AppleÒÑÐÞ¸´ÆäAWDLÖпÉÈƹýÆø϶ϵͳÇÔÈ¡ÐÅÏ¢µÄ©¶´£»Ñо¿ÈËÔ±·¢ÏÖÀûÓÃExchangeÖЩ¶´ProxyShellµÄ¹¥»÷»î¶¯

Ðû²¼Ê±¼ä 2021-08-09
1.AppleÒÑÐÞ¸´ÆäAWDLÖпÉÈƹýÆø϶ϵͳÇÔÈ¡ÐÅÏ¢µÄ©¶´


1.jpg


AppleµÄApple Wireless Direct Link(AWDL)ÖдæÔÚÒ»¸ö©¶´ £¬¿ÉÓÃÀ´ÈƹýÆø϶ϵͳ²¢ÇÔÈ¡Êý¾Ý¡£Õâ¸ö©¶´µÄ¼¼ÊõÅä¾°ÓеãÅÓ´ó £¬¼òÑÔÖ® £¬¾ÍÊÇʹÓÃICMPv6ºÍIPv6Êý¾Ý°ü´ÓÄ¿±êϵͳ»ñÈ¡Êý¾Ý £¬ÔÚËÄÖÜÖ§³ÖAWDLµÄAppleÉ豸ÉÏ·´µ¯Êý¾Ý°ü £¬²¢½«ÇÔÈ¡µÄÎļþ·¢Ë͵½ÁíÒ»¸öÓÐIPv6µØÖ·µÄÉ豸¡£Äþ¾²¹«Ë¾FnishÑо¿ÈËÔ±ÓÚÉÏÖÜÊ״ιûÈ»Á˸鶴 £¬¶øApple¹«Ë¾ÔçÔÚ½ñÄê4Ô £¬¾ÍÔÚiOS 14.5¡¢iPadOS 14.5¡¢watchOS 7.4ºÍBig Sur 11.3µÄÄþ¾²¸üÐÂÖÐÇÄÇĵØÐÞ¸´ÁËÕâһ©¶´¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/apple-fixed-awdl-bug-that-could-be-used-to-escape-air-gapped-networks/


2.Ñо¿ÈËÔ±·¢ÏÖÀûÓÃExchangeÖЩ¶´ProxyShellµÄ¹¥»÷»î¶¯


2.jpg


2021 Black Hat´ó»áÉÏͳ³ÆΪProxyShellµÄ3¸ö©¶´µÄϸ½Ú¹ûÈ»ºó £¬Ñо¿ÈËÔ±·¢ÏÖÁË»ý¼«ÀûÓø鶴µÄ»î¶¯¡£ProxyShell°üÂÞACLÈƹý©¶´£¨CVE-2021-34473£©¡¢ Exchange PowerShellºó¶ËµÄÌáȨ©¶´£¨CVE-2021-34523£©ºÍÈÎÒâÎļþдÈëµ¼ÖµÄRCE©¶´£¨CVE-2021-31207£©¡£ÕâЩ©¶´¿ÉÒÔͨ¹ýIISÖеĶ˿Ú443ÉÏÔËÐеÄMicrosoft Exchange¿Í»§¶Ë·ÃÎÊ·þÎñ(CAS)Ô¶³ÌÀûÓà £¬½áºÏʹÓÿɽøÐÐδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´ÐС£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-servers-scanned-for-proxyshell-vulnerability-patch-now/


3.Ñо¿ÍŶӷ¢ÏÖÀûÓÃArcadyan¹Ì¼þÖЩ¶´°²×°MiraiµÄ»î¶¯


3.jpg


Õ°²©ÍøÂçµÄÑо¿ÍŶÓÔÚ½üÆÚ·¢ÏÖÁËÀûÓÃArcadyan¹Ì¼þÖЩ¶´µÄ¹¥»÷»î¶¯¡£¸Ã©¶´ÊÇ·¾¶±éÀú©¶´ £¬×·×ÙΪCVE-2021-20090 £¬ÆÀ·ÖΪ9.9¡£´æÔÚÓÚʹÓÃArcadyan¹Ì¼þµÄ·ÓÉÆ÷µÄweb½çÃæÉÏ £¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÈƹýÉí·ÝÑéÖ¤ £¬Ó°ÏìÁËÊýÊ®ÖÖÐͺŵÄÊý°ÙÍǫ̀·ÓÉÆ÷¡£×ÔÉÏÖÜËÄÒÔÀ´ £¬Ñо¿ÈËÔ±ÔÚÒ°·¢ÏÖÁËÀûÓôË©¶´µÄ¹¥»÷»î¶¯,Ö¼ÔÚ½Ó¹ÜÄ¿±êÉ豸²¢°²×°½©Ê¬ÍøÂçMiraiµÄpayload¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/actively-exploited-bug-bypasses-authentication-on-millions-of-routers/


4.SeniorAdvisor´æ´¢Í°ÅäÖôíÎóй¶Áè¼Ý300Íò¿Í»§ÐÅÏ¢


4.jpg


WizCaseÑо¿ÍŶӷ¢ÏÖÁ˸߼¶»¤ÀíÉó²éÍøÕ¾SeniorAdvisorµÄAmazon S3´æ´¢Í°ÅäÖôíÎó £¬Ð¹Â¶Áè¼Ý300Íò¿Í»§ÐÅÏ¢¡£¸ÃÍøÕ¾ÓÃÀ´Õ¹Ê¾ ÃÀ¹úºÍ¼ÓÄôóµÄÀÏÄ껤Àí·þÎñÏû·ÑÕßµÄÆÀ·ÖºÍÆÀÂÛ £¬´Ë´Î×ܹ²Ð¹Â¶ÁËÁè¼Ý100Íò¸öÎļþºÍ182GBµÄÊý¾Ý £¬°üÂÞÐÕÃû¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂëºÍÁªÏµÈÕÆÚµÈ £¬¶øÇÒ¶¼Î´¾­¹ý¼ÓÃÜ £¬´ËÍ⻹ÓÐԼĪ2000ÌõÒѱ»É¾³ýµÄÆÀÂÛ¡£WizCase³Æ´Ë´Îй¶ԴÖ÷ÒªÊÇ´¦ÓÚ»ò½Ó½üÍËÐݵÄÀÏÄêÈË £¬ÎªÌض¨µÄÈõÊÆȺÌå £¬¸üÈÝÒ×Ôâµ½Õ©Æ­»î¶¯µÄ¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/senior-citizens-personal-data/


5.Group-IB·¢ÏÖºÚ¿ÍÔÚ¶à¸ö°µÍø¹ûÈ»Áè¼Ý100ÍòÌõÖ§¸¶¼Ç¼


5.jpg


Group-IBÔÚ¶à¸öÔÚ¶à¸ö°µÍøÉϼì²âµ½Ò»¸öÌØÊâÌû×Ó £¬ÃûΪAW_cardsµÄºÚ¿Í¹ûÈ»ÁËÁè¼Ý100ÍòÌõÖ§¸¶¼Ç¼¡£ÕâЩÊý¾Ý°üÂÞÁËÀ´×Ô100¶à¸ö¹ú¼ÒºÍµØÓòµÄ1000¶à¼ÒÒøÐеÄÒøÐп¨ÏêϸÐÅÏ¢ £¬°üÂÞÓ¡¶È¡¢Ä«Î÷¸ç¡¢ÃÀ¹ú¡¢°Ä´óÀûÑÇ¡¢°ÍÎ÷µÈ¡£ÒòΪºÜÉÙÓз¸×ï·Ö×ÓÃâ·ÑÌṩÈç´Ë¶àµÄÒøÐп¨ÐÅÏ¢ £¬ÕâÒýÆðÁËGroup-IBÑо¿ÈËÔ±µÄÐËȤ¡£·ÖÎö·¢ÏÖÕâÊÇÒ»¸ö¶·µ¨µÄ¹ã¸æ £¬Ö¼ÔÚÍƹãÐÂƽ̨All World Cards¡£ÕâЩÊý¾Ý°üÂÞ¿¨ºÅ¡¢½ØÖ¹ÈÕÆÚ¡¢CVV/CVC´úÂë¡¢³Ö¿¨ÈËÐÕÃû¡¢¹ú¼Ò¡¢×´Ì¬¡¢¶¼ÊС¢µØÖ·¡¢ÓÊÕþ±àÂëºÍµç»°µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/120941/cyber-crime/1m-compromised-cards.html


6.RansomEXXÍÅ»ïÉù³ÆÒÑÇÔÈ¡ÉݳÞÆ·ÅÆZegnaÁè¼Ý20GBÊý¾Ý


6.jpg


ÀÕË÷ÍÅ»ïRansomEXX½üÆÚÉù³ÆÒÑÇÔÈ¡ÉݳÞÆ·ÅÆZegnaÁè¼Ý20GBÊý¾Ý¡£ZegnaÊÇÒâ´óÀû×îÖøÃûµÄÉݳÞʱװƷÅÆÖ®Ò» £¬ÊÇÈ«ÇòÊÕÈë×î¸ßµÄÄÐ×°Æ·ÅÆ¡£RansomEXX³ÆÒѴӸù«Ë¾ÇÔÈ¡ÁË20.74GBµÄÊý¾Ý £¬²¢Ðû²¼ÁË43¸öÎļþ£¨42¸ö500MBµÄÎļþºÍ1¸ö239.54MBµÄÎļþ£©×÷ΪÑù±¾¡£½üÆÚ £¬RansomEXXÍÅ»ïÔøѬȾÁËÒâ´óÀûÀ­Æë°Â´óÇøµÄϵͳ £¬²¢¹¥»÷ÁËÖйų́ÍåµÄ¼ÆËã»úÓ²¼þÖÆÔìÉ̼¼¼Î£¨GIGABYTE£©¡£


 Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/120898/data-breach/ransomexx-ransomware-zegna.html