ÑÇÂíÑ·AWSÔÆ·þÎñÔÙ´Îå´»úÓ°ÏìTwitchºÍZoomµÈÓ¦ÓÃ
Ðû²¼Ê±¼ä 2021-12-16AdobeÐû²¼12Ô¸üУ¬ÐÞ¸´¶à¸ö²úÎïÖÐÁè¼Ý60¸ö©¶´
12ÔÂ14ÈÕ£¬AdobeÐû²¼±¾ÔµÄÖܶþ²¹¶¡£¬ÐÞ¸´¶à¸ö²úÎïÖÐÁè¼Ý60¸ö©¶´¡£ÆäÖнÏΪÑÏÖØµÄÊÇExperience ManagerÖеÄXXE©¶´£¨CVE-2021-40722£©£¬CVSSÆÀ·ÖΪ9.8£¬¿Éµ¼ÖÂÈÎÒâ´úÂëÖ´ÐС£´ËÍ⣬»¹ÐÞ¸´ÁËPhotoshopÖпɵ¼ÖÂÈÎÒâ´úÂëÖ´ÐÐÔ½½çдÈë©¶´£¨CVE-2021-43018£©ºÍ»º³åÇøÒç³ö©¶´£¨CVE-2021-44184£©£¬ÒÔ¼°Media EncoderÖеÄÔ½½ç¶ÁÈ¡£¨CVE-2021-43757£©µÈ¶à¸ö©¶´¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/125640/security/adobe-60-vulnerabilities-multiple-products.html
ÒÁÀÊMERCURYÃé×¼Öж«ºÍÑÇÖ޵ĵçÐźÍIT·þÎñÌṩÉÌ
SymantecÔÚ12ÔÂ14ÈÕ¹ûÈ»ÁËÕë¶ÔÖж«ºÍÑÇÖÞµçÐźÍIT·þÎñÌṩÉ̵Ĺ¥»÷£¬ÒÉËÆÀ´×ÔÒÁÀʺڿÍÍÅ»ïMERCURY£¨ÓÖÃûMuddyWater£©¡£¸Ã»î¶¯¿ªÊ¼ÓÚ6¸öÔÂ֮ǰ£¬Ö÷ÒªÀûÓÃÒ×Êܹ¥»÷µÄExchange·þÎñÆ÷ÈëÇÖ×éÖ¯µÄÍøÂç¡£¾¡¹ÜĿǰѬȾý½éÈÔδ֪£¬µ«Ñо¿ÈËÔ±·¢ÏÖÁËÒ»¸öZIPÎļþ¡°Special discount program.zip¡±£¬ÆäÖаüÂÞÔ¶³Ì×ÀÃæÈí¼þÓ¦Ó÷¨Ê½µÄ°²×°·¨Ê½£¬Òò´ËÍÆ¶Ï¹¥»÷ÕßʹÓõÄÊÇÓã²æÊ½µöÓãÓʼþ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/telecom-operators-targeted-in-recent-espionage-hacking-campaign/
Lookout·¢ÏÖÕë¶Ô½ü400¼Ò½ðÈÚ»ú¹¹·Ö·¢AnubisµÄ»î¶¯
12ÔÂ14ÈÕ£¬Lookout·¢ÏÖÁËÕë¶Ô394¼Ò½ðÈÚ»ú¹¹·Ö·¢AndroidÒøÐÐľÂíAnubisµÄ»î¶¯¡£AnubisÓÚ2016ÄêÊ״ηºÆð£¬×÷Ϊ¿ªÔ´ÒøÐÐľÂíÔÚ¶íÂÞ˹ºÚ¿ÍÂÛ̳ÉÏÐû²¼¡£Ôڴ˴λÖУ¬¹¥»÷Õßð³ä·¨¹úµçÐŹ«Ë¾Orange SAµÄÕÊ»§¹ÜÀíÓ¦Óã¬Ãé×¼´óÍ¨ÒøÐС¢¸»¹úÒøÐС¢ÃÀ¹úÒøÐк͵ÚÒ»×ʱ¾µÈ½ðÈÚ»ú¹¹µÄ¿Í»§¡£Ñо¿ÈËÔ±³Æ£¬´Ë´Î¹¥»÷²»½ö½öÕë¶Ô´óÐÍÒøÐеĿͻ§£¬»¹Õë¶ÔÐéÄâÖ§¸¶Æ½Ì¨ºÍ¼ÓÃÜÇ®°ü£¬¸Ã»î¶¯Ä¿Ç°ÈÔ´¦ÓÚ²âÊÔºÍÓÅ»¯½×¶Î¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/400-banks-targeted-anubis-trojan/177038/
VulcanForgeÉù³ÆÆäÔâµ½¹¥»÷Ëðʧ¸ß´ï½ü1.4ÒÚÃÀÔª
ÓÎÏ·¹«Ë¾VulcanForgeÔÚ±¾ÖÜÒ»³ÆÆäÔâµ½ÁËÍøÂç¹¥»÷£¬Ëðʧ¸ß´ï1.35ÒÚÃÀÔª¡£¸Ã¹«Ë¾³Æ£¬¹¥»÷ÕßÒѾ»ñµÃÁË96¸öÇ®°üµÄ˽Կ£¬²¢ÇÔÈ¡ÁË450ÍòPYR£¨VulcanForgeµÄ´ú±Ò£¬¿ÉÔÚÆäÕû¸öÓÎϷϵͳÖÐʹÓã©¡£´ËÍ⣬¹¥»÷Õß³öÊÛÁË´óÁ¿PYR£¬Ê¹PYRµÄ¼Û¸ñϵø22%£¨´Ó31ÃÀÔª½µµ½24ÃÀÔª£©¡£ÕâÊǽüÊ®¼¸ÌìÄÚ·¢ÉúµÄµÚÈýÆð¼ÓÃÜ»õ±ÒʧÇÔʼþ£¬Èý´Î¹¥»÷Ôì³ÉµÄ×ÜËðʧ½ð¶îԼΪ4.04ÒÚÃÀÔª¡£
ÔÎÄÁ´½Ó£º
https://www.theblockcrypto.com/post/127270/96-private-keys-stolen-from-vulcan-forged-in-140-million-theft
KasperskyÅû¶ÀûÓÃIISÄ£¿éOwowaµÄ¹¥»÷»î¶¯Ï¸½Ú
12ÔÂ14ÈÕ£¬KasperskyÅû¶ÁËÀûÓÃIIS Web·þÎñÆ÷Ä£¿éOwowaµÄ¹¥»÷»î¶¯Ï¸½Ú¡£Ò£²âÊý¾ÝÏÔʾ£¬×îÐÂÑù±¾·ºÆðÓÚ2021Äê4Ô£¬Ãé×¼ÂíÀ´Î÷ÑÇ¡¢Ãɹš¢Ó¡¶ÈÄáÎ÷ÑǺͷÆÂɱöµÄ¹Ù·½×éÖ¯ºÍ¹«¹²½»Í¨¹«Ë¾µÈ¡£OwowaÕë¶ÔExchangeµÄOutlook Web Access(OWA)£¬Ö¼ÔڼǼÔÚOWAµÇÂ¼ÍøÒ³ÉÏÀֳɽøÐÐÉí·ÝÑéÖ¤µÄÓû§µÄƾ¾Ý¡£È»ºó£¬¹¥»÷Õß»áÏò¶ñÒâÄ£¿é·¢ËÍÃüÁîÀ´ÊÕ¼¯±»µÁÊý¾Ý£¬²¢ÔÚ±»Ñ¬È¾É豸ÉÏÖ´ÐÐPowerShell£¬½øÐÐÏÂÒ»²½¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/owowa-credential-stealer-and-remote-access/105219/
ÑÇÂíÑ·AWSÔÆ·þÎñÔÙ´Îå´»úÓ°ÏìTwitchºÍZoomµÈÓ¦ÓÃ
12ÔÂ15ÈÕ£¬ÑÇÂíÑ·AWSÔÆ·þÎñÔÙ´Îå´»ú¡£´ËÖжϿªÊ¼ÓÚ̫ƽÑóʱ¼äÉÏÎç7:43×óÓÒ£¬Ö÷ÒªÓ°ÏìÁËUS-WEST-1ºÍUS-WEST-2ÇøÓò£¬µ¼ÖÂTwitch¡¢Zoom¡¢PSN¡¢Xbox Live¡¢Doordash¡¢Quickbooks OnlineºÍHuluµÈ´óÁ¿Æ½Ì¨ºÍÍøÕ¾¹Ø±Õ¡£½ØÖÁ12ÔÂ15ÈÕ11:27 £¬ÑÇÂíÑ·³ÆInternetÁ¬½ÓµÄÎÊÌâÒѾ½â¾ö£¬·þÎñÔËÐÐÕý³£¡£12ÔÂ7ÈÕ£¬ÑÇÂíÑ·AWSÔÆ·þÎñå´»ú£¬Ó°ÏìÁËNetflix¡¢RokuºÍAmazon PrimeµÄµÈÓ¦Óá£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/technology/aws-down-again-outage-impacts-twitch-zoom-psn-hulu-others/