Google 5ÔÂAndroid°²È«²¼¸æÖÐÓÐ4¸ö0day±»ÔÚÒ°ÀûÓã»ÃÀ¹úÁ½µ³³ǫ̈ÎåÏî·¨°¸ÒÔ¼ÓÇ¿¶ÔÍøÂç¹¥»÷µÄ·ÀÓùÄÜÁ¦
°ä²¼¹¦·ò 2021-05-211.Google 5ÔÂAndroid°²È«²¼¸æÖÐÓÐ4¸ö0day±»ÔÚÒ°ÀûÓÃ

Google Project ZeroÍŶӳƣ¬Æä°ä²¼µÄ5ÔÂAndroid°²È«²¼¸æÖÐÓÐ4¸ö0dayÒѱ»ÔÚÒ°ÀûÓá£Õâ4¸ö·ì϶ӰÏìÁËQualcomm GPUºÍArm Mali GPUÇý¶¯·¨Ê½×é¼þ£¬±ðÀëΪ¿ªÊͺóʹÓ÷ì϶£¨CVE-2021-1905£©¡¢µØÖ·×¢Ïúʧ°ÜÇé¿ö´¦Öò»µ±£¨CVE-2021-1906£©¡¢GPUÄÚ´æ²Ù×÷²»µ±£¨CVE-2021-28663£©ºÍÌáȨ·ì϶£¨CVE-2021-28664£©¡£×êÑÐÈËÔ±½¨ÒéÓû§¾¡¿ì×°ÖÃ×îиüС£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/118089/mobile-2/android-4-zero-day-flaws.html
2.×êÑÐÈËÔ±Åû¶±¼ÌÚµÄMBUXÐÅÏ¢ÓéÀÖϵͳÖеĶà¸ö·ì϶

×êÑÐÈËÔ±Åû¶Á˱¼ÌÚÓû§ÂÄÀú£¨MBUX£©ÐÅÏ¢ÓéÀÖϵͳÖеÄ5¸ö·ì϶¡£ÕâЩ·ì϶±ðÀëΪCVE-2021-23906¡¢CVE-2021-23907¡¢CVE-2021-23908¡¢CVE-2021-23909ºÍCVE-2021-23910£¬¿É±»ÓÃÀ´Äܹ»Èƹý³µÁ¾µÄ·ÀµÁ±£»¤ÉõÖÁ½ÚÔì³µÁ¾£¬Èç´ò¿ª·ÕΧµÆ»ò´ò¿ª´ò¿ªÕÚÑôÕֵȲÙ×÷¡£×êÑÐÈËÔ±»¹·¢ÏÖÁ˶àÖÖ¹¥»÷³¡¾°£¬Ô̺¬ÀûÓÃä¯ÀÀÆ÷µÄJavaScriptÒýÇæ¡¢Wi-FiоƬ¡¢À¶ÑÀ²Ö¿â¡¢USBÖ°ÄÜ»òµÚÈý·½ÀûÓ÷¨Ê½½øÐй¥»÷¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/118081/hacking/mercedes-benz-hack.html
3.ÃÀ¹úÁ½µ³³ǫ̈ÎåÏî·¨°¸ÒÔ¼ÓÇ¿¶ÔÍøÂç¹¥»÷µÄ·ÀÓùÄÜÁ¦

ÃÀ¹ú¶àÒéÔººÓɽ°²È«Î¯Ô±»áÓÚ±¾ÖÜһͨ¹ýÁËÎåÏî·¨°¸£¬ÒÔ¼ÓÇ¿¶ÔÍøÂç¹¥»÷µÄ·ÀÓùÄÜÁ¦¡£ÕâЩ·¨°¸Ô̺¬£ºH.R. 2980£¬¡¶ÍøÂ簲ȫ·ì϶²¹¾È·¨°¸¡·£»H.R. 3138£¬¡¶Öݺʹ¦ËùÍøÂ簲ȫ¸Ä½ø·¨°¸¡· £»H.R. 3223£¬¡¶CISAÍøÂçÑÝϰ·¨¡·£»H.R. 3243£¬¡¶¹Ü·°²È«·¨¡·£»H.R. 3264£¬¡¶ºÓɽ°²È«¹Ø¼üÁìÓò·¨°¸¡·¡£ÕâЩ·¨°¸ÊǺÓɽ°²È«Î¯Ô±»áÕë¶Ô×î½üµÄÍøÂç¹¥»÷¶øÌá³öµÄ£¬¾Ý±¨Â·Colonial PipelineÖ§¸¶ÁË500ÍòÃÀÔªÊê½ð£¬µ«²¢Ã»ÓÐ×èÖ¹¶«±±¸÷ÖÝȼÁϵĴó¹æÄ£Ç·È±¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/us-introduces-bills-to-secure-critical-infrastructure-from-cyber-attacks/
4.Win10×îÐÂÀÛ»ý¸üпɵ¼ÖÂTeamsµÅצÓÃÎÞ·¨µÇ¼

Windows 10 1909 KB5003169ÀÛ»ý¸üе¼ÖÂMicrosoft 365Óû§ÎÞ·¨µÇ¼Teams¡¢OutlookºÍOneDrive¡£Óû§»ã±¨£¬ÆäÔÚ³¢ÊԵǼʱ»áÏÔʾÃýÎó´úÂë80080300£¬²¢³öÏÖ¡°ÎÒÃÇÓöµ½ÁËÎÊÌâ¡£ÔÚ³ÁÐÂÏνӡ¡±µÄÌáÐÑ£¬ÒªÇóÓû§³ÁÐÂÆô¶¯¸Ã·¨Ê½¡£Î¢Èí°µÊ¾£¬Õâ´ÎÖжÏÊÂÎñÊÇÓÉÓÚ¸üÐÂÖеÄÒ»¸ö´úÂëÎÊÌâµ¼Öµģ¬Ö»Ó°ÏìÁ˲¿ÃÅÓû§£¬¿Éͨ¹ý³ÁÐÂÆô¶¯Windows 10½øÐн¨¸´¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/recent-windows-10-update-blocks-microsoft-teams-outlook-logins/
5.TeamBMSÒòAWS S3´æ´¢Í°ÅäÖÃÃýÎóй¶2Íò¶àÓû§ÐÅÏ¢

Website Planet·¢ÏÖ£¬FastTrack Reflex Recruitment£¨ÏÖΪTeamBMS£©ÒòAWS S3´æ´¢Í°ÅäÖÃÃýÎóй¶ÁË2Íò¶àÓû§ÐÅÏ¢¡£¸Ã¹«Ë¾ÖØÒª´Óʹ¹ÖþÖÎÀíϵÍÂäìÓòµÄÕÐÆ¸¹¤×÷£¬ÏîÄ¿Ô̺¬Î²¼ÀûÇò³¡¡¢°ÂÁÔ쥿ËÔ˶¯³¡ºÍϣ˼ÂÞ5ºÅº½Õ¾Â¥µÈ¡£Õâ´Îй¶ÁË21000¸öÎļþ£¬Ô̺¬Óû§µÄµç×ÓÓʼþµØÖ·¡¢È«Ãû¡¢ÊÖ»úºÅÂë¡¢¼Òͥסַ¡¢Éç½»ÍøÂçURL¡¢µ®ÉúÈÕÆÚ¡¢»¤ÕÕºÅÂëºÍÉêÇëÈËÕÕÆ¬µÈ¡£×êÑÐÈËÔ±´§¶È£¬Õâ´Îй¶ÊÇÓɸù«Ë¾µÄIT·þÎñÌṩÉ̵¼Öµġ£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/recruiters-cloud-snafu-exposes/
6.Paloalto°ä²¼2021ÄêCortex XpanseÍþв·ÖÎö»ã±¨

Paloalto°ä²¼ÁË2021ÄêCortex XpanseÍþв·ÖÎö»ã±¨¡£¸Ã»ã±¨´Ó2021Äê1Ôµ½3Ô£¬¶ÔÈ«Çò50¼ÒÆóÒµµÄ5000Íò¸öIPµØÖ·½øÐÐÁË¼à¿ØÉ¨Ã裬ÒÔÏàʶ¹¥»÷ÕßÄܶà¿ìµØ¼ø±ð³ö¿É±»ÀûÓõÄϵͳ¡£¹Ø¼ü·ì϶µÄ¹«¿ªÅû¶,»áÒý·¢¹¥»÷ÕߺÍITÖÎÀíÔ±Ö®¼äµÄ½ÏÁ¿£º¹¥»÷ÕßҪѰÕÒÏàÒ˵ÄÖ¸±ê£¬¶øITÈËÔ±Òª½øÐзçÏÕÆÀ¹ÀºÍ×°ÖñØÒªµÄ²¹¶¡¡£»ã±¨Ö¸³ö£¬¹¥»÷Õß¿ÉÄÜÔÚ0day¹«¿ªºóµÄ15·ÖÖÓÄÚ¶ÔÆä½øÐÐɨÃ裬¶øÕë¶ÔMicrosoft ExchangeÖеķì϶£¬¹¥»÷ÕßÐж¯µÃ¸ü¿ì£¬ÔÚ²»µ½Îå·ÖÖӵŦ·òÄÚ¼´¼ì²âµ½ÁËɨÃè¡£
ÔÎÄÁ´½Ó£º
https://start.paloaltonetworks.com/asm-report


¾©¹«Íø°²±¸11010802024551ºÅ