SAM·¢Ã÷MiraiʹÓÃRealtek SDKÖÐÎó²îµÄ¹¥»÷»î¶¯:ºÚ¿ÍÉù³ÆÒÑÇÔÈ¡ÒÁÀÊÀÎÓüÊý°ÙGBµÄ¼à¿ØÊý¾Ý
Ðû²¼Ê±¼ä 2021-08-26SAM·¢Ã÷MiraiʹÓÃRealtek SDKÖÐÎó²îµÄ¹¥»÷»î¶¯
Çå¾²¹«Ë¾SAM SeamlessÓÚ8ÔÂ19ÈÕ³ÆÆä·¢Ã÷Á˽©Ê¬ÍøÂçMiraiʹÓÃRealtek SDKÖÐÎó²îµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¸ÃÎó²îΪÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¬£¬£¬£¬£¬£¬×·×ÙΪCVE-2021-20090£¬£¬£¬£¬£¬£¬ÆÀ·ÖΪ9.8·Ö£¬£¬£¬£¬£¬£¬RealtekÒÑÓÚ8ÔÂ13ÈÕÐû²¼¸ÃÎó²îµÄ²¹¶¡³ÌÐò¡£¡£¡£¡£SAMÌåÏÖ£¬£¬£¬£¬£¬£¬ËûÃÇÓÚ8ÔÂ18ÈÕÔÚÒ°·¢Ã÷ÁË´Ë´ÎÎó²îʹÓû£¬£¬£¬£¬£¬£¬¹¥»÷Ô´ÓÚ31.210.20[.]100£¬£¬£¬£¬£¬£¬µ«¹¥»÷ÕßµÄIPµØµã¿ÉÄÜ»áËæ×Åʱ¼ä¶ø¸Ä±ä¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securingsam.com/realtek-vulnerabilities-weaponized/
OpenSSLÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´²úÆ·ÖеÄ2¸öÇå¾²Îó²î
OpenSSLÓÚ8ÔÂ24ÈÕÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´Æä²úÆ·ÖеÄ2¸öÇå¾²Îó²î¡£¡£¡£¡£ÆäÖÐ×îΪÑÏÖØµÄÊÇ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬×·×ÙΪCVE-2021-3711£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÆä¿Éµ¼ÖÂÓ¦ÓóÌÐòÍ߽⡣¡£¡£¡£¸ÃÎó²îÓëSM2¼ÓÃÜÊý¾ÝµÄ½âÃÜÀú³ÌÏà¹Ø£¬£¬£¬£¬£¬£¬¿ÉÓÃÀ´¸ü¸Ä¶ÑÖеÄÊý¾Ý£¨¼´Æ¾Ö¤£©¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄÁíÒ»¸öÎó²î×·×ÙΪCVE-2021-3712£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î´¥·¢¾Ü¾øÐ§ÀÍ(DoS)£¬£¬£¬£¬£¬£¬»¹¿ÉÄܵ¼ÖÂÉñÃØÐÅϢй¶£¬£¬£¬£¬£¬£¬ÀýÈç˽Կ»òÃô¸ÐÃ÷ÎÄ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/121426/hacking/cve-2021-3711-openssl-flaws.html
ºÚ¿ÍÉù³ÆÒÑÇÔÈ¡ÒÁÀÊÀÎÓüµÄ¼à¿ØÏµÍ³ÖÐÊý°ÙGBµÄÊý¾Ý
ºÚ¿ÍÍÅ»ïTapandegan(Palpitations)ÓÚÉϹûÕæÁË´ó×ÚÒÁÀÊEvinÀÎÓüÖÐݱ¶¾Çô·¸µÄÊÓÆµ¡£¡£¡£¡£ÕâЩÊÓÆµµÄʱ¼ä´ÁΪ2020ÄêºÍ2021Ä꣬£¬£¬£¬£¬£¬°üÀ¨EvinµÄ¾¯ÎÀŹ´òÇô·¸¡¢ÊÔͼ×ÔɱµÄÇô·¸»ò»èØÊ²¢±»ÍϹý×ßÀȵÄÇô·¸µÈÄÚÈÝ¡£¡£¡£¡£¸ÃÍÅ»ï³ÆËûÃÇÖ»×ÊÖúÐû´«ÁËÊÓÆµµ«²¢Î´¼ÓÈë¹¥»÷£¬£¬£¬£¬£¬£¬²¢½«´Ë´Î»î¶¯¹é¹¦ÓÚAli's JusticeÍŻ¡£¡£¡£´ËºóÕßÔòÉù³ÆÆäÔÚ¼¸¸öÔÂǰ¾ÍÈëÇÖÁËÀÎÓüµÄ¼à¿ØÏµÍ³£¬£¬£¬£¬£¬£¬²¢ÇÔÈ¡ÁËÊý°ÙGBµÄÊý¾Ý¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/hackers-leak-footage-of-iranian/
ŵ»ùÑÇ×Ó¹«Ë¾SAC Wireless³ÆÆäÔâµ½ContiÀÕË÷¹¥»÷
λÓÚÃÀ¹úµÄŵ»ùÑÇ×Ó¹«Ë¾SAC WirelessÔÚ6ÔÂ16ÈÕ·¢Ã÷ÆäÔâµ½ÁËContiÀÕË÷¹¥»÷£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÖ»ÊÇ×°ÖÃÁËpayload²¢¼ÓÃÜÁËSACÎÞÏßϵͳ¡£¡£¡£¡£¿ÉÊÇÔÚÖ®ºóµÄȡ֤ÊÓ²ìÖУ¬£¬£¬£¬£¬£¬ÓÚ8ÔÂ13ÈÕ·¢Ã÷ÆäÏÖÔ±¹¤ºÍǰԱ¹¤µÄСÎÒ˽¼ÒÐÅÏ¢Ò²Òѱ»ÇÔ¡£¡£¡£¡£¸Ã¹«Ë¾¾Ü¾øÍ¸Â¶¸ü¶àÓйش˴ι¥»÷µÄÐÅÏ¢£¬£¬£¬£¬£¬£¬µ«ContiÍÅ»ïÔÚËûÃǵÄÊý¾ÝÐ¹Â¶ÍøÕ¾ÉÏ͸¶£¬£¬£¬£¬£¬£¬ÒѾ»ñµÃÁËÁè¼Ý250 GBµÄÊý¾Ý¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/nokia-subsidiary-discloses-data-breach-after-conti-ransomware-attack/
FBIÐû²¼OnePercent Group¹¥»÷»î¶¯µÄTTP»ººÍ½â²½·¥
FBIÐû²¼ÁËÓйØOnePercent GroupµÄ¹¥»÷»î¶¯µÄTTP»ººÍ½â²½·¥£¬£¬£¬£¬£¬£¬²¢³Æ¸ÃÍÅ»ïÖÁÉÙ×Ô2020Äê11ÔÂÒÔÀ´Ò»Ö±ÔÚÕë¶ÔÃÀ¹úµÄ×éÖ¯¾ÙÐÐÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¸Ã»ú¹¹³Æ¹¥»÷ÕßÊ×ÏÈʹÓô¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬ÔÚÄ¿µÄϵͳÉÏ×°ÖÃÒøÐÐľÂíIcedID²¢ÏÂÔØCobalt Strike£¬£¬£¬£¬£¬£¬È»ºó¾ÙÐмÓÃܻ¡£¡£¡£¡£FBIûÓÐÌṩ¹¥»÷»ò¼ÓÃÜÆ÷µÄÏêϸÐÅÏ¢£¬£¬£¬£¬£¬£¬µ«³ÆÆäÓëREvilÓйء£¡£¡£¡£Ñо¿Ö°Ô±Íƶϣ¬£¬£¬£¬£¬£¬Æä¿ÉÄÜÊÇREvilµÄcartelͬÃËÖеÄÏàÖúͬ°é¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/fbi-onepercent-group-ransomware-targeted-us-orgs-since-nov-2020/
Trend MicroÐû²¼2021 H1 LinuxÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ
Trend MicroÐû²¼ÁË2021 H1 LinuxÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬ÔÚ2021ÄêÉϰëÄêÑо¿Ö°Ô±×ܼÆÍ³¼ÆÁ˽ü1500Íò¸öÕë¶ÔLinuxµÄÇå¾²ÊÂÎñ£¬£¬£¬£¬£¬£¬²¢·¢Ã÷ÍÚ¿óÈí¼þºÍÀÕË÷Èí¼þÕ¼ËùÓжñÒâÈí¼þµÄ36.11%£¬£¬£¬£¬£¬£¬Web shellÕ¼19.92%¡£¡£¡£¡£ÔÚÒ°·¢Ã÷µÄ¹¥»÷»î¶¯ÖÐʹÓÃ×î¶àµÄÎó²î°üÀ¨Apache Struts 2ÖеÄRCEÎó²î£¨CVE-2017-5638£©¡¢Apache Struts 2 REST plugin XStreamÖеÄRCEÎó²î£¨CVE-2017-9805£©£¬£¬£¬£¬£¬£¬ÒÔ¼°Drupal CoreÖеÄRCEÎó²î£¨CVE-2018-7600£©µÈ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/linux-threat-report-2021-1h-linux-threats-in-the-cloud-and-security-recommendations