ÐÂSolarLeaksÍøÕ¾³öÊÛSolarWinds¹©Ó¦Á´¹¥»÷ÖÐÊý¾Ý£»£»£»£»GoogleÅû¶Õë¶ÔWindowsºÍAndroidµÄË®¿Ó¹¥»÷
Ðû²¼Ê±¼ä 2021-01-14
ÐÂSolarLeaksÍøÕ¾³öÊÛSolarWinds¹©Ó¦Á´¹¥»÷ÖÐMicrosoft¡¢Cisco¡¢FireEyeºÍSolarWindsµÈ¹«Ë¾µÄʧÔôÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¸ÃÍøÕ¾ÒÔ60ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛMicrosoftÔ´´úÂëºÍ´æ´¢¿â£¬£¬£¬ÒÔ5ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛFireEyeµÄÔ´´úÂëºÍºì¶Ó¹¤¾ß£¬£¬£¬ÒÔ25ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛSolarWindsÔ´´úÂëºÍ¿Í»§ÃÅ»§£¬£¬£¬²¢ÒÔ100ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛËùÓÐй¶Êý¾Ý¡£¡£¡£¡£¡£¡£¡£solarleaks.netÓòÊÇͨ¹ý¶íÂÞ˹Fancy BearºÍCozy BearʹÓõÄÒÑ֪ע²áÉÌNJALLA¾ÙÐÐ×¢²á¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/solarleaks-site-claims-to-sell-data-stolen-in-solarwinds-attacks/
2.MimecastÔâµ½¹¥»÷£¬£¬£¬Microsoft 365 SSLÖ¤Êéй¶

µç×ÓÓʼþÇå¾²¹«Ë¾MimecastÔâµ½¹¥»÷µ¼ÖÂMicrosoft 365 SSLÖ¤Êéй¶£¬£¬£¬Ó°ÏìÁËÔ¼10%µÄÓû§¡£¡£¡£¡£¡£¡£¡£Mimecast³ÆÆäÒѾ½¨ÒéʹÓô˻ùÓÚÖ¤ÊéµÄÅþÁ¬µÄMimecast¿Í»§Á¬Ã¦É¾³ýÏÖÓÐÅþÁ¬£¬£¬£¬²¢Ê¹Óøù«Ë¾ÌṩµÄÐÂÖ¤ÊéÀ´ÖØÐ½¨Éè»ùÓÚÖ¤ÊéµÄÅþÁ¬¡£¡£¡£¡£¡£¡£¡£MimecastûÓÐÖ¸³ö±»ÇÔÈ¡µÄÖ¤ÊéÀàÐÍ£¬£¬£¬µ«Æ¾Ö¤ÉùÃ÷¿ÉÍÆ²âΪMimecastÓû§ÅþÁ¬Microsoft 365µÄ×Ô½ÒÏþµÄÖ¤ÊéÖ®Ò»£¬£¬£¬¿É±»ÓÃÓÚÖÐÐÄÈË£¨MiTM£©¹¥»÷¡£¡£¡£¡£¡£¡£¡£Mimecast³Æ´ËÊ»¹ÔÚÊÓ²ìÖС£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/mimecast-discloses-microsoft-365-ssl-certificate-compromise/
3.GoogleÅû¶Õë¶ÔWindowsºÍAndroidÓû§µÄË®¿Ó¹¥»÷

Google Project ZeroÅû¶ÁË2020ÄêµÚÒ»¼¾¶ÈÖÐʹÓÃÁ˶à¸ö0dayºÍndayµÄË®¿Ó¹¥»÷¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷»î¶¯Ê¹ÓÃÁËÁ½Ì¨Îó²îʹÓÃЧÀÍÆ÷£¬£¬£¬Ò»Ì¨Õë¶ÔWindowsÓû§£¬£¬£¬Áíһ̨Õë¶ÔAndroidÓû§¡£¡£¡£¡£¡£¡£¡£¸ÃЧÀÍÆ÷ʹÓÃÁËGoogle ChromeÖеÄËĸöäÖȾÆ÷µÄÎó²î£¬£¬£¬WindowsÖеÄÁ½¸öɳºÐÌÓ±ÜÎó²î£¬£¬£¬ÉÐÓÐÒ»¸öÕë¶Ô½Ï¾É°æ±¾µÄAndroid OSÌáȨ¹¤¾ß°ü¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷Á´ÖÐʹÓõÄ0day°üÀ¨Chrome TurboFanÖеÄÎó²î£¨CVE-2020-6418£©¡¢WindowsÉϵÄ×ÖÌåÎó²î£¨CVE-2020-0938£©¡¢WindowsÉϵÄ×ÖÌåÎó²î£¨CVE-2020-1020£©ºÍWindows CSRSSÎó²î£¨CVE-2020-1027£©¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/113342/hacking/project-zero-watering-hole-attack.html
4.SophosÅû¶Õë¶Ô°Í»ù˹̹°²×¿Óû§µÄÌØ¹¤Èí¼þ»î¶¯

SophosÑо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öеÄÌØ¹¤Èí¼þ»î¶¯£¬£¬£¬ÆäÖ÷ҪĿµÄÊǰͻù˹̹µÄAndroidÓû§¡£¡£¡£¡£¡£¡£¡£ÕâÐ©ÌØ¹¤Èí¼þαװ³ÉÁ˰ͻù˹̹ʢÐеÄÓ¦Ó㬣¬£¬Èç°Í»ù˹̹¹«ÃñÃÅ»§¡¢×¢²áSIMs¼ì²é³ÌÐò¡¢°Í»ù˹̹µÚÈý·½ÎïÁ÷°ü¹ÜÓ¦ÓÃºÍÆíµ»Ê±¼äÓ¦Óõȣ¬£¬£¬Ö÷ҪĿµÄΪ¼àÊÓºÍй¶ÊÜѬȾװ±¸ÖеÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬Î±ÔìµÄ°Í»ù˹̹¹«ÃñÃÅ»§ÍøÓ¦Óûá͵ȡÓû§µÄÉí·ÝÖ¤¡¢»¤ÕÕÊý¾Ý¡¢FacebookºÍÆäËûÉ罻ýÌåÕÊ»§µÄƾ֤¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/pakistan-android-users-spyware-campaign-malicious-apps/
5.¶à¹ú¾¯·½ÁªºÏµ·»Ù°µÍøÉÏ×î´óµÄºÚÊÐDarkMarket

°Ä´óÀûÑÇ¡¢µ¤Â󡢵¹ú¡¢Ä¦¶û¶àÍß¡¢ÈðÊ¿¡¢ÎÚ¿ËÀ¼¡¢Ó¢¹úºÍÃÀ¹úµÄ¾¯·½ÁªºÏµ·»ÙÁ˰µÍøÉÏ×î´óµÄºÚÊÐDarkMarket¡£¡£¡£¡£¡£¡£¡£DarkMarketÓµÓнü50ÍòÓû§ºÍ2400¶à¼ÒÉÌ»§£¬£¬£¬¾ÙÐÐÁËÖÁÉÙ32Íò±ÊÉúÒ⣬£¬£¬Éæ¼°4650¶à¸ö±ÈÌØ±ÒºÍ12800¸ömonero£¨×ܽð¶îÁè¼Ý1.7ÒÚÃÀÔª£©¡£¡£¡£¡£¡£¡£¡£µÂ¹ú¾¯·½ÓÚÖÜÄ©Ôڵ¹úÓ뵤ÂóÁìÍÁ¾Ð²¶ÁËÒ»Ãû34ËêµÄ°Ä´óÀûÑǹ«Ãñ£¬£¬£¬Îª°µÍøµÄı»®Õߣ¬£¬£¬²¢ÔÚĦ¶û¶àÍߺÍÎÚ¿ËÀ¼½É»ñÁËÆäʹÓõÄ20¶ą̀ЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬ÊÓ²ìÈÔÔÚ¾ÙÐÐÖС£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/darkmarket-taken-down/
6.AdobeÐû²¼Çå¾²¸üУ¬£¬£¬ÐÞ¸´¶à¿î²úÆ·ÖеÄ7¸öÎó²î

AdobeÐû²¼Çå¾²¸üУ¬£¬£¬ÐÞ¸´ÁËPhotoshop¡¢IllustratorºÍAdobe BridgeµÈ¶à¿îÓ¦ÓÃÖеÄ7¸öÎó²î¡£¡£¡£¡£¡£¡£¡£ÆäÖÐ×îÑÏÖØµÄΪAdobe Campaign ClassicÖеÄЧÀÍÆ÷¶ËÇëÇóαÔìÎó²î£¨CVE-2021-21009£©¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬»¹ÐÞ¸´ÁËPhotoshopÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2021-21006£©¡¢IllustratorÖв»ÊܿصÄËÑË÷·¾¶ÔªËØÎó²î£¨CVE-2021-21007£©¡¢Adobe BridgeÖеÄÔ½½çдÈëÎó²îCVE-2021-21012ºÍCVE-2021-21013£©µÈ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/adobe-critical-flaws-flash-player/162958/


¾©¹«Íø°²±¸11010802024551ºÅ