ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ24ÖÜ

Ðû²¼Ê±¼ä 2021-06-15

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2021Äê06ÔÂ07ÈÕÖÁ06ÔÂ13ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´73¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows Defender CVE-2021-31985´úÂëÖ´ÐЩ¶´£»Rockwell Automation ISaGRAF CVE-2020-25176 IXLЭÒé´úÂëÖ´ÐЩ¶´£»SAP NetWeaver ABAP Server CVE-2021-27632ÄÚ´æÆÆ»µÂ©¶´£»Schneider Electric IGSS CGFÔ½½ç䩶´£»Microsoft Windows TCP/IPÄþ¾²Èƹý©¶´ ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÃÀ¹úCox MediaÔâµ½ÀÕË÷¹¥»÷£¬µçÊӺ͵çֱ̨²¥ÖжÏ£»INKYÅû¶ÒÔ·À·¶ÀÕË÷Èí¼þΪÖ÷ÌâµÄÐÂÒ»ÂÖµöÓã»î¶¯£»ºÚ¿ÍÔÚ°µÍø¹ûÈ»°üÂÞ84ÒÚÃÜÂëµÄ¼¯ºÏRockYou2021£»FBI×·»ØColonial PipelineÖ§¸¶µÄ230ÍòÃÀÔªÊê½ð£»MicrosoftÄþ¾²¸üУ¬ÐÞ¸´7¸ö0dayÔÚÄÚµÄ50¸ö©¶´ ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖÐ ¡£


> ÖØÒªÄþ¾²Â©¶´Áбí


1.Microsoft Windows Defender CVE-2021-31985´úÂëÖ´ÐЩ¶´


Microsoft Windows Defender´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë ¡£

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-31985


2.Rockwell Automation ISaGRAF CVE-2020-25176 IXLЭÒé´úÂëÖ´ÐЩ¶´


Rockwell Automation ISaGRAF IXLЭÒé´¦ÖÃÎļþÃû´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë ¡£

https://us-cert.cisa.gov/ics/advisories/icsa-20-280-01


3.SAP NetWeaver ABAP Server CVE-2021-27632ÄÚ´æÆÆ»µÂ©¶´


SAP NetWeaver ABAP Server´æÔÚÄÚ´æÆÆ»µÂ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë ¡£

https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=578125999


4.Schneider Electric IGSS CGFÔ½½ç䩶´


Schneider Electric IGSS CGFÎļþ´¦ÖôæÔÚÔ½½ç䩶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë ¡£

https://us-cert.cisa.gov/ics/advisories/icsa-21-159-04


5.Microsoft Windows TCP/IPÄþ¾²Èƹý©¶´


Microsoft Windows Windows TCP/IP´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÈƹýÄþ¾²ÏÞÖÆδÊÚȨ·ÃÎÊ ¡£

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-31970


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢ÃÀ¹úCox MediaÔâµ½ÀÕË÷¹¥»÷£¬µçÊӺ͵çֱ̨²¥ÖжÏ


1.jpg


ÃÀ¹ú×î´óµÄýÌ弯ÍÅÖ®Ò»Cox Media Group£¨CMG£©Ôâµ½ÀÕË÷¹¥»÷£¬²¿ÃŵçÊӺ͵çֱ̨²¥ÖÐ¶Ï ¡£¸Ã¹«Ë¾ÓµÓÐ33¼ÒµçÊǪ́¡¢54¸ö¹ã²¥µç̨¡¢¶à¸ö¿çƽ̨Á÷ýÌåÊÓƵƽ̨ºÍÊý×Öƽ̨ ¡£Inside Radio³Æ¹¥»÷·¢ÉúÔÚ6ÔÂ3ÈÕÉÏÎ磬Æä¶ÔCMGµÄ¶à¸öµç̨½øÐÐÁËËæ»ú¼ì²é£¬·¢ÏÖµç̨ÍøÕ¾ÈÔ¿É·ÃÎÊ£¬µ«ÔÚÏßÁ÷ýÌåÒÑÀëÏߣ¬²¢Ìáʾ¡°ÒôƵÔÝʱ²»ÐÐÓá± ¡£ÕâÊÇÀÕË÷Èí¼þÍÅ»ïµÚ¶þ´Î¹¥»÷ÃÀ¹úÖ÷ÒªµÄýÌ幫˾£¬2019Äê9Ô£¬CBSÆìϵĹ㲥ÍøÂçEntercomÔâµ½¹¥»÷£¬µ¼Ö²¿ÃŹ㲥µç̨ÖÐ¶Ï ¡£


Ô­ÎÄÁ´½Ó£º

http://www.insideradio.com/free/cox-media-group-stations-still-offline-a-day-after-apparent-malware-attack/article_7c619380-c506-11eb-9b7b-4f6576d00aa0.html


2¡¢INKYÅû¶ÒÔ·À·¶ÀÕË÷Èí¼þΪÖ÷ÌâµÄÐÂÒ»ÂÖµöÓã»î¶¯


2.jpg


ÓʼþÄþ¾²Æ½Ì¨INKYÅû¶ÒÔ·À·¶ÀÕË÷Èí¼þΪÖ÷ÌâµÄÐÂÒ»ÂÖµöÓã»î¶¯ ¡£½üÆÚ¶ÔColonial PipelineµÄÀÕË÷Èí¼þ¹¥»÷¼¤·¢ÁËеĵöÓã»î¶¯£¬¸Ã»î¶¯µÄÓʼþ¾ùΪÓÐÕë¶ÔÐԵĽô¼±Í¨Öª£¬½¨ÒéÊÕ¼þÈ˵ã»÷Á´½ÓÒÔ°²×°ÏµÍ³¸üУ¬À´¼ì²â²¢·À·¶×îеÄÀÕË÷Èí¼þ ¡£¹¥»÷ÕßʹÓõÄÓòÃûΪms-sysupdate[.]comºÍselectionpatch [.]com£¬ÕâºÜÈÝÒ×±»ÎóÈÏΪÊǺϷ¨ÓòÃû£¬Æ仹ʹÓÃÁËCobalt Strike ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/phishing-uses-colonial-pipeline-ransomware-lures-to-infect-victims/


3¡¢ºÚ¿ÍÔÚ°µÍø¹ûÈ»°üÂÞ84ÒÚÃÜÂëµÄ¼¯ºÏRockYou2021


3.jpg


ijºÚ¿ÍÔÚ°µÍøÐû²¼ÁË100GBµÄTXTÎļþ£¬ÆäÖаüÂÞ84ÒÚ¸öÃÜÂ룬ÕâЩÃÜÂë¿ÉÄÜÊÇ´Ó֮ǰµÄй¶Ê¼þÖкϲ¢¶øÀ´µÄ ¡£ºÚ¿Í³ÆÆäÖаüÂÞµÄËùÓÐÃÜÂ볤¶È¾ùΪ6-20¸ö×Ö·û£¬É¾³ýÁË·ÇASCII×Ö·ûºÍ¿Õ¸ñ ¡£Æ仹ÌåÏָü¯ºÏ°üÂÞ820ÒÚ¸öÃÜÂ룬µ«¾­¹ýÑо¿ÈËÔ±²âÊÔ£¬ÆäÖÐÖ»ÓÐ8459060239¸öÊÇΨһµÄ£¬ÕâËƺõÊÇÓÐÊ·ÒÔÀ´×î´óµÄÃÜÂ뼯ºÏ ¡£¸Ã¼¯ºÏ±»³ÆΪRockYou2021£¬´ó¸ÅÊDzο¼ÁË2009Äê·¢ÉúµÄRockYouÊý¾Ýй¶Ê¼þ£¬ºÚ¿ÍÇÔÈ¡ÁËÁè¼Ý3200ÍòÓû§µÄÃÜÂë ¡£


Ô­ÎÄÁ´½Ó£º

https://cybernews.com/security/rockyou2021-alltime-largest-password-compilation-leaked/


4¡¢FBI×·»ØColonial PipelineÖ§¸¶µÄ230ÍòÃÀÔªÊê½ð


4.jpg


ÃÀ¹úFBIºÍDOJÁªºÏ×·»ØÁËColonial PipelineÖ§¸¶µÄÌ©°ëÊê½ð ¡£5ÔÂ7ÈÕ£¬¸Ã¹«Ë¾Ôâµ½ÁËDarkSideÀÕË÷Èí¼þ¹¥»÷ȼÁϹܵÀ¹Ø±Õ£¬Îª´ËÆäÖ§¸¶ÁË×ܼÆ440ÍòÃÀÔªµÄÊê½ð£¬´Ë´Î×·»ØÁËÆäÖеÄ230ÍòÃÀÔª ¡£DOJÌåÏÖ£¬ËûÃÇͨ¹ýÉó²é±ÈÌرҹ«¹²·ÖÀàÕË£¬¸ú×ÙÁ˶à´Î±ÈÌرÒתÕË£¬²¢È·¶¨Ô¼Äª63.7±ÈÌرÒÒÑתÒƵ½Ìض¨µØÖ·£¬¶øFBIÓµÓиõØÖ·µÄ˽Կ»ò´óÖµÈЧµÄµØÖ· ¡£ÃÀ¹ú˾·¨²¿»¹³Æ£¬ÊÂʵÉÏÁª°îÊÓ²ì¾Ö´ÓÒ»¿ªÊ¼¾ÍÉèÁËȦÌ× ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/fbi-claws-back-millions-darksides-ransom/166705/


5¡¢MicrosoftÄþ¾²¸üУ¬ÐÞ¸´7¸ö0dayÔÚÄÚµÄ50¸ö©¶´


5.jpg


MicrosoftÐû²¼ÁË6Ô·ݵÄÖܶþÄþ¾²¸üУ¬ÐÞ¸´ÁË°üÂÞ7¸ö0dayÔÚÄÚµÄ50¸ö©¶´ ¡£´Ë´ÎÐÞ¸´µÄ0day°üÂÞWindowsÄÚºËÐÅϢ鶩¶´£¨CVE-2021-31955£©¡¢Windows NTFSÌáȨ©¶´£¨CVE-2021-31956£©¡¢Microsoft DWMÌáȨ©¶´£¨CVE-2021-33739£©¡¢Windows MSHTMLƽ̨RCE©¶´£¨CVE-2021-33742£©¡¢MicrosoftÔöÇ¿ÐͼÓÃÜÌṩ·¨Ê½ÌáȨ©¶´£¨CVE-2021-31199ºÍCVE-2021-31201£©ºÍWindowsÔ¶³Ì×ÀÃæ·þÎñ¾Ü¾ø·þÎñ©¶´£¨CVE-2021-31968£© ¡£ÆäÖУ¬Ç°6¸ö0dayÒÑÔÚ¹ýÈ¥±»ÀûÓùý ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2021-patch-tuesday-fixes-6-exploited-zero-days-50-flaws/