MicrosoftÅû¶NETGEAR·ÓÉÆ÷¹Ì¼þÖеĶà¸ö©¶´£»Avast³ÆÃɹŵÄCA»ú¹¹MonPassÒÑÔâµ½8´Î¹¥»÷
Ðû²¼Ê±¼ä 2021-07-021.MicrosoftÅû¶NETGEAR·ÓÉÆ÷¹Ì¼þÖеĶà¸ö©¶´
MicrosoftÅû¶ÁËNETGEAR DGN2200v1ϵÁзÓÉÆ÷¹Ì¼þÖеÄ3¸ö©¶´£¬¿É±»ÓÃÀ´ÔÚÆóÒµµÄÍøÂçÖкáÏòÒÆ¶¯¡£ÕâЩ©¶´ÎªHTTPdÉí·ÝÑéÖ¤Äþ¾²Â©¶´£¬CVSSÆÀ·ÖΪ7.1 ¨C 9.4²»µÈ¡£ÆäÖУ¬ÀûÓõÚÒ»¸ö©¶´¿ÉÔÚ×Ó×Ö·û´®ÖеÄÇëÇóÖи½¼ÓGET±äÁ¿£¬À´ÈƹýÉí·ÝÑéÖ¤£¬·ÃÎÊÉè±¹ØÁ¬ÄÈκÎÒ³Ãæ£»µÚ¶þ¸ö©¶´¿ÉÓÃÀ´½øÐвàÐŵÀ¹¥»÷£¬ÒÔÇÔÈ¡´æ´¢µÄƾ¾Ý£»µÚÈý¸ö©¶´¿ÉÓëÏÈǰµÄÈÏÖ¤ÈÆ¹ý©¶´½áºÏʹÓã¬À´ÇÔȡ·ÓÉÆ÷µÄÅäÖûָ´Îļþ¡£Ä¿Ç°£¬NetgearÒÑÐÞ¸´ÁËÕâЩ©¶´¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/06/microsoft-discloses-critical-bugs.html
2.Avast³ÆÃɹŵÄCA»ú¹¹MonPassÒÑÔâµ½8´Î¹¥»÷
Äþ¾²¹«Ë¾Avast³ÆÃɹÅ×î´óµÄÖ¤Êé·¢±í»ú¹¹(CA)Ö®Ò»MonPassÔâµ½ÁË8´ÎÍøÂç¹¥»÷¡£AvastÌåÏÖ£¬ÆäÔÚMonPassÍйܵĹ«¹²Web·þÎñÆ÷Öз¢ÏÖÁË8ÖÖ²îÒìµÄºóÃÅ£¬Õâ±íÃ÷¸Ã»ú¹¹¿ÉÄÜÔâµ½8´Î¹¥»÷¡£ÕâЩºóÃÅÓÚ2ÔÂ8ÈÕÖÁ3ÔÂ3ÈÕÆÚ¼äÔڸù«Ë¾µÄ¹Ù·½Ö¤Êé°²×°Ó¦ÓÃÖлîÔ¾£¬ÓÚ3ÔÂÏÂÑ®±»Åû¶¡£Ñо¿ÈËÔ±³Æ£¬¹¥»÷ÕßÏÔÈ»ÊǼƻ®Í¨¹ýÈëÇÖ¿ÉÐÅÀµµÄÀ´Ô´À´ÏòÃɹŵÄÓû§Á÷´«¶ñÒâÈí¼þ¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/mongolian-certificate-authority-hacked-eight-times-compromised-with-malware/
3.Ñо¿ÈËÔ±·¢ÏÖÀûÓÃBabuk Locker¹¹½¨Æ÷µÄ¹¥»÷»î¶¯
Ñо¿ÈËÔ±·¢ÏÖÀûÓÃÁËBabuk Locker¹¹½¨Æ÷µÄ¹¥»÷»î¶¯¡£Babuk LockerÊÇÒ»¿îÀÕË÷Èí¼þ£¬ÓÚ2021Ä꿪ʼ»îÔ¾£¬Æä¹¹½¨Æ÷ÓÚÉÏÖܱ»Ðû²¼µ½ÁËVirusTotalÉÏ¡£Ôڸù¹½¨Æ÷й¶ºó²»¾Ã£¬ºÚ¿Í¿ªÊ¼Æµ·±µÄʹÓÃËüÀ´ÌᳫÀÕË÷Èí¼þ»î¶¯¡£´Ó±¾Öܶþ¿ªÊ¼£¬ÓÐÓû§·´Ó³ÆäÔâµ½ÁËBabuk LockerÀÕË÷Èí¼þ¹¥»÷£¬Êܺ¦ÕßÀ´×ÔÊÀ½ç¸÷µØ¡£µ«ÊÇÓë×î³õµÄBabukÍŻﶯéüÒªÇóÊý°ÙÍòÃÀÔª²îÒ죬Õâ¸öÐµĹ¥»÷ÕßÖ»Òª0.006±ÈÌØ±Ò»òÔ¼210ÃÀÔªµÄÊê½ð¡£´ËÍ⣬¸ÃºÚ¿Í»¹ÔÚÀÕË÷ÐÅÖаѡ°Babuk¡±Æ´×÷ÁË¡°Babuck¡±¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/leaked-babuk-locker-ransomware-builder-used-in-new-attacks/
4.SMBÈ䳿IndexsinasÕë¶ÔÒ½ÁƱ£½¡¡¢·þÎñºÍ½ÌÓýµÈÐÐÒµ
Guardicore LabsÑо¿ÈËÔ±·¢ÏÖSMBÈ䳿IndexsinasÕë¶ÔÒ½ÁƱ£½¡¡¢·þÎñ¡¢½ÌÓýºÍµçÐŵÈÐÐÒµ¡£Indexsinas£¬ÓÖÃûNSABuffMiner£¬×Ô2019ÄêÒÔÀ´¿ªÊ¼»îÔ¾£¬Ö÷ҪʹÓÃÁË3¸ö©¶´£ºEternalBlue¡¢DoublePulsarºÍEternalRomance¡£Guardicore È«Çò´«¸ÐÆ÷ÍøÂç (GGSN)×Ô2019Ä꿪ʼ×ܹ²¼Ç¼ÁËÀ´×Ô1300¶à¸ö²îÒìÀ´Ô´µÄ2000¶à´Î¹¥»÷£¬ÆäÖдó¶àλÓÚÃÀ¹ú¡¢Ô½ÄϺÍÓ¡¶È¡£Ñо¿ÈËÔ±³Æ£¬¹¥»÷Õ߷dz£½÷É÷£¬C2·þÎñÆ÷¶¼ÔÚº«¹ú²¢¶¼Êܵ½Á˸߶ȱ£»¤£¬°²×°Á˲¹¶¡ÇÒûÓÐÏò»¥ÁªÍøÌ»Â¶¶àÓàµÄ¶Ë¿Ú¡£
ÔÎÄÁ´½Ó£º
https://www.guardicore.com/labs/smb-worm-indexsinas/
5.¸çÂ×±ÈÑÇÕþ¸®´þ²¶Á÷´«¶ñÒâÈí¼þGoziµÄÂÞÂíÄáÑǺڿÍ
¸çÂ×±ÈÑÇÕþ¸®´þ²¶ÁËÂÞÂíÄáÑǺڿÍMihai Ionut Paunescu¡£ËûÒòÔÚ2007ÄêÖÁ2012ÄêÀûÓöñÒâÈí¼þGoziѬȾÁËÁè¼Ý100Íǫ̀¼ÆËã»ú¶ø±»ÃÀ¹úͨ¼©¡£GoziÓÚ2007ÄêÊ״α»·¢ÏÖ£¬Ñ¬È¾ÁËÖÁÉٰ˸ö¹ú¼ÒµÄ¼ÆËã»ú£¬°üÂÞÃÀ¹ú¡¢µÂ¹ú¡¢·ÒÀ¼ºÍÓ¢¹úµÈ¹ú£¬Ôì³ÉÁËÊýǧÍòÃÀÔªµÄËðʧ¡£PaunescuÔøÓÚ2012ÄêÔÚÂÞÂíÄáÑDZ»²¶£¬µ«²¢Î´±»Òý¶É£¬ÏÖÔÚ¸çÂ×±ÈÑÇ×ܼì²ì³¤°ì¹«ÊÒÐû²¼ÔÚ²¨¸ç´ó¹ú¼Ê»ú³¡´þ²¶Á˸úڿ͡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/119550/cyber-crime/hacker-gozi-virus-arrested.html
6.CISAÐû²¼Õë¶ÔÀÕË÷Èí¼þµÄÄþ¾²Éó¼Æ×ÔÎÒÆÀ¹À¹¤¾ßRRA
ÃÀ¹úÍøÂçÄþ¾²ºÍ»ù´¡ÉèÊ©Äþ¾²¾Ö(CISA)Ðû²¼ÁËÀÕË÷Èí¼þ¾ÍÐ÷ÆÀ¹À(RRA)£¬ÕâÊÇÆäÍøÂçÄþ¾²ÆÀ¹À¹¤¾ß(CSET)µÄÐÂÄ£¿é¡£RRAÊÇÒ»ÖÖÄþ¾²Éó¼Æ×ÔÎÒÆÀ¹À¹¤¾ß£¬ÓÃÓÚ×éÖ¯µÖÓùÕë¶ÔÆäÐÅÏ¢¼¼Êõ(IT)¡¢ÔËÓª¼¼Êõ(OT)»ò¹¤Òµ¿ØÖÆÏµÍ³(ICS)µÄÀÕË÷Èí¼þ¹¥»÷£¬ÒÔ¼°´Ó¹¥»÷Öлָ´¡£CISA֮ǰ»¹Ðû²¼ÁËÓÃÓÚÉó²éMicrosoft Azure Active Directory¡¢Office 365ºÍMicrosoft 365ÖеĹ¥»÷»î¶¯µÄ¹¤¾ßAviary¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/cisa-releases-new-ransomware-self-assessment-security-audit-tool/