TIMÍŶÓÅû¶CA Technologies²úÆ·ÖеĶà¸ö0day£»£»£»£»£»£»Î¢Èí³ÆÖÜËĵÄÖжÏÔ´ÓÚ´úÂëȱµãµ¼ÖµÄAzure DNS¹ýÔØ
°ä²¼¹¦·ò 2021-04-061.TIMÍŶÓÅû¶CA Technologies²úÆ·ÖеĶà¸ö0day

CA TechnologiesÊÇÃÀ¹úÒ»¼ÒרһÓÚB2BÈí¼þµÄ¿ç¹ú¹«Ë¾£¬£¬£¬£¬£¬£¬£¬ÏúÊÛ½ü200ÖÖ²úÆ·£¬£¬£¬£¬£¬£¬£¬Éæ¼°É¢²¼Ê½ÍÆËã¡¢ÔÆÍÆËã¡¢DevOpsºÍÍÆËã»ú°²È«Èí¼þÒÔ¼°Òƶ¯É豸¡£¡£¡£¡£¡£¡£¡£¡£TIMµÄRed Team ResearchÍŶÓÅû¶ÁËCA eHealth Performance Manager²úÆ·ÖеÄ5¸öзì϶¡£¡£¡£¡£¡£¡£¡£¡£±ðÀëΪÌáȨ·ì϶£¨CVE-2021-28246ºÍCVE-2021-28249£©¡¢¿çÕ¾µã¾ç±¾·ì϶£¨CVE-2021-28247£©¡¢Í¨¹ýSUID/GUIDÎļþµÄÌáȨ·ì϶£¨CVE-2021-28250£©ºÍÉí·ÝÑéÖ¤·ì϶£¨CVE-2021-28248£©¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/116268/security/ca-ehealth-performance-manager-flaws.html
2.΢Èí³ÆÖÜËĵÄÖжÏÔ´ÓÚ´úÂëȱµãµ¼ÖµÄAzure DNS¹ýÔØ

΢Èíй©£¬£¬£¬£¬£¬£¬£¬ÉÏÖÜËĵÄÈ«ÇòÁìÓòÄڵķþÎñÖжÏÊÇÓÉ´úÂëȱµãµ¼ÖµÄAzure DNS¹ýÔØÒýÆðµÄ¡£¡£¡£¡£¡£¡£¡£¡£ÖжϲúÉúÔÚÉÏÖÜËÄÏÂÎç5:21×óÓÒ£¬£¬£¬£¬£¬£¬£¬MicrosoftÓû§·¢ÏÔìäÎÞ·¨½Ó¼ûXbox Live¡¢Office¡¢TeamsºÍSkypeµÈ·þÎñ£¬£¬£¬£¬£¬£¬£¬¸ÃÎÊÌâÓÚ6:30±»½â¾ö¡£¡£¡£¡£¡£¡£¡£¡£½üÆÚ£¬£¬£¬£¬£¬£¬£¬Microsoft°ä²¼ÁËÓйطþÎñÖжϵĵ××ÓÔÒò·ÖÎö£¨RCA£©£¬£¬£¬£¬£¬£¬£¬³ÆÕë¶ÔAzureÉÏÍйܵÄijЩÓòµÄDNS²éÎÊÒì³£¼¤Ôöµ¼Ö·þÎñÆ÷¹ýÔØ£¬£¬£¬£¬£¬£¬£¬Î¢Èí²¢Î´Ú¹Êͼ¤ÔöµÄÔÒò£¬£¬£¬£¬£¬£¬£¬¾Ý´§Ä¦¿ÉÄÜÊÇÓÉÓÚÕë¶ÔijЩÓòµÄDDoS¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-outage-caused-by-overloaded-azure-dns-servers/
3.ÃÀ¹ú½ðÈÚ»ú¹¹RobinhoodµÄ¿Í»§Ôâµ½´¹µö¹¥»÷

Robinhood MarketsÔÚÉÏÖÜËİ䲼ÏòÆä¿Í»§·¢ËÍÓʼþ³Æ£¬£¬£¬£¬£¬£¬£¬Æä²¿Ãſͻ§¿ÉÄÜÒѾÔâµ½´¹µö¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£RobinhoodÊÇÒ»¼ÒÃÀ¹ú½ðÈÚ·þÎñ»ú¹¹£¬£¬£¬£¬£¬£¬£¬ÆäÊÖ»úÀûÓÿÉÌṩ¹ÉƱºÍ»ù½ðµÄÃâÓ¶½ðÂòÂô£¬£¬£¬£¬£¬£¬£¬½ØÖÁ2020ÄêÒÑÕ¼ÓÐ1300Íò¿Í»§¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷»î¶¯Ê¹ÓÃÁËÁ½ÖÖ¹¥»÷ý½éÓÕÆÊܺ¦Õߣ¬£¬£¬£¬£¬£¬£¬ÆäÒ»ÊÇÀûÓÃÔ̺¬ÁËαÔìRobinhoodÍøÕ¾Á´½ÓµÄ´¹µöÓʼþ£¬£¬£¬£¬£¬£¬£¬ÓÕʹ½Ó¼ûÕßÊäÈëµÇ¼ʹ´¦£»£»£»£»£»£»ÁíÒ»ÖÖÊÇÀûÓÃÁ˱¨Ë°¼¾£¬£¬£¬£¬£¬£¬£¬ÒªÇóÖ¸±êÏÂÔØÔ̺¬Á˶ñÒâÈí¼þµÄαÔì˰ÊÕÎļþ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.ehackingnews.com/2021/04/attackers-targeted-robinhood-with.html
4.KasperskyÅû¶Õë¶ÔÔ½Ä϶à¸ö×éÖ¯µÄÍøÂç¼äµý»î¶¯

KasperskyÅû¶ÁËAPT×éÖ¯CycldekÕë¶ÔÔ½Äϵ±¾ÖºÍ¾üÊÂ×éÖ¯µÄÍøÂç¼äµý»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯Ê¹ÓÃÁËÃûΪFoundCoreµÄ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬¿É½øÐÐÎļþϵͳ°Ñ³Ö¡¢¹ý³Ì°Ñ³Ö¡¢ÆÁÄ»½ØÍ¼²¶»ñºÍËÁÒâºÅÁîÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬Kaspersky³Æ¸Ã×éÖ¯ÔÚ¸´ÔÓÐÔ·½Ãæ»ñµÃÁ˳ÁÃͽøÈ¡£¬£¬£¬£¬£¬£¬£¬ÀýÈ磬£¬£¬£¬£¬£¬£¬ÆäpayloadµÄ±êÍ·£¨´úÂëµÄÖ¸±êºÍÔ´£©±»ÆëÈ«°þÀ룬£¬£¬£¬£¬£¬£¬Ê£ÏµÄÉÙÊý²¿ÃŵÄÖµÊDz»Á¬¹áµÄ£¬£¬£¬£¬£¬£¬£¬Õâ´ó´óÔö³¤ÁË×êÑÐÈËÔ±¶ÔÆä½øÐзÖÎöµÄÄѶȡ£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/spy-operations-vietnam-rat/165243/
5.΢Èí°ä²¼2021Äê3ÔÂSecurity SignalsµÄ·ÖÎö»ã±¨

΢Èí°ä²¼ÁË2021Äê3ÔÂSecurity SignalsµÄ·ÖÎö»ã±¨£¬£¬£¬£¬£¬£¬£¬µ÷²éÁËÀ´×ÔÖйú¡¢µÂ¹ú¡¢ÈÕ±¾¡¢Ó¢¹úºÍÃÀ¹úµÄ1000λÆóÒµ°²È«¾ö²ßÕß¡£¡£¡£¡£¡£¡£¡£¡£»ã±¨·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬´ÓǰÁ½ÄêÖÐÓÐ80£¥µÄÆóÒµÔâµ½ÁËÖÁÉÙÒ»´Î¹Ì¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬µ«Ö»ÓÐ29£¥µÄ×éÖ¯·ÖÅäÁËÔ¤ËãÀ´±£»£»£»£»£»£»¤¹Ì¼þ¡£¡£¡£¡£¡£¡£¡£¡£NVDÖ¤ÇÐʵ´ÓǰËÄÄêÖУ¬£¬£¬£¬£¬£¬£¬Õë¶Ô¹Ì¼þµÄ¹¥»÷Ôö³¤ÁËÎå±¶ÒÔÉÏ¡£¡£¡£¡£¡£¡£¡£¡£21£¥µÄ¾ö²ßÕßÈÏ¿ÉÎÞ·¨¼à¿Ø¹Ì¼þÊý¾Ý£¬£¬£¬£¬£¬£¬£¬82£¥×é֯ûÓÐ×ÊÔ´À´Õмܹ̼þ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£81£¥µÄµÂ¹ú¹«Ë¾¡¢91£¥µÄÃÀ¹ú¡¢Ó¢¹úºÍÈÕ±¾¹«Ë¾ÒÔ¼°95£¥µÄÖйú¹«Ë¾Ô¸ÒâÔÚÕâ¸ö·½Ãæ½øÐÐͶ×Ê¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.microsoft.com/en-us/secured-corepc
6.Ravelin°ä²¼Óйصç×ÓÉÌÎñڲƻµÄ·ÖÎö»ã±¨

Ravelin¶ÔÈ«Çò1000¶à¼ÒÉ̼ҽøÐÐÁ˵÷²é£¬£¬£¬£¬£¬£¬£¬°ä²¼ÁËÓйصç×ÓÉÌÎñڲƻµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£»ã±¨ÏÔʾ£¬£¬£¬£¬£¬£¬£¬½«½ü40£¥µÄ¿ìÏûÁãÊÛÉ̽«ÔÚÏßÖ§¸¶Ú²ÆÊÓΪ×î´óµÄڲƷçÏÕ£¬£¬£¬£¬£¬£¬£¬45%µÄ¹«Ë¾Ëù¾ÀúµÄÕË»§ÊÕÊÜ(ATO)¹¥»÷ÓÐËùÔö³¤¡£¡£¡£¡£¡£¡£¡£¡£»ã±¨Ô¤²â£¬£¬£¬£¬£¬£¬£¬µç×ÓÉÌÎñÐÐÒµÖеÄÚ²ÆÎÊÌâ¿ÉÄÜ»áÓúÑÝÓúÁÒ£¬£¬£¬£¬£¬£¬£¬ÓÈÆäÊÇËæ×źܶഫͳµÄ¸ß½Ôì·ÅÆ£¨ÈçTopshopºÍDebenhams£©±»ÊÕ¹º²¢ÊµÏÖÒµÎñÈ«ÊýÏòÏßÉÏתÐ͵Äʱ³½¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://pages.ravelin.com/retail-fraud-payments-report


¾©¹«Íø°²±¸11010802024551ºÅ