TIMÍŶÓÅû¶CA Technologies²úÆ·ÖеĶà¸ö0day£»£»£» £»£»£»Î¢Èí³ÆÖÜËĵÄÖжÏÔ´ÓÚ´úÂëȱµãµ¼ÖµÄAzure DNS¹ýÔØ

°ä²¼¹¦·ò 2021-04-06

1.TIMÍŶÓÅû¶CA Technologies²úÆ·ÖеĶà¸ö0day


1.jpg


CA TechnologiesÊÇÃÀ¹úÒ»¼ÒרһÓÚB2BÈí¼þµÄ¿ç¹ú¹«Ë¾£¬£¬ £¬£¬£¬£¬ £¬ÏúÊÛ½ü200ÖÖ²úÆ·£¬£¬ £¬£¬£¬£¬ £¬Éæ¼°É¢²¼Ê½ÍÆËã¡¢ÔÆÍÆËã¡¢DevOpsºÍÍÆËã»ú°²È«Èí¼þÒÔ¼°Òƶ¯É豸¡£¡£¡£¡£ ¡£¡£¡£¡£TIMµÄRed Team ResearchÍŶÓÅû¶ÁËCA eHealth Performance Manager²úÆ·ÖеÄ5¸öзì϶¡£¡£¡£¡£ ¡£¡£¡£¡£±ðÀëΪÌáȨ·ì϶£¨CVE-2021-28246ºÍCVE-2021-28249£©¡¢¿çÕ¾µã¾ç±¾·ì϶£¨CVE-2021-28247£©¡¢Í¨¹ýSUID/GUIDÎļþµÄÌáȨ·ì϶£¨CVE-2021-28250£©ºÍÉí·ÝÑéÖ¤·ì϶£¨CVE-2021-28248£©¡£¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116268/security/ca-ehealth-performance-manager-flaws.html


2.΢Èí³ÆÖÜËĵÄÖжÏÔ´ÓÚ´úÂëȱµãµ¼ÖµÄAzure DNS¹ýÔØ


2.jpg


΢Èíй©£¬£¬ £¬£¬£¬£¬ £¬ÉÏÖÜËĵÄÈ«ÇòÁìÓòÄڵķþÎñÖжÏÊÇÓÉ´úÂëȱµãµ¼ÖµÄAzure DNS¹ýÔØÒýÆðµÄ¡£¡£¡£¡£ ¡£¡£¡£¡£ÖжϲúÉúÔÚÉÏÖÜËÄÏÂÎç5:21×óÓÒ£¬£¬ £¬£¬£¬£¬ £¬MicrosoftÓû§·¢ÏÔìäÎÞ·¨½Ó¼ûXbox Live¡¢Office¡¢TeamsºÍSkypeµÈ·þÎñ£¬£¬ £¬£¬£¬£¬ £¬¸ÃÎÊÌâÓÚ6:30±»½â¾ö¡£¡£¡£¡£ ¡£¡£¡£¡£½üÆÚ£¬£¬ £¬£¬£¬£¬ £¬Microsoft°ä²¼ÁËÓйطþÎñÖжϵĵ××ÓÔ­Òò·ÖÎö£¨RCA£©£¬£¬ £¬£¬£¬£¬ £¬³ÆÕë¶ÔAzureÉÏÍйܵÄijЩÓòµÄDNS²éÎÊÒì³£¼¤Ôöµ¼Ö·þÎñÆ÷¹ýÔØ£¬£¬ £¬£¬£¬£¬ £¬Î¢Èí²¢Î´Ú¹Êͼ¤ÔöµÄÔ­Òò£¬£¬ £¬£¬£¬£¬ £¬¾Ý´§Ä¦¿ÉÄÜÊÇÓÉÓÚÕë¶ÔijЩÓòµÄDDoS¹¥»÷¡£¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-outage-caused-by-overloaded-azure-dns-servers/


3.ÃÀ¹ú½ðÈÚ»ú¹¹RobinhoodµÄ¿Í»§Ôâµ½´¹µö¹¥»÷


3.jpg


Robinhood MarketsÔÚÉÏÖÜËİ䲼ÏòÆä¿Í»§·¢ËÍÓʼþ³Æ£¬£¬ £¬£¬£¬£¬ £¬Æä²¿Ãſͻ§¿ÉÄÜÒѾ­Ôâµ½´¹µö¹¥»÷¡£¡£¡£¡£ ¡£¡£¡£¡£RobinhoodÊÇÒ»¼ÒÃÀ¹ú½ðÈÚ·þÎñ»ú¹¹£¬£¬ £¬£¬£¬£¬ £¬ÆäÊÖ»úÀûÓÿÉÌṩ¹ÉƱºÍ»ù½ðµÄÃâÓ¶½ðÂòÂô£¬£¬ £¬£¬£¬£¬ £¬½ØÖÁ2020ÄêÒÑÕ¼ÓÐ1300Íò¿Í»§¡£¡£¡£¡£ ¡£¡£¡£¡£Õâ´Î¹¥»÷»î¶¯Ê¹ÓÃÁËÁ½ÖÖ¹¥»÷ý½éÓÕÆ­Êܺ¦Õߣ¬£¬ £¬£¬£¬£¬ £¬ÆäÒ»ÊÇÀûÓÃÔ̺¬ÁËαÔìRobinhoodÍøÕ¾Á´½ÓµÄ´¹µöÓʼþ£¬£¬ £¬£¬£¬£¬ £¬ÓÕʹ½Ó¼ûÕßÊäÈëµÇ¼ʹ´¦£»£»£» £»£»£»ÁíÒ»ÖÖÊÇÀûÓÃÁ˱¨Ë°¼¾£¬£¬ £¬£¬£¬£¬ £¬ÒªÇóÖ¸±êÏÂÔØÔ̺¬Á˶ñÒâÈí¼þµÄαÔì˰ÊÕÎļþ¡£¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/04/attackers-targeted-robinhood-with.html


4.KasperskyÅû¶Õë¶ÔÔ½Ä϶à¸ö×éÖ¯µÄÍøÂç¼äµý»î¶¯


4.jpg


KasperskyÅû¶ÁËAPT×éÖ¯CycldekÕë¶ÔÔ½Äϵ±¾ÖºÍ¾üÊÂ×éÖ¯µÄÍøÂç¼äµý»î¶¯¡£¡£¡£¡£ ¡£¡£¡£¡£¸Ã»î¶¯Ê¹ÓÃÁËÃûΪFoundCoreµÄ¶ñÒâÈí¼þ£¬£¬ £¬£¬£¬£¬ £¬¿É½øÐÐÎļþϵͳ°Ñ³Ö¡¢¹ý³Ì°Ñ³Ö¡¢ÆÁÄ»½ØÍ¼²¶»ñºÍËÁÒâºÅÁîÖ´ÐС£¡£¡£¡£ ¡£¡£¡£¡£´Ë±í£¬£¬ £¬£¬£¬£¬ £¬Kaspersky³Æ¸Ã×éÖ¯ÔÚ¸´ÔÓÐÔ·½Ãæ»ñµÃÁ˳ÁÃͽøÈ¡£¬£¬ £¬£¬£¬£¬ £¬ÀýÈ磬£¬ £¬£¬£¬£¬ £¬ÆäpayloadµÄ±êÍ·£¨´úÂëµÄÖ¸±êºÍÔ´£©±»ÆëÈ«°þÀ룬£¬ £¬£¬£¬£¬ £¬Ê£ÏµÄÉÙÊý²¿ÃŵÄÖµÊDz»Á¬¹áµÄ£¬£¬ £¬£¬£¬£¬ £¬Õâ´ó´óÔö³¤ÁË×êÑÐÈËÔ±¶ÔÆä½øÐзÖÎöµÄÄѶÈ¡£¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/spy-operations-vietnam-rat/165243/


5.΢Èí°ä²¼2021Äê3ÔÂSecurity SignalsµÄ·ÖÎö»ã±¨


5.jpg


΢Èí°ä²¼ÁË2021Äê3ÔÂSecurity SignalsµÄ·ÖÎö»ã±¨£¬£¬ £¬£¬£¬£¬ £¬µ÷²éÁËÀ´×ÔÖйú¡¢µÂ¹ú¡¢ÈÕ±¾¡¢Ó¢¹úºÍÃÀ¹úµÄ1000λÆóÒµ°²È«¾ö²ßÕß¡£¡£¡£¡£ ¡£¡£¡£¡£»ã±¨·¢ÏÖ£¬£¬ £¬£¬£¬£¬ £¬´ÓǰÁ½ÄêÖÐÓÐ80£¥µÄÆóÒµÔâµ½ÁËÖÁÉÙÒ»´Î¹Ì¼þ¹¥»÷£¬£¬ £¬£¬£¬£¬ £¬µ«Ö»ÓÐ29£¥µÄ×éÖ¯·ÖÅäÁËÔ¤ËãÀ´±£»£»£» £»£»£»¤¹Ì¼þ¡£¡£¡£¡£ ¡£¡£¡£¡£NVDÖ¤ÇÐʵ´ÓǰËÄÄêÖУ¬£¬ £¬£¬£¬£¬ £¬Õë¶Ô¹Ì¼þµÄ¹¥»÷Ôö³¤ÁËÎå±¶ÒÔÉÏ¡£¡£¡£¡£ ¡£¡£¡£¡£21£¥µÄ¾ö²ßÕßÈÏ¿ÉÎÞ·¨¼à¿Ø¹Ì¼þÊý¾Ý£¬£¬ £¬£¬£¬£¬ £¬82£¥×é֯ûÓÐ×ÊÔ´À´Õмܹ̼þ¹¥»÷¡£¡£¡£¡£ ¡£¡£¡£¡£81£¥µÄµÂ¹ú¹«Ë¾¡¢91£¥µÄÃÀ¹ú¡¢Ó¢¹úºÍÈÕ±¾¹«Ë¾ÒÔ¼°95£¥µÄÖйú¹«Ë¾Ô¸ÒâÔÚÕâ¸ö·½Ãæ½øÐÐͶ×Ê¡£¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.microsoft.com/en-us/secured-corepc


6.Ravelin°ä²¼Óйصç×ÓÉÌÎñڲƭ»î¶¯µÄ·ÖÎö»ã±¨


6.jpg


Ravelin¶ÔÈ«Çò1000¶à¼ÒÉ̼ҽøÐÐÁ˵÷²é£¬£¬ £¬£¬£¬£¬ £¬°ä²¼ÁËÓйصç×ÓÉÌÎñڲƭ»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£ ¡£¡£¡£¡£»ã±¨ÏÔʾ£¬£¬ £¬£¬£¬£¬ £¬½«½ü40£¥µÄ¿ìÏûÁãÊÛÉ̽«ÔÚÏßÖ§¸¶Ú²Æ­ÊÓΪ×î´óµÄڲƭ·çÏÕ£¬£¬ £¬£¬£¬£¬ £¬45%µÄ¹«Ë¾Ëù¾­ÀúµÄÕË»§ÊÕÊÜ(ATO)¹¥»÷ÓÐËùÔö³¤¡£¡£¡£¡£ ¡£¡£¡£¡£»ã±¨Ô¤²â£¬£¬ £¬£¬£¬£¬ £¬µç×ÓÉÌÎñÐÐÒµÖеÄڲƭÎÊÌâ¿ÉÄÜ»áÓúÑÝÓúÁÒ£¬£¬ £¬£¬£¬£¬ £¬ÓÈÆäÊÇËæ×źܶഫͳµÄ¸ß½Ôì·ÅÆ£¨ÈçTopshopºÍDebenhams£©±»ÊÕ¹º²¢ÊµÏÖÒµÎñÈ«ÊýÏòÏßÉÏתÐ͵Äʱ³½¡£¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://pages.ravelin.com/retail-fraud-payments-report