TIMÍŶÓÅû¶CA Technologies²úÎïÖеĶà¸ö0day£»Î¢Èí³ÆÖÜËĵÄÖжÏÔ´ÓÚ´úÂëȱÏݵ¼ÖµÄAzure DNS¹ýÔØ
Ðû²¼Ê±¼ä 2021-04-061.TIMÍŶÓÅû¶CA Technologies²úÎïÖеĶà¸ö0day
CA TechnologiesÊÇÃÀ¹úÒ»¼ÒרעÓÚB2BÈí¼þµÄ¿ç¹ú¹«Ë¾£¬ÏúÊÛ½ü200ÖÖ²úÎï£¬Éæ¼°ÂþÑÜʽ¼ÆËã¡¢ÔÆ¼ÆËã¡¢DevOpsºÍ¼ÆËã»úÄþ¾²Èí¼þÒÔ¼°Òƶ¯É豸¡£TIMµÄRed Team ResearchÍŶÓÅû¶ÁËCA eHealth Performance Manager²úÎïÖеÄ5¸öЩ¶´¡£·Ö±ðΪÌáȨ©¶´£¨CVE-2021-28246ºÍCVE-2021-28249£©¡¢¿çÕ¾µã½Å±¾Â©¶´£¨CVE-2021-28247£©¡¢Í¨¹ýSUID/GUIDÎļþµÄÌáȨ©¶´£¨CVE-2021-28250£©ºÍÉí·ÝÑé֤©¶´£¨CVE-2021-28248£©¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/116268/security/ca-ehealth-performance-manager-flaws.html
2.΢Èí³ÆÖÜËĵÄÖжÏÔ´ÓÚ´úÂëȱÏݵ¼ÖµÄAzure DNS¹ýÔØ
΢Èí͸¶£¬ÉÏÖÜËĵÄÈ«Çò·¶Î§ÄڵķþÎñÖжÏÊÇÓÉ´úÂëȱÏݵ¼ÖµÄAzure DNS¹ýÔØÒýÆðµÄ¡£ÖжϷ¢ÉúÔÚÉÏÖÜËÄÏÂÎç5:21×óÓÒ£¬MicrosoftÓû§·¢ÏÖÆäÎÞ·¨·ÃÎÊXbox Live¡¢Office¡¢TeamsºÍSkypeµÈ·þÎñ£¬¸ÃÎÊÌâÓÚ6:30±»½â¾ö¡£½üÆÚ£¬MicrosoftÐû²¼ÁËÓйطþÎñÖжϵĻù´¡ÔÒò·ÖÎö£¨RCA£©£¬³ÆÕë¶ÔAzureÉÏÍйܵÄijЩÓòµÄDNS²éѯÒì³£¼¤Ôöµ¼Ö·þÎñÆ÷¹ýÔØ£¬Î¢Èí²¢Î´½âÊͼ¤ÔöµÄÔÒò£¬¾ÝÍÆ²â¿ÉÄÜÊÇÓÉÓÚÕë¶ÔijЩÓòµÄDDoS¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-outage-caused-by-overloaded-azure-dns-servers/
3.ÃÀ¹ú½ðÈÚ»ú¹¹RobinhoodµÄ¿Í»§Ôâµ½µöÓã¹¥»÷
Robinhood MarketsÔÚÉÏÖÜËÄÐû²¼ÏòÆä¿Í»§·¢ËÍÓʼþ³Æ£¬Æä²¿Ãſͻ§¿ÉÄÜÒѾÔâµ½µöÓã¹¥»÷¡£RobinhoodÊÇÒ»¼ÒÃÀ¹ú½ðÈÚ·þÎñ»ú¹¹£¬ÆäÊÖ»úÓ¦ÓÿÉÌṩ¹ÉƱºÍ»ù½ðµÄÃâÓ¶½ð½»Ò×£¬½ØÖÁ2020ÄêÒÑÓµÓÐ1300Íò¿Í»§¡£´Ë´Î¹¥»÷»î¶¯Ê¹ÓÃÁËÁ½ÖÖ¹¥»÷ý½éÓÕÆÊܺ¦Õߣ¬ÆäÒ»ÊÇÀûÓðüÂÞÁËαÔìRobinhoodÍøÕ¾Á´½ÓµÄµöÓãÓʼþ£¬ÓÕʹ·ÃÎÊÕßÊäÈëµÇ¼ƾ¾Ý£»ÁíÒ»ÖÖÊÇÀûÓÃÁ˱¨Ë°¼¾£¬ÒªÇóÄ¿±êÏÂÔØ°üÂÞÁ˶ñÒâÈí¼þµÄαÔì˰ÊÕÎļþ¡£
ÔÎÄÁ´½Ó£º
https://www.ehackingnews.com/2021/04/attackers-targeted-robinhood-with.html
4.KasperskyÅû¶Õë¶ÔÔ½Ä϶à¸ö×éÖ¯µÄÍøÂç¼äµý»î¶¯
KasperskyÅû¶ÁËAPT×éÖ¯CycldekÕë¶ÔÔ½ÄÏÕþ¸®ºÍ¾üÊÂ×éÖ¯µÄÍøÂç¼äµý»î¶¯¡£¸Ã»î¶¯Ê¹ÓÃÁËÃûΪFoundCoreµÄ¶ñÒâÈí¼þ£¬¿É½øÐÐÎļþϵͳÀûÓᢽø³ÌÀûÓá¢ÆÁÄ»½ØÍ¼²¶×½ºÍÈÎÒâÃüÁîÖ´ÐС£´ËÍ⣬Kaspersky³Æ¸Ã×éÖ¯ÔÚÅÓ´óÐÔ·½ÃæÈ¡µÃÁËÖØ´ó½ø²½£¬ÀýÈ磬ÆäpayloadµÄ±êÍ·£¨´úÂëµÄÄ¿±êºÍÔ´£©±»ÍêÈ«°þÀ룬ʣϵÄÉÙÊý²¿ÃŵÄÖµÊDz»Á¬¹áµÄ£¬Õâ´ó´óÔö¼ÓÁËÑо¿ÈËÔ±¶ÔÆä½øÐзÖÎöµÄÄѶȡ£
ÔÎÄÁ´½Ó£º
https://threatpost.com/spy-operations-vietnam-rat/165243/
5.΢ÈíÐû²¼2021Äê3ÔÂSecurity SignalsµÄ·ÖÎö³ÂËß
΢ÈíÐû²¼ÁË2021Äê3ÔÂSecurity SignalsµÄ·ÖÎö³ÂËߣ¬ÊÓ²ìÁËÀ´×ÔÖйú¡¢µÂ¹ú¡¢ÈÕ±¾¡¢Ó¢¹úºÍÃÀ¹úµÄ1000λÆóÒµÄþ¾²¾ö²ßÕß¡£³ÂËß·¢ÏÖ£¬¹ýÈ¥Á½ÄêÖÐÓÐ80£¥µÄÆóÒµÔâµ½ÁËÖÁÉÙÒ»´Î¹Ì¼þ¹¥»÷£¬µ«Ö»ÓÐ29£¥µÄ×éÖ¯·ÖÅäÁËÔ¤ËãÀ´±£»¤¹Ì¼þ¡£NVD֤ʵÔÚ¹ýÈ¥ËÄÄêÖУ¬Õë¶Ô¹Ì¼þµÄ¹¥»÷Ôö¼ÓÁËÎå±¶ÒÔÉÏ¡£21£¥µÄ¾ö²ßÕßÈÏ¿ÉÎÞ·¨¼à¿Ø¹Ì¼þÊý¾Ý£¬82£¥×é֯ûÓÐ×ÊÔ´À´µÖÓù¹Ì¼þ¹¥»÷¡£81£¥µÄµÂ¹ú¹«Ë¾¡¢91£¥µÄÃÀ¹ú¡¢Ó¢¹úºÍÈÕ±¾¹«Ë¾ÒÔ¼°95£¥µÄÖйú¹«Ë¾Ô¸ÒâÔÚÕâ¸ö·½Ãæ½øÐÐͶ×Ê¡£
ÔÎÄÁ´½Ó£º
https://www.microsoft.com/en-us/secured-corepc
6.RavelinÐû²¼Óйصç×ÓÉÌÎñÆÛÕ©»î¶¯µÄ·ÖÎö³ÂËß
Ravelin¶ÔÈ«Çò1000¶à¼ÒÉ̼ҽøÐÐÁËÊӲ죬Ðû²¼ÁËÓйصç×ÓÉÌÎñÆÛÕ©»î¶¯µÄ·ÖÎö³ÂËß¡£³ÂËßÏÔʾ£¬½«½ü40£¥µÄ¿ìÏûÁãÊÛÉ̽«ÔÚÏßÖ§¸¶ÆÛÕ©ÊÓΪ×î´óµÄÆÛÕ©·çÏÕ£¬45%µÄ¹«Ë¾Ëù¾ÀúµÄÕË»§½Ó¹Ü(ATO)¹¥»÷ÓÐËùÔö¼Ó¡£³ÂËßÔ¤²â£¬µç×ÓÉÌÎñÐÐÒµÖÐµÄÆÛÕ©ÎÊÌâ¿ÉÄÜ»áÓúÑÝÓúÁÒ£¬ÓÈÆäÊÇËæ×ÅÐí¶à´«Í³µÄ¸ß½ÖÆ·ÅÆ£¨ÈçTopshopºÍDebenhams£©±»ÊÕ¹º²¢Íê³ÉÒµÎñÈ«²¿ÏòÏßÉÏתÐ͵Äʱºò¡£
ÔÎÄÁ´½Ó£º
https://pages.ravelin.com/retail-fraud-payments-report