Stratus¹«Ë¾Ñ¬È¾ÀÕË÷Èí¼þ£¬£¬£¬£¬£¬ÍøÂçºÍЧÀÍÔÝʱÖÐÖ¹£» £»£»£»£»£»£»Purple Fox¹¥»÷»î¶¯½ÏÈ¥ÄêÔöÌí600£¥£¬£¬£¬£¬£¬´ï9Íò¶à´Î

Ðû²¼Ê±¼ä 2021-03-25

1.Stratus¹«Ë¾Ñ¬È¾ÀÕË÷Èí¼þ£¬£¬£¬£¬£¬ÍøÂçºÍЧÀÍÔÝʱÖÐÖ¹


1.jpg


Stratus TechnologiesѬȾÀÕË÷Èí¼þ£¬£¬£¬£¬£¬ÍøÂçºÍЧÀÍÔÝʱÖÐÖ¹¡£¡£¡£¡£¡£StratusÊÇ×ÅÃûµÄ¸ß¿ÉÓÃÐÔ²úÆ·ÌṩÉÌ£¬£¬£¬£¬£¬Æä²úÆ·°üÀ¨ztC±ßÑØÅÌËã×°±¸ºÍftServerÈÝ´íЧÀÍÆ÷½â¾ö¼Æ»®µÈ£¬£¬£¬£¬£¬¿Í»§ÎªÒøÐС¢µçÐÅÌṩÉÌ¡¢½ôÆÈºô½ÐÖÐÐĺÍÒ½ÁƱ£½¡»ú¹¹µÈ¡£¡£¡£¡£¡£¸Ã¹«Ë¾³ÆÆäÔÚ3ÔÂ17ÈÕÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬¼ì²âµ½¹¥»÷ºóÁ¬Ã¦¹Ø±ÕÁ˲¿·ÖÍøÂçºÍЧÀÍÒÔ¸ôÀë¹¥»÷£¬£¬£¬£¬£¬°üÀ¨ÆäÈÝ´í²úÆ·µÄЧÀÍActiveService Network£¨ASN£©ºÍStratusЧÀÍÃÅ»§¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/high-availability-server-maker-stratus-hit-by-ransomware/


2.Hobby LobbyÒò´æ´¢Í°ÉèÖùýʧй¶138GBÃô¸ÐÐÅÏ¢


2.jpg


¹¤ÒÕÆ·ÁãÊÛÉÌHobby LobbyÒòAWS´æ´¢Í°ÉèÖùýʧй¶138GBÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬Ó°ÏìÁËÔ¼30ÍòÃûÓû§¡£¡£¡£¡£¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨Óû§ÐÕÃû¡¢²¿·ÖÖ§¸¶¿¨µÄÏêϸÐÅÏ¢¡¢µç»°ºÅÂë¡¢µØµãºÍÓʼþµØµã£¬£¬£¬£¬£¬±ðµÄ»¹°üÀ¨Ó¦ÓóÌÐòµÄÔ´´úÂë¡¢¹«Ë¾Ô±¹¤µÄÐÕÃûºÍµç×ÓÓʼþµØµãµÈ¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬¸Ã´æ´¢Í°Òѱ»±£» £»£»£»£»£»£»¤ÆðÀ´£¬£¬£¬£¬£¬µ«Éв»È·¶¨ÊÇ·ñÓкڿÍÔÚ´Ë֮ǰÇÔÈ¡ÁË̻¶µÄÐÅÏ¢¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/hobby-lobby-customer-data-cloud-misconfiguration/164980/


3.Ó¢¹úÄÉ˰ÈËʹÓõÄÕ˵¥ÌáÐÑϵͳ¿ÉÄÜй¶ÆäÃô¸ÐÊý¾Ý


3.jpg


The RegisteµÄÒ»ÏîÊӲ췢Ã÷Ó¢¹úÄÉ˰ÈËʹÓõÄÕ˵¥ÌáÐÑϵͳ¿ÉÄÜй¶ÆäÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¸ÃϵͳÊÇÓÉTelsolutions¿ª·¢£¬£¬£¬£¬£¬Ö÷Òª¹¦Ð§ÊÇÏòÇ·Õ®Õß·¢ËÍÐÂÎÅÀ´ÌáÐÑÆä»¹Õ®£¬£¬£¬£¬£¬¸ÃÐÂÎÅÖлá°üÀ¨Ò»¸öÖ¸ÏòÎüÊÕÕßСÎÒ˽¼ÒÐÅÏ¢ºÍδÇåÕʵ¥Ò³ÃæµÄURL¡£¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý¸ü¸ÄÍøÖ·ÖеÄ×ÖĸºÍÊý×Ö×Ö·ûÀ´ÅÌÎÊÊôÓÚÆäËûÈ˵ÄÐÅÏ¢£¬£¬£¬£¬£¬ÉõÖÁ°üÀ¨×¡ÔÚ²î±ðµØÇøµÄסÃñÐÅÏ¢¡£¡£¡£¡£¡£TelsolutionsÌåÏÖ¸ÃÎó²îÏÖÒÑÐÞ¸´¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/debt-chasing-uk-councils-potentially-expose-private-resident-data/


4.Purple Fox¹¥»÷»î¶¯½ÏÈ¥ÄêÔöÌí600£¥£¬£¬£¬£¬£¬´ï9Íò¶à´Î


4.jpg


Guardicore LabsÇå¾²Ñо¿Ö°Ô±·¢Ã÷Purple FoxµÄ¹¥»÷»î¶¯×ÔÈ¥Äê5Ô·ÝÖÁ½ñÔöÌíÁË600£¥£¬£¬£¬£¬£¬µÖ´ïÁË9Íò¶à´Î¡£¡£¡£¡£¡£Purple FoxÊÇÒ»ÖÖWindows¶ñÒâÈí¼þ£¬£¬£¬£¬£¬ÓÚ2018Äê3ÔÂÊ״α»·¢Ã÷£¬£¬£¬£¬£¬Í¨¹ýÎó²îʹÓù¤¾ß°üºÍ´¹ÂÚÓʼþÀ´Ñ¬È¾ÅÌËã»ú¡£¡£¡£¡£¡£ÔÚ×î½üµÄ»î¶¯ÖУ¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÁËËüʹÓÃÁËеÄѬȾǰÑÔ£¬£¬£¬£¬£¬Í¨¹ýSMBÃÜÂ뱩Á¦ÆÆ½âÃæÏòÍøÂçµÄWindowsÅÌËã»ú¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬¹¥»÷ÕßÒѽ«Purple FoxËùʹÓõÄÖÖÖÖ¶ñÒâpayloadÍйÜÔÚÓɽü2000̨±»ÈëÇÖµÄЧÀÍÆ÷×é³ÉµÄÖØ´ó½©Ê¬ÍøÂçÉÏ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/03/purple-fox-rootkit-can-now-spread.html


5.΢ÈíÖÒÑÔ½üÆÚ´¹ÂڻÒÑÇÔÈ¡40Íò¸öOWAºÍOffice 365ƾ֤


5.jpg


×ÔÈ¥Äê12ÔÂÒÔÀ´£¬£¬£¬£¬£¬´¹ÂڻÒÑÇÔÈ¡40Íò¸öOWAºÍOffice 365ƾ֤¡£¡£¡£¡£¡£WMC GlobalÓÚÈ¥ÄêÄêÍ··¢Ã÷¸Ã´¹Âڻ£¬£¬£¬£¬£¬Î±×°³Éαװ³ÉÊÓÆµ¾Û»áЧÀÍ¡¢Çå¾²½â¾ö¼Æ»®ºÍÉú²ú¹¤¾ßÀ´ÒÉ»óÊܺ¦Õß¡£¡£¡£¡£¡£È¥Äê12Ô£¬£¬£¬£¬£¬ºÚ¿Íð³äÁËOutlook Web AppÀ´ÓÕÆ­Ä¿µÄÓû§ÊäÈëÆ¾Ö¤£¬£¬£¬£¬£¬ÏÖÔÚÄê1Ô¸ÄΪģÄâOffice 365À´ÇÔȡƾ֤¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬Î¢Èí·¢Ã÷¸Ã»î¶¯»¹Ê¹ÓÃÁËAmazon Simple Email Service£¨SES£©ºÍAppspotÔÆÅÌËãÆ½Ì¨À´·¢ËÍÍøÂç´¹ÂÚµç×ÓÓʼþ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-warns-of-phishing-attacks-bypassing-email-gateways/


6.CiscoÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´JabberÖÐí§Òâ´úÂëÖ´ÐÐÎó²î


6.jpg


CiscoÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´ÁËWindows¡¢macOS¡¢AndroidºÍiOS°æ±¾Jabber clientÖеÄí§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£JabberÊÇÒ»¸öÍøÂç¾Û»áºÍ¼´Ê±ÐÂÎÅת´ïÓ¦Ó㬣¬£¬£¬£¬CiscoÌåÏÖ¸ÃÎó²îÏÖÔÚÉÐδ±»ÆÕ±éʹÓᣡ£¡£¡£¡£¸ÃÎó²î±»×·×ÙΪCVE-2021-1411£¬£¬£¬£¬£¬ÑÏÖØÆ·¼¶Îª9.9£¬£¬£¬£¬£¬ÊÇÓɶÔÊäÈëÐÂÎÅÄÚÈÝÑéÖ¤²»µ±ÒýÆðµÄ¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬´Ë´Î¸üл¹ÐÞ¸´Á˸òúÆ·ÖÐµÄÆäËû4¸öÎó²î£¨CVE-2021-1417ºÍ CVE-2021-1418µÈ£©£¬£¬£¬£¬£¬ÒÔ¼°ÆäËû²úÆ·ÖеÄ37¸öÎó²î¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/cisco-addresses-critical-bug-in-windows-macos-jabber-clients/