Armis·¢Ã÷APC UPS×°±¸ÖÐͳ³ÆÎªTLSstormµÄ3¸öÎó²î
Ðû²¼Ê±¼ä 2022-03-11Armis·¢Ã÷APC UPS×°±¸ÖÐͳ³ÆÎªTLSstormµÄ3¸öÎó²î
¾ÝýÌå3ÔÂÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬Çå¾²¹«Ë¾ArmisÔÚAPCµÄSmartConnectºÍSmart-UPSϵÁвúÆ·Öз¢Ã÷ÁËͳ³ÆÎªTLSstormµÄ3¸öÎó²î¡£¡£¡£¡£ÆäÖÐ2¸öÎó²îÉæ¼°UPSºÍAPCÔÆÖ®¼äµÄTLSÎÕÊÖÀú³Ì£¬£¬£¬£¬£¬£¬£¬»®·ÖΪTLS»º³åÇøÒç³öÎó²î£¨CVE-2022-22805£©ºÍTLSÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2022-22806£©£»£»£»£»£»£»£»µÚÈý¸öÎó²î£¨CVE-2022-0715£©¿É±»ÓÃÀ´¹¹½¨Ò»¸ö¶ñÒâAPC¹Ì¼þ°æ±¾²¢×÷Ϊ¹Ù·½¸üоÙÐзַ¢¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÕâЩÎó²î¿É¶Ô×°±¸Ôì³ÉÎïÀíË𺦣¬£¬£¬£¬£¬£¬£¬ÀýÈçÔ¶³ÌÏú»Ù×°±¸ºÍ¶Ïµç£¬£¬£¬£¬£¬£¬£¬½¨ÒéÁ¬Ã¦×°Öò¹¶¡³ÌÐò¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/apc-ups-zero-day-bugs-can-remotely-burn-out-devices-disable-power/
GoogleÐû²¼3Ô·ÝÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´AndroidÖжà¸öÎó²î
3ÔÂ8ÈÕ£¬£¬£¬£¬£¬£¬£¬GoogleÐû²¼ÁË2022Äê3ÔµÄAndroid 10¡¢11ºÍ12Çå¾²¸üС£¡£¡£¡£´Ë´ÎÐÞ¸´µÄ½ÏΪÑÏÖØµÄÊÇÌáȨÎó²î£¨CVE-2021-39708£©£¬£¬£¬£¬£¬£¬£¬Î»ÓÚAndroidϵͳ×é¼þÖУ¬£¬£¬£¬£¬£¬£¬²»ÐèÒªÓû§½»»¥¼´¿ÉÔ¶³ÌÌáÉýȨÏÞ£»£»£»£»£»£»£»ÁíÍâ2¸öÑÏÖØÎó²îÊÇCVE-2021-1942ºÍCVE-2021-35110£¬£¬£¬£¬£¬£¬£¬ËüÃǶ¼»áÓ°Ïì»ùÓÚQualcommµÄ±ÕÔ´×é¼þ¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬Ã»ÓÐÈκÎÒÑÐÞ¸´Îó²îµÄÊÖÒÕϸ½Ú£¬£¬£¬£¬£¬£¬£¬ÒÔ·À»¹Î´×°ÖÃ×îв¹¶¡µÄÓû§Ôâµ½¹¥»÷¡£¡£¡£¡£
https://source.android.com/security/bulletin/2022-03-01
°¢¸ùÍ¢µçÉ̹«Ë¾Mercado Libre²¿·ÖÔ´ÂëºÍÓû§ÐÅϢй¶
ýÌå3ÔÂ8ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬°¢¸ùÍ¢µçÉ̹«Ë¾Mercado Libre³ÆÆä²¿·ÖÔ´´úÂëÔâµ½ÁËδ¾ÊÚȨµÄ»á¼û¡£¡£¡£¡£¸Ã¹«Ë¾»¹ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹»á¼ûÁËԼĪ300000¸öÓû§µÄÊý¾Ý¡£¡£¡£¡£MercadoLibre×ܲ¿Î»ÓÚ²¼ÒËŵ˹°¬Àû˹£¬£¬£¬£¬£¬£¬£¬ÊÇÀ¶¡ÃÀÖÞ×î´óµÄµç×ÓÉÌÎñºÍÖ§¸¶Éú̬ϵͳ¡£¡£¡£¡£ÀÕË÷ÍÅ»ïLapsus$Éù³ÆÒѾ»á¼ûÁËMercado LibreºÍMercado PagoµÄ24000¸öÔ´´úÂë´æ´¢¡£¡£¡£¡£¸ÃÍŻﻹÔÚ3ÔÂ7ÈÕÌᳫÁËÒ»ÏîͶƱ£¬£¬£¬£¬£¬£¬£¬ÒªÇóÓû§Ñ¡³ö½ÓÏÂÀ´Ó¦¸Ãй¶Êý¾ÝµÄ¹«Ë¾¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/e-commerce-giant-mercado-libre-confirms-source-code-data-breach/
AkamaiÔÚÒ°Íâ·¢Ã÷¶àÆðʹÓÃMitel×°±¸µÄDDoS¹¥»÷»î¶¯
3ÔÂ8ÈÕ£¬£¬£¬£¬£¬£¬£¬AkamaiÐû²¼¹ØÓÚʹÓÃMitel×°±¸µÄDDoS¹¥»÷»î¶¯µÄÆÊÎö±¨¸æ¡£¡£¡£¡£Ñо¿Ö°Ô±ÊӲ쵽ʹÓ÷´ÉäºÍ·Å¸ÅÂÔÁìÀ´¾ÙÐг¤´ï14СʱµÄDDoS¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬£¬·Å´óÂʸߴï4294967296£º1¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬£¬Îó²îTP240PhoneHome(CVE-2022-26143)Òѱ»ÎäÆ÷»¯£¬£¬£¬£¬£¬£¬£¬ÒÔ·¢¶¯Õë¶Ô¿í´øISP¡¢½ðÈÚ»ú¹¹¡¢ÎïÁ÷¹«Ë¾¡¢ÓÎÏ·¹«Ë¾µÈ×éÖ¯µÄDDoS¹¥»÷¡£¡£¡£¡£Ô¼ÓÐ2600¸ö̻¶µÄMitel MiCollabºÍMiVoice Business ExpressÐ×÷ϵͳ£¬£¬£¬£¬£¬£¬£¬±»¹¥»÷ÕßÓÃÓÚÌᳫÿÃëÁè¼Ý5300Íò¸ö°ü(PPS)µÄDDoS¹¥»÷¡£¡£¡£¡£
https://www.akamai.com/blog/security/phone-home-ddos-attack-vector
MandiantÐû²¼¹ØÓÚAPT41¹¥»÷ÃÀ¹úÕþ¸®»ú¹¹µÄÆÊÎö±¨¸æ
MandiantÔÚ3ÔÂ8ÈÕÐû²¼Ò»·Ý±¨¸æ£¬£¬£¬£¬£¬£¬£¬ÏêÊöÁËAPT41Õë¶ÔÃÀ¹úÕþ¸®»ú¹¹¹¥»÷»î¶¯¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬£¬ÔÚ2021Äê5ÔÂÖÁ2022Äê2ÔÂʱ´ú£¬£¬£¬£¬£¬£¬£¬APT41Òѹ¥»÷ÁËÖÁÉÙ6¸öÃÀ¹úÖÝÕþ¸®»ú¹¹£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÁËUSAHERDS Ó¦ÓóÌÐòÖеÄ0 day( CVE-2021-44207 ) ºÍLog4jÖеÄ0 day( CVE-2021-44228 )¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹Ê¹ÓÃÁËеÄÄ£¿£¿£¿£¿£¿£¿£¿é»¯C++ºóÃÅKEYPLUGºÍÌØÖÆµÄdropper DUSTPAN£¬£¬£¬£¬£¬£¬£¬²¢ÔÚC2ͨѶºÍÊý¾Ýй¶·½Ãæ´ó×ÚʹÓÃCloudflareЧÀÍ¡£¡£¡£¡£
https://www.mandiant.com/resources/apt41-us-state-governments
Clearview AIÒòÍøÂçÈËÁ³Í¼Ïñ±»GPDP·£¿£¿£¿£¿£¿£¿£¿î2000ÍòÅ·Ôª
¾Ý3ÔÂ9ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬Òâ´óÀûÒþ˽µ£±£ÈË(GPDP)¶ÔClearview AI´¦ÒÔ20000000Å·ÔªµÄ·£¿£¿£¿£¿£¿£¿£¿î£¬£¬£¬£¬£¬£¬£¬Ôµ¹ÊÔÓÉÊǸù«Ë¾ÔÚδÕ÷µÃÓû§Ô޳ɵÄÇéÐÎÏÂÔÚÒâ´óÀûʵÑéÁËÒ»¸öÉúÎïʶ±ð¼à¿ØÍøÂç¡£¡£¡£¡£ÊÓ²ìÏÔʾ£¬£¬£¬£¬£¬£¬£¬Õâ¼ÒÃÀ¹úµÄÃæ²¿Ê¶±ðÈí¼þ¹«Ë¾ÓµÓÐÒ»¸ö°üÀ¨100ÒÚÕÅÈËÁ³Í¼ÏñµÄÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨´ÓÍøÕ¾ÖеÄСÎÒ˽¼Ò×ÊÁϺÍÔÚÏßÊÓÆµÖÐÌáÈ¡µÄÒâ´óÀû¹«ÃñÃæ²¿Í¼ÏñÊý¾Ý¡£¡£¡£¡£¸Ã»ú¹¹»¹³ÆClearview AIÓµÓв»·¨»ñµÃµÄµØÀíλÖÃÊý¾Ý¡£¡£¡£¡£Clearview±ç»¤³ÆÔÚÒâ´óÀûÊг¡µÄ²âÊÔÒÑÓÚ2020Äê3Ô¿¢Ê£¬£¬£¬£¬£¬£¬£¬µ«GPDP·´¶ÔÁËÕâÒ»Â۵㡣¡£¡£¡£
https://www.bleepingcomputer.com/news/legal/clearview-ai-fined-20m-for-collecting-italians-biometric-data/
Çå¾²¹¤¾ß
LAZYPARIAH
Ò×ÓÚ×°ÖõÄÏÂÁîÐй¤¾ß£¬£¬£¬£¬£¬£¬£¬Óô¿Ruby±àд£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ±¬·¢·´Ïòshell payload¡£¡£¡£¡£
https://github.com/octetsplicer/LAZYPARIAH
lnkbomb
ÓÃÓÚÍøÂçNTLM¹þÏ£µÄ¶ñÒâ¿ì½Ý·½·¨±¬·¢Æ÷¡£¡£¡£¡£
https://github.com/dievus/lnkbomb
AWS_Loot
ËÑË÷Ò»¸öAWSÇéÐÎÖÐѰÕÒÃÜÔ¿£¬£¬£¬£¬£¬£¬£¬Í¨¹ýö¾ÙÇéÐαäÁ¿ºÍÔ´´úÂë¡£¡£¡£¡£
https://github.com/sebastian-mora/AWS-Loot
PwnKit-Exploit
CVE-2021-4034µÄ¿´·¨Ö¤Êµ (PoC)¡£¡£¡£¡£
Çå¾²ÆÊÎö
¹È¸èÒÔ 54 ÒÚÃÀÔªÊÕ¹ºÍøÂçÇå¾²¹«Ë¾ Mandiant
https://thehackernews.com/2022/03/google-buys-cybersecurity-firm-mandiant.html
Apple Ðû²¼ iOS 15.4 RC£¬£¬£¬£¬£¬£¬£¬ÏÂÖÜÖÜÈ«ÉÏÏß
https://news.softpedia.com/news/apple-releases-ios-15-4-rc-full-launch-next-week-535010.shtml
Windows 10 KB5011487 ºÍ KB5011485 ¸üÐÂÐû²¼
https://www.bleepingcomputer.com/news/microsoft/windows-10-kb5011487-and-kb5011485-updates-released/
ÔõÑù¶Ô Apple ×°±¸¾ÙÐÐÍøÂçÇå¾²Éó²é
https://www.hackread.com/how-to-give-apple-devices-a-cybersecurity-review/
Adobe ÐÞ²¹ Illustrator¡¢After Effects Öеġ°ÑÏÖØ¡±Çå¾²Îó²î
https://www.securityweek.com/adobe-patches-critical-security-flaws-illustrator-after-effects


¾©¹«Íø°²±¸11010802024551ºÅ