AzureFunctionsÌáȨÎó²î¿ÉÌÓÒÝÖÁDockerÖ÷»ú£»NCC Group¼ì²âµ½ÓÃSonicWallÖÐ0dayµÄ¹¥»÷Ô˶¯

Ðû²¼Ê±¼ä 2021-02-02
1.Azure FunctionsÖб£´æÌáȨÎó²î £¬¿ÉÌÓÒÝÖÁDockerÖ÷»ú


1.jpg


Intezer LabµÄÑо¿Ö°Ô±Åû¶ÁËMicrosoft Azure FunctionsÖÐδÐÞ¸´µÄÌáȨÎó²î £¬¹¥»÷Õß¿ÉÄÜʹÓÃÀ´ÌÓÒÝÖÁDockerÖ÷»ú¡£Azure Functions¿ÉÒÔÓÉHTTPÇëÇó´¥·¢ £¬Óû§µÄ´úÂëÔÚAzureÍйܵÄÈÝÆ÷ÉÏÔËÐÐ £¬¿ÉÊÇ´úÂëûÓб»Çå¾²Ö§½â £¬²¢ÇÒ¿ÉÄܱ»ÀÄÓÃÀ´»á¼ûµ×²ãÇéÐΡ£Ñо¿Ö°Ô±·¢Ã÷¿ÉÒÔͨ¹ý½¨ÉèÒ»¸öHTTP´¥·¢Æ÷À´Ö´ÐÐshell £¬ÒÔÎÞÌØÈ¨µÄappÓû§Éí·ÝÔÚÈÝÆ÷²éÕÒÊôÓÚrootȨÏÞµÄÀú³Ì½Ó¿Ú¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/114061/hacking/azure-functions-escape-docker.html


2.NCC Group¼ì²âµ½Ê¹ÓÃSonicWallÖÐ0dayµÄ¹¥»÷Ô˶¯


2.png


ÍøÂçÇå¾²¹«Ë¾NCC GroupÖÜÈÕ³Æ £¬ËüÒѼì²âµ½Õë¶ÔSonicWallÍøÂç×°±¸ÖÐÁãÈÕÎó²îµÄ×Ô¶¯Ê¹ÓÃʵÑé¡£ÏÖÔÚÉв»ÇåÎú´ËÎó²îÊÇ·ñÓëSonicWallÔÚ1ÔÂ23ÈÕÅû¶µÄÎó²îÏàͬ £¬µ«NCCÒÔΪÕâÊǼ«ÓпÉÄܵÄ¡£SonicWallÔÚÆäSMA 100Ç徲ͨ¸æµÄ¸üÐÂÖÐÒÑÈ·ÈÏÁËNCC Group·¢Ã÷µÄÁãÈÕÎó²î £¬ÁгöÁËÊÜÓ°ÏìµÄ×°±¸ÐͺŲ¢ÌåÏÖ»áÔÚ2ÔÂ2ÈÕ֮ǰÐû²¼²¹¶¡³ÌÐò¡£ÓйØÎó²îµÄϸ½Ú²¢Î´¹ûÕæ £¬ÒÔ±ÜÃâÆäËû¹¥»÷Õß¶ÔÆä¾ÙÐÐÑо¿²¢·¢¶¯¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/sonicwall-zero-day-exploited-in-the-wild/


3.Cisco·´À¬»øÓʼþ·þÎñSpamCopÖÐÖ¹ £¬´ó×ÚÓʼþ±»¾Ü


3.png


Cisco·´À¬»øÓʼþ·þÎñSpamCopÔÚÉÏÖÜÈÕ±¬·¢ÁËÖÐÖ¹ £¬´ó×ÚÓʼþ±»¾Ü¡£µ±ÈÕ £¬È«Çò¹æÄ£ÄÚµÄÓʼþ¹ÜÀíÔ±¡¢×éÖ¯ºÍISPͻȻ·¢Ã÷ÆäʹÓÃÁËSpamCop·þÎñµÄÓʼþ·þÎñÆ÷¾Ü¾øÍâ·¢Óʼþ £¬²¢·ºÆð´¦Öóͷ£ÄúµÄÇëÇóʱ±¬·¢¹ýʧµÄÌáÐÑ¡£¾ÝϤ £¬´Ë´ÎÖÐÖ¹ÊÇÓÉÓÚspamcop.netÓòµ½ÆÚËùµ¼Ö £¬µ±´«ÈëÓʼþ·þÎñÆ÷µÄRBL¼ì²éÊÕµ½ÏìӦʱ¹ýʧµØ×èÖ¹µç×ÓÓʼþ £¬¾ÍËÆºõËüÀ´×ÔÒÑÖªÀ¬»øÓʼþ·¢ËÍÕßÒ»Ñù¡£ÏÖÔÚ¸ÃÎÊÌâÒѽâ¾ö £¬SpamCop·þÎñ»Ö¸´Õý³£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/spamcop-anti-spam-service-suffers-an-outage-after-its-domain-expired/


4.Ó¢¹úWoodland»ù½ð»áÉÏÔÂÔâµ½¹¥»÷ £¬ÏÖÔÚITϵͳÒÀÈ»ÀëÏß


4.png


Ó¢¹ú×î´óµÄÁֵشÈÉÆ»ú¹¹Woodland TrustÈ·ÈÏÆäÉϸöÔÂÔâµ½ÁËÍøÂç¹¥»÷ £¬ÏÖÔÚ¶à¸öITϵͳÒÀÈ»´¦ÓÚÀëÏß״̬¡£¹¥»÷±¬·¢ÔÚ2020Äê12ÔÂ14ÈÕÍíÉÏ £¬¸Ã×éÖ¯Ôâµ½ÖØ´óÇҸ߼¶±ðµÄ¹¥»÷ £¬µ¼ÖÂÐí¶à·þÎñÍÑ»ú¡£·¢Ã÷¹¥»÷ºó×éÖ¯Á¬Ã¦½ÓÄÉÐж¯²¢¾ÙÐÐÊÓ²ì £¬Éв»È·¶¨Æä50Íò¸ö³ÉÔ±µÄÊý¾ÝÊÇ·ñÒѾ­±»ºÚ¿ÍÇÔÈ¡¡£ÏÖÔÚÊÂÎñµÄÐÔ×ÓºÍÓ°Ïì¹æÄ£ÈÔÔÚÊÓ²ìÖÐ £¬Òò´ËÓÐһЩϸ½ÚÈÔδÐû²¼¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/a-month-after-a-high-level-cyberattack-charity-says-many-it-systems-are-still-offline/


5.kasperskyÐû²¼2021ÄêÒþ˽ÎÊÌâµÄÕ¹Íû±¨¸æ


5.png


kasperskyÐû²¼ÁË2021ÄêÒþ˽ÎÊÌâµÄÕ¹Íû±¨¸æ¡£±¨¸æÌåÏÖ £¬ÔÚ2021Äê £¬ÖÇÄÜÒ½ÁÆ×°±¸¹©Ó¦É̽«ÍøÂ粢ʹÓÃÔ½À´Ô½¶àÑù»¯µÄÊý¾Ý£»ÏûºÄÕßÒþ˽½«³ÉΪһÖÖ¼ÛÖµÖ÷ÕÅ £¬²¢ÇÒÔÚ´ó´ó¶¼ÇéÐÎÏÂ»áÆÆ·Ñ¿î×Ó£»¸÷¹úÕþ¸®¿´ÖØ´óÐͿƼ¼¹«Ë¾µÄ´óÊý¾Ý´æ´¢ £¬²¢ÔÚî¿Ïµ·½ÃæÔ½À´Ô½Æð¾¢£»Êý¾Ý¹«Ë¾½«Éú³¤¸ü¶àµÄ´´Òâ £¬ÉõÖÁÊǸü¾ßÇÖÈëÐÔµÄÊý¾ÝÔ´ £¬ÒÔÍÆ¶¯ÐÐΪÆÊÎö»úеµÄÉú³¤£»²î·ÖÒþ˽ºÍÍŽáѧϰÒÔ¼°±ßÑØÅÌË㽫ԽÀ´Ô½ÆÕ±éµØ±»½ÓÄÉ¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/privacy-predictions-for-2021/100311/


6.MozillaÐû²¼2020Ä껥ÁªÍø¿µ½¡µÄ»ØÊ×±¨¸æ


6.png


MozillaÐû²¼ÁË2020Ä껥ÁªÍø¿µ½¡µÄ»ØÊ×±¨¸æ¡£¸Ã±¨¸æÖ÷ÒªÎ§ÈÆÎå¸öÒªº¦ÎÊÌâ:È¥ÖÐÐÄ»¯¡¢Òþ˽ºÍÇå¾²ÐÔ¡¢¿ª·ÅÐÔ¡¢ÍøÂçÎÄ»¯ºÍÊý×ÖÈÝÄÉÕ½ÂÔ £¬¾ÙÐÐÑо¿ºÍ̽ÌÖ½â¾ö¼Æ»®¡£±¨¸æ·ÖΪËĸö²¿·Ö £¬Ã¿¸ö²¿·Ö´ÓÌØ¶¨µÄ½Ç¶È¾ÙÐÐÑо¿£º2020ÄêµÄ»¥ÁªÍø¿µ½¡¾ÙÐÐÁËÖÜÈ«ÆÊÎö£»ÈýÆªÖØµãÎÄÕÂ̽ÌÖÁËÖÖ×åÕýÒåÓëÈí¼þ¡¢ÀͶ¯Á¦ÓëÊý¾ÝÒÔ¼°É罻ýÌåµÄ͸Ã÷¶ÈºÍÎÊÔðÖÆ£»»ØÊ××ܽὲÊöÁËÀ´×ÔÈ«Çò100¶à¸ö»¥ÁªÍø¼ÓÈëÕߵĹÊÊ£»×îºóÊǹÊʱ³ºóµÄÊý×ÖºÍÇ÷ÊÆ¡£


Ô­ÎÄÁ´½Ó£º

https://foundation.mozilla.org/en/insights/internet-health-report/