AdobeÄþ¾²¸üР£¬ÐÞ¸´MagentoºÍConnectÖжà¸ö©¶´£»LockBit³ÆÒÑÇÔÈ¡°£É­ÕÜ6TBµÄÊý¾Ý²¢ÀÕË÷5000ÍòÃÀÔª

Ðû²¼Ê±¼ä 2021-08-12

1.AdobeÄþ¾²¸üР£¬ÐÞ¸´MagentoºÍConnectÖжà¸ö©¶´


1.jpg


AdobeÐû²¼ÁËÖܶþÄþ¾²¸üР£¬ÐÞ¸´Æäµç×ÓÉÌÎñƽ̨MagentoºÍConnectÖеÄ29¸ö©¶´¡£ÆäÖÐMagentoÖÐÐÞ¸´ÁË26¸ö©¶´ £¬½ÏΪÑÏÖØµÄÊÇÓÉÓÚÊäÈëÑéÖ¤²»Í×µ¼ÖµÄÈÎÒâ´úÂëÖ´ÐЩ¶´£¨CVE-2021-36021¡¢CVE-2021-36024ºÍCVE-2021-36025µÈ£©ºÍÃüÁî×¢Èëµ¼ÖµÄÈÎÒâ´úÂëÖ´ÐЩ¶´£¨CVE-2021-36022ºÍCVE-2021-36023£©µÈ©¶´¡£Adobe ConnectÖÐÐÞ¸´ÁË3¸ö©¶´ £¬°üÂÞÄþ¾²¹¦Ð§Èƹý©¶´£¨CVE-2021-36061£©ºÍ·´ÉäÐÍXSS©¶´£¨CVE-2021-36062ºÍCVE-2021-36063£©¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-preauth-vulnerabilities-in-magento/


2.CiscoÅû¶Mozilla FirefoxÖдúÂëÖ´ÐЩ¶´µÄϸ½Ú


2.jpg


Cisco TalosÅû¶ÁËMozilla FirefoxÖдúÂëÖ´ÐЩ¶´µÄϸ½Ú¡£¸Ã©¶´×·×ÙΪCVE-2021-29985 £¬´æÔÚÓÚFirefoxµÄnsBufferedStream×é¼þÖУ¨Stream»º³å¹¦Ð§µÄÒ»²¿ÃÅ£©¡£¹¥»÷Õß¿ÉÒÔÓÕʹÓû§·ÃÎÊÌØÖÆµÄ¶ñÒâÍøÒ³À´´¥·¢¸Ã©¶´ £¬À´µ¼ÖÂÎÉÂÒÇé¿ö£¨race condition£© £¬´Ó¶øµ¼ÖÂÊͷźóʹÓúÍÔ¶³Ì´úÂëÖ´ÐС£Ñо¿ÈËÔ±³ÆFirefox°æ±¾89.0.3 x64´æÔڸé¶´ £¬½¨ÒéÁ¢¼´¸üС£ 

  

Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2021/08/vuln-spotlight-firefox-code.html


3.LockBit³ÆÒÑÇÔÈ¡°£É­ÕÜ6TBµÄÊý¾Ý²¢ÀÕË÷5000ÍòÃÀÔª


3.jpg


ÀÕË÷ÍÅ»ïLockBit 2.0Éù³ÆÒÑÇÔÈ¡°£É­Õܹ«Ë¾Áè¼Ý6TBµÄÊý¾Ý £¬²¢ÀÕË÷5000ÍòÃÀÔª¡£°£É­ÕÜÊÇÈ«ÇòÖªÃûµÄIT×Éѯ¹«Ë¾ £¬ÊÐÖµ443ÒÚÃÀÔª £¬·þÎñÓÚÆû³µ¡¢ÒøÐС¢Õþ¸®¡¢¼¼Êõ¡¢ÄÜÔ´¡¢µçÐŵÈÖÚ¶àÐÐÒµ¡£¸ÃÍÅ»ï³ÆÒÑͨ¹ý¹«Ë¾µÄ¡°ÄÚ²¿ÈËÔ±¡±·ÃÎʰ£É­ÕܵÄÍøÂç £¬²¢ÌåÏÖÈç¹ûûÓÐÖ§¸¶Êê½ðËûÃǽ«ÔÚ8ÔÂ11ÈÕÍíÉÏÐû²¼Êý¾Ý £¬µ«11ÈÕÍíÉϹýºó¸ÃÍŻォй¶ʱ¼äÍÆ³Ùµ½ÁË8ÔÂ12ÈÕ20:43:00¡£ÍþвÇ鱨¹«Ë¾Hudson RockÌåÏÖ°£É­ÕÜÓÐ2500̨Ա¹¤ºÍºÏ×÷»ï°éµÄµçÄÔÒÑÔâµ½ÈëÇÖ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/121048/data-breach/accenture-lockbit-2-0-ransomware-attack.html


4.ÓÎÏ·¹«Ë¾CrytekÈÏ¿ÉÆäÔøÔâÀÕË÷Èí¼þEgregorµÄ¹¥»÷


4.jpg


ÓÎÏ·¿ª·¢É̺Ϳ¯ÐÐÉÌCrytekÈÏ¿ÉÆäÔøÓÚ2020Äê10ÔÂÔâµ½ÀÕË÷Èí¼þEgregorµÄ¹¥»÷¡£EgregorÔø¹¥»÷¹ýÈ«ÇòÖÚ¶à×éÖ¯ £¬Èçθ绪µÄTransLinkµØÌúϵͳºÍKmartµÈ £¬ÆäÖ÷Òª³ÉÔ±ÓÚ2021Äê2ÔÂÔÚ·¨¹úºÍÎÚ¿ËÀ¼Ö´·¨²¿ÃÅÁªºÏÐж¯Öб»²¶¡£Crytek³Æ´Ë´Î¹¥»÷й¶Á˿ͻ§¸öÈËÐÅÏ¢ £¬ÐÕÃû¡¢Ö°Îñ¡¢¹«Ë¾Ãû³Æ¡¢µç×ÓÓʼþ¡¢¹«Ë¾µØÖ·¡¢µç»°ºÅÂëºÍµØÓòµÈ¡£¶øEgregor֮ǰÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾¹ûÈ»µÄÊý¾Ý°üÂÞÓëWarFaceÏà¹ØµÄÎļþ¡¢MOBAÓÎÏ·ÃüÔ˾º¼¼³¡ºÍÓÐ¹ØÆäÍøÂçÔËÐÐÐÅÏ¢µÄÎļþ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/crytek-confirms-egregor-ransomware-attack-customer-data-theft/


5.FireEye·¢ÏÖUNC215Õë¶ÔÒÔÉ«ÁÐÕþ¸®ÍøÂçµÄ¹¥»÷»î¶¯


FireEye·¢ÏÖUNC215Õë¶ÔÒÔÉ«ÁÐÕþ¸®ÍøÂçµÄ¹¥»÷»î¶¯.png


FireEye·¢ÏÖ¼äµý×éÖ¯UNC215½üÆÚÕë¶ÔÒÔÉ«ÁÐÕþ¸®ÍøÂçµÄ¹¥»÷»î¶¯¡£MandiantÔÚ2019Äê³õ·¢ÏÖUNC215Õë¶ÔÖж«µÄ¹¥»÷»î¶¯ £¬¹¥»÷ÕßÀûÓÃSharePointÖЩ¶´CVE-2019-0604ÔÚÖж«ºÍÖÐÑǵÄÄ¿±êÉ豸Éϰ²×°web shellºÍFOCUSFJORD payload¡£³ýÁËÒ£²âÊý¾Ý £¬Ñо¿ÈËÔ±»¹ÓëÒÔÉ«Áйú·À»ú¹¹ºÏ×÷ £¬·¢ÏÖ×Ô2019Äê1Ô¿ªÊ¼µÄÕë¶ÔÒÔÉ«ÁÐÕþ¸®»ú¹¹¡¢IT¹©Ó¦É̺͵çÐŹ«Ë¾µÄ¶à¸ö²¢Ðл £¬ÆÚ¼äUNC215 ʹÓÃеÄTTPÀ´Èƹý¼ì²â¡¢Òþ²Ø¹¥»÷»î¶¯²¢ÀûÓÿÉÐŹØÏµºáÏòÒÆ¶¯¡£


Ô­ÎÄÁ´½Ó£º

https://www.fireeye.com/blog/threat-research/2021/08/unc215-chinese-espionage-campaign-in-israel.html


6.Unit 42Ðû²¼ÀÕË÷Èí¼þeCh0raixбäÖֵķÖÎö³ÂËß


6.jpg


Unit 42Ðû²¼ÁËÓйØÀÕË÷Èí¼þeCh0raixбäÖֵķÖÎö³ÂËß¡£³ÂËßÖ¸³ö £¬¸Ã±äÖÖÀûÓÃÁË©¶´CVE-2021-28799 £¬Ö÷ÒªÕë¶ÔSynologyÍøÂ總¼Ó´æ´¢(NAS)ºÍQuality Network Appliance Provider (QNAP)NASÉ豸 £¬ÒѾ­ÔÚÒ°Íâ»îÔ¾Á˽üÒ»Äê¡£¸Ã³ÂËß½¨ÒéÓû§¸üÐÂÉ豸¹Ì¼þÒÔ·ÀÖ¹´ËÀ๥»÷¡¢´´½¨ÅÓ´óµÄµÇ¼ÃÜÂëÒÔ·ÀÖ¹±©Á¦ÆÆ½â £¬ÒÔ¼°½öͨ¹ýÒÑʶ±ðIPµÄÓ²±àÂëÁбíÏÞÖÆÓëSOHOÉ豸µÄÁ¬½Ó¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/ech0raix-ransomware-soho/