¸çÂ×±ÈÑÇConinsa Ramon H´æ´¢Í°ÅäÖÃÃýÎó1TBÊý¾Ýй¶

°ä²¼¹¦·ò 2021-09-27

Google°ä²¼´¹Î£¸üн¨¸´ChromeÖпªÊͺóʹÓ÷ì϶


Google°ä²¼´¹Î£¸üн¨¸´ChromeÖпªÊͺóʹÓ÷ì϶.png


GoogleÔÚ9ÔÂ24ÈÕ°ä²¼´¹Î£¸üУ¬½¨¸´½ñÄêµÚ12¸öChromeÖеÄ0day¡£¸Ã·ì϶ΪPortals APIÖеĿªÊͺóʹÓ÷ì϶£¬×·×ÙΪCVE-2021-37973¡£Google³Æ¸Ã·ì϶Òѱ»ÔÚÒ°ÀûÓ㬲¢Î´Åû¶Óйش˷ì϶µÄ¾ßÌåÐÅÏ¢¡£¸Ã·ì϶ÊÇÔÚApple½¨¸´CVE-2021-30869Ö®ºóµÄµÚ¶þÌì°ä²¼µÄ£¬×êÑÐÈËÔ±Ö¸³ö£¬Ëü»¹Äܹ»ÓëWebKitÖеÄÔ¶³Ì´úÂëÖ´ÐнáºÏʹÓᣠ


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/122561/security/google-chrome-zero-day-flaw.html



Cisco°ä²¼¸üУ¬½¨¸´Æä¶à¿î²úÆ·ÖеÄ32¸ö·ì϶


Cisco°ä²¼¸üУ¬½¨¸´Æä¶à¿î²úÆ·ÖеÄ32¸ö·ì϶.png


CiscoÔÚ9ÔÂ22ÈÕ°ä²¼¸üУ¬½¨¸´ÁËÆä¶à¿î²úÆ·ÖеÄ32¸ö·ì϶¡£Õâ´Î½¨¸´Á˺±¼ûµÄCVSSÆÀ·ÖΪ10µÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-34770£©£¬´æÔÚÓÚCisco IOS XEÈí¼þµÄÎÞÏß½ÓÈëµã½ÚÔìºÍÅäÖúÍ̸(CAPWAP)ÖУ¬¿Éµ¼ÖÂRCE»òDoS¡£´Ë±í£¬»¹½¨¸´ÁËÁ½¸öCVSSÆÀ·ÖΪ9.8µÄ·ì϶£¬±ðÀëÊÇSD-WANÖеÄÈí¼þ»º³åÇøÒç¶Âí½Å(CVE-2021-34727)ºÍIOS XEÖеÄÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2021-1619£©¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/critical-cisco-bugs-wireless-sd-wan/174991/



ÃÀ¹úÒ½ÁÆÖÐÐÄUHCÔâµ½Vice SocietyµÄÀÕË÷¹¥»÷


ÃÀ¹úÒ½ÁÆÖÐÐÄUHCÔâµ½Vice SocietyµÄÀÕË÷¹¥»÷.png


±¾ÖÜ£¬ÀÕË÷ÔËÓªÍÅ»ïVice SocietyÐû³ÆËûÃÇÔÚ8Ô·ݹ¥»÷Á˼ÓÀû¸£ÄáÑÇÖݵÄÃÀ¹úÒ½ÁÆÖÐÐÄUnited Health Centers£¨UHC£©¡£Vice SocietyÊÇÒ»¸öÏà¶Ô½ÏеÄÍŻÓÚ2021Äê6ÔÂÆðÍ·»îÔ¾£¬Æä20%µÄÊܺ¦ÕßÊôÓÚÒ½ÁÆÐÐÒµ¡£8ÔÂ31ÈÕ£¬ÖªÁµÈËʿй©UHCÔâµ½ÁËÀÕË÷¹¥»÷£¬ÏµÍÂäÙʱ¹Ø¹Ø¡£¹¥»÷Õß³ÆÒÑÇÔÈ¡»¼ÕßÐÅÏ¢¡¢²ÆÕþÎļþ¡¢»¼Õß³¢ÊÔÊҲ鳭Á˾ֺÍÉ󼯵ÈÐÅÏ¢£¬UHCÉÐδ×÷³ö»ØÓ¦¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/united-health-centers-ransomware-attack-claimed-by-vice-society/



¸çÂ×±ÈÑÇConinsa Ramon H´æ´¢Í°ÅäÖÃÃýÎó1TBÊý¾Ýй¶


¸çÂ×±ÈÑÇConinsa Ramon H´æ´¢Í°ÅäÖÃÃýÎó1TBÊý¾Ýй¶.png


°²È«¹«Ë¾WizCase·¢ÏÖ¸çÂ×±ÈÑÇ·¿µØ²ú¾­¼Í¹«Ë¾Coninsa Ramon HµÄ´æ´¢Í°ÅäÖÃÃýÎ󣬵¼ÖÂ1TBÊý¾Ýй¶¡£Õâ´Îй¶Á˳¬¹ý550Íò¸öÎļþ£¬Éæ¼°µ½10Íò¶à¿Í»§µÄÓ×ÎÒÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢µç»°ºÅÂë¡¢ÓʼþµØÖ·¡¢¾ÓסµØÖ·¡¢Ö§¸¶½ð¶îÒÔ¼°×ʲú¼ÛÖµµÈ¡£´Ë±í£¬×êÑÐÈËÔ±»¹Ôڴ洢ͰÖз¢ÏÖÁ˺óÃÅ´úÂ룬¿É±»ÀûÓÃÀ´¶ÔÍøÕ¾½øÐгÖÐø½Ó¼û£¬²¢½«ºÁÎÞ½äÐĵĽӼûÕß³Á¶¨Ïòµ½Ú¿Æ­ÍøÕ¾¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/09/colombian-real-estate-agency-leak.html



°²È«¹«Ë¾·¢ÏÖÀûÓÃVMware vCenterÖÐRCEµÄ¹¥»÷»î¶¯


°²È«¹«Ë¾·¢ÏÖÀûÓÃVMware vCenterÖÐRCEµÄ¹¥»÷»î¶¯.png


°²È«¹«Ë¾Bad PacketsÔÚ9ÔÂ22ÈÕ·¢ÏÖÀûÓÃVMware vCenterÖÐRCE·ì϶£¨CVE-2021-22005£©µÄ¹¥»÷»î¶¯¡£¸Ã·ì϶ÒÑÔÚ9ÔÂ21ÈÕ½¨¸´£¬×êÑÐÈËÔ±ÔÚ9ÔÂ22ÈÕ16:21(GMT)·¢ÏÖÀ´×ÔÀ´×Ô¼ÓÄôó¡¢ÃÀ¹ú¡¢ÂÞÂíÄáÑÇ¡¢ºÉÀ¼¡¢ÖйúºÍÐÂ¼ÓÆÂµÄ¹¥»÷³¢ÊÔ¡£×êÑÐÈËÔ±ÓÚ9ÔÂ24ÈÕ°ä²¼Á˲»ÆëÈ«·ì϶ÀûÓôúÂ룬BleepingComputerÔÚµ±Ìì17:41·¢ÏÖºÚ¿ÍÀûÓøôúÂëµÄ¹¥»÷»î¶¯¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hackers-exploiting-critical-vmware-vcenter-cve-2021-22005-bug/



Comparitech°ä²¼ÀÕË÷Èí¼þ¶Ô¹É¼ÛÓ°ÏìµÄ·ÖÎö»ã±¨


Comparitech°ä²¼ÀÕË÷Èí¼þ¶Ô¹É¼ÛÓ°ÏìµÄ·ÖÎö»ã±¨.png


ComparitechÔÚ9ÔÂ23ÈÕ°ä²¼ÁËÀÕË÷Èí¼þ¶Ô¹É¼ÛÓ°ÏìµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬¹«Ë¾¹É¼ÛÔÚÀÕË÷¹¥»÷ºóµÄ24Ó×ʱÄڻᱩµø22.9%£¬µ«µÚ¶þÌìµ±¼´»ØÉý£¬µ½µÚ10Ì죬¾ùÔȹɼۻá±È¹¥»÷ǰ¸ü¸ß £»ÔÚËùÓÐÀÕË÷Èí¼þÖУ¬Ryuk¶Ô¹É¼ÛµÄ¸ºÃæÓ°Ïì×î´ó £»Ö»¹ÜÔÚÅû¶¹¥»÷»î¶¯ºó¿Æ¼¼¹«Ë¾µÄ¹É¼ÛÆð³õµø·ù½Ï´ó£¬µ«ËüÃÇÔÚ6¸öÔºóµÄ²û·¢ÓÅÓڷǿƼ¼¹«Ë¾¡£


Ô­ÎÄÁ´½Ó£º

https://www.comparitech.com/blog/information-security/ransomware-share-price-analysis/