È«ÇòÖ´·¨²¿·ÖÁªºÏÆÆ»ñEmotet½©Ê¬ÍøÂçµÄ»ù´¡ÉèÊ©£» £»£» £»£» £»£»SudoÎó²îBaronSameditÎÞÐèÃÜÂë¿ÉÌáȨÖÁrootȨÏÞ

Ðû²¼Ê±¼ä 2021-01-28

1.SudoÎó²îBaronSameditÎÞÐèÃÜÂë¿ÉÌáȨÖÁrootȨÏÞ


1.jpg


Çå¾²É󼯹«Ë¾Qualys·¢Ã÷SudoÎó²îBaronSameditÎÞÐèÃÜÂë¿ÉÌáȨÖÁrootȨÏÞ£¬£¬£¬£¬£¬£¬ÒÑÓнüÊ®ÄêµÄÀúÊ·¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÓÉÓÚsudo¹ýʧµØÔÚ²ÎÊýÖÐתÒåÁË·´Ð±¸Üµ¼Ö»ùÓڶѵĻº³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬±»×·×ÙΪCVE-2021-3156£¬£¬£¬£¬£¬£¬ÔÊÐíÈκÎÍâµØÓû§£¨ÎÞÂÛÊÇ·ñÔÚsudoersÎļþÖУ©ÎÞÐè¾ÙÐÐÉí·ÝÑéÖ¤»ñµÃrootȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£ÔÚÒÑÍùÁ½ÄêÖз¢Ã÷ÁËÁíÍâÁ½¸öSudoÎó²î£¨CVE-2019-14287ºÍCVE-2019-18634£©£¬£¬£¬£¬£¬£¬¿ÉÊÇ´Ë´ÎÅû¶µÄÎó²îÊÇÈýÆäÖÐ×îΣÏÕµÄÒ»¸ö¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/10-years-old-sudo-bug-lets-linux-users-gain-root-level-access/


2.MicrosoftÐû²¼Î¢Âë¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´¶à¿îIntel CPUÖеÄÎó²î


2.png


MicrosoftÕë¶ÔWindows 10 20H2¡¢ 2004¡¢ 1909ÒÔ¼°¸üÀϵİ汾Ðû²¼ÁË΢Âë¸üУ¬£¬£¬£¬£¬£¬ÒÔÐÞ¸´Ó°Ïì¶à¸öIntel CPUϵÁеÄÎó²î¡£¡£¡£¡£¡£¡£¡£¡£Î¢Âë²¹¶¡¾­³£±»ÓÃÓÚÐÞ¸´Ó²¼þÇå¾²Îó²î£¬£¬£¬£¬£¬£¬ÈçSpectre¡¢Meltdown¡¢Î¢¼Ü¹¹Êý¾Ý²ÉÑù(MDS)ºÍPlatypusÎó²î¡£¡£¡£¡£¡£¡£¡£¡£´Ë´Î΢Âë¸üÐÂÐÂÔöÁËÆß¸öCPUϵÁУ¬£¬£¬£¬£¬£¬°üÀ¨µÚÊ®´úÓ¢ÌØ¶û¿á¦Öóͷ£Æ÷¼Ò×å¡¢åçÐǺþS£¨6+2£©¡¢åçÐǺþS£¨10+2£©¡¢U62åçÐǺþ¡¢U6+2åçÐǺþ¡¢±ùºþY42/U42 ES2 SUPºÍLakefield¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-new-windows-10-intel-cpu-microcode-updates/


3.GoogleÐÞ¸´Golang WindowsÖеĴúÂëÖ´ÐÐÎó²î


3.png


Google¹¤³ÌʦÐÞ¸´ÁËGolang WindowsÖеĴúÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î±»×·×ÙΪCVE-2021-3115£¬£¬£¬£¬£¬£¬ÊÇÓÉÓÚÓû§ÔËÐÐgo getÏÂÁî»ñÈ¡´æ´¢¿âʱ±àÒëÀú³ÌµÄÊÂÇé·½·¨Ëùµ¼ÖµÄ¡£¡£¡£¡£¡£¡£¡£¡£GoµÄexec.Commandº¯ÊýŲÓÃGCC±àÒëÆ÷ʱ¿ÉÄÜ»áÆô¶¯¹¥»÷ÕßÒþ²ØÔÚÆäÓ¦ÓóÌÐòÔ´ÖеĶñÒâgcc.exe£¬£¬£¬£¬£¬£¬¶ø·ÇÕýµ±µÄGCC±àÒëÆ÷¡£¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬´Ë´Î¸üл¹ÐÞ¸´Á˼ÓÃÜÎó²î£¨CVE-2021-3114£©£¬£¬£¬£¬£¬£¬ÒÔ¼° CVE-2021-3114ºÍCVE-2021-3115Îó²î¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/google-fixes-severe-golang-windows-rce-vulnerability/


4.VIPGamesÒòЧÀÍÆ÷ÉèÖùýʧй¶2300ÍòÌõÓû§¼Í¼


4.png


WizCase·¢Ã÷VIPGamesÒòЧÀÍÆ÷ÉèÖùýʧй¶ÁË66000¸öÓû§µÄ2300ÍòÌõ¼Í¼¡£¡£¡£¡£¡£¡£¡£¡£VIPGames.comÊÇÒ»¸öÃâ·ÑµÄÓÎϷƽ̨£¬£¬£¬£¬£¬£¬ÌṩHearts¡¢Crazy ThreesºÍEuchreµÈ56ÖÖ¾­µäÆåÅÌÓÎÏ·¡£¡£¡£¡£¡£¡£¡£¡£´Ë´Îй¶ÁËÁè¼Ý30GBµÄÊý¾Ý£¬£¬£¬£¬£¬£¬°üÀ¨Óû§Ãû¡¢µç×ÓÓʼþ¡¢IPµØµã¡¢¹þÏ£ÃÜÂë¡¢Facebook¡¢TwitterºÍGoogle ID¡¢¶Ä×¢µÈ¡£¡£¡£¡£¡£¡£¡£¡£WizCase³ÆÐ¹Â¶ÐÅÏ¢¿É±»ÓÃÓÚÉí·Ý͵ÇÔ¡¢ÃÜÂëй¶¡¢ÍøÂç´¹ÂÚÕ©Æ­¡¢¶ñÒâÈí¼þÒÔ¼°Ç±ÔÚµÄÀÕË÷£¬£¬£¬£¬£¬£¬VIPGames.comÉÐδ¶Ô´ËÊÂ×ö³ö»ØÓ¦¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/gamer-records-exposed-vipgames-leak/163352/


5.ÁãÊÛÉÌDairy FarmѬȾREvil£¬£¬£¬£¬£¬£¬±»ÀÕË÷3000ÍòÃÀÔª


5.png


´óÐÍÁãÊÛÁ¬ËøÔËÓªÉÌDairy FarmѬȾREvil£¬£¬£¬£¬£¬£¬±»ÀÕË÷3000ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚÑÇÖÞÊг¡Ä±»®Ö򦈮ၮ£¬£¬£¬£¬£¬£¬ÈçWellcome¡¢Giant¡¢Hero¡¢7-11ºÍÒ˼ҵÈ¡£¡£¡£¡£¡£¡£¡£¡£REvilÀÕË÷Èí¼þÍÅ»ï³ÆÆäÒÑÔÚ2021Äê1ÔÂ14ÈÕ×óÓÒ¹¥»÷ÁËDairy Farm GroupµÄÍøÂç²¢¼ÓÃÜÁËÆä×°±¸£¬£¬£¬£¬£¬£¬Êê½ðÒªÇóΪ3000ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£¡£ÎªÁË֤ʵ¹¥»÷Àֳɣ¬£¬£¬£¬£¬£¬ºÚ¿Í·ÖÏíÁËActive DirectoryÓû§ºÍÅÌËã»úMMCµÄÆÁÄ»½ØÍ¼¡£¡£¡£¡£¡£¡£¡£¡£ºÚ¿ÍÉù³ÆÈÔÓжԸù«Ë¾ÓʼþµÄÍêÈ«¿ØÖÆÈ¨£¬£¬£¬£¬£¬£¬²¢»á½«ÕâЩÓʼþÓÃÓÚÍøÂç´¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£Dairy FarmÔòÌåÏÖ£¬£¬£¬£¬£¬£¬ÔÚ¹¥»÷Àú³ÌÖÐÓÐÈκÎÊý¾Ý±»µÁ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/pan-asian-retail-giant-dairy-farm-suffers-revil-ransomware-attack/


6.È«ÇòÖ´·¨²¿·ÖÁªºÏÆÆ»ñEmotet½©Ê¬ÍøÂçµÄ»ù´¡ÉèÊ©


6.png


ÓÉÅ·ÖÞÐ̾¯×éÖ¯£¨Europol£©Ïòµ¼µÄÈ«ÇòÖ´·¨Ðж¯ÆÆ»ñÁËÖøÃû½©Ê¬ÍøÂçEmotetµÄ»ù´¡ÉèÊ©¡£¡£¡£¡£¡£¡£¡£¡£EmotetÖÁÉÙ´Ó2014Äê×îÏÈ»îÔ¾£¬£¬£¬£¬£¬£¬ÓëºÚ¿Í×éÖ¯TA542ÓйØ¡£¡£¡£¡£¡£¡£¡£¡£Europol³Æ£¬£¬£¬£¬£¬£¬´Ë´ÎÐж¯±»³ÆÎªOperation Ladybird£¬£¬£¬£¬£¬£¬ÓɺÉÀ¼¡¢µÂ¹ú¡¢ÃÀ¹ú¡¢Ó¢¹ú¡¢·¨¹ú¡¢Á¢ÌÕÍð¡¢¼ÓÄôóºÍÎÚ¿ËÀ¼Õþ¸®ÅäºÏÏàÖú£¬£¬£¬£¬£¬£¬ÆÆËð²¢½ÓÊÜÁËλÓÚ90¶à¸ö¹ú¼ÒµÄEmotetµÄC&C£¬£¬£¬£¬£¬£¬²¢¾Ð²¶Á˶àÁ½ÃûÍøÂç·¸·¨·Ö×Ó¡£¡£¡£¡£¡£¡£¡£¡£¾ÝºÉÀ¼¾¯·½³Æ£¬£¬£¬£¬£¬£¬Emotet×ܼÆÔì³ÉÁËÊýÒÚÃÀÔªµÄËðʧ£¬£¬£¬£¬£¬£¬¶øÎÚ¿ËÀ¼Ö´·¨²¿·ÖËðʧ¶îÔ¤¼ÆÎª25ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/113933/cyber-crime/emotet-global-takedown.html