MicrosoftÐû²¼5Ô²¹¶¡ £¬ £¬£¬ £¬£¬£¬£¬£¬ÐÞ¸´3¸ö0dayÔÚÄÚµÄ55¸öÎó²î£»£»£» £»£»£»ÃÀ¹úºÍ°Ä´óÀûÑÇÖÒÑÔÕë¶ÔÈ«ÇòµÄAvaddonÀÕË÷Èí¼þ»î¶¯

Ðû²¼Ê±¼ä 2021-05-12

1.MicrosoftÐû²¼5Ô²¹¶¡ £¬ £¬£¬ £¬£¬£¬£¬£¬ÐÞ¸´3¸ö0dayÔÚÄÚµÄ55¸öÎó²î


1.jpg


MicrosoftÐû²¼5Ô·ݵÄÖܶþ²¹¶¡ £¬ £¬£¬ £¬£¬£¬£¬£¬ÐÞ¸´°üÀ¨3¸ö0dayÔÚÄÚµÄ55¸öÎó²î¡£ ¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄ0 day»®·ÖÊÇNETºÍVisual StudioÖеÄÌáȨÎó²î£¨CVE-2021-31204£©¡¢Microsoft Exchange ServerÖеÄÇå¾²¹¦Ð§ÈƹýÎó²î£¨CVE-2021-31207£©ºÍͨÓù¤¾ßÖеÄÔ¶³ÌÖ´ÐдúÂëÎó²î£¨CVE-2021-31200£© £¬ £¬£¬ £¬£¬£¬£¬£¬ÕâЩÎó²î»¹Î´±»ÔÚҰʹÓᣠ¡£¡£¡£¡£±ðµÄ £¬ £¬£¬ £¬£¬£¬£¬£¬»¹ÐÞ¸´ÁËHTTP.sysÖеÄÔ¶³ÌÖ´ÐдúÂëÎó²î£¨CVE-2021-31166£©ºÍIEä¯ÀÀÆ÷ÖеÄÄÚ´æËð»µÎó²î£¨CVE-2021-26419£©µÈÎó²î¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/microsoft-patch-tuesday-55-vulnerabilities-4-critical-3-publicly-known


2.CiscoÅû¶Lemon DuckÕë¶Ô±±ÃÀµØÇøµÄÐÂÒ»ÂÖ¹¥»÷»î¶¯


2.jpg


Cisco TalosÑо¿Ö°Ô±·¢Ã÷Lemon DuckÕë¶Ô±±ÃÀµØÇøµÄÐÂÒ»ÂÖ¹¥»÷»î¶¯¸Ä±äÁ˹¥»÷Õ½ÂÔ¡£ ¡£¡£¡£¡£È¥Äê8Ô £¬ £¬£¬ £¬£¬£¬£¬£¬Lemon DuckÖ÷ÒªÕë¶Ô°£¼°¡¢Ó¡¶È¡¢ÒÁÀÊ¡¢·ÆÂɱöºÍÔ½ÄϾÙÐÐÍÚ¿óµÄ»î¶¯¡£ ¡£¡£¡£¡£ÔÚ4Ô·Ý×îÏȵÄÐÂÒ»ÂÖÖÐ £¬ £¬£¬ £¬£¬£¬£¬£¬¸ÃÍÅ»ï¸Ä±äÁËÄ¿µÄ £¬ £¬£¬ £¬£¬£¬£¬£¬Ö÷ÒªÕë¶Ô±±ÃÀµØÇø £¬ £¬£¬ £¬£¬£¬£¬£¬Æä´ÎÊÇÅ·ÖÞ¡¢¶«ÄÏÑÇ¡¢·ÇÖÞºÍÄÏÃÀ¡£ ¡£¡£¡£¡£Ôڴ˴ι¥»÷»î¶¯ÖÐ £¬ £¬£¬ £¬£¬£¬£¬£¬¸ÃÍÅ»ïʹÓÃÁËCobalt Strike¹¥»÷¿ò¼Ü £¬ £¬£¬ £¬£¬£¬£¬£¬²¢ÔÚ¶«ÑǶ¥¼¶ÓòÃû£¨TLD£©ÉÏʹÓÃαÔìµÄÓòÃûÀ´Òþ²ØÏÂÁîºÍ¿ØÖÆ£¨C2£©»ù´¡¼Ü¹¹ £¬ £¬£¬ £¬£¬£¬£¬£¬Ö¼ÔÚÔöÇ¿·´¼ì²âµÄÄÜÁ¦¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/lemon-duck-cryptojacking-botnet-tactics/165986/


3.ÃÀ¹úºÍ°Ä´óÀûÑÇÖÒÑÔÕë¶ÔÈ«ÇòµÄAvaddonÀÕË÷Èí¼þ»î¶¯


3.jpg


ÃÀ¹úÁª°îÊÓ²ì¾Ö£¨FBI£©ºÍ°Ä´óÀûÑÇÍøÂçÇå¾²ÖÐÐÄ£¨ACSC£©ÖÒÑÔÕë¶ÔÈ«ÇòµÄAvaddonÀÕË÷Èí¼þ¹¥»÷»î¶¯¡£ ¡£¡£¡£¡£FBIÌåÏÖ £¬ £¬£¬ £¬£¬£¬£¬£¬AvaddonÀÕË÷Èí¼þÕýÊÔͼ¹¥»÷È«ÇòµÄÖÆÔì¡¢Ò½ÁƱ£½¡ºÍÆäËûÐÐÒµ×éÖ¯µÄÍøÂç¡£ ¡£¡£¡£¡£ACSCÔòÖ¸³ö¸ÃÍÅ»ïÖ÷ÒªÕë¶ÔÕþ¸®¡¢½ðÈÚ¡¢Ö´·¨¡¢ÄÜÔ´¡¢ÐÅÏ¢ÊÖÒÕºÍÎÀÉúµÈÐÐÒµ £¬ £¬£¬ £¬£¬£¬£¬£¬²¢ÁгöÁËÊܵ½¹¥»÷µÄ¹ú¼ÒµÄÇåµ¥ £¬ £¬£¬ £¬£¬£¬£¬£¬°üÀ¨ÃÀ¹ú¡¢Ó¢¹ú¡¢µÂ¹ú¡¢Öйú¡¢°ÍÎ÷¡¢Ó¡¶È¡¢°¢ÁªÇõ¡¢·¨¹úºÍÎ÷°àÑÀµÈ¡£ ¡£¡£¡£¡£±ðµÄ £¬ £¬£¬ £¬£¬£¬£¬£¬ACSC³ÆAvaddonÖ÷ҪʹÓþܾøÐ§ÀÍ£¨DDoS£©¹¥»÷À´ÍþвÊܺ¦Õß £¬ £¬£¬ £¬£¬£¬£¬£¬µ«FBIÌåÏÖÉÐδ·¢Ã÷ÓйØAvaddonÍŻ﷢¶¯DDoS¹¥»÷µÄÖ¤¾Ý¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/117765/malware/avaddon-targets-orgs-worldwide.html


4.Cleafy·¢Ã÷¶ñÒâÈí¼þTeaBotÒѹ¥»÷Å·ÖÞµÄ60¶à¼ÒÒøÐÐ


4.jpg


Òâ´óÀûCleafyµÄÇå¾²ÍŶӷ¢Ã÷¶ñÒâÈí¼þTeaBotÒѹ¥»÷Å·ÖÞµÄ60¶à¼ÒÒøÐС£ ¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÈÔ´¦ÓÚ¿ª·¢µÄÔçÆÚ½×¶Î £¬ £¬£¬ £¬£¬£¬£¬£¬µ«¾ß±¸Ô¶³Ì¿ØÖÆÄ¿µÄ×°±¸¡¢ÇÔÈ¡µÇ¼ƾ֤¡¢·¢ËͺÍ×èµ²SMSÐÂÎŵȹ¦Ð§¡£ ¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÖ§³Ö6ÖÖ²î±ðµÄÓïÑÔ £¬ £¬£¬ £¬£¬£¬£¬£¬°üÀ¨µÂÓï¡¢Ó¢Óï¡¢Òâ´óÀûÓï¡¢·¨Óï¡¢Î÷°àÑÀÓïºÍºÉÀ¼Óï¡£ ¡£¡£¡£¡£µ½ÏÖÔÚΪֹ £¬ £¬£¬ £¬£¬£¬£¬£¬CleafyÒÑÈ·¶¨Òâ´óÀû¡¢Î÷°àÑÀ¡¢µÂ¹ú¡¢±ÈÀûʱºÍºÉÀ¼µÈ¶à¸öÅ·ÖÞ¹ú¼ÒµÄ60¶à¼ÒÒøÐÐÔâµ½Á˹¥»÷¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/teabot-android-malware-steals-data-sms/


5.Office 365¸ôÀëÀ´×ÔGoogleºÍLinkedInµÈÓòµÄÕýµ±Óʼþ


5.jpg


΢ÈíÔÚMicrosoft 365ÖÎÀíÖÐÐÄÌåÏÖ £¬ £¬£¬ £¬£¬£¬£¬£¬Ä³Ð©Óû§µÄOffice 365µÄExchange Online Protection£¦Defender»áδÀ´×Ô¶à¸öÓò£¨°üÀ¨GoogleºÍLinkedIn£©µÄÕýµ±µç×ÓÓʼþ¸ôÀë»ò±ê¼ÇΪ¶ñÒâµç×ÓÓʼþ¡£ ¡£¡£¡£¡£ÏÖÔÚ £¬ £¬£¬ £¬£¬£¬£¬£¬Î¢ÈíÒѽâ¾öÁ˸ÃÎÊÌâ²¢ÖØÐ·¢Ëͱ»¸ôÀëµÄÓʼþ¡£ ¡£¡£¡£¡£±ðµÄ £¬ £¬£¬ £¬£¬£¬£¬£¬Î¢Èí11ÈÕÐû²¼µÄOutlook¸üе¼ÖÂÈ«Çò¹æÄ£ÄÚµÄÓû§ÎÞ·¨Éó²é»ò½¨Éèµç×ÓÓʼþ £¬ £¬£¬ £¬£¬£¬£¬£¬ÌØÊâÊÇÔÚ½¨ÉèÐÂÓʼþʱ £¬ £¬£¬ £¬£¬£¬£¬£¬Ã¿´Î°´Enter¼ü £¬ £¬£¬ £¬£¬£¬£¬£¬ÏÈǰ±àдµÄËùÓÐÄÚÈݶ¼½«±»É¾³ý¡£ ¡£¡£¡£¡£Î¢Èí½¨ÒéÓû§»Ø¹öµ½4Ôµİ汾 £¬ £¬£¬ £¬£¬£¬£¬£¬»òÔÚÇ徲ģʽÏÂÆô¶¯Outlook¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-office-365-is-blocking-emails-from-google-linkedin-domains/


6.NatWestÒøÐÐ֪ͨ¿Í»§Òòϵͳ¹ýʧ £¬ £¬£¬ £¬£¬£¬£¬£¬×Ô¶¯¿Û¿î¿ÉÄÜÍÉ»¯


6.jpg


Ó¢¹úNatWestÒøÐÐ֪ͨ¿Í»§Òòϵͳ¹ýʧ £¬ £¬£¬ £¬£¬£¬£¬£¬×Ô¶¯¿Û¿î¿ÉÄÜÍÉ»¯¡£ ¡£¡£¡£¡£Ó¢¹úÒøÐпͻ§Í¨³£Ê¹ÓÃÀο¿¶©µ¥À´Ö§¸¶Õ˵¥¡¢×â½ðºÍÆä°´ÆÚ¸¶¿î¡£ ¡£¡£¡£¡£Í¨Àý¶©µ¥°üÀ¨¸¶¿î½ð¶î¡¢¸¶¿îƵÂÊ£¨¼´Ã¿ÖÜ¡¢Ã¿Ô¡¢Ã¿¼¾¶ÈµÈ£©ÒÔ¼°¸¶¿îÓ¦ÔÚºÎʱ¿¢Ê¡£ ¡£¡£¡£¡£´Ë´Îϵͳ¹ÊÕϵ¼Ö¿ͻ§ËùÉèÖõÄͨÀý¶©µ¥Ã»ÓÐ׼ȷµØ¼Í¼×Ô¶¯¸¶¿îµÄÆÚÊý»ò×èÖ¹¸¶¿îÈÕÆÚ £¬ £¬£¬ £¬£¬£¬£¬£¬ÕâÒâζ×Ŷ©µ¥¿¢ÊºóÈÔ¿ÉÄÜÔÚ¿Í»§ÕË»§ÖÐ×Ô¶¯¿Û¿î¡£ ¡£¡£¡£¡£ÓÉÓÚ¹ýʧÒÑÒ»Á¬ÁË11¸öÔÂÒÔÉÏ £¬ £¬£¬ £¬£¬£¬£¬£¬Òò´Ë¸ÃÐн¨Òé¿Í»§¼ì²éÆäÕË»§ÖÐ×Ô2020Äê3ÔÂ23ÈÕÒÔÀ´ÉúÒâµÄ¿î×Ó¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/technology/natwest-bank-scheduled-payments-bug-may-have-cost-you-money/