ForescoutÅû¶ӰÏìÉÏÒŲ́װ±¸µÄDNSÎó²îNAME£ºWRECK£»£» £»£»£»£»£»Î¢ÈíÐû²¼4Ô²¹¶¡£¬ £¬£¬£¬£¬£¬£¬ÐÞ¸´5¸ö0dayÔÚÄÚµÄ108¸öÎó²î

Ðû²¼Ê±¼ä 2021-04-14

1.ForescoutÅû¶ӰÏìÉÏÒŲ́װ±¸µÄDNSÎó²îNAME£ºWRECK


1.jpg


Çå¾²¹«Ë¾ForescoutºÍÒÔÉ«ÁÐÇå¾²ÍŶÓJSOFÁªºÏÅû¶ÁËTCP/IP¿ÍÕ»ÖÐDNSЭÒéÖеÄ9¸öÇå¾²Îó²î£¬ £¬£¬£¬£¬£¬£¬Í³³ÆÎªNAME£ºWRECK£¬ £¬£¬£¬£¬£¬£¬Ó°ÏìÁË1ÒÚ¸öÔÚInternetÉÏÔËÐеÄ×°±¸¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îʹװ±¸ÍÑ»ú»òÕßÍêÈ«¿ØÖÆ×°±¸¡£¡£¡£ÕâЩÎó²îÖÐ×îÑÏÖØµÄΪIPnetÖеÄRCEÎó²î£¨CVE-2016-20009£©£¬ £¬£¬£¬£¬£¬£¬ÑÏÖØÐԵ÷ÖΪ9.8¡£¡£¡£Æä´ÎΪRCE£¨CVE-2020-7461¡¢CVE-2020-15795ºÍCVE-2020-27009£©ºÍDoS£¨CVE-2020-27736ºÍCVE-2020-27737£©µÈÎó²î¡£¡£¡£    


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/name-wreck-dns-vulnerabilities-affect-over-100-million-devices/


2.Ñо¿Ö°Ô±¹ûÕæChromeºÍEdgeµÈÓ¦ÓõÄRCE 0dayµÄPoC


2.jpg


Ñо¿Ö°Ô±ÔÚRajvardhan AgarwalÔÚTwitterÐû²¼ÁËChromeºÍEdgeµÈÓ¦ÓÃÖеÄRCE 0dayµÄPoC¡£¡£¡£¸ÃÎó²îÊÇ»ùÓÚChromiumµÄä¯ÀÀÆ÷µÄV8 JavaScriptÒýÇæÖÐÔ¶³ÌÖ´ÐдúÂëÎó²î£¬ £¬£¬£¬£¬£¬£¬Ó°ÏìÁËChrome¡¢Edge¡¢OperaºÍBraveµÈä¯ÀÀÆ÷¡£¡£¡£±ðµÄ£¬ £¬£¬£¬£¬£¬£¬AgarwalÌåÏÖ¸Ã0dayÐèÒªÓëÁíÒ»¸ö¿ÉÒÔÔÚChromiumµÄɳÏäÌÓÒݵÄÎó²îÒ»ÆðʹÓòŻªÊ©Õ¹×÷Óᣡ£¡£ÏÖÔÚ£¬ £¬£¬£¬£¬£¬£¬¸ÃÎó²îÒÑÔÚV8 JavaScriptÒýÇæµÄ×îа汾Öб»ÐÞ¸´¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/04/rce-exploit-released-for-unpatched.html


3.MicrosoftÐû²¼4Ô²¹¶¡£¬ £¬£¬£¬£¬£¬£¬ÐÞ¸´5¸ö0dayÔÚÄÚµÄ108¸öÎó²î


3.jpg


MicrosoftÐû²¼ÁË4Ô·ݵÄÖܶþ²¹¶¡£¬ £¬£¬£¬£¬£¬£¬×ܼÆÐÞ¸´Á˰üÀ¨5¸ö0dayÔÚÄÚµÄ108¸öÎó²î¡£¡£¡£´Ë´ÎÐÞ¸´µÄ0day°üÀ¨RPC¶ËµãÓ³ÉäÆ÷µÄÌáȨÎó²î£¨CVE-2021-27091£©¡¢NTFS¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2021-28312£©¡¢Windows×°ÖóÌÐòÖеÄÐÅϢй¶Îó²î£¨CVE-2021-28437£©¡¢Azure ms-rest-nodeauth¿âµÄÌáȨÎó²î£¨CVE-2021-28458£©ÒÔ¼°Win32kÖеÄÌáȨÎó²î£¨CVE-2021-28310£©¡£¡£¡£ÆäÖУ¬ £¬£¬£¬£¬£¬£¬CVE-2021-28310Îó²îÊÇKasperskyÔÚÒ°·¢Ã÷µÄ£¬ £¬£¬£¬£¬£¬£¬Òѱ»APT×éÖ¯BITTERʹÓᣡ£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2021-patch-tuesday-fixes-108-flaws-5-zero-days/


4.ºÚ¿Í³öÊÛ2100Íò¸öÍ£³µÓ¦ÓÃParkMobileµÄÓû§µÄÐÅÏ¢


4.jpg


Gemini Advisory·¢Ã÷ºÚ¿ÍÔÚ°µÍø³öÊÛ2100Íò¸öÒÆ¶¯Í£³µÓ¦ÓóÌÐòParkMobileµÄÓû§µÄÐÅÏ¢£¬ £¬£¬£¬£¬£¬£¬ÊÛ¼ÛΪ125000ÃÀÔª¡£¡£¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨¿Í»§µç×ÓÓʼþµØµã¡¢ÉúÈÕ¡¢µç»°ºÅÂë¡¢³µÅƺš¢¹þÏ£ÃÜÂëºÍÓʼĵصãµÈ¡£¡£¡£ParkMobile¹«Ë¾³Æ£¬ £¬£¬£¬£¬£¬£¬Æä3ÔÂ26ÈÕ¾ÍÐû²¼ÁËÓйØÊý¾Ýй¶µÄ֪ͨ£¬ £¬£¬£¬£¬£¬£¬²¢ÔÚÇå¾²¹«Ë¾µÄЭÖú϶ԴËÊÂÕö¿ªÁËÊӲ졣¡£¡£µ«Ñо¿Ö°Ô±ÌåÏÖÆä¹ÙÍø²¢Ã»ÓиÃÇ徲֪ͨ£¬ £¬£¬£¬£¬£¬£¬Ò²Ã»ÓÐÇ¿ÖÆÆäÓû§ÐÞ¸ÄÃÜÂë¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://krebsonsecurity.com/2021/04/parkmobile-breach-exposes-license-plate-data-mobile-numbers-of-21m-users/


5.McAfee·¢Ã÷BRATAαװ³ÉÇ徲ɨÃè³ÌÐòÔÚGoogle PlayÖзַ¢


5.jpg


McAfee·¢Ã÷ÁËBRATAµÄ¶à¸öбäÖÖ£¬ £¬£¬£¬£¬£¬£¬Î±×°³ÉÇ徲ɨÃè³ÌÐòÔÚGoogle PlayÖзַ¢¡£¡£¡£BRATA×î³õÓÚ2018Äêµ×ÔÚÒ°Íâ·ºÆð£¬ £¬£¬£¬£¬£¬£¬ÒÔ°ÍÎ÷µÄÓû§ÎªÄ¿µÄ£¬ £¬£¬£¬£¬£¬£¬¾ßÓпØÖÆ×°±¸¡¢Ê¹Óô¹ÂÚÍøÒ³ÇÔÈ¡ÒøÐÐÆ¾Ö¤¡¢»ñÈ¡ÆÁÄ»Ëø¶¨Æ¾Ö¤£¨PIN¡¢ÃÜÂë»òͼ°¸£©µÈ¹¦Ð§¡£¡£¡£ÕâЩеıäÖÖÖ÷ÒªÔÚGoogle PlayÉϾÙÐзַ¢£¬ £¬£¬£¬£¬£¬£¬ÒªÇóÓû§¸üÐÂChrome¡¢WhatsApp»òPDFÔĶÁÆ÷£¬ £¬£¬£¬£¬£¬£¬²¢Í¨¹ý¸¨Öú¹¦Ð§À´ÍêÈ«¿ØÖÆ×°±¸£¬ £¬£¬£¬£¬£¬£¬Õë¶Ô°ÍÎ÷¡¢Î÷°àÑÀºÍÃÀ¹úµÈµØÇøµÄ½ðÈÚ×éÖ¯µÄÓû§¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.mcafee.com/blogs/other-blogs/mcafee-labs/brata-keeps-sneaking-into-google-play-now-targeting-usa-and-spain/


6.Unit 42Ðû²¼2020ÄêQ4Çå¾²Ç÷ÊÆµÄÆÊÎö±¨¸æ


6.jpg


Unit 42Ðû²¼ÁË2020ÄêQ4Çå¾²Ç÷ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£±¨¸æ·¢Ã÷£¬ £¬£¬£¬£¬£¬£¬2020Äê11ÔÂÖÁ2021Äê1ÔµĴó´ó¶¼¹¥»÷¶¼±»¹éΪÑÏÖØ¹¥»÷£¬ £¬£¬£¬£¬£¬£¬Õ¼±ÈΪ75£¥£¬ £¬£¬£¬£¬£¬£¬¶øÔÚÇ^Ϊ50.4£¥¡£¡£¡£¹¥»÷Õ߸ü¶àµÄʹÓÃ2017ÄêÖÁ2020ÄêÔÚÒ°ÍâʹÓõÄÎó²î¡£¡£¡£ÔÚ¹¥»÷ÀàÐÍ·½Ã棬 £¬£¬£¬£¬£¬£¬µ¥¶ÀµÄ´úÂëÖ´ÐÐÕ¼×ܹ¥»÷µÄ46.6£¥£¬ £¬£¬£¬£¬£¬£¬´úÂëÖ´ÐкÍÌØÈ¨ÌáÉýÁ¬ÏµµÄ¹¥»÷Õ¼17.3£¥£¬ £¬£¬£¬£¬£¬£¬SQL×¢ÈëÕ¼9.9£¥¡£¡£¡£ÑÏÖØÐÔ×î¸ßµÄÎó²îΪÏÂÁî×¢ÈëÎó²î£¨CVE-2020-28188£©¡¢Ä¿Â¼±éÀúÎó²î£¨CVE-2020-17519£©ºÍÍâµØÎļþ°üÀ¨Îó²î£¨CVE-2020-29227£©µÈ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/network-attack-trends-winter-2020/