¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.07.19-2021.07.25£©
2021-07-26
Ò»¡¢ Íþвͨ¸æ
WindowsȨÏÞÌáÉýÎó²îͨ¸æ£¨CVE-2021-36934£©
¡¾Ðû²¼Ê±¼ä¡¿2021-07-2310:00:00GMT
¡¾¸ÅÊö¡¿
AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½Î¢ÈíÐû²¼½ôÆÈͨ¸æ£¬Åû¶ÁËWindowsȨÏÞÌáÉýÎó²î£¨CVE-2021-36934£©¡£ÓÉÓÚ¶Ô¶à¸öϵͳÎļþ£¨°üÀ¨Çå¾²ÕÊ»§ÖÎÀíÆ÷(SAM)Êý¾Ý¿â£©µÄ»á¼û¿ØÖÆÁбí(ACL)¹ýÓÚ¿íËÉ£¬µ±ÏµÍ³ÆôÓÃÁËÄÚÖÃÖÎÀíÔ±ÕË»§(administrator)ʱ£¬Í¨Ë×Óû§¿ÉÒÔʹÓôËÎó²îÍŽá¹þϣת´ï¹¥»÷ʵÏÖȨÏÞÌáÉý£¬´Ó¶øÔÚÄ¿µÄÖ÷»úÉÏÒÔSYSTEMȨÏÞÖ´ÐÐí§Òâ´úÂë¡£ÏÖÔÚÎó²îϸ½ÚÓëʹÓóÌÐòÒѹûÕæ£¬½¨ÒéÏà¹ØÓû§¾ÙÐÐÅŲ鲢½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
LinuxÄÚºËȨÏÞÌáÉýÎó²îͨ¸æ£¨CVE-2021-33909£©
¡¾Ðû²¼Ê±¼ä¡¿2021-07-2214:00:00GMT
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²â·¢Ã÷QualysÑо¿ÍŶÓÅû¶ÁËLinuxÄÚºËÎļþϵͳ²ãÖеÄÒ»¸öÍâµØÌáȨÎó²î£¨CVE-2021-33909£¬Ò²³ÆÎªSequoia£©£¬¸ÃÎó²îΪLinuxÄں˵Äseq_file½Ó¿Ú±£´æsize_t-to-intÀàÐÍת»»Îó²î£¬ÓÉÓÚfs/seq_file.cûÓÐ׼ȷÏÞÖÆseq»º³åÇø·ÖÅÉ£¬´Ó¶øµ¼ÖÂÕûÊýÒç³ö¡¢Ô½½çдÈëÒÔ¼°È¨ÏÞÌáÉý¡£í§ÒâÓû§È¨Ï޵Ĺ¥»÷Õß¶¼¿ÉÒÔÔÚĬÈÏÉèÖÃÖÐʹÓôËÎó²î£¬´Ó¶ø»ñµÃÊÜÓ°ÏìÖ÷»úµÄrootȨÏÞ¡£¸ÃÎó²îÓ°ÏìÁË×Ô2014ÄêÒÔÀ´Ðû²¼µÄËùÓÐLinuxÄں˰汾£¬ÏÖÔÚPoCÒѹûÕæ£¬ÇëÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
Oracleȫϵ²úÆ·7ÔÂÒªº¦²¹¶¡¸üÐÂͨ¸æ
¡¾Ðû²¼Ê±¼ä¡¿2021-07-2210:00:00GMT
¡¾¸ÅÊö¡¿
2021Äê7ÔÂ21ÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²â·¢Ã÷Oracle¹Ù·½Ðû²¼ÁË7ÔÂÒªº¦²¹¶¡¸üÐÂͨ¸æCPU£¨CriticalPatchUpdate£©£¬¹²ÐÞ¸´ÁË342¸ö²î±ðˮƽµÄÎó²î£¬´Ë´ÎÇå¾²¸üÐÂÉæ¼°OracleDatabaseServer¡¢OracleJavaSE¡¢OracleFusionMiddleware¡¢OracleMySQL¡¢OracleCommunicationsµÈ¶à¸ö³£ÓòúÆ·¡£OracleÇ¿ÁÒ½¨Òé¿Í»§¾¡¿ìÓ¦ÓÃÒªº¦²¹¶¡¸üÐÂÐÞ¸´³ÌÐò£¬¶ÔÎó²î¾ÙÐÐÐÞ¸´¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
WebLogic¶à¸ö¸ßΣÎó²îͨ¸æ
¡¾Ðû²¼Ê±¼ä¡¿2021-07-2210:00:00GMT
¡¾¸ÅÊö¡¿
7ÔÂ21ÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½Oracle¹Ù·½Ðû²¼ÁË2021Äê7ÔÂÒªº¦²¹¶¡¸üÐÂͨ¸æCPU£¨CriticalPatchUpdate£©£¬¹²ÐÞ¸´ÁË342¸ö²î±ðˮƽµÄÎó²î£¬ÆäÖаüÀ¨3¸öÓ°ÏìWebLogicµÄÑÏÖØÎó²î£¬Ê¹ÓÃÖØÆ¯ºóµÍ£¬½¨ÒéÓû§¾¡¿ì½ÓÄɲ½·¥£¬¶Ô´Ë´ÎµÄÎó²î¾ÙÐзÀ»¤¡£CVE-2021-2382/CVE-2021-2394/CVE-2021-2397£ºÎ´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß·¢ËͶñÒâ½á¹¹µÄT3»òIIOPÐÒéÇëÇ󣬿ÉÔÚÄ¿µÄ·þÎñÆ÷ÉÏÖ´ÐÐí§Òâ´úÂ룬CVSSÆÀ·ÖΪ9.8CVE-2021-2376/CVE-2021-2378£ºÎ´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýT3»òIIOPÐÒé·¢ËͶñÒâÇëÇ󣬿ÉÔì³ÉÄ¿µÄ·þÎñÆ÷¹ÒÆð»òÍ߽⣬CVSSÆÀ·ÖΪ7.5CVE-2015-0254£º´ËÎó²î±£´æÓÚApacheStandardTaglibsÖУ¬µ±Ó¦ÓóÌÐòʹÓÃ
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. ºÚ¿Í×éÖ¯APT31ʹÓð칫·ÓÉÆ÷¹¥»÷·¨¹ú×éÖ¯
¡¾¸ÅÊö¡¿
·¨¹ú¹ú¼ÒÍøÂçÇå¾²¾Ö(ANSSI)ÏÂÊôµÄ·¨¹úÕþ¸®ÅÌËã»úÓ¦¼±×¼±¸Ð¡×éCERT-FRÖÒÑÔ˵£¬ÓëºÚ¿Í×éÖ¯APT31Õýͨ¹ýÔÚÌØ¹¤Ô˶¯ÖÐʹÓüÒÍ¥ºÍ°ì¹«ÊÒ·ÓÉÆ÷À´¹¥»÷·¨¹ú×éÖ¯¡£
APT31£¬Ò²³ÆÎªZirconium£¬ÒÔ¹¥»÷Õþ¸®¡¢¹ú¼Ê½ðÈÚ¡¢º½¿Õº½ÌìºÍ¹ú·À×éÖ¯¶øÖøÃû¡£¸Ã¼¯ÍÅ»¹¹¥»÷Á˸߿Ƽ¼¡¢ÐÞ½¨ºÍ¹¤³Ì¡¢µçÐÅ¡¢Ã½ÌåºÍ°ü¹Ü¹«Ë¾¡£CERT-FRÖ¸³ö£º“ÔÚÖ´ÐÐÕì̽ºÍ¹¥»÷Ðж¯Ö®Ç°£¬ÍþвÐÐΪÕßʹÓÃÊÜѬȾµÄ·ÓÉÆ÷×÷ΪÄäÃûÖм̡£”CERT-FRûÓлØÓ¦ÐÅÏ¢Ç徲ýÌ弯ÍŹØÓÚÌṩ¸ü¶àÐÅÏ¢µÄÇëÇ󣬰üÀ¨ÄÄЩ×éÖ¯Êܵ½Á˹¥»÷¡£¸Ã×éÖ¯ÌṩÁËÈëÇÖIOCµÄÖ¸±ê£¬ÒÔ×ÊÖú¼ì²âÎó²î¡£“ÔÚÈÕÖ¾ÖÐÕÒµ½ÆäÖÐÒ»¸öIOC£¬²¢²»ÁÏζ×ÅÕû¸öϵͳÒѱ»¹¥ÏÝ£¬Òò´Ë»¹ÐèÒª½øÒ»²½ÆÊÎö¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYRO
2. SolarWindsºÚ¿ÍʹÓÃiOSÁãÈÕÎó²î¹¥»÷iPhone
¡¾¸ÅÊö¡¿
SolarWinds ºÚ¿ÍʹÓÃλÓÚä¯ÀÀÆ÷ÒýÇæ WebKit ÖÐµÄ iOS ÁãÈÕÎó²îÒÔ¹¥»÷¸üÐ嵀 iPhone£¬²¢Í¨¹ýÃé׼ȫÇòÊÖ»ú׬ȡÊý°ÙÍòÃÀÔª¡£¹È¸èÑо¿Ö°Ô± Maddie Stone ºÍ Clement Lecitne дµÀ£¬¹¥»÷ÕߺܿÉÄÜÊǶíÂÞ˹Õþ¸®×ÊÖúµÄ×éÖ¯£¬Ê¹ÓÃÆäʱδ֪µÄiOS ÁãÈÕÎó²î¡£ÏÓÒɺڿÍÕýÔÚΪ¶íÂÞ˹Íâ¹úÇ鱨¾ÖÊÂÇé¡£
ºÚ¿Íͨ¹ýLinkedInÏòÕþ¸®¹ÙÔ±·¢ËÍÐÅÏ¢¡£Î¢ÈíÑо¿Ö°Ô±Í¸Â¶£¬Nobelium Ò²ÏòWindows Óû§·¢ËÍÁ˶ñÒâÈí¼þ¡£
ËûÃÇÊ×ÏÈÈëÇÖÁËÒ»¸öÃûΪ Constant Contact µÄÔÚÏßÓªÏú¹«Ë¾µÄ USAID ÕÊ»§¡£È»ºó£¬ËûÃÇʹÓôËÕÊ»§ÏòÊôÓÚÃÀ¹úÃñ¼ä¶ÔÍâÖúÖúºÍÉú³¤Ô®ÖúÖÎÀí×éÖ¯µÄµØµã·¢Ë͵ç×ÓÓʼþ¡£
ÁíÒ»·½Ã棬¹¥»÷ÕßµÄÄ¿µÄÊÇ iOS 12.4 µ½ 13.7 °æ±¾£¬ÉõÖÁÊǸüÐ嵀 iPhone¡£ÕâЩ¸ºÔصÄʹÃüÊÇ´ÓÖÖÖÖÍøÕ¾ÍøÂçÉí·ÝÑéÖ¤ cookie£¬°üÀ¨ Facebook¡¢LinkedIn¡¢¹È¸èºÍÑÅ»¢¡£Êý¾ÝØÊºóͨ¹ýWebSocket·¢Ë͸øºÚ¿Í¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYS1
3. ¹¥»÷ÕßÇÔÈ¡ÁË´ó×ÚµÄHumana¿Í»§µÄÒ½ÁÆÊý¾Ý
¡¾¸ÅÊö¡¿
ר¼Ò·¢Ã÷ÁËÒ»¸öÒ½ÁÆÊý¾Ý¿â£¬ÆäÖаüÀ¨ÊôÓÚÃÀ¹ú°ü¹Ü¾ÞÍ·Humana¿Í»§µÄÃô¸Ð¿µ½¡°ü¹ÜÊý¾Ý£¬Ð¹ÃÜÊÂÎñ±¬·¢ÔÚÃÀ¹úµÚÈý´ó¿µ½¡°ü¹Ü¹«Ë¾£¬Humana֪ͨÆä65,000Ãû¿µ½¡ÍýÏë³ÉÔ±£¬¸ÃÎó²î±¬·¢ÔÚ2020Äê10ÔÂ12ÈÕʱ´ú“·Ö°üÉ̵ÄÔ±¹¤Ïòδ¾ÊÚȨµÄСÎÒ˽¼Òй¶ÁËÒ½ÁƼͼ”¡£2020Äê12ÔÂ16ÈÕ£¬ÊÜÊý¾Ýй¶ӰÏìµÄÒ»Ãû»¼ÕßÏò¸Ã¹«Ë¾ÌáÆðËßËÏ¡£7ÔÂ18ÈÕ£¬ÎÒÃÇÁªÏµÁËHumanaÒÔÈ·ÈÏÊý¾ÝÊôÓÚËûÃÇ£¬µ«ËûÃÇÉÐδ×ö³ö»ØÓ¦¡£ÏÂÔØ¸ÃÊý¾Ý¿âµÄһλÂÛ̳³ÉÔ±Éù³Æ£¬¸Ãµµ°¸°üÀ¨2020ÄêµÄÐÅÏ¢£¬¶ø²»ÊÇйÃÜÕßËù½¨ÒéµÄ2019ÄêµÄÐÅÏ¢¡£ÈôÊÇÂÛ̳³ÉÔ±µÄ˵·¨Êôʵ£¬Ôòй¶µÄÊý¾Ý¿â¿ÉÄÜÊÇ2020ÄêÎ¥¹æÐÐΪµÄÒ»²¿·Ö¡£»°ËäÔÆÔÆ£¬Ð¹ÃÜÕßÐû²¼µÄÑù±¾Öз¢Ã÷µÄÊý¾Ý´ó¶àÀ´×Ô2019Ä꣬Õâ¿ÉÄÜÅú×¢ËüÓë֮ǰµÄÊÂÎñÎ޹أ¬¿ÉÄÜÊǵ¥¶À»ñÈ¡µÄ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYRM
4. ¹¥»÷ÕßʹÓÃAWÊÂÇéÁ÷¹¥»÷Kubernetes¼¯Èº
¡¾¸ÅÊö¡¿
ArgoÃæÏòWebµÄÒDZí°åµÄ¹ýʧÉèÖÃȨÏÞÔÊÐíδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÔÚKubernetesÄ¿µÄÉÏÔËÐдúÂ룬°üÀ¨¼ÓÃÜÍÚ¾òÈÝÆ÷¡£Çå¾²Ñо¿Ö°Ô±ÖÒÑÔ˵£¬Kubernetes¼¯ÈºÕýÊܵ½ÉèÖùýʧµÄArgoWorkflowsʵÀýµÄ¹¥»÷¡£
ArgoWorkflowsÊÇÒ»¸ö¿ªÔ´µÄÈÝÆ÷ÔÉúÊÂÇéÁ÷ÒýÇæ£¬ÓÃÓÚÔÚKubernetesÉϱàÅŲ¢ÐÐ×÷Òµ——ÒÔ¼ÓËÙÅÌËã÷缯ÐÍ×÷ÒµµÄ´¦Öóͷ£Ê±¼ä¡£Ëü»¹Í¨³£ÓÃÓÚ¼ò»¯ÈÝÆ÷°²ÅÅ¡£
Óë´Ëͬʱ£¬KubernetesÊÇÒ»ÖÖÊ¢ÐеÄÈÝÆ÷±àÅÅÒýÇæ£¬ÓÃÓÚÖÎÀíÔÆ°²ÅÅ¡£Æ¾Ö¤IntezerµÄÒ»ÏîÆÊÎö£¬¶ñÒâÈí¼þÔËÓªÉÌÕýÔÚͨ¹ýArgo½«¼ÓÃܿ󹤷ÅÈëÔÆÖУ¬ÕâÒª¹é¹¦ÓÚijЩʵÀý¿Éͨ¹ý²»ÐèÒªÍⲿÓû§Éí·ÝÑéÖ¤µÄÒDZí°å¹ûÕæ¿ÉÓá£Òò´Ë£¬ÕâЩ¹ýʧÉèÖõÄȨÏÞ¿ÉÄÜÔÊÐíÍþвÐÐΪÕßÔÚÊܺ¦ÕßµÄÇéÐÎÖÐÔËÐÐδ¾ÊÚȨµÄ´úÂë¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYRs
5. MosaicLoader¶ñÒâÈí¼þÌṩFacebookÇÔÈ¡³ÌÐòºÍRAT
¡¾¸ÅÊö¡¿
Ò»ÖÖÃûΪMosaicLoaderµÄWindows¶ñÒâÈí¼þÕýÔÚÈ«Çò¹æÄ£ÄÚÈö²¥£¬³äµ±È«·½Î»·þÎñµÄ¶ñÒâÈí¼þ´«ËÍÆ½Ì¨£¬±»ÓÃÀ´Í¨¹ýÔ¶³Ì»á¼ûľÂí(RAT)¡¢FacebookcookieÇÔÈ¡³ÌÐòºÍÆäËûÍþвѬȾÊܺ¦Õß¡£
ƾ֤BitdefenderÑо¿Ö°Ô±µÄ˵·¨£¬ËûÃÇ·¢Ã÷¼ÓÔØ³ÌÐòͨ¹ýËÑË÷Ч¹ûÖеĸ¶·Ñ¹ã¸æÔÚÈ«Çò¹æÄ£ÄÚÈö²¥£¬Ä¿µÄÊÇѰÕÒµÁ°æÈí¼þºÍÓÎÏ·µÄÈË¡£Ëüαװ³ÉÆÆ½âµÄÈí¼þ×°ÖóÌÐò£¬µ«ÏÖʵÉÏ£¬ËüÊÇÒ»¸öÏÂÔØ³ÌÐò£¬¿ÉÒÔ½«ÈκÎÓÐÓøºÔØ´«Ë͵½ÊÜѬȾµÄϵͳ¡£
BitdefenderµÄÑо¿Ö°Ô±Ú¹ÊÍ˵£º“MosaicLoader±³ºóµÄ¹¥»÷Õß½¨ÉèÁËÒ»ÖÖ¶ñÒâÈí¼þ£¬¿ÉÒÔÔÚϵͳÉÏ´«ËÍÈκÎÓÐÓÃÔØºÉ£¬Ê¹Æä×÷Ϊ´«ËÍ·þÎñÓпÉÄÜ׬Ǯ¡£”“ËüÏÂÔØÒ»¸ö¶ñÒâÈí¼þÅçÉäÆ÷£¬´ÓÏÂÁîºÍ¿ØÖÆ(C2)·þÎñÆ÷»ñÈ¡URLÁÐ±í£¬²¢´ÓÎüÊÕµ½µÄÁ´½ÓÏÂÔØÓÐÓøºÔØ¡£”
Ñо¿Ö°Ô±ÊӲ쵽¶ñÒâÈí¼þÅçÉäÆ÷ÌṩFacebookcookieÇÔÈ¡³ÌÐò£¬ÕâЩ³ÌÐò»áй¶µÇ¼Êý¾Ý——ÕâÔÊÐíÍøÂç¹¥»÷Õß½Ó»á¼Æ»§£¬½¨ÉèÈö²¥¶ñÒâÈí¼þµÄÌû×Ó»òµ¼ÖÂÉùÓþÊÜËðµÄÌû×Ó¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYRf
6. ¹¥»÷ÕßÇÔÈ¡·ðÂÞÀï´ï¹«Ô¢Ì®»ÙÊܺ¦ÕßÉí·Ý
¡¾¸ÅÊö¡¿
ºÚ¿ÍÕýÔÚÇÔÈ¡ÔÚ¹«Ô¢Ì®»ÙÊܺ¦ÕßÖÐɥʧÈ˵ÄÉí·Ý¡£ÓÉÓÚһȺºÚ¿ÍÒÔеÄÉí·Ý͵ÇÔΪĿµÄ£¬Îª·ðÂÞÀï´ïÖÝɪ·òÈüµÂµÄÉÐÆÕÀ¼ËþÄϹ«Ô¢´óÂ¥²¿·ÖÌ®»Ù¶ø×·µ¿Ê§È¥Ç×È˵ļÒÍ¥ÏÖÔÚ±»±Þ²ß¼ì²éËûÃÇÒѹÊÖ§ÊôµÄÐÅÓüƻ®¡£ÏÔÈ»£¬ÍøÂç·¸·¨·Ö×ÓÕýÔÚԢĿÐÂÎŲ¢ÇÔÈ¡Ôڹ㲥ʱ´úÔĶÁµÄÊܺ¦ÕßÉí·Ý¡£SurfsideÊг¤CharlesBurkett¸æËß·ðÂÞÀï´ïÍâµØÐÂÎĄ̊£¬Ö´·¨²¿·ÖÕýÔÚÆð¾¢×·²éÍøÂç·¸·¨·Ö×Ó¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYR1
7. ¹¥»÷ÕßʹÓù¤³ÌºÍÍøÂç´¹ÂÚÔ˶¯Ö²Èë¶ñÒâÈí¼þ¹¥»÷¶«¾©°ÂÔË»á
¡¾¸ÅÊö¡¿
¶¨ÓÚÖÜÎåÍíÉÏ¿ªÄ»µÄ¶«¾©°ÂÔË»áÒѾ³ÉΪÍþвÐÐΪÕßµÄÄ¿µÄ£¬È»¶ø£¬Áª°îÊÓ²ì¾ÖµÄÍøÂ粿·Ö·¢³öÖÒÑÔ£¬°ÂÔË»áµÄµçÊӹ㲥ºÜ¿ÉÄÜ»áÊܵ½ÍþвÐÐΪÕߵĹ¥»÷¡£
Áª°îÊÓ²ì¾ÖµÄ֪ͨ³Æ£º“¹¥»÷Õß¿ÉÒÔÔÚÊÂÎñ±¬·¢Ö®Ç°Ê¹ÓÃÉç½»¹¤³ÌºÍÍøÂç´¹ÂÚÔ˶¯À´»ñÈ¡»á¼ûȨÏÞ»òʹÓÃÏÈǰ»ñµÃµÄ»á¼ûȨÏÞÀ´¹¥»÷¶ñÒâÈí¼þ£¬ÒÔÔÚÊÂÎñʱ´úÆÆËðÊÜÓ°ÏìµÄÍøÂç¡£”“Éç»á¹¤³ÌºÍÍøÂç´¹ÂÚÔ˶¯¼ÌÐøÎª¹¥»÷ÕßÌṩ¾ÙÐдËÀ๥»÷ËùÐèµÄ»á¼ûȨÏÞ¡£”
Áª°îÊÓ²ì¾ÖÔö²¹Ëµ£¬°ÂÔ˻ὫÎüÒýÄÇЩÏëÒª“׬Ǯ¡¢É¢²¥ÔÓÂÒ¡¢ÔöÌí¶ñÃû¡¢Ú®»ÙµÐÊÖºÍÍÆ½øÒâʶÐÎ̬ĿµÄ”µÄͨË×ÍøÂç·¸·¨·Ö×ÓºÍÃñ×å¹ú¼ÒÐÐΪÕß¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYRH
8. ¹¥»÷Õß¹¥»÷²Æ²ú500ǿ״ʦÊÂÎñËù
¡¾¸ÅÊö¡¿
ÃÀ¹ú״ʦÊÂÎñËù£¬ÒÔ¼°ÖÚ¶àÖÁ¹«Ë¾¼û¸æ¿Í»§£¬ÈëÇÖÕß¿ÉÄÜÒѾÇÔÈ¡ÁËËûÃǵÄÊý¾Ý¡£½ñÄê2Ô·ݣ¬¸Ã¹«Ë¾Ôâµ½ÀÕË÷Èí¼þµÄ¹¥»÷£¬ÏÖÔÚÕýÔÚÔâÊÜÊý¾Ýй¶ӰÏì¡£
ÕâЩ¿Í»§º¸ÇÖÚ¶àÐÐÒµ£¬ÆäÖаüÀ¨Æ»¹û¡¢²¨Òô¡¢Ó¢¹úº½¿Õ¹«Ë¾¡¢¿ËÀ³Ë¹ÀÕ¡¢°£¿ËÉÃÀæÚ¡¢·ÑÑ©-ÆÕÀ³Ë¹¡¢¸£ÌØ¡¢±¾Ìï¡¢IBM¡¢½Ý±ª¡¢ÃÏɽ¶¼¡¢·áÌïºÍÃÀ¹úº½¿ÕµÈ¹«Ë¾¡£
ÖÜÎ壬¸Ã¹«Ë¾ÔÚÒ»·ÝÐÂΟåÖÐÌåÏÖ£¬ËüÔÚ2ÔÂ27ÈÕÒâʶµ½×Ô¼ºÊܵ½ÁËÀÕË÷Èí¼þ¹¥»÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYRe
9. ¹¥»÷Õß¹¥»÷É³ÌØ°¢ÃÀµÄÊý¾Ý
¡¾¸ÅÊö¡¿
Ò»ÃûºÚ¿ÍÉù³Æ´ÓÉ³ÌØ°¢À²®Ê¯ÓͺÍ×ÔÈ»Æø¾ÞÍ·É³ÌØ°¢ÃÀ¹«Ë¾ÇÔÈ¡ÁË1TBµÄÃô¸ÐÊý¾Ý¡£Õâ¼ÒʯÓ;ÞÍ·µÄÔ±¹¤ÄêÊÕÈëÁè¼Ý2000ÒÚÃÀÔª£¬ÍþвÐÐΪÕßÒÔ500ÍòÃÀÔªµÄ³õʼ¼ÛÇ®Ìṩ±»µÁÊý¾Ý¡£
BleepingComputerÁªÏµÁ˸ù«Ë¾£¬¸Ã¹«Ë¾È·ÈÏÁ˵ÚÈý·½³Ð°üÉ̵ÄÊý¾Ýй¶£¬µ«Ö¸³ö¸ÃÊÂÎñ¶ÔAramcoµÄÔËӪûÓÐÓ°Ïì¡£É³ÌØ°¢ÃÀ»¹¸æËßBleepingComputer£¬Õâ²»ÊÇÀÕË÷Èí¼þÇå¾²Îó²î¡£
“É³ÌØ°¢ÃÀ×î½üÒâʶµ½µÚÈý·½³Ð°üÉ̳ÖÓеÄÓÐÏÞÊýÄ¿µÄ¹«Ë¾Êý¾Ý¡£”É³ÌØ°¢ÃÀ½²»°È˸æËßBleepingComputer¡£“ÎÒÃÇÈ·ÈÏÊý¾ÝµÄÐû²¼¶ÔÎÒÃǵÄÔËӪûÓÐÓ°Ï죬¹«Ë¾¼ÌÐø¼á³ÖÎȽ¡µÄÍøÂçÇå¾²Ì¬ÊÆ¡£”ZeroXÉù³ÆÒÑÔÚ2020ÄêʹÓÃÁãÈÕÎó²î´ÓÉ³ÌØ°¢ÃÀµÄ»ù´¡ÉèÊ©ÖÐÇÔÈ¡Êý¾Ý¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYQY
10. ¹¥»÷ÕßʹÓÃÐéαµÄFlash¸üй¥»÷MacOsÓû§
¡¾¸ÅÊö¡¿
Ê·µÙ·òÇDz¼Ë¹³Æ£¬¹¥»÷Õß½èÖúÐéαµÄFlash¸üÐÂÀ´¹¥»÷macOSÓû§£¬macOSʹ¶ñÒâÐÐΪÕߺÜÄÑÔÚMacÉÏ×°ÖöñÒâÈí¼þ¡£¿ÉÊÇ×Ô´ÓAppleÈ¥Äê×èÖ¹Ö§³ÖAdob??eFlashÒÔÀ´£¬¶ñÒâÈí¼þ×÷Õß¾ÍʹÓÃÕâÒ»²î±ð¡£ÓÕÆÓû§ÏÂÔØºÍ×°ÖÃÐéαµÄFlash×°ÖóÌÐò¡£ÕâЩÐéαװÖóÌÐò¿ÉÒÔÈÝÄÉ´Ó¹ã¸æÈí¼þµ½ºóÃųÌÐòµÄÈκÎÄÚÈÝ£¬ÀýÈçShlayerºÍBundlore¡£Ö»¹ÜÕâЩװÖóÌÐòͨ³£Ã»ÓÐÊý×ÖÊðÃû²¢ÒªÇóÓû§ÊÖ¶¯ÈƹýGatekeeper£¬µ«ÎÒÃÇ¿´µ½Óû§Ô¸ÒâÈÆ¹ý²Ù×÷ϵͳÖÒÑÔ²¢ÊÖ¶¯×°ÖÃÕâЩÇ徲Σº¦¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYQQ

AG¹«Ë¾ÔÆ







