MicrosoftÐû²¼²¹¶¡ÐÞ¸´86¸ö©¶´:IntezerÐû²¼·ÖÎö³ÂËß
Ðû²¼Ê±¼ä 2021-09-16¹È¸èÒòÀÄÓð²×¿µÄÊг¡Ö÷µ¼Ö°Î»±»º«¹ú·£¿î2070ÒÚº«Ôª
9ÔÂ14ÈÕ£¬º«¹ú¹«ÕýóÒ×ίԱ»á¶Ô¹È¸è´¦ÒÔ2070ÒÚº«Ôª£¨Ô¼Îª1.77 ÒÚÃÀÔª£©µÄ·£¿î¡£ÔÒòÊǹȸèÒòÀÄÓð²×¿ÔÚÒÆ¶¯²Ù×÷ϵͳÊг¡µÄÖ÷µ¼Ö°Î»£¬ÆÈʹÖÇÄÜÊÖ»úÖÆÔìÉÌÖ»ÄÜʹÓÃAndroid²Ù×÷ϵͳ¡£¸Ã»ú¹¹³Æ£¬¹È¸èÒªÇóÖÆÔìÉ̱ØÐëÇ©Êð¡°·´Ë鯬»¯ÐÒ飨AFA£©¡±£¬¸ÃÐÒé½ûֹʹÓÃAndroid²Ù×÷ϵͳµÄÐ޸İ汾£¬¼´ËùνµÄ¡°Android·ÖÖ§¡±¡£±¨µÀ³Æ£¬¹È¸èµÄ¢¶ÏÐÐΪʹÆäÔÚ2019ÄêÒÆ¶¯²Ù×÷ϵͳÊг¡µÄ·Ý¶îÉÏÉýµ½ÁË97.7%¡£
ÔÎÄÁ´½Ó£º
https://www.theregister.com/2021/09/14/south_korea_fines_google/
MicrosoftÐû²¼9Ô·ÝÐÇÆÚ¶þ²¹¶¡£¬×ܼÆÐÞ¸´86¸ö©¶´
MicrosoftÓÚ9ÔÂ14ÈÕÐû²¼Á˱¾ÔµÄÐÇÆÚ¶þÄþ¾²¸üУ¬×ܼÆÐÞ¸´ÁË86¸ö©¶´¡£´Ë´Î¸üÐÂÐÞ¸´ÁË2¸öÁãÈÕ©¶´£¬°üÂÞWindows MSHTMLÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-40444£©£¬ÒÑÔÚÒ°Íâ·¢ÏÖÀûÓøÃ©¶´µÄ¹¥»÷»î¶¯£»ÒÔ¼°Windows DNSÌáȨ©¶´£¨CVE-2021-36968£©¡£´ËÍ⣬»¹ÐÞ¸´ÁËAzure ¿ª·Åʽ¹ÜÀí»ù´¡ÉèÊ©ÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-38647£©ºÍWindows½Å±¾ÒýÇæÄÚ´æËð»µÂ©¶´£¨CVE-2021-26435£©µÈ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2021-patch-tuesday-fixes-2-zero-days-60-flaws/
GoogleÐÞ¸´ChromeÖеİüÂÞ2¸ö0dayÔÚÄÚµÄ11¸ö©¶´
GoogleÓÚ±¾ÖÜÒ»Ðû²¼Äþ¾²¸üУ¬ÐÞ¸´ÁËChromeÖаüÂÞ2¸ö0dayÔÚÄÚµÄ11¸ö©¶´¡£ÕâÁ½¸ö0day·Ö±ðΪV8 JavaScriptÒýÇæÖеÄÔ½½çдÈë©¶´£¨CVE-2021-30632£©ºÍË÷ÒýÊý¾Ý¿âAPIÖеÄÊͷźóʹÓé¶´£¨CVE-2021-30633£©¡£Google³ÆÕâÁ½¸ö©¶´Òѱ»ÔÚÒ°ÀûÓ㬵«ÊDz¢Î´¹ûÈ»Óйع¥»÷»î¶¯µÄÏêϸÐÅÏ¢¡£´ËÍ⣬»¹ÐÞ¸´ÁËSelection APIÖеÄÊͷźóʹÓé¶´£¨CVE-2021-30625£©ºÍANGLEÖеÄÄÚ´æ·ÃÎÊÔ½½ç©¶´£¨CVE-2021-30626£©µÈ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/122192/hacking/google-zero-day-10.html
GetHealthÒòÊý¾Ý¿âÅäÖôíÎóй¶6000Íò¶àÌõÓû§¼Ç¼
9ÔÂ13ÈÕ£¬WebsitePlanet³ÆGetHealthµÄÊý¾Ý¿âй¶ÁË6000Íò¶àÌõÓû§¼Ç¼¡£2021Äê6ÔÂ30ÈÕ£¬¸ÃÄþ¾²ÍŶӷ¢ÏÖÁËÒ»¸öûÓÐÃÜÂë±£»¤µÄÊý¾Ý¿â£¬ÆäÖаüÂÞÁËÁè¼Ý6100ÍòÌõ¼Ç¼£¬ÀýÈçÓû§ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢ÌåÖØ¡¢Éí¸ß¡¢ÐÔ±ðºÍGPSÈÕÖ¾µÈ¡£¾¹ý·ÖÎö£¬·¢ÏÖ´ó²¿ÃÅÊý¾ÝÔ´À´×ÔFitbitºÍAppleµÄHealthKit¡£GetHealthÔڵõ½Í¨ÖªºóÁ¢¼´×ö³öÏìÓ¦£¬ÔÚÊýСʱÄÚ½«¸ÃÊý¾Ý¿â±£»¤ÆðÀ´¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/over-60-million-records-exposed-in-wearable-fitness-tracking-data-breach-via-unsecured-database/
Ò½ÁƼ¼Êõ¹«Ë¾Olympus³ÆÆäÔâµ½BlackMatterÀÕË÷¹¥»÷
Ò½ÁƼ¼Êõ¹«Ë¾OlympusÔÚÉÏÖÜÁùÐû²¼ÉùÃ÷£¬³ÆÆäÔâµ½ÁËBlackMatterµÄÀÕË÷¹¥»÷¡£ÉùÃ÷ÌåÏÖ£¬¹¥»÷·¢ÉúÔÚ9ÔÂ8ÈÕ£¬Ó°ÏìÁËÆäEMEA£¨Å·ÖÞ¡¢Öж«¡¢·ÇÖÞ£©ITϵͳ¡£OlympusÒÑÔÝÍ£ÊÜÓ°Ïìϵͳ£¬²¢ÔÚÈ·¶¨¹¥»÷Ôì³ÉµÄÓ°Ï췶Χ£¬ÔÊÐí½«¾¡¿ìÐû²¼ÏêϸÐÅÏ¢¡£BlackMatterÊÇÏà¶Ô½ÏеÄÀÕË÷ÔËÓªÍŻÓÚ2021Äê7Ô¿ªÊ¼»îÔ¾£¬×î³õ±»ÈÏΪÊÇDarkSideµÄ¼ÌÈÎÕß¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/blackmatter-ransomware-hits-medical-technology-giant-olympus/
IntezerÐû²¼ÓйØVermilion StrikeµÄ·ÖÎö³ÂËß
IntezerÓÚ9ÔÂ13ÈÕÐû²¼ÁËÓйØVermilion StrikeµÄ·ÖÎö³ÂËß¡£2021Äê8Ô£¬Ñо¿ÈËÔ±·¢ÏÖÁËLinux°æ±¾µÄCobalt Strike BeaconµÄELFÑù±¾£¬ÒÑÓÃÓÚÕë¶ÔÈ«ÇòµçÐŹ«Ë¾¡¢Õþ¸®»ú¹¹¡¢IT ¹«Ë¾¡¢½ðÈÚ»ú¹¹ºÍ×Éѯ¹«Ë¾¡£ÆäÔÚÓëC2ͨÐÅʱʹÓÃÁËCobalt StrikeµÄC2ÐÒ飬²¢¾ßÓÐÔ¶³Ì·ÃÎʹ¦Ð§£¬ÀýÈçÉÏ´«Îļþ¡¢ÔËÐÐshellÃüÁîºÍдÈëÎļþ¡£
ÔÎÄÁ´½Ó£º
https://www.intezer.com/blog/malware-analysis/vermilionstrike-reimplementation-cobaltstrike/