Print Spooler´æÔÚ佨¸´RCE£¬Î¢Èí³Ðŵ¾¡¿ì½¨¸´£»ÀÕË÷ÍÅ»ïSynAckΪ֮ǰµÄÊܺ¦ÕßÃâ·ÑÌṩ½âÃÜÃÜÔ¿ άËûÃü άËûÃü°²È« ½ñÌì

°ä²¼¹¦·ò 2021-08-13

1.Print Spooler´æÔÚ佨¸´RCE£¬Î¢Èí³Ðŵ¾¡¿ì½¨¸´


1.jpg


ÔÚ°ä²¼8Ô·ÝÖܶþ°²È«¸üеĵڶþÌ죬΢ÈíÈ·ÈÏÁËWindows Print Spooler×é¼þÖдæÔÚµÄÁíÒ»¸ö佨¸´µÄÔ¶³Ì´úÂëÖ´Ðзì϶£¬²¢°µÊ¾ËüÔÚÖÂÁ¦½¨¸´¸Ã·ì϶¡£¸Ã·ì϶¸ú×ÙΪCVE-2021-36958£¬CVSSÆÀ·ÖΪ7.3£¬ÊôÓÚ·ì϶PrintNightmareµÄÒ»²¿ÃÅ£¬¿ÉÓÃÀ´½«DelpyµÄDLL¸´Ôìµ½¿Í»§¶ËÖ´ÐÐÀ´´ò¿ªÏµÍ³µÄºÅÁîÌáÐÑ·û¡£Ä¿Ç°Î¢ÈíÉÐδ°ä²¼Õë¶Ô´Ë·ì϶µÄ°²È«¸üУ¬Óû§Äܹ»Í¨¹ý½ûÓÃPrint SpoolerÀ´»º½â´ËÀ๥»÷¡£

   

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/08/microsoft-security-bulletin-warns-of.html


2.SAP°ä²¼°²È«¸üУ¬½¨¸´Æä²úÆ·ÖеĶà¸ö°²È«·ì϶


2.jpg


SAPÓÚ8ÔÂ10ÈÕ°ä²¼°²È«¸üУ¬½¨¸´Æä²úÆ·ÖеĶà¸ö°²È«·ì϶¡£Õâ´Î½¨¸´µÄ½ÏΪÑϳÁµÄÊÇSAP Business OneÖеÄÎÞÏÞ¶ÈÎļþÉÏ´«·ì϶£¨CVE-2021-33698£©£¬CVSSÆÀ·ÖΪ9.9£»SAP NetWeaver¿ª·¢»ù´¡¼Ü¹¹ÖеķþÎñÆ÷¶ËÒªÇóαÔì·ì϶£¨CVE-2021-33690£©£¬CVSSÆÀ·ÖΪ9.9£»ÒÔ¼°SAP NZDTÖеÄSQL×¢Èë·ì϶£¨CVE-2021-33701£©£¬CVSSÆÀ·ÖΪ9.1¡£´Ë±í£¬»¹½¨¸´ÁË¿çÕ¾¾ç±¾·ì϶£¨CVE-2021-33702ºÍCVE-2021-33703£©µÈ·ì϶¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/sap-patches-critical-bugs/168558/


3.ÐÂ¼ÓÆÂµçÐŹ«Ë¾StarHub³ÆÆä³¬¹ý5.7ÍòÓû§ÐÅϢй©


ÐÂ¼ÓÆÂµçÐŹ«Ë¾StarHub³ÆÆä³¬¹ý5.7ÍòÓû§ÐÅϢй©.png


ÐÂ¼ÓÆÂµÚ¶þ´óµçÐÅÔËÓªÉÌStarHubÓÚ8ÔÂ11ÈÕ·¢ËÍÓʼþ³ÆÆä³¬¹ý5.7ÍòÓû§ÐÅϢй©¡£ÓʼþÖÐд·£¬¸Ã¹«Ë¾ÓÚ±¾ÔÂÔçЩʱ³½ÔÚµÚÈý·½Êý¾Ýת´¢ÍøÕ¾ÉÏ·¢ÏÖÁËÒ»¸ö·¸·¨ÉÏ´«µÄÎļþ£¬ÆäÖÐÔ̺¬2007Äê֮ǰÆä¿Í»§¶©ÔÄStarHubµÄÓйØÐÅÏ¢¡£StarHubÐû³Æ¿Í»§µÄÐÅÓþ¿¨ºÍÒøÐÐÐÅϢûÓÐй¶£¬²¢ÇÒËûÃǽ«ÎªËùÓÐÊÜÓ°ÏìµÄ¿Í»§ÌṩÁù¸öÔµÄÃâ·ÑÐÅÓþ¼à¿Ø¡£The Register°µÊ¾£¬Õâ´Îй¶ÊÂÎñÓÚ7ÔÂ6ÈÕ·¢ÏÖ£¬µ«Ö±µ½8ÔÂ6ÈղŰ䲼³öÀ´¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.theregister.com/2021/08/12/singapore_telecom_breach_leaked_personal/


4.ReindeerÒò´æ´¢Í°ÅäÖÃÃýÎóй¶³¬¹ý30ÍòÓû§µÄÐÅÏ¢


4.jpg


WizCase×êÑÐÈËÔ±·¢ÏÖReindeerÒòS3´æ´¢Í°ÅäÖÃÃýÎóй¶ÁËÔ¼360009¸öÓû§µÄÐÅÏ¢¡£ReindeerÊÇÒ»¼ÒÃÀ¹úÓªÏú¹«Ë¾£¬Ö®Ç°ÓëTiffany&Co.¡¢Patr¨°n TequilaµÈ¹«Ë¾ºÏ×÷¹ý¡£Õâ´Îй¶µÄÊý¾ÝÄܹ»×·Òäµ½2007Äê5ÔÂÖÁ2012Äê2Ô£¬Ô¼ÄªÓÐ50000¸öÎļþºÍ×ܹ²32GBµÄÊý¾Ý£¬Ô̺¬¿Í»§ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µç×ÓÓʼþ¡¢Facebook ID ºÍÃÜÂë¡¢µç»°ºÅÂë¡¢µØÖ·µÈÐÅÏ¢£¬Ó°ÏìÁË35¸ö¹ú¶È»òµØÓòµÄÓû§¡£


Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/reindeer-suffers-massive-data-breach-affecting-300-000-users-533740.shtml


5.¶ñÒâÈí¼þAdLoadµÄбäÖÖ¿ÉÈÆ¹ýAppleµÄXProtect


5.jpg


°²È«¹«Ë¾SentinelOne·¢ÏÖ¶ñÒâÈí¼þAdLoadµÄбäÖÖ¿ÉÈÆ¹ýAppleÄÚÖð²È«½ÚÔìXProtect¡£AdLoadÊÇÒ»ÖÖÕë¶ÔmacOSƽ̨µÄľÂí£¬×Ô2017ËêĺÒÔÀ´»îÔ¾£¬ÓÃÓÚ×°Öø÷Ààpayload£¬Ô̺¬¸æ°×Èí¼þºÍPUAs¡£Õâ´Î´ó¹æÄ£µÄ³ÖÐø¹¥»÷×îÔçÓÚ2020Äê11ÔÂÆðÍ·£¬²¢ÓÚ2021Äê7ÔºÍ8Ô³õÔö³¤¡£×êÑÐÈËÔ±°µÊ¾£¬XProtectÓÐԼĪ11¸ö·ÖÆçµÄAdLoadÊðÃû£¬µ«ÊÇËüÆëȫûÓмì²âµ½Õâ´ÎµÄ¹¥»÷»î¶¯¡£


Ô­ÎÄÁ´½Ó£º

https://labs.sentinelone.com/massive-new-adload-campaign-goes-entirely-undetected-by-apples-xprotect/


6.ÀÕË÷ÍÅ»ïSynAckΪ֮ǰµÄÊܺ¦ÕßÃâ·ÑÌṩ½âÃÜÃÜÔ¿


6.jpg


ÀÕË÷ÍÅ»ïEl_Cometa£¨Ç°ÉíΪSynAck£©ÔÚ8ÔÂ12ÈÕΪ2017Äê7ÔÂÖÁ2021ËêÊ×±»Ï°È¾µÄÊܺ¦ÕßÌṩÖ÷½âÃÜÃÜÔ¿¡£SynAckÓÚ2017Äê7Ô³õ´Î±»·¢ÏÖ£¬Êǵ±½ñÈÔÔÚÔËÐеÄ×î¹ÅÀϵÄÀÕË÷Èí¼þÍÅ»ïÖ®Ò»£¬Ëû°ä²¼µÄÃÜÔ¿Òѱ»°²È«¹«Ë¾EmsisoftÑéÖ¤ÎªÕæÊµµÄ¡£SynAck°µÊ¾£¬ËûÃǾö¶¨ÎªÊܺ¦Õß°ä²¼Ö÷½âÃÜÃÜÔ¿£¬ÓÉÓÚËûÃÇ´Ë¿ÌÒѾ­ÊµÏÖÁ˾ɵÄSynAckʱÆÚ£¬²¢×¨Ò»ÓÚÉϸöÔÂÆô¶¯µÄEl_CometaÐÂÏîÄ¿¡£

  

Ô­ÎÄÁ´½Ó£º

https://therecord.media/synack-ransomware-gang-releases-decryption-keys-for-old-victims/