Google 5ÔÂAndroid°²È«²¼¸æÖÐÓÐ4¸ö0day±»ÔÚÒ°ÀûÓã»ÃÀ¹úÁ½µ³³ǫ̈ÎåÏî·¨°¸ÒÔ¼ÓÇ¿¶ÔÍøÂç¹¥»÷µÄ·ÀÓùÄÜÁ¦

°ä²¼¹¦·ò 2021-05-21

1.Google 5ÔÂAndroid°²È«²¼¸æÖÐÓÐ4¸ö0day±»ÔÚÒ°ÀûÓÃ


1.jpg


Google Project ZeroÍŶӳÆ£¬Æä°ä²¼µÄ5ÔÂAndroid°²È«²¼¸æÖÐÓÐ4¸ö0dayÒѱ»ÔÚÒ°ÀûÓá£Õâ4¸ö·ì϶ӰÏìÁËQualcomm GPUºÍArm Mali GPUÇý¶¯·¨Ê½×é¼þ£¬±ðÀëΪ¿ªÊͺóʹÓ÷ì϶£¨CVE-2021-1905£©¡¢µØÖ·×¢Ïúʧ°ÜÇé¿ö´¦Öò»µ±£¨CVE-2021-1906£©¡¢GPUÄÚ´æ²Ù×÷²»µ±£¨CVE-2021-28663£©ºÍÌáȨ·ì϶£¨CVE-2021-28664£©¡£×êÑÐÈËÔ±½¨ÒéÓû§¾¡¿ì×°ÖÃ×îиüС£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/118089/mobile-2/android-4-zero-day-flaws.html


2.×êÑÐÈËÔ±Åû¶±¼ÌÚµÄMBUXÐÅÏ¢ÓéÀÖϵͳÖеĶà¸ö·ì϶


2.jpg


×êÑÐÈËÔ±Åû¶Á˱¼ÌÚÓû§ÂÄÀú£¨MBUX£©ÐÅÏ¢ÓéÀÖϵͳÖеÄ5¸ö·ì϶¡£ÕâЩ·ì϶±ðÀëΪCVE-2021-23906¡¢CVE-2021-23907¡¢CVE-2021-23908¡¢CVE-2021-23909ºÍCVE-2021-23910£¬¿É±»ÓÃÀ´Äܹ»Èƹý³µÁ¾µÄ·ÀµÁ±£»¤ÉõÖÁ½ÚÔì³µÁ¾£¬Èç´ò¿ª·ÕΧµÆ»ò´ò¿ª´ò¿ªÕÚÑôÕֵȲÙ×÷¡£×êÑÐÈËÔ±»¹·¢ÏÖÁ˶àÖÖ¹¥»÷³¡¾°£¬Ô̺¬ÀûÓÃä¯ÀÀÆ÷µÄJavaScriptÒýÇæ¡¢Wi-FiоƬ¡¢À¶ÑÀ²Ö¿â¡¢USBÖ°ÄÜ»òµÚÈý·½ÀûÓ÷¨Ê½½øÐй¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/118081/hacking/mercedes-benz-hack.html


3.ÃÀ¹úÁ½µ³³ǫ̈ÎåÏî·¨°¸ÒÔ¼ÓÇ¿¶ÔÍøÂç¹¥»÷µÄ·ÀÓùÄÜÁ¦


3.jpg


ÃÀ¹ú¶àÒéÔººÓɽ°²È«Î¯Ô±»áÓÚ±¾ÖÜһͨ¹ýÁËÎåÏî·¨°¸£¬ÒÔ¼ÓÇ¿¶ÔÍøÂç¹¥»÷µÄ·ÀÓùÄÜÁ¦¡£ÕâЩ·¨°¸Ô̺¬£ºH.R. 2980£¬¡¶ÍøÂ簲ȫ·ì϶²¹¾È·¨°¸¡·£»H.R. 3138£¬¡¶Öݺʹ¦ËùÍøÂ簲ȫ¸Ä½ø·¨°¸¡· £»H.R. 3223£¬¡¶CISAÍøÂçÑÝϰ·¨¡·£»H.R. 3243£¬¡¶¹Ü·°²È«·¨¡·£»H.R. 3264£¬¡¶ºÓɽ°²È«¹Ø¼üÁìÓò·¨°¸¡·¡£ÕâЩ·¨°¸ÊǺÓɽ°²È«Î¯Ô±»áÕë¶Ô×î½üµÄÍøÂç¹¥»÷¶øÌá³öµÄ£¬¾Ý±¨Â·Colonial PipelineÖ§¸¶ÁË500ÍòÃÀÔªÊê½ð£¬µ«²¢Ã»ÓÐ×èÖ¹¶«±±¸÷ÖÝȼÁϵĴó¹æÄ£Ç·È±¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-introduces-bills-to-secure-critical-infrastructure-from-cyber-attacks/


4.Win10×îÐÂÀÛ»ý¸üпɵ¼ÖÂTeamsµÅצÓÃÎÞ·¨µÇ¼


4.jpg


Windows 10 1909 KB5003169ÀÛ»ý¸üе¼ÖÂMicrosoft 365Óû§ÎÞ·¨µÇ¼Teams¡¢OutlookºÍOneDrive¡£Óû§»ã±¨£¬ÆäÔÚ³¢ÊԵǼʱ»áÏÔʾÃýÎó´úÂë80080300£¬²¢³öÏÖ¡°ÎÒÃÇÓöµ½ÁËÎÊÌâ¡£ÔÚ³ÁÐÂÏνӡ­¡±µÄÌáÐÑ£¬ÒªÇóÓû§³ÁÐÂÆô¶¯¸Ã·¨Ê½¡£Î¢Èí°µÊ¾£¬Õâ´ÎÖжÏÊÂÎñÊÇÓÉÓÚ¸üÐÂÖеÄÒ»¸ö´úÂëÎÊÌ⵼ֵģ¬Ö»Ó°ÏìÁ˲¿ÃÅÓû§£¬¿Éͨ¹ý³ÁÐÂÆô¶¯Windows 10½øÐн¨¸´¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/recent-windows-10-update-blocks-microsoft-teams-outlook-logins/


5.TeamBMSÒòAWS S3´æ´¢Í°ÅäÖÃÃýÎóй¶2Íò¶àÓû§ÐÅÏ¢


5.jpg


Website Planet·¢ÏÖ£¬FastTrack Reflex Recruitment£¨ÏÖΪTeamBMS£©ÒòAWS S3´æ´¢Í°ÅäÖÃÃýÎóй¶ÁË2Íò¶àÓû§ÐÅÏ¢¡£¸Ã¹«Ë¾ÖØÒª´Óʹ¹ÖþÖÎÀíϵÍÂäìÓòµÄÕÐÆ¸¹¤×÷£¬ÏîÄ¿Ô̺¬Î²¼ÀûÇò³¡¡¢°ÂÁÔ쥿ËÔ˶¯³¡ºÍϣ˼ÂÞ5ºÅº½Õ¾Â¥µÈ¡£Õâ´Îй¶ÁË21000¸öÎļþ£¬Ô̺¬Óû§µÄµç×ÓÓʼþµØÖ·¡¢È«Ãû¡¢ÊÖ»úºÅÂë¡¢¼Òͥסַ¡¢Éç½»ÍøÂçURL¡¢µ®ÉúÈÕÆÚ¡¢»¤ÕÕºÅÂëºÍÉêÇëÈËÕÕÆ¬µÈ¡£×êÑÐÈËÔ±´§¶È£¬Õâ´Îй¶ÊÇÓɸù«Ë¾µÄIT·þÎñÌṩÉ̵¼ÖµÄ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/recruiters-cloud-snafu-exposes/


6.Paloalto°ä²¼2021ÄêCortex XpanseÍþв·ÖÎö»ã±¨


6.jpg


Paloalto°ä²¼ÁË2021ÄêCortex XpanseÍþв·ÖÎö»ã±¨¡£¸Ã»ã±¨´Ó2021Äê1Ôµ½3Ô£¬¶ÔÈ«Çò50¼ÒÆóÒµµÄ5000Íò¸öIPµØÖ·½øÐÐÁË¼à¿ØÉ¨Ã裬ÒÔÏàʶ¹¥»÷ÕßÄܶà¿ìµØ¼ø±ð³ö¿É±»ÀûÓõÄϵͳ¡£¹Ø¼ü·ì϶µÄ¹«¿ªÅû¶,»áÒý·¢¹¥»÷ÕߺÍITÖÎÀíÔ±Ö®¼äµÄ½ÏÁ¿£º¹¥»÷ÕßҪѰÕÒÏàÒ˵ÄÖ¸±ê£¬¶øITÈËÔ±Òª½øÐзçÏÕÆÀ¹ÀºÍ×°ÖñØÒªµÄ²¹¶¡¡£»ã±¨Ö¸³ö£¬¹¥»÷Õß¿ÉÄÜÔÚ0day¹«¿ªºóµÄ15·ÖÖÓÄÚ¶ÔÆä½øÐÐɨÃ裬¶øÕë¶ÔMicrosoft ExchangeÖеķì϶£¬¹¥»÷ÕßÐж¯µÃ¸ü¿ì£¬ÔÚ²»µ½Îå·ÖÖӵŦ·òÄÚ¼´¼ì²âµ½ÁËɨÃè¡£


Ô­ÎÄÁ´½Ó£º

https://start.paloaltonetworks.com/asm-report