Apple°²È«¸üУ¬½¨¸´macOSÖб»ShlayerÀûÓõÄ0day £»CiscoÅû¶LinuxÄÚºËÖпÉÈÆ¹ýKASLRµÄÐÅϢй¶·ì϶

°ä²¼¹¦·ò 2021-04-28

1.Apple°²È«¸üУ¬½¨¸´macOSÖб»ShlayerÀûÓõÄ0day


1.jpg


Apple°ä²¼°²È«¸üУ¬½¨¸´macOS Big Sur 11.3ÖÐÒѱ»ÀûÓõÄ0day¡£°²È«ÍŶÓJamf·¢ÏÖ£¬´Ó2021Äê1ÔÂÆðÍ·¶ñÒâÈí¼þShlayerÀûÓÃÁËÒ»¸ö0day£¨CVE-2021-30657£©£¬À´ÈƹýAppleµÄÎļþ¸ôÀë¡¢GatekeeperºÍ¹«Ö¤°²È«²é³­£¬²¢ÏÂÔØµÚ¶þ½×¶ÎËùʹÓõÄpayload¡£´Ë±í£¬Õâ´Î¸üл¹½¨¸´ÁËiOS¡¢iPadOSºÍwatchOSÖеĶà¸ö0day£¬Ô̺¬WebKit StorageµÄÄÚ´æ°Ü»µ·ì϶£¨CVE-2021-30661£©¡¢Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-27930£©¡¢ÄÚºËÄÚ´æÐ¹Â¶·ì϶£¨CVE-2020-27950£©ºÍÄÚºËÌØÈ¨ÌáÉý·ì϶£¨CVE-2020-27932£©¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/apple-fixes-macos-zero-day-bug-exploited-by-shlayer-malware/


2.Valve°ä²¼¸üУ¬½¨¸´SteamÖÐÒÑ´æÔÚÁ½ÄêµÄRCE·ì϶


2.jpg


Valve°ä²¼¸üУ¬½¨¸´ÓÎϷƽ̨SteamÖÐÒÑ´æÔÚÁ½ÄêµÄRCE·ì϶¡£¸Ã·ì϶¿ÉÔÚ¶ñÒâÓÎÏ·Ô¼ÇëÖÐÔö³¤ºÅÁ¶ÔÓÎÏ·×ö³ö΢Ó׵ĵĵ÷Õû£¬ÈçÅú¸ÄÓÎϷ˵»°¡¢»îÂç¶È¡¢·Ö±æÂʵÈ¡£µ«ÊÇÓÉÓÚSource RCONºÍ̸ÔÊÐí·þÎñÆ÷ËùÓÐÕßÔÚ·þÎñÆ÷ÖÐÖ´ÐкÅÁÀûÓô˸öÐÔ¿ÉÌáÒéRCE¹¥»÷¡£´Ë±í£¬×êÑÐÈËÔ±»¹ÑÝʾÁËÈôºÎÀûÓø÷ì϶À´ÆëÈ«ÊÕÊÜCS£ºGOÓÎÏ·Íæ¼ÒµÄÕ˺Å¡£×êÑÐÈËÔ±FlorianÓÚ2019Äê»ã±¨Á˸÷ì϶£¬ValveÔÚ2021Äê4ÔÂ17ÈÕ°ä²¼Á˲¹¶¡·¨Ê½£¬²¢·ÖÅäÁËCVE-2021-30481¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2021/04/26/valve-finally-patched-a-steam-rce-vulnerability-that-waited-a-fix-for-two-years/


3.CiscoÅû¶LinuxÄÚºËÖпÉÈÆ¹ýKASLRµÄÐÅϢй¶·ì϶


3.jpg


Cisco Talos³Æ£¬LinuxÄÚºËÖдæÔÚ¿ÉÈÆ¹ýKASLRµÄÐÅϢй¶·ì϶¡£¸Ã·ì϶±»×·×ÙΪCVE-2020-28588£¬Î»ÓÚÔËÐÐLinuxµÄ32λARMÉ豸µÄ/proc/pid/ syscallÖ°ÄÜÖУ¬ÊÇÓÉÓÚ¶ÁÈ¡ÎļþʱÊýֵת»»²»ÕýÈ·¶øÒýÆðµÄ¡£Í¨¹ýʹÓü¸ÌõshellºÅÁ¹¥»÷ÕßÄܹ»Êä³ö24¸ö×Ö½ÚµÄδ³õʼ»¯µÄ²Ö¿âÄڴ棬ÕâЩÄÚ´æÄܹ»±»ÓÃÀ´ÈƹýÄں˵ØÖ·¿Õ¼ä²¼¾ÖËæ»ú»¯£¨KASLR£©¡£Cisco½¨ÒéÓû§¾¡¿ì¸üÐÂÊÜÓ°ÏìµÄ²úÆ·LinuxÄں˰汾5.10-rc4¡¢5.4.66ºÍ5.9.8¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/linux-kernel-bug-wider-cyberattacks/165640/


4.ÓÍÌ﹫˾GyrodataϰȾÀÕË÷Èí¼þ£¬Ô±¹¤Ãô¸ÐÐÅϢй¶


4.jpg


ÃÀ¹úÓÍÌ﹫˾Gyrodataй©£¬ÆäÓÚ2ÔÂ21ÈÕ·¢ÏÖÔâµ½ÁËÀÕË÷Èí¼þ¹¥»÷£¬Ô±¹¤Ãô¸ÐÐÅϢй¶¡£¾­µ÷²éÈ·¶¨£¬ºÚ¿ÍÔÚ2021Äê1ÔÂ16ÈÕÖÁ2ÔÂ22ÈÕÖ®¼äÄܹ»½Ó¼ûÆä²¿ÃÅϵͳºÍÓйØÊý¾Ý£¬¿ÉÄÜй¶ÁËÏÖÔ±¹¤ºÍǰԱ¹¤µÄÓ×ÎÒÐÅÏ¢£¬Ô̺¬µ®ÉúÈÕÆÚ¡¢µØÖ·¡¢Éç»á±£Ïպš¢¼ÝÕÕºÅÂë¡¢»¤ÕÕºÅÂë¡¢W-2˰±íºÍ½¡È«´òËãÐÅÏ¢µÈ¡£½ØÖÁÉÏÖÜËÄ£¬¸Ã¹«Ë¾Ò»ÏòÔÚÁªÏµÊÜÓ°ÏìµÄÔ±¹¤£¬²¢³ÉÁ¢ÁËרÃŵĺô½ÐÖÐÐÄÀ´Ó¦¶Ô¿ÉÄܳöÏÖµÄÎÊÌâ¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/oilfield-services-company-gyrodata-discloses-data-breach


5.Reverb֪ͨ¿Í»§ÒòÆä·þÎñÆ÷ÅäÖÃÃýÎóй¶560¶àÍò±Ê¼Í¼


5.jpg


ReverbÓÚ4ÔÂ26ÈÕÏòÆä¿Í»§·¢ËÍÁËÊý¾Ýй¶֪ͨ£¬Åú×¢ÒÑй¶Á˿ͻ§ÐÅÏ¢¡£ReverbÖØÒªÔÚÏßÏúÊÛÀÔì÷µÈÉ豸£¬Õâ´Îй¶µÄ¿Í»§ÐÅÏ¢Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢PayPalÓʼþµØÖ·ºÍ¶©µ¥ÐÅÏ¢µÈÄÚÈÝ¡£Reverb²¢Î´ÔÚ֪ͨÖÐ×¢Ã÷ËûÃÇÊÇÒòºÎй¶Êý¾ÝµÄ£¬µ«°²È«×êÑÐÔ±Bob Diachenko³ÆÆäÔÚInternetÉÏ·¢ÏÖÁËÒ»¸ö¶³öµÄElasticsearch·þÎñÆ÷£¬ÆäÖÐÔ̺¬³¬¹ý560Íò±Ê¼Í¼¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/reverb-discloses-data-breach-exposing-musicians-personal-info/


6.ºÚ¿ÍÔÚ°µÍø¹«¿ªÃÀ¹ú2.5ÒÚ¸ö¹«ÃñµÄÓ×ÎҺͼÒÍ¥ÐÅÏ¢


6.jpg


2021Äê4ÔÂ22ÈÕ£¬ÃûΪPompompurinµÄºÚ¿ÍÔÚ°µÍø¹«¿ªÁËÒ»¸öÊý¾Ý¿â£¬ÆäÖÐÔ̺¬Á˳¬¹ý250807711¸öÃÀ¹ú¹«ÃñµÄÓ×ÎҺͼÒÍ¥ÐÅÏ¢¡£¸ÃÊý¾Ý¿âÓÐ263 GBµÄ¼Í¼£¬Ô̺¬ÁË1255¸öCSV×ÓÎļþ£¬Ã¿¸ö×ÓÎļþÓÐ200000¸öÁбí£¬Ô̺¬ÐÕÃû¡¢µç»°ºÅÂë¡¢ÓʼþµØÖ·¡¢µ®ÉúÈÕÆÚ¡¢»éÒöÇé¿ö¡¢ÐÔ±ð¡¢ÐÅÓþÄÜÁ¦¡¢ÕþÖÎÁ÷ÅÉ¡¢³µÁ¾ÊýÁ¿¡¢ÊÕÈëÃ÷ϸºÍº¢×Ó¸öÊýµÈÄÚÈÝ¡£Ä¿Ç°Éв»Ã÷ÏÔÊý¾ÝµÄÆðÔ´£¬ÓйØÈËԱй©À´×ÔAmazon Web ServerÉÏÍйܵÄÊ¢¿ªÊ½Apache SOLR¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/hacker-dumps-household-records-of-americans/