Stratus¹«Ë¾Ï°È¾ÀÕË÷Èí¼þ£¬£¬£¬£¬£¬ÍøÂçºÍ·þÎñÁÙʱÖжϣ»£»£»£»£»Purple Fox¹¥»÷»î¶¯½ÏÈ¥ÄêÔö³¤600£¥£¬£¬£¬£¬£¬´ï9ÍòÂÅ´Î
°ä²¼¹¦·ò 2021-03-251.Stratus¹«Ë¾Ï°È¾ÀÕË÷Èí¼þ£¬£¬£¬£¬£¬ÍøÂçºÍ·þÎñÁÙʱÖжÏ

Stratus TechnologiesϰȾÀÕË÷Èí¼þ£¬£¬£¬£¬£¬ÍøÂçºÍ·þÎñÁÙʱÖжϡ£¡£¡£¡£¡£¡£StratusÊdzÛÃûµÄ¸ß¿ÉÓÃÐÔ²úÆ·ÌṩÉÌ£¬£¬£¬£¬£¬Æä²úÆ·Ô̺¬ztC±ßÔµÍÆËãÉ豸ºÍftServerÈÝ´í·þÎñÆ÷½â¾ö¹æ»®µÈ£¬£¬£¬£¬£¬¿Í»§ÎªÒøÐÓ×¢µçÐÅÌṩÉÌ¡¢´¹Î£ºô½ÐÖÐÐĺÍÒ½ÁƱ£½¡»ú¹¹µÈ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾³ÆÆäÔÚ3ÔÂ17ÈÕÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬¼ì²âµ½¹¥»÷ºóÁ¢¿Ì¹Ø¹ØÁ˲¿ÃÅÍøÂçºÍ·þÎñÒÔ¸ôÀë¹¥»÷£¬£¬£¬£¬£¬Ô̺¬ÆäÈÝ´í²úÆ·µÄ·þÎñActiveService Network£¨ASN£©ºÍStratus·þÎñÃÅ»§¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/high-availability-server-maker-stratus-hit-by-ransomware/
2.Hobby LobbyÒò´æ´¢Í°ÅäÖÃÃýÎóй¶138GBÃô¸ÐÐÅÏ¢

¹¤ÒÕÆ·ÁãÊÛÉÌHobby LobbyÒòAWS´æ´¢Í°ÅäÖÃÃýÎóй¶138GBÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬Ó°ÏìÁËÔ¼30ÍòÃûÓû§¡£¡£¡£¡£¡£¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬Óû§ÐÕÃû¡¢²¿ÃÅÖ§¸¶¿¨µÄ¾ßÌåÐÅÏ¢¡¢µç»°ºÅÂë¡¢µØÖ·ºÍÓʼþµØÖ·£¬£¬£¬£¬£¬´Ë±í»¹Ô̺¬ÀûÓ÷¨Ê½µÄÔ´´úÂë¡¢¹«Ë¾Ô±¹¤µÄÐÕÃûºÍµç×ÓÓʼþµØÖ·µÈ¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬¸Ã´æ´¢Í°Òѱ»±£»£»£»£»£»¤ÆðÀ´£¬£¬£¬£¬£¬µ«Éв»È·¶¨ÊÇ·ñÓкڿÍÔÚ´Ë֮ǰÇÔÈ¡Á˶³öµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/hobby-lobby-customer-data-cloud-misconfiguration/164980/
3.Ó¢¹úÄÉ˰ÈËʹÓõÄÕ˵¥ÌáÐÑϵͳ¿ÉÄÜй¶ÆäÃô¸ÐÊý¾Ý

The RegisteµÄÒ»Ïîµ÷²é·¢ÏÖÓ¢¹úÄÉ˰ÈËʹÓõÄÕ˵¥ÌáÐÑϵͳ¿ÉÄÜй¶ÆäÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£¸ÃϵͳÊÇÓÉTelsolutions¿ª·¢£¬£¬£¬£¬£¬ÖØÒªÖ°ÄÜÊÇÏò¸ºÕ®Õß·¢ËÍÐÂÎÅÀ´ÌáÐÑÆä»¹Õ®£¬£¬£¬£¬£¬¸ÃÐÂÎÅÖлáÔ̺¬Ò»¸öÖ¸Ïò½Ó¹ÜÕßÓ×ÎÒÐÅÏ¢ºÍδÇåÕʵ¥Ò³ÃæµÄURL¡£¡£¡£¡£¡£¡£µ«ÊÇ£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ý¸ü¸ÄÍøÖ·ÖеÄ×ÖĸºÍÊý×Ö×Ö·ûÀ´²éÎÊÊôÓÚÆäËûÈ˵ÄÐÅÏ¢£¬£¬£¬£¬£¬ÉõÖÁÔ̺¬×¡ÔÚ·ÖÆçµØÓòµÄ¾ÓÃñÐÅÏ¢¡£¡£¡£¡£¡£¡£Telsolutions°µÊ¾¸Ã·ì϶ÏÖÒѽ¨¸´¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/debt-chasing-uk-councils-potentially-expose-private-resident-data/
4.Purple Fox¹¥»÷»î¶¯½ÏÈ¥ÄêÔö³¤600£¥£¬£¬£¬£¬£¬´ï9ÍòÂÅ´Î

Guardicore Labs°²È«×êÑÐÈËÔ±·¢ÏÖPurple FoxµÄ¹¥»÷»î¶¯×ÔÈ¥Äê5Ô·ÝÖÁ½ñÔö³¤ÁË600£¥£¬£¬£¬£¬£¬´ïµ½ÁË9ÍòÂŴΡ£¡£¡£¡£¡£¡£Purple FoxÊÇÒ»ÖÖWindows¶ñÒâÈí¼þ£¬£¬£¬£¬£¬ÓÚ2018Äê3Ô³õ´Î±»·¢ÏÖ£¬£¬£¬£¬£¬Í¨¹ý·ì϶ÀûÓù¤¾ß°üºÍ´¹µöÓʼþÀ´Ï°È¾ÍÆËã»ú¡£¡£¡£¡£¡£¡£ÔÚ×î½üµÄ»î¶¯ÖУ¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÁËËüʹÓÃÁËеÄϰȾý½é£¬£¬£¬£¬£¬Í¨¹ýSMBÃÜÂ뱩Á¦ÆÆ½âÃæÏòÍøÂçµÄWindowsÍÆËã»ú¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬¹¥»÷ÕßÒѽ«Purple FoxËùʹÓõĸ÷Àà¶ñÒâpayloadÍйÜÔÚÓɽü2000̨±»ÈëÇֵķþÎñÆ÷×é³ÉµÄÖØ´ó½©Ê¬ÍøÂçÉÏ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/03/purple-fox-rootkit-can-now-spread.html
5.΢ÈíÖÒ¸æ½üÆÚ´¹µö»î¶¯ÒÑÇÔÈ¡40Íò¸öOWAºÍOffice 365Í´´¦

×ÔÈ¥Äê12ÔÂÒÔÀ´£¬£¬£¬£¬£¬´¹µö»î¶¯ÒÑÇÔÈ¡40Íò¸öOWAºÍOffice 365Í´´¦¡£¡£¡£¡£¡£¡£WMC GlobalÓÚÈ¥ÄêËêÊ×·¢Ïָô¹µö»î¶¯£¬£¬£¬£¬£¬¼Ù×°³É¼Ù×°³ÉÊÓÆµ»áÒé·þÎñ¡¢°²È«½â¾ö¹æ»®ºÍ³ö²ú¹¤¾ßÀ´¹Æ»óÊܺ¦Õß¡£¡£¡£¡£¡£¡£È¥Äê12Ô£¬£¬£¬£¬£¬ºÚ¿Í¼ÙÒâÁËOutlook Web AppÀ´ºýŪָ±êÓû§ÊäÈëÍ´´¦£¬£¬£¬£¬£¬¶ø½ñÄê1Ô¸ÄΪ·ÂÕÕOffice 365À´ÇÔȡʹ´¦¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬Î¢Èí·¢Ïָû»¹ÀûÓÃÁËAmazon Simple Email Service£¨SES£©ºÍAppspotÔÆÍÆËãÆ½Ì¨À´·¢ËÍÍøÂç´¹µöµç×ÓÓʼþ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-warns-of-phishing-attacks-bypassing-email-gateways/
6.Cisco°ä²¼°²È«¸üУ¬£¬£¬£¬£¬½¨¸´JabberÖÐËÁÒâ´úÂëÖ´Ðзì϶

Cisco°ä²¼°²È«¸üУ¬£¬£¬£¬£¬½¨¸´ÁËWindows¡¢macOS¡¢AndroidºÍiOS°æ±¾Jabber clientÖеÄËÁÒâ´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£JabberÊÇÒ»¸öÍøÂç»áÒéºÍ¼´Ê±ÐÂÎÅ´«µÝÀûÓ㬣¬£¬£¬£¬Cisco°µÊ¾¸Ã·ì϶ĿǰÉÐδ±»¿í·ºÀûÓᣡ£¡£¡£¡£¡£¸Ã·ì϶±»×·×ÙΪCVE-2021-1411£¬£¬£¬£¬£¬ÑϳÁµÈ¼¶Îª9.9£¬£¬£¬£¬£¬ÊÇÓɶÔÊäÈëÐÂÎÅÄÚÈÝÑéÖ¤²»µ±ÒýÆðµÄ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬Õâ´Î¸üл¹½¨¸´Á˸òúÆ·ÖÐµÄÆäËû4¸ö·ì϶£¨CVE-2021-1417ºÍ CVE-2021-1418µÈ£©£¬£¬£¬£¬£¬ÒÔ¼°ÆäËû²úÆ·ÖеÄ37¸ö·ì϶¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/cisco-addresses-critical-bug-in-windows-macos-jabber-clients/


¾©¹«Íø°²±¸11010802024551ºÅ