ZeroXÍÅ»ïÔÚ°µÍø³öÊÛʯÓ͹«Ë¾É³Ìذ¢ÃÀ1TBµÄÊý¾Ý£»£»£»£»£»£»Òѱ£´æ16ÄêµÄÎó²îÓ°ÏìÊýÒŲ́»ÝÆÕ¡¢XeroxºÍÈýÐÇ´òÓ¡»ú

Ðû²¼Ê±¼ä 2021-07-21
1.ZeroXÍÅ»ïÔÚ°µÍø³öÊÛʯÓ͹«Ë¾É³Ìذ¢ÃÀ1TBµÄÊý¾Ý


1.jpg


±¾Ô£¬ £¬£¬£¬£¬Ò»¸öÃûΪZeroXµÄºÚ¿ÍÍÅ»ïÔÚ°µÍøÒÔ500ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛÉ³ÌØ°¢ÃÀ¹«Ë¾1TBµÄÊý¾Ý¡£¡£¡£É³Ìذ¢À­²®Ê¯Ó͹«Ë¾¼ò³ÆÉ³Ìذ¢ÃÀ£¨Saudi Aramco£©£¬ £¬£¬£¬£¬ÊÇÌìÏÂÉÏ×î´óµÄ¹«¹²Ê¯ÓͺÍ×ÔÈ»Æø¹«Ë¾Ö®Ò»£¬ £¬£¬£¬£¬ÓµÓÐÁè¼Ý66000ÃûÔ±¹¤£¬ £¬£¬£¬£¬ÄêÊÕÈë½ü2300ÒÚÃÀÔª¡£¡£¡£ZeroX³ÆÕâЩÊý¾ÝÊÇÔÚ2020Äêͨ¹ýÈëÇÖÉ³ÌØ°¢ÃÀµÄÍøÂ缰ЧÀÍÆ÷»ñµÃµÄ£¬ £¬£¬£¬£¬ÆäÖÐ×îÔçµÄ¿É×·Ëݵ½1993Äê¡£¡£¡£´Ë´Îй¶µÄÊý¾Ý°üÀ¨14254ÃûÔ±¹¤µÄÍêÕûÐÅÏ¢¡¢ÖÖÖÖϵͳµÄÏîÄ¿¹æ·¶£»£»£»£»£»£»ÄÚ²¿·ÖÎö±¨¸æ¡¢Ð­Òé¡¢Ðź¯¡¢¶¨¼Û±í£»£»£»£»£»£»Scadaµã¡¢Wi-Fi¡¢IPÉãÏñ»úºÍIoT×°±¸µÄÍøÂç½á¹¹£»£»£»£»£»£»Aramco¿Í»§Ãûµ¥¡¢·¢Æ±ºÍÌõÔ¼µÈ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/saudi-aramco-data-breach-sees-1-tb-stolen-data-for-sale/


2.ºÚ¿ÍÔÚ°µÍø¹ûÕæº¬9100ÍòÌõ¼Í¼µÄÄ«Î÷¸çÑ¡ÃñÊý¾Ý¿â


2.jpg


ºÚ¿Í×î½üÔÚ°µÍøÉϹûÕæÁË2021ÄêµÄÕû¸öÄ«Î÷¸çÑ¡ÃñÊý¾Ý¿â£¬ £¬£¬£¬£¬°üÀ¨9100ÍòÌõ¼Í¼¡£¡£¡£¹ú¼ÒÑ¡¾ÙÑо¿Ëù(INE)³ÆËûÃÇÒѾ­ÏòÕþ¸®±¨¸æ´ËÊÂÎñ£¬ £¬£¬£¬£¬²¢ÌåÏÖÆäÔÚ2020Äê5ÔÂ8ÈÕ¾ÍÏòÑ¡¾Ù·¸·¨ÌØÊâÉó²é¹Ù(FEDE)±¨¸æÁË»á¼ûºÍ²»µ±Ê¹ÓÃÓëÑ¡¾Ù¹ÒºÅ²áÏà¹ØÊý¾ÝµÄÎÊÌâ¡£¡£¡£Õâ²¢²»ÊÇINEµÚÒ»´Î±¬·¢Êý¾Ýй¶ÊÂÎñ£¬ £¬£¬£¬£¬ÔçÔÚ2016ÄêÔøÐ¹Â¶¹ý93424710ÃûÄ«Î÷¸ç¹«ÃñµÄÑ¡Ãñ¹ÒºÅÐÅÏ¢¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/how-many-leaks-have-there-been-of-mexicos-voter-database/


3.Òѱ£´æ16ÄêµÄÎó²îÓ°ÏìÊýÒŲ́»ÝÆÕ¡¢XeroxºÍÈýÐÇ´òÓ¡»ú


3.jpg


SentinelLabsÅû¶ÔÚHP¡¢SamsungºÍXerox´òÓ¡»úÇý¶¯³ÌÐòÖз¢Ã÷µÄÒ»¸öÑÏÖØµÄ»º³åÇøÒç³öÎó²î¡£¡£¡£¸ÃÎó²î×Ô2005Äê¾Í×îÏȱ£´æ£¬ £¬£¬£¬£¬×·×ÙΪCVE-2021-3438£¬ £¬£¬£¬£¬CVSSÆÀ·ÖΪ8.8£¬ £¬£¬£¬£¬Ó°ÏìÁè¼Ý380¿îµÄ»ÝÆÕºÍÈýÐÇ´òÓ¡»ú£¬ £¬£¬£¬£¬ÒÔ¼°12ÖÖXerox´òÓ¡»ú¡£¡£¡£¸ÃÎó²îλÓÚ´òÓ¡Çý¶¯³ÌÐò×°ÖóÌÐò°üSSPORT.SYSÖУ¬ £¬£¬£¬£¬ÍâµØ¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î½«È¨ÏÞÌáÉýµ½SYSTEM²¢ÔÚÄÚºËģʽÏÂÔËÐдúÂ룬 £¬£¬£¬£¬À´×°Öá¢Éó²é¡¢¸ü¸Ä¡¢¼ÓÃÜ»òɾ³ýÊý¾ÝµÈ¡£¡£¡£ÏÖÔÚ£¬ £¬£¬£¬£¬¸ÃÎó²îÒѾ­ÐÞ¸´¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hp-patches-vulnerable-printer-driver-impacting-millions-of-devices/


4.еÄMosaicLoader¿ÉʹÓÃWindows DefenderÈÆ¹ý¼ì²â


4.jpg


BitdefenderÑо¿Ö°Ô±·¢Ã÷жñÒâÈí¼þMosaicLoader¿ÉʹÓÃWindows DefenderÈÆ¹ý¼ì²â¡£¡£¡£¸Ã¶ñÒâÈí¼þͨ¹ýËÑË÷ÒýÇæÐ§¹ûαװ³ÉÆÆ½âÈí¼þ£¬ £¬£¬£¬£¬¾ßÓÐÖØ´óµÄÄÚ²¿½á¹¹£¬ £¬£¬£¬£¬Ö¼ÔÚÈÆ¹ý¶ñÒâÈí¼þÆÊÎö¡£¡£¡£ÆäÄ£ÄâÀàËÆÓÚÕýµ±Èí¼þµÄÎļþÐÅÏ¢²¢Ê¹ÓÃС¿éºÍÎÞÐòÖ´ÐÐ˳Ðò¾ÙÐдúÂë»ìÏý¡£¡£¡£ÔÚÀÖ³ÉѬȾĿµÄºó£¬ £¬£¬£¬£¬×î³õµÄ»ùÓÚDelphiµÄdropper»á´ÓÔ¶³ÌЧÀÍÆ÷»ñÈ¡ÏÂÒ»½×¶ÎµÄpayload£¬ £¬£¬£¬£¬²¢ÔÚWindows DefenderÖÐΪÏÂÔØµÄ¿ÉÖ´ÐÐÎļþÌí¼ÓÍâµØÉ¨³ýÏîÒÔÈÆ¹ýɱ¶¾Èí¼þµÄɨÃè¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/07/this-new-malware-hides-itself-among.html    


5.NSO GroupʹÓÃiMessageÖÐ0day×°ÖÃÌØ¹¤Èí¼þPegasus


5.jpg


´óÉâ¹ú¼ÊºÍForbidden StoriesÅû¶ÒÔÉ«ÁÐNSO GroupʹÓÃiMessageÖеÄÁãµã»÷0day×°ÖÃÌØ¹¤Èí¼þPegasus¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬ £¬£¬£¬£¬Ó¡¶È¼ÇÕߣ¨CODE INJRN1£©ÔËÐÐÁË×îа汾iOS 14.6µÄiPhone XRÓÚ2021Äê6ÔÂ16ÈÕÔâµ½ÈëÇÖ£¬ £¬£¬£¬£¬6ÔÂ24ÈÕ£¬ £¬£¬£¬£¬Ò»»îÔ¾ÈËÊ¿(CODE RWHRD1)µÄiPhone XÒ²Ôâµ½ÁËÈëÇÖ¡£¡£¡£Æ»¹û¹«Ë¾ÏÖÔÚÕýÔÚÊÓ²ì´ËÊ£¬ £¬£¬£¬£¬²¢ÌåÏÖÏñÉÏÊöÄÇÑùµÄ¹¥»÷ºÜÊÇÖØ´ó£¬ £¬£¬£¬£¬¿ª·¢±¾Ç®ÎªÊý°ÙÍòÃÀÔª£¬ £¬£¬£¬£¬Í¨³£ÓÐÓÃʱ¼äºÜ¶Ì£¬ £¬£¬£¬£¬²¢ÇÒ½öÓÃÓÚÕë¶ÔÌØ¶¨µÄСÎÒ˽¼Ò¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/iphones-running-latest-ios-hacked-to-deploy-nso-group-spyware/


6.Unit42Ðû²¼Ê¹ÓÃTrap FlagÈÆ¹ýɳºÐµÄ¹¥»÷µÄÆÊÎö±¨¸æ


6.jpg


Unit 42ÔÚIntel CPU¼Ä´æÆ÷Öз¢Ã÷ÁËÒ»¸öÌØÊâµÄbit¡ª¡ªÏÝÚå±ê¼Ç£¨Trap Flag£©£¬ £¬£¬£¬£¬¶ñÒâÈí¼þͨ³£»£»£»£»£»£»áʹÓøÃλÀ´ÌÓ±ÜɳÏä¼ì²â¡£¡£¡£¸Ã±¨¸æÆÊÎöÁ˶ñÒâÈí¼þÔõÑùÔÚCPU¼Ä´æÆ÷ÖÐÖ»ÓÃÒ»¸öbitµÄÇéÐÎϼì²âÐéÄâ»ú»òÎïÀí»úCPUÐÐΪµÄ²î±ð¡£¡£¡£ÏÝÚå±ê¼Ç(TF)ÊÇIntel x86 CPU¼Ü¹¹µÄEFLAGs¼Ä´æÆ÷ÖеĵÚ8¸öbit¡£¡£¡£ÆäÖÐÕë¶ÔÆÏÌÑÑÀÓû§µÄLampionʹÓÃx86»ã±àÖ¸ÁîÒÔ¼°×îÉÙµÄWindows APIŲÓþÍʵÏÖÁËËùÓÐϵͳµÄ¼ì²é£¬ £¬£¬£¬£¬µ±ËüÈ·ÈÏÔÚVMÖÐÔËÐкó¾Í»á×Ô¶¯ÖÕÖ¹¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/single-bit-trap-flag-intel-cpu/