ZeroXÍÅ»ïÔÚ°µÍø³öÊÛʯÓ͹«Ë¾É³Ìذ¢ÃÀ1TBµÄÊý¾Ý£»£»£»£»£»Òѱ£´æ16ÄêµÄÎó²îÓ°ÏìÊýÒŲ́»ÝÆÕ¡¢XeroxºÍÈýÐÇ´òÓ¡»ú

Ðû²¼Ê±¼ä 2021-07-21
1.ZeroXÍÅ»ïÔÚ°µÍø³öÊÛʯÓ͹«Ë¾É³Ìذ¢ÃÀ1TBµÄÊý¾Ý


1.jpg


±¾Ô£¬£¬ £¬Ò»¸öÃûΪZeroXµÄºÚ¿ÍÍÅ»ïÔÚ°µÍøÒÔ500ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛÉ³ÌØ°¢ÃÀ¹«Ë¾1TBµÄÊý¾Ý¡£¡£¡£¡£¡£É³Ìذ¢À­²®Ê¯Ó͹«Ë¾¼ò³ÆÉ³Ìذ¢ÃÀ£¨Saudi Aramco£©£¬£¬ £¬ÊÇÌìÏÂÉÏ×î´óµÄ¹«¹²Ê¯ÓͺÍ×ÔÈ»Æø¹«Ë¾Ö®Ò»£¬£¬ £¬ÓµÓÐÁè¼Ý66000ÃûÔ±¹¤£¬£¬ £¬ÄêÊÕÈë½ü2300ÒÚÃÀÔª¡£¡£¡£¡£¡£ZeroX³ÆÕâЩÊý¾ÝÊÇÔÚ2020Äêͨ¹ýÈëÇÖÉ³ÌØ°¢ÃÀµÄÍøÂ缰ЧÀÍÆ÷»ñµÃµÄ£¬£¬ £¬ÆäÖÐ×îÔçµÄ¿É×·Ëݵ½1993Äê¡£¡£¡£¡£¡£´Ë´Îй¶µÄÊý¾Ý°üÀ¨14254ÃûÔ±¹¤µÄÍêÕûÐÅÏ¢¡¢ÖÖÖÖϵͳµÄÏîÄ¿¹æ·¶£»£»£»£»£»ÄÚ²¿·ÖÎö±¨¸æ¡¢Ð­Òé¡¢Ðź¯¡¢¶¨¼Û±í£»£»£»£»£»Scadaµã¡¢Wi-Fi¡¢IPÉãÏñ»úºÍIoT×°±¸µÄÍøÂç½á¹¹£»£»£»£»£»Aramco¿Í»§Ãûµ¥¡¢·¢Æ±ºÍÌõÔ¼µÈ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/saudi-aramco-data-breach-sees-1-tb-stolen-data-for-sale/


2.ºÚ¿ÍÔÚ°µÍø¹ûÕæº¬9100ÍòÌõ¼Í¼µÄÄ«Î÷¸çÑ¡ÃñÊý¾Ý¿â


2.jpg


ºÚ¿Í×î½üÔÚ°µÍøÉϹûÕæÁË2021ÄêµÄÕû¸öÄ«Î÷¸çÑ¡ÃñÊý¾Ý¿â£¬£¬ £¬°üÀ¨9100ÍòÌõ¼Í¼¡£¡£¡£¡£¡£¹ú¼ÒÑ¡¾ÙÑо¿Ëù(INE)³ÆËûÃÇÒѾ­ÏòÕþ¸®±¨¸æ´ËÊÂÎñ£¬£¬ £¬²¢ÌåÏÖÆäÔÚ2020Äê5ÔÂ8ÈÕ¾ÍÏòÑ¡¾Ù·¸·¨ÌØÊâÉó²é¹Ù(FEDE)±¨¸æÁË»á¼ûºÍ²»µ±Ê¹ÓÃÓëÑ¡¾Ù¹ÒºÅ²áÏà¹ØÊý¾ÝµÄÎÊÌâ¡£¡£¡£¡£¡£Õâ²¢²»ÊÇINEµÚÒ»´Î±¬·¢Êý¾Ýй¶ÊÂÎñ£¬£¬ £¬ÔçÔÚ2016ÄêÔøÐ¹Â¶¹ý93424710ÃûÄ«Î÷¸ç¹«ÃñµÄÑ¡Ãñ¹ÒºÅÐÅÏ¢¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/how-many-leaks-have-there-been-of-mexicos-voter-database/


3.Òѱ£´æ16ÄêµÄÎó²îÓ°ÏìÊýÒŲ́»ÝÆÕ¡¢XeroxºÍÈýÐÇ´òÓ¡»ú


3.jpg


SentinelLabsÅû¶ÔÚHP¡¢SamsungºÍXerox´òÓ¡»úÇý¶¯³ÌÐòÖз¢Ã÷µÄÒ»¸öÑÏÖØµÄ»º³åÇøÒç³öÎó²î¡£¡£¡£¡£¡£¸ÃÎó²î×Ô2005Äê¾Í×îÏȱ£´æ£¬£¬ £¬×·×ÙΪCVE-2021-3438£¬£¬ £¬CVSSÆÀ·ÖΪ8.8£¬£¬ £¬Ó°ÏìÁè¼Ý380¿îµÄ»ÝÆÕºÍÈýÐÇ´òÓ¡»ú£¬£¬ £¬ÒÔ¼°12ÖÖXerox´òÓ¡»ú¡£¡£¡£¡£¡£¸ÃÎó²îλÓÚ´òÓ¡Çý¶¯³ÌÐò×°ÖóÌÐò°üSSPORT.SYSÖУ¬£¬ £¬ÍâµØ¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î½«È¨ÏÞÌáÉýµ½SYSTEM²¢ÔÚÄÚºËģʽÏÂÔËÐдúÂ룬£¬ £¬À´×°Öá¢Éó²é¡¢¸ü¸Ä¡¢¼ÓÃÜ»òɾ³ýÊý¾ÝµÈ¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬ £¬¸ÃÎó²îÒѾ­ÐÞ¸´¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hp-patches-vulnerable-printer-driver-impacting-millions-of-devices/


4.еÄMosaicLoader¿ÉʹÓÃWindows DefenderÈÆ¹ý¼ì²â


4.jpg


BitdefenderÑо¿Ö°Ô±·¢Ã÷жñÒâÈí¼þMosaicLoader¿ÉʹÓÃWindows DefenderÈÆ¹ý¼ì²â¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þͨ¹ýËÑË÷ÒýÇæÐ§¹ûαװ³ÉÆÆ½âÈí¼þ£¬£¬ £¬¾ßÓÐÖØ´óµÄÄÚ²¿½á¹¹£¬£¬ £¬Ö¼ÔÚÈÆ¹ý¶ñÒâÈí¼þÆÊÎö¡£¡£¡£¡£¡£ÆäÄ£ÄâÀàËÆÓÚÕýµ±Èí¼þµÄÎļþÐÅÏ¢²¢Ê¹ÓÃС¿éºÍÎÞÐòÖ´ÐÐ˳Ðò¾ÙÐдúÂë»ìÏý¡£¡£¡£¡£¡£ÔÚÀÖ³ÉѬȾĿµÄºó£¬£¬ £¬×î³õµÄ»ùÓÚDelphiµÄdropper»á´ÓÔ¶³ÌЧÀÍÆ÷»ñÈ¡ÏÂÒ»½×¶ÎµÄpayload£¬£¬ £¬²¢ÔÚWindows DefenderÖÐΪÏÂÔØµÄ¿ÉÖ´ÐÐÎļþÌí¼ÓÍâµØÉ¨³ýÏîÒÔÈÆ¹ýɱ¶¾Èí¼þµÄɨÃè¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/07/this-new-malware-hides-itself-among.html    


5.NSO GroupʹÓÃiMessageÖÐ0day×°ÖÃÌØ¹¤Èí¼þPegasus


5.jpg


´óÉâ¹ú¼ÊºÍForbidden StoriesÅû¶ÒÔÉ«ÁÐNSO GroupʹÓÃiMessageÖеÄÁãµã»÷0day×°ÖÃÌØ¹¤Èí¼þPegasus¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬ £¬Ó¡¶È¼ÇÕߣ¨CODE INJRN1£©ÔËÐÐÁË×îа汾iOS 14.6µÄiPhone XRÓÚ2021Äê6ÔÂ16ÈÕÔâµ½ÈëÇÖ£¬£¬ £¬6ÔÂ24ÈÕ£¬£¬ £¬Ò»»îÔ¾ÈËÊ¿(CODE RWHRD1)µÄiPhone XÒ²Ôâµ½ÁËÈëÇÖ¡£¡£¡£¡£¡£Æ»¹û¹«Ë¾ÏÖÔÚÕýÔÚÊÓ²ì´ËÊ£¬£¬ £¬²¢ÌåÏÖÏñÉÏÊöÄÇÑùµÄ¹¥»÷ºÜÊÇÖØ´ó£¬£¬ £¬¿ª·¢±¾Ç®ÎªÊý°ÙÍòÃÀÔª£¬£¬ £¬Í¨³£ÓÐÓÃʱ¼äºÜ¶Ì£¬£¬ £¬²¢ÇÒ½öÓÃÓÚÕë¶ÔÌØ¶¨µÄСÎÒ˽¼Ò¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/iphones-running-latest-ios-hacked-to-deploy-nso-group-spyware/


6.Unit42Ðû²¼Ê¹ÓÃTrap FlagÈÆ¹ýɳºÐµÄ¹¥»÷µÄÆÊÎö±¨¸æ


6.jpg


Unit 42ÔÚIntel CPU¼Ä´æÆ÷Öз¢Ã÷ÁËÒ»¸öÌØÊâµÄbit¡ª¡ªÏÝÚå±ê¼Ç£¨Trap Flag£©£¬£¬ £¬¶ñÒâÈí¼þͨ³£»£»£»£»£»áʹÓøÃλÀ´ÌÓ±ÜɳÏä¼ì²â¡£¡£¡£¡£¡£¸Ã±¨¸æÆÊÎöÁ˶ñÒâÈí¼þÔõÑùÔÚCPU¼Ä´æÆ÷ÖÐÖ»ÓÃÒ»¸öbitµÄÇéÐÎϼì²âÐéÄâ»ú»òÎïÀí»úCPUÐÐΪµÄ²î±ð¡£¡£¡£¡£¡£ÏÝÚå±ê¼Ç(TF)ÊÇIntel x86 CPU¼Ü¹¹µÄEFLAGs¼Ä´æÆ÷ÖеĵÚ8¸öbit¡£¡£¡£¡£¡£ÆäÖÐÕë¶ÔÆÏÌÑÑÀÓû§µÄLampionʹÓÃx86»ã±àÖ¸ÁîÒÔ¼°×îÉÙµÄWindows APIŲÓþÍʵÏÖÁËËùÓÐϵͳµÄ¼ì²é£¬£¬ £¬µ±ËüÈ·ÈÏÔÚVMÖÐÔËÐкó¾Í»á×Ô¶¯ÖÕÖ¹¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/single-bit-trap-flag-intel-cpu/