AzureÔÆÕÊ»§ÒòÅäÖÃÃýÎóй¶΢Èí¶à¿î²úÆ·µÄÔ´´úÂ룻£»£»£»£»£»Microsoft TeamsÓÉÓÚÅäÖøü¸ÄÔÙ´ÎÖжÏ£¬£¬£¬£¬£¬£¬Ó°ÏìÈ«ÇòÓû§

°ä²¼¹¦·ò 2021-04-29

1.AzureÔÆÕÊ»§ÒòÅäÖÃÃýÎóй¶΢Èí¶à¿î²úÆ·µÄÔ´´úÂë


1.jpg


vpnMentor×êÑÐÍŶӷ¢ÏÖÒ»¸öÅäÖÃÃýÎóµÄMicrosoft Azure BlobÔÆÕÊ»§Ð¹Â¶ÁË΢Èí¶à¿î²úÆ·µÄÔ´´úÂë¡£¡£¡£¡£¡£¡£ ¡£Ð¹Â¶Êý¾ÝµÄ×Ü´óÓ×Ϊ63GB£¬£¬£¬£¬£¬£¬Ô̺¬³¬¹ý3800¸öÎļþ£¬£¬£¬£¬£¬£¬Éæ¼°Éϰټҹ«Ë¾µÄÈÚ×ÊÑݽ²¸åºÍ10-15ÖÖ²úÆ·µÄÔ´´úÂ룬£¬£¬£¬£¬£¬ÓÚ2021Äê1ÔÂ7ÈÕ±»·¢ÏÖ²¢ÒÑÔÚ2021Äê2ÔÂ23Èյõ½±£»£»£»£»£»£»¤¡£¡£¡£¡£¡£¡£ ¡£ÕâЩÎļþΪ¶à¶à¹«Ë¾ÏòMicrosoft Dynamics×ö³öµÄһϵÁÐóÒ×Ðû´«ºÍ²úÆ·×¢Ã÷£¬£¬£¬£¬£¬£¬¿ÉÄÜÀ´×Ô΢Èí¹«Ë¾¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.vpnmentor.com/blog/report-microsoft-dynamics-leak/


2.ÔÆÌṩÉÌDigitalOcean³ÆÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬¿Í»§ÕÊ»§ÐÅϢй¶


2.jpg


ÔÆÍйÜÌṩÉÌDigitalOcean³ÆÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬²¿Ãſͻ§µÄÕÊ»§ÐÅϢй¶¡£¡£¡£¡£¡£¡£ ¡£DigitalOceanÏòÊÜÓ°Ïì¿Í»§·¢ËÍÓʼþ£¬£¬£¬£¬£¬£¬³ÆÔÚ2021Äê4ÔÂ9ÈÕÖÁ2021Äê4ÔÂ22ÈÕÖ®¼ä£¬£¬£¬£¬£¬£¬Î´¾­ÊÚȨµÄÓû§ÀûÓÃÒ»¸ö·ì϶½Ó¼ûÁ˲¿ÃÅÓû§µÄÕ˵¥ÐÅÏ¢£¬£¬£¬£¬£¬£¬´Ë¿Ì¸Ã·ì϶Òѱ»½¨¸´¡£¡£¡£¡£¡£¡£ ¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬¿Í»§µÄÕ˵¥Ãû³Æ¡¢Õ˵¥µØÖ·¡¢ÐÅÓþ¿¨µ½ÆÚ¹¦·ò¡¢ÐÅÓþ¿¨µÄºóËÄλÊý×ÖÒÔ¼°ÐÅÓþ¿¨µÄÒøÐÐÃû³Æ¡£¡£¡£¡£¡£¡£ ¡£DigitalOceanÔÚÈ¥ÄêÒ²²úÉúÁËÊý¾Ýй¶£¬£¬£¬£¬£¬£¬ÊÇÓÉÓÚ¹«¿ªÁ´½ÓÖÐÔ̺¬Á˿ͻ§ÕÊ»§ÐÅÏ¢µÄÎĵµ¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/digitalocean-data-breach-exposes-customer-billing-information/    


3.Microsoft TeamsÓÉÓÚÅäÖøü¸ÄÔÙ´ÎÖжÏ£¬£¬£¬£¬£¬£¬Ó°ÏìÈ«ÇòÓû§


3.jpg


Microsoft TeamsÔٴβúÉú·þÎñÖжÏ£¬£¬£¬£¬£¬£¬Ó°ÏìÈ«ÇòÁìÓòÄÚµÄÓû§¡£¡£¡£¡£¡£¡£ ¡£Õâ´ÎÖжϲúÉúÔÚ4ÔÂ27ÈÕUTC¹¦·ò9:58ºÍ12:05Ö®¼ä£¬£¬£¬£¬£¬£¬Óû§ÎÞ·¨·¢ËͺͽӹÜÐÂÎÅ¡¢²ÎÓëÆµÂ·¡¢²ÎÓë̸ÌìºÍÅÔ¹ÛÆµÂ·¡£¡£¡£¡£¡£¡£ ¡£¾­µ÷²é£¬£¬£¬£¬£¬£¬MicrosoftÈ·ÈÏÕâÊÇÓÉ×î½üµÄÅäÖøü¸ÄÒýÆðµÄ£¬£¬£¬£¬£¬£¬¸ü¸Äµ¼ÖÂÌØ¶¨Ö°ÄÜÉèÖÃÖеÄÖµÃýÎ󣬣¬£¬£¬£¬£¬´Ó¶ø¶Ô·þÎñÔì³ÉÓ°Ï죬£¬£¬£¬£¬£¬ÎÊÌâÏÖÒѽ¨¸´¡£¡£¡£¡£¡£¡£ ¡£ÔÚ±¾Ô³õ£¬£¬£¬£¬£¬£¬ÓÉÓÚDNS²éÎÊÒì³£¼¤ÔöʹAzure DNS·þÎñÆ÷³¬ÔØ£¬£¬£¬£¬£¬£¬µ¼ÖÂÁËMicrosoft TeamsµÈ¶à¶à·þÎñÔÚÈ«ÇòÁìÓòÄÚÀï¶Ï¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-teams-worldwide-outage-impacts-user-logins-chats/


4.ArmorbloxÅû¶Õë¶ÔĦ¸ù´óÍ¨ÒøÐпͻ§µÄ´¹µö¹¥»÷»î¶¯


4.jpg


Armorblox×êÑÐÈËÔ±Åû¶½üÆÚÕë¶ÔĦ¸ù´óÍ¨ÒøÐпͻ§µÄ´¹µö¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£ ¡£ÕâЩ»î¶¯¶¼Ñ¡È¡ÁËÉç»á¹¤³Ì¹¥»÷ºÍ¼ÙÒâÆ·ÅÆµÄÕ½Êõ£¬£¬£¬£¬£¬£¬²¢ÀûÓÃÁËһϵÁм¼ÊõÀ´Èƹýµç×ÓÓʼþ°²È«¹ýÂËÆ÷£¬£¬£¬£¬£¬£¬Ì°Í¼ÇÔÈ¡¿Í»§µÄµÇ¼ʹ´¦¡£¡£¡£¡£¡£¡£ ¡£Ò»²¿ÃŹ¥»÷¼ÙÒâJp Morgan Chase£¬£¬£¬£¬£¬£¬ÒÔ¡°ÄúµÄÐÅÓþ¿¨¶ÔÕʵ¥Òѳﱸ¾ÍÐ÷¡±ÎªÌ⣬£¬£¬£¬£¬£¬ÓÕʹָ±êµã»÷¼Ù×°³Éδ֧¸¶Õ˵¥µÄÁ´½Ó²¢ÊäÈëÒøÐÐÍ´´¦¡£¡£¡£¡£¡£¡£ ¡£ÁíһЩ¹¥»÷¼ÙÒâÒøÐеķÀڲƭ²¿ÃÅ£¬£¬£¬£¬£¬£¬ÒÔ¡°´¹Î££ºÒì³£µÄµÇ¼»î¶¯¡±Îª±êÌâ±êÓʼþÇÔÈ¡ÒøÐÐÍ´´¦¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/threat-actors-impersonate-chase/


5.Èí¼þ°üÖÎÀíÆ÷CocoaPods´æÔÚRCE·ì϶£¬£¬£¬£¬£¬£¬300¶àÍò¸öÀûÓÃÊÜÓ°Ïì


5.jpg


×êÑÐÔ±Max Justicz·¢ÏÖÈí¼þ°üÖÎÀíÆ÷CocoaPods´æÔÚRCE·ì϶£¬£¬£¬£¬£¬£¬¿ÉÄÜÓ°ÏìSignalµÈ300¶àÍò¸öÀûÓᣡ£¡£¡£¡£¡£ ¡£CocoaPodsÊÇʹÓÃRuby¹¹½¨µÄÀûÓ÷¨Ê½¼¶ÒÀÀµ¹ØÏµÖÎÀíÆ÷£¬£¬£¬£¬£¬£¬ÌṩÁËÒ»Öֳ߶ÈÌåʽÀ´ÖÎÀí±í²¿¿â¡£¡£¡£¡£¡£¡£ ¡£¹¥»÷ÕßÔÚÉÏ´«°üµÄ¹æ¸ñµ½CocoaPodsʱ£¬£¬£¬£¬£¬£¬¿ÉÆëÈ«½ÚÔì@specification.source[:git]ºÍref.to_£¬£¬£¬£¬£¬£¬Òò¶øÔÚÓµÓÐTrunk key£¨¹æ¸ñ¿â£©µÄCocoaPods·þÎñÆ÷Äܹ»Ô¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£ ¡£×êÑÐÔ±³Æ¸Ã·ì϶ÒѾ­´æÔÚ6Ä꣨³õ´Î³Ê´Ë¿Ì2015Äê6ÔÂ4ÈÕ£©£¬£¬£¬£¬£¬£¬Ö±µ½×î½ü²Å±»½¨¸´¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2021/04/27/cocoapods-rce-vulnerability-could-risk-3-million-mobile-apps-including-signal/


6.CISAºÍNIST½áºÏ°ä²¼ÓйØÕмÜÈí¼þ¹©¸øÁ´¹¥»÷µÄÖ¸ÄÏ


6.jpg


CISAºÍÃÀ¹ú¹ú¶È³ß¶È¼¼Êõ×êÑÐÔº£¨NIST£©½áºÏ°ä²¼ÁËÓйØÕмÜÈí¼þ¹©¸øÁ´¹¥»÷µÄÖ¸ÄÏ¡£¡£¡£¡£¡£¡£ ¡£¸ÃÖ¸ÄϸÅÊöÁËÈí¼þ¹©¸øÁ´µÄ·çÏÕ£¬£¬£¬£¬£¬£¬ÒÔ¼°Èí¼þ¿Í»§ºÍ¹©¸øÉÌÈôºÎʹÓÃNISTÍøÂ繩¸øÁ´·çÏÕÖÎÀí(C-SCRM)¿ò¼ÜºÍ°²È«Èí¼þ¿ª·¢¿ò¼Ü(SSDF)À´¼ø±ð¡¢ÆÀ¹À»ººÍ½âÈí¼þ¹©¸øÁ´·çÏյĽ¨Òé¡£¡£¡£¡£¡£¡£ ¡£´Ë±í£¬£¬£¬£¬£¬£¬¸ÃÖ¸ÄÏΪÈí¼þ¿Í»§ºÍ¹©¸øÉÌÌṩÁËÔ¤·À¡¢»º½âºÍ¸´Ô­Èí¼þ¹©¸øÁ´¹¥»÷µÄ¹Ø¼ü²½ÖèºÍÉî¿ÌµÄ½¨Òé¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/04/26/cisa-and-nist-release-new-interagency-resource-defending-against