SAM·¢Ã÷MiraiʹÓÃRealtek SDKÖÐÎó²îµÄ¹¥»÷Ô˶¯:ºÚ¿ÍÉù³ÆÒÑÇÔÈ¡ÒÁÀÊÀÎÓüÊý°ÙGBµÄ¼à¿ØÊý¾Ý

Ðû²¼Ê±¼ä 2021-08-26

SAM·¢Ã÷MiraiʹÓÃRealtek SDKÖÐÎó²îµÄ¹¥»÷Ô˶¯


 SAM Seamless.jpg


Çå¾²¹«Ë¾SAM SeamlessÓÚ8ÔÂ19ÈÕ³ÆÆä·¢Ã÷Á˽©Ê¬ÍøÂçMiraiʹÓÃRealtek SDKÖÐÎó²îµÄ¹¥»÷Ô˶¯¡£¸ÃÎó²îΪÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¬×·×ÙΪCVE-2021-20090£¬ÆÀ·ÖΪ9.8·Ö£¬RealtekÒÑÓÚ8ÔÂ13ÈÕÐû²¼¸ÃÎó²îµÄ²¹¶¡³ÌÐò¡£SAMÌåÏÖ£¬ËûÃÇÓÚ8ÔÂ18ÈÕÔÚÒ°·¢Ã÷ÁË´Ë´ÎÎó²îʹÓÃÔ˶¯£¬¹¥»÷Ô´ÓÚ31.210.20[.]100£¬µ«¹¥»÷ÕßµÄIPµØµã¿ÉÄÜ»áËæ×Åʱ¼ä¶ø¸Ä±ä¡£


Ô­ÎÄÁ´½Ó£º

https://securingsam.com/realtek-vulnerabilities-weaponized/


OpenSSLÐû²¼Çå¾²¸üУ¬ÐÞ¸´²úÆ·ÖеÄ2¸öÇå¾²Îó²î


OpenSSLÐû²¼Çå¾²¸üУ¬ÐÞ¸´²úÆ·ÖеÄ2¸öÇå¾²Îó²î.png


OpenSSLÓÚ8ÔÂ24ÈÕÐû²¼Çå¾²¸üУ¬ÐÞ¸´Æä²úÆ·ÖеÄ2¸öÇå¾²Îó²î¡£ÆäÖÐ×îΪÑÏÖØµÄÊÇ»º³åÇøÒç³öÎó²î£¬×·×ÙΪCVE-2021-3711£¬¹¥»÷ÕßʹÓÃÆä¿Éµ¼ÖÂÓ¦ÓóÌÐòÍ߽⡣¸ÃÎó²îÓëSM2¼ÓÃÜÊý¾ÝµÄ½âÃÜÀú³ÌÏà¹Ø£¬¿ÉÓÃÀ´¸ü¸Ä¶ÑÖеÄÊý¾Ý£¨¼´Æ¾Ö¤£©¡£´Ë´ÎÐÞ¸´µÄÁíÒ»¸öÎó²î×·×ÙΪCVE-2021-3712£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î´¥·¢¾Ü¾ø·þÎñ(DoS)£¬»¹¿ÉÄܵ¼ÖÂÉñÃØÐÅϢй¶£¬ÀýÈç˽Կ»òÃô¸ÐÃ÷ÎÄ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/121426/hacking/cve-2021-3711-openssl-flaws.html


ºÚ¿ÍÉù³ÆÒÑÇÔÈ¡ÒÁÀÊÀÎÓüµÄ¼à¿ØÏµÍ³ÖÐÊý°ÙGBµÄÊý¾Ý


ºÚ¿ÍÉù³ÆÒÑÇÔÈ¡ÒÁÀÊÀÎÓüµÄ¼à¿ØÏµÍ³ÖÐÊý°ÙGBµÄÊý¾Ý.jpg


ºÚ¿ÍÍÅ»ïTapandegan(Palpitations)ÓÚÉϹûÕæÁË´ó×ÚÒÁÀÊEvinÀÎÓüÖÐݱ¶¾Çô·¸µÄÊÓÆµ¡£ÕâЩÊÓÆµµÄʱ¼ä´ÁΪ2020ÄêºÍ2021Ä꣬°üÀ¨EvinµÄ¾¯ÎÀŹ´òÇô·¸¡¢ÊÔͼ×ÔɱµÄÇô·¸»ò»èØÊ²¢±»ÍϹý×ßÀȵÄÇô·¸µÈÄÚÈÝ¡£¸ÃÍÅ»ï³ÆËûÃÇÖ»×ÊÖúÐû´«ÁËÊÓÆµµ«²¢Î´¼ÓÈë¹¥»÷£¬²¢½«´Ë´ÎÔ˶¯¹é¹¦ÓÚAli's JusticeÍŻ´ËºóÕßÔòÉù³ÆÆäÔÚ¼¸¸öÔÂǰ¾ÍÈëÇÖÁËÀÎÓüµÄ¼à¿ØÏµÍ³£¬²¢ÇÔÈ¡ÁËÊý°ÙGBµÄÊý¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/hackers-leak-footage-of-iranian/



ŵ»ùÑÇ×Ó¹«Ë¾SAC Wireless³ÆÆäÔâµ½ContiÀÕË÷¹¥»÷


ContiÀÕË÷¹¥»÷.jpg


λÓÚÃÀ¹úµÄŵ»ùÑÇ×Ó¹«Ë¾SAC WirelessÔÚ6ÔÂ16ÈÕ·¢Ã÷ÆäÔâµ½ÁËContiÀÕË÷¹¥»÷£¬¹¥»÷ÕßÖ»ÊÇ×°ÖÃÁËpayload²¢¼ÓÃÜÁËSACÎÞÏßϵͳ¡£¿ÉÊÇÔÚÖ®ºóµÄȡ֤ÊÓ²ìÖУ¬ÓÚ8ÔÂ13ÈÕ·¢Ã÷ÆäÏÖÔ±¹¤ºÍǰԱ¹¤µÄСÎÒ˽¼ÒÐÅÏ¢Ò²Òѱ»ÇÔ¡£¸Ã¹«Ë¾¾Ü¾øÍ¸Â¶¸ü¶àÓйش˴ι¥»÷µÄÐÅÏ¢£¬µ«ContiÍÅ»ïÔÚËûÃǵÄÊý¾ÝÐ¹Â¶ÍøÕ¾ÉÏ͸¶£¬ÒѾ­»ñµÃÁËÁè¼Ý250 GBµÄÊý¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/nokia-subsidiary-discloses-data-breach-after-conti-ransomware-attack/


FBIÐû²¼OnePercent Group¹¥»÷Ô˶¯µÄTTP»ººÍ½â²½·¥


FBIÐû²¼OnePercent Group.jpg


FBIÐû²¼ÁËÓйØOnePercent GroupµÄ¹¥»÷Ô˶¯µÄTTP»ººÍ½â²½·¥£¬²¢³Æ¸ÃÍÅ»ïÖÁÉÙ×Ô2020Äê11ÔÂÒÔÀ´Ò»Ö±ÔÚÕë¶ÔÃÀ¹úµÄ×éÖ¯¾ÙÐÐÀÕË÷Èí¼þ¹¥»÷¡£¸Ã»ú¹¹³Æ¹¥»÷ÕßÊ×ÏÈʹÓô¹ÂÚ¹¥»÷£¬ÔÚÄ¿µÄϵͳÉÏ×°ÖÃÒøÐÐľÂíIcedID²¢ÏÂÔØCobalt Strike£¬È»ºó¾ÙÐмÓÃÜÔ˶¯¡£FBIûÓÐÌṩ¹¥»÷»ò¼ÓÃÜÆ÷µÄÏêϸÐÅÏ¢£¬µ«³ÆÆäÓëREvilÓйØ¡£Ñо¿Ö°Ô±ÍƶÏ£¬Æä¿ÉÄÜÊÇREvilµÄcartelͬÃËÖеÄÏàÖúͬ°é¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fbi-onepercent-group-ransomware-targeted-us-orgs-since-nov-2020/


Trend MicroÐû²¼2021 H1 LinuxÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ


Trend MicroÐû²¼2021 H1 LinuxÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ.jpg


Trend MicroÐû²¼ÁË2021 H1 LinuxÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£±¨¸æÖ¸³ö£¬ÔÚ2021ÄêÉϰëÄêÑо¿Ö°Ô±×ܼÆÍ³¼ÆÁ˽ü1500Íò¸öÕë¶ÔLinuxµÄÇå¾²ÊÂÎñ£¬²¢·¢Ã÷ÍÚ¿óÈí¼þºÍÀÕË÷Èí¼þÕ¼ËùÓжñÒâÈí¼þµÄ36.11%£¬Web shellÕ¼19.92%¡£ÔÚÒ°·¢Ã÷µÄ¹¥»÷Ô˶¯ÖÐʹÓÃ×î¶àµÄÎó²î°üÀ¨Apache Struts 2ÖеÄRCEÎó²î£¨CVE-2017-5638£©¡¢Apache Struts 2 REST plugin XStreamÖеÄRCEÎó²î£¨CVE-2017-9805£©£¬ÒÔ¼°Drupal CoreÖеÄRCEÎó²î£¨CVE-2018-7600£©µÈ¡£    


Ô­ÎÄÁ´½Ó£º

https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/linux-threat-report-2021-1h-linux-threats-in-the-cloud-and-security-recommendations