Crystal Valley Farm CoopÔâµ½ÀÕË÷Èí¼þ¹¥»÷£ºAppleÐû²¼¶à¿î²úÆ·Îó²î
Ðû²¼Ê±¼ä 2021-09-24VMwareÐÞ¸´vCenter ServerÖÐÑÏÖØµÄÎļþÉÏ´«Îó²î
VMwareÓÚ±¾ÖܶþÐû²¼Çå¾²¸üУ¬£¬£¬£¬ÐÞ¸´vCenter ServerºÍCloud FoundationÖеÄ19¸öÎó²î¡£¡£¡£ÆäÖÐ×îΪÑÏÖØµÄÊÇvCenter ServerÖеÄí§ÒâÎļþÉÏ´«Îó²î(CVE-2021-22005)£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÍøÂç»á¼û¶Ë¿Ú443µÄÉÏ´«ÌØÖÆÎļþÀ´Ö´ÐдúÂë¡£¡£¡£±ðµÄ£¬£¬£¬£¬»¹ÐÞ¸´ÁËÍâµØÌáȨÎó²î£¨CVE-2021-21991£©¡¢·´ÏòÊðÀíÈÆ¹ýÎó²î£¨CVE-2021-22006£©¡¢API¶ËµãÎó²î£¨CVE-2021-22011£©ºÍAPIÐÅϢй¶Îó²î£¨CVE-2021-22012£©µÈ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/09/vmware-warns-of-critical-file-upload.html
AppleÐû²¼Çå¾²¸üУ¬£¬£¬£¬ÐÞ¸´¶à¿î²úÆ·ÖеÄRCEµÈÎó²î
AppleÓÚ9ÔÂ20ÈÕÐû²¼Çå¾²¸üУ¬£¬£¬£¬ÐÞ¸´ÁËSafari 15¡¢Xcode 13¡¢tvOS 15¡¢watchOS 8¡¢iOS 15¡¢iPadOS 15ºÍiTunes 12.12ÖеĶà¸öÎó²î¡£¡£¡£ÆäÖаüÀ¨Safari 15ÖеÄÄÚ´æË𻵵¼ÖµÄí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-30846ºÍCVE-2021-30851µÈ£©¡¢tvOS 15ÖеÄDoSÎó²î£¨CVE-2013-0340£©ºÍɳºÐÈÆ¹ýÎó²î£¨CVE-2021-30854£©£¬£¬£¬£¬ÒÔ¼°iOS 15ºÍiPadOS 15ÖеĴúÂëÖ´ÐÐÎó²î£¨CVE-2021-30837ºÍCVE-2021-30811£©µÈ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2021/09/21/apple-releases-security-updates-multiple-products
¶íÂÞ˹APT×éÖ¯TurlaʹÓÃкóÃŹ¥»÷ÃÀ¡¢µÂºÍ°¢¸»º¹
Cisco TalosÔÚ9ÔÂ21ÈÕÅû¶Á˶íÂÞ˹APT×éÖ¯TurlaʹÓÃкóÃÅTinyTurla¹¥»÷ÃÀ¡¢µÂºÍ°¢¸»º¹µÄ»î¶¯¡£¡£¡£Turla×Ô2004ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬£¬¹¥»÷ÁËÖж«¡¢ÑÇÖÞ¡¢Å·ÖÞ¡¢±±ÃÀºÍÄÏÃÀµÈµØÇøµÄÄ¿µÄ¡£¡£¡£Ñо¿Ö°Ô±Í¨¹ýÒ£²â·¢Ã÷Á˺óÃÅ£¬£¬£¬£¬µ«Éв»ÇåÎúÆäÈ·ÇеÄ×°Ö÷½·¨£¬£¬£¬£¬½öÖªµÀ¹¥»÷ÕßʹÓÃ.batÎļþÈö²¥ºóÃÅ¡£¡£¡£¸ÃºóÃÅαװ³ÉMicrosoft DLL£¬£¬£¬£¬²¢ÃüÃûΪw64time.dll£¬£¬£¬£¬¿ÉÉÏ´«ºÍÖ´ÐÐÎļþ¡¢½¨Éè×ÓÁ÷³ÌºÍÇÔÈ¡Êý¾ÝµÈ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2021/09/tinyturla.html
DeFiƽ̨pNetwork³ÆÆäÔâµ½¹¥»÷ËðʧÁè¼Ý1200ÍòÃÀÔª
DeFiƽ̨pNetworkÔÚ9ÔÂ19ÈÕÐû²¼Twitter³ÆÆäÔâµ½¹¥»÷£¬£¬£¬£¬ËðʧÁè¼Ý1200ÍòÃÀÔª¡£¡£¡£¸Ãƽ̨³Æ£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÆä´úÂë¿âÖеÄÎó²î¹¥»÷ÁËpBTC-on-BSC £¬£¬£¬£¬²¢ÇÔÈ¡ÁË277¸öBTC¡£¡£¡£pNetwork»¹ÌåÏÖ£¬£¬£¬£¬ÈôÊǹ¥»÷ÕßÄÜÍ˻ر»µÁ×ʽ𣬣¬£¬£¬ËûÃÇÔ¸Ö§¸¶×ܽð¶îµÄ12.5%£¨150ÍòÃÀÔª£©×÷ΪÉͽ𡣡£¡£9ÔÂ22ÈÕ£¬£¬£¬£¬¸ÃÍŶÓÐû²¼ÁËÓйش˴ι¥»÷ÊÂÎñµÄÊӲ챨¸æ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/hacker-steals-12m-from-defi/
ÃÀ¹úCrystal Valley Farm CoopÔâµ½ÀÕË÷Èí¼þ¹¥»÷
Crystal Valley Farm CoopÔÚ9ÔÂ21ÈÕ͸¶ÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬³ÉΪ±¾Öܵڶþ¸öÔâµ½¹¥»÷µÄũҵÏàÖúÉç¡£¡£¡£¹¥»÷±¬·¢ÔÚÉÏÖÜÈÕ£¨9ÔÂ19ÈÕ£©£¬£¬£¬£¬ÆäÖ§¸¶ÏµÍ³Êܵ½Ó°Ï죬£¬£¬£¬ÎÞ·¨Ê¹ÓÃVisa¡¢MastercardºÍDiscoverÐÅÓÿ¨¸¶¿î¡£¡£¡£×èÖ¹±¾ÖÜÈýÏÂÖç¸Ã¹«Ë¾µÄÍøÕ¾ÈÔ´¦ÓڹرÕ״̬£¬£¬£¬£¬ÏÖÔÚÉв»ÇåÎú´Ë´Î¹¥»÷±³ºóµÄÀÕË÷ÔËÓªÍŻ¡£¡£±¾ÖÜÒ»£¬£¬£¬£¬NEW CooperativeÔøÔâµ½BlackMatter¹¥»÷£¬£¬£¬£¬²¢±»ÀÕË÷590ÍòÃÀÔª¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/second-farming-cooperative-shut-down-by-ransomware-this-week/
Recorded FutureÐû²¼TAG-28¹¥»÷Ó¡¶ÈµÄÆÊÎö±¨¸æ
Recorded FutureÓÚ9ÔÂ21ÈÕÐû²¼Á˹ØÓÚTAG-28¹¥»÷Ó¡¶ÈµÄÆÊÎö±¨¸æ¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬TAG-28¿ÉÄÜÓëÕë¶ÔÓ¡¶ÈýÌ弯ÍÅBennett Coleman And Co Ltd(BCCL£¬£¬£¬£¬ÓÖ³ÆÊ±´ú¼¯ÍÅ£©¡¢Ó¡¶ÈÉí·Ýʶ±ð»ú¹¹UIDAIºÍÖÐÑë°î¾¯Ô±¾ÖµÄ¹¥»÷»î¶¯Óйء£¡£¡£±ðµÄ£¬£¬£¬£¬Óë2020ÄêÏà±È£¬£¬£¬£¬2021ÄêÕë¶ÔÓ¡¶È×éÖ¯µÄÒÉËÆÓɹú¼Ò×ÊÖúµÄ¹¥»÷»î¶¯ÔöÌíÁË261%£¬£¬£¬£¬¶ø¸ÃÊý¾Ý´Ó2019ÄêÖÁ2020ÄêÔöÌíÁË120%¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.recordedfuture.com/china-linked-tag-28-targets-indias-the-times-group/