°ÍÎ÷³ÆÆä²ÆÕþ²¿ÃØÊé´¦µÄÄÚ²¿ÍøÂçÔâµ½ÀÕË÷Èí¼þ¹¥»÷:Fortinet FortiWeb WAF´æÔÚ佨¸´µÄºÅÁî×¢Èë0day

°ä²¼¹¦·ò 2021-08-23

°ÍÎ÷³ÆÆä²ÆÕþ²¿ÃØÊé´¦µÄÄÚ²¿ÍøÂçÔâµ½ÀÕË÷Èí¼þ¹¥»÷


°ÍÎ÷³ÆÆä²ÆÕþ²¿ÃØÊé´¦µÄÄÚ²¿ÍøÂçÔâµ½ÀÕË÷Èí¼þ¹¥»÷.jpg


°ÍÎ÷µ±¾ÖÔÚÉÏÖÜÁùÍí¼äй© £¬Æä²ÆÕþ²¿ÃØÊé´¦µÄÄÚ²¿ÍøÂçÔÚÖÜÎåÍíÉÏ£¨8ÔÂ13ÈÕ£©Ôâµ½ÁËÀÕË÷Èí¼þ¹¥»÷¡£°ÍÎ÷¾­¼Ã²¿°ä²¼ÉêÃ÷³Æ £¬¾­¹ý³õ²½ÆÀ¹ÀÈ·¶¨¹ú¿âµÄϵͳ²¢Î´Êܵ½Ó°Ïì¡£8ÔÂ16ÈÕ £¬°ÍÎ÷µ±¾ÖÓë°ÍÎ÷֤ȯÂòÂôËù¾Í¸ÃÊÂÎñ°ä·¢Á˽áºÏÉêÃ÷ £¬³Æ¾ÓÃñ²É°ì°ÍÎ÷µ±¾ÖծȯµÄTesouro Diretoƽ̨ҲδÊܵ½Ó°Ïì¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/brazilian-government-discloses-national-treasury-ransomware-attack/



Cisco·¢ÏÖÕë¶ÔÄ«Î÷¸ç½ðÈÚ»ú¹¹µÄÐÂľÂíNeurevt


Cisco·¢ÏÖÕë¶ÔÄ«Î÷¸ç½ðÈÚ»ú¹¹µÄÐÂľÂíNeurevt.png


Cisco TalosÓÚ2021Äê6Ô¼ì²âµ½ÐÂNeurevtľÂí¡£¸Ã¶ñÒâÈí¼þ½«ºóÃźÍÐÅÏ¢ÇÔÈ¡·¨Ê½½áºÏÔÚһ· £¬ÖØÒªÕë¶ÔÄ«Î÷¸ç½ðÈÚ»ú¹¹µÄÓû§¡£¹¥»÷ÕßÒ»µ©³É¹¦Ï°È¾Ö¸±êÉ豸 £¬¾ÍÄܹ»½Ó¼ûÖ¸±êϵͳ²¢Åú¸ÄËûÃǵÄÉèÖÃÒÔ°µ²Ø×Ô¼º¡£¸ÃľÂíÄܹ»Í¨¹ý½Ó¼ûÊܺ¦ÕßµÄϵͳ·þÎñÁîÅÆÀ´ÌáȨ £¬´Ó¶ø½Ó¼û²Ù×÷ϵͳ¡¢Óû§ÕÊ»§ÐÅÏ¢¡¢ÒøÐÐÍøÕ¾Í´´¦¡¢½ØÈ¡ÆÁÄ»½ØÍ¼²¢·¢Ë͵½C2·þÎñÆ÷ÒÔÇÔȡָ±êµÄÐÅÏ¢¡£ 


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2021/08/neurevt-trojan-takes-aim-at-mexican.html



×êÑÐÍŶӷ¢ÏÖÕë¶ÔÈÕ±¾ÐÄÔÚ·Ö·¢CinobiµÄ¶ñÒâ¸æ°×»î¶¯


×êÑÐÍŶӷ¢ÏÖÕë¶ÔÈÕ±¾ÐÄÔÚ·Ö·¢CinobiµÄ¶ñÒâ¸æ°×»î¶¯2.jpg


Ç÷Ïò¿Æ¼¼×êÑÐÍŶÓÓÚÉÏÖܰ䲼ÁËÒ»Ïî·ÖÎö £¬½ÒʾÁ˺ڿÍÍÅ»ïWater KappaÕë¶ÔÈÕ±¾µÄ¶ñÒâ¸æ°×»î¶¯¡£¹¥»÷ÕßÊ×ÏÈʹÓÃÈÕ±¾¶¯»­ÓÎÏ·¡¢¼Î½±»ý·ÖÀûÓúÍÊÓÆµÁ÷·þÎñ·Ö·¢¶ñÒâ¸æ°× £¬×îÖÕ×°ÖÃÒøÐÐľÂíCinobi¡£×êÑÐÈËÔ±·¢ÏÖÕâ´Î»î¶¯ÖØÒªÕë¶ÔʹÓÃInternet ExplorerÒÔ±íµÄä¯ÀÀÆ÷µÄÈÕ±¾Óû§ £¬²¢ÖØÒªÇÔÈ¡ÈÕ±¾µÄ11¼Ò½ðÈÚ»ú¹¹µÄÓû§ÃûºÍÃÜÂë £¬ÆäÖÐ3¼ÒÉæ¼°¼ÓÃÜÇ®±ÒÂòÂô¡£


Ô­ÎÄÁ´½Ó£º

https://www.trendmicro.com/en_in/research/21/h/cinobi-banking-trojan-targets-users-of-cryptocurrency-exchanges-.html


ClearSky·¢ÏÖSiamesekittenÕë¶ÔÒÔÉ«Áеļäµý»î¶¯


ClearSky·¢ÏÖSiamesekittenÕë¶ÔÒÔÉ«Áеļäµý»î¶¯.png


ClearSkyµÄ×êÑÐÈËÔ±ÔÚ8ÔÂ17ÈÕÅû¶ÁËÒÁÀÊAPT×éÖ¯SiamesekittenÕë¶ÔÒÔÉ«Áеļäµý»î¶¯¡£ClearSkyÓÚ2021Äê5Ô³õ¼ì²âµ½¸ÃÍÅ»ïÕë¶ÔÒÔÉ«ÁеÄÒ»¼ÒIT¹«Ë¾µÄµÚÒ»´Î¹¥»÷ £¬²¢ÔÚ5ÔºÍ7ÔÂÓÖ¼ì²âµ½ÁËÂŴι¥»÷¡£ÔÚÕâ´Î»î¶¯ÖÐ £¬ºÚ¿Í¼Ù×°³ÉChipPcºÍSoftware AGµÈ³ÛÃû¹«Ë¾µÄÈËÁ¦×ÊÔ´²¿Ô±¹¤ £¬ÒÔÓÕÈ˵ÄְλÓÕʹָ±ê½øÈë´¹µöÍøÒ³ÏÂÔØÔ¶³Ì½Ó¼ûľÂíDanBot¡£ÓÉÓÚÕâ´Î¹¥»÷ÖØÒªÕë¶ÔITºÍͨѶ¹«Ë¾ £¬Òò¶øClearSky´§Ä¦ºÚ¿Í¿ÉÄÜÖ¼ÔÚ¶ÔËûÃǵĿͻ§ÌáÒ鹩¸øÁ´¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.clearskysec.com/siamesekitten/


Fortinet FortiWeb WAF´æÔÚ佨¸´µÄºÅÁî×¢Èë0day


Fortinet FortiWeb WAF´æÔÚ佨¸´µÄºÅÁî×¢Èë0day.jpg


Fortinet FortiWeb WebÀûÓ÷¨Ê½·À»ðǽ(WAF)´æÔÚºÅÁî×¢Èë0day £¬¹¥»÷ÕßÀûÓø÷ì϶Äܹ»Í¨¹ýSAML·þÎñÆ÷ÅäÖÃÒ³ÃæÒÔrootÓû§Éí·ÝÖ´ÐÐËÁÒâºÅÁî¡£¹ÌÈ»¹¥»÷Õß±ØÐëͨ¹ýÁËÖ¸±êÉ豸ÖÎÀí½çÃæµÄÉí·ÝÑéÖ¤ÄÜÁ¦ÀûÓô˷ì϶ £¬µ«ÈôÊÇÓëÆäËû·ì϶£¨ÀýÈçÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶CVE-2020-29015£©½áºÏʹÓà £¬Äܹ»ÆëÈ«½ÚÔìÖ¸±ê·þÎñÆ÷¡£FortinetÒѽ«¸Ã·ì϶µÄ½¨¸´´òËãÍÆ³Ùµ½8Ôµ× £¬×êÑÐÈËÔ±½¨Ò齨ÒéÖÎÀíÔ±²»ÈÝ´Ó²»ÊÜÐÅÀµµÄÍøÂç½Ó¼ûFortiWebÉ豸µÄÖÎÀí½çÃæÒÔÔ¤·À´ËÀ๥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/121221/security/fortinet-fortiweb-os-command-injection.html


Adobe°ä²¼°²È«¸üР£¬½¨¸´Æä¶à¿î²úÆ·Öеݲȫ·ì϶


Adobe°ä²¼°²È«¸üÐÂ£¬½¨¸´Æä¶à¿î²úÆ·Öеݲȫ·ì϶.jpg


AdobeÓÚ8ÔÂ17ÈÕ°ä²¼°²È«¸üР£¬½¨¸´ÁËAdobe Captivate¡¢XMP Toolkit SDK¡¢Photoshop¡¢BridgeºÍMedia EncoderÖеĶà¸ö°²È«·ì϶¡£ÆäÖнÏΪÑϳÁµÄÊÇAdobe XMP Toolkit SDKÖеÄËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-36052ºÍCVE-2021-36064£©¡¢PhotoshopÖеÄËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-36065ºÍCVE-2021-36066£© £¬ÒÔ¼°Adobe BridgeÖеÄËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-36078µÈ£©µÈ·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/08/18/adobe-releases-multiple-security-updates