ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ18ÖÜ
°ä²¼¹¦·ò 2021-05-06> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2021Äê04ÔÂ26ÈÕÖÁ05ÔÂ02ÈÕ¹²ÊÕ¼°²È«·ì϶66¸ö£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApple macOS Big Sur WebKit CVE-2021-1817ÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶£»£»£»£»£»Google Chrome ANGLE¶ÑÒç³ö´úÂëÖ´Ðзì϶£»£»£»£»£»Cisco Adaptive Security Appliances Software CVE-2021-1504»º³åÇøÒç¶Âí½Å£»£»£»£»£»PHP FilteredIterator·´ÐòÁл¯´úÂëÖ´Ðзì϶£»£»£»£»£»Vivotek VIVOTEK IP Camera OSºÅÁî×¢Èë·ì϶¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǺڿÍÔÚ°µÍø¹«¿ªÓ¡¶ÈBigBasketÔ¼2000Íò¸öÓû§µÄÐÅÏ¢£»£»£»£»£»FacebookÅû¶½üÆÚ2¸ö°ÍÀÕ˹̹ºÚ¿ÍÍÅ»ïµÄ¼äµý»î¶¯£»£»£»£»£»µÂ¹úÁª¹ú¾¯Ô±¾Ö³ÁÖÃEmotet£¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ½«×Ô¶¯Ð¶ÔØ£»£»£»£»£»Apple°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´macOSÖб»ShlayerÀûÓõÄ0day£»£»£»£»£»AzureÔÆÕÊ»§ÒòÅäÖÃÃýÎóй¶΢Èí¶à¿î²úÆ·µÄÔ´´úÂë¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£
> ³ÁÒª°²È«·ì϶Áбí
1.Apple macOS Big Sur WebKit CVE-2021-1817ÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶
Apple macOS Big Sur WebKit´æÔÚÄÚ´æ·ÛËé·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇ󣬣¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
https://support.apple.com/zh-cn/HT212325
2.Google Chrome ANGLE¶ÑÒç³ö´úÂëÖ´Ðзì϶
Google Chrome ANGLE´æÔÚ¶ÑÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇ󣬣¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_26.html
3.Cisco Adaptive Security Appliances Software CVE-2021-1504»º³åÇøÒç¶Âí½Å
Cisco Adaptive Security Appliances Software HTTPSÒªÇó´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿É½øÐлؾø·þÎñ¹¥»÷¡£¡£¡£¡£¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-vpn-dos-fpBcpEcD
4.PHP FilteredIterator·´ÐòÁл¯´úÂëÖ´Ðзì϶
PHP FilteredIterator´æÔÚ·´ÐòÁл¯·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
https://github.com/WordPress/Requests/security/advisories/GHSA-52qp-jpq7-6c54
5.Vivotek VIVOTEK IP Camera OSºÅÁî×¢Èë·ì϶
Vivotek VIVOTEK IP Camera NTP Server configuration´¦ÖòÎÊý´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâOSºÅÁî¡£¡£¡£¡£¡£
https://www.meritlilin.com/assets/uploads/support/file/M00166-TW.pdf
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢ºÚ¿ÍÔÚ°µÍø¹«¿ªÓ¡¶ÈBigBasketÔ¼2000Íò¸öÓû§µÄÐÅÏ¢

BigBasketÊÇÓ¡¶ÈµÄÔÚÏßÔÓ»õÅäËÍ·þÎñ£¬£¬£¬£¬£¬£¬£¬¿ÉÔÚÓû§ÔÚÏ߲ɰìÎïÆ·Ö®ºó½«ÆäÔËË͵½¼ÒÖС£¡£¡£¡£¡£4ÔÂ25ÈÕÔ糿£¬£¬£¬£¬£¬£¬£¬³ÛÃûй¶Êý¾ÝÂô¼ÒShinyHunterÔÚ°µÍøÉϰ䲼ÁËÒ»¸ö¾Ý³ÆÊÇ´ÓBigBasketµÁÈ¡µÄÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÓг¬¹ý2000Íò¸öÓû§µÄ¼Í¼£¬£¬£¬£¬£¬£¬£¬Ô̺¬µç×ÓÓʼþµØÖ·¡¢SHA1¹þÏ£ÃÜÂë¡¢µØÖ·¡¢µç»°ºÅÂëºÍÆäËûÀàÐ͵ÄÐÅÏ¢µÈ¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬¸ÃºÚ¿Í³ÆÆäÒѾʹÓÃSHA1Ëã·¨ÆÆ½âÁË200Íò¸öÃÜÂ룬£¬£¬£¬£¬£¬£¬ÆäÖÐ70ÍòÃû¿Í»§Ê¹ÓÃÁË¡°password¡±×÷ΪÃÜÂë¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hacker-leaks-20-million-alleged-bigbasket-user-records-for-free/
2¡¢FacebookÅû¶½üÆÚ2¸ö°ÍÀÕ˹̹ºÚ¿ÍÍÅ»ïµÄ¼äµý»î¶¯

Facebook½üÆÚ·¢ÏÖÁË2¸ö±ðÀëÔÚ2019ÄêºÍ2020ÄêÆðÍ·»îÔ¾µÄ°ÍÀÕ˹̹ºÚ¿ÍÍÅ»ïµÄ¼äµý»î¶¯¡£¡£¡£¡£¡£ÕâÁ½¸ö×éÖ¯Ö®¼äËÆºõûÓÐÁªÏµ£¬£¬£¬£¬£¬£¬£¬µ«ËüÃǵÄÖ÷ÕÅËÆºõÏà·´¡£¡£¡£¡£¡£ËûÃǾùÀûÓÃÁËiOS¼äµýÈí¼þ£¬£¬£¬£¬£¬£¬£¬²¢ÒÔFacebookµÈÉ罻ýÌåÆ½Ì¨ÎªÆðµã£¬£¬£¬£¬£¬£¬£¬ÓëÖ¸±ê³ÉÁ¢ÁªÏµ²¢ÌáÒéÉç»á¹¤³Ì¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÓÕʹËûÃǽøÈë´¹µöÒ³ÃæºÍÆäËû¶ñÒâÍøÕ¾¡£¡£¡£¡£¡£×êÑÐÈËÔ±´§¶ÈÆäÖÐÖ®Ò»Óë°ÍÀÕ˹̹°²È«»ú¹¹Óйأ¬£¬£¬£¬£¬£¬£¬ÔÚÍÁ¶úÆä¡¢ÒÁÀ¿Ë¡¢Àè°ÍÄÛºÍÀû±ÈÑÇÒ²Óй¥»÷»î¶¯¡£¡£¡£¡£¡£ÁíÒ»×éÓëArid ViperÓйأ¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶Ô·¨ËþºÕÕþµ³³ÉÔ±¡¢µ±¾Ö¹ÙÔ±¡¢°²È«¶ÓÁкÍѧÉú¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.wired.com/story/palestine-hacking-ios-custom-spyware/
3¡¢µÂ¹úÁª¹ú¾¯Ô±¾Ö³ÁÖÃEmotet£¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ½«×Ô¶¯Ð¶ÔØ

µÂ¹úÁª¹ú¾¯Ô±¾ÖBundeskriminalamt³ÁÖÃÁËEmotet£¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ½«ÔÚËùÓÐÊÜϰȾµÄϵͳÖÐ×Ô¶¯Ð¶ÔØ¡£¡£¡£¡£¡£EmotetÊǽüÆÚ×îΣÏÕµÄÀ¬»øÓʼþ½©Ê¬ÍøÂçÖ®Ò»£¬£¬£¬£¬£¬£¬£¬Æä»ù´¡ÉèÊ©ÓÚ½ñÄê1Ô·ÝÓɶà¹ú·¨Âɲ¿ÃŽáºÏµ·»Ù¡£¡£¡£¡£¡£ÔÚÕâ´ÎÐж¯ÖУ¬£¬£¬£¬£¬£¬£¬µÂ¹ú¾¯·½Õƹܿª·¢ºÍÍÆËÍÐ¶ÔØÄ£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬£¬ÆäΪÁËÍøÂçÖ¤¾ÝºÍÐÅÏ¢¶øÍƳÙÁ˸ÃÐ¶ÔØÄ£¿£¿£¿£¿£¿éµÄ°ä²¼¡£¡£¡£¡£¡£¸Ã»ú¹¹Í¨¹ýÆä½ÚÔìµÄC2·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬½«32λEmotetLoader.dll´ó¾ÖµÄÐÂEmotetÄ£¿£¿£¿£¿£¿é·Ö·¢¸øËùÓÐÊÜϰȾµÄϵͳ£¬£¬£¬£¬£¬£¬£¬Ê¹ÕâЩϵͳÔÚ2021Äê4ÔÂ25ÈÕ×Ô¶¯Ð¶ÔظöñÒâÈí¼þ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/emotet-malware-nukes-itself-today-from-all-infected-computers-worldwide/
4¡¢Apple°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´macOSÖб»ShlayerÀûÓõÄ0day

Apple°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´macOS Big Sur 11.3ÖÐÒѱ»ÀûÓõÄ0day¡£¡£¡£¡£¡£°²È«ÍŶÓJamf·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬´Ó2021Äê1ÔÂÆðÍ·¶ñÒâÈí¼þShlayerÀûÓÃÁËÒ»¸ö0day£¨CVE-2021-30657£©£¬£¬£¬£¬£¬£¬£¬À´ÈƹýAppleµÄÎļþ¸ôÀë¡¢GatekeeperºÍ¹«Ö¤°²È«²é³£¬£¬£¬£¬£¬£¬£¬²¢ÏÂÔØµÚ¶þ½×¶ÎËùʹÓõÄpayload¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬Õâ´Î¸üл¹½¨¸´ÁËiOS¡¢iPadOSºÍwatchOSÖеĶà¸ö0day£¬£¬£¬£¬£¬£¬£¬Ô̺¬WebKit StorageµÄÄÚ´æ°Ü»µ·ì϶£¨CVE-2021-30661£©¡¢Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-27930£©¡¢ÄÚºËÄÚ´æÐ¹Â¶·ì϶£¨CVE-2020-27950£©ºÍÄÚºËÌØÈ¨ÌáÉý·ì϶£¨CVE-2020-27932£©¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/apple-fixes-macos-zero-day-bug-exploited-by-shlayer-malware/
5¡¢AzureÔÆÕÊ»§ÒòÅäÖÃÃýÎóй¶΢Èí¶à¿î²úÆ·µÄÔ´´úÂë

vpnMentor×êÑÐÍŶӷ¢ÏÖÒ»¸öÅäÖÃÃýÎóµÄMicrosoft Azure BlobÔÆÕÊ»§Ð¹Â¶ÁË΢Èí¶à¿î²úÆ·µÄÔ´´úÂë¡£¡£¡£¡£¡£Ð¹Â¶Êý¾ÝµÄ×Ü´óÓ×Ϊ63GB£¬£¬£¬£¬£¬£¬£¬Ô̺¬³¬¹ý3800¸öÎļþ£¬£¬£¬£¬£¬£¬£¬Éæ¼°Éϰټҹ«Ë¾µÄÈÚ×ÊÑݽ²¸åºÍ10-15ÖÖ²úÆ·µÄÔ´´úÂ룬£¬£¬£¬£¬£¬£¬ÓÚ2021Äê1ÔÂ7ÈÕ±»·¢ÏÖ²¢ÒÑÔÚ2021Äê2ÔÂ23Èյõ½±£»£»£»£»£»¤¡£¡£¡£¡£¡£ÕâЩÎļþΪ¶à¶à¹«Ë¾ÏòMicrosoft Dynamics×ö³öµÄһϵÁÐóÒ×Ðû´«ºÍ²úÆ·×¢Ã÷£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜÀ´×Ô΢Èí¹«Ë¾¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.vpnmentor.com/blog/report-microsoft-dynamics-leak/


¾©¹«Íø°²±¸11010802024551ºÅ