°ÍÎ÷³ÆÆä²ÆÎñ²¿ÃØÊé´¦µÄÄÚ²¿ÍøÂçÔâµ½ÀÕË÷Èí¼þ¹¥»÷:Fortinet FortiWeb WAF±£´æÎ´ÐÞ¸´µÄÏÂÁî×¢Èë0day

Ðû²¼Ê±¼ä 2021-08-23

°ÍÎ÷³ÆÆä²ÆÎñ²¿ÃØÊé´¦µÄÄÚ²¿ÍøÂçÔâµ½ÀÕË÷Èí¼þ¹¥»÷


°ÍÎ÷³ÆÆä²ÆÎñ²¿ÃØÊé´¦µÄÄÚ²¿ÍøÂçÔâµ½ÀÕË÷Èí¼þ¹¥»÷.jpg


°ÍÎ÷Õþ¸®ÔÚÉÏÖÜÁùÍí¼ä͸¶£¬£¬£¬£¬ £¬Æä²ÆÎñ²¿ÃØÊé´¦µÄÄÚ²¿ÍøÂçÔÚÖÜÎåÍíÉÏ£¨8ÔÂ13ÈÕ£©Ôâµ½ÁËÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£°ÍÎ÷¾­¼Ã²¿Ðû²¼ÉùÃ÷³Æ£¬£¬£¬£¬ £¬¾­ÓÉÆðÔ´ÆÀ¹ÀÈ·¶¨¹ú¿âµÄϵͳ²¢Î´Êܵ½Ó°Ïì¡£¡£¡£8ÔÂ16ÈÕ£¬£¬£¬£¬ £¬°ÍÎ÷Õþ¸®Óë°ÍÎ÷֤ȯÉúÒâËù¾Í¸ÃÊÂÎñ½ÒÏþÁËÁªºÏÉùÃ÷£¬£¬£¬£¬ £¬³Æ×¡Ãñ¹ºÖðÍÎ÷Õþ¸®Õ®È¯µÄTesouro Diretoƽ̨ҲδÊܵ½Ó°Ïì¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/brazilian-government-discloses-national-treasury-ransomware-attack/



Cisco·¢Ã÷Õë¶ÔÄ«Î÷¸ç½ðÈÚ»ú¹¹µÄÐÂľÂíNeurevt


Cisco·¢Ã÷Õë¶ÔÄ«Î÷¸ç½ðÈÚ»ú¹¹µÄÐÂľÂíNeurevt.png


Cisco TalosÓÚ2021Äê6Ô¼ì²âµ½ÐÂNeurevtľÂí¡£¡£¡£¸Ã¶ñÒâÈí¼þ½«ºóÃźÍÐÅÏ¢ÇÔÈ¡³ÌÐòÁ¬ÏµÔÚÒ»Æð£¬£¬£¬£¬ £¬Ö÷ÒªÕë¶ÔÄ«Î÷¸ç½ðÈÚ»ú¹¹µÄÓû§¡£¡£¡£¹¥»÷ÕßÒ»µ©ÀÖ³ÉѬȾĿµÄ×°±¸£¬£¬£¬£¬ £¬¾Í¿ÉÒÔ»á¼ûÄ¿µÄϵͳ²¢ÐÞ¸ÄËûÃǵÄÉèÖÃÒÔÒþ²Ø×Ô¼º¡£¡£¡£¸ÃľÂí¿ÉÒÔͨ¹ý»á¼ûÊܺ¦ÕßµÄϵͳЧÀÍÁîÅÆÀ´ÌáȨ£¬£¬£¬£¬ £¬´Ó¶ø»á¼û²Ù×÷ϵͳ¡¢Óû§ÕÊ»§ÐÅÏ¢¡¢ÒøÐÐÍøÕ¾Æ¾Ö¤¡¢½ØÈ¡ÆÁÄ»½ØÍ¼²¢·¢Ë͵½C2ЧÀÍÆ÷ÒÔÇÔȡĿµÄµÄÐÅÏ¢¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2021/08/neurevt-trojan-takes-aim-at-mexican.html



Ñо¿ÍŶӷ¢Ã÷Õë¶ÔÈÕ±¾ÐÄÔÚ·Ö·¢CinobiµÄ¶ñÒâ¹ã¸æ»î¶¯


Ñо¿ÍŶӷ¢Ã÷Õë¶ÔÈÕ±¾ÐÄÔÚ·Ö·¢CinobiµÄ¶ñÒâ¹ã¸æ»î¶¯2.jpg


Ç÷ÊÆ¿Æ¼¼Ñо¿ÍŶÓÓÚÉÏÖÜÐû²¼ÁËÒ»ÏîÆÊÎö£¬£¬£¬£¬ £¬Õ¹ÏÖÁ˺ڿÍÍÅ»ïWater KappaÕë¶ÔÈÕ±¾µÄ¶ñÒâ¹ã¸æ»î¶¯¡£¡£¡£¹¥»÷ÕßÊ×ÏÈʹÓÃÈÕ±¾¶¯»­ÓÎÏ·¡¢½±Àø»ý·ÖÓ¦ÓúÍÊÓÆµÁ÷ЧÀÍ·Ö·¢¶ñÒâ¹ã¸æ£¬£¬£¬£¬ £¬×îÖÕ×°ÖÃÒøÐÐľÂíCinobi¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷´Ë´Î»î¶¯Ö÷ÒªÕë¶ÔʹÓÃInternet ExplorerÒÔÍâµÄä¯ÀÀÆ÷µÄÈÕ±¾Óû§£¬£¬£¬£¬ £¬²¢Ö÷ÒªÇÔÈ¡ÈÕ±¾µÄ11¼Ò½ðÈÚ»ú¹¹µÄÓû§ÃûºÍÃÜÂ룬£¬£¬£¬ £¬ÆäÖÐ3¼ÒÉæ¼°¼ÓÃÜÇ®±ÒÉúÒâ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.trendmicro.com/en_in/research/21/h/cinobi-banking-trojan-targets-users-of-cryptocurrency-exchanges-.html


ClearSky·¢Ã÷SiamesekittenÕë¶ÔÒÔÉ«ÁеÄÌØ¹¤»î¶¯


ClearSky·¢Ã÷SiamesekittenÕë¶ÔÒÔÉ«ÁеÄÌØ¹¤»î¶¯.png


ClearSkyµÄÑо¿Ö°Ô±ÔÚ8ÔÂ17ÈÕÅû¶ÁËÒÁÀÊAPT×éÖ¯SiamesekittenÕë¶ÔÒÔÉ«ÁеÄÌØ¹¤»î¶¯¡£¡£¡£ClearSkyÓÚ2021Äê5Ô³õ¼ì²âµ½¸ÃÍÅ»ïÕë¶ÔÒÔÉ«ÁеÄÒ»¼ÒIT¹«Ë¾µÄµÚÒ»´Î¹¥»÷£¬£¬£¬£¬ £¬²¢ÔÚ5ÔºÍ7ÔÂÓÖ¼ì²âµ½Á˶à´Î¹¥»÷¡£¡£¡£Ôڴ˴λÖУ¬£¬£¬£¬ £¬ºÚ¿Íαװ³ÉChipPcºÍSoftware AGµÈ×ÅÃû¹«Ë¾µÄÈËÁ¦×ÊÔ´²¿Ô±¹¤£¬£¬£¬£¬ £¬ÒÔÓÕÈ˵ÄְλÓÕʹĿµÄ½øÈë´¹ÂÚÍøÒ³ÏÂÔØÔ¶³Ì»á¼ûľÂíDanBot¡£¡£¡£ÓÉÓڴ˴ι¥»÷Ö÷ÒªÕë¶ÔITºÍͨѶ¹«Ë¾£¬£¬£¬£¬ £¬Òò´ËClearSkyÍÆ²âºÚ¿Í¿ÉÄÜÖ¼ÔÚ¶ÔËûÃǵĿͻ§Ìᳫ¹©Ó¦Á´¹¥»÷¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.clearskysec.com/siamesekitten/


Fortinet FortiWeb WAF±£´æÎ´ÐÞ¸´µÄÏÂÁî×¢Èë0day


Fortinet FortiWeb WAF±£´æÎ´ÐÞ¸´µÄÏÂÁî×¢Èë0day.jpg


Fortinet FortiWeb WebÓ¦ÓóÌÐò·À»ðǽ(WAF)±£´æÏÂÁî×¢Èë0day£¬£¬£¬£¬ £¬¹¥»÷ÕßʹÓøÃÎó²î¿ÉÒÔͨ¹ýSAMLЧÀÍÆ÷ÉèÖÃÒ³ÃæÒÔrootÓû§Éí·ÝÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£ËäÈ»¹¥»÷Õß±ØÐèͨ¹ýÁËÄ¿µÄ×°±¸ÖÎÀí½çÃæµÄÉí·ÝÑéÖ¤²Å»ªÊ¹ÓôËÎó²î£¬£¬£¬£¬ £¬µ«ÈôÊÇÓëÆäËûÎó²î£¨ÀýÈçÉí·ÝÑéÖ¤ÈÆ¹ýÎó²îCVE-2020-29015£©Á¬ÏµÊ¹Ó㬣¬£¬£¬ £¬¿ÉÒÔÍêÈ«¿ØÖÆÄ¿µÄЧÀÍÆ÷¡£¡£¡£FortinetÒѽ«¸ÃÎó²îµÄÐÞ¸´ÍýÏëÍÆ³Ùµ½8ÔÂ⣬£¬£¬£¬ £¬Ñо¿Ö°Ô±½¨Ò齨ÒéÖÎÀíԱեȡ´Ó²»ÊÜÐÅÈεÄÍøÂç»á¼ûFortiWeb×°±¸µÄÖÎÀí½çÃæÒÔ±ÜÃâ´ËÀ๥»÷¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/121221/security/fortinet-fortiweb-os-command-injection.html


AdobeÐû²¼Çå¾²¸üУ¬£¬£¬£¬ £¬ÐÞ¸´Æä¶à¿î²úÆ·ÖеÄÇå¾²Îó²î


AdobeÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´Æä¶à¿î²úÆ·ÖеÄÇå¾²Îó²î.jpg


AdobeÓÚ8ÔÂ17ÈÕÐû²¼Çå¾²¸üУ¬£¬£¬£¬ £¬ÐÞ¸´ÁËAdobe Captivate¡¢XMP Toolkit SDK¡¢Photoshop¡¢BridgeºÍMedia EncoderÖеĶà¸öÇå¾²Îó²î¡£¡£¡£ÆäÖнÏΪÑÏÖØµÄÊÇAdobe XMP Toolkit SDKÖеÄí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-36052ºÍCVE-2021-36064£©¡¢PhotoshopÖеÄí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-36065ºÍCVE-2021-36066£©£¬£¬£¬£¬ £¬ÒÔ¼°Adobe BridgeÖеÄí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-36078µÈ£©µÈÎó²î¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/08/18/adobe-releases-multiple-security-updates