Apple°ä²¼°²È«¸üУ¬£¬£¬£¬£¬½¨¸´3¸öÒѱ»ÔÚÒ°ÀûÓõÄ0day£»£»£»£»£»£»£»×êÑÐÈËÔ±³ÆWindows IIS·þÎñÆ÷Öеķì϶¿ÉÓ°ÏìWinRM
°ä²¼¹¦·ò 2021-05-251.Apple°ä²¼°²È«¸üУ¬£¬£¬£¬£¬½¨¸´3¸öÒѱ»ÔÚÒ°ÀûÓõÄ0day

Æ»¹ûÒѾ°ä²¼Á˰²È«¸üУ¬£¬£¬£¬£¬½¨²¹3¸öÒѱ»ÔÚÒ°ÀûÓõÄmacOSºÍtvOS 0day¡£¡£¡£¡£¡£¡£¡£ÆäÖеÄÁ½¸öÊÇÄÚ´æ°Ü»µ·ì϶£¨CVE-2021-30663ºÍCVE-2021-30665£©£¬£¬£¬£¬£¬Ó°ÏìÁËApple TV 4KºÍApple TV HDÉ豸¡£¡£¡£¡£¡£¡£¡£µÚÈý¸öÊÇTCC¿ò¼ÜÖеÄÌáȨ·ì϶£¬£¬£¬£¬£¬Ó°ÏìÁËmacOS Big SurÉ豸£¬£¬£¬£¬£¬ÏÖÒѱ»XCSSET¶ñÒâÈí¼þÓÃÀ´ÈƹýmacOSÒþÖÔ±£»£»£»£»£»£»£»¤¡£¡£¡£¡£¡£¡£¡£±¾Ô³õ£¬£¬£¬£¬£¬Apple»¹½¨¸´ÁËWebkitÒýÇæÖеÄÁ½¸öiOS 0day¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/apple-fixes-three-zero-days-one-abused-by-xcsset-macos-malware/
2.ÃÀ¹úÔËͨÒò·¢ËÍ400¶àÍòÀ¬»øÓʼþ±»Ó¢¹ú·£¿£¿£¿£¿£¿£¿î9ÍòÓ¢°÷

ÃÀ¹úÔËͨ£¨Amex£©ÒòÔÚÒ»ÄêÄÚÏò¿Í»§·¢Ëͳ¬¹ý400Íò·âÀ¬»øÓʼþ£¬£¬£¬£¬£¬±»Ó¢¹úÊý¾Ý¼à¹Ü»ú¹¹·£¿£¿£¿£¿£¿£¿î90000Ó¢°÷¡£¡£¡£¡£¡£¡£¡£Ó¢¹úICO³Æ£¬£¬£¬£¬£¬ÔÚ2018Äê6ÔÂ1ÈÕÖÁ2019Äê5ÔÂ21ÈÕ£¬£¬£¬£¬£¬Amex·¢ËÍÁË4098841·âÖ¼ÔÚΪAmex´øÀ´¾¼ÃÀûÒæµÄÓªÏúµç×ÓÓʼþ¡£¡£¡£¡£¡£¡£¡£Òòδ¾ÔÞ³ÉÏòÊÕ¼þÈË·¢ËÍÓªÏúÓʼþ£¬£¬£¬£¬£¬AmexÎ¥·´ÁË2003Äê¡¶ÒþÖԺ͵ç×ÓͨѶÌõÀý¡·£¨PECR£©µÚ22Ìõ¡£¡£¡£¡£¡£¡£¡£Æ¾¾Ý¸ÃÌõ¿î¿É¶ÔÆä´¦ÒÔ×î¸ß50ÍòÓ¢°÷µÄ·£¿£¿£¿£¿£¿£¿î£¬£¬£¬£¬£¬µ«ÒòÆäûÓÐÓÐÒâÎ¥·´PECR£¬£¬£¬£¬£¬½ö·£¿£¿£¿£¿£¿£¿î9Íò£¬£¬£¬£¬£¬AmexÐëÔÚ6ÔÂ17ÈÕ֮ǰ֧¸¶Õâ±Ê·£¿£¿£¿£¿£¿£¿î¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/amex-fined-90-000-for-sending-4-million-spam-emails-in-a-year/
3.΢ÈíÎ´Ðø¶©ExchangeµÄSSLÖ¤Ê飬£¬£¬£¬£¬ChromeÌáÐѲ»ÈݽӼû

ÃÀ¹ú¶«²¿±ê¶¨¹¦·ò2021Äê5ÔÂ23ÈÕÉÏÎç8µãÆðÍ·£¬£¬£¬£¬£¬Óû§·´Ó³ÎÞ·¨µÇ¼ExchangeµÄÍøÕ¾admin.exchange.microsoft.com¡£¡£¡£¡£¡£¡£¡£ÕâÊÇÓÉÓÚ¸ÃÍøÕ¾µÄSSLÖ¤ÊéÒѹýÆÚ¶øMicrosoft½¡ÍüÐø¶©µ¼Öµġ£¡£¡£¡£¡£¡£¡£ÎªÁ˰²È«Æð¼û£¬£¬£¬£¬£¬¹È¸èä¯ÀÀÆ÷ÆëÈ«²»ÈÝÁ˽Ӽû¸ÃÍøÕ¾£¬£¬£¬£¬£¬¶øFirefoxÔòÖÒ¸æÁ´½Ó²»°²È«¡£¡£¡£¡£¡£¡£¡£Microsoft³ÆÓû§Äܹ»Ò»Ê±Ê¹ÓÃhttps://outlook.office.com/ecp/Á´½ÓÀ´½Ó¼û¸ÃÍøÕ¾£¬£¬£¬£¬£¬²¢ÒÑÓÚ5ÔÂ24ÈÕ½â¾ö¸ÃÎÊÌâ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-admin-portal-blocked-by-expired-ssl-certificate/
4.×êÑÐÈËÔ±³ÆWindows IIS·þÎñÆ÷Öеķì϶¿ÉÓ°ÏìWinRM

×êÑÐÈËÔ±im DeVries³ÆWindows IIS·þÎñÆ÷Öеķì϶¿ÉÓ°ÏìWinRM¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇWindows IIS·þÎñÆ÷ʹÓõÄHTTPºÍ̸ջ£¨http.sys£©ÖеÄÔ¶³ÌÖ´ÐдúÂë·ì϶£¬£¬£¬£¬£¬±»×·×ÙΪCVE-2021-31166£¬£¬£¬£¬£¬ÒÑͨ¹ýMicrosoft°ä²¼µÄ5Ô·ݰ²È«¸üн¨¸´¡£¡£¡£¡£¡£¡£¡£ÉÏÖÜÄ©£¬£¬£¬£¬£¬Axel Souchet°ä²¼Á˸÷ì϶µÄPoC£¬£¬£¬£¬£¬¿ÉÀûÓÃÌØÔìµÄÊý¾Ý°üµ¼ÖÂÀ¶ÆÁËÀ»ú¡£¡£¡£¡£¡£¡£¡£µ«ÊÇ£¬£¬£¬£¬£¬Jim DeVries·¢ÏÖËü»¹»áÓ°ÏìÔËÐÐÁËWinRM·þÎñ£¨WindowsÔ¶³ÌÖÎÀí£©µÄWindows 10ϵͳºÍ·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£Will Dormann³Æ£¬£¬£¬£¬£¬Óг¬¹ý200Íò¸öWinRM·þÎñ¶³öµÄWindowsϵͳÄܹ»Í¨¹ýInternet½Ó¼û¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/118189/security/cve-2021-31166-windows-http-flaw.html
5.Proofpoint°ä²¼2021ÄêQ2ÆóÒµµç×ÓÓʼþ°²È«µÄ»ã±¨

Proofpoint°ä²¼ÁË2021ÄêQ2ÆóÒµµç×ÓÓʼþ°²È«µÄ»ã±¨¡£¡£¡£¡£¡£¡£¡£¸Ã»ã±¨»ùÓÚ25¸ö³ß¶È¶Ô15¸öÆóÒµµç×ÓÓʼþ·þÎñÌṩÉ̽øÐÐÁËÆÀ¹À£¬£¬£¬£¬£¬Éæ¼°Èý¸ö·½Ã棺µ±Ç°²úÆ·¡¢Õ½ÊõºÍÊг¡Õ¼ÓÐÂÊ¡£¡£¡£¡£¡£¡£¡£ÔÚÆÀ¹ÀµÄ¹©¸øÉÌÖУ¬£¬£¬£¬£¬ProofpointÊǽöÓеÄÎå¸öµ±ÏÈÕßÖ®Ò»¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬×î¼ÑµÄµç×ÓÓʼþ°²È«½â¾ö¹æ»®½«¿Í»§»·¾³ÓëEDR¡¢WebÄÚÈݰ²È«ÐÔ£¨Ô̺¬ä¯ÀÀÆ÷¸ôÀ룩ÒÔ¼°°²È«ÒâʶºÍÅàѵ£¨SA£¦T£©µÈ½â¾ö¹æ»®¼¯³ÉÔÚһ·¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.proofpoint.com/us/resources/analyst-reports/forrester-wave-report-enterprise-email-security
6.Lookout°ä²¼ÓйؽðÈÚ·þÎñµÄÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨

Lookout°ä²¼ÁËÓйؽðÈÚ·þÎñ2019ÄêÖÁ2020ÄêÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£LookoutÊý¾ÝÏÔʾ£¬£¬£¬£¬£¬½ðÈÚ×é֯ÿ¼¾¶È¾ùÔÈÔâ·êµÄÍøÂç´¹µö¹¥»÷Ôö³¤ÁË125£¥£¬£¬£¬£¬£¬¶ñÒâÀûÓ÷¨Ê½Ôö³¤ÁË400£¥£¬£¬£¬£¬£¬Òƶ¯É豸ÖÎÀí£¨MDM£©Ê¹ÓÃÂÊÌá¸ßÁË50£¥£¬£¬£¬£¬£¬ÏÕЩ50£¥µÄ´¹µö¹¥»÷¶¼ÊÔͼÇÔÈ¡¹«Ë¾µÇ¼ʹ´¦£¬£¬£¬£¬£¬½ü20£¥µÄÒÆ¶¯ÒøÐпͻ§¶Ë×°ÓÐľÂíÀûÓᣡ£¡£¡£¡£¡£¡£¸Ã»ã±¨½¨Òé½ðÈÚ»ú¹¹±ØÒªÑ¡È¡ÏÖ´ú°²È«¼¼ÊõºÍÕ½Êõ£¬£¬£¬£¬£¬À´±£ÕÏÔ±¹¤ºÍ¿Í»§³£ÓÃÉ豸ÉÏά³Ö°²È«ÐÔ¡¢¾ºÕùÁ¦ºÍÓйØÐÔ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.lookout.com/info/financial-services-threat-report-lp


¾©¹«Íø°²±¸11010802024551ºÅ