΢ÈíÐû²¼7Ô·ÝÄþ¾²¸üР£¬ÐÞ¸´9¸ö0dayÔÚÄÚµÄ117¸ö©¶´£»Ê±ÉÐÆ·ÅÆGuessÔâµ½DarkSideÀÕË÷¹¥»÷й¶200GBÎļþ

Ðû²¼Ê±¼ä 2021-07-15

1.΢ÈíÐû²¼7Ô·ÝÄþ¾²¸üР£¬ÐÞ¸´9¸ö0dayÔÚÄÚµÄ117¸ö©¶´


1.jpg


΢ÈíÐû²¼ÁË2021Äê7Ô·ݵÄÖܶþ²¹¶¡ £¬ÐÞ¸´Á˰üÂÞ9¸ö0dayÔÚÄÚµÄ117¸ö©¶´ ¡£ÕâЩ©¶´ÖÐ £¬44¸öΪԶ³Ì´úÂëÖ´ÐÐ £¬32¸öΪÌáȨ©¶´ £¬14¸öΪÐÅϢй¶©¶´ £¬12¸öΪ¾Ü¾ø·þÎñ©¶´ £¬8¸öΪÄþ¾²¹¦Ð§Èƹý©¶´ £¬7¸öΪÆÛƭ©¶´ ¡£´Ë´ÎÐÞ¸´µÄ9¸ö0dayÖÐ £¬ÓÐ4¸öÒѱ»ÔÚÔÚÒ°ÀûÓà £¬°üÂÞPrintNightmare©¶´£¨CVE-2021-34527£©¡¢WindowsÄÚºËÌáȨ©¶´£¨CVE-2021-33771ºÍCVE-2021-31979£©ÒÔ¼°½Å±¾ÒýÇæÄÚ´æËð»µÂ©¶´£¨CVE-2021-34448£© ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2021-patch-tuesday-fixes-9-zero-days-117-flaws/


2.SolarWindsÐÞ¸´Serv-UÖÐÒѱ»ÀûÓõÄÔ¶³Ì´úÂëÖ´ÐЩ¶´


2.jpg


SolarWindsÔÚ7ÔÂ9ÈÕÐû²¼µÄServ-U 15.2.3 HF2ÖÐÐÞ¸´ÁËÒ»¸öÒѱ»ÀûÓõÄ0day ¡£MicrosoftÅû¶ÁËServ-U²úÎïµÄÔ¶³Ì´úÂëÖ´ÐÐ0day£¨CVE-2021-35211£© £¬Ô¶³Ì¹¥»÷ÕßÀûÓôË©¶´Äܹ»ÒÔÌØÊâȨÏÞÖ´ÐÐÈÎÒâ´úÂë £¬ÔÚÄ¿±êϵͳÉϰ²×°²¢ÔËÐз¨Ê½¡¢¼ì²ì¡¢¸ü¸Ä»òɾ³ýÊý¾ÝµÈ ¡£Ä¿Ç°¸Ã©¶´ÒѾ­³ö±»Ò°ÀûÓà £¬µ«SolarWindsÌåÏÖ £¬Èç¹ûServ-U»·¾³ÖÐδÆôÓÃSSH £¬Ôò¸Ã©¶´²»´æÔÚ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/solarwinds-patches-critical-serv-u-vulnerability-exploited-in-the-wild/


3.ʱÉÐÆ·ÅÆGuessÔâµ½DarkSideÀÕË÷¹¥»÷й¶200GBÎļþ


3.jpg


ÃÀ¹úʱÉÐÆ·ÅƺÍÁãÊÛÉÌGuessÔâµ½DarkSideÀÕË÷¹¥»÷й¶200GBÎļþ ¡£¸Ã¹«Ë¾³Æ £¬¹¥»÷·¢ÉúÔÚ2021Äê2ÔÂ2ÈÕÖÁ2021Äê2ÔÂ23ÈÕ £¬¸Ã¹«Ë¾ÔÚ6ÔÂ3ÈÕÍê³ÉÊÓ²ìºóÈ·¶¨ÁËÊÜÓ°ÏìµÄ¿Í»§²¢ÓÚ6ÔÂ9ÈÕ½«´Ëʼþ֪ͨ¸øÆä¿Í»§ ¡£¾­ÊÓ²ìÈ·¶¨ £¬Ð¹Â¶ÐÅÏ¢°üÂÞÉç»áÄþ¾²ºÅÂë¡¢¼ÝÕÕºÅÂë¡¢»¤ÕÕºÅÂëºÍ/»ò²ÆÕþÕʺÅ £¬Ö»Éæ¼°1300¶àÈË ¡£Guess²¢Î´Í¸Â©Óйع¥»÷ÕßµÄÈκÎÐÅÏ¢ £¬µ«ÊÇDarkSideÔøÔÚ4Ô·ÝÉù³ÆÆä¹¥»÷ÁËGuess²¢ÇÔÈ¡ÁËÁè¼Ý200GBµÄÎļþ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/fashion-retailer-guess-notifies-users-data-breach


4.ºÚ¿Í³öÊÛ6ÒÚLinkedInÓû§ÐÅÏ¢²¢³ÆÐÂÊý¾Ý±È֮ǰµÄ¸üºÃ


4.jpg


ºÚ¿ÍÔÚ°µÍø³öÊÛÁË6ÒÚ¸öLinkedInÓû§µÄÐÅÏ¢ £¬²¢³ÆÕâЩÊý¾ÝÊÇеÄ £¬±È֮ǰÊÕ¼¯µÄÊý¾Ý¸üºÃ ¡£ºÚ¿ÍÐû²¼ÁË632699¸öÓû§ÐÅÏ¢×÷ΪÑù±¾ £¬ÆäÖаüÂÞÁËÐÕÃû¡¢ÁìÓ¢ID¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢LinkedIn¸öÈË×ÊÁÏURL¡¢ÆäËûÉ罻ýÌå×ÊÁϵÄÁ´½Ó¡¢ÐԱ𡢳öÉúÈÕÆÚ¡¢ËùÔÚ¡¢Ö°³ÆºÍÆäËûÊÂÇéÏà¹ØÊý¾ÝµÈ ¡£Ñо¿ÈËÔ±³Æ £¬ËäÈ»ÕâЩÊý¾Ý²»ÊǺÜÃô¸Ð £¬µ«¹¥»÷ÕßÈÔÈ»¿ÉÒÔÀûÓÃÕâЩÐÅϢͨ¹ýÉç»á¹¤³ÌµÄÒªÁì¿ìËÙµØÕÒµ½Ð¹¥»÷Ä¿±ê ¡£


Ô­ÎÄÁ´½Ó£º

https://cybernews.com/news/threat-actors-scrape-600-million-linkedin-profiles-and-are-selling-the-data-online-again/


5.Ñо¿ÈËÔ±·¢ÏÖTrickBot»Ø¹é²¢ÐÂÔöÓÃÓÚ¼à¿ØµÄVNCÄ£¿é


5.jpg


Ñо¿ÈËÔ±·¢ÏÖTrickBot»Ø¹é²¢ÐÂÔöÁËÓÃÓÚ¼à¿ØºÍÇ鱨ÊÕ¼¯µÄVNCÄ£¿é ¡£Trickbot×Ô2016Äêµ×ÒÔÀ´Ò»Ö±»îÔ¾ £¬²¢ÓÚ2020Äê10Ô·ݱ»Î¢ÈíºÍ¶à¸öÄþ¾²³§ÉÌÁªºÏµ·»Ù ¡£µ«ÊÇ £¬Ñо¿ÈËÔ±·¢ÏÖĿǰµÄTrickbot±ÈÒÔÍùÈκÎʱºò¶¼Ô½·¢»îÔ¾ £¬²¢ÓÚ2021Äê5Ô¼ì²âµ½ÁËvncDllÄ£¿éµÄ¸üа汾tvncDll £¬ÓÃÓÚ¼à¿ØºÍÇ鱨ÊÕ¼¯ ¡£¸ÃÄ£¿éËÆºõ»¹ÔÚ¿ª·¢ÖÐ £¬ÒòΪÓÐÒ»¸öƵ·±µÄ¸üÐÂʱ¼ä±í £¬À´¶¨ÆÚÌí¼Óй¦Ð§ºÍÐÞ¸´´íÎó ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bitdefender.com/blog/labs/trickbot-activity-increases-new-vnc-module-on-the-radar


6.AberdeenºÍcode42ÁªºÏÐû²¼ÓйØÄÚ²¿·çÏյķÖÎö³ÂËß


6.jpg


AberdeenºÍcode42ÁªºÏÐû²¼ÁËÓйØÄÚ²¿·çÏյķÖÎö³ÂËß ¡£³ÂËßÖ¸³ö £¬Èý·ÖÖ®Ò»µÄÊý¾Ýй¶Ê¼þÉæ¼°ÄÚ²¿ÈËÔ± £¬¶øÆäÖÐÔ¼80%ÈËÊÇÎÞÒâµÄ£»75%µÄ×éÖ¯¶ÔÆä»·¾³Ã»ÓÐÒ»Ö¡¢¼¯ÖеĿɼûÐÔ£»2020Äê £¬ÔÚÖÕ¶ËÉÏ·¢Éú©¶´µÄ¿ÉÄÜÐÔÊÇ·þÎñÆ÷ÉϵÄ4.5±¶£»Êý¾Ý̻¶й¶µÄƽ¾ùÊýÁ¿ÊÇÿ¸öÓû§Ã¿Ìì»á·¢Éú13¸öÊý¾Ýй¶Ê¼þ£»ÄÚ²¿ÈËÔ±Êý¾Ýй¶µÄ³É±¾¿ÉÄܸߴ﹫˾ÄêÊÕÈëµÄ20% ¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.code42.com/blog/aberdeen-report-key-takeaways/