Google³Æ¶íºÚ¿ÍʹÓÃSafariÖÐ0day¹¥»÷LinkedIn£»£»£»£»SonicWallÖÒÑÔÕë¶ÔSMA100ºÍSRA²úÆ·µÄÀÕË÷¹¥»÷
Ðû²¼Ê±¼ä 2021-07-16
GoogleÇå¾²Ñо¿Ö°Ô±Ðû²¼ÁËÓйØ4¸ö0day±»ÔÚҰʹÓõÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£ÕâЩÎó²î»®·ÖÊÇChromeÖеÄCVE-2021-21166ºÍCVE-2021-30551¡¢Internet ExplorerÖеÄCVE-2021-33742£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°WebKit(Safari)ÖеÄCVE-2021-1879¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬£¬£¬¶íÂÞ˹SVRµÄºÚ¿ÍÍÅ»ïNobeliumʹÓÃSafariÖеÄ0day£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýLinkedIn Messaging·¢ËͶñÒâÁ´½ÓÀ´¹¥»÷Î÷Å·¹ú¼ÒµÄÕþ¸®¹ÙÔ±¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬Google³Æ½ö2021ÄêÉϰëÄê¾ÍÅû¶ÁË33ÆðʹÓÃ0dayµÄ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬±È2020ÄêµÄ×ÜÊý¶àÁË11Æð¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/google-russian-svr-hackers-targeted-linkedin-users-with-safari-zero-day/
2.KasperskyÅû¶LuminousMoth APTÕë¶Ô¶«ÄÏÑǵĹ¥»÷

KasperskyÅû¶ÁËAPT×éÖ¯LuminousMothÕë¶Ô¶«ÄÏÑǵĹ¥»÷»î¶¯¡£¡£¡£¡£¡£¸Ã»î¶¯ÖÁÉÙ¿ÉÒÔ×·Ëݵ½2020Äê10Ô£¬£¬£¬£¬£¬£¬£¬£¬ÔçÆÚµÄ¹¥»÷´ó¶àÔÚÃåµéµ«ÏÖÔÚÖ÷ÒªÔÚ·ÆÂɱö£¬£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚ·¢Ã÷Ãåµé¹²ÓÐ100ÃûÊܺ¦Õß¶ø·ÆÂɱöÓÐ1400Ãû¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ¹¥»÷µÄ¹æÄ£ºÜÊÇÓÐÊý£¬£¬£¬£¬£¬£¬£¬£¬Õâ¿ÉÄÜÊÇÓÉÓÚʹÓÃUSBÇý¶¯Æ÷×÷ΪÈö²¥»úÖÆ¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓôøÓÐDropboxÏÂÔØÁ´½ÓµÄ´¹ÂÚÓʼþ·Ö·¢Î±×°³ÉwordÎĵµµÄrarÎļþ£¬£¬£¬£¬£¬£¬£¬£¬À´×°ÖöñÒâÈí¼þ¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þ»áʹÓÿÉÒÆ¶¯USBÇý¶¯Æ÷´ø×ÅÇÔÈ¡µÄÎļþÒÆ¶¯µ½ÆäËüµÄϵͳÖÐ
ÔÎÄÁ´½Ó£º
https://securelist.com/apt-luminousmoth/103332/
3.Ñо¿ÍŶӷ¢Ã÷·Ö·¢BazarBackdoorµÄÐÂÒ»ÂÖ´¹Âڻ

CofenseÑо¿ÍŶӷ¢Ã÷ÁËÒ»¸öеĴ¹Âڻ£¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÓöàÖØÑ¹ËõÊÖÒÕÀ´·Ö·¢BazarBackdoor¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÁËÒÔ¡°ÇéÐÎÈÕ¡±ÎªÖ÷ÌâµÄÓʼþÀ´ÎüÒýÊܺ¦Õߣ¬£¬£¬£¬£¬£¬£¬£¬Æä¸½¼þÖÐËù¸½µÄZIPºÍRARÎļþ¶¼°üÀ¨ÁËÒ»¸öJavaScriptÎļþ£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÏÂÔØÀ©Õ¹ÃûΪͼÏñµÄpayload¡£¡£¡£¡£¡£Cofense³Æ¹¥»÷ÕßÓÐÒâʹÓöàÖÖÎļþÀàÐÍ£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔµ¼ÖÂÇå¾²µç×ÓÓʼþÍø¹Ø(SEG)µÖ´ï½âѹËõÏÞÖÆ£¬£¬£¬£¬£¬£¬£¬£¬»òÕßÓÉÓÚδ֪µÄ¹éµµÀàÐͶø½âѹʧ°Ü£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øÊ¹¶ñÒâÎļþ¸üÄѱ»¼ì²âµ½¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/bazarbackdoor-sneaks-in-through-nested-rar-and-zip-archives/
4.CyberArkÅû¶Windows HelloÖпÉÈÆ¹ýÉí·ÝÑéÖ¤µÄÎó²î

CyberArk LabsµÄÑо¿Ö°Ô±Åû¶ÁËWindows HelloÖпÉÈÆ¹ýÉí·ÝÑéÖ¤µÄÎó²î¡£¡£¡£¡£¡£Windows HelloÊÇWin10ÖеÄÒ»ÏЧ£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÓû§ÔÚûÓÐÃÜÂëµÄÇéÐÎÏÂʹÓÃPINÂë»òÉúÎïʶ±ðÉí·Ý¾ÙÐÐÑéÖ¤ÒÔ»á¼û×°±¸£¬£¬£¬£¬£¬£¬£¬£¬Ô¼85%µÄWin10Óû§Ê¹Óøù¦Ð§¡£¡£¡£¡£¡£¸ÃÎó²î×·×ÙΪCVE-2021-34466£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ²¶»ñ»òÖØÐÞÄ¿µÄµÄÃæ²¿ÕÕÆ¬£¬£¬£¬£¬£¬£¬£¬£¬È»ºó²åÈëÌØÖÆµÄUSB×°±¸½«Î±ÔìµÄͼÏñ×¢ÈëÉí·ÝÑéÖ¤Ö÷»ú£¬£¬£¬£¬£¬£¬£¬£¬À´ÈƹýÉí·ÝÑé֤ϵͳ¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÒѱ»ÐÞ¸´¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/windows-hello-bypass-biometrics-pcs/167771/
5.Cisco TalosÅû¶D-LINK DIR-3040·ÓÉÆ÷Öжà¸öÎó²î

Cisco TalosÅû¶D-LINK DIR-3040ÎÞÏß·ÓÉÆ÷ÖеĶà¸öÎó²î¡£¡£¡£¡£¡£´Ë´Î·¢Ã÷µÄÎó²î°üÀ¨ÐÅϢй¶Îó²î£¨CVE-2021-21816ºÍCVE-2021-21817£©£¬£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ýÌØÖÆµÄÍøÂçÇëÇó´¥·¢£¬£¬£¬£¬£¬£¬£¬£¬À´Éó²é×°±¸µÄϵͳÈÕÖ¾£»£»£»£»Ó²±àÂëÃÜÂëÎó²îCVE-2021-21818ºÍCVE-2021-21820£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐǰÕß¿ÉÄܵ¼Ö¾ܾøÐ§ÀÍ£¬£¬£¬£¬£¬£¬£¬£¬ºóÕßÔÊÐí¹¥»÷ÕßÔÚ·ÓÉÆ÷ÉÏÖ´ÐдúÂ룻£»£»£»ÒÔ¼°´úÂëÖ´ÐÐÎó²î(CVE-2021-21819) ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2021/07/vuln-spotlight-d-link.html
6.SonicWallÖÒÑÔÕë¶ÔÆäSMA100ϵÁкÍSRA²úÆ·µÄÀÕË÷¹¥»÷

SonicWallÐû²¼½ôÆÈÇ徲֪ͨ£¬£¬£¬£¬£¬£¬£¬£¬ÖÒÑÔÕë¶ÔÆä²»Ö§³Ö¸üÐÂ(EoL)µÄÇå¾²ÒÆ¶¯»á¼û(SMA)100ϵÁкÍÇå¾²Ô¶³Ì»á¼û(SRA)²úÆ·µÄÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓõÄÊÇÒ»¸ö¾ÉÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÒÑÔÚÆä×îа汾µÄ¹Ì¼þÖÐÐÞ¸´£¬£¬£¬£¬£¬£¬£¬£¬¿Í»§ÐèÒª¾¡¿ì¸üÐÂÆä×°±¸µÄ¹Ì¼þ¡£¡£¡£¡£¡£ÈôÊÇ×é֯ʹÓõľÉSRA×°±¸ÒÑÊÇEoL״̬²¢ÇÒÎÞ·¨¸üе½9.x¹Ì¼þ£¬£¬£¬£¬£¬£¬£¬£¬ÈÔ¼ÌÐøÊ¹ÓÿÉÄÜÔâµ½ÀÕË÷¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾½¨ÒéÁ¬Ã¦¶Ï¿ª×°±¸ÅþÁ¬²¢ÖØÖÃÆä»á¼ûÃÜÂ룬£¬£¬£¬£¬£¬£¬£¬ÈôÊÇ¿ÉÒԵϰÆôÓÃÕÊ»§¶àÖØÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/sonicwall-warns-of-imminent-ransomware-campaign-targeting-its-eol-equipment/


¾©¹«Íø°²±¸11010802024551ºÅ