Ñо¿ÍŶӷ¢ÏÖAdobe Experience ManagerÖÐRCE 0day£»¶íÂÞ˹ºÚ¿ÍÒÑÔÚµ¤ÂóÖÐÑëÒøÐеÄÍøÂçDZ·üÁè¼Ý°ëÄê

Ðû²¼Ê±¼ä 2021-06-30

1.Ñо¿ÍŶӷ¢ÏÖAdobe Experience ManagerÖÐRCE 0day


1.jpg


Ñо¿ÍŶӷ¢ÏÖAdobe Experience Manager(AEM)ÖдæÔÚRCE 0day¡£AEMÊÇÁ÷ÐеÄÄÚÈݹÜÀí½â¾ö·½°¸£¬ÒѳÉΪÐí¶àÖªÃûÆóÒµµÄÊ×Ñ¡ÄÚÈݹÜÀíϵͳ (CMS)£¬°üÂÞÍòÊ´│¡¢LinkedIn¡¢PlayStationºÍMcAfeeÔÚÄڵĶà¼Ò¹«Ë¾¶¼Êܵ½ÁËÓ°Ïì¡£¸Ã©¶´´æÔÚÓÚÉúÔÚCRX /crx/packmgr/¶Ëµã£¬¹¥»÷Õß¿ÉÒÔÈÆ¹ýDispatcherÖеÄÉí·ÝÑéÖ¤À´·ÃÎÊCRX Package Manager£¬È»ºóÔÚAEMÖÐÉÏ´«¶ñÒâ°üÀ´»ñµÃ¶ÔÓ¦Ó÷¨Ê½µÄÍêÈ«¿ØÖÆ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/zero-day-exploit-found-in-adobe/


2.¶íÂÞ˹ºÚ¿ÍÒÑÔÚµ¤ÂóÖÐÑëÒøÐеÄÍøÂçDZ·üÁè¼Ý°ëÄê


2.jpg


¶íÂÞ˹ºÚ¿ÍÍÅ»ïNobeliumÈëÇÖÁ˵¤ÂóÖÐÑëÒøÐÐ(Danmarks Nationalbank)²¢Ö²ÈëÁ˶ñÒâÈí¼þ£¬ÔÚûÓб»·¢ÏÖµÄÇé¿öÏ·ÃÎÊÍøÂçÁè¼Ý°ëÄê¡£¸Ã»î¶¯ÊÇÈ¥ÄêSolarWinds¹©Ó¦Á´¹¥»÷µÄÒ»²¿ÃÅ£¬ÔÚVersion2ÒÔÐÅÏ¢×ÔÓÉΪÓÉ´Óµ¤ÂóÑëÐлñµÃ¹Ù·½Îļþºó²ÅÅû¶µÄ¡£¸Ã¶ñÒâÈí¼þÒѾ­ÔÚµ¤ÂóÑëÐеÄÍøÂçÖдæÔÚÁ˳¤´ï7¸öÔÂÖ®¾Ã£¬Ö±µ½FireEyeÅû¶Á˴˴ι©Ó¦Á´¹¥»÷»î¶¯ºó²Å±»·¢ÏÖ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/russian-hackers-had-months-long-access-to-denmarks-central-bank/


3.΢ÈíÐû²¼Äþ¾²¸üУ¬ÐÞ¸´Edgeä¯ÀÀÆ÷ÖеĶà¸ö©¶´


3.jpg


΢ÈíÐû²¼Äþ¾²¸üУ¬ÐÞ¸´ÁËEdgeä¯ÀÀÆ÷ÖеÄ2¸ö©¶´¡£ÆäÖнÏΪÑÏÖØµÄÊÇÄþ¾²Èƹý©¶´£¨CVE-2021-34506£©£¬Ê¹ÓÃEdgeä¯ÀÀÆ÷ÄÚÖõÄMicrosoft Translator¹¦Ð§×Ô¶¯·­ÒëÍøÒ³Ê±´¥·¢µÄ¿çÕ¾µã½Å±¾(UXSS)©¶´µ¼ÖµÄ£¬¿ÉÒÔÓÃÀ´ÔÚÍøÕ¾ÉÏÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£Ñо¿ÈËÔ±³Æ¸Ã©¶´µÄÅÓ´óÐԺܵÍ£¬¹¥»÷Õß¿ÉÒÔÔÚ²»ÐèÒªÈκÎȨÏÞµÄÇé¿öÏÂʵÏÖ¡£´Ë´ÎÐÞ¸´µÄÁíÒ»¸ö©¶´ÎªÌØÈ¨ÌáÉý©¶´£¨CVE-2021-34475£©¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/06/microsoft-edge-bug-couldve-let-hackers.html


4.NVIDIAÐû²¼Äþ¾²¸üУ¬ÐÞ¸´GeForceÖеÄÄþ¾²Â©¶´


4.jpg


NVIDIAÐû²¼Äþ¾²¸üУ¬ÐÞ¸´ÁËGeForce ExperienceÖеÄÄþ¾²Â©¶´¡£¸Ã©¶´±»¸ú×ÙΪCVE?2021?1073£¬CVSSÆÀ·ÖΪ8.3¡£¸Ã¹«Ë¾³ÆÂ©¶´»áµ¼ÖÂÆÛÆ­¹¥»÷£¬ÊÇÓÉNVIDIA GeForce ExperienceÈí¼þÖжÔÌØÊâ¸ñʽÁ´½ÓµÄ²»Í×´¦Öõ¼ÖµÄ¡£¹¥»÷Õß¿ÉÒÔ´´½¨Ò»¸öÌØÖÆµÄÁ´½Ó£¬Óû§ÔÚä¯ÀÀÆ÷Öжø·ÇÓ¦Ó÷¨Ê½Öдò¿ªµÇÂ¼Ò³Ãæ£¬²¢ÊäÈëËûÃǵÄÃÜÂëºó±»½Ù³Ö¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/nvidia-high-severity-geforce-spoof-bug/167345/


5.AcadeME¹«Ë¾Ôâµ½¹¥»÷£¬Ð¹Â¶ÒÔÉ«ÁÐÔ¼28ÍòѧÉúÐÅÏ¢


5.jpg


AcadeMEÊÇÒÔÉ«ÁеÄÒ»¼Ò·þÎñÌṩÉÌ£¬ÎªÑ°ÕÒÊÂÇéµÄѧÉúÌṩ×ÊÖú¡£6ÔÂ20ÈÕ£¬ÃûΪDragonForceµÄÂíÀ´Î÷ÑǺڿÍÍÅ»ï³ÆÆäÈëÇÖÁËAcadeME£¬²¢ÇÔÈ¡ÁËÔ¼28Íò¸öѧÉúµÄ¸öÈËÐÅÏ¢£¬°üÂÞµç×ÓÓʼþ¡¢ÃÜÂë¡¢ÐÕÃû¡¢µØÖ·ÉõÖÁµç»°ºÅÂë¡£ËäÈ»AcadeME·ñÈÏÁËÕâһ˵·¨£¬µ«¹¥»÷Õß¹ûÈ»ÁË´úÂë½ØÍ¼¡¢·þÎñÆ÷µØÖ·ÒÔ¼°Êý¾ÝµÄ±í¸ñÖ¤Ã÷´Ë´Î¹¥»÷¡£´ËÍ⣬¸ÃÍŻﻹÔÚÉÏÖÜÎå¶ÔÒÔÉ«ÁеĶà¼ÒÒøÐУ¨Bank of Israel¡¢Bank LeumiºÍMizrahi Tefahot£©ÌᳫÁËDDoS¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.jpost.com/israel-news/details-of-over-200000-students-leaked-in-cyberattack-672179    


6.TesorionÑо¿ÈËÔ±¼Æ»®¹ûÈ»ÐÂÀÕË÷Èí¼þLorenz½âÃÜÆ÷


6.jpg


ºÉÀ¼ÍøÂçÄþ¾²¹«Ë¾Tesorion¼Æ»®¹ûÈ»ÐÂÀÕË÷Èí¼þLorenzµÄ½âÃÜÆ÷¡£LorenzÀÕË÷Èí¼þÍÅ»ï×Ô2021Äê4ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬¹¥»÷ÁËÈ«ÇòµÄ¶à¸ö×éÖ¯£¬ÆäÊê½ðÒªÇóÏ൱¸ß£¬ÔÚ50ÍòÃÀÔªµ½70ÍòÃÀÔªÖ®¼ä¡£LorenzÔÚCBCģʽÏÂʹÓÃRSAºÍAES-128µÄ×éºÏÀ´¼ÓÃÜÎļþ£¬ÎªÃ¿¸öÎļþʹÓÃËæ»úÉú³ÉµÄÃÜÂ룬ȻºóʹÓÃCryptDeriveKeyº¯Êýµ¼³ö¼ÓÃÜÃÜÔ¿¡£Tesorion·ÖÎöÁ˸ÃÀÕË÷Èí¼þ²¢¼Æ»®Í¨¹ýNoMoreRansomÐû²¼¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/119492/cyber-crime/lorenz-ransomware-free-decryptor.html