×êÑÐÍŶÓÅû¶net¿âÖдæÔÚµÄIPµØÖ·ÑéÖ¤·ì϶µÄϸ½Ú£»£»£»£» £»ÐÂAndroid¶ñÒâÈí¼þFlyTrap½Ù³ÖÊýǧFacebookÕÊ»§

°ä²¼¹¦·ò 2021-08-10
1.×êÑÐÍŶÓÅû¶net¿âÖдæÔÚµÄIPµØÖ·ÑéÖ¤·ì϶µÄϸ½Ú


1.jpg


ÉÏÖÜ£¬£¬£¬£¬£¬£¬×êÑÐÍŶÓÅû¶GoºÍRust˵»°³£ÓõÄnet¿âÖеÄIPµØÖ·ÑéÖ¤·ì϶µÄϸ½Ú¡£¡£¡£¡£¡£¡£·ì϶׷×ÙΪCVE-2021-29922£¨ÓÃÓÚRust£©ºÍCVE-2021-29923£¨ÓÃÓÚGolang£©£¬£¬£¬£¬£¬£¬Éæ¼°netÈôºÎ´¦ÖûìºÏÌåʽµÄIPµØÖ·£¬£¬£¬£¬£¬£¬»òÕ߸ü¾ßÌåµØËµµ±Ê®½øÔìIPv4µØÖ·Ô̺¬Ç°µ¼ÁãʱµÄ´¦Öᣡ£¡£¡£¡£¡£¸Ã·ì϶¿ÉÄܻᵼÖÂÀûÓ÷¨Ê½ÖгöÏÖ·þÎñÆ÷¶ËÒªÇóαÔì (SSRF) ºÍÔ¶³ÌÎļþÔ̺¬ (RFI) ·ì϶£¬£¬£¬£¬£¬£¬Ó°ÏìÁ˳ÉǧÉÏÍòÒÀÀµ¸Ã¿âµÄÀûÓᣡ£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/go-rust-net-library-affected-by-critical-ip-address-validation-vulnerability/


2.×êÑÐÈËÔ±ÑÝʾÈôºÎÓÃÍÏí³»ú·ì϶¹¥»÷Á¸Ê³³ö²ú¹©¸øÁ´


2.jpg


8ÔÂ8ÈÕ£¬£¬£¬£¬£¬£¬ÔÚDEF CON 29»áÒéÉÏ£¬£¬£¬£¬£¬£¬±»³ÆÎªSick CodesµÄ°Ä´óÀûÑÇ×êÑÐÈËÔ±¾ßÌå½éÉÜÁËËûËùνµÄÍÏí³»ú·ì϶£¨tractor load of vulnerabilities£©¡£¡£¡£¡£¡£¡£Sick Codes³Æ·¢ÏÖÁ˶à¸ö·ì϶£¬£¬£¬£¬£¬£¬¿ÉÈëÇÖũҵÉ豸¹©¸øÉÌJohn DeereÓÃÀ´´¦ÖÃÐÅÏ¢ºÍ½ÚÔìÉ豸µÄÔËÓªÖÐÐÄ£¬£¬£¬£¬£¬£¬²¢Äܹ»Í¨¹ý¸ÃÖÐÐĽӼûһЩÁªÍøµÄũҵÉ豸¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓø÷ì϶£¬£¬£¬£¬£¬£¬¿ÉÄܶÔÈ«ÇòµÄÁ¸Ê³³ö²ú¹©¸øÁ´Ôì³É¾Þ´óµÄÓ°Ï죬£¬£¬£¬£¬£¬ÀýÈç¹ý¶ÈÅçÈ÷»¯Ñ§Ò©¼Á£¬£¬£¬£¬£¬£¬»òÔ¶³Ì¼ÝÊ»ÍÏí³»úµÈ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/defcon-exploiting-vulnerabilities/


3.ACSC³ÆLockBit 2.0Õë¶Ô°Ä´óÀûÑǵÄÀÕË÷¹¥»÷¼¤Ôö


3.jpg


°Ä´óÀûÑÇÍøÂ簲ȫÖÐÐÄ (ACSC)³Æ£¬£¬£¬£¬£¬£¬´Ó2021Äê7ÔÂÆðÍ·£¬£¬£¬£¬£¬£¬LockBit 2.0Õë¶Ô°Ä´óÀûÑÇ×éÖ¯µÄÀÕË÷Èí¼þ¹¥»÷¼¤Ôö¡£¡£¡£¡£¡£¡£ACSCÖ¸³öLockBitÒѳɹ¦µØÔÚÉæ¼°×¨Òµ·þÎñ¡¢¹¹Öþ¡¢Ôì×÷¡¢ÁãÊÛºÍʳƷÔÚÄڵĸ÷¸öÐÐÒµµÄ¹«Ë¾ÏµÍ³ÉÏ×°ÖÃÁËÀÕË÷Èí¼þ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬¸Ã»ú¹¹»¹°ä²¼ÁËÒ»·ÝÀÕË÷Èí¼þÅäÖÃÎļþ£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬ÓйØLockBitÍÅ»ïµÄÆäËûÐÅÏ¢£¬£¬£¬£¬£¬£¬Ô̺¬³õʼ½Ó¼ûÖ¸±ê¡¢Ö¸±êÐÐÒµ»ººÍ½â´ëÊ©µÈ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/australian-govt-warns-of-escalating-lockbit-ransomware-attacks/


4.ÐÂAndroid¶ñÒâÈí¼þFlyTrap½Ù³ÖÊýǧFacebookÕÊ»§


4.jpg


Zimperium×êÑÐÈËÔ±·¢ÏÖÁËÒ»ÖÖÃûΪFlyTrapµÄÐÂÐÍAndroidľÂí¡£¡£¡£¡£¡£¡£×Ô3ÔÂÒÔÀ´£¬£¬£¬£¬£¬£¬FlyTrapÒÑͨ¹ýGoogle PlayÉ̵êºÍµÚÈý·½ÀûÓ÷¨Ê½Êг¡ÉϵĶñÒâÀûÓô«²¼µ½ÖÁÉÙ144¸ö¹ú¶ÈºÍµØÓò¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬ÔÚÔ½ÄϵĹ¥»÷»î¶¯Ö¼ÔÚ½Ù³ÖFacebookÕÊ»§¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓöàÖÖ¼¿Á©À´·Ö·¢¸Ã¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬ÈçÃâ·ÑNetflixÓÅ»Ýȯ´úÂë¡¢Google AdWordsÓÅ»Ýȯ´úÂ룬£¬£¬£¬£¬£¬ÒÔ¼°×î¼ÑÇò¶Ó»òÇòÔ±µÄͶƱ¡£¡£¡£¡£¡£¡£Ò»µ©Ö¸±ê³É¹¦×°Ö㬣¬£¬£¬£¬£¬Æä¾Í»áÇÔÈ¡Facebook ID¡¢µØÎ»¡¢ÓʼþµØÖ·¡¢IPµØÖ·£¬£¬£¬£¬£¬£¬ÒÔ¼°ÓйصÄcookieºÍ´ú±Ò¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/android-malware-flytrap-facebook/168463/


5.Kaspersky°ä²¼2021ÄêQ2À¬»øÓʼþºÍ´¹µö»î¶¯µÄ»ã±¨


5.jpg


Kaspersky°ä²¼ÁËÓйØ2021ÄêQ2À¬»øÓʼþºÍ´¹µö»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£2021ÄêQ2£¬£¬£¬£¬£¬£¬ÆóÒµÕË»§ÒÀÈ»Êǹ¥»÷ÕßµÄÖØÒªÖ¸±êÖ®Ò»¡£¡£¡£¡£¡£¡£ÎªÁËÔö³¤´¹µöÓʼþÖÐÁ´½ÓµÄ¿ÉÐŶȣ¬£¬£¬£¬£¬£¬¹¥»÷Õß¼Ù×°³ÆÀ´×ÔÔÆ·þÎñµÄÓʼþ£¬£¬£¬£¬£¬£¬ÀýÈçMicrosoft Teams»áÒéµÄ֪ͨµÈ¡£¡£¡£¡£¡£¡£À¬»øÓʼþÊýÁ¿µÄÕ¼±ÈÔÚ3Ô·ݴ¥µ×£¨45.10%£©ºó£¬£¬£¬£¬£¬£¬ÔÚ4Ô·ÝÓ×·ùÉÏÉý£¨45.29%£©£¬£¬£¬£¬£¬£¬µ½6Ô£¨48.03%£©Óë2020ÄêQ4Ï൱¡£¡£¡£¡£¡£¡£À¬»øÓʼþÆðÔ´×î¶àµÄ¹ú¶ÈΪ¶íÂÞ˹£¨26.07%£©£¬£¬£¬£¬£¬£¬Æä´ÎÊǵ¹ú£¨13.97%£©ºÍÃÀ¹ú£¨11.24%£©¡£¡£¡£¡£¡£¡£×î³£¼ûµÄ¶ñÒ⸽¼þÊÇBadun¼Ò×壨7.09%£©¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/spam-and-phishing-in-q2-2021/103548/


6.Digital Shadow°ä²¼2021ÄêQ2ÀÕË÷¹¥»÷µÄ·ÖÎö»ã±¨


6.jpg


Digital Shadow°ä²¼ÁË2021ÄêQ2ÀÕË÷¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬2021ÄêQ2ÊÇ×î³ÁÒªµÄÀÕË÷Èí¼þʱÆÚÖ®Ò»£¬£¬£¬£¬£¬£¬²úÉúÁ˼¸Æð³Á´óÊÂÎñ£¬£¬£¬£¬£¬£¬ÈçDarkSide¶ÔColonial PipelineµÄ¹¥»÷¡¢JBS¶ÔÈ«Çò×î´óÈâÀà¼Ó¹¤É̵Ĺ¥»÷£¬£¬£¬£¬£¬£¬ÒÔ¼°ÃÀ¹úºÍÅ·Ö޵ķ¨ÂÉÐж¯µÈ¡£¡£¡£¡£¡£¡£½öÔÚQ2¾ÍÓÐ740¼Ò¹«Ë¾µÄÐÅÏ¢±»°ä²¼µ½ÀÕË÷ÍÅ»ïµÄÊý¾ÝÐ¹Â¶ÍøÕ¾£¬£¬£¬£¬£¬£¬±ÈQ1Ôö³¤ÁË47%¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬ContiÍÅ»ï×îΪ»îÔ¾£¬£¬£¬£¬£¬£¬Æä´ÎΪAvaddon¡¢PYSAºÍREvil¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.digitalshadows.com/blog-and-research/q2-2021-ransomware-roll-up/