Kaseya°²È«¸üн¨¸´REvilÔÚ¹©¸øÁ´¹¥»÷ÖÐÓõÄ0day£»£» £»£»£»£»Ð¶ñÒâÈí¼þBIOPASSÀûÓÃÖ±²¥ÀûÓÃOBS¼ÔìÖ¸±êµÄÆÁÄ»

°ä²¼¹¦·ò 2021-07-13
1.Kaseya°²È«¸üн¨¸´REvilÔÚ¹©¸øÁ´¹¥»÷ÖÐÓõÄ0day


1.jpg


Kaseya°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´REvilÔÚ¹©¸øÁ´¹¥»÷ÖÐÓõÄ0day¡£¡£¡£¡£¡£4Ô£¬£¬£¬£¬£¬£¬£¬£¬ºÉÀ¼·ì϶Åû¶×êÑÐËù (DIVD)Åû¶ÁËKaseyaµÄ7¸ö·ì϶¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬£¬£¬Kaseya¶ÔÆäVSA SaaS·þÎñÉϵĴó²¿ÃÅ·ì϶°ä²¼Á˲¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬£¬µ«ÉÐδʵÏÖÄÚ²¿°æ±¾VSAµÄ²¹¶¡¡£¡£¡£¡£¡£¶øREvilÍÅ»ïÏÈÒ»²½ÀûÓÃÁËÕâЩ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÓÚ7ÔÂ2ÈÕ¶ÔԼĪ60¸öMSPºÍ1500¼ÒÆóÒµ¿Í»§ÌáÒéÁË´ó¹æÄ£¹¥»÷¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬Kaseya°ä²¼ÁËVSA 9.5.7a (9.5.7.2994) ¸üÐÂÒÔ½¨¸´REvilʹÓõķì϶£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬CVE-2021-30116¡¢CVE-2021-30119ºÍCVE-2021-30120µÈ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/kaseya-patches-vsa-vulnerabilities-used-in-revil-ransomware-attack/


2.жñÒâÈí¼þBIOPASSÀûÓÃÖ±²¥ÀûÓÃOBS¼ÔìÖ¸±êµÄÆÁÄ»


2.jpg


°²È«¹«Ë¾Ç÷Ïò¿Æ¼¼·¢ÏÖжñÒâÈí¼þBIOPASSÀûÓÃÖ±²¥ÀûÓÃOBS¼ÔìÖ¸±êÍÆËã»úµÄÆÁÄ»¡£¡£¡£¡£¡£BIOPASSÊÇÓÃPython±àдµÄÔ¶³Ì½Ó¼ûľÂí (RAT)£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ×î½üÕë¶ÔÔÚÏß´ò¶Ä¹«Ë¾µÄ¹¥»÷Öб»·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬±»°µ²ØÔںϷ¨µÄAdobe Flash Player»òMicrosoft SilverlightµÄ×°Ö÷¨Ê½ÖС£¡£¡£¡£¡£BIOPASS RATÓµÓÐÔÚÆäËû¶ñÒâÈí¼þµÄ¸ù»ùÖ°ÄÜ£¬£¬£¬£¬£¬£¬£¬£¬µ«»¹ÓÐÒ»ÏîÐÂÖ°ÄÜ£¬£¬£¬£¬£¬£¬£¬£¬¼´ÔÚÖ¸±êϵͳÉÏ×°ÖÃOBS StudioÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓøÃÈí¼þµÄ RTMP£¨ÊµÊ±ÐÂÎÅ´«µÝºÍ̸£©Á÷ýÌåÖ°ÄÜÀ´Â¼ÔìÓû§µÄÆÁÄ»²¢½«Æä¹ã²¥µ½¹¥»÷ÕߵĽÚÔį̀¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/malware-abuses-obs-live-streaming-software-to-record-victims-screens/


3.ÃÀ¹úÏðÊ÷ÁëÒøÐÐ֪ͨÆä¿Í»§ÒòÍøÂç¹¥»÷Ó×ÎÒÐÅϢй¶


3.jpg


ÃÀ¹úÏðÊ÷ÁëÒøÐУ¨Bank Of Oak Ridge£©ÓÚ7ÔÂ9ÈÕÐÇÆÚÎå֪ͨÆä¿Í»§ÒòÍøÂç¹¥»÷Ó×ÎÒÐÅϢй¶¡£¡£¡£¡£¡£¸ÃÒøÐÐ³ÆÆäÔâµ½ÁËÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÒøÐеIJ¿ÃÅ·þÎñÁÙʱÖжϣ¬£¬£¬£¬£¬£¬£¬£¬¾­µ÷²é·¢ÏÖ»¹ÓÐδ¾­ÊÚȨµÄ¹¥»÷Õß½Ó¼ûÁËÆäϵͳ¡£¡£¡£¡£¡£Õâ´Î¹¥»÷²úÉúÔÚ4ÔÂ26ÈÕºÍ4ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ2009Äê9ÔÂ30ÈÕ֮ǰ¿ªÉèÕË»§µÄ³Ö¾Ã¿Í»§µÄÐÅÏ¢¿ÉÄÜÒѾ­Ð¹Â¶£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬Éç»á°²È«ºÅÂë¡¢ÒøÐÐÕʺ𢵮ÉúÈÕÆÚºÍ¼ÝÊ»ÅÆÕÕºÅÂëµÈ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.rhinotimes.com/featured-article/hackers-steal-critical-customer-data-from-bank-of-oak-ridge/


4.CISAÖÒ¸æForgeRock½Ó¼ûÖÎÀíÖÐÒѱ»ÀûÓõÄREC·ì϶


4.jpg


CISAÖҸ湥»÷ÕßÔÚ»ý¼«ÀûÓÃForgeRock½Ó¼ûÖÎÀí(AM)ÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶ (CVE-2021-35464)¡£¡£¡£¡£¡£ForgeRock½Ó¼ûÖÎÀíÊÇÒ»¸ö»ùÓÚ¿ªÔ´½Ó¼ûÖÎÀí½â¾ö¹æ»®OpenAMµÄóÒ×Ê¢¿ª½Ó¼ûÖÎÀíµÄ½â¾ö¹æ»®¡£¡£¡£¡£¡£ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚµ±Ç°Óû§µÄϵͳÖÐÖ´ÐкÅÁ£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁËAM°æ±¾6.0.0.x¡¢6.5.0.x¡¢6.5.1¡¢6.5.2.xºÍ6.5.3¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÒѰ䲼ÁËÕë¶Ô¸Ã·ì϶µÄ»º½â´ëÊ©¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/07/12/critical-forgerock-access-management-vulnerability


5.Security Compass°ä²¼2021ÄêÍþв½¨Ä£µÄÌ¬ÊÆ»ã±¨


5.jpg


Security Compass°ä²¼ÁË2021ÄêÍþв½¨Ä£Ì¬ÊƵķÖÎö»ã±¨¡£¡£¡£¡£¡£¸Ã»ã±¨Ö¼ÔÚÏàʶÍþв½¨Ä£È·µ±Ç°Ì¬ÊÆ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°´óÐÍÆóÒµÔÚ¹¹½¨ºÍ²¿ÊðÀûÓ÷¨Ê½Ê±Óöµ½µÄÌôÕ½¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬£¬£¬Ö»ÓÐ25%µÄÊÜ·ÃÕß°µÊ¾ËûÃǵÄ×éÖ¯ÔÚÈí¼þ¿ª·¢µÄÐèÒªÍøÂçºÍÉè¼ÆÔçÆÚ½×¶Î½øÐÐÁËÍþв½¨Ä££¬£¬£¬£¬£¬£¬£¬£¬²»µ½10%µÄÊÜ·ÃÕß°µÊ¾ËûÃǶÔ90%Ö®ÉϵÄÀûÓýøÐÐÁËÍþв½¨Ä£¡£¡£¡£¡£¡£µ«ÊÇÓÉÓÚCOVID-19£¬£¬£¬£¬£¬£¬£¬£¬³¬¹ý80%µÄ×éÖ¯²»µÃ²»ºÏÆäÍøÂ簲ȫ´ëÊ©½øÐÐŤת¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://resources.securitycompass.com/research/2021-state-of-threatmodeling


6.BetterCloud°ä²¼2021ÄêÎļþ°²È«µÄ·çÏÕ·ÖÎö»ã±¨


6.jpg


BetterCloud°ä²¼ÁË2021ÄêÎļþ°²È«µÄ·çÏÕ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¸Ã»ã±¨µ÷²éÁË500¶àÃûITºÍ°²È«ÈËÔ±ÒÔÏàʶµ±½ñSaaSÎļþ°²È«¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬£¬£¬½üÒ»°ëµÄ×éÖ¯°µÊ¾ËûÃÇ×î¹ØÇеݲȫÎÊÌâÊDz»ÖªÂ·Ãô¸ÐÊý¾ÝµÄµØÎ»£»£» £»£»£»£»³¬¹ý70%µÄ×éÖ¯°µÊ¾×î´óµÄÊý¾Ýй¶·çÏÕÊÇÔ±¹¤£»£» £»£»£»£»Ö»ÓÐ35%µÄÊÜ·ÃÕßÏàÐÅÖÕ¶ËÓû§»áÕÆ¹ÜÈεطÖÏíºÍ´æ´¢¹«Ë¾Êý¾Ý¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬2021ÄêËæ×ÅÈ«ÇòÒµÎñµÄ¸´Ô­£¬£¬£¬£¬£¬£¬£¬£¬Îļþ°²È«ÊÂÎñì­ÉýÁË134%¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bettercloud.com/monitor/file-security-report-2021/