ÑÇÂíÑ·AWSÔÆÐ§ÀÍÔÙ´Îå´»úÓ°ÏìTwitchºÍZoomµÈÓ¦ÓÃ
Ðû²¼Ê±¼ä 2021-12-16AdobeÐû²¼12Ô¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´¶à¸ö²úÆ·ÖÐÁè¼Ý60¸öÎó²î
12ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬AdobeÐû²¼±¾ÔµÄÖܶþ²¹¶¡£¬£¬£¬£¬£¬£¬ÐÞ¸´¶à¸ö²úÆ·ÖÐÁè¼Ý60¸öÎó²î¡£¡£¡£¡£¡£ÆäÖнÏΪÑÏÖØµÄÊÇExperience ManagerÖеÄXXEÎó²î£¨CVE-2021-40722£©£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂí§Òâ´úÂëÖ´ÐС£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬»¹ÐÞ¸´ÁËPhotoshopÖпɵ¼ÖÂí§Òâ´úÂëÖ´ÐÐÔ½½çдÈëÎó²î£¨CVE-2021-43018£©»ººÍ³åÇøÒç³öÎó²î£¨CVE-2021-44184£©£¬£¬£¬£¬£¬£¬ÒÔ¼°Media EncoderÖеÄÔ½½ç¶ÁÈ¡£¡£¡£¡£¡£¨CVE-2021-43757£©µÈ¶à¸öÎó²î¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/125640/security/adobe-60-vulnerabilities-multiple-products.html
ÒÁÀÊMERCURYÃé×¼Öж«ºÍÑÇÖ޵ĵçÐźÍITЧÀÍÌṩÉÌ
SymantecÔÚ12ÔÂ14ÈÕ¹ûÕæÁËÕë¶ÔÖж«ºÍÑÇÖÞµçÐźÍITЧÀÍÌṩÉ̵Ĺ¥»÷£¬£¬£¬£¬£¬£¬ÒÉËÆÀ´×ÔÒÁÀʺڿÍÍÅ»ïMERCURY£¨ÓÖÃûMuddyWater£©¡£¡£¡£¡£¡£¸Ã»î¶¯×îÏÈÓÚ6¸öÔÂ֮ǰ£¬£¬£¬£¬£¬£¬Ö÷ҪʹÓÃÒ×Êܹ¥»÷µÄExchangeЧÀÍÆ÷ÈëÇÖ×éÖ¯µÄÍøÂç¡£¡£¡£¡£¡£Ö»¹ÜÏÖÔÚѬȾǰÑÔÈÔδ֪£¬£¬£¬£¬£¬£¬µ«Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öZIPÎļþ¡°Special discount program.zip¡±£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨Ô¶³Ì×ÀÃæÈí¼þÓ¦ÓóÌÐòµÄ×°ÖóÌÐò£¬£¬£¬£¬£¬£¬Òò´ËÍÆ¶Ï¹¥»÷ÕßʹÓõÄÊÇÓã²æÊ½´¹ÂÚÓʼþ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/telecom-operators-targeted-in-recent-espionage-hacking-campaign/
Lookout·¢Ã÷Õë¶Ô½ü400¼Ò½ðÈÚ»ú¹¹·Ö·¢AnubisµÄ»î¶¯
12ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬Lookout·¢Ã÷ÁËÕë¶Ô394¼Ò½ðÈÚ»ú¹¹·Ö·¢AndroidÒøÐÐľÂíAnubisµÄ»î¶¯¡£¡£¡£¡£¡£AnubisÓÚ2016ÄêÊ״ηºÆð£¬£¬£¬£¬£¬£¬×÷Ϊ¿ªÔ´ÒøÐÐľÂíÔÚ¶íÂÞ˹ºÚ¿ÍÂÛ̳ÉÏÐû²¼¡£¡£¡£¡£¡£Ôڴ˴λÖУ¬£¬£¬£¬£¬£¬¹¥»÷Õßð³ä·¨¹úµçÐŹ«Ë¾Orange SAµÄÕÊ»§ÖÎÀíÓ¦Ó㬣¬£¬£¬£¬£¬Ãé×¼´óÍ¨ÒøÐС¢¸»¹úÒøÐС¢ÃÀ¹úÒøÐк͵ÚÒ»×ÊÔ´µÈ½ðÈÚ»ú¹¹µÄ¿Í»§¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬£¬£¬´Ë´Î¹¥»÷²»µ«½öÕë¶Ô´óÐÍÒøÐеĿͻ§£¬£¬£¬£¬£¬£¬»¹Õë¶ÔÐéÄâÖ§¸¶Æ½Ì¨ºÍ¼ÓÃÜÇ®°ü£¬£¬£¬£¬£¬£¬¸Ã»î¶¯ÏÖÔÚÈÔ´¦ÓÚ²âÊÔºÍÓÅ»¯½×¶Î¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/400-banks-targeted-anubis-trojan/177038/
VulcanForgeÉù³ÆÆäÔâµ½¹¥»÷Ëðʧ¸ß´ï½ü1.4ÒÚÃÀÔª
ÓÎÏ·¹«Ë¾VulcanForgeÔÚ±¾ÖÜÒ»³ÆÆäÔâµ½ÁËÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬Ëðʧ¸ß´ï1.35ÒÚÃÀÔª¡£¡£¡£¡£¡£¸Ã¹«Ë¾³Æ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÒѾ»ñµÃÁË96¸öÇ®°üµÄ˽Կ£¬£¬£¬£¬£¬£¬²¢ÇÔÈ¡ÁË450ÍòPYR£¨VulcanForgeµÄ´ú±Ò£¬£¬£¬£¬£¬£¬¿ÉÔÚÆäÕû¸öÓÎϷϵͳÖÐʹÓã©¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬¹¥»÷Õß³öÊÛÁË´ó×ÚPYR£¬£¬£¬£¬£¬£¬Ê¹PYRµÄ¼ÛǮϵø22%£¨´Ó31ÃÀÔª½µµ½24ÃÀÔª£©¡£¡£¡£¡£¡£ÕâÊǽüÊ®¼¸ÌìÄÚ±¬·¢µÄµÚÈýÆð¼ÓÃÜÇ®±ÒʧÔôÊÂÎñ£¬£¬£¬£¬£¬£¬Èý´Î¹¥»÷Ôì³ÉµÄ×ÜËðʧ½ð¶îԼΪ4.04ÒÚÃÀÔª¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.theblockcrypto.com/post/127270/96-private-keys-stolen-from-vulcan-forged-in-140-million-theft
KasperskyÅû¶ʹÓÃIISÄ£¿£¿£¿£¿éOwowaµÄ¹¥»÷»î¶¯Ï¸½Ú
12ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬KasperskyÅû¶ÁËʹÓÃIIS WebЧÀÍÆ÷Ä£¿£¿£¿£¿éOwowaµÄ¹¥»÷»î¶¯Ï¸½Ú¡£¡£¡£¡£¡£Ò£²âÊý¾ÝÏÔʾ£¬£¬£¬£¬£¬£¬×îÐÂÑù±¾·ºÆðÓÚ2021Äê4Ô£¬£¬£¬£¬£¬£¬Ãé×¼ÂíÀ´Î÷ÑÇ¡¢Ãɹš¢Ó¡¶ÈÄáÎ÷ÑǺͷÆÂɱöµÄ¹Ù·½×éÖ¯ºÍ¹«¹²½»Í¨¹«Ë¾µÈ¡£¡£¡£¡£¡£OwowaÕë¶ÔExchangeµÄOutlook Web Access(OWA)£¬£¬£¬£¬£¬£¬Ö¼ÔڼͼÔÚOWAµÇÂ¼ÍøÒ³ÉÏÀֳɾÙÐÐÉí·ÝÑéÖ¤µÄÓû§µÄƾ֤¡£¡£¡£¡£¡£È»ºó£¬£¬£¬£¬£¬£¬¹¥»÷Õß»áÏò¶ñÒâÄ£¿£¿£¿£¿é·¢ËÍÏÂÁîÀ´ÍøÂç±»µÁÊý¾Ý£¬£¬£¬£¬£¬£¬²¢ÔÚ±»Ñ¬È¾×°±¸ÉÏÖ´ÐÐPowerShell£¬£¬£¬£¬£¬£¬¾ÙÐÐÏÂÒ»²½¹¥»÷¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/owowa-credential-stealer-and-remote-access/105219/
ÑÇÂíÑ·AWSÔÆÐ§ÀÍÔÙ´Îå´»úÓ°ÏìTwitchºÍZoomµÈÓ¦ÓÃ
12ÔÂ15ÈÕ£¬£¬£¬£¬£¬£¬ÑÇÂíÑ·AWSÔÆÐ§ÀÍÔÙ´Îå´»ú¡£¡£¡£¡£¡£ÆäÖÐÖ¹×îÏÈÓÚ̫ƽÑóʱ¼äÉÏÎç7:43×óÓÒ£¬£¬£¬£¬£¬£¬Ö÷ÒªÓ°ÏìÁËUS-WEST-1ºÍUS-WEST-2ÇøÓò£¬£¬£¬£¬£¬£¬µ¼ÖÂTwitch¡¢Zoom¡¢PSN¡¢Xbox Live¡¢Doordash¡¢Quickbooks OnlineºÍHuluµÈ´ó×ÚÆ½Ì¨ºÍÍøÕ¾¹Ø±Õ¡£¡£¡£¡£¡£×èÖ¹12ÔÂ15ÈÕ11:27 £¬£¬£¬£¬£¬£¬ÑÇÂíÑ·³ÆInternetÅþÁ¬µÄÎÊÌâÒѾ½â¾ö£¬£¬£¬£¬£¬£¬Ð§ÀÍÔËÐÐÕý³£¡£¡£¡£¡£¡£12ÔÂ7ÈÕ£¬£¬£¬£¬£¬£¬ÑÇÂíÑ·AWSÔÆÐ§ÀÍå´»ú£¬£¬£¬£¬£¬£¬Ó°ÏìÁËNetflix¡¢RokuºÍAmazon PrimeµÄµÈÓ¦Óᣡ£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/technology/aws-down-again-outage-impacts-twitch-zoom-psn-hulu-others/