Dell SupportAssistзì϶ӰÏ쳬¹ý3000ÍòÌ¨ÍÆËã»ú£»Microsoft StoreÈ«ÇòWin10ϵͳÉÏ·þÎñÖжÏ
°ä²¼¹¦·ò 2021-06-251.Dell SupportAssistзì϶ӰÏ쳬¹ý3000ÍòÌ¨ÍÆËã»ú

Eclypsium°²È«×êÑÐÈËÔ±ÔÚDell SupportAssistµÄBIOSConnectÖ°ÄÜÖз¢ÏÖÁË4¸ö·ì϶£¬Ó°Ï쳬¹ý3000ÍòÌ¨ÍÆËã»ú¡£´óÎÞÊýWindowsϵͳµÄ´÷¶ûÉ豸ÉϾùԤװÁËSupportAssistÈí¼þ£¬BIOSConnectÔòÌṩԶ³Ì¹Ì¼þ¸üкͲÙ×÷ϵͳ¸´ÔÖ°ÄÜ¡£ÕâЩ·ì϶±ðÀëΪ²»°²È«µÄTLSÏνÓÎÊÌ⣨CVE-2021-21571£©ºÍ3¸öÒç¶Âí½Å£¨CVE-2021-21572¡¢CVE-2021-21573ºÍCVE-2021-21574£©£¬ÔÊÐí¹¥»÷ÕßÔÚÖ¸±êÉ豸µÄBIOSÖÐÖ´ÐÐËÁÒâ´úÂ룬CVSSÆÀ·ÖΪ8.3£¬Ó°ÏìÁË128¿î´÷¶û±Ê¼Ç±¾µçÄÔ¡¢Æ½°åµçÄÔºĮ́ʽ»ú¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/dell-devices-biosconnect-code-execution-bugs/
2.°ÍÎ÷×î´óÒ½Áƹ«Ë¾Grupo FleuryϰȾÀÕË÷Èí¼þREvil

°ÍÎ÷Grupo Fleury¹«Ë¾Ï°È¾ÀÕË÷Èí¼þREvil£¬ÏµÍÂäÙʱÎÞ·¨½Ó¼û¡£Grupo FleuryÊǰÍÎ÷×î´óµÄÒ½ÁÆÕï¶Ï¹«Ë¾£¬Õ¼ÓÐ200¶à¸ö·þÎñÖÐÐĺÍ10000¶àÃûÔ±¹¤¡£6ÔÂ22ÈÕ£¬¸Ã¹«Ë¾¹ÙÍøÏÔʾϵͳ¹Ø¹Ø£¬µ¼ÖÂÒµÎñÔËÓªÖжϣ¬»¼ÕßÎÞ·¨ÔÚÏßÔ¤Ô¼³¢ÊÔÊÒ¼ì²â»òÆäËûÁÙ´²²é³¡£Grupo FleuryÉÐδÕýʽȷÈÏÆäÔâµ½ÁËÀÕË÷Èí¼þ¹¥»÷£¬µ«±¾µØÃ½ÌåÒÑÈ·ÈÏ´ËΪREvilÀÕË÷Èí¼þ¹¥»÷£¬²¢ÇÒÊê½ðÒªÇóΪ500ÍòÃÀÔª¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/healthcare-giant-grupo-fleury-hit-by-revil-ransomware-attack/
3.BlackBerry·¢ÏÖжñÒâÈí¼þChaChi¶Ô׼ȫÇò½ÌÓý×éÖ¯

BlackBerry·¢ÏÖÒ»ÖÖеÄжñÒâÈí¼þChaChi¶Ô׼ȫÇò½ÌÓý×éÖ¯¡£ChaChiÓÉGoLang±àд£¬ÓÚ2020ÄêÉϰëÄê³õ´Î±»·¢ÏÖ¡£ChaChiµÄÃû×ÖÀ´×ÔÓÚÁ½¸ö¹Ø¼ü×é¼þ£¬Cha shellºÍChi sel£¬Ç°ÕßÊÇ·´Ïòshell£¬¶øºóÕßÓÃÓÚ¶Ë¿Úת·¢¡£¸Ã¶ñÒâÈí¼þ×îÔç±»ÓÃÓÚÕë¶Ô·¨¹ú´¦Ëùµ±¾Ö×éÖ¯µÄ¹¥»÷£¬µ«×î½üÖØÒªÕë¶Ô½ÌÓý×éÖ¯¡£×êÑÐÈËÔ±ÒÔΪ£¬¸ÃľÂíÓÉPYSA/MespinozaÍÅ»ïÓÚ2020ËêÊ׿ª·¢µÄ£¬ÓÃÓÚ½Ó¼ûºÍ½ÚÔìÊÜϰȾµÄϵͳ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/chachi-golang-a-new-go-trojan-focuses-on-attacking-us-schools/
4.еÄÀÕË÷ÍÅ»ïLVËÆºõ¸ü¸ÄÁËREvil¶þ½øÔìpayload

Secureworks·¢ÏÖеÄÀÕË÷ÍÅ»ïLVËÆºõ¸ü¸ÄÁËREvil¶þ½øÔìpayload¡£×êÑÐÈËÔ±·¢ÏÖLVÀÕË÷Èí¼þºÍREvilÔ´´úÂëµÄ´úÂë½á¹¹ºÍÖ°ÄÜÆëȫһÑù£¬´§Ä¦ÆäʹÓÃÁËÊ®Áù½øÔì±à×ëÆ÷Åú¸ÄÁËREvilµÄpayload£¬²¢ÈƹýÁËREvilµÄ·À´Û¸Ä½ÚÔì¡£´Ë±í£¬¸ÃÍŻﻹÊÔͼ·ÂÕÕREvilÔÚ°µÍøÉϳÉÁ¢ÁËÒ»¸öÊý¾ÝÐ¹Â¶ÍøÕ¾£¬µ«ÊǸÃ×éÖ¯´Óδй¶¹ýËûÃÇÔÚÍøÕ¾ÉÏÁгöµÄÊܺ¦ÕßµÄÊý¾Ý£¬ÕâÅú×¢Æä¿ÉÄÜûÓд洢ÇÔÈ¡µÄÊý¾ÝµÄÄÜÁ¦¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/lv-ransomware-gang-hijacks-revils-binary/
5.×êÑÐÈËÔ±·¢ÏÖÕë¶ÔÄÏÑǺÍÖÐÑÇÈ·µ±¾ÖºÍÄÜÔ´×éÖ¯µÄ¹¥»÷

LumenµÄ×êÑÐÈËÔ±·¢ÏÖÕë¶ÔÄÏÑǺÍÖÐÑǵØÓòÈ·µ±¾ÖºÍÄÜÔ´×éÖ¯µÄ¹¥»÷»î¶¯¡£Õâ´Î¹¥»÷ÖÁÉÙÔÚ2021Äê1ÔÂÆðÍ·£¬ÖØÒªÕë¶Ôµ±¾Ö¡¢µçÁ¦µ÷¶ÈºÍµç³§µÈ×éÖ¯£¬Êܺ¦ÕßÖØÒªÉ¢²¼ÔÚÓ¡¶È£¬Æä´ÎΪ°¢¸»º¹¡£ÔÚÕâ´Î¹¥»÷ÖУ¬ºÚ¿ÍʹÓÃÁËеÄÔ¶³Ì½Ó¼ûľÂíReverseRat£¬²¢ÇÒʹÓÃÁËÁ½¸öϰȾý½é£ºÒ»¸öפÁôÔÚÄÚ´æÖУ¬ÁíÒ»¸öÊÇside-loaded£¬Ê¹¹¥»÷ÕßÄܹ»ÔÚÖ¸±êÖÐά³ÖÓÆ¾ÃÐÔ¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/06/pakistan-linked-hackers-targeted-indian.html
6.Microsoft StoreÔÚÈ«ÇòµÄWin10ϵͳÉÏ·þÎñÖжÏ

6ÔÂ23ÈÕ£¬Microsoft StoreÔÚÈ«ÇòÁìÓòÄڵĵÄWin10ϵͳÉÏ·þÎñÖжϡ£Óû§´ÓMicrosoft StoreÏÂÔØÀûÓ÷¨Ê½Ê±£¬Ò»Ïò»á´¦ÓÚ¼ÓÔØÒ³Ãæ¡£×îÖÕ£¬Microsoft Store½«±»ÆëÈ«¹ÒÆð£¬²¢ÇÒÖ»ÄÜͨ¹ý¹¤×÷ÖÎÀíÆ÷»òÔÚ´°¿Ú´¦Óڻ״̬ʱʹÓÃALT+F4À´¹Ø¹Ø¡£±ÀÀ£Ê±£¬ÊÂÎñ²é¿´Æ÷»á¼Í¼һÌõÃýÎóÐÂÎÅ£¬Ö¸³öWindowsÀûÓÃÉ̵êÎÞ·¨Óë²Ù×÷ϵͳ½»»¥¡£½ØÖÁÃÀ¹ú¶«²¿¹¦·ò6ÔÂ23ÈÕÏÂÎç6µã45·Ö£¬¸ÃÎÊÌâÒѱ»½â¾ö¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-store-is-crashing-worldwide-on-windows-10-pcs/


¾©¹«Íø°²±¸11010802024551ºÅ