΢ÈíÖܶþ°²È«¸üР£¬½¨¸´Ô̺¬3¸ö0dayÔÚÄÚµÄ44¸ö·ì϶£»×êÑÐÈËÔ±³ÆGlowworm¹¥»÷¿Éͨ¹ýÑïÉùÆ÷µçÔ´µÆÇÔÈ¡ÒôƵ

°ä²¼¹¦·ò 2021-08-11
1.΢ÈíÖܶþ°²È«¸üР£¬½¨¸´Ô̺¬3¸ö0dayÔÚÄÚµÄ44¸ö·ì϶


1.jpg


΢Èí°ä²¼2021Äê8ÔµÄÖܶþ°²È«¸üР£¬×ܼƽ¨¸´ÁË44¸ö·ì϶¡£ÆäÖÐÔ̺¬13¸öÔ¶³Ì´úÂëÖ´Ðзì϶¡¢8¸öÐÅϢй¶·ì϶¡¢2¸ö»Ø¾ø·þÎñ·ì϶ºÍ4¸öºýŪ·ì϶¡£Õâ´Î½¨¸´µÄ3¸ö0dayΪWindows Print SpoolerÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-36936£©¡¢ Windows LSAÖеĺýŪ·ì϶£¨CVE-2021-36942£©ÒÔ¼°Windows Update Medic·þÎñÖеÄÌáȨ·ì϶£¨CVE-2021-36948£©¡£´Ë±í £¬×êÑÐÈËÔ±ÒѾ­·¢ÏÖ×Ô¶¯ÀûÓÃCVE-2021-36948µÄ¹¥»÷»î¶¯¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2021-patch-tuesday-fixes-3-zero-days-44-flaws/


2.×êÑÐÈËÔ±³ÆGlowworm¹¥»÷¿Éͨ¹ýÑïÉùÆ÷µçÔ´µÆÇÔÈ¡ÒôƵ


2.jpg


±¾¹ÅÀï°²´óѧµÄ×êÑÐÈËÔ±·¢ÏÖÁËÒ»ÖÖÐµĹ¥»÷·½Ê½Glowworm £¬Äܹ»Í¨¹ýÑïÉùÆ÷µçÔ´µÆÇÔÈ¡ÒôƵ¡£×êÑÐÈËÔ±³Æ £¬´ËÀ๥»÷ÊÇͨ¹ýÉ豸¹¦ºÄ±ä¶¯ÒýÆðµÄÉ豸µçÔ´ÅúʾµÆLEDÇ¿¶ÈµÄ΢Ó׵ı䶯À´¸´ÔìÓïÒô¡£ËûÃÇÑÝʾÁËÈôºÎÀûÓôøÓйâµç´«¸ÐÆ÷µÄÍûÔ¶¾µ´Ó35Ã×±í¶Ô×¼±Ê¼Ç±¾µçÄÔµÄÑïÉùÆ÷À´²¶»ñ¶Ô»° £¬²¢·­Òë³ÉÓïÒô¡£´Ë±í £¬³¢ÊÔÅú×¢·ÖÆçÔì×÷É̳ö²úµÄºÜ¶à²úÆ·¶¼ÈÝÒ×Ôâµ½Glowworm¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/glowworm-attack-light-flickers-audio/168501/


3.ºÉÀ¼µ±¾Ö°ä·¢ÓÉÓڳ߶ÈÔ½À´Ô½¸´ÔÓ½«ÖÕ³¡Ðû¸æTLSÖ¤Êé


3.jpg


ºÉÀ¼µÐÔÖÊÇ×îºóÒ»¸öÈÔÔÚÔËÐÐ×Ô¼ºµÄÖ¤ÊéÐû¸æ»ú¹¹(CA)µÄÅ·Ã˹ú¶È £¬ÆäÔÚÉÏÖܰ䷢´òËã´Ó2021Äê12ÔÂÆðÍ·ÖÕ³¡Ðû¸æÐµÄTLSÖ¤Êé¡£°ä²¼ÕâÒ»´òËãµÄÔ­ÒòÔ̺¬£ºä¯ÀÀÆ÷Ôì×÷É̶ÔÔËÐмæÈݵÄTLSÖ¤ÊéÐû¸æ»ú¹¹Ìá³öµÄ¼¼ÊõÒªÇó²»ÐÝÌá¸ß£»2019ÄêºÍ2020Äê²úÉúµÄ´óÁ¿°²È«ÊÂÎñÆÈʹÆäΪ¿Í»§¸ü»»ÁË´óÁ¿Ö¤Ê飻´ó²¿Ãŵ±¾Ö¶¼½«ÕâÒ»Á÷³Ì×ªÒÆµ½Ë½Óª¹«Ë¾¡£´Ë±í £¬ºÉÀ¼¹ÙÔ±°µÊ¾ÔÚ¸ùÖ¤Êéµ½ÆÚºó½«²»ÔÙÐøÆÚ¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/dutch-government-to-stop-issuing-tls-certs-because-of-ever-complicated-standards/


4.Synology³ÆStealthWorkerÕë¶ÔÆäNASÉ豸µÄ¹¥»÷¼¤Ôö


4.jpg


Öйų́Í幩¸øÉÌSynology³Æ½üÆÚ½©Ê¬ÍøÂçStealthWorkerÕë¶ÔÆäNASÉ豸µÄ¹¥»÷»î¶¯¼¤Ôö¡£Synology°²È«²¼¸æ°µÊ¾ £¬ÕâЩ¹¥»÷ÀûÓÃһЩÒѾ­ÊÜϰȾµÄÉ豸 £¬ÊÔͼ²Â²â³£¼ûµÄÖÎÀíÆ¾Ö¤ £¬Ôڳɹ¦ºó½«½Ó¼ûϵͳ £¬×¢Èëpayload £¬ÆäÖпÉÄÜÔ̺¬ÀÕË÷Èí¼þ¡£´Ë±í £¬ÊÜϰȾµÄÉ豸¿ÉÄÜ»¹»á¶ÔÆäËû»ùÓÚLinuxµÄÉ豸½øÐй¥»÷¡£¸Ã¹«Ë¾»¹°ä²¼ÁË·À±¸´ËÀ๥»÷µÄ½¨Òé´ëÊ© £¬Ô̺¬Ê¹Óø´Ôӽý¡µÄÃÜÂëºÍ´´½¨Ò»¸öÐÂÕÊ»§²¢½ûÓÃϵͳĬÈϵÄadminÕÊ»§µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/120962/malware/synology-nas-devices-ransomware.html


5.AT&T Alien·¢ÏÖÀûÓÃTelegram·Ö·¢µÄÐÂľÂíFatalRAT


5.jpg


AT&T Alien Labs×êÑÐÈËÔ±×î½ü·¢ÏÖÁËÒ»ÖÖÃûΪFatalRATµÄÐÂľÂí £¬Äܹ»Í¨¹ýÈí¼þµÄÏÂÔØ·ì϶»òTelegram½øÐд«²¼¡£¸Ã¶ñÒâÈí¼þÔÚÆëȫϰȾϵͳ֮ǰ»áÔËÐÐÂŴβâÊÔ £¬²é³­ÊÇ·ñ´æÔÚ¶à¸öÐé¹¹»ú²úÆ·¡¢´ÅÅ̿ռ䡢ÎïÀí´¦ÖÃÆ÷ÊýÁ¿µÈ¡£ÆäÓµÓжàÖÖÖ°ÄÜ£ºÈƹý¼ì²â¡¢»ñÈ¡ÏµÍ³ÓÆ¾ÃÐÔ¡¢¼Í¼Óû§¼üÅÌ¡¢ÍøÂçϵͳÐÅÏ¢¡¢Í¨¹ý¼ÓÃܵÄC&CÍ¨Â·ÉøÈëµÈ¡£´Ë±í £¬Ëü»¹¿ÉÄÜ´ÓÖîÈçEdge¡¢Chrome¡¢Firefox¡¢360¡¢Ëѹ·ºÍQQµÈ¶à¶àä¯ÀÀÆ÷ÖвÁ³ýÌØ¶¨Óû§ÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/fatalrat-new-trojan-targeting-telegram-533712.shtml


6.ÏãÄζùº«¹ú¹«Ë¾³ÆÆäÔâµ½¹¥»÷µ¼Ö¿ͻ§µÄÐÅϢй¶


6.png


ÏãÄζùº«¹ú·Ö¹«Ë¾³ÆÆäÊý¾ÝÖÐÐÄÔÚ8ÔÂ5ÈÕºÍ6Ö®¼äÔâµ½¹¥»÷ £¬µ¼Ö¿ͻ§µÄÐÅϢй¶¡£Õâ´Îй¶ÁËÒÑ×¢²á»áÔ±µÄÓ×ÎÒÐÅÏ¢ £¬Ô̺¬ÐÕÃû¡¢ÉúÈÕ¡¢µç»°ºÅÂë¡¢µØÖ·¡¢ÐԱ𡢵ç×ÓÓʼþµØÖ·ºÍ²úÆ·²É°ìÇåµ¥µÈ¡£¸Ã¹«Ë¾³Æ £¬ÔÚ·¢ÏÖ¹¥»÷ºóËüµ±¼´²ÉÈ¡Ðж¯²éÃ÷ÊÂÎñÔ­Òò £¬²¢×èÖ¹Á˹¥»÷Õß¶ÔÆäÊý¾Ý¿âµÄ·¸·¨½Ó¼û £¬Ä¿Ç°ÒѾ­½¨¸´¸ÃÍøÕ¾±»ÀûÓõķì϶¡£ÏãÄζùÉÐδÌá³ö¾ßÌå´òËãÀ´Åâ³¥ÊÜÓ°ÏìµÄ¿Í»§¡£    


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/chanel-korea-issues-apology-over-data-theft/