°ÍÎ÷³ÆÆä²ÆÕþ²¿ÃØÊé´¦µÄÄÚ²¿ÍøÂçÔâµ½ÀÕË÷Èí¼þ¹¥»÷:Fortinet FortiWeb WAF´æÔÚ佨¸´µÄºÅÁî×¢Èë0day

°ä²¼¹¦·ò 2021-08-23

°ÍÎ÷³ÆÆä²ÆÕþ²¿ÃØÊé´¦µÄÄÚ²¿ÍøÂçÔâµ½ÀÕË÷Èí¼þ¹¥»÷


°ÍÎ÷³ÆÆä²ÆÕþ²¿ÃØÊé´¦µÄÄÚ²¿ÍøÂçÔâµ½ÀÕË÷Èí¼þ¹¥»÷.jpg


°ÍÎ÷µ±¾ÖÔÚÉÏÖÜÁùÍí¼äй©£¬£¬ £¬£¬£¬£¬£¬Æä²ÆÕþ²¿ÃØÊé´¦µÄÄÚ²¿ÍøÂçÔÚÖÜÎåÍíÉÏ£¨8ÔÂ13ÈÕ£©Ôâµ½ÁËÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£ ¡£¡£¡£°ÍÎ÷¾­¼Ã²¿°ä²¼ÉêÃ÷³Æ£¬£¬ £¬£¬£¬£¬£¬¾­¹ý³õ²½ÆÀ¹ÀÈ·¶¨¹ú¿âµÄϵͳ²¢Î´Êܵ½Ó°Ïì¡£¡£¡£ ¡£¡£¡£8ÔÂ16ÈÕ£¬£¬ £¬£¬£¬£¬£¬°ÍÎ÷µ±¾ÖÓë°ÍÎ÷֤ȯÂòÂôËù¾Í¸ÃÊÂÎñ°ä·¢Á˽áºÏÉêÃ÷£¬£¬ £¬£¬£¬£¬£¬³Æ¾ÓÃñ²É°ì°ÍÎ÷µ±¾ÖծȯµÄTesouro Diretoƽ̨ҲδÊܵ½Ó°Ïì¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/brazilian-government-discloses-national-treasury-ransomware-attack/



Cisco·¢ÏÖÕë¶ÔÄ«Î÷¸ç½ðÈÚ»ú¹¹µÄÐÂľÂíNeurevt


Cisco·¢ÏÖÕë¶ÔÄ«Î÷¸ç½ðÈÚ»ú¹¹µÄÐÂľÂíNeurevt.png


Cisco TalosÓÚ2021Äê6Ô¼ì²âµ½ÐÂNeurevtľÂí¡£¡£¡£ ¡£¡£¡£¸Ã¶ñÒâÈí¼þ½«ºóÃźÍÐÅÏ¢ÇÔÈ¡·¨Ê½½áºÏÔÚһ·£¬£¬ £¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÄ«Î÷¸ç½ðÈÚ»ú¹¹µÄÓû§¡£¡£¡£ ¡£¡£¡£¹¥»÷ÕßÒ»µ©³É¹¦Ï°È¾Ö¸±êÉ豸£¬£¬ £¬£¬£¬£¬£¬¾ÍÄܹ»½Ó¼ûÖ¸±êϵͳ²¢Åú¸ÄËûÃǵÄÉèÖÃÒÔ°µ²Ø×Ô¼º¡£¡£¡£ ¡£¡£¡£¸ÃľÂíÄܹ»Í¨¹ý½Ó¼ûÊܺ¦ÕßµÄϵͳ·þÎñÁîÅÆÀ´ÌáȨ£¬£¬ £¬£¬£¬£¬£¬´Ó¶ø½Ó¼û²Ù×÷ϵͳ¡¢Óû§ÕÊ»§ÐÅÏ¢¡¢ÒøÐÐÍøÕ¾Í´´¦¡¢½ØÈ¡ÆÁÄ»½ØÍ¼²¢·¢Ë͵½C2·þÎñÆ÷ÒÔÇÔȡָ±êµÄÐÅÏ¢¡£¡£¡£ ¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2021/08/neurevt-trojan-takes-aim-at-mexican.html



×êÑÐÍŶӷ¢ÏÖÕë¶ÔÈÕ±¾ÐÄÔÚ·Ö·¢CinobiµÄ¶ñÒâ¸æ°×»î¶¯


×êÑÐÍŶӷ¢ÏÖÕë¶ÔÈÕ±¾ÐÄÔÚ·Ö·¢CinobiµÄ¶ñÒâ¸æ°×»î¶¯2.jpg


Ç÷Ïò¿Æ¼¼×êÑÐÍŶÓÓÚÉÏÖܰ䲼ÁËÒ»Ïî·ÖÎö£¬£¬ £¬£¬£¬£¬£¬½ÒʾÁ˺ڿÍÍÅ»ïWater KappaÕë¶ÔÈÕ±¾µÄ¶ñÒâ¸æ°×»î¶¯¡£¡£¡£ ¡£¡£¡£¹¥»÷ÕßÊ×ÏÈʹÓÃÈÕ±¾¶¯»­ÓÎÏ·¡¢¼Î½±»ý·ÖÀûÓúÍÊÓÆµÁ÷·þÎñ·Ö·¢¶ñÒâ¸æ°×£¬£¬ £¬£¬£¬£¬£¬×îÖÕ×°ÖÃÒøÐÐľÂíCinobi¡£¡£¡£ ¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖÕâ´Î»î¶¯ÖØÒªÕë¶ÔʹÓÃInternet ExplorerÒÔ±íµÄä¯ÀÀÆ÷µÄÈÕ±¾Óû§£¬£¬ £¬£¬£¬£¬£¬²¢ÖØÒªÇÔÈ¡ÈÕ±¾µÄ11¼Ò½ðÈÚ»ú¹¹µÄÓû§ÃûºÍÃÜÂ룬£¬ £¬£¬£¬£¬£¬ÆäÖÐ3¼ÒÉæ¼°¼ÓÃÜÇ®±ÒÂòÂô¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.trendmicro.com/en_in/research/21/h/cinobi-banking-trojan-targets-users-of-cryptocurrency-exchanges-.html


ClearSky·¢ÏÖSiamesekittenÕë¶ÔÒÔÉ«Áеļäµý»î¶¯


ClearSky·¢ÏÖSiamesekittenÕë¶ÔÒÔÉ«Áеļäµý»î¶¯.png


ClearSkyµÄ×êÑÐÈËÔ±ÔÚ8ÔÂ17ÈÕÅû¶ÁËÒÁÀÊAPT×éÖ¯SiamesekittenÕë¶ÔÒÔÉ«Áеļäµý»î¶¯¡£¡£¡£ ¡£¡£¡£ClearSkyÓÚ2021Äê5Ô³õ¼ì²âµ½¸ÃÍÅ»ïÕë¶ÔÒÔÉ«ÁеÄÒ»¼ÒIT¹«Ë¾µÄµÚÒ»´Î¹¥»÷£¬£¬ £¬£¬£¬£¬£¬²¢ÔÚ5ÔºÍ7ÔÂÓÖ¼ì²âµ½ÁËÂŴι¥»÷¡£¡£¡£ ¡£¡£¡£ÔÚÕâ´Î»î¶¯ÖУ¬£¬ £¬£¬£¬£¬£¬ºÚ¿Í¼Ù×°³ÉChipPcºÍSoftware AGµÈ³ÛÃû¹«Ë¾µÄÈËÁ¦×ÊÔ´²¿Ô±¹¤£¬£¬ £¬£¬£¬£¬£¬ÒÔÓÕÈ˵ÄְλÓÕʹָ±ê½øÈë´¹µöÍøÒ³ÏÂÔØÔ¶³Ì½Ó¼ûľÂíDanBot¡£¡£¡£ ¡£¡£¡£ÓÉÓÚÕâ´Î¹¥»÷ÖØÒªÕë¶ÔITºÍͨѶ¹«Ë¾£¬£¬ £¬£¬£¬£¬£¬Òò¶øClearSky´§Ä¦ºÚ¿Í¿ÉÄÜÖ¼ÔÚ¶ÔËûÃǵĿͻ§ÌáÒ鹩¸øÁ´¹¥»÷¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.clearskysec.com/siamesekitten/


Fortinet FortiWeb WAF´æÔÚ佨¸´µÄºÅÁî×¢Èë0day


Fortinet FortiWeb WAF´æÔÚ佨¸´µÄºÅÁî×¢Èë0day.jpg


Fortinet FortiWeb WebÀûÓ÷¨Ê½·À»ðǽ(WAF)´æÔÚºÅÁî×¢Èë0day£¬£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓø÷ì϶Äܹ»Í¨¹ýSAML·þÎñÆ÷ÅäÖÃÒ³ÃæÒÔrootÓû§Éí·ÝÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£ ¡£¡£¡£¹ÌÈ»¹¥»÷Õß±ØÐëͨ¹ýÁËÖ¸±êÉ豸ÖÎÀí½çÃæµÄÉí·ÝÑéÖ¤ÄÜÁ¦ÀûÓô˷ì϶£¬£¬ £¬£¬£¬£¬£¬µ«ÈôÊÇÓëÆäËû·ì϶£¨ÀýÈçÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶CVE-2020-29015£©½áºÏʹÓ㬣¬ £¬£¬£¬£¬£¬Äܹ»ÆëÈ«½ÚÔìÖ¸±ê·þÎñÆ÷¡£¡£¡£ ¡£¡£¡£FortinetÒѽ«¸Ã·ì϶µÄ½¨¸´´òËãÍÆ³Ùµ½8Ôµף¬£¬ £¬£¬£¬£¬£¬×êÑÐÈËÔ±½¨Ò齨ÒéÖÎÀíÔ±²»ÈÝ´Ó²»ÊÜÐÅÀµµÄÍøÂç½Ó¼ûFortiWebÉ豸µÄÖÎÀí½çÃæÒÔÔ¤·À´ËÀ๥»÷¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/121221/security/fortinet-fortiweb-os-command-injection.html


Adobe°ä²¼°²È«¸üУ¬£¬ £¬£¬£¬£¬£¬½¨¸´Æä¶à¿î²úÆ·Öеݲȫ·ì϶


Adobe°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´Æä¶à¿î²úÆ·Öеݲȫ·ì϶.jpg


AdobeÓÚ8ÔÂ17ÈÕ°ä²¼°²È«¸üУ¬£¬ £¬£¬£¬£¬£¬½¨¸´ÁËAdobe Captivate¡¢XMP Toolkit SDK¡¢Photoshop¡¢BridgeºÍMedia EncoderÖеĶà¸ö°²È«·ì϶¡£¡£¡£ ¡£¡£¡£ÆäÖнÏΪÑϳÁµÄÊÇAdobe XMP Toolkit SDKÖеÄËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-36052ºÍCVE-2021-36064£©¡¢PhotoshopÖеÄËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-36065ºÍCVE-2021-36066£©£¬£¬ £¬£¬£¬£¬£¬ÒÔ¼°Adobe BridgeÖеÄËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-36078µÈ£©µÈ·ì϶¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/08/18/adobe-releases-multiple-security-updates