×êÑÐÈËÔ±Åû¶FragAttacks£¬Ó°Ïì½ü24ÄêËùÓÐWi-FiÉ豸£»Adobe°ä²¼°²È«¸üУ¬½¨¸´12¿î²úÆ·ÖеÄ43¸ö·ì϶
°ä²¼¹¦·ò 2021-05-131.×êÑÐÈËÔ±Åû¶FragAttacks£¬Ó°Ïì½ü24ÄêËùÓÐWi-FiÉ豸

±ÈÀûʱ°²È«×êÑÐÔ±Mathy VanhoefÅû¶Á˱»Í³³ÆÎªFragAttacksµÄ¶à¸ö·ì϶£¬Ó°ÏìÁË1997ÄêÖÁ½ñµÄËùÓÐWi-FiÉ豸£¨Ô̺¬ÍÆËã»ú¡¢ÖÇÄÜÊÖ»úºÍÖÇÄÜÉ豸£©¡£ÔÚÕâЩ·ì϶ÖУ¬ÓÐ3¸öÊÇWi-Fi 802.11³ß¶ÈÔÚÖ¡¾ÛºÏºÍÖ¡Ë鯬ְÄÜÉϵÄÉè¼ÆÈ±µã£¬¶øÆäËû·ì϶ÔòÊÇWi-Fi²úÆ·Öеıà³ÌÃýÎó¡£Vanhoef³Æ£¬³¢ÊÔÁ˾ÖÏÔʾÿ¸öWi-Fi²úÆ·¶¼´æÔÚÖÁÉÙÒ»¸ö·ì϶ÇÒ´óÎÞÊý²úÆ·´æÔÚ¶à¸ö·ì϶£¬Ö»ÓÐNetBSDºÍOpenBSD²»ÊÜÓ°Ï죬ÓÉÓÚËüÃDz»Ö§³ÖA-MSDUµÄ½Ó¹Ü¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/117819/hacking/wifi-fragattacks.html
2.Adobe°ä²¼°²È«¸üУ¬½¨¸´12¿î²úÆ·ÖеÄ43¸ö·ì϶

Adobe°ä²¼ÁË´ó¹æÄ£µÄÖܶþ²¹¶¡³Ì£¬½¨¸´ÁË12¿î²úÆ·ÖеÄ43¸ö·ì϶¡£Õâ´Î°²È«¸üн¨¸´ÁËAdobe AcrobatºÍReaderÖÐÒѱ»ÔÚÒ°ÀûÓõÄÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2021-28550£©£¬¹¥»÷Õß¿ÉÀûÓÃÆäÔÚÖ¸±êϵͳÖÐ×°ÖöñÒâÈí¼þ»òÊÕÊÜÍÆËã»ú¡£´Ë±í£¬»¹½¨¸´ÁËAcrobatºÍReaderÖеÄËÁÒâ´úÂëÖ´Ðеķì϶£¨CVE-2021-28562ºÍCVE-2021-28553£©¡¢ IllustratorÖеÄÔ½½çд·ì϶£¨CVE-2021-21101£©ºÍAEMÖеÄXSS·ì϶£¨CVE-2021-21084£©µÈ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/adobe-fixes-reader-zero-day-vulnerability-exploited-in-the-wild/
3.¼ÙװΪChromeµÄAndroid¶ñÒâÈí¼þÒÑϰȾÊýÊ®ÍòÉ豸

PradeoµÄ×êÑÐÈËÔ±·¢ÏÖ£¬ÔÚ´ÓǰµÄ¼¸ÖÜÖУ¬¼ÙװΪChromeµÄÒ»ÖÖеÄAndroid¶ñÒâÈí¼þÒÑϰȾÊýÊ®ÍòÉ豸¡£ºÚ¿Í»áÏòÖ¸±ê·¢ËÍÒ»Ìõ¶ÌÐÅ£¬ÒªÇóËûÃÇÖ§¸¶º£¹ØÓöÈÀ´Í¶µÝ°ü¹ü¡£µ±Ö¸±êµã»÷¶ÌÐÅÖеÄÁ´½Óºó¾Í»áµ¯³öÒ»ÌõÐÅÏ¢£¬ÌáÐÑËûÃǸüÐÂChromeÀûÓ÷¨Ê½¡£Ö®ºóÓû§»á±»³Á¶¨Ïòµ½´¹µöÍøÕ¾£¬²¢±»ÒªÇóÖ§¸¶Ò»Ó×±ÊÇ®£¨Í¨³£Îª1»ò2ÃÀÔª£©ÒÔÍøÂçÐÅÓþ¿¨¾ßÌåÐÅÏ¢¡£´Ë±í£¬¸ÃαÔìµÄChrome»áÀûÓñ»Ï°È¾µÄÊÖ»úÿÌì×Ô¶¯·¢ËÍ300Ìõ´¹µö¶ÌÐŽøÐд«²¼¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/fake-chrome-app-worming-smish-cyberattack/166038/
4.United ValorÔâÀÕË÷¹¥»÷£¬Ð¹Â¼ûÀ¹ú20ÍòÍËÒÛÎäÊ¿ÐÅÏ¢

Jeremiah FowlerÓÚ4ÔÂ18ÈÕ·¢ÏÖUnited Valorй¶Á˽ü20ÍòÃûÃÀ¹úÍËÒÛÎäÊ¿µÄÒ½ÁƼͼ¡£United ValorÊDZ±¿¨ÂÞÀ´ÄÉÖݵÄÒ»¼ÒΪÍËÒÛÎäÊ¿ÖÎÀí¾ÖÒÔ¼°ÆäËûÁª¹úºÍÖݵĻú¹¹Ìṩ²Ð¼²ÆÀ¹À·þÎñµÄ¹«Ë¾¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢Ò½ÁÆÐÅÏ¢¡¢ÁªÏµÐÅÏ¢¡¢Ò½ÉúÐÅÏ¢ºÍÔ¤Ô¼¹¦·ò£¬ÒÔ¼°ÁËδ¼ÓÃܵÄÃÜÂëºÍÕ˵¥¾ßÌåÐÅÏ¢¡£¸Ã¹«Ë¾³ÆÕâ´Îй¶ÊÇÓÉÓÚÄÚ²¿²Ù×÷ÃýÎóµ¼Öµģ¬µ«Fowler³ÆÆä·¢ÏÖÁËÃûΪread_meµÄÀÕË÷ÐÅÏ¢£¬ÉÏÃæ°µÊ¾ËùÓмͼ¾ùÒÑÏÂÔØ£¬²¢ÒªÇóÖ§¸¶0.15±ÈÌØ±Ò£¨8148ÃÀÔª£©¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/veterans-medical-records-ransomware/166025/
5.BabukÍÅ»ïÐû³ÆÒÑÇÔÈ¡ÈÕ±¾µÄYamabiko 0.5TBÊý¾Ý

BabukÍÅ»ïÐû³ÆÒѹ¥»÷ÈÕ±¾¹«Ë¾Yamabiko²¢ÇÔÈ¡ÁË0.5TBÊý¾Ý¡£YamabikoµÄ×ܲ¿Î»ÓÚ¶«¾©£¬ÔÚÈ«ÇòÁìÓòÄÚÏúÊ۵綯¹¤¾ß¡¢Å©Òµ»úеºÍ»§±í¶¯Á¦É豸£¬ÄêÊÕÈ볬¹ýÊ®ÒÚÃÀÔª¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬Îļþϵͳ¡¢SolidworksÎļþ¡¢Ô±¹¤Ó×ÎÒÊý¾Ý¡¢²ÆÕþ»ã±¨¡¢²âÊÔͼºÍµç·µÀÀíͼµÈ¡£µ«ÊÇÁîÈËÒÉ»óµÄÊÇ£¬BabukÔø°µÊ¾Õë¶Ô»ªÊ¢¶ÙÌØÇø¾¯Ô±¾ÖµÄ¹¥»÷½«ÊÇÆä×îºóÒ»´Î»î¶¯£¬²¢½«¹«¿ªÆä´úÂ룬µ«Ä¿Ç°ËƺõÒѸ´ÔÕý³£ÔËÐС£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/japanese-manufacturer-yamabiko/
6.CISAºÍFBI½áºÏ°ä²¼ÓйØDarkSideÍÅ»ïµÄ°²È«Õ÷ѯ

ÃÀ¹úCISAºÍFBI½áºÏ°ä²¼ÁËÓйØDarkSideÍÅ»ïµÄ°²È«Õ÷ѯ¡£ÔÚ½üÆÚµÄ»î¶¯ÖУ¬DarkSide½«Ö¸±ê¶Ô×¼Á˶à¸öÁìÓòµÄ¹Ø¼ü»ù´¡ÉèÊ©£¨CI£©×éÖ¯£¬Ô̺¬Ôì×÷¡¢Ë¾·¨¡¢±£ÏÕ¡¢Ò½ÁƱ£½¡ºÍÄÜÔ´ÐÐÒµ¡£¸ÃÍÅ»ïÔø¹«¿ª°µÊ¾£¬ËûÃǸÊÐĶÔ×¼ÓÐÄÜÁ¦Ö§¸¶´ó±ÊÊê½ðµÄ×éÖ¯£¬¶ø·ÇÒ½Ôº¡¢Ñ§ÌᢷÇͶ»ú×éÖ¯ºÍµ±¾Ö»ú¹¹¡£×îºó£¬¸ÃÕ÷ѯ»¹ÌṩÁË´óÁ¿µÄ»º½â´ëÊ©À´Ô®ÊÖCIÔËÓªÉÌÕмܺÍÓ¦¶Ô´ËÀ๥»÷¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2021/05/11/joint-cisa-fbi-cybersecurity-advisory-darkside-ransomware


¾©¹«Íø°²±¸11010802024551ºÅ