Anker Eufy Homebase 2´æÔÚRCE·ì϶CVE-2022-21806

°ä²¼¹¦·ò 2022-06-21
1¡¢Anker Eufy Homebase 2´æÔÚRCE·ì϶CVE-2022-21806

      

¾ÝýÌå6ÔÂ16ÈÕ±¨Â·£¬ £¬£¬£¬£¬£¬AnkerµÄÖÐÑëÖÇÄܼҾÓÉ豸ÖÐÐÄEufy Homebase 2´æÔÚ3¸ö°²È«·ì϶¡£¡£¡£ ¡£¡£¡£¡£¡£Homebase 2ÊÇËùÓÐAnker EufyÖÇÄܼҾÓÉ豸µÄÊÓÆµ´æ´¢ºÍÍøÂçÍø¹Ø£¬ £¬£¬£¬£¬£¬×÷ΪÕâЩÉ豸µÄÖÐÐÄÕ¾ÔËÐÓ×£¡£¡£ ¡£¡£¡£¡£¡£ÆäÖÐ×îÑϳÁµÄÊÇÒ»¸ö´úÂëÖ´Ðзì϶£¨CVE-2022-21806£¬ £¬£¬£¬£¬£¬CVSSÆÀ·Ö10)£¬ £¬£¬£¬£¬£¬ÊÇÄÚ²¿·þÎñÆ÷Ö°ÄÜÖеĿªÊͺóʹÓ÷ì϶µ¼Öµģ¬ £¬£¬£¬£¬£¬¿Éͨ¹ýÏòÖ¸±êÉ豸·¢ËÍÌØÔìµÄÍøÂçÊý¾Ý°üÀ´´¥·¢¡£¡£¡£ ¡£¡£¡£¡£¡£ÆäËüÁ½¸ö·ì϶±ðÀëΪ»Ø¾ø·þÎñ·ì϶£¨CVE-2022-26073£©ºÍÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2022-25989£©¡£¡£¡£ ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/anker-eufy-smart-home-hubs-exposed-to-rce-attacks-by-critical-flaw/


2¡¢ÃÀ¹úFlagstarÒøÐÐ֪ͨÆä¿Í»§È¥ÄêÔâµ½¹¥»÷

      

¾Ý6ÔÂ20ÈÕ±¨Â·£¬ £¬£¬£¬£¬£¬FlagstarÒøÐÐÔÚ֪ͨ¿Í»§¹ØÓÚÊý¾Ýй¶ÊÂÎñ¡£¡£¡£ ¡£¡£¡£¡£¡£FlagstarÊÇλÓÚÃÜЪ¸ùÖݵĽðÈÚ·þÎñÌṩÉÌ£¬ £¬£¬£¬£¬£¬Ò²ÊÇÃÀ¹ú×î´óµÄÒøÐÐÖ®Ò»£¬ £¬£¬£¬£¬£¬×Ü×ʲú³¬¹ý300ÒÚÃÀÔª¡£¡£¡£ ¡£¡£¡£¡£¡£Æ¾¾Ýй¶֪ͨ£¬ £¬£¬£¬£¬£¬FlagstarµÄÍøÂçÔÚ2021Äê12Ô±»ÈëÇÖ£¬ £¬£¬£¬£¬£¬¸ÃÒøÐÐÓÚ½ñÄê6ÔÂ2ÈÕ·¢ÏÖ¡£¡£¡£ ¡£¡£¡£¡£¡£¾­µ÷²é£¬ £¬£¬£¬£¬£¬¹¥»÷Õß½Ó¼ûÁ˿ͻ§µÄ¾ßÌåÐÅÏ¢£¬ £¬£¬£¬£¬£¬Ô̺¬ÐÕÃûºÍÉç»á°²È«ºÅÂëµÈ¡£¡£¡£ ¡£¡£¡£¡£¡£Õâ´ÎÊÂÎñÓ°ÏìÁË1547169ÈË£¬ £¬£¬£¬£¬£¬Flagstar½«ÎªÊÜÓ°ÏìµÄÓ×ÎÒÌṩÁ½ÄêÃâ·ÑµÄÉí·Ý¼à¿ØºÍ±£» £»£»£»£»¤·þÎñ¡£¡£¡£ ¡£¡£¡£¡£¡£2021Äê1Ô£¬ £¬£¬£¬£¬£¬¸ÃÐÐÔøÔâµ½ClopÍÅ»ïµÄÀÕË÷¹¥»÷¡£¡£¡£ ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/flagstar-bank-discloses-data-breach-impacting-15-million-customers/


3¡¢Robert Half³ÆºÚ¿ÍÒѹ¥»÷Æä1000¶à¸ö¿Í»§µÄÕÊ»§

      

ýÌå6ÔÂ17Èճƣ¬ £¬£¬£¬£¬£¬ÈËÁ¦×ÊÔ´¹«Ë¾Robert HalfµÄ1000¶à¸ö¿Í»§µÄÕÊ»§Ôâµ½¹¥»÷¡£¡£¡£ ¡£¡£¡£¡£¡£µ÷²éÏÔʾ£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÔÚ4ÔÂ26ÈÕÖÁ5ÔÂ16ÈÕÆÚ¼äÈëÇÖÁËRobertHalf.comÍøÕ¾µÄÕÊ»§£¬ £¬£¬£¬£¬£¬¸ÃÊÂÎñÓÚ5ÔÂ31ÈÕ±»·¢ÏÖ£¬ £¬£¬£¬£¬£¬Ó°ÏìÁË1058Ó×ÎÒ¡£¡£¡£ ¡£¡£¡£¡£¡£Õâ´Îй¶Á˿ͻ§ÐÕÃû¡¢µØÖ·ºÍÉç»á°²È«ºÅÂëµÈÓ×ÎÒÐÅÏ¢£¬ £¬£¬£¬£¬£¬ÒÔ¼°¹¤×ʺÍ˰ÊյȲÆÕþÐÅÏ¢¡£¡£¡£ ¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ã»Óй«¿ª¹ØÓÚ¹¥»÷µÄ¸ü¶àÐÅÏ¢£¬ £¬£¬£¬£¬£¬µ«Æ¾¾ÝÆäÃèÊö£¬ £¬£¬£¬£¬£¬ËƺõÉæ¼°Æ¾Ö¤Ìî³ä¹¥»÷¡£¡£¡£ ¡£¡£¡£¡£¡£Robert Half½¨Òé¿Í»§¸ü¸ÄʹÓÃÁËÒ»ÑùÍ´´¦µÄÆäËüÕÊ»§£¬ £¬£¬£¬£¬£¬²¢½«ÎªÊÜÓ°ÏìµÄÓ×ÎÒÌṩÁ½ÄêµÄÉí·Ý¼à¿Ø·þÎñ¡£¡£¡£ ¡£¡£¡£¡£¡£


https://www.securityweek.com/staffing-firm-robert-half-says-hackers-targeted-over-1000-customer-accounts


4¡¢Lookout³Æ¼äµýÈí¼þHermitÓëÒâ´óÀûRCS LabÓйØ

      

6ÔÂ16ÈÕ£¬ £¬£¬£¬£¬£¬LookoutµÄ×îÐÂ×êÑн«¼äµýÈí¼þHermitºÍÒâ´óÀûRCS LabÁªÏµÆðÀ´¡£¡£¡£ ¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾£¬ £¬£¬£¬£¬£¬ËûÃÇÔÚ2022Äê4Ô¼ì²âµ½ÁËеÄÑù±¾¡£¡£¡£ ¡£¡£¡£¡£¡£HermitÊÇÄ£¿£¿£¿£¿£¿£¿é»¯¶ñÒâÈí¼þ£¬ £¬£¬£¬£¬£¬ÓµÓжàÖÖÖ°ÄÜ£¬ £¬£¬£¬£¬£¬¿É¼ÔìÒôƵ¡¢²¦´òºÍ³Á¶¨Ïòµç»°ÒÔ¼°ÍøÂç¶àÖÖÊý¾Ý¡£¡£¡£ ¡£¡£¡£¡£¡£Ëüͨ¹ýSMSÐÂÎŽøÐд«²¼£¬ £¬£¬£¬£¬£¬¼ÙÒâÈýÐÇ¡¢VivoºÍOppoµÄÀûÓ㬠£¬£¬£¬£¬£¬Lookout½«¸ÃÆä¹é×ïÓÚÒâ´óÀûRCS Lab SpAºÍÒ»¼ÒµçÕÛ·þÎñÌṩÉÌTykelab Srl¡£¡£¡£ ¡£¡£¡£¡£¡£


https://thehackernews.com/2022/06/researchers-uncover-hermit-android.html


5¡¢Cleafy°ä²¼¹ØÓÚAndroid¶ñÒâÈí¼þBRATAµÄ·ÖÎö»ã±¨


CleafyÔÚ6ÔÂ17ÈÕ°ä²¼Á˹ØÓÚAndroid¶ñÒâÈí¼þBRATAµÄ·ÖÎö»ã±¨¡£¡£¡£ ¡£¡£¡£¡£¡£BRATAÓÚ2018Äêµ×³õ´ÎÔÚ°ÍÎ÷±»·¢ÏÖ£¬ £¬£¬£¬£¬£¬ÓÚ2021Äê³Ê´Ë¿ÌÅ·ÖÞ¡£¡£¡£ ¡£¡£¡£¡£¡£½üÆÚ£¬ £¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÔËÓªÍÅ»ïÔÙ´ÎΪ¸ÃAndroid¶ñÒâÈí¼þÔö³¤Á˸ü¶àÖ°Äܲ¢ÇҸĽøÁ˹¥»÷Õ½Êõ£¬ £¬£¬£¬£¬£¬´Ë¿Ì¸üÇкϸ߼¶³ÖÐøÍþв(APT)¹¥»÷»î¶¯µÄģʽ¡£¡£¡£ ¡£¡£¡£¡£¡£Ð°汾µÄBRATA¸ü¾ßÕë¶ÔÐÔ£¬ £¬£¬£¬£¬£¬ËüÒ»´ÎÖ»Õë¶ÔÒ»¼Ò½ðÈÚ»ú¹¹£¬ £¬£¬£¬£¬£¬Ö»ÓÐÔÚÆä¹¥»÷»î¶¯±äµÃµÍЧʱ²Å»áתÏòÁíÒ»¸öÖ¸±ê¡£¡£¡£ ¡£¡£¡£¡£¡£´Ë±í£¬ £¬£¬£¬£¬£¬BRATAÔö³¤Á˸ü¶àȨÏÞ£¬ £¬£¬£¬£¬£¬ÀýÈç·¢ËͺͽӹÜSMS£¬ £¬£¬£¬£¬£¬Õâ¿ÉÓÃÀ´ÇÔÈ¡ÒøÐз¢Ë͸ø¿Í»§µÄһʱÃÜÂë¡£¡£¡£ ¡£¡£¡£¡£¡£


https://www.cleafy.com/cleafy-labs/brata-is-evolving-into-an-advanced-persistent-threat


6¡¢Trend Micro°ä²¼2022ÄêOT°²È«Ì¬ÊƵĵ÷²é»ã±¨

      

6ÔÂ15ÈÕ£¬ £¬£¬£¬£¬£¬Trend Micro°ä²¼ÁË2022ÄêOT°²È«Ì¬ÊƵĵ÷²é»ã±¨¡£¡£¡£ ¡£¡£¡£¡£¡£×êÑÐÈËÔ±¶Ô2022ÄêÔì×÷¡¢µçÁ¦ºÍʯÓͺÍÌìÈ»Æø¹«Ë¾µÄ¹¤ÒµÍøÂç°²È«Ì¬ÊÆ½øÐÐÁ˵÷²é¡£¡£¡£ ¡£¡£¡£¡£¡£µ÷²éÏÔʾ£¬ £¬£¬£¬£¬£¬ÔÚ´Óǰ12¸öÔÂÖУ¬ £¬£¬£¬£¬£¬¼«¶ÈÖ®¾ÅµÄ×éÖ¯µÄ³ö²ú»òÄÜÔ´¹©¸ø¶¼Êܵ½¹¥»÷µÄÓ°Ïì¡£¡£¡£ ¡£¡£¡£¡£¡£¹ØÓÚϵͳÖжϵijÖÐø¹¦·òºÍ¾­¼ÃËðʧ£¬ £¬£¬£¬£¬£¬56%µÄÊÜ·ÃÕß°µÊ¾Öжϻá³ÖÐøËÄÌì»ò¸ü³¤¹¦·ò£» £»£»£»£»È¥ÄêµÄ¾ùÔȾ­¼ÃËðʧԼΪ280ÍòÃÀÔª£» £»£»£»£»¾­¼ÃËðʧ³ýÁËÔ̺¬ÀÕË÷¹¥»÷µÄÊê½ðÖ®±í£¬ £¬£¬£¬£¬£¬»¹Óи´Ô­ÏµÍ³¡¢Õмܹ¥»÷ºÍ¹ÍÓöî±íÔ±¹¤µÄÓöȡ£¡£¡£ ¡£¡£¡£¡£¡£


https://www.trendmicro.com/en_us/research/22/f/state-of-ot-security-2022.html