Stratus¹«Ë¾Ñ¬È¾ÀÕË÷Èí¼þ£¬£¬£¬£¬ÍøÂçºÍЧÀÍÔÝʱÖÐÖ¹£»£»£»£»Purple Fox¹¥»÷»î¶¯½ÏÈ¥ÄêÔöÌí600£¥£¬£¬£¬£¬´ï9Íò¶à´Î

Ðû²¼Ê±¼ä 2021-03-25

1.Stratus¹«Ë¾Ñ¬È¾ÀÕË÷Èí¼þ£¬£¬£¬£¬ÍøÂçºÍЧÀÍÔÝʱÖÐÖ¹


1.jpg


Stratus TechnologiesѬȾÀÕË÷Èí¼þ£¬£¬£¬£¬ÍøÂçºÍЧÀÍÔÝʱÖÐÖ¹¡£¡£¡£ ¡£StratusÊÇ×ÅÃûµÄ¸ß¿ÉÓÃÐÔ²úÆ·ÌṩÉÌ£¬£¬£¬£¬Æä²úÆ·°üÀ¨ztC±ßÑØÅÌËã×°±¸ºÍftServerÈÝ´íЧÀÍÆ÷½â¾ö¼Æ»®µÈ£¬£¬£¬£¬¿Í»§ÎªÒøÐС¢µçÐÅÌṩÉÌ¡¢½ôÆÈºô½ÐÖÐÐĺÍÒ½ÁƱ£½¡»ú¹¹µÈ¡£¡£¡£ ¡£¸Ã¹«Ë¾³ÆÆäÔÚ3ÔÂ17ÈÕÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬¼ì²âµ½¹¥»÷ºóÁ¬Ã¦¹Ø±ÕÁ˲¿·ÖÍøÂçºÍЧÀÍÒÔ¸ôÀë¹¥»÷£¬£¬£¬£¬°üÀ¨ÆäÈÝ´í²úÆ·µÄЧÀÍActiveService Network£¨ASN£©ºÍStratusЧÀÍÃÅ»§¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/high-availability-server-maker-stratus-hit-by-ransomware/


2.Hobby LobbyÒò´æ´¢Í°ÉèÖùýʧй¶138GBÃô¸ÐÐÅÏ¢


2.jpg


¹¤ÒÕÆ·ÁãÊÛÉÌHobby LobbyÒòAWS´æ´¢Í°ÉèÖùýʧй¶138GBÃô¸ÐÐÅÏ¢£¬£¬£¬£¬Ó°ÏìÁËÔ¼30ÍòÃûÓû§¡£¡£¡£ ¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨Óû§ÐÕÃû¡¢²¿·ÖÖ§¸¶¿¨µÄÏêϸÐÅÏ¢¡¢µç»°ºÅÂë¡¢µØµãºÍÓʼþµØµã£¬£¬£¬£¬±ðµÄ»¹°üÀ¨Ó¦ÓóÌÐòµÄÔ´´úÂë¡¢¹«Ë¾Ô±¹¤µÄÐÕÃûºÍµç×ÓÓʼþµØµãµÈ¡£¡£¡£ ¡£ÏÖÔÚ£¬£¬£¬£¬¸Ã´æ´¢Í°Òѱ»±£»£»£»£»¤ÆðÀ´£¬£¬£¬£¬µ«Éв»È·¶¨ÊÇ·ñÓкڿÍÔÚ´Ë֮ǰÇÔÈ¡ÁË̻¶µÄÐÅÏ¢¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/hobby-lobby-customer-data-cloud-misconfiguration/164980/


3.Ó¢¹úÄÉ˰ÈËʹÓõÄÕ˵¥ÌáÐÑϵͳ¿ÉÄÜй¶ÆäÃô¸ÐÊý¾Ý


3.jpg


The RegisteµÄÒ»ÏîÊӲ췢Ã÷Ó¢¹úÄÉ˰ÈËʹÓõÄÕ˵¥ÌáÐÑϵͳ¿ÉÄÜй¶ÆäÃô¸ÐÊý¾Ý¡£¡£¡£ ¡£¸ÃϵͳÊÇÓÉTelsolutions¿ª·¢£¬£¬£¬£¬Ö÷Òª¹¦Ð§ÊÇÏòÇ·Õ®Õß·¢ËÍÐÂÎÅÀ´ÌáÐÑÆä»¹Õ®£¬£¬£¬£¬¸ÃÐÂÎÅÖлá°üÀ¨Ò»¸öÖ¸ÏòÎüÊÕÕßСÎÒ˽¼ÒÐÅÏ¢ºÍδÇåÕʵ¥Ò³ÃæµÄURL¡£¡£¡£ ¡£¿ÉÊÇ£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý¸ü¸ÄÍøÖ·ÖеÄ×ÖĸºÍÊý×Ö×Ö·ûÀ´ÅÌÎÊÊôÓÚÆäËûÈ˵ÄÐÅÏ¢£¬£¬£¬£¬ÉõÖÁ°üÀ¨×¡ÔÚ²î±ðµØÇøµÄסÃñÐÅÏ¢¡£¡£¡£ ¡£TelsolutionsÌåÏÖ¸ÃÎó²îÏÖÒÑÐÞ¸´¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/debt-chasing-uk-councils-potentially-expose-private-resident-data/


4.Purple Fox¹¥»÷»î¶¯½ÏÈ¥ÄêÔöÌí600£¥£¬£¬£¬£¬´ï9Íò¶à´Î


4.jpg


Guardicore LabsÇå¾²Ñо¿Ö°Ô±·¢Ã÷Purple FoxµÄ¹¥»÷»î¶¯×ÔÈ¥Äê5Ô·ÝÖÁ½ñÔöÌíÁË600£¥£¬£¬£¬£¬µÖ´ïÁË9Íò¶à´Î¡£¡£¡£ ¡£Purple FoxÊÇÒ»ÖÖWindows¶ñÒâÈí¼þ£¬£¬£¬£¬ÓÚ2018Äê3ÔÂÊ״α»·¢Ã÷£¬£¬£¬£¬Í¨¹ýÎó²îʹÓù¤¾ß°üºÍ´¹ÂÚÓʼþÀ´Ñ¬È¾ÅÌËã»ú¡£¡£¡£ ¡£ÔÚ×î½üµÄ»î¶¯ÖУ¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÁËËüʹÓÃÁËеÄѬȾǰÑÔ£¬£¬£¬£¬Í¨¹ýSMBÃÜÂ뱩Á¦ÆÆ½âÃæÏòÍøÂçµÄWindowsÅÌËã»ú¡£¡£¡£ ¡£±ðµÄ£¬£¬£¬£¬¹¥»÷ÕßÒѽ«Purple FoxËùʹÓõÄÖÖÖÖ¶ñÒâpayloadÍйÜÔÚÓɽü2000̨±»ÈëÇÖµÄЧÀÍÆ÷×é³ÉµÄÖØ´ó½©Ê¬ÍøÂçÉÏ¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/03/purple-fox-rootkit-can-now-spread.html


5.΢ÈíÖÒÑÔ½üÆÚ´¹ÂڻÒÑÇÔÈ¡40Íò¸öOWAºÍOffice 365ƾ֤


5.jpg


×ÔÈ¥Äê12ÔÂÒÔÀ´£¬£¬£¬£¬´¹ÂڻÒÑÇÔÈ¡40Íò¸öOWAºÍOffice 365ƾ֤¡£¡£¡£ ¡£WMC GlobalÓÚÈ¥ÄêÄêÍ··¢Ã÷¸Ã´¹Âڻ£¬£¬£¬£¬Î±×°³Éαװ³ÉÊÓÆµ¾Û»áЧÀÍ¡¢Çå¾²½â¾ö¼Æ»®ºÍÉú²ú¹¤¾ßÀ´ÒÉ»óÊܺ¦Õß¡£¡£¡£ ¡£È¥Äê12Ô£¬£¬£¬£¬ºÚ¿Íð³äÁËOutlook Web AppÀ´ÓÕÆ­Ä¿µÄÓû§ÊäÈëÆ¾Ö¤£¬£¬£¬£¬ÏÖÔÚÄê1Ô¸ÄΪģÄâOffice 365À´ÇÔȡƾ֤¡£¡£¡£ ¡£±ðµÄ£¬£¬£¬£¬Î¢Èí·¢Ã÷¸Ã»î¶¯»¹Ê¹ÓÃÁËAmazon Simple Email Service£¨SES£©ºÍAppspotÔÆÅÌËãÆ½Ì¨À´·¢ËÍÍøÂç´¹ÂÚµç×ÓÓʼþ¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-warns-of-phishing-attacks-bypassing-email-gateways/


6.CiscoÐû²¼Çå¾²¸üУ¬£¬£¬£¬ÐÞ¸´JabberÖÐí§Òâ´úÂëÖ´ÐÐÎó²î


6.jpg


CiscoÐû²¼Çå¾²¸üУ¬£¬£¬£¬ÐÞ¸´ÁËWindows¡¢macOS¡¢AndroidºÍiOS°æ±¾Jabber clientÖеÄí§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£¡£ ¡£JabberÊÇÒ»¸öÍøÂç¾Û»áºÍ¼´Ê±ÐÂÎÅת´ïÓ¦Ó㬣¬£¬£¬CiscoÌåÏÖ¸ÃÎó²îÏÖÔÚÉÐδ±»ÆÕ±éʹÓᣡ£¡£ ¡£¸ÃÎó²î±»×·×ÙΪCVE-2021-1411£¬£¬£¬£¬ÑÏÖØÆ·¼¶Îª9.9£¬£¬£¬£¬ÊÇÓɶÔÊäÈëÐÂÎÅÄÚÈÝÑéÖ¤²»µ±ÒýÆðµÄ¡£¡£¡£ ¡£±ðµÄ£¬£¬£¬£¬´Ë´Î¸üл¹ÐÞ¸´Á˸òúÆ·ÖÐµÄÆäËû4¸öÎó²î£¨CVE-2021-1417ºÍ CVE-2021-1418µÈ£©£¬£¬£¬£¬ÒÔ¼°ÆäËû²úÆ·ÖеÄ37¸öÎó²î¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/cisco-addresses-critical-bug-in-windows-macos-jabber-clients/