MicrosoftÐû²¼5Ô²¹¶¡£¬ÐÞ¸´3¸ö0dayÔÚÄÚµÄ55¸ö©¶´£»ÃÀ¹úºÍ°Ä´óÀûÑǾ¯¸æÕë¶ÔÈ«ÇòµÄAvaddonÀÕË÷Èí¼þ»î¶¯

Ðû²¼Ê±¼ä 2021-05-12

1.MicrosoftÐû²¼5Ô²¹¶¡£¬ÐÞ¸´3¸ö0dayÔÚÄÚµÄ55¸ö©¶´


1.jpg


MicrosoftÐû²¼5Ô·ݵÄÖܶþ²¹¶¡£¬ÐÞ¸´°üÂÞ3¸ö0dayÔÚÄÚµÄ55¸ö©¶´¡£´Ë´ÎÐÞ¸´µÄ0 day·Ö±ðÊÇNETºÍVisual StudioÖеÄÌáȨ©¶´£¨CVE-2021-31204£©¡¢Microsoft Exchange ServerÖеÄÄþ¾²¹¦Ð§Èƹý©¶´£¨CVE-2021-31207£©ºÍͨÓù¤¾ßÖеÄÔ¶³ÌÖ´ÐдúÂë©¶´£¨CVE-2021-31200£©£¬ÕâЩ©¶´»¹Î´±»ÔÚÒ°ÀûÓᣴËÍ⣬»¹ÐÞ¸´ÁËHTTP.sysÖеÄÔ¶³ÌÖ´ÐдúÂë©¶´£¨CVE-2021-31166£©ºÍIEä¯ÀÀÆ÷ÖеÄÄÚ´æËð»µÂ©¶´£¨CVE-2021-26419£©µÈ©¶´¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/microsoft-patch-tuesday-55-vulnerabilities-4-critical-3-publicly-known


2.CiscoÅû¶Lemon DuckÕë¶Ô±±ÃÀµØÓòµÄÐÂÒ»ÂÖ¹¥»÷»î¶¯


2.jpg


Cisco TalosÑо¿ÈËÔ±·¢ÏÖLemon DuckÕë¶Ô±±ÃÀµØÓòµÄÐÂÒ»ÂÖ¹¥»÷»î¶¯¸Ä±äÁ˹¥»÷¼ÆÄ±¡£È¥Äê8Ô£¬Lemon DuckÖ÷ÒªÕë¶Ô°£¼°¡¢Ó¡¶È¡¢ÒÁÀÊ¡¢·ÆÂɱöºÍÔ½ÄϽøÐÐÍÚ¿óµÄ»î¶¯¡£ÔÚ4Ô·ݿªÊ¼µÄÐÂÒ»ÂÖÖУ¬¸ÃÍÅ»ï¸Ä±äÁËÄ¿±ê£¬Ö÷ÒªÕë¶Ô±±ÃÀµØÓò£¬Æä´ÎÊÇÅ·ÖÞ¡¢¶«ÄÏÑÇ¡¢·ÇÖÞºÍÄÏÃÀ¡£Ôڴ˴ι¥»÷»î¶¯ÖУ¬¸ÃÍÅ»ïʹÓÃÁËCobalt Strike¹¥»÷¿ò¼Ü£¬²¢ÔÚ¶«ÑǶ¥¼¶ÓòÃû£¨TLD£©ÉÏʹÓÃαÔìµÄÓòÃûÀ´Òþ²ØÃüÁîºÍ¿ØÖÆ£¨C2£©»ù´¡¼Ü¹¹£¬Ö¼ÔÚÔöÇ¿·´¼ì²âµÄÄÜÁ¦¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/lemon-duck-cryptojacking-botnet-tactics/165986/


3.ÃÀ¹úºÍ°Ä´óÀûÑǾ¯¸æÕë¶ÔÈ«ÇòµÄAvaddonÀÕË÷Èí¼þ»î¶¯


3.jpg


ÃÀ¹úÁª°îÊÓ²ì¾Ö£¨FBI£©ºÍ°Ä´óÀûÑÇÍøÂçÄþ¾²ÖÐÐÄ£¨ACSC£©¾¯¸æÕë¶ÔÈ«ÇòµÄAvaddonÀÕË÷Èí¼þ¹¥»÷»î¶¯¡£FBIÌåÏÖ£¬AvaddonÀÕË÷Èí¼þÕýÊÔͼ¹¥»÷È«ÇòµÄÖÆÔì¡¢Ò½ÁƱ£½¡ºÍÆäËûÐÐÒµ×éÖ¯µÄÍøÂç¡£ACSCÔòÖ¸³ö¸ÃÍÅ»ïÖ÷ÒªÕë¶ÔÕþ¸®¡¢½ðÈÚ¡¢Ö´·¨¡¢ÄÜÔ´¡¢ÐÅÏ¢¼¼ÊõºÍÎÀÉúµÈÐÐÒµ£¬²¢ÁгöÁËÊܵ½¹¥»÷µÄ¹ú¼ÒµÄÇåµ¥£¬°üÂÞÃÀ¹ú¡¢Ó¢¹ú¡¢µÂ¹ú¡¢Öйú¡¢°ÍÎ÷¡¢Ó¡¶È¡¢°¢ÁªÇõ¡¢·¨¹úºÍÎ÷°àÑÀµÈ¡£´ËÍ⣬ACSC³ÆAvaddonÖ÷ÒªÀûÓþܾø·þÎñ£¨DDoS£©¹¥»÷À´ÍþвÊܺ¦Õߣ¬µ«FBIÌåÏÖÉÐδ·¢ÏÖÓйØAvaddonÍŻ﷢¶¯DDoS¹¥»÷µÄÖ¤¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/117765/malware/avaddon-targets-orgs-worldwide.html


4.Cleafy·¢ÏÖ¶ñÒâÈí¼þTeaBotÒѹ¥»÷Å·ÖÞµÄ60¶à¼ÒÒøÐÐ


4.jpg


Òâ´óÀûCleafyµÄÄþ¾²ÍŶӷ¢ÏÖ¶ñÒâÈí¼þTeaBotÒѹ¥»÷Å·ÖÞµÄ60¶à¼ÒÒøÐС£¸Ã¶ñÒâÈí¼þÈÔ´¦ÓÚ¿ª·¢µÄÔçÆÚ½×¶Î£¬µ«¾ß±¸Ô¶³Ì¿ØÖÆÄ¿±êÉ豸¡¢ÇÔÈ¡µÇ¼ƾ¾Ý¡¢·¢ËͺÍÀ¹½ØSMSÏûÏ¢µÈ¹¦Ð§¡£¸Ã¶ñÒâÈí¼þÖ§³Ö6ÖÖ²îÒìµÄÓïÑÔ£¬°üÂÞµÂÓï¡¢Ó¢Óï¡¢Òâ´óÀûÓï¡¢·¨Óï¡¢Î÷°àÑÀÓïºÍºÉÀ¼Óï¡£µ½Ä¿Ç°ÎªÖ¹£¬CleafyÒÑÈ·¶¨Òâ´óÀû¡¢Î÷°àÑÀ¡¢µÂ¹ú¡¢±ÈÀûʱºÍºÉÀ¼µÈ¶à¸öÅ·ÖÞ¹ú¼ÒµÄ60¶à¼ÒÒøÐÐÔâµ½Á˹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/teabot-android-malware-steals-data-sms/


5.Office 365¸ôÀëÀ´×ÔGoogleºÍLinkedInµÈÓòµÄºÏ·¨Óʼþ


5.jpg


΢ÈíÔÚMicrosoft 365¹ÜÀíÖÐÐÄÌåÏÖ£¬Ä³Ð©Óû§µÄOffice 365µÄExchange Online Protection£¦Defender»á½«À´×Ô¶à¸öÓò£¨°üÂÞGoogleºÍLinkedIn£©µÄºÏ·¨µç×ÓÓʼþ¸ôÀë»ò±ê־Ϊ¶ñÒâµç×ÓÓʼþ¡£Ä¿Ç°£¬Î¢ÈíÒѽâ¾öÁ˸ÃÎÊÌâ²¢ÖØÐ·¢Ëͱ»¸ôÀëµÄÓʼþ¡£´ËÍ⣬΢Èí11ÈÕÐû²¼µÄOutlook¸üе¼ÖÂÈ«Çò·¶Î§ÄÚµÄÓû§ÎÞ·¨¼ì²ì»ò´´½¨µç×ÓÓʼþ£¬ÌرðÊÇÔÚ´´½¨ÐÂÓʼþʱ£¬Ã¿´Î°´Enter¼ü£¬ÏÈǰ±àдµÄËùÓÐÄÚÈݶ¼½«±»É¾³ý¡£Î¢Èí½¨ÒéÓû§»Ø¹öµ½4Ôµİ汾£¬»òÔÚÄþ¾²Ä£Ê½ÏÂÆô¶¯Outlook¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-office-365-is-blocking-emails-from-google-linkedin-domains/


6.NatWestÒøÐÐ֪ͨ¿Í»§Òòϵͳ´íÎó£¬×Ô¶¯¿Û¿î¿ÉÄܶéÂä


6.jpg


Ó¢¹úNatWestÒøÐÐ֪ͨ¿Í»§Òòϵͳ´íÎó£¬×Ô¶¯¿Û¿î¿ÉÄܶéÂä¡£Ó¢¹úÒøÐпͻ§Í¨³£Ê¹ÓÃÀι̶©µ¥À´Ö§¸¶Õ˵¥¡¢×â½ðºÍÆä¶¨ÆÚ¸¶¿î¡£Í¨Àý¶©µ¥°üÂÞ¸¶¿î½ð¶î¡¢¸¶¿îƵÂÊ£¨¼´Ã¿ÖÜ¡¢Ã¿Ô¡¢Ã¿¼¾¶ÈµÈ£©ÒÔ¼°¸¶¿îÓ¦ÔÚºÎʱ½áÊø¡£´Ë´Îϵͳ¹ÊÕϵ¼Ö¿ͻ§ËùÉèÖõÄͨÀý¶©µ¥Ã»ÓÐÕýÈ·µØ¼Ç¼×Ô¶¯¸¶¿îµÄÆÚÊý»òÍ£Ö¹¸¶¿îÈÕÆÚ£¬ÕâÒâζ×Ŷ©µ¥½áÊøºóÈÔ¿ÉÄÜÔÚ¿Í»§ÕË»§ÖÐ×Ô¶¯¿Û¿î¡£ÓÉÓÚ´íÎóÒÑÁ¬ÐøÁË11¸öÔÂÒÔÉÏ£¬Òò´Ë¸ÃÐн¨Òé¿Í»§¼ì²éÆäÕË»§ÖÐ×Ô2020Äê3ÔÂ23ÈÕÒÔÀ´½»Ò׵ĿîÏî¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/technology/natwest-bank-scheduled-payments-bug-may-have-cost-you-money/