Anker Eufy Homebase 2´æÔÚRCE©¶´CVE-2022-21806

Ðû²¼Ê±¼ä 2022-06-21
1¡¢Anker Eufy Homebase 2´æÔÚRCE©¶´CVE-2022-21806

      

¾ÝýÌå6ÔÂ16ÈÕ±¨µÀ£¬AnkerµÄÖÐÑëÖÇÄܼҾÓÉ豸ÖÐÐÄEufy Homebase 2´æÔÚ3¸öÄþ¾²Â©¶´ ¡£Homebase 2ÊÇËùÓÐAnker EufyÖÇÄܼҾÓÉ豸µÄÊÓÆµ´æ´¢ºÍÍøÂçÍø¹Ø£¬×÷ΪÕâЩÉ豸µÄÖÐÐÄÕ¾ÔËÐÐ ¡£ÆäÖÐ×îÑÏÖØµÄÊÇÒ»¸ö´úÂëÖ´ÐЩ¶´£¨CVE-2022-21806£¬CVSSÆÀ·Ö10)£¬ÊÇÄÚ²¿·þÎñÆ÷¹¦Ð§ÖеÄÊͷźóʹÓé¶´µ¼ÖµÄ£¬¿Éͨ¹ýÏòÄ¿±êÉ豸·¢ËÍÌØÖÆµÄÍøÂçÊý¾Ý°üÀ´´¥·¢ ¡£ÆäËüÁ½¸ö©¶´·Ö±ðΪ¾Ü¾ø·þÎñ©¶´£¨CVE-2022-26073£©ºÍÉí·ÝÑéÖ¤ÈÆ¹ý©¶´£¨CVE-2022-25989£© ¡£


https://www.bleepingcomputer.com/news/security/anker-eufy-smart-home-hubs-exposed-to-rce-attacks-by-critical-flaw/


2¡¢ÃÀ¹úFlagstarÒøÐÐ֪ͨÆä¿Í»§È¥ÄêÔâµ½¹¥»÷

      

¾Ý6ÔÂ20ÈÕ±¨µÀ£¬FlagstarÒøÐÐÕýÔÚ֪ͨ¿Í»§¹ØÓÚÊý¾Ýй¶Ê¼þ ¡£FlagstarÊÇλÓÚÃÜЪ¸ùÖݵĽðÈÚ·þÎñÌṩÉÌ£¬Ò²ÊÇÃÀ¹ú×î´óµÄÒøÐÐÖ®Ò»£¬×Ü×ʲúÁè¼Ý300ÒÚÃÀÔª ¡£Æ¾¾Ýй¶֪ͨ£¬FlagstarµÄÍøÂçÔÚ2021Äê12Ô±»ÈëÇÖ£¬¸ÃÒøÐÐÓÚ½ñÄê6ÔÂ2ÈÕ·¢ÏÖ ¡£¾­ÊӲ죬¹¥»÷Õß·ÃÎÊÁ˿ͻ§µÄÏêϸÐÅÏ¢£¬°üÂÞÐÕÃûºÍÉç»áÄþ¾²ºÅÂëµÈ ¡£´Ë´ÎʼþÓ°ÏìÁË1547169ÈË£¬Flagstar½«ÎªÊÜÓ°ÏìµÄ¸öÈËÌṩÁ½ÄêÃâ·ÑµÄÉí·Ý¼à¿ØºÍ± £»¤·þÎñ ¡£2021Äê1Ô£¬¸ÃÐÐÔøÔâµ½ClopÍÅ»ïµÄÀÕË÷¹¥»÷ ¡£


https://www.bleepingcomputer.com/news/security/flagstar-bank-discloses-data-breach-impacting-15-million-customers/


3¡¢Robert Half³ÆºÚ¿ÍÒѹ¥»÷Æä1000¶à¸ö¿Í»§µÄÕÊ»§

      

ýÌå6ÔÂ17Èճƣ¬ÈËÁ¦×ÊÔ´¹«Ë¾Robert HalfµÄ1000¶à¸ö¿Í»§µÄÕÊ»§Ôâµ½¹¥»÷ ¡£ÊÓ²ìÏÔʾ£¬¹¥»÷ÕßÔÚ4ÔÂ26ÈÕÖÁ5ÔÂ16ÈÕÆÚ¼äÈëÇÖÁËRobertHalf.comÍøÕ¾µÄÕÊ»§£¬¸ÃʼþÓÚ5ÔÂ31ÈÕ±»·¢ÏÖ£¬Ó°ÏìÁË1058¸öÈË ¡£´Ë´Îй¶Á˿ͻ§ÐÕÃû¡¢µØÖ·ºÍÉç»áÄþ¾²ºÅÂëµÈ¸öÈËÐÅÏ¢£¬ÒÔ¼°ÈËΪºÍ˰ÊյȲÆÕþÐÅÏ¢ ¡£¸Ã¹«Ë¾Ã»ÓйûÈ»¹ØÓÚ¹¥»÷µÄ¸ü¶àÐÅÏ¢£¬µ«Æ¾¾ÝÆäÃèÊö£¬ËƺõÉæ¼°Æ¾Ö¤Ìî³ä¹¥»÷ ¡£Robert Half½¨Òé¿Í»§¸ü¸ÄʹÓÃÁËÏàͬƾ¾ÝµÄÆäËüÕÊ»§£¬²¢½«ÎªÊÜÓ°ÏìµÄ¸öÈËÌṩÁ½ÄêµÄÉí·Ý¼à¿Ø·þÎñ ¡£


https://www.securityweek.com/staffing-firm-robert-half-says-hackers-targeted-over-1000-customer-accounts


4¡¢Lookout³Æ¼äµýÈí¼þHermitÓëÒâ´óÀûRCS LabÓйØ

      

6ÔÂ16ÈÕ£¬LookoutµÄ×îÐÂÑо¿½«¼äµýÈí¼þHermitºÍÒâ´óÀûRCS LabÁªÏµÆðÀ´ ¡£Ñо¿ÈËÔ±ÌåÏÖ£¬ËûÃÇÔÚ2022Äê4Ô¼ì²âµ½ÁËеÄÑù±¾ ¡£HermitÊÇÄ £¿é»¯¶ñÒâÈí¼þ£¬¾ßÓжàÖÖ¹¦Ð§£¬¿ÉÂ¼ÖÆÒôƵ¡¢²¦´òºÍÖØ¶¨Ïòµç»°ÒÔ¼°ÊÕ¼¯¶àÖÖÊý¾Ý ¡£Ëüͨ¹ýSMSÏûÏ¢½øÐÐÁ÷´«£¬Ã°³äÈýÐÇ¡¢VivoºÍOppoµÄÓ¦Óã¬Lookout½«¸ÃÆä¹é¾ÌÓÚÒâ´óÀûRCS Lab SpAºÍÒ»¼ÒµçÐÅ·þÎñÌṩÉÌTykelab Srl ¡£


https://thehackernews.com/2022/06/researchers-uncover-hermit-android.html


5¡¢CleafyÐû²¼¹ØÓÚAndroid¶ñÒâÈí¼þBRATAµÄ·ÖÎö³ÂËß


CleafyÔÚ6ÔÂ17ÈÕÐû²¼Á˹ØÓÚAndroid¶ñÒâÈí¼þBRATAµÄ·ÖÎö³ÂËß ¡£BRATAÓÚ2018Äêµ×Ê×´ÎÔÚ°ÍÎ÷±»·¢ÏÖ£¬ÓÚ2021Äê·ºÆðÔÚÅ·ÖÞ ¡£½üÆÚ£¬Ñо¿ÈËÔ±·¢ÏÖÔËÓªÍÅ»ïÔÙ´ÎΪ¸ÃAndroid¶ñÒâÈí¼þÌí¼ÓÁ˸ü¶à¹¦Ð§¶øÇÒ¸ïÐÂÁ˹¥»÷¼ÆÄ±£¬ÏÖÔÚ¸üÇкϸ߼¶Á¬ÐøÍþв(APT)¹¥»÷»î¶¯µÄģʽ ¡£Ð°汾µÄBRATA¸ü¾ßÕë¶ÔÐÔ£¬ËüÒ»´ÎÖ»Õë¶ÔÒ»¼Ò½ðÈÚ»ú¹¹£¬Ö»ÓÐÔÚÆä¹¥»÷»î¶¯±äµÃµÍЧʱ²Å»áתÏòÁíÒ»¸öÄ¿±ê ¡£´ËÍ⣬BRATAÌí¼ÓÁ˸ü¶àȨÏÞ£¬ÀýÈç·¢ËͺͽÓÊÕSMS£¬Õâ¿ÉÓÃÀ´ÇÔÈ¡ÒøÐз¢Ë͸ø¿Í»§µÄÁÙʱÃÜÂë ¡£


https://www.cleafy.com/cleafy-labs/brata-is-evolving-into-an-advanced-persistent-threat


6¡¢Trend MicroÐû²¼2022ÄêOTÄþ¾²Ì¬ÊƵÄÊÓ²ì³ÂËß

      

6ÔÂ15ÈÕ£¬Trend MicroÐû²¼ÁË2022ÄêOTÄþ¾²Ì¬ÊƵÄÊÓ²ì³ÂËß ¡£Ñо¿ÈËÔ±¶Ô2022ÄêÖÆÔì¡¢µçÁ¦ºÍʯÓͺÍÌìÈ»Æø¹«Ë¾µÄ¹¤ÒµÍøÂçÄþ¾²Ì¬ÊƽøÐÐÁËÊÓ²ì ¡£ÊÓ²ìÏÔʾ£¬ÔÚ¹ýÈ¥12¸öÔÂÖУ¬Ê®·ÖÖ®¾ÅµÄ×éÖ¯µÄÉú²ú»òÄÜÔ´¹©Ó¦¶¼Êܵ½¹¥»÷µÄÓ°Ïì ¡£¹ØÓÚϵͳÖжϵÄÁ¬ÐøÊ±¼äºÍ¾­¼ÃËðʧ£¬56%µÄÊÜ·ÃÕßÌåÏÖÖжϻáÁ¬ÐøËÄÌì»ò¸ü³¤Ê±¼ä £»È¥ÄêµÄƽ¾ù¾­¼ÃËðʧԼΪ280ÍòÃÀÔª £»¾­¼ÃËðʧ³ýÁ˰üÂÞÀÕË÷¹¥»÷µÄÊê½ðÖ®Í⣬»¹Óлָ´ÏµÍ³¡¢µÖÓù¹¥»÷ºÍÕÐÆ¸ÌرðÔ±¹¤µÄÓöÈ ¡£


https://www.trendmicro.com/en_us/research/22/f/state-of-ot-security-2022.html