Google³Æ¶íºÚ¿ÍÀûÓÃSafariÖÐ0day¹¥»÷LinkedIn£»£»£»£»£»£»£»SonicWallÖÒ¸æÕë¶ÔSMA100ºÍSRA²úÆ·µÄÀÕË÷¹¥»÷
°ä²¼¹¦·ò 2021-07-16
Google°²È«×êÑÐÈËÔ±°ä²¼ÁËÓйØ4¸ö0day±»ÔÚÒ°ÀûÓõľßÌåÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶±ðÀëÊÇChromeÖеÄCVE-2021-21166ºÍCVE-2021-30551¡¢Internet ExplorerÖеÄCVE-2021-33742£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°WebKit(Safari)ÖеÄCVE-2021-1879¡£¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬£¬¶íÂÞ˹SVRµÄºÚ¿ÍÍÅ»ïNobeliumÀûÓÃSafariÖеÄ0day£¬£¬£¬£¬£¬£¬£¬Í¨¹ýLinkedIn Messaging·¢ËͶñÒâÁ´½ÓÀ´¹¥»÷Î÷Å·¹ú¶ÈÈ·µ±¾Ö¹ÙÔ±¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬Google³Æ½ö2021ÄêÉϰëÄê¾ÍÅû¶ÁË33ÆðʹÓÃ0dayµÄ¹¥»÷£¬£¬£¬£¬£¬£¬£¬±È2020ÄêµÄ×ÜÊý¶àÁË11Æð¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/google-russian-svr-hackers-targeted-linkedin-users-with-safari-zero-day/
2.KasperskyÅû¶LuminousMoth APTÕë¶Ô¶«ÄÏÑǵĹ¥»÷

KasperskyÅû¶ÁËAPT×éÖ¯LuminousMothÕë¶Ô¶«ÄÏÑǵĹ¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯ÖÁÉÙÄܹ»×·Òäµ½2020Äê10Ô£¬£¬£¬£¬£¬£¬£¬ÔçÆÚµÄ¹¥»÷´ó¶àÔÚÃåµéµ«´Ë¿ÌÖØÒªÔÚ·ÆÂɱö£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°·¢ÏÖÃåµé¹²ÓÐ100ÃûÊܺ¦Õß¶ø·ÆÂɱöÓÐ1400Ãû¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ¹¥»÷µÄ¹æÄ£¼«¶Èº±¼û£¬£¬£¬£¬£¬£¬£¬Õâ¿ÉÄÜÊÇÓÉÓÚʹÓÃUSBÇý¶¯Æ÷×÷Ϊ´«²¼»úÔì¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓôøÓÐDropboxÏÂÔØÁ´½ÓµÄ´¹µöÓʼþ·Ö·¢¼Ù×°³ÉwordÎĵµµÄrarÎļþ£¬£¬£¬£¬£¬£¬£¬À´×°ÖöñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þ»áÀûÓÿÉÒÆ¶¯USBÇý¶¯Æ÷´ø×ÅÇÔÈ¡µÄÎļþÒÆ¶¯µ½ÆäËüµÄϵͳÖÐ
ÔÎÄÁ´½Ó£º
https://securelist.com/apt-luminousmoth/103332/
3.×êÑÐÍŶӷ¢ÏÖ·Ö·¢BazarBackdoorµÄÐÂÒ»ÂÖ´¹µö»î¶¯

Cofense×êÑÐÍŶӷ¢ÏÖÁËÒ»¸öеĴ¹µö»î¶¯£¬£¬£¬£¬£¬£¬£¬Ê¹Óöà³ÁѹËõ¼¼ÊõÀ´·Ö·¢BazarBackdoor¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÁËÒÔ¡°»·¾³ÈÕ¡±ÎªÖ÷ÌâµÄÓʼþÀ´ÎüÒýÊܺ¦Õߣ¬£¬£¬£¬£¬£¬£¬Æä¸½¼þÖÐËù¸½µÄZIPºÍRARÎļþ¶¼Ô̺¬ÁËÒ»¸öJavaScriptÎļþ£¬£¬£¬£¬£¬£¬£¬Ö¼±ÉÈËÔØÀ©´óÃûΪͼÏñµÄpayload¡£¡£¡£¡£¡£¡£¡£Cofense³Æ¹¥»÷ÕßÓÐÒâʹÓöàÖÖÎļþÀàÐÍ£¬£¬£¬£¬£¬£¬£¬Äܹ»µ¼Ö°²È«µç×ÓÓʼþÍø¹Ø(SEG)´ïµ½½âѹËõÏÞ¶È£¬£¬£¬£¬£¬£¬£¬»òÕßÓÉÓÚδ֪µÄ¹éµÂ·àÐͶø½âѹʧ°Ü£¬£¬£¬£¬£¬£¬£¬´Ó¶øÊ¹¶ñÒâÎļþ¸üÄѱ»¼ì²âµ½¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/bazarbackdoor-sneaks-in-through-nested-rar-and-zip-archives/
4.CyberArkÅû¶Windows HelloÖпÉÈÆ¹ýÉí·ÝÑéÖ¤µÄ·ì϶

CyberArk LabsµÄ×êÑÐÈËÔ±Åû¶ÁËWindows HelloÖпÉÈÆ¹ýÉí·ÝÑéÖ¤µÄ·ì϶¡£¡£¡£¡£¡£¡£¡£Windows HelloÊÇWin10ÖеÄÒ»ÏîÖ°ÄÜ£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÓû§ÔÚûÓÐÃÜÂëµÄÇé¿öÏÂʹÓÃPINÂë»òÉúÎï¼ø±ðÉí·Ý½øÐÐÑéÖ¤ÒÔ½Ó¼ûÉ豸£¬£¬£¬£¬£¬£¬£¬Ô¼85%µÄWin10Óû§Ê¹ÓøÃÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶׷×ÙΪCVE-2021-34466£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»×½Äûò³Á½¨Ö¸±êµÄÃæ²¿ÕÕÆ¬£¬£¬£¬£¬£¬£¬£¬¶øºó²åÈëÌØÔìµÄUSBÉ豸½«Î±ÔìµÄͼÏñ×¢ÈëÉí·ÝÑéÖ¤Ö÷»ú£¬£¬£¬£¬£¬£¬£¬À´ÈƹýÉí·ÝÑé֤ϵͳ¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶Òѱ»½¨¸´¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/windows-hello-bypass-biometrics-pcs/167771/
5.Cisco TalosÅû¶D-LINK DIR-3040·ÓÉÆ÷Öжà¸ö·ì϶

Cisco TalosÅû¶D-LINK DIR-3040ÎÞÏß·ÓÉÆ÷ÖеĶà¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£Õâ´Î·¢Ïֵķì϶Ô̺¬ÐÅϢй¶·ì϶£¨CVE-2021-21816ºÍCVE-2021-21817£©£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ýÌØÔìµÄÍøÂçÒªÇó´¥·¢£¬£¬£¬£¬£¬£¬£¬À´²é¿´É豸µÄϵͳÈÕÖ¾£»£»£»£»£»£»£»Ó²±àÂëÃÜÂë·ì϶CVE-2021-21818ºÍCVE-2021-21820£¬£¬£¬£¬£¬£¬£¬ÆäÖÐǰÕß¿ÉÄܵ¼Ö»ؾø·þÎñ£¬£¬£¬£¬£¬£¬£¬ºóÕßÔÊÐí¹¥»÷ÕßÔÚ·ÓÉÆ÷ÉÏÖ´ÐдúÂ룻£»£»£»£»£»£»ÒÔ¼°´úÂëÖ´Ðзì϶(CVE-2021-21819) ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2021/07/vuln-spotlight-d-link.html
6.SonicWallÖÒ¸æÕë¶ÔÆäSMA100ϵÁкÍSRA²úÆ·µÄÀÕË÷¹¥»÷

SonicWall°ä²¼´¹Î£°²È«Í¨Öª£¬£¬£¬£¬£¬£¬£¬ÖÒ¸æÕë¶ÔÆä²»Ö§³Ö¸üÐÂ(EoL)µÄ°²È«Òƶ¯½Ó¼û(SMA)100ϵÁкͰ²È«Ô¶³Ì½Ó¼û(SRA)²úÆ·µÄÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾°µÊ¾£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓõÄÊÇÒ»¸ö¾É·ì϶£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÒÑÔÚÆä×îа汾µÄ¹Ì¼þÖн¨¸´£¬£¬£¬£¬£¬£¬£¬¿Í»§±ØÒª¾¡¿ì¸üÐÂÆäÉ豸µÄ¹Ì¼þ¡£¡£¡£¡£¡£¡£¡£ÈôÊÇ×é֯ʹÓõľÉSRAÉ豸ÒÑÊÇEoL״̬²¢ÇÒÎÞ·¨¸üе½9.x¹Ì¼þ£¬£¬£¬£¬£¬£¬£¬ÈÔ³ÖÐøÊ¹ÓÿÉÄÜÔâµ½ÀÕË÷¹¥»÷£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾½¨ÒéÁ¢¼´¶Ï¿ªÉ豸ÏνӲ¢³ÁÖÃÆä½Ó¼ûÃÜÂ룬£¬£¬£¬£¬£¬£¬ÈôÊÇÄܹ»µÄ»°ÆôÓÃÕÊ»§¶à³ÁÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/sonicwall-warns-of-imminent-ransomware-campaign-targeting-its-eol-equipment/


¾©¹«Íø°²±¸11010802024551ºÅ