ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ28ÖÜ

Ðû²¼Ê±¼ä 2021-07-12

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2021Äê07ÔÂ05ÈÕÖÁ07ÔÂ11ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´61¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAdvantech WebAccess Node BwFreRPTÕ»Òç³ö´úÂëÖ´ÐЩ¶´ £»Microsoft Teams ElectronJSÖ¡Öض¨Ïò´úÂëÖ´ÐЩ¶´ £»NPort IA5000A-I/O Series CVE-2021-32968¾Ü¾ø·þÎñ©¶´ £»Phoenix Contact Automationworx BCPÎļþÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´ £»Siemens Simcenter Femap FEMAPÔ½½çд´úÂëÖ´ÐЩ¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÈðµäÁ¬Ëø³¬ÊÐCoopÒòKaseya¹©Ó¦Á´¹¥»÷¹Ø±ÕÊý°Ù¼ÒÃŵê £»ÃÀ¹ú±£ÏÕ¹«Ë¾AJG³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬¿Í»§ÐÅϢй¶ £»CISAºÍFBIÐû²¼Õë¶ÔKaseya¹©Ó¦Á´¹¥»÷Êܺ¦ÕßµÄÖ¸ÄÏ £»Î¢ÈíÐû²¼µÄPrintNightmareµÄ½ô¼±¸üпɱ»Èƹý £»Kaspersky·¢ÏÖWildPressureÕë¶ÔmacOSµÄ¹¥»÷»î¶¯¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


> ÖØÒªÄþ¾²Â©¶´Áбí


1.Advantech WebAccess Node BwFreRPTÕ»Òç³ö´úÂëÖ´ÐЩ¶´


Advantech WebAccess Node BwFreRPT´æÔÚÕ»Òç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄ0x2711 IOCTLÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ £»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-779/


2.Microsoft Teams ElectronJSÖ¡Öض¨Ïò´úÂëÖ´ÐЩ¶´


Microsoft Teams ElectronJSÖ¡± £»¤´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâÇëÇ󣬿ÉÖض¨Ïò¶ñÒâÒ³Ã棬·ÃÎÊÄÚ²¿Ó¦Óù¤¾ß£¬ÌáÉýȨÏÞ¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-772/


3.NPort IA5000A-I/O Series CVE-2021-32968¾Ü¾ø·þÎñ©¶´


NPort IA5000A-I/O SeriesÄÚ²¿WEB·þÎñ´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâÇëÇ󣬿ÉʹӦÓ÷¨Ê½Í߽⡣

https://us-cert.cisa.gov/ics/advisories/icsa-21-187-01


4.Phoenix Contact Automationworx BCPÎļþÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´


Phoenix Contact Automationworx BCPÎļþ´¦ÖôæÔÚÄÚ´æÆÆ»µÂ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ £»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-782/


5.Siemens Simcenter Femap FEMAPÔ½½çд´úÂëÖ´ÐЩ¶´


Siemens Simcenter Femap FEMAPÎļþ´¦ÖôæÔÚÔ½½ç䩶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ £»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-781/


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢ÈðµäÁ¬Ëø³¬ÊÐCoopÒòKaseya¹©Ó¦Á´¹¥»÷¹Ø±ÕÊý°Ù¼ÒÃŵê


1.jpg


ÈðµäÁ¬Ëø³¬ÊÐCoop³ÆÆäÔâµ½ÁËKaseya¹©Ó¦Á´¹¥»÷£¬Êý°Ù¼ÒÃŵê¹Ø±Õ¡£CoopµÄ·¢ÑÔÈËÌåÏÖÆäÓÚÉÏÖÜÎåÍíÉÏ6µã30·Ö×óÓÒ·¢ÏÖÓÐÉÙÊýÃŵ귺ÆðÎÊÌ⣬µ«Ò»Ò¹Ö®ºóÆä´ó²¿ÃÅÃŵ궼±»Æȹرգ¬°üÂÞÊÕÒø̨ºÍ×ÔÖú½áÕËÔÚÄÚµÄÕû¸öÖ§¸¶ÏµÍ³¶¼ÖжÏÁË¡£´ËÍ⣬CoopûÓÐʹÓÃKesayaÈí¼þ£¬ÒòΪËûÃǵÄÒ»¸öÈí¼þÌṩÉÌʹÓÃÁ˸ÃÈí¼þ¶øÊܵ½Ó°Ïì¡£Äþ¾²¹«Ë¾HuntressLabs³Æ£¬´Ë´Î¹¥»÷»î¶¯µÄÊÓ²ìÈÔÔÚ½øÐÐÖУ¬ÖÁÉÙÓÐ200¼Ò×éÖ¯Êܵ½Ó°Ïì¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/119663/cyber-crime/coop-supermarket-kaseya-ransomware-attack.html


2¡¢ÃÀ¹ú±£ÏÕ¹«Ë¾AJG³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬¿Í»§ÐÅϢй¶


2.jpg


ÃÀ¹úArthur J. Gallagher (AJG) ³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬¿Í»§ÐÅϢй¶¡£AJGÊÇÃÀ¹úµÄÈ«Çò±£ÏÕ¾­¼ÍºÍ·çÏÕ¹ÜÀí¹«Ë¾£¬×÷ΪȫÇò×î´óµÄ±£ÏÕ¾­¼ÍÉÌÖ®Ò»£¬ÒµÎñ±é¼°49¸ö¹ú¼Ò/µØÓò¡£¹¥»÷·¢ÉúÔÚ2020Äê6ÔÂ3ÈÕÖÁ2020Äê9ÔÂ26ÈÕÆڼ䣬ÆäÔÚ2020Äê9ÔÂ28ÈÕÅû¶¸Ãʼþ²¢³ÆûÓÐÊý¾Ýй¶¡£µ«ÔÚËæºóµÄÊӲ췢ÏÖ£¬7376È˵ÄÃô¸ÐÐÅϢй¶£¬°üÂÞÉç»áÄþ¾²ºÅÂë»òË°ºÅ¡¢¼ÝÕÕ¡¢»¤ÕÕ¡¢³öÉúÈÕÆÚ¡¢Óû§ÃûºÍÃÜÂë¡¢Ô±¹¤Ê¶±ðºÅ¡¢²ÆÕþÕË»§»òÐÅÓÿ¨ÐÅÏ¢¡¢µç×ÓÇ©Ãû¡¢Ò½ÁÆÐÅÏ¢¡¢±£ÏÕÐÅÏ¢ÒÔ¼°ÉúÎïʶ±ðÐÅÏ¢µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-insurance-giant-ajg-reports-data-breach-after-ransomware-attack/


3¡¢CISAºÍFBIÐû²¼Õë¶ÔKaseya¹©Ó¦Á´¹¥»÷Êܺ¦ÕßµÄÖ¸ÄÏ


3.jpg


CISAºÍFBIÁªºÏÐû²¼ÁËÕë¶ÔÊܵ½Kaseya¹©Ó¦Á´¹¥»÷Ó°ÏìµÄÊܺ¦ÕßµÄÖ¸ÄÏ¡£ÕâÁ½¸ö»ú¹¹½¨Òé×é֯ʹÓÃKaseyaÌṩµÄ¼ì²â¹¤¾ßÀ´¼ì²éËûÃǵÄϵͳÊÇ·ñ´æÔÚÈëÇÖ¼£Ï󣬲¢ÆôÓöàÒòËØÉí·ÝÑéÖ¤(MFA)¡£´ËÍ⣬×éÖ¯»¹Ó¦Ê¹Óð×Ãûµ¥À´ÍⲿÏÞÖƶÔÆäÄÚ²¿×ʲúµÄ·ÃÎÊ£¬²¢Ê¹Ó÷À»ðǽ»òVPN± £»¤ÆäÔ¶³Ì¼à¿Ø¹¤¾ßµÄ¹ÜÀí½çÃæ¡£¶øÊÜÓ°ÏìµÄMSP¿Í»§ÐèҪȷ±£±¸·ÝÊÇ×îеģ¬¶øÇÒÁ¢¼´°²×°¹©Ó¦ÉÌÌṩµÄ×îеIJ¹¶¡¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/119728/cyber-crime/cisa-fbi-guidance-kaseya-attack.html


4¡¢Î¢ÈíÐû²¼µÄPrintNightmareµÄ½ô¼±¸üпɱ»Èƹý


4.jpg


MicrosoftÐû²¼KB5004945½ô¼±Äþ¾²¸üУ¬ÐÞ¸´Ó°ÏìËùÓÐWindows Print Spooler·þÎñÖб»»ý¼«ÀûÓõÄPrintNightmare 0day¡£¸ÃÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-34527£©ÔÊÐí¹¥»÷ÕßʹÓÃSYSTEMȨÏÞµÄÔ¶³ÌÖ´ÐдúÂë²¢ÍêÈ«½Ó¹ÜÄ¿±ê·þÎñÆ÷¡£ÔÚ¸üÐÂÐû²¼ºó£¬Ñо¿ÈËÔ±·¢Ïָò¹¶¡½öÐÞ¸´ÁËÉæ¼°Ô¶³Ì´úÂëÖ´ÐеÄ×é¼þ£¬Òò´ËÑо¿ÈËÔ±¿ªÊ¼Ð޸ĩ¶´ÀûÓ÷¨Ê½²¢²âÊÔ²¹¶¡£¬È·¶¨¿ÉÒÔÍêÈ«ÈƹýÕû¸ö²¹¶¡À´ÊµÏÖµ±µØÌáȨºÍÔ¶³Ì´úÂëÖ´ÐС£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-pushes-emergency-update-for-windows-printnightmare-zero-day/


5¡¢Kaspersky·¢ÏÖWildPressureÕë¶ÔmacOSµÄ¹¥»÷»î¶¯


5.jpg


KasperskyµÄÑо¿ÈËÔ±·¢ÏÖWildPressureÔÚ×î½üµÄ¹¥»÷»î¶¯ÖÐÔö¼ÓÁËÕë¶ÔmacOSµÄ¶ñÒâÈí¼þ±äÌå¡£Ñо¿ÈËÔ±ÓÚ2020Äê3ÔÂÊ״η¢ÏÖ¸ÃÍŻÆäʱWildPressureʹÓÃÁËC++°æ±¾µÄMilumľÂí¹¥»÷Öж«µÄ×éÖ¯¡£ÔÚ½üÆÚÕë¶ÔÄÜÔ´ÐÐÒµµÄ¹¥»÷ÖУ¬MilumÒѾ­Í¨¹ýPyInstaller°ü½øÐÐÁËÖØ×飬ÆäÖаüÂÞÁËÓëWindowsºÍmacOSϵͳ¼æÈݵÄľÂí·¨Ê½£¬±»ºÚµÄÍøÕ¾¿É±»APT×éÖ¯ÓÃÀ´ÏÂÔغÍÉÏ´«Îļþ²¢Ö´ÐÐÃüÁî¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/macos-wildpressure-apt/167606/