QualysÅû¶LinuxÄÚºËÖеı¾µØÌáȨ·ì϶Sequoia£»Win10ÖÐÌáȨ·ì϶SeriousSAMÓ°Ïì½üÁ½Äê°ä²¼µÄ°æ±¾

°ä²¼¹¦·ò 2021-07-22

1.QualysÅû¶LinuxÄÚºËÖеı¾µØÌáȨ·ì϶Sequoia


1.jpg


Qualys×êÑÐÈËÔ±Åû¶ÁËLinuxÄÚºËÖеı¾µØÌáȨ·ì϶Sequoia¡£¸Ã·ì϶׷×ÙΪCVE-2021-33909£¬´æÔÚÓÚÓÃÀ´ÖÎÀíÓû§Êý¾ÝµÄÎļþϵͳ²ã£¬ÊÇÓÉÓÚfs/seq_file.cûÓÐÕýÈ·ÏÞ¶Èseq»º³å·Ö±æÅä¶øµ¼ÖµÄ¡£Qualys³Æ£¬¸Ã·ì϶ӰÏìÁË×Ô2014ÄêÒÔÀ´°ä²¼µÄËùÓÐLinuxÄں˰汾¡£´Ë±í£¬×êÑÐÈËÔ±»¹·¢ÏÖÁËsystemdÖеÄÒ»¸ö²Ö¿âºÄ¾¡µ¼ÖµĻؾø·þÎñ·ì϶£¨CVE-2021-33910£©£¬´æÔÚÓÚ2015Äê4ÔÂÖ®ºó°ä²¼µÄËùÓÐsystemd°æ±¾ÖС£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-linux-kernel-bug-lets-you-get-root-on-most-modern-distros/


2.Win10ÖÐÌáȨ·ì϶SeriousSAMÓ°Ïì½üÁ½Äê°ä²¼µÄ°æ±¾


2.jpg


×êÑÐÈËÔ±Jonas LykkegaardÅû¶ÁËWin10ÖеÄÌáȨ·ì϶SeriousSAM£¬Ó°ÏìÁ˽üÁ½Äê¶à°ä²¼µÄËùÓа汾¡£LykkegaardÔÚ²âÊÔ×îа䲼µÄWin11ʱ·¢ÏÖ£¬¹ÌÈ»WindowsÏÞ¶ÈÁ˵ÍȨÏÞÓû§½Ó¼ûSAM¡¢SECURITYºÍSYSTEMµÈÎļþ¼ÐÖеÄÃô¸ÐÅäÖÃÎļþ£¬µ«ÕâЩÎļþµÄ¸±±¾Ò²±»±£ÁôÔÚShadow Volume Copy´´½¨µÄ±¸·ÝÎļþÖУ¬¶ø×Ô2018Äê11Ô°䲼µÄWindows 10 v1809ÒÔÀ´£¬Î¢ÈíÒ»ÏòûÓÐ×èÖ¹¶ÔÕâЩ±¸·ÝµÄ½Ó¼û¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/serioussam-bug-impacts-all-windows-10-versions-released-in-the-past-2-5-years/


3.Adobe°ä²¼°²È«¸üУ¬½¨¸´Æä7¿î²úÆ·ÖеÄ21¸ö·ì϶


3.jpg


AdobeÔÚ7ÔÂ20ÈÕ±¾Öܶþ°ä²¼Á˰²È«¸üУ¬×ܼƽ¨¸´ÁËÆä7¿î²úÆ·ÖеÄ21¸ö·ì϶¡£Õâ´Î½¨¸´ÁËAdobe After EffectsÖеÄ7¸ö·ì϶£¬ÆäÖÐ5¸öÄܹ»µ¼ÖÂËÁÒâ´úÂëÖ´ÐУ¨CVE-2021-36017¡¢CVE-2021-35993¡¢CVE-2021-35994¡¢CVE-2021-35995ºÍCVE-2021-35996£©¡£´Ë±í£¬»¹½¨¸´ÁËPhotoshopÖеĻº³åÇøÒç³öµ¼ÖµĴúÂëÖ´Ðзì϶£¨CVE-2021-36005£©¡¢Character AnimatorÖеÄËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-36000£©ºÍPreludeÖеÄËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-35999£©µÈ¶à¸öÑϳÁµÄ·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/adobe-patches-21-vulnerabilities-across-seven-products


4.WizCase·¢ÏÖÃÀ¹úµÄ80¶à¸öÊÐÕþµ±¾Ö´æ´¢Í°ÅäÖÃÃýÎó


4.jpg


WizCase×êÑÐÍŶӷ¢ÏÖÃÀ¹úµÄ80¶à¸öÊÐÕþµ±¾Ö´æ´¢Í°ÅäÖÃÃýÎó¡£×êÑÐÈËÔ±·¢ÏÖÃÀ¹ú¶à¸ö³ÇÊеÄÊý¾Ý¾ù´æ´¢ÔÚÃýÎóÅäÖõÄAmazon S3´æ´¢Í°ÖУ¬¶øÕâЩ³ÇÊж¼Ê¹ÓÃÁËÓÉÃÀ¹ú¹«Ë¾PeopleGISÌṩµÄͳһ¿î²úÆ·mapsonline.net¡£Í¨¹ýɨÃè·¢ÏÖÁË114¸öÓëPeopleGISÓйصĴ洢Ͱ£¬ÆäÖÐ28¸öÅäÖÃÕýÈ·£¬Ê£ÏµÄ86¸öÎÞÐèÈκÎÃÜÂë¼´¿É½Ó¼û¡£ÕâЩ¶³öµÄ´æ´¢Í°ÖÐÔ̺¬ÁËÓëÕâЩ³ÇÊÐÓйصÄÊý¾Ý£¬×ܼÆÓг¬¹ý1000 GBµÄÊý¾ÝºÍ³¬¹ý160Íò¸öÎļþ¡£


Ô­ÎÄÁ´½Ó£º

https://www.wizcase.com/blog/us-municipality-breach-report/


5.Shahaf»ã±¨³ÆÒÔÉ«ÁеÄIT¹«Ë¾PionetÔâµ½ÀÕË÷¹¥»÷


5.jpg


Shahaf»ã±¨³Æ£¬ÒÔÉ«ÁÐMalam TimÆìϵÄIT¹«Ë¾PionetÔâµ½ÁËÀÕË÷¹¥»÷¡£Õâ´Î¹¥»÷µ¼ÖÂÁ˸ù«Ë¾µÄºÜ¶àϵͳºÍÆäÉϰٶà¸ö¿Í»§µÄÍøÕ¾Ì±»¾£¬ÆäÖÐÔ̺¬AssutaÒ½Ôº¡¢SonoȼÁϹ«Ë¾ºÍAppleµÄ½ø¿ÚÉÌIdigitalµÈ£¬ÆäÖÐIdigitalµÄ¿Í»§Ô̺¬ÒÔÉ«ÁеçÁ¦¹«Ë¾ºÍÒÔÉ«ÁÐÌú·¹«Ë¾¡£¾Ý³Æ£¬¹¥»÷ÕßÒªÇóÖ§¸¶Ô¼50ÍòÉá¿ÍÀÕ(ÕÛºÏ151861.82ÃÀÔª)Êê½ð£¬²¢ÒªÇóÏȵ±¼´Ö§¸¶5000ÃÀÔªµÄÃÅÂÞ±Ò¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/il-ransomware-attack-on-israeli-it-company-impacts-more-than-100-customers-including-hospitals/


6.Link11°ä²¼2021ÄêÉϰëÄêDDoS¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨


6.jpg


Link11°ä²¼ÁË2021ÄêÉϰëÄêDDoS¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬ÔÚ2021ÄêQ1ºÍQ2Ö®¼ä£¬DDoS»î¶¯Ôö³¤ÁË19%£¬ÆäÖÐһЩ¹¥»÷Á¿³¬¹ýÁË100Gbps¡£Óë2020ÄêÉϰëÄêÏà±È£¬2021ÄêµÄ¹¥»÷´ÎÊýͬ±ÈÔö³¤ÁË33%£»×ÜÌå¹¥»÷´ø¿íÒÀÈ»ºÜ¸ß£¬×î´ó¹¥»÷Á¿Îª555 Gbps£»¹¥»÷´ø¿í¼±¾çÔö³¤£¬Óë2020 H1Ïà±ÈÔö³¤ÁË37%£»2021ÄêÉϰëÄ곬¹ý100 GbpsµÄ¹¥»÷´ÎÊý¶à´ï28´Î¡£


Ô­ÎÄÁ´½Ó£º

https://www.link11.com/en/blog/threat-landscape/link11-report-discovers-record-number-of-ddos-attacks-in-first-half-of-2021/