΢ÈíÖܶþ°²È«¸üУ¬½¨¸´Ô̺¬3¸ö0dayÔÚÄÚµÄ44¸ö·ì϶£»×êÑÐÈËÔ±³ÆGlowworm¹¥»÷¿Éͨ¹ýÑïÉùÆ÷µçÔ´µÆÇÔÈ¡ÒôƵ
°ä²¼¹¦·ò 2021-08-11
΢Èí°ä²¼2021Äê8ÔµÄÖܶþ°²È«¸üУ¬×ܼƽ¨¸´ÁË44¸ö·ì϶¡£ÆäÖÐÔ̺¬13¸öÔ¶³Ì´úÂëÖ´Ðзì϶¡¢8¸öÐÅϢй¶·ì϶¡¢2¸ö»Ø¾ø·þÎñ·ì϶ºÍ4¸öºýŪ·ì϶¡£Õâ´Î½¨¸´µÄ3¸ö0dayΪWindows Print SpoolerÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-36936£©¡¢ Windows LSAÖеĺýŪ·ì϶£¨CVE-2021-36942£©ÒÔ¼°Windows Update Medic·þÎñÖеÄÌáȨ·ì϶£¨CVE-2021-36948£©¡£´Ë±í£¬×êÑÐÈËÔ±ÒѾ·¢ÏÖ×Ô¶¯ÀûÓÃCVE-2021-36948µÄ¹¥»÷»î¶¯¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2021-patch-tuesday-fixes-3-zero-days-44-flaws/
2.×êÑÐÈËÔ±³ÆGlowworm¹¥»÷¿Éͨ¹ýÑïÉùÆ÷µçÔ´µÆÇÔÈ¡ÒôƵ

±¾¹ÅÀï°²´óѧµÄ×êÑÐÈËÔ±·¢ÏÖÁËÒ»ÖÖÐµĹ¥»÷·½Ê½Glowworm£¬Äܹ»Í¨¹ýÑïÉùÆ÷µçÔ´µÆÇÔÈ¡ÒôƵ¡£×êÑÐÈËÔ±³Æ£¬´ËÀ๥»÷ÊÇͨ¹ýÉ豸¹¦ºÄ±ä¶¯ÒýÆðµÄÉ豸µçÔ´ÅúʾµÆLEDÇ¿¶ÈµÄ΢Ó׵ı䶯À´¸´ÔìÓïÒô¡£ËûÃÇÑÝʾÁËÈôºÎÀûÓôøÓйâµç´«¸ÐÆ÷µÄÍûÔ¶¾µ´Ó35Ã×±í¶Ô×¼±Ê¼Ç±¾µçÄÔµÄÑïÉùÆ÷À´²¶»ñ¶Ô»°£¬²¢·Òë³ÉÓïÒô¡£´Ë±í£¬³¢ÊÔÅú×¢·ÖÆçÔì×÷É̳ö²úµÄºÜ¶à²úÆ·¶¼ÈÝÒ×Ôâµ½Glowworm¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/glowworm-attack-light-flickers-audio/168501/
3.ºÉÀ¼µ±¾Ö°ä·¢ÓÉÓڳ߶ÈÔ½À´Ô½¸´ÔÓ½«ÖÕ³¡Ðû¸æTLSÖ¤Êé

ºÉÀ¼µÐÔÖÊÇ×îºóÒ»¸öÈÔÔÚÔËÐÐ×Ô¼ºµÄÖ¤ÊéÐû¸æ»ú¹¹(CA)µÄÅ·Ã˹ú¶È£¬ÆäÔÚÉÏÖܰ䷢´òËã´Ó2021Äê12ÔÂÆðÍ·ÖÕ³¡Ðû¸æÐµÄTLSÖ¤Êé¡£°ä²¼ÕâÒ»´òËãµÄÔÒòÔ̺¬£ºä¯ÀÀÆ÷Ôì×÷É̶ÔÔËÐмæÈݵÄTLSÖ¤ÊéÐû¸æ»ú¹¹Ìá³öµÄ¼¼ÊõÒªÇó²»ÐÝÌá¸ß£»2019ÄêºÍ2020Äê²úÉúµÄ´óÁ¿°²È«ÊÂÎñÆÈʹÆäΪ¿Í»§¸ü»»ÁË´óÁ¿Ö¤Ê飻´ó²¿Ãŵ±¾Ö¶¼½«ÕâÒ»Á÷³Ì×ªÒÆµ½Ë½Óª¹«Ë¾¡£´Ë±í£¬ºÉÀ¼¹ÙÔ±°µÊ¾ÔÚ¸ùÖ¤Êéµ½ÆÚºó½«²»ÔÙÐøÆÚ¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/dutch-government-to-stop-issuing-tls-certs-because-of-ever-complicated-standards/
4.Synology³ÆStealthWorkerÕë¶ÔÆäNASÉ豸µÄ¹¥»÷¼¤Ôö

Öйų́Í幩¸øÉÌSynology³Æ½üÆÚ½©Ê¬ÍøÂçStealthWorkerÕë¶ÔÆäNASÉ豸µÄ¹¥»÷»î¶¯¼¤Ôö¡£Synology°²È«²¼¸æ°µÊ¾£¬ÕâЩ¹¥»÷ÀûÓÃһЩÒѾÊÜϰȾµÄÉ豸£¬ÊÔͼ²Â²â³£¼ûµÄÖÎÀíÆ¾Ö¤£¬Ôڳɹ¦ºó½«½Ó¼ûϵͳ£¬×¢Èëpayload£¬ÆäÖпÉÄÜÔ̺¬ÀÕË÷Èí¼þ¡£´Ë±í£¬ÊÜϰȾµÄÉ豸¿ÉÄÜ»¹»á¶ÔÆäËû»ùÓÚLinuxµÄÉ豸½øÐй¥»÷¡£¸Ã¹«Ë¾»¹°ä²¼ÁË·À±¸´ËÀ๥»÷µÄ½¨Òé´ëÊ©£¬Ô̺¬Ê¹Óø´Ôӽý¡µÄÃÜÂëºÍ´´½¨Ò»¸öÐÂÕÊ»§²¢½ûÓÃϵͳĬÈϵÄadminÕÊ»§µÈ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/120962/malware/synology-nas-devices-ransomware.html
5.AT&T Alien·¢ÏÖÀûÓÃTelegram·Ö·¢µÄÐÂľÂíFatalRAT

AT&T Alien Labs×êÑÐÈËÔ±×î½ü·¢ÏÖÁËÒ»ÖÖÃûΪFatalRATµÄÐÂľÂí£¬Äܹ»Í¨¹ýÈí¼þµÄÏÂÔØ·ì϶»òTelegram½øÐд«²¼¡£¸Ã¶ñÒâÈí¼þÔÚÆëȫϰȾϵͳ֮ǰ»áÔËÐÐÂŴβâÊÔ£¬²é³ÊÇ·ñ´æÔÚ¶à¸öÐé¹¹»ú²úÆ·¡¢´ÅÅ̿ռ䡢ÎïÀí´¦ÖÃÆ÷ÊýÁ¿µÈ¡£ÆäÓµÓжàÖÖÖ°ÄÜ£ºÈƹý¼ì²â¡¢»ñÈ¡ÏµÍ³ÓÆ¾ÃÐÔ¡¢¼Í¼Óû§¼üÅÌ¡¢ÍøÂçϵͳÐÅÏ¢¡¢Í¨¹ý¼ÓÃܵÄC&CÍ¨Â·ÉøÈëµÈ¡£´Ë±í£¬Ëü»¹¿ÉÄÜ´ÓÖîÈçEdge¡¢Chrome¡¢Firefox¡¢360¡¢Ëѹ·ºÍQQµÈ¶à¶àä¯ÀÀÆ÷ÖвÁ³ýÌØ¶¨Óû§ÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/fatalrat-new-trojan-targeting-telegram-533712.shtml
6.ÏãÄζùº«¹ú¹«Ë¾³ÆÆäÔâµ½¹¥»÷µ¼Ö¿ͻ§µÄÐÅϢй¶

ÏãÄζùº«¹ú·Ö¹«Ë¾³ÆÆäÊý¾ÝÖÐÐÄÔÚ8ÔÂ5ÈÕºÍ6Ö®¼äÔâµ½¹¥»÷£¬µ¼Ö¿ͻ§µÄÐÅϢй¶¡£Õâ´Îй¶ÁËÒÑ×¢²á»áÔ±µÄÓ×ÎÒÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢ÉúÈÕ¡¢µç»°ºÅÂë¡¢µØÖ·¡¢ÐԱ𡢵ç×ÓÓʼþµØÖ·ºÍ²úÆ·²É°ìÇåµ¥µÈ¡£¸Ã¹«Ë¾³Æ£¬ÔÚ·¢ÏÖ¹¥»÷ºóËüµ±¼´²ÉÈ¡Ðж¯²éÃ÷ÊÂÎñÔÒò£¬²¢×èÖ¹Á˹¥»÷Õß¶ÔÆäÊý¾Ý¿âµÄ·¸·¨½Ó¼û£¬Ä¿Ç°ÒѾ½¨¸´¸ÃÍøÕ¾±»ÀûÓõķì϶¡£ÏãÄζùÉÐδÌá³ö¾ßÌå´òËãÀ´Åâ³¥ÊÜÓ°ÏìµÄ¿Í»§¡£
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/chanel-korea-issues-apology-over-data-theft/


¾©¹«Íø°²±¸11010802024551ºÅ