×êÑÐÈËÔ±Åû¶FragAttacks  £¬Ó°Ïì½ü24ÄêËùÓÐWi-FiÉ豸£»Adobe°ä²¼°²È«¸üР £¬½¨¸´12¿î²úÆ·ÖеÄ43¸ö·ì϶

°ä²¼¹¦·ò 2021-05-13

1.×êÑÐÈËÔ±Åû¶FragAttacks  £¬Ó°Ïì½ü24ÄêËùÓÐWi-FiÉ豸


1.jpg


±ÈÀûʱ°²È«×êÑÐÔ±Mathy VanhoefÅû¶Á˱»Í³³ÆÎªFragAttacksµÄ¶à¸ö·ì϶  £¬Ó°ÏìÁË1997ÄêÖÁ½ñµÄËùÓÐWi-FiÉ豸£¨Ô̺¬ÍÆËã»ú¡¢ÖÇÄÜÊÖ»úºÍÖÇÄÜÉ豸£©¡£ÔÚÕâЩ·ì϶ÖÐ  £¬ÓÐ3¸öÊÇWi-Fi 802.11³ß¶ÈÔÚÖ¡¾ÛºÏºÍÖ¡Ë鯬ְÄÜÉϵÄÉè¼ÆÈ±µã  £¬¶øÆäËû·ì϶ÔòÊÇWi-Fi²úÆ·Öеıà³ÌÃýÎó¡£Vanhoef³Æ  £¬³¢ÊÔÁ˾ÖÏÔʾÿ¸öWi-Fi²úÆ·¶¼´æÔÚÖÁÉÙÒ»¸ö·ì϶ÇÒ´óÎÞÊý²úÆ·´æÔÚ¶à¸ö·ì϶  £¬Ö»ÓÐNetBSDºÍOpenBSD²»ÊÜÓ°Ïì  £¬ÓÉÓÚËüÃDz»Ö§³ÖA-MSDUµÄ½Ó¹Ü¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/117819/hacking/wifi-fragattacks.html


2.Adobe°ä²¼°²È«¸üР £¬½¨¸´12¿î²úÆ·ÖеÄ43¸ö·ì϶


2.jpg


Adobe°ä²¼ÁË´ó¹æÄ£µÄÖܶþ²¹¶¡³Ì  £¬½¨¸´ÁË12¿î²úÆ·ÖеÄ43¸ö·ì϶¡£Õâ´Î°²È«¸üн¨¸´ÁËAdobe AcrobatºÍReaderÖÐÒѱ»ÔÚÒ°ÀûÓõÄÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2021-28550£©  £¬¹¥»÷Õß¿ÉÀûÓÃÆäÔÚÖ¸±êϵͳÖÐ×°ÖöñÒâÈí¼þ»òÊÕÊÜÍÆËã»ú¡£´Ë±í  £¬»¹½¨¸´ÁËAcrobatºÍReaderÖеÄËÁÒâ´úÂëÖ´Ðеķì϶£¨CVE-2021-28562ºÍCVE-2021-28553£©¡¢ IllustratorÖеÄÔ½½çд·ì϶£¨CVE-2021-21101£©ºÍAEMÖеÄXSS·ì϶£¨CVE-2021-21084£©µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-fixes-reader-zero-day-vulnerability-exploited-in-the-wild/


3.¼ÙװΪChromeµÄAndroid¶ñÒâÈí¼þÒÑϰȾÊýÊ®ÍòÉ豸


3.jpg


PradeoµÄ×êÑÐÈËÔ±·¢ÏÖ  £¬ÔÚ´ÓǰµÄ¼¸ÖÜÖÐ  £¬¼ÙװΪChromeµÄÒ»ÖÖеÄAndroid¶ñÒâÈí¼þÒÑϰȾÊýÊ®ÍòÉ豸¡£ºÚ¿Í»áÏòÖ¸±ê·¢ËÍÒ»Ìõ¶ÌÐÅ  £¬ÒªÇóËûÃÇÖ§¸¶º£¹ØÓöÈÀ´Í¶µÝ°ü¹ü¡£µ±Ö¸±êµã»÷¶ÌÐÅÖеÄÁ´½Óºó¾Í»áµ¯³öÒ»ÌõÐÅÏ¢  £¬ÌáÐÑËûÃǸüÐÂChromeÀûÓ÷¨Ê½¡£Ö®ºóÓû§»á±»³Á¶¨Ïòµ½´¹µöÍøÕ¾  £¬²¢±»ÒªÇóÖ§¸¶Ò»Ó×±ÊÇ®£¨Í¨³£Îª1»ò2ÃÀÔª£©ÒÔÍøÂçÐÅÓþ¿¨¾ßÌåÐÅÏ¢¡£´Ë±í  £¬¸ÃαÔìµÄChrome»áÀûÓñ»Ï°È¾µÄÊÖ»úÿÌì×Ô¶¯·¢ËÍ300Ìõ´¹µö¶ÌÐŽøÐд«²¼¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/fake-chrome-app-worming-smish-cyberattack/166038/


4.United ValorÔâÀÕË÷¹¥»÷  £¬Ð¹Â¼ûÀ¹ú20ÍòÍËÒÛÎäÊ¿ÐÅÏ¢


4.png


Jeremiah FowlerÓÚ4ÔÂ18ÈÕ·¢ÏÖUnited Valorй¶Á˽ü20ÍòÃûÃÀ¹úÍËÒÛÎäÊ¿µÄÒ½ÁƼͼ¡£United ValorÊDZ±¿¨ÂÞÀ´ÄÉÖݵÄÒ»¼ÒΪÍËÒÛÎäÊ¿ÖÎÀí¾ÖÒÔ¼°ÆäËûÁª¹úºÍÖݵĻú¹¹Ìṩ²Ð¼²ÆÀ¹À·þÎñµÄ¹«Ë¾¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢Ò½ÁÆÐÅÏ¢¡¢ÁªÏµÐÅÏ¢¡¢Ò½ÉúÐÅÏ¢ºÍÔ¤Ô¼¹¦·ò  £¬ÒÔ¼°ÁËδ¼ÓÃܵÄÃÜÂëºÍÕ˵¥¾ßÌåÐÅÏ¢¡£¸Ã¹«Ë¾³ÆÕâ´Îй¶ÊÇÓÉÓÚÄÚ²¿²Ù×÷ÃýÎóµ¼Ö嵀  £¬µ«Fowler³ÆÆä·¢ÏÖÁËÃûΪread_meµÄÀÕË÷ÐÅÏ¢  £¬ÉÏÃæ°µÊ¾ËùÓмͼ¾ùÒÑÏÂÔØ  £¬²¢ÒªÇóÖ§¸¶0.15±ÈÌØ±Ò£¨8148ÃÀÔª£©¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/veterans-medical-records-ransomware/166025/


5.BabukÍÅ»ïÐû³ÆÒÑÇÔÈ¡ÈÕ±¾µÄYamabiko 0.5TBÊý¾Ý


5.jpg


BabukÍÅ»ïÐû³ÆÒѹ¥»÷ÈÕ±¾¹«Ë¾Yamabiko²¢ÇÔÈ¡ÁË0.5TBÊý¾Ý¡£YamabikoµÄ×ܲ¿Î»ÓÚ¶«¾©  £¬ÔÚÈ«ÇòÁìÓòÄÚÏúÊ۵綯¹¤¾ß¡¢Å©Òµ»úеºÍ»§±í¶¯Á¦É豸  £¬ÄêÊÕÈ볬¹ýÊ®ÒÚÃÀÔª¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬Îļþϵͳ¡¢SolidworksÎļþ¡¢Ô±¹¤Ó×ÎÒÊý¾Ý¡¢²ÆÕþ»ã±¨¡¢²âÊÔͼºÍµç·µÀÀíͼµÈ¡£µ«ÊÇÁîÈËÒÉ»óµÄÊÇ  £¬BabukÔø°µÊ¾Õë¶Ô»ªÊ¢¶ÙÌØÇø¾¯Ô±¾ÖµÄ¹¥»÷½«ÊÇÆä×îºóÒ»´Î»î¶¯  £¬²¢½«¹«¿ªÆä´úÂë  £¬µ«Ä¿Ç°ËƺõÒѸ´Ô­Õý³£ÔËÐС£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/japanese-manufacturer-yamabiko/


6.CISAºÍFBI½áºÏ°ä²¼ÓйØDarkSideÍÅ»ïµÄ°²È«Õ÷ѯ


6.jpg


ÃÀ¹úCISAºÍFBI½áºÏ°ä²¼ÁËÓйØDarkSideÍÅ»ïµÄ°²È«Õ÷ѯ¡£ÔÚ½üÆÚµÄ»î¶¯ÖÐ  £¬DarkSide½«Ö¸±ê¶Ô×¼Á˶à¸öÁìÓòµÄ¹Ø¼ü»ù´¡ÉèÊ©£¨CI£©×éÖ¯  £¬Ô̺¬Ôì×÷¡¢Ë¾·¨¡¢±£ÏÕ¡¢Ò½ÁƱ£½¡ºÍÄÜÔ´ÐÐÒµ¡£¸ÃÍÅ»ïÔø¹«¿ª°µÊ¾  £¬ËûÃǸÊÐĶÔ×¼ÓÐÄÜÁ¦Ö§¸¶´ó±ÊÊê½ðµÄ×éÖ¯  £¬¶ø·ÇÒ½Ôº¡¢Ñ§ÌᢷÇͶ»ú×éÖ¯ºÍµ±¾Ö»ú¹¹¡£×îºó  £¬¸ÃÕ÷ѯ»¹ÌṩÁË´óÁ¿µÄ»º½â´ëÊ©À´Ô®ÊÖCIÔËÓªÉÌÕмܺÍÓ¦¶Ô´ËÀ๥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/05/11/joint-cisa-fbi-cybersecurity-advisory-darkside-ransomware