ã¶ñÒâÈí¼þ±»ÃüÃûΪLoJax¡£LoJax±»·¸·¨ÍÅ»ïAPT28ÓÃÓÚÕë¶Ô°Í¶û¸ÉµØÇøÒÔ¼°ÖÐÅ·ºÍ¶«Å·µÄÕþ¸®»ú¹¹¡£LoJax±»ÊµÏÖΪUEFI/BIOSÄ£¿é£¬Ê¹µÃÆä¿ÉÒÔÔÚÖØÐÂ×°ÖòÙ×÷ϵͳÒÔ¼°Ìæ»»Ó²Å̺óÒÀ¾É±£´æ¡£É¾³ý¸Ã¶ñÒâÈí¼þµÄΨһҪÁìÊÇÖØË¢UEFI¹Ì¼þ¡£Í¨¹ýÆôÓÃÇå¾²ÆôÄîÍ·ÖÆÒ²¿ÉÒÔ±ÜÃâLoJaxѬȾ¡£
https://www.bleepingcomputer.com/news/security/apt28-uses-lojax-first-uefi-rootkit-seen-in-the-wild/
¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±·¢Ã÷IoT½©Ê¬ÍøÂç×½ÃÔ²Ø×îÏÈÕë¶ÔAndroid×°±¸
ƾ֤BitDefenderµÄб¨¸æ£¬ÎïÁªÍø½©Ê¬ÍøÂç×½ÃԲأ¨HNS£©µÄ×îÐÂÑù±¾×îÏÈÕë¶ÔÆôÓÃÁËÎÞÏßµ÷ÊÔ¹¦Ð§£¨ADB£©µÄAndroid×°±¸¡£ÕâÒ»¸Ä±äʹµÃ×½ÃÔ²ØÑ¬È¾µÄ×°±¸×ÜÊýÐÂÔöÁË4Íò£¬ÆäÖд󲿷ÖλÓÚÖйų́ÍåºÍº«¹úµÈµØÇø¡£BitDefenderÌåÏÖ¿ÉÒÔÒ»¶¨µÄÊÇ£¬²»µ«ÊÇÔËÐÐAndroidϵͳµÄÖÇÄÜÊÖ»úÊܵ½Ó°Ï죬ÆäËüÖÇÄܵçÊÓ¡¢DVRÒÔ¼°ÏÕЩÈÎºÎÆôÓÃÁËADB¹¦Ð§µÄ×°±¸¶¼»áÊܵ½Ó°Ïì¡£ÏÖÔڸý©Ê¬ÍøÂçµÄÕæÕýÄ¿µÄÈÔȻδ֪¡£
https://labs.bitdefender.com/2018/09/hide-and-seek-iot-botnet-learns-new-tricks-uses-adb-over-internet-to-exploit-thousands-of-android-devices/
¡¾ÍþвÇ鱨¡¿AvastÑо¿ÍŶӷ¢Ã÷еÄÎïÁªÍø½©Ê¬ÍøÂçTorii
AvastÑо¿ÍŶÓÐû²¼¹ØÓÚÐÂÎïÁªÍø½©Ê¬ÍøÂçToriiµÄÆÊÎö±¨¸æ¡£Torii×Ô2017Äê12ÔÂÆðÒ»Ö±»îÔ¾£¬Ëü¿ÉÒÔѬȾ¶àÖÖCPU¼Ü¹¹µÄ×°±¸£¬ÈçMIPS¡¢ARM¡¢x86¡¢x64¡¢PowerPCºÍSuperHµÈ¡£ToriiÊÇ×ÔVPNFilterºÍ×½ÃÔ²ØÒÔÀ´µÄµÚÈý¸öʵÏÖÁ˳¤ÆÚÐÔµÄÎïÁªÍø½©Ê¬ÍøÂ磬ÕâÒâζ×ÅËü¿ÉÒÔÔÚ×°±¸ÖØÆôºó¼ÌÐøÔËÐС£½«×°±¸¹Ì¼þµÄÉèÖÃÖØÖÃΪĬÈϳö³§ÉèÖÿÉÄÜ¿ÉÒÔɾ³ýËü¡£
https://blog.avast.com/new-torii-botnet-threat-research
¡¾Îó²î²¹¶¡¡¿Ë¼¿ÆÐû²¼Cisco IOSºÍIOS XEµÄ°ëÄê¶ÈÇ徲ת´ï£¬¹²ÐÞ¸´13¸öÎó²î
9ÔÂ26ÈÕ˼¿ÆÐû²¼Cisco IOSºÍIOS XEÈí¼þµÄ°ëÄê¶ÈÇ徲ת´ï£¬¹²ÐÞ¸´13¸öÇå¾²Îó²î¡£Ë¼¿ÆÔÚÿÄêµÄ3ÔºÍ9ÔµĵÚËĸöÐÇÆÚÈý¶¼»áÐû²¼ÆäCisco IOSºÍIOS XEÈí¼þµÄ°ëÄê¶ÈÇ徲ת´ï¡£±¾´Îת´ïÖÐÐÞ¸´µÄ13¸öÎó²îµÄÇå¾²ÆÀ¼¶£¨SIR£©¶¼Îª¸ß£¬ÀÖ³ÉʹÓÃÕâЩÎó²î½«»áµ¼ÖÂÌáȨ»ò¾Ü¾ø·þÎñ¡£ÏêϸÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£
https://tools.cisco.com/security/center/viewErp.x?alertId=ERP-69981
¡¾Çå¾²²¥±¨¡¿Å̹ÅÍŶÓÀÖ³ÉÔÚÔËÐÐiOS 12µÄiPhone XSÉÏÔ½Óü
ƾ֤Çå¾²Ñо¿Ö°Ô±Min(Spark) ZhengµÄÍÆÎÄ£¬Å̹ÅÍŶÓÀÖ³ÉÔÚÔËÐÐiOS 12µÄiPhone XSÉÏÔ½Óü¡£Ñо¿Ö°Ô±Í¸Â¶Ô½ÓüµÄÊÂÇéÔÀíÊÇÈÆ¹ýA12·ÂÉúоƬÖÐʵÑéµÄPAC·À»¤¹¦Ð§¡£±ðµÄ£¬ÓÉÓÚiPhone XSµÄÓ²¼þÓëiPhone XS MaxºÜÊÇÏàËÆ£¬Òò´Ë¸ÃÔ½ÓüÒªÁìÒ²ÊÊÓÃÓÚiPhone XS Max¡£ÏÖÔÚÉв»ÇåÎú¸ÃÍŶÓÊÇ·ñ»áÏò¹«ÖÚÐû²¼ÆäÔ½ÓüÒªÁì¡£
https://thehackernews.com/2018/09/ios12-iphone-jailbreak-exploit.html


¾©¹«Íø°²±¸11010802024551ºÅ