SkypeÔÚÈ«ÇòÁìÓòÄÚ·þÎñÖжϣ¬£¬£¬£¬£¬£¬£¬£¬ÔÒòÉв»Ã÷È·£»£»£»£»£»£»£»£»CISA³ÆºÚ¿Í¿ÉÈÆ¹ýMFAÉí·ÝÑéÖ¤½Ó¼ûÔÆ·þÎñÕÊ»§
°ä²¼¹¦·ò 2021-01-151.SkypeÔÚÈ«ÇòÁìÓòÄÚ·þÎñÖжϣ¬£¬£¬£¬£¬£¬£¬£¬ÔÒòÉв»Ã÷È·

1ÔÂ13ÈÕÉÏÎ磬£¬£¬£¬£¬£¬£¬£¬SkypeÔÚÈ«ÇòÁìÓòÄÚ·þÎñÖжϣ¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°¸ÃÎÊÌâÒѱ»½â¾ö¡£¡£¡£¡£¡£Æ¾¾ÝÔÚÏßÐÂÎÅÆ½Ì¨DownDetectorͳ¼Æ£¬£¬£¬£¬£¬£¬£¬£¬ÖжÏÖØÒª¼¯ÖÐÔÚÃÀ¹ú¡¢Å·ÖÞ¡¢ÑÇÖÞºÍÊÀ½çÆäËûµØÓò¡£¡£¡£¡£¡£Óû§ÔÚ½Ó¼ûSkypeÍøÕ¾Ê±£¬£¬£¬£¬£¬£¬£¬£¬»áÏÔʾÎÒÃÇÎÞ·¨ÊµÏÖÄúµÄÒªÇóµÄÌáÐÑ¡£¡£¡£¡£¡£MicrosoftÔÚSkype״̬ҳÉϰµÊ¾·¢ÏÖÁ˸ÃÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬ÆäÓ°ÏìÁËSkypeµÇ¼¡¢ºô½Ó×¢ÐÂÎÅ¡¢ËÑË÷¡¢Òƶ¯¹²Ïí¡¢Ö§¸¶ÏµÍ³¡¢SMSºÍÆäËû·þÎñ¡£¡£¡£¡£¡£ÎÊÌâÏÖÒѸ´Ô£¬£¬£¬£¬£¬£¬£¬£¬Skype¿ÉÔÙ´ÎÁª»ú¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/skype-is-down-worldwide-microsoft-working-on-issues/
2.CERTFAÅû¶APT35Óã²æÊ½´¹µö¹¥»÷»î¶¯µÄÏêÇé

CERTFAÅû¶ÁËÒÁÀʵÄAPT×éÖ¯Charming Kitten (±ðÃûAPT35£©Óã²æÊ½´¹µö¹¥»÷»î¶¯µÄÏêÇé¡£¡£¡£¡£¡£Õâ´Î¹¥»÷»î¶¯ÖØÒªÕë¶ÔλÓÚ²¨Ë¹Í塢ŷÖÞºÍÃÀ¹úÖÜΧ¹ú¶ÈµÄÖÇÄÒÍųÉÔ±¡¢ÕþÖÎ×êÑÐÖÐÐÄ¡¢´óѧ½ÌÊÚ¡¢¼ÇÕߺͻ·¾³»î¶¯¼Ò¡£¡£¡£¡£¡£¸Ã»î¶¯Í¬Ê±ÀûÓÃÁ˵ç×ÓÓʼþºÍSMS£¬£¬£¬£¬£¬£¬£¬£¬SMSÐÅÏ¢±»¼Ù×°³ÉGoogle°²È«¾¯±¨£¬£¬£¬£¬£¬£¬£¬£¬¶ø´¹µöÓʼþÔòÒÔ½ÚÈÕΪÖ÷Ìâ¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿Í³É¹¦µØ½«¶ñÒâÁ´½Ó°µ²ØÔںϷ¨Google URLºó£¬£¬£¬£¬£¬£¬£¬£¬Ê¹µÃÓû§¸üÄѱç±ðÆäÕæÎ±ÐÔ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/iranian-cyberspies-behind-major-christmas-sms-spear-phishing-campaign/
3.Check Point·¢ÏÖ¿ÉÊÕÊÜÉ豸²¢ÇÔÈ¡Êý¾ÝµÄ°²×¿Ä¾ÂíRogue

Check Point·¢ÏÖÁË¿ÉÊÕÊÜÉ豸²¢ÇÔÈ¡Êý¾ÝµÄÐÂÐͰ²×¿Ä¾ÂíRogue¡£¡£¡£¡£¡£Rogue RAT³É¹¦ÈëÇÖÖ¸±êÉ豸ºó»á°µ²ØÆäͼ±ê£¬£¬£¬£¬£¬£¬£¬£¬²¢·´¸´ÒªÇóÓû§ÊÚÓèËùÓбØÐëµÄȨÏÞ¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ»¹»á×¢²áΪÉ豸ÖÎÀíÔ±£¬£¬£¬£¬£¬£¬£¬£¬µ±Êܺ¦Õß·¢ÏÖ²¢ÊÔͼ²Ã³·ÖÎÀíԱȨÏÞ£¬£¬£¬£¬£¬£¬£¬£¬»¹»áÏÔʾ¡°ÄúÈ·¶¨Òª²Á³ýËùº±¼û¾ÝÂ𣿣¿£¿£¿£¿£¿£¿¡±µÄÌáÐÑÀ´¿ÖÏÅÓû§¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬RogueÀûÓÃÁËGoogleµÄFirebase£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÔÆÐÂÎÅ´«µÝ½Ó¹ÜÀ´×ÔC£¦CµÄºÅÁ£¬£¬£¬£¬£¬£¬£¬Í¨¹ýʵʱÊý¾Ý¿âÒÔ´ÓÉ豸ÉÏ´«Êý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýCloud FirestoreÉÏ´«Îļþ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/113369/malware/rogue-android-rat-darkweb.html
4.CISA³ÆºÚ¿Í¿ÉÈÆ¹ýMFAÉí·ÝÑéÖ¤½Ó¼ûÔÆ·þÎñÕÊ»§

ÃÀ¹úCISA³ÆºÚ¿Í¿ÉÈÆ¹ý¶à³É·ÖÉí·ÝÑéÖ¤£¨MFA£©½Ó¼ûÔÆ·þÎñÕÊ»§£¬£¬£¬£¬£¬£¬£¬£¬²¢°µÊ¾Æä·¢ÏÖÁ˼¸ÆðÕë¶Ô·ÖÆç×éÖ¯µÄÔÆ·þÎñµÄ¹¥»÷ÊÂÎñ¡£¡£¡£¡£¡£CISAÒÔΪ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓñ»µÁµÄ»á»°cookieÀ´½Ù³ÖÒÑͨ¹ýÉí·ÝÑéÖ¤µÄ»á»°£¬£¬£¬£¬£¬£¬£¬£¬¾Í¿ÉÈÆ¹ýMFAµÇ¼ÔÚÏß·þÎñ»òWebÀûÓ÷¨Ê½¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹»áͨ¹ýÇÔȡԱ¹¤Í´´¦À´»ñµÃ½Ó¼ûȨ£¬£¬£¬£¬£¬£¬£¬£¬»òͨ¹ýÅú¸ÄÓÊÏ乿¶¨ÒÔÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£Îª´Ë£¬£¬£¬£¬£¬£¬£¬£¬CISAÌṩÁ˼¼Êõϸ½ÚºÍ½â¾ö·½Ê½£¬£¬£¬£¬£¬£¬£¬£¬Ô®ÊÖ×éÖ¯Ó¦¶Ô´ËÀ๥»÷¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/cisa-hackers-bypassed-mfa-to-access-cloud-service-accounts/
5.Imperva°ä²¼Õë¶ÔÒ½ÁÆÐÐÒµµÄ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨

Imperva°ä²¼ÁËÕë¶ÔÒ½ÁÆÐÐÒµµÄ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬£¬£¬Õë¶ÔÒ½ÁÆÐÐÒµµÄWebÀûÓù¥»÷»î¶¯µÄÊýÁ¿Ôö³¤ÁË51£¥¡£¡£¡£¡£¡£È«ÇòÒ½ÁÆÐÐÒµ¾ùÔÈÿÔÂÔâ·ê1.87Òڴι¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Ã¿¸ö×é֯ÿÔ¾ùÔÈÔâ·ê498´Î¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬±ÈÈ¥ÄêͬÆÚÔö³¤ÁË10£¥¡£¡£¡£¡£¡£ºÚ¿ÍʹÓÃÁ˶àÖÖý½é£¬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÃÀ¹ú¡¢°ÍÎ÷¡¢Ó¢¹úºÍ¼ÓÄôóµÈ¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬ÔÚÈ¥Äê12Ô£¬£¬£¬£¬£¬£¬£¬£¬XSS¹¥»÷Ôö³¤ÁË43£¥£¬£¬£¬£¬£¬£¬£¬£¬SQL×¢ÈëÔö³¤ÁË44£¥£¬£¬£¬£¬£¬£¬£¬£¬ºÍ̸¹¥»÷Ôö³¤ÁË76£¥£¬£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì´úÂëÖ´ÐÐ/Ô¶³ÌÎļþÔ̺¬¹¥»÷Ôö³¤ÁË68£¥¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.imperva.com/blog/web-application-attacks-on-healthcare-spike-51-as-covid-19-vaccines-are-introduced/
6.Cisco°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´¶à¿î²úÆ·ÖеÄ67¸ö·ì϶

Cisco°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´Á˶à¿î²úÆ·ÖеÄ67¸ö·ì϶¡£¡£¡£¡£¡£ÆäÖÐ×îÑϳÁµÄ·ì϶ΪCisco Connected Mobile Experiences£¨CMX£©ÖеÄCVE-2021-1144£¬£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ8.8£¬£¬£¬£¬£¬£¬£¬£¬¿É±»Ô¶³Ì¹¥»÷ÕßÓÃÀ´¸ü¸ÄÖ¸±êϵͳÉÏËÁÒâÕÊ»§µÄÃÜÂë¡£¡£¡£¡£¡£»£»£»£»£»£»£»£»¹ÓÐCisco AnyConnect°²È«Òƶ¯¿Í»§¶ËÖеÄDLL×¢Èë·ì϶£¨CVE-2021-1237£©£¬£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ7.8¡£¡£¡£¡£¡£Õâ´Î¸üл¹½¨¸´ÁËÓ×ÐÍÆóҵ·ÓÉÆ÷RV110W¡¢RV130¡¢RV130WºÍRV215WÖÎÀí½Ó¿ÚÖеÄһϵÁпɵ¼ÖÂÔ¶³ÌºÅÁîÖ´Ðкͻؾø·þÎñ¹¥»÷µÄ·ì϶¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/113395/security/cisco-high-severity-flaw-cmx.html


¾©¹«Íø°²±¸11010802024551ºÅ