ÑÇÂíÑ·AWSÔÆ·þÎñÔÙ´Îå´»úÓ°ÏìTwitchºÍZoomµÅצÓÃ

°ä²¼¹¦·ò 2021-12-16

Adobe°ä²¼12Ô¸üУ¬½¨¸´¶à¸ö²úÆ·Öг¬¹ý60¸ö·ì϶


Adobe°ä²¼12Ô¸üУ¬½¨¸´¶à¸ö²úÆ·Öг¬¹ý60¸ö·ì϶.png


12ÔÂ14ÈÕ£¬Adobe°ä²¼±¾ÔµÄÖܶþ²¹¶¡£¬½¨¸´¶à¸ö²úÆ·Öг¬¹ý60¸ö·ì϶¡£ÆäÖнÏΪÑϳÁµÄÊÇExperience ManagerÖеÄXXE·ì϶£¨CVE-2021-40722£©£¬CVSSÆÀ·ÖΪ9.8£¬¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐС£´Ë±í£¬»¹½¨¸´ÁËPhotoshopÖпɵ¼ÖÂËÁÒâ´úÂëÖ´ÐÐÔ½½çдÈë·ì϶£¨CVE-2021-43018£©»ººÍ³åÇøÒç¶Âí½Å£¨CVE-2021-44184£©£¬ÒÔ¼°Media EncoderÖеÄÔ½½ç¶ÁÈ¡£¨CVE-2021-43757£©µÈ¶à¸ö·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/125640/security/adobe-60-vulnerabilities-multiple-products.html


ÒÁÀÊMERCURY¶Ô×¼Öж«ºÍÑÇÖ޵ĵçÐźÍIT·þÎñÌṩÉÌ


ÒÁÀÊMERCURY¶Ô×¼Öж«ºÍÑÇÖ޵ĵçÐźÍIT·þÎñÌṩÉÌ.png


SymantecÔÚ12ÔÂ14ÈÕ¹«¿ªÁËÕë¶ÔÖж«ºÍÑÇÖÞµçÐźÍIT·þÎñÌṩÉ̵Ĺ¥»÷£¬ÒÉËÆÀ´×ÔÒÁÀʺڿÍÍÅ»ïMERCURY£¨±ðÃûMuddyWater£©¡£¸Ã»î¶¯ÆðÍ·ÓÚ6¸öÔÂ֮ǰ£¬ÖØÒªÀûÓÃÒ×Êܹ¥»÷µÄExchange·þÎñÆ÷ÈëÇÖ×éÖ¯µÄÍøÂç¡£Ö»¹ÜĿǰϰȾý½éÈÔδ֪£¬µ«×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸öZIPÎļþ¡°Special discount program.zip¡±£¬ÆäÖÐÔ̺¬Ô¶³Ì×ÀÃæÈí¼þÀûÓ÷¨Ê½µÄ×°Ö÷¨Ê½£¬Òò¶ø´§¶È¹¥»÷ÕßʹÓõÄÊÇÓã²æÊ½´¹µöÓʼþ¡£     


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/telecom-operators-targeted-in-recent-espionage-hacking-campaign/


Lookout·¢ÏÖÕë¶Ô½ü400¼Ò½ðÈÚ»ú¹¹·Ö·¢AnubisµÄ»î¶¯


Lookout·¢ÏÖÕë¶Ô½ü400¼Ò½ðÈÚ»ú¹¹·Ö·¢AnubisµÄ»î¶¯.png


12ÔÂ14ÈÕ£¬Lookout·¢ÏÖÁËÕë¶Ô394¼Ò½ðÈÚ»ú¹¹·Ö·¢AndroidÒøÐÐľÂíAnubisµÄ»î¶¯¡£AnubisÓÚ2016Äê³õ´Î³öÏÖ£¬×÷Ϊ¿ªÔ´ÒøÐÐľÂíÔÚ¶íÂÞ˹ºÚ¿ÍÂÛ̳Éϰ䲼¡£ÔÚÕâ´Î»î¶¯ÖУ¬¹¥»÷Õß¼ÙÒâ·¨¹úµçÐŹ«Ë¾Orange SAµÄÕÊ»§ÖÎÀíµ±Ó㬶Ô×¼´óÍ¨ÒøÐÓ×¢¸»¹úÒøÐÓ×¢ÃÀ¹úÒøÐк͵ÚÒ»±¾Ç®µÈ½ðÈÚ»ú¹¹µÄ¿Í»§¡£×êÑÐÈËÔ±³Æ£¬Õâ´Î¹¥»÷²»½ö½öÕë¶Ô´óÐÍÒøÐеĿͻ§£¬»¹Õë¶ÔÐé¹¹Ö§¸¶Æ½Ì¨ºÍ¼ÓÃÜÇ®°ü£¬¸Ã»î¶¯Ä¿Ç°ÈÔ´¦ÓÚ²âÊÔºÍÓÅ»¯½×¶Î¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/400-banks-targeted-anubis-trojan/177038/


VulcanForgeÐû³ÆÆäÔâµ½¹¥»÷Ëðʧ¸ß´ï½ü1.4ÒÚÃÀÔª


VulcanForgeÐû³ÆÆäÔâµ½¹¥»÷Ëðʧ¸ß´ï½ü1.4ÒÚÃÀÔª.png


ÓÎÏ·¹«Ë¾VulcanForgeÔÚ±¾ÖÜÒ»³ÆÆäÔâµ½ÁËÍøÂç¹¥»÷£¬Ëðʧ¸ß´ï1.35ÒÚÃÀÔª¡£¸Ã¹«Ë¾³Æ£¬¹¥»÷ÕßÒѾ­»ñµÃÁË96¸öÇ®°üµÄ˽Կ£¬²¢ÇÔÈ¡ÁË450ÍòPYR£¨VulcanForgeµÄ´ú±Ò£¬¿ÉÔÚÆäÕû¸öÓÎϷϵͳÖÐʹÓã©¡£´Ë±í£¬¹¥»÷ÕßÏúÊÛÁË´óÁ¿PYR£¬Ê¹PYRµÄ¼ÛÖµ×ÅÂä22%£¨´Ó31ÃÀÔª½µµ½24ÃÀÔª£©¡£ÕâÊǽüÊ®¼¸ÌìÄÚ²úÉúµÄµÚÈýÆð¼ÓÃÜÇ®±ÒʧÇÔÊÂÎñ£¬Èý´Î¹¥»÷Ôì³ÉµÄ×ÜËðʧ½ð¶îԼΪ4.04ÒÚÃÀÔª¡£


Ô­ÎÄÁ´½Ó£º

https://www.theblockcrypto.com/post/127270/96-private-keys-stolen-from-vulcan-forged-in-140-million-theft


KasperskyÅû¶ÀûÓÃIISÄ£¿éOwowaµÄ¹¥»÷»î¶¯Ï¸½Ú


KasperskyÅû¶ÀûÓÃIISÄ£¿éOwowaµÄ¹¥»÷»î¶¯Ï¸½Ú.png


12ÔÂ14ÈÕ£¬KasperskyÅû¶ÁËÀûÓÃIIS Web·þÎñÆ÷Ä£¿éOwowaµÄ¹¥»÷»î¶¯Ï¸½Ú¡£Ò£²âÊý¾ÝÏÔʾ£¬×îÐÂÑù±¾³öÏÖÓÚ2021Äê4Ô£¬¶Ô×¼ÂíÀ´Î÷ÑÇ¡¢Ãɹš¢Ó¡¶ÈÄáÎ÷ÑǺͷÆÂɱöµÄ¹Ù·½×éÖ¯ºÍ¹«¹²½»Í¨¹«Ë¾µÈ¡£OwowaÕë¶ÔExchangeµÄOutlook Web Access(OWA)£¬Ö¼ÔڼͼÔÚOWAµÇÂ¼ÍøÒ³Éϳɹ¦½øÐÐÉí·ÝÑéÖ¤µÄÓû§µÄÍ´´¦¡£¶øºó£¬¹¥»÷Õß»áÏò¶ñÒâÄ£¿é·¢ËͺÅÁîÀ´ÍøÂç±»µÁÊý¾Ý£¬²¢ÔÚ±»Ï°È¾É豸ÉÏÖ´ÐÐPowerShell£¬½øÐÐÏÂÒ»²½¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/owowa-credential-stealer-and-remote-access/105219/


ÑÇÂíÑ·AWSÔÆ·þÎñÔÙ´Îå´»úÓ°ÏìTwitchºÍZoomµÅצÓÃ


ÑÇÂíÑ·AWSÔÆ·þÎñÔÙ´Îå´»úÓ°ÏìTwitchºÍZoomµÅצÓÃ.png


12ÔÂ15ÈÕ£¬ÑÇÂíÑ·AWSÔÆ·þÎñÔÙ´Îå´»ú¡£ÆäÖÐ¶ÏÆðÍ·ÓÚÉýƽÑ󹦷òÉÏÎç7:43×óÓÒ£¬ÖØÒªÓ°ÏìÁËUS-WEST-1ºÍUS-WEST-2ÇøÓò£¬µ¼ÖÂTwitch¡¢Zoom¡¢PSN¡¢Xbox Live¡¢Doordash¡¢Quickbooks OnlineºÍHuluµÈ´óÁ¿Æ½Ì¨ºÍÍøÕ¾¹Ø¹Ø¡£½ØÖÁ12ÔÂ15ÈÕ11:27 £¬ÑÇÂíÑ·³ÆInternetÏνӵÄÎÊÌâÒѾ­½â¾ö£¬·þÎñÔËÐÐÕý³£¡£12ÔÂ7ÈÕ£¬ÑÇÂíÑ·AWSÔÆ·þÎñå´»ú£¬Ó°ÏìÁËNetflix¡¢RokuºÍAmazon PrimeµÄµÅצÓá£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/technology/aws-down-again-outage-impacts-twitch-zoom-psn-hulu-others/