Google°ä²¼°²È«¸üУ¬½¨¸´ChromeÖÐÒѱ»ÀûÓõÄ0day£»Avas·¢ÏÖÖÁÉÙ100¼ÒÒâ´óÀûµÄÒøÐÐÒѳÉΪUrsnifµÄ¹¥»÷Ö¸±ê
°ä²¼¹¦·ò 2021-03-051.Google°ä²¼°²È«¸üУ¬½¨¸´ChromeÖÐÒѱ»ÀûÓõÄ0day

Google°ä²¼°²È«¸üУ¬½¨¸´Chromeä¯ÀÀÆ÷ÖеÄ47¸ö·ì϶£¬ÆäÖÐÔ̺¬Ò»¸öÒѱ»ÀûÓõÄ0day¡£¸Ã0day±»×·×ÙΪCVE-2021-21166£¬ÓÚ2ÔÂ11ÈÕ±»Åû¶£¬Ä¿Ç°Google²¢Î´Ð¹Â©Óйظ÷ì϶µÄ¸ü¶àÐÅÏ¢¡£´Ë±í£¬Õâ´Î¸üл¹½¨¸´ÁËTabStripÖеĶѻº³åÇøÒç¶Âí½Å£¨CVE-2021-21159£©¡¢WebAudioÖеĶѻº³åÇøÒç¶Âí½Å£¨CVE-2021-21160£©ÒÔ¼°WebRTCÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2021-21162£©µÈ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/google-patches-actively-exploited-chrome-browser-zero-day-vulnerability/
2.GRUBÏîÄ¿°ä²¼²¹¶¡£¬½¨¸´GRUB2ÖеÄ117¸ö·ì϶

±¾ÖÜ£¬GRUBÏîÖ÷ÕÅÊØ»¤ÈËÔ±°ä²¼Á˲¹¶¡£¬½¨¸´ÁËGRUB2ÖеÄ117¸ö·ì϶¡£Õâ´Î½¨¸´µÄ½ÏΪÑϳÁµÄ·ì϶ΪacpiºÅÁîÔÊÐíÌØÈ¨Óû§¼ÓÔØÌØÔìµÄACPI±í£¨CVE-2020-14372£©¡¢rmmodÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2020-25632£©¡¢Å²ÓÃgrub_usb_device_initialize£¨£©À´´¦ÖÃUSBÉ豸³õʼ»¯Ê±µÄÔ½½çд·ì϶£¨CVE-2020-25647£©µÈ¡£¼øÓÚÈ¥Äê·¢ÏÖµÄBootHole·ì϶£¬×êÑÐÈËÔ±½¨Ò龡¿ì½¨²¹ÕâЩÑϳÁµÄ·ì϶¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/grub2-boot-loader-reveals-multiple-high-severity-vulnerabilities/
3.¶íÂÞ˹µÄºÚ¿ÍÂÛ̳MazaÔâµ½¹¥»÷£¬Óû§ÐÅÏ¢ÒÑй¶

¶íÂÞ˹¶¥¼¶ºÚ¿ÍÂÛ̳Maza£¨ÒÔǰ³ÆÎªMazafaka£©Ôâµ½¹¥»÷£¬Óû§ÐÅÏ¢ÒÑй¶¡£MazaÖØÒªÒÔÂòÂô±»µÁµÄ²ÆÕþÐÅÏ¢£¨ÓÈÆäÊÇÐÅÓþ¿¨ºÍ½è¼Ç¿¨¾ßÌåÐÅÏ¢£©¶øÎÅÃû¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬Óû§Éí·Ý¡¢Óû§Ãû¡¢µç×ÓÓʼþµØÖ·£¨Ô¼3000¸ö£©¡¢¹þÏ£ÃÜÂëºÍSkypeµØÖ·µÈ£¬¿ÉÄÜ»¹ÓÐÒ»¸öMAZAÖÎÀíԱʹÓõÄ˽ÓмÓÃÜÃÜÔ¿¡£´Ë±í£¬ÁíÒ»¸ö°µÍøVerifiedÒ²Ôâµ½Á˹¥»÷£¬ÍøÕ¾±»³Á¶¨Ïòµ½¹¥»÷ÕßËù½ÚÔìµÄ·þÎñÆ÷¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/russian-hacker-forums-maza-verified-hacked/
4.Avas·¢ÏÖÖÁÉÙÓÐ100¼ÒÒâ´óÀûµÄÒøÐÐÒѳÉΪUrsnifµÄ¹¥»÷Ö¸±ê

Avast×êÑÐÈËÔ±·¢ÏÖÖÁÉÙÓÐ100¼ÒÒâ´óÀûÒøÐÐÒѳÉΪUrsnif TrojanµÄ¹¥»÷Ö¸±ê¡£UrsnifÓÚ2007Äê³õ´Î±»·¢ÏÖ£¬ÖØÒªÇÔÈ¡Óû§Ãû¡¢ÃÜÂë¡¢ÐÅÓþ¿¨¡¢ÒøÐÐÒµÎñºÍ¸¶¿îÐÅÏ¢µÈÊý¾Ý¡£Í³¼Æ·¢ÏָöñÒâÈí¼þÒѱ»ÓÃÓÚ¹¥»÷ÉϰټÒÒâ´óÀûÒøÐУ¬ºÚ¿Í½öÔÚÒ»´Î¹¥»÷ÖоÍÇÔÈ¡ÁË1700¶à¸öƾ֤¡£´Ë±í£¬DatktraceµÄ×êÑÐÈËÔ±Ò²·¢ÏÖÁËÀûÓøöñÒâÈí¼þÕë¶ÔÃÀ¹úÒ»¼ÒÒøÐеĹ¥»÷»î¶¯¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/115245/cyber-crime/ursnif-targets-italian-banks.html
5.ÃÀ¹úCallX¹«Ë¾AWS S3´æ´¢Í°ÅäÖÃÃýÎóй¶³¬¹ý10Íò¸öÎļþ

vpnMentor·¢ÏÖÃÀ¹úµç»°ÍÆÏú¹«Ë¾CallXµÄAWS S3´æ´¢Í°ÅäÖÃÃýÎóй¶³¬¹ý10Íò¸öÎļþ¡£vpnMentor·¢ÏÖ¸Ãй©µÄ´æ´¢Í°ÖÐ×ܹ²ÓÐ114000¸ö¹«¿ªµÄÎļþ£¬ÆäÖдóÎÞÊýÊÇÏúÊ۵绰µÄÒôƵ¼Í¼¡¢ÎÄ×Ö̸Ìì¼Í¼ÒÔ¼°Ó×ÎÒÉí·ÝÐÅÏ¢£¨PII£©£¨Ô̺¬È«Ãû¡¢¼ÒͥסַºÍµç»°ºÅÂëµÈ£©¡£vpnMentor°µÊ¾£¬ÕâЩй©µÄÊý¾Ý¿É±»ÓÃÀ´ÌáÒéÍøÂç´¹µö¹¥»÷¡¢Ú²Æ»î¶¯ºÍÓÕÆ¹¥»÷µÈ¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/telemarketing-biz-exposes-114000/
6.CompuCom MSPÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬·þÎñÁÙʱÖжÏ

ÃÀ¹úITÍйܷþÎñÌṩÉÌCompuComÔâµ½DarkSideÀÕË÷Èí¼þ¹¥»÷£¬·þÎñÁÙʱÖжϡ£CompuCom¿ÉΪ¹«Ë¾ÌṩԶ³ÌÖ§³Ö¡¢Ó²¼þºÍÈí¼þά½¨ÒÔ¼°ÆäËû¼¼Êõ·þÎñ£¬¿Í»§Ô̺¬Home Depot¡¢»¨ÆìÒøÐÓ×¢Truist BankºÍLowe'sµÈ¡£ÉÏÖÜÄ©£¬Æä¿Í»§·¢ÏÖÎÞ·¨½Ó¼û¸Ã¹«Ë¾µÄÃÅ»§ÍøÕ¾¡£Ö®ºó£¬CompuCom°µÊ¾ÆäÔâµ½Á˹¥»÷£¬²¿ÃÅϵͳÊܵ½Ó°Ï죬µ¼ÖÂijЩ·þÎñ²»³ÉÓ᣾µ÷²é£¬¹¥»÷¿ÉÄܲúÉúÓÚ2ÔÂ28ÈÕ£¬DarkSideÔÚÆä¶à¸öϵͳÉÏ×°ÖÃÁËCobalt Strike Beacons¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/compucom-msp-confirms-ongoing-outage-following-malware-incident/


¾©¹«Íø°²±¸11010802024551ºÅ