MicrosoftÅû¶NETGEAR·ÓÉÆ÷¹Ì¼þÖеĶà¸öÎó²î£»£»£»£»£»£»£»£»Avast³ÆÃɹŵÄCA»ú¹¹MonPassÒÑÔâµ½8´Î¹¥»÷
Ðû²¼Ê±¼ä 2021-07-021.MicrosoftÅû¶NETGEAR·ÓÉÆ÷¹Ì¼þÖеĶà¸öÎó²î

MicrosoftÅû¶ÁËNETGEAR DGN2200v1ϵÁзÓÉÆ÷¹Ì¼þÖеÄ3¸öÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¿É±»ÓÃÀ´ÔÚÆóÒµµÄÍøÂçÖкáÏòÒÆ¶¯¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²îΪHTTPdÉí·ÝÑéÖ¤Çå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ7.1 ¨C 9.4²»µÈ¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÓõÚÒ»¸öÎó²î¿ÉÔÚ×Ó×Ö·û´®ÖеÄÇëÇóÖи½¼ÓGET±äÁ¿£¬£¬£¬£¬£¬£¬£¬£¬À´ÈƹýÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬£¬£¬»á¼ûÉè±¹ØÁ¬ÄÈκÎÒ³Ãæ£»£»£»£»£»£»£»£»µÚ¶þ¸öÎó²î¿ÉÓÃÀ´¾ÙÐвàÐŵÀ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÇÔÈ¡´æ´¢µÄƾ֤£»£»£»£»£»£»£»£»µÚÈý¸öÎó²î¿ÉÓëÏÈǰµÄÈÏÖ¤ÈÆ¹ýÎó²îÁ¬ÏµÊ¹Ó㬣¬£¬£¬£¬£¬£¬£¬À´ÇÔȡ·ÓÉÆ÷µÄÉèÖûָ´Îļþ¡£¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬£¬NetgearÒÑÐÞ¸´ÁËÕâЩÎó²î¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/06/microsoft-discloses-critical-bugs.html
2.Avast³ÆÃɹŵÄCA»ú¹¹MonPassÒÑÔâµ½8´Î¹¥»÷

Çå¾²¹«Ë¾Avast³ÆÃɹÅ×î´óµÄÖ¤Êé½ÒÏþ»ú¹¹(CA)Ö®Ò»MonPassÔâµ½ÁË8´ÎÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£AvastÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ÆäÔÚMonPassÍйܵĹ«¹²WebЧÀÍÆ÷Öз¢Ã÷ÁË8ÖÖ²î±ðµÄºóÃÅ£¬£¬£¬£¬£¬£¬£¬£¬ÕâÅú×¢¸Ã»ú¹¹¿ÉÄÜÔâµ½8´Î¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩºóÃÅÓÚ2ÔÂ8ÈÕÖÁ3ÔÂ3ÈÕʱ´úÔڸù«Ë¾µÄ¹Ù·½Ö¤Êé×°ÖÃÓ¦ÓÃÖлîÔ¾£¬£¬£¬£¬£¬£¬£¬£¬ÓÚ3ÔÂÏÂÑ®±»Åû¶¡£¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÏÔÈ»ÊÇÍýÏëͨ¹ýÈëÇÖ¿ÉÐÅÈεÄȪԴÀ´ÏòÃɹŵÄÓû§Èö²¥¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/mongolian-certificate-authority-hacked-eight-times-compromised-with-malware/
3.Ñо¿Ö°Ô±·¢Ã÷ʹÓÃBabuk Locker¹¹½¨Æ÷µÄ¹¥»÷»î¶¯

Ñо¿Ö°Ô±·¢Ã÷ʹÓÃÁËBabuk Locker¹¹½¨Æ÷µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£Babuk LockerÊÇÒ»¿îÀÕË÷Èí¼þ£¬£¬£¬£¬£¬£¬£¬£¬ÓÚ2021Äê×îÏÈ»îÔ¾£¬£¬£¬£¬£¬£¬£¬£¬Æä¹¹½¨Æ÷ÓÚÉÏÖܱ»Ðû²¼µ½ÁËVirusTotalÉÏ¡£¡£¡£¡£¡£¡£¡£¡£Ôڸù¹½¨Æ÷й¶ºó²»¾Ã£¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿Í×îÏÈÆµÈÔµÄʹÓÃËüÀ´ÌᳫÀÕË÷Èí¼þ»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£´Ó±¾Öܶþ×îÏÈ£¬£¬£¬£¬£¬£¬£¬£¬ÓÐÓû§·´Ó¦ÆäÔâµ½ÁËBabuk LockerÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Êܺ¦ÕßÀ´×ÔÌìϸ÷µØ¡£¡£¡£¡£¡£¡£¡£¡£¿ÉÊÇÓë×î³õµÄBabukÍŻﶯéüÒªÇóÊý°ÙÍòÃÀÔª²î±ð£¬£¬£¬£¬£¬£¬£¬£¬Õâ¸öÐµĹ¥»÷ÕßÖ»Òª0.006±ÈÌØ±Ò»òÔ¼210ÃÀÔªµÄÊê½ð¡£¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃºÚ¿Í»¹ÔÚÀÕË÷ÐÅÖаѡ°Babuk¡±Æ´×÷ÁË¡°Babuck¡±¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/leaked-babuk-locker-ransomware-builder-used-in-new-attacks/
4.SMBÈ䳿IndexsinasÕë¶ÔÒ½ÁƱ£½¡¡¢Ð§ÀͺͽÌÓýµÈÐÐÒµ

Guardicore LabsÑо¿Ö°Ô±·¢Ã÷SMBÈ䳿IndexsinasÕë¶ÔÒ½ÁƱ£½¡¡¢Ð§ÀÍ¡¢½ÌÓýºÍµçÐŵÈÐÐÒµ¡£¡£¡£¡£¡£¡£¡£¡£Indexsinas£¬£¬£¬£¬£¬£¬£¬£¬ÓÖÃûNSABuffMiner£¬£¬£¬£¬£¬£¬£¬£¬×Ô2019ÄêÒÔÀ´×îÏÈ»îÔ¾£¬£¬£¬£¬£¬£¬£¬£¬Ö÷ҪʹÓÃÁË3¸öÎó²î£ºEternalBlue¡¢DoublePulsarºÍEternalRomance¡£¡£¡£¡£¡£¡£¡£¡£Guardicore È«Çò´«¸ÐÆ÷ÍøÂç (GGSN)×Ô2019Äê×îÏÈ×ܹ²¼Í¼ÁËÀ´×Ô1300¶à¸ö²î±ðȪԴµÄ2000¶à´Î¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖдó¶àλÓÚÃÀ¹ú¡¢Ô½ÄϺÍÓ¡¶È¡£¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕߺÜÊÇÉóÉ÷£¬£¬£¬£¬£¬£¬£¬£¬C2ЧÀÍÆ÷¶¼ÔÚº«¹ú²¢¶¼Êܵ½Á˸߶ȱ£»£»£»£»£»£»£»£»¤£¬£¬£¬£¬£¬£¬£¬£¬×°ÖÃÁ˲¹¶¡ÇÒûÓÐÏò»¥ÁªÍøÌ»Â¶¶àÓàµÄ¶Ë¿Ú¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.guardicore.com/labs/smb-worm-indexsinas/
5.¸çÂ×±ÈÑÇÕþ¸®¾Ð²¶Èö²¥¶ñÒâÈí¼þGoziµÄÂÞÂíÄáÑǺڿÍ

¸çÂ×±ÈÑÇÕþ¸®¾Ð²¶ÁËÂÞÂíÄáÑǺڿÍMihai Ionut Paunescu¡£¡£¡£¡£¡£¡£¡£¡£ËûÒòÔÚ2007ÄêÖÁ2012ÄêʹÓöñÒâÈí¼þGoziѬȾÁËÁè¼Ý100Íǫ̀ÅÌËã»ú¶ø±»ÃÀ¹úͨ¼©¡£¡£¡£¡£¡£¡£¡£¡£GoziÓÚ2007ÄêÊ״α»·¢Ã÷£¬£¬£¬£¬£¬£¬£¬£¬Ñ¬È¾ÁËÖÁÉٰ˸ö¹ú¼ÒµÄÅÌËã»ú£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨ÃÀ¹ú¡¢µÂ¹ú¡¢·ÒÀ¼ºÍÓ¢¹úµÈ¹ú£¬£¬£¬£¬£¬£¬£¬£¬Ôì³ÉÁËÊýÍòÍòÃÀÔªµÄËðʧ¡£¡£¡£¡£¡£¡£¡£¡£PaunescuÔøÓÚ2012ÄêÔÚÂÞÂíÄáÑDZ»²¶£¬£¬£¬£¬£¬£¬£¬£¬µ«²¢Î´±»Òý¶É£¬£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚ¸çÂ×±ÈÑÇ×ÜÉó²é³¤°ì¹«ÊÒÐû²¼ÔÚ²¨¸ç´ó¹ú¼Ê»ú³¡¾Ð²¶Á˸úڿ͡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/119550/cyber-crime/hacker-gozi-virus-arrested.html
6.CISAÐû²¼Õë¶ÔÀÕË÷Èí¼þµÄÇå¾²Éó¼Æ×ÔÎÒÆÀ¹À¹¤¾ßRRA

ÃÀ¹úÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö(CISA)Ðû²¼ÁËÀÕË÷Èí¼þÍ£µ±ÆÀ¹À(RRA)£¬£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÆäÍøÂçÇå¾²ÆÀ¹À¹¤¾ß(CSET)µÄÐÂÄ£¿£¿£¿£¿é¡£¡£¡£¡£¡£¡£¡£¡£RRAÊÇÒ»ÖÖÇå¾²Éó¼Æ×ÔÎÒÆÀ¹À¹¤¾ß£¬£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ×éÖ¯µÖÓùÕë¶ÔÆäÐÅÏ¢ÊÖÒÕ(IT)¡¢ÔËÓªÊÖÒÕ(OT)»ò¹¤Òµ¿ØÖÆÏµÍ³(ICS)µÄÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°´Ó¹¥»÷Öлָ´¡£¡£¡£¡£¡£¡£¡£¡£CISA֮ǰ»¹Ðû²¼ÁËÓÃÓÚÉó²éMicrosoft Azure Active Directory¡¢Office 365ºÍMicrosoft 365ÖеĹ¥»÷»î¶¯µÄ¹¤¾ßAviary¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/cisa-releases-new-ransomware-self-assessment-security-audit-tool/


¾©¹«Íø°²±¸11010802024551ºÅ