΢Èí3ÔÂÄþ¾²¸üУ¬ÐÞ¸´°üÂÞ2¸ö0dayÔÚÄÚµÄ82¸ö©¶´£»unit42Ðû²¼ÓйØdnsmasq©¶´µÄ·ÖÎö³ÂËß
Ðû²¼Ê±¼ä 2021-03-101.΢Èí3ÔÂÄþ¾²¸üУ¬ÐÞ¸´°üÂÞ2¸ö0dayÔÚÄÚµÄ82¸ö©¶´
΢ÈíÐû²¼ÁË3ÔÂÄþ¾²¸üУ¬ÐÞ¸´Á˰üÂÞ2¸ö0dayÔÚÄÚµÄ82¸ö©¶´¡£´Ë´ÎÐÞ¸´µÄ2¸ö0day·Ö±ðΪInternet ExplorerÖеÄÄÚ´æËð»µÂ©¶´£¨CVE-2021-26411£©ºÍWindows Win32kÖеÄÌØÈ¨ÌáÉý©¶´£¨CVE-2021-27077£©£¬¾ÝϤǰÕßÒѹûÈ»ÓÃÓÚ¹¥»÷¡£´ËÍ⣬΢Èí»¹ÐÞ¸´ÁËAzure SphereÖеĴúÂëÖ´ÐЩ¶´£¨CVE-2021-27074ºÍCVE-2021-27080£©¡¢OpenType×ÖÌå½âÎöÖÐÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-26876£©ºÍHyper-VÖеÄÔ¶³ÌÖ´ÐдúÂë©¶´£¨CVE-2021-26867£©µÈ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-march-2021-patch-tuesday-fixes-82-flaws-2-zero-days/
2.unit42Ðû²¼ÓйØdnsmasq©¶´µÄ·ÖÎö³ÂËß
unit42Ðû²¼ÓйØDNSαװ£¨dnsmasq£©Â©¶´µÄ·ÖÎö³ÂËß¡£DNSαװ£¨dnsmasq£©ÊÇÒ»Öֹ㷺ʹÓõĿªÔ´DNS½âÎöÆ÷£¬ÎªÐí¶àÏîÄ¿ºÍÓ²¼þËùʹÓã¬ÈçKubernetesºÍ·ÓÉÆ÷µÈ²úÎï¡£×î½üÑо¿ÈËÔ±·¢ÏÖÁËÐÂÎÊÌ⣬ʹµÃdnsmasqÈÝÒ×Êܵ½¹¥»÷¡£ÕâЩ©¶´¿É·ÖΪÁ½À࣬·Ö±ðΪDNSÐÒéʵʩÖеÄ©¶´CVE-2020-25684¡¢CVE-2020-25685ºÍCVE-2020-25686£¬ÒÔ¼°µ¼ÖÂDoS¹¥»÷µÄ»º³åÇøÒç³ö©¶´CVE-2020-25681¡¢CVE-2020-25682¡¢CVE-2020-25683ºÍCVE-2020-25687¡£
ÔÎÄÁ´½Ó£º
https://unit42.paloaltonetworks.com/overview-of-dnsmasq-vulnerabilities-the-dangers-of-dns-cache-poisoning/
3.EdgescanÐû²¼2020-2021Äê©¶´Í³¼ÆµÄ·ÖÎö³ÂËß
EdgescanÐû²¼ÁË2020-2021Äê©¶´Í³¼ÆµÄ·ÖÎö³ÂËß¡£³ÂËß½ÒʾÁË2020ÄêÒÔÀ´µÄ©¶´µÄͳ¼ÆÊý¾ÝºÍÇ÷ÊÆ£¬²¢´ÓÒÑ֪©¶´£¨CVE£©¡¢¶ñÒâÈí¼þ¡¢ÀÕË÷Èí¼þºÍ¿É¼ûÐԽǶȣ¨¹ûÈ»µÄ·þÎñ£©ÉîÈëÑо¿ÁË©¶´Ö¸±ê¡£2020ÄêÔ¶³Ì×ÀÃæ£¨RDPºÍSSH£©µÄ̻¶Ôö¼ÓÁË40%£¬ÓÐ21070¸ö»¥ÁªÍø¶Ëµã̻¶ÁËÊý¾Ý¿âϵͳ¡£È¥Äê·¢ÏÖµÄ×î³£¼ûµÄ©¶´ÊÇLogjam (CVE-2015-4000)£¬ÕâÊÇÒ»¸öʹÓÃDiffie-HellmanÃÜÔ¿½»»»ÃÜÂëϵͳµÄ©¶´£¬¿Éµ¼ÖÂÖмäÈ˹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://info.edgescan.com/vulnerability-stats-report-2021
4.Ñо¿ÈËÔ±·¢ÏÖUnityMinerÀûÓÃQNAP NASÖеÄ©¶´ÍÚ¿ó
Ñо¿ÈËÔ±·¢ÏÖÀûÓöñÒâÈí¼þUnityMinerÕë¶Ôδ´ò²¹¶¡µÄQNAPÍøÂçÁ¬½Ó´æ´¢£¨NAS£©É豸µÄ¼ÓÃÜ»õ±Ò¶ñÒâÈí¼þ»î¶¯¡£¸Ã»î¶¯Éæ¼°µ½ÁË2¸öδ¾ÊÚȨµÄÔ¶³ÌÃüÁîÖ´ÐЩ¶´£¨CVE-2020-2506£¦CVE-2020-2507£©£¬Ó°Ïì2020Äê8ÔÂ֮ǰµÄQNAP NAS¹Ì¼þ°æ±¾£¬ÒÑÓÚ2020Äê10ÔÂÐÞ¸´¡£ÓÐ4297426̨QNAP NAS¿ÉÄÜ»áÔâµ½´ËÀ๥»÷£¬ÆäÖÐ951486̨¾ßÓÐΨһµÄIPµØÖ·£¬´ó¶àÊýλÓÚÃÀ¹ú¡¢ÖйúºÍÒâ´óÀû¡£Ä¿Ç°Éв»Çå³þUnityMinerµÄÀúÊ·ÒÔ¼°Æä±³ºóµÄºÚ¿Í×éÖ¯¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/115403/hacking/unityminer-qnap-nas-devices.html
5.Ç÷ÊÆ¿Æ¼¼·¢ÏÖÒÁÀÊMuddyWaterÕë¶ÔÖж«×éÖ¯µÄ¹¥»÷»î¶¯
Trend Micro·¢ÏÖÒÁÀʺڿÍ×éÖ¯MuddyWaterÕë¶ÔÖж«×éÖ¯µÄ¹¥»÷»î¶¯¡£ºÚ¿ÍʹÓÃÁË´øÓÐǶÈëʽÁ´½ÓµÄÓã²æÊ½µç×ÓÓʼþ£¬½«Êܺ¦ÕßÖØ¶¨Ïòµ½ºÏ·¨µÄÎļþ¹²Ïí·þÎñScreenConnect£¬À´·Ö·¢Æä¶ñÒâÈí¼þ°ü¡£¸Ã»î¶¯Ö÷ÒªÕë¶ÔÖж«ºÍÖܱߵØÓòµÄѧÊõ½ç¡¢Õþ¸®»ú¹¹ºÍÂÃÓÎʵÌ壬ΪּÔÚÇÔÈ¡Êý¾ÝµÄ¼äµý»î¶¯¡£Trend Micro»¹·¢ÏÖ·Ö·¢RemoteUtilitiesºÍScreenConnectµÄÁ½¸ö»î¶¯Ö®¼äµÄ¼ÆÄ±ºÍ¼¼Êõ´óÖÂÏàËÆ£¬ÌåÏÖÐÂÒ»ÂÖ¹¥»÷Ö÷ÒªÕë¶Ô°¢Èû°Ý½®¡¢°ÍÁÖ¡¢ÒÔÉ«ÁС¢É³Ìذ¢À²®ºÍ°¢ÁªÇõµÄ×éÖ¯¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/03/iranian-hackers-using-remote-utilities.html
6.µÂ¿ËÈøË¹´óѧÔâµ½¹¥»÷£¬Ñ§Ð£ËùÓÐϵͳ±»ÆÈ¹Ø±Õ
µÂ¿ËÈøË¹´óѧ£¨University of Texas£©ÓÚ3ÔÂ7ÈÕÐû²¼ÉùÃ÷³ÆÆäÔâµ½¹¥»÷£¬Ñ§Ð£ËùÓÐϵͳ±»ÆÈ¹Ø±Õ¡£¸ÃУÌåÏÖ£¬ËûÃÇÔÚÖÜÎåÁ賿·¢ÏÖÁ˴˴ι¥»÷£¬Æäµç×ÓÓʼþºÍÍйܴóÑ§ÍøÕ¾µÄ·þÎñÆ÷¾ùÊܵ½´ËʼþµÄÓ°Ï죬½ÌÖ°Ô±¹¤ºÍѧÉúÖ»ÄÜͨ¹ýBlackboard½øÐÐͨÐÅ¡£´ËÍ⣬ÆäÔÚ¼ì²âµ½¹¥»÷ºóÁ¢¼´¹Ø±ÕÁËËùÓÐУ԰ϵͳ£¬²¢¶Ôÿ¸öϵͳ½øÐÐÁ˳¹µ×¼ì²é£¬·¢ÏÖ²¢Ã»ÓÐÈκθöÈËÐÅÏ¢±»Ð¹Â¶¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/hackers-target-texas-university/