AdobeÐû²¼²¹¶¡ÐÞ¸´¶à¿î²úÆ·Îó²î:KasperskyÐû²¼Ó¦¼±ÏìÓ¦ÊÂÎñ±¨¸æ
Ðû²¼Ê±¼ä 2021-09-17AdobeÐû²¼ÐÇÆÚ¶þ²¹¶¡£¬£¬£¬£¬ÐÞ¸´¶à¿î²úÆ·ÖеÄ59¸öÎó²î
AdobeÐû²¼ÐÇÆÚ¶þÇå¾²¸üУ¬£¬£¬£¬ÐÞ¸´ÁËAdobe Acrobat Reader¡¢XMP Toolkit SDKºÍPhotoshopµÈ²úÆ·ÖеÄ59¸öÎó²î¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄ½ÏΪÑÏÖØµÄÊÇPhotoshopÖлº³åÇøÒç³öµ¼ÖµÄí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-40709£©¡¢FramemakerÖеÄí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-39830¡¢CVE-2021-39829ºÍCVE-2021-39831£©ÒÔ¼°InDesignÖеÄí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-39820£©µÈ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/adobe-bugs-acrobat-experience-manager/169467/
HP OMEN Gaming HubÖÐÌáȨÎó²îÓ°ÏìÊý°ÙÍòÅÌËã»ú
SentinelLabsÓÚ9ÔÂ14ÈÕÅû¶ÁËHP OMEN Gaming HubÖеÄÌáȨÎó²î£¬£¬£¬£¬¿ÉÄÜÓ°ÏìÊý°ÙÍǫ̀ÅÌËã»ú¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î×·×ÙΪCVE-2021-3437£¬£¬£¬£¬CVSSÆÀ·ÖΪ7.8£¬£¬£¬£¬ÒÑÓÚ2021Äê2ÔÂ17ÈÕ±¨¸æ¸ø»ÝÆÕ£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚ7ÔÂ27ÈÕÐû²¼ÁËÇå¾²¸üС£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚ¶ÔOpenLibSys¿ª·¢µÄWinRing0.sysÖÐÎó²î´úÂëµÄÖØÓ㬣¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÆä½ûÓÃÇå¾²²úÆ·¡¢ÁýÕÖϵͳ×é¼þ¡¢ÆÆËð²Ù×÷ϵͳ»òÖ´ÐÐÆäËü¶ñÒâ²Ù×÷¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.sentinelone.com/labs/cve-2021-3437-hp-omen-gaming-hub-privilege-escalation-bug-hits-millions-of-gaming-devices/
Zloader»Ø¹é£¬£¬£¬£¬Ö÷ÒªÕë¶ÔµÂ¹úºÍ°Ä´óÀûÑǵĽðÈÚÐÐÒµ
Ñо¿Ö°Ô±·¢Ã÷ZloaderÐÂÒ»ÂֵĹ¥»÷»î¶¯£¬£¬£¬£¬Ö÷ÒªÕë¶ÔµÂ¹úºÍ°Ä´óÀûÑǵĽðÈÚÐÐÒµ¡£¡£¡£¡£¡£¡£¡£ZLoaderÓÚ2016ÄêÊ״α»·¢Ã÷£¬£¬£¬£¬ÊÇÒ»Öֵ䷶µÄÒøÐÐľÂí£¬£¬£¬£¬¿ÉÓÃÀ´ÇÔÈ¡cookie¡¢ÃÜÂëºÍÈκÎÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷½ÓÄÉÁׯü¸ß¼¶µÄÒþ²ØÊÖÒÕ£¬£¬£¬£¬ÆäµÚÒ»½×¶ÎµÄdropperÒÑ´Ó¶ñÒâÎĵµ¸ü¸ÄΪÒþ²ØµÄ¡¢ÒÑÊðÃûµÄMSI payload¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬Ëü»¹¿ÉÒÔ½ûÓÃÄ¿µÄÅÌËã»úÉϵÄMicrosoft Defender AntivirusÀ´Èƹý¼ì²â¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-zloader-attacks-disable-windows-defender-to-evade-detection/
¿Í»§Ð§À͹«Ë¾TTECÔâµ½Ragnar LockerÀÕË÷¹¥»÷
9ÔÂ14ÈÕ£¬£¬£¬£¬ÃÀ¹úµÄ¿Í»§Ð§À͹«Ë¾TTEC֪ͨԱ¹¤ÆäÔâµ½ÁË¿ÉÄÜÊÇÀ´×ÔRagnar LockerµÄÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚ9ÔÂ12ÈÕ£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚ֪ͨÖÐÌáÐÑÔ±¹¤²»Òª·¿ªWindows×îÏȲ˵¥ÖÐͻȻ·ºÆðµÄÃûΪ¡°!RA!G!N!A!R!¡±µÄÎļþ¡£¡£¡£¡£¡£¡£¡£TTECÌåÏִ˴ι¥»÷µ¼Ö´󲿷ÖÔ±¹¤¶¼ÎÞ·¨Õý³£ÊÂÇ飬£¬£¬£¬ÆäÔÚÆð¾¢»Ö¸´ÊÜÓ°Ïìϵͳ£¬£¬£¬£¬ÏÖÔÚÉÐδ·¢Ã÷¿Í»§Êý¾Ýй¶µÄÇéÐΡ£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://krebsonsecurity.com/2021/09/customer-care-giant-ttec-hit-by-ransomware/
ÐÂÎ÷À¼CERT NZÐû²¼Õë¶ÔÆóÒµµÄÀÕË÷Èí¼þ±£»£»£»£»£»£»£»¤Ö¸ÄÏ
ÐÂÎ÷À¼ÅÌËã»úÓ¦¼±ÏìӦС×é(CERT NZ)ÓÚ9ÔÂ14ÈÕÐû²¼ÁËÕë¶ÔÆóÒµµÄÀÕË÷Èí¼þ±£»£»£»£»£»£»£»¤Ö¸ÄÏ¡£¡£¡£¡£¡£¡£¡£¸ÃÖ¸ÄÏʹÓÃ2ÕÅͼ±í£¬£¬£¬£¬¸ÅÊöÁ˲î±ðµÄÀÕË÷Èí¼þ¹¥»÷µÄ;¾¶£¬£¬£¬£¬²¢ËµÃ÷ÎúÏà¹ØÇå¾²¿ØÖƲ½·¥¿ÉÒÔÔÚÄÄЩ·½ÃæÊ©Õ¹×÷ÓÃÀ´µÖÓù¹¥»÷¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬CERT NZ²»½¨Òé×éÖ¯Ö§¸¶Êê½ð£¬£¬£¬£¬ÓÉÓÚÕâ²»¿É°ü¹ÜÎļþ»á±»Í˻أ¬£¬£¬£¬²¢ÇÒ¿ÉÄÜʹÊܺ¦Õß³ÉΪ½øÒ»²½¹¥»÷µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2021/09/14/cert-nz-releases-ransomware-protection-guide-businesses
KasperskyÐû²¼2020ÄêÓ¦¼±ÏìÓ¦ÊÂÎñµÄÆÊÎö±¨¸æ
KasperskyÔÚ9ÔÂ13ÈÕÐû²¼ÁËÓйØ2020ÄêÓ¦¼±ÏìÓ¦ÊÂÎñµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£±¨¸æÆÊÎöÁËKasperskyÔÚ2020Ä꿪չµÄÊÂÎñÊÓ²ìЧÀÍ£¬£¬£¬£¬²¢´ÓÆô¶¯ÊÂÎñÏìÓ¦µÄÔµ¹ÊÔÓÉ¡¢¹¥»÷ÕßÔõÑù½øÈëÄ¿µÄÍøÂ硢ʹÓõŤ¾ßºÍÎó²îÒÔ¼°¹¥»÷Ò»Á¬Ê±¼äÕâ4¸ö·½ÃæÁÙÆä¾ÙÐÐÁËÆÊÎö¡£¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬´ó´ó¶¼Ó¦¼±ÏìÓ¦ÊÂÎñÀ´×Ô¶íÂÞ˹ºÍ¶ÀÁªÌå(27.8%)¡¢Å·ÃË(24.7%)ºÍÖж«(22.7%)µØÇø£»£»£»£»£»£»£»ÆäÖУ¬£¬£¬£¬¹¤ÒµÐÐÒµÊܵ½µÄÓ°Ïì×î´ó(22%)£¬£¬£¬£¬Æä´ÎÊÇÕþ¸®»ú¹¹(19%)¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/incident-response-analyst-report-2020/104080/