ForescoutÅû¶ӰÏìÉÏÒŲ́װ±¸µÄDNSÎó²îNAME£ºWRECK£»£»£»£»£»£»£»Î¢ÈíÐû²¼4Ô²¹¶¡£¬ £¬£¬£¬ÐÞ¸´5¸ö0dayÔÚÄÚµÄ108¸öÎó²î

Ðû²¼Ê±¼ä 2021-04-14

1.ForescoutÅû¶ӰÏìÉÏÒŲ́װ±¸µÄDNSÎó²îNAME£ºWRECK


1.jpg


Çå¾²¹«Ë¾ForescoutºÍÒÔÉ«ÁÐÇå¾²ÍŶÓJSOFÁªºÏÅû¶ÁËTCP/IP¿ÍÕ»ÖÐDNSЭÒéÖеÄ9¸öÇå¾²Îó²î£¬ £¬£¬£¬Í³³ÆÎªNAME£ºWRECK£¬ £¬£¬£¬Ó°ÏìÁË1ÒÚ¸öÔÚInternetÉÏÔËÐеÄ×°±¸¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îʹװ±¸ÍÑ»ú»òÕßÍêÈ«¿ØÖÆ×°±¸¡£¡£¡£¡£¡£¡£ÕâЩÎó²îÖÐ×îÑÏÖØµÄΪIPnetÖеÄRCEÎó²î£¨CVE-2016-20009£©£¬ £¬£¬£¬ÑÏÖØÐԵ÷ÖΪ9.8¡£¡£¡£¡£¡£¡£Æä´ÎΪRCE£¨CVE-2020-7461¡¢CVE-2020-15795ºÍCVE-2020-27009£©ºÍDoS£¨CVE-2020-27736ºÍCVE-2020-27737£©µÈÎó²î¡£¡£¡£¡£¡£¡£    


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/name-wreck-dns-vulnerabilities-affect-over-100-million-devices/


2.Ñо¿Ö°Ô±¹ûÕæChromeºÍEdgeµÈÓ¦ÓõÄRCE 0dayµÄPoC


2.jpg


Ñо¿Ö°Ô±ÔÚRajvardhan AgarwalÔÚTwitterÐû²¼ÁËChromeºÍEdgeµÈÓ¦ÓÃÖеÄRCE 0dayµÄPoC¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇ»ùÓÚChromiumµÄä¯ÀÀÆ÷µÄV8 JavaScriptÒýÇæÖÐÔ¶³ÌÖ´ÐдúÂëÎó²î£¬ £¬£¬£¬Ó°ÏìÁËChrome¡¢Edge¡¢OperaºÍBraveµÈä¯ÀÀÆ÷¡£¡£¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬AgarwalÌåÏÖ¸Ã0dayÐèÒªÓëÁíÒ»¸ö¿ÉÒÔÔÚChromiumµÄɳÏäÌÓÒݵÄÎó²îÒ»ÆðʹÓòŻªÊ©Õ¹×÷Óᣡ£¡£¡£¡£¡£ÏÖÔÚ£¬ £¬£¬£¬¸ÃÎó²îÒÑÔÚV8 JavaScriptÒýÇæµÄ×îа汾Öб»ÐÞ¸´¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/04/rce-exploit-released-for-unpatched.html


3.MicrosoftÐû²¼4Ô²¹¶¡£¬ £¬£¬£¬ÐÞ¸´5¸ö0dayÔÚÄÚµÄ108¸öÎó²î


3.jpg


MicrosoftÐû²¼ÁË4Ô·ݵÄÖܶþ²¹¶¡£¬ £¬£¬£¬×ܼÆÐÞ¸´Á˰üÀ¨5¸ö0dayÔÚÄÚµÄ108¸öÎó²î¡£¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄ0day°üÀ¨RPC¶ËµãÓ³ÉäÆ÷µÄÌáȨÎó²î£¨CVE-2021-27091£©¡¢NTFS¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2021-28312£©¡¢Windows×°ÖóÌÐòÖеÄÐÅϢй¶Îó²î£¨CVE-2021-28437£©¡¢Azure ms-rest-nodeauth¿âµÄÌáȨÎó²î£¨CVE-2021-28458£©ÒÔ¼°Win32kÖеÄÌáȨÎó²î£¨CVE-2021-28310£©¡£¡£¡£¡£¡£¡£ÆäÖУ¬ £¬£¬£¬CVE-2021-28310Îó²îÊÇKasperskyÔÚÒ°·¢Ã÷µÄ£¬ £¬£¬£¬Òѱ»APT×éÖ¯BITTERʹÓᣡ£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2021-patch-tuesday-fixes-108-flaws-5-zero-days/


4.ºÚ¿Í³öÊÛ2100Íò¸öÍ£³µÓ¦ÓÃParkMobileµÄÓû§µÄÐÅÏ¢


4.jpg


Gemini Advisory·¢Ã÷ºÚ¿ÍÔÚ°µÍø³öÊÛ2100Íò¸öÒÆ¶¯Í£³µÓ¦ÓóÌÐòParkMobileµÄÓû§µÄÐÅÏ¢£¬ £¬£¬£¬ÊÛ¼ÛΪ125000ÃÀÔª¡£¡£¡£¡£¡£¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨¿Í»§µç×ÓÓʼþµØµã¡¢ÉúÈÕ¡¢µç»°ºÅÂë¡¢³µÅƺš¢¹þÏ£ÃÜÂëºÍÓʼĵصãµÈ¡£¡£¡£¡£¡£¡£ParkMobile¹«Ë¾³Æ£¬ £¬£¬£¬Æä3ÔÂ26ÈÕ¾ÍÐû²¼ÁËÓйØÊý¾Ýй¶µÄ֪ͨ£¬ £¬£¬£¬²¢ÔÚÇå¾²¹«Ë¾µÄЭÖú϶ԴËÊÂÕö¿ªÁËÊӲ졣¡£¡£¡£¡£¡£µ«Ñо¿Ö°Ô±ÌåÏÖÆä¹ÙÍø²¢Ã»ÓиÃÇ徲֪ͨ£¬ £¬£¬£¬Ò²Ã»ÓÐÇ¿ÖÆÆäÓû§ÐÞ¸ÄÃÜÂë¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://krebsonsecurity.com/2021/04/parkmobile-breach-exposes-license-plate-data-mobile-numbers-of-21m-users/


5.McAfee·¢Ã÷BRATAαװ³ÉÇ徲ɨÃè³ÌÐòÔÚGoogle PlayÖзַ¢


5.jpg


McAfee·¢Ã÷ÁËBRATAµÄ¶à¸öбäÖÖ£¬ £¬£¬£¬Î±×°³ÉÇ徲ɨÃè³ÌÐòÔÚGoogle PlayÖзַ¢¡£¡£¡£¡£¡£¡£BRATA×î³õÓÚ2018Äêµ×ÔÚÒ°Íâ·ºÆð£¬ £¬£¬£¬ÒÔ°ÍÎ÷µÄÓû§ÎªÄ¿µÄ£¬ £¬£¬£¬¾ßÓпØÖÆ×°±¸¡¢Ê¹Óô¹ÂÚÍøÒ³ÇÔÈ¡ÒøÐÐÆ¾Ö¤¡¢»ñÈ¡ÆÁÄ»Ëø¶¨Æ¾Ö¤£¨PIN¡¢ÃÜÂë»òͼ°¸£©µÈ¹¦Ð§¡£¡£¡£¡£¡£¡£ÕâЩеıäÖÖÖ÷ÒªÔÚGoogle PlayÉϾÙÐзַ¢£¬ £¬£¬£¬ÒªÇóÓû§¸üÐÂChrome¡¢WhatsApp»òPDFÔĶÁÆ÷£¬ £¬£¬£¬²¢Í¨¹ý¸¨Öú¹¦Ð§À´ÍêÈ«¿ØÖÆ×°±¸£¬ £¬£¬£¬Õë¶Ô°ÍÎ÷¡¢Î÷°àÑÀºÍÃÀ¹úµÈµØÇøµÄ½ðÈÚ×éÖ¯µÄÓû§¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.mcafee.com/blogs/other-blogs/mcafee-labs/brata-keeps-sneaking-into-google-play-now-targeting-usa-and-spain/


6.Unit 42Ðû²¼2020ÄêQ4Çå¾²Ç÷ÊÆµÄÆÊÎö±¨¸æ


6.jpg


Unit 42Ðû²¼ÁË2020ÄêQ4Çå¾²Ç÷ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£±¨¸æ·¢Ã÷£¬ £¬£¬£¬2020Äê11ÔÂÖÁ2021Äê1ÔµĴó´ó¶¼¹¥»÷¶¼±»¹éΪÑÏÖØ¹¥»÷£¬ £¬£¬£¬Õ¼±ÈΪ75£¥£¬ £¬£¬£¬¶øÔÚÇ^Ϊ50.4£¥¡£¡£¡£¡£¡£¡£¹¥»÷Õ߸ü¶àµÄʹÓÃ2017ÄêÖÁ2020ÄêÔÚÒ°ÍâʹÓõÄÎó²î¡£¡£¡£¡£¡£¡£ÔÚ¹¥»÷ÀàÐÍ·½Ã棬 £¬£¬£¬µ¥¶ÀµÄ´úÂëÖ´ÐÐÕ¼×ܹ¥»÷µÄ46.6£¥£¬ £¬£¬£¬´úÂëÖ´ÐкÍÌØÈ¨ÌáÉýÁ¬ÏµµÄ¹¥»÷Õ¼17.3£¥£¬ £¬£¬£¬SQL×¢ÈëÕ¼9.9£¥¡£¡£¡£¡£¡£¡£ÑÏÖØÐÔ×î¸ßµÄÎó²îΪÏÂÁî×¢ÈëÎó²î£¨CVE-2020-28188£©¡¢Ä¿Â¼±éÀúÎó²î£¨CVE-2020-17519£©ºÍÍâµØÎļþ°üÀ¨Îó²î£¨CVE-2020-29227£©µÈ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/network-attack-trends-winter-2020/