ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ27ÖÜ
°ä²¼¹¦·ò 2021-07-05> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2021Äê06ÔÂ28ÈÕÖÁ07ÔÂ04ÈÕ¹²ÊÕ¼°²È«·ì϶62¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAcrobat Reader DC CVE-2021-28562ÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶£»£»HelpcomÔ¶³ÌºÅÁîÖ´Ðзì϶£»£»helpUS ShellExecutionExA´úÂëÖ´Ðзì϶£»£»Huawei AnyOffice V200R006C10·´ÐòÁл¯´úÂëÖ´Ðзì϶£»£»MVISION EDR 'execute reaction'Ô¶³ÌºÅÁîÖ´Ðзì϶¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ΢Èí³ÆÆäÔâµ½SolarWinds¹¥»÷±³ºóÍÅ»ïNobeliumµÄÈëÇÖ£»£»GitGuardian°ä²¼2021ÄêGitHubÉÏÊý¾Ýй¶µÄ·ÖÎö»ã±¨£»£»ºÚ¿ÍÔÚRaidForumsÏúÊÛ7ÒÚ¶àÌõLinkedInÓû§µÄ¼Í¼£»£»ÃÀ¹úFINRAÖÒ¸æ¼Ù×°³ÉFINRA SupportµÄ´¹µö¹¥»÷»î¶¯£»£»Î¢Èí°ä²¼°²È«¸üУ¬ÐÞ¸´Edgeä¯ÀÀÆ÷ÖеĶà¸ö·ì϶¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£
> ÖØÒª°²È«·ì϶Áбí
1.Acrobat Reader DC CVE-2021-28562ÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶
Acrobat Reader DC´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£
https://helpx.adobe.com/security/products/acrobat/apsb21-29.html
2.HelpcomÔ¶³ÌºÅÁîÖ´Ðзì϶
Helpcom´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£
https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36095
3.helpUS ShellExecutionExA´úÂëÖ´Ðзì϶
helpUS ShellExecutionExA´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£
https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36088
4.Huawei AnyOffice V200R006C10·´ÐòÁл¯´úÂëÖ´Ðзì϶
Huawei AnyOffice´æÔÚ·´ÐòÁл¯·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210619-01-injection-en
5.MVISION EDR 'execute reaction'Ô¶³ÌºÅÁîÖ´Ðзì϶
MVISION EDR 'execute reaction'´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£
https://kc.mcafee.com/corporate/index?page=content&id=SB10342
> ÖØÒª°²È«ÊÂÎñ×ÛÊö
1¡¢¡¢Î¢Èí³ÆÆäÔâµ½SolarWinds¹¥»÷±³ºóÍÅ»ïNobeliumµÄÈëÇÖ

΢Èí³ÆÆäÔâµ½Á˺ڿÍÍÅ»ïNobeliumµÄ¹¥»÷¡£¡£¡£NobeliumÊǶíÂÞ˹¹ú¶ÈÔÞÖúµÄºÚ¿Í×éÖ¯£¬ÓëSolarWinds¹©¸øÁ´¹¥»÷Óйأ¬Î¢Èí°µÊ¾¸ÃºÚ¿Í×éÖ¯Ò»ÏòÔÚ½øÐÐÃÜÂëÅçÈ÷¹¥»÷ºÍ±©Á¦¹¥»÷£¬ÒÔ»ñÈ¡¶Ô¹«Ë¾ÍøÂçµÄ½Ó¼ûȨÏÞ¡£¡£¡£Í¨¹ýµ÷²é£¬Î¢ÈíÔÚÆä¿Í»§Ö§³Ö´úÀíµÄÍÆËã»úÉϼì²âµ½Ò»¸öÐÅÏ¢ÇÔȡľÂí£¬ÇÔÈ¡Á˲¿Ãſͻ§µÄСÎÒÐÅÏ¢£¬¶øNobelium½«Ê¹ÓÃÕâЩÐÅÏ¢¶Ô΢ÈíµÄ¿Í»§½øÐÐÓÐÕë¶ÔÐÔµÄÍøÂç´¹µö¹¥»÷¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/nobelium-hackers-accessed-microsoft-customer-support-tools/
2¡¢¡¢GitGuardian°ä²¼2021ÄêGitHubÉÏÊý¾Ýй¶µÄ·ÖÎö»ã±¨

GitGuardian°ä²¼ÁË2021ÄêGitHubÉÏÊý¾Ýй¶µÄ·ÖÎö»ã±¨¡£¡£¡£×Ô2017ÄêÒÔÀ´£¬GitGuardianÒ»ÏòÔÚɨÃèÔÚGitHubÉϹ«¿ªÌá½»µÄÿһ¸öSecret£¬²¢ºâÁ¿Á˹«¹²´æ´¢¿âÖÐÊý¾Ýй¶µÄÇé¿ö¡£¡£¡£ÖÁ½ñÓг¬¹ý5000Íò¿ª·¢ÈËԱʹÓÃGitHub£¬Ò»ÄêÄÚÓÐ6000Íò¸öн¨µÄ´æ´¢¿â£¬Ìá½»´ÎÊý³¬¹ý20ÒڴΡ£¡£¡£»ã±¨Ö¸³ö£¬¹«¹²GitHubÖÐÊý¾Ýй¶µÄÊýÁ¿Í¬±ÈÔö³¤ÁË20%£¬ÆäÖÐ15%µÄÐÂäį´×ÔÓÚ×éÖ¯µÄ¹«¹²´æ´¢¿âÖУ¬¶ø85%µÄÐÂäį´×ÔÓÚ¿ª·¢ÈËÔ±µÄСÎÒ´æ´¢¿âÖС£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.gitguardian.com/state-of-secrets-sprawl-2021/
3¡¢¡¢ºÚ¿ÍÔÚRaidForumsÏúÊÛ7ÒÚ¶àÌõLinkedInÓû§µÄ¼Í¼

Privacy Sharks×êÑÐÈËÔ±·¢ÏÖÃûΪ¡°GOD User TomLiner¡±µÄºÚ¿ÍÕýÔÚRaidForumsÉÏÏúÊÛLinkedInÓû§µÄÊý¾Ý¡£¡£¡£¸Ã¸æ°×ÓÚ6ÔÂ22ÈÕ°ä²¼£¬Ðû³ÆÔ̺¬7Òڱʼͼ£¬²¢¹«¿ªÁË100ÍòÌõÑù±¾×÷Ϊ֤¾Ý¡£¡£¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬·¢ÏּͼÔ̺¬È«Ãû¡¢¡¢ÐԱ𡢡¢µç×ÓÓʼþµØÖ·¡¢¡¢µç»°ºÅÂëºÍÐÐÒµÐÅÏ¢¡£¡£¡£Ä¿Ç°Éв»Ã÷ÏÔÊý¾ÝµÄÆðÔ´ÊÇʲô£¬µ«×êÑÐÈËÔ±´§Ä¦Õâ´ÎÊý¾Ýй¶Óë4Ô·ÝÏúÊÛµÄ5ÒÚÌõLinkedIn¼Í¼¿ÉÄÜÊÇͳһÆðÔ´¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/data-700m-linkedin-users-cyber-underground/167362/
4¡¢¡¢ÃÀ¹úFINRAÖÒ¸æ¼Ù×°³ÉFINRA SupportµÄ´¹µö¹¥»÷»î¶¯

ÃÀ¹ú֤ȯҵ¼à¹Ü»ú¹¹FINRAÖÒ¸æ¼Ù×°³ÉFINRA SupportµÄ´¹µö¹¥»÷»î¶¯¡£¡£¡£FINRAÊǵÐÔÖÊÚȨµÄ·ÇͶ»ú×éÖ¯£¬Õƹܼà¹ÜÔÚÃÀ¹ú¹«¿ª»î¶¯µÄËùÓÐÂòÂôËùÊг¡ºÍ֤ȯ¹«Ë¾£¬Ã¿×ÊÖÊÎöÊýÊ®ÒÚ¸öÊг¡ÂòÂô¡£¡£¡£ÕâЩÓʼþÐû³ÆÀ´×Ô¡°FINRA SUPPORT¡±£¬µØÖ·Îª¡°support@westour.org¡±¡£¡£¡£¸ÃÓʼþÒªÇóÊÕ¼þÈ˰ÑÎÈÏÂÃæËù¸½µÄ»ã±¨²¢Á¢¼´»Ø¸´£¬»¹Ö¸³ö¸½¼þÔ̺¬¸üÐµĹ«¹²Õþ²ßÐÅÏ¢£¬µ«ÕâЩµç×ÓÓʼþ¿ÉÄܵ××ÓûÓи½¼þ¡£¡£¡£ÔçÔÚ½ñÄê3ÔºÍ6Ô³õ£¬FINRA»¹ÖÒ¸æÁËαÔì³É¡°FINRAºÏ¹æÉ󼯡±ºÍÒÔ³ÍÖÎΪµö¶üµÄÁ½´Î´¹µö»î¶¯¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/us-brokerage-firms-warned-of-finra-support-phishing-attacks/
5¡¢¡¢Î¢Èí°ä²¼°²È«¸üУ¬ÐÞ¸´Edgeä¯ÀÀÆ÷ÖеĶà¸ö·ì϶

΢Èí°ä²¼°²È«¸üУ¬ÐÞ¸´ÁËEdgeä¯ÀÀÆ÷ÖеÄ2¸ö·ì϶¡£¡£¡£ÆäÖнÏΪÑÏÖØµÄÊǰ²È«Èƹý·ì϶£¨CVE-2021-34506£©£¬Ê¹ÓÃEdgeä¯ÀÀÆ÷ÄÚÖõÄMicrosoft TranslatorÖ°ÄÜ×Ô¶¯·ÒëÍøÒ³Ê±´¥·¢µÄ¿çÕ¾µã¾ç±¾(UXSS)·ì϶µ¼Öµģ¬Äܹ»ÓÃÀ´ÔÚÍøÕ¾ÉÏÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£×êÑÐÈËÔ±³Æ¸Ã·ì϶µÄ¸´ÔÓÐԺܵͣ¬¹¥»÷ÕßÄܹ»ÔÚ²»±ØÒªÈκÎȨÏÞµÄÇé¿öÏÂʵÏÖ¡£¡£¡£Õâ´ÎÐÞ¸´µÄÁíÒ»¸ö·ìÏ¶ÎªÌØÈ¨ÌáÉý·ì϶£¨CVE-2021-34475£©¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/06/microsoft-edge-bug-couldve-let-hackers.html


¾©¹«Íø°²±¸11010802024551ºÅ