ÑÇÂíÑ·AWSÔÆÐ§ÀÍÔÙ´Îå´»úÓ°ÏìTwitchºÍZoomµÈÓ¦ÓÃ

Ðû²¼Ê±¼ä 2021-12-16

AdobeÐû²¼12Ô¸üУ¬£¬ £¬£¬ÐÞ¸´¶à¸ö²úÆ·ÖÐÁè¼Ý60¸öÎó²î


AdobeÐû²¼12Ô¸üУ¬£¬£¬£¬ÐÞ¸´¶à¸ö²úÆ·ÖÐÁè¼Ý60¸öÎó²î.png


12ÔÂ14ÈÕ£¬£¬ £¬£¬AdobeÐû²¼±¾ÔµÄÖܶþ²¹¶¡£¬£¬ £¬£¬ÐÞ¸´¶à¸ö²úÆ·ÖÐÁè¼Ý60¸öÎó²î¡£¡£¡£¡£¡£¡£ÆäÖнÏΪÑÏÖØµÄÊÇExperience ManagerÖеÄXXEÎó²î£¨CVE-2021-40722£©£¬£¬ £¬£¬CVSSÆÀ·ÖΪ9.8£¬£¬ £¬£¬¿Éµ¼ÖÂí§Òâ´úÂëÖ´ÐС£¡£¡£¡£¡£¡£±ðµÄ£¬£¬ £¬£¬»¹ÐÞ¸´ÁËPhotoshopÖпɵ¼ÖÂí§Òâ´úÂëÖ´ÐÐÔ½½çдÈëÎó²î£¨CVE-2021-43018£©»ººÍ³åÇøÒç³öÎó²î£¨CVE-2021-44184£©£¬£¬ £¬£¬ÒÔ¼°Media EncoderÖеÄÔ½½ç¶ÁÈ¡£¡£¡£¡£¡£¡£¨CVE-2021-43757£©µÈ¶à¸öÎó²î¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/125640/security/adobe-60-vulnerabilities-multiple-products.html


ÒÁÀÊMERCURYÃé×¼Öж«ºÍÑÇÖ޵ĵçÐźÍITЧÀÍÌṩÉÌ


ÒÁÀÊMERCURYÃé×¼Öж«ºÍÑÇÖ޵ĵçÐźÍITЧÀÍÌṩÉÌ.png


SymantecÔÚ12ÔÂ14ÈÕ¹ûÕæÁËÕë¶ÔÖж«ºÍÑÇÖÞµçÐźÍITЧÀÍÌṩÉ̵Ĺ¥»÷£¬£¬ £¬£¬ÒÉËÆÀ´×ÔÒÁÀʺڿÍÍÅ»ïMERCURY£¨ÓÖÃûMuddyWater£©¡£¡£¡£¡£¡£¡£¸Ã»î¶¯×îÏÈÓÚ6¸öÔÂ֮ǰ£¬£¬ £¬£¬Ö÷ҪʹÓÃÒ×Êܹ¥»÷µÄExchangeЧÀÍÆ÷ÈëÇÖ×éÖ¯µÄÍøÂç¡£¡£¡£¡£¡£¡£Ö»¹ÜÏÖÔÚѬȾǰÑÔÈÔδ֪£¬£¬ £¬£¬µ«Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öZIPÎļþ¡°Special discount program.zip¡±£¬£¬ £¬£¬ÆäÖаüÀ¨Ô¶³Ì×ÀÃæÈí¼þÓ¦ÓóÌÐòµÄ×°ÖóÌÐò£¬£¬ £¬£¬Òò´ËÍÆ¶Ï¹¥»÷ÕßʹÓõÄÊÇÓã²æÊ½´¹ÂÚÓʼþ¡£¡£¡£¡£¡£¡£     


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/telecom-operators-targeted-in-recent-espionage-hacking-campaign/


Lookout·¢Ã÷Õë¶Ô½ü400¼Ò½ðÈÚ»ú¹¹·Ö·¢AnubisµÄ»î¶¯


Lookout·¢Ã÷Õë¶Ô½ü400¼Ò½ðÈÚ»ú¹¹·Ö·¢AnubisµÄ»î¶¯.png


12ÔÂ14ÈÕ£¬£¬ £¬£¬Lookout·¢Ã÷ÁËÕë¶Ô394¼Ò½ðÈÚ»ú¹¹·Ö·¢AndroidÒøÐÐľÂíAnubisµÄ»î¶¯¡£¡£¡£¡£¡£¡£AnubisÓÚ2016ÄêÊ״ηºÆð£¬£¬ £¬£¬×÷Ϊ¿ªÔ´ÒøÐÐľÂíÔÚ¶íÂÞ˹ºÚ¿ÍÂÛ̳ÉÏÐû²¼¡£¡£¡£¡£¡£¡£Ôڴ˴λÖУ¬£¬ £¬£¬¹¥»÷Õßð³ä·¨¹úµçÐŹ«Ë¾Orange SAµÄÕÊ»§ÖÎÀíÓ¦Ó㬣¬ £¬£¬Ãé×¼´óÍ¨ÒøÐС¢¸»¹úÒøÐС¢ÃÀ¹úÒøÐк͵ÚÒ»×ÊÔ´µÈ½ðÈÚ»ú¹¹µÄ¿Í»§¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬ £¬£¬´Ë´Î¹¥»÷²»µ«½öÕë¶Ô´óÐÍÒøÐеĿͻ§£¬£¬ £¬£¬»¹Õë¶ÔÐéÄâÖ§¸¶Æ½Ì¨ºÍ¼ÓÃÜÇ®°ü£¬£¬ £¬£¬¸Ã»î¶¯ÏÖÔÚÈÔ´¦ÓÚ²âÊÔºÍÓÅ»¯½×¶Î¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/400-banks-targeted-anubis-trojan/177038/


VulcanForgeÉù³ÆÆäÔâµ½¹¥»÷Ëðʧ¸ß´ï½ü1.4ÒÚÃÀÔª


VulcanForgeÉù³ÆÆäÔâµ½¹¥»÷Ëðʧ¸ß´ï½ü1.4ÒÚÃÀÔª.png


ÓÎÏ·¹«Ë¾VulcanForgeÔÚ±¾ÖÜÒ»³ÆÆäÔâµ½ÁËÍøÂç¹¥»÷£¬£¬ £¬£¬Ëðʧ¸ß´ï1.35ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾³Æ£¬£¬ £¬£¬¹¥»÷ÕßÒѾ­»ñµÃÁË96¸öÇ®°üµÄ˽Կ£¬£¬ £¬£¬²¢ÇÔÈ¡ÁË450ÍòPYR£¨VulcanForgeµÄ´ú±Ò£¬£¬ £¬£¬¿ÉÔÚÆäÕû¸öÓÎϷϵͳÖÐʹÓã©¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬ £¬£¬¹¥»÷Õß³öÊÛÁË´ó×ÚPYR£¬£¬ £¬£¬Ê¹PYRµÄ¼ÛǮϵø22%£¨´Ó31ÃÀÔª½µµ½24ÃÀÔª£©¡£¡£¡£¡£¡£¡£ÕâÊǽüÊ®¼¸ÌìÄÚ±¬·¢µÄµÚÈýÆð¼ÓÃÜÇ®±ÒʧÔôÊÂÎñ£¬£¬ £¬£¬Èý´Î¹¥»÷Ôì³ÉµÄ×ÜËðʧ½ð¶îԼΪ4.04ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.theblockcrypto.com/post/127270/96-private-keys-stolen-from-vulcan-forged-in-140-million-theft


KasperskyÅû¶ʹÓÃIISÄ£¿£¿£¿éOwowaµÄ¹¥»÷»î¶¯Ï¸½Ú


KasperskyÅû¶ʹÓÃIISÄ£¿£¿£¿éOwowaµÄ¹¥»÷»î¶¯Ï¸½Ú.png


12ÔÂ14ÈÕ£¬£¬ £¬£¬KasperskyÅû¶ÁËʹÓÃIIS WebЧÀÍÆ÷Ä£¿£¿£¿éOwowaµÄ¹¥»÷»î¶¯Ï¸½Ú¡£¡£¡£¡£¡£¡£Ò£²âÊý¾ÝÏÔʾ£¬£¬ £¬£¬×îÐÂÑù±¾·ºÆðÓÚ2021Äê4Ô£¬£¬ £¬£¬Ãé×¼ÂíÀ´Î÷ÑÇ¡¢Ãɹš¢Ó¡¶ÈÄáÎ÷ÑǺͷÆÂɱöµÄ¹Ù·½×éÖ¯ºÍ¹«¹²½»Í¨¹«Ë¾µÈ¡£¡£¡£¡£¡£¡£OwowaÕë¶ÔExchangeµÄOutlook Web Access(OWA)£¬£¬ £¬£¬Ö¼ÔڼͼÔÚOWAµÇÂ¼ÍøÒ³ÉÏÀֳɾÙÐÐÉí·ÝÑéÖ¤µÄÓû§µÄƾ֤¡£¡£¡£¡£¡£¡£È»ºó£¬£¬ £¬£¬¹¥»÷Õß»áÏò¶ñÒâÄ£¿£¿£¿é·¢ËÍÏÂÁîÀ´ÍøÂç±»µÁÊý¾Ý£¬£¬ £¬£¬²¢ÔÚ±»Ñ¬È¾×°±¸ÉÏÖ´ÐÐPowerShell£¬£¬ £¬£¬¾ÙÐÐÏÂÒ»²½¹¥»÷¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/owowa-credential-stealer-and-remote-access/105219/


ÑÇÂíÑ·AWSÔÆÐ§ÀÍÔÙ´Îå´»úÓ°ÏìTwitchºÍZoomµÈÓ¦ÓÃ


ÑÇÂíÑ·AWSÔÆÐ§ÀÍÔÙ´Îå´»úÓ°ÏìTwitchºÍZoomµÈÓ¦ÓÃ.png


12ÔÂ15ÈÕ£¬£¬ £¬£¬ÑÇÂíÑ·AWSÔÆÐ§ÀÍÔÙ´Îå´»ú¡£¡£¡£¡£¡£¡£ÆäÖÐÖ¹×îÏÈÓÚ̫ƽÑóʱ¼äÉÏÎç7:43×óÓÒ£¬£¬ £¬£¬Ö÷ÒªÓ°ÏìÁËUS-WEST-1ºÍUS-WEST-2ÇøÓò£¬£¬ £¬£¬µ¼ÖÂTwitch¡¢Zoom¡¢PSN¡¢Xbox Live¡¢Doordash¡¢Quickbooks OnlineºÍHuluµÈ´ó×ÚÆ½Ì¨ºÍÍøÕ¾¹Ø±Õ¡£¡£¡£¡£¡£¡£×èÖ¹12ÔÂ15ÈÕ11:27 £¬£¬ £¬£¬ÑÇÂíÑ·³ÆInternetÅþÁ¬µÄÎÊÌâÒѾ­½â¾ö£¬£¬ £¬£¬Ð§ÀÍÔËÐÐÕý³£¡£¡£¡£¡£¡£¡£12ÔÂ7ÈÕ£¬£¬ £¬£¬ÑÇÂíÑ·AWSÔÆÐ§ÀÍå´»ú£¬£¬ £¬£¬Ó°ÏìÁËNetflix¡¢RokuºÍAmazon PrimeµÄµÈÓ¦Óᣡ£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/technology/aws-down-again-outage-impacts-twitch-zoom-psn-hulu-others/