TIMÍŶÓÅû¶CA Technologies²úÆ·ÖеĶà¸ö0day £»Î¢Èí³ÆÖÜËĵÄÖжÏÔ´ÓÚ´úÂëȱµãµ¼ÖµÄAzure DNS¹ýÔØ

°ä²¼¹¦·ò 2021-04-06

1.TIMÍŶÓÅû¶CA Technologies²úÆ·ÖеĶà¸ö0day


1.jpg


CA TechnologiesÊÇÃÀ¹úÒ»¼ÒרһÓÚB2BÈí¼þµÄ¿ç¹ú¹«Ë¾£¬ÏúÊÛ½ü200ÖÖ²úÆ·£¬Éæ¼°É¢²¼Ê½ÍÆËã¡¢ÔÆÍÆËã¡¢DevOpsºÍÍÆËã»ú°²È«Èí¼þÒÔ¼°Òƶ¯É豸¡£TIMµÄRed Team ResearchÍŶÓÅû¶ÁËCA eHealth Performance Manager²úÆ·ÖеÄ5¸öзì϶¡£±ðÀëΪÌáȨ·ì϶£¨CVE-2021-28246ºÍCVE-2021-28249£©¡¢¿çÕ¾µã¾ç±¾·ì϶£¨CVE-2021-28247£©¡¢Í¨¹ýSUID/GUIDÎļþµÄÌáȨ·ì϶£¨CVE-2021-28250£©ºÍÉí·ÝÑéÖ¤·ì϶£¨CVE-2021-28248£©¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116268/security/ca-ehealth-performance-manager-flaws.html


2.΢Èí³ÆÖÜËĵÄÖжÏÔ´ÓÚ´úÂëȱµãµ¼ÖµÄAzure DNS¹ýÔØ


2.jpg


΢Èíй©£¬ÉÏÖÜËĵÄÈ«ÇòÁìÓòÄڵķþÎñÖжÏÊÇÓÉ´úÂëȱµãµ¼ÖµÄAzure DNS¹ýÔØÒýÆðµÄ¡£ÖжϲúÉúÔÚÉÏÖÜËÄÏÂÎç5:21×óÓÒ£¬MicrosoftÓû§·¢ÏÔìäÎÞ·¨½Ó¼ûXbox Live¡¢Office¡¢TeamsºÍSkypeµÈ·þÎñ£¬¸ÃÎÊÌâÓÚ6:30±»½â¾ö¡£½üÆÚ£¬Microsoft°ä²¼ÁËÓйطþÎñÖжϵĵ××ÓÔ­Òò·ÖÎö£¨RCA£©£¬³ÆÕë¶ÔAzureÉÏÍйܵÄijЩÓòµÄDNS²éÎÊÒì³£¼¤Ôöµ¼Ö·þÎñÆ÷¹ýÔØ£¬Î¢Èí²¢Î´Ú¹Êͼ¤ÔöµÄÔ­Òò£¬¾Ý´§Ä¦¿ÉÄÜÊÇÓÉÓÚÕë¶ÔijЩÓòµÄDDoS¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-outage-caused-by-overloaded-azure-dns-servers/


3.ÃÀ¹ú½ðÈÚ»ú¹¹RobinhoodµÄ¿Í»§Ôâµ½´¹µö¹¥»÷


3.jpg


Robinhood MarketsÔÚÉÏÖÜËİ䲼ÏòÆä¿Í»§·¢ËÍÓʼþ³Æ£¬Æä²¿Ãſͻ§¿ÉÄÜÒѾ­Ôâµ½´¹µö¹¥»÷¡£RobinhoodÊÇÒ»¼ÒÃÀ¹ú½ðÈÚ·þÎñ»ú¹¹£¬ÆäÊÖ»úÀûÓÿÉÌṩ¹ÉƱºÍ»ù½ðµÄÃâÓ¶½ðÂòÂô£¬½ØÖÁ2020ÄêÒÑÕ¼ÓÐ1300Íò¿Í»§¡£Õâ´Î¹¥»÷»î¶¯Ê¹ÓÃÁËÁ½ÖÖ¹¥»÷ý½éÓÕÆ­Êܺ¦Õߣ¬ÆäÒ»ÊÇÀûÓÃÔ̺¬ÁËαÔìRobinhoodÍøÕ¾Á´½ÓµÄ´¹µöÓʼþ£¬ÓÕʹ½Ó¼ûÕßÊäÈëµÇ¼ʹ´¦ £»ÁíÒ»ÖÖÊÇÀûÓÃÁ˱¨Ë°¼¾£¬ÒªÇóÖ¸±êÏÂÔØÔ̺¬Á˶ñÒâÈí¼þµÄαÔì˰ÊÕÎļþ¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/04/attackers-targeted-robinhood-with.html


4.KasperskyÅû¶Õë¶ÔÔ½Ä϶à¸ö×éÖ¯µÄÍøÂç¼äµý»î¶¯


4.jpg


KasperskyÅû¶ÁËAPT×éÖ¯CycldekÕë¶ÔÔ½Äϵ±¾ÖºÍ¾üÊÂ×éÖ¯µÄÍøÂç¼äµý»î¶¯¡£¸Ã»î¶¯Ê¹ÓÃÁËÃûΪFoundCoreµÄ¶ñÒâÈí¼þ£¬¿É½øÐÐÎļþϵͳ°Ñ³Ö¡¢¹ý³Ì°Ñ³Ö¡¢ÆÁÄ»½ØÍ¼²¶»ñºÍËÁÒâºÅÁîÖ´ÐС£´Ë±í£¬Kaspersky³Æ¸Ã×éÖ¯ÔÚ¸´ÔÓÐÔ·½Ãæ»ñµÃÁ˳ÁÃͽøÈ¡£¬ÀýÈ磬ÆäpayloadµÄ±êÍ·£¨´úÂëµÄÖ¸±êºÍÔ´£©±»ÆëÈ«°þÀ룬ʣϵÄÉÙÊý²¿ÃŵÄÖµÊDz»Á¬¹áµÄ£¬Õâ´ó´óÔö³¤ÁË×êÑÐÈËÔ±¶ÔÆä½øÐзÖÎöµÄÄѶÈ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/spy-operations-vietnam-rat/165243/


5.΢Èí°ä²¼2021Äê3ÔÂSecurity SignalsµÄ·ÖÎö»ã±¨


5.jpg


΢Èí°ä²¼ÁË2021Äê3ÔÂSecurity SignalsµÄ·ÖÎö»ã±¨£¬µ÷²éÁËÀ´×ÔÖйú¡¢µÂ¹ú¡¢ÈÕ±¾¡¢Ó¢¹úºÍÃÀ¹úµÄ1000λÆóÒµ°²È«¾ö²ßÕß¡£»ã±¨·¢ÏÖ£¬´ÓǰÁ½ÄêÖÐÓÐ80£¥µÄÆóÒµÔâµ½ÁËÖÁÉÙÒ»´Î¹Ì¼þ¹¥»÷£¬µ«Ö»ÓÐ29£¥µÄ×éÖ¯·ÖÅäÁËÔ¤ËãÀ´± £»¤¹Ì¼þ¡£NVDÖ¤ÇÐʵ´ÓǰËÄÄêÖУ¬Õë¶Ô¹Ì¼þµÄ¹¥»÷Ôö³¤ÁËÎå±¶ÒÔÉÏ¡£21£¥µÄ¾ö²ßÕßÈÏ¿ÉÎÞ·¨¼à¿Ø¹Ì¼þÊý¾Ý£¬82£¥×é֯ûÓÐ×ÊÔ´À´Õмܹ̼þ¹¥»÷¡£81£¥µÄµÂ¹ú¹«Ë¾¡¢91£¥µÄÃÀ¹ú¡¢Ó¢¹úºÍÈÕ±¾¹«Ë¾ÒÔ¼°95£¥µÄÖйú¹«Ë¾Ô¸ÒâÔÚÕâ¸ö·½Ãæ½øÐÐͶ×Ê¡£


Ô­ÎÄÁ´½Ó£º

https://www.microsoft.com/en-us/secured-corepc


6.Ravelin°ä²¼Óйصç×ÓÉÌÎñڲƭ»î¶¯µÄ·ÖÎö»ã±¨


6.jpg


Ravelin¶ÔÈ«Çò1000¶à¼ÒÉ̼ҽøÐÐÁ˵÷²é£¬°ä²¼ÁËÓйصç×ÓÉÌÎñڲƭ»î¶¯µÄ·ÖÎö»ã±¨¡£»ã±¨ÏÔʾ£¬½«½ü40£¥µÄ¿ìÏûÁãÊÛÉ̽«ÔÚÏßÖ§¸¶Ú²Æ­ÊÓΪ×î´óµÄڲƭ·çÏÕ£¬45%µÄ¹«Ë¾Ëù¾­ÀúµÄÕË»§ÊÕÊÜ(ATO)¹¥»÷ÓÐËùÔö³¤¡£»ã±¨Ô¤²â£¬µç×ÓÉÌÎñÐÐÒµÖеÄڲƭÎÊÌâ¿ÉÄÜ»áÓúÑÝÓúÁÒ£¬ÓÈÆäÊÇËæ×źܶഫͳµÄ¸ß½Ôì·ÅÆ£¨ÈçTopshopºÍDebenhams£©±»ÊÕ¹º²¢ÊµÏÖÒµÎñÈ«ÊýÏòÏßÉÏתÐ͵Äʱ³½¡£


Ô­ÎÄÁ´½Ó£º

https://pages.ravelin.com/retail-fraud-payments-report