AppleÒѽ¨¸´ÆäAWDLÖпÉÈÆ¹ýÆøÏ¶ÏµÍ³ÇÔÊØÐÅÏ¢µÄ·ì϶£»£»£»£»£»£»£»×êÑÐÈËÔ±·¢ÏÖÀûÓÃExchangeÖзì϶ProxyShellµÄ¹¥»÷»î¶¯

°ä²¼¹¦·ò 2021-08-09
1.AppleÒѽ¨¸´ÆäAWDLÖпÉÈÆ¹ýÆøÏ¶ÏµÍ³ÇÔÊØÐÅÏ¢µÄ·ì϶


1.jpg


AppleµÄApple Wireless Direct Link(AWDL)ÖдæÔÚÒ»¸ö·ì϶£¬£¬ £¬£¬£¬¿ÉÓÃÀ´ÈƹýÆøÏ¶ÏµÍ³²¢ÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£¡£Õâ¸ö·ì϶µÄ¼¼Êõ²¼¾°Óе㸴ÔÓ£¬£¬ £¬£¬£¬¼òÑÔÖ®£¬£¬ £¬£¬£¬¾ÍÊÇʹÓÃICMPv6ºÍIPv6Êý¾Ý°ü´ÓÖ¸±êϵͳ»ñÈ¡Êý¾Ý£¬£¬ £¬£¬£¬ÔÚ×ó½üÖ§³ÖAWDLµÄAppleÉ豸ÉÏ·´µ¯Êý¾Ý°ü£¬£¬ £¬£¬£¬²¢½«ÇÔÈ¡µÄÎļþ·¢Ë͵½ÁíÒ»¸öÓÐIPv6µØÖ·µÄÉ豸¡£¡£¡£¡£¡£¡£°²È«¹«Ë¾Fnish×êÑÐÈËÔ±ÓÚÉÏÖܳõ´Î¹«¿ªÁ˸÷ì϶£¬£¬ £¬£¬£¬¶øApple¹«Ë¾ÔçÔÚ½ñÄê4Ô£¬£¬ £¬£¬£¬¾ÍÔÚiOS 14.5¡¢iPadOS 14.5¡¢watchOS 7.4ºÍBig Sur 11.3µÄ°²È«¸üÐÂÖÐ͵͵µØ½¨¸´ÁËÕâÒ»·ì϶¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/apple-fixed-awdl-bug-that-could-be-used-to-escape-air-gapped-networks/


2.×êÑÐÈËÔ±·¢ÏÖÀûÓÃExchangeÖзì϶ProxyShellµÄ¹¥»÷»î¶¯


2.jpg


2021 Black Hat´ó»áÉÏͳ³ÆÎªProxyShellµÄ3¸ö·ì϶µÄϸ½Ú¹«¿ªºó£¬£¬ £¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÁË»ý¼«ÀûÓø÷ì϶µÄ»î¶¯¡£¡£¡£¡£¡£¡£ProxyShellÔ̺¬ACLÈÆ¹ý·ì϶£¨CVE-2021-34473£©¡¢ Exchange PowerShellºó¶ËµÄÌáȨ·ì϶£¨CVE-2021-34523£©ºÍËÁÒâÎļþдÈëµ¼ÖµÄRCE·ì϶£¨CVE-2021-31207£©¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶Äܹ»Í¨¹ýIISÖеĶ˿Ú443ÉÏÔËÐеÄMicrosoft Exchange¿Í»§¶Ë½Ó¼û·þÎñ(CAS)Ô¶³ÌÀûÓ㬣¬ £¬£¬£¬½áºÏʹÓÿɽøÐÐδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-servers-scanned-for-proxyshell-vulnerability-patch-now/


3.×êÑÐÍŶӷ¢ÏÖÀûÓÃArcadyan¹Ì¼þÖзì϶װÖÃMiraiµÄ»î¶¯


3.jpg


Õ°²©ÍøÂçµÄ×êÑÐÍŶÓÔÚ½üÆÚ·¢ÏÖÁËÀûÓÃArcadyan¹Ì¼þÖзì϶µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇõè¾¶±éÀú·ì϶£¬£¬ £¬£¬£¬×·×ÙΪCVE-2021-20090£¬£¬ £¬£¬£¬ÆÀ·ÖΪ9.9¡£¡£¡£¡£¡£¡£´æÔÚÓÚʹÓÃArcadyan¹Ì¼þµÄ·ÓÉÆ÷µÄweb½çÃæÉÏ£¬£¬ £¬£¬£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÈÆ¹ýÉí·ÝÑéÖ¤£¬£¬ £¬£¬£¬Ó°ÏìÁËÊýÊ®ÖÖÐͺŵÄÊý°ÙÍǫ̀·ÓÉÆ÷¡£¡£¡£¡£¡£¡£×ÔÉÏÖÜËÄÒÔÀ´£¬£¬ £¬£¬£¬×êÑÐÈËÔ±ÔÚÒ°·¢ÏÖÁËÀûÓô˷ì϶µÄ¹¥»÷»î¶¯,Ö¼ÔÚÊÕÊÜÖ¸±êÉ豸²¢×°Öý©Ê¬ÍøÂçMiraiµÄpayload¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/actively-exploited-bug-bypasses-authentication-on-millions-of-routers/


4.SeniorAdvisor´æ´¢Í°ÅäÖÃÃýÎóй¶³¬¹ý300Íò¿Í»§ÐÅÏ¢


4.jpg


WizCase×êÑÐÍŶӷ¢ÏÖÁ˸߼¶»¤ÀíÉó²éÍøÕ¾SeniorAdvisorµÄAmazon S3´æ´¢Í°ÅäÖÃÃýÎ󣬣¬ £¬£¬£¬Ð¹Â¶³¬¹ý300Íò¿Í»§ÐÅÏ¢¡£¡£¡£¡£¡£¡£¸ÃÍøÕ¾ÓÃÀ´Õ¹Ê¾ ÃÀ¹úºÍ¼ÓÄôóµÄÀÏÄ껤Àí·þÎñÏû·ÑÕߵįÀ·ÖºÍÆÀÂÛ£¬£¬ £¬£¬£¬Õâ´Î×ܹ²Ð¹Â¶Á˳¬¹ý100Íò¸öÎļþºÍ182GBµÄÊý¾Ý£¬£¬ £¬£¬£¬Ô̺¬ÐÕÃû¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂëºÍÁªÏµÈÕÆÚµÈ£¬£¬ £¬£¬£¬²¢ÇÒ¶¼Î´¾­¹ý¼ÓÃÜ£¬£¬ £¬£¬£¬´Ë±í»¹ÓÐԼĪ2000ÌõÒѱ»É¾³ýµÄÆÀÂÛ¡£¡£¡£¡£¡£¡£WizCase³ÆÕâ´ÎÐ¹Â¶Ô´ÖØÒªÊÇ´¦ÓÚ»ò¿¿½üÍËÐݵÄÀÏÄêÈË£¬£¬ £¬£¬£¬ÎªÌض¨µÄÈõÊÆÈºÌ壬£¬ £¬£¬£¬¸üÈÝÒ×Ôâµ½Ú¿Æ­»î¶¯µÄ¹¥»÷¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/senior-citizens-personal-data/


5.Group-IB·¢ÏÖºÚ¿ÍÔÚ¶à¸ö°µÍø¹«¿ª³¬¹ý100ÍòÌõÖ§¸¶¼Í¼


5.jpg


Group-IBÔÚ¶à¸öÔÚ¶à¸ö°µÍøÉϼì²âµ½Ò»¸öÌØÊâÌû×Ó£¬£¬ £¬£¬£¬ÃûΪAW_cardsµÄºÚ¿Í¹«¿ªÁ˳¬¹ý100ÍòÌõÖ§¸¶¼Í¼¡£¡£¡£¡£¡£¡£ÕâЩÊý¾ÝÔ̺¬ÁËÀ´×Ô100¶à¸ö¹ú¶ÈºÍµØÓòµÄ1000¶à¼ÒÒøÐеÄÒøÐп¨¾ßÌåÐÅÏ¢£¬£¬ £¬£¬£¬Ô̺¬Ó¡¶È¡¢Ä«Î÷¸ç¡¢ÃÀ¹ú¡¢°Ä´óÀûÑÇ¡¢°ÍÎ÷µÈ¡£¡£¡£¡£¡£¡£ÓÉÓÚºÜÉÙÓз¸×ï·Ö×ÓÃâ·ÑÌṩÈç´Ë¶àµÄÒøÐп¨ÐÅÏ¢£¬£¬ £¬£¬£¬ÕâÒýÆðÁËGroup-IB×êÑÐÈËÔ±µÄÐËÖ¡£¡£¡£¡£¡£¡£·ÖÎö·¢ÏÖÕâÊÇÒ»¸ö¶·µ¨µÄ¸æ°×£¬£¬ £¬£¬£¬Ö¼ÔÚÍÆ¹ãÐÂÆ½Ì¨All World Cards¡£¡£¡£¡£¡£¡£ÕâЩÊý¾ÝÔ̺¬¿¨ºÅ¡¢½ØÖ¹ÈÕÆÚ¡¢CVV/CVC´úÂë¡¢³Ö¿¨ÈËÐÕÃû¡¢¹ú¶È¡¢×´Ì¬¡¢³ÇÊÓ×¢µØÖ·¡¢ÓÊÕþ±àÂëºÍµç»°µÈ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/120941/cyber-crime/1m-compromised-cards.html


6.RansomEXXÍÅ»ïÐû³ÆÒÑÇÔÈ¡ÉÝ³ÞÆ·ÅÆZegna³¬¹ý20GBÊý¾Ý


6.jpg


ÀÕË÷ÍÅ»ïRansomEXX½üÆÚÐû³ÆÒÑÇÔÈ¡ÉÝ³ÞÆ·ÅÆZegna³¬¹ý20GBÊý¾Ý¡£¡£¡£¡£¡£¡£ZegnaÊÇÒâ´óÀû×î³ÛÃûµÄÉݳÞÊ±×°Æ·ÅÆÖ®Ò»£¬£¬ £¬£¬£¬ÊÇÈ«ÇòÊÕÈë×î¸ßµÄÄÐ×°Æ·ÅÆ¡£¡£¡£¡£¡£¡£RansomEXX³ÆÒѴӸù«Ë¾ÇÔÈ¡ÁË20.74GBµÄÊý¾Ý£¬£¬ £¬£¬£¬²¢°ä²¼ÁË43¸öÎļþ£¨42¸ö500MBµÄÎļþºÍ1¸ö239.54MBµÄÎļþ£©×÷ΪÑù±¾¡£¡£¡£¡£¡£¡£½üÆÚ£¬£¬ £¬£¬£¬RansomEXXÍÅ»ïÔøÏ°È¾ÁËÒâ´óÀûÀ­Æë°Â´óÇøµÄϵͳ£¬£¬ £¬£¬£¬²¢¹¥»÷ÁËÖйų́ÍåµÄÍÆËã»úÓ²¼þÔì×÷É̼¼¼Î£¨GIGABYTE£©¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/120898/data-breach/ransomexx-ransomware-zegna.html