CiscoÅû¶Foxit PDFµÄ¶à¸ö¿ªÊͺóʹÓ÷ì϶£»CleafyÅû¶ÐÂAndroid½©Ê¬ÍøÂçUBELÓëOscorpÓйØ
°ä²¼¹¦·ò 2021-07-29
Cisco TalosÅû¶×î½üÔÚFoxit PDF ReaderÖз¢ÏֵĶà¸ö¿ªÊͺóʹÓ÷ì϶¡£Foxit PDF ReaderÊÇĿǰ×îÊ¢ÐеÄPDFÔĶÁÆ÷Ö®Ò»£¬Ö§³Ö½»»¥Ê½ÎĵµºÍ¶¯Ì¬±íµ¥µÄJavaScript¡£Õâ´ÎÅû¶µÄ·ì϶Ô̺¬CVE-2021-21831¡¢CVE-2021-21870ºÍCVE-2021-21893£¬¹¥»÷ÕßÄܹ»Í¨¹ýÓÕʹÓû§´ò¿ªÌØÔìµÄ¶ñÒâPDF£¬À´ÀûÓÃÕâЩ·ì϶ÔÚÖ¸±êÉ豸ÉÏÖ´ÐÐËÁÒâ´úÂë¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2021/07/vulnerability-spotlight-use-after-free.html
2.×êÑÐÈËÔ±Åû¶µç×ÓÓʼþºÏ×÷Èí¼þZimbraÖеĶà¸ö·ì϶

SonarSource×êÑÐÈËÔ±Åû¶µç×ÓÓʼþºÏ×÷Èí¼þZimbraÖеÄ2¸ö·ì϶¡£µÚÒ»¸öÊÇÔÚÈÕÀúÔ¼Çë×é¼þZmMailMsgView.jsÖеĿçÕ¾¾ç±¾·ì϶£¬×·×ÙΪCVE-2021-35208£¬Êܺ¦ÕßÔÚä¯ÀÀÊÕµ½µÄÓʼþʱ¿ÉÄܻᴥ·¢¸Ã·ì϶¡£µÚ¶þ¸öÊÇServletÖеÄProxyServlet.javaÖеÄÊ¢¿ª³Á¶¨Ïò·ì϶£¬×·×ÙΪCVE-2021-35209£¬ÔÊÐíÁбíÈÆ¹ý£¬¿ÉÄܵ¼Ö·þÎñÆ÷¶ËµÄÒªÇóαÔì·ì϶¡£×êÑÐÈËÔ±³Æ£¬Ô¶³Ì¹¥»÷Õß½áºÏʹÓÃÁ½¸ö·ì϶Äܹ»ÇÔÈ¡¹È¸èÔÆAPIÁîÅÆ»òAWS IAMÍ´´¦¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/120603/hacking/zimbra-vulnerabilities.html
3.¼ÓÖÝ´óѧʥµØÑǸç·ÖУ³ÆÆäITϵͳÔâµ½ÍøÂç´¹µö¹¥»÷

¼ÓÖÝ´óѧʥµØÑǸç·ÖУ½¡È«ÖÐÐÄ³ÆÆäITϵͳÔâµ½ÍøÂç´¹µö¹¥»÷µ¼ÖÂÊý¾Ýй¶¡£¸Ã½¡È«ÖÐÐÄÊÇÈ«ÃÀ×îºÃµÄÒ½ÔºÖ®Ò»£¬ÂŴ௒ÀΪʥµØÑǸç×îºÃµÄÒ½ÁƱ£½¡ÏµÍ³¡£¸Ã»ú¹¹ÔÚ3ÔÂ12ÈÕÊÕµ½ÁË¿ÉÒɻµÄ¾¯±¨£¬²¢ÓÚ4ÔÂ8ÈÕ·¢ÏÖ¹¥»÷Õß½Ó¼ûÁËÆä²¿ÃÅÔ±¹¤µÄÓʼþÕÊ»§¡£¾µ÷²é£¬¹¥»÷Õß¿ÉÄÜÔÚ2020Äê12ÔÂ2ÈÕÖÁ2021Äê4ÔÂ8ÈÕ¼äÇÔÈ¡ÁË»¼Õß¡¢Ô±¹¤ºÍѧÉúµÄÓ×ÎÒÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢Óʼþ¡¢´«ÕæºÅÂë¡¢Ò½ÖÎÐÅÏ¢¡¢Ò½ÁÆÐÅÏ¢¡¢Éç»á°²È«ºÅÂë¡¢Éí·ÝÖ¤ºÅÂë¡¢Ö§¸¶¿¨ºÅÂë»ò½ðÈÚÕʺźͰ²È«Â롢ѧÉúÖ¤ºÅÂëÒÔ¼°Óû§ÃûºÍÃÜÂëµÈ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/uc-san-diego-health-discloses-data-breach-after-phishing-attack/
4.ÐÂÀÕË÷ÍÅ»ïBlackMatter³Æ½öÕë¶ÔÄêÊÕÈë1ÒÚÒÔÉϹ«Ë¾

Recorded Future·¢´Ë¿Ì±¾ÖÜÆðÍ·ÔË×÷µÄÐÂÀÕË÷ÍÅ»ïBlackMatter¡£BlackMatterĿǰÔÚºÚ¿ÍÂÛ̳ExploitºÍXSS°ä²¼µÄ¸æ°×ÕÐļºÏ×÷Õߣ¬²¢°µÊ¾ÄêËûÃǽöÕë¶ÔÊÕÈëΪ1ÒÚÃÀÔª»òÒÔÉϵĹ«Ë¾¡£¸ÃÍÅ»ïÐû³ÆÆä½áºÏÁËDarksideºÍREviµÄÓÅÊÆ£¬²¢ÒªÇóºÏ×ÊÈ˵ÄÍøÂç±ØÒªÕ¼ÓÐ500µ½15000̨Ö÷»ú£¬ÇÒλÓÚÃÀ¹ú¡¢Ó¢¹ú¡¢¼ÓÄôó»ò°Ä´óÀûÑÇ¡£´Ë±í£¬¸ÃÍÅ»ïÒ²ÔËÓªÁËÒ»¸öÊý¾ÝÐ¹Â¶ÍøÕ¾£¬µ«ÊǸÃÍøÕ¾Ä¿Ç°Êǿյġ£
ÔÎÄÁ´½Ó£º
https://therecord.media/blackmatter-ransomware-targets-companies-with-revenues-of-100-million-and-more/
5.ÄÏ·ÇÎïÁ÷¹«Ë¾Transnet SOCÔâµ½ÀÕË÷¹¥»÷ÁÙʱͣÔË

ÄÏ·ÇÎïÁ÷¹«Ë¾Transnet SOCÔâµ½ÀÕË÷¹¥»÷£¬ÆäËùÓиۿڴ¬²ºÁÙʱͣÔË¡£¹¥»÷²úÉúÔÚ7ÔÂ22ÈÕÐÇÆÚËÄ£¬²úÉú¹¥»÷ºó¸Ã¹«Ë¾µ±¼´¶ÔÊÂÎñ·¢Õ¹µ÷²é£¬²¢½¨ÒéÆäÔ±¹¤ÔÝͣʹÓõç×ÓÓʼþ£¬ÒÔ·À¹¥»÷µÄÊæÕ¹¡£Transnetй©£¬¿¨³µÔËÊäʹÓõÄNavisϵͳÊܵ½Ó°Ï죬Ŀǰ½ø³ö¸Û¿ÚµÄ´¬Ö»±ØÒªÓÉÈËΪ¼Í¼£¬²¢ÇÒTransnet SOC LtdµÄÍøÕ¾Ò²ÒѾ¹Ø¹Ø¡£Ä¿Ç°ÉÐδй©ÀÕË÷Èí¼þµÄÀàÐÍ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/120596/cyber-crime/transnet-soc-cyber-attack.html
6.CleafyÅû¶ÐÂAndroid½©Ê¬ÍøÂçUBELÓëOscorpÓйØ

Òâ´óÀû°²È«¹«Ë¾CleafyÅû¶ÐµÄAndroid½©Ê¬ÍøÂçUBELÓëOscorpÓйء£×êÑÐÈËÔ±ÔÚ2021Äê5ÔÂÖÁ6ÔÂÆÚ¼ä£¬ÔÚÒ°±í·¢ÏÖÁËеÄOscorpÑù±¾£¬Óë´Ëͬʱ£¬Ò»¸öÃûΪUBELµÄÐÂÐÍAndroid½©Ê¬ÍøÂçÆðÍ·ÔÚºÚ¿ÍÂÛ̳ÉÏÐû´«¡£Í¨¹ý¶ÈÎö£¬·¢ÏÖOscorpºÍUBELÄܹ»Á´½Óµ½Í³Ò»¸ö¶ñÒâ´úÂë¿â£¬Åú×¢ËüÃÇÊôÓÚͳһÏîÖ÷ÕÅ·ÖÖ§»òÆäËüºÏ×ÊÈ˵ijÁж¨Ãû¡£UBELÓµÓжÁÈ¡ºÍ·¢ËÍSMSÐÂÎÅ¡¢Â¼ÔìÒôƵ¡¢×°ÖúÍɾ³ýÀûÓá¢×Ô¶¯Æô¶¯µÈÖ°ÄÜ¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/07/ubel-is-new-oscorp-android-credential.html


¾©¹«Íø°²±¸11010802024551ºÅ