Microsoft°ä²¼²¹¶¡½¨¸´86¸ö·ì϶:Intezer°ä²¼·ÖÎö»ã±¨

°ä²¼¹¦·ò 2021-09-16

¹È¸èÒòÀÄÓð²×¿µÄÊг¡Ö÷µ¼Ö°Î»±»º«¹ú·£¿£¿£¿£¿£¿î2070ÒÚº«Ôª


¹È¸èÒòÀÄÓð²×¿µÄÊг¡Ö÷µ¼Ö°Î»±»º«¹ú·£¿£¿£¿£¿£¿î2070ÒÚº«Ôª.png


9ÔÂ14ÈÕ£¬£¬£¬£¬ £¬£¬º«¹úƽÕýÒµÎñίԱ»á¶Ô¹È¸è´¦ÒÔ2070ÒÚº«Ôª£¨Ô¼Îª1.77 ÒÚÃÀÔª£©µÄ·£¿£¿£¿£¿£¿î¡£¡£¡£¡£¡£¡£¡£¡£Ô­ÒòÊǹȸèÒòÀÄÓð²×¿ÔÚÒÆ¶¯²Ù×÷ϵͳÊг¡µÄÖ÷µ¼Ö°Î»£¬£¬£¬£¬ £¬£¬ÆÈʹÖÇÄÜÊÖ»úÔì×÷ÉÌÖ»ÄÜʹÓÃAndroid²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»ú¹¹³Æ£¬£¬£¬£¬ £¬£¬¹È¸èÒªÇóÔì×÷É̱ØÐëÇ©Êð¡°·´Ë鯬»¯ºÍ̸£¨AFA£©¡±£¬£¬£¬£¬ £¬£¬¸ÃºÍ̸²»ÈÝʹÓÃAndroid²Ù×÷ϵͳµÄÅú¸Ä°æ±¾£¬£¬£¬£¬ £¬£¬¼´ËùνµÄ¡°Android·ÖÖ§¡±¡£¡£¡£¡£¡£¡£¡£¡£±¨Â·³Æ£¬£¬£¬£¬ £¬£¬¹È¸èµÄ¢¶ÏÐÐΪʹÆäÔÚ2019ÄêÒÆ¶¯²Ù×÷ϵͳÊг¡µÄ·Ý¶îÉÏÉýµ½ÁË97.7%¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.com/2021/09/14/south_korea_fines_google/


Microsoft°ä²¼9Ô·ÝÐÇÆÚ¶þ²¹¶¡£¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬ £¬£¬×ܼƽ¨¸´86¸ö·ì϶


Microsoft°ä²¼9Ô·ÝÐÇÆÚ¶þ²¹¶¡£¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬×ܼƽ¨¸´86¸ö·ì϶.jpg


MicrosoftÓÚ9ÔÂ14ÈÕ°ä²¼Á˱¾ÔµÄÐÇÆÚ¶þ°²È«¸üУ¬£¬£¬£¬ £¬£¬×ܼƽ¨¸´ÁË86¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î¸üн¨¸´ÁË2¸öÁãÈÕ·ì϶£¬£¬£¬£¬ £¬£¬Ô̺¬Windows MSHTMLÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-40444£©£¬£¬£¬£¬ £¬£¬ÒÑÔÚÒ°±í·¢ÏÖÀûÓø÷ì϶µÄ¹¥»÷»î¶¯£»£»£»£»£»ÒÔ¼°Windows DNSÌáȨ·ì϶£¨CVE-2021-36968£©¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬ £¬£¬»¹½¨¸´ÁËAzure Ê¢¿ªÊ½ÖÎÀí»ù´¡ÉèÊ©ÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-38647£©ºÍWindows¾ç±¾ÒýÇæÄÚ´æ°Ü»µ·ì϶£¨CVE-2021-26435£©µÈ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2021-patch-tuesday-fixes-2-zero-days-60-flaws/


Google½¨¸´ChromeÖеÄÔ̺¬2¸ö0dayÔÚÄÚµÄ11¸ö·ì϶


Google½¨¸´ChromeÖеÄÔ̺¬2¸ö0dayÔÚÄÚµÄ11¸ö·ì϶.jpg


GoogleÓÚ±¾ÖÜÒ»°ä²¼°²È«¸üУ¬£¬£¬£¬ £¬£¬½¨¸´ÁËChromeÖÐÔ̺¬2¸ö0dayÔÚÄÚµÄ11¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£¡£ÕâÁ½¸ö0day±ðÀëΪV8 JavaScriptÒýÇæÖеÄÔ½½çдÈë·ì϶£¨CVE-2021-30632£©ºÍË÷ÒýÊý¾Ý¿âAPIÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2021-30633£©¡£¡£¡£¡£¡£¡£¡£¡£Google³ÆÕâÁ½¸ö·ì϶Òѱ»ÔÚÒ°ÀûÓ㬣¬£¬£¬ £¬£¬µ«ÊDz¢Î´¹«¿ªÓйع¥»÷»î¶¯µÄ¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬ £¬£¬»¹½¨¸´ÁËSelection APIÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2021-30625£©ºÍANGLEÖеÄÄÚ´æ½Ó¼ûÔ½½ç·ì϶£¨CVE-2021-30626£©µÈ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/122192/hacking/google-zero-day-10.html


GetHealthÒòÊý¾Ý¿âÅäÖÃÃýÎóй¶6000Íò¶àÌõÓû§¼Í¼


GetHealthÒòÊý¾Ý¿âÅäÖÃÃýÎóй¶6000Íò¶àÌõÓû§¼Í¼.jpg


9ÔÂ13ÈÕ£¬£¬£¬£¬ £¬£¬WebsitePlanet³ÆGetHealthµÄÊý¾Ý¿âй¶ÁË6000Íò¶àÌõÓû§¼Í¼¡£¡£¡£¡£¡£¡£¡£¡£2021Äê6ÔÂ30ÈÕ£¬£¬£¬£¬ £¬£¬¸Ã°²È«ÍŶӷ¢ÏÖÁËÒ»¸öûÓÐÃÜÂë±£»£»£»£»£»¤µÄÊý¾Ý¿â£¬£¬£¬£¬ £¬£¬ÆäÖÐÔ̺¬Á˳¬¹ý6100Íò±Ê¼Í¼£¬£¬£¬£¬ £¬£¬ÀýÈçÓû§ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢Ìå³Á¡¢Éí¸ß¡¢ÐÔ±ðºÍGPSÈÕÖ¾µÈ¡£¡£¡£¡£¡£¡£¡£¡£¾­¹ý¶ÈÎö£¬£¬£¬£¬ £¬£¬·¢ÏÖ´ó²¿ÃÅÊý¾ÝÔ´À´×ÔFitbitºÍAppleµÄHealthKit¡£¡£¡£¡£¡£¡£¡£¡£GetHealthÔڵõ½Í¨ÖªºóÁ¢¼´×ö³öÏìÓ¦£¬£¬£¬£¬ £¬£¬ÔÚÊýÓ×ʱÄÚ½«¸ÃÊý¾Ý¿â±£»£»£»£»£»¤ÆðÀ´¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º


https://www.zdnet.com/article/over-60-million-records-exposed-in-wearable-fitness-tracking-data-breach-via-unsecured-database/


Ò½ÁƼ¼Êõ¹«Ë¾Olympus³ÆÆäÔâµ½BlackMatterÀÕË÷¹¥»÷


Ò½ÁƼ¼Êõ¹«Ë¾Olympus³ÆÆäÔâµ½BlackMatterÀÕË÷¹¥»÷.jpg


Ò½ÁƼ¼Êõ¹«Ë¾OlympusÔÚÉÏÖÜÁù°ä²¼ÉêÃ÷£¬£¬£¬£¬ £¬£¬³ÆÆäÔâµ½ÁËBlackMatterµÄÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£ÉêÃ÷°µÊ¾£¬£¬£¬£¬ £¬£¬¹¥»÷²úÉúÔÚ9ÔÂ8ÈÕ£¬£¬£¬£¬ £¬£¬Ó°ÏìÁËÆäEMEA£¨Å·ÖÞ¡¢Öж«¡¢·ÇÖÞ£©ITϵͳ¡£¡£¡£¡£¡£¡£¡£¡£OlympusÒÑÔÝÍ£ÊÜÓ°Ïìϵͳ£¬£¬£¬£¬ £¬£¬²¢ÔÚÈ·¶¨¹¥»÷Ôì³ÉµÄÓ°ÏìÁìÓò£¬£¬£¬£¬ £¬£¬³Ðŵ½«¾¡¿ì°ä²¼¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£BlackMatterÊÇÏà¶Ô½ÏеÄÀÕË÷ÔËÓªÍŻ£¬£¬£¬ £¬£¬ÓÚ2021Äê7ÔÂÆðÍ·»îÔ¾£¬£¬£¬£¬ £¬£¬×î³õ±»ÒÔΪÊÇDarkSideµÄ¼ÌÈÎÕß¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/blackmatter-ransomware-hits-medical-technology-giant-olympus/


Intezer°ä²¼ÓйØVermilion StrikeµÄ·ÖÎö»ã±¨


Intezer°ä²¼ÓйØVermilion StrikeµÄ·ÖÎö»ã±¨.jpg


IntezerÓÚ9ÔÂ13ÈÕ°ä²¼ÁËÓйØVermilion StrikeµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£2021Äê8Ô£¬£¬£¬£¬ £¬£¬×êÑÐÈËÔ±·¢ÏÖÁËLinux°æ±¾µÄCobalt Strike BeaconµÄELFÑù±¾£¬£¬£¬£¬ £¬£¬ÒÑÓÃÓÚÕë¶ÔÈ«ÇòµçÐŹ«Ë¾¡¢µ±¾Ö»ú¹¹¡¢IT ¹«Ë¾¡¢½ðÈÚ»ú¹¹ºÍÕ÷ѯ¹«Ë¾¡£¡£¡£¡£¡£¡£¡£¡£ÆäÔÚÓëC2ͨѶʱʹÓÃÁËCobalt StrikeµÄC2ºÍ̸£¬£¬£¬£¬ £¬£¬²¢ÓµÓÐÔ¶³Ì½Ó¼ûÖ°ÄÜ£¬£¬£¬£¬ £¬£¬ÀýÈçÉÏ´«Îļþ¡¢ÔËÐÐshellºÅÁîºÍдÈëÎļþ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.intezer.com/blog/malware-analysis/vermilionstrike-reimplementation-cobaltstrike/