AppleÄþ¾²¸üР£¬ÐÞ¸´macOSÖб»ShlayerÀûÓõÄ0day £»CiscoÅû¶LinuxÄÚºËÖпÉÈÆ¹ýKASLRµÄÐÅϢй¶©¶´

Ðû²¼Ê±¼ä 2021-04-28

1.AppleÄþ¾²¸üР£¬ÐÞ¸´macOSÖб»ShlayerÀûÓõÄ0day


1.jpg


AppleÐû²¼Äþ¾²¸üР£¬ÐÞ¸´macOS Big Sur 11.3ÖÐÒѱ»ÀûÓõÄ0day¡£Äþ¾²ÍŶÓJamf·¢ÏÖ £¬´Ó2021Äê1Ô¿ªÊ¼¶ñÒâÈí¼þShlayerÀûÓÃÁËÒ»¸ö0day£¨CVE-2021-30657£© £¬À´ÈƹýAppleµÄÎļþ¸ôÀë¡¢GatekeeperºÍ¹«Ö¤Äþ¾²¼ì²é £¬²¢ÏÂÔØµÚ¶þ½×¶ÎËùʹÓõÄpayload¡£´ËÍâ £¬´Ë´Î¸üл¹ÐÞ¸´ÁËiOS¡¢iPadOSºÍwatchOSÖеĶà¸ö0day £¬°üÂÞWebKit StorageµÄÄÚ´æËð»µÂ©¶´£¨CVE-2021-30661£©¡¢Ô¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2020-27930£©¡¢ÄÚºËÄÚ´æÐ¹Â¶Â©¶´£¨CVE-2020-27950£©ºÍÄÚºËÌØÈ¨ÌáÉý©¶´£¨CVE-2020-27932£©¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/apple-fixes-macos-zero-day-bug-exploited-by-shlayer-malware/


2.ValveÐû²¼¸üР£¬ÐÞ¸´SteamÖÐÒÑ´æÔÚÁ½ÄêµÄRCE©¶´


2.jpg


ValveÐû²¼¸üР£¬ÐÞ¸´ÓÎϷƽ̨SteamÖÐÒÑ´æÔÚÁ½ÄêµÄRCE©¶´¡£¸Ã©¶´¿ÉÔÚ¶ñÒâÓÎÏ·ÑûÇëÖÐÌí¼ÓÃüÁî £¬¶ÔÓÎÏ·×ö³ö΢СµÄµÄµ÷Õû £¬ÈçÐÞ¸ÄÓÎÏ·ÓïÑÔ¡¢ÁéÃô¶È¡¢·Ö±æÂʵÈ¡£µ«ÊÇÓÉÓÚSource RCONЭÒéÔÊÐí·þÎñÆ÷ËùÓÐÕßÔÚ·þÎñÆ÷ÖÐÖ´ÐÐÃüÁî £¬ÀûÓôËÌØÐÔ¿ÉÌᳫRCE¹¥»÷¡£´ËÍâ £¬Ñо¿ÈËÔ±»¹ÑÝʾÁËÈçºÎÀûÓøÃ©¶´À´ÍêÈ«½Ó¹ÜCS£ºGOÓÎÏ·Íæ¼ÒµÄÕ˺Å¡£Ñо¿ÈËÔ±FlorianÓÚ2019Äê³ÂËßÁ˸é¶´ £¬ValveÔÚ2021Äê4ÔÂ17ÈÕÐû²¼Á˲¹¶¡·¨Ê½ £¬²¢·ÖÅäÁËCVE-2021-30481¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2021/04/26/valve-finally-patched-a-steam-rce-vulnerability-that-waited-a-fix-for-two-years/


3.CiscoÅû¶LinuxÄÚºËÖпÉÈÆ¹ýKASLRµÄÐÅϢй¶©¶´


3.jpg


Cisco Talos³Æ £¬LinuxÄÚºËÖдæÔÚ¿ÉÈÆ¹ýKASLRµÄÐÅϢй¶©¶´¡£¸Ã©¶´±»×·×ÙΪCVE-2020-28588 £¬Î»ÓÚÔËÐÐLinuxµÄ32λARMÉ豸µÄ/proc/pid/ syscall¹¦Ð§ÖÐ £¬ÊÇÓÉÓÚ¶ÁÈ¡ÎļþʱÊýֵת»»²»ÕýÈ·¶øÒýÆðµÄ¡£Í¨¹ýʹÓü¸ÌõshellÃüÁî £¬¹¥»÷Õß¿ÉÒÔÊä³ö24¸ö×Ö½ÚµÄδ³õʼ»¯µÄ¶ÑÕ»ÄÚ´æ £¬ÕâЩÄÚ´æ¿ÉÒÔ±»ÓÃÀ´ÈƹýÄں˵ØÖ·¿Õ¼ä½á¹¹Ëæ»ú»¯£¨KASLR£©¡£Cisco½¨ÒéÓû§¾¡¿ì¸üÐÂÊÜÓ°ÏìµÄ²úÎïLinuxÄں˰汾5.10-rc4¡¢5.4.66ºÍ5.9.8¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/linux-kernel-bug-wider-cyberattacks/165640/


4.ÓÍÌ﹫˾GyrodataѬȾÀÕË÷Èí¼þ £¬Ô±¹¤Ãô¸ÐÐÅϢй¶


4.jpg


ÃÀ¹úÓÍÌ﹫˾Gyrodata͸¶ £¬ÆäÓÚ2ÔÂ21ÈÕ·¢ÏÖÔâµ½ÁËÀÕË÷Èí¼þ¹¥»÷ £¬Ô±¹¤Ãô¸ÐÐÅϢй¶¡£¾­ÊÓ²ìÈ·¶¨ £¬ºÚ¿ÍÔÚ2021Äê1ÔÂ16ÈÕÖÁ2ÔÂ22ÈÕÖ®¼ä¿ÉÒÔ·ÃÎÊÆä²¿ÃÅϵͳºÍÏà¹ØÊý¾Ý £¬¿ÉÄÜй¶ÁËÏÖÔ±¹¤ºÍǰԱ¹¤µÄ¸öÈËÐÅÏ¢ £¬°üÂÞ³öÉúÈÕÆÚ¡¢µØÖ·¡¢Éç»á±£Ïպš¢¼ÝÕÕºÅÂë¡¢»¤ÕÕºÅÂë¡¢W-2˰±íºÍ½¡¿µ¼Æ»®ÐÅÏ¢µÈ¡£½ØÖÁÉÏÖÜËÄ £¬¸Ã¹«Ë¾Ò»Ö±ÔÚÁªÏµÊÜÓ°ÏìµÄÔ±¹¤ £¬²¢½¨Á¢ÁËרÃŵĺô½ÐÖÐÐÄÀ´Ó¦¶Ô¿ÉÄÜ·ºÆðµÄÎÊÌâ¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/oilfield-services-company-gyrodata-discloses-data-breach


5.Reverb֪ͨ¿Í»§ÒòÆä·þÎñÆ÷ÅäÖôíÎóй¶560¶àÍòÌõ¼Ç¼


5.jpg


ReverbÓÚ4ÔÂ26ÈÕÏòÆä¿Í»§·¢ËÍÁËÊý¾Ýй¶֪ͨ £¬±íÃ÷ÒÑй¶Á˿ͻ§ÐÅÏ¢¡£ReverbÖ÷ÒªÔÚÏßÏúÊÛÀÖÆ÷µÈÉ豸 £¬´Ë´Îй¶µÄ¿Í»§ÐÅÏ¢°üÂÞÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢PayPalÓʼþµØÖ·ºÍ¶©µ¥ÐÅÏ¢µÈÄÚÈÝ¡£Reverb²¢Î´ÔÚ֪ͨÖÐ˵Ã÷ËûÃÇÊÇÒòºÎй¶Êý¾ÝµÄ £¬µ«Äþ¾²Ñо¿Ô±Bob Diachenko³ÆÆäÔÚInternetÉÏ·¢ÏÖÁËÒ»¸ö̻¶µÄElasticsearch·þÎñÆ÷ £¬ÆäÖаüÂÞÁè¼Ý560ÍòÌõ¼Ç¼¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/reverb-discloses-data-breach-exposing-musicians-personal-info/


6.ºÚ¿ÍÔÚ°µÍø¹ûÈ»ÃÀ¹ú2.5ÒÚ¸ö¹«ÃñµÄ¸öÈ˺ͼÒÍ¥ÐÅÏ¢


6.jpg


2021Äê4ÔÂ22ÈÕ £¬ÃûΪPompompurinµÄºÚ¿ÍÔÚ°µÍø¹ûÈ»ÁËÒ»¸öÊý¾Ý¿â £¬ÆäÖаüÂÞÁËÁè¼Ý250807711¸öÃÀ¹ú¹«ÃñµÄ¸öÈ˺ͼÒÍ¥ÐÅÏ¢¡£¸ÃÊý¾Ý¿âÓÐ263 GBµÄ¼Ç¼ £¬°üÂÞÁË1255¸öCSV×ÓÎļþ £¬Ã¿¸ö×ÓÎļþÓÐ200000¸öÁбí £¬°üÂÞÐÕÃû¡¢µç»°ºÅÂë¡¢ÓʼþµØÖ·¡¢³öÉúÈÕÆÚ¡¢»éÒö×´¿ö¡¢ÐÔ±ð¡¢ÐÅÓÃÄÜÁ¦¡¢ÕþÖÎÅɱ𡢳µÁ¾ÊýÁ¿¡¢ÊÕÈëÃ÷ϸºÍº¢×Ó¸öÊýµÈÄÚÈÝ¡£Ä¿Ç°Éв»Çå³þÊý¾ÝµÄÀ´Ô´ £¬Ïà¹ØÈËԱ͸¶À´×ÔAmazon Web ServerÉÏÍйܵĿª·ÅʽApache SOLR¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/hacker-dumps-household-records-of-americans/