΢Èí3Ô°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´Ô̺¬2¸ö0dayÔÚÄÚµÄ82¸ö·ì϶£»£» £»£»£»unit42°ä²¼ÓйØdnsmasq·ì϶µÄ·ÖÎö»ã±¨

°ä²¼¹¦·ò 2021-03-10

1.΢Èí3Ô°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´Ô̺¬2¸ö0dayÔÚÄÚµÄ82¸ö·ì϶


1.jpg


΢Èí°ä²¼ÁË3Ô°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´ÁËÔ̺¬2¸ö0dayÔÚÄÚµÄ82¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ2¸ö0day±ðÀëΪInternet ExplorerÖеÄÄÚ´æ°Ü»µ·ì϶£¨CVE-2021-26411£©ºÍWindows Win32kÖеÄÌØÈ¨ÌáÉý·ì϶£¨CVE-2021-27077£©£¬£¬£¬£¬£¬£¬¾ÝϤǰÕßÒѹ«¿ªÓÃÓÚ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬Î¢Èí»¹½¨¸´ÁËAzure SphereÖеĴúÂëÖ´Ðзì϶£¨CVE-2021-27074ºÍCVE-2021-27080£©¡¢OpenType×ÖÌå½âÎöÖÐÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-26876£©ºÍHyper-VÖеÄÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2021-26867£©µÈ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-march-2021-patch-tuesday-fixes-82-flaws-2-zero-days/    


2.unit42°ä²¼ÓйØdnsmasq·ì϶µÄ·ÖÎö»ã±¨


2.jpg


unit42°ä²¼ÓйØDNS¼Ù×°£¨dnsmasq£©·ì϶µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£DNS¼Ù×°£¨dnsmasq£©ÊÇÒ»ÖÖ¿í·ºÊ¹ÓõĿªÔ´DNS½âÎöÆ÷£¬£¬£¬£¬£¬£¬ÎªºÜ¶àÏîÄ¿ºÍÓ²¼þËùʹÓ㬣¬£¬£¬£¬£¬ÈçKubernetesºÍ·ÓÉÆ÷µÈ²úÆ·¡£¡£¡£¡£¡£¡£¡£¡£×î½ü×êÑÐÈËÔ±·¢ÏÖÁËÐÂÎÊÌ⣬£¬£¬£¬£¬£¬Ê¹µÃdnsmasqÈÝÒ×Êܵ½¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶¿É·ÖΪÁ½À࣬£¬£¬£¬£¬£¬±ðÀëΪDNSºÍ̸ִÐÐÖеķì϶CVE-2020-25684¡¢CVE-2020-25685ºÍCVE-2020-25686£¬£¬£¬£¬£¬£¬ÒÔ¼°µ¼ÖÂDoS¹¥»÷µÄ»º³åÇøÒç¶Âí½ÅCVE-2020-25681¡¢CVE-2020-25682¡¢CVE-2020-25683ºÍCVE-2020-25687¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/overview-of-dnsmasq-vulnerabilities-the-dangers-of-dns-cache-poisoning/


3.Edgescan°ä²¼2020-2021Äê·ì϶ͳ¼ÆµÄ·ÖÎö»ã±¨


3.jpg


Edgescan°ä²¼ÁË2020-2021Äê·ì϶ͳ¼ÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£»ã±¨½ÒʾÁË2020ÄêÒÔÀ´µÄ·ì϶µÄͳ¼ÆÊý¾ÝºÍÇ÷Ïò£¬£¬£¬£¬£¬£¬²¢´ÓÒÑÖª·ì϶£¨CVE£©¡¢¶ñÒâÈí¼þ¡¢ÀÕË÷Èí¼þºÍ¿É¼ûÐԽǶȣ¨¹«¿ªµÄ·þÎñ£©Éî¿Ì×êÑÐÁË·ì϶ָ±ê¡£¡£¡£¡£¡£¡£¡£¡£2020ÄêÔ¶³Ì×ÀÃæ£¨RDPºÍSSH£©µÄ¶³öÔö³¤ÁË40%£¬£¬£¬£¬£¬£¬ÓÐ21070¸ö»¥ÁªÍø¶Ëµã¶³öÁËÊý¾Ý¿âϵͳ¡£¡£¡£¡£¡£¡£¡£¡£È¥Äê·¢ÏÖµÄ×î³£¼ûµÄ·ì϶ÊÇLogjam (CVE-2015-4000)£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»¸öʹÓÃDiffie-HellmanÃÜÔ¿»¥»»ÃÜÂëϵͳµÄ·ì϶£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÖÐÑëÈ˹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://info.edgescan.com/vulnerability-stats-report-2021


4.×êÑÐÈËÔ±·¢ÏÖUnityMinerÀûÓÃQNAP NASÖеķì϶ÍÚ¿ó


4.jpg


×êÑÐÈËÔ±·¢ÏÖÀûÓöñÒâÈí¼þUnityMinerÕë¶Ôδ´ò²¹¶¡µÄQNAPÍøÂçÏνӴ洢£¨NAS£©É豸µÄ¼ÓÃÜÇ®±Ò¶ñÒâÈí¼þ»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯Éæ¼°µ½ÁË2¸öδ¾­ÊÚȨµÄÔ¶³ÌºÅÁîÖ´Ðзì϶£¨CVE-2020-2506£¦CVE-2020-2507£©£¬£¬£¬£¬£¬£¬Ó°Ïì2020Äê8ÔÂ֮ǰµÄQNAP NAS¹Ì¼þ°æ±¾£¬£¬£¬£¬£¬£¬ÒÑÓÚ2020Äê10Ô½¨¸´¡£¡£¡£¡£¡£¡£¡£¡£ÓÐ4297426̨QNAP NAS¿ÉÄÜ»áÔâµ½´ËÀ๥»÷£¬£¬£¬£¬£¬£¬ÆäÖÐ951486̨ӵÓÐΨһµÄIPµØÖ·£¬£¬£¬£¬£¬£¬´óÎÞÊýλÓÚÃÀ¹ú¡¢ÖйúºÍÒâ´óÀû¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°Éв»Ã÷ÏÔUnityMinerµÄº¹ÇàÒÔ¼°Æä±³ºóµÄºÚ¿Í×éÖ¯¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/115403/hacking/unityminer-qnap-nas-devices.html


5.Ç÷Ïò¿Æ¼¼·¢ÏÖÒÁÀÊMuddyWaterÕë¶ÔÖж«×éÖ¯µÄ¹¥»÷»î¶¯


5.jpg


Trend Micro·¢ÏÖÒÁÀʺڿÍ×éÖ¯MuddyWaterÕë¶ÔÖж«×éÖ¯µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£ºÚ¿ÍʹÓÃÁË´øÓÐǶÈëʽÁ´½ÓµÄÓã²æÊ½µç×ÓÓʼþ£¬£¬£¬£¬£¬£¬½«Êܺ¦Õß³Á¶¨Ïòµ½ºÏ·¨µÄÎļþ¹²Ïí·þÎñScreenConnect£¬£¬£¬£¬£¬£¬À´·Ö·¢Æä¶ñÒâÈí¼þ°ü¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯ÖØÒªÕë¶ÔÖж«ºÍÖܱߵØÓòµÄѧÊõ½ç¡¢µ±¾Ö»ú¹¹ºÍÓÎÀÀʵÌ壬£¬£¬£¬£¬£¬ÎªÖ¼ÔÚÇÔÈ¡Êý¾ÝµÄ¼äµý»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£Trend Micro»¹·¢ÏÖ·Ö·¢RemoteUtilitiesºÍScreenConnectµÄÁ½¸ö»î¶¯Ö®¼äµÄÕ½ÊõºÍ¼¼Êõ´óÌåÀàËÆ£¬£¬£¬£¬£¬£¬°µÊ¾ÐÂÒ»ÂÖ¹¥»÷ÖØÒªÕë¶Ô°¢Èû°Ý½®¡¢°ÍÁÖ¡¢ÒÔÉ«ÁÓ×¢É³ÌØ°¢À­²®ºÍ°¢ÁªÇõµÄ×éÖ¯¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/03/iranian-hackers-using-remote-utilities.html


6.µÂ¿ËÈøË¹´óѧÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬Ñ§ÌÃËùÓÐϵͳ±»ÆÈ¹Ø¹Ø


6.jpg


µÂ¿ËÈøË¹´óѧ£¨University of Texas£©ÓÚ3ÔÂ7ÈÕ°ä²¼ÉêÃ÷³ÆÆäÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬Ñ§ÌÃËùÓÐϵͳ±»ÆÈ¹Ø¹Ø¡£¡£¡£¡£¡£¡£¡£¡£¸ÃУ°µÊ¾£¬£¬£¬£¬£¬£¬ËûÃÇÔÚÖÜÎåÁ賿·¢ÏÖÁËÕâ´Î¹¥»÷£¬£¬£¬£¬£¬£¬Æäµç×ÓÓʼþºÍÍйܴóÑ§ÍøÕ¾µÄ·þÎñÆ÷¾ùÊܵ½´ËÊÂÎñµÄÓ°Ï죬£¬£¬£¬£¬£¬½ÌÈËÔ±¹¤ºÍѧÉúÖ»ÄÜͨ¹ýBlackboard½øÐÐͨѶ¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬ÆäÔÚ¼ì²âµ½¹¥»÷ºóÁ¢¼´¹Ø¹ØÁËËùÓÐУ԰ϵͳ£¬£¬£¬£¬£¬£¬²¢¶Ôÿ¸öϵͳ½øÐÐÁ˳¹µ×²é³­£¬£¬£¬£¬£¬£¬·¢ÏÖ²¢Ã»ÓÐÈκÎÓ×ÎÒÐÅÏ¢±»Ð¹Â¶¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/hackers-target-texas-university/