MicrosoftÅû¶NETGEAR·ÓÉÆ÷¹Ì¼þÖеĶà¸ö·ì϶£»Avast³ÆÃɹŵÄCA»ú¹¹MonPassÒÑÔâµ½8´Î¹¥»÷
°ä²¼¹¦·ò 2021-07-021.MicrosoftÅû¶NETGEAR·ÓÉÆ÷¹Ì¼þÖеĶà¸ö·ì϶

MicrosoftÅû¶ÁËNETGEAR DGN2200v1ϵÁзÓÉÆ÷¹Ì¼þÖеÄ3¸ö·ì϶£¬¿É±»ÓÃÀ´ÔÚÆóÒµµÄÍøÂçÖкáÏòÒÆ¶¯¡£ÕâЩ·ì϶ΪHTTPdÉí·ÝÑéÖ¤°²È«·ì϶£¬CVSSÆÀ·ÖΪ7.1 ¨C 9.4²»µÈ¡£ÆäÖУ¬ÀûÓõÚÒ»¸ö·ì϶¿ÉÔÚ×Ó×Ö·û´®ÖеÄÒªÇóÖи½¼ÓGET±äÁ¿£¬À´ÈƹýÉí·ÝÑéÖ¤£¬½Ó¼ûÉ豸ÉϵÄÈκÎÒ³Ãæ£»µÚ¶þ¸ö·ì϶¿ÉÓÃÀ´½øÐвàÐÅ·¹¥»÷£¬ÒÔÇÔÈ¡´æ´¢µÄÍ´´¦£»µÚÈý¸ö·ì϶¿ÉÓëÏÈǰµÄÈÏÖ¤ÈÆ¹ý·ì϶½áºÏʹÓã¬À´ÇÔȡ·ÓÉÆ÷µÄÅäÖø´ÔÎļþ¡£Ä¿Ç°£¬NetgearÒѽ¨¸´ÁËÕâЩ·ì϶¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/06/microsoft-discloses-critical-bugs.html
2.Avast³ÆÃɹŵÄCA»ú¹¹MonPassÒÑÔâµ½8´Î¹¥»÷

°²È«¹«Ë¾Avast³ÆÃɹÅ×î´óµÄÖ¤ÊéÐû¸æ»ú¹¹(CA)Ö®Ò»MonPassÔâµ½ÁË8´ÎÍøÂç¹¥»÷¡£Avast°µÊ¾£¬ÆäÔÚMonPassÍйܵĹ«¹²Web·þÎñÆ÷Öз¢ÏÖÁË8ÖÖ·ÖÆçµÄºóÃÅ£¬ÕâÅú×¢¸Ã»ú¹¹¿ÉÄÜÔâµ½8´Î¹¥»÷¡£ÕâЩºóÃÅÓÚ2ÔÂ8ÈÕÖÁ3ÔÂ3ÈÕÆÚ¼äÔڸù«Ë¾µÄ¹Ù·½Ö¤Êé×°ÖÃÀûÓÃÖлîÔ¾£¬ÓÚ3ÔÂÏÂÑ®±»Åû¶¡£×êÑÐÈËÔ±³Æ£¬¹¥»÷ÕßÏÔÈ»ÊdzïËãͨ¹ýÈëÇÖ¿ÉÐÅÈÎµÄÆðÔ´À´ÏòÃɹŵÄÓû§´«²¼¶ñÒâÈí¼þ¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/mongolian-certificate-authority-hacked-eight-times-compromised-with-malware/
3.×êÑÐÈËÔ±·¢ÏÖÀûÓÃBabuk Locker¹¹½¨Æ÷µÄ¹¥»÷»î¶¯

×êÑÐÈËÔ±·¢ÏÖÀûÓÃÁËBabuk Locker¹¹½¨Æ÷µÄ¹¥»÷»î¶¯¡£Babuk LockerÊÇÒ»¿îÀÕË÷Èí¼þ£¬ÓÚ2021ÄêÆðÍ·»îÔ¾£¬Æä¹¹½¨Æ÷ÓÚÉÏÖܱ»°ä²¼µ½ÁËVirusTotalÉÏ¡£Ôڸù¹½¨Æ÷й¶ºó²»¾Ã£¬ºÚ¿ÍÆðͷƵÈÔµÄʹÓÃËüÀ´ÌáÒéÀÕË÷Èí¼þ»î¶¯¡£´Ó±¾ÖܶþÆðÍ·£¬ÓÐЧ»§·´Ó³ÆäÔâµ½ÁËBabuk LockerÀÕË÷Èí¼þ¹¥»÷£¬Êܺ¦ÕßÀ´×ÔÊÀ½ç¸÷µØ¡£µ«ÊÇÓë×î³õµÄBabukÍŻﶯéüÒªÇóÊý°ÙÍòÃÀÔª·ÖÆç£¬Õâ¸öÐµĹ¥»÷ÕßÖ»ÓÐ0.006±ÈÌØ±Ò»òÔ¼210ÃÀÔªµÄÊê½ð¡£´Ë±í£¬¸ÃºÚ¿Í»¹ÔÚÀÕË÷ÐÅÖаѡ°Babuk¡±Æ´×÷ÁË¡°Babuck¡±¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/leaked-babuk-locker-ransomware-builder-used-in-new-attacks/
4.SMBÈ䳿IndexsinasÕë¶ÔÒ½ÁƱ£½¡¡¢·þÎñºÍ½ÌÓýµÈÐÐÒµ

Guardicore Labs×êÑÐÈËÔ±·¢ÏÖSMBÈ䳿IndexsinasÕë¶ÔÒ½ÁƱ£½¡¡¢·þÎñ¡¢½ÌÓýºÍµçÐŵÈÐÐÒµ¡£Indexsinas£¬±ðÃûNSABuffMiner£¬×Ô2019ÄêÒÔÀ´ÆðÍ·»îÔ¾£¬ÖØÒªÊ¹ÓÃÁË3¸ö·ì϶£ºEternalBlue¡¢DoublePulsarºÍEternalRomance¡£Guardicore È«Çò´«¸ÐÆ÷ÍøÂç (GGSN)×Ô2019ÄêÆðÍ·×ܹ²¼Í¼ÁËÀ´×Ô1300¶à¸ö·ÖÆçÆðÔ´µÄ2000ÂŴι¥»÷£¬ÆäÖдó¶àλÓÚÃÀ¹ú¡¢Ô½ÄϺÍÓ¡¶È¡£×êÑÐÈËÔ±³Æ£¬¹¥»÷Õß¼«¶ÈÉóÉ÷£¬C2·þÎñÆ÷¶¼ÔÚº«¹ú²¢¶¼Êܵ½Á˸߶ȱ£»¤£¬×°ÖÃÁ˲¹¶¡ÇÒûÓÐÏò»¥ÁªÍøÂ¶³öÓÐÓàµÄ¶Ë¿Ú¡£
ÔÎÄÁ´½Ó£º
https://www.guardicore.com/labs/smb-worm-indexsinas/
5.¸çÂ×±ÈÑǵ±¾Ö¿ÛÁô´«²¼¶ñÒâÈí¼þGoziµÄÂÞÂíÄáÑǺڿÍ

¸çÂ×±ÈÑǵ±¾Ö¿ÛÁôÁËÂÞÂíÄáÑǺڿÍMihai Ionut Paunescu¡£ËûÒòÔÚ2007ÄêÖÁ2012ÄêÀûÓöñÒâÈí¼þGoziϰȾÁ˳¬¹ý100ÍòÌ¨ÍÆËã»ú¶ø±»ÃÀ¹úͨ¼©¡£GoziÓÚ2007Äê³õ´Î±»·¢ÏÖ£¬Ï°È¾ÁËÖÁÉٰ˸ö¹ú¶ÈµÄÍÆËã»ú£¬Ô̺¬ÃÀ¹ú¡¢µÂ¹ú¡¢·ÒÀ¼ºÍÓ¢¹úµÈ¹ú£¬Ôì³ÉÁËÊýǧÍòÃÀÔªµÄËðʧ¡£PaunescuÔøÓÚ2012ÄêÔÚÂÞÂíÄáÑDZ»²¶£¬µ«²¢Î´±»Òý¶É£¬´Ë¿Ì¸çÂ×±ÈÑÇ×ܼì²ì³¤°ì¹«ÊÒ°ä·¢ÔÚ²¨¸ç´ó¹ú¼Ê»ú³¡¿ÛÁôÁ˸úڿ͡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/119550/cyber-crime/hacker-gozi-virus-arrested.html
6.CISA°ä²¼Õë¶ÔÀÕË÷Èí¼þµÄ°²È«Éó¼Æ×ÔÎÒÆÀ¹À¹¤¾ßRRA

ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö(CISA)°ä²¼ÁËÀÕË÷Èí¼þ¾ÍÐ÷ÆÀ¹À(RRA)£¬ÕâÊÇÆäÍøÂ簲ȫÆÀ¹À¹¤¾ß(CSET)µÄÐÂÄ£¿é¡£RRAÊÇÒ»ÖÖ°²È«Éó¼Æ×ÔÎÒÆÀ¹À¹¤¾ß£¬ÓÃÓÚ×éÖ¯ÕмÜÕë¶ÔÆäÐÅÏ¢¼¼Êõ(IT)¡¢ÔËÓª¼¼Êõ(OT)»ò¹¤Òµ½ÚÔìϵͳ(ICS)µÄÀÕË÷Èí¼þ¹¥»÷£¬ÒÔ¼°´Ó¹¥»÷Öи´Ô¡£CISA֮ǰ»¹°ä²¼ÁËÓÃÓÚÉó²éMicrosoft Azure Active Directory¡¢Office 365ºÍMicrosoft 365ÖеĹ¥»÷»î¶¯µÄ¹¤¾ßAviary¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/cisa-releases-new-ransomware-self-assessment-security-audit-tool/


¾©¹«Íø°²±¸11010802024551ºÅ