Razer SynapseÖеÄÍâµØÌáȨ0dayÓ°ÏìÁè¼Ý1ÒÚÓû§£ºÎ¢ÈíPower AppsÍøÕ¾ÒòÉèÖùýʧй¶3800ÍòÌõ¼Í¼

Ðû²¼Ê±¼ä 2021-08-24

Razer SynapseÖеÄÍâµØÌáȨ0dayÓ°ÏìÁè¼Ý1ÒÚÓû§


Razer SynapseÖеÄÍâµØÌáȨ0dayÓ°ÏìÁè¼Ý1ÒÚÓû§.jpg


Ñо¿Ö°Ô±jonhatÓÚ2021Äê8ÔÂ21ÈÕÔÚTwitterÉÏÅû¶ÁËRazer SynapseÖеÄÍâµØÌáȨ0dayµÄϸ½Ú¡£¡£¡£¡£¡£¡£RazerÊÇÒ»¼ÒÅÌËã»úÍâÉèÖÆÔìÉÌ£¬£¬£¬£¬£¬Éù³ÆÆäRazer SynapseÒѱ»È«ÇòÁè¼Ý1ÒÚÓû§Ê¹Óᣡ£¡£¡£¡£¡£ÕâÊÇÒ»¸öÍâµØÌáȨ£¨LPE£©Îó²î£¬£¬£¬£¬£¬½«Razer×°±¸²åÈëWindows 10ʱ£¬£¬£¬£¬£¬ÏµÍ³»á×Ô¶¯ÏÂÔØ²¢×°ÖÃÇý¶¯³ÌÐòºÍRazer Synapse£¬£¬£¬£¬£¬ÓÉÓÚRazerInstaller.exeÊÇͨ¹ýSYSTEMȨÏÞµÄWindowsÀú³ÌÆô¶¯µÄ£¬£¬£¬£¬£¬Òò´ËÆäÒ²»ñµÃÁËSYSTEMȨÏÞ¡£¡£¡£¡£¡£¡£Ö®ºóÔÚÑ¡Ôñ×°ÖÃÎļþ¼Ðʱ£¬£¬£¬£¬£¬°´ÏÂShift²¢ÓÒ¼üµ¥»÷¶Ô»°¿ò£¬£¬£¬£¬£¬¾Í¿ÉÒÔ·­¿ªSYSTEMȨÏÞµÄPowerShell´°¿Ú¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/razer-bug-lets-you-become-a-windows-10-admin-by-plugging-in-a-mouse/


΢ÈíPower AppsÍøÕ¾ÒòÉèÖùýʧй¶3800ÍòÌõ¼Í¼


΢ÈíPower AppsÍøÕ¾ÒòÉèÖùýʧй¶3800ÍòÌõ¼Í¼.jpg


UpGuard ResearchÓÚ8ÔÂ23ÈÕ±¾ÖÜÒ»³ÆÎ¢ÈíµÄPower AppsÃÅ»§ÍøÕ¾ÒòÉèÖùýʧй¶47¸ö×éÖ¯µÄ3800ÍòÌõ¼Í¼¡£¡£¡£¡£¡£¡£Power AppsÊÇһϵÁÐÓ¦Óá¢Ð§ÀÍ¡¢ÅþÁ¬Æ÷ºÍÊý¾Ýƽ̨£¬£¬£¬£¬£¬¿ÉÌṩ¿ìËÙµÄÓ¦Óÿª·¢ÇéÐΡ£¡£¡£¡£¡£¡£UpGuard³Æ£¬£¬£¬£¬£¬Êý¾Ýй¶ÓëPower Appsƽ̨ÔõÑùʹÓÿª·ÅÊý¾ÝЭÒé(OData)¼°ÆäAPIsÓйØ¡£¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñÉæ¼°ÁËÓ¡µÚ°²ÄÉÖÝ¡¢ÂíÀïÀ¼ÖݺÍŦԼÊеÈÕþ¸®µÄ×éÖ¯,ÒÔ¼°ÃÀ¹úº½¿Õ¹«Ë¾¡¢JB HuntºÍ΢ÈíµÈ¹«Ë¾¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/microsoft-38-million-sensitive-records-power-app/168885/


¶à¼ÒÒ½ÔºµÄÒ½ÁÆÏµÍ³MemorialÔâµ½HiveµÄÀÕË÷¹¥»÷


¶à¼ÒÒ½ÔºµÄÒ½ÁÆÏµÍ³MemorialÔâµ½HiveµÄÀÕË÷¹¥»÷.jpg


Memorial Health SystemÓÚ2021Äê8ÔÂ15ÈÕÔâµ½ÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¸Ãϵͳ°üÀ¨Èý¼ÒÒ½Ôº£¨Marietta MemorialÒ½Ôº¡¢Selby GeneralÒ½ÔººÍSistersville GeneralÒ½Ôº£©¡¢ÃÅÕïЧÀÍÕ¾µãºÍÕïËù×é³É¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷µ¼ÖÂÁÙ´²ºÍ²ÆÎñµÄÔËÓªÖÐÖ¹£¬£¬£¬£¬£¬²¢ÇÒ½ôÆÈÊÖÊõºÍ·ÅÉä¿Æ¼ì²é±»ÆÈ×÷·Ï¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬BleepingComputer³Æ¹¥»÷Õß¿ÉÄÜΪHiveÍŻ£¬£¬£¬£¬²¢ÒÑÇÔÈ¡200000¸ö»¼ÕßµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/121378/cyber-crime/memorial-health-system-ransomware.html


Cisco·¢Ã÷Õë¶ÔÀ­¶¡ÃÀÖÞ·Ö·¢njRATºÍAsyncRATµÄ»î¶¯


Cisco·¢Ã÷Õë¶ÔÀ­¶¡ÃÀÖÞ·Ö·¢njRATºÍAsyncRATµÄ»î¶¯.jpg


Cisco TalosÓÚ8ÔÂ19ÈÕ½ÒÏþÑо¿Åû¶ÆäÊӲ쵽µÄÒ»¸öеĶñÒâÈí¼þ»î¶¯¡£¡£¡£¡£¡£¡£´Ë´Î»î¶¯Ö÷ÒªÕë¶ÔÀ­¶¡ÃÀÖÞµÄÂÃÓκÍÂùݹ«Ë¾·Ö·¢njRATºÍAsyncRAT£¬£¬£¬£¬£¬ÆäÖÐʹÓõÄÊÖÒÕÓëAggahÍÅ»ïµÄÊÖÒÕÓÐһЩÏàËÆÖ®´¦¡£¡£¡£¡£¡£¡£¹¥»÷Õß×Ô³Æalosh£¬£¬£¬£¬£¬ÖÁÉÙ´Ó2018Äê¾Í×îÏÈ»îÔ¾ÁË£¬£¬£¬£¬£¬²¢ÇÒÕվɼÓÃÜÆ÷3losh crypter ratµÄ¿ª·¢Õß¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÍƲ⹥»÷ÕßÀ´×Ô°ÍÎ÷£¬£¬£¬£¬£¬ÓÉÓÚÆäÖ÷ÒªµÄÓòÖ®Ò»(updatewin32[.]xyz) ×¢²áÓÚ°ÍÎ÷£¬£¬£¬£¬£¬²¢Æ«ÐÒʹÓÃÆÏÌÑÑÀÓï¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2021/08/rat-campaign-targets-latin-america.html


Area 1 SecurityÐû²¼2021Äêµç×ÓÓʼþÍþÐ²Ì¬ÊÆµÄ±¨¸æ


Area 1 SecurityÐû²¼2021Äêµç×ÓÓʼþÍþÐ²Ì¬ÊÆµÄ±¨¸æ.jpg


Area 1 SecurityÐû²¼ÁË2021Äêµç×ÓÓʼþÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¸Ã±¨¸æÆÊÎöÁË¿ç¶à¸ö×éÖ¯ºÍÐÐÒµµÄÁè¼Ý3100Íò¸öÍþв£¬£¬£¬£¬£¬·¢Ã÷½ü9%µÄ¹¥»÷ʹÓÃÁËÉí·ÝÓÕÆ­Õ½ÂÔ£»£»£»£» £»£» £»±»Ã°³ä×î¶àµÄÆ·ÅÆ°üÀ¨ÌìÏÂÎÀÉú×éÖ¯(WHO)¡¢¹È¸èºÍ΢Èí£»£»£»£» £»£» £»BEC¹¥»÷µÄÕ¼±ÈºÜµÍ(1.3%£©£¬£¬£¬£¬£¬¿ÉÊÇÔì³ÉµÄ¾­¼ÃËðʧ×î´ó£¬£¬£¬£¬£¬Æ½¾ùËðʧΪ150ÍòÃÀÔª£»£»£»£» £»£» £»Áè¼Ý92%µÄÓû§±¨¸æµÄ´¹ÂÚÓʼþÊôÓÚÎ󱨵ÄÁ¼ÐÔÓʼþ£¬£¬£¬£¬£¬µ¼ÖÂITÍŶÓÐèÒª´¦Öóͷ£´ó×ڵĵÄÎ󱨡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.area1security.com/2021-email-threat-report/


KELAÐû²¼°µÍøÊÛÂôRDPºÍVPNµÄ»á¼ûȨÏÞµÄÇ÷ÊÆ±¨¸æ


KELAÐû²¼°µÍøÊÛÂôRDPºÍVPNµÄ»á¼ûȨÏÞµÄÇ÷ÊÆ±¨¸æ.jpg


KELAÐû²¼ÁËÓйذµÍøÊÛÂôRDPºÍVPNµÄ»á¼ûȨÏÞµÄÇ÷ÊÆÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¸Ã±¨¸æ¶ÔInitial Access Brokers£¨IAB£©´Ó2020Äê7ÔÂ1ÈÕµ½2021Äê6ÔÂ30ÈյĻ¾ÙÐÐÆÊÎö£¬£¬£¬£¬£¬²¢×ܽáÁË5¸öÖ÷ÒªÇ÷ÊÆ¡£¡£¡£¡£¡£¡£ÆäÖаüÀ¨£¬£¬£¬£¬£¬»á¼ûȨÏ޵ľù¼ÛΪ5400ÃÀÔª£¬£¬£¬£¬£¬ÖÐÐļÛΪ1000ÃÀÔª£»£»£»£» £»£» £»»á¼û¶àÑù»¯ÔöÌí£¬£¬£¬£¬£¬×î³£¼ûµÄÊÇÊÇ»ùÓÚRDPºÍVPNµÄ»á¼û£»£»£»£» £»£» £»ÀֳɵÄIABÇ÷ÓÚÇå¾²£»£»£»£» £»£» £»ÀÕË÷ÍÅ»ïÉú³¤³öְҵƷµÂ£¬£¬£¬£¬£¬ÔÊÐí²»»áÕë¶ÔijЩ²¿·Ö£»£»£»£» £»£» £»Í¨¹ý¶àÖÖ·½·¨½«»á¼ûȨÏÞÇ®±Ò»¯¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://ke-la.com/all-access-pass-five-trends-with-initial-access-brokers/