SAM·¢Ã÷MiraiʹÓÃRealtek SDKÖÐÎó²îµÄ¹¥»÷»î¶¯:ºÚ¿ÍÉù³ÆÒÑÇÔÈ¡ÒÁÀÊÀÎÓüÊý°ÙGBµÄ¼à¿ØÊý¾Ý

Ðû²¼Ê±¼ä 2021-08-26

SAM·¢Ã÷MiraiʹÓÃRealtek SDKÖÐÎó²îµÄ¹¥»÷»î¶¯


 SAM Seamless.jpg


Çå¾²¹«Ë¾SAM SeamlessÓÚ8ÔÂ19ÈÕ³ÆÆä·¢Ã÷Á˽©Ê¬ÍøÂçMiraiʹÓÃRealtek SDKÖÐÎó²îµÄ¹¥»÷»î¶¯¡£¡£¡£¸ÃÎó²îΪÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¬£¬£¬×·×ÙΪCVE-2021-20090£¬£¬£¬ÆÀ·ÖΪ9.8·Ö£¬£¬£¬RealtekÒÑÓÚ8ÔÂ13ÈÕÐû²¼¸ÃÎó²îµÄ²¹¶¡³ÌÐò¡£¡£¡£SAMÌåÏÖ£¬£¬£¬ËûÃÇÓÚ8ÔÂ18ÈÕÔÚÒ°·¢Ã÷ÁË´Ë´ÎÎó²îʹÓû£¬£¬£¬¹¥»÷Ô´ÓÚ31.210.20[.]100£¬£¬£¬µ«¹¥»÷ÕßµÄIPµØµã¿ÉÄÜ»áËæ×Åʱ¼ä¶ø¸Ä±ä¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securingsam.com/realtek-vulnerabilities-weaponized/


OpenSSLÐû²¼Çå¾²¸üУ¬£¬£¬ÐÞ¸´²úÆ·ÖеÄ2¸öÇå¾²Îó²î


OpenSSLÐû²¼Çå¾²¸üУ¬£¬£¬ÐÞ¸´²úÆ·ÖеÄ2¸öÇå¾²Îó²î.png


OpenSSLÓÚ8ÔÂ24ÈÕÐû²¼Çå¾²¸üУ¬£¬£¬ÐÞ¸´Æä²úÆ·ÖеÄ2¸öÇå¾²Îó²î¡£¡£¡£ÆäÖÐ×îΪÑÏÖØµÄÊÇ»º³åÇøÒç³öÎó²î£¬£¬£¬×·×ÙΪCVE-2021-3711£¬£¬£¬¹¥»÷ÕßʹÓÃÆä¿Éµ¼ÖÂÓ¦ÓóÌÐòÍ߽⡣¡£¡£¸ÃÎó²îÓëSM2¼ÓÃÜÊý¾ÝµÄ½âÃÜÀú³ÌÏà¹Ø£¬£¬£¬¿ÉÓÃÀ´¸ü¸Ä¶ÑÖеÄÊý¾Ý£¨¼´Æ¾Ö¤£©¡£¡£¡£´Ë´ÎÐÞ¸´µÄÁíÒ»¸öÎó²î×·×ÙΪCVE-2021-3712£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î´¥·¢¾Ü¾øÐ§ÀÍ(DoS)£¬£¬£¬»¹¿ÉÄܵ¼ÖÂÉñÃØÐÅϢй¶£¬£¬£¬ÀýÈç˽Կ»òÃô¸ÐÃ÷ÎÄ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/121426/hacking/cve-2021-3711-openssl-flaws.html


ºÚ¿ÍÉù³ÆÒÑÇÔÈ¡ÒÁÀÊÀÎÓüµÄ¼à¿ØÏµÍ³ÖÐÊý°ÙGBµÄÊý¾Ý


ºÚ¿ÍÉù³ÆÒÑÇÔÈ¡ÒÁÀÊÀÎÓüµÄ¼à¿ØÏµÍ³ÖÐÊý°ÙGBµÄÊý¾Ý.jpg


ºÚ¿ÍÍÅ»ïTapandegan(Palpitations)ÓÚÉϹûÕæÁË´ó×ÚÒÁÀÊEvinÀÎÓüÖÐݱ¶¾Çô·¸µÄÊÓÆµ¡£¡£¡£ÕâЩÊÓÆµµÄʱ¼ä´ÁΪ2020ÄêºÍ2021Ä꣬£¬£¬°üÀ¨EvinµÄ¾¯ÎÀŹ´òÇô·¸¡¢ÊÔͼ×ÔɱµÄÇô·¸»ò»èØÊ²¢±»ÍϹý×ßÀȵÄÇô·¸µÈÄÚÈÝ¡£¡£¡£¸ÃÍÅ»ï³ÆËûÃÇÖ»×ÊÖúÐû´«ÁËÊÓÆµµ«²¢Î´¼ÓÈë¹¥»÷£¬£¬£¬²¢½«´Ë´Î»î¶¯¹é¹¦ÓÚAli's JusticeÍŻ¡£¡£´ËºóÕßÔòÉù³ÆÆäÔÚ¼¸¸öÔÂǰ¾ÍÈëÇÖÁËÀÎÓüµÄ¼à¿ØÏµÍ³£¬£¬£¬²¢ÇÔÈ¡ÁËÊý°ÙGBµÄÊý¾Ý¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/hackers-leak-footage-of-iranian/



ŵ»ùÑÇ×Ó¹«Ë¾SAC Wireless³ÆÆäÔâµ½ContiÀÕË÷¹¥»÷


ContiÀÕË÷¹¥»÷.jpg


λÓÚÃÀ¹úµÄŵ»ùÑÇ×Ó¹«Ë¾SAC WirelessÔÚ6ÔÂ16ÈÕ·¢Ã÷ÆäÔâµ½ÁËContiÀÕË÷¹¥»÷£¬£¬£¬¹¥»÷ÕßÖ»ÊÇ×°ÖÃÁËpayload²¢¼ÓÃÜÁËSACÎÞÏßϵͳ¡£¡£¡£¿ÉÊÇÔÚÖ®ºóµÄȡ֤ÊÓ²ìÖУ¬£¬£¬ÓÚ8ÔÂ13ÈÕ·¢Ã÷ÆäÏÖÔ±¹¤ºÍǰԱ¹¤µÄСÎÒ˽¼ÒÐÅÏ¢Ò²Òѱ»ÇÔ¡£¡£¡£¸Ã¹«Ë¾¾Ü¾øÍ¸Â¶¸ü¶àÓйش˴ι¥»÷µÄÐÅÏ¢£¬£¬£¬µ«ContiÍÅ»ïÔÚËûÃǵÄÊý¾ÝÐ¹Â¶ÍøÕ¾ÉÏ͸¶£¬£¬£¬ÒѾ­»ñµÃÁËÁè¼Ý250 GBµÄÊý¾Ý¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/nokia-subsidiary-discloses-data-breach-after-conti-ransomware-attack/


FBIÐû²¼OnePercent Group¹¥»÷»î¶¯µÄTTP»ººÍ½â²½·¥


FBIÐû²¼OnePercent Group.jpg


FBIÐû²¼ÁËÓйØOnePercent GroupµÄ¹¥»÷»î¶¯µÄTTP»ººÍ½â²½·¥£¬£¬£¬²¢³Æ¸ÃÍÅ»ïÖÁÉÙ×Ô2020Äê11ÔÂÒÔÀ´Ò»Ö±ÔÚÕë¶ÔÃÀ¹úµÄ×éÖ¯¾ÙÐÐÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¸Ã»ú¹¹³Æ¹¥»÷ÕßÊ×ÏÈʹÓô¹ÂÚ¹¥»÷£¬£¬£¬ÔÚÄ¿µÄϵͳÉÏ×°ÖÃÒøÐÐľÂíIcedID²¢ÏÂÔØCobalt Strike£¬£¬£¬È»ºó¾ÙÐмÓÃܻ¡£¡£¡£FBIûÓÐÌṩ¹¥»÷»ò¼ÓÃÜÆ÷µÄÏêϸÐÅÏ¢£¬£¬£¬µ«³ÆÆäÓëREvilÓйء£¡£¡£Ñо¿Ö°Ô±Íƶϣ¬£¬£¬Æä¿ÉÄÜÊÇREvilµÄcartelͬÃËÖеÄÏàÖúͬ°é¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fbi-onepercent-group-ransomware-targeted-us-orgs-since-nov-2020/


Trend MicroÐû²¼2021 H1 LinuxÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ


Trend MicroÐû²¼2021 H1 LinuxÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ.jpg


Trend MicroÐû²¼ÁË2021 H1 LinuxÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬ÔÚ2021ÄêÉϰëÄêÑо¿Ö°Ô±×ܼÆÍ³¼ÆÁ˽ü1500Íò¸öÕë¶ÔLinuxµÄÇå¾²ÊÂÎñ£¬£¬£¬²¢·¢Ã÷ÍÚ¿óÈí¼þºÍÀÕË÷Èí¼þÕ¼ËùÓжñÒâÈí¼þµÄ36.11%£¬£¬£¬Web shellÕ¼19.92%¡£¡£¡£ÔÚÒ°·¢Ã÷µÄ¹¥»÷»î¶¯ÖÐʹÓÃ×î¶àµÄÎó²î°üÀ¨Apache Struts 2ÖеÄRCEÎó²î£¨CVE-2017-5638£©¡¢Apache Struts 2 REST plugin XStreamÖеÄRCEÎó²î£¨CVE-2017-9805£©£¬£¬£¬ÒÔ¼°Drupal CoreÖеÄRCEÎó²î£¨CVE-2018-7600£©µÈ¡£¡£¡£    


Ô­ÎÄÁ´½Ó£º

https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/linux-threat-report-2021-1h-linux-threats-in-the-cloud-and-security-recommendations