TIMÍŶÓÅû¶CA Technologies²úÆ·ÖеĶà¸ö0day£»Î¢Èí³ÆÖÜËĵÄÖжÏÔ´ÓÚ´úÂëȱµãµ¼ÖµÄAzure DNS¹ýÔØ
°ä²¼¹¦·ò 2021-04-061.TIMÍŶÓÅû¶CA Technologies²úÆ·ÖеĶà¸ö0day

CA TechnologiesÊÇÃÀ¹úÒ»¼ÒרһÓÚB2BÈí¼þµÄ¿ç¹ú¹«Ë¾£¬ÏúÊÛ½ü200ÖÖ²úÆ·£¬Éæ¼°É¢²¼Ê½ÍÆËã¡¢ÔÆÍÆËã¡¢DevOpsºÍÍÆËã»ú°²È«Èí¼þÒÔ¼°Òƶ¯É豸¡£TIMµÄRed Team ResearchÍŶÓÅû¶ÁËCA eHealth Performance Manager²úÆ·ÖеÄ5¸öзì϶¡£±ðÀëΪÌáȨ·ì϶£¨CVE-2021-28246ºÍCVE-2021-28249£©¡¢¿çÕ¾µã¾ç±¾·ì϶£¨CVE-2021-28247£©¡¢Í¨¹ýSUID/GUIDÎļþµÄÌáȨ·ì϶£¨CVE-2021-28250£©ºÍÉí·ÝÑéÖ¤·ì϶£¨CVE-2021-28248£©¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/116268/security/ca-ehealth-performance-manager-flaws.html
2.΢Èí³ÆÖÜËĵÄÖжÏÔ´ÓÚ´úÂëȱµãµ¼ÖµÄAzure DNS¹ýÔØ

΢Èíй©£¬ÉÏÖÜËĵÄÈ«ÇòÁìÓòÄڵķþÎñÖжÏÊÇÓÉ´úÂëȱµãµ¼ÖµÄAzure DNS¹ýÔØÒýÆðµÄ¡£ÖжϲúÉúÔÚÉÏÖÜËÄÏÂÎç5:21×óÓÒ£¬MicrosoftÓû§·¢ÏÔìäÎÞ·¨½Ó¼ûXbox Live¡¢Office¡¢TeamsºÍSkypeµÈ·þÎñ£¬¸ÃÎÊÌâÓÚ6:30±»½â¾ö¡£½üÆÚ£¬Microsoft°ä²¼ÁËÓйطþÎñÖжϵĵ××ÓÔÒò·ÖÎö£¨RCA£©£¬³ÆÕë¶ÔAzureÉÏÍйܵÄijЩÓòµÄDNS²éÎÊÒì³£¼¤Ôöµ¼Ö·þÎñÆ÷¹ýÔØ£¬Î¢Èí²¢Î´Ú¹Êͼ¤ÔöµÄÔÒò£¬¾Ý´§Ä¦¿ÉÄÜÊÇÓÉÓÚÕë¶ÔijЩÓòµÄDDoS¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-outage-caused-by-overloaded-azure-dns-servers/
3.ÃÀ¹ú½ðÈÚ»ú¹¹RobinhoodµÄ¿Í»§Ôâµ½´¹µö¹¥»÷

Robinhood MarketsÔÚÉÏÖÜËİ䲼ÏòÆä¿Í»§·¢ËÍÓʼþ³Æ£¬Æä²¿Ãſͻ§¿ÉÄÜÒѾÔâµ½´¹µö¹¥»÷¡£RobinhoodÊÇÒ»¼ÒÃÀ¹ú½ðÈÚ·þÎñ»ú¹¹£¬ÆäÊÖ»úÀûÓÿÉÌṩ¹ÉƱºÍ»ù½ðµÄÃâÓ¶½ðÂòÂô£¬½ØÖÁ2020ÄêÒÑÕ¼ÓÐ1300Íò¿Í»§¡£Õâ´Î¹¥»÷»î¶¯Ê¹ÓÃÁËÁ½ÖÖ¹¥»÷ý½éÓÕÆÊܺ¦Õߣ¬ÆäÒ»ÊÇÀûÓÃÔ̺¬ÁËαÔìRobinhoodÍøÕ¾Á´½ÓµÄ´¹µöÓʼþ£¬ÓÕʹ½Ó¼ûÕßÊäÈëµÇ¼ʹ´¦£»ÁíÒ»ÖÖÊÇÀûÓÃÁ˱¨Ë°¼¾£¬ÒªÇóÖ¸±êÏÂÔØÔ̺¬Á˶ñÒâÈí¼þµÄαÔì˰ÊÕÎļþ¡£
ÔÎÄÁ´½Ó£º
https://www.ehackingnews.com/2021/04/attackers-targeted-robinhood-with.html
4.KasperskyÅû¶Õë¶ÔÔ½Ä϶à¸ö×éÖ¯µÄÍøÂç¼äµý»î¶¯

KasperskyÅû¶ÁËAPT×éÖ¯CycldekÕë¶ÔÔ½Äϵ±¾ÖºÍ¾üÊÂ×éÖ¯µÄÍøÂç¼äµý»î¶¯¡£¸Ã»î¶¯Ê¹ÓÃÁËÃûΪFoundCoreµÄ¶ñÒâÈí¼þ£¬¿É½øÐÐÎļþϵͳ°Ñ³Ö¡¢¹ý³Ì°Ñ³Ö¡¢ÆÁÄ»½ØÍ¼²¶»ñºÍËÁÒâºÅÁîÖ´ÐС£´Ë±í£¬Kaspersky³Æ¸Ã×éÖ¯ÔÚ¸´ÔÓÐÔ·½Ãæ»ñµÃÁ˳ÁÃͽøÈ¡£¬ÀýÈ磬ÆäpayloadµÄ±êÍ·£¨´úÂëµÄÖ¸±êºÍÔ´£©±»ÆëÈ«°þÀ룬ʣϵÄÉÙÊý²¿ÃŵÄÖµÊDz»Á¬¹áµÄ£¬Õâ´ó´óÔö³¤ÁË×êÑÐÈËÔ±¶ÔÆä½øÐзÖÎöµÄÄѶȡ£
ÔÎÄÁ´½Ó£º
https://threatpost.com/spy-operations-vietnam-rat/165243/
5.΢Èí°ä²¼2021Äê3ÔÂSecurity SignalsµÄ·ÖÎö»ã±¨

΢Èí°ä²¼ÁË2021Äê3ÔÂSecurity SignalsµÄ·ÖÎö»ã±¨£¬µ÷²éÁËÀ´×ÔÖйú¡¢µÂ¹ú¡¢ÈÕ±¾¡¢Ó¢¹úºÍÃÀ¹úµÄ1000λÆóÒµ°²È«¾ö²ßÕß¡£»ã±¨·¢ÏÖ£¬´ÓǰÁ½ÄêÖÐÓÐ80£¥µÄÆóÒµÔâµ½ÁËÖÁÉÙÒ»´Î¹Ì¼þ¹¥»÷£¬µ«Ö»ÓÐ29£¥µÄ×éÖ¯·ÖÅäÁËÔ¤ËãÀ´±£»¤¹Ì¼þ¡£NVDÖ¤ÇÐʵ´ÓǰËÄÄêÖУ¬Õë¶Ô¹Ì¼þµÄ¹¥»÷Ôö³¤ÁËÎå±¶ÒÔÉÏ¡£21£¥µÄ¾ö²ßÕßÈÏ¿ÉÎÞ·¨¼à¿Ø¹Ì¼þÊý¾Ý£¬82£¥×é֯ûÓÐ×ÊÔ´À´Õмܹ̼þ¹¥»÷¡£81£¥µÄµÂ¹ú¹«Ë¾¡¢91£¥µÄÃÀ¹ú¡¢Ó¢¹úºÍÈÕ±¾¹«Ë¾ÒÔ¼°95£¥µÄÖйú¹«Ë¾Ô¸ÒâÔÚÕâ¸ö·½Ãæ½øÐÐͶ×Ê¡£
ÔÎÄÁ´½Ó£º
https://www.microsoft.com/en-us/secured-corepc
6.Ravelin°ä²¼Óйصç×ÓÉÌÎñڲƻµÄ·ÖÎö»ã±¨

Ravelin¶ÔÈ«Çò1000¶à¼ÒÉ̼ҽøÐÐÁ˵÷²é£¬°ä²¼ÁËÓйصç×ÓÉÌÎñڲƻµÄ·ÖÎö»ã±¨¡£»ã±¨ÏÔʾ£¬½«½ü40£¥µÄ¿ìÏûÁãÊÛÉ̽«ÔÚÏßÖ§¸¶Ú²ÆÊÓΪ×î´óµÄڲƷçÏÕ£¬45%µÄ¹«Ë¾Ëù¾ÀúµÄÕË»§ÊÕÊÜ(ATO)¹¥»÷ÓÐËùÔö³¤¡£»ã±¨Ô¤²â£¬µç×ÓÉÌÎñÐÐÒµÖеÄÚ²ÆÎÊÌâ¿ÉÄÜ»áÓúÑÝÓúÁÒ£¬ÓÈÆäÊÇËæ×źܶഫͳµÄ¸ß½Ôì·ÅÆ£¨ÈçTopshopºÍDebenhams£©±»ÊÕ¹º²¢ÊµÏÖÒµÎñÈ«ÊýÏòÏßÉÏתÐ͵Äʱ³½¡£
ÔÎÄÁ´½Ó£º
https://pages.ravelin.com/retail-fraud-payments-report


¾©¹«Íø°²±¸11010802024551ºÅ