6ÔÂWindows¸üпÉÄܵ¼Ö²¿ÃÅÀûÓÃÎÞ·¨Ê¹ÓÃVSS±¸·Ý

°ä²¼¹¦·ò 2022-06-17
1¡¢6Ô·ÝWindows¸üпÉÄܵ¼Ö²¿ÃÅÀûÓÃÎÞ·¨Ê¹ÓÃVSS±¸·Ý

      

¾Ý6ÔÂ15ÈÕ±¨Â·£¬£¬£¬£¬£¬ £¬£¬ £¬Î¢Èí°µÊ¾£¬£¬£¬£¬£¬ £¬£¬ £¬ÔÚ×°ÖÃ2022Äê6ÔµÄWindows¸üк󣬣¬£¬£¬£¬ £¬£¬ £¬Ä³Ð©ÀûÓ÷¨Ê½¿ÉÄÜÎÞ·¨Ê¹ÓþíÓ°¸´Ôì·þÎñ(VSS)À´±¸·ÝÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¸ÃÎÊÌâÊǽ¨¸´MicrosoftÎļþ·þÎñÆ÷¾íÓ°¸´Ôì´úÀí·þÎñ(RVSS)ÖеÄÌáȨ·ì϶(CVE-2022-30154)µ¼ÖµÄ¡£¡£¡£¡£¡£¡£¡£´æÔÚÎÊÌâµÄϵͳÖУ¬£¬£¬£¬£¬ £¬£¬ £¬Windows±¸·ÝÀûÓ÷¨Ê½ÔÚ¾íÓ°¸´Ôì´´½¨¹ý³ÌÖпÉÄÜ»áÊÕµ½E_ACCESSDENIEDÃýÎ󣬣¬£¬£¬£¬ £¬£¬ £¬ÇÒ»áÔÚÎļþ·þÎñÆ÷ÖмͼΪ"FileShareShadowCopyAgent Event 1013"¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-june-windows-server-updates-may-cause-backup-issues/


2¡¢F5 LabsÅû¶ÐÂAndroidľÂíMaliBotµÄϸ½ÚÐÅÏ¢

      

6ÔÂ15ÈÕ£¬£¬£¬£¬£¬ £¬£¬ £¬F5 Labs×îл㱨Åû¶ÁËAndroidľÂíMaliBotµÄϸ½ÚÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£MaliBotרһÓÚÇÔÈ¡½ðÈÚÐÅÏ¢£¬£¬£¬£¬£¬ £¬£¬ £¬ÀýÈçµç×ÓÒøÐзþÎñƾ֤¡¢¼ÓÃÜÇ®°üÃÜÂëºÍÓ×ÎÒ¾ßÌåÐÅÏ¢£¬£¬£¬£¬£¬ £¬£¬ £¬»¹Äܹ»ÇÔÈ¡ºÍÈÆ¹ý¶à³É·Ö(2FA/MFA)´úÂ룬£¬£¬£¬£¬ £¬£¬ £¬ÖØÒªÕë¶ÔÒâ´óÀûºÍÎ÷°àÑÀµÄ½ðÈÚ»ú¹¹¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ»á¼Ù×°³É¼ÓÃÜÇ®±ÒÍÚ¾òÀûÓ÷¨Ê½¡°Mining X¡±ºÍ¡°The CryptoApp¡±£¬£¬£¬£¬£¬ £¬£¬ £¬ÓÐʱҲ¼Ù×°³É¡°MySocialSecurity¡±ºÍ¡°Chrome¡±¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ £¬£¬ £¬×êÑÐÈËÔ±°µÊ¾ÆäC2·þÎñÆ÷λÓÚ¶íÂÞ˹£¬£¬£¬£¬£¬ £¬£¬ £¬ËƺõÓë·Ö·¢SalityµÄ»î¶¯Ê¹ÓõÄÊÇͳһ¸ö·þÎñÆ÷£¬£¬£¬£¬£¬ £¬£¬ £¬×Ô2020Äê6ÔÂÒÔÀ´£¬£¬£¬£¬£¬ £¬£¬ £¬ºÜ¶à»î¶¯¶¼Ô´×Ô´ËIP¡£¡£¡£¡£¡£¡£¡£


https://www.f5.com/labs/articles/threat-intelligence/f5-labs-investigates-malibot


3¡¢Citrix ADM¿É³ÁÖÃÖÎÀíÔ±ÃÜÂëµÄ·ì϶CVE-2022-27511

      

¾ÝýÌå6ÔÂ15ÈÕ±¨Â·£¬£¬£¬£¬£¬ £¬£¬ £¬CitrixÀûÓý»¸¶ÖÎÀí(ADM)´æÔڿɳÁÖÃÖÎÀíÔ±ÃÜÂëµÄ·ì϶¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶׷×ÙΪCVE-2022-27511£¬£¬£¬£¬£¬ £¬£¬ £¬ÊÇÓɲ»ÕýÈ·µÄ½Ó¼û½ÚÔ쵼ֵ쬣¬£¬£¬£¬ £¬£¬ £¬Ó°ÏìËùÓÐÊÜÖ§³ÖµÄCitrix ADM·þÎñÆ÷ºÍCitrix ADM´úÀí°æ±¾¡£¡£¡£¡£¡£¡£¡£CitrixÚ¹ÊÍ·£¬£¬£¬£¬£¬ £¬£¬ £¬ÀûÓø÷ì϶¿ÉÄܱÉÈË´ÎÉ豸³ÁÆôʱ³ÁÖÃÖÎÀíÔ±ÃÜÂ룬£¬£¬£¬£¬ £¬£¬ £¬ÓµÓÐssh½Ó¼ûȨÏ޵Ĺ¥»÷ÕßÔÚÉ豸³ÁÆôºóÄܹ»Ê¹ÓÃĬÈÏÖÎÀíԱʹ´¦½øÐÐÏνÓ¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬ £¬£¬ £¬·ì϶Òѱ»½¨¸´£¬£¬£¬£¬£¬ £¬£¬ £¬¸Ã¹«Ë¾½¨ÒéÖÎÀíÔ±Á¢¼´×°Öò¹¶¡¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/citrix-warns-critical-bug-can-let-attackers-reset-admin-passwords/


4¡¢×êÑÐÈËÔ±·¢ÏÖBeanVPN½ü20GBµÄÏνÓÈÕÖ¾¿É¹«¿ª½Ó¼û

      

ýÌå6ÔÂ15Èճƣ¬£¬£¬£¬£¬ £¬£¬ £¬CybernewsµÄµ÷²é·¢ÏÖÌṩÉÌBeanVPN 18.5 GBµÄÏνÓÈÕÖ¾¿É±»¹«¿ª½Ó¼û¡£¡£¡£¡£¡£¡£¡£¸Ã»º´æÈÕÖ¾Ô̺¬³¬¹ý2500Íò±Ê¼Í¼£¬£¬£¬£¬£¬ £¬£¬ £¬Éæ¼°Óû§É豸ºÍPlay·þÎñID¡¢Ïνӹ¦·ò´ÁºÍIPµØÖ·µÈ¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬ £¬£¬ £¬Play·þÎñID¿ÉÓÃÓÚ²éÕÒÓû§µÇ¼É豸ʱʹÓõĵç×ÓÓʼþµØÖ·¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ £¬£¬ £¬¸ÃÌṩḚ́µÊ¾²»ÍøÂçÓû§IPµØÖ·¡¢´«³öIPµØÖ·¡¢Ïνӹ¦·ò´ÁºÍ»á»°³ÖÐø¹¦·òµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£µ«Õâһ˵·¨Óëй¶µÄÐÅÏ¢²¢²»Ò»Ö£¬£¬£¬£¬£¬ £¬£¬ £¬ºóÕßÏÕЩÔ̺¬ÁËBeanVPNÐû³Æ²»»áÍøÂçµÄËùº±¼û¾Ý¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬ £¬£¬ £¬Ð¹Â¶µÄÊý¾ÝÒѱ»±£»£»£»£» £»£»£»¤ÆðÀ´¡£¡£¡£¡£¡£¡£¡£


https://www.infosecurity-magazine.com/news/beanvpn-leaks-user-records/


5¡¢ÃÀ¹úTransact CampusÅäÖÃÃýÎóй¶3Íò¶àѧÉúµÄÐÅÏ¢

      

ýÌå6ÔÂ15ÈÕ±¨Â·£¬£¬£¬£¬£¬ £¬£¬ £¬SafetyDetectives·¢ÏÖÁËÒ»¸öÅäÖÃÃýÎóµÄElasticsearch·þÎñÆ÷£¬£¬£¬£¬£¬ £¬£¬ £¬ÆäÖÐÔ̺¬Transact CampusµÄÀûÓ÷¨Ê½µÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¸ÃÀûÓÃÓÃÓڸߵµ½ÌÓý»ú¹¹µÄѧÉúµÄÖ§¸¶Á÷³Ì£¬£¬£¬£¬£¬ £¬£¬ £¬Õâ´ÎÊÂÎñй¶ÁËÔ¼100Íò±Ê¼Í¼£¬£¬£¬£¬£¬ £¬£¬ £¬Éæ¼°3ÖÁ4ÍòÃûѧÉú¡£¡£¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬£¬£¬ £¬£¬ £¬Óû§ÃûºÍÃÜÂëµÈµÇ¼Êý¾Ý¾ùÒÔ´¿Îı¾Ìåʽ´æ´¢£¬£¬£¬£¬£¬ £¬£¬ £¬ÇÒй¶µÄÐÅÓþ¿¨ÐÅÏ¢Ô̺¬ÒøÐмø±ðºÅ¡¢ÐÅÓþ¿¨ºÅµÄǰÁùλºÍºóËÄλºÍµ½ÆÚÈÕÆÚµÈ¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬ £¬£¬ £¬Êý¾Ý¿âÒѱ»±£»£»£»£» £»£»£»¤ÆðÀ´£¬£¬£¬£¬£¬ £¬£¬ £¬µ«¸Ã¹«Ë¾Ðû³Æ·þÎñÆ÷²»ÔÚËûÃǵĽÚÔìÖ®ÏÂÇÒÊý¾ÝÊǼٵÄ¡£¡£¡£¡£¡£¡£¡£µ«×êÑÐÈËÔ±°µÊ¾¾­¹ý¿ªÔ´¹¤¾ßµÄ²é³­£¬£¬£¬£¬£¬ £¬£¬ £¬ÕâЩÊý¾ÝÊôÓÚÕæÊµµÄÓû§¡£¡£¡£¡£¡£¡£¡£


https://www.hackread.com/elasticsearch-database-expose-login-pii-data-students/


6¡¢Blue MockingbirdÍÅ»ïÀÄÓÃTelerik UIÖеķì϶ÍÚ¿ó

      

6ÔÂ15ÈÕ£¬£¬£¬£¬£¬ £¬£¬ £¬Sophos°ä²¼ÁËBlue Mockingbird½üÆÚ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïÀûÓÃÁËTelerik UI WebÀûÓ÷¨Ê½¿ò¼ÜÖеķì϶À´ÈëÇÖ·þÎñÆ÷£¬£¬£¬£¬£¬ £¬£¬ £¬×°ÖÃCobalt Strike beacons£¬£¬£¬£¬£¬ £¬£¬ £¬¶øºó½Ù³Öϵͳ×ÊÔ´À´ÍÚ¾òMonero¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓõÄÊÇÒÑ´æÔÚ3ÄêµÄ.NET·´ÐòÁл¯·ì϶£¨CVE-2019-18935£¬£¬£¬£¬£¬ £¬£¬ £¬CVSSÆÀ·Ö9.8£©£¬£¬£¬£¬£¬ £¬£¬ £¬¿ÉÔÚTelerik UI¿âÖÐÔ¶³ÌÖ´ÐÐASP.NET AJAXµÄ´úÂë¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ £¬£¬ £¬ÔÚ¹¥»÷¹ý³ÌÖУ¬£¬£¬£¬£¬ £¬£¬ £¬¸ÃÍÅ»ïʹÓÃÁËÒ»ÖÖÏֳɵÄPoC£¬£¬£¬£¬£¬ £¬£¬ £¬¿É´¦ÖüÓÃÜÂß¼­²¢×Ô¶¯Ö´ÐÐDLL±àÒë¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/hackers-exploit-three-year-old-telerik-flaws-to-deploy-cobalt-strike/