΢Èí°ä²¼7Ô·ݰ²È«¸üУ¬½¨¸´9¸ö0dayÔÚÄÚµÄ117¸ö·ì϶£»Ê±ÉÐÆ·ÅÆGuessÔâµ½DarkSideÀÕË÷¹¥»÷й¶200GBÎļþ
°ä²¼¹¦·ò 2021-07-151.΢Èí°ä²¼7Ô·ݰ²È«¸üУ¬½¨¸´9¸ö0dayÔÚÄÚµÄ117¸ö·ì϶

΢Èí°ä²¼ÁË2021Äê7Ô·ݵÄÖܶþ²¹¶¡£¬½¨¸´ÁËÔ̺¬9¸ö0dayÔÚÄÚµÄ117¸ö·ì϶¡£ÕâЩ·ì϶ÖУ¬44¸öΪԶ³Ì´úÂëÖ´ÐУ¬32¸öΪÌáȨ·ì϶£¬14¸öΪÐÅϢй¶·ì϶£¬12¸öΪ»Ø¾ø·þÎñ·ì϶£¬8¸öΪ°²È«Ö°ÄÜÈÆ¹ý·ì϶£¬7¸öΪºýŪ·ì϶¡£Õâ´Î½¨¸´µÄ9¸ö0dayÖУ¬ÓÐ4¸öÒѱ»ÔÚÔÚÒ°ÀûÓã¬Ô̺¬PrintNightmare·ì϶£¨CVE-2021-34527£©¡¢WindowsÄÚºËÌáȨ·ì϶£¨CVE-2021-33771ºÍCVE-2021-31979£©ÒÔ¼°¾ç±¾ÒýÇæÄÚ´æ°Ü»µ·ì϶£¨CVE-2021-34448£©¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2021-patch-tuesday-fixes-9-zero-days-117-flaws/
2.SolarWinds½¨¸´Serv-UÖÐÒѱ»ÀûÓõÄÔ¶³Ì´úÂëÖ´Ðзì϶

SolarWindsÔÚ7ÔÂ9ÈÕ°ä²¼µÄServ-U 15.2.3 HF2Öн¨¸´ÁËÒ»¸öÒѱ»ÀûÓõÄ0day¡£MicrosoftÅû¶ÁËServ-U²úÆ·µÄÔ¶³Ì´úÂëÖ´ÐÐ0day£¨CVE-2021-35211£©£¬Ô¶³Ì¹¥»÷ÕßÀûÓô˷ì϶¿ÉÄÜÒÔÌØÊâȨÏÞÖ´ÐÐËÁÒâ´úÂ룬ÔÚÖ¸±êϵͳÉÏ×°Öò¢ÔËÐз¨Ê½¡¢²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾ÝµÈ¡£Ä¿Ç°¸Ã·ì϶ÒѾ³ö±»Ò°ÀûÓ㬵«SolarWinds°µÊ¾£¬ÈôÊÇServ-U»·¾³ÖÐδÆôÓÃSSH£¬Ôò¸Ã·ì϶²»´æÔÚ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/solarwinds-patches-critical-serv-u-vulnerability-exploited-in-the-wild/
3.ʱÉÐÆ·ÅÆGuessÔâµ½DarkSideÀÕË÷¹¥»÷й¶200GBÎļþ

ÃÀ¹úʱÉÐÆ·ÅƺÍÁãÊÛÉÌGuessÔâµ½DarkSideÀÕË÷¹¥»÷й¶200GBÎļþ¡£¸Ã¹«Ë¾³Æ£¬¹¥»÷²úÉúÔÚ2021Äê2ÔÂ2ÈÕÖÁ2021Äê2ÔÂ23ÈÕ£¬¸Ã¹«Ë¾ÔÚ6ÔÂ3ÈÕʵÏÖµ÷²éºóÈ·¶¨ÁËÊÜÓ°ÏìµÄ¿Í»§²¢ÓÚ6ÔÂ9ÈÕ½«´ËÊÂÎñ֪ͨ¸øÆä¿Í»§¡£¾µ÷²éÈ·¶¨£¬Ð¹Â¶ÐÅÏ¢Ô̺¬Éç»á°²È«ºÅÂë¡¢¼ÝÕÕºÅÂë¡¢»¤ÕÕºÅÂëºÍ/»ò²ÆÕþÕʺţ¬Ö»Éæ¼°1300¶àÈË¡£Guess²¢Î´Í¸Â©Óйع¥»÷ÕßµÄÈκÎÐÅÏ¢£¬µ«ÊÇDarkSideÔøÔÚ4Ô·ÝÐû³ÆÆä¹¥»÷ÁËGuess²¢ÇÔÈ¡Á˳¬¹ý200GBµÄÎļþ¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/fashion-retailer-guess-notifies-users-data-breach
4.ºÚ¿ÍÏúÊÛ6ÒÚLinkedInÓû§ÐÅÏ¢²¢³ÆÐÂÊý¾Ý±È֮ǰµÄ¸üºÃ

ºÚ¿ÍÔÚ°µÍøÏúÊÛÁË6ÒÚ¸öLinkedInÓû§µÄÐÅÏ¢£¬²¢³ÆÕâЩÊý¾ÝÊÇÐµģ¬±ÈÖ®Ç°ÍøÂçµÄÊý¾Ý¸üºÃ¡£ºÚ¿Í°ä²¼ÁË632699¸öÓû§ÐÅÏ¢×÷ΪÑù±¾£¬ÆäÖÐÔ̺¬ÁËÐÕÃû¡¢ÁìÓ¢ID¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢LinkedInÓ×ÎÒ×ÊÁÏURL¡¢ÆäËûÉ罻ýÌå×ÊÁϵÄÁ´½Ó¡¢ÐԱ𡢵®ÉúÈÕÆÚ¡¢µØÖ·¡¢Ö°³ÆºÍÆäËû¹¤×÷ÓйØÊý¾ÝµÈ¡£×êÑÐÈËÔ±³Æ£¬¹ÌÈ»ÕâЩÊý¾Ý²»ÊǺÜÃô¸Ð£¬µ«¹¥»÷ÕßÒÀÈ»Äܹ»ÀûÓÃÕâЩÐÅϢͨ¹ýÉç»á¹¤³ÌµÄ²½Öè¼±¾çµØÕÒµ½Ð¹¥»÷Ö¸±ê¡£
ÔÎÄÁ´½Ó£º
https://cybernews.com/news/threat-actors-scrape-600-million-linkedin-profiles-and-are-selling-the-data-online-again/
5.×êÑÐÈËÔ±·¢ÏÖTrickBot»Ø¹é²¢ÐÂÔöÓÃÓÚ¼à¿ØµÄVNCÄ£¿é

×êÑÐÈËÔ±·¢ÏÖTrickBot»Ø¹é²¢ÐÂÔöÁËÓÃÓÚ¼à¿ØºÍµý±¨ÍøÂçµÄVNCÄ£¿é¡£Trickbot×Ô2016Äêµ×ÒÔÀ´Ò»Ïò»îÔ¾£¬²¢ÓÚ2020Äê10Ô·ݱ»Î¢ÈíºÍ¶à¸ö°²È«³§É̽áºÏµ·»Ù¡£µ«ÊÇ£¬×êÑÐÈËÔ±·¢ÏÖĿǰµÄTrickbot±ÈÒÔÍùÈκÎʱ³½¶¼Ô½·¢»îÔ¾£¬²¢ÓÚ2021Äê5Ô¼ì²âµ½ÁËvncDllÄ£¿éµÄ¸üа汾tvncDll£¬ÓÃÓÚ¼à¿ØºÍµý±¨ÍøÂç¡£¸ÃÄ£¿éËÆºõ»¹ÔÚ¿ª·¢ÖУ¬ÓÉÓÚÓÐÒ»¸öƵÈԵĸüй¦·ò±í£¬À´¶¨ÆÚÔö³¤ÐÂÖ°Äܺͽ¨¸´ÃýÎó¡£
ÔÎÄÁ´½Ó£º
https://www.bitdefender.com/blog/labs/trickbot-activity-increases-new-vnc-module-on-the-radar
6.AberdeenºÍcode42½áºÏ°ä²¼ÓйØÄÚ²¿·çÏյķÖÎö»ã±¨

AberdeenºÍcode42½áºÏ°ä²¼ÁËÓйØÄÚ²¿·çÏյķÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬Èý·ÖÖ®Ò»µÄÊý¾Ýй¶ÊÂÎñÉæ¼°ÄÚ²¿ÈËÔ±£¬¶øÆäÖÐÔ¼80%ÈËÊÇÎÞÒâµÄ£»75%µÄ×éÖ¯¶ÔÆä»·¾³Ã»ÓÐÒ»Ö¡¢¼¯ÖеĿɼûÐÔ£»2020Ä꣬ÔÚÖÕ¶ËÉϲúÉú·ì϶µÄ¿ÉÄÜÐÔÊÇ·þÎñÆ÷ÉϵÄ4.5±¶£»Êý¾Ý¶³öй¶µÄ¾ùÔÈÊýÁ¿ÊÇÿ¸öÓû§Ã¿Ìì»á²úÉú13¸öÊý¾Ýй¶ÊÂÎñ£»ÄÚ²¿ÈËÔ±Êý¾Ýй¶µÄ³É±¾¿ÉÄܸߴ﹫˾ÄêÊÕÈëµÄ20%¡£
ÔÎÄÁ´½Ó£º
https://www.code42.com/blog/aberdeen-report-key-takeaways/


¾©¹«Íø°²±¸11010802024551ºÅ