VMwareÄþ¾²¸üУ¬ÐÞ¸´vCenterÖÐÑÏÖØµÄRCE©¶´£»ANSSIÅû¶BluetoothCoreºÍMeshЭÒéÖжà¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2021-05-26

1.VMwareÐû²¼Äþ¾²¸üУ¬ÐÞ¸´vCenterÖÐÑÏÖØµÄRCE©¶´


1.jpg


VMwareÐû²¼Äþ¾²¸üУ¬ÐÞ¸´vCenterÖÐÑÏÖØµÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©Â©¶´ ¡£¸Ã©¶´±»×·×ÙΪCVE-2021-21985£¬CVSSv3ÆÀ·ÖΪ9.8£¬Ó°ÏìÁËvCenter Server 6.5¡¢6.7ºÍ7.0 ¡£Â©¶´ÊÇÓÉÓÚVirtual SANÔËÐÐ×´¿ö¼ì²é²å¼þÖÐȱÉÙÊäÈëÑéÖ¤µ¼ÖµÄ£¬¾ßÓÐ443¶Ë¿Ú·ÃÎÊȨµÄ¹¥»÷Õß¿ÉÒÔÀûÓÃÆäÖ´ÐÐÈÎÒâÃüÁî ¡£VMware³Æ£¬ËùÓÐvCenter Server£¬ÎÞÂÛÆäÊÇ·ñʹÓÃvSAN£¬¶¼Ä¬ÈÏÆôÓÃÁËVirtual SANÔËÐÐ×´¿ö¼ì²é²å¼þ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/vmware-warns-of-critical-bug-affecting-all-vcenter-server-installs/


2.ANSSIÅû¶Bluetooth CoreºÍMeshЭÒéÖжà¸öÄþ¾²Â©¶´


2.jpg


·¨¹úÇ鱨»ú¹¹ANSSIµÄÑо¿ÈËÔ±·¢ÏÖÁËBluetooth CoreºÍMesh ProfileЭÒéÖдæÔÚ¶à¸ö©¶´ ¡£ÕâÁ½¸öЭÒé½ç˵ÁËÀ¶ÑÀÉ豸Ï໥ͨÐÅËùÐèµÄÐèÇó£¬ÒÔ¼°À¶ÑÀÉ豸ʹÓõÍÄܺÄÎÞÏß¼¼ÊõʵÏÖ»¥²Ù×÷µÄÍø×´ÍøÂç½â¾ö·½°¸ËùÐèµÄÐèÇó ¡£Â©¶´·Ö±ðΪCVE-2020-26559¡¢CVE-2020-26556¡¢CVE-2020-26557ºÍCVE-2020-26560µÈ£¬¹¥»÷ÕßÀûÓÃÕâЩ©¶´¿ÉÔÚÅä¶Ô¹ý³ÌÖÐð³äºÏ·¨É豸£¬²¢ÌᳫÖмäÈË£¨MitM£©¹¥»÷ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/118219/hacking/bluetooth-core-mesh-specs-flaws.html


3.ÈÕ±¾»é½éÓ¦ÓÃOmiaiÔâµ½¹¥»÷£¬171Íò»áÔ±µÄÐÅϢй¶


3.jpg


ÈÕ±¾×î´óµÄ»é½éÓ¦ÓÃOmiaiÔâµ½¹¥»÷£¬1711756¸ö»áÔ±µÄÐÅϢй¶ ¡£Õâ¿îÓ¦ÓÃÓµÓÐÁè¼Ý680Íò¸öÕÊ»§£¬Ã¿ÔÂÏòÄÐÊ¿ÊÕÈ¡37ÃÀÔªµÄÓöÈ ¡£OmiaiÌåÏÖ£¬Ð¹Â¶µÄÐÅϢΪ2018Äê1ÔÂÖÁ2021Äê4ÔÂÖ®¼ä£¬°üÂÞÐÕÃû³öÉúÈÕÆÚ¡¢×¢²áºÅ¡¢¼ÝÕÕ¡¢±£ÏÕ¿¨ºÍ»¤Õյȣ¬²¢¼á³ÆÃ»ÓÐÈκÎÐÅÓÿ¨Êý¾Ýй¶ ¡£Hackread.com֤ʵ£¬Ä¿Ç°Ò»Ð©ºÚ¿ÍÂÛ̳ÉϵÄÍþвÕßÒѾ­ÔÚѰÕÒ±»µÁµÄOmiaiÊý¾Ý¿â ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/japanese-dating-app-omiai-hack-users-at-risk/


4.ClearSky³ÆÒÑÇÔÈ¡ÊýÒÚÃÀÔªµÄCryptoCoreÓ볯ÏÊÓйØ


4.jpg


ÍøÂçÄþ¾²¹«Ë¾ClearSky³ÆÒÑÇÔÈ¡ÊýÒÚÃÀÔªµÄCryptoCoreÓ볯ÏÊÓйØ ¡£CryptoCore×Ô2018Ä꿪ʼ»îÔ¾£¬¹¥»÷ÁËÃÀ¹ú¡¢ÒÔÉ«ÁС¢Å·ÖÞºÍÈÕ±¾µÈ¹úµÄ¼ÓÃÜ»õ±Ò½»Ò×Ëù£¬Ôì³ÉµÄËðʧԤ¼ÆÁè¼Ý2ÒÚÃÀÔª ¡£×î³õ£¬ClearSkyÈÏΪ¸ÃÍÅ»ïÓëÎÚ¿ËÀ¼¡¢¶íÂÞ˹ºÍÂÞÂíÄáÑǵȶ«Å·¹ú¼ÒÓйØ ¡£½üÆÚ·¢ÏÖCryptoCoreÓëF-SecureµÄ»î¶¯¸ß¶ÈÒ»Ö£¬ºóÕßÓ볯ÏʵÄLazarus×éÖ¯ÓйØ ¡£Ñо¿ÈËÔ±»¹Ö¸³ö£¬ºÚ¿ÍµÄ»î¶¯Ò²ÔÚÀ©´ó£¬×î½ü¿ªÊ¼½«É«ÁÐ×÷ΪĿ±ê ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/north-korean-hackers-behind-cryptocore-multi-million-dollar-heists/


5.FBIǰÇ鱨·ÖÎöʦ±»Ö¸¿ØÔÚ¹ýÈ¥13ÄêÀïÇÔÈ¡»úÃÜÎļþ


5.jpg


FBIǰÇ鱨·ÖÎöʦKendra Kingsbury±»Ö¸¿ØÔÚ¹ýÈ¥13ÄêÀïÇÔÈ¡»úÃÜÎļþ ¡£ÃÀ¹ú˾·¨²¿£¨DoJ£©ÌåÏÖ£¬´Ó2004Äê6ÔÂÖÁ2017Äê12Ô£¬Kingsbury½«Óйعú¼ÒÄþ¾²¡¢»úÃܺͻúÒªµÄÎļþÉú´æÔÚ¼ÒÀï ¡£ÆðËßÊéÖ¸³ö£¬±»¸æÎÞȨɾ³ýºÍ±£ÁôÕâЩÃô¸ÐµÄÕþ¸®ÖÊÁÏ ¡£KingsburyÔÚFBIÊÂÇé12ÄêÒÔÉÏ£¬Êܹý´¦ÖÃÃô¸ÐÖÊÁϺͱ£ÃÜÐÐΪµÄÅàѵ£¬ÈÎÖ°ÆÚ¼äÔÚ·´¿Ö¡¢··¶¾ºÍ°ïÅÉ·¸×ïµÄС¶ÓÊÂÇé ¡£KingsburyÓÚ2017Ä걻ְͣ£¬±»¿ØÁ½Ïî¹ÊÒâ±£Áô¹ú·ÀÐÅÏ¢µÄ×ïÃû£¬ÏÖÒѱ»²¶ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/fbi-intelligence-officer-indicted-for-theft-of-cybersecurity-threat-counterterrorism-documents/


6.ÖÆÒ©¹«Ë¾SiegfriedÔâµ½¹¥»÷£¬¶à¸ö·Ö¹«Ë¾ÔÝÍ£Éú²ú


6.jpg


ÖÆÒ©¹«Ë¾Siegfried³ÆÆäÔâµ½¹¥»÷£¬¶à¸ö·Ö¹«Ë¾ÔÝÍ£Éú²ú ¡£SiegfriedÊÇÒ»¼ÒÈ«ÇòÐÔµÄÒ½Ò©¹«Ë¾£¬ÔÚÈðÊ¿¡¢µÂ¹ú¡¢Î÷°àÑÀ¡¢·¨¹ú¡¢Âí¶úËû¡¢ÃÀ¹úºÍÖйúÉèÓзֹ«Ë¾ ¡£¸Ã¹«Ë¾ÓÚ5ÔÂ21ÈÕÐÇÆÚÎåÍíÉϼì²âµ½¹¥»÷£¬Ö®ºóÁ¢¼´½ÓÄÉ´ëÊ©£¬ÔÝÍ£Á˸÷¸ö·Ö¹«Ë¾µÄÉú²ú²¢ÖжÏÁËÍøÂçÁ¬½Ó ¡£¸Ã¹«Ë¾³Æ£¬³ýÁËÔÚÎ÷°àÑÀµÄÁ½¸öËùÔÚÒòΪÔÚ¸ôÀëµÄÍøÂçÉÏÔËÐÐÍâ¶øÎ´ÊÜÓ°ÏìÍ⣬ÆäËûµÄ¹«Ë¾¾ùÊܵ½Á˲îÒìˮƽµÄÓ°Ïì ¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/ch-siegfried-affected-by-attack-on-its-it-systems/