΢Èí°ä²¼7Ô·ݰ²È«¸üУ¬ £¬£¬£¬£¬£¬£¬½¨¸´9¸ö0dayÔÚÄÚµÄ117¸ö·ì϶£»£»£»£»£»£»£»£»Ê±ÉÐÆ·ÅÆGuessÔâµ½DarkSideÀÕË÷¹¥»÷й¶200GBÎļþ

°ä²¼¹¦·ò 2021-07-15

1.΢Èí°ä²¼7Ô·ݰ²È«¸üУ¬ £¬£¬£¬£¬£¬£¬½¨¸´9¸ö0dayÔÚÄÚµÄ117¸ö·ì϶


1.jpg


΢Èí°ä²¼ÁË2021Äê7Ô·ݵÄÖܶþ²¹¶¡£¬ £¬£¬£¬£¬£¬£¬½¨¸´ÁËÔ̺¬9¸ö0dayÔÚÄÚµÄ117¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶ÖУ¬ £¬£¬£¬£¬£¬£¬44¸öΪԶ³Ì´úÂëÖ´ÐУ¬ £¬£¬£¬£¬£¬£¬32¸öΪÌáȨ·ì϶£¬ £¬£¬£¬£¬£¬£¬14¸öΪÐÅϢй¶·ì϶£¬ £¬£¬£¬£¬£¬£¬12¸öΪ»Ø¾ø·þÎñ·ì϶£¬ £¬£¬£¬£¬£¬£¬8¸öΪ°²È«Ö°ÄÜÈÆ¹ý·ì϶£¬ £¬£¬£¬£¬£¬£¬7¸öΪºýŪ·ì϶¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ9¸ö0dayÖУ¬ £¬£¬£¬£¬£¬£¬ÓÐ4¸öÒѱ»ÔÚÔÚÒ°ÀûÓ㬠£¬£¬£¬£¬£¬£¬Ô̺¬PrintNightmare·ì϶£¨CVE-2021-34527£©¡¢WindowsÄÚºËÌáȨ·ì϶£¨CVE-2021-33771ºÍCVE-2021-31979£©ÒÔ¼°¾ç±¾ÒýÇæÄÚ´æ°Ü»µ·ì϶£¨CVE-2021-34448£©¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2021-patch-tuesday-fixes-9-zero-days-117-flaws/


2.SolarWinds½¨¸´Serv-UÖÐÒѱ»ÀûÓõÄÔ¶³Ì´úÂëÖ´Ðзì϶


2.jpg


SolarWindsÔÚ7ÔÂ9ÈÕ°ä²¼µÄServ-U 15.2.3 HF2Öн¨¸´ÁËÒ»¸öÒѱ»ÀûÓõÄ0day¡£¡£¡£¡£¡£¡£¡£¡£MicrosoftÅû¶ÁËServ-U²úÆ·µÄÔ¶³Ì´úÂëÖ´ÐÐ0day£¨CVE-2021-35211£©£¬ £¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷ÕßÀûÓô˷ì϶¿ÉÄÜÒÔÌØÊâȨÏÞÖ´ÐÐËÁÒâ´úÂ룬 £¬£¬£¬£¬£¬£¬ÔÚÖ¸±êϵͳÉÏ×°Öò¢ÔËÐз¨Ê½¡¢²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾ÝµÈ¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°¸Ã·ì϶ÒѾ­³ö±»Ò°ÀûÓ㬠£¬£¬£¬£¬£¬£¬µ«SolarWinds°µÊ¾£¬ £¬£¬£¬£¬£¬£¬ÈôÊÇServ-U»·¾³ÖÐδÆôÓÃSSH£¬ £¬£¬£¬£¬£¬£¬Ôò¸Ã·ì϶²»´æÔÚ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/solarwinds-patches-critical-serv-u-vulnerability-exploited-in-the-wild/


3.ʱÉÐÆ·ÅÆGuessÔâµ½DarkSideÀÕË÷¹¥»÷й¶200GBÎļþ


3.jpg


ÃÀ¹úʱÉÐÆ·ÅƺÍÁãÊÛÉÌGuessÔâµ½DarkSideÀÕË÷¹¥»÷й¶200GBÎļþ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾³Æ£¬ £¬£¬£¬£¬£¬£¬¹¥»÷²úÉúÔÚ2021Äê2ÔÂ2ÈÕÖÁ2021Äê2ÔÂ23ÈÕ£¬ £¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚ6ÔÂ3ÈÕʵÏÖµ÷²éºóÈ·¶¨ÁËÊÜÓ°ÏìµÄ¿Í»§²¢ÓÚ6ÔÂ9ÈÕ½«´ËÊÂÎñ֪ͨ¸øÆä¿Í»§¡£¡£¡£¡£¡£¡£¡£¡£¾­µ÷²éÈ·¶¨£¬ £¬£¬£¬£¬£¬£¬Ð¹Â¶ÐÅÏ¢Ô̺¬Éç»á°²È«ºÅÂë¡¢¼ÝÕÕºÅÂë¡¢»¤ÕÕºÅÂëºÍ/»ò²ÆÕþÕʺÅ£¬ £¬£¬£¬£¬£¬£¬Ö»Éæ¼°1300¶àÈË¡£¡£¡£¡£¡£¡£¡£¡£Guess²¢Î´Í¸Â©Óйع¥»÷ÕßµÄÈκÎÐÅÏ¢£¬ £¬£¬£¬£¬£¬£¬µ«ÊÇDarkSideÔøÔÚ4Ô·ÝÐû³ÆÆä¹¥»÷ÁËGuess²¢ÇÔÈ¡Á˳¬¹ý200GBµÄÎļþ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/fashion-retailer-guess-notifies-users-data-breach


4.ºÚ¿ÍÏúÊÛ6ÒÚLinkedInÓû§ÐÅÏ¢²¢³ÆÐÂÊý¾Ý±È֮ǰµÄ¸üºÃ


4.jpg


ºÚ¿ÍÔÚ°µÍøÏúÊÛÁË6ÒÚ¸öLinkedInÓû§µÄÐÅÏ¢£¬ £¬£¬£¬£¬£¬£¬²¢³ÆÕâЩÊý¾ÝÊÇеÄ£¬ £¬£¬£¬£¬£¬£¬±ÈÖ®Ç°ÍøÂçµÄÊý¾Ý¸üºÃ¡£¡£¡£¡£¡£¡£¡£¡£ºÚ¿Í°ä²¼ÁË632699¸öÓû§ÐÅÏ¢×÷ΪÑù±¾£¬ £¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬ÁËÐÕÃû¡¢ÁìÓ¢ID¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢LinkedInÓ×ÎÒ×ÊÁÏURL¡¢ÆäËûÉ罻ýÌå×ÊÁϵÄÁ´½Ó¡¢ÐԱ𡢵®ÉúÈÕÆÚ¡¢µØÖ·¡¢Ö°³ÆºÍÆäËû¹¤×÷ÓйØÊý¾ÝµÈ¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬ £¬£¬£¬£¬£¬£¬¹ÌÈ»ÕâЩÊý¾Ý²»ÊǺÜÃô¸Ð£¬ £¬£¬£¬£¬£¬£¬µ«¹¥»÷ÕßÒÀÈ»Äܹ»ÀûÓÃÕâЩÐÅϢͨ¹ýÉç»á¹¤³ÌµÄ²½Öè¼±¾çµØÕÒµ½Ð¹¥»÷Ö¸±ê¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cybernews.com/news/threat-actors-scrape-600-million-linkedin-profiles-and-are-selling-the-data-online-again/


5.×êÑÐÈËÔ±·¢ÏÖTrickBot»Ø¹é²¢ÐÂÔöÓÃÓÚ¼à¿ØµÄVNCÄ£¿£¿£¿£¿£¿£¿£¿é


5.jpg


×êÑÐÈËÔ±·¢ÏÖTrickBot»Ø¹é²¢ÐÂÔöÁËÓÃÓÚ¼à¿ØºÍµý±¨ÍøÂçµÄVNCÄ£¿£¿£¿£¿£¿£¿£¿é¡£¡£¡£¡£¡£¡£¡£¡£Trickbot×Ô2016Äêµ×ÒÔÀ´Ò»Ïò»îÔ¾£¬ £¬£¬£¬£¬£¬£¬²¢ÓÚ2020Äê10Ô·ݱ»Î¢ÈíºÍ¶à¸ö°²È«³§É̽áºÏµ·»Ù¡£¡£¡£¡£¡£¡£¡£¡£µ«ÊÇ£¬ £¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖĿǰµÄTrickbot±ÈÒÔÍùÈκÎʱ³½¶¼Ô½·¢»îÔ¾£¬ £¬£¬£¬£¬£¬£¬²¢ÓÚ2021Äê5Ô¼ì²âµ½ÁËvncDllÄ£¿£¿£¿£¿£¿£¿£¿éµÄ¸üа汾tvncDll£¬ £¬£¬£¬£¬£¬£¬ÓÃÓÚ¼à¿ØºÍµý±¨ÍøÂç¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÄ£¿£¿£¿£¿£¿£¿£¿éËÆºõ»¹ÔÚ¿ª·¢ÖУ¬ £¬£¬£¬£¬£¬£¬ÓÉÓÚÓÐÒ»¸öƵÈԵĸüй¦·ò±í£¬ £¬£¬£¬£¬£¬£¬À´¶¨ÆÚÔö³¤ÐÂÖ°Äܺͽ¨¸´ÃýÎ󡣡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bitdefender.com/blog/labs/trickbot-activity-increases-new-vnc-module-on-the-radar


6.AberdeenºÍcode42½áºÏ°ä²¼ÓйØÄÚ²¿·çÏյķÖÎö»ã±¨


6.jpg


AberdeenºÍcode42½áºÏ°ä²¼ÁËÓйØÄÚ²¿·çÏյķÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬ £¬£¬£¬£¬£¬£¬Èý·ÖÖ®Ò»µÄÊý¾Ýй¶ÊÂÎñÉæ¼°ÄÚ²¿ÈËÔ±£¬ £¬£¬£¬£¬£¬£¬¶øÆäÖÐÔ¼80%ÈËÊÇÎÞÒâµÄ£»£»£»£»£»£»£»£»75%µÄ×éÖ¯¶ÔÆä»·¾³Ã»ÓÐÒ»Ö¡¢¼¯ÖеĿɼûÐÔ£»£»£»£»£»£»£»£»2020Ä꣬ £¬£¬£¬£¬£¬£¬ÔÚÖÕ¶ËÉϲúÉú·ì϶µÄ¿ÉÄÜÐÔÊÇ·þÎñÆ÷ÉϵÄ4.5±¶£»£»£»£»£»£»£»£»Êý¾Ý¶³öй¶µÄ¾ùÔÈÊýÁ¿ÊÇÿ¸öÓû§Ã¿Ìì»á²úÉú13¸öÊý¾Ýй¶ÊÂÎñ£»£»£»£»£»£»£»£»ÄÚ²¿ÈËÔ±Êý¾Ýй¶µÄ³É±¾¿ÉÄܸߴ﹫˾ÄêÊÕÈëµÄ20%¡£¡£¡£¡£¡£¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.code42.com/blog/aberdeen-report-key-takeaways/