ForescoutÅû¶ӰÏìÉÏÒŲ́װ±¸µÄDNSÎó²îNAME£ºWRECK£»£»£»£»Î¢ÈíÐû²¼4Ô²¹¶¡£¬£¬£¬ÐÞ¸´5¸ö0dayÔÚÄÚµÄ108¸öÎó²î

Ðû²¼Ê±¼ä 2021-04-14

1.ForescoutÅû¶ӰÏìÉÏÒŲ́װ±¸µÄDNSÎó²îNAME£ºWRECK


1.jpg


Çå¾²¹«Ë¾ForescoutºÍÒÔÉ«ÁÐÇå¾²ÍŶÓJSOFÁªºÏÅû¶ÁËTCP/IP¿ÍÕ»ÖÐDNSЭÒéÖеÄ9¸öÇå¾²Îó²î£¬£¬£¬Í³³ÆÎªNAME£ºWRECK£¬£¬£¬Ó°ÏìÁË1ÒÚ¸öÔÚInternetÉÏÔËÐеÄ×°±¸ ¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îʹװ±¸ÍÑ»ú»òÕßÍêÈ«¿ØÖÆ×°±¸ ¡£¡£¡£ÕâЩÎó²îÖÐ×îÑÏÖØµÄΪIPnetÖеÄRCEÎó²î£¨CVE-2016-20009£©£¬£¬£¬ÑÏÖØÐԵ÷ÖΪ9.8 ¡£¡£¡£Æä´ÎΪRCE£¨CVE-2020-7461¡¢CVE-2020-15795ºÍCVE-2020-27009£©ºÍDoS£¨CVE-2020-27736ºÍCVE-2020-27737£©µÈÎó²î ¡£¡£¡£    


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/name-wreck-dns-vulnerabilities-affect-over-100-million-devices/


2.Ñо¿Ö°Ô±¹ûÕæChromeºÍEdgeµÈÓ¦ÓõÄRCE 0dayµÄPoC


2.jpg


Ñо¿Ö°Ô±ÔÚRajvardhan AgarwalÔÚTwitterÐû²¼ÁËChromeºÍEdgeµÈÓ¦ÓÃÖеÄRCE 0dayµÄPoC ¡£¡£¡£¸ÃÎó²îÊÇ»ùÓÚChromiumµÄä¯ÀÀÆ÷µÄV8 JavaScriptÒýÇæÖÐÔ¶³ÌÖ´ÐдúÂëÎó²î£¬£¬£¬Ó°ÏìÁËChrome¡¢Edge¡¢OperaºÍBraveµÈä¯ÀÀÆ÷ ¡£¡£¡£±ðµÄ£¬£¬£¬AgarwalÌåÏÖ¸Ã0dayÐèÒªÓëÁíÒ»¸ö¿ÉÒÔÔÚChromiumµÄɳÏäÌÓÒݵÄÎó²îÒ»ÆðʹÓòŻªÊ©Õ¹×÷Óà ¡£¡£¡£ÏÖÔÚ£¬£¬£¬¸ÃÎó²îÒÑÔÚV8 JavaScriptÒýÇæµÄ×îа汾Öб»ÐÞ¸´ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/04/rce-exploit-released-for-unpatched.html


3.MicrosoftÐû²¼4Ô²¹¶¡£¬£¬£¬ÐÞ¸´5¸ö0dayÔÚÄÚµÄ108¸öÎó²î


3.jpg


MicrosoftÐû²¼ÁË4Ô·ݵÄÖܶþ²¹¶¡£¬£¬£¬×ܼÆÐÞ¸´Á˰üÀ¨5¸ö0dayÔÚÄÚµÄ108¸öÎó²î ¡£¡£¡£´Ë´ÎÐÞ¸´µÄ0day°üÀ¨RPC¶ËµãÓ³ÉäÆ÷µÄÌáȨÎó²î£¨CVE-2021-27091£©¡¢NTFS¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2021-28312£©¡¢Windows×°ÖóÌÐòÖеÄÐÅϢй¶Îó²î£¨CVE-2021-28437£©¡¢Azure ms-rest-nodeauth¿âµÄÌáȨÎó²î£¨CVE-2021-28458£©ÒÔ¼°Win32kÖеÄÌáȨÎó²î£¨CVE-2021-28310£© ¡£¡£¡£ÆäÖУ¬£¬£¬CVE-2021-28310Îó²îÊÇKasperskyÔÚÒ°·¢Ã÷µÄ£¬£¬£¬Òѱ»APT×éÖ¯BITTERʹÓà ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2021-patch-tuesday-fixes-108-flaws-5-zero-days/


4.ºÚ¿Í³öÊÛ2100Íò¸öÍ£³µÓ¦ÓÃParkMobileµÄÓû§µÄÐÅÏ¢


4.jpg


Gemini Advisory·¢Ã÷ºÚ¿ÍÔÚ°µÍø³öÊÛ2100Íò¸öÒÆ¶¯Í£³µÓ¦ÓóÌÐòParkMobileµÄÓû§µÄÐÅÏ¢£¬£¬£¬ÊÛ¼ÛΪ125000ÃÀÔª ¡£¡£¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨¿Í»§µç×ÓÓʼþµØµã¡¢ÉúÈÕ¡¢µç»°ºÅÂë¡¢³µÅƺš¢¹þÏ£ÃÜÂëºÍÓʼĵصãµÈ ¡£¡£¡£ParkMobile¹«Ë¾³Æ£¬£¬£¬Æä3ÔÂ26ÈÕ¾ÍÐû²¼ÁËÓйØÊý¾Ýй¶µÄ֪ͨ£¬£¬£¬²¢ÔÚÇå¾²¹«Ë¾µÄЭÖú϶ԴËÊÂÕö¿ªÁËÊÓ²ì ¡£¡£¡£µ«Ñо¿Ö°Ô±ÌåÏÖÆä¹ÙÍø²¢Ã»ÓиÃÇ徲֪ͨ£¬£¬£¬Ò²Ã»ÓÐÇ¿ÖÆÆäÓû§ÐÞ¸ÄÃÜÂë ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://krebsonsecurity.com/2021/04/parkmobile-breach-exposes-license-plate-data-mobile-numbers-of-21m-users/


5.McAfee·¢Ã÷BRATAαװ³ÉÇ徲ɨÃè³ÌÐòÔÚGoogle PlayÖзַ¢


5.jpg


McAfee·¢Ã÷ÁËBRATAµÄ¶à¸öбäÖÖ£¬£¬£¬Î±×°³ÉÇ徲ɨÃè³ÌÐòÔÚGoogle PlayÖзַ¢ ¡£¡£¡£BRATA×î³õÓÚ2018Äêµ×ÔÚÒ°Íâ·ºÆð£¬£¬£¬ÒÔ°ÍÎ÷µÄÓû§ÎªÄ¿µÄ£¬£¬£¬¾ßÓпØÖÆ×°±¸¡¢Ê¹Óô¹ÂÚÍøÒ³ÇÔÈ¡ÒøÐÐÆ¾Ö¤¡¢»ñÈ¡ÆÁÄ»Ëø¶¨Æ¾Ö¤£¨PIN¡¢ÃÜÂë»òͼ°¸£©µÈ¹¦Ð§ ¡£¡£¡£ÕâЩеıäÖÖÖ÷ÒªÔÚGoogle PlayÉϾÙÐзַ¢£¬£¬£¬ÒªÇóÓû§¸üÐÂChrome¡¢WhatsApp»òPDFÔĶÁÆ÷£¬£¬£¬²¢Í¨¹ý¸¨Öú¹¦Ð§À´ÍêÈ«¿ØÖÆ×°±¸£¬£¬£¬Õë¶Ô°ÍÎ÷¡¢Î÷°àÑÀºÍÃÀ¹úµÈµØÇøµÄ½ðÈÚ×éÖ¯µÄÓû§ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.mcafee.com/blogs/other-blogs/mcafee-labs/brata-keeps-sneaking-into-google-play-now-targeting-usa-and-spain/


6.Unit 42Ðû²¼2020ÄêQ4Çå¾²Ç÷ÊÆµÄÆÊÎö±¨¸æ


6.jpg


Unit 42Ðû²¼ÁË2020ÄêQ4Çå¾²Ç÷ÊÆµÄÆÊÎö±¨¸æ ¡£¡£¡£±¨¸æ·¢Ã÷£¬£¬£¬2020Äê11ÔÂÖÁ2021Äê1ÔµĴó´ó¶¼¹¥»÷¶¼±»¹éΪÑÏÖØ¹¥»÷£¬£¬£¬Õ¼±ÈΪ75£¥£¬£¬£¬¶øÔÚÇ^Ϊ50.4£¥ ¡£¡£¡£¹¥»÷Õ߸ü¶àµÄʹÓÃ2017ÄêÖÁ2020ÄêÔÚÒ°ÍâʹÓõÄÎó²î ¡£¡£¡£ÔÚ¹¥»÷ÀàÐÍ·½Ã棬£¬£¬µ¥¶ÀµÄ´úÂëÖ´ÐÐÕ¼×ܹ¥»÷µÄ46.6£¥£¬£¬£¬´úÂëÖ´ÐкÍÌØÈ¨ÌáÉýÁ¬ÏµµÄ¹¥»÷Õ¼17.3£¥£¬£¬£¬SQL×¢ÈëÕ¼9.9£¥ ¡£¡£¡£ÑÏÖØÐÔ×î¸ßµÄÎó²îΪÏÂÁî×¢ÈëÎó²î£¨CVE-2020-28188£©¡¢Ä¿Â¼±éÀúÎó²î£¨CVE-2020-17519£©ºÍÍâµØÎļþ°üÀ¨Îó²î£¨CVE-2020-29227£©µÈ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/network-attack-trends-winter-2020/