GoogleÐû²¼Çå¾²¸üУ¬£¬£¬ £¬£¬ÐÞ¸´ChromeÖÐÒѱ»Ê¹ÓõÄ0day£»£»£»£»£»£»Avas·¢Ã÷ÖÁÉÙ100¼ÒÒâ´óÀûµÄÒøÐÐÒѳÉΪUrsnifµÄ¹¥»÷Ä¿µÄ

Ðû²¼Ê±¼ä 2021-03-05

1.GoogleÐû²¼Çå¾²¸üУ¬£¬£¬ £¬£¬ÐÞ¸´ChromeÖÐÒѱ»Ê¹ÓõÄ0day


1.jpg


GoogleÐû²¼Çå¾²¸üУ¬£¬£¬ £¬£¬ÐÞ¸´Chromeä¯ÀÀÆ÷ÖеÄ47¸öÎó²î£¬£¬£¬ £¬£¬ÆäÖаüÀ¨Ò»¸öÒѱ»Ê¹ÓõÄ0day¡£¡£¡£¡£ ¡£¸Ã0day±»×·×ÙΪCVE-2021-21166£¬£¬£¬ £¬£¬ÓÚ2ÔÂ11ÈÕ±»Åû¶£¬£¬£¬ £¬£¬ÏÖÔÚGoogle²¢Î´Í¸Â¶ÓйظÃÎó²îµÄ¸ü¶àÐÅÏ¢¡£¡£¡£¡£ ¡£±ðµÄ£¬£¬£¬ £¬£¬´Ë´Î¸üл¹ÐÞ¸´ÁËTabStripÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2021-21159£©¡¢WebAudioÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2021-21160£©ÒÔ¼°WebRTCÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2021-21162£©µÈ¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/google-patches-actively-exploited-chrome-browser-zero-day-vulnerability/


2.GRUBÏîÄ¿Ðû²¼²¹¶¡£¡£¡£¡£ ¡£¬£¬£¬ £¬£¬ÐÞ¸´GRUB2ÖеÄ117¸öÎó²î


2.jpg


±¾ÖÜ£¬£¬£¬ £¬£¬GRUBÏîÄ¿µÄά»¤Ö°Ô±Ðû²¼Á˲¹¶¡£¡£¡£¡£ ¡£¬£¬£¬ £¬£¬ÐÞ¸´ÁËGRUB2ÖеÄ117¸öÎó²î¡£¡£¡£¡£ ¡£´Ë´ÎÐÞ¸´µÄ½ÏΪÑÏÖØµÄÎó²îΪacpiÏÂÁîÔÊÐíÌØÈ¨Óû§¼ÓÔØÌØÖÆµÄACPI±í£¨CVE-2020-14372£©¡¢rmmodÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2020-25632£©¡¢Å²ÓÃgrub_usb_device_initialize£¨£©À´´¦Öóͷ£USB×°±¸³õʼ»¯Ê±µÄÔ½½çдÎó²î£¨CVE-2020-25647£©µÈ¡£¡£¡£¡£ ¡£¼øÓÚÈ¥Äê·¢Ã÷µÄBootHoleÎó²î£¬£¬£¬ £¬£¬Ñо¿Ö°Ô±½¨Ò龡¿ìÐÞ²¹ÕâЩÑÏÖØµÄÎó²î¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/grub2-boot-loader-reveals-multiple-high-severity-vulnerabilities/


3.¶íÂÞ˹µÄºÚ¿ÍÂÛ̳MazaÔâµ½¹¥»÷£¬£¬£¬ £¬£¬Óû§ÐÅÏ¢ÒÑй¶


3.jpg


¶íÂÞ˹¶¥¼¶ºÚ¿ÍÂÛ̳Maza£¨ÒÔǰ³ÆÎªMazafaka£©Ôâµ½¹¥»÷£¬£¬£¬ £¬£¬Óû§ÐÅÏ¢ÒÑй¶¡£¡£¡£¡£ ¡£MazaÖ÷ÒªÒÔÉúÒâ±»µÁµÄ²ÆÎñÐÅÏ¢£¨ÓÈÆäÊÇÐÅÓÿ¨ºÍ½è¼Ç¿¨ÏêϸÐÅÏ¢£©¶øÖøÃû¡£¡£¡£¡£ ¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨Óû§Éí·Ý¡¢Óû§Ãû¡¢µç×ÓÓʼþµØµã£¨Ô¼3000¸ö£©¡¢¹þÏ£ÃÜÂëºÍSkypeµØµãµÈ£¬£¬£¬ £¬£¬¿ÉÄÜÉÐÓÐÒ»¸öMAZAÖÎÀíԱʹÓõÄ˽ÓмÓÃÜÃÜÔ¿¡£¡£¡£¡£ ¡£±ðµÄ£¬£¬£¬ £¬£¬ÁíÒ»¸ö°µÍøVerifiedÒ²Ôâµ½Á˹¥»÷£¬£¬£¬ £¬£¬ÍøÕ¾±»Öض¨Ïòµ½¹¥»÷ÕßËù¿ØÖƵÄЧÀÍÆ÷¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/russian-hacker-forums-maza-verified-hacked/


4.Avas·¢Ã÷ÖÁÉÙÓÐ100¼ÒÒâ´óÀûµÄÒøÐÐÒѳÉΪUrsnifµÄ¹¥»÷Ä¿µÄ


4.jpg


AvastÑо¿Ö°Ô±·¢Ã÷ÖÁÉÙÓÐ100¼ÒÒâ´óÀûÒøÐÐÒѳÉΪUrsnif TrojanµÄ¹¥»÷Ä¿µÄ¡£¡£¡£¡£ ¡£UrsnifÓÚ2007ÄêÊ״α»·¢Ã÷£¬£¬£¬ £¬£¬Ö÷ÒªÇÔÈ¡Óû§Ãû¡¢ÃÜÂë¡¢ÐÅÓÿ¨¡¢ÒøÐÐÓªÒµºÍ¸¶¿îÐÅÏ¢µÈÊý¾Ý¡£¡£¡£¡£ ¡£Í³¼Æ·¢Ã÷¸Ã¶ñÒâÈí¼þÒѱ»ÓÃÓÚ¹¥»÷ÉϰټÒÒâ´óÀûÒøÐУ¬£¬£¬ £¬£¬ºÚ¿Í½öÔÚÒ»´Î¹¥»÷ÖоÍÇÔÈ¡ÁË1700¶à¸öƾ֤¡£¡£¡£¡£ ¡£±ðµÄ£¬£¬£¬ £¬£¬DatktraceµÄÑо¿Ö°Ô±Ò²·¢Ã÷ÁËʹÓøöñÒâÈí¼þÕë¶ÔÃÀ¹úÒ»¼ÒÒøÐеĹ¥»÷»î¶¯¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/115245/cyber-crime/ursnif-targets-italian-banks.html


5.ÃÀ¹úCallX¹«Ë¾AWS S3´æ´¢Í°ÉèÖùýʧй¶Áè¼Ý10Íò¸öÎļþ


5.jpg


vpnMentor·¢Ã÷ÃÀ¹úµç»°ÍÆÏú¹«Ë¾CallXµÄAWS S3´æ´¢Í°ÉèÖùýʧй¶Áè¼Ý10Íò¸öÎļþ¡£¡£¡£¡£ ¡£vpnMentor·¢Ã÷¸Ã×ß©µÄ´æ´¢Í°ÖÐ×ܹ²ÓÐ114000¸ö¹ûÕæµÄÎļþ£¬£¬£¬ £¬£¬ÆäÖдó´ó¶¼ÊÇÏúÊ۵绰µÄÒôƵ¼Í¼¡¢ÎÄ×Ö̸Ìì¼Í¼ÒÔ¼°Ð¡ÎÒ˽¼ÒÉí·ÝÐÅÏ¢£¨PII£©£¨°üÀ¨È«Ãû¡¢¼ÒͥסַºÍµç»°ºÅÂëµÈ£©¡£¡£¡£¡£ ¡£vpnMentorÌåÏÖ£¬£¬£¬ £¬£¬ÕâЩ×ß©µÄÊý¾Ý¿É±»ÓÃÀ´Ìá³«ÍøÂç´¹ÂÚ¹¥»÷¡¢Ú²Æ­»î¶¯ºÍÓÕÆ­¹¥»÷µÈ¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/telemarketing-biz-exposes-114000/


6.CompuCom MSPÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬ £¬£¬Ð§ÀÍÔÝʱÖÐÖ¹


6.jpg


ÃÀ¹úITÍйÜЧÀÍÌṩÉÌCompuComÔâµ½DarkSideÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬ £¬£¬Ð§ÀÍÔÝʱÖÐÖ¹¡£¡£¡£¡£ ¡£CompuCom¿ÉΪ¹«Ë¾ÌṩԶ³ÌÖ§³Ö¡¢Ó²¼þºÍÈí¼þάÐÞÒÔ¼°ÆäËûÊÖÒÕЧÀÍ£¬£¬£¬ £¬£¬¿Í»§°üÀ¨Home Depot¡¢»¨ÆìÒøÐС¢Truist BankºÍLowe'sµÈ¡£¡£¡£¡£ ¡£ÉÏÖÜÄ©£¬£¬£¬ £¬£¬Æä¿Í»§·¢Ã÷ÎÞ·¨»á¼û¸Ã¹«Ë¾µÄÃÅ»§ÍøÕ¾¡£¡£¡£¡£ ¡£Ö®ºó£¬£¬£¬ £¬£¬CompuComÌåÏÖÆäÔâµ½Á˹¥»÷£¬£¬£¬ £¬£¬²¿·ÖϵͳÊܵ½Ó°Ï죬£¬£¬ £¬£¬µ¼ÖÂijЩЧÀͲ»¿ÉÓᣡ£¡£¡£ ¡£¾­ÊӲ죬£¬£¬ £¬£¬¹¥»÷¿ÉÄܱ¬·¢ÓÚ2ÔÂ28ÈÕ£¬£¬£¬ £¬£¬DarkSideÔÚÆä¶à¸öϵͳÉÏ×°ÖÃÁËCobalt Strike Beacons¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/compucom-msp-confirms-ongoing-outage-following-malware-incident/