CiscoÅû¶Foxit PDFµÄ¶à¸öÊͷźóʹÓé¶´£»CleafyÅû¶ÐÂAndroid½©Ê¬ÍøÂçUBELÓëOscorpÓйØ
Ðû²¼Ê±¼ä 2021-07-29Cisco TalosÅû¶×î½üÔÚFoxit PDF ReaderÖз¢ÏֵĶà¸öÊͷźóʹÓé¶´¡£Foxit PDF ReaderÊÇĿǰ×îÁ÷ÐеÄPDFÔĶÁÆ÷Ö®Ò»£¬Ö§³Ö½»»¥Ê½ÎĵµºÍ¶¯Ì¬±íµ¥µÄJavaScript¡£´Ë´ÎÅû¶µÄ©¶´°üÂÞCVE-2021-21831¡¢CVE-2021-21870ºÍCVE-2021-21893£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÓÕʹÓû§´ò¿ªÌØÖƵĶñÒâPDF£¬À´ÀûÓÃÕâЩ©¶´ÔÚÄ¿±êÉ豸ÉÏÖ´ÐÐÈÎÒâ´úÂë¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2021/07/vulnerability-spotlight-use-after-free.html
2.Ñо¿ÈËÔ±Åû¶µç×ÓÓʼþÐ×÷Èí¼þZimbraÖеĶà¸ö©¶´
SonarSourceÑо¿ÈËÔ±Åû¶µç×ÓÓʼþÐ×÷Èí¼þZimbraÖеÄ2¸ö©¶´¡£µÚÒ»¸öÊÇÔÚÈÕÀúÑûÇë×é¼þZmMailMsgView.jsÖеĿçÕ¾½Å±¾Â©¶´£¬×·×ÙΪCVE-2021-35208£¬Êܺ¦ÕßÔÚä¯ÀÀÊÕµ½µÄÓʼþʱ¿ÉÄܻᴥ·¢¸Ã©¶´¡£µÚ¶þ¸öÊÇServletÖеÄProxyServlet.javaÖеĿª·ÅÖØ¶¨Ïò©¶´£¬×·×ÙΪCVE-2021-35209£¬ÔÊÐíÁбíÈÆ¹ý£¬¿ÉÄܵ¼Ö·þÎñÆ÷¶ËµÄÇëÇóαÔì©¶´¡£Ñо¿ÈËÔ±³Æ£¬Ô¶³Ì¹¥»÷Õß½áºÏʹÓÃÁ½¸ö©¶´¿ÉÒÔÇÔÈ¡¹È¸èÔÆAPIÁîÅÆ»òAWS IAMƾ¾Ý¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/120603/hacking/zimbra-vulnerabilities.html
3.¼ÓÖÝ´óѧʥµØÑǸç·ÖУ³ÆÆäITϵͳÔâµ½ÍøÂçµöÓã¹¥»÷
¼ÓÖÝ´óѧʥµØÑǸç·ÖУ½¡¿µÖÐÐÄ³ÆÆäITϵͳÔâµ½ÍøÂçµöÓã¹¥»÷µ¼ÖÂÊý¾Ýй¶¡£¸Ã½¡¿µÖÐÐÄÊÇÈ«ÃÀ×îºÃµÄÒ½ÔºÖ®Ò»£¬¶à´Î±»ÆÀΪʥµØÑǸç×îºÃµÄÒ½ÁƱ£½¡ÏµÍ³¡£¸Ã»ú¹¹ÔÚ3ÔÂ12ÈÕÊÕµ½ÁË¿ÉÒɻµÄ¾¯±¨£¬²¢ÓÚ4ÔÂ8ÈÕ·¢ÏÖ¹¥»÷Õß·ÃÎÊÁËÆä²¿ÃÅÔ±¹¤µÄÓʼþÕÊ»§¡£¾ÊӲ죬¹¥»÷Õß¿ÉÄÜÔÚ2020Äê12ÔÂ2ÈÕÖÁ2021Äê4ÔÂ8ÈÕ¼äÇÔÈ¡ÁË»¼Õß¡¢Ô±¹¤ºÍѧÉúµÄ¸öÈËÐÅÏ¢£¬°üÂÞÐÕÃû¡¢µØÖ·¡¢³öÉúÈÕÆÚ¡¢Óʼþ¡¢´«ÕæºÅÂë¡¢ÖÎÁÆÐÅÏ¢¡¢Ò½ÁÆÐÅÏ¢¡¢Éç»áÄþ¾²ºÅÂë¡¢Éí·ÝÖ¤ºÅÂë¡¢Ö§¸¶¿¨ºÅÂë»ò½ðÈÚÕʺźÍÄþ¾²Â롢ѧÉúÖ¤ºÅÂëÒÔ¼°Óû§ÃûºÍÃÜÂëµÈ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/uc-san-diego-health-discloses-data-breach-after-phishing-attack/
4.ÐÂÀÕË÷ÍÅ»ïBlackMatter³Æ½öÕë¶ÔÄêÊÕÈë1ÒÚÒÔÉϹ«Ë¾
Recorded Future·¢ÏÖÔÚ±¾ÖÜ¿ªÊ¼ÔË×÷µÄÐÂÀÕË÷ÍÅ»ïBlackMatter¡£BlackMatterĿǰÕýÔÚºÚ¿ÍÂÛ̳ExploitºÍXSSÐû²¼µÄ¹ã¸æÕÐļºÏ×÷Õߣ¬²¢ÌåÏÖÄêËûÃǽöÕë¶ÔÊÕÈëΪ1ÒÚÃÀÔª»òÒÔÉϵĹ«Ë¾¡£¸ÃÍÅ»ïÉù³ÆÆä½áºÏÁËDarksideºÍREviµÄÓÅÊÆ£¬²¢ÒªÇóºÏ»ïÈ˵ÄÍøÂçÐèÒªÓµÓÐ500µ½15000̨Ö÷»ú£¬ÇÒλÓÚÃÀ¹ú¡¢Ó¢¹ú¡¢¼ÓÄôó»ò°Ä´óÀûÑÇ¡£´ËÍ⣬¸ÃÍÅ»ïÒ²ÔËÓªÁËÒ»¸öÊý¾ÝÐ¹Â¶ÍøÕ¾£¬µ«ÊǸÃÍøÕ¾Ä¿Ç°Êǿյġ£
ÔÎÄÁ´½Ó£º
https://therecord.media/blackmatter-ransomware-targets-companies-with-revenues-of-100-million-and-more/
5.ÄÏ·ÇÎïÁ÷¹«Ë¾Transnet SOCÔâµ½ÀÕË÷¹¥»÷ÔÝʱͣÔË
ÄÏ·ÇÎïÁ÷¹«Ë¾Transnet SOCÔâµ½ÀÕË÷¹¥»÷£¬ÆäËùÓпڰ¶ÂëÍ·ÔÝʱͣÔË¡£¹¥»÷·¢ÉúÔÚ7ÔÂ22ÈÕÐÇÆÚËÄ£¬·¢Éú¹¥»÷ºó¸Ã¹«Ë¾Á¢¼´¶ÔʼþÕ¹¿ªÊӲ죬²¢½¨ÒéÆäÔ±¹¤ÔÝͣʹÓõç×ÓÓʼþ£¬ÒÔ·À¹¥»÷µÄÂûÑÓ¡£Transnet͸¶£¬¿¨³µÔËÊäʹÓõÄNavisϵͳÊܵ½Ó°Ï죬Ŀǰ½ø³ö¿Ú°¶µÄ´¬Ö»ÐèÒªÓÉÈ˹¤¼Ç¼£¬¶øÇÒTransnet SOC LtdµÄÍøÕ¾Ò²ÒѾ¹Ø±Õ¡£Ä¿Ç°ÉÐδ͸¶ÀÕË÷Èí¼þµÄÀàÐÍ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/120596/cyber-crime/transnet-soc-cyber-attack.html
6.CleafyÅû¶ÐÂAndroid½©Ê¬ÍøÂçUBELÓëOscorpÓйØ
Òâ´óÀûÄþ¾²¹«Ë¾CleafyÅû¶ÐµÄAndroid½©Ê¬ÍøÂçUBELÓëOscorpÓйء£Ñо¿ÈËÔ±ÔÚ2021Äê5ÔÂÖÁ6ÔÂÆÚ¼ä£¬ÔÚÒ°Íâ·¢ÏÖÁËеÄOscorpÑù±¾£¬Óë´Ëͬʱ£¬Ò»¸öÃûΪUBELµÄÐÂÐÍAndroid½©Ê¬ÍøÂ翪ʼÔÚºÚ¿ÍÂÛ̳ÉÏÐû´«¡£Í¨¹ý·ÖÎö£¬·¢ÏÖOscorpºÍUBEL¿ÉÒÔÁ´½Óµ½Í¬Ò»¸ö¶ñÒâ´úÂë¿â£¬±íÃ÷ËüÃÇÊôÓÚͬһÏîÄ¿µÄ·ÖÖ§»òÆäËüºÏ»ïÈ˵ÄÖØÐÂÃüÃû¡£UBEL¾ßÓжÁÈ¡ºÍ·¢ËÍSMSÏûÏ¢¡¢Â¼ÖÆÒôƵ¡¢°²×°ºÍɾ³ýÓ¦Óá¢×Ô¶¯Æô¶¯µÈ¹¦Ð§¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/07/ubel-is-new-oscorp-android-credential.html