CiscoÅû¶Foxit PDFµÄ¶à¸öÊͷźóʹÓé¶´ £»CleafyÅû¶ÐÂAndroid½©Ê¬ÍøÂçUBELÓëOscorpÓйØ

Ðû²¼Ê±¼ä 2021-07-29
1.CiscoÅû¶Foxit PDF ReaderµÄ¶à¸öÊͷźóʹÓé¶´


1.jpg


Cisco TalosÅû¶×î½üÔÚFoxit PDF ReaderÖз¢ÏֵĶà¸öÊͷźóʹÓé¶´¡£Foxit PDF ReaderÊÇĿǰ×îÁ÷ÐеÄPDFÔĶÁÆ÷Ö®Ò»£¬Ö§³Ö½»»¥Ê½ÎĵµºÍ¶¯Ì¬±íµ¥µÄJavaScript¡£´Ë´ÎÅû¶µÄ©¶´°üÂÞCVE-2021-21831¡¢CVE-2021-21870ºÍCVE-2021-21893£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÓÕʹÓû§´ò¿ªÌØÖƵĶñÒâPDF£¬À´ÀûÓÃÕâЩ©¶´ÔÚÄ¿±êÉ豸ÉÏÖ´ÐÐÈÎÒâ´úÂë¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2021/07/vulnerability-spotlight-use-after-free.html


2.Ñо¿ÈËÔ±Åû¶µç×ÓÓʼþЭ×÷Èí¼þZimbraÖеĶà¸ö©¶´


2.jpg


SonarSourceÑо¿ÈËÔ±Åû¶µç×ÓÓʼþЭ×÷Èí¼þZimbraÖеÄ2¸ö©¶´¡£µÚÒ»¸öÊÇÔÚÈÕÀúÑûÇë×é¼þZmMailMsgView.jsÖеĿçÕ¾½Å±¾Â©¶´£¬×·×ÙΪCVE-2021-35208£¬Êܺ¦ÕßÔÚä¯ÀÀÊÕµ½µÄÓʼþʱ¿ÉÄܻᴥ·¢¸Ã©¶´¡£µÚ¶þ¸öÊÇServletÖеÄProxyServlet.javaÖеĿª·ÅÖØ¶¨Ïò©¶´£¬×·×ÙΪCVE-2021-35209£¬ÔÊÐíÁбíÈÆ¹ý£¬¿ÉÄܵ¼Ö·þÎñÆ÷¶ËµÄÇëÇóαÔì©¶´¡£Ñо¿ÈËÔ±³Æ£¬Ô¶³Ì¹¥»÷Õß½áºÏʹÓÃÁ½¸ö©¶´¿ÉÒÔÇÔÈ¡¹È¸èÔÆAPIÁîÅÆ»òAWS IAMƾ¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/120603/hacking/zimbra-vulnerabilities.html


3.¼ÓÖÝ´óѧʥµØÑǸç·ÖУ³ÆÆäITϵͳÔâµ½ÍøÂçµöÓã¹¥»÷


3.jpg


¼ÓÖÝ´óѧʥµØÑǸç·ÖУ½¡¿µÖÐÐÄ³ÆÆäITϵͳÔâµ½ÍøÂçµöÓã¹¥»÷µ¼ÖÂÊý¾Ýй¶¡£¸Ã½¡¿µÖÐÐÄÊÇÈ«ÃÀ×îºÃµÄÒ½ÔºÖ®Ò»£¬¶à´Î±»ÆÀΪʥµØÑǸç×îºÃµÄÒ½ÁƱ£½¡ÏµÍ³¡£¸Ã»ú¹¹ÔÚ3ÔÂ12ÈÕÊÕµ½ÁË¿ÉÒɻµÄ¾¯±¨£¬²¢ÓÚ4ÔÂ8ÈÕ·¢ÏÖ¹¥»÷Õß·ÃÎÊÁËÆä²¿ÃÅÔ±¹¤µÄÓʼþÕÊ»§¡£¾­ÊӲ죬¹¥»÷Õß¿ÉÄÜÔÚ2020Äê12ÔÂ2ÈÕÖÁ2021Äê4ÔÂ8ÈÕ¼äÇÔÈ¡ÁË»¼Õß¡¢Ô±¹¤ºÍѧÉúµÄ¸öÈËÐÅÏ¢£¬°üÂÞÐÕÃû¡¢µØÖ·¡¢³öÉúÈÕÆÚ¡¢Óʼþ¡¢´«ÕæºÅÂë¡¢ÖÎÁÆÐÅÏ¢¡¢Ò½ÁÆÐÅÏ¢¡¢Éç»áÄþ¾²ºÅÂë¡¢Éí·ÝÖ¤ºÅÂë¡¢Ö§¸¶¿¨ºÅÂë»ò½ðÈÚÕʺźÍÄþ¾²Â롢ѧÉúÖ¤ºÅÂëÒÔ¼°Óû§ÃûºÍÃÜÂëµÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/uc-san-diego-health-discloses-data-breach-after-phishing-attack/


4.ÐÂÀÕË÷ÍÅ»ïBlackMatter³Æ½öÕë¶ÔÄêÊÕÈë1ÒÚÒÔÉϹ«Ë¾


4.jpg


Recorded Future·¢ÏÖÔÚ±¾ÖÜ¿ªÊ¼ÔË×÷µÄÐÂÀÕË÷ÍÅ»ïBlackMatter¡£BlackMatterĿǰÕýÔÚºÚ¿ÍÂÛ̳ExploitºÍXSSÐû²¼µÄ¹ã¸æÕÐļºÏ×÷Õߣ¬²¢ÌåÏÖÄêËûÃǽöÕë¶ÔÊÕÈëΪ1ÒÚÃÀÔª»òÒÔÉϵĹ«Ë¾¡£¸ÃÍÅ»ïÉù³ÆÆä½áºÏÁËDarksideºÍREviµÄÓÅÊÆ£¬²¢ÒªÇóºÏ»ïÈ˵ÄÍøÂçÐèÒªÓµÓÐ500µ½15000̨Ö÷»ú£¬ÇÒλÓÚÃÀ¹ú¡¢Ó¢¹ú¡¢¼ÓÄôó»ò°Ä´óÀûÑÇ¡£´ËÍ⣬¸ÃÍÅ»ïÒ²ÔËÓªÁËÒ»¸öÊý¾ÝÐ¹Â¶ÍøÕ¾£¬µ«ÊǸÃÍøÕ¾Ä¿Ç°ÊǿյÄ¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/blackmatter-ransomware-targets-companies-with-revenues-of-100-million-and-more/


5.ÄÏ·ÇÎïÁ÷¹«Ë¾Transnet SOCÔâµ½ÀÕË÷¹¥»÷ÔÝʱͣÔË


5.jpg


ÄÏ·ÇÎïÁ÷¹«Ë¾Transnet SOCÔâµ½ÀÕË÷¹¥»÷£¬ÆäËùÓпڰ¶ÂëÍ·ÔÝʱͣÔË¡£¹¥»÷·¢ÉúÔÚ7ÔÂ22ÈÕÐÇÆÚËÄ£¬·¢Éú¹¥»÷ºó¸Ã¹«Ë¾Á¢¼´¶ÔʼþÕ¹¿ªÊӲ죬²¢½¨ÒéÆäÔ±¹¤ÔÝͣʹÓõç×ÓÓʼþ£¬ÒÔ·À¹¥»÷µÄÂûÑÓ¡£Transnet͸¶£¬¿¨³µÔËÊäʹÓõÄNavisϵͳÊܵ½Ó°Ï죬Ŀǰ½ø³ö¿Ú°¶µÄ´¬Ö»ÐèÒªÓÉÈ˹¤¼Ç¼£¬¶øÇÒTransnet SOC LtdµÄÍøÕ¾Ò²ÒѾ­¹Ø±Õ¡£Ä¿Ç°ÉÐδ͸¶ÀÕË÷Èí¼þµÄÀàÐÍ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/120596/cyber-crime/transnet-soc-cyber-attack.html


6.CleafyÅû¶ÐÂAndroid½©Ê¬ÍøÂçUBELÓëOscorpÓйØ


6.jpg


Òâ´óÀûÄþ¾²¹«Ë¾CleafyÅû¶ÐµÄAndroid½©Ê¬ÍøÂçUBELÓëOscorpÓйØ¡£Ñо¿ÈËÔ±ÔÚ2021Äê5ÔÂÖÁ6ÔÂÆÚ¼ä£¬ÔÚÒ°Íâ·¢ÏÖÁËеÄOscorpÑù±¾£¬Óë´Ëͬʱ£¬Ò»¸öÃûΪUBELµÄÐÂÐÍAndroid½©Ê¬ÍøÂ翪ʼÔÚºÚ¿ÍÂÛ̳ÉÏÐû´«¡£Í¨¹ý·ÖÎö£¬·¢ÏÖOscorpºÍUBEL¿ÉÒÔÁ´½Óµ½Í¬Ò»¸ö¶ñÒâ´úÂë¿â£¬±íÃ÷ËüÃÇÊôÓÚͬһÏîÄ¿µÄ·ÖÖ§»òÆäËüºÏ»ïÈ˵ÄÖØÐÂÃüÃû¡£UBEL¾ßÓжÁÈ¡ºÍ·¢ËÍSMSÏûÏ¢¡¢Â¼ÖÆÒôƵ¡¢°²×°ºÍɾ³ýÓ¦Óá¢×Ô¶¯Æô¶¯µÈ¹¦Ð§¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/07/ubel-is-new-oscorp-android-credential.html