¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.1.18-1.24£©
2021-01-25
Ò»¡¢ ÈÈÃÅ×ÊѶ
1. Ó¢¹ú¾¯·½ÔÚÈí¼þ¹ÊÕÏÖÐÎóɾ³ýÁË15Íò·Ý¾Ð²¶¼Í¼
¡¾¸ÅÊö¡¿
Ó¢¹úÕþ¸®ÈϿɣ¬ÊÖÒÕ¹ÊÕϵ¼ÖÂÒâÍâɾ³ýÁËÌìϾ¯Ô±Êý¾Ý¿âÖеÄ150,000¸ö¾Ð²¶¼Í¼¡£¡¶Ê±´ú¡·±¨µÀ£¬ÕâÖÖ²Á³ýÊÇÎÞÒâµÄ£¬ÊÇÈËΪ¹ýʧÔì³ÉµÄ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.hackread.com/uk-police-deleted-arrest-records-technical-glitch/
2. Ò»ÌõÏÂÁî¸ã»µÓ²ÅÌ£¬Windows10Õâ¸öÁãÈÕÎó²îÄê¾ÃʧÐÞ
¡¾¸ÅÊö¡¿
Microsoft Windows 10ÖÐÒ»¸öδÐÞ²¹µÄÁãÈÕÎó²îÔÊÐí¹¥»÷ÕßʹÓõ¥ÐÐÏÂÁîÆÆËðNTFSÃûÌõÄÓ²ÅÌ¡£¹¥»÷Õß¿ÉÒÔ½«ÕâÌõÏÂÁî¿ÉÒÔÒþ²ØÔÚWindows¿ì½Ý·½·¨Îļþ¡¢ZIP´æµµ¡¢Åú´¦Öóͷ£Îļþ»òÆäËûÖÖÖÖʸÁ¿ÖУ¬ÒÔ´¥·¢Ó²ÅÌÇý¶¯Æ÷¹ýʧ£¬Ë²¼äÆÆËðÎļþϵͳË÷Òý¡£
¡¾²Î¿¼Á´½Ó¡¿
3. COVID-19ÒßÃçÖ÷ÌâÔÚÚ²ÆÍýÏëÖÐÒ»Á¬±£´æ
¡¾¸ÅÊö¡¿
Çå¾²¹«Ë¾ProofpointµÄÑо¿Ö°Ô±ÕýÔÚ×·×Ù¼¸ÖÖʹÓÃCOVID-19ÒßÃçÖ÷Ìâµç×ÓÓʼþµÄÚ²ÆÍýÏ롣ƾ֤ProofpointµÄ˵·¨£¬ÕâЩÍýÏë°üÀ¨ÉÌÒµµç×ÓÓʼþй¶թƣ¬´øÓжñÒ⸽¼þµÄÓʼþ£¨ÓÃÓÚת´ï¶ñÒâÈí¼þ£©ºÍÍøÂç´¹ÂÚµç×ÓÓʼþ£¬ÕâЩµç×ÓÓʼþÖ¼ÔÚÍøÂçÆ¾Ö¤-°üÀ¨Microsoft Office 365µÄÓû§ÃûºÍÃÜÂë¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.inforisktoday.com/covid-19-vaccine-themes-persist-in-fraud-schemes-a-15783
4. Æ»¹û¹«Ë¾ÏòÁ½ÃûÇÔÌýÆ÷ÉͽðÁÔÈËÖ§¸¶ÁË5ÍòÃÀÔªµÄÉͽð
¡¾¸ÅÊö¡¿
Á½Ãû°×ñºÚ¿ÍÉù³Æ´ÓApple׬ÁË50,000ÃÀÔª£¬Ôµ¹ÊÔÓÉÊÇËûÃǾٱ¨ÁËÑÏÖØµÄÎó²î£¬Ê¹ËûÃÇ¿ÉÒÔ½øÈ빫˾µÄ·þÎñÆ÷¡£Ó¡¶È°×ñºÚ¿ÍHarsh JaiswalºÍRahul MainiÉù³Æ·¢Ã÷Á˶à¸öÎó²î£¬ÕâЩÎó²îʹËûÃÇ¿ÉÒÔ»á¼ûApple·þÎñÆ÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/113572/hacking/apple-paid-bug-bounty.html
5. ÌØÀÊÆÕÏÂÁîIaaSÌṩÉÌ×·×ÙÍâ¹úÓû§
¡¾¸ÅÊö¡¿
ÌÆÄÉµÂ·ÌØÀÊÆÕ£¨Donald Trump£©ÔÚÖܶþµ£µ±×Üͳʱ´úµÄʱ¼äÒÑδ¼¸ÁË£¬Ðû²¼ÁËÒ»ÏîÐÐÕþÏÂÁҪÇóÃÀ¹ú»ù´¡ÉèÊ©¼´·þÎñÌṩÉÌºÍÆäËûÔÆ·þÎñÌṩÉ̱£´æÓйØÍâ¹ú¿Í»§µÄÏêϸ¼Í¼£¬ÒÔ×ÊÖú×·×ÙÄÇЩʵÑéÍøÂç·¸·¨µÄÈË¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.inforisktoday.com/trump-orders-iaas-providers-to-track-foreign-users-a-15810
6. Nitro PDFÓû§Êý¾Ý¿â´ó¹æÄ£Ð¹Â¶
¡¾¸ÅÊö¡¿
°üÀ¨Áè¼Ý7700ÍòÌõNitro PDFÓû§¼Í¼£¨µç×ÓÓʼþµØµã¡¢Óû§ÃûºÍÃÜÂ룩Êý¾Ý¿â±»µÁ£¬×òÌìÒѱ»ºÚ¿ÍÃâ·Ñ¹ûÕæ×ß©¡£ºÚ¿ÍÐû²¼µÄÕâ¸ö14GBµÄ×ß©Êý¾Ý¿â°üÀ¨77,159,696Ìõ¼Í¼£¬ÆäÖаüÀ¨Óû§µÄµç×ÓÓʼþµØµã¡¢È«Ãû¡¢bcrypt¹þÏ£ÃÜÂë¡¢ÎÊÌâ¡¢¹«Ë¾Ãû³Æ¡¢IPµØµãÒÔ¼°ÆäËûÓëϵͳÏà¹ØµÄÐÅÏ¢¡£¸ÃÊý¾Ý¿âÒѾ±»Ìí¼Óµ½“Have I Been Pwned”й¶¼ì²â·þÎñÖУ¬¸Ã·þÎñʹÓû§¿ÉÒÔ¼ì²éÆäÐÅÏ¢ÊÇ·ñÔÚÊý¾Ýй¶ÖÐ̻¶¡£
¡¾²Î¿¼Á´½Ó¡¿
7. ÔõÑù½¨ÉèÒ»¸öºìÀ¶ÍŶÓÀ´ÔöÇ¿ÄãµÄÍøÂçÇå¾²
¡¾¸ÅÊö¡¿
Çå¾²ÉçÇøÕýÔÚһֱת±ä£¬Éú³¤ºÍÏ໥ѧϰ£¬ÒÔ¸üºÃµØÓ¦¶ÔÈ«ÇòÍøÂçÍþв¡£ÔÚÎÒÃÇеÄÉçÇøÖ®Éù²©¿ÍϵÁеĵÚһƪÎÄÕÂÖУ¬Microsoft²úÆ·ÓªÏú˾ÀíNatalia Godyla ÓëRendition InfoSecµÄÊ×´´ÈË Jake Williams¾ÙÐÐÁËÅÊ̸ ¡£Jake·ÖÏíÁËËûÔÚ×éÖ¯ÄÚ²¿ÔõÑù×éÖ¯ºÍÉú³¤ºìÉ«ºÍÀ¶É«ÍŶӵÄ×î¼Ñʵ¼ù¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.microsoft.com/security/blog/2021/01/21/the-dynamic-duo-how-to-build-a-red-and-blue-team-to-strengthen-your-cybersecurity-part-2/
8. ΢ÈíµÄ±¨¸æÌṩÁËÕû¸öSolarWinds¹¥»÷Á´µÄÏêϸÐÅÏ¢
¡¾¸ÅÊö¡¿
MicrosoftÐû²¼ÁËÒ»·Ýб¨¸æ£¬ÆäÖаüÀ¨SolarWinds¹©Ó¦Á´¹¥»÷µÄÆäËûÏêϸÐÅÏ¢¡£ÐÂÆÊÎöΪ´ÓSolorigate DLLºóÃŵ½Cobalt Strike×°ÔØ»úµÄÒÆ½»ÌṩÁËÁÁµã¡£¹¥»÷Õß½«×¢ÖØÁ¦¼¯ÖÐÔÚ¹¥»÷Á´µÄÕâÁ½¸ö×é³É²¿·ÖÉÏ£¬ÒÔ¾¡¿ÉÄܵØÌӱܼì²â¡£¸Ã±¨¸æÌṩÁËÓйØSolorigateµÚ¶þ½×¶Î¼¤»îµÄÏêϸÐÅÏ¢£¬¸Ã¼¤»îʹ¹¥»÷Õß¿ÉÒÔ½»¸¶Cobalt Strike×°ÔØ»ú£¬ÀýÈçTeardropºÍRaindrop¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/113681/apt/microsoft-solorigate.html?utm_source=rss&utm_medium=rss&utm_campaign=microsoft-solorigate
9. FacebookÏòFBIÌṩÓû§ÌÖÂÛ¹ú»áɽɧÂÒµÄ˽ÈËÐÅÏ¢
¡¾¸ÅÊö¡¿
Ö»¹ÜÊÔͼÔÚ¹ú»áɽɧÂÒÕßÖе»¯FacebookµÄʹÓ㬵«ÔÚÁ¢·¨ÕߵĺôÓõÖ®ºó£¬Õâ¼ÒÉ罻ýÌå¾ÞÍ·ÈÔÏòÁª°îÊÓ²ì¾ÖÌṩÁ˼ÓÈëΧ¹¥µÄÓû§µÄÊý¾Ý£¬°üÀ¨ËûÃǵÄ˽ÈËÐÅÏ¢¡£ÔÚÖÜÈý¶ÔŦԼסÃñ¿ËÀï˹Íи¥·¿Àû£¨Christopher M. Kelly£©ÌáÆðµÄÐÌÊÂËßËÏÖУ¬ËûµÄFacebookÕÊ»§ÉÏÏÔʾÁËËѲéÁî¡£ÔÚ1ÔÂ6ÈÕÃÀ¹ú¹ú»á´óÏÃÔâ¿ñ·çÓêÏ®»÷ºó£¬Áª°îÊÓ²ì¾Ö£¨FBI£©Á¥ÊôÓÚ¿ÀûµÄÕÊ»§ÖÐÐû²¼Á˰üÀ¨ËûµÄÕÕÆ¬µÄFacebookÌû×Ó£¬Ö®ºó£¬ËûÕ÷²ÉÁËËûµÄ˽ÈËÐÂÎÅÒÔ¼°Á´½ÓµÄIPµØµã£¬µç»°ºÅÂëºÍGmailµØµã¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.forbes.com/sites/thomasbrewster/2021/01/21/facebook-gives-fbi-private-messages-of-users-discussing-capitol-hill-riot/
10. Weblogic¶à¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î
¡¾¸ÅÊö¡¿
2021Äê1ÔÂ20ÈÕ£¬AG¹«Ë¾¿Æ¼¼¼à²â·¢Ã÷Oracle¹Ù·½Ðû²¼ÁË2021Äê1ÔÂÒªº¦²¹¶¡¸üÐÂͨ¸æCPU£¨Critical Patch Update£©£¬¹²ÐÞ¸´ÁË329¸ö²î±ðˮƽµÄÎó²î£¬ÆäÖаüÀ¨7¸öÓ°ÏìWebLogicµÄÑÏÖØÎó²î£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ý´Ë´ÎµÄÎó²îʵÏÖÔ¶³Ì´úÂëÖ´ÐС£CVSSÆÀ·Ö¾ùΪ9.8£¬Ê¹ÓÃÖØÆ¯ºóµÍ¡£½¨ÒéÓû§¾¡¿ì½ÓÄɲ½·¥£¬¶ÔÉÏÊöÎó²î¾ÙÐзÀ»¤
¡¾²Î¿¼Á´½Ó¡¿

AG¹«Ë¾ÔÆ







