SkypeÔÚÈ«Çò¹æÄ£ÄÚЧÀÍÖÐÖ¹£¬£¬£¬£¬£¬£¬£¬Ôµ¹ÊÔÓÉÉв»Ã÷È·£»£»£»£»£»CISA³ÆºÚ¿Í¿ÉÈÆ¹ýMFAÉí·ÝÑéÖ¤»á¼ûÔÆÐ§ÀÍÕÊ»§
Ðû²¼Ê±¼ä 2021-01-151.SkypeÔÚÈ«Çò¹æÄ£ÄÚЧÀÍÖÐÖ¹£¬£¬£¬£¬£¬£¬£¬Ôµ¹ÊÔÓÉÉв»Ã÷È·

1ÔÂ13ÈÕÉÏÎ磬£¬£¬£¬£¬£¬£¬SkypeÔÚÈ«Çò¹æÄ£ÄÚЧÀÍÖÐÖ¹£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚ¸ÃÎÊÌâÒѱ»½â¾ö¡£¡£¡£¡£¡£Æ¾Ö¤ÔÚÏßÐÂÎÅÆ½Ì¨DownDetectorͳ¼Æ£¬£¬£¬£¬£¬£¬£¬ÖÐÖ¹Ö÷Òª¼¯ÖÐÔÚÃÀ¹ú¡¢Å·ÖÞ¡¢ÑÇÖÞºÍÌìÏÂÆäËûµØÇø¡£¡£¡£¡£¡£Óû§ÔÚ»á¼ûSkypeÍøÕ¾Ê±£¬£¬£¬£¬£¬£¬£¬»áÏÔʾÎÒÃÇÎÞ·¨Íê³ÉÄúµÄÇëÇóµÄÌáÐÑ¡£¡£¡£¡£¡£MicrosoftÔÚSkype״̬ҳÉÏÌåÏÖ·¢Ã÷Á˸ÃÎÊÌ⣬£¬£¬£¬£¬£¬£¬ÆäÓ°ÏìÁËSkypeµÇ¼¡¢ºô½Ð¡¢ÐÂÎÅ¡¢ËÑË÷¡¢Òƶ¯¹²Ïí¡¢Ö§¸¶ÏµÍ³¡¢SMSºÍÆäËûЧÀÍ¡£¡£¡£¡£¡£ÎÊÌâÏÖÒѻָ´£¬£¬£¬£¬£¬£¬£¬Skype¿ÉÔÙ´ÎÁª»ú¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/skype-is-down-worldwide-microsoft-working-on-issues/
2.CERTFAÅû¶APT35Óã²æÊ½´¹ÂÚ¹¥»÷»î¶¯µÄÏêÇé

CERTFAÅû¶ÁËÒÁÀʵÄAPT×éÖ¯Charming Kitten (ÓÖÃûAPT35£©Óã²æÊ½´¹ÂÚ¹¥»÷»î¶¯µÄÏêÇé¡£¡£¡£¡£¡£´Ë´Î¹¥»÷»î¶¯Ö÷ÒªÕë¶ÔλÓÚ²¨Ë¹Í塢ŷÖÞºÍÃÀ¹úÖÜΧ¹ú¼ÒµÄÖÇÄÒÍųÉÔ±¡¢ÕþÖÎÑо¿ÖÐÐÄ¡¢´óѧ½ÌÊÚ¡¢¼ÇÕߺÍÇéÐλ¼Ò¡£¡£¡£¡£¡£¸Ã»î¶¯Í¬Ê±Ê¹ÓÃÁ˵ç×ÓÓʼþºÍSMS£¬£¬£¬£¬£¬£¬£¬SMSÐÅÏ¢±»Î±×°³ÉGoogleÇå¾²¾¯±¨£¬£¬£¬£¬£¬£¬£¬¶ø´¹ÂÚÓʼþÔòÒÔ½ÚÈÕΪÖ÷Ìâ¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÀֳɵؽ«¶ñÒâÁ´½ÓÒþ²ØÔÚÕýµ±Google URLºó£¬£¬£¬£¬£¬£¬£¬Ê¹µÃÓû§¸üÄѱç±ðÆäÕæÎ±ÐÔ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/iranian-cyberspies-behind-major-christmas-sms-spear-phishing-campaign/
3.Check Point·¢Ã÷¿É½ÓÊÜ×°±¸²¢ÇÔÈ¡Êý¾ÝµÄ°²×¿Ä¾ÂíRogue

Check Point·¢Ã÷Á˿ɽÓÊÜ×°±¸²¢ÇÔÈ¡Êý¾ÝµÄÐÂÐͰ²×¿Ä¾ÂíRogue¡£¡£¡£¡£¡£Rogue RATÀÖ³ÉÈëÇÖÄ¿µÄ×°±¸ºó»áÒþ²ØÆäͼ±ê£¬£¬£¬£¬£¬£¬£¬²¢Öظ´ÒªÇóÓû§ÊÚÓèËùÓбØÐèµÄȨÏÞ¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ»¹»á×¢²áΪװ±¸ÖÎÀíÔ±£¬£¬£¬£¬£¬£¬£¬µ±Êܺ¦Õß·¢Ã÷²¢ÊÔͼµõÏúÖÎÀíԱȨÏÞ£¬£¬£¬£¬£¬£¬£¬»¹»áÏÔʾ¡°ÄúÈ·¶¨Òª²Á³ýËùÓÐÊý¾ÝÂ𣿣¿£¿£¿¡±µÄÌáÐÑÀ´ÏÅ»£Óû§¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬RogueʹÓÃÁËGoogleµÄFirebase£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÔÆÐÂÎÅת´ïÎüÊÕÀ´×ÔC£¦CµÄÏÂÁ£¬£¬£¬£¬£¬£¬Í¨¹ýʵʱÊý¾Ý¿âÒÔ´Ó×°±¸ÉÏ´«Êý¾Ý£¬£¬£¬£¬£¬£¬£¬Í¨¹ýCloud FirestoreÉÏ´«Îļþ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/113369/malware/rogue-android-rat-darkweb.html
4.CISA³ÆºÚ¿Í¿ÉÈÆ¹ýMFAÉí·ÝÑéÖ¤»á¼ûÔÆÐ§ÀÍÕÊ»§

ÃÀ¹úCISA³ÆºÚ¿Í¿ÉÈÆ¹ý¶àÒòËØÉí·ÝÑéÖ¤£¨MFA£©»á¼ûÔÆÐ§ÀÍÕÊ»§£¬£¬£¬£¬£¬£¬£¬²¢ÌåÏÖÆä·¢Ã÷Á˼¸ÆðÕë¶Ô²î±ð×éÖ¯µÄÔÆÐ§À͵Ĺ¥»÷ÊÂÎñ¡£¡£¡£¡£¡£CISAÒÔΪ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓñ»µÁµÄ»á»°cookieÀ´Ð®ÖÆÒÑͨ¹ýÉí·ÝÑéÖ¤µÄ»á»°£¬£¬£¬£¬£¬£¬£¬¾Í¿ÉÈÆ¹ýMFAµÇ¼ÔÚÏßЧÀÍ»òWebÓ¦ÓóÌÐò¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹»áͨ¹ýÇÔȡԱ¹¤Æ¾Ö¤À´»ñµÃ»á¼ûȨ£¬£¬£¬£¬£¬£¬£¬»òͨ¹ýÐÞ¸ÄÓÊÏ乿ÔòÒÔÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£Îª´Ë£¬£¬£¬£¬£¬£¬£¬CISAÌṩÁËÊÖÒÕϸ½ÚÏ¢Õù¾ö·½·¨£¬£¬£¬£¬£¬£¬£¬×ÊÖú×éÖ¯Ó¦¶Ô´ËÀ๥»÷¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/cisa-hackers-bypassed-mfa-to-access-cloud-service-accounts/
5.ImpervaÐû²¼Õë¶ÔÒ½ÁÆÐÐÒµµÄ¹¥»÷»î¶¯µÄÆÊÎö±¨¸æ

ImpervaÐû²¼ÁËÕë¶ÔÒ½ÁÆÐÐÒµµÄ¹¥»÷»î¶¯µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬£¬Õë¶ÔÒ½ÁÆÐÐÒµµÄWebÓ¦Óù¥»÷»î¶¯µÄÊýÄ¿ÔöÌíÁË51£¥¡£¡£¡£¡£¡£È«ÇòÒ½ÁÆÐÐҵƽ¾ùÿÔÂÔâÊÜ1.87Òڴι¥»÷£¬£¬£¬£¬£¬£¬£¬Ã¿¸ö×é֯ÿÔÂÆ½¾ùÔâÊÜ498´Î¹¥»÷£¬£¬£¬£¬£¬£¬£¬±ÈÈ¥ÄêͬÆÚÔöÌíÁË10£¥¡£¡£¡£¡£¡£ºÚ¿ÍʹÓÃÁ˶àÖÖǰÑÔ£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹ú¡¢°ÍÎ÷¡¢Ó¢¹úºÍ¼ÓÄôóµÈ¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬ÔÚÈ¥Äê12Ô£¬£¬£¬£¬£¬£¬£¬XSS¹¥»÷ÔöÌíÁË43£¥£¬£¬£¬£¬£¬£¬£¬SQL×¢ÈëÔöÌíÁË44£¥£¬£¬£¬£¬£¬£¬£¬ÐÒé¹¥»÷ÔöÌíÁË76£¥£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì´úÂëÖ´ÐÐ/Ô¶³ÌÎļþ°üÀ¨¹¥»÷ÔöÌíÁË68£¥¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.imperva.com/blog/web-application-attacks-on-healthcare-spike-51-as-covid-19-vaccines-are-introduced/
6.CiscoÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´¶à¿î²úÆ·ÖеÄ67¸öÎó²î

CiscoÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´Á˶à¿î²úÆ·ÖеÄ67¸öÎó²î¡£¡£¡£¡£¡£ÆäÖÐ×îÑÏÖØµÄÎó²îΪCisco Connected Mobile Experiences£¨CMX£©ÖеÄCVE-2021-1144£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ8.8£¬£¬£¬£¬£¬£¬£¬¿É±»Ô¶³Ì¹¥»÷ÕßÓÃÀ´¸ü¸ÄÄ¿µÄϵͳÉÏí§ÒâÕÊ»§µÄÃÜÂë¡£¡£¡£¡£¡£»£»£»£»£ÉÐÓÐCisco AnyConnectÇå¾²ÒÆ¶¯¿Í»§¶ËÖеÄDLL×¢ÈëÎó²î£¨CVE-2021-1237£©£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ7.8¡£¡£¡£¡£¡£´Ë´Î¸üл¹ÐÞ¸´ÁËСÐÍÆóҵ·ÓÉÆ÷RV110W¡¢RV130¡¢RV130WºÍRV215WÖÎÀí½Ó¿ÚÖеÄһϵÁпɵ¼ÖÂÔ¶³ÌÏÂÁîÖ´Ðк;ܾøÐ§À͹¥»÷µÄÎó²î¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/113395/security/cisco-high-severity-flaw-cmx.html


¾©¹«Íø°²±¸11010802024551ºÅ