ÐÂSolarLeaksÍøÕ¾³öÊÛSolarWinds¹©Ó¦Á´¹¥»÷ÖÐÊý¾Ý£»£»£»£»£»£»£»GoogleÅû¶Õë¶ÔWindowsºÍAndroidµÄË®¿Ó¹¥»÷
Ðû²¼Ê±¼ä 2021-01-14
ÐÂSolarLeaksÍøÕ¾³öÊÛSolarWinds¹©Ó¦Á´¹¥»÷ÖÐMicrosoft¡¢Cisco¡¢FireEyeºÍSolarWindsµÈ¹«Ë¾µÄʧÔôÊý¾Ý¡£¡£¡£¡£¡£¡£¸ÃÍøÕ¾ÒÔ60ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛMicrosoftÔ´´úÂëºÍ´æ´¢¿â£¬£¬£¬£¬ÒÔ5ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛFireEyeµÄÔ´´úÂëºÍºì¶Ó¹¤¾ß£¬£¬£¬£¬ÒÔ25ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛSolarWindsÔ´´úÂëºÍ¿Í»§ÃÅ»§£¬£¬£¬£¬²¢ÒÔ100ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛËùÓÐй¶Êý¾Ý¡£¡£¡£¡£¡£¡£solarleaks.netÓòÊÇͨ¹ý¶íÂÞ˹Fancy BearºÍCozy BearʹÓõÄÒÑ֪ע²áÉÌNJALLA¾ÙÐÐ×¢²á¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/solarleaks-site-claims-to-sell-data-stolen-in-solarwinds-attacks/
2.MimecastÔâµ½¹¥»÷£¬£¬£¬£¬Microsoft 365 SSLÖ¤Êéй¶

µç×ÓÓʼþÇå¾²¹«Ë¾MimecastÔâµ½¹¥»÷µ¼ÖÂMicrosoft 365 SSLÖ¤Êéй¶£¬£¬£¬£¬Ó°ÏìÁËÔ¼10%µÄÓû§¡£¡£¡£¡£¡£¡£Mimecast³ÆÆäÒѾ½¨ÒéʹÓô˻ùÓÚÖ¤ÊéµÄÅþÁ¬µÄMimecast¿Í»§Á¬Ã¦É¾³ýÏÖÓÐÅþÁ¬£¬£¬£¬£¬²¢Ê¹Óøù«Ë¾ÌṩµÄÐÂÖ¤ÊéÀ´ÖØÐ½¨Éè»ùÓÚÖ¤ÊéµÄÅþÁ¬¡£¡£¡£¡£¡£¡£MimecastûÓÐÖ¸³ö±»ÇÔÈ¡µÄÖ¤ÊéÀàÐÍ£¬£¬£¬£¬µ«Æ¾Ö¤ÉùÃ÷¿ÉÍÆ²âΪMimecastÓû§ÅþÁ¬Microsoft 365µÄ×Ô½ÒÏþµÄÖ¤ÊéÖ®Ò»£¬£¬£¬£¬¿É±»ÓÃÓÚÖÐÐÄÈË£¨MiTM£©¹¥»÷¡£¡£¡£¡£¡£¡£Mimecast³Æ´ËÊ»¹ÔÚÊÓ²ìÖС£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/mimecast-discloses-microsoft-365-ssl-certificate-compromise/
3.GoogleÅû¶Õë¶ÔWindowsºÍAndroidÓû§µÄË®¿Ó¹¥»÷

Google Project ZeroÅû¶ÁË2020ÄêµÚÒ»¼¾¶ÈÖÐʹÓÃÁ˶à¸ö0dayºÍndayµÄË®¿Ó¹¥»÷¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷»î¶¯Ê¹ÓÃÁËÁ½Ì¨Îó²îʹÓÃЧÀÍÆ÷£¬£¬£¬£¬Ò»Ì¨Õë¶ÔWindowsÓû§£¬£¬£¬£¬Áíһ̨Õë¶ÔAndroidÓû§¡£¡£¡£¡£¡£¡£¸ÃЧÀÍÆ÷ʹÓÃÁËGoogle ChromeÖеÄËĸöäÖȾÆ÷µÄÎó²î£¬£¬£¬£¬WindowsÖеÄÁ½¸öɳºÐÌÓ±ÜÎó²î£¬£¬£¬£¬ÉÐÓÐÒ»¸öÕë¶Ô½Ï¾É°æ±¾µÄAndroid OSÌáȨ¹¤¾ß°ü¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷Á´ÖÐʹÓõÄ0day°üÀ¨Chrome TurboFanÖеÄÎó²î£¨CVE-2020-6418£©¡¢WindowsÉϵÄ×ÖÌåÎó²î£¨CVE-2020-0938£©¡¢WindowsÉϵÄ×ÖÌåÎó²î£¨CVE-2020-1020£©ºÍWindows CSRSSÎó²î£¨CVE-2020-1027£©¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/113342/hacking/project-zero-watering-hole-attack.html
4.SophosÅû¶Õë¶Ô°Í»ù˹̹°²×¿Óû§µÄÌØ¹¤Èí¼þ»î¶¯

SophosÑо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öеÄÌØ¹¤Èí¼þ»î¶¯£¬£¬£¬£¬ÆäÖ÷ҪĿµÄÊǰͻù˹̹µÄAndroidÓû§¡£¡£¡£¡£¡£¡£ÕâÐ©ÌØ¹¤Èí¼þαװ³ÉÁ˰ͻù˹̹ʢÐеÄÓ¦Ó㬣¬£¬£¬Èç°Í»ù˹̹¹«ÃñÃÅ»§¡¢×¢²áSIMs¼ì²é³ÌÐò¡¢°Í»ù˹̹µÚÈý·½ÎïÁ÷°ü¹ÜÓ¦ÓÃºÍÆíµ»Ê±¼äÓ¦Óõȣ¬£¬£¬£¬Ö÷ҪĿµÄΪ¼àÊÓºÍй¶ÊÜѬȾװ±¸ÖеÄÊý¾Ý¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬Î±ÔìµÄ°Í»ù˹̹¹«ÃñÃÅ»§ÍøÓ¦Óûá͵ȡÓû§µÄÉí·ÝÖ¤¡¢»¤ÕÕÊý¾Ý¡¢FacebookºÍÆäËûÉ罻ýÌåÕÊ»§µÄƾ֤¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/pakistan-android-users-spyware-campaign-malicious-apps/
5.¶à¹ú¾¯·½ÁªºÏµ·»Ù°µÍøÉÏ×î´óµÄºÚÊÐDarkMarket

°Ä´óÀûÑÇ¡¢µ¤Â󡢵¹ú¡¢Ä¦¶û¶àÍß¡¢ÈðÊ¿¡¢ÎÚ¿ËÀ¼¡¢Ó¢¹úºÍÃÀ¹úµÄ¾¯·½ÁªºÏµ·»ÙÁ˰µÍøÉÏ×î´óµÄºÚÊÐDarkMarket¡£¡£¡£¡£¡£¡£DarkMarketÓµÓнü50ÍòÓû§ºÍ2400¶à¼ÒÉÌ»§£¬£¬£¬£¬¾ÙÐÐÁËÖÁÉÙ32Íò±ÊÉúÒ⣬£¬£¬£¬Éæ¼°4650¶à¸ö±ÈÌØ±ÒºÍ12800¸ömonero£¨×ܽð¶îÁè¼Ý1.7ÒÚÃÀÔª£©¡£¡£¡£¡£¡£¡£µÂ¹ú¾¯·½ÓÚÖÜÄ©Ôڵ¹úÓ뵤ÂóÁìÍÁ¾Ð²¶ÁËÒ»Ãû34ËêµÄ°Ä´óÀûÑǹ«Ãñ£¬£¬£¬£¬Îª°µÍøµÄı»®Õߣ¬£¬£¬£¬²¢ÔÚĦ¶û¶àÍߺÍÎÚ¿ËÀ¼½É»ñÁËÆäʹÓõÄ20¶ą̀ЧÀÍÆ÷¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬ÊÓ²ìÈÔÔÚ¾ÙÐÐÖС£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/darkmarket-taken-down/
6.AdobeÐû²¼Çå¾²¸üУ¬£¬£¬£¬ÐÞ¸´¶à¿î²úÆ·ÖеÄ7¸öÎó²î

AdobeÐû²¼Çå¾²¸üУ¬£¬£¬£¬ÐÞ¸´ÁËPhotoshop¡¢IllustratorºÍAdobe BridgeµÈ¶à¿îÓ¦ÓÃÖеÄ7¸öÎó²î¡£¡£¡£¡£¡£¡£ÆäÖÐ×îÑÏÖØµÄΪAdobe Campaign ClassicÖеÄЧÀÍÆ÷¶ËÇëÇóαÔìÎó²î£¨CVE-2021-21009£©¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬»¹ÐÞ¸´ÁËPhotoshopÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2021-21006£©¡¢IllustratorÖв»ÊܿصÄËÑË÷·¾¶ÔªËØÎó²î£¨CVE-2021-21007£©¡¢Adobe BridgeÖеÄÔ½½çдÈëÎó²îCVE-2021-21012ºÍCVE-2021-21013£©µÈ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/adobe-critical-flaws-flash-player/162958/


¾©¹«Íø°²±¸11010802024551ºÅ