ÑÇÂíÑ·AWSÔÆ·þÎñÔÙ´Îå´»úÓ°ÏìTwitchºÍZoomµÈÓ¦ÓÃ

Ðû²¼Ê±¼ä 2021-12-16

AdobeÐû²¼12Ô¸üУ¬ÐÞ¸´¶à¸ö²úÆ·ÖÐÁè¼Ý60¸öÎó²î


AdobeÐû²¼12Ô¸üУ¬ÐÞ¸´¶à¸ö²úÆ·ÖÐÁè¼Ý60¸öÎó²î.png


12ÔÂ14ÈÕ£¬AdobeÐû²¼±¾ÔµÄÖܶþ²¹¶¡£¬ÐÞ¸´¶à¸ö²úÆ·ÖÐÁè¼Ý60¸öÎó²î¡£ÆäÖнÏΪÑÏÖØµÄÊÇExperience ManagerÖеÄXXEÎó²î£¨CVE-2021-40722£©£¬CVSSÆÀ·ÖΪ9.8£¬¿Éµ¼ÖÂí§Òâ´úÂëÖ´ÐС£±ðµÄ£¬»¹ÐÞ¸´ÁËPhotoshopÖпɵ¼ÖÂí§Òâ´úÂëÖ´ÐÐÔ½½çдÈëÎó²î£¨CVE-2021-43018£©»ººÍ³åÇøÒç³öÎó²î£¨CVE-2021-44184£©£¬ÒÔ¼°Media EncoderÖеÄÔ½½ç¶ÁÈ¡£¨CVE-2021-43757£©µÈ¶à¸öÎó²î¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/125640/security/adobe-60-vulnerabilities-multiple-products.html


ÒÁÀÊMERCURYÃé×¼Öж«ºÍÑÇÖ޵ĵçÐźÍIT·þÎñÌṩÉÌ


ÒÁÀÊMERCURYÃé×¼Öж«ºÍÑÇÖ޵ĵçÐźÍIT·þÎñÌṩÉÌ.png


SymantecÔÚ12ÔÂ14ÈÕ¹ûÕæÁËÕë¶ÔÖж«ºÍÑÇÖÞµçÐźÍIT·þÎñÌṩÉ̵Ĺ¥»÷£¬ÒÉËÆÀ´×ÔÒÁÀʺڿÍÍÅ»ïMERCURY£¨ÓÖÃûMuddyWater£©¡£¸ÃÔ˶¯×îÏÈÓÚ6¸öÔÂ֮ǰ£¬Ö÷ҪʹÓÃÒ×Êܹ¥»÷µÄExchange·þÎñÆ÷ÈëÇÖ×éÖ¯µÄÍøÂç¡£Ö»¹ÜÏÖÔÚѬȾǰÑÔÈÔδ֪£¬µ«Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öZIPÎļþ¡°Special discount program.zip¡±£¬ÆäÖаüÀ¨Ô¶³Ì×ÀÃæÈí¼þÓ¦ÓóÌÐòµÄ×°ÖóÌÐò£¬Òò´ËÍÆ¶Ï¹¥»÷ÕßʹÓõÄÊÇÓã²æÊ½´¹ÂÚÓʼþ¡£     


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/telecom-operators-targeted-in-recent-espionage-hacking-campaign/


Lookout·¢Ã÷Õë¶Ô½ü400¼Ò½ðÈÚ»ú¹¹·Ö·¢AnubisµÄÔ˶¯


Lookout·¢Ã÷Õë¶Ô½ü400¼Ò½ðÈÚ»ú¹¹·Ö·¢AnubisµÄÔ˶¯.png


12ÔÂ14ÈÕ£¬Lookout·¢Ã÷ÁËÕë¶Ô394¼Ò½ðÈÚ»ú¹¹·Ö·¢AndroidÒøÐÐľÂíAnubisµÄÔ˶¯¡£AnubisÓÚ2016ÄêÊ״ηºÆð£¬×÷Ϊ¿ªÔ´ÒøÐÐľÂíÔÚ¶íÂÞ˹ºÚ¿ÍÂÛ̳ÉÏÐû²¼¡£ÔÚ´Ë´ÎÔ˶¯ÖУ¬¹¥»÷Õßð³ä·¨¹úµçÐŹ«Ë¾Orange SAµÄÕÊ»§ÖÎÀíÓ¦Óã¬Ãé×¼´óÍ¨ÒøÐС¢¸»¹úÒøÐС¢ÃÀ¹úÒøÐк͵ÚÒ»×ÊÔ´µÈ½ðÈÚ»ú¹¹µÄ¿Í»§¡£Ñо¿Ö°Ô±³Æ£¬´Ë´Î¹¥»÷²»µ«½öÕë¶Ô´óÐÍÒøÐеĿͻ§£¬»¹Õë¶ÔÐéÄâÖ§¸¶Æ½Ì¨ºÍ¼ÓÃÜÇ®°ü£¬¸ÃÔ˶¯ÏÖÔÚÈÔ´¦ÓÚ²âÊÔºÍÓÅ»¯½×¶Î¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/400-banks-targeted-anubis-trojan/177038/


VulcanForgeÉù³ÆÆäÔâµ½¹¥»÷Ëðʧ¸ß´ï½ü1.4ÒÚÃÀÔª


VulcanForgeÉù³ÆÆäÔâµ½¹¥»÷Ëðʧ¸ß´ï½ü1.4ÒÚÃÀÔª.png


ÓÎÏ·¹«Ë¾VulcanForgeÔÚ±¾ÖÜÒ»³ÆÆäÔâµ½ÁËÍøÂç¹¥»÷£¬Ëðʧ¸ß´ï1.35ÒÚÃÀÔª¡£¸Ã¹«Ë¾³Æ£¬¹¥»÷ÕßÒѾ­»ñµÃÁË96¸öÇ®°üµÄ˽Կ£¬²¢ÇÔÈ¡ÁË450ÍòPYR£¨VulcanForgeµÄ´ú±Ò£¬¿ÉÔÚÆäÕû¸öÓÎϷϵͳÖÐʹÓã©¡£±ðµÄ£¬¹¥»÷Õß³öÊÛÁË´ó×ÚPYR£¬Ê¹PYRµÄ¼ÛǮϵø22%£¨´Ó31ÃÀÔª½µµ½24ÃÀÔª£©¡£ÕâÊǽüÊ®¼¸ÌìÄÚ±¬·¢µÄµÚÈýÆð¼ÓÃÜÇ®±ÒʧÔôÊÂÎñ£¬Èý´Î¹¥»÷Ôì³ÉµÄ×ÜËðʧ½ð¶îԼΪ4.04ÒÚÃÀÔª¡£


Ô­ÎÄÁ´½Ó£º

https://www.theblockcrypto.com/post/127270/96-private-keys-stolen-from-vulcan-forged-in-140-million-theft


KasperskyÅû¶ʹÓÃIISÄ£¿éOwowaµÄ¹¥»÷Ô˶¯Ï¸½Ú


KasperskyÅû¶ʹÓÃIISÄ£¿éOwowaµÄ¹¥»÷Ô˶¯Ï¸½Ú.png


12ÔÂ14ÈÕ£¬KasperskyÅû¶ÁËʹÓÃIIS Web·þÎñÆ÷Ä£¿éOwowaµÄ¹¥»÷Ô˶¯Ï¸½Ú¡£Ò£²âÊý¾ÝÏÔʾ£¬×îÐÂÑù±¾·ºÆðÓÚ2021Äê4Ô£¬Ãé×¼ÂíÀ´Î÷ÑÇ¡¢Ãɹš¢Ó¡¶ÈÄáÎ÷ÑǺͷÆÂɱöµÄ¹Ù·½×éÖ¯ºÍ¹«¹²½»Í¨¹«Ë¾µÈ¡£OwowaÕë¶ÔExchangeµÄOutlook Web Access(OWA)£¬Ö¼ÔڼͼÔÚOWAµÇÂ¼ÍøÒ³ÉÏÀֳɾÙÐÐÉí·ÝÑéÖ¤µÄÓû§µÄƾ֤¡£È»ºó£¬¹¥»÷Õß»áÏò¶ñÒâÄ£¿é·¢ËÍÏÂÁîÀ´ÍøÂç±»µÁÊý¾Ý£¬²¢ÔÚ±»Ñ¬È¾×°±¸ÉÏÖ´ÐÐPowerShell£¬¾ÙÐÐÏÂÒ»²½¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/owowa-credential-stealer-and-remote-access/105219/


ÑÇÂíÑ·AWSÔÆ·þÎñÔÙ´Îå´»úÓ°ÏìTwitchºÍZoomµÈÓ¦ÓÃ


ÑÇÂíÑ·AWSÔÆ·þÎñÔÙ´Îå´»úÓ°ÏìTwitchºÍZoomµÈÓ¦ÓÃ.png


12ÔÂ15ÈÕ£¬ÑÇÂíÑ·AWSÔÆ·þÎñÔÙ´Îå´»ú¡£ÆäÖÐÖ¹×îÏÈÓÚ̫ƽÑóʱ¼äÉÏÎç7:43×óÓÒ£¬Ö÷ÒªÓ°ÏìÁËUS-WEST-1ºÍUS-WEST-2ÇøÓò£¬µ¼ÖÂTwitch¡¢Zoom¡¢PSN¡¢Xbox Live¡¢Doordash¡¢Quickbooks OnlineºÍHuluµÈ´ó×ÚÆ½Ì¨ºÍÍøÕ¾¹Ø±Õ¡£×èÖ¹12ÔÂ15ÈÕ11:27 £¬ÑÇÂíÑ·³ÆInternetÅþÁ¬µÄÎÊÌâÒѾ­½â¾ö£¬·þÎñÔËÐÐÕý³£¡£12ÔÂ7ÈÕ£¬ÑÇÂíÑ·AWSÔÆ·þÎñå´»ú£¬Ó°ÏìÁËNetflix¡¢RokuºÍAmazon PrimeµÄµÈÓ¦Óá£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/technology/aws-down-again-outage-impacts-twitch-zoom-psn-hulu-others/