ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ2ÖÜ

Ðû²¼Ê±¼ä 2021-01-11

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2021Äê01ÔÂ04ÈÕÖÁ01ÔÂ10ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´68¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇDell Wyse ThinOSĬÈÏÅäÖÃÎļþ²Ù×÷©¶´£»Panasonic FPWIN Pro»º³åÇøÒç³ö©¶´£»Qualcomm Video NAL½âÎöÔ½½ç䩶´£»Google Android¼Ü¹¹CVE-2021-0313¾Ü¾ø·þÎñ©¶´£»Delta Electronics Industrial Automation DOPSoft CVE-2020-27277»º³åÇøÒç³ö©¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÄÉʲά¶û±¬Õ¨µ¼ÖÂÃÀ¹úÊý°ÙÓ¢ÀïͨÐÅ·þÎñÖжÏ£»Cyble·¢ÏÖºÚ¿ÍÔÚ°µÍø³öÊÛÁ½ÒÚ¶àÖйú¹«ÃñµÄÐÅÏ¢£»ÁÄÌìȺ×éSlack·þÎñÖжÏ £¬²¨¼°È«ÇòÓû§£»ESTsecurityÅû¶ThalliumÕë¶Ô½ðÈÚÐÐÒµµÄ¹©Ó¦Á´¹¥»÷£»GreyNoiseÔÚÒ°·¢ÏÖÀûÓÃZyxelÖЩ¶´µÄ¹¥»÷»î¶¯¡£


ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾ÖÜÄþ¾²ÍþвΪÖС£


ÖØÒªÄþ¾²Â©¶´Áбí


1.Dell Wyse ThinOSĬÈÏÅäÖÃÎļþ²Ù×÷©¶´


Dell Wyse ThinOSĬÈÏÅäÖôæÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉдÎļþµ½ÏµÍ³»òÕß²Ù×÷Ä¿±êÅäÖá£

https://www.dell.com/support/kbdoc/zh-hk/000180768/dsa-2020-281


2.Panasonic FPWIN Pro»º³åÇøÒç³ö©¶´


Panasonic FPWIN Pro´¦ÖÃÏîÄ¿Îļþ´æÔÚ»º³åÇøÒç³ö©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿É½øÐоܾø·þÎñ¹¥»÷»òÕßÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://us-cert.cisa.gov/ics/advisories/icsa-21-005-02


3.Qualcomm Video NAL½âÎöÔ½½ç䩶´


Qualcomm Video NAL½âÎö´æÔÚÔ½½ç䩶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://www.qualcomm.com/company/product-security/bulletins/january-2021-bulletin



4.Google Android¼Ü¹¹CVE-2021-0313¾Ü¾ø·þÎñ©¶´


Google Android¼Ü¹¹´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿É½øÐоܾø·þÎñ¹¥»÷¡£

https://source.android.com/security/bulletin/2021-01-01


5.Delta Electronics Industrial Automation DOPSoft CVE-2020-27277»º³åÇøÒç³ö©¶´


Delta Electronics Industrial Automation DOPSoft´¦ÖÃÏîÄ¿Îļþ´æÔÚ»º³åÇøÒç³ö©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿É½øÐоܾø·þÎñ¹¥»÷»òÕßÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://us-cert.cisa.gov/ics/advisories/icsa-21-005-05


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢ÄÉʲά¶û±¬Õ¨µ¼ÖÂÃÀ¹úÊý°ÙÓ¢ÀïͨÐÅ·þÎñÖжÏ


1.png


ÄÉʲά¶ûÊÐÖÐÐÄ·¢ÉúµÄÊ¥µ®½Ú±¬Õ¨Ê¼þµ¼ÖÂÃÀ¹úÊý°ÙÓ¢ÀïͨÐÅ·þÎñÖжÏ¡£´Ë´Î±¬Õ¨Ëð»µÁËÃÀ¹úµç»°µç±¨¹«Ë¾(AT£¦T)Òªº¦µÄÍøÂçÉèÊ© £¬ÆäÔÚÌïÄÉÎ÷ÖÝ¡¢¿ÏËþ»ùÖݺͰ¢À­°ÍÂíÖݵĴó²¿ÃŵØÓòµÄ¿Í»§¾ùÊܵ½Ó°Ïì £¬ÎÞ·¨Í¨ÐźÍÉÏÍø¡£´ËÍâ £¬´Ë´Î±¬Õ¨»¹Ôì³ÉÁËÊýÊ®ÈËËÀÍöºÍÊýÊ®ÈËÊÜÉË £¬Ô¼ÓÐ100¸ö911ºô½ÐÖÐÐÄ·ºÆðÎÊÌâ¡£AT£¦TÌåÏÖ½ØÖÁÉÏÖÜÈý £¬ËùÓзþÎñ»ù±¾ÒѾ­»Ö¸´¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/nashville-bombing-spotlights-vulnerable-voice-data-networks


2¡¢Cyble·¢ÏÖºÚ¿ÍÔÚ°µÍø³öÊÛÁ½ÒÚ¶àÖйú¹«ÃñµÄÐÅÏ¢


2.png


CybleµÄÑо¿ÍŶӷ¢ÏÖºÚ¿ÍÔÚ°µÍø³öÊÛÁ½ÒÚ¶àÖйú¹«ÃñµÄÐÅÏ¢¡£´Ë´Î鶵ÄÊý¾ÝÀ´×Ô¶à¸öƽ̨ºÍÈí¼þ £¬ÆäÖаüÂÞ730Íòºþ±±Ê¡¾£ÖÝÊй«°²ÏؾÓÃñµÄÉí·ÝÖ¤ºÅ¡¢ÐÔ±ð¡¢ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢ÊÖ»ú¡¢µØÖ·ºÍ´úÂëµÈÐÅÏ¢ £¬4180Íò¸ö΢²©Óû§µÄÕ˺źÍÏàÓ¦µÄÊÖ»úºÅÂë £¬ÒÔ¼°1.92ÒÚQQÓû§µÄÕ˺źÍÏàÓ¦µÄÊÖ»úºÅÂë¡£´Ë´Î鶵ÄÓëÖйú¹«ÃñÓйصļǼ×ÜÊýÁè¼Ý2ÒÚ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/112966/deep-web/chinese-citizens-data-darkweb.html


3¡¢ÁÄÌìȺ×éSlack·þÎñÖжÏ £¬²¨¼°È«ÇòÓû§


3.png


ÁÄÌìȺ×éSlack·þÎñ·¢ÉúÁË2021ÄêµÄÊ×´ÎÖжÏ £¬²¨¼°È«ÇòÓû§¡£ÐÂÄêºóµÄµÚÒ»¸öÊÂÇéÈÕ £¬ÃÀ¹ú¶«²¿Ê±¼ä1ÔÂ4ÈÕÉÏÎç10µãSlack·ºÆðÁËÖжÏ £¬Ó°ÏìÁË×ÀÃæ¿Í»§¶ËºÍWeb½çÃæ £¬Óû§ÎÞ·¨Á¬½Ó·þÎñÆ÷¡¢ÎÞ·¨·¢ËͺͽÓÊÕÏûÏ¢¶øÇÒÎÞ·¨¼ìË÷ƵµÀÀúÊ·¼Ç¼¡£×î³õ·¢ÉúÖжÏʱSlack³ÆÕâÖ»Ó°ÏìÁËÏûϢͨ±¨ £¬µ«ËæºóSlackµÄËùÓзþÎñµÄ¶¼·ºÆðÁËÖжÏ¡£Ä¿Ç°Slack»Ö¸´ÁË¿Í»§¶ËµÄ²¿ÃŹ¦Ð§ £¬Èç½ÓÊպͷ¢ËÍÏûÏ¢ £¬µ«GoogleÈÕÀúºÍOutlookÈÕÀúµÈ·þÎñÈÔÎÞ·¨Õý³£ÊÂÇé¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/technology/slack-suffers-its-first-massive-outage-of-2021/


4¡¢ESTsecurityÅû¶ThalliumÕë¶Ô½ðÈÚÐÐÒµµÄ¹©Ó¦Á´¹¥»÷


4.png


ESTsecurityÅû¶APT×éÖ¯Thallium£¨ÓÖÃûAPT37£©Õë¶Ô½ðÈÚÐÐÒµµÄ¹©Ó¦Á´¹¥»÷¡£Ôڴ˴ι¥»÷»î¶¯ÖÐ £¬ºÚ¿Í¸Ä¶¯ÁËÒ»¿î˽È˹ÉƱͶ×ÊÐÅϢͨ±¨µÄÓ¦Óà £¬ÒÔ·Ö·¢¶ñÒâ´úÂë¡£ThalliumÊ×ÏÈʹÓÃNullsoft½Å±¾°²×°ÏµÍ³£¨NSIS£©Éú³ÉWindows¿ÉÖ´ÐÐÎļþ £¬¸ÃÎļþ°üÂÞÁËÀ´×ԺϷ¨¹ÉƱͶ×ÊÓ¦Ó÷¨Ê½µÄºÏ·¨ÎļþºÍ¶ñÒâ´úÂë¡£µ±Óû§ÔÚ°²×°ÕæÕýµÄ¹ÉƱͶ×ÊÓ¦Ó÷¨Ê½Ê± £¬ºǫ́ͬʱÔËÐжñÒâ½Å±¾¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/north-korean-software-supply-chain-attack-targets-stock-investors/


5¡¢GreyNoiseÔÚÒ°·¢ÏÖÀûÓÃZyxelÖЩ¶´µÄ¹¥»÷»î¶¯


5.png


ÍøÂçÄþ¾²¹«Ë¾GreyNoiseÔÚÒ°·¢ÏÖÀûÓÃZyxelÖЩ¶´£¨CVE-2020-29583£©µÄ¹¥»÷»î¶¯¡£¸Ã©¶´ÓëZyxelÖÐÓ²±àÂëµÄºóÃÅÕÊ»§zyfwpÓйØ £¬¹¥»÷Õß¿ÉÒÔÀûÓÃÀ´½Ó¹ÜÍøÂçÉ豸¡£GreyNoise¼ì²âµ½Èý¸ö²îÒìµÄIPµØÖ·ÕýÔÚɨÃèSSHÉ豸 £¬²¢ÊµÑéʹÓÃZyxelºóÃŵǼ¡£µ«ÊÇÕâЩ¹¥»÷Õß²¢Ã»ÓÐרÃÅÕë¶ÔZyxelÉ豸 £¬¶øÊÇɨÃèInternetÉÏËùÓÐÕýÔÚÔËÐеÄSSH¡£ÆäÖÐÒ»¸ö¹¥»÷ÕßʹÓÃÁËCobalt StrikeµÄÄÚÖÃSSH¿Í»§¶ËÀ´Ö´ÐÐɨÃè £¬Ö¼ÔÚÈƹý¼ì²â¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hackers-start-exploiting-the-new-backdoor-in-zyxel-devices/