Microsoft°ä²¼5Ô²¹¶¡£¡£¡£¡£¡£¡£¬£¬£¬£¬ £¬£¬£¬£¬½¨¸´3¸ö0dayÔÚÄÚµÄ55¸ö·ì϶£»£»£»£»£»£»£» £»ÃÀ¹úºÍ°Ä´óÀûÑÇÖÒ¸æÕë¶ÔÈ«ÇòµÄAvaddonÀÕË÷Èí¼þ»î¶¯

°ä²¼¹¦·ò 2021-05-12

1.Microsoft°ä²¼5Ô²¹¶¡£¡£¡£¡£¡£¡£¬£¬£¬£¬ £¬£¬£¬£¬½¨¸´3¸ö0dayÔÚÄÚµÄ55¸ö·ì϶


1.jpg


Microsoft°ä²¼5Ô·ݵÄÖܶþ²¹¶¡£¡£¡£¡£¡£¡£¬£¬£¬£¬ £¬£¬£¬£¬½¨¸´Ô̺¬3¸ö0dayÔÚÄÚµÄ55¸ö·ì϶¡£¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ0 day±ðÀëÊÇNETºÍVisual StudioÖеÄÌáȨ·ì϶£¨CVE-2021-31204£©¡¢Microsoft Exchange ServerÖеݲȫְÄÜÈÆ¹ý·ì϶£¨CVE-2021-31207£©ºÍͨÓù¤¾ßÖеÄÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2021-31200£©£¬£¬£¬£¬ £¬£¬£¬£¬ÕâЩ·ì϶»¹Î´±»ÔÚÒ°ÀûÓᣡ£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬ £¬£¬£¬£¬»¹½¨¸´ÁËHTTP.sysÖеÄÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2021-31166£©ºÍIEä¯ÀÀÆ÷ÖеÄÄÚ´æ°Ü»µ·ì϶£¨CVE-2021-26419£©µÈ·ì϶¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/microsoft-patch-tuesday-55-vulnerabilities-4-critical-3-publicly-known


2.CiscoÅû¶Lemon DuckÕë¶Ô±±ÃÀµØÓòµÄÐÂÒ»ÂÖ¹¥»÷»î¶¯


2.jpg


Cisco Talos×êÑÐÈËÔ±·¢ÏÖLemon DuckÕë¶Ô±±ÃÀµØÓòµÄÐÂÒ»ÂÖ¹¥»÷»î¶¯Å¤×ªÁ˹¥»÷Õ½Êõ¡£¡£¡£¡£¡£¡£È¥Äê8Ô£¬£¬£¬£¬ £¬£¬£¬£¬Lemon DuckÖØÒªÕë¶Ô°£¼°¡¢Ó¡¶È¡¢ÒÁÀÊ¡¢·ÆÂɱöºÍÔ½ÄϽøÐÐÍÚ¿óµÄ»î¶¯¡£¡£¡£¡£¡£¡£ÔÚ4ÔÂ·ÝÆðÍ·µÄÐÂÒ»ÂÖÖУ¬£¬£¬£¬ £¬£¬£¬£¬¸ÃÍÅ»ïŤתÁËÖ¸±ê£¬£¬£¬£¬ £¬£¬£¬£¬ÖØÒªÕë¶Ô±±ÃÀµØÓò£¬£¬£¬£¬ £¬£¬£¬£¬Æä´ÎÊÇÅ·ÖÞ¡¢¶«ÄÏÑÇ¡¢·ÇÖÞºÍÄÏÃÀ¡£¡£¡£¡£¡£¡£ÔÚÕâ´Î¹¥»÷»î¶¯ÖУ¬£¬£¬£¬ £¬£¬£¬£¬¸ÃÍÅ»ïʹÓÃÁËCobalt Strike¹¥»÷¿ò¼Ü£¬£¬£¬£¬ £¬£¬£¬£¬²¢ÔÚ¶«ÑǶ¥¼¶ÓòÃû£¨TLD£©ÉÏʹÓÃαÔìµÄÓòÃûÀ´°µ²ØºÅÁîºÍ½ÚÔ죨C2£©»ù´¡¼Ü¹¹£¬£¬£¬£¬ £¬£¬£¬£¬Ö¼ÔÚ¼ÓÇ¿·´¼ì²âµÄÄÜÁ¦¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/lemon-duck-cryptojacking-botnet-tactics/165986/


3.ÃÀ¹úºÍ°Ä´óÀûÑÇÖÒ¸æÕë¶ÔÈ«ÇòµÄAvaddonÀÕË÷Èí¼þ»î¶¯


3.jpg


ÃÀ¹úÁª¹úµ÷²é¾Ö£¨FBI£©ºÍ°Ä´óÀûÑÇÍøÂ簲ȫÖÐÐÄ£¨ACSC£©ÖÒ¸æÕë¶ÔÈ«ÇòµÄAvaddonÀÕË÷Èí¼þ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£FBI°µÊ¾£¬£¬£¬£¬ £¬£¬£¬£¬AvaddonÀÕË÷Èí¼þÕýÊÔͼ¹¥»÷È«ÇòµÄÔì×÷¡¢Ò½ÁƱ£½¡ºÍÆäËûÐÐÒµ×éÖ¯µÄÍøÂç¡£¡£¡£¡£¡£¡£ACSCÔòÖ¸³ö¸ÃÍÅ»ïÖØÒªÕë¶Ôµ±¾Ö¡¢½ðÈÚ¡¢·¨ÂÉ¡¢ÄÜÔ´¡¢ÐÅÏ¢¼¼ÊõºÍÎÀÉúµÈÐÐÒµ£¬£¬£¬£¬ £¬£¬£¬£¬²¢ÁгöÁËÊܵ½¹¥»÷µÄ¹ú¶ÈµÄÇåµ¥£¬£¬£¬£¬ £¬£¬£¬£¬Ô̺¬ÃÀ¹ú¡¢Ó¢¹ú¡¢µÂ¹ú¡¢Öйú¡¢°ÍÎ÷¡¢Ó¡¶È¡¢°¢ÁªÇõ¡¢·¨¹úºÍÎ÷°àÑÀµÈ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬ £¬£¬£¬£¬ACSC³ÆAvaddonÖØÒªÀûÓûؾø·þÎñ£¨DDoS£©¹¥»÷À´ÍþвÊܺ¦Õߣ¬£¬£¬£¬ £¬£¬£¬£¬µ«FBI°µÊ¾ÉÐδ·¢ÏÖÓйØAvaddonÍŻ﷢ÆðDDoS¹¥»÷µÄÖ¤¾Ý¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/117765/malware/avaddon-targets-orgs-worldwide.html


4.Cleafy·¢ÏÖ¶ñÒâÈí¼þTeaBotÒѹ¥»÷Å·ÖÞµÄ60¶à¼ÒÒøÐÐ


4.jpg


Òâ´óÀûCleafyµÄ°²È«ÍŶӷ¢ÏÖ¶ñÒâÈí¼þTeaBotÒѹ¥»÷Å·ÖÞµÄ60¶à¼ÒÒøÐС£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÈÔ´¦ÓÚ¿ª·¢µÄÔçÆÚ½×¶Î£¬£¬£¬£¬ £¬£¬£¬£¬µ«¾ß±¸Ô¶³Ì½ÚÔìÖ¸±êÉ豸¡¢ÇÔÈ¡µÇ¼ʹ´¦¡¢·¢ËͺÍÀ¹½ØSMSÐÂÎŵÈÖ°ÄÜ¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÖ§³Ö6ÖÖ·ÖÆçµÄ˵»°£¬£¬£¬£¬ £¬£¬£¬£¬Ô̺¬µÂÓï¡¢Ó¢Óï¡¢Òâ´óÀûÓï¡¢·¨Óï¡¢Î÷°àÑÀÓïºÍºÉÀ¼Óï¡£¡£¡£¡£¡£¡£µ½Ä¿Ç°ÎªÖ¹£¬£¬£¬£¬ £¬£¬£¬£¬CleafyÒÑÈ·¶¨Òâ´óÀû¡¢Î÷°àÑÀ¡¢µÂ¹ú¡¢±ÈÀûʱºÍºÉÀ¼µÈ¶à¸öÅ·ÖÞ¹ú¶ÈµÄ60¶à¼ÒÒøÐÐÔâµ½Á˹¥»÷¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/teabot-android-malware-steals-data-sms/


5.Office 365¸ôÀëÀ´×ÔGoogleºÍLinkedInµÅ×òµÄºÏ·¨Óʼþ


5.jpg


΢ÈíÔÚMicrosoft 365ÖÎÀíÖÐÐݵʾ£¬£¬£¬£¬ £¬£¬£¬£¬Ä³Ð©Óû§µÄOffice 365µÄExchange Online Protection£¦Defender»á½«À´×Ô¶à¸öÓò£¨Ô̺¬GoogleºÍLinkedIn£©µÄºÏ·¨µç×ÓÓʼþ¸ôÀë»òÏóÕ÷Ϊ¶ñÒâµç×ÓÓʼþ¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬ £¬£¬£¬£¬Î¢ÈíÒѽâ¾öÁ˸ÃÎÊÌâ²¢³Áз¢Ëͱ»¸ôÀëµÄÓʼþ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬ £¬£¬£¬£¬Î¢Èí11ÈÕ°ä²¼µÄOutlook¸üе¼ÖÂÈ«ÇòÁìÓòÄÚµÄÓû§ÎÞ·¨²é¿´»ò´´½¨µç×ÓÓʼþ£¬£¬£¬£¬ £¬£¬£¬£¬³ö¸ñÊÇÔÚ´´½¨ÐÂÓʼþʱ£¬£¬£¬£¬ £¬£¬£¬£¬Ã¿´Î°´Enter¼ü£¬£¬£¬£¬ £¬£¬£¬£¬ÏÈǰ±àдµÄËùÓÐÄÚÈݶ¼½«±»É¾³ý¡£¡£¡£¡£¡£¡£Î¢Èí½¨ÒéÓû§»Ø¹öµ½4Ôµİ汾£¬£¬£¬£¬ £¬£¬£¬£¬»òÔÚ°²È«Ä£Ê½ÏÂÆô¶¯Outlook¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-office-365-is-blocking-emails-from-google-linkedin-domains/


6.NatWestÒøÐÐ֪ͨ¿Í»§ÒòϵͳÃýÎ󣬣¬£¬£¬ £¬£¬£¬£¬×Ô¶¯¿Û¿î¿ÉÄÜ·¸´í


6.jpg


Ó¢¹úNatWestÒøÐÐ֪ͨ¿Í»§ÒòϵͳÃýÎ󣬣¬£¬£¬ £¬£¬£¬£¬×Ô¶¯¿Û¿î¿ÉÄÜ·¸´í¡£¡£¡£¡£¡£¡£Ó¢¹úÒøÐпͻ§Í¨³£Ê¹Óù̶¨¶©µ¥À´Ö§¸¶Õ˵¥¡¢×â½ðºÍÆä¶¨ÆÚ¸¶¿î¡£¡£¡£¡£¡£¡£Í¨Àý¶©µ¥Ô̺¬¸¶¿î½ð¶î¡¢¸¶¿îƵÂÊ£¨¼´Ã¿ÖÜ¡¢Ã¿Ô¡¢Ã¿¼¾¶ÈµÈ£©ÒÔ¼°¸¶¿îÓ¦ÔÚºÎʱʵÏÖ¡£¡£¡£¡£¡£¡£Õâ´Îϵͳ¹ÊÕϵ¼Ö¿ͻ§ËùÉèÖõÄͨÀý¶©µ¥Ã»ÓÐÕýÈ·µØ¼Í¼×Ô¶¯¸¶¿îµÄÆÚÊý»òÖÕ³¡¸¶¿îÈÕÆÚ£¬£¬£¬£¬ £¬£¬£¬£¬ÕâÒâζ×Ŷ©µ¥ÊµÏÖºóÈÔ¿ÉÄÜÔÚ¿Í»§ÕË»§ÖÐ×Ô¶¯¿Û¿î¡£¡£¡£¡£¡£¡£ÓÉÓÚÃýÎóÒѳÖÐøÁË11¸öÔÂÒÔÉÏ£¬£¬£¬£¬ £¬£¬£¬£¬Òò¶ø¸ÃÐн¨Òé¿Í»§²é³­ÆäÕË»§ÖÐ×Ô2020Äê3ÔÂ23ÈÕÒÔÀ´ÂòÂôµÄ¿î×Ó¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/technology/natwest-bank-scheduled-payments-bug-may-have-cost-you-money/