΢ÈíÕý×ÅÊÖµ÷²éй¶Exchange·ì϶ϸ½ÚµÄ°²È«³§ÉÌ £»GoogleÔÙ·¢²¹¶¡£¬½¨¸´½ñÄêµÚ3¸ö±»ÀûÓõÄchrome 0day

°ä²¼¹¦·ò 2021-03-17

1.΢ÈíÕý×ÅÊÖµ÷²éй¶Exchange·ì϶ϸ½ÚµÄ°²È«³§ÉÌ


1.jpg


΢ÈíĿǰÕý×ÅÊÖµ÷²éй¶ÁËMicrosoft Exchange·ì϶ϸ½ÚµÄ°²È«³§ÉÌ¡£ÔÚ²¹¶¡°ä²¼Ö®Ç°£¬Î¢ÈíÒÑÓÚ2ÔÂ23ÈÕ½«¸Ã·ì϶µÄPoC´úÂë·¢Ë͸øÁ˲ÎÓëMicrosoft Active Protections´òË㣨Mapp£©µÄÍøÂ簲ȫ¹«Ë¾£¬Éæ¼°Ô¼80¸ö×éÖ¯¡£Î¢Èí°µÊ¾£¬´Ë¿ÌÓÃÓÚ¹¥»÷µÄ·ì϶ÀûÓù¤¾ßÓëÆäÆäʱ¹²ÏíµÄPoC´úÂëÀàËÆ¡£Òò¶ø£¬Î¢ÈíÒÉ»óÕâ´ÎÕë¶ÔMicrosoft Exchange·þÎñÆ÷µÄ¹¥»÷º£³±Ó밲ȫ³§ÉÌй¶·ì϶ÐÅÏ¢ÓйØ£¬²¢°µÊ¾ÈôÊÇÊÇMAPP¹«Ë¾Ð¹Â¶ÁËÓйØÐÅÏ¢£¬ËûÃǽ«¿ª³ý¸Ã³ÉÔ±¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/microsoft-investigates-potential-tie-between-partner-firm-and-potential-exchange-bug-leak/


2.GoogleÔÙ·¢²¹¶¡£¬½¨¸´½ñÄêµÚ3¸ö±»ÀûÓõÄchrome 0day


2.jpg


GoogleÓÚ±¾Ôµڶþ´Î°ä²¼²¹¶¡£¬½¨¸´½ñÄêµÚ3¸ö±»ÀûÓõÄchrome 0day¡£¸Ã·ì϶´æÔÚÓÚBlinkÖУ¬ÊÇÒ»¸ö¿ªÊͺóʹÓ÷ì϶£¨CVE-2021-21193£©£¬CVSSÆÀ·ÖΪ8.8£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë»ò´¥·¢»Ø¾ø·þÎñ״̬¡£³ý´ËÖ®±í£¬Õâ´Î¸üл¹½¨¸´ÁËWebRTCÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2021-21191£©ºÍChromeÑ¡ÏÖеĶѻº³åÇøÒç¶Âí½Å£¨CVE-2021-21192£©µÈÁí±í4¸ö·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/115600/security/google-chrome-0-day.html


3.3DͼÐÎÈí¼þBlenderÔâµ½¹¥»÷£¬¹ÙÍøÁÙʱÎÞ·¨½Ó¼û


3.jpg


3DÍÆËã»úͼÐÎÈí¼þ¹«Ë¾BlenderÔâµ½¹¥»÷£¬¹ÙÍøÁÙʱÎÞ·¨½Ó¼û¡£BlenderÓÚ3ÔÂ15ÈÕÔçÉÏ°ä²¼ÍÆÎijÆÓÉÓںڿ͹¥»÷£¬http£º//blender.orgÍøÕ¾ÔÚÊØ»¤ÖУ¬²¢°µÊ¾½«¾¡¿ì¸´Ô­¸ÃÍøÕ¾¡£Ö®ºó£¬Æä³ÆËùÓпÉÏÂÔØÎļþ¶¼ÒѾ­¹ýУÑ飬Äܹ»°²È«ÏÂÔØ£¬µ«¹ÙÍøºÍÆäËû²©¿Í»¹Ðèά³ÖÀëÏß״̬¡£Ä¿Ç°£¬BlenderÉÐδ°ä²¼ÓйØÕâ´Î¹¥»÷µÄ¸ü¶àÐÅÏ¢£¬ÆäÔâµ½µÄ¹¥»÷ÀàÐÍÒÀȻδ֪¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/blender-website-in-maintenance-mode-after-hacking-attempt/


4.ºÚ¿ÍÔÚ°µÍøÏúÊÛGuns.comµÄÔ´´úÂëºÍÓû§ÓйØÐÅÏ¢


4.jpg


2021Äê3ÔÂ9ÈÕ£¬ºÚ¿ÍÔÚ°µÍøÏúÊÛÃÀ¹úÍøÕ¾Guns.comµÄÔ´´úÂëºÍÓû§ÓйØÐÅÏ¢¡£Õâ´Îй¶Êý¾ÝÔ̺¬Óû§ID¡¢ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢ÃÜÂë¡¢ÎïÀíµØÖ·¡¢ÓʵÝÇøºÅ¡¢³ÇÊÓע״̬¡¢Magneto ID¡¢µç»°ºÅÂëºÍÕÊ»§´´½¨ÈÕÆÚµÅ×û§ÐÅÏ¢£¬ÒÔ¼°ÐÕÃû¡¢ÒøÐÐÃû³Æ¡¢ÕÊ»§ÀàÐͺÍDwolla IDµÈ²ÆÕþÐÅÏ¢¡£´Ë±í£¬¸ÃÍøÕ¾ÖÎÀíÔ±µÄWordPress¡¢MYSQLºÍCloud£¨Azure£©Í´´¦Ò²ÒÑй¶£¬Ô̺¬´¿Îı¾ÌåʽµÄµç×ÓÓʼþ¡¢ÃÜÂë¡¢µÇ¼Á´½ÓºÍ·þÎñÆ÷µØÖ·¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/hacker-dumps-guns-com-database-customers-admin-data/


5.FBI°ä²¼Õë¶Ô½ÌÓý»ú¹¹µÄÀÕË÷Èí¼þPysa¹¥»÷»î¶¯µÄÖÒ¸æ


5.jpg


ÖÒ¸æÖгÆ£¬×Ô2020Äê3ÔÂÆð£¬ºÚ¿ÍÆðÍ·ÀûÓÃPYSAÀÕË÷Èí¼þ¹¥»÷¶à¹úÈ·µ±¾Ö×éÖ¯¡¢½ÌÓý»ú¹¹¡¢Ë½Óª¹«Ë¾ºÍÒ½ÁÆÐÐÒµ¡£Õâ´ÎÕë¶ÔÓ¢¹úºÍÃÀ¹úµÄ12¸öÖݽÌÓý»ú¹¹µÄPYSAÀÕË÷Èí¼þ¹¥»÷»î¶¯¼¤Ôö£¬ÀýÈç¸ßµµ½ÌÓý¡¢K-12ѧÌúÍÉñѧԺ¡£Pysa£¨ÓÖ³ÆMespinoza£©ÓÚ2019Äê10Ô³õ´Î±»·¢ÏÖ£¬Æä»áÔÚ×°ÖÃÀÕË÷Èí¼þ֮ǰ½ûÓÃÖ¸±êϵͳÉϵÄɱ¶¾Èí¼þ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fbi-warns-of-escalating-pysa-ransomware-attacks-on-education-orgs/


6.unit42°ä²¼ÓйضñÒâÈí¼þMiraiбäÌåµÄ·ÖÎö»ã±¨


6.jpg


unit42°ä²¼ÁËÓйضñÒâÈí¼þMiraiбäÌåµÄ·ÖÎö»ã±¨¡£2021Äê2ÔÂ16ÈÕµ½3ÔÂ13ÈÕ£¬unit42µÄ×êÑÐÈËÔ±·¢ÏÖÁËÀûÓÃSonicWall SSL-VPNÖеÄVisualDoor¡¢D-Link DNS-320·À»ðǽÖеÄCVE-2020-25506ºÍNetgear ProSAFE PlusÖеÄCVE-2020-26919µÈ¶à¸öIoT·ì϶µÄ¹¥»÷»î¶¯£¬²¢°µÊ¾ÕâЩ¹¥»÷ÓëMiraiµÄбäÖÖÓйØ¡£´Ë±í£¬¹¥»÷ÕßÔÚ¹¥»÷³É¹¦ºó»áÀûÓÃwgetÏÂÔØShell¾ç±¾£¬¸Ã¾ç±¾½«ÏÂÔØ²¢Ö´ÐÐÕë¶Ô·ÖÆç¼Ü¹¹¶ø±àÒëµÄ¶à¸öMirai¶þ½øÔìÎļþ¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/