AzureFunctionsÌáȨ·ì϶¿ÉÌÓÒÝÖÁDockerÖ÷»ú£»NCC Group¼ì²âµ½ÓÃSonicWallÖÐ0dayµÄ¹¥»÷»î¶¯
°ä²¼¹¦·ò 2021-02-02
Intezer LabµÄ×êÑÐÈËÔ±Åû¶ÁËMicrosoft Azure FunctionsÖÐ佨¸´µÄÌáȨ·ì϶£¬¹¥»÷Õß¿ÉÄÜÀûÓÃÀ´ÌÓÒÝÖÁDockerÖ÷»ú¡£Azure FunctionsÄܹ»ÓÉHTTPÒªÇó´¥·¢£¬Óû§µÄ´úÂëÔÚAzureÍйܵÄÈÝÆ÷ÉÏÔËÐУ¬µ«ÊÇ´úÂëûÓб»°²È«Ô׸²¢ÇÒ¿ÉÄܱ»ÀÄÓÃÀ´½Ó¼ûµ×²ã»·¾³¡£×êÑÐÈËÔ±·¢ÏÖÄܹ»Í¨¹ý´´½¨Ò»¸öHTTP´¥·¢Æ÷À´Ö´ÐÐshell£¬ÒÔÎÞÌØÈ¨µÄappÓû§Éí·ÝÔÚÈÝÆ÷²éÕÒÊôÓÚrootȨÏ޵Ĺý³Ì½Ó¿Ú¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/114061/hacking/azure-functions-escape-docker.html
2.NCC Group¼ì²âµ½ÀûÓÃSonicWallÖÐ0dayµÄ¹¥»÷»î¶¯

ÍøÂ簲ȫ¹«Ë¾NCC GroupÖÜÈճƣ¬ËüÒѼì²âµ½Õë¶ÔSonicWallÍøÂçÉ豸ÖÐÁãÈÕ·ì϶µÄ×Ô¶¯ÀûÓó¢ÊÔ¡£Ä¿Ç°Éв»Ã÷ÏÔ´Ë·ì϶ÊÇ·ñÓëSonicWallÔÚ1ÔÂ23ÈÕÅû¶µÄ·ì϶һÑù£¬µ«NCCÒÔΪÕâÊǼ«ÓпÉÄܵġ£SonicWallÔÚÆäSMA 100°²È«²¼¸æµÄ¸üÐÂÖÐÒÑÈ·ÈÏÁËNCC Group·¢ÏÖµÄÁãÈÕ·ì϶£¬ÁгöÁËÊÜÓ°ÏìµÄÉ豸ÐͺŲ¢°µÊ¾»áÔÚ2ÔÂ2ÈÕ֮ǰ°ä²¼²¹¶¡·¨Ê½¡£Óйطì϶µÄϸ½Ú²¢Î´¹«¿ª£¬ÒÔÔ¤·ÀÆäËû¹¥»÷Õß¶ÔÆä½øÐÐ×êÑв¢·¢Æð¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/sonicwall-zero-day-exploited-in-the-wild/
3.Cisco·´À¬»øÓʼþ·þÎñSpamCopÖжϣ¬´óÁ¿Óʼþ±»¾Ü

Cisco·´À¬»øÓʼþ·þÎñSpamCopÔÚÉÏÖÜÈÕ²úÉúÁËÖжϣ¬´óÁ¿Óʼþ±»¾Ü¡£µ±ÈÕ£¬È«ÇòÁìÓòÄÚµÄÓʼþÖÎÀíÔ±¡¢×éÖ¯ºÍISPºöÈ»·¢ÏÔìäʹÓÃÁËSpamCop·þÎñµÄÓʼþ·þÎñÆ÷»Ø¾ø±í·¢Óʼþ£¬²¢³öÏÖ´¦ÖÃÄúµÄÒªÇóʱ²úÉúÃýÎóµÄÌáÐÑ¡£¾ÝϤ£¬Õâ´ÎÖжÏÊÇÓÉÓÚspamcop.netÓòµ½ÆÚËùµ¼Ö£¬µ±´«ÈëÓʼþ·þÎñÆ÷µÄRBL²é³ÊÕµ½ÏìӦʱÃýÎóµØ×èÖ¹µç×ÓÓʼþ£¬¾ÍÈçͬËüÀ´×ÔÒÑÖªÀ¬»øÓʼþ·¢ËÍÕßÒ»Ñù¡£Ä¿Ç°¸ÃÎÊÌâÒѽâ¾ö£¬SpamCop·þÎñ¸´ÔÕý³£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/spamcop-anti-spam-service-suffers-an-outage-after-its-domain-expired/
4.Ó¢¹úWoodland»ù½ð»áÉÏÔÂÔâµ½¹¥»÷£¬Ä¿Ç°ITϵͳÒÀÈ»ÀëÏß

Ó¢¹ú×î´óµÄÁֵشȱ¯»ú¹¹Woodland TrustÈ·ÈÏÆäÉϸöÔÂÔâµ½ÁËÍøÂç¹¥»÷£¬Ä¿Ç°¶à¸öITϵͳÒÀÈ»´¦ÓÚÀëÏß״̬¡£¹¥»÷²úÉúÔÚ2020Äê12ÔÂ14ÈÕÍíÉÏ£¬¸Ã×éÖ¯Ôâµ½¸´ÔÓÇҸ߼¶´ËÍâ¹¥»÷£¬µ¼Öºܶà·þÎñÍÑ»ú¡£·¢ÏÖ¹¥»÷ºó×éÖ¯µ±¼´²ÉÈ¡Ðж¯²¢½øÐе÷²é£¬Éв»È·¶¨Æä50Íò¸ö³ÉÔ±µÄÊý¾ÝÊÇ·ñÒѾ±»ºÚ¿ÍÇÔÈ¡¡£Ä¿Ç°ÊÂÎñµÄÐÔÖʺÍÓ°ÏìÁìÓòÈÔÔÚµ÷²éÖУ¬Òò¶øÓÐһЩϸ½ÚÈÔδ°ä²¼¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/a-month-after-a-high-level-cyberattack-charity-says-many-it-systems-are-still-offline/
5.kaspersky°ä²¼2021ÄêÒþÖÔÎÊÌâµÄÔ¤²â»ã±¨

kaspersky°ä²¼ÁË2021ÄêÒþÖÔÎÊÌâµÄÔ¤²â»ã±¨¡£»ã±¨°µÊ¾£¬ÔÚ2021Ä꣬ÖÇÄÜÒ½ÁÆÉ豸¹©¸øÉ̽«ÍøÂç²¢ÀûÓÃÔ½À´Ô½¶àÑù»¯µÄÊý¾Ý£»Ïû·ÑÕßÒþÖÔ½«³ÉΪһÖÖ¼ÛÖµÖ÷ÕÅ£¬²¢ÇÒÔÚ´óÎÞÊýÇé¿öÏÂ»áÆÆ·Ñ½ðÇ®£»Áйúµ±¾Ö¿´³Á´óÐͿƼ¼¹«Ë¾µÄ´óÊý¾Ý´æ´¢£¬²¢ÔÚ¼à¹Ü·½ÃæÔ½À´Ô½»ý¼«£»Êý¾Ý¹«Ë¾½«·¢Õ¹¸ü¶àµÄ´´Ò⣬ÉõÖÁÊǸü¾ßÇÖÈëÐÔµÄÊý¾ÝÔ´£¬ÒÔÍÆ¶¯ÐÐΪ·ÖÎö»úеµÄ·¢Õ¹£»²î·ÖÒþÖԺͽáºÏ½ø½¨ÒÔ¼°±ßÔµÍÆË㽫ԽÀ´Ô½¿í·ºµØ±»Ñ¡È¡¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/privacy-predictions-for-2021/100311/
6.Mozilla°ä²¼2020Ä껥ÁªÍø½¡È«µÄ»ØÊ׻㱨

Mozilla°ä²¼ÁË2020Ä껥ÁªÍø½¡È«µÄ»ØÊ׻㱨¡£¸Ã»ã±¨ÖØÒªÝÓÈÆÎå¸ö¹Ø¼üÎÊÌâ:È¥ÖÐÐÄ»¯¡¢ÒþÖԺͰ²È«ÐÔ¡¢Ê¢¿ªÐÔ¡¢ÍøÂçÎÄ»¯ºÍÊý×Ö°üºÕ½Êõ£¬½øÐÐ×êÑкÍ̽Çó½â¾ö¹æ»®¡£»ã±¨·ÖΪËĸö²¿ÃÅ£¬Ã¿¸ö²¿ÃÅ´ÓÌØ¶¨µÄ½Ç¶È½øÐÐ×êÑУº2020ÄêµÄ»¥ÁªÍø½¡È«½øÐÐÁËÈ«Ãæ·ÖÎö£»Èýƪ³ÁµãÎÄÕÂ̽ÇóÁËÖÖ×åÕýÒåÓëÈí¼þ¡¢ÀͶ¯Á¦ÓëÊý¾ÝÒÔ¼°É罻ýÌåµÄͨÃ÷¶ÈºÍÎÊÔðÔ죻»ØÊ××ܽὲÊöÁËÀ´×ÔÈ«Çò100¶à¸ö»¥ÁªÍø²Î¼ÓÕߵĹÊÊ£»×îºóÊǹÊʱ³ºóµÄÊý×ÖºÍÇ÷Ïò¡£
ÔÎÄÁ´½Ó£º
https://foundation.mozilla.org/en/insights/internet-health-report/


¾©¹«Íø°²±¸11010802024551ºÅ