GoogleÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬ £¬£¬£¬ÐÞ¸´ChromeÖÐÒѱ»Ê¹ÓõÄ0day£»£»£»£»£»£»Avas·¢Ã÷ÖÁÉÙ100¼ÒÒâ´óÀûµÄÒøÐÐÒѳÉΪUrsnifµÄ¹¥»÷Ä¿µÄ

Ðû²¼Ê±¼ä 2021-03-05

1.GoogleÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬ £¬£¬£¬ÐÞ¸´ChromeÖÐÒѱ»Ê¹ÓõÄ0day


1.jpg


GoogleÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬ £¬£¬£¬ÐÞ¸´Chromeä¯ÀÀÆ÷ÖеÄ47¸öÎó²î£¬£¬£¬£¬£¬ £¬£¬£¬ÆäÖаüÀ¨Ò»¸öÒѱ»Ê¹ÓõÄ0day¡£¡£¡£ ¡£¸Ã0day±»×·×ÙΪCVE-2021-21166£¬£¬£¬£¬£¬ £¬£¬£¬ÓÚ2ÔÂ11ÈÕ±»Åû¶£¬£¬£¬£¬£¬ £¬£¬£¬ÏÖÔÚGoogle²¢Î´Í¸Â¶ÓйظÃÎó²îµÄ¸ü¶àÐÅÏ¢¡£¡£¡£ ¡£±ðµÄ£¬£¬£¬£¬£¬ £¬£¬£¬´Ë´Î¸üл¹ÐÞ¸´ÁËTabStripÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2021-21159£©¡¢WebAudioÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2021-21160£©ÒÔ¼°WebRTCÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2021-21162£©µÈ¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/google-patches-actively-exploited-chrome-browser-zero-day-vulnerability/


2.GRUBÏîÄ¿Ðû²¼²¹¶¡£¬£¬£¬£¬£¬ £¬£¬£¬ÐÞ¸´GRUB2ÖеÄ117¸öÎó²î


2.jpg


±¾ÖÜ£¬£¬£¬£¬£¬ £¬£¬£¬GRUBÏîÄ¿µÄά»¤Ö°Ô±Ðû²¼Á˲¹¶¡£¬£¬£¬£¬£¬ £¬£¬£¬ÐÞ¸´ÁËGRUB2ÖеÄ117¸öÎó²î¡£¡£¡£ ¡£´Ë´ÎÐÞ¸´µÄ½ÏΪÑÏÖØµÄÎó²îΪacpiÏÂÁîÔÊÐíÌØÈ¨Óû§¼ÓÔØÌØÖÆµÄACPI±í£¨CVE-2020-14372£©¡¢rmmodÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2020-25632£©¡¢Å²ÓÃgrub_usb_device_initialize£¨£©À´´¦Öóͷ£USB×°±¸³õʼ»¯Ê±µÄÔ½½çдÎó²î£¨CVE-2020-25647£©µÈ¡£¡£¡£ ¡£¼øÓÚÈ¥Äê·¢Ã÷µÄBootHoleÎó²î£¬£¬£¬£¬£¬ £¬£¬£¬Ñо¿Ö°Ô±½¨Ò龡¿ìÐÞ²¹ÕâЩÑÏÖØµÄÎó²î¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/grub2-boot-loader-reveals-multiple-high-severity-vulnerabilities/


3.¶íÂÞ˹µÄºÚ¿ÍÂÛ̳MazaÔâµ½¹¥»÷£¬£¬£¬£¬£¬ £¬£¬£¬Óû§ÐÅÏ¢ÒÑй¶


3.jpg


¶íÂÞ˹¶¥¼¶ºÚ¿ÍÂÛ̳Maza£¨ÒÔǰ³ÆÎªMazafaka£©Ôâµ½¹¥»÷£¬£¬£¬£¬£¬ £¬£¬£¬Óû§ÐÅÏ¢ÒÑй¶¡£¡£¡£ ¡£MazaÖ÷ÒªÒÔÉúÒâ±»µÁµÄ²ÆÎñÐÅÏ¢£¨ÓÈÆäÊÇÐÅÓÿ¨ºÍ½è¼Ç¿¨ÏêϸÐÅÏ¢£©¶øÖøÃû¡£¡£¡£ ¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨Óû§Éí·Ý¡¢Óû§Ãû¡¢µç×ÓÓʼþµØµã£¨Ô¼3000¸ö£©¡¢¹þÏ£ÃÜÂëºÍSkypeµØµãµÈ£¬£¬£¬£¬£¬ £¬£¬£¬¿ÉÄÜÉÐÓÐÒ»¸öMAZAÖÎÀíԱʹÓõÄ˽ÓмÓÃÜÃÜÔ¿¡£¡£¡£ ¡£±ðµÄ£¬£¬£¬£¬£¬ £¬£¬£¬ÁíÒ»¸ö°µÍøVerifiedÒ²Ôâµ½Á˹¥»÷£¬£¬£¬£¬£¬ £¬£¬£¬ÍøÕ¾±»Öض¨Ïòµ½¹¥»÷ÕßËù¿ØÖƵÄЧÀÍÆ÷¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/russian-hacker-forums-maza-verified-hacked/


4.Avas·¢Ã÷ÖÁÉÙÓÐ100¼ÒÒâ´óÀûµÄÒøÐÐÒѳÉΪUrsnifµÄ¹¥»÷Ä¿µÄ


4.jpg


AvastÑо¿Ö°Ô±·¢Ã÷ÖÁÉÙÓÐ100¼ÒÒâ´óÀûÒøÐÐÒѳÉΪUrsnif TrojanµÄ¹¥»÷Ä¿µÄ¡£¡£¡£ ¡£UrsnifÓÚ2007ÄêÊ״α»·¢Ã÷£¬£¬£¬£¬£¬ £¬£¬£¬Ö÷ÒªÇÔÈ¡Óû§Ãû¡¢ÃÜÂë¡¢ÐÅÓÿ¨¡¢ÒøÐÐÓªÒµºÍ¸¶¿îÐÅÏ¢µÈÊý¾Ý¡£¡£¡£ ¡£Í³¼Æ·¢Ã÷¸Ã¶ñÒâÈí¼þÒѱ»ÓÃÓÚ¹¥»÷ÉϰټÒÒâ´óÀûÒøÐУ¬£¬£¬£¬£¬ £¬£¬£¬ºÚ¿Í½öÔÚÒ»´Î¹¥»÷ÖоÍÇÔÈ¡ÁË1700¶à¸öƾ֤¡£¡£¡£ ¡£±ðµÄ£¬£¬£¬£¬£¬ £¬£¬£¬DatktraceµÄÑо¿Ö°Ô±Ò²·¢Ã÷ÁËʹÓøöñÒâÈí¼þÕë¶ÔÃÀ¹úÒ»¼ÒÒøÐеĹ¥»÷»î¶¯¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/115245/cyber-crime/ursnif-targets-italian-banks.html


5.ÃÀ¹úCallX¹«Ë¾AWS S3´æ´¢Í°ÉèÖùýʧй¶Áè¼Ý10Íò¸öÎļþ


5.jpg


vpnMentor·¢Ã÷ÃÀ¹úµç»°ÍÆÏú¹«Ë¾CallXµÄAWS S3´æ´¢Í°ÉèÖùýʧй¶Áè¼Ý10Íò¸öÎļþ¡£¡£¡£ ¡£vpnMentor·¢Ã÷¸Ã×ß©µÄ´æ´¢Í°ÖÐ×ܹ²ÓÐ114000¸ö¹ûÕæµÄÎļþ£¬£¬£¬£¬£¬ £¬£¬£¬ÆäÖдó´ó¶¼ÊÇÏúÊ۵绰µÄÒôƵ¼Í¼¡¢ÎÄ×Ö̸Ìì¼Í¼ÒÔ¼°Ð¡ÎÒ˽¼ÒÉí·ÝÐÅÏ¢£¨PII£©£¨°üÀ¨È«Ãû¡¢¼ÒͥסַºÍµç»°ºÅÂëµÈ£©¡£¡£¡£ ¡£vpnMentorÌåÏÖ£¬£¬£¬£¬£¬ £¬£¬£¬ÕâЩ×ß©µÄÊý¾Ý¿É±»ÓÃÀ´Ìá³«ÍøÂç´¹ÂÚ¹¥»÷¡¢Ú²Æ­»î¶¯ºÍÓÕÆ­¹¥»÷µÈ¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/telemarketing-biz-exposes-114000/


6.CompuCom MSPÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬ £¬£¬£¬Ð§ÀÍÔÝʱÖÐÖ¹


6.jpg


ÃÀ¹úITÍйÜЧÀÍÌṩÉÌCompuComÔâµ½DarkSideÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬ £¬£¬£¬Ð§ÀÍÔÝʱÖÐÖ¹¡£¡£¡£ ¡£CompuCom¿ÉΪ¹«Ë¾ÌṩԶ³ÌÖ§³Ö¡¢Ó²¼þºÍÈí¼þάÐÞÒÔ¼°ÆäËûÊÖÒÕЧÀÍ£¬£¬£¬£¬£¬ £¬£¬£¬¿Í»§°üÀ¨Home Depot¡¢»¨ÆìÒøÐС¢Truist BankºÍLowe'sµÈ¡£¡£¡£ ¡£ÉÏÖÜÄ©£¬£¬£¬£¬£¬ £¬£¬£¬Æä¿Í»§·¢Ã÷ÎÞ·¨»á¼û¸Ã¹«Ë¾µÄÃÅ»§ÍøÕ¾¡£¡£¡£ ¡£Ö®ºó£¬£¬£¬£¬£¬ £¬£¬£¬CompuComÌåÏÖÆäÔâµ½Á˹¥»÷£¬£¬£¬£¬£¬ £¬£¬£¬²¿·ÖϵͳÊܵ½Ó°Ï죬£¬£¬£¬£¬ £¬£¬£¬µ¼ÖÂijЩЧÀͲ»¿ÉÓᣡ£¡£ ¡£¾­ÊӲ죬£¬£¬£¬£¬ £¬£¬£¬¹¥»÷¿ÉÄܱ¬·¢ÓÚ2ÔÂ28ÈÕ£¬£¬£¬£¬£¬ £¬£¬£¬DarkSideÔÚÆä¶à¸öϵͳÉÏ×°ÖÃÁËCobalt Strike Beacons¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/compucom-msp-confirms-ongoing-outage-following-malware-incident/