F5Çå¾²¸üУ¬ÐÞ¸´BIG-IPºÍBIG-IQÖжà¸öRCEÎó²î£»ÔÆÌṩÉÌOVHÊý¾ÝÖÐÐĵÄij»ú·¿×Ż𣬵¼Ö·þÎñÔÝʱÖÐÖ¹
Ðû²¼Ê±¼ä 2021-03-111.F5Çå¾²¸üУ¬ÐÞ¸´BIG-IPºÍBIG-IQÖжà¸öRCEÎó²î

F5 NetworksÐû²¼Çå¾²¸üУ¬ÐÞ¸´Ó°ÏìÁËBIG-IPºÍBIG-IQÖеĶà¸öÎó²î£¬ÆäÖаüÀ¨4¸öÑÏÖØµÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©Îó²î¡£´Ë´ÎÐÞ¸´µÄRCE»®·ÖΪiControl RESTÖеÄRCE£¨CVE-2021-22986£¬CVSSÆÀ·ÖΪ9.8£©¡¢TMUIÖеÄRCE£¨CVE-2021-22987£¬CVSSÆÀ·ÖΪ9.9£©¡¢TMMÖпɵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐеĻº³åÇøÒç³öÎó²î£¨CVE-2021-22991£¬CVSSÆÀ·ÖΪ9.0£©ºÍAdvanced WAF/ASMÖпɵ¼ÖÂDoS¹¥»÷ºÍRCEµÄ»º³åÇøÒç³öÎó²î£¨CVE-2021-22992 £¬CVSSÆÀ·ÖΪ9.0£©¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/f5-urges-customers-to-patch-critical-big-ip-pre-auth-rce-bug/
2.AdobeÐû²¼Çå¾²¸üУ¬ÐÞ¸´¶à¿î²úÆ·ÖеÄ8¸öÎó²î

AdobeÐû²¼Çå¾²¸üУ¬ÐÞ¸´Framemaker¡¢Creative CloudºÍConnectÖеÄ8¸öÎó²î¡£´Ë´ÎÐÞ¸´µÄ×îΪÑÏÖØµÄÎó²îΪFramemakerÖеĿɵ¼ÖÂí§Òâ´úÂëÖ´ÐеÄÔ½½ç¶ÁÈ¡Îó²î£¨CVE-2021-21056£©ÒÔ¼°ConnectÖеÄí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-21085£©¡£±ðµÄ£¬»¹ÐÞ¸´ÁËCreative CloudÖÐí§ÒâÎļþÁýÕÖÎó²î£¨CVE-2021-21068£©¡¢OSÏÂÁî×¢ÈëÇå¾²Îó²î£¨CVE-2021-21078£©ºÍ²»×¼È·µÄÊäÈëÑéÖ¤µ¼ÖµÄÌáȨÎó²î£¨CVE-2021-21069£©£¬ÒÔ¼°ConnectÖеÄ3¸öXSSÎó²î£¨CVE-2021-21079¡¢CVE-2021-21080ºÍCVE-2021-21081£©¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/adobe-releases-batch-of-security-fixes-for-framemaker-creative-cloud-connect/
3.Ñо¿ÍŶӷ¢Ã÷½©Ê¬ÍøÂçz0MinerÍÚ¿óµÄ¹¥»÷Ô˶¯

Ñо¿ÍŶӷ¢Ã÷½©Ê¬ÍøÂçz0MinerÊÔͼ¿ØÖÆJenkinsºÍElasticSearch·þÎñÆ÷À´ÍÚ¾òMonero£¨XMR£©¼ÓÃÜÇ®±ÒµÄ¹¥»÷Ô˶¯¡£z0MinerÊÇÈ¥ÄêÔÚ11Ô±»·¢Ã÷µÄÒ»ÖÖÍÚ¿ó¶ñÒâÈí¼þ£¬ÆäʹÓÃWeblogicÎó²îѬȾÁËÊýǧ̨·þÎñÆ÷¡£¶ø´Ë´ÎÔ˶¯Ê¹ÓÃÁËElasticSearchÖеÄRCEÎó²î£¨CVE-2015-1427£©ºÍÓ°ÏìÁËJenkins·þÎñÆ÷µÄÒ»¸ö¹ÅÀϵÄRCE¡£ÔÚÈëÇÖ·þÎñÆ÷ºó£¬¸Ã¶ñÒâÈí¼þ½«ÏÈÏÂÔØ¶ñÒâshell¾ç±¾£¬È»ºóѰÕÒ²¢É¾³ýÒÔǰװÖõÄÍÚ¿ó¾ç±¾¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/z0miner-botnet-hunts-for-unpatched-elasticsearch-jenkins-servers/
4.Î÷°àÑÀÀ͹¤¾ÖÔâÀÕË÷¹¥»÷£¬ÆäÔ±¹¤±»ÆÈÓÃÖ½±Ê°ì¹«

Î÷°àÑÀ¹¤»áÓÚ±¾ÖܶþÌåÏÖÎ÷°àÑÀ¹ú¼Ò¹«¹²¾ÍÒµ·þÎñ¾Ö£¨SEPE£©Ôâµ½ÁËRyukÀÕË÷¹¥»÷£¬ÏµÍ³ÒѾ¹Ø±Õ¡£´Ë´Î¹¥»÷µ¼Ö¸ûú¹¹ÔÚÌìÏÂ700¶à¼Ò·þÎñ´¦Êܵ½Ó°Ï죬ÆäÔ±¹¤±»ÆÈʹÓÃÖ½±Ê°ì¹«¡£¾ÝϤ£¬¸ÃÀÕË÷Èí¼þÒ²ÒѾÀ©É¢µ½SEPEµÄ°ì¹«ÊÒÖ®Í⣬ӰÏìÁËÔ¶³ÌÊÂÇéÖ°Ô±µÄÌõ¼Ç±¾µçÄÔ¡£¹¤»á³ÆSEPEµÄITϵͳÒѾÀÏ»¯£¬¶ø¸Ã»ú¹¹²¢Î´ÎªÆäÉý¼¶¡£SEPE×ܼà֤ʵ£¬ÆäϵͳÒѱ»Ryuk¼ÓÃÜ£¬µ«Ã»ÓÐÊý¾Ýй¶£¬Ê§Òµ¾ÈÔ®½ðµÄ·¢·ÅҲûÊܵ½Ó°Ïì¡£
ÔÎÄÁ´½Ó£º
https://www.cyberscoop.com/spain-ransomware-employment-agency-sepe/
5.ÔÆÌṩÉÌOVHÊý¾ÝÖÐÐĵÄij»ú·¿×Ż𣬵¼Ö·þÎñÔÝʱÖÐÖ¹

λÓÚ·¨¹úË¹ÌØÀ˹±¤µÄÔÆÌṩÉ̵ÄOVHÊý¾ÝÖÐÐÄׯ𣬵¼Ö·þÎñÔÝʱÖÐÖ¹¡£OVHÊÇÅ·ÖÞ×î´óµÄÍйܷþÎñÌṩÉÌ£¬Ò²ÊÇÌìϵÚÈý´óÍйܷþÎñÌṩÉÌ£¬¿ÉÌṩVPS¡¢×¨Ó÷þÎñÆ÷ºÍÆäËûWeb·þÎñ¡£3ÔÂ10ÈÕ£¬OVHÊý¾ÝÖÐÐÄSBG2±¬·¢ÁË»ðÔÖ£¬Ïû·ÀÖ°Ô±Á¬Ã¦¸Ïµ½ÏÖ³¡µ«ÎÞ·¨¿ØÖÆ»ðÊÆ¡£Òò´ËÕû¸öÕ¾µãÒѱ»¸ôÀ룬ÕâÒ²Ó°ÏìÁËSBG1¡¢SBG2¡¢SBG3ºÍSBG4ÉϵÄËùÓзþÎñ¡£ÊÓÆµÓÎÏ·¹«Ë¾Rust³Æ£¬´ËÊÂÎñÒѵ¼ÖÂÆäËùÓÐÊý¾Ýɥʧ£¬ÎÞ·¨»Ö¸´¡£OVHÕýÔÚÆð¾¢»Ö¸´Æä·þÎñ£¬²¢½¨Òé¿Í»§Ó¦Á¬Ã¦¼¤»îÔÖÄѱ¸·ÝÍýÏë¡£
ÔÎÄÁ´½Ó£º
https://www.theregister.com/2021/03/10/ovh_strasbourg_fire/
6.iPhoneÓ¦ÓÃAcr call recorderй¶13ÍòÌõͨ»°¼Í¼

iPhoneµÄÓ¦ÓÃAcr call recorder±£´æÎó²î£¬¿Éй¶13ÍòÌõͨ»°¼Í¼¡£¸ÃÓ¦ÓÃÔÚApp StoreÖÐÓµÓÐÁè¼ÝÒ»°ÙÍòµÄÏÂÔØÁ¿£¬±»ÁÐΪiPhone¶¥¼¶Í¨»°¼Í¼ӦÓÃÖ®Ò»¡£PingSafe AIµÄÑо¿Ö°Ô±ÔÚÑÇÂíÑ·ÉÏ·¢Ã÷Á˸ÃÓ¦ÓÃԼΪ300 GBµÄ´æ´¢Í°£¬°üÀ¨ÁË130000¶à¸ö¼Í¼¡£¹¥»÷ÕßʹÓÃBurp»òZapÖ®ÀàµÄWebÊðÀí¹¤¾ß£¬¿ÉÔÚÇëÇóÖвåÈëÓû§µÄµç»°ºÅÂë¡£ÓÉÓÚÏìÓ¦µÄAPIûÓÐÈκÎÉí·ÝÑéÖ¤£¬ÒÔÊǽ«·µ»ØÓëÇëÇóÖеĵ绰ºÅÂëÏà¹ØµÄÊý¾Ý£¬°üÀ¨Óû§µÄÕû¸öͨ»°¼Í¼¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/iphone-call-recorder-bug-gave-acess-to-other-peoples-conversations/


¾©¹«Íø°²±¸11010802024551ºÅ