×êÑÐÈËÔ±·¢ÏÖ¿ÉÀûÓÃChrome SyncÖ°ÄÜÇÔÈ¡Óû§Êý¾Ý £»£»£»£»£»£»°ÍÎ÷ÄÜÔ´¹«Ë¾CopelºÍEletrobrasÔâµ½ÀÕË÷Èí¼þ¹¥»÷

°ä²¼¹¦·ò 2021-02-07

1.×êÑÐÈËÔ±·¢ÏÖ¿ÉÀûÓÃChrome SyncÖ°ÄÜÇÔÈ¡Óû§Êý¾Ý


1.png


°²È«×êÑÐÈËÔ±Bojan Zdrnja·¢ÏÖºÚ¿Í¿ÉÀÄÓÃGoogle Chrome SyncÖ°ÄÜÀ´ÇÔÈ¡Óû§Êý¾Ý¡£ ¡£¡£¡£¡£Chrome Sync¿ÉÔÚÓû§µÇ¼GoogleÕÊ»§ºó×Ô¶¯Í¬²½ÆäÊéÇ©¡¢º¹Çà¼Í¼¡¢ÃÜÂëºÍÆäËûÉèÖᣠ¡£¡£¡£¡£Zdrnja°µÊ¾ºÚ¿ÍÀûÓüÙװΪForcepoint Endpoint Chrome WindowsÀ©´óµÄ¶ñÒ⸽¼þÓëÔ¶³ÌºÅÁîºÍ½ÚÔ죨C£¦C£©·þÎñÆ÷½øÐÐͨѶ£¬£¬£¬£¬£¬ £¬£¬£¬ÒÔ´ÓÖ¸±êä¯ÀÀÆ÷ÇÔÈ¡Óû§Êý¾Ý¡£ ¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ £¬£¬£¬ÎªÁËÔ¤·À¸ÃÀ©´ó±»Googleɾ³ý£¬£¬£¬£¬£¬ £¬£¬£¬ºÚ¿ÍûÓÐʹÓÃChrome Web Store£¬£¬£¬£¬£¬ £¬£¬£¬¶øÊǽ«À©´ó·ÅÔÚ±¾µØµÄÒ»¸öÎļþ¼ÐÖУ¬£¬£¬£¬£¬ £¬£¬£¬¶øºóÖ±½Ó´ÓChrome½øÐÐ×°Öᣠ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/malicious-chrome-extensions-steal-data-sync-feature/


2.΢ÈíÖÒ¸æÀûÓÃOAuth Office 365µÄ´¹µö¹¥»÷»î¶¯Ôö¶à


2.png


΢ÈíÖÒ¸æ½ü¼¸¸öÔÂÒÔÀ´ÀûÓÃOAuth Office 365µÄ´¹µö¹¥»÷»î¶¯Ôö¶à¡£ ¡£¡£¡£¡£OAuthÍøÂç´¹µöÊÇÒ»ÖÖ»ùÓÚÀûÓ÷¨Ê½µÄ¹¥»÷±äÌ壬£¬£¬£¬£¬ £¬£¬£¬¹¥»÷ÕßÓÕʹָ±êµã»÷¶ñÒâOAuthÀûÓÃÒÔÇÔÈ¡ÆäOffice 365ÕÊ»§Æ¾Ö¤¡£ ¡£¡£¡£¡£ÕâЩ¹¥»÷»î¶¯Îª2020Äê9ÔÂÖÁ12ÔÂÖ®¼äµÄÁ½ÂÖ¹¥»÷»î¶¯µÄÒ»²¿ÃÅ£¬£¬£¬£¬£¬ £¬£¬£¬ÆäÖÐÖ®Ò»¼ÙÒâÁËÄ«Î÷¸çµÄ˰ÊÕÖÎÀí·þÎñÀ´Õë¶ÔÎ÷°àÑÀÈË£¬£¬£¬£¬£¬ £¬£¬£¬ÁíÒ»ÂÖÕë¶ÔÁË×éÖ¯µÄͶ×ÊÍŶӡ£ ¡£¡£¡£¡£Îª´Ë£¬£¬£¬£¬£¬ £¬£¬£¬Î¢Èí²ÉÈ¡ÁË˾·¨Ðж¯£¬£¬£¬£¬£¬ £¬£¬£¬¹Ø¹ØÁËÍйܶñÒâÀûÓ÷¨Ê½µÄ6¸öÓòÃû£¬£¬£¬£¬£¬ £¬£¬£¬²¢½ûÓÃÁË·¢ÏֵĶñÒâOAuthÀûÓᣠ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-warns-of-increasing-oauth-office-365-phishing-attacks/


3.°ÍÎ÷ÄÜÔ´¹«Ë¾CopelºÍEletrobrasÔâµ½ÀÕË÷Èí¼þ¹¥»÷


3.png


°ÍÎ÷Á½¼ÒÖØÒªµÄÄÜÔ´¹«Ë¾CopelºÍEletrobrasÓÚÉÏÖÜÔâµ½ÀÕË÷Èí¼þ¹¥»÷¡£ ¡£¡£¡£¡£¾ÍEletrobras¶øÑÔ£¬£¬£¬£¬£¬ £¬£¬£¬¹¥»÷²úÉúÔÚÆäEletronuclear×Ó¹«Ë¾£¬£¬£¬£¬£¬ £¬£¬£¬Ó°ÏìÁ˲¿ÃÅ·þÎñÆ÷£¬£¬£¬£¬£¬ £¬£¬£¬µ«ÊÇÆäºËµç³§Angra 1ºÍAngra 2µÄÔËӪûÓÐÊܵ½Ó°Ïì¡£ ¡£¡£¡£¡£CopelÔò°µÊ¾ÆäϰȾÁËDarksideÀÕË÷Èí¼þ£¬£¬£¬£¬£¬ £¬£¬£¬ºÚ¿Í³ÆÆäÒÑÇÔÈ¡Á˳¬¹ý1000GBµÄÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬ £¬£¬£¬ÀýÈç´¿Îı¾ÃÜÂë¡¢±¸·Ý¹æ»®¡¢¹¦·ò±íÒÔ¼°¸ß²ãÖÎÀíÈËÔ±ºÍ¿Í»§µÄÓ×ÎÒ¾ßÌåÐÅÏ¢¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/eletrobras-copel-energy-companies-hit-by-ransomware-attacks/


4.Realtek Wi-FiÄ£¿£¿£¿£¿£¿ £¿é´æÔÚ¶à¸ö·ì϶£¬£¬£¬£¬£¬ £¬£¬£¬¿É±»ÓÃÀ´½ÚÔìÉ豸


4.png


ÒÔÉ«ÁÐÎïÁªÍø°²È«¹«Ë¾VdooµÄ×êÑÐÈËÔ±ÔÚRealtek RTL8195A Wi-FiÄ£¿£¿£¿£¿£¿ £¿éÖз¢ÏÖÁË6¸ö·ì϶£¬£¬£¬£¬£¬ £¬£¬£¬ÕâЩ·ì϶¿ÉÄÜÒѱ»ÓÃÀ´»ñµÃrootȨÏÞ²¢½ÚÔìÉ豸µÄÎÞÏßͨѶ¡£ ¡£¡£¡£¡£ÆäÖÐ×îΪÑϳÁµÄÊÇÔ¶³Ì²Ö¿âÒç¶Âí½Å£¨CVE-2020-9395£©£¬£¬£¬£¬£¬ £¬£¬£¬¿É±»ÓÃÀ´ÊÕÊÜÉ豸¡£ ¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ £¬£¬£¬×êÑÐÈËÔ±»¹·¢ÏÖÁ˻ؾø·þÎñ·ì϶ºÍ¶à¸ö¿ÉÖ´ÐÐËÁÒâ´úÂëµÄ·ì϶£¨CVE-2020-25853¡¢CVE-2020-25854¡¢CVE-2020-25855¡¢CVE-2020-25856ºÍCVE-2020-25857£©¡£ ¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬ £¬£¬£¬ RealtekÒѰ䲼Õë¶ÔÕâЩ·ì϶µÄ°²È«¸üС£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/114280/security/realtek-rtl8195a-flaws.html


5.Unit42°ä²¼ÓйØCVE-2020-25213·ì϶µÄ·ÖÎö»ã±¨


5.png


Unit42°ä²¼ÁËÓйØCVE-2020-25213·ì϶µÄ·ÖÎö»ã±¨¡£ ¡£¡£¡£¡£¸Ã·ì϶ԴÓÚWordPress File Manager²å¼þ¿É½«elFinder¿âµÄconnector.minimal.php.distÉϵÄÎļþÀ©´óÃû³Á¶¨ÃûΪ.php£¬£¬£¬£¬£¬ £¬£¬£¬²¢Ö±½ÓÖ´ÐÓ×£ ¡£¡£¡£¡£ÓÉÓÚûÓнӼûÏÞ¶È£¬£¬£¬£¬£¬ £¬£¬£¬Òò¶øÈκÎä¯ÀÀWeb·þÎñÆ÷µÄÈ˶¼Äܹ»Ö´ÐÐÉÏ´«µÄÎļþ¡£ ¡£¡£¡£¡£¹¥»÷Õßͨ³£ÀûÓÃÕâ¸ö·ì϶ÉÏ´«webshell£¬£¬£¬£¬£¬ £¬£¬£¬ÒÔ×°ÖÃÓÃÓÚ¼ÓÃܽٳֹ¥»÷µÄ¶ñÒâÈí¼þKinsing¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/cve-2020-25213/


6.Claroty°ä²¼2020ϰëÄê¶ÈICS·çÏպͷì϶µÄ»ØÊ׻㱨


6.png


Claroty°ä²¼ÁË2020ϰëÄê¶ÈICS·çÏպͷì϶µÄ»ØÊ׻㱨¡£ ¡£¡£¡£¡£¸Ã»ã±¨Í³¼ÆÁËÀ´×Ô59¸öICS¹©¸øÉ̵Ä449¸ö·ì϶£¨ÕûÄê¹²893¸ö£©£¬£¬£¬£¬£¬ £¬£¬£¬2018ÕûÄê¹²Åû¶ÁË672¸ö·ì϶£¬£¬£¬£¬£¬ £¬£¬£¬¶ø2019ÄêΪ716¸ö¡£ ¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬ £¬£¬£¬ICSÅû¶ÐÅÏ¢±È2018Äêͬ±ÈÔö³¤Á˽ü33£¥£¬£¬£¬£¬£¬ £¬£¬£¬Åû¶×î¶àµÄÐÐҵΪ¹Ø¼üµÄÔì×÷Òµ¡¢ÄÜÔ´ÐÐÒµ¡¢Ë®ºÍ·ÏË®ÐÐÒµÒÔ¼°Ã³Ò×ÉèÊ©¡£ ¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ £¬£¬£¬ËùÅû¶µÄICS·ì϶ÖÐÓÐ72£¥¿É±»Ô¶³ÌÀûÓ㬣¬£¬£¬£¬ £¬£¬£¬ÓÐ47£¥µÄ·ì϶ӰÏìÁËLevels 1ºÍ2µÄPurdueÄ£ÐÍ£¬£¬£¬£¬£¬ £¬£¬£¬ÓÐ76£¥µÄ·ì϶²»±ØÒªÉí·ÝÑéÖ¤¼´¿É½øÐÐÀûÓᣠ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://security.claroty.com/biannual-ics-risk-vulnerability-report-2H-2020