Apple°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´iOSºÍmacOSÖÐÒѱ»ÀûÓõÄ0day£»£»£»£»£»Ï£À°µÚ¶þ´ó³ÇÊÐThessalonikiÔâµ½¹¥»÷ÊÐÕþ·þÎñÖжÏ

°ä²¼¹¦·ò 2021-07-27

1.Apple°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´iOSºÍmacOSÖÐÒѱ»ÀûÓõÄ0day


1.jpg


Apple°ä²¼Á˰²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´ÁËiOSºÍmacOSÖÐÒѱ»ÔÚÒ°ÀûÓõÄ0day¡£ ¡£¡£¡£¡£¡£¡£¸Ã·ì϶׷×ÙΪCVE-2021-30807£¬£¬£¬£¬£¬£¬£¬ÊÇÓÃÓÚÖÎÀíÆÁĻ֡»º³åÇøµÄÄÚºËÀ©´óIOMobileFramebufferÖеÄÄÚ´æ°Ü»µ·ì϶¡£ ¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÔÚÖ¸±êÉ豸ÉÏʹÓÃÄÚºËȨÏÞÖ´ÐÐËÁÒâ´úÂ룬£¬£¬£¬£¬£¬£¬²¢ÆëÈ«½ÚÔìÉ豸¡£ ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾³Æ·ì϶¿ÉÄÜÒѱ»»ý¼«ÀûÓ㬣¬£¬£¬£¬£¬£¬µ«²¢Î´Ð¹Â©ÓйØÕâЩ¹¥»÷µÄÈÎºÎÆäËûÐÅÏ¢¡£ ¡£¡£¡£¡£¡£¡£ÕâÊÇAppleÔÚ½ñÄ꽨¸´µÄµÚ13¸ö0day¡£ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/apple/apple-fixes-zero-day-affecting-iphones-and-macs-exploited-in-the-wild/


2.Ï£À°µÚ¶þ´ó³ÇÊÐThessalonikiÔâµ½¹¥»÷ÊÐÕþ·þÎñÖжÏ


2.jpg


Ï£À°µÚ¶þ´ó³ÇÊÐÈøÂÞÄá¼Ó£¨Thessaloniki£©Ôâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÊÐÕþ·þÎñÁÙʱÖжϡ£ ¡£¡£¡£¡£¡£¡£¸ÃÊи±Êг¤Giorgos Avarlis³Æ¹¥»÷²úÉúÔÚ2021Äê7ÔÂ23ÈÕ£¬£¬£¬£¬£¬£¬£¬·¢ÏÖºó¸ÃÊÐÁ¢¼´¹ØÁË·þÎñºÍwebÀûÓ÷¨Ê½¡£ ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÒѾ­×°ÖÃÁËÒ»ÖÖ¶ñÒⲡ¶¾²¢ÒªÇóÖ§¸¶Êê½ðÀ´½âËøÎļþ£¬£¬£¬£¬£¬£¬£¬µ«²¢Î´Ð¹Â©ÆäÊÇ·ñÖ§¸¶ÁËÊê½ð»òÖ§¸¶Á˼¸¶àÇ®¡£ ¡£¡£¡£¡£¡£¡£Avarlis»¹°µÊ¾£¬£¬£¬£¬£¬£¬£¬ÊÐÕþµ±¾ÖµÄËùÓÐÎļþ¶¼Êǰ²È«µÄ£¬£¬£¬£¬£¬£¬£¬µ«ÈÔδȷ¶¨¹¥»÷µÄÆðÔ´¡£ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.thenationalherald.com/archive_general_news_greece/arthro/cyberattack_shuts_down_services_in_greece_s_second_largest_city-2960445/


3.×êÑÐÍŶӷ¢ÏÖ¹¥»÷ÕßÀûÓÃArgo WorkflowsÍÚ¿óµÄ»î¶¯


3.jpg


Intezer×êÑÐÍŶӷ¢ÏÖ¹¥»÷ÕßÀûÓÃÅäÖÃÃýÎóµÄArgo WorkflowsµÄÍÚ¿ó»î¶¯¡£ ¡£¡£¡£¡£¡£¡£Argo WorkflowsÊÇÒ»¸ö¿ªÔ´µÄ¡¢ÈÝÆ÷Ô­ÉúµÄ¹¤×÷Á÷ÒýÇæ£¬£¬£¬£¬£¬£¬£¬ÔÚKubernetes(K8s)¼¯ÈºÉÏÔËÐÓ×£ ¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖһЩȨÏÞÅäÖÃÃýÎóµÄÊ·ý£¬£¬£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷Õß½Ó¼ûÊ¢¿ªµÄArgo½ÚÔìÃæ°å£¬£¬£¬£¬£¬£¬£¬²¢ÀûÓø÷ÀàMonero¿ó¹¤ÈÝÆ÷×°ÖÃ×Ô¼ºµÄ¶ñÒâWorkflows£¬£¬£¬£¬£¬£¬£¬Ô̺¬kannix/monero-miner¡£ ¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬£¬£¬ÒÑ·¢ÏÖÊý°Ù¸öÅäÖÃÃýÎóµÄArgo Workflows£¬£¬£¬£¬£¬£¬£¬Òò¶øÄܹ»Ô¤¼Æ½«Óиü´ó¹æÄ£µÄ¹¥»÷¡£ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/120544/malware/kubernetes-attacks-argo-workflows.html


4.Sophos·¢ÏÖÀûÓÃDiscord CDNºÍAPIµÄ¹¥»÷»î¶¯¼¤Ôö


4.jpg


Sophos·¢ÏÖDiscord¶ñÒâÈí¼þµÄÊýÁ¿¼¤Ôö£¬£¬£¬£¬£¬£¬£¬Óë2020ÄêÏà±ÈÔö³¤ÁË140±¶¡£ ¡£¡£¡£¡£¡£¡£µ¼Ö´ËÇ÷ÏòµÄÖØÒªÔ­ÒòÊǺڿÍÒ»ÏòÔÚÀÄÓÃDiscordµÄÄÚÈݽ»¸¶ÍøÂç(CDN)ºÍÀûÓ÷¨Ê½±à³Ì½Ó¿Ú(API)£¬£¬£¬£¬£¬£¬£¬ÆäÖÐCDN±»ÓÃÀ´ÍйܶñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬¶øAPI±»ÓÃÀ´ÇÔÈ¡Êý¾ÝÒÔ¼°ÏνӺÅÁîºÍ½ÚÔì·þÎñÆ÷¡£ ¡£¡£¡£¡£¡£¡£Sophos³Æ£¬£¬£¬£¬£¬£¬£¬4Ô·ÝÔÚDiscordµÄCDNÉϼì²âµ½9500¸ö¶ñÒâURL£¬£¬£¬£¬£¬£¬£¬¶øÔÚ½ÓÏÂÀ´µÄ¼¸¸öÔÂÀ£¬£¬£¬£¬£¬£¬Õâ¸öÊý×Öì­ÉýÖÁ17000¡£ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/discord-malware-researchers/168096/


5.Coveware°ä²¼2021ÄêQ2ÓйØÀÕË÷¹¥»÷µÄ·ÖÎö»ã±¨


5.jpg


Coveware°ä²¼ÁË2021ÄêQ2ÓйØÀÕË÷¹¥»÷µÄ·ÖÎö»ã±¨¡£ ¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö2021ÄêQ2ÀÕË÷Èí¼þµÄ¾ùÔȸ¶¿î¶î½µÂäÖÁ136576ÃÀÔª£¬£¬£¬£¬£¬£¬£¬ÓëQ1µÄ220298ÃÀÔªÏà±È½µÂäÁË38%¡£ ¡£¡£¡£¡£¡£¡£2020ÄêÓÐ65%µÄÊܺ¦ÕßÑ¡ÔñÖ§¸¶Êê½ð£¬£¬£¬£¬£¬£¬£¬¶ø2021ÄêQ2Ö»ÓÐ50%µÄÊܺ¦Õ߸¶¿î¡£ ¡£¡£¡£¡£¡£¡£ÔÚÕâÒ»¼¾¶È×î³£¼ûµÄÀÕË÷Èí¼þ±äÌåΪSodinokibi£¨16.5%£©¡¢ContiV2£¨14.4%£©¡¢Avaddon£¨5.4%£©¡¢Mespinoza£¨4.9%£©ºÍHello Kitty£¨4.5%£©µÈ¡£ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.coveware.com/blog/2021/7/23/q2-ransom-payment-amounts-decline-as-ransomware-becomes-a-national-security-priority


6.Vade°ä²¼2021ÄêÉϰëÄêÍøÂç´¹µö¹¥»÷µÄ·ÖÎö»ã±¨


6.jpg


Vade°ä²¼ÁË2021ÄêÉϰëÄêÈ«ÇòÍøÂç´¹µö¹¥»÷µÄ·ÖÎö»ã±¨£¬£¬£¬£¬£¬£¬£¬·ÖÎöÁ˹¥»÷Õß×î°®µÄ25¸öÆ·ÅÆ¡£ ¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬£¬×ÜÌåµÄÍøÂç´¹µöÊýÁ¿ÔÚ2021ÄêQ2¼±¾çÔö³¤£¬£¬£¬£¬£¬£¬£¬5Ô·ݼ¤ÔöÁË281%£¬£¬£¬£¬£¬£¬£¬6Ô·ÝÓÖÔö³¤ÁË284%£¬£¬£¬£¬£¬£¬£¬½öÔÚ6Ô·ݵ±Ô¾ͼì²âµ½42ÒڴεĴ¹µöµç×ÓÓʼþ¡£ ¡£¡£¡£¡£¡£¡£ÔÚÉϰëÄ꣬£¬£¬£¬£¬£¬£¬·¨¹úũҵÐÅ´ûÒøÐУ¨Cr¨¦dit Agricole£©ÊDZ»¼ÙÒâ×î¶àµÄÆ·ÅÆ£¬£¬£¬£¬£¬£¬£¬ÓÐ17555¸öÓйصĴ¹µöURL£¬£¬£¬£¬£¬£¬£¬Æä´ÎΪFacebook£¨17338¸ö£©ºÍMicrosoft£¨12777¸ö£©¡£ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.vadesecure.com/en/blog/phishers-favorites-top-25-h1-2021-worldwide-edition