AppleÄþ¾²¸üР£¬ÐÞ¸´iOSºÍmacOSÖÐÒѱ»ÀûÓõÄ0day£»Ï£À°µÚ¶þ¶àÊý»áThessalonikiÔâµ½¹¥»÷ÊÐÕþ·þÎñÖжÏ

Ðû²¼Ê±¼ä 2021-07-27

1.AppleÄþ¾²¸üР£¬ÐÞ¸´iOSºÍmacOSÖÐÒѱ»ÀûÓõÄ0day


1.jpg


AppleÐû²¼ÁËÄþ¾²¸üР£¬ÐÞ¸´ÁËiOSºÍmacOSÖÐÒѱ»ÔÚÒ°ÀûÓõÄ0day¡£¸Ã©¶´×·×ÙΪCVE-2021-30807 £¬ÊÇÓÃÓÚ¹ÜÀíÆÁĻ֡»º³åÇøµÄÄÚºËÀ©Õ¹IOMobileFramebufferÖеÄÄÚ´æËð»µÂ©¶´¡£¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´ÔÚÄ¿±êÉ豸ÉÏʹÓÃÄÚºËȨÏÞÖ´ÐÐÈÎÒâ´úÂë £¬²¢ÍêÈ«¿ØÖÆÉ豸¡£¸Ã¹«Ë¾³ÆÂ©¶´¿ÉÄÜÒѱ»»ý¼«ÀûÓà £¬µ«²¢Î´Í¸Â¶ÓйØÕâЩ¹¥»÷µÄÈÎºÎÆäËûÐÅÏ¢¡£ÕâÊÇAppleÔÚ½ñÄêÐÞ¸´µÄµÚ13¸ö0day¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/apple/apple-fixes-zero-day-affecting-iphones-and-macs-exploited-in-the-wild/


2.Ï£À°µÚ¶þ¶àÊý»áThessalonikiÔâµ½¹¥»÷ÊÐÕþ·þÎñÖжÏ


2.jpg


Ï£À°µÚ¶þ¶àÊý»áÈøÂÞÄá¼Ó£¨Thessaloniki£©Ôâµ½ÍøÂç¹¥»÷ £¬ÊÐÕþ·þÎñÔÝʱÖжÏ¡£¸ÃÊи±Êг¤Giorgos Avarlis³Æ¹¥»÷·¢ÉúÔÚ2021Äê7ÔÂ23ÈÕ £¬·¢ÏÖºó¸ÃÊÐÁ¢¼´±ÕÁË·þÎñºÍwebÓ¦Ó÷¨Ê½¡£´ËÍâ £¬¹¥»÷ÕßÒѾ­°²×°ÁËÒ»ÖÖ¶ñÒⲡ¶¾²¢ÒªÇóÖ§¸¶Êê½ðÀ´½âËøÎļþ £¬µ«²¢Î´Í¸Â¶ÆäÊÇ·ñÖ§¸¶ÁËÊê½ð»òÖ§¸¶Á˼¸¶àÇ®¡£Avarlis»¹ÌåÏÖ £¬ÊÐÕþÕþ¸®µÄËùÓÐÎļþ¶¼ÊÇÄþ¾²µÄ £¬µ«ÈÔδȷ¶¨¹¥»÷µÄÀ´Ô´¡£


Ô­ÎÄÁ´½Ó£º

https://www.thenationalherald.com/archive_general_news_greece/arthro/cyberattack_shuts_down_services_in_greece_s_second_largest_city-2960445/


3.Ñо¿ÍŶӷ¢ÏÖ¹¥»÷ÕßÀûÓÃArgo WorkflowsÍÚ¿óµÄ»î¶¯


3.jpg


IntezerÑо¿ÍŶӷ¢ÏÖ¹¥»÷ÕßÀûÓÃÅäÖôíÎóµÄArgo WorkflowsµÄÍÚ¿ó»î¶¯¡£Argo WorkflowsÊÇÒ»¸ö¿ªÔ´µÄ¡¢ÈÝÆ÷Ô­ÉúµÄÊÂÇéÁ÷ÒýÇæ £¬ÔÚKubernetes(K8s)¼¯ÈºÉÏÔËÐС£Ñо¿ÈËÔ±·¢ÏÖһЩȨÏÞÅäÖôíÎóµÄʵÀý £¬ÔÊÐí¹¥»÷Õß·ÃÎÊ¿ª·ÅµÄArgo¿ØÖÆÃæ°å £¬²¢ÀûÓÃÖÖÖÖMonero¿ó¹¤ÈÝÆ÷°²×°×Ô¼ºµÄ¶ñÒâWorkflows £¬°üÂÞkannix/monero-miner¡£Ñо¿ÈËÔ±³Æ £¬ÒÑ·¢ÏÖÊý°Ù¸öÅäÖôíÎóµÄArgo Workflows £¬Òò´Ë¿ÉÒÔÔ¤¼Æ½«Óиü´ó¹æÄ£µÄ¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/120544/malware/kubernetes-attacks-argo-workflows.html


4.Sophos·¢ÏÖÀûÓÃDiscord CDNºÍAPIµÄ¹¥»÷»î¶¯¼¤Ôö


4.jpg


Sophos·¢ÏÖDiscord¶ñÒâÈí¼þµÄÊýÁ¿¼¤Ôö £¬Óë2020ÄêÏà±ÈÔö¼ÓÁË140±¶¡£µ¼Ö´ËÇ÷ÊÆµÄÖ÷ÒªÔ­ÒòÊǺڿÍÒ»Ö±ÔÚÀÄÓÃDiscordµÄÄÚÈݽ»¸¶ÍøÂç(CDN)ºÍÓ¦Ó÷¨Ê½±à³Ì½Ó¿Ú(API) £¬ÆäÖÐCDN±»ÓÃÀ´ÍйܶñÒâÈí¼þ £¬¶øAPI±»ÓÃÀ´ÇÔÈ¡Êý¾ÝÒÔ¼°Á¬½ÓÃüÁîºÍ¿ØÖÆ·þÎñÆ÷¡£Sophos³Æ £¬4Ô·ÝÔÚDiscordµÄCDNÉϼì²âµ½9500¸ö¶ñÒâURL £¬¶øÔÚ½ÓÏÂÀ´µÄ¼¸¸öÔÂÀï £¬Õâ¸öÊý×Öì­ÉýÖÁ17000¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/discord-malware-researchers/168096/


5.CovewareÐû²¼2021ÄêQ2ÓйØÀÕË÷¹¥»÷µÄ·ÖÎö³ÂËß


5.jpg


CovewareÐû²¼ÁË2021ÄêQ2ÓйØÀÕË÷¹¥»÷µÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö2021ÄêQ2ÀÕË÷Èí¼þµÄƽ¾ù¸¶¿î¶îϽµÖÁ136576ÃÀÔª £¬ÓëQ1µÄ220298ÃÀÔªÏà±ÈϽµÁË38%¡£2020ÄêÓÐ65%µÄÊܺ¦ÕßÑ¡ÔñÖ§¸¶Êê½ð £¬¶ø2021ÄêQ2Ö»ÓÐ50%µÄÊܺ¦Õ߸¶¿î¡£ÔÚÕâÒ»¼¾¶È×î³£¼ûµÄÀÕË÷Èí¼þ±äÌåΪSodinokibi£¨16.5%£©¡¢ContiV2£¨14.4%£©¡¢Avaddon£¨5.4%£©¡¢Mespinoza£¨4.9%£©ºÍHello Kitty£¨4.5%£©µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.coveware.com/blog/2021/7/23/q2-ransom-payment-amounts-decline-as-ransomware-becomes-a-national-security-priority


6.VadeÐû²¼2021ÄêÉϰëÄêÍøÂçµöÓã¹¥»÷µÄ·ÖÎö³ÂËß


6.jpg


VadeÐû²¼ÁË2021ÄêÉϰëÄêÈ«ÇòÍøÂçµöÓã¹¥»÷µÄ·ÖÎö³ÂËß £¬·ÖÎöÁ˹¥»÷Õß×î°®µÄ25¸öÆ·ÅÆ¡£³ÂËßÖ¸³ö £¬×ÜÌåµÄÍøÂçµöÓãÊýÁ¿ÔÚ2021ÄêQ2¼±¾çÔö¼Ó £¬5Ô·ݼ¤ÔöÁË281% £¬6Ô·ÝÓÖÔö¼ÓÁË284% £¬½öÔÚ6Ô·ݵ±Ô¾ͼì²âµ½42ÒڴεĵöÓãµç×ÓÓʼþ¡£ÔÚÉϰëÄê £¬·¨¹úũҵÐÅ´ûÒøÐУ¨Cr¨¦dit Agricole£©ÊDZ»Ã°³ä×î¶àµÄÆ·ÅÆ £¬ÓÐ17555¸öÏà¹ØµÄµöÓãURL £¬Æä´ÎΪFacebook£¨17338¸ö£©ºÍMicrosoft£¨12777¸ö£©¡£


Ô­ÎÄÁ´½Ó£º

https://www.vadesecure.com/en/blog/phishers-favorites-top-25-h1-2021-worldwide-edition