ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ25ÖÜ

°ä²¼¹¦·ò 2021-06-21

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2021Äê06ÔÂ14ÈÕÖÁ06ÔÂ20ÈÕ¹²ÊÕ¼°²È«·ì϶55¸ö£¬£¬£¬£¬ £¬£¬ÖµµÃ¹Ø×¢µÄÊÇBandai Namco FromSoftware Dark Souls III´úÂëÖ´Ðзì϶£»£» £»£» £»£»£»Apache Chainsaw·´ÐòÁл¯´úÂëÖ´Ðзì϶£»£» £»£» £»£»£»Contiki-NG 6LoWPANʵÏÖÔ½½ç¶Á·ì϶£»£» £»£» £»£»£»QEMU SLiRPÍøÂçʵÏÖtftp_input()Ô½½ç¶Á¾Ü½Ó·þÎñ·ì϶£»£» £»£» £»£»£»SonicOS»º³åÇøÒç³ö»Ø¾ø·þÎñ·ì϶¡£¡£¡£¡£ ¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÃÀ¹úºË±øÆ÷³Ð°üÉÌSol OriensÔâREvilÀÕË÷Èí¼þ¹¥»÷£»£» £»£» £»£»£»APWG°ä²¼2021ÄêQ1ÍøÂç´¹µö»î¶¯Ì¬ÊƵķÖÎö»ã±¨£»£» £»£» £»£»£»°²È«¹«Ë¾CognyteÊý¾Ý¿âÅäÖÃÃýÎóй¶³¬¹ý50Òڱʼͼ£»£» £»£» £»£»£»Apple´¹Î£¸üУ¬£¬£¬£¬ £¬£¬½¨¸´iOSÖÐÒѱ»ÔÚÒ°ÀûÓõÄ2¸ö0day£»£» £»£» £»£»£»Ò˼ҷ¨¹ú¹«Ë¾ÓüäµýÈí¼þ·¸·¨¼à¿ØÔ±¹¤±»·£¿£¿£¿£¿£¿ £¿î120ÍòÃÀÔª¡£¡£¡£¡£ ¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬ £¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£ ¡£¡£


> ³ÁÒª°²È«·ì϶Áбí


1.Bandai Namco FromSoftware Dark Souls III´úÂëÖ´Ðзì϶


Bandai Namco FromSoftware Dark Souls III´æÔÚ°²È«·ì϶£¬£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬ £¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£ ¡£¡£

https://www.reddit.com/r/darksouls3/comments/n1235k/potential_pc_security_exploit_spreading/


2.Apache Chainsaw·´ÐòÁл¯´úÂëÖ´Ðзì϶


Apache Chainsaw´æÔÚ·´ÐòÁл¯·ì϶£¬£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬ £¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£ ¡£¡£

http://www.openwall.com/lists/oss-security/2021/06/16/1


3.Contiki-NG 6LoWPANʵÏÖÔ½½ç¶Á·ì϶


Contiki-NG 6LoWPANʵÏÖ´æÔÚÔ½½ç¶Á·ì϶£¬£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬ £¬£¬¿Éʹ·þÎñ·¨Ê½±ÀÀ£¡£¡£¡£¡£ ¡£¡£

https://github.com/contiki-ng/contiki-ng/security/advisories/GHSA-hhwj-2p59-v8p9


4.QEMU SLiRPÍøÂçʵÏÖtftp_input()Ô½½ç¶Á¾Ü½Ó·þÎñ·ì϶



QEMU SLiRPÍøÂçʵÏÖtftp_input()´æÔÚÔ½½ç¶Á·ì϶£¬£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬ £¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£¡£¡£¡£¡£ ¡£¡£

https://bugzilla.redhat.com/show_bug.cgi?id=1970489


5.SonicOS»º³åÇøÒç³ö»Ø¾ø·þÎñ·ì϶



SonicOS´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬ £¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë»òʹÀûÓ÷¨Ê½±ÀÀ£¡£¡£¡£¡£ ¡£¡£

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0016


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢ÃÀ¹úºË±øÆ÷³Ð°üÉÌSol OriensÔâREvilÀÕË÷Èí¼þ¹¥»÷


1.jpg


ÃÀ¹úºË±øÆ÷³Ð°üÉÌSol OriensÔâµ½ÁËREvilÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£ ¡£¡£¸Ã¹«Ë¾³ÆÆäÖØÒªÐ­Öú¹ú·À²¿¡¢ÄÜÔ´²¿¡¢º½¿Õº½Ìì³Ð°üÉ̺ͼ¼Êõ¹«Ë¾·¢Õ¹¸´ÔÓµÄÏîÄ¿¡£¡£¡£¡£ ¡£¡£REvilÍÅ»ïÔÚÅÄÂô¹¥»÷ÆÚ¼äÇÔÈ¡µÄÊý¾Ý£¬£¬£¬£¬ £¬£¬ÆäÖÐÔ̺¬ÒµÎñÊý¾ÝºÍÔ±¹¤ÐÅÏ¢£¬£¬£¬£¬ £¬£¬ÀýÈçÔ±¹¤Éç»á°²È«ºÅÂë¡¢ÕÐÆ¸¸ÅÀÀÎļþ¡¢¹¤×ʵ¥ÎļþºÍ¹¤×ʻ㱨µÈ¡£¡£¡£¡£ ¡£¡£Sols OriensҲ֤ʵÁËÆäÔÚ2021Äê5ÔÂÔâµ½ÁËÍøÂç¹¥»÷£¬£¬£¬£¬ £¬£¬¿ÉÄÜÒѾ­Ð¹Â¶²¿ÃÅÊý¾Ý£¬£¬£¬£¬ £¬£¬Ä¿Ç°µ÷²éÈÔÔÚ½øÐÐÖÓ×£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/revil-ransomware-hits-us-nuclear-weapons-contractor/


2¡¢APWG°ä²¼2021ÄêQ1ÍøÂç´¹µö»î¶¯Ì¬ÊƵķÖÎö»ã±¨


2.jpg


APWG°ä²¼ÁË2021ÄêQ1ÍøÂç´¹µö»î¶¯Ì¬ÊƵķÖÎö»ã±¨¡£¡£¡£¡£ ¡£¡£»ã±¨ÏÔʾ£¬£¬£¬£¬ £¬£¬ÍøÂç´¹µöÍøÕ¾ÊýÁ¿ÔÚ2021Äê1Ô´ﵽ·åÖµ£¬£¬£¬£¬ £¬£¬´´ÏÂÁË245771¸öµÄº¹Çàиߣ¬£¬£¬£¬ £¬£¬¶øºóÔÚ±¾¼¾¶ÈµÄºóÆÚÆðÍ·½µÂä¡£¡£¡£¡£ ¡£¡£Ã³Ò×µç×ÓÓʼþ(BEC)Ú¿Æ­µÄ³É±¾Ô½À´Ô½¸ß£¬£¬£¬£¬ £¬£¬´Ó2020ÄêQ3µÄ48000ÃÀÔªÔö³¤µ½ÁË2021ÄêQ1µÄ85000ÃÀÔª¡£¡£¡£¡£ ¡£¡£Õë¶Ô½ðÈÚ»ú¹¹µÄÍøÂç´¹µöÊÇQ1Õ¼±È×î´óµÄÀàÐÍ£¬£¬£¬£¬ £¬£¬Õ¼ËùÓй¥»÷µÄ24.9%¡£¡£¡£¡£ ¡£¡£´Ë±í£¬£¬£¬£¬ £¬£¬Õë¶ÔÉ罻ýÌåÐÐÒµµÄÍøÂç´¹µöÔÚËùÓй¥»÷ÖÐËùÕ¼±ÈÀý´Ó2020ÄêQ4µÄ11.8%¼¤ÔöÖÁ23.6%¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.prnewswire.com/news-releases/apwg-q1-2021-report-detected-phishing-websites-maintain-historic-high-in-q1-2021-after-doubling-in-2020-301309187.html


3¡¢°²È«¹«Ë¾CognyteÊý¾Ý¿âÅäÖÃÃýÎóй¶³¬¹ý50Òڱʼͼ


3.jpg


Comparitech°²È«×êÑÐÈËÔ±·¢ÏÖÁËÍøÂ簲ȫ·ÖÎö¹«Ë¾CognyteδÊܱ£»£» £»£» £»£»£»¤µÄÊý¾Ý¿â¡£¡£¡£¡£ ¡£¡£¸ÃÊý¾Ý¿â×÷ΪCognyteÍøÂçµý±¨·þÎñµÄÒ»²¿ÃÅ£¬£¬£¬£¬ £¬£¬ÓÃÓÚÌáÐÑÆä¿Í»§µÚÈý·½µÄÊý¾Ýй¶¡£¡£¡£¡£ ¡£¡£ÓµÓг°·íÒâζµÄÊÇ£¬£¬£¬£¬ £¬£¬ÓÃÓÚ½»²æ²é³­Ð¹Â¶µÄÓ×ÎÒÐÅÏ¢µÄÊý¾Ý¿â×ÔÉíÒÑй¶¡£¡£¡£¡£ ¡£¡£¸ÃÊý¾Ý¿â×ܹ²ÓÐ5085132102±Ê¼Í¼£¬£¬£¬£¬ £¬£¬Ô̺¬Ãû³Æ¡¢µç×ÓÓʼþµØÖ·¡¢ÃÜÂëºÍÊý¾ÝÔ´£¬£¬£¬£¬ £¬£¬ÓÚ2021Äê5ÔÂ29ÈÕ±»·¢ÏÖ£¬£¬£¬£¬ £¬£¬ºóÓÚ6ÔÂ2ÈÕ±»±£»£» £»£» £»£»£»¤ÆðÀ´¡£¡£¡£¡£ ¡£¡£Ä¿Ç°£¬£¬£¬£¬ £¬£¬Éв»È·¶¨ÕâЩÊý¾ÝÔÚ¶³öÆÚ¼äÊÇ·ñÓб»ÈκεÚÈý·½½Ó¼û¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.comparitech.com/blog/information-security/breach-database-leak/


4¡¢Apple´¹Î£¸üУ¬£¬£¬£¬ £¬£¬½¨¸´iOSÖÐÒѱ»ÔÚÒ°ÀûÓõÄ2¸ö0day


4.jpg


Apple°ä²¼´¹Î£¸üУ¬£¬£¬£¬ £¬£¬½¨¸´iOS 12.5.3ÖÐÒѱ»ÔÚÒ°ÀûÓõÄ2¸ö0day¡£¡£¡£¡£ ¡£¡£ÕâÁ½¸ö0dayΪWebKitä¯ÀÀÆ÷ÒýÇæÖеÄÄÚ´æ°Ü»µ·ì϶£¨CVE-2021-30761£©ºÍ¿ªÊͺóʹÓ÷ì϶£¨CVE-2021-30762£©£¬£¬£¬£¬ £¬£¬¾ù¿É±»ÓÃÀ´Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£ ¡£¡£Apple°µÊ¾¸Ã·ì϶¿ÉÄÜÒѱ»»ý¼«ÀûÓ㬣¬£¬£¬ £¬£¬µ«²¢Î´Ð¹Â©ÈκÎÓйشËÀ๥»÷µÄ¾ßÌåÐÅÏ¢¡£¡£¡£¡£ ¡£¡£´Ë±í£¬£¬£¬£¬ £¬£¬Õâ´Î¸üл¹½¨¸´ÁËASN.1½âÂëÆ÷ÖеÄÄÚ´æ°Ü»µ·ì϶(CVE-2021-30737)¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/06/apple-issues-urgent-patches-for-2-zero.html


5¡¢Ò˼ҷ¨¹ú¹«Ë¾ÓüäµýÈí¼þ·¸·¨¼à¿ØÔ±¹¤±»·£¿£¿£¿£¿£¿ £¿î120ÍòÃÀÔª


5.jpg


Èðµä¼Ò¾ß¼¯ÍÅÒ˼ҷ¨¹ú·Ö¹«Ë¾ÒòʹÓüäµýÈí¼þ·¸·¨¼à¿ØÔ±¹¤±»·£¿£¿£¿£¿£¿ £¿î120ÍòÃÀÔª¡£¡£¡£¡£ ¡£¡£¸ÃÊÂÎñ²úÉúÔÚ2009ÄêÖÁ2012Äê¼ä£¬£¬£¬£¬ £¬£¬Ò˼ҷ¨¹ú¹«Ë¾¿ª·¢ÁËÒ»¸ö¼äµýϵͳÀ´¼à¿ØÔ±¹¤ºÍÌá³ö¾À·×µÄ¿Í»§¡£¡£¡£¡£ ¡£¡£¸ÃϵͳΪ¹«Ë¾1996ÄêÖÁ2002ÄêµÄÕÆ¹ÜÈËJean-Louis Baillot³ÉÁ¢µÄ£¬£¬£¬£¬ £¬£¬Æä±»´¦ÒÔÁ½Ä껺Ð̺Í60630ÃÀÔª·£¿£¿£¿£¿£¿ £¿î¡£¡£¡£¡£ ¡£¡£¼ì²ì¹Ù°µÊ¾£¬£¬£¬£¬ £¬£¬Ò˼ҷ¨¹ú¹«Ë¾ÀûÓþ¯·½ÐÂÎÅÆðÔ´£¬£¬£¬£¬ £¬£¬ÀñƸÁËÒ»¼Ò¸öÈ˱£°²¹«Ë¾ºÍ¸öÈËÕì̽·¸·¨»ñÈ¡ÆäÔ±¹¤µÄ»úÃÜÐÅÏ¢¡£¡£¡£¡£ ¡£¡£¸ÃÐÌʵ÷²éÓÚ2012ÄêÆô¶¯£¬£¬£¬£¬ £¬£¬Ö±µ½±¾Öܶþ²ÅºÅÁî·£¿£¿£¿£¿£¿ £¿î¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/ikea-fined-12m-for-spying-on/