TIMÍŶÓÅû¶CA Technologies²úÆ·ÖеĶà¸ö0day£»£»£»£»£»£»£»Î¢Èí³ÆÖÜËĵÄÖÐÖ¹Ô´ÓÚ´úÂëȱÏݵ¼ÖµÄAzure DNS¹ýÔØ
Ðû²¼Ê±¼ä 2021-04-061.TIMÍŶÓÅû¶CA Technologies²úÆ·ÖеĶà¸ö0day

CA TechnologiesÊÇÃÀ¹úÒ»¼ÒרעÓÚB2BÈí¼þµÄ¿ç¹ú¹«Ë¾£¬£¬£¬£¬£¬£¬£¬ÏúÊÛ½ü200ÖÖ²úÆ·£¬£¬£¬£¬£¬£¬£¬Éæ¼°ÂþÑÜʽÅÌËã¡¢ÔÆÅÌËã¡¢DevOpsºÍÅÌËã»úÇå¾²Èí¼þÒÔ¼°Òƶ¯×°±¸¡£¡£¡£¡£¡£¡£¡£TIMµÄRed Team ResearchÍŶÓÅû¶ÁËCA eHealth Performance Manager²úÆ·ÖеÄ5¸öÐÂÎó²î¡£¡£¡£¡£¡£¡£¡£»®·ÖΪÌáȨÎó²î£¨CVE-2021-28246ºÍCVE-2021-28249£©¡¢¿çÕ¾µã¾ç±¾Îó²î£¨CVE-2021-28247£©¡¢Í¨¹ýSUID/GUIDÎļþµÄÌáȨÎó²î£¨CVE-2021-28250£©ºÍÉí·ÝÑéÖ¤Îó²î£¨CVE-2021-28248£©¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/116268/security/ca-ehealth-performance-manager-flaws.html
2.΢Èí³ÆÖÜËĵÄÖÐÖ¹Ô´ÓÚ´úÂëȱÏݵ¼ÖµÄAzure DNS¹ýÔØ

΢Èí͸¶£¬£¬£¬£¬£¬£¬£¬ÉÏÖÜËĵÄÈ«Çò¹æÄ£ÄÚµÄЧÀÍÖÐÖ¹ÊÇÓÉ´úÂëȱÏݵ¼ÖµÄAzure DNS¹ýÔØÒýÆðµÄ¡£¡£¡£¡£¡£¡£¡£ÖÐÖ¹±¬·¢ÔÚÉÏÖÜËÄÏÂÖç5:21×óÓÒ£¬£¬£¬£¬£¬£¬£¬MicrosoftÓû§·¢Ã÷ÆäÎÞ·¨»á¼ûXbox Live¡¢Office¡¢TeamsºÍSkypeµÈЧÀÍ£¬£¬£¬£¬£¬£¬£¬¸ÃÎÊÌâÓÚ6:30±»½â¾ö¡£¡£¡£¡£¡£¡£¡£½üÆÚ£¬£¬£¬£¬£¬£¬£¬MicrosoftÐû²¼ÁËÓйØÐ§ÀÍÖÐÖ¹µÄ»ù´¡Ôµ¹ÊÔÓÉÆÊÎö£¨RCA£©£¬£¬£¬£¬£¬£¬£¬³ÆÕë¶ÔAzureÉÏÍйܵÄijЩÓòµÄDNSÅÌÎÊÒì³£¼¤Ôöµ¼ÖÂЧÀÍÆ÷¹ýÔØ£¬£¬£¬£¬£¬£¬£¬Î¢Èí²¢Î´Ú¹Êͼ¤ÔöµÄÔµ¹ÊÔÓÉ£¬£¬£¬£¬£¬£¬£¬¾ÝÍÆ²â¿ÉÄÜÊÇÓÉÓÚÕë¶ÔijЩÓòµÄDDoS¹¥»÷¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-outage-caused-by-overloaded-azure-dns-servers/
3.ÃÀ¹ú½ðÈÚ»ú¹¹RobinhoodµÄ¿Í»§Ôâµ½´¹ÂÚ¹¥»÷

Robinhood MarketsÔÚÉÏÖÜËÄÐû²¼ÏòÆä¿Í»§·¢ËÍÓʼþ³Æ£¬£¬£¬£¬£¬£¬£¬Æä²¿·Ö¿Í»§¿ÉÄÜÒѾÔâµ½´¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£¡£¡£RobinhoodÊÇÒ»¼ÒÃÀ¹ú½ðÈÚЧÀÍ»ú¹¹£¬£¬£¬£¬£¬£¬£¬ÆäÊÖ»úÓ¦ÓÿÉÌṩ¹ÉƱºÍ»ù½ðµÄÃâÓ¶½ðÉúÒ⣬£¬£¬£¬£¬£¬£¬×èÖ¹2020ÄêÒÑÓµÓÐ1300Íò¿Í»§¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷»î¶¯Ê¹ÓÃÁËÁ½ÖÖ¹¥»÷ǰÑÔÓÕÆÊܺ¦Õߣ¬£¬£¬£¬£¬£¬£¬ÆäÒ»ÊÇʹÓðüÀ¨ÁËαÔìRobinhoodÍøÕ¾Á´½ÓµÄ´¹ÂÚÓʼþ£¬£¬£¬£¬£¬£¬£¬ÓÕʹ»á¼ûÕßÊäÈëµÇ¼ƾ֤£»£»£»£»£»£»£»ÁíÒ»ÖÖÊÇʹÓÃÁ˱¨Ë°¼¾£¬£¬£¬£¬£¬£¬£¬ÒªÇóÄ¿µÄÏÂÔØ°üÀ¨Á˶ñÒâÈí¼þµÄαÔì˰ÊÕÎļþ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.ehackingnews.com/2021/04/attackers-targeted-robinhood-with.html
4.KasperskyÅû¶Õë¶ÔÔ½Ä϶à¸ö×éÖ¯µÄÍøÂçÌØ¹¤»î¶¯

KasperskyÅû¶ÁËAPT×éÖ¯CycldekÕë¶ÔÔ½ÄÏÕþ¸®ºÍ¾üÊÂ×éÖ¯µÄÍøÂçÌØ¹¤»î¶¯¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯Ê¹ÓÃÁËÃûΪFoundCoreµÄ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬¿É¾ÙÐÐÎļþϵͳʹÓá¢Àú³ÌʹÓá¢ÆÁÄ»½ØÍ¼²¶»ñºÍí§ÒâÏÂÁîÖ´ÐС£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬Kaspersky³Æ¸Ã×éÖ¯ÔÚÖØ´óÐÔ·½ÃæÈ¡µÃÁËÖØ´óǰ½ø£¬£¬£¬£¬£¬£¬£¬ÀýÈ磬£¬£¬£¬£¬£¬£¬ÆäpayloadµÄ±êÍ·£¨´úÂëµÄÄ¿µÄºÍÔ´£©±»ÍêÈ«°þÀ룬£¬£¬£¬£¬£¬£¬Ê£ÏµÄÉÙÊý²¿·ÖµÄÖµÊDz»Á¬¹áµÄ£¬£¬£¬£¬£¬£¬£¬Õâ´ó´óÔöÌíÁËÑо¿Ö°Ô±¶ÔÆä¾ÙÐÐÆÊÎöµÄÄѶȡ£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/spy-operations-vietnam-rat/165243/
5.΢ÈíÐû²¼2021Äê3ÔÂSecurity SignalsµÄÆÊÎö±¨¸æ

΢ÈíÐû²¼ÁË2021Äê3ÔÂSecurity SignalsµÄÆÊÎö±¨¸æ£¬£¬£¬£¬£¬£¬£¬ÊÓ²ìÁËÀ´×ÔÖйú¡¢µÂ¹ú¡¢ÈÕ±¾¡¢Ó¢¹úºÍÃÀ¹úµÄ1000λÆóÒµÇå¾²¾öÒéÕß¡£¡£¡£¡£¡£¡£¡£±¨¸æ·¢Ã÷£¬£¬£¬£¬£¬£¬£¬ÒÑÍùÁ½ÄêÖÐÓÐ80£¥µÄÆóÒµÔâµ½ÁËÖÁÉÙÒ»´Î¹Ì¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬µ«Ö»ÓÐ29£¥µÄ×éÖ¯·ÖÅÉÁËÔ¤ËãÀ´±£»£»£»£»£»£»£»¤¹Ì¼þ¡£¡£¡£¡£¡£¡£¡£NVDÖ¤×ÅʵÒÑÍùËÄÄêÖУ¬£¬£¬£¬£¬£¬£¬Õë¶Ô¹Ì¼þµÄ¹¥»÷ÔöÌíÁËÎå±¶ÒÔÉÏ¡£¡£¡£¡£¡£¡£¡£21£¥µÄ¾öÒéÕßÈÏ¿ÉÎÞ·¨¼à¿Ø¹Ì¼þÊý¾Ý£¬£¬£¬£¬£¬£¬£¬82£¥×é֯ûÓÐ×ÊÔ´À´µÖÓù¹Ì¼þ¹¥»÷¡£¡£¡£¡£¡£¡£¡£81£¥µÄµÂ¹ú¹«Ë¾¡¢91£¥µÄÃÀ¹ú¡¢Ó¢¹úºÍÈÕ±¾¹«Ë¾ÒÔ¼°95£¥µÄÖйú¹«Ë¾Ô¸ÒâÔÚÕâ¸ö·½Ãæ¾ÙÐÐͶ×Ê¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.microsoft.com/en-us/secured-corepc
6.RavelinÐû²¼Óйصç×ÓÉÌÎñڲƻµÄÆÊÎö±¨¸æ

Ravelin¶ÔÈ«Çò1000¶à¼ÒÉ̼ҾÙÐÐÁËÊӲ죬£¬£¬£¬£¬£¬£¬Ðû²¼ÁËÓйصç×ÓÉÌÎñڲƻµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£±¨¸æÏÔʾ£¬£¬£¬£¬£¬£¬£¬¿ìÒª40£¥µÄ¿ìÏûÁãÊÛÉ̽«ÔÚÏßÖ§¸¶Ú²ÆÊÓΪ×î´óµÄÚ²ÆÎ£º¦£¬£¬£¬£¬£¬£¬£¬45%µÄ¹«Ë¾ËùÂÄÀúµÄÕË»§½ÓÊÜ(ATO)¹¥»÷ÓÐËùÔöÌí¡£¡£¡£¡£¡£¡£¡£±¨¸æÕ¹Íû£¬£¬£¬£¬£¬£¬£¬µç×ÓÉÌÎñÐÐÒµÖеÄÚ²ÆÎÊÌâ¿ÉÄÜ»áÓúÑÝÓúÁÒ£¬£¬£¬£¬£¬£¬£¬ÓÈÆäÊÇËæ×ÅÐí¶à¹Å°åµÄ¸ß½ÖÆ·ÅÆ£¨ÈçTopshopºÍDebenhams£©±»ÊÕ¹º²¢Íê³ÉÓªÒµËùÓÐÏòÏßÉÏתÐ͵Äʱ¼ä¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://pages.ravelin.com/retail-fraud-payments-report


¾©¹«Íø°²±¸11010802024551ºÅ