Ñо¿ÈËÔ±Åû¶FragAttacks£¬Ó°Ïì½ü24ÄêËùÓÐWi-FiÉ豸 £»AdobeÐû²¼Äþ¾²¸üУ¬ÐÞ¸´12¿î²úÎïÖеÄ43¸ö©¶´

Ðû²¼Ê±¼ä 2021-05-13

1.Ñо¿ÈËÔ±Åû¶FragAttacks£¬Ó°Ïì½ü24ÄêËùÓÐWi-FiÉ豸


1.jpg


±ÈÀûʱÄþ¾²Ñо¿Ô±Mathy VanhoefÅû¶Á˱»Í³³ÆÎªFragAttacksµÄ¶à¸ö©¶´£¬Ó°ÏìÁË1997ÄêÖÁ½ñµÄËùÓÐWi-FiÉ豸£¨°üÂÞ¼ÆËã»ú¡¢ÖÇÄÜÊÖ»úºÍÖÇÄÜÉ豸£©¡£ÔÚÕâЩ©¶´ÖУ¬ÓÐ3¸öÊÇWi-Fi 802.11³ß¶ÈÔÚÖ¡¾ÛºÏºÍÖ¡Ë鯬¹¦Ð§ÉϵÄÉè¼ÆÈ±ÏÝ£¬¶øÆäËû©¶´ÔòÊÇWi-Fi²úÎïÖеıà³Ì´íÎó¡£Vanhoef³Æ£¬ÊµÑé½á¹ûÏÔʾÿ¸öWi-Fi²úÎï¶¼´æÔÚÖÁÉÙÒ»¸ö©¶´ÇÒ´ó¶àÊý²úÎï´æÔÚ¶à¸ö©¶´£¬Ö»ÓÐNetBSDºÍOpenBSD²»ÊÜÓ°Ï죬ÒòΪËüÃDz»Ö§³ÖA-MSDUµÄ½ÓÊÕ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/117819/hacking/wifi-fragattacks.html


2.AdobeÐû²¼Äþ¾²¸üУ¬ÐÞ¸´12¿î²úÎïÖеÄ43¸ö©¶´


2.jpg


AdobeÐû²¼ÁË´ó¹æÄ£µÄÖܶþ²¹¶¡³Ì£¬ÐÞ¸´ÁË12¿î²úÎïÖеÄ43¸ö©¶´¡£´Ë´ÎÄþ¾²¸üÐÂÐÞ¸´ÁËAdobe AcrobatºÍReaderÖÐÒѱ»ÔÚÒ°ÀûÓõÄÔ¶³ÌÖ´ÐдúÂë©¶´£¨CVE-2021-28550£©£¬¹¥»÷Õß¿ÉÀûÓÃÆäÔÚÄ¿±êϵͳÖа²×°¶ñÒâÈí¼þ»ò½Ó¹Ü¼ÆËã»ú¡£´ËÍ⣬»¹ÐÞ¸´ÁËAcrobatºÍReaderÖеÄÈÎÒâ´úÂëÖ´ÐеÄ©¶´£¨CVE-2021-28562ºÍCVE-2021-28553£©¡¢ IllustratorÖеÄÔ½½çд©¶´£¨CVE-2021-21101£©ºÍAEMÖеÄXSS©¶´£¨CVE-2021-21084£©µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-fixes-reader-zero-day-vulnerability-exploited-in-the-wild/


3.αװΪChromeµÄAndroid¶ñÒâÈí¼þÒÑѬȾÊýÊ®ÍòÉ豸


3.jpg


PradeoµÄÑо¿ÈËÔ±·¢ÏÖ£¬ÔÚ¹ýÈ¥µÄ¼¸ÖÜÖУ¬Î±×°ÎªChromeµÄÒ»ÖÖеÄAndroid¶ñÒâÈí¼þÒÑѬȾÊýÊ®ÍòÉ豸¡£ºÚ¿Í»áÏòÄ¿±ê·¢ËÍÒ»Ìõ¶ÌÐÅ£¬ÒªÇóËûÃÇÖ§¸¶º£¹ØÓöÈÀ´Í¶µÝ°ü¹ü¡£µ±Ä¿±êµã»÷¶ÌÐÅÖеÄÁ´½Óºó¾Í»áµ¯³öÒ»ÌõÐÅÏ¢£¬ÌáʾËûÃǸüÐÂChromeÓ¦Ó÷¨Ê½¡£Ö®ºóÓû§»á±»Öض¨Ïòµ½µöÓãÍøÕ¾£¬²¢±»ÒªÇóÖ§¸¶Ò»Ð¡±ÊÇ®£¨Í¨³£Îª1»ò2ÃÀÔª£©ÒÔÊÕ¼¯ÐÅÓÿ¨ÏêϸÐÅÏ¢¡£´ËÍ⣬¸ÃαÔìµÄChrome»áÀûÓñ»Ñ¬È¾µÄÊÖ»úÿÌì×Ô¶¯·¢ËÍ300ÌõµöÓã¶ÌÐŽøÐÐÁ÷´«¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/fake-chrome-app-worming-smish-cyberattack/166038/


4.United ValorÔâÀÕË÷¹¥»÷£¬Ð¹Â¶ÃÀ¹ú20ÍòÍËÎé¾üÈËÐÅÏ¢


4.png


Jeremiah FowlerÓÚ4ÔÂ18ÈÕ·¢ÏÖUnited Valorй¶Á˽ü20ÍòÃûÃÀ¹úÍËÎé¾üÈ˵ÄÒ½ÁƼǼ¡£United ValorÊDZ±¿¨ÂÞÀ´ÄÉÖݵÄÒ»¼ÒΪÍËÎé¾üÈ˹ÜÀí¾ÖÒÔ¼°ÆäËûÁª°îºÍÖݵĻú¹¹Ìṩ²Ð¼²ÆÀ¹À·þÎñµÄ¹«Ë¾¡£´Ë´Îй¶µÄÐÅÏ¢°üÂÞÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Ò½ÁÆÐÅÏ¢¡¢ÁªÏµÐÅÏ¢¡¢Ò½ÉúÐÅÏ¢ºÍԤԼʱ¼ä£¬ÒÔ¼°ÁËδ¼ÓÃܵÄÃÜÂëºÍÕ˵¥ÏêϸÐÅÏ¢¡£¸Ã¹«Ë¾³Æ´Ë´Îй¶ÊÇÓÉÓÚÄÚ²¿²Ù×÷´íÎóµ¼ÖµÄ£¬µ«Fowler³ÆÆä·¢ÏÖÁËÃûΪread_meµÄÀÕË÷ÐÅÏ¢£¬ÉÏÃæÌåÏÖËùÓмǼ¾ùÒÑÏÂÔØ£¬²¢ÒªÇóÖ§¸¶0.15±ÈÌØ±Ò£¨8148ÃÀÔª£©¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/veterans-medical-records-ransomware/166025/


5.BabukÍÅ»ïÉù³ÆÒÑÇÔÈ¡ÈÕ±¾µÄYamabiko 0.5TBÊý¾Ý


5.jpg


BabukÍÅ»ïÉù³ÆÒѹ¥»÷ÈÕ±¾¹«Ë¾Yamabiko²¢ÇÔÈ¡ÁË0.5TBÊý¾Ý¡£YamabikoµÄ×ܲ¿Î»ÓÚ¶«¾©£¬ÔÚÈ«Çò·¶Î§ÄÚÏúÊ۵綯¹¤¾ß¡¢Å©Òµ»úеºÍ»§Í⶯Á¦É豸£¬ÄêÊÕÈëÁè¼ÝÊ®ÒÚÃÀÔª¡£´Ë´Îй¶µÄÐÅÏ¢°üÂÞÎļþϵͳ¡¢SolidworksÎļþ¡¢Ô±¹¤¸öÈËÊý¾Ý¡¢²ÆÕþ³ÂËß¡¢²âÊÔͼºÍµç·ԭÀíͼµÈ¡£µ«ÊÇÁîÈËÒÉ»óµÄÊÇ£¬BabukÔøÌåÏÖÕë¶Ô»ªÊ¢¶ÙÌØÇø¾¯²ì¾ÖµÄ¹¥»÷½«ÊÇÆä×îºóÒ»´Î»î¶¯£¬²¢½«¹ûÈ»Æä´úÂ룬µ«Ä¿Ç°ËƺõÒѻָ´Õý³£ÔËÐС£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/japanese-manufacturer-yamabiko/


6.CISAºÍFBIÁªºÏÐû²¼ÓйØDarkSideÍÅ»ïµÄÄþ¾²×Éѯ


6.jpg


ÃÀ¹úCISAºÍFBIÁªºÏÐû²¼ÁËÓйØDarkSideÍÅ»ïµÄÄþ¾²×Éѯ¡£ÔÚ½üÆÚµÄ»î¶¯ÖУ¬DarkSide½«Ä¿±êÃé×¼Á˶à¸öÁìÓòµÄÒªº¦»ù´¡ÉèÊ©£¨CI£©×éÖ¯£¬°üÂÞÖÆÔì¡¢Ö´·¨¡¢±£ÏÕ¡¢Ò½ÁƱ£½¡ºÍÄÜÔ´ÐÐÒµ¡£¸ÃÍÅ»ïÔø¹ûÈ»ÌåÏÖ£¬ËûÃÇÄþÔ¸Ãé×¼ÓÐÄÜÁ¦Ö§¸¶´ó±ÊÊê½ðµÄ×éÖ¯£¬¶ø·ÇÒ½Ôº¡¢Ñ§Ð£¡¢·ÇÓªÀû×éÖ¯ºÍÕþ¸®»ú¹¹¡£×îºó£¬¸Ã×Éѯ»¹ÌṩÁË´óÁ¿µÄ»º½â´ëÊ©À´×ÊÖúCIÔËÓªÉ̵ÖÓùºÍÓ¦¶Ô´ËÀ๥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/05/11/joint-cisa-fbi-cybersecurity-advisory-darkside-ransomware