Google 5ÔÂAndroidÇ徲ͨ¸æÖÐÓÐ4¸ö0day±»ÔÚҰʹÓ㻣»£»£»£»ÃÀ¹úÁ½µ³³ǫ̈ÎåÏî·¨°¸ÒÔÔöÇ¿¶ÔÍøÂç¹¥»÷µÄ·ÀÓùÄÜÁ¦

Ðû²¼Ê±¼ä 2021-05-21

1.Google 5ÔÂAndroidÇ徲ͨ¸æÖÐÓÐ4¸ö0day±»ÔÚҰʹÓÃ


1.jpg


Google Project ZeroÍŶӳÆ£¬£¬£¬£¬£¬£¬£¬ÆäÐû²¼µÄ5ÔÂAndroidÇ徲ͨ¸æÖÐÓÐ4¸ö0dayÒѱ»ÔÚҰʹÓᣡ£ ¡£Õâ4¸öÎó²îÓ°ÏìÁËQualcomm GPUºÍArm Mali GPUÇý¶¯³ÌÐò×é¼þ£¬£¬£¬£¬£¬£¬£¬»®·ÖΪÊͷźóʹÓÃÎó²î£¨CVE-2021-1905£©¡¢µØµã×¢Ïúʧ°ÜÇéÐδ¦Öóͷ£²»µ±£¨CVE-2021-1906£©¡¢GPUÄÚ´æ²Ù×÷²»µ±£¨CVE-2021-28663£©ºÍÌáȨÎó²î£¨CVE-2021-28664£©¡£¡£ ¡£Ñо¿Ö°Ô±½¨ÒéÓû§¾¡¿ì×°ÖÃ×îиüС£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/118089/mobile-2/android-4-zero-day-flaws.html


2.Ñо¿Ö°Ô±Åû¶¼²³ÛµÄMBUXÐÅÏ¢ÓéÀÖϵͳÖеĶà¸öÎó²î


2.jpg


Ñо¿Ö°Ô±Åû¶Á˼²³ÛÓû§ÌåÑ飨MBUX£©ÐÅÏ¢ÓéÀÖϵͳÖеÄ5¸öÎó²î¡£¡£ ¡£ÕâЩÎó²î»®·ÖΪCVE-2021-23906¡¢CVE-2021-23907¡¢CVE-2021-23908¡¢CVE-2021-23909ºÍCVE-2021-23910£¬£¬£¬£¬£¬£¬£¬¿É±»ÓÃÀ´¿ÉÒÔÈÆ¹ý³µÁ¾µÄ·ÀµÁ±£»£»£»£»£»¤ÉõÖÁ¿ØÖƳµÁ¾£¬£¬£¬£¬£¬£¬£¬Èç·­¿ªÆø·ÕµÆ»ò·­¿ª·­¿ªÕÚÑôÕֵȲÙ×÷¡£¡£ ¡£Ñо¿Ö°Ô±»¹·¢Ã÷Á˶àÖÖ¹¥»÷³¡¾°£¬£¬£¬£¬£¬£¬£¬°üÀ¨Ê¹ÓÃä¯ÀÀÆ÷µÄJavaScriptÒýÇæ¡¢Wi-FiоƬ¡¢À¶ÑÀ¿ÍÕ»¡¢USB¹¦Ð§»òµÚÈý·½Ó¦ÓóÌÐò¾ÙÐй¥»÷¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/118081/hacking/mercedes-benz-hack.html


3.ÃÀ¹úÁ½µ³³ǫ̈ÎåÏî·¨°¸ÒÔÔöÇ¿¶ÔÍøÂç¹¥»÷µÄ·ÀÓùÄÜÁ¦


3.jpg


ÃÀ¹úÖÚÒéÔºÁìÍÁÇ徲ίԱ»áÓÚ±¾ÖÜһͨ¹ýÁËÎåÏî·¨°¸£¬£¬£¬£¬£¬£¬£¬ÒÔÔöÇ¿¶ÔÍøÂç¹¥»÷µÄ·ÀÓùÄÜÁ¦¡£¡£ ¡£ÕâЩ·¨°¸°üÀ¨£ºH.R. 2980£¬£¬£¬£¬£¬£¬£¬¡¶ÍøÂçÇå¾²Îó²îµ÷½â·¨°¸¡·£»£»£»£»£»H.R. 3138£¬£¬£¬£¬£¬£¬£¬¡¶Öݺ͵ط½ÍøÂçÇ徲ˢз¨°¸¡· £»£»£»£»£»H.R. 3223£¬£¬£¬£¬£¬£¬£¬¡¶CISAÍøÂçÑÝϰ·¨¡·£»£»£»£»£»H.R. 3243£¬£¬£¬£¬£¬£¬£¬¡¶¹ÜµÀÇå¾²·¨¡·£»£»£»£»£»H.R. 3264£¬£¬£¬£¬£¬£¬£¬¡¶ÁìÍÁÇå¾²Òªº¦ÁìÓò·¨°¸¡·¡£¡£ ¡£ÕâЩ·¨°¸ÊÇÁìÍÁÇ徲ίԱ»áÕë¶Ô×î½üµÄÍøÂç¹¥»÷¶øÌá³öµÄ£¬£¬£¬£¬£¬£¬£¬¾Ý±¨µÀColonial PipelineÖ§¸¶ÁË500ÍòÃÀÔªÊê½ð£¬£¬£¬£¬£¬£¬£¬µ«²¢Ã»ÓÐ×èÖ¹¶«±±¸÷ÖÝȼÁϵĴó¹æÄ£Ç·È±¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-introduces-bills-to-secure-critical-infrastructure-from-cyber-attacks/


4.Win10×îÐÂÀÛ»ý¸üпɵ¼ÖÂTeamsµÈÓ¦ÓÃÎÞ·¨µÇ¼


4.jpg


Windows 10 1909 KB5003169ÀÛ»ý¸üе¼ÖÂMicrosoft 365Óû§ÎÞ·¨µÇ¼Teams¡¢OutlookºÍOneDrive¡£¡£ ¡£Óû§±¨¸æ£¬£¬£¬£¬£¬£¬£¬ÆäÔÚʵÑéµÇ¼ʱ»áÏÔʾ¹ýʧ´úÂë80080300£¬£¬£¬£¬£¬£¬£¬²¢·ºÆð¡°ÎÒÃÇÓöµ½ÁËÎÊÌâ¡£¡£ ¡£ÕýÔÚÖØÐÂÅþÁ¬¡­¡±µÄÌáÐÑ£¬£¬£¬£¬£¬£¬£¬ÒªÇóÓû§ÖØÐÂÆô¶¯¸Ã³ÌÐò¡£¡£ ¡£Î¢ÈíÌåÏÖ£¬£¬£¬£¬£¬£¬£¬´Ë´ÎÖÐÖ¹ÊÂÎñÊÇÓÉÓÚ¸üÐÂÖеÄÒ»¸ö´úÂëÎÊÌ⵼ֵ쬣¬£¬£¬£¬£¬£¬Ö»Ó°ÏìÁ˲¿·ÖÓû§£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ýÖØÐÂÆô¶¯Windows 10¾ÙÐÐÐÞ¸´¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/recent-windows-10-update-blocks-microsoft-teams-outlook-logins/


5.TeamBMSÒòAWS S3´æ´¢Í°ÉèÖùýʧй¶2Íò¶àÓû§ÐÅÏ¢


5.jpg


Website Planet·¢Ã÷£¬£¬£¬£¬£¬£¬£¬FastTrack Reflex Recruitment£¨ÏÖΪTeamBMS£©ÒòAWS S3´æ´¢Í°ÉèÖùýʧй¶ÁË2Íò¶àÓû§ÐÅÏ¢¡£¡£ ¡£¸Ã¹«Ë¾Ö÷Òª´ÓÊÂÐÞ½¨ÖÎÀíϽµµÍìÓòµÄÕÐÆ¸ÊÂÇ飬£¬£¬£¬£¬£¬£¬ÏîÄ¿°üÀ¨Î²¼ÀûÇò³¡¡¢°ÂÁÖÆ¥¿ËÌåÓý³¡ºÍϣ˼ÂÞ5ºÅº½Õ¾Â¥µÈ¡£¡£ ¡£´Ë´Îй¶ÁË21000¸öÎļþ£¬£¬£¬£¬£¬£¬£¬°üÀ¨Óû§µÄµç×ÓÓʼþµØµã¡¢È«Ãû¡¢ÊÖ»úºÅÂë¡¢¼Òͥסַ¡¢Éç½»ÍøÂçURL¡¢³öÉúÈÕÆÚ¡¢»¤ÕÕºÅÂëºÍÉêÇëÈËÕÕÆ¬µÈ¡£¡£ ¡£Ñо¿Ö°Ô±ÍƶÏ£¬£¬£¬£¬£¬£¬£¬´Ë´Îй¶ÊÇÓɸù«Ë¾µÄITЧÀÍÌṩÉ̵¼ÖµÄ¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/recruiters-cloud-snafu-exposes/


6.PaloaltoÐû²¼2021ÄêCortex XpanseÍþвÆÊÎö±¨¸æ


6.jpg


PaloaltoÐû²¼ÁË2021ÄêCortex XpanseÍþвÆÊÎö±¨¸æ¡£¡£ ¡£¸Ã±¨¸æ´Ó2021Äê1Ôµ½3Ô£¬£¬£¬£¬£¬£¬£¬¶ÔÈ«Çò50¼ÒÆóÒµµÄ5000Íò¸öIPµØµã¾ÙÐÐÁË¼à¿ØÉ¨Ã裬£¬£¬£¬£¬£¬£¬ÒÔÏàʶ¹¥»÷ÕßÄܶà¿ìµØÊ¶±ð³ö¿É±»Ê¹ÓõÄϵͳ¡£¡£ ¡£Òªº¦Îó²îµÄ¹ûÕæÅû¶,»áÒý·¢¹¥»÷ÕߺÍITÖÎÀíÔ±Ö®¼äµÄ¾ºÈü£º¹¥»÷ÕßҪѰÕÒºÏÊʵÄÄ¿µÄ£¬£¬£¬£¬£¬£¬£¬¶øITÖ°Ô±Òª¾ÙÐÐΣº¦ÆÀ¹ÀºÍ×°ÖÃÐëÒªµÄ²¹¶¡¡£¡£ ¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜÔÚ0day¹ûÕæºóµÄ15·ÖÖÓÄÚ¶ÔÆä¾ÙÐÐɨÃ裬£¬£¬£¬£¬£¬£¬¶øÕë¶ÔMicrosoft ExchangeÖеÄÎó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÐж¯µÃ¸ü¿ì£¬£¬£¬£¬£¬£¬£¬ÔÚ²»µ½Îå·ÖÖÓµÄʱ¼äÄÚ¼´¼ì²âµ½ÁËɨÃè¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://start.paloaltonetworks.com/asm-report