ÃÀ¹úÕþ¸®È·ÈÏSolarWinds¹¥»÷Óë¶íÂÞ˹Ç鱨¾ÖSVRÓйØ£»Ó¡¶ÈBizongoµÄ´æ´¢Í°ÅäÖôíÎó£¬Ð¹Â¶643 GBµÄÊý¾Ý

Ðû²¼Ê±¼ä 2021-04-16

1.ÃÀ¹úÕþ¸®È·ÈÏSolarWinds¹¥»÷Óë¶íÂÞ˹Ç鱨¾ÖSVRÓйØ


1.jpg


ÃÀ¹úÕþ¸®Õýʽָ¿Ø¶íÂÞ˹Õþ¸®ÌᳫÁËSolarWinds¹©Ó¦Á´¹¥»÷£¬Ó°ÏìÁËÃÀ¹úµÄ¶à¸ö×éÖ¯ºÍ¹«Ë¾¼¼Êõ²¿ÃŵÄÍøÂç¡£½ñÄê1Ô³õ£¬ÍøÂçͳһЭµ÷С×飨UCG£©½«´Ë´Î¹¥»÷¹éÒòÓÚ¶íÂÞ˹Åä¾°µÄºÚ¿Í×éÖ¯£¬µ«Î´Ö¸³ö¾ßÌåÃû³Æ¡£4ÔÂ15ÈÕ£¬°×¹¬ÕýʽȷÈ϶íÂÞ˹Íâ¹úÇ鱨¾ÖSVRÊǴ˴ι¥»÷µÄÄ»ºóºÚÊÖ£¬Í¨¹ýÆäºÚ¿Í²¿ÃÅAPT29£¨ÓÖ³ÆCozy Bear£©¿ªÕ¹µÄÍøÂç¼äµý»î¶¯¡£´ËÍ⣬ÃÀ¹úNSA¡¢CISAºÍFBIÁªºÏÐû²¼ÁËÄþ¾²×Éѯ£¬¾¯¸æSVRÔÚ¹¥»÷ÖÐÀûÓõÄÎå¸öÖ÷ÒªµÄ©¶´¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-government-confirms-russian-svr-behind-the-solarwinds-hack/


2.Ó¡¶ÈBizongoµÄ´æ´¢Í°ÅäÖôíÎó£¬Ð¹Â¶643 GBµÄÊý¾Ý


2.jpg


Ó¡¶ÈB2B°ü×°Êг¡BizongoÒòAWS S3´æ´¢Í°ÅäÖôíÎó£¬Ð¹Â¶643 GBµÄÊý¾Ý¡£´Ë´Îй¶µÄÊý¾ÝÉæ¼°Óû§µÄPIIºÍBizongoµÄ¸¶¿îÐÅÏ¢£¬°üÂÞÓû§µÄÐÕÃû¡¢µç»°ºÅÂë¡¢Õʵ¥µØÖ·¡¢ÊÕ»õµØÖ·¡¢ÔËËͺ͸ú×Ù±àºÅ¡¢Õʵ¥Ã÷ϸºÍ¿Í»§µÄ²ÆÕþÃ÷ϸµÈ¡£Website PlanetµÄÑо¿ÈËÔ±ÓÚ2020Äê12ÔÂÏÂÑ®·¢Ïָô洢Ͱ£¬²¢Á¢¼´¾Í´ËʼþÓëBizongoÁªÏµ£¬µ«Ä¿Ç°ÈÔδÊÕµ½ÈκλØÓ¦¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/india-bizongo-supply-chain-exposed-data/


3.SAPÐû²¼Äþ¾²¸üУ¬ÐÞ¸´Æä²úÎïÖеĶà¸öÑÏÖØµÄ©¶´


3.jpg


±¾Öܶþ£¬SAPÐû²¼Äþ¾²¸üУ¬ÐÞ¸´ÁËBusiness Client¡¢CommerceºÍNetWeaverÖеÄ×ܼƶà¸ö©¶´¡£ÆäÖнÏΪÑÏÖØµÄÊÇCommerceÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-27602£©£¬µÃ·ÖΪ9.8£»ÒÔ¼°NetWeaver¶ÑÕ»µÄMigration Service×é¼þÖеÄCVE-2021-21481£¬µÃ·ÖΪ9.6£¬Î´¾­ÊÚȨµÄ¹¥»÷Õß¿ÉÒÔ·ÃÎÊÅäÖù¤¾ßÒÔ»ñµÃϵͳÉϵĹÜÀíȨÏÞ¡£´ËÍ⣬»¹ÐÞ¸´ÁËCVE-2021-21482¡¢CVE-2021-21483ºÍCVE-2020-26832µÈ©¶´¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/sap-fixes-critical-bugs-in-business-client-commerce-and-netweaver/


4.Census LabsÅû¶°²×¿°æ±¾WhatsAppµÄ´úÂëÖ´ÐЩ¶´


4.jpg


Census LabsµÄÑо¿ÈËÔ±Åû¶Á˰²×¿°æ±¾µÄWhatsAppÖеÄÁ½¸ö´úÂëÖ´ÐЩ¶´£¬¿É±»ÓÃÀ´ÔÚÄ¿±êÉ豸ÉÏÖ´ÐжñÒâ´úÂë²¢ÇÔÌýͨÐÅ¡£ÕâÁ½¸ö©¶´¿ÉÓÃÀ´Ô¶³ÌÊÕ¼¯TLS 1.3ºÍTLS 1.2»á»°µÄTLS¼ÓÃÜÐÅÏ¢£¬²¢ÌᳫÖмäÈË£¨MitM£©¹¥»÷¡£ÓÈÆäÊÇCVE-2021-24027©¶´£¬ÀûÓÃÁËChrome¶ÔAndroidÖÐÄÚÈÝÌṩÕßµÄÖ§³ÖÒÔ¼°ä¯ÀÀÆ÷ÖеÄͬԴ¼ÆÄ±Èƹý©¶´£¨CVE-2020-6516£©£¬Í¨¹ýWhatsApp½«ÌØÖƵÄHTMLÎļþ·¢Ë͸øÊܺ¦Õߣ¬µ±Êܺ¦ÕßÔÚä¯ÀÀÆ÷Öдò¿ªºó£¬½«Ö´ÐиÃÎļþÖаüÂ޵ĴúÂë¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116833/hacking/whatsapp-flaws-remote-hack.html


5.FireEyeÐû²¼ÃûΪM-Trend 2021µÄÄê¶È·ÖÎö³ÂËß


5.jpg


FireEye»ùÓÚ¶ÔÆä¹ÜÀíµÄÄþ¾²Ê¼þ½øÐÐÊÓ²ìÆÚ¼äÊÕ¼¯µÄÊý¾Ý£¬Ðû²¼ÁËÃûΪM-Trend 2021µÄÄê·ÖÎö¶È³ÂËß¡£FireEye MandiantÊÓ²ìÁË246¸öºÚ¿Í×éÖ¯µÄ¹¥»÷»î¶¯£¬ÆäÖаüÂÞ4¸ö²ÆÕþÍþв£¨FIN£©×éÖ¯£¬6¸ö¸ß¼¶Á¬ÐøÍþв£¨APT£©×éÖ¯ºÍ236¸öδ·ÖÀàÍþв£¨UNC£©×éÖ¯¡£´ËÍ⣬ǰ5ÖÖ¶ñÒâÈí¼þÀà±ðÊǺóÃÅ£¨36£¥£©¡¢ÏÂÔØÆ÷£¨16£¥£©¡¢droppers£¨8£¥£©¡¢Æô¶¯Æ÷£¨7£¥£©ºÍÀÕË÷Èí¼þ£¨5£¥£©£¬Ç°5¸ö¶ñÒâÈí¼þ¼Ò×å·Ö±ðÊÇBEACON¡¢EMPIRE¡¢MAZE¡¢NETWALKERºÍMetasploit¡£


Ô­ÎÄÁ´½Ó£º

https://content.fireeye.com/m-trends/rpt-m-trends-2021


6.CISAÐû²¼Õë¶ÔÍøÂçÄþ¾²Ñо¿ÈËÔ±µÄAPT»î¶¯µÄ¾¯±¨


6.jpg


CISAÐû²¼ÁËÕë¶ÔÍøÂçÄþ¾²Ñо¿ÈËÔ±µÄAPT»î¶¯µÄ¾¯±¨¡£¾¯±¨Ö¸³öAPT¹¥»÷ÕßÕýÔÚʹÓÃαÔìµÄÉ罻ýÌå×ÊÁϺÍÃ²ËÆºÏ·¨µÄÍøÕ¾À´ÓÕ»óÄþ¾²Ñо¿ÈËÔ±·ÃÎʶñÒâÍøÕ¾£¬ÒÔÇÔÈ¡°üÂÞ©¶´ÀûÓúÍÁãÈÕ©¶´ÔÚÄÚµÄÐÅÏ¢¡£´ËÍ⣬GoogleºÍMicrosoft×î½ü¶¼Ðû²¼ÁËÕë¶Ô´ËÀ๥»÷µÄ³ÂËß¡£CISA½¨ÒéÍøÂçÄþ¾²´ÓÒµÈËÔ±ÔÚ·ÃÎʲ»ÊÜÐÅÈεĴúÂë»òÍøÕ¾Ê±£¬Ê¹ÓÃÓëÊÜÐÅÈεÄϵͳºÍÍøÂç¸ôÀëµÄɳºÐ»·¾³¡£ 


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/04/14/threat-actors-targeting-cybersecurity-researchers