VMwareÇå¾²¸üУ¬£¬ÐÞ¸´vCenterÖÐÑÏÖØµÄRCEÎó²î£»£»£»£»£»£»ANSSIÅû¶BluetoothCoreºÍMeshÐÒéÖжà¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-05-261.VMwareÐû²¼Çå¾²¸üУ¬£¬ÐÞ¸´vCenterÖÐÑÏÖØµÄRCEÎó²î

VMwareÐû²¼Çå¾²¸üУ¬£¬ÐÞ¸´vCenterÖÐÑÏÖØµÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©Îó²î¡£¡£¡£¡£¸ÃÎó²î±»×·×ÙΪCVE-2021-21985£¬£¬CVSSv3ÆÀ·ÖΪ9.8£¬£¬Ó°ÏìÁËvCenter Server 6.5¡¢6.7ºÍ7.0¡£¡£¡£¡£Îó²îÊÇÓÉÓÚVirtual SANÔËÐÐ״̬¼ì²é²å¼þÖÐȱÉÙÊäÈëÑéÖ¤µ¼Öµģ¬£¬¾ßÓÐ443¶Ë¿Ú»á¼ûȨµÄ¹¥»÷Õß¿ÉÒÔʹÓÃÆäÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£VMware³Æ£¬£¬ËùÓÐvCenter Server£¬£¬ÎÞÂÛÆäÊÇ·ñʹÓÃvSAN£¬£¬¶¼Ä¬ÈÏÆôÓÃÁËVirtual SANÔËÐÐ״̬¼ì²é²å¼þ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/vmware-warns-of-critical-bug-affecting-all-vcenter-server-installs/
2.ANSSIÅû¶Bluetooth CoreºÍMeshÐÒéÖжà¸öÇå¾²Îó²î

·¨¹úÇ鱨»ú¹¹ANSSIµÄÑо¿Ö°Ô±·¢Ã÷ÁËBluetooth CoreºÍMesh ProfileÐÒéÖб£´æ¶à¸öÎó²î¡£¡£¡£¡£ÕâÁ½¸öÐÒé½ç˵ÁËÀ¶ÑÀ×°±¸Ï໥ͨѶËùÐèµÄÐèÇ󣬣¬ÒÔ¼°À¶ÑÀ×°±¸Ê¹ÓõÍÄܺÄÎÞÏßÊÖÒÕʵÏÖ»¥²Ù×÷µÄÍø×´ÍøÂç½â¾ö¼Æ»®ËùÐèµÄÐèÇ󡣡£¡£¡£Îó²î»®·ÖΪCVE-2020-26559¡¢CVE-2020-26556¡¢CVE-2020-26557ºÍCVE-2020-26560µÈ£¬£¬¹¥»÷ÕßʹÓÃÕâЩÎó²î¿ÉÔÚÅä¶ÔÀú³ÌÖÐð³äÕýµ±×°±¸£¬£¬²¢ÌᳫÖÐÐÄÈË£¨MitM£©¹¥»÷¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/118219/hacking/bluetooth-core-mesh-specs-flaws.html
3.ÈÕ±¾»é½éÓ¦ÓÃOmiaiÔâµ½¹¥»÷£¬£¬171Íò»áÔ±µÄÐÅϢй¶

ÈÕ±¾×î´óµÄ»é½éÓ¦ÓÃOmiaiÔâµ½¹¥»÷£¬£¬1711756¸ö»áÔ±µÄÐÅϢй¶¡£¡£¡£¡£Õâ¿îÓ¦ÓÃÓµÓÐÁè¼Ý680Íò¸öÕÊ»§£¬£¬Ã¿ÔÂÏòÄÐÊ¿ÊÕÈ¡37ÃÀÔªµÄÓöȡ£¡£¡£¡£OmiaiÌåÏÖ£¬£¬Ð¹Â¶µÄÐÅϢΪ2018Äê1ÔÂÖÁ2021Äê4ÔÂÖ®¼ä£¬£¬°üÀ¨ÐÕÃû³öÉúÈÕÆÚ¡¢×¢²áºÅ¡¢¼ÝÕÕ¡¢°ü¹Ü¿¨ºÍ»¤Õյȣ¬£¬²¢¼á³ÆÃ»ÓÐÈκÎÐÅÓÿ¨Êý¾Ýй¶¡£¡£¡£¡£Hackread.com֤ʵ£¬£¬ÏÖÔÚһЩºÚ¿ÍÂÛ̳ÉϵÄÍþвÕßÒѾÔÚѰÕÒ±»µÁµÄOmiaiÊý¾Ý¿â¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/japanese-dating-app-omiai-hack-users-at-risk/
4.ClearSky³ÆÒÑÇÔÈ¡ÊýÒÚÃÀÔªµÄCryptoCoreÓ볯ÏÊÓйØ

ÍøÂçÇå¾²¹«Ë¾ClearSky³ÆÒÑÇÔÈ¡ÊýÒÚÃÀÔªµÄCryptoCoreÓ볯ÏÊÓйء£¡£¡£¡£CryptoCore×Ô2018Äê×îÏÈ»îÔ¾£¬£¬¹¥»÷ÁËÃÀ¹ú¡¢ÒÔÉ«ÁС¢Å·ÖÞºÍÈÕ±¾µÈ¹úµÄ¼ÓÃÜÇ®±ÒÉúÒâËù£¬£¬Ôì³ÉµÄËðʧԤ¼ÆÁè¼Ý2ÒÚÃÀÔª¡£¡£¡£¡£×î³õ£¬£¬ClearSkyÒÔΪ¸ÃÍÅ»ïÓëÎÚ¿ËÀ¼¡¢¶íÂÞ˹ºÍÂÞÂíÄáÑǵȶ«Å·¹ú¼ÒÓйء£¡£¡£¡£½üÆÚ·¢Ã÷CryptoCoreÓëF-SecureµÄ»î¶¯¸ß¶ÈÒ»Ö£¬£¬ºóÕßÓ볯ÏʵÄLazarus×éÖ¯Óйء£¡£¡£¡£Ñо¿Ö°Ô±»¹Ö¸³ö£¬£¬ºÚ¿ÍµÄ»î¶¯Ò²ÔÚÀ©´ó£¬£¬×î½ü×îÏȽ«É«ÁÐ×÷ΪĿµÄ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/north-korean-hackers-behind-cryptocore-multi-million-dollar-heists/
5.FBIǰÇ鱨ÆÊÎöʦ±»Ö¸¿ØÔÚÒÑÍù13ÄêÀïÇÔÈ¡ÉñÃØÎļþ

FBIǰÇ鱨ÆÊÎöʦKendra Kingsbury±»Ö¸¿ØÔÚÒÑÍù13ÄêÀïÇÔÈ¡ÉñÃØÎļþ¡£¡£¡£¡£ÃÀ¹ú˾·¨²¿£¨DoJ£©ÌåÏÖ£¬£¬´Ó2004Äê6ÔÂÖÁ2017Äê12Ô£¬£¬Kingsbury½«Óйعú¼ÒÇå¾²¡¢ÉñÃØºÍÉñÃØµÄÎļþÉúÑÄÔÚ¼ÒÀï¡£¡£¡£¡£ÆðËßÊéÖ¸³ö£¬£¬±»¸æÎÞȨɾ³ýºÍ±£´æÕâЩÃô¸ÐµÄÕþ¸®ÖÊÁÏ¡£¡£¡£¡£KingsburyÔÚFBIÊÂÇé12ÄêÒÔÉÏ£¬£¬Êܹý´¦Öóͷ£Ãô¸ÐÖÊÁϺͱ£ÃÜÐÐΪµÄÅàѵ£¬£¬ÈÎְʱ´úÔÚ·´¿Ö¡¢··¶¾ºÍ°ïÅÉ·¸·¨µÄС¶ÓÊÂÇé¡£¡£¡£¡£KingsburyÓÚ2017Ä걻ְͣ£¬£¬±»¿ØÁ½Ïî¾ÓÐı£´æ¹ú·ÀÐÅÏ¢µÄ×ïÃû£¬£¬ÏÖÒѱ»²¶¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/fbi-intelligence-officer-indicted-for-theft-of-cybersecurity-threat-counterterrorism-documents/
6.ÖÆÒ©¹«Ë¾SiegfriedÔâµ½¹¥»÷£¬£¬¶à¸ö·Ö¹«Ë¾ÔÝÍ£Éú²ú

ÖÆÒ©¹«Ë¾Siegfried³ÆÆäÔâµ½¹¥»÷£¬£¬¶à¸ö·Ö¹«Ë¾ÔÝÍ£Éú²ú¡£¡£¡£¡£SiegfriedÊÇÒ»¼ÒÈ«ÇòÐÔµÄÒ½Ò©¹«Ë¾£¬£¬ÔÚÈðÊ¿¡¢µÂ¹ú¡¢Î÷°àÑÀ¡¢·¨¹ú¡¢Âí¶úËû¡¢ÃÀ¹úºÍÖйúÉèÓзֹ«Ë¾¡£¡£¡£¡£¸Ã¹«Ë¾ÓÚ5ÔÂ21ÈÕÐÇÆÚÎåÍíÉϼì²âµ½¹¥»÷£¬£¬Ö®ºóÁ¬Ã¦½ÓÄɲ½·¥£¬£¬ÔÝÍ£Á˸÷¸ö·Ö¹«Ë¾µÄÉú²ú²¢ÖÐÖ¹ÁËÍøÂçÅþÁ¬¡£¡£¡£¡£¸Ã¹«Ë¾³Æ£¬£¬³ýÁËÔÚÎ÷°àÑÀµÄÁ½¸öËùÔÚÓÉÓÚÔÚ¸ôÀëµÄÍøÂçÉÏÔËÐÐÍâ¶øÎ´ÊÜÓ°ÏìÍ⣬£¬ÆäËûµÄ¹«Ë¾¾ùÊܵ½Á˲î±ðˮƽµÄÓ°Ïì¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/ch-siegfried-affected-by-attack-on-its-it-systems/


¾©¹«Íø°²±¸11010802024551ºÅ