¸çÂ×±ÈÑÇConinsa Ramon H´æ´¢Í°ÅäÖÃÃýÎó1TBÊý¾Ýй¶

°ä²¼¹¦·ò 2021-09-27

Google°ä²¼´¹Î£¸üн¨¸´ChromeÖпªÊͺóʹÓ÷ì϶


Google°ä²¼´¹Î£¸üн¨¸´ChromeÖпªÊͺóʹÓ÷ì϶.png


GoogleÔÚ9ÔÂ24ÈÕ°ä²¼´¹Î£¸üУ¬£¬£¬ £¬£¬£¬ £¬½¨¸´½ñÄêµÚ12¸öChromeÖеÄ0day¡£¡£¡£¡£¡£¡£¸Ã·ì϶ΪPortals APIÖеĿªÊͺóʹÓ÷ì϶£¬£¬£¬ £¬£¬£¬ £¬×·×ÙΪCVE-2021-37973¡£¡£¡£¡£¡£¡£Google³Æ¸Ã·ì϶Òѱ»ÔÚÒ°ÀûÓ㬣¬£¬ £¬£¬£¬ £¬²¢Î´Åû¶Óйش˷ì϶µÄ¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇÔÚApple½¨¸´CVE-2021-30869Ö®ºóµÄµÚ¶þÌì°ä²¼µÄ£¬£¬£¬ £¬£¬£¬ £¬×êÑÐÈËÔ±Ö¸³ö£¬£¬£¬ £¬£¬£¬ £¬Ëü»¹Äܹ»ÓëWebKitÖеÄÔ¶³Ì´úÂëÖ´ÐнáºÏʹÓᣡ£¡£¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/122561/security/google-chrome-zero-day-flaw.html



Cisco°ä²¼¸üУ¬£¬£¬ £¬£¬£¬ £¬½¨¸´Æä¶à¿î²úÆ·ÖеÄ32¸ö·ì϶


Cisco°ä²¼¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´Æä¶à¿î²úÆ·ÖеÄ32¸ö·ì϶.png


CiscoÔÚ9ÔÂ22ÈÕ°ä²¼¸üУ¬£¬£¬ £¬£¬£¬ £¬½¨¸´ÁËÆä¶à¿î²úÆ·ÖеÄ32¸ö·ì϶¡£¡£¡£¡£¡£¡£Õâ´Î½¨¸´Á˺±¼ûµÄCVSSÆÀ·ÖΪ10µÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-34770£©£¬£¬£¬ £¬£¬£¬ £¬´æÔÚÓÚCisco IOS XEÈí¼þµÄÎÞÏß½ÓÈëµã½ÚÔìºÍÅäÖúÍ̸(CAPWAP)ÖУ¬£¬£¬ £¬£¬£¬ £¬¿Éµ¼ÖÂRCE»òDoS¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬£¬ £¬»¹½¨¸´ÁËÁ½¸öCVSSÆÀ·ÖΪ9.8µÄ·ì϶£¬£¬£¬ £¬£¬£¬ £¬±ðÀëÊÇSD-WANÖеÄÈí¼þ»º³åÇøÒç¶Âí½Å(CVE-2021-34727)ºÍIOS XEÖеÄÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2021-1619£©¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/critical-cisco-bugs-wireless-sd-wan/174991/



ÃÀ¹úÒ½ÁÆÖÐÐÄUHCÔâµ½Vice SocietyµÄÀÕË÷¹¥»÷


ÃÀ¹úÒ½ÁÆÖÐÐÄUHCÔâµ½Vice SocietyµÄÀÕË÷¹¥»÷.png


±¾ÖÜ£¬£¬£¬ £¬£¬£¬ £¬ÀÕË÷ÔËÓªÍÅ»ïVice SocietyÐû³ÆËûÃÇÔÚ8Ô·ݹ¥»÷Á˼ÓÀû¸£ÄáÑÇÖݵÄÃÀ¹úÒ½ÁÆÖÐÐÄUnited Health Centers£¨UHC£©¡£¡£¡£¡£¡£¡£Vice SocietyÊÇÒ»¸öÏà¶Ô½ÏеÄÍŻ£¬£¬ £¬£¬£¬ £¬ÓÚ2021Äê6ÔÂÆðÍ·»îÔ¾£¬£¬£¬ £¬£¬£¬ £¬Æä20%µÄÊܺ¦ÕßÊôÓÚÒ½ÁÆÐÐÒµ¡£¡£¡£¡£¡£¡£8ÔÂ31ÈÕ£¬£¬£¬ £¬£¬£¬ £¬ÖªÁµÈËʿй©UHCÔâµ½ÁËÀÕË÷¹¥»÷£¬£¬£¬ £¬£¬£¬ £¬ÏµÍÂäÙʱ¹Ø¹Ø¡£¡£¡£¡£¡£¡£¹¥»÷Õß³ÆÒÑÇÔÈ¡»¼ÕßÐÅÏ¢¡¢²ÆÕþÎļþ¡¢»¼Õß³¢ÊÔÊҲ鳭Á˾ֺÍÉ󼯵ÈÐÅÏ¢£¬£¬£¬ £¬£¬£¬ £¬UHCÉÐδ×÷³ö»ØÓ¦¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/united-health-centers-ransomware-attack-claimed-by-vice-society/



¸çÂ×±ÈÑÇConinsa Ramon H´æ´¢Í°ÅäÖÃÃýÎó1TBÊý¾Ýй¶


¸çÂ×±ÈÑÇConinsa Ramon H´æ´¢Í°ÅäÖÃÃýÎó1TBÊý¾Ýй¶.png


°²È«¹«Ë¾WizCase·¢ÏÖ¸çÂ×±ÈÑÇ·¿µØ²ú¾­¼Í¹«Ë¾Coninsa Ramon HµÄ´æ´¢Í°ÅäÖÃÃýÎ󣬣¬£¬ £¬£¬£¬ £¬µ¼ÖÂ1TBÊý¾Ýй¶¡£¡£¡£¡£¡£¡£Õâ´Îй¶Á˳¬¹ý550Íò¸öÎļþ£¬£¬£¬ £¬£¬£¬ £¬Éæ¼°µ½10Íò¶à¿Í»§µÄÓ×ÎÒÐÅÏ¢£¬£¬£¬ £¬£¬£¬ £¬Ô̺¬ÐÕÃû¡¢µç»°ºÅÂë¡¢ÓʼþµØÖ·¡¢¾ÓסµØÖ·¡¢Ö§¸¶½ð¶îÒÔ¼°×ʲú¼ÛÖµµÈ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬£¬ £¬×êÑÐÈËÔ±»¹Ôڴ洢ͰÖз¢ÏÖÁ˺óÃÅ´úÂ룬£¬£¬ £¬£¬£¬ £¬¿É±»ÀûÓÃÀ´¶ÔÍøÕ¾½øÐгÖÐø½Ó¼û£¬£¬£¬ £¬£¬£¬ £¬²¢½«ºÁÎÞ½äÐĵĽӼûÕß³Á¶¨Ïòµ½Ú¿Æ­ÍøÕ¾¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/09/colombian-real-estate-agency-leak.html



°²È«¹«Ë¾·¢ÏÖÀûÓÃVMware vCenterÖÐRCEµÄ¹¥»÷»î¶¯


°²È«¹«Ë¾·¢ÏÖÀûÓÃVMware vCenterÖÐRCEµÄ¹¥»÷»î¶¯.png


°²È«¹«Ë¾Bad PacketsÔÚ9ÔÂ22ÈÕ·¢ÏÖÀûÓÃVMware vCenterÖÐRCE·ì϶£¨CVE-2021-22005£©µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÒÑÔÚ9ÔÂ21ÈÕ½¨¸´£¬£¬£¬ £¬£¬£¬ £¬×êÑÐÈËÔ±ÔÚ9ÔÂ22ÈÕ16:21(GMT)·¢ÏÖÀ´×ÔÀ´×Ô¼ÓÄôó¡¢ÃÀ¹ú¡¢ÂÞÂíÄáÑÇ¡¢ºÉÀ¼¡¢ÖйúºÍÐÂ¼ÓÆÂµÄ¹¥»÷³¢ÊÔ¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÓÚ9ÔÂ24ÈÕ°ä²¼Á˲»ÆëÈ«·ì϶ÀûÓôúÂ룬£¬£¬ £¬£¬£¬ £¬BleepingComputerÔÚµ±Ìì17:41·¢ÏÖºÚ¿ÍÀûÓøôúÂëµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hackers-exploiting-critical-vmware-vcenter-cve-2021-22005-bug/



Comparitech°ä²¼ÀÕË÷Èí¼þ¶Ô¹É¼ÛÓ°ÏìµÄ·ÖÎö»ã±¨


Comparitech°ä²¼ÀÕË÷Èí¼þ¶Ô¹É¼ÛÓ°ÏìµÄ·ÖÎö»ã±¨.png


ComparitechÔÚ9ÔÂ23ÈÕ°ä²¼ÁËÀÕË÷Èí¼þ¶Ô¹É¼ÛÓ°ÏìµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬ £¬£¬£¬ £¬¹«Ë¾¹É¼ÛÔÚÀÕË÷¹¥»÷ºóµÄ24Ó×ʱÄڻᱩµø22.9%£¬£¬£¬ £¬£¬£¬ £¬µ«µÚ¶þÌìÁ¢¼´»ØÉý£¬£¬£¬ £¬£¬£¬ £¬µ½µÚ10Ì죬£¬£¬ £¬£¬£¬ £¬¾ùÔȹɼۻá±È¹¥»÷ǰ¸ü¸ß£»£»£»£»£»ÔÚËùÓÐÀÕË÷Èí¼þÖУ¬£¬£¬ £¬£¬£¬ £¬Ryuk¶Ô¹É¼ÛµÄ¸ºÃæÓ°Ïì×î´ó£»£»£»£»£»Ö»¹ÜÔÚÅû¶¹¥»÷»î¶¯ºó¿Æ¼¼¹«Ë¾µÄ¹É¼ÛÆð³õµø·ù½Ï´ó£¬£¬£¬ £¬£¬£¬ £¬µ«ËüÃÇÔÚ6¸öÔºóµÄ²û·¢ÓÅÓڷǿƼ¼¹«Ë¾¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.comparitech.com/blog/information-security/ransomware-share-price-analysis/