CiscoÐÞ¸´SMB VPN·ÓÉÆ÷ÖеĶà¸ö´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»£»£»Çå¾²¹«Ë¾StormshieldÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬²¿·ÖÔ´´úÂëй¶
Ðû²¼Ê±¼ä 2021-02-051.CiscoÐÞ¸´SMB VPN·ÓÉÆ÷ÖеĶà¸ö´úÂëÖ´ÐÐÎó²î

CiscoÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´Ó°ÏìÁ˶à¸öСÐÍÆóÒµVPN·ÓÉÆ÷µÄ´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄÎó²î°üÀ¨CVE-2021-1289¡¢CVE-2021-1290¡¢CVE-2021-1291¡¢CVE-2021-1292¡¢CVE-2021-1293¡¢CVE-2021-1294ºÍCVE-2021-1295¡£¡£¡£¡£¡£¡£¡£ÆäÖÐ×îÑÏÖØµÄÎó²îÊÇÓÉÓÚ¶Ô»ùÓÚWebµÄÖÎÀí½Ó¿ÚµÄHTTPÇëÇóÑéÖ¤²»×¼È·µ¼Öµģ¬£¬£¬£¬£¬£¬£¬¿É±»ÓÃÀ´ÒÔrootȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬Cisco»¹ÐÞ¸´ÁËÓ°ÏìÆäËû·ÓÉÆ÷ºÍIOS XRÈí¼þÖеĶà¸öÎó²î¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/cisco-fixes-critical-code-execution-bugs-in-smb-vpn-routers/
2.SudoÌáȨÎó²îÓ°ÏìmacOS Big Sur£¬£¬£¬£¬£¬£¬£¬ÉÐδÐû²¼²¹¶¡

SudoÌáȨÎó²îÒ²Ó°ÏìÁË×îа汾µÄmacOS Big Sur£¬£¬£¬£¬£¬£¬£¬ÉÐδÐû²¼²¹¶¡³ÌÐò¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î±»×·×ÙΪCVE-2021-3156£¬£¬£¬£¬£¬£¬£¬ÓÖÃûBaron Samedit£¬£¬£¬£¬£¬£¬£¬ÊÇ»ùÓڶѵĻº³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬£¬¿ÉʹÍâµØÓû§»ñµÃrootȨÏÞ¡£¡£¡£¡£¡£¡£¡£Hacker HouseÑо¿Ö°Ô±³Æ£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔ½«sudoÓësudoedit½¨Éè·ûºÅÁ´½Ó´¥·¢¶ÑÒç³ö£¬£¬£¬£¬£¬£¬£¬°ÑÓû§µÄȨÏÞÉý¼¶µ½1337 uid=0À´Ê¹ÓøÃÎó²î¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚÒÑÐû²¼ÁËÕë¶ÔUbuntu¡¢DebianºÍFedoraµÈ¶à¸öLinuxϵͳµÄ²¹¶¡³ÌÐò£¬£¬£¬£¬£¬£¬£¬µ«¾ù²»ÊÊÓÃÓÚmacOS¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/recent-sudo-vulnerability-affects-apple-cisco-products
3.Çå¾²¹«Ë¾StormshieldÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬²¿·ÖÔ´´úÂëй¶

·¨¹úÇå¾²¹«Ë¾Stormshield³ÆÆäÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬¿Í»§µÄÐÅÏ¢ºÍSNS·À»ðǽµÄÔ´´úÂëй¶¡£¡£¡£¡£¡£¡£¡£StormshieldÊÇ·¨¹úÕþ¸®Ö÷ÒªµÄÇ徲ЧÀͺÍÍøÂçÇå¾²×°±¸ÌṩÉÌ£¬£¬£¬£¬£¬£¬£¬ÆäÕýÔÚÓë·¨¹úÍøÂç¹ú¼ÒÇ鱨¾ÖÒ»ÆðÊÓ²ì´ËÊÂÎñ£¬£¬£¬£¬£¬£¬£¬²¢ÆÀ¹À¸ÃÎó²î¶ÔÕþ¸®ÏµÍ³µÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£StormshieldÌåÏÖ£¬£¬£¬£¬£¬£¬£¬ËûÃÇÒÑ¾Ìæ»»ÁËÓÃÀ´Ç©ÊðSNSÈí¼þ¸üеÄÊý×ÖÖ¤Ê飬£¬£¬£¬£¬£¬£¬µ½ÏÖÔÚΪֹºÚ¿Í»¹Ã»ÓжԴúÂë¾ÙÐи͝£¬£¬£¬£¬£¬£¬£¬Ò²Ã»ÓÐÈκÎStormshield²úÆ·Êܵ½Ë𺦡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
zdnet.com/article/security-firm-stormshield-discloses-data-breach-theft-of-source-code/
4.н©Ê¬ÍøÂçMatryoshÕë¶ÔADB̻¶µÄAndroid×°±¸

н©Ê¬ÍøÂçMatryoshÕë¶ÔAndroid Debug Bridge½çÃæÌ»Â¶µÄAndroid×°±¸¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÔÚ»¥ÁªÍøÉÏɨÃèADB½çÃæÎª»î¶¯×´Ì¬µÄAndroid×°±¸£¬£¬£¬£¬£¬£¬£¬²¢ÔÚÀÖ³ÉÅþÁ¬Ä¿µÄ×°±¸ºóÏÂÔØ×°ÖöñÒâpayload¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬ÆäʹÓÃÁËTorÍøÂçÀ´Òþ²ØC&CЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃÒ»¸ö¶à²ãµÄÀú³ÌÀ´»ñÈ¡Õâ¸öЧÀÍÆ÷µÄµØµã£¬£¬£¬£¬£¬£¬£¬Òò´Ë¸Ã½©Ê¬ÍøÂçµÄÃû×ÖҲȪԴÓÚ¶íÂÞ˹Ì×ÍÞ¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ´ó´ó¶¼»ùÓÚAndroidµÄ×°±¸²»Ö§³ÖÔÚOSÑ¡ÏîÖÐÉèÖÃADB¹¦Ð§£¬£¬£¬£¬£¬£¬£¬Òò´ËÐí¶àϵͳÔÚδÀ´ÊýÄêÄÚÈÔÒ×Ôâµ½ÀÄÓᣡ£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/android-devices-ensnared-in-ddos-botnet/
5.Defender ATPÎó½«Chrome¶à¸ö¸üбê¼ÇΪPHPºóÃÅ

Microsoft Defender ATPÎó½«Chrome¶à¸ö¸üбê¼ÇΪPHPºóÃÅ¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤¼ì²âЧ¹ûµÄ½ØÍ¼£¬£¬£¬£¬£¬£¬£¬Microsoft Defender¼ì²âµ½Chrome v88.0.4324.146¸üаüµÄ¶à¸öÎļþ°üÀ¨ÁËÒ»¸öÃûΪPHP/Funvalget.A.µÄͨÓúóÃÅľÂí¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬£¬Æä½«Chrome sl.pakÓïÑÔÎļþÎó±ê¼ÇΪºóÃųÌÐò£¬£¬£¬£¬£¬£¬£¬²¢Á¬Ã¦½ÓÄÉÁËÏìÓ¦²½·¥£¬£¬£¬£¬£¬£¬£¬×Ô¶¯¸ôÀë¼ì²âµ½µÄÎļþ¡£¡£¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬£¬Microsoft½ÒÏþÉùÃ÷³Æ´ËÊÂÎñΪ×Ô¶¯»¯ÎÊÌ⣬£¬£¬£¬£¬£¬£¬¹ýʧµØ½«×°ÖóÌÐò°ü¹éÀàΪ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬ÎÊÌâÏÖÒѽâ¾ö¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-defender-atp-detects-chrome-updates-as-php-backdoors/
6.GoogleÐû²¼2020ÄêÔÚҰʹÓõÄÁãÈÕÎó²îµÄ»ØÊ×±¨¸æ

Google Project ZeroÐû²¼ÁË2020ÄêÔÚҰʹÓõÄÁãÈÕÎó²îµÄ»ØÊ×±¨¸æ¡£¡£¡£¡£¡£¡£¡£±¨¸æÏÔʾ£¬£¬£¬£¬£¬£¬£¬2020Äê×ܹ²¼ì²âµ½24¸öÒѱ»Ê¹ÓõÄÁãÈÕÎó²î£¬£¬£¬£¬£¬£¬£¬ÆäÖÐ6ÖÖÊÇǰ¼¸ÄêËùÅû¶µÄÎó²îµÄ±äÖÖ£¬£¬£¬£¬£¬£¬£¬»®·ÖΪInternet ExplorerÖеÄCVE-2020-0674¡¢»ðºüÖеÄCVE-2020-6820¡¢¹È¸èä¯ÀÀÆ÷ÖеÄCVE-2020-6572¡¢WindowsÖеÄCVE-2020-0986¡¢FreetypeÖеÄCVE-2020-15999ºÍÆ»¹ûSafariÖеÄCVE-2020-27930¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖijЩÎó²îÖ»ÐèÒª¸ü¸ÄÒ»»òÁ½ÐдúÂë¾Í¿ÉÒÔ³ÉΪеÄÎó²î£¬£¬£¬£¬£¬£¬£¬Òò´Ë¶ÔÎó²î¾ÙÐиü³¹µ×µÄÊÓ²ìºÍÐÞ¸´£¬£¬£¬£¬£¬£¬£¬Ôò¿ÉÄÜ×èÖ¹ËÄ·ÖÖ®Ò»µÄÎó²îµÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://googleprojectzero.blogspot.com/2021/02/deja-vu-lnerability.html


¾©¹«Íø°²±¸11010802024551ºÅ