΢Èí3ÔÂÇå¾²¸üР£¬£¬£¬£¬ £¬ £¬ÐÞ¸´°üÀ¨2¸ö0dayÔÚÄÚµÄ82¸öÎó²î£»£» £» £»£» £»unit42Ðû²¼ÓйØdnsmasqÎó²îµÄÆÊÎö±¨¸æ

Ðû²¼Ê±¼ä 2021-03-10

1.΢Èí3ÔÂÇå¾²¸üР£¬£¬£¬£¬ £¬ £¬ÐÞ¸´°üÀ¨2¸ö0dayÔÚÄÚµÄ82¸öÎó²î


1.jpg


΢ÈíÐû²¼ÁË3ÔÂÇå¾²¸üР£¬£¬£¬£¬ £¬ £¬ÐÞ¸´Á˰üÀ¨2¸ö0dayÔÚÄÚµÄ82¸öÎó²î¡£¡£¡£ ¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄ2¸ö0day»®·ÖΪInternet ExplorerÖеÄÄÚ´æËð»µÎó²î£¨CVE-2021-26411£©ºÍWindows Win32kÖеÄÌØÈ¨ÌáÉýÎó²î£¨CVE-2021-27077£© £¬£¬£¬£¬ £¬ £¬¾ÝϤǰÕßÒѹûÕæÓÃÓÚ¹¥»÷¡£¡£¡£ ¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬ £¬ £¬Î¢Èí»¹ÐÞ¸´ÁËAzure SphereÖеĴúÂëÖ´ÐÐÎó²î£¨CVE-2021-27074ºÍCVE-2021-27080£©¡¢OpenType×ÖÌåÆÊÎöÖÐÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-26876£©ºÍHyper-VÖеÄÔ¶³ÌÖ´ÐдúÂëÎó²î£¨CVE-2021-26867£©µÈ¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-march-2021-patch-tuesday-fixes-82-flaws-2-zero-days/    


2.unit42Ðû²¼ÓйØdnsmasqÎó²îµÄÆÊÎö±¨¸æ


2.jpg


unit42Ðû²¼ÓйØDNSαװ£¨dnsmasq£©Îó²îµÄÆÊÎö±¨¸æ¡£¡£¡£ ¡£¡£¡£¡£DNSαװ£¨dnsmasq£©ÊÇÒ»ÖÖÆÕ±éʹÓõĿªÔ´DNSÆÊÎöÆ÷ £¬£¬£¬£¬ £¬ £¬ÎªÐí¶àÏîÄ¿ºÍÓ²¼þËùʹÓà £¬£¬£¬£¬ £¬ £¬ÈçKubernetesºÍ·ÓÉÆ÷µÈ²úÆ·¡£¡£¡£ ¡£¡£¡£¡£×î½üÑо¿Ö°Ô±·¢Ã÷ÁËÐÂÎÊÌâ £¬£¬£¬£¬ £¬ £¬Ê¹µÃdnsmasqÈÝÒ×Êܵ½¹¥»÷¡£¡£¡£ ¡£¡£¡£¡£ÕâЩÎó²î¿É·ÖΪÁ½Àà £¬£¬£¬£¬ £¬ £¬»®·ÖΪDNSЭÒéʵÑéÖеÄÎó²îCVE-2020-25684¡¢CVE-2020-25685ºÍCVE-2020-25686 £¬£¬£¬£¬ £¬ £¬ÒÔ¼°µ¼ÖÂDoS¹¥»÷µÄ»º³åÇøÒç³öÎó²îCVE-2020-25681¡¢CVE-2020-25682¡¢CVE-2020-25683ºÍCVE-2020-25687¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/overview-of-dnsmasq-vulnerabilities-the-dangers-of-dns-cache-poisoning/


3.EdgescanÐû²¼2020-2021ÄêÎó²îͳ¼ÆµÄÆÊÎö±¨¸æ


3.jpg


EdgescanÐû²¼ÁË2020-2021ÄêÎó²îͳ¼ÆµÄÆÊÎö±¨¸æ¡£¡£¡£ ¡£¡£¡£¡£±¨¸æÕ¹ÏÖÁË2020ÄêÒÔÀ´µÄÎó²îµÄͳ¼ÆÊý¾ÝºÍÇ÷ÊÆ £¬£¬£¬£¬ £¬ £¬²¢´ÓÒÑÖªÎó²î£¨CVE£©¡¢¶ñÒâÈí¼þ¡¢ÀÕË÷Èí¼þºÍ¿É¼ûÐԽǶȣ¨¹ûÕæµÄЧÀÍ£©ÉîÈëÑо¿ÁËÎó²îÖ¸±ê¡£¡£¡£ ¡£¡£¡£¡£2020ÄêÔ¶³Ì×ÀÃæ£¨RDPºÍSSH£©µÄ̻¶ÔöÌíÁË40% £¬£¬£¬£¬ £¬ £¬ÓÐ21070¸ö»¥ÁªÍø¶Ëµã̻¶ÁËÊý¾Ý¿âϵͳ¡£¡£¡£ ¡£¡£¡£¡£È¥Äê·¢Ã÷µÄ×î³£¼ûµÄÎó²îÊÇLogjam (CVE-2015-4000) £¬£¬£¬£¬ £¬ £¬ÕâÊÇÒ»¸öʹÓÃDiffie-HellmanÃÜÔ¿½»Á÷ÃÜÂëϵͳµÄÎó²î £¬£¬£¬£¬ £¬ £¬¿Éµ¼ÖÂÖÐÐÄÈ˹¥»÷¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://info.edgescan.com/vulnerability-stats-report-2021


4.Ñо¿Ö°Ô±·¢Ã÷UnityMinerʹÓÃQNAP NASÖеÄÎó²îÍÚ¿ó


4.jpg


Ñо¿Ö°Ô±·¢Ã÷ʹÓöñÒâÈí¼þUnityMinerÕë¶Ôδ´ò²¹¶¡µÄQNAPÍøÂçÅþÁ¬´æ´¢£¨NAS£©×°±¸µÄ¼ÓÃÜÇ®±Ò¶ñÒâÈí¼þ»î¶¯¡£¡£¡£ ¡£¡£¡£¡£¸Ã»î¶¯Éæ¼°µ½ÁË2¸öδ¾­ÊÚȨµÄÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨CVE-2020-2506£¦CVE-2020-2507£© £¬£¬£¬£¬ £¬ £¬Ó°Ïì2020Äê8ÔÂ֮ǰµÄQNAP NAS¹Ì¼þ°æ±¾ £¬£¬£¬£¬ £¬ £¬ÒÑÓÚ2020Äê10ÔÂÐÞ¸´¡£¡£¡£ ¡£¡£¡£¡£ÓÐ4297426̨QNAP NAS¿ÉÄÜ»áÔâµ½´ËÀ๥»÷ £¬£¬£¬£¬ £¬ £¬ÆäÖÐ951486̨¾ßÓÐΨһµÄIPµØµã £¬£¬£¬£¬ £¬ £¬´ó´ó¶¼Î»ÓÚÃÀ¹ú¡¢ÖйúºÍÒâ´óÀû¡£¡£¡£ ¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎúUnityMinerµÄÀúÊ·ÒÔ¼°Æä±³ºóµÄºÚ¿Í×éÖ¯¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/115403/hacking/unityminer-qnap-nas-devices.html


5.Ç÷ÊÆ¿Æ¼¼·¢Ã÷ÒÁÀÊMuddyWaterÕë¶ÔÖж«×éÖ¯µÄ¹¥»÷»î¶¯


5.jpg


Trend Micro·¢Ã÷ÒÁÀʺڿÍ×éÖ¯MuddyWaterÕë¶ÔÖж«×éÖ¯µÄ¹¥»÷»î¶¯¡£¡£¡£ ¡£¡£¡£¡£ºÚ¿ÍʹÓÃÁË´øÓÐǶÈëʽÁ´½ÓµÄÓã²æÊ½µç×ÓÓʼþ £¬£¬£¬£¬ £¬ £¬½«Êܺ¦ÕßÖØ¶¨Ïòµ½Õýµ±µÄÎļþ¹²ÏíЧÀÍScreenConnect £¬£¬£¬£¬ £¬ £¬À´·Ö·¢Æä¶ñÒâÈí¼þ°ü¡£¡£¡£ ¡£¡£¡£¡£¸Ã»î¶¯Ö÷ÒªÕë¶ÔÖж«ºÍÖܱߵØÇøµÄѧÊõ½ç¡¢Õþ¸®»ú¹¹ºÍÂÃÓÎʵÌå £¬£¬£¬£¬ £¬ £¬ÎªÖ¼ÔÚÇÔÈ¡Êý¾ÝµÄÌØ¹¤»î¶¯¡£¡£¡£ ¡£¡£¡£¡£Trend Micro»¹·¢Ã÷·Ö·¢RemoteUtilitiesºÍScreenConnectµÄÁ½¸ö»î¶¯Ö®¼äµÄÕ½ÂÔºÍÊÖÒÕ´óÖÂÏàËÆ £¬£¬£¬£¬ £¬ £¬ÌåÏÖÐÂÒ»ÂÖ¹¥»÷Ö÷ÒªÕë¶Ô°¢Èû°Ý½®¡¢°ÍÁÖ¡¢ÒÔÉ«ÁС¢É³Ìذ¢À­²®ºÍ°¢ÁªÇõµÄ×éÖ¯¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/03/iranian-hackers-using-remote-utilities.html


6.µÂ¿ËÈøË¹´óѧÔâµ½¹¥»÷ £¬£¬£¬£¬ £¬ £¬Ñ§Ð£ËùÓÐϵͳ±»ÆÈ¹Ø±Õ


6.jpg


µÂ¿ËÈøË¹´óѧ£¨University of Texas£©ÓÚ3ÔÂ7ÈÕÐû²¼ÉùÃ÷³ÆÆäÔâµ½¹¥»÷ £¬£¬£¬£¬ £¬ £¬Ñ§Ð£ËùÓÐϵͳ±»ÆÈ¹Ø±Õ¡£¡£¡£ ¡£¡£¡£¡£¸ÃУÌåÏÖ £¬£¬£¬£¬ £¬ £¬ËûÃÇÔÚÖÜÎ寯Ïþ·¢Ã÷Á˴˴ι¥»÷ £¬£¬£¬£¬ £¬ £¬Æäµç×ÓÓʼþºÍÍйܴóÑ§ÍøÕ¾µÄЧÀÍÆ÷¾ùÊܵ½´ËÊÂÎñµÄÓ°Ïì £¬£¬£¬£¬ £¬ £¬½ÌÖ°Ô±¹¤ºÍѧÉúÖ»ÄÜͨ¹ýBlackboard¾ÙÐÐͨѶ¡£¡£¡£ ¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬ £¬ £¬ÆäÔÚ¼ì²âµ½¹¥»÷ºóÁ¬Ã¦¹Ø±ÕÁËËùÓÐУ԰ϵͳ £¬£¬£¬£¬ £¬ £¬²¢¶Ôÿ¸öϵͳ¾ÙÐÐÁ˳¹µ×¼ì²é £¬£¬£¬£¬ £¬ £¬·¢Ã÷²¢Ã»ÓÐÈκÎСÎÒ˽¼ÒÐÅÏ¢±»Ð¹Â¶¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/hackers-target-texas-university/