Ñо¿ÍŶӷ¢Ã÷Adobe Experience ManagerÖÐRCE 0day£»¶íÂÞ˹ºÚ¿ÍÒÑÔÚµ¤ÂóÖÐÑëÒøÐеÄÍøÂçDZÔÚÁè¼Ý°ëÄê
Ðû²¼Ê±¼ä 2021-06-301.Ñо¿ÍŶӷ¢Ã÷Adobe Experience ManagerÖÐRCE 0day

Ñо¿ÍŶӷ¢Ã÷Adobe Experience Manager(AEM)Öб£´æRCE 0day¡£AEMÊÇÊ¢ÐеÄÄÚÈÝÖÎÃ÷È·¾ö¼Æ»®£¬ÒѳÉΪÐí¶à×ÅÃûÆóÒµµÄÊ×Ñ¡ÄÚÈÝÖÎÀíϵͳ (CMS)£¬°üÀ¨ÍòÊ´│¡¢LinkedIn¡¢PlayStationºÍMcAfeeÔÚÄڵĶà¼Ò¹«Ë¾¶¼Êܵ½ÁËÓ°Ïì¡£¸ÃÎó²î±£´æÓÚÉúÔÚCRX /crx/packmgr/¶Ëµã£¬¹¥»÷Õß¿ÉÒÔÈÆ¹ýDispatcherÖеÄÉí·ÝÑéÖ¤À´»á¼ûCRX Package Manager£¬È»ºóÔÚAEMÖÐÉÏ´«¶ñÒâ°üÀ´»ñµÃ¶ÔÓ¦ÓóÌÐòµÄÍêÈ«¿ØÖÆ¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/zero-day-exploit-found-in-adobe/
2.¶íÂÞ˹ºÚ¿ÍÒÑÔÚµ¤ÂóÖÐÑëÒøÐеÄÍøÂçDZÔÚÁè¼Ý°ëÄê

¶íÂÞ˹ºÚ¿ÍÍÅ»ïNobeliumÈëÇÖÁ˵¤ÂóÖÐÑëÒøÐÐ(Danmarks Nationalbank)²¢Ö²ÈëÁ˶ñÒâÈí¼þ£¬ÔÚûÓб»·¢Ã÷µÄÇéÐÎÏ»á¼ûÍøÂçÁè¼Ý°ëÄê¡£¸ÃÔ˶¯ÊÇÈ¥ÄêSolarWinds¹©Ó¦Á´¹¥»÷µÄÒ»²¿·Ö£¬ÔÚVersion2ÒÔÐÅÏ¢×ÔÓÉΪÓÉ´Óµ¤ÂóÑëÐлñµÃ¹Ù·½Îļþºó²ÅÅû¶µÄ¡£¸Ã¶ñÒâÈí¼þÒѾÔÚµ¤ÂóÑëÐеÄÍøÂçÖб£´æÁ˳¤´ï7¸öÔÂÖ®¾Ã£¬Ö±µ½FireEyeÅû¶Á˴˴ι©Ó¦Á´¹¥»÷Ô˶¯ºó²Å±»·¢Ã÷¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/russian-hackers-had-months-long-access-to-denmarks-central-bank/
3.΢ÈíÐû²¼Çå¾²¸üУ¬ÐÞ¸´Edgeä¯ÀÀÆ÷ÖеĶà¸öÎó²î

΢ÈíÐû²¼Çå¾²¸üУ¬ÐÞ¸´ÁËEdgeä¯ÀÀÆ÷ÖеÄ2¸öÎó²î¡£ÆäÖнÏΪÑÏÖØµÄÊÇÇå¾²ÈÆ¹ýÎó²î£¨CVE-2021-34506£©£¬Ê¹ÓÃEdgeä¯ÀÀÆ÷ÄÚÖõÄMicrosoft Translator¹¦Ð§×Ô¶¯·ÒëÍøÒ³Ê±´¥·¢µÄ¿çÕ¾µã¾ç±¾(UXSS)Îó²îµ¼Öµģ¬¿ÉÒÔÓÃÀ´ÔÚÍøÕ¾ÉÏÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£Ñо¿Ö°Ô±³Æ¸ÃÎó²îµÄÖØ´óÐԺܵͣ¬¹¥»÷Õß¿ÉÒÔÔÚ²»ÐèÒªÈκÎȨÏÞµÄÇéÐÎÏÂʵÏÖ¡£´Ë´ÎÐÞ¸´µÄÁíÒ»¸öÎó²îÎªÌØÈ¨ÌáÉýÎó²î£¨CVE-2021-34475£©¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/06/microsoft-edge-bug-couldve-let-hackers.html
4.NVIDIAÐû²¼Çå¾²¸üУ¬ÐÞ¸´GeForceÖеÄÇå¾²Îó²î

NVIDIAÐû²¼Çå¾²¸üУ¬ÐÞ¸´ÁËGeForce ExperienceÖеÄÇå¾²Îó²î¡£¸ÃÎó²î±»¸ú×ÙΪCVE?2021?1073£¬CVSSÆÀ·ÖΪ8.3¡£¸Ã¹«Ë¾³ÆÎó²î»áµ¼ÖÂÓÕÆ¹¥»÷£¬ÊÇÓÉNVIDIA GeForce ExperienceÈí¼þÖжÔÌØÊâÃûÌÃÁ´½ÓµÄ²»µ±´¦Öóͷ£µ¼Öµġ£¹¥»÷Õß¿ÉÒÔ½¨ÉèÒ»¸öÌØÖÆµÄÁ´½Ó£¬Óû§ÔÚä¯ÀÀÆ÷Öжø·ÇÓ¦ÓóÌÐòÖз¿ªµÇÂ¼Ò³Ãæ£¬²¢ÊäÈëËûÃǵÄÃÜÂëºó±»Ð®ÖÆ¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/nvidia-high-severity-geforce-spoof-bug/167345/
5.AcadeME¹«Ë¾Ôâµ½¹¥»÷£¬Ð¹Â¶ÒÔÉ«ÁÐÔ¼28ÍòѧÉúÐÅÏ¢

AcadeMEÊÇÒÔÉ«ÁеÄÒ»¼Ò·þÎñÌṩÉÌ£¬ÎªÑ°ÕÒÊÂÇéµÄѧÉúÌṩ×ÊÖú¡£6ÔÂ20ÈÕ£¬ÃûΪDragonForceµÄÂíÀ´Î÷ÑǺڿÍÍÅ»ï³ÆÆäÈëÇÖÁËAcadeME£¬²¢ÇÔÈ¡ÁËÔ¼28Íò¸öѧÉúµÄСÎÒ˽¼ÒÐÅÏ¢£¬°üÀ¨µç×ÓÓʼþ¡¢ÃÜÂë¡¢ÐÕÃû¡¢µØµãÉõÖÁµç»°ºÅÂë¡£ËäÈ»AcadeME·ñ¶¨ÁËÕâһ˵·¨£¬µ«¹¥»÷Õß¹ûÕæÁË´úÂë½ØÍ¼¡¢·þÎñÆ÷µØµãÒÔ¼°Êý¾ÝµÄ±í¸ñ֤ʵ´Ë´Î¹¥»÷¡£±ðµÄ£¬¸ÃÍŻﻹÔÚÉÏÖÜÎå¶ÔÒÔÉ«ÁеĶà¼ÒÒøÐУ¨Bank of Israel¡¢Bank LeumiºÍMizrahi Tefahot£©ÌᳫÁËDDoS¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.jpost.com/israel-news/details-of-over-200000-students-leaked-in-cyberattack-672179
6.TesorionÑо¿Ö°Ô±ÍýÏë¹ûÕæÐÂÀÕË÷Èí¼þLorenz½âÃÜÆ÷

ºÉÀ¼ÍøÂçÇå¾²¹«Ë¾TesorionÍýÏë¹ûÕæÐÂÀÕË÷Èí¼þLorenzµÄ½âÃÜÆ÷¡£LorenzÀÕË÷Èí¼þÍÅ»ï×Ô2021Äê4ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬¹¥»÷ÁËÈ«ÇòµÄ¶à¸ö×éÖ¯£¬ÆäÊê½ðÒªÇóÏ൱¸ß£¬ÔÚ50ÍòÃÀÔªµ½70ÍòÃÀÔªÖ®¼ä¡£LorenzÔÚCBCģʽÏÂʹÓÃRSAºÍAES-128µÄ×éºÏÀ´¼ÓÃÜÎļþ£¬ÎªÃ¿¸öÎļþʹÓÃËæ»úÌìÉúµÄÃÜÂ룬ȻºóʹÓÃCryptDeriveKeyº¯Êýµ¼³ö¼ÓÃÜÃÜÔ¿¡£TesorionÆÊÎöÁ˸ÃÀÕË÷Èí¼þ²¢ÍýÏëͨ¹ýNoMoreRansomÐû²¼¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/119492/cyber-crime/lorenz-ransomware-free-decryptor.html


¾©¹«Íø°²±¸11010802024551ºÅ