AppleÐû²¼Çå¾²¸üУ¬ÐÞ¸´3¸öÒѱ»ÔÚҰʹÓõÄ0day£»Ñо¿Ö°Ô±³ÆWindows IIS·þÎñÆ÷ÖеÄÎó²î¿ÉÓ°ÏìWinRM
Ðû²¼Ê±¼ä 2021-05-251.AppleÐû²¼Çå¾²¸üУ¬ÐÞ¸´3¸öÒѱ»ÔÚҰʹÓõÄ0day

Æ»¹ûÒѾÐû²¼ÁËÇå¾²¸üУ¬ÐÞ²¹3¸öÒѱ»ÔÚҰʹÓõÄmacOSºÍtvOS 0day¡£ÆäÖеÄÁ½¸öÊÇÄÚ´æËð»µÎó²î£¨CVE-2021-30663ºÍCVE-2021-30665£©£¬Ó°ÏìÁËApple TV 4KºÍApple TV HD×°±¸¡£µÚÈý¸öÊÇTCC¿ò¼ÜÖеÄÌáȨÎó²î£¬Ó°ÏìÁËmacOS Big Sur×°±¸£¬ÏÖÒѱ»XCSSET¶ñÒâÈí¼þÓÃÀ´ÈƹýmacOSÒþ˽±£»¤¡£±¾Ô³õ£¬Apple»¹ÐÞ¸´ÁËWebkitÒýÇæÖеÄÁ½¸öiOS 0day¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/apple-fixes-three-zero-days-one-abused-by-xcsset-macos-malware/
2.ÃÀ¹úÔËͨÒò·¢ËÍ400¶àÍòÀ¬»øÓʼþ±»Ó¢¹ú·£¿î9ÍòÓ¢°÷

ÃÀ¹úÔËͨ£¨Amex£©ÒòÔÚÒ»ÄêÄÚÏò¿Í»§·¢ËÍÁè¼Ý400Íò·âÀ¬»øÓʼþ£¬±»Ó¢¹úÊý¾Ýî¿Ïµ»ú¹¹·£¿î90000Ó¢°÷¡£Ó¢¹úICO³Æ£¬ÔÚ2018Äê6ÔÂ1ÈÕÖÁ2019Äê5ÔÂ21ÈÕ£¬Amex·¢ËÍÁË4098841·âÖ¼ÔÚΪAmex´øÀ´¾¼ÃÀûÒæµÄÓªÏúµç×ÓÓʼþ¡£Òòδ¾ÔÞ³ÉÏòÊÕ¼þÈË·¢ËÍÓªÏúÓʼþ£¬AmexÎ¥·´ÁË2003Äê¡¶Òþ˽ºÍµç×ÓͨѶÌõÀý¡·£¨PECR£©µÚ22Ìõ¡£Æ¾Ö¤¸ÃÌõ¿î¿É¶ÔÆä´¦ÒÔ×î¸ß50ÍòÓ¢°÷µÄ·£¿î£¬µ«ÒòÆäûÓоÓÐÄÎ¥·´PECR£¬½ö·£¿î9Íò£¬AmexÐëÔÚ6ÔÂ17ÈÕ֮ǰ֧¸¶Õâ±Ê·£¿î¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/amex-fined-90-000-for-sending-4-million-spam-emails-in-a-year/
3.΢ÈíÎ´Ðø¶©ExchangeµÄSSLÖ¤Ê飬ChromeÌáÐÑեȡ»á¼û

ÃÀ¹ú¶«²¿±ê׼ʱ¼ä2021Äê5ÔÂ23ÈÕÉÏÎç8µã×îÏÈ£¬Óû§·´Ó¦ÎÞ·¨µÇ¼ExchangeµÄÍøÕ¾admin.exchange.microsoft.com¡£ÕâÊÇÓÉÓÚ¸ÃÍøÕ¾µÄSSLÖ¤ÊéÒÑÓâÆÚ¶øMicrosoftÒÅÍüÐø¶©µ¼Öµġ£ÎªÁËÇå¾²Æð¼û£¬¹È¸èä¯ÀÀÆ÷ÍêȫեȡÁË»á¼û¸ÃÍøÕ¾£¬¶øFirefoxÔòÖÒÑÔÁ´½Ó²»Çå¾²¡£Microsoft³ÆÓû§¿ÉÒÔÔÝʱʹÓÃhttps://outlook.office.com/ecp/Á´½ÓÀ´»á¼û¸ÃÍøÕ¾£¬²¢ÒÑÓÚ5ÔÂ24ÈÕ½â¾ö¸ÃÎÊÌâ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-admin-portal-blocked-by-expired-ssl-certificate/
4.Ñо¿Ö°Ô±³ÆWindows IIS·þÎñÆ÷ÖеÄÎó²î¿ÉÓ°ÏìWinRM

Ñо¿Ö°Ô±im DeVries³ÆWindows IIS·þÎñÆ÷ÖеÄÎó²î¿ÉÓ°ÏìWinRM¡£¸ÃÎó²îÊÇWindows IIS·þÎñÆ÷ʹÓõÄHTTPÐÒéÕ»£¨http.sys£©ÖеÄÔ¶³ÌÖ´ÐдúÂëÎó²î£¬±»×·×ÙΪCVE-2021-31166£¬ÒÑͨ¹ýMicrosoftÐû²¼µÄ5Ô·ÝÇå¾²¸üÐÂÐÞ¸´¡£ÉÏÖÜÄ©£¬Axel SouchetÐû²¼Á˸ÃÎó²îµÄPoC£¬¿ÉʹÓÃÌØÖÆµÄÊý¾Ý°üµ¼ÖÂÀ¶ÆÁËÀ»ú¡£¿ÉÊÇ£¬Jim DeVries·¢Ã÷Ëü»¹»áÓ°ÏìÔËÐÐÁËWinRM·þÎñ£¨WindowsÔ¶³ÌÖÎÀí£©µÄWindows 10ϵͳºÍ·þÎñÆ÷¡£Will Dormann³Æ£¬ÓÐÁè¼Ý200Íò¸öWinRM·þÎñ̻¶µÄWindowsϵͳ¿ÉÒÔͨ¹ýInternet»á¼û¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/118189/security/cve-2021-31166-windows-http-flaw.html
5.ProofpointÐû²¼2021ÄêQ2ÆóÒµµç×ÓÓʼþÇå¾²µÄ±¨¸æ

ProofpointÐû²¼ÁË2021ÄêQ2ÆóÒµµç×ÓÓʼþÇå¾²µÄ±¨¸æ¡£¸Ã±¨¸æ»ùÓÚ25¸ö±ê×¼¶Ô15¸öÆóÒµµç×ÓÓʼþ·þÎñÌṩÉ̾ÙÐÐÁËÆÀ¹À£¬Éæ¼°Èý¸ö·½Ã棺Ŀ½ñ²úÆ·¡¢Õ½ÂÔºÍÊг¡Õ¼ÓÐÂÊ¡£ÔÚÆÀ¹ÀµÄ¹©Ó¦ÉÌÖУ¬ProofpointÊǽöÓеÄÎå¸öÁìÏÈÕßÖ®Ò»¡£±¨¸æÖ¸³ö£¬×î¼ÑµÄµç×ÓÓʼþÇå¾²½â¾ö¼Æ»®½«¿Í»§ÇéÐÎÓëEDR¡¢WebÄÚÈÝÇå¾²ÐÔ£¨°üÀ¨ä¯ÀÀÆ÷¸ôÀ룩ÒÔ¼°Çå¾²ÒâʶºÍÅàѵ£¨SA£¦T£©µÈ½â¾ö¼Æ»®¼¯³ÉÔÚÒ»Æð¡£
ÔÎÄÁ´½Ó£º
https://www.proofpoint.com/us/resources/analyst-reports/forrester-wave-report-enterprise-email-security
6.LookoutÐû²¼ÓйؽðÈÚ·þÎñµÄÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ

LookoutÐû²¼ÁËÓйؽðÈÚ·þÎñ2019ÄêÖÁ2020ÄêÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£LookoutÊý¾ÝÏÔʾ£¬½ðÈÚ×é֯ÿ¼¾¶Èƽ¾ùÔâÊܵÄÍøÂç´¹ÂÚ¹¥»÷ÔöÌíÁË125£¥£¬¶ñÒâÓ¦ÓóÌÐòÔöÌíÁË400£¥£¬Òƶ¯×°±¸ÖÎÀí£¨MDM£©Ê¹ÓÃÂÊÌá¸ßÁË50£¥£¬ÏÕЩ50£¥µÄ´¹ÂÚ¹¥»÷¶¼ÊÔͼÇÔÈ¡¹«Ë¾µÇ¼ƾ֤£¬½ü20£¥µÄÒÆ¶¯ÒøÐпͻ§¶Ë×°ÓÐľÂíÓ¦Ó᣸ñ¨¸æ½¨Òé½ðÈÚ»ú¹¹ÐèÒª½ÓÄÉÏÖ´úÇå¾²ÊÖÒÕºÍÕ½ÂÔ£¬À´°ü¹ÜÔ±¹¤ºÍ¿Í»§³£ÓÃ×°±¸Éϼá³ÖÇå¾²ÐÔ¡¢¾ºÕùÁ¦ºÍÏà¹ØÐÔ¡£
ÔÎÄÁ´½Ó£º
https://www.lookout.com/info/financial-services-threat-report-lp


¾©¹«Íø°²±¸11010802024551ºÅ