Print Spooler´æÔÚ佨¸´RCE£¬Î¢Èí³Ðŵ¾¡¿ì½¨¸´£»ÀÕË÷ÍÅ»ïSynAckΪ֮ǰµÄÊܺ¦ÕßÃâ·ÑÌṩ½âÃÜÃÜÔ¿ άËûÃü άËûÃü°²È« ½ñÌì
°ä²¼¹¦·ò 2021-08-131.Print Spooler´æÔÚ佨¸´RCE£¬Î¢Èí³Ðŵ¾¡¿ì½¨¸´

ÔÚ°ä²¼8Ô·ÝÖܶþ°²È«¸üеĵڶþÌ죬΢ÈíÈ·ÈÏÁËWindows Print Spooler×é¼þÖдæÔÚµÄÁíÒ»¸ö佨¸´µÄÔ¶³Ì´úÂëÖ´Ðзì϶£¬²¢°µÊ¾ËüÔÚÖÂÁ¦½¨¸´¸Ã·ì϶¡£¸Ã·ì϶¸ú×ÙΪCVE-2021-36958£¬CVSSÆÀ·ÖΪ7.3£¬ÊôÓÚ·ì϶PrintNightmareµÄÒ»²¿ÃÅ£¬¿ÉÓÃÀ´½«DelpyµÄDLL¸´Ôìµ½¿Í»§¶ËÖ´ÐÐÀ´´ò¿ªÏµÍ³µÄºÅÁîÌáÐÑ·û¡£Ä¿Ç°Î¢ÈíÉÐδ°ä²¼Õë¶Ô´Ë·ì϶µÄ°²È«¸üУ¬Óû§Äܹ»Í¨¹ý½ûÓÃPrint SpoolerÀ´»º½â´ËÀ๥»÷¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/08/microsoft-security-bulletin-warns-of.html
2.SAP°ä²¼°²È«¸üУ¬½¨¸´Æä²úÆ·ÖеĶà¸ö°²È«·ì϶

SAPÓÚ8ÔÂ10ÈÕ°ä²¼°²È«¸üУ¬½¨¸´Æä²úÆ·ÖеĶà¸ö°²È«·ì϶¡£Õâ´Î½¨¸´µÄ½ÏΪÑϳÁµÄÊÇSAP Business OneÖеÄÎÞÏÞ¶ÈÎļþÉÏ´«·ì϶£¨CVE-2021-33698£©£¬CVSSÆÀ·ÖΪ9.9£»SAP NetWeaver¿ª·¢»ù´¡¼Ü¹¹ÖеķþÎñÆ÷¶ËÒªÇóαÔì·ì϶£¨CVE-2021-33690£©£¬CVSSÆÀ·ÖΪ9.9£»ÒÔ¼°SAP NZDTÖеÄSQL×¢Èë·ì϶£¨CVE-2021-33701£©£¬CVSSÆÀ·ÖΪ9.1¡£´Ë±í£¬»¹½¨¸´ÁË¿çÕ¾¾ç±¾·ì϶£¨CVE-2021-33702ºÍCVE-2021-33703£©µÈ·ì϶¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/sap-patches-critical-bugs/168558/
3.ÐÂ¼ÓÆÂµçÐŹ«Ë¾StarHub³ÆÆä³¬¹ý5.7ÍòÓû§ÐÅϢй©

ÐÂ¼ÓÆÂµÚ¶þ´óµçÐÅÔËÓªÉÌStarHubÓÚ8ÔÂ11ÈÕ·¢ËÍÓʼþ³ÆÆä³¬¹ý5.7ÍòÓû§ÐÅϢй©¡£ÓʼþÖÐд·£¬¸Ã¹«Ë¾ÓÚ±¾ÔÂÔçЩʱ³½ÔÚµÚÈý·½Êý¾Ýת´¢ÍøÕ¾ÉÏ·¢ÏÖÁËÒ»¸ö·¸·¨ÉÏ´«µÄÎļþ£¬ÆäÖÐÔ̺¬2007Äê֮ǰÆä¿Í»§¶©ÔÄStarHubµÄÓйØÐÅÏ¢¡£StarHubÐû³Æ¿Í»§µÄÐÅÓþ¿¨ºÍÒøÐÐÐÅϢûÓÐй¶£¬²¢ÇÒËûÃǽ«ÎªËùÓÐÊÜÓ°ÏìµÄ¿Í»§ÌṩÁù¸öÔµÄÃâ·ÑÐÅÓþ¼à¿Ø¡£The Register°µÊ¾£¬Õâ´Îй¶ÊÂÎñÓÚ7ÔÂ6ÈÕ·¢ÏÖ£¬µ«Ö±µ½8ÔÂ6ÈղŰ䲼³öÀ´¡£
ÔÎÄÁ´½Ó£º
https://www.theregister.com/2021/08/12/singapore_telecom_breach_leaked_personal/
4.ReindeerÒò´æ´¢Í°ÅäÖÃÃýÎóй¶³¬¹ý30ÍòÓû§µÄÐÅÏ¢

WizCase×êÑÐÈËÔ±·¢ÏÖReindeerÒòS3´æ´¢Í°ÅäÖÃÃýÎóй¶ÁËÔ¼360009¸öÓû§µÄÐÅÏ¢¡£ReindeerÊÇÒ»¼ÒÃÀ¹úÓªÏú¹«Ë¾£¬Ö®Ç°ÓëTiffany&Co.¡¢Patr¨°n TequilaµÈ¹«Ë¾ºÏ×÷¹ý¡£Õâ´Îй¶µÄÊý¾ÝÄܹ»×·Òäµ½2007Äê5ÔÂÖÁ2012Äê2Ô£¬Ô¼ÄªÓÐ50000¸öÎļþºÍ×ܹ²32GBµÄÊý¾Ý£¬Ô̺¬¿Í»§ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µç×ÓÓʼþ¡¢Facebook ID ºÍÃÜÂë¡¢µç»°ºÅÂë¡¢µØÖ·µÈÐÅÏ¢£¬Ó°ÏìÁË35¸ö¹ú¶È»òµØÓòµÄÓû§¡£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/reindeer-suffers-massive-data-breach-affecting-300-000-users-533740.shtml
5.¶ñÒâÈí¼þAdLoadµÄбäÖÖ¿ÉÈÆ¹ýAppleµÄXProtect

°²È«¹«Ë¾SentinelOne·¢ÏÖ¶ñÒâÈí¼þAdLoadµÄбäÖÖ¿ÉÈÆ¹ýAppleÄÚÖð²È«½ÚÔìXProtect¡£AdLoadÊÇÒ»ÖÖÕë¶ÔmacOSƽ̨µÄľÂí£¬×Ô2017ËêĺÒÔÀ´»îÔ¾£¬ÓÃÓÚ×°Öø÷Ààpayload£¬Ô̺¬¸æ°×Èí¼þºÍPUAs¡£Õâ´Î´ó¹æÄ£µÄ³ÖÐø¹¥»÷×îÔçÓÚ2020Äê11ÔÂÆðÍ·£¬²¢ÓÚ2021Äê7ÔºÍ8Ô³õÔö³¤¡£×êÑÐÈËÔ±°µÊ¾£¬XProtectÓÐԼĪ11¸ö·ÖÆçµÄAdLoadÊðÃû£¬µ«ÊÇËüÆëȫûÓмì²âµ½Õâ´ÎµÄ¹¥»÷»î¶¯¡£
ÔÎÄÁ´½Ó£º
https://labs.sentinelone.com/massive-new-adload-campaign-goes-entirely-undetected-by-apples-xprotect/
6.ÀÕË÷ÍÅ»ïSynAckΪ֮ǰµÄÊܺ¦ÕßÃâ·ÑÌṩ½âÃÜÃÜÔ¿

ÀÕË÷ÍÅ»ïEl_Cometa£¨Ç°ÉíΪSynAck£©ÔÚ8ÔÂ12ÈÕΪ2017Äê7ÔÂÖÁ2021ËêÊ×±»Ï°È¾µÄÊܺ¦ÕßÌṩÖ÷½âÃÜÃÜÔ¿¡£SynAckÓÚ2017Äê7Ô³õ´Î±»·¢ÏÖ£¬Êǵ±½ñÈÔÔÚÔËÐеÄ×î¹ÅÀϵÄÀÕË÷Èí¼þÍÅ»ïÖ®Ò»£¬Ëû°ä²¼µÄÃÜÔ¿Òѱ»°²È«¹«Ë¾EmsisoftÑéÖ¤ÎªÕæÊµµÄ¡£SynAck°µÊ¾£¬ËûÃǾö¶¨ÎªÊܺ¦Õß°ä²¼Ö÷½âÃÜÃÜÔ¿£¬ÓÉÓÚËûÃÇ´Ë¿ÌÒѾʵÏÖÁ˾ɵÄSynAckʱÆÚ£¬²¢×¨Ò»ÓÚÉϸöÔÂÆô¶¯µÄEl_CometaÐÂÏîÄ¿¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/synack-ransomware-gang-releases-decryption-keys-for-old-victims/


¾©¹«Íø°²±¸11010802024551ºÅ