Apple°²È«¸üУ¬½¨¸´iOSºÍmacOSÖÐÒѱ»ÀûÓõÄ0day£»Ï£À°µÚ¶þ´ó³ÇÊÐThessalonikiÔâµ½¹¥»÷ÊÐÕþ·þÎñÖжÏ
°ä²¼¹¦·ò 2021-07-271.Apple°²È«¸üУ¬½¨¸´iOSºÍmacOSÖÐÒѱ»ÀûÓõÄ0day

Apple°ä²¼Á˰²È«¸üУ¬½¨¸´ÁËiOSºÍmacOSÖÐÒѱ»ÔÚÒ°ÀûÓõÄ0day¡£¸Ã·ì϶׷×ÙΪCVE-2021-30807£¬ÊÇÓÃÓÚÖÎÀíÆÁĻ֡»º³åÇøµÄÄÚºËÀ©´óIOMobileFramebufferÖеÄÄÚ´æ°Ü»µ·ì϶¡£¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÔÚÖ¸±êÉ豸ÉÏʹÓÃÄÚºËȨÏÞÖ´ÐÐËÁÒâ´úÂ룬²¢ÆëÈ«½ÚÔìÉ豸¡£¸Ã¹«Ë¾³Æ·ì϶¿ÉÄÜÒѱ»»ý¼«ÀûÓ㬵«²¢Î´Ð¹Â©ÓйØÕâЩ¹¥»÷µÄÈÎºÎÆäËûÐÅÏ¢¡£ÕâÊÇAppleÔÚ½ñÄ꽨¸´µÄµÚ13¸ö0day¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/apple/apple-fixes-zero-day-affecting-iphones-and-macs-exploited-in-the-wild/
2.Ï£À°µÚ¶þ´ó³ÇÊÐThessalonikiÔâµ½¹¥»÷ÊÐÕþ·þÎñÖжÏ

Ï£À°µÚ¶þ´ó³ÇÊÐÈøÂÞÄá¼Ó£¨Thessaloniki£©Ôâµ½ÍøÂç¹¥»÷£¬ÊÐÕþ·þÎñÁÙʱÖжϡ£¸ÃÊи±Êг¤Giorgos Avarlis³Æ¹¥»÷²úÉúÔÚ2021Äê7ÔÂ23ÈÕ£¬·¢ÏÖºó¸ÃÊе±¼´¹ØÁË·þÎñºÍwebÀûÓ÷¨Ê½¡£´Ë±í£¬¹¥»÷ÕßÒѾװÖÃÁËÒ»ÖÖ¶ñÒⲡ¶¾²¢ÒªÇóÖ§¸¶Êê½ðÀ´½âËøÎļþ£¬µ«²¢Î´Ð¹Â©ÆäÊÇ·ñÖ§¸¶ÁËÊê½ð»òÖ§¸¶Á˼¸¶àÇ®¡£Avarlis»¹°µÊ¾£¬ÊÐÕþµ±¾ÖµÄËùÓÐÎļþ¶¼Êǰ²È«µÄ£¬µ«ÈÔδȷ¶¨¹¥»÷µÄÆðÔ´¡£
ÔÎÄÁ´½Ó£º
https://www.thenationalherald.com/archive_general_news_greece/arthro/cyberattack_shuts_down_services_in_greece_s_second_largest_city-2960445/
3.×êÑÐÍŶӷ¢ÏÖ¹¥»÷ÕßÀûÓÃArgo WorkflowsÍÚ¿óµÄ»î¶¯

Intezer×êÑÐÍŶӷ¢ÏÖ¹¥»÷ÕßÀûÓÃÅäÖÃÃýÎóµÄArgo WorkflowsµÄÍÚ¿ó»î¶¯¡£Argo WorkflowsÊÇÒ»¸ö¿ªÔ´µÄ¡¢ÈÝÆ÷ÔÉúµÄ¹¤×÷Á÷ÒýÇæ£¬ÔÚKubernetes(K8s)¼¯ÈºÉÏÔËÐС£×êÑÐÈËÔ±·¢ÏÖһЩȨÏÞÅäÖÃÃýÎóµÄÊ·ý£¬ÔÊÐí¹¥»÷Õß½Ó¼ûÊ¢¿ªµÄArgo½ÚÔìÃæ°å£¬²¢ÀûÓø÷ÀàMonero¿ó¹¤ÈÝÆ÷×°ÖÃ×Ô¼ºµÄ¶ñÒâWorkflows£¬Ô̺¬kannix/monero-miner¡£×êÑÐÈËÔ±³Æ£¬ÒÑ·¢ÏÖÊý°Ù¸öÅäÖÃÃýÎóµÄArgo Workflows£¬Òò¶øÄܹ»Ô¤¼Æ½«Óиü´ó¹æÄ£µÄ¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/120544/malware/kubernetes-attacks-argo-workflows.html
4.Sophos·¢ÏÖÀûÓÃDiscord CDNºÍAPIµÄ¹¥»÷»î¶¯¼¤Ôö

Sophos·¢ÏÖDiscord¶ñÒâÈí¼þµÄÊýÁ¿¼¤Ôö£¬Óë2020ÄêÏà±ÈÔö³¤ÁË140±¶¡£µ¼Ö´ËÇ÷ÏòµÄÖØÒªÔÒòÊǺڿÍÒ»ÏòÔÚÀÄÓÃDiscordµÄÄÚÈݽ»¸¶ÍøÂç(CDN)ºÍÀûÓ÷¨Ê½±à³Ì½Ó¿Ú(API)£¬ÆäÖÐCDN±»ÓÃÀ´ÍйܶñÒâÈí¼þ£¬¶øAPI±»ÓÃÀ´ÇÔÈ¡Êý¾ÝÒÔ¼°ÏνӺÅÁîºÍ½ÚÔì·þÎñÆ÷¡£Sophos³Æ£¬4Ô·ÝÔÚDiscordµÄCDNÉϼì²âµ½9500¸ö¶ñÒâURL£¬¶øÔÚ½ÓÏÂÀ´µÄ¼¸¸öÔÂÀÕâ¸öÊý×ÖìÉýÖÁ17000¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/discord-malware-researchers/168096/
5.Coveware°ä²¼2021ÄêQ2ÓйØÀÕË÷¹¥»÷µÄ·ÖÎö»ã±¨

Coveware°ä²¼ÁË2021ÄêQ2ÓйØÀÕË÷¹¥»÷µÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö2021ÄêQ2ÀÕË÷Èí¼þµÄ¾ùÔȸ¶¿î¶î½µÂäÖÁ136576ÃÀÔª£¬ÓëQ1µÄ220298ÃÀÔªÏà±È½µÂäÁË38%¡£2020ÄêÓÐ65%µÄÊܺ¦ÕßÑ¡ÔñÖ§¸¶Êê½ð£¬¶ø2021ÄêQ2Ö»ÓÐ50%µÄÊܺ¦Õ߸¶¿î¡£ÔÚÕâÒ»¼¾¶È×î³£¼ûµÄÀÕË÷Èí¼þ±äÌåΪSodinokibi£¨16.5%£©¡¢ContiV2£¨14.4%£©¡¢Avaddon£¨5.4%£©¡¢Mespinoza£¨4.9%£©ºÍHello Kitty£¨4.5%£©µÈ¡£
ÔÎÄÁ´½Ó£º
https://www.coveware.com/blog/2021/7/23/q2-ransom-payment-amounts-decline-as-ransomware-becomes-a-national-security-priority
6.Vade°ä²¼2021ÄêÉϰëÄêÍøÂç´¹µö¹¥»÷µÄ·ÖÎö»ã±¨

Vade°ä²¼ÁË2021ÄêÉϰëÄêÈ«ÇòÍøÂç´¹µö¹¥»÷µÄ·ÖÎö»ã±¨£¬·ÖÎöÁ˹¥»÷Õß×î°®µÄ25¸öÆ·ÅÆ¡£»ã±¨Ö¸³ö£¬×ÜÌåµÄÍøÂç´¹µöÊýÁ¿ÔÚ2021ÄêQ2¼±¾çÔö³¤£¬5Ô·ݼ¤ÔöÁË281%£¬6Ô·ÝÓÖÔö³¤ÁË284%£¬½öÔÚ6Ô·ݵ±Ô¾ͼì²âµ½42ÒڴεĴ¹µöµç×ÓÓʼþ¡£ÔÚÉϰëÄ꣬·¨¹úũҵÐÅ´ûÒøÐУ¨Cr¨¦dit Agricole£©ÊDZ»¼ÙÒâ×î¶àµÄÆ·ÅÆ£¬ÓÐ17555¸öÓйصĴ¹µöURL£¬Æä´ÎΪFacebook£¨17338¸ö£©ºÍMicrosoft£¨12777¸ö£©¡£
ÔÎÄÁ´½Ó£º
https://www.vadesecure.com/en/blog/phishers-favorites-top-25-h1-2021-worldwide-edition


¾©¹«Íø°²±¸11010802024551ºÅ