ÃÀ¹úµ±¾ÖÈ·ÈÏSolarWinds¹¥»÷Óë¶íÂÞ˹µý±¨¾ÖSVRÓйØ £»Ó¡¶ÈBizongoµÄ´æ´¢Í°ÅäÖÃÃýÎó£¬Ð¹Â¶643 GBµÄÊý¾Ý

°ä²¼¹¦·ò 2021-04-16

1.ÃÀ¹úµ±¾ÖÈ·ÈÏSolarWinds¹¥»÷Óë¶íÂÞ˹µý±¨¾ÖSVRÓйØ


1.jpg


ÃÀ¹úµ±¾ÖÕýʽָ¿Ø¶íÂÞ˹µ±¾ÖÌáÒéÁËSolarWinds¹©¸øÁ´¹¥»÷£¬Ó°ÏìÁËÃÀ¹úµÄ¶à¸ö×éÖ¯ºÍ¹«Ë¾¼¼Êõ²¿ÃŵÄÍøÂç¡£½ñÄê1Ô³õ£¬ÍøÂçͳһЭµ÷Ó××飨UCG£©½«Õâ´Î¹¥»÷¹éÒòÓÚ¶íÂÞ˹²¼¾°µÄºÚ¿Í×éÖ¯£¬µ«Î´Ö¸³ö¾ßÌåÃû³Æ¡£4ÔÂ15ÈÕ£¬°×¹¬ÕýʽȷÈ϶íÂÞ˹±í¹úµý±¨¾ÖSVRÊÇÕâ´Î¹¥»÷µÄÄ»ºóºÚÊÖ£¬Í¨¹ýÆäºÚ¿Í²¿ÃÅAPT29£¨ÓÖ³ÆCozy Bear£©·¢Õ¹µÄÍøÂç¼äµý»î¶¯¡£´Ë±í£¬ÃÀ¹úNSA¡¢CISAºÍFBI½áºÏ°ä²¼Á˰²È«Õ÷ѯ£¬ÖÒ¸æSVRÔÚ¹¥»÷ÖÐÀûÓõÄÎå¸öÖØÒªµÄ·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-government-confirms-russian-svr-behind-the-solarwinds-hack/


2.Ó¡¶ÈBizongoµÄ´æ´¢Í°ÅäÖÃÃýÎó£¬Ð¹Â¶643 GBµÄÊý¾Ý


2.jpg


Ó¡¶ÈB2B°ü×°Êг¡BizongoÒòAWS S3´æ´¢Í°ÅäÖÃÃýÎó£¬Ð¹Â¶643 GBµÄÊý¾Ý¡£Õâ´Îй¶µÄÊý¾ÝÉæ¼°Óû§µÄPIIºÍBizongoµÄ¸¶¿îÐÅÏ¢£¬Ô̺¬Óû§µÄÐÕÃû¡¢µç»°ºÅÂë¡¢Õʵ¥µØÖ·¡¢ÊÕ»õµØÖ·¡¢ÔËËͺ͸ú×Ù±àºÅ¡¢Õʵ¥Ã÷ϸºÍ¿Í»§µÄ²ÆÕþÃ÷ϸµÈ¡£Website PlanetµÄ×êÑÐÈËÔ±ÓÚ2020Äê12ÔÂÏÂÑ®·¢Ïָô洢Ͱ£¬²¢µ±¼´¾Í´ËÊÂÎñÓëBizongoÁªÏµ£¬µ«Ä¿Ç°ÈÔδÊÕµ½ÈκλØÓ¦¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/india-bizongo-supply-chain-exposed-data/


3.SAP°ä²¼°²È«¸üУ¬½¨¸´Æä²úÆ·ÖеĶà¸öÑϳÁµÄ·ì϶


3.jpg


±¾Öܶþ£¬SAP°ä²¼°²È«¸üУ¬½¨¸´ÁËBusiness Client¡¢CommerceºÍNetWeaverÖеÄ×ܼƶà¸ö·ì϶¡£ÆäÖнÏΪÑϳÁµÄÊÇCommerceÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-27602£©£¬µÃ·ÖΪ9.8 £»ÒÔ¼°NetWeaver²Ö¿âµÄMigration Service×é¼þÖеÄCVE-2021-21481£¬µÃ·ÖΪ9.6£¬Î´¾­ÊÚȨµÄ¹¥»÷ÕßÄܹ»½Ó¼ûÅäÖöÔÏóÒÔ»ñµÃϵͳÉϵÄÖÎÀíȨÏÞ¡£´Ë±í£¬»¹½¨¸´ÁËCVE-2021-21482¡¢CVE-2021-21483ºÍCVE-2020-26832µÈ·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/sap-fixes-critical-bugs-in-business-client-commerce-and-netweaver/


4.Census LabsÅû¶°²×¿°æ±¾WhatsAppµÄ´úÂëÖ´Ðзì϶


4.jpg


Census LabsµÄ×êÑÐÈËÔ±Åû¶Á˰²×¿°æ±¾µÄWhatsAppÖеÄÁ½¸ö´úÂëÖ´Ðзì϶£¬¿É±»ÓÃÀ´ÔÚÖ¸±êÉ豸ÉÏÖ´ÐжñÒâ´úÂë²¢ÇÔÌýͨѶ¡£ÕâÁ½¸ö·ì϶¿ÉÓÃÀ´Ô¶³ÌÍøÂçTLS 1.3ºÍTLS 1.2»á»°µÄTLS¼ÓÃÜÐÅÏ¢£¬²¢ÌáÒéÖÐÑëÈË£¨MitM£©¹¥»÷¡£ÓÈÆäÊÇCVE-2021-24027·ì϶£¬ÀûÓÃÁËChrome¶ÔAndroidÖÐÄÚÈÝÌṩÕßµÄÖ§³ÖÒÔ¼°ä¯ÀÀÆ÷ÖеÄͬԴսÊõÈÆ¹ý·ì϶£¨CVE-2020-6516£©£¬Í¨¹ýWhatsApp½«ÌØÔìµÄHTMLÎļþ·¢Ë͸øÊܺ¦Õߣ¬µ±Êܺ¦ÕßÔÚä¯ÀÀÆ÷Öдò¿ªºó£¬½«Ö´ÐиÃÎļþÖÐÔ̺¬µÄ´úÂë¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116833/hacking/whatsapp-flaws-remote-hack.html


5.FireEye°ä²¼ÃûΪM-Trend 2021µÄÄê¶È·ÖÎö»ã±¨


5.jpg


FireEye»ùÓÚ¶ÔÆäÖÎÀíµÄ°²È«ÊÂÎñ½øÐе÷²éÆÚ¼äÍøÂçµÄÊý¾Ý£¬°ä²¼ÁËÃûΪM-Trend 2021µÄÄê·ÖÎö¶È»ã±¨¡£FireEye Mandiantµ÷²éÁË246¸öºÚ¿Í×éÖ¯µÄ¹¥»÷»î¶¯£¬ÆäÖÐÔ̺¬4¸ö²ÆÕþÍþв£¨FIN£©×éÖ¯£¬6¸ö¸ß¼¶³ÖÐøÍþв£¨APT£©×éÖ¯ºÍ236¸öδ·ÖÀàÍþв£¨UNC£©×éÖ¯¡£´Ë±í£¬Ç°5ÖÖ¶ñÒâÈí¼þÀà±ðÊǺóÃÅ£¨36£¥£©¡¢ÏÂÔØÆ÷£¨16£¥£©¡¢droppers£¨8£¥£©¡¢Æô¶¯Æ÷£¨7£¥£©ºÍÀÕË÷Èí¼þ£¨5£¥£©£¬Ç°5¸ö¶ñÒâÈí¼þ¼Ò×å±ðÀëÊÇBEACON¡¢EMPIRE¡¢MAZE¡¢NETWALKERºÍMetasploit¡£


Ô­ÎÄÁ´½Ó£º

https://content.fireeye.com/m-trends/rpt-m-trends-2021


6.CISA°ä²¼Õë¶ÔÍøÂ簲ȫ×êÑÐÈËÔ±µÄAPT»î¶¯µÄ¾¯±¨


6.jpg


CISA°ä²¼ÁËÕë¶ÔÍøÂ簲ȫ×êÑÐÈËÔ±µÄAPT»î¶¯µÄ¾¯±¨¡£¾¯±¨Ö¸³öAPT¹¥»÷ÕßÔÚʹÓÃαÔìµÄÉ罻ýÌå×ÊÁϺÍÃ²ËÆºÏ·¨µÄÍøÕ¾À´ÒýÓÕ°²È«×êÑÐÈËÔ±½Ó¼û¶ñÒâÍøÕ¾£¬ÒÔÇÔÈ¡Ô̺¬·ì϶ÀûÓúÍÁãÈÕ·ì϶ÔÚÄÚµÄÐÅÏ¢¡£´Ë±í£¬GoogleºÍMicrosoft×î½ü¶¼°ä²¼ÁËÕë¶Ô´ËÀ๥»÷µÄ»ã±¨¡£CISA½¨ÒéÍøÂ簲ȫ´ÓÒµÈËÔ±ÔÚ½Ó¼û²»ÊÜÐÅÀµµÄ´úÂë»òÍøÕ¾Ê±£¬Ê¹ÓÃÓëÊÜÐÅÀµµÄϵͳºÍÍøÂç¸ôÀëµÄɳºÐ»·¾³¡£ 


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/04/14/threat-actors-targeting-cybersecurity-researchers