AppleÒѽ¨¸´ÆäAWDLÖпÉÈÆ¹ýÆøÏ¶ÏµÍ³ÇÔÊØÐÅÏ¢µÄ·ì϶ £»×êÑÐÈËÔ±·¢ÏÖÀûÓÃExchangeÖзì϶ProxyShellµÄ¹¥»÷»î¶¯

°ä²¼¹¦·ò 2021-08-09
1.AppleÒѽ¨¸´ÆäAWDLÖпÉÈÆ¹ýÆøÏ¶ÏµÍ³ÇÔÊØÐÅÏ¢µÄ·ì϶


1.jpg


AppleµÄApple Wireless Direct Link(AWDL)ÖдæÔÚÒ»¸ö·ì϶£¬¿ÉÓÃÀ´ÈƹýÆøÏ¶ÏµÍ³²¢ÇÔÈ¡Êý¾Ý¡£Õâ¸ö·ì϶µÄ¼¼Êõ²¼¾°Óе㸴ÔÓ£¬¼òÑÔÖ®£¬¾ÍÊÇʹÓÃICMPv6ºÍIPv6Êý¾Ý°ü´ÓÖ¸±êϵͳ»ñÈ¡Êý¾Ý£¬ÔÚ×ó½üÖ§³ÖAWDLµÄAppleÉ豸ÉÏ·´µ¯Êý¾Ý°ü£¬²¢½«ÇÔÈ¡µÄÎļþ·¢Ë͵½ÁíÒ»¸öÓÐIPv6µØÖ·µÄÉ豸¡£°²È«¹«Ë¾Fnish×êÑÐÈËÔ±ÓÚÉÏÖܳõ´Î¹«¿ªÁ˸÷ì϶£¬¶øApple¹«Ë¾ÔçÔÚ½ñÄê4Ô£¬¾ÍÔÚiOS 14.5¡¢iPadOS 14.5¡¢watchOS 7.4ºÍBig Sur 11.3µÄ°²È«¸üÐÂÖÐ͵͵µØ½¨¸´ÁËÕâÒ»·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/apple-fixed-awdl-bug-that-could-be-used-to-escape-air-gapped-networks/


2.×êÑÐÈËÔ±·¢ÏÖÀûÓÃExchangeÖзì϶ProxyShellµÄ¹¥»÷»î¶¯


2.jpg


2021 Black Hat´ó»áÉÏͳ³ÆÎªProxyShellµÄ3¸ö·ì϶µÄϸ½Ú¹«¿ªºó£¬×êÑÐÈËÔ±·¢ÏÖÁË»ý¼«ÀûÓø÷ì϶µÄ»î¶¯¡£ProxyShellÔ̺¬ACLÈÆ¹ý·ì϶£¨CVE-2021-34473£©¡¢ Exchange PowerShellºó¶ËµÄÌáȨ·ì϶£¨CVE-2021-34523£©ºÍËÁÒâÎļþдÈëµ¼ÖµÄRCE·ì϶£¨CVE-2021-31207£©¡£ÕâЩ·ì϶Äܹ»Í¨¹ýIISÖеĶ˿Ú443ÉÏÔËÐеÄMicrosoft Exchange¿Í»§¶Ë½Ó¼û·þÎñ(CAS)Ô¶³ÌÀûÓ㬽áºÏʹÓÿɽøÐÐδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´ÐС£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-servers-scanned-for-proxyshell-vulnerability-patch-now/


3.×êÑÐÍŶӷ¢ÏÖÀûÓÃArcadyan¹Ì¼þÖзì϶װÖÃMiraiµÄ»î¶¯


3.jpg


Õ°²©ÍøÂçµÄ×êÑÐÍŶÓÔÚ½üÆÚ·¢ÏÖÁËÀûÓÃArcadyan¹Ì¼þÖзì϶µÄ¹¥»÷»î¶¯¡£¸Ã·ì϶ÊÇõè¾¶±éÀú·ì϶£¬×·×ÙΪCVE-2021-20090£¬ÆÀ·ÖΪ9.9¡£´æÔÚÓÚʹÓÃArcadyan¹Ì¼þµÄ·ÓÉÆ÷µÄweb½çÃæÉÏ£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÈÆ¹ýÉí·ÝÑéÖ¤£¬Ó°ÏìÁËÊýÊ®ÖÖÐͺŵÄÊý°ÙÍǫ̀·ÓÉÆ÷¡£×ÔÉÏÖÜËÄÒÔÀ´£¬×êÑÐÈËÔ±ÔÚÒ°·¢ÏÖÁËÀûÓô˷ì϶µÄ¹¥»÷»î¶¯,Ö¼ÔÚÊÕÊÜÖ¸±êÉ豸²¢×°Öý©Ê¬ÍøÂçMiraiµÄpayload¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/actively-exploited-bug-bypasses-authentication-on-millions-of-routers/


4.SeniorAdvisor´æ´¢Í°ÅäÖÃÃýÎóй¶³¬¹ý300Íò¿Í»§ÐÅÏ¢


4.jpg


WizCase×êÑÐÍŶӷ¢ÏÖÁ˸߼¶»¤ÀíÉó²éÍøÕ¾SeniorAdvisorµÄAmazon S3´æ´¢Í°ÅäÖÃÃýÎó£¬Ð¹Â¶³¬¹ý300Íò¿Í»§ÐÅÏ¢¡£¸ÃÍøÕ¾ÓÃÀ´Õ¹Ê¾ ÃÀ¹úºÍ¼ÓÄôóµÄÀÏÄ껤Àí·þÎñÏû·ÑÕߵįÀ·ÖºÍÆÀÂÛ£¬Õâ´Î×ܹ²Ð¹Â¶Á˳¬¹ý100Íò¸öÎļþºÍ182GBµÄÊý¾Ý£¬Ô̺¬ÐÕÃû¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂëºÍÁªÏµÈÕÆÚµÈ£¬²¢ÇÒ¶¼Î´¾­¹ý¼ÓÃÜ£¬´Ë±í»¹ÓÐԼĪ2000ÌõÒѱ»É¾³ýµÄÆÀÂÛ¡£WizCase³ÆÕâ´ÎÐ¹Â¶Ô´ÖØÒªÊÇ´¦ÓÚ»ò¿¿½üÍËÐݵÄÀÏÄêÈË£¬ÎªÌض¨µÄÈõÊÆÈºÌ壬¸üÈÝÒ×Ôâµ½Ú¿Æ­»î¶¯µÄ¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/senior-citizens-personal-data/


5.Group-IB·¢ÏÖºÚ¿ÍÔÚ¶à¸ö°µÍø¹«¿ª³¬¹ý100ÍòÌõÖ§¸¶¼Í¼


5.jpg


Group-IBÔÚ¶à¸öÔÚ¶à¸ö°µÍøÉϼì²âµ½Ò»¸öÌØÊâÌû×Ó£¬ÃûΪAW_cardsµÄºÚ¿Í¹«¿ªÁ˳¬¹ý100ÍòÌõÖ§¸¶¼Í¼¡£ÕâЩÊý¾ÝÔ̺¬ÁËÀ´×Ô100¶à¸ö¹ú¶ÈºÍµØÓòµÄ1000¶à¼ÒÒøÐеÄÒøÐп¨¾ßÌåÐÅÏ¢£¬Ô̺¬Ó¡¶È¡¢Ä«Î÷¸ç¡¢ÃÀ¹ú¡¢°Ä´óÀûÑÇ¡¢°ÍÎ÷µÈ¡£ÓÉÓÚºÜÉÙÓз¸×ï·Ö×ÓÃâ·ÑÌṩÈç´Ë¶àµÄÒøÐп¨ÐÅÏ¢£¬ÕâÒýÆðÁËGroup-IB×êÑÐÈËÔ±µÄÐËÖ¡£·ÖÎö·¢ÏÖÕâÊÇÒ»¸ö¶·µ¨µÄ¸æ°×£¬Ö¼ÔÚÍÆ¹ãÐÂÆ½Ì¨All World Cards¡£ÕâЩÊý¾ÝÔ̺¬¿¨ºÅ¡¢½ØÖ¹ÈÕÆÚ¡¢CVV/CVC´úÂë¡¢³Ö¿¨ÈËÐÕÃû¡¢¹ú¶È¡¢×´Ì¬¡¢³ÇÊÓ×¢µØÖ·¡¢ÓÊÕþ±àÂëºÍµç»°µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/120941/cyber-crime/1m-compromised-cards.html


6.RansomEXXÍÅ»ïÐû³ÆÒÑÇÔÈ¡ÉÝ³ÞÆ·ÅÆZegna³¬¹ý20GBÊý¾Ý


6.jpg


ÀÕË÷ÍÅ»ïRansomEXX½üÆÚÐû³ÆÒÑÇÔÈ¡ÉÝ³ÞÆ·ÅÆZegna³¬¹ý20GBÊý¾Ý¡£ZegnaÊÇÒâ´óÀû×î³ÛÃûµÄÉݳÞÊ±×°Æ·ÅÆÖ®Ò»£¬ÊÇÈ«ÇòÊÕÈë×î¸ßµÄÄÐ×°Æ·ÅÆ¡£RansomEXX³ÆÒѴӸù«Ë¾ÇÔÈ¡ÁË20.74GBµÄÊý¾Ý£¬²¢°ä²¼ÁË43¸öÎļþ£¨42¸ö500MBµÄÎļþºÍ1¸ö239.54MBµÄÎļþ£©×÷ΪÑù±¾¡£½üÆÚ£¬RansomEXXÍÅ»ïÔøÏ°È¾ÁËÒâ´óÀûÀ­Æë°Â´óÇøµÄϵͳ£¬²¢¹¥»÷ÁËÖйų́ÍåµÄÍÆËã»úÓ²¼þÔì×÷É̼¼¼Î£¨GIGABYTE£©¡£


 Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/120898/data-breach/ransomexx-ransomware-zegna.html