QualysÅû¶LinuxÄÚºËÖеĵ±µØÌáȨ©¶´Sequoia£»Win10ÖÐÌáȨ©¶´SeriousSAMÓ°Ïì½üÁ½ÄêÐû²¼µÄ°æ±¾
Ðû²¼Ê±¼ä 2021-07-221.QualysÅû¶LinuxÄÚºËÖеĵ±µØÌáȨ©¶´Sequoia
QualysÑо¿ÈËÔ±Åû¶ÁËLinuxÄÚºËÖеĵ±µØÌáȨ©¶´Sequoia¡£¸Ã©¶´×·×ÙΪCVE-2021-33909£¬´æÔÚÓÚÓÃÀ´¹ÜÀíÓû§Êý¾ÝµÄÎļþϵͳ²ã£¬ÊÇÓÉÓÚfs/seq_file.cûÓÐÕýÈ·ÏÞÖÆseq»º³åÇø·ÖÅä¶øµ¼Öµġ£Qualys³Æ£¬¸Ã©¶´Ó°ÏìÁË×Ô2014ÄêÒÔÀ´Ðû²¼µÄËùÓÐLinuxÄں˰汾¡£´ËÍ⣬Ñо¿ÈËÔ±»¹·¢ÏÖÁËsystemdÖеÄÒ»¸ö¶ÑÕ»ºÄ¾¡µ¼Öµľܾø·þÎñ©¶´£¨CVE-2021-33910£©£¬´æÔÚÓÚ2015Äê4ÔÂÖ®ºóÐû²¼µÄËùÓÐsystemd°æ±¾ÖС£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-linux-kernel-bug-lets-you-get-root-on-most-modern-distros/
2.Win10ÖÐÌáȨ©¶´SeriousSAMÓ°Ïì½üÁ½ÄêÐû²¼µÄ°æ±¾
Ñо¿ÈËÔ±Jonas LykkegaardÅû¶ÁËWin10ÖеÄÌáȨ©¶´SeriousSAM£¬Ó°ÏìÁ˽üÁ½Äê¶àÐû²¼µÄËùÓа汾¡£LykkegaardÔÚ²âÊÔ×îÐÂÐû²¼µÄWin11ʱ·¢ÏÖ£¬ËäÈ»WindowsÏÞÖÆÁ˵ÍȨÏÞÓû§·ÃÎÊSAM¡¢SECURITYºÍSYSTEMµÈÎļþ¼ÐÖеÄÃô¸ÐÅäÖÃÎļþ£¬µ«ÕâЩÎļþµÄ¸±±¾Ò²±»Éú´æÔÚShadow Volume Copy´´½¨µÄ±¸·ÝÎļþÖУ¬¶ø×Ô2018Äê11ÔÂÐû²¼µÄWindows 10 v1809ÒÔÀ´£¬Î¢ÈíһֱûÓÐ×èÖ¹¶ÔÕâЩ±¸·ÝµÄ·ÃÎÊ¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/serioussam-bug-impacts-all-windows-10-versions-released-in-the-past-2-5-years/
3.AdobeÐû²¼Äþ¾²¸üУ¬ÐÞ¸´Æä7¿î²úÎïÖеÄ21¸ö©¶´
AdobeÔÚ7ÔÂ20ÈÕ±¾ÖܶþÐû²¼ÁËÄþ¾²¸üУ¬×ܼÆÐÞ¸´ÁËÆä7¿î²úÎïÖеÄ21¸ö©¶´¡£´Ë´ÎÐÞ¸´ÁËAdobe After EffectsÖеÄ7¸ö©¶´£¬ÆäÖÐ5¸ö¿ÉÒÔµ¼ÖÂÈÎÒâ´úÂëÖ´ÐУ¨CVE-2021-36017¡¢CVE-2021-35993¡¢CVE-2021-35994¡¢CVE-2021-35995ºÍCVE-2021-35996£©¡£´ËÍ⣬»¹ÐÞ¸´ÁËPhotoshopÖеĻº³åÇøÒç³öµ¼ÖµĴúÂëÖ´ÐЩ¶´£¨CVE-2021-36005£©¡¢Character AnimatorÖеÄÈÎÒâ´úÂëÖ´ÐЩ¶´£¨CVE-2021-36000£©ºÍPreludeÖеÄÈÎÒâ´úÂëÖ´ÐЩ¶´£¨CVE-2021-35999£©µÈ¶à¸öÑÏÖØµÄ©¶´¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/adobe-patches-21-vulnerabilities-across-seven-products
4.WizCase·¢ÏÖÃÀ¹úµÄ80¶à¸öÊÐÕþÕþ¸®´æ´¢Í°ÅäÖôíÎó
WizCaseÑо¿ÍŶӷ¢ÏÖÃÀ¹úµÄ80¶à¸öÊÐÕþÕþ¸®´æ´¢Í°ÅäÖôíÎó¡£Ñо¿ÈËÔ±·¢ÏÖÃÀ¹ú¶à¸ö¶¼ÊеÄÊý¾Ý¾ù´æ´¢ÔÚ´íÎóÅäÖõÄAmazon S3´æ´¢Í°ÖУ¬¶øÕâЩ¶¼Êж¼Ê¹ÓÃÁËÓÉÃÀ¹ú¹«Ë¾PeopleGISÌṩµÄͬһ¿î²úÎïmapsonline.net¡£Í¨¹ýɨÃè·¢ÏÖÁË114¸öÓëPeopleGISÏà¹ØµÄ´æ´¢Í°£¬ÆäÖÐ28¸öÅäÖÃÕýÈ·£¬Ê£ÏµÄ86¸öÎÞÐèÈκÎÃÜÂë¼´¿É·ÃÎÊ¡£ÕâЩ̻¶µÄ´æ´¢Í°ÖаüÂÞÁËÓëÕâЩ¶¼ÊÐÏà¹ØµÄÊý¾Ý£¬×ܼÆÓÐÁè¼Ý1000 GBµÄÊý¾ÝºÍÁè¼Ý160Íò¸öÎļþ¡£
ÔÎÄÁ´½Ó£º
https://www.wizcase.com/blog/us-municipality-breach-report/
5.Shahaf³ÂËß³ÆÒÔÉ«ÁеÄIT¹«Ë¾PionetÔâµ½ÀÕË÷¹¥»÷
Shahaf³ÂË߳ƣ¬ÒÔÉ«ÁÐMalam TimÆìϵÄIT¹«Ë¾PionetÔâµ½ÁËÀÕË÷¹¥»÷¡£´Ë´Î¹¥»÷µ¼ÖÂÁ˸ù«Ë¾µÄÐí¶àϵͳºÍÆäÉϰٶà¸ö¿Í»§µÄÍøÕ¾Ì±»¾£¬ÆäÖаüÂÞAssutaÒ½Ôº¡¢SonoȼÁϹ«Ë¾ºÍAppleµÄ½ø¿ÚÉÌIdigitalµÈ£¬ÆäÖÐIdigitalµÄ¿Í»§°üÂÞÒÔÉ«ÁеçÁ¦¹«Ë¾ºÍÒÔÉ«ÁÐÌú·¹«Ë¾¡£¾Ý³Æ£¬¹¥»÷ÕßÒªÇóÖ§¸¶Ô¼50ÍòÉá¿ÍÀÕ(ÕÛºÏ151861.82ÃÀÔª)Êê½ð£¬²¢ÒªÇóÏÈÁ¢¼´Ö§¸¶5000ÃÀÔªµÄÃÅÂÞ±Ò¡£
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/il-ransomware-attack-on-israeli-it-company-impacts-more-than-100-customers-including-hospitals/
6.Link11Ðû²¼2021ÄêÉϰëÄêDDoS¹¥»÷Ì¬ÊÆµÄ·ÖÎö³ÂËß
Link11Ðû²¼ÁË2021ÄêÉϰëÄêDDoS¹¥»÷Ì¬ÊÆµÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬ÔÚ2021ÄêQ1ºÍQ2Ö®¼ä£¬DDoS»î¶¯Ôö¼ÓÁË19%£¬ÆäÖÐһЩ¹¥»÷Á¿Áè¼ÝÁË100Gbps¡£Óë2020ÄêÉϰëÄêÏà±È£¬2021ÄêµÄ¹¥»÷´ÎÊýͬ±ÈÔö³¤ÁË33%£»×ÜÌå¹¥»÷´ø¿íÈÔÈ»ºÜ¸ß£¬×î´ó¹¥»÷Á¿Îª555 Gbps£»¹¥»÷´ø¿í¼±¾çÔö¼Ó£¬Óë2020 H1Ïà±ÈÔö¼ÓÁË37%£»2021ÄêÉϰëÄêÁè¼Ý100 GbpsµÄ¹¥»÷´ÎÊý¶à´ï28´Î¡£
ÔÎÄÁ´½Ó£º
https://www.link11.com/en/blog/threat-landscape/link11-report-discovers-record-number-of-ddos-attacks-in-first-half-of-2021/