Adobe°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´MagentoºÍConnectÖжà¸ö·ì϶£»£»£»£»£»£»LockBit³ÆÒÑÇÔÈ¡°£É­ÕÜ6TBµÄÊý¾Ý²¢ÀÕË÷5000ÍòÃÀÔª

°ä²¼¹¦·ò 2021-08-12

1.Adobe°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´MagentoºÍConnectÖжà¸ö·ì϶


1.jpg


Adobe°ä²¼ÁËÖܶþ°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´Æäµç×ÓÉÌÎñƽ̨MagentoºÍConnectÖеÄ29¸ö·ì϶¡£¡£¡£¡£¡£¡£ÆäÖÐMagentoÖн¨¸´ÁË26¸ö·ì϶£¬£¬£¬£¬£¬£¬½ÏΪÑϳÁµÄÊÇÓÉÓÚÊäÈëÑéÖ¤²»µ±µ¼ÖµÄËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-36021¡¢CVE-2021-36024ºÍCVE-2021-36025µÈ£©ºÍºÅÁî×¢Èëµ¼ÖµÄËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-36022ºÍCVE-2021-36023£©µÈ·ì϶¡£¡£¡£¡£¡£¡£Adobe ConnectÖн¨¸´ÁË3¸ö·ì϶£¬£¬£¬£¬£¬£¬Ô̺¬°²È«Ö°ÄÜÈÆ¹ý·ì϶£¨CVE-2021-36061£©ºÍ·´ÉäÐÍXSS·ì϶£¨CVE-2021-36062ºÍCVE-2021-36063£©¡£¡£¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-preauth-vulnerabilities-in-magento/


2.CiscoÅû¶Mozilla FirefoxÖдúÂëÖ´Ðзì϶µÄϸ½Ú


2.jpg


Cisco TalosÅû¶ÁËMozilla FirefoxÖдúÂëÖ´Ðзì϶µÄϸ½Ú¡£¡£¡£¡£¡£¡£¸Ã·ì϶׷×ÙΪCVE-2021-29985£¬£¬£¬£¬£¬£¬´æÔÚÓÚFirefoxµÄnsBufferedStream×é¼þÖУ¨Stream»º³åÖ°ÄܵÄÒ»²¿ÃÅ£©¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»ÓÕʹÓû§½Ó¼ûÌØÔìµÄ¶ñÒâÍøÒ³À´´¥·¢¸Ã·ì϶£¬£¬£¬£¬£¬£¬À´µ¼Ö´íÂÒÇé¿ö£¨race condition£©£¬£¬£¬£¬£¬£¬´Ó¶øµ¼Ö¿ªÊͺóʹÓúÍÔ¶³Ì´úÂëÖ´ÐÓ×£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³ÆFirefox°æ±¾89.0.3 x64´æÔڸ÷ì϶£¬£¬£¬£¬£¬£¬½¨ÒéÁ¢¼´¸üС£¡£¡£¡£¡£¡£ 

  

Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2021/08/vuln-spotlight-firefox-code.html


3.LockBit³ÆÒÑÇÔÈ¡°£É­ÕÜ6TBµÄÊý¾Ý²¢ÀÕË÷5000ÍòÃÀÔª


3.jpg


ÀÕË÷ÍÅ»ïLockBit 2.0Ðû³ÆÒÑÇÔÈ¡°£É­Õܹ«Ë¾³¬¹ý6TBµÄÊý¾Ý£¬£¬£¬£¬£¬£¬²¢ÀÕË÷5000ÍòÃÀÔª¡£¡£¡£¡£¡£¡£°£É­ÕÜÊÇÈ«Çò³ÛÃûµÄITÕ÷ѯ¹«Ë¾£¬£¬£¬£¬£¬£¬ÊÐÖµ443ÒÚÃÀÔª£¬£¬£¬£¬£¬£¬·þÎñÓÚÆû³µ¡¢ÒøÐÓ×¢µ±¾Ö¡¢¼¼Êõ¡¢ÄÜÔ´¡¢µçÐŵȶà¶àÐÐÒµ¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ï³ÆÒÑͨ¹ý¹«Ë¾µÄ¡°ÄÚ²¿ÈËÔ±¡±½Ó¼û°£É­ÕܵÄÍøÂ磬£¬£¬£¬£¬£¬²¢°µÊ¾ÈôÊÇûÓÐÖ§¸¶Êê½ðËûÃǽ«ÔÚ8ÔÂ11ÈÕÍíÉϰ䲼Êý¾Ý£¬£¬£¬£¬£¬£¬µ«11ÈÕÍíÉϹýºó¸ÃÍŻォй¶¹¦·òÍÆ³Ùµ½ÁË8ÔÂ12ÈÕ20:43:00¡£¡£¡£¡£¡£¡£Íþвµý±¨¹«Ë¾Hudson Rock°µÊ¾°£É­ÕÜÓÐ2500̨Ա¹¤ºÍºÏ×÷ͬ°éµÄµçÄÔÒÑÔâµ½ÈëÇÖ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/121048/data-breach/accenture-lockbit-2-0-ransomware-attack.html


4.ÓÎÏ·¹«Ë¾CrytekÈÏ¿ÉÆäÔøÔâÀÕË÷Èí¼þEgregorµÄ¹¥»÷


4.jpg


ÓÎÏ·¿ª·¢É̺Ϳ¯ÐÐÉÌCrytekÈÏ¿ÉÆäÔøÓÚ2020Äê10ÔÂÔâµ½ÀÕË÷Èí¼þEgregorµÄ¹¥»÷¡£¡£¡£¡£¡£¡£EgregorÔø¹¥»÷¹ýÈ«Çò¶à¶à×éÖ¯£¬£¬£¬£¬£¬£¬Èçθ绪µÄTransLinkµØÌúϵͳºÍKmartµÈ£¬£¬£¬£¬£¬£¬ÆäÖØÒª³ÉÔ±ÓÚ2021Äê2ÔÂÔÚ·¨¹úºÍÎÚ¿ËÀ¼·¨Âɲ¿ÃŽáºÏÐж¯Öб»²¶¡£¡£¡£¡£¡£¡£Crytek³ÆÕâ´Î¹¥»÷й¶Á˿ͻ§Ó×ÎÒÐÅÏ¢£¬£¬£¬£¬£¬£¬ÐÕÃû¡¢Ö°Îñ¡¢¹«Ë¾Ãû³Æ¡¢µç×ÓÓʼþ¡¢¹«Ë¾µØÖ·¡¢µç»°ºÅÂëºÍµØÓòµÈ¡£¡£¡£¡£¡£¡£¶øEgregor֮ǰÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾¹«¿ªµÄÊý¾ÝÔ̺¬ÓëWarFaceÓйصÄÎļþ¡¢MOBAÓÎÏ·ÃüÔ˾º¼¼³¡ºÍÓÐ¹ØÆäÍøÂçÔËÐÐÐÅÏ¢µÄÎļþ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/crytek-confirms-egregor-ransomware-attack-customer-data-theft/


5.FireEye·¢ÏÖUNC215Õë¶ÔÒÔÉ«Áе±¾ÖÍøÂçµÄ¹¥»÷»î¶¯


FireEye·¢ÏÖUNC215Õë¶ÔÒÔÉ«Áе±¾ÖÍøÂçµÄ¹¥»÷»î¶¯.png


FireEye·¢ÏÖ¼äµý×éÖ¯UNC215½üÆÚÕë¶ÔÒÔÉ«Áе±¾ÖÍøÂçµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£MandiantÔÚ2019ËêÊ×·¢ÏÖUNC215Õë¶ÔÖж«µÄ¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÃSharePointÖзì϶CVE-2019-0604ÔÚÖж«ºÍÖÐÑǵÄÖ¸±êÉ豸ÉÏ×°ÖÃweb shellºÍFOCUSFJORD payload¡£¡£¡£¡£¡£¡£³ýÁËÒ£²âÊý¾Ý£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±»¹ÓëÒÔÉ«Áйú·À»ú¹¹ºÏ×÷£¬£¬£¬£¬£¬£¬·¢ÏÖ×Ô2019Äê1ÔÂÆðÍ·µÄÕë¶ÔÒÔÉ«Áе±¾Ö»ú¹¹¡¢IT¹©¸øÉ̺͵çÐŹ«Ë¾µÄ¶à¸ö²¢Ðл£¬£¬£¬£¬£¬£¬ÆÚ¼äUNC215 ʹÓÃеÄTTPÀ´Èƹý¼ì²â¡¢°µ²Ø¹¥»÷»î¶¯²¢ÀûÓÿÉÐŹØÏµºáÏòÒÆ¶¯¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.fireeye.com/blog/threat-research/2021/08/unc215-chinese-espionage-campaign-in-israel.html


6.Unit 42°ä²¼ÀÕË÷Èí¼þeCh0raixбäÖֵķÖÎö»ã±¨


6.jpg


Unit 42°ä²¼ÁËÓйØÀÕË÷Èí¼þeCh0raixбäÖֵķÖÎö»ã±¨¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬¸Ã±äÖÖÀûÓÃÁË·ì϶CVE-2021-28799£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔSynologyÍøÂ總¼Ó´æ´¢(NAS)ºÍQuality Network Appliance Provider (QNAP)NASÉ豸£¬£¬£¬£¬£¬£¬ÒѾ­ÔÚÒ°±í»îÔ¾Á˽üÒ»Äê¡£¡£¡£¡£¡£¡£¸Ã»ã±¨½¨ÒéÓû§¸üÐÂÉ豸¹Ì¼þÒÔÔ¤·À´ËÀ๥»÷¡¢´´½¨¸´ÔӵĵǼÃÜÂëÒÔÔ¤·À±©Á¦ÆÆ½â£¬£¬£¬£¬£¬£¬ÒÔ¼°½öͨ¹ýÒѼø±ðIPµÄÓ²±àÂëÁбíÏÞ¶Å×ëSOHOÉ豸µÄÏνӡ£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/ech0raix-ransomware-soho/