TIMÍŶÓÅû¶CA Technologies²úÆ·ÖеĶà¸ö0day £»Î¢Èí³ÆÖÜËĵÄÖÐÖ¹Ô´ÓÚ´úÂëȱÏݵ¼ÖµÄAzure DNS¹ýÔØ

Ðû²¼Ê±¼ä 2021-04-06

1.TIMÍŶÓÅû¶CA Technologies²úÆ·ÖеĶà¸ö0day


1.jpg


CA TechnologiesÊÇÃÀ¹úÒ»¼ÒרעÓÚB2BÈí¼þµÄ¿ç¹ú¹«Ë¾ £¬ÏúÊÛ½ü200ÖÖ²úÆ· £¬Éæ¼°ÂþÑÜʽÅÌËã¡¢ÔÆÅÌËã¡¢DevOpsºÍÅÌËã»úÇå¾²Èí¼þÒÔ¼°Òƶ¯×°±¸ ¡£TIMµÄRed Team ResearchÍŶÓÅû¶ÁËCA eHealth Performance Manager²úÆ·ÖеÄ5¸öÐÂÎó²î ¡£»®·ÖΪÌáȨÎó²î£¨CVE-2021-28246ºÍCVE-2021-28249£©¡¢¿çÕ¾µã¾ç±¾Îó²î£¨CVE-2021-28247£©¡¢Í¨¹ýSUID/GUIDÎļþµÄÌáȨÎó²î£¨CVE-2021-28250£©ºÍÉí·ÝÑéÖ¤Îó²î£¨CVE-2021-28248£© ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116268/security/ca-ehealth-performance-manager-flaws.html


2.΢Èí³ÆÖÜËĵÄÖÐÖ¹Ô´ÓÚ´úÂëȱÏݵ¼ÖµÄAzure DNS¹ýÔØ


2.jpg


΢Èí͸¶ £¬ÉÏÖÜËĵÄÈ«Çò¹æÄ£ÄڵķþÎñÖÐÖ¹ÊÇÓÉ´úÂëȱÏݵ¼ÖµÄAzure DNS¹ýÔØÒýÆðµÄ ¡£ÖÐÖ¹±¬·¢ÔÚÉÏÖÜËÄÏÂÖç5:21×óÓÒ £¬MicrosoftÓû§·¢Ã÷ÆäÎÞ·¨»á¼ûXbox Live¡¢Office¡¢TeamsºÍSkypeµÈ·þÎñ £¬¸ÃÎÊÌâÓÚ6:30±»½â¾ö ¡£½üÆÚ £¬MicrosoftÐû²¼ÁËÓйطþÎñÖÐÖ¹µÄ»ù´¡Ôµ¹ÊÔ­ÓÉÆÊÎö£¨RCA£© £¬³ÆÕë¶ÔAzureÉÏÍйܵÄijЩÓòµÄDNSÅÌÎÊÒì³£¼¤Ôöµ¼Ö·þÎñÆ÷¹ýÔØ £¬Î¢Èí²¢Î´Ú¹Êͼ¤ÔöµÄÔµ¹ÊÔ­ÓÉ £¬¾ÝÍÆ²â¿ÉÄÜÊÇÓÉÓÚÕë¶ÔijЩÓòµÄDDoS¹¥»÷ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-outage-caused-by-overloaded-azure-dns-servers/


3.ÃÀ¹ú½ðÈÚ»ú¹¹RobinhoodµÄ¿Í»§Ôâµ½´¹ÂÚ¹¥»÷


3.jpg


Robinhood MarketsÔÚÉÏÖÜËÄÐû²¼ÏòÆä¿Í»§·¢ËÍÓʼþ³Æ £¬Æä²¿·Ö¿Í»§¿ÉÄÜÒѾ­Ôâµ½´¹ÂÚ¹¥»÷ ¡£RobinhoodÊÇÒ»¼ÒÃÀ¹ú½ðÈÚ·þÎñ»ú¹¹ £¬ÆäÊÖ»úÓ¦ÓÿÉÌṩ¹ÉƱºÍ»ù½ðµÄÃâÓ¶½ðÉúÒâ £¬×èÖ¹2020ÄêÒÑÓµÓÐ1300Íò¿Í»§ ¡£´Ë´Î¹¥»÷Ô˶¯Ê¹ÓÃÁËÁ½ÖÖ¹¥»÷ǰÑÔÓÕÆ­Êܺ¦Õß £¬ÆäÒ»ÊÇʹÓðüÀ¨ÁËαÔìRobinhoodÍøÕ¾Á´½ÓµÄ´¹ÂÚÓʼþ £¬ÓÕʹ»á¼ûÕßÊäÈëµÇ¼ƾ֤ £»ÁíÒ»ÖÖÊÇʹÓÃÁ˱¨Ë°¼¾ £¬ÒªÇóÄ¿µÄÏÂÔØ°üÀ¨Á˶ñÒâÈí¼þµÄαÔì˰ÊÕÎļþ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/04/attackers-targeted-robinhood-with.html


4.KasperskyÅû¶Õë¶ÔÔ½Ä϶à¸ö×éÖ¯µÄÍøÂçÌØ¹¤Ô˶¯


4.jpg


KasperskyÅû¶ÁËAPT×éÖ¯CycldekÕë¶ÔÔ½ÄÏÕþ¸®ºÍ¾üÊÂ×éÖ¯µÄÍøÂçÌØ¹¤Ô˶¯ ¡£¸ÃÔ˶¯Ê¹ÓÃÁËÃûΪFoundCoreµÄ¶ñÒâÈí¼þ £¬¿É¾ÙÐÐÎļþϵͳʹÓá¢Àú³ÌʹÓá¢ÆÁÄ»½ØÍ¼²¶»ñºÍí§ÒâÏÂÁîÖ´ÐÐ ¡£±ðµÄ £¬Kaspersky³Æ¸Ã×éÖ¯ÔÚÖØ´óÐÔ·½ÃæÈ¡µÃÁËÖØ´óǰ½ø £¬ÀýÈç £¬ÆäpayloadµÄ±êÍ·£¨´úÂëµÄÄ¿µÄºÍÔ´£©±»ÍêÈ«°þÀë £¬Ê£ÏµÄÉÙÊý²¿·ÖµÄÖµÊDz»Á¬¹áµÄ £¬Õâ´ó´óÔöÌíÁËÑо¿Ö°Ô±¶ÔÆä¾ÙÐÐÆÊÎöµÄÄѶÈ ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/spy-operations-vietnam-rat/165243/


5.΢ÈíÐû²¼2021Äê3ÔÂSecurity SignalsµÄÆÊÎö±¨¸æ


5.jpg


΢ÈíÐû²¼ÁË2021Äê3ÔÂSecurity SignalsµÄÆÊÎö±¨¸æ £¬ÊÓ²ìÁËÀ´×ÔÖйú¡¢µÂ¹ú¡¢ÈÕ±¾¡¢Ó¢¹úºÍÃÀ¹úµÄ1000λÆóÒµÇå¾²¾öÒéÕß ¡£±¨¸æ·¢Ã÷ £¬ÒÑÍùÁ½ÄêÖÐÓÐ80£¥µÄÆóÒµÔâµ½ÁËÖÁÉÙÒ»´Î¹Ì¼þ¹¥»÷ £¬µ«Ö»ÓÐ29£¥µÄ×éÖ¯·ÖÅÉÁËÔ¤ËãÀ´± £»¤¹Ì¼þ ¡£NVDÖ¤×ÅʵÒÑÍùËÄÄêÖÐ £¬Õë¶Ô¹Ì¼þµÄ¹¥»÷ÔöÌíÁËÎå±¶ÒÔÉÏ ¡£21£¥µÄ¾öÒéÕßÈÏ¿ÉÎÞ·¨¼à¿Ø¹Ì¼þÊý¾Ý £¬82£¥×é֯ûÓÐ×ÊÔ´À´µÖÓù¹Ì¼þ¹¥»÷ ¡£81£¥µÄµÂ¹ú¹«Ë¾¡¢91£¥µÄÃÀ¹ú¡¢Ó¢¹úºÍÈÕ±¾¹«Ë¾ÒÔ¼°95£¥µÄÖйú¹«Ë¾Ô¸ÒâÔÚÕâ¸ö·½Ãæ¾ÙÐÐͶ×Ê ¡£


Ô­ÎÄÁ´½Ó£º

https://www.microsoft.com/en-us/secured-corepc


6.RavelinÐû²¼Óйصç×ÓÉÌÎñڲƭÔ˶¯µÄÆÊÎö±¨¸æ


6.jpg


Ravelin¶ÔÈ«Çò1000¶à¼ÒÉ̼ҾÙÐÐÁËÊÓ²ì £¬Ðû²¼ÁËÓйصç×ÓÉÌÎñڲƭÔ˶¯µÄÆÊÎö±¨¸æ ¡£±¨¸æÏÔʾ £¬¿ìÒª40£¥µÄ¿ìÏûÁãÊÛÉ̽«ÔÚÏßÖ§¸¶Ú²Æ­ÊÓΪ×î´óµÄڲƭΣº¦ £¬45%µÄ¹«Ë¾ËùÂÄÀúµÄÕË»§½ÓÊÜ(ATO)¹¥»÷ÓÐËùÔöÌí ¡£±¨¸æÕ¹Íû £¬µç×ÓÉÌÎñÐÐÒµÖеÄڲƭÎÊÌâ¿ÉÄÜ»áÓúÑÝÓúÁÒ £¬ÓÈÆäÊÇËæ×ÅÐí¶à¹Å°åµÄ¸ß½ÖÆ·ÅÆ£¨ÈçTopshopºÍDebenhams£©±»ÊÕ¹º²¢Íê³ÉÓªÒµËùÓÐÏòÏßÉÏתÐ͵Äʱ¼ä ¡£


Ô­ÎÄÁ´½Ó£º

https://pages.ravelin.com/retail-fraud-payments-report