ÐÂSolarLeaksÍøÕ¾ÏúÊÛSolarWinds¹©¸øÁ´¹¥»÷ÖÐÊý¾Ý£»£»£» £»£» £»£»GoogleÅû¶Õë¶ÔWindowsºÍAndroidµÄË®¿Ó¹¥»÷

°ä²¼¹¦·ò 2021-01-14
1.ÐÂSolarLeaksÍøÕ¾ÏúÊÛSolarWinds¹©¸øÁ´¹¥»÷Öеĺ¹ÇàÊý¾Ý


1.jpg


ÐÂSolarLeaksÍøÕ¾ÏúÊÛSolarWinds¹©¸øÁ´¹¥»÷ÖÐMicrosoft¡¢Cisco¡¢FireEyeºÍSolarWindsµÈ¹«Ë¾µÄʧÇÔÊý¾Ý¡£¡£¡£¡£ ¡£¡£¡£¡£¸ÃÍøÕ¾ÒÔ60ÍòÃÀÔªµÄ¼ÛÖµÏúÊÛMicrosoftÔ´´úÂëºÍ´æ´¢¿â£¬£¬ £¬£¬£¬£¬ÒÔ5ÍòÃÀÔªµÄ¼ÛÖµÏúÊÛFireEyeµÄÔ´´úÂëºÍºì¶Ó¹¤¾ß£¬£¬ £¬£¬£¬£¬ÒÔ25ÍòÃÀÔªµÄ¼ÛÖµÏúÊÛSolarWindsÔ´´úÂëºÍ¿Í»§ÃÅ»§£¬£¬ £¬£¬£¬£¬²¢ÒÔ100ÍòÃÀÔªµÄ¼ÛÖµÏúÊÛÈ«Êýй¶Êý¾Ý¡£¡£¡£¡£ ¡£¡£¡£¡£solarleaks.netÓòÊÇͨ¹ý¶íÂÞ˹Fancy BearºÍCozy BearʹÓõÄÒÑ֪ע²áÉÌNJALLA½øÐÐ×¢²á¡£¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/solarleaks-site-claims-to-sell-data-stolen-in-solarwinds-attacks/


2.MimecastÔâµ½¹¥»÷£¬£¬ £¬£¬£¬£¬Microsoft 365 SSLÖ¤Êéй¶


2.jpg


µç×ÓÓʼþ°²È«¹«Ë¾MimecastÔâµ½¹¥»÷µ¼ÖÂMicrosoft 365 SSLÖ¤Êéй¶£¬£¬ £¬£¬£¬£¬Ó°ÏìÁËÔ¼10%µÄÓû§¡£¡£¡£¡£ ¡£¡£¡£¡£Mimecast³ÆÆäÒѾ­½¨ÒéʹÓô˻ùÓÚÖ¤ÊéµÄÏνӵÄMimecast¿Í»§Á¢¼´É¾³ýÏÖÓÐÏνÓ£¬£¬ £¬£¬£¬£¬²¢Ê¹Óøù«Ë¾ÌṩµÄÐÂÖ¤ÊéÀ´³ÁгÉÁ¢»ùÓÚÖ¤ÊéµÄÏνӡ£¡£¡£¡£ ¡£¡£¡£¡£MimecastûÓÐÖ¸³ö±»ÇÔÈ¡µÄÖ¤ÊéÀàÐÍ£¬£¬ £¬£¬£¬£¬µ«Æ¾¾ÝÉêÃ÷¿É´§Ä¦ÎªMimecastÓû§ÏνÓMicrosoft 365µÄ×ÔÐû¸æµÄÖ¤ÊéÖ®Ò»£¬£¬ £¬£¬£¬£¬¿É±»ÓÃÓÚÖÐÑëÈË£¨MiTM£©¹¥»÷¡£¡£¡£¡£ ¡£¡£¡£¡£Mimecast³Æ´ËÊ»¹ÔÚµ÷²éÖÓ×£¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/mimecast-discloses-microsoft-365-ssl-certificate-compromise/


3.GoogleÅû¶Õë¶ÔWindowsºÍAndroidÓû§µÄË®¿Ó¹¥»÷


3.png


Google Project ZeroÅû¶ÁË2020ÄêµÚÒ»¼¾¶ÈÖÐʹÓÃÁ˶à¸ö0dayºÍndayµÄË®¿Ó¹¥»÷¡£¡£¡£¡£ ¡£¡£¡£¡£Õâ´Î¹¥»÷»î¶¯Ê¹ÓÃÁËÁ½Ì¨·ì϶ÀûÓ÷þÎñÆ÷£¬£¬ £¬£¬£¬£¬Ò»Ì¨Õë¶ÔWindowsÓû§£¬£¬ £¬£¬£¬£¬Áíһ̨Õë¶ÔAndroidÓû§¡£¡£¡£¡£ ¡£¡£¡£¡£¸Ã·þÎñÆ÷ÀûÓÃÁËGoogle ChromeÖеÄËĸöäÖȾÆ÷µÄ·ì϶£¬£¬ £¬£¬£¬£¬WindowsÖеÄÁ½¸öɳºÐÌӱܷì϶£¬£¬ £¬£¬£¬£¬»¹ÓÐÒ»¸öÕë¶Ô½Ï¾É°æ±¾µÄAndroid OSÌáȨ¹¤¾ß°ü¡£¡£¡£¡£ ¡£¡£¡£¡£¸Ã¹¥»÷Á´ÖÐÀûÓõÄ0dayÔ̺¬Chrome TurboFanÖеķì϶£¨CVE-2020-6418£©¡¢WindowsÉϵÄ×ÖÌå·ì϶£¨CVE-2020-0938£©¡¢WindowsÉϵÄ×ÖÌå·ì϶£¨CVE-2020-1020£©ºÍWindows CSRSS·ì϶£¨CVE-2020-1027£©¡£¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/113342/hacking/project-zero-watering-hole-attack.html


4.SophosÅû¶Õë¶Ô°Í»ù˹̹°²×¿Óû§µÄ¼äµýÈí¼þ»î¶¯


4.png


Sophos×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸öеļäµýÈí¼þ»î¶¯£¬£¬ £¬£¬£¬£¬ÆäÖØÒªÖ¸±êÊǰͻù˹̹µÄAndroidÓû§¡£¡£¡£¡£ ¡£¡£¡£¡£ÕâЩ¼äµýÈí¼þ¼Ù×°³ÉÁ˰ͻù˹̹ʢÐеÄÀûÓ㬣¬ £¬£¬£¬£¬Èç°Í»ù˹̹¹«ÃñÃÅ»§¡¢×¢²áSIMs²é³­·¨Ê½¡¢°Í»ù˹̹µÚÈý·½ÎïÁ÷±£ÏÕÀûÓú͵»¸æ¹¦·òÀûÓõÈ£¬£¬ £¬£¬£¬£¬ÖØÒªÖ÷ÕÅΪ¼à¶½ºÍй¶ÊÜϰȾÉ豸ÖеÄÊý¾Ý¡£¡£¡£¡£ ¡£¡£¡£¡£ÆäÖУ¬£¬ £¬£¬£¬£¬Î±ÔìµÄ°Í»ù˹̹¹«ÃñÃÅ»§ÍøÀûÓûáµÁÈ¡Óû§µÄÉí·ÝÖ¤¡¢»¤ÕÕÊý¾Ý¡¢FacebookºÍÆäËûÉ罻ýÌåÕÊ»§µÄÍ´´¦¡£¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/pakistan-android-users-spyware-campaign-malicious-apps/


5.¶à¹ú¾¯·½½áºÏµ·»Ù°µÍøÉÏ×î´óµÄ°µÅÌDarkMarket


5.png


°Ä´óÀûÑÇ¡¢µ¤Â󡢵¹ú¡¢Ä¦¶û¶àÍß¡¢ÈðÊ¿¡¢ÎÚ¿ËÀ¼¡¢Ó¢¹úºÍÃÀ¹úµÄ¾¯·½½áºÏµ·»ÙÁ˰µÍøÉÏ×î´óµÄ°µÅÌDarkMarket¡£¡£¡£¡£ ¡£¡£¡£¡£DarkMarketÕ¼Óнü50ÍòÓû§ºÍ2400¶à¼ÒÉÌ»§£¬£¬ £¬£¬£¬£¬½øÐÐÁËÖÁÉÙ32Íò±ÊÂòÂô£¬£¬ £¬£¬£¬£¬Éæ¼°4650¶à¸ö±ÈÌØ±ÒºÍ12800¸ömonero£¨×ܽð¶î³¬¹ý1.7ÒÚÃÀÔª£©¡£¡£¡£¡£ ¡£¡£¡£¡£µÂ¹ú¾¯·½ÓÚÖÜÄ©Ôڵ¹úÓ뵤Âó±ßÚï¿ÛÁôÁËÒ»Ãû34ËêµÄ°Ä´óÀûÑǹ«Ãñ£¬£¬ £¬£¬£¬£¬Îª°µÍøµÄ¾­ÓªÕߣ¬£¬ £¬£¬£¬£¬²¢ÔÚĦ¶û¶àÍߺÍÎÚ¿ËÀ¼½É»ñÁËÆäʹÓõÄ20¶ą̀·þÎñÆ÷¡£¡£¡£¡£ ¡£¡£¡£¡£Ä¿Ç°£¬£¬ £¬£¬£¬£¬µ÷²éÈÔÔÚ½øÐÐÖÓ×£¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/darkmarket-taken-down/


6.Adobe°ä²¼°²È«¸üУ¬£¬ £¬£¬£¬£¬½¨¸´¶à¿î²úÆ·ÖеÄ7¸ö·ì϶


6.png


Adobe°ä²¼°²È«¸üУ¬£¬ £¬£¬£¬£¬½¨¸´ÁËPhotoshop¡¢IllustratorºÍAdobe BridgeµÈ¶à¿îÀûÓÃÖеÄ7¸ö·ì϶¡£¡£¡£¡£ ¡£¡£¡£¡£ÆäÖÐ×îÑϳÁµÄΪAdobe Campaign ClassicÖеķþÎñÆ÷¶ËÒªÇóαÔì·ì϶£¨CVE-2021-21009£©¡£¡£¡£¡£ ¡£¡£¡£¡£´Ë±í£¬£¬ £¬£¬£¬£¬»¹½¨¸´ÁËPhotoshopÖеĶѻº³åÇøÒç¶Âí½Å£¨CVE-2021-21006£©¡¢IllustratorÖв»ÊܿصÄËÑË÷õè¾¶ÔªËØ·ì϶£¨CVE-2021-21007£©¡¢Adobe BridgeÖеÄÔ½½çдÈë·ì϶CVE-2021-21012ºÍCVE-2021-21013£©µÈ¡£¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/adobe-critical-flaws-flash-player/162958/