ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ18ÖÜ

°ä²¼¹¦·ò 2021-05-06

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2021Äê04ÔÂ26ÈÕÖÁ05ÔÂ02ÈÕ¹²ÊÕ¼°²È«·ì϶66¸ö£¬£¬£¬£¬ £¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApple macOS Big Sur WebKit CVE-2021-1817ÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶£» £»£»£» £»Google Chrome ANGLE¶ÑÒç³ö´úÂëÖ´Ðзì϶£» £»£»£» £»Cisco Adaptive Security Appliances Software CVE-2021-1504»º³åÇøÒç¶Âí½Å£» £»£»£» £»PHP FilteredIterator·´ÐòÁл¯´úÂëÖ´Ðзì϶£» £»£»£» £»Vivotek VIVOTEK IP Camera OSºÅÁî×¢Èë·ì϶¡£¡£ ¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǺڿÍÔÚ°µÍø¹«¿ªÓ¡¶ÈBigBasketÔ¼2000Íò¸öÓû§µÄÐÅÏ¢£» £»£»£» £»FacebookÅû¶½üÆÚ2¸ö°ÍÀÕ˹̹ºÚ¿ÍÍÅ»ïµÄ¼äµý»î¶¯£» £»£»£» £»µÂ¹úÁª¹ú¾¯Ô±¾Ö³ÁÖÃEmotet£¬£¬£¬£¬ £¬£¬£¬¸Ã¶ñÒâÈí¼þ½«×Ô¶¯Ð¶ÔØ£» £»£»£» £»Apple°²È«¸üУ¬£¬£¬£¬ £¬£¬£¬½¨¸´macOSÖб»ShlayerÀûÓõÄ0day£» £»£»£» £»AzureÔÆÕÊ»§ÒòÅäÖÃÃýÎóй¶΢Èí¶à¿î²úÆ·µÄÔ´´úÂë¡£¡£ ¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬ £¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£ ¡£¡£¡£


> ³ÁÒª°²È«·ì϶Áбí


1.Apple macOS Big Sur WebKit CVE-2021-1817ÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶


Apple macOS Big Sur WebKit´æÔÚÄÚ´æ·ÛËé·ì϶£¬£¬£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇ󣬣¬£¬£¬ £¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬ £¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£» £»£»£» £»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£ ¡£¡£¡£

https://support.apple.com/zh-cn/HT212325


2.Google Chrome ANGLE¶ÑÒç³ö´úÂëÖ´Ðзì϶


Google Chrome ANGLE´æÔÚ¶ÑÒç¶Âí½Å£¬£¬£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇ󣬣¬£¬£¬ £¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬ £¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£» £»£»£» £»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£ ¡£¡£¡£

https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_26.html


3.Cisco Adaptive Security Appliances Software CVE-2021-1504»º³åÇøÒç¶Âí½Å


Cisco Adaptive Security Appliances Software HTTPSÒªÇó´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬ £¬£¬£¬¿É½øÐлؾø·þÎñ¹¥»÷¡£¡£ ¡£¡£¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-vpn-dos-fpBcpEcD


4.PHP FilteredIterator·´ÐòÁл¯´úÂëÖ´Ðзì϶


PHP FilteredIterator´æÔÚ·´ÐòÁл¯·ì϶£¬£¬£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬ £¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£» £»£»£» £»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£ ¡£¡£¡£

https://github.com/WordPress/Requests/security/advisories/GHSA-52qp-jpq7-6c54


5.Vivotek VIVOTEK IP Camera OSºÅÁî×¢Èë·ì϶


Vivotek VIVOTEK IP Camera NTP Server configuration´¦ÖòÎÊý´æÔÚ°²È«·ì϶£¬£¬£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬ £¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâOSºÅÁî¡£¡£ ¡£¡£¡£

https://www.meritlilin.com/assets/uploads/support/file/M00166-TW.pdf


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢ºÚ¿ÍÔÚ°µÍø¹«¿ªÓ¡¶ÈBigBasketÔ¼2000Íò¸öÓû§µÄÐÅÏ¢


1.jpg


BigBasketÊÇÓ¡¶ÈµÄÔÚÏßÔÓ»õÅäËÍ·þÎñ£¬£¬£¬£¬ £¬£¬£¬¿ÉÔÚÓû§ÔÚÏ߲ɰìÎïÆ·Ö®ºó½«ÆäÔËË͵½¼ÒÖС£¡£ ¡£¡£¡£4ÔÂ25ÈÕÔ糿£¬£¬£¬£¬ £¬£¬£¬³ÛÃûй¶Êý¾ÝÂô¼ÒShinyHunterÔÚ°µÍøÉϰ䲼ÁËÒ»¸ö¾Ý³ÆÊÇ´ÓBigBasketµÁÈ¡µÄÊý¾Ý¿â£¬£¬£¬£¬ £¬£¬£¬ÆäÖÐÓг¬¹ý2000Íò¸öÓû§µÄ¼Í¼£¬£¬£¬£¬ £¬£¬£¬Ô̺¬µç×ÓÓʼþµØÖ·¡¢SHA1¹þÏ£ÃÜÂë¡¢µØÖ·¡¢µç»°ºÅÂëºÍÆäËûÀàÐ͵ÄÐÅÏ¢µÈ¡£¡£ ¡£¡£¡£´Ë±í£¬£¬£¬£¬ £¬£¬£¬¸ÃºÚ¿Í³ÆÆäÒѾ­Ê¹ÓÃSHA1Ëã·¨ÆÆ½âÁË200Íò¸öÃÜÂ룬£¬£¬£¬ £¬£¬£¬ÆäÖÐ70ÍòÃû¿Í»§Ê¹ÓÃÁË¡°password¡±×÷ΪÃÜÂë¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hacker-leaks-20-million-alleged-bigbasket-user-records-for-free/


2¡¢FacebookÅû¶½üÆÚ2¸ö°ÍÀÕ˹̹ºÚ¿ÍÍÅ»ïµÄ¼äµý»î¶¯


2.jpg


Facebook½üÆÚ·¢ÏÖÁË2¸ö±ðÀëÔÚ2019ÄêºÍ2020ÄêÆðÍ·»îÔ¾µÄ°ÍÀÕ˹̹ºÚ¿ÍÍÅ»ïµÄ¼äµý»î¶¯¡£¡£ ¡£¡£¡£ÕâÁ½¸ö×éÖ¯Ö®¼äËÆºõûÓÐÁªÏµ£¬£¬£¬£¬ £¬£¬£¬µ«ËüÃǵÄÖ÷ÕÅËÆºõÏà·´¡£¡£ ¡£¡£¡£ËûÃǾùÀûÓÃÁËiOS¼äµýÈí¼þ£¬£¬£¬£¬ £¬£¬£¬²¢ÒÔFacebookµÈÉ罻ýÌåÆ½Ì¨ÎªÆðµã£¬£¬£¬£¬ £¬£¬£¬ÓëÖ¸±ê³ÉÁ¢ÁªÏµ²¢ÌáÒéÉç»á¹¤³Ì¹¥»÷£¬£¬£¬£¬ £¬£¬£¬ÓÕʹËûÃǽøÈë´¹µöÒ³ÃæºÍÆäËû¶ñÒâÍøÕ¾¡£¡£ ¡£¡£¡£×êÑÐÈËÔ±´§¶ÈÆäÖÐÖ®Ò»Óë°ÍÀÕ˹̹°²È«»ú¹¹Óйأ¬£¬£¬£¬ £¬£¬£¬ÔÚÍÁ¶úÆä¡¢ÒÁÀ­¿Ë¡¢Àè°ÍÄÛºÍÀû±ÈÑÇÒ²Óй¥»÷»î¶¯¡£¡£ ¡£¡£¡£ÁíÒ»×éÓëArid ViperÓйأ¬£¬£¬£¬ £¬£¬£¬ÖØÒªÕë¶Ô·¨ËþºÕÕþµ³³ÉÔ±¡¢µ±¾Ö¹ÙÔ±¡¢°²È«¶ÓÁкÍѧÉú¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.wired.com/story/palestine-hacking-ios-custom-spyware/


3¡¢µÂ¹úÁª¹ú¾¯Ô±¾Ö³ÁÖÃEmotet£¬£¬£¬£¬ £¬£¬£¬¸Ã¶ñÒâÈí¼þ½«×Ô¶¯Ð¶ÔØ


3.jpg


µÂ¹úÁª¹ú¾¯Ô±¾ÖBundeskriminalamt³ÁÖÃÁËEmotet£¬£¬£¬£¬ £¬£¬£¬¸Ã¶ñÒâÈí¼þ½«ÔÚËùÓÐÊÜϰȾµÄϵͳÖÐ×Ô¶¯Ð¶ÔØ¡£¡£ ¡£¡£¡£EmotetÊǽüÆÚ×îΣÏÕµÄÀ¬»øÓʼþ½©Ê¬ÍøÂçÖ®Ò»£¬£¬£¬£¬ £¬£¬£¬Æä»ù´¡ÉèÊ©ÓÚ½ñÄê1Ô·ÝÓɶà¹ú·¨Âɲ¿ÃŽáºÏµ·»Ù¡£¡£ ¡£¡£¡£ÔÚÕâ´ÎÐж¯ÖУ¬£¬£¬£¬ £¬£¬£¬µÂ¹ú¾¯·½Õƹܿª·¢ºÍÍÆËÍÐ¶ÔØÄ£¿£¿£¿£¿£¿é£¬£¬£¬£¬ £¬£¬£¬ÆäΪÁËÍøÂçÖ¤¾ÝºÍÐÅÏ¢¶øÍƳÙÁ˸ÃÐ¶ÔØÄ£¿£¿£¿£¿£¿éµÄ°ä²¼¡£¡£ ¡£¡£¡£¸Ã»ú¹¹Í¨¹ýÆä½ÚÔìµÄC2·þÎñÆ÷£¬£¬£¬£¬ £¬£¬£¬½«32λEmotetLoader.dll´ó¾ÖµÄÐÂEmotetÄ£¿£¿£¿£¿£¿é·Ö·¢¸øËùÓÐÊÜϰȾµÄϵͳ£¬£¬£¬£¬ £¬£¬£¬Ê¹ÕâЩϵͳÔÚ2021Äê4ÔÂ25ÈÕ×Ô¶¯Ð¶ÔظöñÒâÈí¼þ¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/emotet-malware-nukes-itself-today-from-all-infected-computers-worldwide/


4¡¢Apple°²È«¸üУ¬£¬£¬£¬ £¬£¬£¬½¨¸´macOSÖб»ShlayerÀûÓõÄ0day


4.jpg


Apple°ä²¼°²È«¸üУ¬£¬£¬£¬ £¬£¬£¬½¨¸´macOS Big Sur 11.3ÖÐÒѱ»ÀûÓõÄ0day¡£¡£ ¡£¡£¡£°²È«ÍŶÓJamf·¢ÏÖ£¬£¬£¬£¬ £¬£¬£¬´Ó2021Äê1ÔÂÆðÍ·¶ñÒâÈí¼þShlayerÀûÓÃÁËÒ»¸ö0day£¨CVE-2021-30657£©£¬£¬£¬£¬ £¬£¬£¬À´ÈƹýAppleµÄÎļþ¸ôÀë¡¢GatekeeperºÍ¹«Ö¤°²È«²é³­£¬£¬£¬£¬ £¬£¬£¬²¢ÏÂÔØµÚ¶þ½×¶ÎËùʹÓõÄpayload¡£¡£ ¡£¡£¡£´Ë±í£¬£¬£¬£¬ £¬£¬£¬Õâ´Î¸üл¹½¨¸´ÁËiOS¡¢iPadOSºÍwatchOSÖеĶà¸ö0day£¬£¬£¬£¬ £¬£¬£¬Ô̺¬WebKit StorageµÄÄÚ´æ°Ü»µ·ì϶£¨CVE-2021-30661£©¡¢Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-27930£©¡¢ÄÚºËÄÚ´æÐ¹Â¶·ì϶£¨CVE-2020-27950£©ºÍÄÚºËÌØÈ¨ÌáÉý·ì϶£¨CVE-2020-27932£©¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/apple-fixes-macos-zero-day-bug-exploited-by-shlayer-malware/


5¡¢AzureÔÆÕÊ»§ÒòÅäÖÃÃýÎóй¶΢Èí¶à¿î²úÆ·µÄÔ´´úÂë


5.jpg


vpnMentor×êÑÐÍŶӷ¢ÏÖÒ»¸öÅäÖÃÃýÎóµÄMicrosoft Azure BlobÔÆÕÊ»§Ð¹Â¶ÁË΢Èí¶à¿î²úÆ·µÄÔ´´úÂë¡£¡£ ¡£¡£¡£Ð¹Â¶Êý¾ÝµÄ×Ü´óÓ×Ϊ63GB£¬£¬£¬£¬ £¬£¬£¬Ô̺¬³¬¹ý3800¸öÎļþ£¬£¬£¬£¬ £¬£¬£¬Éæ¼°Éϰټҹ«Ë¾µÄÈÚ×ÊÑݽ²¸åºÍ10-15ÖÖ²úÆ·µÄÔ´´úÂ룬£¬£¬£¬ £¬£¬£¬ÓÚ2021Äê1ÔÂ7ÈÕ±»·¢ÏÖ²¢ÒÑÔÚ2021Äê2ÔÂ23Èյõ½±£» £»£»£» £»¤¡£¡£ ¡£¡£¡£ÕâЩÎļþΪ¶à¶à¹«Ë¾ÏòMicrosoft Dynamics×ö³öµÄһϵÁÐóÒ×Ðû´«ºÍ²úÆ·×¢Ã÷£¬£¬£¬£¬ £¬£¬£¬¿ÉÄÜÀ´×Ô΢Èí¹«Ë¾¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.vpnmentor.com/blog/report-microsoft-dynamics-leak/