ForescoutÅû¶ӰÏìÉÏÒŲ́װ±¸µÄDNSÎó²îNAME£ºWRECK£»£»£»£»£»£»Î¢ÈíÐû²¼4Ô²¹¶¡£¬£¬£¬ £¬£¬£¬ £¬ÐÞ¸´5¸ö0dayÔÚÄÚµÄ108¸öÎó²î

Ðû²¼Ê±¼ä 2021-04-14

1.ForescoutÅû¶ӰÏìÉÏÒŲ́װ±¸µÄDNSÎó²îNAME£ºWRECK


1.jpg


Çå¾²¹«Ë¾ForescoutºÍÒÔÉ«ÁÐÇå¾²ÍŶÓJSOFÁªºÏÅû¶ÁËTCP/IP¿ÍÕ»ÖÐDNSЭÒéÖеÄ9¸öÇå¾²Îó²î£¬£¬£¬ £¬£¬£¬ £¬Í³³ÆÎªNAME£ºWRECK£¬£¬£¬ £¬£¬£¬ £¬Ó°ÏìÁË1ÒÚ¸öÔÚInternetÉÏÔËÐеÄ×°±¸¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îʹװ±¸ÍÑ»ú»òÕßÍêÈ«¿ØÖÆ×°±¸¡£¡£¡£¡£ÕâЩÎó²îÖÐ×îÑÏÖØµÄΪIPnetÖеÄRCEÎó²î£¨CVE-2016-20009£©£¬£¬£¬ £¬£¬£¬ £¬ÑÏÖØÐԵ÷ÖΪ9.8¡£¡£¡£¡£Æä´ÎΪRCE£¨CVE-2020-7461¡¢CVE-2020-15795ºÍCVE-2020-27009£©ºÍDoS£¨CVE-2020-27736ºÍCVE-2020-27737£©µÈÎó²î¡£¡£¡£¡£    


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/name-wreck-dns-vulnerabilities-affect-over-100-million-devices/


2.Ñо¿Ö°Ô±¹ûÕæChromeºÍEdgeµÈÓ¦ÓõÄRCE 0dayµÄPoC


2.jpg


Ñо¿Ö°Ô±ÔÚRajvardhan AgarwalÔÚTwitterÐû²¼ÁËChromeºÍEdgeµÈÓ¦ÓÃÖеÄRCE 0dayµÄPoC¡£¡£¡£¡£¸ÃÎó²îÊÇ»ùÓÚChromiumµÄä¯ÀÀÆ÷µÄV8 JavaScriptÒýÇæÖÐÔ¶³ÌÖ´ÐдúÂëÎó²î£¬£¬£¬ £¬£¬£¬ £¬Ó°ÏìÁËChrome¡¢Edge¡¢OperaºÍBraveµÈä¯ÀÀÆ÷¡£¡£¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬ £¬AgarwalÌåÏÖ¸Ã0dayÐèÒªÓëÁíÒ»¸ö¿ÉÒÔÔÚChromiumµÄɳÏäÌÓÒݵÄÎó²îÒ»ÆðʹÓòŻªÊ©Õ¹×÷Óᣡ£¡£¡£ÏÖÔÚ£¬£¬£¬ £¬£¬£¬ £¬¸ÃÎó²îÒÑÔÚV8 JavaScriptÒýÇæµÄ×îа汾Öб»ÐÞ¸´¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/04/rce-exploit-released-for-unpatched.html


3.MicrosoftÐû²¼4Ô²¹¶¡£¬£¬£¬ £¬£¬£¬ £¬ÐÞ¸´5¸ö0dayÔÚÄÚµÄ108¸öÎó²î


3.jpg


MicrosoftÐû²¼ÁË4Ô·ݵÄÖܶþ²¹¶¡£¬£¬£¬ £¬£¬£¬ £¬×ܼÆÐÞ¸´Á˰üÀ¨5¸ö0dayÔÚÄÚµÄ108¸öÎó²î¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄ0day°üÀ¨RPC¶ËµãÓ³ÉäÆ÷µÄÌáȨÎó²î£¨CVE-2021-27091£©¡¢NTFS¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2021-28312£©¡¢Windows×°ÖóÌÐòÖеÄÐÅϢй¶Îó²î£¨CVE-2021-28437£©¡¢Azure ms-rest-nodeauth¿âµÄÌáȨÎó²î£¨CVE-2021-28458£©ÒÔ¼°Win32kÖеÄÌáȨÎó²î£¨CVE-2021-28310£©¡£¡£¡£¡£ÆäÖУ¬£¬£¬ £¬£¬£¬ £¬CVE-2021-28310Îó²îÊÇKasperskyÔÚÒ°·¢Ã÷µÄ£¬£¬£¬ £¬£¬£¬ £¬Òѱ»APT×éÖ¯BITTERʹÓᣡ£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2021-patch-tuesday-fixes-108-flaws-5-zero-days/


4.ºÚ¿Í³öÊÛ2100Íò¸öÍ£³µÓ¦ÓÃParkMobileµÄÓû§µÄÐÅÏ¢


4.jpg


Gemini Advisory·¢Ã÷ºÚ¿ÍÔÚ°µÍø³öÊÛ2100Íò¸öÒÆ¶¯Í£³µÓ¦ÓóÌÐòParkMobileµÄÓû§µÄÐÅÏ¢£¬£¬£¬ £¬£¬£¬ £¬ÊÛ¼ÛΪ125000ÃÀÔª¡£¡£¡£¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨¿Í»§µç×ÓÓʼþµØµã¡¢ÉúÈÕ¡¢µç»°ºÅÂë¡¢³µÅƺš¢¹þÏ£ÃÜÂëºÍÓʼĵصãµÈ¡£¡£¡£¡£ParkMobile¹«Ë¾³Æ£¬£¬£¬ £¬£¬£¬ £¬Æä3ÔÂ26ÈÕ¾ÍÐû²¼ÁËÓйØÊý¾Ýй¶µÄ֪ͨ£¬£¬£¬ £¬£¬£¬ £¬²¢ÔÚÇå¾²¹«Ë¾µÄЭÖú϶ԴËÊÂÕö¿ªÁËÊӲ졣¡£¡£¡£µ«Ñо¿Ö°Ô±ÌåÏÖÆä¹ÙÍø²¢Ã»ÓиÃÇ徲֪ͨ£¬£¬£¬ £¬£¬£¬ £¬Ò²Ã»ÓÐÇ¿ÖÆÆäÓû§ÐÞ¸ÄÃÜÂë¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://krebsonsecurity.com/2021/04/parkmobile-breach-exposes-license-plate-data-mobile-numbers-of-21m-users/


5.McAfee·¢Ã÷BRATAαװ³ÉÇ徲ɨÃè³ÌÐòÔÚGoogle PlayÖзַ¢


5.jpg


McAfee·¢Ã÷ÁËBRATAµÄ¶à¸öбäÖÖ£¬£¬£¬ £¬£¬£¬ £¬Î±×°³ÉÇ徲ɨÃè³ÌÐòÔÚGoogle PlayÖзַ¢¡£¡£¡£¡£BRATA×î³õÓÚ2018Äêµ×ÔÚÒ°Íâ·ºÆð£¬£¬£¬ £¬£¬£¬ £¬ÒÔ°ÍÎ÷µÄÓû§ÎªÄ¿µÄ£¬£¬£¬ £¬£¬£¬ £¬¾ßÓпØÖÆ×°±¸¡¢Ê¹Óô¹ÂÚÍøÒ³ÇÔÈ¡ÒøÐÐÆ¾Ö¤¡¢»ñÈ¡ÆÁÄ»Ëø¶¨Æ¾Ö¤£¨PIN¡¢ÃÜÂë»òͼ°¸£©µÈ¹¦Ð§¡£¡£¡£¡£ÕâЩеıäÖÖÖ÷ÒªÔÚGoogle PlayÉϾÙÐзַ¢£¬£¬£¬ £¬£¬£¬ £¬ÒªÇóÓû§¸üÐÂChrome¡¢WhatsApp»òPDFÔĶÁÆ÷£¬£¬£¬ £¬£¬£¬ £¬²¢Í¨¹ý¸¨Öú¹¦Ð§À´ÍêÈ«¿ØÖÆ×°±¸£¬£¬£¬ £¬£¬£¬ £¬Õë¶Ô°ÍÎ÷¡¢Î÷°àÑÀºÍÃÀ¹úµÈµØÇøµÄ½ðÈÚ×éÖ¯µÄÓû§¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.mcafee.com/blogs/other-blogs/mcafee-labs/brata-keeps-sneaking-into-google-play-now-targeting-usa-and-spain/


6.Unit 42Ðû²¼2020ÄêQ4Çå¾²Ç÷ÊÆµÄÆÊÎö±¨¸æ


6.jpg


Unit 42Ðû²¼ÁË2020ÄêQ4Çå¾²Ç÷ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£±¨¸æ·¢Ã÷£¬£¬£¬ £¬£¬£¬ £¬2020Äê11ÔÂÖÁ2021Äê1ÔµĴó´ó¶¼¹¥»÷¶¼±»¹éΪÑÏÖØ¹¥»÷£¬£¬£¬ £¬£¬£¬ £¬Õ¼±ÈΪ75£¥£¬£¬£¬ £¬£¬£¬ £¬¶øÔÚÇ^Ϊ50.4£¥¡£¡£¡£¡£¹¥»÷Õ߸ü¶àµÄʹÓÃ2017ÄêÖÁ2020ÄêÔÚÒ°ÍâʹÓõÄÎó²î¡£¡£¡£¡£ÔÚ¹¥»÷ÀàÐÍ·½Ã棬£¬£¬ £¬£¬£¬ £¬µ¥¶ÀµÄ´úÂëÖ´ÐÐÕ¼×ܹ¥»÷µÄ46.6£¥£¬£¬£¬ £¬£¬£¬ £¬´úÂëÖ´ÐкÍÌØÈ¨ÌáÉýÁ¬ÏµµÄ¹¥»÷Õ¼17.3£¥£¬£¬£¬ £¬£¬£¬ £¬SQL×¢ÈëÕ¼9.9£¥¡£¡£¡£¡£ÑÏÖØÐÔ×î¸ßµÄÎó²îΪÏÂÁî×¢ÈëÎó²î£¨CVE-2020-28188£©¡¢Ä¿Â¼±éÀúÎó²î£¨CVE-2020-17519£©ºÍÍâµØÎļþ°üÀ¨Îó²î£¨CVE-2020-29227£©µÈ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/network-attack-trends-winter-2020/