Å·ÃË³ÆÆä¶à¸ö»ú¹¹ÔÚÉÏÖÜÔâµ½¹¥»÷£¬Ê¼þÈÔÔÚÊÓ²ìÖУ»ºÚ¿ÍÔÚ°µÍø³öÊÛÊýǧ¼ÒÉ̵êµÄ¼ÛÖµ3800ÍòÃÀÔªµÄÀñÆ·¿¨

Ðû²¼Ê±¼ä 2021-04-08

1.Å·ÃË³ÆÆä¶à¸ö»ú¹¹ÔÚÉÏÖÜÔâµ½¹¥»÷£¬Ê¼þÈÔÔÚÊÓ²ìÖÐ


1.jpg


Å·ÃËίԱ»á·¢ÑÔÈ˳Æ£¬°üÂÞίԱ»áÔÚÄڵĶà¸öÅ·ÃË×éÖ¯ÔÚÉÏÖÜÔâµ½ÁËÍøÂç¹¥»÷¡£ÏÖÔÚ¶Ô¸ÃʼþµÄȡ֤·ÖÎöÈÔ´¦ÓÚ³õÆÚ½×¶Î£¬ÉÐδ¼ì²âµ½´æÔÚÐÅϢй¶ÎÊÌâ¡£Åí²©ÉçÌåÏÖ£¬´Ë´Îʼþ±ÈÅ·ÃËÒÔÍùÔâµ½µÄ¹¥»÷¸üΪÑÏÖØ£¬Å·ÃËij¹ÙÔ±»¹Í¸Â¶£¬ÆäÊÂÇéÈËÔ±½üÆÚÊÕµ½ÁËÓйØÕë¶ÔÅ·Ã˵ĵöÓã¹¥»÷Ô¤¾¯¡£Ä¿Ç°£¬Å·ÃËÈÔδ¹ûÈ»Óйش˴ÎʼþµÄÐÔÖÊ»òÆä±³ºóµÄ¹¥»÷ÕßÉí·ÝµÄÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://www.bloomberg.com/news/articles/2021-04-06/european-institutions-were-targeted-in-a-cyber-attack-last-week


2.CiscoÄþ¾²¸üУ¬ÐÞ¸´SD-WAN vManageÖеÄRCE©¶´


2.jpg


CiscoÐû²¼Äþ¾²¸üУ¬ÐÞ¸´SD-WAN vManageÈí¼þµÄÔ¶³Ì¹ÜÀí×é¼þÖеÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©Â©¶´¡£¸Ã©¶´±»×·×ÙΪCVE-2021-1479£¬ÑÏÖØÐԵ÷ÖΪ9.8 £¬ÀֳɵÄÀûÓÃÀÖ³ÉÀûÓøÃ©¶´¿ÉÒÔrootȨÏÞÔڵײã²Ù×÷ϵͳÉÏÖ´ÐÐÈÎÒâ´úÂë¡£´Ë´Î¸üл¹ÐÞ¸´Á˸òúÎïµÄÓû§¹ÜÀí¹¦Ð§ºÍϵͳÎļþ´«Ê书ЧÖеÄ2¸öÌáȨ©¶´£¨CVE-2021-1137ºÍCVE-2021-1480£©¡£´ËÍ⣬Cisco»¹Åû¶ÁËСÆóҵ·ÓÉÆ÷ÖеÄRCE©¶´(CVE-2021-1459)£¬µ«ÒòΪÕâЩÉ豸ÒÑÖÁEOL£¬Òò´Ë²¢Î´Ðû²¼Ïà¹Ø²¹¶¡¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/cisco-fixes-bug-allowing-remote-code-execution-with-root-privileges/


3.ºÚ¿ÍÔÚ°µÍø³öÊÛÊýǧ¼ÒÉ̵êµÄ¼ÛÖµ3800ÍòÃÀÔªµÄÀñÆ·¿¨


3.jpg


¶íÂÞ˹ºÚ¿ÍÔÚ°µÍøÉϳöÊÛÀ´×Ô3010¼Ò¹«Ë¾½ü900000ÕÅÀñÆ·¿¨£¬×ܼÛÖµÔ¤¼ÆÎª3800ÍòÃÀÔª£¬Éæ¼°Airbnb¡¢ÑÇÂíÑ·¡¢ÍòºÀ¾Æµê¡¢ÄͿˣ¬SubwayºÍÎÖ¶ûÂêµÈÉ̵ê¡£×îÖÕ£¬Âô¼ÒÒÔ20000ÃÀÔªµÄ¼Û¸ñÂô³öÁËÕâЩÀñÆ·¿¨£¬Gemini AdvisoryÌåÏÖ£¬ÀñÆ·¿¨µÄÊÛ¼Ûͨ³£ÎªÆä¼ÛÖµµÄ10£¥£¬µ«´Ë´ÎµÄÊÛ¼ÛÖ»ÓÐԼΪ0.05£¥¡£ÔÚ³öÊÛÀñÆ·¿¨µÄµÚ¶þÌ죬¸ÃºÚ¿ÍÓÖÒÔ15000ÃÀÔªµÄ¼Û¸ñ³öÊÛÁË330000ÕÅÐÅÓÿ¨µÄÊý¾Ý£¬°üÂÞÕʵ¥µØÖ·¡¢¿¨ºÅ¡¢ÓÐЧÆÚºÍ·¢¿¨ÐÐÃû³ÆµÈÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hacker-sells-38m-worth-of-gift-cards-from-thousands-of-shops/


4.°®¶ûÀ¼¹úÁ¢Ñ§ÔººÍ¶¼°ØÁÖÀí¹¤´óѧ³ÆÆäITϵͳÔâµ½ÀÕË÷¹¥»÷


4.jpg


°®¶ûÀ¼¹úÁ¢Ñ§Ôº£¨NCI£©ºÍ¶¼°ØÁֿƼ¼´óѧÐû²¼£¬ÆäITϵͳÔâµ½ÀÕË÷¹¥»÷¡£NCIÔÚ4ÔÂ3ÈÕÔâµ½¹¥»÷£¬ÆäITϵͳ±»ÆÈ¹Ø±Õ£¬µ¼ÖÂMoodle¡¢Í¼Êé¹Ý·þÎñºÍѧÉúµÄMyDetailsµÈ·þÎñÖжÏ£¬4ÔÂ6ÈÕÖÁ8ÈÕµÄËùÓпγ̡¢ÆÀ¹ÀºÍÈëÖ°Åàѵ¶¼ÒÑÍÆ³Ù¡£¶¼°ØÁÖ¹¤Òµ´óѧ£¨TU Dublin£©ÔÚÖÜËÄÔçÉÏÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬Ñ§Ð£ITϵͳºÍÊý¾Ý±¸·ÝÊܵ½Ó°Ï죬¸ÃУÌåÏÖĿǰÈÔ´¦ÓÚÊÓ²ìµÄ³õÆÚ½×¶Î£¬»¹ÒªÇóѧÉúÔÚÏÂÖÜÒ»£¨4ÔÂ12ÈÕ£©Ö®Ç°²»ÒªÊ¹ÓÃÈκÎУ԰ITϵͳ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ransomware-hits-tu-dublin-and-national-college-of-ireland/


5.ESETÅû¶Õë¶ÔÀ­¶¡ÃÀÖÞµØÓòÓû§µÄÐÂÒøÐÐľÂíJaneleiro


5.jpg


ESETµÄÑо¿ÈËÔ±Åû¶ÁËÕë¶ÔÀ­¶¡ÃÀÖÞµØÓòÓû§µÄÐÂÐÍÒøÐÐľÂíJaneleiro¡£¸ÃľÂíÖÁÉÙ´Ó2019ÄêÒÔÀ´¾Í¿ªÊ¼Õë¶Ô°ÍÎ÷µÄÆóÒµ£¬Éæ¼°¹¤³Ì¡¢Ò½ÁƱ£½¡¡¢ÁãÊÛ¡¢ÖÆÔìÒµ¡¢½ðÈÚ¡¢ÔËÊäºÍÕþ¸®µÈ¸÷¸öÁìÓò¡£Janeleiroͨ¹ýαÔì´óÐÍÒøÐÐÍøÕ¾£¨SantanderºÍBanco do BrasilµÈ£©µÄµ¯´°À´ÓÕ»óÄ¿±ê£¬ÕâЩµ¯´°°üÂÞÐé¼ÙµÄ±í¸ñÀ´ÓÕʹĿ±êÊäÈëÒøÐÐÆ¾Ö¤ºÍ¸öÈËÐÅÏ¢¡£´ËÍ⣬JaneleiroÊÇÓÉVisual Basic .NET±àдµÄ£¬ÕâÓë¸ÃµØÓòµÄºÚ¿ÍËùϲ»¶µÄDelphiÓкܴóµÄÊÕÖ§¡£    


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/04/experts-uncover-new-banking-trojan.html


6.Intel 471ÍŶӳƶ¥¼¶ºÚ¿ÍÍÅ»ïÆ«°®EtterSilentÉú³ÉÆ÷


6.jpg


Intel 471Ñо¿ÍŶӳƶ¥¼¶ºÚ¿ÍÍÅ»ïÆ«°®EtterSilent¶ñÒâÎĵµÉú³ÉÆ÷¡£ºÚ¿Í´Ó2020Ä꿪ʼÔÚ°µÍøÐû²¼ÓйØEtterSilentµÄ¹ã¸æ£¬³ÆÆä¿ÉÈÆ¹ýWindows Defender¡¢Windows AMSI·´¶ñÒâÈí¼þɨÃè½çÃæºÍÁ÷Ðеĵç×ÓÓʼþ·þÎñ£¨°üÂÞGmail£©µÈ¡£¸Ã¹¤¾ß¿ÉÌṩÁ½ÀàÐ͵ĶñÒâÎĵµ£¨maldocs£©£¬ÆäÒ»ÊÇÀûÓÃMicrosoft OfficeÖеÄÒÑ֪©¶´CVE-2017-8570¡¢CVE-2017-11882ºÍCVE-2018-0802µÈ£¬ÁíÒ»ÖÖÊÇʹÓöñÒâºê¡£


Ô­ÎÄÁ´½Ó£º

https://intel471.com/blog/ettersilent-maldoc-builder-macro-trickbot-qbot/