SkypeÔÚÈ«Çò¹æÄ£ÄÚЧÀÍÖÐÖ¹£¬£¬Ôµ¹ÊÔÓÉÉв»Ã÷È·£»£»CISA³ÆºÚ¿Í¿ÉÈÆ¹ýMFAÉí·ÝÑéÖ¤»á¼ûÔÆÐ§ÀÍÕÊ»§
Ðû²¼Ê±¼ä 2021-01-151.SkypeÔÚÈ«Çò¹æÄ£ÄÚЧÀÍÖÐÖ¹£¬£¬Ôµ¹ÊÔÓÉÉв»Ã÷È·

1ÔÂ13ÈÕÉÏÎ磬£¬SkypeÔÚÈ«Çò¹æÄ£ÄÚЧÀÍÖÐÖ¹£¬£¬ÏÖÔÚ¸ÃÎÊÌâÒѱ»½â¾ö¡£¡£¡£¡£Æ¾Ö¤ÔÚÏßÐÂÎÅÆ½Ì¨DownDetectorͳ¼Æ£¬£¬ÖÐÖ¹Ö÷Òª¼¯ÖÐÔÚÃÀ¹ú¡¢Å·ÖÞ¡¢ÑÇÖÞºÍÌìÏÂÆäËûµØÇø¡£¡£¡£¡£Óû§ÔÚ»á¼ûSkypeÍøÕ¾Ê±£¬£¬»áÏÔʾÎÒÃÇÎÞ·¨Íê³ÉÄúµÄÇëÇóµÄÌáÐÑ¡£¡£¡£¡£MicrosoftÔÚSkype״̬ҳÉÏÌåÏÖ·¢Ã÷Á˸ÃÎÊÌ⣬£¬ÆäÓ°ÏìÁËSkypeµÇ¼¡¢ºô½Ð¡¢ÐÂÎÅ¡¢ËÑË÷¡¢Òƶ¯¹²Ïí¡¢Ö§¸¶ÏµÍ³¡¢SMSºÍÆäËûЧÀÍ¡£¡£¡£¡£ÎÊÌâÏÖÒѻָ´£¬£¬Skype¿ÉÔÙ´ÎÁª»ú¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/skype-is-down-worldwide-microsoft-working-on-issues/
2.CERTFAÅû¶APT35Óã²æÊ½´¹ÂÚ¹¥»÷»î¶¯µÄÏêÇé

CERTFAÅû¶ÁËÒÁÀʵÄAPT×éÖ¯Charming Kitten (ÓÖÃûAPT35£©Óã²æÊ½´¹ÂÚ¹¥»÷»î¶¯µÄÏêÇé¡£¡£¡£¡£´Ë´Î¹¥»÷»î¶¯Ö÷ÒªÕë¶ÔλÓÚ²¨Ë¹Í塢ŷÖÞºÍÃÀ¹úÖÜΧ¹ú¼ÒµÄÖÇÄÒÍųÉÔ±¡¢ÕþÖÎÑо¿ÖÐÐÄ¡¢´óѧ½ÌÊÚ¡¢¼ÇÕߺÍÇéÐλ¼Ò¡£¡£¡£¡£¸Ã»î¶¯Í¬Ê±Ê¹ÓÃÁ˵ç×ÓÓʼþºÍSMS£¬£¬SMSÐÅÏ¢±»Î±×°³ÉGoogleÇå¾²¾¯±¨£¬£¬¶ø´¹ÂÚÓʼþÔòÒÔ½ÚÈÕΪÖ÷Ìâ¡£¡£¡£¡£±ðµÄ£¬£¬ºÚ¿ÍÀֳɵؽ«¶ñÒâÁ´½ÓÒþ²ØÔÚÕýµ±Google URLºó£¬£¬Ê¹µÃÓû§¸üÄѱç±ðÆäÕæÎ±ÐÔ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/iranian-cyberspies-behind-major-christmas-sms-spear-phishing-campaign/
3.Check Point·¢Ã÷¿É½ÓÊÜ×°±¸²¢ÇÔÈ¡Êý¾ÝµÄ°²×¿Ä¾ÂíRogue

Check Point·¢Ã÷Á˿ɽÓÊÜ×°±¸²¢ÇÔÈ¡Êý¾ÝµÄÐÂÐͰ²×¿Ä¾ÂíRogue¡£¡£¡£¡£Rogue RATÀÖ³ÉÈëÇÖÄ¿µÄ×°±¸ºó»áÒþ²ØÆäͼ±ê£¬£¬²¢Öظ´ÒªÇóÓû§ÊÚÓèËùÓбØÐèµÄȨÏÞ¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ»¹»á×¢²áΪװ±¸ÖÎÀíÔ±£¬£¬µ±Êܺ¦Õß·¢Ã÷²¢ÊÔͼµõÏúÖÎÀíԱȨÏÞ£¬£¬»¹»áÏÔʾ¡°ÄúÈ·¶¨Òª²Á³ýËùÓÐÊý¾ÝÂ𣿣¿¡±µÄÌáÐÑÀ´ÏÅ»£Óû§¡£¡£¡£¡£±ðµÄ£¬£¬RogueʹÓÃÁËGoogleµÄFirebase£¬£¬Í¨¹ýÔÆÐÂÎÅת´ïÎüÊÕÀ´×ÔC£¦CµÄÏÂÁ£¬Í¨¹ýʵʱÊý¾Ý¿âÒÔ´Ó×°±¸ÉÏ´«Êý¾Ý£¬£¬Í¨¹ýCloud FirestoreÉÏ´«Îļþ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/113369/malware/rogue-android-rat-darkweb.html
4.CISA³ÆºÚ¿Í¿ÉÈÆ¹ýMFAÉí·ÝÑéÖ¤»á¼ûÔÆÐ§ÀÍÕÊ»§

ÃÀ¹úCISA³ÆºÚ¿Í¿ÉÈÆ¹ý¶àÒòËØÉí·ÝÑéÖ¤£¨MFA£©»á¼ûÔÆÐ§ÀÍÕÊ»§£¬£¬²¢ÌåÏÖÆä·¢Ã÷Á˼¸ÆðÕë¶Ô²î±ð×éÖ¯µÄÔÆÐ§À͵Ĺ¥»÷ÊÂÎñ¡£¡£¡£¡£CISAÒÔΪ£¬£¬¹¥»÷ÕßʹÓñ»µÁµÄ»á»°cookieÀ´Ð®ÖÆÒÑͨ¹ýÉí·ÝÑéÖ¤µÄ»á»°£¬£¬¾Í¿ÉÈÆ¹ýMFAµÇ¼ÔÚÏßЧÀÍ»òWebÓ¦ÓóÌÐò¡£¡£¡£¡£±ðµÄ£¬£¬¹¥»÷Õß»¹»áͨ¹ýÇÔȡԱ¹¤Æ¾Ö¤À´»ñµÃ»á¼ûȨ£¬£¬»òͨ¹ýÐÞ¸ÄÓÊÏ乿ÔòÒÔÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£Îª´Ë£¬£¬CISAÌṩÁËÊÖÒÕϸ½ÚÏ¢Õù¾ö·½·¨£¬£¬×ÊÖú×éÖ¯Ó¦¶Ô´ËÀ๥»÷¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/cisa-hackers-bypassed-mfa-to-access-cloud-service-accounts/
5.ImpervaÐû²¼Õë¶ÔÒ½ÁÆÐÐÒµµÄ¹¥»÷»î¶¯µÄÆÊÎö±¨¸æ

ImpervaÐû²¼ÁËÕë¶ÔÒ½ÁÆÐÐÒµµÄ¹¥»÷»î¶¯µÄÆÊÎö±¨¸æ¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬Õë¶ÔÒ½ÁÆÐÐÒµµÄWebÓ¦Óù¥»÷»î¶¯µÄÊýÄ¿ÔöÌíÁË51£¥¡£¡£¡£¡£È«ÇòÒ½ÁÆÐÐҵƽ¾ùÿÔÂÔâÊÜ1.87Òڴι¥»÷£¬£¬Ã¿¸ö×é֯ÿÔÂÆ½¾ùÔâÊÜ498´Î¹¥»÷£¬£¬±ÈÈ¥ÄêͬÆÚÔöÌíÁË10£¥¡£¡£¡£¡£ºÚ¿ÍʹÓÃÁ˶àÖÖǰÑÔ£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹ú¡¢°ÍÎ÷¡¢Ó¢¹úºÍ¼ÓÄôóµÈ¡£¡£¡£¡£±ðµÄ£¬£¬ÔÚÈ¥Äê12Ô£¬£¬XSS¹¥»÷ÔöÌíÁË43£¥£¬£¬SQL×¢ÈëÔöÌíÁË44£¥£¬£¬ÐÒé¹¥»÷ÔöÌíÁË76£¥£¬£¬Ô¶³Ì´úÂëÖ´ÐÐ/Ô¶³ÌÎļþ°üÀ¨¹¥»÷ÔöÌíÁË68£¥¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.imperva.com/blog/web-application-attacks-on-healthcare-spike-51-as-covid-19-vaccines-are-introduced/
6.CiscoÐû²¼Çå¾²¸üУ¬£¬ÐÞ¸´¶à¿î²úÆ·ÖеÄ67¸öÎó²î

CiscoÐû²¼Çå¾²¸üУ¬£¬ÐÞ¸´Á˶à¿î²úÆ·ÖеÄ67¸öÎó²î¡£¡£¡£¡£ÆäÖÐ×îÑÏÖØµÄÎó²îΪCisco Connected Mobile Experiences£¨CMX£©ÖеÄCVE-2021-1144£¬£¬CVSSÆÀ·ÖΪ8.8£¬£¬¿É±»Ô¶³Ì¹¥»÷ÕßÓÃÀ´¸ü¸ÄÄ¿µÄϵͳÉÏí§ÒâÕÊ»§µÄÃÜÂë¡£¡£¡£¡£»£ÉÐÓÐCisco AnyConnectÇå¾²ÒÆ¶¯¿Í»§¶ËÖеÄDLL×¢ÈëÎó²î£¨CVE-2021-1237£©£¬£¬CVSSÆÀ·ÖΪ7.8¡£¡£¡£¡£´Ë´Î¸üл¹ÐÞ¸´ÁËСÐÍÆóҵ·ÓÉÆ÷RV110W¡¢RV130¡¢RV130WºÍRV215WÖÎÀí½Ó¿ÚÖеÄһϵÁпɵ¼ÖÂÔ¶³ÌÏÂÁîÖ´Ðк;ܾøÐ§À͹¥»÷µÄÎó²î¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/113395/security/cisco-high-severity-flaw-cmx.html


¾©¹«Íø°²±¸11010802024551ºÅ