F5°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´BIG-IPºÍBIG-IQÖжà¸öRCE·ì϶£»£»£»£»£»£»£»£»ÔÆÌṩÉÌOVHÊý¾ÝÖÐÐĵÄij»ú·¿×Ż𣬣¬£¬£¬£¬£¬£¬µ¼Ö·þÎñÁÙʱÖжÏ
°ä²¼¹¦·ò 2021-03-111.F5°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´BIG-IPºÍBIG-IQÖжà¸öRCE·ì϶

F5 Networks°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´Ó°ÏìÁËBIG-IPºÍBIG-IQÖеĶà¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬4¸öÑϳÁµÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©·ì϶¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄRCE±ðÀëΪiControl RESTÖеÄRCE£¨CVE-2021-22986£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.8£©¡¢TMUIÖеÄRCE£¨CVE-2021-22987£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.9£©¡¢TMMÖпɵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐеĻº³åÇøÒç¶Âí½Å£¨CVE-2021-22991£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.0£©ºÍAdvanced WAF/ASMÖпɵ¼ÖÂDoS¹¥»÷ºÍRCEµÄ»º³åÇøÒç¶Âí½Å£¨CVE-2021-22992 £¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.0£©¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/f5-urges-customers-to-patch-critical-big-ip-pre-auth-rce-bug/
2.Adobe°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´¶à¿î²úÆ·ÖеÄ8¸ö·ì϶

Adobe°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´Framemaker¡¢Creative CloudºÍConnectÖеÄ8¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ×îΪÑϳÁµÄ·ì϶ΪFramemakerÖеĿɵ¼ÖÂËÁÒâ´úÂëÖ´ÐеÄÔ½½ç¶ÁÈ¡·ì϶£¨CVE-2021-21056£©ÒÔ¼°ConnectÖеÄËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-21085£©¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬»¹½¨¸´ÁËCreative CloudÖÐËÁÒâÎļþ¸²¸Ç·ì϶£¨CVE-2021-21068£©¡¢OSºÅÁî×¢È밲ȫ·ì϶£¨CVE-2021-21078£©ºÍ²»ÕýÈ·µÄÊäÈëÑéÖ¤µ¼ÖµÄÌáȨ·ì϶£¨CVE-2021-21069£©£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ConnectÖеÄ3¸öXSS·ì϶£¨CVE-2021-21079¡¢CVE-2021-21080ºÍCVE-2021-21081£©¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/adobe-releases-batch-of-security-fixes-for-framemaker-creative-cloud-connect/
3.×êÑÐÍŶӷ¢ÏÖ½©Ê¬ÍøÂçz0MinerÍÚ¿óµÄ¹¥»÷»î¶¯

×êÑÐÍŶӷ¢ÏÖ½©Ê¬ÍøÂçz0MinerÊÔͼ½ÚÔìJenkinsºÍElasticSearch·þÎñÆ÷À´ÍÚ¾òMonero£¨XMR£©¼ÓÃÜÇ®±ÒµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£z0MinerÊÇÈ¥ÄêÔÚ11Ô±»·¢ÏÖµÄÒ»ÖÖÍÚ¿ó¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬ÆäÀûÓÃWeblogic·ì϶ϰȾÁËÊýǧ̨·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£¶øÕâ´Î»î¶¯ÀûÓÃÁËElasticSearchÖеÄRCE·ì϶£¨CVE-2015-1427£©ºÍÓ°ÏìÁËJenkins·þÎñÆ÷µÄÒ»¸ö¹ÅÀϵÄRCE¡£¡£¡£¡£¡£¡£¡£¡£ÔÚÈëÇÖ·þÎñÆ÷ºó£¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ½«ÏÈÏÂÔØ¶ñÒâshell¾ç±¾£¬£¬£¬£¬£¬£¬£¬¶øºóѰÕÒ²¢É¾³ýÒÔǰװÖõÄÍÚ¿ó¾ç±¾¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/z0miner-botnet-hunts-for-unpatched-elasticsearch-jenkins-servers/
4.Î÷°àÑÀÀ͹¤¾ÖÔâÀÕË÷¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÆäÔ±¹¤±»ÆÅ×ÃÖ½±Ê°ì¹«

Î÷°àÑÀ¹¤»áÓÚ±¾Öܶþ°µÊ¾Î÷°àÑÀ¹ú¶È¹«¹²¾ÍÒµ·þÎñ¾Ö£¨SEPE£©Ôâµ½ÁËRyukÀÕË÷¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÏµÍ³ÒѾ¹Ø¹Ø¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷µ¼Ö¸ûú¹¹ÔÚÈ«¹ú700¶à¼Ò´¦Ê´¦Êܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬ÆäÔ±¹¤±»ÆÈʹÓÃÖ½±Ê°ì¹«¡£¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬£¬¸ÃÀÕË÷Èí¼þÒ²ÒѾÀ©É¢µ½SEPEµÄ°ì¹«ÊÒÖ®±í£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁËÔ¶³Ì¹¤×÷ÈËÔ±µÄ±Ê¼Ç±¾µçÄÔ¡£¡£¡£¡£¡£¡£¡£¡£¹¤»á³ÆSEPEµÄITϵͳÒѾÀÏ»¯£¬£¬£¬£¬£¬£¬£¬¶ø¸Ã»ú¹¹²¢Î´ÎªÆäÉý¼¶¡£¡£¡£¡£¡£¡£¡£¡£SEPE×ܼà֤ʵ£¬£¬£¬£¬£¬£¬£¬ÆäϵͳÒѱ»Ryuk¼ÓÃÜ£¬£¬£¬£¬£¬£¬£¬µ«Ã»º±¼û¾Ýй¶£¬£¬£¬£¬£¬£¬£¬Ê§Òµ¾ÈÖú½ðµÄ·¢·ÅҲûÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.cyberscoop.com/spain-ransomware-employment-agency-sepe/
5.ÔÆÌṩÉÌOVHÊý¾ÝÖÐÐĵÄij»ú·¿×Ż𣬣¬£¬£¬£¬£¬£¬µ¼Ö·þÎñÁÙʱÖжÏ

λÓÚ·¨¹úË¹ÌØÀ˹±¤µÄÔÆÌṩÉ̵ÄOVHÊý¾ÝÖÐÐÄׯ𣬣¬£¬£¬£¬£¬£¬µ¼Ö·þÎñÁÙʱÖжϡ£¡£¡£¡£¡£¡£¡£¡£OVHÊÇÅ·ÖÞ×î´óµÄÍйܷþÎñÌṩÉÌ£¬£¬£¬£¬£¬£¬£¬Ò²ÊÇÊÀ½çµÚÈý´óÍйܷþÎñÌṩÉÌ£¬£¬£¬£¬£¬£¬£¬¿ÉÌṩVPS¡¢×¨Ó÷þÎñÆ÷ºÍÆäËûWeb·þÎñ¡£¡£¡£¡£¡£¡£¡£¡£3ÔÂ10ÈÕ£¬£¬£¬£¬£¬£¬£¬OVHÊý¾ÝÖÐÐÄSBG2²úÉúÁ˻𾯣¬£¬£¬£¬£¬£¬£¬Ïû·ÀÈËÔ±Á¢¼´¸Ïµ½ÏÖ³¡µ«ÎÞ·¨½ÚÔì»ðÊÆ¡£¡£¡£¡£¡£¡£¡£¡£Òò¶øÕû¸öÕ¾µãÒѱ»¸ôÀ룬£¬£¬£¬£¬£¬£¬ÕâÒ²Ó°ÏìÁËSBG1¡¢SBG2¡¢SBG3ºÍSBG4ÉϵÄËùÓзþÎñ¡£¡£¡£¡£¡£¡£¡£¡£ÊÓÆµÓÎÏ·¹«Ë¾Rust³Æ£¬£¬£¬£¬£¬£¬£¬´ËÊÂÎñÒѵ¼ÖÂÆäÈ«ÊýÊý¾ÝÃÔʧ£¬£¬£¬£¬£¬£¬£¬ÎÞ·¨¸´Ô¡£¡£¡£¡£¡£¡£¡£¡£OVHÔÚÖÂÁ¦¸´ÔÆä·þÎñ£¬£¬£¬£¬£¬£¬£¬²¢½¨Òé¿Í»§Ó¦Á¢¼´¼¤»î¿àÄѱ¸·Ý´òËã¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.theregister.com/2021/03/10/ovh_strasbourg_fire/
6.iPhoneÀûÓÃAcr call recorderй¶13ÍòÌõͨ»°¼Í¼

iPhoneµÄÀûÓÃAcr call recorder´æÔÚ·ì϶£¬£¬£¬£¬£¬£¬£¬¿Éй¶13ÍòÌõͨ»°¼Í¼¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÀûÓÃÔÚApp StoreÖÐÕ¼Óг¬¹ýÒ»°ÙÍòµÄÏÂÔØÁ¿£¬£¬£¬£¬£¬£¬£¬±»ÁÐΪiPhone¶¥¼¶Í¨»°¼Í¼ÀûÓÃÖ®Ò»¡£¡£¡£¡£¡£¡£¡£¡£PingSafe AIµÄ×êÑÐÈËÔ±ÔÚÑÇÂíÑ·ÉÏ·¢ÏÖÁ˸ÃÀûÓÃԼΪ300 GBµÄ´æ´¢Í°£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÁË130000¶à¸ö¼Í¼¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓÃBurp»òZapÖ®ÀàµÄWeb´úÀí¹¤¾ß£¬£¬£¬£¬£¬£¬£¬¿ÉÔÚÒªÇóÖвåÈëÓû§µÄµç»°ºÅÂë¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÏìÓ¦µÄAPIûÓÐÈκÎÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬£¬ËùÒÔ½«·µ»ØÓëÒªÇóÖеĵ绰ºÅÂëÓйصÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬Ô̺¬Óû§µÄÕû¸öͨ»°¼Í¼¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/iphone-call-recorder-bug-gave-acess-to-other-peoples-conversations/


¾©¹«Íø°²±¸11010802024551ºÅ