SAM·¢ÏÖMiraiÀûÓÃRealtek SDKÖЩ¶´µÄ¹¥»÷»î¶¯:ºÚ¿ÍÉù³ÆÒÑÇÔÈ¡ÒÁÀʼàÓüÊý°ÙGBµÄ¼à¿ØÊý¾Ý
Ðû²¼Ê±¼ä 2021-08-26SAM·¢ÏÖMiraiÀûÓÃRealtek SDKÖЩ¶´µÄ¹¥»÷»î¶¯
Äþ¾²¹«Ë¾SAM SeamlessÓÚ8ÔÂ19ÈÕ³ÆÆä·¢ÏÖÁ˽©Ê¬ÍøÂçMiraiÀûÓÃRealtek SDKÖЩ¶´µÄ¹¥»÷»î¶¯¡£¸Ã©¶´ÎªÉí·ÝÑéÖ¤ÈÆ¹ý©¶´£¬×·×ÙΪCVE-2021-20090£¬ÆÀ·ÖΪ9.8·Ö£¬RealtekÒÑÓÚ8ÔÂ13ÈÕÐû²¼¸Ã©¶´µÄ²¹¶¡·¨Ê½¡£SAMÌåÏÖ£¬ËûÃÇÓÚ8ÔÂ18ÈÕÔÚÒ°·¢ÏÖÁ˴˴Ω¶´ÀûÓû£¬¹¥»÷Ô´ÓÚ31.210.20[.]100£¬µ«¹¥»÷ÕßµÄIPµØÖ·¿ÉÄÜ»áËæ×Åʱ¼ä¶ø¸Ä±ä¡£
ÔÎÄÁ´½Ó£º
https://securingsam.com/realtek-vulnerabilities-weaponized/
OpenSSLÐû²¼Äþ¾²¸üУ¬ÐÞ¸´²úÎïÖеÄ2¸öÄþ¾²Â©¶´
OpenSSLÓÚ8ÔÂ24ÈÕÐû²¼Äþ¾²¸üУ¬ÐÞ¸´Æä²úÎïÖеÄ2¸öÄþ¾²Â©¶´¡£ÆäÖÐ×îΪÑÏÖØµÄÊÇ»º³åÇøÒç³ö©¶´£¬×·×ÙΪCVE-2021-3711£¬¹¥»÷ÕßÀûÓÃÆä¿Éµ¼ÖÂÓ¦Ó÷¨Ê½Í߽⡣¸Ã©¶´ÓëSM2¼ÓÃÜÊý¾ÝµÄ½âÃܹý³ÌÏà¹Ø£¬¿ÉÓÃÀ´¸ü¸Ä¶ÑÖеÄÊý¾Ý£¨¼´Æ¾¾Ý£©¡£´Ë´ÎÐÞ¸´µÄÁíÒ»¸ö©¶´×·×ÙΪCVE-2021-3712£¬¹¥»÷Õß¿ÉÒÔÀûÓøÃ©¶´´¥·¢¾Ü¾ø·þÎñ(DoS)£¬»¹¿ÉÄܵ¼Ö»úÃÜÐÅϢй¶£¬ÀýÈç˽Կ»òÃô¸ÐÃ÷ÎÄ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/121426/hacking/cve-2021-3711-openssl-flaws.html
ºÚ¿ÍÉù³ÆÒÑÇÔÈ¡ÒÁÀʼàÓüµÄ¼à¿ØÏµÍ³ÖÐÊý°ÙGBµÄÊý¾Ý
ºÚ¿ÍÍÅ»ïTapandegan(Palpitations)ÓÚÉϹûÈ»ÁË´óÁ¿ÒÁÀÊEvin¼àÓüÖÐŰ´ýÇô·¸µÄÊÓÆµ¡£ÕâЩÊÓÆµµÄʱ¼ä´ÁΪ2020ÄêºÍ2021Ä꣬°üÂÞEvinµÄ¾¯ÎÀŹ´òÇô·¸¡¢ÊÔͼ×ÔɱµÄÇô·¸»ò»èµ¹²¢±»ÍϹý×ßÀȵÄÇô·¸µÈÄÚÈÝ¡£¸ÃÍÅ»ï³ÆËûÃÇÖ»×ÊÖúÐû´«ÁËÊÓÆµµ«²¢Î´¼ÓÈë¹¥»÷£¬²¢½«´Ë´Î»î¶¯¹é¹¦ÓÚAli's JusticeÍŻ¶ûºóÕßÔòÉù³ÆÆäÔÚ¼¸¸öÔÂǰ¾ÍÈëÇÖÁ˼àÓüµÄ¼à¿ØÏµÍ³£¬²¢ÇÔÈ¡ÁËÊý°ÙGBµÄÊý¾Ý¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/hackers-leak-footage-of-iranian/
ŵ»ùÑÇ×Ó¹«Ë¾SAC Wireless³ÆÆäÔâµ½ContiÀÕË÷¹¥»÷
λÓÚÃÀ¹úµÄŵ»ùÑÇ×Ó¹«Ë¾SAC WirelessÔÚ6ÔÂ16ÈÕ·¢ÏÖÆäÔâµ½ÁËContiÀÕË÷¹¥»÷£¬¹¥»÷ÕßÖ»Êǰ²×°ÁËpayload²¢¼ÓÃÜÁËSACÎÞÏßϵͳ¡£µ«ÊÇÔÚÖ®ºóµÄȡ֤ÊÓ²ìÖУ¬ÓÚ8ÔÂ13ÈÕ·¢ÏÖÆäÏÖÔ±¹¤ºÍǰԱ¹¤µÄ¸öÈËÐÅÏ¢Ò²Òѱ»ÇÔ¡£¸Ã¹«Ë¾¾Ü¾øÍ¸Â¶¸ü¶àÓйش˴ι¥»÷µÄÐÅÏ¢£¬µ«ContiÍÅ»ïÔÚËûÃǵÄÊý¾ÝÐ¹Â¶ÍøÕ¾ÉÏ͸¶£¬ÒѾ»ñµÃÁËÁè¼Ý250 GBµÄÊý¾Ý¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/nokia-subsidiary-discloses-data-breach-after-conti-ransomware-attack/
FBIÐû²¼OnePercent Group¹¥»÷»î¶¯µÄTTPºÍ»º½â´ëÊ©
FBIÐû²¼ÁËÓйØOnePercent GroupµÄ¹¥»÷»î¶¯µÄTTPºÍ»º½â´ëÊ©£¬²¢³Æ¸ÃÍÅ»ïÖÁÉÙ×Ô2020Äê11ÔÂÒÔÀ´Ò»Ö±ÔÚÕë¶ÔÃÀ¹úµÄ×éÖ¯½øÐÐÀÕË÷Èí¼þ¹¥»÷¡£¸Ã»ú¹¹³Æ¹¥»÷ÕßÊ×ÏÈʹÓõöÓã¹¥»÷£¬ÔÚÄ¿±êϵͳÉϰ²×°ÒøÐÐľÂíIcedID²¢ÏÂÔØCobalt Strike£¬È»ºó½øÐмÓÃܻ¡£FBIûÓÐÌṩ¹¥»÷»ò¼ÓÃÜÆ÷µÄÏêϸÐÅÏ¢£¬µ«³ÆÆäÓëREvilÓйء£Ñо¿ÈËÔ±ÍÆ¶Ï£¬Æä¿ÉÄÜÊÇREvilµÄcartelÁªÃËÖеĺÏ×÷»ï°é¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/fbi-onepercent-group-ransomware-targeted-us-orgs-since-nov-2020/
Trend MicroÐû²¼2021 H1 LinuxÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß
Trend MicroÐû²¼ÁË2021 H1 LinuxÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬ÔÚ2021ÄêÉϰëÄêÑо¿ÈËÔ±×ܼÆÍ³¼ÆÁ˽ü1500Íò¸öÕë¶ÔLinuxµÄÄþ¾²Ê¼þ£¬²¢·¢ÏÖÍÚ¿óÈí¼þºÍÀÕË÷Èí¼þÕ¼ËùÓжñÒâÈí¼þµÄ36.11%£¬Web shellÕ¼19.92%¡£ÔÚÒ°·¢ÏֵĹ¥»÷»î¶¯ÖÐÀûÓÃ×î¶àµÄ©¶´°üÂÞApache Struts 2ÖеÄRCE©¶´£¨CVE-2017-5638£©¡¢Apache Struts 2 REST plugin XStreamÖеÄRCE©¶´£¨CVE-2017-9805£©£¬ÒÔ¼°Drupal CoreÖеÄRCE©¶´£¨CVE-2018-7600£©µÈ¡£
ÔÎÄÁ´½Ó£º
https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/linux-threat-report-2021-1h-linux-threats-in-the-cloud-and-security-recommendations