ÐÂSolarLeaksÍøÕ¾³öÊÛSolarWinds¹©Ó¦Á´¹¥»÷ÖÐÊý¾Ý£»£»£»£»£»£»£»£»GoogleÅû¶Õë¶ÔWindowsºÍAndroidµÄË®¿Ó¹¥»÷
Ðû²¼Ê±¼ä 2021-01-14
ÐÂSolarLeaksÍøÕ¾³öÊÛSolarWinds¹©Ó¦Á´¹¥»÷ÖÐMicrosoft¡¢Cisco¡¢FireEyeºÍSolarWindsµÈ¹«Ë¾µÄʧÔôÊý¾Ý¡£¡£¡£¡£¸ÃÍøÕ¾ÒÔ60ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛMicrosoftÔ´´úÂëºÍ´æ´¢¿â£¬£¬£¬£¬£¬ÒÔ5ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛFireEyeµÄÔ´´úÂëºÍºì¶Ó¹¤¾ß£¬£¬£¬£¬£¬ÒÔ25ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛSolarWindsÔ´´úÂëºÍ¿Í»§ÃÅ»§£¬£¬£¬£¬£¬²¢ÒÔ100ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛËùÓÐй¶Êý¾Ý¡£¡£¡£¡£solarleaks.netÓòÊÇͨ¹ý¶íÂÞ˹Fancy BearºÍCozy BearʹÓõÄÒÑ֪ע²áÉÌNJALLA¾ÙÐÐ×¢²á¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/solarleaks-site-claims-to-sell-data-stolen-in-solarwinds-attacks/
2.MimecastÔâµ½¹¥»÷£¬£¬£¬£¬£¬Microsoft 365 SSLÖ¤Êéй¶

µç×ÓÓʼþÇå¾²¹«Ë¾MimecastÔâµ½¹¥»÷µ¼ÖÂMicrosoft 365 SSLÖ¤Êéй¶£¬£¬£¬£¬£¬Ó°ÏìÁËÔ¼10%µÄÓû§¡£¡£¡£¡£Mimecast³ÆÆäÒѾ½¨ÒéʹÓô˻ùÓÚÖ¤ÊéµÄÅþÁ¬µÄMimecast¿Í»§Á¬Ã¦É¾³ýÏÖÓÐÅþÁ¬£¬£¬£¬£¬£¬²¢Ê¹Óøù«Ë¾ÌṩµÄÐÂÖ¤ÊéÀ´ÖØÐ½¨Éè»ùÓÚÖ¤ÊéµÄÅþÁ¬¡£¡£¡£¡£MimecastûÓÐÖ¸³ö±»ÇÔÈ¡µÄÖ¤ÊéÀàÐÍ£¬£¬£¬£¬£¬µ«Æ¾Ö¤ÉùÃ÷¿ÉÍÆ²âΪMimecastÓû§ÅþÁ¬Microsoft 365µÄ×Ô½ÒÏþµÄÖ¤ÊéÖ®Ò»£¬£¬£¬£¬£¬¿É±»ÓÃÓÚÖÐÐÄÈË£¨MiTM£©¹¥»÷¡£¡£¡£¡£Mimecast³Æ´ËÊ»¹ÔÚÊÓ²ìÖС£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/mimecast-discloses-microsoft-365-ssl-certificate-compromise/
3.GoogleÅû¶Õë¶ÔWindowsºÍAndroidÓû§µÄË®¿Ó¹¥»÷

Google Project ZeroÅû¶ÁË2020ÄêµÚÒ»¼¾¶ÈÖÐʹÓÃÁ˶à¸ö0dayºÍndayµÄË®¿Ó¹¥»÷¡£¡£¡£¡£´Ë´Î¹¥»÷»î¶¯Ê¹ÓÃÁËÁ½Ì¨Îó²îʹÓÃЧÀÍÆ÷£¬£¬£¬£¬£¬Ò»Ì¨Õë¶ÔWindowsÓû§£¬£¬£¬£¬£¬Áíһ̨Õë¶ÔAndroidÓû§¡£¡£¡£¡£¸ÃЧÀÍÆ÷ʹÓÃÁËGoogle ChromeÖеÄËĸöäÖȾÆ÷µÄÎó²î£¬£¬£¬£¬£¬WindowsÖеÄÁ½¸öɳºÐÌÓ±ÜÎó²î£¬£¬£¬£¬£¬ÉÐÓÐÒ»¸öÕë¶Ô½Ï¾É°æ±¾µÄAndroid OSÌáȨ¹¤¾ß°ü¡£¡£¡£¡£¸Ã¹¥»÷Á´ÖÐʹÓõÄ0day°üÀ¨Chrome TurboFanÖеÄÎó²î£¨CVE-2020-6418£©¡¢WindowsÉϵÄ×ÖÌåÎó²î£¨CVE-2020-0938£©¡¢WindowsÉϵÄ×ÖÌåÎó²î£¨CVE-2020-1020£©ºÍWindows CSRSSÎó²î£¨CVE-2020-1027£©¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/113342/hacking/project-zero-watering-hole-attack.html
4.SophosÅû¶Õë¶Ô°Í»ù˹̹°²×¿Óû§µÄÌØ¹¤Èí¼þ»î¶¯

SophosÑо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öеÄÌØ¹¤Èí¼þ»î¶¯£¬£¬£¬£¬£¬ÆäÖ÷ҪĿµÄÊǰͻù˹̹µÄAndroidÓû§¡£¡£¡£¡£ÕâÐ©ÌØ¹¤Èí¼þαװ³ÉÁ˰ͻù˹̹ʢÐеÄÓ¦Ó㬣¬£¬£¬£¬Èç°Í»ù˹̹¹«ÃñÃÅ»§¡¢×¢²áSIMs¼ì²é³ÌÐò¡¢°Í»ù˹̹µÚÈý·½ÎïÁ÷°ü¹ÜÓ¦ÓÃºÍÆíµ»Ê±¼äÓ¦Óõȣ¬£¬£¬£¬£¬Ö÷ҪĿµÄΪ¼àÊÓºÍй¶ÊÜѬȾװ±¸ÖеÄÊý¾Ý¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬Î±ÔìµÄ°Í»ù˹̹¹«ÃñÃÅ»§ÍøÓ¦Óûá͵ȡÓû§µÄÉí·ÝÖ¤¡¢»¤ÕÕÊý¾Ý¡¢FacebookºÍÆäËûÉ罻ýÌåÕÊ»§µÄƾ֤¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/pakistan-android-users-spyware-campaign-malicious-apps/
5.¶à¹ú¾¯·½ÁªºÏµ·»Ù°µÍøÉÏ×î´óµÄºÚÊÐDarkMarket

°Ä´óÀûÑÇ¡¢µ¤Â󡢵¹ú¡¢Ä¦¶û¶àÍß¡¢ÈðÊ¿¡¢ÎÚ¿ËÀ¼¡¢Ó¢¹úºÍÃÀ¹úµÄ¾¯·½ÁªºÏµ·»ÙÁ˰µÍøÉÏ×î´óµÄºÚÊÐDarkMarket¡£¡£¡£¡£DarkMarketÓµÓнü50ÍòÓû§ºÍ2400¶à¼ÒÉÌ»§£¬£¬£¬£¬£¬¾ÙÐÐÁËÖÁÉÙ32Íò±ÊÉúÒ⣬£¬£¬£¬£¬Éæ¼°4650¶à¸ö±ÈÌØ±ÒºÍ12800¸ömonero£¨×ܽð¶îÁè¼Ý1.7ÒÚÃÀÔª£©¡£¡£¡£¡£µÂ¹ú¾¯·½ÓÚÖÜÄ©Ôڵ¹úÓ뵤ÂóÁìÍÁ¾Ð²¶ÁËÒ»Ãû34ËêµÄ°Ä´óÀûÑǹ«Ãñ£¬£¬£¬£¬£¬Îª°µÍøµÄı»®Õߣ¬£¬£¬£¬£¬²¢ÔÚĦ¶û¶àÍߺÍÎÚ¿ËÀ¼½É»ñÁËÆäʹÓõÄ20¶ą̀ЧÀÍÆ÷¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬ÊÓ²ìÈÔÔÚ¾ÙÐÐÖС£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/darkmarket-taken-down/
6.AdobeÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´¶à¿î²úÆ·ÖеÄ7¸öÎó²î

AdobeÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´ÁËPhotoshop¡¢IllustratorºÍAdobe BridgeµÈ¶à¿îÓ¦ÓÃÖеÄ7¸öÎó²î¡£¡£¡£¡£ÆäÖÐ×îÑÏÖØµÄΪAdobe Campaign ClassicÖеÄЧÀÍÆ÷¶ËÇëÇóαÔìÎó²î£¨CVE-2021-21009£©¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬»¹ÐÞ¸´ÁËPhotoshopÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2021-21006£©¡¢IllustratorÖв»ÊܿصÄËÑË÷·¾¶ÔªËØÎó²î£¨CVE-2021-21007£©¡¢Adobe BridgeÖеÄÔ½½çдÈëÎó²îCVE-2021-21012ºÍCVE-2021-21013£©µÈ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/adobe-critical-flaws-flash-player/162958/


¾©¹«Íø°²±¸11010802024551ºÅ