Cisco½¨¸´SMB VPN·ÓÉÆ÷ÖеĶà¸ö´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»°²È«¹«Ë¾StormshieldÔâµ½¹¥»÷£¬£¬£¬£¬£¬²¿ÃÅÔ´´úÂëй¶
°ä²¼¹¦·ò 2021-02-051.Cisco½¨¸´SMB VPN·ÓÉÆ÷ÖеĶà¸ö´úÂëÖ´Ðзì϶

Cisco°ä²¼°²È«¸üУ¬£¬£¬£¬£¬½¨¸´Ó°ÏìÁ˶à¸öÓ×ÐÍÆóÒµVPN·ÓÉÆ÷µÄ´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ·ì϶Ô̺¬CVE-2021-1289¡¢CVE-2021-1290¡¢CVE-2021-1291¡¢CVE-2021-1292¡¢CVE-2021-1293¡¢CVE-2021-1294ºÍCVE-2021-1295¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖÐ×îÑϳÁµÄ·ì϶ÊÇÓÉÓÚ¶Ô»ùÓÚWebµÄÖÎÀí½Ó¿ÚµÄHTTPÒªÇóÑéÖ¤²»ÕýÈ·µ¼Öµģ¬£¬£¬£¬£¬¿É±»ÓÃÀ´ÒÔrootȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬Cisco»¹½¨¸´ÁËÓ°ÏìÆäËû·ÓÉÆ÷ºÍIOS XRÈí¼þÖеĶà¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/cisco-fixes-critical-code-execution-bugs-in-smb-vpn-routers/
2.SudoÌáȨ·ì϶ӰÏìmacOS Big Sur£¬£¬£¬£¬£¬ÉÐδ°ä²¼²¹¶¡

SudoÌáȨ·ì϶ҲӰÏìÁË×îа汾µÄmacOS Big Sur£¬£¬£¬£¬£¬ÉÐδ°ä²¼²¹¶¡·¨Ê½¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶±»×·×ÙΪCVE-2021-3156£¬£¬£¬£¬£¬±ðÃûBaron Samedit£¬£¬£¬£¬£¬ÊÇ»ùÓڶѵĻº³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬¿Éʹ±¾µØÓû§»ñµÃrootȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£Hacker House×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬Äܹ»½«sudoÓësudoedit³ÉÁ¢·ûºÅÁ´½Ó´¥·¢¶ÑÒç³ö£¬£¬£¬£¬£¬°ÑÓû§µÄȨÏÞÉý¼¶µ½1337 uid=0À´ÀûÓø÷ì϶¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°ÒѰ䲼ÁËÕë¶ÔUbuntu¡¢DebianºÍFedoraµÈ¶à¸öLinuxϵͳµÄ²¹¶¡·¨Ê½£¬£¬£¬£¬£¬µ«¾ù²»ºÏÓÃÓÚmacOS¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/recent-sudo-vulnerability-affects-apple-cisco-products
3.°²È«¹«Ë¾StormshieldÔâµ½¹¥»÷£¬£¬£¬£¬£¬²¿ÃÅÔ´´úÂëй¶

·¨¹ú°²È«¹«Ë¾Stormshield³ÆÆäÔâµ½¹¥»÷£¬£¬£¬£¬£¬¿Í»§µÄÐÅÏ¢ºÍSNS·À»ðǽµÄÔ´´úÂëй¶¡£¡£¡£¡£¡£¡£¡£¡£StormshieldÊÇ·¨¹úµ±¾ÖÖØÒªµÄ°²È«·þÎñºÍÍøÂ簲ȫÉ豸ÌṩÉÌ£¬£¬£¬£¬£¬ÆäÔÚÓë·¨¹úÍøÂç¹ú¶Èµý±¨¾Öһ·µ÷²é´ËÊÂÎñ£¬£¬£¬£¬£¬²¢ÆÀ¹À¸Ã·ì϶¶Ôµ±¾ÖϵͳµÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£Stormshield°µÊ¾£¬£¬£¬£¬£¬ËûÃÇÒѾ¸ü»»ÁËÓÃÀ´Ç©ÊðSNSÈí¼þ¸üеÄÊý×ÖÖ¤Ê飬£¬£¬£¬£¬µ½Ä¿Ç°ÎªÖ¹ºÚ¿Í»¹Ã»ÓжԴúÂë½øÐд۸쬣¬£¬£¬£¬Ò²Ã»ÓÐÈκÎStormshield²úÆ·Êܵ½ÇÖº¦¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
zdnet.com/article/security-firm-stormshield-discloses-data-breach-theft-of-source-code/
4.н©Ê¬ÍøÂçMatryoshÕë¶ÔADB¶³öµÄAndroidÉ豸

н©Ê¬ÍøÂçMatryoshÕë¶ÔAndroid Debug Bridge½çÃæÂ¶³öµÄAndroidÉ豸¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÔÚ»¥ÁªÍøÉÏɨÃèADB½çÃæÎª»î¶¯×´Ì¬µÄAndroidÉ豸£¬£¬£¬£¬£¬²¢Ôڳɹ¦ÏνÓÖ¸±êÉ豸ºóÏÂÔØ×°ÖöñÒâpayload¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ÆäʹÓÃÁËTorÍøÂçÀ´°µ²ØC&C·þÎñÆ÷£¬£¬£¬£¬£¬²¢Ê¹ÓÃÒ»¸ö¶à²ãµÄ¹ý³ÌÀ´»ñÈ¡Õâ¸ö·þÎñÆ÷µÄµØÖ·£¬£¬£¬£¬£¬Òò¶ø¸Ã½©Ê¬ÍøÂçµÄÃû×ÖÒ²ÆðÔ´ÓÚ¶íÂÞ˹Ì×ÍÞ¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ´óÎÞÊý»ùÓÚAndroidµÄÉ豸²»Ö§³ÖÔÚOSÑ¡ÏîÖÐÉèÖÃADBÖ°ÄÜ£¬£¬£¬£¬£¬Òò¶øºÜ¶àϵͳÔÚ½«À´ÊýÄêÄÚÈÔÒ×Ôâµ½ÀÄÓᣡ£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/android-devices-ensnared-in-ddos-botnet/
5.Defender ATPÎó½«Chrome¶à¸ö¸üÐÂÏóÕ÷ΪPHPºóÃÅ

Microsoft Defender ATPÎó½«Chrome¶à¸ö¸üÐÂÏóÕ÷ΪPHPºóÃÅ¡£¡£¡£¡£¡£¡£¡£¡£Æ¾¾Ý¼ì²âÁ˾ֵĽØÍ¼£¬£¬£¬£¬£¬Microsoft Defender¼ì²âµ½Chrome v88.0.4324.146¸üаüµÄ¶à¸öÎļþÔ̺¬ÁËÒ»¸öÃûΪPHP/Funvalget.A.µÄͨÓúóÃÅľÂí¡£¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬Æä½«Chrome sl.pak˵»°ÎļþÎóÏóÕ÷ΪºóÃÅ·¨Ê½£¬£¬£¬£¬£¬²¢Á¢¼´²ÉÈ¡ÁËÏìÓ¦´ëÊ©£¬£¬£¬£¬£¬×Ô¶¯¸ôÀë¼ì²âµ½µÄÎļþ¡£¡£¡£¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬Microsoft°ä·¢ÉêÃ÷³Æ´ËÊÂÎñΪ×Ô¶¯»¯ÎÊÌ⣬£¬£¬£¬£¬ÃýÎ󵨽«×°Ö÷¨Ê½°ü¹éÀàΪ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬ÎÊÌâÏÖÒѽâ¾ö¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-defender-atp-detects-chrome-updates-as-php-backdoors/
6.Google°ä²¼2020ÄêÔÚÒ°ÀûÓõÄÁãÈÕ·ì϶µÄ»ØÊ׻㱨

Google Project Zero°ä²¼ÁË2020ÄêÔÚÒ°ÀûÓõÄÁãÈÕ·ì϶µÄ»ØÊ׻㱨¡£¡£¡£¡£¡£¡£¡£¡£»ã±¨ÏÔʾ£¬£¬£¬£¬£¬2020Äê×ܹ²¼ì²âµ½24¸öÒѱ»ÀûÓõÄÁãÈÕ·ì϶£¬£¬£¬£¬£¬ÆäÖÐ6ÖÖÊÇǰ¼¸ÄêËùÅû¶µÄ·ì϶µÄ±äÖÖ£¬£¬£¬£¬£¬±ðÀëΪInternet ExplorerÖеÄCVE-2020-0674¡¢»ðºüÖеÄCVE-2020-6820¡¢¹È¸èä¯ÀÀÆ÷ÖеÄCVE-2020-6572¡¢WindowsÖеÄCVE-2020-0986¡¢FreetypeÖеÄCVE-2020-15999ºÍÆ»¹ûSafariÖеÄCVE-2020-27930¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾Ä³Ð©·ì϶ֻ±ØÒª¸ü¸ÄÒ»»òÁ½ÐдúÂë¾ÍÄܹ»³ÉΪеķì϶£¬£¬£¬£¬£¬Òò¶ø¶Ô·ì϶½øÐиü³¹µ×µÄµ÷²éºÍ½¨¸´£¬£¬£¬£¬£¬Ôò¿ÉÄÜÔ¤·ÀËÄ·ÖÖ®Ò»µÄ·ì϶µÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://googleprojectzero.blogspot.com/2021/02/deja-vu-lnerability.html


¾©¹«Íø°²±¸11010802024551ºÅ