TIMÍŶÓÅû¶CA Technologies²úÆ·ÖеĶà¸ö0day£»Î¢Èí³ÆÖÜËĵÄÖжÏÔ´ÓÚ´úÂëȱµãµ¼ÖµÄAzure DNS¹ýÔØ

°ä²¼¹¦·ò 2021-04-06

1.TIMÍŶÓÅû¶CA Technologies²úÆ·ÖеĶà¸ö0day


1.jpg


CA TechnologiesÊÇÃÀ¹úÒ»¼ÒרһÓÚB2BÈí¼þµÄ¿ç¹ú¹«Ë¾ £¬ÏúÊÛ½ü200ÖÖ²úÆ· £¬Éæ¼°É¢²¼Ê½ÍÆËã¡¢ÔÆÍÆËã¡¢DevOpsºÍÍÆËã»ú°²È«Èí¼þÒÔ¼°Òƶ¯É豸  ¡£TIMµÄRed Team ResearchÍŶÓÅû¶ÁËCA eHealth Performance Manager²úÆ·ÖеÄ5¸öзì϶  ¡£±ðÀëΪÌáȨ·ì϶£¨CVE-2021-28246ºÍCVE-2021-28249£©¡¢¿çÕ¾µã¾ç±¾·ì϶£¨CVE-2021-28247£©¡¢Í¨¹ýSUID/GUIDÎļþµÄÌáȨ·ì϶£¨CVE-2021-28250£©ºÍÉí·ÝÑéÖ¤·ì϶£¨CVE-2021-28248£©  ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116268/security/ca-ehealth-performance-manager-flaws.html


2.΢Èí³ÆÖÜËĵÄÖжÏÔ´ÓÚ´úÂëȱµãµ¼ÖµÄAzure DNS¹ýÔØ


2.jpg


΢Èíй© £¬ÉÏÖÜËĵÄÈ«ÇòÁìÓòÄڵķþÎñÖжÏÊÇÓÉ´úÂëȱµãµ¼ÖµÄAzure DNS¹ýÔØÒýÆðµÄ  ¡£ÖжϲúÉúÔÚÉÏÖÜËÄÏÂÎç5:21×óÓÒ £¬MicrosoftÓû§·¢ÏÔìäÎÞ·¨½Ó¼ûXbox Live¡¢Office¡¢TeamsºÍSkypeµÈ·þÎñ £¬¸ÃÎÊÌâÓÚ6:30±»½â¾ö  ¡£½üÆÚ £¬Microsoft°ä²¼ÁËÓйطþÎñÖжϵĵ××ÓÔ­Òò·ÖÎö£¨RCA£© £¬³ÆÕë¶ÔAzureÉÏÍйܵÄijЩÓòµÄDNS²éÎÊÒì³£¼¤Ôöµ¼Ö·þÎñÆ÷¹ýÔØ £¬Î¢Èí²¢Î´Ú¹Êͼ¤ÔöµÄÔ­Òò £¬¾Ý´§Ä¦¿ÉÄÜÊÇÓÉÓÚÕë¶ÔijЩÓòµÄDDoS¹¥»÷  ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-outage-caused-by-overloaded-azure-dns-servers/


3.ÃÀ¹ú½ðÈÚ»ú¹¹RobinhoodµÄ¿Í»§Ôâµ½´¹µö¹¥»÷


3.jpg


Robinhood MarketsÔÚÉÏÖÜËİ䲼ÏòÆä¿Í»§·¢ËÍÓʼþ³Æ £¬Æä²¿Ãſͻ§¿ÉÄÜÒѾ­Ôâµ½´¹µö¹¥»÷  ¡£RobinhoodÊÇÒ»¼ÒÃÀ¹ú½ðÈÚ·þÎñ»ú¹¹ £¬ÆäÊÖ»úÀûÓÿÉÌṩ¹ÉƱºÍ»ù½ðµÄÃâÓ¶½ðÂòÂô £¬½ØÖÁ2020ÄêÒÑÕ¼ÓÐ1300Íò¿Í»§  ¡£Õâ´Î¹¥»÷»î¶¯Ê¹ÓÃÁËÁ½ÖÖ¹¥»÷ý½éÓÕÆ­Êܺ¦Õß £¬ÆäÒ»ÊÇÀûÓÃÔ̺¬ÁËαÔìRobinhoodÍøÕ¾Á´½ÓµÄ´¹µöÓʼþ £¬ÓÕʹ½Ó¼ûÕßÊäÈëµÇ¼ʹ´¦£»ÁíÒ»ÖÖÊÇÀûÓÃÁ˱¨Ë°¼¾ £¬ÒªÇóÖ¸±êÏÂÔØÔ̺¬Á˶ñÒâÈí¼þµÄαÔì˰ÊÕÎļþ  ¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/04/attackers-targeted-robinhood-with.html


4.KasperskyÅû¶Õë¶ÔÔ½Ä϶à¸ö×éÖ¯µÄÍøÂç¼äµý»î¶¯


4.jpg


KasperskyÅû¶ÁËAPT×éÖ¯CycldekÕë¶ÔÔ½Äϵ±¾ÖºÍ¾üÊÂ×éÖ¯µÄÍøÂç¼äµý»î¶¯  ¡£¸Ã»î¶¯Ê¹ÓÃÁËÃûΪFoundCoreµÄ¶ñÒâÈí¼þ £¬¿É½øÐÐÎļþϵͳ°Ñ³Ö¡¢¹ý³Ì°Ñ³Ö¡¢ÆÁÄ»½ØÍ¼²¶»ñºÍËÁÒâºÅÁîÖ´ÐÐ  ¡£´Ë±í £¬Kaspersky³Æ¸Ã×éÖ¯ÔÚ¸´ÔÓÐÔ·½Ãæ»ñµÃÁ˳ÁÃͽøÈ¡ £¬ÀýÈç £¬ÆäpayloadµÄ±êÍ·£¨´úÂëµÄÖ¸±êºÍÔ´£©±»ÆëÈ«°þÀë £¬Ê£ÏµÄÉÙÊý²¿ÃŵÄÖµÊDz»Á¬¹áµÄ £¬Õâ´ó´óÔö³¤ÁË×êÑÐÈËÔ±¶ÔÆä½øÐзÖÎöµÄÄÑ¶È  ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/spy-operations-vietnam-rat/165243/


5.΢Èí°ä²¼2021Äê3ÔÂSecurity SignalsµÄ·ÖÎö»ã±¨


5.jpg


΢Èí°ä²¼ÁË2021Äê3ÔÂSecurity SignalsµÄ·ÖÎö»ã±¨ £¬µ÷²éÁËÀ´×ÔÖйú¡¢µÂ¹ú¡¢ÈÕ±¾¡¢Ó¢¹úºÍÃÀ¹úµÄ1000λÆóÒµ°²È«¾ö²ßÕß  ¡£»ã±¨·¢ÏÖ £¬´ÓǰÁ½ÄêÖÐÓÐ80£¥µÄÆóÒµÔâµ½ÁËÖÁÉÙÒ»´Î¹Ì¼þ¹¥»÷ £¬µ«Ö»ÓÐ29£¥µÄ×éÖ¯·ÖÅäÁËÔ¤ËãÀ´±£»¤¹Ì¼þ  ¡£NVDÖ¤ÇÐʵ´ÓǰËÄÄêÖÐ £¬Õë¶Ô¹Ì¼þµÄ¹¥»÷Ôö³¤ÁËÎå±¶ÒÔÉÏ  ¡£21£¥µÄ¾ö²ßÕßÈÏ¿ÉÎÞ·¨¼à¿Ø¹Ì¼þÊý¾Ý £¬82£¥×é֯ûÓÐ×ÊÔ´À´Õмܹ̼þ¹¥»÷  ¡£81£¥µÄµÂ¹ú¹«Ë¾¡¢91£¥µÄÃÀ¹ú¡¢Ó¢¹úºÍÈÕ±¾¹«Ë¾ÒÔ¼°95£¥µÄÖйú¹«Ë¾Ô¸ÒâÔÚÕâ¸ö·½Ãæ½øÐÐͶ×Ê  ¡£


Ô­ÎÄÁ´½Ó£º

https://www.microsoft.com/en-us/secured-corepc


6.Ravelin°ä²¼Óйصç×ÓÉÌÎñڲƭ»î¶¯µÄ·ÖÎö»ã±¨


6.jpg


Ravelin¶ÔÈ«Çò1000¶à¼ÒÉ̼ҽøÐÐÁ˵÷²é £¬°ä²¼ÁËÓйصç×ÓÉÌÎñڲƭ»î¶¯µÄ·ÖÎö»ã±¨  ¡£»ã±¨ÏÔʾ £¬½«½ü40£¥µÄ¿ìÏûÁãÊÛÉ̽«ÔÚÏßÖ§¸¶Ú²Æ­ÊÓΪ×î´óµÄڲƭ·çÏÕ £¬45%µÄ¹«Ë¾Ëù¾­ÀúµÄÕË»§ÊÕÊÜ(ATO)¹¥»÷ÓÐËùÔö³¤  ¡£»ã±¨Ô¤²â £¬µç×ÓÉÌÎñÐÐÒµÖеÄڲƭÎÊÌâ¿ÉÄÜ»áÓúÑÝÓúÁÒ £¬ÓÈÆäÊÇËæ×źܶഫͳµÄ¸ß½Ôì·ÅÆ£¨ÈçTopshopºÍDebenhams£©±»ÊÕ¹º²¢ÊµÏÖÒµÎñÈ«ÊýÏòÏßÉÏתÐ͵Äʱ³½  ¡£


Ô­ÎÄÁ´½Ó£º

https://pages.ravelin.com/retail-fraud-payments-report