Apple°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´macOSÖб»ShlayerÀûÓõÄ0day£»£»£»£»£»£»CiscoÅû¶LinuxÄÚºËÖпÉÈÆ¹ýKASLRµÄÐÅϢй¶·ì϶
°ä²¼¹¦·ò 2021-04-281.Apple°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´macOSÖб»ShlayerÀûÓõÄ0day

Apple°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´macOS Big Sur 11.3ÖÐÒѱ»ÀûÓõÄ0day¡£¡£¡£¡£¡£¡£¡£¡£°²È«ÍŶÓJamf·¢ÏÖ£¬£¬£¬£¬£¬£¬´Ó2021Äê1ÔÂÆðÍ·¶ñÒâÈí¼þShlayerÀûÓÃÁËÒ»¸ö0day£¨CVE-2021-30657£©£¬£¬£¬£¬£¬£¬À´ÈƹýAppleµÄÎļþ¸ôÀë¡¢GatekeeperºÍ¹«Ö¤°²È«²é³£¬£¬£¬£¬£¬£¬²¢ÏÂÔØµÚ¶þ½×¶ÎËùʹÓõÄpayload¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬Õâ´Î¸üл¹½¨¸´ÁËiOS¡¢iPadOSºÍwatchOSÖеĶà¸ö0day£¬£¬£¬£¬£¬£¬Ô̺¬WebKit StorageµÄÄÚ´æ°Ü»µ·ì϶£¨CVE-2021-30661£©¡¢Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-27930£©¡¢ÄÚºËÄÚ´æÐ¹Â¶·ì϶£¨CVE-2020-27950£©ºÍÄÚºËÌØÈ¨ÌáÉý·ì϶£¨CVE-2020-27932£©¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/apple-fixes-macos-zero-day-bug-exploited-by-shlayer-malware/
2.Valve°ä²¼¸üУ¬£¬£¬£¬£¬£¬½¨¸´SteamÖÐÒÑ´æÔÚÁ½ÄêµÄRCE·ì϶

Valve°ä²¼¸üУ¬£¬£¬£¬£¬£¬½¨¸´ÓÎϷƽ̨SteamÖÐÒÑ´æÔÚÁ½ÄêµÄRCE·ì϶¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶¿ÉÔÚ¶ñÒâÓÎÏ·Ô¼ÇëÖÐÔö³¤ºÅÁ£¬£¬£¬£¬£¬¶ÔÓÎÏ·×ö³ö΢Ó׵ĵĵ÷Õû£¬£¬£¬£¬£¬£¬ÈçÅú¸ÄÓÎϷ˵»°¡¢»îÂç¶È¡¢·Ö±æÂʵȡ£¡£¡£¡£¡£¡£¡£¡£µ«ÊÇÓÉÓÚSource RCONºÍ̸ÔÊÐí·þÎñÆ÷ËùÓÐÕßÔÚ·þÎñÆ÷ÖÐÖ´ÐкÅÁ£¬£¬£¬£¬£¬ÀûÓô˸öÐÔ¿ÉÌáÒéRCE¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±»¹ÑÝʾÁËÈôºÎÀûÓø÷ì϶À´ÆëÈ«ÊÕÊÜCS£ºGOÓÎÏ·Íæ¼ÒµÄÕ˺𣡣¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±FlorianÓÚ2019Äê»ã±¨Á˸÷ì϶£¬£¬£¬£¬£¬£¬ValveÔÚ2021Äê4ÔÂ17ÈÕ°ä²¼Á˲¹¶¡·¨Ê½£¬£¬£¬£¬£¬£¬²¢·ÖÅäÁËCVE-2021-30481¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://latesthackingnews.com/2021/04/26/valve-finally-patched-a-steam-rce-vulnerability-that-waited-a-fix-for-two-years/
3.CiscoÅû¶LinuxÄÚºËÖпÉÈÆ¹ýKASLRµÄÐÅϢй¶·ì϶

Cisco Talos³Æ£¬£¬£¬£¬£¬£¬LinuxÄÚºËÖдæÔÚ¿ÉÈÆ¹ýKASLRµÄÐÅϢй¶·ì϶¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶±»×·×ÙΪCVE-2020-28588£¬£¬£¬£¬£¬£¬Î»ÓÚÔËÐÐLinuxµÄ32λARMÉ豸µÄ/proc/pid/ syscallÖ°ÄÜÖУ¬£¬£¬£¬£¬£¬ÊÇÓÉÓÚ¶ÁÈ¡ÎļþʱÊýֵת»»²»ÕýÈ·¶øÒýÆðµÄ¡£¡£¡£¡£¡£¡£¡£¡£Í¨¹ýʹÓü¸ÌõshellºÅÁ£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Êä³ö24¸ö×Ö½ÚµÄδ³õʼ»¯µÄ²Ö¿âÄڴ棬£¬£¬£¬£¬£¬ÕâЩÄÚ´æÄܹ»±»ÓÃÀ´ÈƹýÄں˵ØÖ·¿Õ¼ä²¼¾ÖËæ»ú»¯£¨KASLR£©¡£¡£¡£¡£¡£¡£¡£¡£Cisco½¨ÒéÓû§¾¡¿ì¸üÐÂÊÜÓ°ÏìµÄ²úÆ·LinuxÄں˰汾5.10-rc4¡¢5.4.66ºÍ5.9.8¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/linux-kernel-bug-wider-cyberattacks/165640/
4.ÓÍÌ﹫˾GyrodataϰȾÀÕË÷Èí¼þ£¬£¬£¬£¬£¬£¬Ô±¹¤Ãô¸ÐÐÅϢй¶

ÃÀ¹úÓÍÌ﹫˾Gyrodataй©£¬£¬£¬£¬£¬£¬ÆäÓÚ2ÔÂ21ÈÕ·¢ÏÖÔâµ½ÁËÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬Ô±¹¤Ãô¸ÐÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£¡£¾µ÷²éÈ·¶¨£¬£¬£¬£¬£¬£¬ºÚ¿ÍÔÚ2021Äê1ÔÂ16ÈÕÖÁ2ÔÂ22ÈÕÖ®¼äÄܹ»½Ó¼ûÆä²¿ÃÅϵͳºÍÓйØÊý¾Ý£¬£¬£¬£¬£¬£¬¿ÉÄÜй¶ÁËÏÖÔ±¹¤ºÍǰԱ¹¤µÄÓ×ÎÒÐÅÏ¢£¬£¬£¬£¬£¬£¬Ô̺¬µ®ÉúÈÕÆÚ¡¢µØÖ·¡¢Éç»á±£Ïպš¢¼ÝÕÕºÅÂë¡¢»¤ÕÕºÅÂë¡¢W-2˰±íºÍ½¡È«´òËãÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¡£¡£½ØÖÁÉÏÖÜËÄ£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾Ò»ÏòÔÚÁªÏµÊÜÓ°ÏìµÄÔ±¹¤£¬£¬£¬£¬£¬£¬²¢³ÉÁ¢ÁËרÃŵĺô½ÐÖÐÐÄÀ´Ó¦¶Ô¿ÉÄܳöÏÖµÄÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/oilfield-services-company-gyrodata-discloses-data-breach
5.Reverb֪ͨ¿Í»§ÒòÆä·þÎñÆ÷ÅäÖÃÃýÎóй¶560¶àÍò±Ê¼Í¼

ReverbÓÚ4ÔÂ26ÈÕÏòÆä¿Í»§·¢ËÍÁËÊý¾Ýй¶֪ͨ£¬£¬£¬£¬£¬£¬Åú×¢ÒÑй¶Á˿ͻ§ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ReverbÖØÒªÔÚÏßÏúÊÛÀÔì÷µÈÉ豸£¬£¬£¬£¬£¬£¬Õâ´Îй¶µÄ¿Í»§ÐÅÏ¢Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢PayPalÓʼþµØÖ·ºÍ¶©µ¥ÐÅÏ¢µÈÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£¡£Reverb²¢Î´ÔÚ֪ͨÖÐ×¢Ã÷ËûÃÇÊÇÒòºÎй¶Êý¾ÝµÄ£¬£¬£¬£¬£¬£¬µ«°²È«×êÑÐÔ±Bob Diachenko³ÆÆäÔÚInternetÉÏ·¢ÏÖÁËÒ»¸ö¶³öµÄElasticsearch·þÎñÆ÷£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬³¬¹ý560Íò±Ê¼Í¼¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/reverb-discloses-data-breach-exposing-musicians-personal-info/
6.ºÚ¿ÍÔÚ°µÍø¹«¿ªÃÀ¹ú2.5ÒÚ¸ö¹«ÃñµÄÓ×ÎҺͼÒÍ¥ÐÅÏ¢

2021Äê4ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬ÃûΪPompompurinµÄºÚ¿ÍÔÚ°µÍø¹«¿ªÁËÒ»¸öÊý¾Ý¿â£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Á˳¬¹ý250807711¸öÃÀ¹ú¹«ÃñµÄÓ×ÎҺͼÒÍ¥ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÓÐ263 GBµÄ¼Í¼£¬£¬£¬£¬£¬£¬Ô̺¬ÁË1255¸öCSV×ÓÎļþ£¬£¬£¬£¬£¬£¬Ã¿¸ö×ÓÎļþÓÐ200000¸öÁÐ±í£¬£¬£¬£¬£¬£¬Ô̺¬ÐÕÃû¡¢µç»°ºÅÂë¡¢ÓʼþµØÖ·¡¢µ®ÉúÈÕÆÚ¡¢»éÒöÇé¿ö¡¢ÐÔ±ð¡¢ÐÅÓþÄÜÁ¦¡¢ÕþÖÎÁ÷ÅÉ¡¢³µÁ¾ÊýÁ¿¡¢ÊÕÈëÃ÷ϸºÍº¢×Ó¸öÊýµÈÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°Éв»Ã÷ÏÔÊý¾ÝµÄÆðÔ´£¬£¬£¬£¬£¬£¬ÓйØÈËԱй©À´×ÔAmazon Web ServerÉÏÍйܵÄÊ¢¿ªÊ½Apache SOLR¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/hacker-dumps-household-records-of-americans/


¾©¹«Íø°²±¸11010802024551ºÅ