ÑÇÂíÑ·AWSÔÆÐ§ÀÍÔÙ´Îå´»úÓ°ÏìTwitchºÍZoomµÈÓ¦ÓÃ

Ðû²¼Ê±¼ä 2021-12-16

AdobeÐû²¼12Ô¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´¶à¸ö²úÆ·ÖÐÁè¼Ý60¸öÎó²î


AdobeÐû²¼12Ô¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´¶à¸ö²úÆ·ÖÐÁè¼Ý60¸öÎó²î.png


12ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬AdobeÐû²¼±¾ÔµÄÖܶþ²¹¶¡£¬£¬£¬£¬£¬£¬ÐÞ¸´¶à¸ö²úÆ·ÖÐÁè¼Ý60¸öÎó²î¡£¡£ ¡£¡£¡£ÆäÖнÏΪÑÏÖØµÄÊÇExperience ManagerÖеÄXXEÎó²î£¨CVE-2021-40722£©£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂí§Òâ´úÂëÖ´ÐС£¡£ ¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬»¹ÐÞ¸´ÁËPhotoshopÖпɵ¼ÖÂí§Òâ´úÂëÖ´ÐÐÔ½½çдÈëÎó²î£¨CVE-2021-43018£©»ººÍ³åÇøÒç³öÎó²î£¨CVE-2021-44184£©£¬£¬£¬£¬£¬£¬ÒÔ¼°Media EncoderÖеÄÔ½½ç¶ÁÈ¡£¡£ ¡£¡£¡£¨CVE-2021-43757£©µÈ¶à¸öÎó²î¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/125640/security/adobe-60-vulnerabilities-multiple-products.html


ÒÁÀÊMERCURYÃé×¼Öж«ºÍÑÇÖ޵ĵçÐźÍITЧÀÍÌṩÉÌ


ÒÁÀÊMERCURYÃé×¼Öж«ºÍÑÇÖ޵ĵçÐźÍITЧÀÍÌṩÉÌ.png


SymantecÔÚ12ÔÂ14ÈÕ¹ûÕæÁËÕë¶ÔÖж«ºÍÑÇÖÞµçÐźÍITЧÀÍÌṩÉ̵Ĺ¥»÷£¬£¬£¬£¬£¬£¬ÒÉËÆÀ´×ÔÒÁÀʺڿÍÍÅ»ïMERCURY£¨ÓÖÃûMuddyWater£©¡£¡£ ¡£¡£¡£¸Ã»î¶¯×îÏÈÓÚ6¸öÔÂ֮ǰ£¬£¬£¬£¬£¬£¬Ö÷ҪʹÓÃÒ×Êܹ¥»÷µÄExchangeЧÀÍÆ÷ÈëÇÖ×éÖ¯µÄÍøÂç¡£¡£ ¡£¡£¡£Ö»¹ÜÏÖÔÚѬȾǰÑÔÈÔδ֪£¬£¬£¬£¬£¬£¬µ«Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öZIPÎļþ¡°Special discount program.zip¡±£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨Ô¶³Ì×ÀÃæÈí¼þÓ¦ÓóÌÐòµÄ×°ÖóÌÐò£¬£¬£¬£¬£¬£¬Òò´ËÍÆ¶Ï¹¥»÷ÕßʹÓõÄÊÇÓã²æÊ½´¹ÂÚÓʼþ¡£¡£ ¡£¡£¡£     


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/telecom-operators-targeted-in-recent-espionage-hacking-campaign/


Lookout·¢Ã÷Õë¶Ô½ü400¼Ò½ðÈÚ»ú¹¹·Ö·¢AnubisµÄ»î¶¯


Lookout·¢Ã÷Õë¶Ô½ü400¼Ò½ðÈÚ»ú¹¹·Ö·¢AnubisµÄ»î¶¯.png


12ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬Lookout·¢Ã÷ÁËÕë¶Ô394¼Ò½ðÈÚ»ú¹¹·Ö·¢AndroidÒøÐÐľÂíAnubisµÄ»î¶¯¡£¡£ ¡£¡£¡£AnubisÓÚ2016ÄêÊ״ηºÆð£¬£¬£¬£¬£¬£¬×÷Ϊ¿ªÔ´ÒøÐÐľÂíÔÚ¶íÂÞ˹ºÚ¿ÍÂÛ̳ÉÏÐû²¼¡£¡£ ¡£¡£¡£Ôڴ˴λÖУ¬£¬£¬£¬£¬£¬¹¥»÷Õßð³ä·¨¹úµçÐŹ«Ë¾Orange SAµÄÕÊ»§ÖÎÀíÓ¦Ó㬣¬£¬£¬£¬£¬Ãé×¼´óÍ¨ÒøÐС¢¸»¹úÒøÐС¢ÃÀ¹úÒøÐк͵ÚÒ»×ÊÔ´µÈ½ðÈÚ»ú¹¹µÄ¿Í»§¡£¡£ ¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬£¬£¬´Ë´Î¹¥»÷²»µ«½öÕë¶Ô´óÐÍÒøÐеĿͻ§£¬£¬£¬£¬£¬£¬»¹Õë¶ÔÐéÄâÖ§¸¶Æ½Ì¨ºÍ¼ÓÃÜÇ®°ü£¬£¬£¬£¬£¬£¬¸Ã»î¶¯ÏÖÔÚÈÔ´¦ÓÚ²âÊÔºÍÓÅ»¯½×¶Î¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/400-banks-targeted-anubis-trojan/177038/


VulcanForgeÉù³ÆÆäÔâµ½¹¥»÷Ëðʧ¸ß´ï½ü1.4ÒÚÃÀÔª


VulcanForgeÉù³ÆÆäÔâµ½¹¥»÷Ëðʧ¸ß´ï½ü1.4ÒÚÃÀÔª.png


ÓÎÏ·¹«Ë¾VulcanForgeÔÚ±¾ÖÜÒ»³ÆÆäÔâµ½ÁËÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬Ëðʧ¸ß´ï1.35ÒÚÃÀÔª¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾³Æ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÒѾ­»ñµÃÁË96¸öÇ®°üµÄ˽Կ£¬£¬£¬£¬£¬£¬²¢ÇÔÈ¡ÁË450ÍòPYR£¨VulcanForgeµÄ´ú±Ò£¬£¬£¬£¬£¬£¬¿ÉÔÚÆäÕû¸öÓÎϷϵͳÖÐʹÓã©¡£¡£ ¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬¹¥»÷Õß³öÊÛÁË´ó×ÚPYR£¬£¬£¬£¬£¬£¬Ê¹PYRµÄ¼ÛǮϵø22%£¨´Ó31ÃÀÔª½µµ½24ÃÀÔª£©¡£¡£ ¡£¡£¡£ÕâÊǽüÊ®¼¸ÌìÄÚ±¬·¢µÄµÚÈýÆð¼ÓÃÜÇ®±ÒʧÔôÊÂÎñ£¬£¬£¬£¬£¬£¬Èý´Î¹¥»÷Ôì³ÉµÄ×ÜËðʧ½ð¶îԼΪ4.04ÒÚÃÀÔª¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.theblockcrypto.com/post/127270/96-private-keys-stolen-from-vulcan-forged-in-140-million-theft


KasperskyÅû¶ʹÓÃIISÄ£¿£¿£¿£¿éOwowaµÄ¹¥»÷»î¶¯Ï¸½Ú


KasperskyÅû¶ʹÓÃIISÄ£¿£¿£¿£¿éOwowaµÄ¹¥»÷»î¶¯Ï¸½Ú.png


12ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬KasperskyÅû¶ÁËʹÓÃIIS WebЧÀÍÆ÷Ä£¿£¿£¿£¿éOwowaµÄ¹¥»÷»î¶¯Ï¸½Ú¡£¡£ ¡£¡£¡£Ò£²âÊý¾ÝÏÔʾ£¬£¬£¬£¬£¬£¬×îÐÂÑù±¾·ºÆðÓÚ2021Äê4Ô£¬£¬£¬£¬£¬£¬Ãé×¼ÂíÀ´Î÷ÑÇ¡¢Ãɹš¢Ó¡¶ÈÄáÎ÷ÑǺͷÆÂɱöµÄ¹Ù·½×éÖ¯ºÍ¹«¹²½»Í¨¹«Ë¾µÈ¡£¡£ ¡£¡£¡£OwowaÕë¶ÔExchangeµÄOutlook Web Access(OWA)£¬£¬£¬£¬£¬£¬Ö¼ÔڼͼÔÚOWAµÇÂ¼ÍøÒ³ÉÏÀֳɾÙÐÐÉí·ÝÑéÖ¤µÄÓû§µÄƾ֤¡£¡£ ¡£¡£¡£È»ºó£¬£¬£¬£¬£¬£¬¹¥»÷Õß»áÏò¶ñÒâÄ£¿£¿£¿£¿é·¢ËÍÏÂÁîÀ´ÍøÂç±»µÁÊý¾Ý£¬£¬£¬£¬£¬£¬²¢ÔÚ±»Ñ¬È¾×°±¸ÉÏÖ´ÐÐPowerShell£¬£¬£¬£¬£¬£¬¾ÙÐÐÏÂÒ»²½¹¥»÷¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/owowa-credential-stealer-and-remote-access/105219/


ÑÇÂíÑ·AWSÔÆÐ§ÀÍÔÙ´Îå´»úÓ°ÏìTwitchºÍZoomµÈÓ¦ÓÃ


ÑÇÂíÑ·AWSÔÆÐ§ÀÍÔÙ´Îå´»úÓ°ÏìTwitchºÍZoomµÈÓ¦ÓÃ.png


12ÔÂ15ÈÕ£¬£¬£¬£¬£¬£¬ÑÇÂíÑ·AWSÔÆÐ§ÀÍÔÙ´Îå´»ú¡£¡£ ¡£¡£¡£ÆäÖÐÖ¹×îÏÈÓÚ̫ƽÑóʱ¼äÉÏÎç7:43×óÓÒ£¬£¬£¬£¬£¬£¬Ö÷ÒªÓ°ÏìÁËUS-WEST-1ºÍUS-WEST-2ÇøÓò£¬£¬£¬£¬£¬£¬µ¼ÖÂTwitch¡¢Zoom¡¢PSN¡¢Xbox Live¡¢Doordash¡¢Quickbooks OnlineºÍHuluµÈ´ó×ÚÆ½Ì¨ºÍÍøÕ¾¹Ø±Õ¡£¡£ ¡£¡£¡£×èÖ¹12ÔÂ15ÈÕ11:27 £¬£¬£¬£¬£¬£¬ÑÇÂíÑ·³ÆInternetÅþÁ¬µÄÎÊÌâÒѾ­½â¾ö£¬£¬£¬£¬£¬£¬Ð§ÀÍÔËÐÐÕý³£¡£¡£ ¡£¡£¡£12ÔÂ7ÈÕ£¬£¬£¬£¬£¬£¬ÑÇÂíÑ·AWSÔÆÐ§ÀÍå´»ú£¬£¬£¬£¬£¬£¬Ó°ÏìÁËNetflix¡¢RokuºÍAmazon PrimeµÄµÈÓ¦Óᣡ£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/technology/aws-down-again-outage-impacts-twitch-zoom-psn-hulu-others/