QualysÅû¶LinuxÄÚºËÖеÄÍâµØÌáȨÎó²îSequoia£»£»£»Win10ÖÐÌáȨÎó²îSeriousSAMÓ°Ïì½üÁ½ÄêÐû²¼µÄ°æ±¾

Ðû²¼Ê±¼ä 2021-07-22

1.QualysÅû¶LinuxÄÚºËÖеÄÍâµØÌáȨÎó²îSequoia


1.jpg


QualysÑо¿Ö°Ô±Åû¶ÁËLinuxÄÚºËÖеÄÍâµØÌáȨÎó²îSequoia¡£¡£¡£¸ÃÎó²î×·×ÙΪCVE-2021-33909£¬£¬£¬£¬£¬£¬±£´æÓÚÓÃÀ´ÖÎÀíÓû§Êý¾ÝµÄÎļþϵͳ²ã£¬£¬£¬£¬£¬£¬ÊÇÓÉÓÚfs/seq_file.cûÓÐ׼ȷÏÞÖÆseq»º³åÇø·ÖÅɶøµ¼Öµġ£¡£¡£Qualys³Æ£¬£¬£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìÁË×Ô2014ÄêÒÔÀ´Ðû²¼µÄËùÓÐLinuxÄں˰汾¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±»¹·¢Ã÷ÁËsystemdÖеÄÒ»¸ö¿ÍÕ»ºÄ¾¡µ¼ÖµľܾøÐ§ÀÍÎó²î£¨CVE-2021-33910£©£¬£¬£¬£¬£¬£¬±£´æÓÚ2015Äê4ÔÂÖ®ºóÐû²¼µÄËùÓÐsystemd°æ±¾ÖС£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-linux-kernel-bug-lets-you-get-root-on-most-modern-distros/


2.Win10ÖÐÌáȨÎó²îSeriousSAMÓ°Ïì½üÁ½ÄêÐû²¼µÄ°æ±¾


2.jpg


Ñо¿Ö°Ô±Jonas LykkegaardÅû¶ÁËWin10ÖеÄÌáȨÎó²îSeriousSAM£¬£¬£¬£¬£¬£¬Ó°ÏìÁ˽üÁ½Äê¶àÐû²¼µÄËùÓа汾¡£¡£¡£LykkegaardÔÚ²âÊÔ×îÐÂÐû²¼µÄWin11ʱ·¢Ã÷£¬£¬£¬£¬£¬£¬ËäÈ»WindowsÏÞÖÆÁ˵ÍȨÏÞÓû§»á¼ûSAM¡¢SECURITYºÍSYSTEMµÈÎļþ¼ÐÖеÄÃô¸ÐÉèÖÃÎļþ£¬£¬£¬£¬£¬£¬µ«ÕâЩÎļþµÄ¸±±¾Ò²±»ÉúÑÄÔÚShadow Volume Copy½¨ÉèµÄ±¸·ÝÎļþÖУ¬£¬£¬£¬£¬£¬¶ø×Ô2018Äê11ÔÂÐû²¼µÄWindows 10 v1809ÒÔÀ´£¬£¬£¬£¬£¬£¬Î¢ÈíһֱûÓÐ×èÖ¹¶ÔÕâЩ±¸·ÝµÄ»á¼û¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/serioussam-bug-impacts-all-windows-10-versions-released-in-the-past-2-5-years/


3.AdobeÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´Æä7¿î²úÆ·ÖеÄ21¸öÎó²î


3.jpg


AdobeÔÚ7ÔÂ20ÈÕ±¾ÖܶþÐû²¼ÁËÇå¾²¸üУ¬£¬£¬£¬£¬£¬×ܼÆÐÞ¸´ÁËÆä7¿î²úÆ·ÖеÄ21¸öÎó²î¡£¡£¡£´Ë´ÎÐÞ¸´ÁËAdobe After EffectsÖеÄ7¸öÎó²î£¬£¬£¬£¬£¬£¬ÆäÖÐ5¸ö¿ÉÒÔµ¼ÖÂí§Òâ´úÂëÖ´ÐУ¨CVE-2021-36017¡¢CVE-2021-35993¡¢CVE-2021-35994¡¢CVE-2021-35995ºÍCVE-2021-35996£©¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬»¹ÐÞ¸´ÁËPhotoshopÖеĻº³åÇøÒç³öµ¼ÖµĴúÂëÖ´ÐÐÎó²î£¨CVE-2021-36005£©¡¢Character AnimatorÖеÄí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-36000£©ºÍPreludeÖеÄí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-35999£©µÈ¶à¸öÑÏÖØµÄÎó²î¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/adobe-patches-21-vulnerabilities-across-seven-products


4.WizCase·¢Ã÷ÃÀ¹úµÄ80¶à¸öÊÐÕþÕþ¸®´æ´¢Í°ÉèÖùýʧ


4.jpg


WizCaseÑо¿ÍŶӷ¢Ã÷ÃÀ¹úµÄ80¶à¸öÊÐÕþÕþ¸®´æ´¢Í°ÉèÖùýʧ¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷ÃÀ¹ú¶à¸ö¶¼»áµÄÊý¾Ý¾ù´æ´¢ÔÚ¹ýʧÉèÖõÄAmazon S3´æ´¢Í°ÖУ¬£¬£¬£¬£¬£¬¶øÕâЩ¶¼»á¶¼Ê¹ÓÃÁËÓÉÃÀ¹ú¹«Ë¾PeopleGISÌṩµÄͳһ¿î²úÆ·mapsonline.net¡£¡£¡£Í¨¹ýɨÃè·¢Ã÷ÁË114¸öÓëPeopleGISÏà¹ØµÄ´æ´¢Í°£¬£¬£¬£¬£¬£¬ÆäÖÐ28¸öÉèÖÃ׼ȷ£¬£¬£¬£¬£¬£¬Ê£ÏµÄ86¸öÎÞÐèÈκÎÃÜÂë¼´¿É»á¼û¡£¡£¡£ÕâЩ̻¶µÄ´æ´¢Í°ÖаüÀ¨ÁËÓëÕâЩ¶¼»áÏà¹ØµÄÊý¾Ý£¬£¬£¬£¬£¬£¬×ܼÆÓÐÁè¼Ý1000 GBµÄÊý¾ÝºÍÁè¼Ý160Íò¸öÎļþ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.wizcase.com/blog/us-municipality-breach-report/


5.Shahaf±¨¸æ³ÆÒÔÉ«ÁеÄIT¹«Ë¾PionetÔâµ½ÀÕË÷¹¥»÷


5.jpg


Shahaf±¨¸æ³Æ£¬£¬£¬£¬£¬£¬ÒÔÉ«ÁÐMalam TimÆìϵÄIT¹«Ë¾PionetÔâµ½ÁËÀÕË÷¹¥»÷¡£¡£¡£´Ë´Î¹¥»÷µ¼ÖÂÁ˸ù«Ë¾µÄÐí¶àϵͳºÍÆäÉϰٶà¸ö¿Í»§µÄÍøÕ¾Ì±»¾£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨AssutaÒ½Ôº¡¢SonoȼÁϹ«Ë¾ºÍAppleµÄÈë¿ÚÉÌIdigitalµÈ£¬£¬£¬£¬£¬£¬ÆäÖÐIdigitalµÄ¿Í»§°üÀ¨ÒÔÉ«ÁеçÁ¦¹«Ë¾ºÍÒÔÉ«ÁÐÌú·¹«Ë¾¡£¡£¡£¾Ý³Æ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÒªÇóÖ§¸¶Ô¼50ÍòÉá¿ÍÀÕ(ÕÛºÏ151861.82ÃÀÔª)Êê½ð£¬£¬£¬£¬£¬£¬²¢ÒªÇóÏÈÁ¬Ã¦Ö§¸¶5000ÃÀÔªµÄÃÅÂÞ±Ò¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/il-ransomware-attack-on-israeli-it-company-impacts-more-than-100-customers-including-hospitals/


6.Link11Ðû²¼2021ÄêÉϰëÄêDDoS¹¥»÷Ì¬ÊÆµÄÆÊÎö±¨¸æ


6.jpg


Link11Ðû²¼ÁË2021ÄêÉϰëÄêDDoS¹¥»÷Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬ÔÚ2021ÄêQ1ºÍQ2Ö®¼ä£¬£¬£¬£¬£¬£¬DDoS»î¶¯ÔöÌíÁË19%£¬£¬£¬£¬£¬£¬ÆäÖÐһЩ¹¥»÷Á¿Áè¼ÝÁË100Gbps¡£¡£¡£Óë2020ÄêÉϰëÄêÏà±È£¬£¬£¬£¬£¬£¬2021ÄêµÄ¹¥»÷´ÎÊýͬ±ÈÔöÌíÁË33%£»£»£»×ÜÌå¹¥»÷´ø¿íÈÔÈ»ºÜ¸ß£¬£¬£¬£¬£¬£¬×î´ó¹¥»÷Á¿Îª555 Gbps£»£»£»¹¥»÷´ø¿í¼±¾çÔöÌí£¬£¬£¬£¬£¬£¬Óë2020 H1Ïà±ÈÔöÌíÁË37%£»£»£»2021ÄêÉϰëÄêÁè¼Ý100 GbpsµÄ¹¥»÷´ÎÊý¶à´ï28´Î¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.link11.com/en/blog/threat-landscape/link11-report-discovers-record-number-of-ddos-attacks-in-first-half-of-2021/