Apple°ä²¼°²È«¸üУ¬½¨¸´3¸öÒѱ»ÔÚÒ°ÀûÓõÄ0day£»×êÑÐÈËÔ±³ÆWindows IIS·þÎñÆ÷Öеķì϶¿ÉÓ°ÏìWinRM
°ä²¼¹¦·ò 2021-05-251.Apple°ä²¼°²È«¸üУ¬½¨¸´3¸öÒѱ»ÔÚÒ°ÀûÓõÄ0day

Æ»¹ûÒѾ°ä²¼Á˰²È«¸üУ¬½¨²¹3¸öÒѱ»ÔÚÒ°ÀûÓõÄmacOSºÍtvOS 0day¡£ÆäÖеÄÁ½¸öÊÇÄÚ´æ°Ü»µ·ì϶£¨CVE-2021-30663ºÍCVE-2021-30665£©£¬Ó°ÏìÁËApple TV 4KºÍApple TV HDÉ豸¡£µÚÈý¸öÊÇTCC¿ò¼ÜÖеÄÌáȨ·ì϶£¬Ó°ÏìÁËmacOS Big SurÉ豸£¬ÏÖÒѱ»XCSSET¶ñÒâÈí¼þÓÃÀ´ÈƹýmacOSÒþÖÔ±£»¤¡£±¾Ô³õ£¬Apple»¹½¨¸´ÁËWebkitÒýÇæÖеÄÁ½¸öiOS 0day¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/apple-fixes-three-zero-days-one-abused-by-xcsset-macos-malware/
2.ÃÀ¹úÔËͨÒò·¢ËÍ400¶àÍòÀ¬»øÓʼþ±»Ó¢¹ú·£¿î9ÍòÓ¢°÷

ÃÀ¹úÔËͨ£¨Amex£©ÒòÔÚÒ»ÄêÄÚÏò¿Í»§·¢Ëͳ¬¹ý400Íò·âÀ¬»øÓʼþ£¬±»Ó¢¹úÊý¾Ý¼à¹Ü»ú¹¹·£¿î90000Ó¢°÷¡£Ó¢¹úICO³Æ£¬ÔÚ2018Äê6ÔÂ1ÈÕÖÁ2019Äê5ÔÂ21ÈÕ£¬Amex·¢ËÍÁË4098841·âÖ¼ÔÚΪAmex´øÀ´¾¼ÃÀûÒæµÄÓªÏúµç×ÓÓʼþ¡£Òòδ¾ÔÞ³ÉÏòÊÕ¼þÈË·¢ËÍÓªÏúÓʼþ£¬AmexÎ¥·´ÁË2003Äê¡¶ÒþÖԺ͵ç×ÓͨѶÌõÀý¡·£¨PECR£©µÚ22Ìõ¡£Æ¾¾Ý¸ÃÌõ¿î¿É¶ÔÆä´¦ÒÔ×î¸ß50ÍòÓ¢°÷µÄ·£¿î£¬µ«ÒòÆäûÓÐÓÐÒâÎ¥·´PECR£¬½ö·£¿î9Íò£¬AmexÐëÔÚ6ÔÂ17ÈÕ֮ǰ֧¸¶Õâ±Ê·£¿î¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/amex-fined-90-000-for-sending-4-million-spam-emails-in-a-year/
3.΢ÈíÎ´Ðø¶©ExchangeµÄSSLÖ¤Ê飬ChromeÌáÐѲ»ÈݽӼû

ÃÀ¹ú¶«²¿±ê¶¨¹¦·ò2021Äê5ÔÂ23ÈÕÉÏÎç8µãÆðÍ·£¬Óû§·´Ó³ÎÞ·¨µÇ¼ExchangeµÄÍøÕ¾admin.exchange.microsoft.com¡£ÕâÊÇÓÉÓÚ¸ÃÍøÕ¾µÄSSLÖ¤ÊéÒѹýÆÚ¶øMicrosoft½¡ÍüÐø¶©µ¼Öµġ£ÎªÁ˰²È«Æð¼û£¬¹È¸èä¯ÀÀÆ÷ÆëÈ«²»ÈÝÁ˽Ӽû¸ÃÍøÕ¾£¬¶øFirefoxÔòÖÒ¸æÁ´½Ó²»°²È«¡£Microsoft³ÆÓû§Äܹ»Ò»Ê±Ê¹ÓÃhttps://outlook.office.com/ecp/Á´½ÓÀ´½Ó¼û¸ÃÍøÕ¾£¬²¢ÒÑÓÚ5ÔÂ24ÈÕ½â¾ö¸ÃÎÊÌâ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-admin-portal-blocked-by-expired-ssl-certificate/
4.×êÑÐÈËÔ±³ÆWindows IIS·þÎñÆ÷Öеķì϶¿ÉÓ°ÏìWinRM

×êÑÐÈËÔ±im DeVries³ÆWindows IIS·þÎñÆ÷Öеķì϶¿ÉÓ°ÏìWinRM¡£¸Ã·ì϶ÊÇWindows IIS·þÎñÆ÷ʹÓõÄHTTPºÍ̸ջ£¨http.sys£©ÖеÄÔ¶³ÌÖ´ÐдúÂë·ì϶£¬±»×·×ÙΪCVE-2021-31166£¬ÒÑͨ¹ýMicrosoft°ä²¼µÄ5Ô·ݰ²È«¸üн¨¸´¡£ÉÏÖÜÄ©£¬Axel Souchet°ä²¼Á˸÷ì϶µÄPoC£¬¿ÉÀûÓÃÌØÔìµÄÊý¾Ý°üµ¼ÖÂÀ¶ÆÁËÀ»ú¡£µ«ÊÇ£¬Jim DeVries·¢ÏÖËü»¹»áÓ°ÏìÔËÐÐÁËWinRM·þÎñ£¨WindowsÔ¶³ÌÖÎÀí£©µÄWindows 10ϵͳºÍ·þÎñÆ÷¡£Will Dormann³Æ£¬Óг¬¹ý200Íò¸öWinRM·þÎñ¶³öµÄWindowsϵͳÄܹ»Í¨¹ýInternet½Ó¼û¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/118189/security/cve-2021-31166-windows-http-flaw.html
5.Proofpoint°ä²¼2021ÄêQ2ÆóÒµµç×ÓÓʼþ°²È«µÄ»ã±¨

Proofpoint°ä²¼ÁË2021ÄêQ2ÆóÒµµç×ÓÓʼþ°²È«µÄ»ã±¨¡£¸Ã»ã±¨»ùÓÚ25¸ö³ß¶È¶Ô15¸öÆóÒµµç×ÓÓʼþ·þÎñÌṩÉ̽øÐÐÁËÆÀ¹À£¬Éæ¼°Èý¸ö·½Ã棺µ±Ç°²úÆ·¡¢Õ½ÊõºÍÊг¡Õ¼ÓÐÂÊ¡£ÔÚÆÀ¹ÀµÄ¹©¸øÉÌÖУ¬ProofpointÊǽöÓеÄÎå¸öµ±ÏÈÕßÖ®Ò»¡£»ã±¨Ö¸³ö£¬×î¼ÑµÄµç×ÓÓʼþ°²È«½â¾ö¹æ»®½«¿Í»§»·¾³ÓëEDR¡¢WebÄÚÈݰ²È«ÐÔ£¨Ô̺¬ä¯ÀÀÆ÷¸ôÀ룩ÒÔ¼°°²È«ÒâʶºÍÅàѵ£¨SA£¦T£©µÈ½â¾ö¹æ»®¼¯³ÉÔÚһ·¡£
ÔÎÄÁ´½Ó£º
https://www.proofpoint.com/us/resources/analyst-reports/forrester-wave-report-enterprise-email-security
6.Lookout°ä²¼ÓйؽðÈÚ·þÎñµÄÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨

Lookout°ä²¼ÁËÓйؽðÈÚ·þÎñ2019ÄêÖÁ2020ÄêÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£LookoutÊý¾ÝÏÔʾ£¬½ðÈÚ×é֯ÿ¼¾¶È¾ùÔÈÔâ·êµÄÍøÂç´¹µö¹¥»÷Ôö³¤ÁË125£¥£¬¶ñÒâÀûÓ÷¨Ê½Ôö³¤ÁË400£¥£¬Òƶ¯É豸ÖÎÀí£¨MDM£©Ê¹ÓÃÂÊÌá¸ßÁË50£¥£¬ÏÕЩ50£¥µÄ´¹µö¹¥»÷¶¼ÊÔͼÇÔÈ¡¹«Ë¾µÇ¼ʹ´¦£¬½ü20£¥µÄÒÆ¶¯ÒøÐпͻ§¶Ë×°ÓÐľÂíÀûÓ᣸û㱨½¨Òé½ðÈÚ»ú¹¹±ØÒªÑ¡È¡ÏÖ´ú°²È«¼¼ÊõºÍÕ½Êõ£¬À´±£ÕÏÔ±¹¤ºÍ¿Í»§³£ÓÃÉ豸ÉÏά³Ö°²È«ÐÔ¡¢¾ºÕùÁ¦ºÍÓйØÐÔ¡£
ÔÎÄÁ´½Ó£º
https://www.lookout.com/info/financial-services-threat-report-lp


¾©¹«Íø°²±¸11010802024551ºÅ