ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ27ÖÜ

Ðû²¼Ê±¼ä 2021-07-05

> ±¾ÖÜÇ徲̬ÊÆ×ÛÊö


2021Äê06ÔÂ28ÈÕÖÁ07ÔÂ04ÈÕ¹²ÊÕ¼Çå¾²Îó²î62¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAcrobat Reader DC CVE-2021-28562ÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î£»HelpcomÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£»helpUS ShellExecutionExA´úÂëÖ´ÐÐÎó²î£»Huawei AnyOffice V200R006C10·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î£»MVISION EDR 'execute reaction'Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇ΢Èí³ÆÆäÔâµ½SolarWinds¹¥»÷±³ºóÍÅ»ïNobeliumµÄÈëÇÖ£»GitGuardianÐû²¼2021ÄêGitHubÉÏÊý¾Ý鶵ÄÆÊÎö±¨¸æ£»ºÚ¿ÍÔÚRaidForums³öÊÛ7ÒÚ¶àÌõLinkedInÓû§µÄ¼Í¼£»ÃÀ¹úFINRAÖÒÑÔαװ³ÉFINRA SupportµÄ´¹ÂÚ¹¥»÷Ô˶¯£»Î¢ÈíÐû²¼Çå¾²¸üУ¬ÐÞ¸´Edgeä¯ÀÀÆ÷ÖеĶà¸öÎó²î¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£


> Ö÷ÒªÇå¾²Îó²îÁбí


1.Acrobat Reader DC CVE-2021-28562ÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î


Acrobat Reader DC±£´æÊͷźóʹÓÃÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉʹӦÓóÌÐò±ÀÀ£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£

https://helpx.adobe.com/security/products/acrobat/apsb21-29.html


2.HelpcomÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î


Helpcom±£´æÊäÈëÑéÖ¤Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£

https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36095


3.helpUS ShellExecutionExA´úÂëÖ´ÐÐÎó²î


helpUS ShellExecutionExA±£´æÊäÈëÑéÖ¤Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£

https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36088


4.Huawei AnyOffice V200R006C10·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î


Huawei AnyOffice±£´æ·´ÐòÁл¯Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£

https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210619-01-injection-en


5.MVISION EDR 'execute reaction'Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î


MVISION EDR 'execute reaction'±£´æÊäÈëÑéÖ¤Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£

https://kc.mcafee.com/corporate/index?page=content&id=SB10342


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Î¢Èí³ÆÆäÔâµ½SolarWinds¹¥»÷±³ºóÍÅ»ïNobeliumµÄÈëÇÖ


1.jpg


΢Èí³ÆÆäÔâµ½Á˺ڿÍÍÅ»ïNobeliumµÄ¹¥»÷¡£NobeliumÊǶíÂÞ˹¹ú¼Ò×ÊÖúµÄºÚ¿Í×éÖ¯£¬ÓëSolarWinds¹©Ó¦Á´¹¥»÷ÓйØ£¬Î¢ÈíÌåÏָúڿÍ×éÖ¯Ò»Ö±ÔÚ¾ÙÐÐÃÜÂëÅçÈ÷¹¥»÷ºÍ±©Á¦¹¥»÷£¬ÒÔ»ñÈ¡¶Ô¹«Ë¾ÍøÂçµÄ»á¼ûȨÏÞ¡£Í¨¹ýÊӲ죬΢ÈíÔÚÆä¿Í»§Ö§³ÖÊðÀíµÄÅÌËã»úÉϼì²âµ½Ò»¸öÐÅÏ¢ÇÔȡľÂí£¬ÇÔÈ¡Á˲¿·Ö¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢£¬¶øNobelium½«Ê¹ÓÃÕâЩÐÅÏ¢¶Ô΢ÈíµÄ¿Í»§¾ÙÐÐÓÐÕë¶ÔÐÔµÄÍøÂç´¹ÂÚ¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/nobelium-hackers-accessed-microsoft-customer-support-tools/


2¡¢GitGuardianÐû²¼2021ÄêGitHubÉÏÊý¾Ý鶵ÄÆÊÎö±¨¸æ


2.jpg


GitGuardianÐû²¼ÁË2021ÄêGitHubÉÏÊý¾Ý鶵ÄÆÊÎö±¨¸æ¡£×Ô2017ÄêÒÔÀ´£¬GitGuardianÒ»Ö±ÔÚɨÃèÔÚGitHubÉϹûÕæÌá½»µÄÿһ¸öSecret£¬²¢È¨ºâÁ˹«¹²´æ´¢¿âÖÐÊý¾Ý鶵ÄÇéÐΡ£ÖÁ½ñÓÐÁè¼Ý5000Íò¿ª·¢Ö°Ô±Ê¹ÓÃGitHub£¬Ò»ÄêÄÚÓÐ6000Íò¸öн¨µÄ´æ´¢¿â£¬Ìá½»´ÎÊýÁè¼Ý20ÒڴΡ£±¨¸æÖ¸³ö£¬¹«¹²GitHubÖÐÊý¾Ý鶵ÄÊýĿͬ±ÈÔöÌíÁË20%£¬ÆäÖÐ15%µÄй¿à´×ÔÓÚ×éÖ¯µÄ¹«¹²´æ´¢¿âÖУ¬¶ø85%µÄй¿à´×ÔÓÚ¿ª·¢Ö°Ô±µÄСÎÒ˽¼Ò´æ´¢¿âÖС£


Ô­ÎÄÁ´½Ó£º

https://blog.gitguardian.com/state-of-secrets-sprawl-2021/


3¡¢ºÚ¿ÍÔÚRaidForums³öÊÛ7ÒÚ¶àÌõLinkedInÓû§µÄ¼Í¼


3.jpg


Privacy SharksÑо¿Ö°Ô±·¢Ã÷ÃûΪ¡°GOD User TomLiner¡±µÄºÚ¿ÍÕýÔÚRaidForumsÉϳöÊÛLinkedInÓû§µÄÊý¾Ý¡£¸Ã¹ã¸æÓÚ6ÔÂ22ÈÕÐû²¼£¬Éù³Æ°üÀ¨7ÒÚÌõ¼Í¼£¬²¢¹ûÕæÁË100ÍòÌõÑù±¾×÷Ϊ֤¾Ý¡£´Ë´Î鶵ÄÐÅÏ¢°üÀ¨·¢Ã÷¼Í¼°üÀ¨È«Ãû¡¢ÐԱ𡢵ç×ÓÓʼþµØµã¡¢µç»°ºÅÂëºÍÐÐÒµÐÅÏ¢¡£ÏÖÔÚÉв»ÇåÎúÊý¾ÝµÄȪԴÊÇʲô£¬µ«Ñо¿Ö°Ô±ÍƲâ´Ë´ÎÊý¾Ýй¶Óë4Ô·ݳöÊÛµÄ5ÒÚÌõLinkedIn¼Í¼¿ÉÄÜÊÇͳһȪԴ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/data-700m-linkedin-users-cyber-underground/167362/


4¡¢ÃÀ¹úFINRAÖÒÑÔαװ³ÉFINRA SupportµÄ´¹ÂÚ¹¥»÷Ô˶¯


4.jpg


ÃÀ¹ú֤ȯҵî¿Ïµ»ú¹¹FINRAÖÒÑÔαװ³ÉFINRA SupportµÄ´¹ÂÚ¹¥»÷Ô˶¯¡£FINRAÊÇÕþ¸®ÊÚȨµÄ·ÇÓªÀû×éÖ¯£¬ÈÏÕæî¿ÏµÔÚÃÀ¹ú¹ûÕæÔ˶¯µÄËùÓÐÉúÒâËùÊг¡ºÍ֤ȯ¹«Ë¾£¬ÌìÌìÆÊÎöÊýÊ®ÒÚ¸öÊг¡ÉúÒâ¡£ÕâЩÓʼþÉù³ÆÀ´×Ô¡°FINRA SUPPORT¡±£¬µØµãΪ¡°support@westour.org¡±¡£¸ÃÓʼþÒªÇóÊÕ¼þÈË×¢ÖØÏÂÃæËù¸½µÄ±¨¸æ²¢Á¬Ã¦»Ø¸´£¬»¹Ö¸³ö¸½¼þ°üÀ¨¸üÐµĹ«¹²Õþ²ßÐÅÏ¢£¬µ«ÕâЩµç×ÓÓʼþ¿ÉÄÜ»ù´¡Ã»Óи½¼þ¡£ÔçÔÚ½ñÄê3ÔºÍ6Ô³õ£¬FINRA»¹ÖÒÑÔÁËαÔì³É¡°FINRAºÏ¹æÉó¼Æ¡±ºÍÒÔ´¦·ÖΪÓÕ¶üµÄÁ½´Î´¹ÂÚÔ˶¯¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-brokerage-firms-warned-of-finra-support-phishing-attacks/


5¡¢Î¢ÈíÐû²¼Çå¾²¸üУ¬ÐÞ¸´Edgeä¯ÀÀÆ÷ÖеĶà¸öÎó²î


5.jpg


΢ÈíÐû²¼Çå¾²¸üУ¬ÐÞ¸´ÁËEdgeä¯ÀÀÆ÷ÖеÄ2¸öÎó²î¡£ÆäÖнÏΪÑÏÖصÄÊÇÇå¾²ÈƹýÎó²î£¨CVE-2021-34506£©£¬Ê¹ÓÃEdgeä¯ÀÀÆ÷ÄÚÖõÄMicrosoft Translator¹¦Ð§×Ô¶¯·­ÒëÍøҳʱ´¥·¢µÄ¿çÕ¾µã¾ç±¾(UXSS)Îó²îµ¼ÖµÄ£¬¿ÉÒÔÓÃÀ´ÔÚÍøÕ¾ÉÏÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£Ñо¿Ö°Ô±³Æ¸ÃÎó²îµÄÖØ´óÐԺܵÍ£¬¹¥»÷Õß¿ÉÒÔÔÚ²»ÐèÒªÈκÎȨÏÞµÄÇéÐÎÏÂʵÏÖ¡£´Ë´ÎÐÞ¸´µÄÁíÒ»¸öÎó²îΪÌØȨÌáÉýÎó²î£¨CVE-2021-34475£©¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/06/microsoft-edge-bug-couldve-let-hackers.html