VMware°²È«¸üУ¬½¨¸´vCenterÖÐÑϳÁµÄRCE·ì϶£»ANSSIÅû¶BluetoothCoreºÍMeshºÍ̸Öжà¸ö°²È«·ì϶
°ä²¼¹¦·ò 2021-05-261.VMware°ä²¼°²È«¸üУ¬½¨¸´vCenterÖÐÑϳÁµÄRCE·ì϶

VMware°ä²¼°²È«¸üУ¬½¨¸´vCenterÖÐÑϳÁµÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©·ì϶¡£¸Ã·ì϶±»×·×ÙΪCVE-2021-21985£¬CVSSv3ÆÀ·ÖΪ9.8£¬Ó°ÏìÁËvCenter Server 6.5¡¢6.7ºÍ7.0¡£·ì϶ÊÇÓÉÓÚVirtual SANÔËÐÐÇé¿ö²é³²å¼þÖжÌȱÊäÈëÑéÖ¤µ¼Öµģ¬ÓµÓÐ443¶Ë¿Ú½Ó¼ûȨµÄ¹¥»÷ÕßÄܹ»ÀûÓÃÆäÖ´ÐÐËÁÒâºÅÁî¡£VMware³Æ£¬ËùÓÐvCenter Server£¬ÎÞÂÛÆäÊÇ·ñʹÓÃvSAN£¬¶¼Ä¬ÈÏÆôÓÃÁËVirtual SANÔËÐÐÇé¿ö²é³²å¼þ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/vmware-warns-of-critical-bug-affecting-all-vcenter-server-installs/
2.ANSSIÅû¶Bluetooth CoreºÍMeshºÍ̸Öжà¸ö°²È«·ì϶

·¨¹úµý±¨»ú¹¹ANSSIµÄ×êÑÐÈËÔ±·¢ÏÖÁËBluetooth CoreºÍMesh ProfileºÍ̸ÖдæÔÚ¶à¸ö·ì϶¡£ÕâÁ½¸öºÍ̸½ç˵ÁËÀ¶ÑÀÉ豸Ï໥ͨѶËùÐèµÄÐèÒª£¬ÒÔ¼°À¶ÑÀÉ豸ʹÓõÍÄܺÄÎÞÏß¼¼ÊõʵÏÖ»¥²Ù×÷µÄÍø×´ÍøÂç½â¾ö¹æ»®ËùÐèµÄÐèÒª¡£·ì϶±ðÀëΪCVE-2020-26559¡¢CVE-2020-26556¡¢CVE-2020-26557ºÍCVE-2020-26560µÈ£¬¹¥»÷ÕßÀûÓÃÕâЩ·ì϶¿ÉÔÚÅä¶Ô¹ý³ÌÖмÙÒâºÏ·¨É豸£¬²¢ÌáÒéÖÐÑëÈË£¨MitM£©¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/118219/hacking/bluetooth-core-mesh-specs-flaws.html
3.ÈÕ±¾»é½éÀûÓÃOmiaiÔâµ½¹¥»÷£¬171Íò»áÔ±µÄÐÅϢй¶

ÈÕ±¾×î´óµÄ»é½éÀûÓÃOmiaiÔâµ½¹¥»÷£¬1711756¸ö»áÔ±µÄÐÅϢй¶¡£Õâ¿îÀûÓÃÕ¼Óг¬¹ý680Íò¸öÕÊ»§£¬Ã¿ÔÂÏòÄÐÊ¿ÊÕÈ¡37ÃÀÔªµÄÓöȡ£Omiai°µÊ¾£¬Ð¹Â¶µÄÐÅϢΪ2018Äê1ÔÂÖÁ2021Äê4ÔÂÖ®¼ä£¬Ô̺¬ÐÕÃûµ®ÉúÈÕÆÚ¡¢×¢²áºÅ¡¢¼ÝÕÕ¡¢±£ÏÕ¿¨ºÍ»¤Õյȣ¬²¢¼á³ÆÃ»ÓÐÈκÎÐÅÓþ¿¨Êý¾Ýй¶¡£Hackread.com֤ʵ£¬Ä¿Ç°Ò»Ð©ºÚ¿ÍÂÛ̳ÉϵÄÍþвÕßÒѾÔÚѰÕÒ±»µÁµÄOmiaiÊý¾Ý¿â¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/japanese-dating-app-omiai-hack-users-at-risk/
4.ClearSky³ÆÒÑÇÔÈ¡ÊýÒÚÃÀÔªµÄCryptoCoreÓ볯ÏÊÓйØ

ÍøÂ簲ȫ¹«Ë¾ClearSky³ÆÒÑÇÔÈ¡ÊýÒÚÃÀÔªµÄCryptoCoreÓ볯ÏÊÓйء£CryptoCore×Ô2018ÄêÆðÍ·»îÔ¾£¬¹¥»÷ÁËÃÀ¹ú¡¢ÒÔÉ«ÁÓעŷÖÞºÍÈÕ±¾µÈ¹úµÄ¼ÓÃÜÇ®±ÒÂòÂôËù£¬Ôì³ÉµÄËðʧ¹À¼Æ³¬¹ý2ÒÚÃÀÔª¡£×î³õ£¬ClearSkyÒÔΪ¸ÃÍÅ»ïÓëÎÚ¿ËÀ¼¡¢¶íÂÞ˹ºÍÂÞÂíÄáÑǵȶ«Å·¹ú¶ÈÓйء£½üÆÚ·¢ÏÖCryptoCoreÓëF-SecureµÄ»î¶¯¸ß¶ÈÒ»Ö£¬ºóÕßÓ볯ÏʵÄLazarus×éÖ¯Óйء£×êÑÐÈËÔ±»¹Ö¸³ö£¬ºÚ¿ÍµÄ»î¶¯Ò²ÔÚÀ©´ó£¬×î½üÆðÍ·½«É«ÁÐ×÷Ϊָ±ê¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/north-korean-hackers-behind-cryptocore-multi-million-dollar-heists/
5.FBIǰµý±¨·ÖÎöʦ±»Ö¸¿ØÔÚ´Óǰ13ÄêÀïÇÔÈ¡»úÃÜÎļþ

FBIǰµý±¨·ÖÎöʦKendra Kingsbury±»Ö¸¿ØÔÚ´Óǰ13ÄêÀïÇÔÈ¡»úÃÜÎļþ¡£ÃÀ¹ú˾·¨²¿£¨DoJ£©°µÊ¾£¬´Ó2004Äê6ÔÂÖÁ2017Äê12Ô£¬Kingsbury½«Óйعú¶È°²È«¡¢»úÃܺͻúÒªµÄÎļþ±£ÁôÔÚ¼ÒÀï¡£¸æ×´ÊéÖ¸³ö£¬±»¸æÎÞȨɾ³ýºÍ±£ÁôÕâЩÃô¸ÐÈ·µ±¾Ö×ÊÁÏ¡£KingsburyÔÚFBI¹¤×÷12ÄêÒÔÉÏ£¬Êܹý´¦ÖÃÃô¸Ð×ÊÁϺͱ£ÃÜÐÐΪµÄÅàѵ£¬ÈÎÖ°ÆÚ¼äÔÚ·´¿Ö¡¢··¶¾ºÍÖúÅÉ·¸×ïµÄÓ×¶Ó¹¤×÷¡£KingsburyÓÚ2017Ä걻ְͣ£¬±»¿ØÁ½ÏîÓÐÒâ±£Áô¹ú·ÀÐÅÏ¢µÄ×ïÃû£¬ÏÖÒѱ»²¶¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/fbi-intelligence-officer-indicted-for-theft-of-cybersecurity-threat-counterterrorism-documents/
6.ÔìÒ©¹«Ë¾SiegfriedÔâµ½¹¥»÷£¬¶à¸ö·Ö¹«Ë¾ÔÝÍ£³ö²ú

ÔìÒ©¹«Ë¾Siegfried³ÆÆäÔâµ½¹¥»÷£¬¶à¸ö·Ö¹«Ë¾ÔÝÍ£³ö²ú¡£SiegfriedÊÇÒ»¼ÒÈ«ÇòÐÔµÄÒ½Ò©¹«Ë¾£¬ÔÚÈðÊ¿¡¢µÂ¹ú¡¢Î÷°àÑÀ¡¢·¨¹ú¡¢Âí¶úËû¡¢ÃÀ¹úºÍÖйúÉèÓзֹ«Ë¾¡£¸Ã¹«Ë¾ÓÚ5ÔÂ21ÈÕÐÇÆÚÎåÍíÉϼì²âµ½¹¥»÷£¬Ö®ºóµ±¼´²ÉÈ¡´ëÊ©£¬ÔÝÍ£Á˸÷¸ö·Ö¹«Ë¾µÄ³ö²ú²¢ÖжÏÁËÍøÂçÏνӡ£¸Ã¹«Ë¾³Æ£¬³ýÁËÔÚÎ÷°àÑÀµÄÁ½¸öµØÖ·ÓÉÓÚÔÚ¸ôÀëµÄÍøÂçÉÏÔËÐÐ±í¶øÎ´ÊÜÓ°Ïì±í£¬ÆäËûµÄ¹«Ë¾¾ùÊܵ½ÁË·ÖÆçˮƽµÄÓ°Ïì¡£
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/ch-siegfried-affected-by-attack-on-its-it-systems/


¾©¹«Íø°²±¸11010802024551ºÅ