AppleÒÑÐÞ¸´ÆäAWDLÖпÉÈÆ¹ýÆøÏ¶ÏµÍ³ÇÔÊØÐÅÏ¢µÄÎó²î£»Ñо¿Ö°Ô±·¢Ã÷ʹÓÃExchangeÖÐÎó²îProxyShellµÄ¹¥»÷Ô˶¯
Ðû²¼Ê±¼ä 2021-08-09
AppleµÄApple Wireless Direct Link(AWDL)Öб£´æÒ»¸öÎó²î£¬¿ÉÓÃÀ´ÈƹýÆøÏ¶ÏµÍ³²¢ÇÔÈ¡Êý¾Ý¡£Õâ¸öÎó²îµÄÊÖÒÕÅä¾°ÓеãÖØ´ó£¬¼òÑÔÖ®£¬¾ÍÊÇʹÓÃICMPv6ºÍIPv6Êý¾Ý°ü´ÓÄ¿µÄϵͳ»ñÈ¡Êý¾Ý£¬ÔÚÖÜΧ֧³ÖAWDLµÄApple×°±¸ÉÏ·´µ¯Êý¾Ý°ü£¬²¢½«ÇÔÈ¡µÄÎļþ·¢Ë͵½ÁíÒ»¸öÓÐIPv6µØµãµÄ×°±¸¡£Çå¾²¹«Ë¾FnishÑо¿Ö°Ô±ÓÚÉÏÖÜÊ״ιûÕæÁ˸ÃÎó²î£¬¶øApple¹«Ë¾ÔçÔÚ½ñÄê4Ô£¬¾ÍÔÚiOS 14.5¡¢iPadOS 14.5¡¢watchOS 7.4ºÍBig Sur 11.3µÄÇå¾²¸üÐÂÖÐÇÄÇĵØÐÞ¸´ÁËÕâÒ»Îó²î¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/apple-fixed-awdl-bug-that-could-be-used-to-escape-air-gapped-networks/
2.Ñо¿Ö°Ô±·¢Ã÷ʹÓÃExchangeÖÐÎó²îProxyShellµÄ¹¥»÷Ô˶¯

2021 Black Hat´ó»áÉÏͳ³ÆÎªProxyShellµÄ3¸öÎó²îµÄϸ½Ú¹ûÕæºó£¬Ñо¿Ö°Ô±·¢Ã÷ÁËÆð¾¢Ê¹ÓøÃÎó²îµÄÔ˶¯¡£ProxyShell°üÀ¨ACLÈÆ¹ýÎó²î£¨CVE-2021-34473£©¡¢ Exchange PowerShellºó¶ËµÄÌáȨÎó²î£¨CVE-2021-34523£©ºÍí§ÒâÎļþдÈëµ¼ÖµÄRCEÎó²î£¨CVE-2021-31207£©¡£ÕâЩÎó²î¿ÉÒÔͨ¹ýIISÖеĶ˿Ú443ÉÏÔËÐеÄMicrosoft Exchange¿Í»§¶Ë»á¼û·þÎñ(CAS)Ô¶³ÌʹÓã¬ÍŽáʹÓÿɾÙÐÐδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´ÐС£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-servers-scanned-for-proxyshell-vulnerability-patch-now/
3.Ñо¿ÍŶӷ¢Ã÷ʹÓÃArcadyan¹Ì¼þÖÐÎó²î×°ÖÃMiraiµÄÔ˶¯

Õ°²©ÍøÂçµÄÑо¿ÍŶÓÔÚ½üÆÚ·¢Ã÷ÁËʹÓÃArcadyan¹Ì¼þÖÐÎó²îµÄ¹¥»÷Ô˶¯¡£¸ÃÎó²îÊÇ·¾¶±éÀúÎó²î£¬×·×ÙΪCVE-2021-20090£¬ÆÀ·ÖΪ9.9¡£±£´æÓÚʹÓÃArcadyan¹Ì¼þµÄ·ÓÉÆ÷µÄweb½çÃæÉÏ£¬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÈÆ¹ýÉí·ÝÑéÖ¤£¬Ó°ÏìÁËÊýÊ®ÖÖÐͺŵÄÊý°ÙÍǫ̀·ÓÉÆ÷¡£×ÔÉÏÖÜËÄÒÔÀ´£¬Ñо¿Ö°Ô±ÔÚÒ°·¢Ã÷ÁËʹÓôËÎó²îµÄ¹¥»÷Ô˶¯,Ö¼ÔÚ½ÓÊÜÄ¿µÄ×°±¸²¢×°Öý©Ê¬ÍøÂçMiraiµÄpayload¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/actively-exploited-bug-bypasses-authentication-on-millions-of-routers/
4.SeniorAdvisor´æ´¢Í°ÉèÖùýʧй¶Áè¼Ý300Íò¿Í»§ÐÅÏ¢

WizCaseÑо¿ÍŶӷ¢Ã÷Á˸߼¶Õչ˻¤Ê¿Éó²éÍøÕ¾SeniorAdvisorµÄAmazon S3´æ´¢Í°ÉèÖùýʧ£¬Ð¹Â¶Áè¼Ý300Íò¿Í»§ÐÅÏ¢¡£¸ÃÍøÕ¾ÓÃÀ´Õ¹Ê¾ ÃÀ¹úºÍ¼ÓÄôóµÄÍíÄêÕչ˻¤Ê¿·þÎñÏûºÄÕߵįÀ·ÖºÍ̸ÂÛ£¬´Ë´Î×ܹ²Ð¹Â¶ÁËÁè¼Ý100Íò¸öÎļþºÍ182GBµÄÊý¾Ý£¬°üÀ¨ÐÕÃû¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂëºÍÁªÏµÈÕÆÚµÈ£¬²¢ÇÒ¶¼Î´¾ÓɼÓÃÜ£¬±ðµÄÉÐÓÐԼĪ2000ÌõÒѱ»É¾³ýµÄ̸ÂÛ¡£WizCase³Æ´Ë´Îй¶ԴÖ÷ÒªÊÇ´¦ÓÚ»ò¿¿½üÍËÐݵÄÍíÄêÈË£¬ÎªÌض¨µÄÈõÊÆÈºÌ壬¸üÈÝÒ×Ôâµ½Õ©ÆÔ˶¯µÄ¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/senior-citizens-personal-data/
5.Group-IB·¢Ã÷ºÚ¿ÍÔÚ¶à¸ö°µÍø¹ûÕæÁè¼Ý100ÍòÌõÖ§¸¶¼Í¼

Group-IBÔÚ¶à¸öÔÚ¶à¸ö°µÍøÉϼì²âµ½Ò»¸öÌØÊâÌû×Ó£¬ÃûΪAW_cardsµÄºÚ¿Í¹ûÕæÁËÁè¼Ý100ÍòÌõÖ§¸¶¼Í¼¡£ÕâЩÊý¾Ý°üÀ¨ÁËÀ´×Ô100¶à¸ö¹ú¼ÒºÍµØÇøµÄ1000¶à¼ÒÒøÐеÄÒøÐп¨ÏêϸÐÅÏ¢£¬°üÀ¨Ó¡¶È¡¢Ä«Î÷¸ç¡¢ÃÀ¹ú¡¢°Ä´óÀûÑÇ¡¢°ÍÎ÷µÈ¡£ÓÉÓÚºÜÉÙÓз¸·¨·Ö×ÓÃâ·ÑÌá¹©ÔÆÔÆ¶àµÄÒøÐп¨ÐÅÏ¢£¬ÕâÒýÆðÁËGroup-IBÑо¿Ö°Ô±µÄÐËȤ¡£ÆÊÎö·¢Ã÷ÕâÊÇÒ»¸ö´óµ¨µÄ¹ã¸æ£¬Ö¼ÔÚÍÆ¹ãÐÂÆ½Ì¨All World Cards¡£ÕâЩÊý¾Ý°üÀ¨¿¨ºÅ¡¢×èÖ¹ÈÕÆÚ¡¢CVV/CVC´úÂë¡¢³Ö¿¨ÈËÐÕÃû¡¢¹ú¼Ò¡¢×´Ì¬¡¢¶¼»á¡¢µØµã¡¢ÓÊÕþ±àÂëºÍµç»°µÈ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/120941/cyber-crime/1m-compromised-cards.html
6.RansomEXXÍÅ»ïÉù³ÆÒÑÇÔÈ¡ÉÝ³ÞÆ·ÅÆZegnaÁè¼Ý20GBÊý¾Ý

ÀÕË÷ÍÅ»ïRansomEXX½üÆÚÉù³ÆÒÑÇÔÈ¡ÉÝ³ÞÆ·ÅÆZegnaÁè¼Ý20GBÊý¾Ý¡£ZegnaÊÇÒâ´óÀû×îÖøÃûµÄÉݳÞÊ±×°Æ·ÅÆÖ®Ò»£¬ÊÇÈ«ÇòÊÕÈë×î¸ßµÄÄÐ×°Æ·ÅÆ¡£RansomEXX³ÆÒѴӸù«Ë¾ÇÔÈ¡ÁË20.74GBµÄÊý¾Ý£¬²¢Ðû²¼ÁË43¸öÎļþ£¨42¸ö500MBµÄÎļþºÍ1¸ö239.54MBµÄÎļþ£©×÷ΪÑù±¾¡£½üÆÚ£¬RansomEXXÍÅ»ïÔøÑ¬È¾ÁËÒâ´óÀûÀÆë°Â´óÇøµÄϵͳ£¬²¢¹¥»÷ÁËÖйų́ÍåµÄÅÌËã»úÓ²¼þÖÆÔìÉ̼¼¼Î£¨GIGABYTE£©¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/120898/data-breach/ransomexx-ransomware-zegna.html


¾©¹«Íø°²±¸11010802024551ºÅ