¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.12.20-2021.12.26£©
2021-12-27
Ò»¡¢ ÈÈÃÅ×ÊѶ
1. ÒÁÀʺڿÍʹÓÃSlack API¹¥»÷ÑÇÖÞº½¿Õ¹«Ë¾
¡¾¸ÅÊö¡¿
¾ÝÑо¿Ö°Ô±³Æ£¬ÒÁÀʵÄÒ»¸öºÚ¿Í×éÖ¯ÕýÔÚʹÓÃÐÂÎÅÆ½Ì¨SlackÉϵÄÃâ·ÑÊÂÇé¿Õ¼ä£¬ÔÚÑÇÖÞijº½¿Õ¹«Ë¾µÄϵͳÖа²ÅÅÁ˺óÃÅ¡£²¢ÌåÏÖ±»³ÆÎªAclipµÄºóÃÅ¿ÉÄÜʹ¹¥»÷ÕßÄܹ»»á¼ûº½¿Õ¹«Ë¾µÄÂÿÍÔ¤¶©Êý¾Ý¡£AclipÃû³ÆÀ´×ÔÃûΪ“aclip.bat”µÄ Windows Åú´¦Öóͷ£¾ç±¾£¬ÄÜͨ¹ýÌí¼ÓÒ»¸ö×¢²á±íÃÜÔ¿½¨É賤ÆÚÐÔ£¬²¢ÔÚÊÜѬȾװ±¸µÄϵͳÆô¶¯Ê±×Ô¶¯Æô¶¯¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN97
2. ¹¥»÷ÕßʹÓÃеÄJoker¶ñÒâÈí¼þ¶ÔAndroidÓû§Ìᳫ¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷Ò»¸ö´Ó Google Play Ó¦ÓÃÊÐËÁÏÂÔØÁè¼Ý500,000´ÎµÄ¶ñÒâAndroidÓ¦Óñ»·¢Ã÷ÍйܶñÒâÈí¼þ£¬¸ÃÓ¦ÓûáÇÄÇĵؽ«Óû§µÄÁªÏµÈËÁбíй¶µ½¹¥»÷Õß¿ØÖƵķþÎñÆ÷£¬²¢ÔÚÓû§²»ÖªÇéµÄÇéÐÎÏÂΪÓû§×¢²á²»ÐèÒªµÄ¸¶·Ñ¸ß¼¶¶©ÔÄ¡£²¢ÌåÏÖ×îÐ嵀 Joker ¶ñÒâÈí¼þÊÇÔÚÃûΪColor Message£¨“com.guo.smscolor.amessage”£©µÄרעÓÚÐÂÎÅת´ïµÄÓ¦ÓóÌÐòÖз¢Ã÷µÄ£¬¸ÃÓ¦ÓóÌÐòÒÑ´Ó¹Ù·½Ó¦ÓóÌÐòÊг¡ÖÐɾ³ý¡£±ðµÄ£¬»¹ÊӲ쵽ģÄâµã»÷ÒÔ´Ó¶ñÒâ¹ã¸æÖлñµÃÊÕÈë²¢ÅþÁ¬µ½Î»ÓÚ¶íÂÞ˹µÄ·þÎñÆ÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN9b
3. ¹¥»÷ÕßʹÓÃDarkWatchman ¶ñÒâÈí¼þÌá³«ÍøÂç´¹ÂÚ¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±ÌåÏÖDarkWatchman ×î³õÊÇÔÚ 11 Ô³õ·¢Ã÷µÄ£¬Æäʱ¹¥»÷Õß×îÏÈͨ¹ý´øÓжñÒâ ZIP ÎļþµÄÍøÂç´¹ÂÚµç×ÓÓʼþ·Ö·¢¶ñÒâÈí¼þ£»ZIP Îļþ°üÀ¨Ò»¸ö¿ÉÖ´ÐÐÎļþ£¬¸ÃÎļþʹÓÃͼ±êαװ³ÉÎı¾Îĵµ¡£´ËÓ¦ÓóÌÐòÊÇÒ»¸ö WinRAR ´æµµ£¬¿É×ÔÐÐ×°ÖÃRATºÍ¼üÅ̼ͼÆ÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN9c
4. ºÚ¿Í´ÓÔ˶¯×°±¸ÍøÕ¾ÇÔÈ¡ÁËÁè¼Ý180ÍòÈ˵ÄÐÅÓÿ¨Êý¾Ý
¡¾¸ÅÊö¡¿
ËĸöÖøÃûµÄÁ¥ÊôÔÚÏßÌåÓý×°±¸ÍøÕ¾×î½üÐû²¼²¢±¨¸æÁË´ó¹æÄ£µÄÍøÂç¹¥»÷¡£²¢ÌåÏÖÔÚÕâ´ÎÍøÂç¹¥»÷ÖУ¬ºÚ¿ÍÈëÇÖ²¢ÇÔÈ¡ÁËÁè¼Ý180ÍòÈ˵ÄÐÅÓÿ¨ÐÅÏ¢£¬ºÚ¿Íй¶ÁËСÎÒ˽¼ÒÐÅÏ¢ºÍÐÅÓÿ¨ÐÅÏ¢¡£ËĸöÍøÕ¾»®·ÖÊÇÔËÐпÍÕ»ÓÐÏÞÔðÈι«Ë¾¡¢ÍøÇò¿ÍÕ» LCC¡¢»¬°å¿ÍÕ»ÓÐÏÞÔðÈι«Ë¾Ï¢Õù¾ö¿ÍÕ»ÓÐÏÞÔðÈι«Ë¾¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN9d
5. ¹¥»÷ÕßʹÓÃαװ³ÉÓÎÏ·Ó¦ÓõÄľÂí¹¥»÷Android×°±¸
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷Ò»¸öÐÅÏ¢ÇÔȡľÂíÒѾͨ¹ý»ªÎªµÄ AppGallery Ó¦ÓÃÊÐËÁ½øÈëÁËÁè¼Ý 900 Íǫ̀ Android ×°±¸¡£Áè¼Ý 190 ¸ö²î±ðµÄÓ¦ÓóÌÐòѬȾÁËľÂí£¬È»ºó±»ºÁÎÞ½äÐĵÄÓû§ÏÂÔØÁËԼĪ 930 Íò´Î¡£²¢ÌåÏÖÌØÂåÒÁľÂíÓÉÒ»¼ÒÃûΪ Doctor Web µÄ¶íÂÞ˹·´¶ñÒâÈí¼þ¹«Ë¾¿ª·¢¡£Dr.Web ½«¸ÃľÂíʶ±ðΪ“Android.Cynos.7.origin”£¬ÕâÊÇÒ»ÖÖÖ¼ÔÚÍøÂçÃô¸ÐÓû§ÐÅÏ¢µÄ Cynos ¶ñÒâÈí¼þµÄÐ޸İ汾¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN9u
6. ¹¥»÷ÕßÈÆ¹ýMicrosoft²¹¶¡À´Èö²¥Formbook ¶ñÒâÈí¼þ
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±¼ì²âµ½Ê¹ÓÃÒ»ÖÖÄܹ»ÈƹýÓ°Ïì Microsoft Office ÎļþÃûÌõÄÒªº¦Îó²î (CVE-2021-40444) µÄ²¹¶¡µÄÐÂÐÍÎó²î¡£¹¥»÷ÕßʹÓùûÕæ¿ÉÓõĿ´·¨ÑéÖ¤ Office Îó²î²¢½«ÆäÎäÆ÷»¯ÒÔÈö²¥ Formbook ¶ñÒâÈí¼þ¡£¹¥»÷ÕßËæºóͨ¹ýÀ¬»øÓʼþ·Ö·¢ÁËԼĪ 36 Сʱ£¬È»ºóËüÏûÊÅÁË¡£Ñо¿Ö°Ô±·¢Ã÷¹¥»÷Õßͨ¹ý½«¶ñÒâ Word Îĵµ·ÅÔÚÌØÖÆµÄ RAR ´æµµÖÐÀ´ÖØÐÂÉè¼ÆÔʼÎó²î¡£½ÏеēÎÞ CAB”ÐÎʽµÄÎó²îʹÓÃÀֳɱܿªÁËÔʼ²¹¶¡¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN9H
7. ¹¥»÷Õßð³ä»ÔÈð¹«Ë¾Ìá³«ÍøÂç´¹ÂÚ¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±ÌåÏÖ»ÔÈð¹«Ë¾£¨Pfizer£©ÒòÉú²úmRNAйÚÒßÃç¶ø³ÉÎªÍøÂç´¹ÂÚ¹¥»÷ÕßµÄÈÈÃÅð³ä¹¤¾ß¡£¹¥»÷Õß2021Äê8ÔÂ15ÈÕ×óÓÒ×îÏȵÄÒ»¸öÍøÂç´¹ÂÚµç×ÓÓʼþÔ˶¯Ã°³äÁË»ÔÈð¹«Ë¾£¬ÊÔͼ´ÓÊܺ¦ÕßÄÇÀïÇÔÈ¡ÉÌÒµºÍ²ÆÎñÐÅÏ¢¡£¹¥»÷ÕßʹÓ÷ÂðÓòÃûÌìÉúµÄµç×ÓÓʼþÕÊ»§£¬·¢ËÍ´¹ÂÚµç×ÓÓʼþ£¬ÒÔÈÆ¹ýÆóÒµ³£¼ûµÄµç×ÓÓʼþ±£»¤½â¾ö¼Æ»®¡£¶øÕâЩ´¹ÂÚÓʼþµÄÖ÷Ìâͨ³£Éæ¼°½ôÆÈ±¨¼Û¡¢ÕбêºÍ¹¤Òµ×°±¸¹©Ó¦µÈ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN9I
8. ¹¥»÷ÕßʹÓÃLog4j2Îó²î´ó¹æÄ£¿ìËÙÈö²¥BillGatesľÂí
¡¾¸ÅÊö¡¿
½üÆÚ£¬Çå¾²Ñо¿Ô±Í¨¹ýÃÛ¹Þ²¶»ñµ½ BillGates ¼Ò×åµÄľÂíÑù±¾£¬¸ÃľÂíͨ¹ý×î½ü±¬·¢µÄ Log4j2 Îó²îÈö²¥¡£²¢ÌåÏÖLog4j2 Îó²îÊÇÓÉËüµÄ lookup ¹¦Ð§Ôì³ÉµÄ£¬¸Ã¹¦Ð§ÔÊÐí¿ª·¢Õßͨ¹ýÐÒéÈ¥¶ÁÈ¡ÇéÐεÄÉèÖã¬ÓÉÓÚδ¶ÔÊäÈë¾ÙÐÐÑÏ¿áµÄÅжϣ¬´Ó¶øÔì³ÉÎó²îµÄ±¬·¢¡£¹¥»÷µÄÍøÂçÊý¾ÝÒ»Ñùƽ³£»á°üÀ¨ÓÐ “jndi” ×Ö·û¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN9X
9. MonongaliaÎÀÉúϵͳÔâÊÜBEC¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±ÌåÏÖλÓÚÎ÷¸¥¼ªÄáÑÇÖݵÄÈý¼ÒÒ½ÔºµÄÎÀÉúϵͳÊܵ½È¦Ì׵Ĺ¥»÷¡£×ÔÊÕµ½¾¯±¨ÒÔÀ´£¬Monongalia Health System ÒѶԸÃÊÂÎñÕö¿ªÊӲ죬·¢Ã÷¸Ã×éÖ¯µÄ¼¸ÃûÔ±¹¤µÄµç×ÓÓʼþÕÊ»§ÔÚ 2021 Äê 5 ÔÂÖÁ 8 ÔÂʱ´úÔâµ½Á˹¥»÷ÕßµÄÈëÇÖ¡£Í¨¹ýÆÆËðµç×ÓÓʼþ£¬¹¥»÷Õß»ñµÃÁ˶ÔÔ±¹¤µç×ÓÓʼþºÍ¸½¼þµÄδ¾ÊÚȨµÄ»á¼û¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN9W
10. Conti×é֯ʹÓÃLog4ShellÎó²îÕë¶Ô VMware vCenter ·þÎñÆ÷Ìᳫ¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷Conti ×éÖ¯ËÆºõ×ÜÊÇÈÈÖÔÓÚѰÕÒѬȾ¹«Ë¾ºÍÈö²¥ÀÕË÷Èí¼þµÄÐÂÒªÁ죬ÓÉÓÚËûÃǾ³£Ê¹ÓÃÎó²îʹÓÃ×÷Ϊ×î³õµÄÈëÇÖǰÑÔ¡£²¢ÌåÏÖLog4Shell ÊÇÒ»¸öΣÏÕµÄÇå¾²ÎÊÌ⣬ÀÕË÷Èí¼þ×éÖ¯ Conti ÕýÔÚʹÓÃËüÀ´¹¥»÷Ò×Êܹ¥»÷µÄ·þÎñÆ÷ÒÔÀÕË÷Êý°ÙÍòÃÀÔª¡£¸Ã×é֯ʹÓà Log4Shell Îó²îרÃÅÕë¶Ô VMware vCenter ·þÎñÆ÷¡£¸ÃÎó²îÓÃÓÚ»á¼û·þÎñÆ÷£¬È»ºóÄܹ»ÔÚÄ¿µÄ¹«Ë¾µÄÍøÂçÖкáÏòÒÆ¶¯¡£ÓëËûÃÇ¿ÉÄÜʹÓÃµÄÆäËûÎó²îʹÓÃÏà±È£¬ÕâÊÇÒ»¸öÏÔ×ŵÄÇø±ð£ºÕâ¸öÎó²îרÃÅÓÃÓÚÔÚÊÜÑ¬È¾ÍøÂçÄÚºáÏòÒÆ¶¯£»¹¥»÷ÕßÒѾÀֳɻñµÃÁ˶Թ«Ë¾ÍøÂçµÄ³õʼ»á¼ûȨÏÞ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN9U

AG¹«Ë¾ÔÆ







