Google 5ÔÂAndroid°²È«²¼¸æÖÐÓÐ4¸ö0day±»ÔÚÒ°ÀûÓã»ÃÀ¹úÁ½µ³³ǫ̈ÎåÏî·¨°¸ÒÔ¼ÓÇ¿¶ÔÍøÂç¹¥»÷µÄ·ÀÓùÄÜÁ¦

°ä²¼¹¦·ò 2021-05-21

1.Google 5ÔÂAndroid°²È«²¼¸æÖÐÓÐ4¸ö0day±»ÔÚÒ°ÀûÓÃ


1.jpg


Google Project ZeroÍŶӳÆ £¬Æä°ä²¼µÄ5ÔÂAndroid°²È«²¼¸æÖÐÓÐ4¸ö0dayÒѱ»ÔÚÒ°ÀûÓá£Õâ4¸ö·ì϶ӰÏìÁËQualcomm GPUºÍArm Mali GPUÇý¶¯·¨Ê½×é¼þ £¬±ðÀëΪ¿ªÊͺóʹÓ÷ì϶£¨CVE-2021-1905£©¡¢µØÖ·×¢Ïúʧ°ÜÇé¿ö´¦Öò»µ±£¨CVE-2021-1906£©¡¢GPUÄÚ´æ²Ù×÷²»µ±£¨CVE-2021-28663£©ºÍÌáȨ·ì϶£¨CVE-2021-28664£©¡£×êÑÐÈËÔ±½¨ÒéÓû§¾¡¿ì×°ÖÃ×îиüС£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/118089/mobile-2/android-4-zero-day-flaws.html


2.×êÑÐÈËÔ±Åû¶±¼ÌÚµÄMBUXÐÅÏ¢ÓéÀÖϵͳÖеĶà¸ö·ì϶


2.jpg


×êÑÐÈËÔ±Åû¶Á˱¼ÌÚÓû§ÂÄÀú£¨MBUX£©ÐÅÏ¢ÓéÀÖϵͳÖеÄ5¸ö·ì϶¡£ÕâЩ·ì϶±ðÀëΪCVE-2021-23906¡¢CVE-2021-23907¡¢CVE-2021-23908¡¢CVE-2021-23909ºÍCVE-2021-23910 £¬¿É±»ÓÃÀ´Äܹ»Èƹý³µÁ¾µÄ·ÀµÁ±£»¤ÉõÖÁ½ÚÔì³µÁ¾ £¬Èç´ò¿ª·ÕΧµÆ»ò´ò¿ª´ò¿ªÕÚÑôÕֵȲÙ×÷¡£×êÑÐÈËÔ±»¹·¢ÏÖÁ˶àÖÖ¹¥»÷³¡¾° £¬Ô̺¬ÀûÓÃä¯ÀÀÆ÷µÄJavaScriptÒýÇæ¡¢Wi-FiоƬ¡¢À¶ÑÀ²Ö¿â¡¢USBÖ°ÄÜ»òµÚÈý·½ÀûÓ÷¨Ê½½øÐй¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/118081/hacking/mercedes-benz-hack.html


3.ÃÀ¹úÁ½µ³³ǫ̈ÎåÏî·¨°¸ÒÔ¼ÓÇ¿¶ÔÍøÂç¹¥»÷µÄ·ÀÓùÄÜÁ¦


3.jpg


ÃÀ¹ú¶àÒéÔººÓɽ°²È«Î¯Ô±»áÓÚ±¾ÖÜһͨ¹ýÁËÎåÏî·¨°¸ £¬ÒÔ¼ÓÇ¿¶ÔÍøÂç¹¥»÷µÄ·ÀÓùÄÜÁ¦¡£ÕâЩ·¨°¸Ô̺¬£ºH.R. 2980 £¬¡¶ÍøÂ簲ȫ·ì϶²¹¾È·¨°¸¡·£»H.R. 3138 £¬¡¶Öݺʹ¦ËùÍøÂ簲ȫ¸Ä½ø·¨°¸¡· £»H.R. 3223 £¬¡¶CISAÍøÂçÑÝϰ·¨¡·£»H.R. 3243 £¬¡¶¹Ü·°²È«·¨¡·£»H.R. 3264 £¬¡¶ºÓɽ°²È«¹Ø¼üÁìÓò·¨°¸¡·¡£ÕâЩ·¨°¸ÊǺÓɽ°²È«Î¯Ô±»áÕë¶Ô×î½üµÄÍøÂç¹¥»÷¶øÌá³öµÄ £¬¾Ý±¨Â·Colonial PipelineÖ§¸¶ÁË500ÍòÃÀÔªÊê½ð £¬µ«²¢Ã»ÓÐ×èÖ¹¶«±±¸÷ÖÝȼÁϵĴó¹æÄ£Ç·È±¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-introduces-bills-to-secure-critical-infrastructure-from-cyber-attacks/


4.Win10×îÐÂÀÛ»ý¸üпɵ¼ÖÂTeamsµÅצÓÃÎÞ·¨µÇ¼


4.jpg


Windows 10 1909 KB5003169ÀÛ»ý¸üе¼ÖÂMicrosoft 365Óû§ÎÞ·¨µÇ¼Teams¡¢OutlookºÍOneDrive¡£Óû§»ã±¨ £¬ÆäÔÚ³¢ÊԵǼʱ»áÏÔʾÃýÎó´úÂë80080300 £¬²¢³öÏÖ¡°ÎÒÃÇÓöµ½ÁËÎÊÌâ¡£ÔÚ³ÁÐÂÏνӡ­¡±µÄÌáÐÑ £¬ÒªÇóÓû§³ÁÐÂÆô¶¯¸Ã·¨Ê½¡£Î¢Èí°µÊ¾ £¬Õâ´ÎÖжÏÊÂÎñÊÇÓÉÓÚ¸üÐÂÖеÄÒ»¸ö´úÂëÎÊÌâµ¼ÖµÄ £¬Ö»Ó°ÏìÁ˲¿ÃÅÓû§ £¬¿Éͨ¹ý³ÁÐÂÆô¶¯Windows 10½øÐн¨¸´¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/recent-windows-10-update-blocks-microsoft-teams-outlook-logins/


5.TeamBMSÒòAWS S3´æ´¢Í°ÅäÖÃÃýÎóй¶2Íò¶àÓû§ÐÅÏ¢


5.jpg


Website Planet·¢ÏÖ £¬FastTrack Reflex Recruitment£¨ÏÖΪTeamBMS£©ÒòAWS S3´æ´¢Í°ÅäÖÃÃýÎóй¶ÁË2Íò¶àÓû§ÐÅÏ¢¡£¸Ã¹«Ë¾ÖØÒª´Óʹ¹ÖþÖÎÀíϵÍÂäìÓòµÄÕÐÆ¸¹¤×÷ £¬ÏîÄ¿Ô̺¬Î²¼ÀûÇò³¡¡¢°ÂÁÔ쥿ËÔ˶¯³¡ºÍϣ˼ÂÞ5ºÅº½Õ¾Â¥µÈ¡£Õâ´Îй¶ÁË21000¸öÎļþ £¬Ô̺¬Óû§µÄµç×ÓÓʼþµØÖ·¡¢È«Ãû¡¢ÊÖ»úºÅÂë¡¢¼Òͥסַ¡¢Éç½»ÍøÂçURL¡¢µ®ÉúÈÕÆÚ¡¢»¤ÕÕºÅÂëºÍÉêÇëÈËÕÕÆ¬µÈ¡£×êÑÐÈËÔ±´§¶È £¬Õâ´Îй¶ÊÇÓɸù«Ë¾µÄIT·þÎñÌṩÉ̵¼ÖµÄ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/recruiters-cloud-snafu-exposes/


6.Paloalto°ä²¼2021ÄêCortex XpanseÍþв·ÖÎö»ã±¨


6.jpg


Paloalto°ä²¼ÁË2021ÄêCortex XpanseÍþв·ÖÎö»ã±¨¡£¸Ã»ã±¨´Ó2021Äê1Ôµ½3Ô £¬¶ÔÈ«Çò50¼ÒÆóÒµµÄ5000Íò¸öIPµØÖ·½øÐÐÁË¼à¿ØÉ¨Ãè £¬ÒÔÏàʶ¹¥»÷ÕßÄܶà¿ìµØ¼ø±ð³ö¿É±»ÀûÓõÄϵͳ¡£¹Ø¼ü·ì϶µÄ¹«¿ªÅû¶,»áÒý·¢¹¥»÷ÕߺÍITÖÎÀíÔ±Ö®¼äµÄ½ÏÁ¿£º¹¥»÷ÕßҪѰÕÒÏàÒ˵ÄÖ¸±ê £¬¶øITÈËÔ±Òª½øÐзçÏÕÆÀ¹ÀºÍ×°ÖñØÒªµÄ²¹¶¡¡£»ã±¨Ö¸³ö £¬¹¥»÷Õß¿ÉÄÜÔÚ0day¹«¿ªºóµÄ15·ÖÖÓÄÚ¶ÔÆä½øÐÐɨÃè £¬¶øÕë¶ÔMicrosoft ExchangeÖеķì϶ £¬¹¥»÷ÕßÐж¯µÃ¸ü¿ì £¬ÔÚ²»µ½Îå·ÖÖӵŦ·òÄÚ¼´¼ì²âµ½ÁËɨÃè¡£


Ô­ÎÄÁ´½Ó£º

https://start.paloaltonetworks.com/asm-report