TIMÍŶÓÅû¶CA Technologies²úÎïÖеĶà¸ö0day £»Î¢Èí³ÆÖÜËĵÄÖжÏÔ´ÓÚ´úÂëȱÏݵ¼ÖµÄAzure DNS¹ýÔØ

Ðû²¼Ê±¼ä 2021-04-06

1.TIMÍŶÓÅû¶CA Technologies²úÎïÖеĶà¸ö0day


1.jpg


CA TechnologiesÊÇÃÀ¹úÒ»¼ÒרעÓÚB2BÈí¼þµÄ¿ç¹ú¹«Ë¾ £¬ÏúÊÛ½ü200ÖÖ²úÎï £¬Éæ¼°ÂþÑÜʽ¼ÆËã¡¢ÔÆ¼ÆËã¡¢DevOpsºÍ¼ÆËã»úÄþ¾²Èí¼þÒÔ¼°Òƶ¯É豸¡£TIMµÄRed Team ResearchÍŶÓÅû¶ÁËCA eHealth Performance Manager²úÎïÖеÄ5¸öЩ¶´¡£·Ö±ðΪÌáȨ©¶´£¨CVE-2021-28246ºÍCVE-2021-28249£©¡¢¿çÕ¾µã½Å±¾Â©¶´£¨CVE-2021-28247£©¡¢Í¨¹ýSUID/GUIDÎļþµÄÌáȨ©¶´£¨CVE-2021-28250£©ºÍÉí·ÝÑé֤©¶´£¨CVE-2021-28248£©¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116268/security/ca-ehealth-performance-manager-flaws.html


2.΢Èí³ÆÖÜËĵÄÖжÏÔ´ÓÚ´úÂëȱÏݵ¼ÖµÄAzure DNS¹ýÔØ


2.jpg


΢Èí͸¶ £¬ÉÏÖÜËĵÄÈ«Çò·¶Î§ÄڵķþÎñÖжÏÊÇÓÉ´úÂëȱÏݵ¼ÖµÄAzure DNS¹ýÔØÒýÆðµÄ¡£ÖжϷ¢ÉúÔÚÉÏÖÜËÄÏÂÎç5:21×óÓÒ £¬MicrosoftÓû§·¢ÏÖÆäÎÞ·¨·ÃÎÊXbox Live¡¢Office¡¢TeamsºÍSkypeµÈ·þÎñ £¬¸ÃÎÊÌâÓÚ6:30±»½â¾ö¡£½üÆÚ £¬MicrosoftÐû²¼ÁËÓйطþÎñÖжϵĻù´¡Ô­Òò·ÖÎö£¨RCA£© £¬³ÆÕë¶ÔAzureÉÏÍйܵÄijЩÓòµÄDNS²éѯÒì³£¼¤Ôöµ¼Ö·þÎñÆ÷¹ýÔØ £¬Î¢Èí²¢Î´½âÊͼ¤ÔöµÄÔ­Òò £¬¾ÝÍÆ²â¿ÉÄÜÊÇÓÉÓÚÕë¶ÔijЩÓòµÄDDoS¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-outage-caused-by-overloaded-azure-dns-servers/


3.ÃÀ¹ú½ðÈÚ»ú¹¹RobinhoodµÄ¿Í»§Ôâµ½µöÓã¹¥»÷


3.jpg


Robinhood MarketsÔÚÉÏÖÜËÄÐû²¼ÏòÆä¿Í»§·¢ËÍÓʼþ³Æ £¬Æä²¿Ãſͻ§¿ÉÄÜÒѾ­Ôâµ½µöÓã¹¥»÷¡£RobinhoodÊÇÒ»¼ÒÃÀ¹ú½ðÈÚ·þÎñ»ú¹¹ £¬ÆäÊÖ»úÓ¦ÓÿÉÌṩ¹ÉƱºÍ»ù½ðµÄÃâÓ¶½ð½»Ò× £¬½ØÖÁ2020ÄêÒÑÓµÓÐ1300Íò¿Í»§¡£´Ë´Î¹¥»÷»î¶¯Ê¹ÓÃÁËÁ½ÖÖ¹¥»÷ý½éÓÕÆ­Êܺ¦Õß £¬ÆäÒ»ÊÇÀûÓðüÂÞÁËαÔìRobinhoodÍøÕ¾Á´½ÓµÄµöÓãÓʼþ £¬ÓÕʹ·ÃÎÊÕßÊäÈëµÇ¼ƾ¾Ý £»ÁíÒ»ÖÖÊÇÀûÓÃÁ˱¨Ë°¼¾ £¬ÒªÇóÄ¿±êÏÂÔØ°üÂÞÁ˶ñÒâÈí¼þµÄαÔì˰ÊÕÎļþ¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/04/attackers-targeted-robinhood-with.html


4.KasperskyÅû¶Õë¶ÔÔ½Ä϶à¸ö×éÖ¯µÄÍøÂç¼äµý»î¶¯


4.jpg


KasperskyÅû¶ÁËAPT×éÖ¯CycldekÕë¶ÔÔ½ÄÏÕþ¸®ºÍ¾üÊÂ×éÖ¯µÄÍøÂç¼äµý»î¶¯¡£¸Ã»î¶¯Ê¹ÓÃÁËÃûΪFoundCoreµÄ¶ñÒâÈí¼þ £¬¿É½øÐÐÎļþϵͳÀûÓᢽø³ÌÀûÓá¢ÆÁÄ»½ØÍ¼²¶×½ºÍÈÎÒâÃüÁîÖ´ÐС£´ËÍâ £¬Kaspersky³Æ¸Ã×éÖ¯ÔÚÅÓ´óÐÔ·½ÃæÈ¡µÃÁËÖØ´ó½ø²½ £¬ÀýÈç £¬ÆäpayloadµÄ±êÍ·£¨´úÂëµÄÄ¿±êºÍÔ´£©±»ÍêÈ«°þÀë £¬Ê£ÏµÄÉÙÊý²¿ÃŵÄÖµÊDz»Á¬¹áµÄ £¬Õâ´ó´óÔö¼ÓÁËÑо¿ÈËÔ±¶ÔÆä½øÐзÖÎöµÄÄѶÈ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/spy-operations-vietnam-rat/165243/


5.΢ÈíÐû²¼2021Äê3ÔÂSecurity SignalsµÄ·ÖÎö³ÂËß


5.jpg


΢ÈíÐû²¼ÁË2021Äê3ÔÂSecurity SignalsµÄ·ÖÎö³ÂËß £¬ÊÓ²ìÁËÀ´×ÔÖйú¡¢µÂ¹ú¡¢ÈÕ±¾¡¢Ó¢¹úºÍÃÀ¹úµÄ1000λÆóÒµÄþ¾²¾ö²ßÕß¡£³ÂËß·¢ÏÖ £¬¹ýÈ¥Á½ÄêÖÐÓÐ80£¥µÄÆóÒµÔâµ½ÁËÖÁÉÙÒ»´Î¹Ì¼þ¹¥»÷ £¬µ«Ö»ÓÐ29£¥µÄ×éÖ¯·ÖÅäÁËÔ¤ËãÀ´± £»¤¹Ì¼þ¡£NVD֤ʵÔÚ¹ýÈ¥ËÄÄêÖÐ £¬Õë¶Ô¹Ì¼þµÄ¹¥»÷Ôö¼ÓÁËÎå±¶ÒÔÉÏ¡£21£¥µÄ¾ö²ßÕßÈÏ¿ÉÎÞ·¨¼à¿Ø¹Ì¼þÊý¾Ý £¬82£¥×é֯ûÓÐ×ÊÔ´À´µÖÓù¹Ì¼þ¹¥»÷¡£81£¥µÄµÂ¹ú¹«Ë¾¡¢91£¥µÄÃÀ¹ú¡¢Ó¢¹úºÍÈÕ±¾¹«Ë¾ÒÔ¼°95£¥µÄÖйú¹«Ë¾Ô¸ÒâÔÚÕâ¸ö·½Ãæ½øÐÐͶ×Ê¡£


Ô­ÎÄÁ´½Ó£º

https://www.microsoft.com/en-us/secured-corepc


6.RavelinÐû²¼Óйصç×ÓÉÌÎñÆÛÕ©»î¶¯µÄ·ÖÎö³ÂËß


6.jpg


Ravelin¶ÔÈ«Çò1000¶à¼ÒÉ̼ҽøÐÐÁËÊÓ²ì £¬Ðû²¼ÁËÓйصç×ÓÉÌÎñÆÛÕ©»î¶¯µÄ·ÖÎö³ÂËß¡£³ÂËßÏÔʾ £¬½«½ü40£¥µÄ¿ìÏûÁãÊÛÉ̽«ÔÚÏßÖ§¸¶ÆÛÕ©ÊÓΪ×î´óµÄÆÛÕ©·çÏÕ £¬45%µÄ¹«Ë¾Ëù¾­ÀúµÄÕË»§½Ó¹Ü(ATO)¹¥»÷ÓÐËùÔö¼Ó¡£³ÂËßÔ¤²â £¬µç×ÓÉÌÎñÐÐÒµÖÐµÄÆÛÕ©ÎÊÌâ¿ÉÄÜ»áÓúÑÝÓúÁÒ £¬ÓÈÆäÊÇËæ×ÅÐí¶à´«Í³µÄ¸ß½ÖÆ·ÅÆ£¨ÈçTopshopºÍDebenhams£©±»ÊÕ¹º²¢Íê³ÉÒµÎñÈ«²¿ÏòÏßÉÏתÐ͵Äʱºò¡£


Ô­ÎÄÁ´½Ó£º

https://pages.ravelin.com/retail-fraud-payments-report