Google 5ÔÂAndroidÄþ¾²Í¨¸æÖÐÓÐ4¸ö0day±»ÔÚÒ°ÀûÓã»ÃÀ¹úÁ½µ³³ǫ̈ÎåÏî·¨°¸ÒÔÔöÇ¿¶ÔÍøÂç¹¥»÷µÄ·ÀÓùÄÜÁ¦
Ðû²¼Ê±¼ä 2021-05-211.Google 5ÔÂAndroidÄþ¾²Í¨¸æÖÐÓÐ4¸ö0day±»ÔÚÒ°ÀûÓÃ
Google Project ZeroÍŶӳƣ¬ÆäÐû²¼µÄ5ÔÂAndroidÄþ¾²Í¨¸æÖÐÓÐ4¸ö0dayÒѱ»ÔÚÒ°ÀûÓá£Õâ4¸ö©¶´Ó°ÏìÁËQualcomm GPUºÍArm Mali GPUÇý¶¯·¨Ê½×é¼þ£¬·Ö±ðΪÊͷźóʹÓé¶´£¨CVE-2021-1905£©¡¢µØÖ·×¢Ïúʧ°ÜÇé¿ö´¦Öò»Í×£¨CVE-2021-1906£©¡¢GPUÄÚ´æ²Ù×÷²»Í×£¨CVE-2021-28663£©ºÍÌáȨ©¶´£¨CVE-2021-28664£©¡£Ñо¿ÈËÔ±½¨ÒéÓû§¾¡¿ì°²×°×îиüС£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/118089/mobile-2/android-4-zero-day-flaws.html
2.Ñо¿ÈËÔ±Åû¶¼²³ÛµÄMBUXÐÅÏ¢ÓéÀÖϵͳÖеĶà¸ö©¶´
Ñо¿ÈËÔ±Åû¶Á˼²³ÛÓû§ÌåÑ飨MBUX£©ÐÅÏ¢ÓéÀÖϵͳÖеÄ5¸ö©¶´¡£ÕâЩ©¶´·Ö±ðΪCVE-2021-23906¡¢CVE-2021-23907¡¢CVE-2021-23908¡¢CVE-2021-23909ºÍCVE-2021-23910£¬¿É±»ÓÃÀ´¿ÉÒÔÈÆ¹ý³µÁ¾µÄ·ÀµÁ±£»¤ÉõÖÁ¿ØÖƳµÁ¾£¬Èç´ò¿ªÆø·ÕµÆ»ò´ò¿ª´ò¿ªÕÚÑôÕֵȲÙ×÷¡£Ñо¿ÈËÔ±»¹·¢ÏÖÁ˶àÖÖ¹¥»÷³¡¾°£¬°üÂÞÀûÓÃä¯ÀÀÆ÷µÄJavaScriptÒýÇæ¡¢Wi-FiоƬ¡¢À¶ÑÀ¶ÑÕ»¡¢USB¹¦Ð§»òµÚÈý·½Ó¦Ó÷¨Ê½½øÐй¥»÷¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/118081/hacking/mercedes-benz-hack.html
3.ÃÀ¹úÁ½µ³³ǫ̈ÎåÏî·¨°¸ÒÔÔöÇ¿¶ÔÍøÂç¹¥»÷µÄ·ÀÓùÄÜÁ¦
ÃÀ¹úÖÚÒéÔº¹úÍÁÄþ¾²Î¯Ô±»áÓÚ±¾ÖÜһͨ¹ýÁËÎåÏî·¨°¸£¬ÒÔÔöÇ¿¶ÔÍøÂç¹¥»÷µÄ·ÀÓùÄÜÁ¦¡£ÕâЩ·¨°¸°üÂÞ£ºH.R. 2980£¬¡¶ÍøÂçÄþ¾²Â©¶´µ÷Í£·¨°¸¡·£»H.R. 3138£¬¡¶Öݺ͵ط½ÍøÂçÄþ¾²¸ïз¨°¸¡· £»H.R. 3223£¬¡¶CISAÍøÂçÑÝϰ·¨¡·£»H.R. 3243£¬¡¶¹ÜµÀÄþ¾²·¨¡·£»H.R. 3264£¬¡¶¹úÍÁÄþ¾²Òªº¦ÁìÓò·¨°¸¡·¡£ÕâЩ·¨°¸ÊǹúÍÁÄþ¾²Î¯Ô±»áÕë¶Ô×î½üµÄÍøÂç¹¥»÷¶øÌá³öµÄ£¬¾Ý±¨µÀColonial PipelineÖ§¸¶ÁË500ÍòÃÀÔªÊê½ð£¬µ«²¢Ã»ÓÐ×èÖ¹¶«±±¸÷ÖÝȼÁϵĴó¹æÄ£¶Ìȱ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/us-introduces-bills-to-secure-critical-infrastructure-from-cyber-attacks/
4.Win10×îÐÂÀÛ»ý¸üпɵ¼ÖÂTeamsµÈÓ¦ÓÃÎÞ·¨µÇ¼
Windows 10 1909 KB5003169ÀÛ»ý¸üе¼ÖÂMicrosoft 365Óû§ÎÞ·¨µÇ¼Teams¡¢OutlookºÍOneDrive¡£Óû§³ÂËߣ¬ÆäÔÚʵÑéµÇ¼ʱ»áÏÔʾ´íÎó´úÂë80080300£¬²¢·ºÆð¡°ÎÒÃÇÓöµ½ÁËÎÊÌâ¡£ÕýÔÚÖØÐÂÁ¬½Ó¡¡±µÄÌáʾ£¬ÒªÇóÓû§ÖØÐÂÆô¶¯¸Ã·¨Ê½¡£Î¢ÈíÌåÏÖ£¬´Ë´ÎÖжÏʼþÊÇÓÉÓÚ¸üÐÂÖеÄÒ»¸ö´úÂëÎÊÌâµ¼Öµģ¬Ö»Ó°ÏìÁ˲¿ÃÅÓû§£¬¿Éͨ¹ýÖØÐÂÆô¶¯Windows 10½øÐÐÐÞ¸´¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/recent-windows-10-update-blocks-microsoft-teams-outlook-logins/
5.TeamBMSÒòAWS S3´æ´¢Í°ÅäÖôíÎóй¶2Íò¶àÓû§ÐÅÏ¢
Website Planet·¢ÏÖ£¬FastTrack Reflex Recruitment£¨ÏÖΪTeamBMS£©ÒòAWS S3´æ´¢Í°ÅäÖôíÎóй¶ÁË2Íò¶àÓû§ÐÅÏ¢¡£¸Ã¹«Ë¾Ö÷Òª´Óʽ¨Öþ¹ÜÀíϵÍÂäìÓòµÄÕÐÆ¸ÊÂÇ飬ÏîÄ¿°üÂÞβ¼ÀûÇò³¡¡¢°ÂÁÖÆ¥¿ËÌåÓý³¡ºÍϣ˼ÂÞ5ºÅº½Õ¾Â¥µÈ¡£´Ë´Îй¶ÁË21000¸öÎļþ£¬°üÂÞÓû§µÄµç×ÓÓʼþµØÖ·¡¢È«Ãû¡¢ÊÖ»úºÅÂë¡¢¼Òͥסַ¡¢Éç½»ÍøÂçURL¡¢³öÉúÈÕÆÚ¡¢»¤ÕÕºÅÂëºÍÉêÇëÈËÕÕÆ¬µÈ¡£Ñо¿ÈËÔ±ÍÆ¶Ï£¬´Ë´Îй¶ÊÇÓɸù«Ë¾µÄIT·þÎñÌṩÉ̵¼Öµġ£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/recruiters-cloud-snafu-exposes/
6.PaloaltoÐû²¼2021ÄêCortex XpanseÍþв·ÖÎö³ÂËß
PaloaltoÐû²¼ÁË2021ÄêCortex XpanseÍþв·ÖÎö³ÂËß¡£¸Ã³ÂËß´Ó2021Äê1Ôµ½3Ô£¬¶ÔÈ«Çò50¼ÒÆóÒµµÄ5000Íò¸öIPµØÖ·½øÐÐÁË¼à¿ØÉ¨Ã裬ÒÔÁ˽⹥»÷ÕßÄܶà¿ìµØÊ¶±ð³ö¿É±»ÀûÓõÄϵͳ¡£Òªº¦Â©¶´µÄ¹ûÈ»Åû¶,»áÒý·¢¹¥»÷ÕߺÍIT¹ÜÀíÔ±Ö®¼äµÄ¾ºÈü£º¹¥»÷ÕßҪѰÕÒºÏÊʵÄÄ¿±ê£¬¶øITÈËÔ±Òª½øÐзçÏÕÆÀ¹ÀºÍ°²×°ÐëÒªµÄ²¹¶¡¡£³ÂËßÖ¸³ö£¬¹¥»÷Õß¿ÉÄÜÔÚ0day¹ûÈ»ºóµÄ15·ÖÖÓÄÚ¶ÔÆä½øÐÐɨÃ裬¶øÕë¶ÔMicrosoft ExchangeÖеÄ©¶´£¬¹¥»÷ÕßÐж¯µÃ¸ü¿ì£¬ÔÚ²»µ½Îå·ÖÖÓµÄʱ¼äÄÚ¼´¼ì²âµ½ÁËɨÃè¡£
ÔÎÄÁ´½Ó£º
https://start.paloaltonetworks.com/asm-report