Print Spooler´æÔÚ佨¸´RCE£¬£¬£¬£¬£¬£¬£¬£¬Î¢Èí³Ðŵ¾¡¿ì½¨¸´£»£»£»£»£»£»£»£»ÀÕË÷ÍÅ»ïSynAckΪ֮ǰµÄÊܺ¦ÕßÃâ·ÑÌṩ½âÃÜÃÜÔ¿ άËûÃü άËûÃü°²È« ½ñÌì

°ä²¼¹¦·ò 2021-08-13

1.Print Spooler´æÔÚ佨¸´RCE£¬£¬£¬£¬£¬£¬£¬£¬Î¢Èí³Ðŵ¾¡¿ì½¨¸´


1.jpg


ÔÚ°ä²¼8Ô·ÝÖܶþ°²È«¸üеĵڶþÌ죬£¬£¬£¬£¬£¬£¬£¬Î¢ÈíÈ·ÈÏÁËWindows Print Spooler×é¼þÖдæÔÚµÄÁíÒ»¸ö佨¸´µÄÔ¶³Ì´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬£¬£¬£¬²¢°µÊ¾ËüÔÚÖÂÁ¦½¨¸´¸Ã·ì϶¡£¡£¡£¡£¡£¸Ã·ì϶¸ú×ÙΪCVE-2021-36958£¬£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ7.3£¬£¬£¬£¬£¬£¬£¬£¬ÊôÓÚ·ì϶PrintNightmareµÄÒ»²¿ÃÅ£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÓÃÀ´½«DelpyµÄDLL¸´Ôìµ½¿Í»§¶ËÖ´ÐÐÀ´´ò¿ªÏµÍ³µÄºÅÁîÌáÐÑ·û¡£¡£¡£¡£¡£Ä¿Ç°Î¢ÈíÉÐδ°ä²¼Õë¶Ô´Ë·ì϶µÄ°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬Óû§Äܹ»Í¨¹ý½ûÓÃPrint SpoolerÀ´»º½â´ËÀ๥»÷¡£¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/08/microsoft-security-bulletin-warns-of.html


2.SAP°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´Æä²úÆ·ÖеĶà¸ö°²È«·ì϶


2.jpg


SAPÓÚ8ÔÂ10ÈÕ°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´Æä²úÆ·ÖеĶà¸ö°²È«·ì϶¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ½ÏΪÑϳÁµÄÊÇSAP Business OneÖеÄÎÞÏÞ¶ÈÎļþÉÏ´«·ì϶£¨CVE-2021-33698£©£¬£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.9£»£»£»£»£»£»£»£»SAP NetWeaver¿ª·¢»ù´¡¼Ü¹¹ÖеķþÎñÆ÷¶ËÒªÇóαÔì·ì϶£¨CVE-2021-33690£©£¬£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.9£»£»£»£»£»£»£»£»ÒÔ¼°SAP NZDTÖеÄSQL×¢Èë·ì϶£¨CVE-2021-33701£©£¬£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.1¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬»¹½¨¸´ÁË¿çÕ¾¾ç±¾·ì϶£¨CVE-2021-33702ºÍCVE-2021-33703£©µÈ·ì϶¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/sap-patches-critical-bugs/168558/


3.ÐÂ¼ÓÆÂµçÐŹ«Ë¾StarHub³ÆÆä³¬¹ý5.7ÍòÓû§ÐÅϢй©


ÐÂ¼ÓÆÂµçÐŹ«Ë¾StarHub³ÆÆä³¬¹ý5.7ÍòÓû§ÐÅϢй©.png


ÐÂ¼ÓÆÂµÚ¶þ´óµçÐÅÔËÓªÉÌStarHubÓÚ8ÔÂ11ÈÕ·¢ËÍÓʼþ³ÆÆä³¬¹ý5.7ÍòÓû§ÐÅϢй©¡£¡£¡£¡£¡£ÓʼþÖÐд·£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÓÚ±¾ÔÂÔçЩʱ³½ÔÚµÚÈý·½Êý¾Ýת´¢ÍøÕ¾ÉÏ·¢ÏÖÁËÒ»¸ö·¸·¨ÉÏ´«µÄÎļþ£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬2007Äê֮ǰÆä¿Í»§¶©ÔÄStarHubµÄÓйØÐÅÏ¢¡£¡£¡£¡£¡£StarHubÐû³Æ¿Í»§µÄÐÅÓþ¿¨ºÍÒøÐÐÐÅϢûÓÐй¶£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒËûÃǽ«ÎªËùÓÐÊÜÓ°ÏìµÄ¿Í»§ÌṩÁù¸öÔµÄÃâ·ÑÐÅÓþ¼à¿Ø¡£¡£¡£¡£¡£The Register°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬Õâ´Îй¶ÊÂÎñÓÚ7ÔÂ6ÈÕ·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬µ«Ö±µ½8ÔÂ6ÈղŰ䲼³öÀ´¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.theregister.com/2021/08/12/singapore_telecom_breach_leaked_personal/


4.ReindeerÒò´æ´¢Í°ÅäÖÃÃýÎóй¶³¬¹ý30ÍòÓû§µÄÐÅÏ¢


4.jpg


WizCase×êÑÐÈËÔ±·¢ÏÖReindeerÒòS3´æ´¢Í°ÅäÖÃÃýÎóй¶ÁËÔ¼360009¸öÓû§µÄÐÅÏ¢¡£¡£¡£¡£¡£ReindeerÊÇÒ»¼ÒÃÀ¹úÓªÏú¹«Ë¾£¬£¬£¬£¬£¬£¬£¬£¬Ö®Ç°ÓëTiffany&Co.¡¢Patr¨°n TequilaµÈ¹«Ë¾ºÏ×÷¹ý¡£¡£¡£¡£¡£Õâ´Îй¶µÄÊý¾ÝÄܹ»×·Òäµ½2007Äê5ÔÂÖÁ2012Äê2Ô£¬£¬£¬£¬£¬£¬£¬£¬Ô¼ÄªÓÐ50000¸öÎļþºÍ×ܹ²32GBµÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬¿Í»§ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µç×ÓÓʼþ¡¢Facebook ID ºÍÃÜÂë¡¢µç»°ºÅÂë¡¢µØÖ·µÈÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁË35¸ö¹ú¶È»òµØÓòµÄÓû§¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/reindeer-suffers-massive-data-breach-affecting-300-000-users-533740.shtml


5.¶ñÒâÈí¼þAdLoadµÄбäÖÖ¿ÉÈÆ¹ýAppleµÄXProtect


5.jpg


°²È«¹«Ë¾SentinelOne·¢ÏÖ¶ñÒâÈí¼þAdLoadµÄбäÖÖ¿ÉÈÆ¹ýAppleÄÚÖð²È«½ÚÔìXProtect¡£¡£¡£¡£¡£AdLoadÊÇÒ»ÖÖÕë¶ÔmacOSƽ̨µÄľÂí£¬£¬£¬£¬£¬£¬£¬£¬×Ô2017ËêĺÒÔÀ´»îÔ¾£¬£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ×°Öø÷Ààpayload£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬¸æ°×Èí¼þºÍPUAs¡£¡£¡£¡£¡£Õâ´Î´ó¹æÄ£µÄ³ÖÐø¹¥»÷×îÔçÓÚ2020Äê11ÔÂÆðÍ·£¬£¬£¬£¬£¬£¬£¬£¬²¢ÓÚ2021Äê7ÔºÍ8Ô³õÔö³¤¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬XProtectÓÐԼĪ11¸ö·ÖÆçµÄAdLoadÊðÃû£¬£¬£¬£¬£¬£¬£¬£¬µ«ÊÇËüÆëȫûÓмì²âµ½Õâ´ÎµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://labs.sentinelone.com/massive-new-adload-campaign-goes-entirely-undetected-by-apples-xprotect/


6.ÀÕË÷ÍÅ»ïSynAckΪ֮ǰµÄÊܺ¦ÕßÃâ·ÑÌṩ½âÃÜÃÜÔ¿


6.jpg


ÀÕË÷ÍÅ»ïEl_Cometa£¨Ç°ÉíΪSynAck£©ÔÚ8ÔÂ12ÈÕΪ2017Äê7ÔÂÖÁ2021ËêÊ×±»Ï°È¾µÄÊܺ¦ÕßÌṩÖ÷½âÃÜÃÜÔ¿¡£¡£¡£¡£¡£SynAckÓÚ2017Äê7Ô³õ´Î±»·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬Êǵ±½ñÈÔÔÚÔËÐеÄ×î¹ÅÀϵÄÀÕË÷Èí¼þÍÅ»ïÖ®Ò»£¬£¬£¬£¬£¬£¬£¬£¬Ëû°ä²¼µÄÃÜÔ¿Òѱ»°²È«¹«Ë¾EmsisoftÑéÖ¤ÎªÕæÊµµÄ¡£¡£¡£¡£¡£SynAck°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬ËûÃǾö¶¨ÎªÊܺ¦Õß°ä²¼Ö÷½âÃÜÃÜÔ¿£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚËûÃÇ´Ë¿ÌÒѾ­ÊµÏÖÁ˾ɵÄSynAckʱÆÚ£¬£¬£¬£¬£¬£¬£¬£¬²¢×¨Ò»ÓÚÉϸöÔÂÆô¶¯µÄEl_CometaÐÂÏîÄ¿¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://therecord.media/synack-ransomware-gang-releases-decryption-keys-for-old-victims/