ForescoutÅû¶ӰÏìÉÏÒŲ́É豸µÄDNS·ì϶NAME£ºWRECK£»£»£»£»£»Î¢Èí°ä²¼4Ô²¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬½¨¸´5¸ö0dayÔÚÄÚµÄ108¸ö·ì϶
°ä²¼¹¦·ò 2021-04-141.ForescoutÅû¶ӰÏìÉÏÒŲ́É豸µÄDNS·ì϶NAME£ºWRECK

°²È«¹«Ë¾ForescoutºÍÒÔÉ«Áа²È«ÍŶÓJSOF½áºÏÅû¶ÁËTCP/IP²Ö¿âÖÐDNSºÍ̸ÖеÄ9¸ö°²È«·ì϶£¬£¬£¬£¬£¬£¬Í³³ÆÎªNAME£ºWRECK£¬£¬£¬£¬£¬£¬Ó°ÏìÁË1ÒÚ¸öÔÚInternetÉÏÔËÐеÄÉ豸¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ì϶ʹÉ豸ÍÑ»ú»òÕ߯ëÈ«½ÚÔìÉ豸¡£¡£¡£¡£¡£ÕâЩ·ì϶ÖÐ×îÑϳÁµÄΪIPnetÖеÄRCE·ì϶£¨CVE-2016-20009£©£¬£¬£¬£¬£¬£¬ÑϳÁÐԵ÷ÖΪ9.8¡£¡£¡£¡£¡£Æä´ÎΪRCE£¨CVE-2020-7461¡¢CVE-2020-15795ºÍCVE-2020-27009£©ºÍDoS£¨CVE-2020-27736ºÍCVE-2020-27737£©µÈ·ì϶¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/name-wreck-dns-vulnerabilities-affect-over-100-million-devices/
2.×êÑÐÈËÔ±¹«¿ªChromeºÍEdgeµÅצÓõÄRCE 0dayµÄPoC

×êÑÐÈËÔ±ÔÚRajvardhan AgarwalÔÚTwitter°ä²¼ÁËChromeºÍEdgeµÅצÓÃÖеÄRCE 0dayµÄPoC¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇ»ùÓÚChromiumµÄä¯ÀÀÆ÷µÄV8 JavaScriptÒýÇæÖÐÔ¶³ÌÖ´ÐдúÂë·ì϶£¬£¬£¬£¬£¬£¬Ó°ÏìÁËChrome¡¢Edge¡¢OperaºÍBraveµÈä¯ÀÀÆ÷¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬Agarwal°µÊ¾¸Ã0day±ØÒªÓëÁíÒ»¸öÄܹ»ÔÚChromiumµÄɳÏäÌÓÒݵķì϶һ·ʹÓÃÄÜÁ¦²ûÑï×÷Óᣡ£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÒÑÔÚV8 JavaScriptÒýÇæµÄ×îа汾Öб»½¨¸´¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/04/rce-exploit-released-for-unpatched.html
3.Microsoft°ä²¼4Ô²¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬½¨¸´5¸ö0dayÔÚÄÚµÄ108¸ö·ì϶

Microsoft°ä²¼ÁË4Ô·ݵÄÖܶþ²¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬×ܼƽ¨¸´ÁËÔ̺¬5¸ö0dayÔÚÄÚµÄ108¸ö·ì϶¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ0dayÔ̺¬RPC¶ËµãÓ³ÉäÆ÷µÄÌáȨ·ì϶£¨CVE-2021-27091£©¡¢NTFS»Ø¾ø·þÎñ·ì϶£¨CVE-2021-28312£©¡¢Windows×°Ö÷¨Ê½ÖеÄÐÅϢй¶·ì϶£¨CVE-2021-28437£©¡¢Azure ms-rest-nodeauth¿âµÄÌáȨ·ì϶£¨CVE-2021-28458£©ÒÔ¼°Win32kÖеÄÌáȨ·ì϶£¨CVE-2021-28310£©¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬CVE-2021-28310·ì϶ÊÇKasperskyÔÚÒ°·¢Ïֵ쬣¬£¬£¬£¬£¬Òѱ»APT×éÖ¯BITTERÀûÓᣡ£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2021-patch-tuesday-fixes-108-flaws-5-zero-days/
4.ºÚ¿ÍÏúÊÛ2100Íò¸öÍ£³µÀûÓÃParkMobileµÄÓû§µÄÐÅÏ¢

Gemini Advisory·¢ÏÖºÚ¿ÍÔÚ°µÍøÏúÊÛ2100Íò¸öÒÆ¶¯Í£³µÀûÓ÷¨Ê½ParkMobileµÄÓû§µÄÐÅÏ¢£¬£¬£¬£¬£¬£¬ÊÛ¼ÛΪ125000ÃÀÔª¡£¡£¡£¡£¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬¿Í»§µç×ÓÓʼþµØÖ·¡¢ÉúÈÕ¡¢µç»°ºÅÂë¡¢³µÉ̱ꡢ¹þÏ£ÃÜÂëºÍÓʼĵØÖ·µÈ¡£¡£¡£¡£¡£ParkMobile¹«Ë¾³Æ£¬£¬£¬£¬£¬£¬Æä3ÔÂ26ÈվͰ䲼ÁËÓйØÊý¾Ýй¶µÄ֪ͨ£¬£¬£¬£¬£¬£¬²¢ÔÚ°²È«¹«Ë¾µÄÐÖú϶ԴËÊ·¢Õ¹Á˵÷²é¡£¡£¡£¡£¡£µ«×êÑÐÈËÔ±°µÊ¾Æä¹ÙÍø²¢Ã»Óиð²È«Í¨Öª£¬£¬£¬£¬£¬£¬Ò²Ã»ÓÐÇ¿ÔìÆäÓû§Åú¸ÄÃÜÂë¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://krebsonsecurity.com/2021/04/parkmobile-breach-exposes-license-plate-data-mobile-numbers-of-21m-users/
5.McAfee·¢ÏÖBRATA¼Ù×°³É°²È«É¨Ã跨ʽÔÚGoogle PlayÖзַ¢

McAfee·¢ÏÖÁËBRATAµÄ¶à¸öбäÖÖ£¬£¬£¬£¬£¬£¬¼Ù×°³É°²È«É¨Ã跨ʽÔÚGoogle PlayÖзַ¢¡£¡£¡£¡£¡£BRATA×î³õÓÚ2018Äêµ×ÔÚÒ°±í³öÏÖ£¬£¬£¬£¬£¬£¬ÒÔ°ÍÎ÷µÄÓû§ÎªÖ¸±ê£¬£¬£¬£¬£¬£¬ÓµÓнÚÔìÉ豸¡¢ÀûÓô¹µöÍøÒ³ÇÔÈ¡ÒøÐÐÍ´´¦¡¢»ñÈ¡ÆÁÄ»Ëø¶¨Æ¾Ö¤£¨PIN¡¢ÃÜÂë»òͼ°¸£©µÈÖ°ÄÜ¡£¡£¡£¡£¡£ÕâЩеıäÖÖÖØÒªÔÚGoogle PlayÉϽøÐзַ¢£¬£¬£¬£¬£¬£¬ÒªÇóÓû§¸üÐÂChrome¡¢WhatsApp»òPDFÔĶÁÆ÷£¬£¬£¬£¬£¬£¬²¢Í¨¹ý¸¨ÖúÖ°ÄÜÀ´ÆëÈ«½ÚÔìÉ豸£¬£¬£¬£¬£¬£¬Õë¶Ô°ÍÎ÷¡¢Î÷°àÑÀºÍÃÀ¹úµÈµØÓòµÄ½ðÈÚ×éÖ¯µÄÓû§¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/brata-keeps-sneaking-into-google-play-now-targeting-usa-and-spain/
6.Unit 42°ä²¼2020ÄêQ4°²È«Ç÷ÏòµÄ·ÖÎö»ã±¨

Unit 42°ä²¼ÁË2020ÄêQ4°²È«Ç÷ÏòµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£»ã±¨·¢ÏÖ£¬£¬£¬£¬£¬£¬2020Äê11ÔÂÖÁ2021Äê1ÔµĴóÎÞÊý¹¥»÷¶¼±»¹éΪÑϳÁ¹¥»÷£¬£¬£¬£¬£¬£¬Õ¼±ÈΪ75£¥£¬£¬£¬£¬£¬£¬¶øÔÚÇ^Ϊ50.4£¥¡£¡£¡£¡£¡£¹¥»÷Õ߸ü¶àµÄʹÓÃ2017ÄêÖÁ2020ÄêÔÚÒ°±íÀûÓõķì϶¡£¡£¡£¡£¡£ÔÚ¹¥»÷ÀàÐÍ·½Ã棬£¬£¬£¬£¬£¬µ¥¶ÀµÄ´úÂëÖ´ÐÐÕ¼×ܹ¥»÷µÄ46.6£¥£¬£¬£¬£¬£¬£¬´úÂëÖ´ÐкÍÌØÈ¨ÌáÉý½áºÏµÄ¹¥»÷Õ¼17.3£¥£¬£¬£¬£¬£¬£¬SQL×¢ÈëÕ¼9.9£¥¡£¡£¡£¡£¡£ÑϳÁÐÔ×î¸ßµÄ·ì϶ΪºÅÁî×¢Èë·ì϶£¨CVE-2020-28188£©¡¢Ä¿Â¼±éÀú·ì϶£¨CVE-2020-17519£©ºÍ±¾µØÎļþÔ̺¬·ì϶£¨CVE-2020-29227£©µÈ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://unit42.paloaltonetworks.com/network-attack-trends-winter-2020/


¾©¹«Íø°²±¸11010802024551ºÅ