ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ28ÖÜ
Ðû²¼Ê±¼ä 2021-07-12> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2021Äê07ÔÂ05ÈÕÖÁ07ÔÂ11ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´61¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAdvantech WebAccess Node BwFreRPTÕ»Òç³ö´úÂëÖ´ÐЩ¶´£»Microsoft Teams ElectronJSÖ¡Öض¨Ïò´úÂëÖ´ÐЩ¶´£»NPort IA5000A-I/O Series CVE-2021-32968¾Ü¾ø·þÎñ©¶´£»Phoenix Contact Automationworx BCPÎļþÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´£»Siemens Simcenter Femap FEMAPÔ½½çд´úÂëÖ´ÐЩ¶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÈðµäÁ¬Ëø³¬ÊÐCoopÒòKaseya¹©Ó¦Á´¹¥»÷¹Ø±ÕÊý°Ù¼ÒÃŵꣻÃÀ¹ú±£ÏÕ¹«Ë¾AJG³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬¿Í»§ÐÅϢй¶£»CISAºÍFBIÐû²¼Õë¶ÔKaseya¹©Ó¦Á´¹¥»÷Êܺ¦ÕßµÄÖ¸ÄÏ£»Î¢ÈíÐû²¼µÄPrintNightmareµÄ½ô¼±¸üпɱ»Èƹý£»Kaspersky·¢ÏÖWildPressureÕë¶ÔmacOSµÄ¹¥»÷»î¶¯¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
> ÖØÒªÄþ¾²Â©¶´Áбí
1.Advantech WebAccess Node BwFreRPTÕ»Òç³ö´úÂëÖ´ÐЩ¶´
Advantech WebAccess Node BwFreRPT´æÔÚÕ»Òç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄ0x2711 IOCTLÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-779/
2.Microsoft Teams ElectronJSÖ¡Öض¨Ïò´úÂëÖ´ÐЩ¶´
Microsoft Teams ElectronJSÖ¡±£»¤´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâÇëÇ󣬿ÉÖض¨Ïò¶ñÒâÒ³Ã棬·ÃÎÊÄÚ²¿Ó¦Óù¤¾ß£¬ÌáÉýȨÏÞ¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-772/
3.NPort IA5000A-I/O Series CVE-2021-32968¾Ü¾ø·þÎñ©¶´
NPort IA5000A-I/O SeriesÄÚ²¿WEB·þÎñ´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâÇëÇ󣬿ÉʹӦÓ÷¨Ê½Í߽⡣
https://us-cert.cisa.gov/ics/advisories/icsa-21-187-01
4.Phoenix Contact Automationworx BCPÎļþÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´
Phoenix Contact Automationworx BCPÎļþ´¦ÖôæÔÚÄÚ´æÆÆ»µÂ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-782/
5.Siemens Simcenter Femap FEMAPÔ½½çд´úÂëÖ´ÐЩ¶´
Siemens Simcenter Femap FEMAPÎļþ´¦ÖôæÔÚÔ½½ç䩶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-781/
> ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢ÈðµäÁ¬Ëø³¬ÊÐCoopÒòKaseya¹©Ó¦Á´¹¥»÷¹Ø±ÕÊý°Ù¼ÒÃŵê
ÈðµäÁ¬Ëø³¬ÊÐCoop³ÆÆäÔâµ½ÁËKaseya¹©Ó¦Á´¹¥»÷£¬Êý°Ù¼ÒÃŵê¹Ø±Õ¡£CoopµÄ·¢ÑÔÈËÌåÏÖÆäÓÚÉÏÖÜÎåÍíÉÏ6µã30·Ö×óÓÒ·¢ÏÖÓÐÉÙÊýÃŵ귺ÆðÎÊÌ⣬µ«Ò»Ò¹Ö®ºóÆä´ó²¿ÃÅÃŵ궼±»Æȹرգ¬°üÂÞÊÕÒø̨ºÍ×ÔÖú½áÕËÔÚÄÚµÄÕû¸öÖ§¸¶ÏµÍ³¶¼ÖжÏÁË¡£´ËÍ⣬CoopûÓÐʹÓÃKesayaÈí¼þ£¬ÒòΪËûÃǵÄÒ»¸öÈí¼þÌṩÉÌʹÓÃÁ˸ÃÈí¼þ¶øÊܵ½Ó°Ïì¡£Äþ¾²¹«Ë¾HuntressLabs³Æ£¬´Ë´Î¹¥»÷»î¶¯µÄÊÓ²ìÈÔÔÚ½øÐÐÖУ¬ÖÁÉÙÓÐ200¼Ò×éÖ¯Êܵ½Ó°Ïì¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/119663/cyber-crime/coop-supermarket-kaseya-ransomware-attack.html
2¡¢ÃÀ¹ú±£ÏÕ¹«Ë¾AJG³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬¿Í»§ÐÅϢй¶
ÃÀ¹úArthur J. Gallagher (AJG) ³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬¿Í»§ÐÅϢй¶¡£AJGÊÇÃÀ¹úµÄÈ«Çò±£ÏÕ¾¼ÍºÍ·çÏÕ¹ÜÀí¹«Ë¾£¬×÷ΪȫÇò×î´óµÄ±£ÏÕ¾¼ÍÉÌÖ®Ò»£¬ÒµÎñ±é¼°49¸ö¹ú¼Ò/µØÓò¡£¹¥»÷·¢ÉúÔÚ2020Äê6ÔÂ3ÈÕÖÁ2020Äê9ÔÂ26ÈÕÆڼ䣬ÆäÔÚ2020Äê9ÔÂ28ÈÕÅû¶¸Ãʼþ²¢³ÆûÓÐÊý¾Ýй¶¡£µ«ÔÚËæºóµÄÊӲ췢ÏÖ£¬7376È˵ÄÃô¸ÐÐÅϢй¶£¬°üÂÞÉç»áÄþ¾²ºÅÂë»òË°ºÅ¡¢¼ÝÕÕ¡¢»¤ÕÕ¡¢³öÉúÈÕÆÚ¡¢Óû§ÃûºÍÃÜÂë¡¢Ô±¹¤Ê¶±ðºÅ¡¢²ÆÕþÕË»§»òÐÅÓÿ¨ÐÅÏ¢¡¢µç×ÓÇ©Ãû¡¢Ò½ÁÆÐÅÏ¢¡¢±£ÏÕÐÅÏ¢ÒÔ¼°ÉúÎïʶ±ðÐÅÏ¢µÈ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/us-insurance-giant-ajg-reports-data-breach-after-ransomware-attack/
3¡¢CISAºÍFBIÐû²¼Õë¶ÔKaseya¹©Ó¦Á´¹¥»÷Êܺ¦ÕßµÄÖ¸ÄÏ
CISAºÍFBIÁªºÏÐû²¼ÁËÕë¶ÔÊܵ½Kaseya¹©Ó¦Á´¹¥»÷Ó°ÏìµÄÊܺ¦ÕßµÄÖ¸ÄÏ¡£ÕâÁ½¸ö»ú¹¹½¨Òé×é֯ʹÓÃKaseyaÌṩµÄ¼ì²â¹¤¾ßÀ´¼ì²éËûÃǵÄϵͳÊÇ·ñ´æÔÚÈëÇÖ¼£Ï󣬲¢ÆôÓöàÒòËØÉí·ÝÑéÖ¤(MFA)¡£´ËÍ⣬×éÖ¯»¹Ó¦Ê¹Óð×Ãûµ¥À´ÍⲿÏÞÖƶÔÆäÄÚ²¿×ʲúµÄ·ÃÎÊ£¬²¢Ê¹Ó÷À»ðǽ»òVPN±£»¤ÆäÔ¶³Ì¼à¿Ø¹¤¾ßµÄ¹ÜÀí½çÃæ¡£¶øÊÜÓ°ÏìµÄMSP¿Í»§ÐèҪȷ±£±¸·ÝÊÇ×îеģ¬¶øÇÒÁ¢¼´°²×°¹©Ó¦ÉÌÌṩµÄ×îеIJ¹¶¡¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/119728/cyber-crime/cisa-fbi-guidance-kaseya-attack.html
4¡¢Î¢ÈíÐû²¼µÄPrintNightmareµÄ½ô¼±¸üпɱ»Èƹý
MicrosoftÐû²¼KB5004945½ô¼±Äþ¾²¸üУ¬ÐÞ¸´Ó°ÏìËùÓÐWindows Print Spooler·þÎñÖб»»ý¼«ÀûÓõÄPrintNightmare 0day¡£¸ÃÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-34527£©ÔÊÐí¹¥»÷ÕßʹÓÃSYSTEMȨÏÞµÄÔ¶³ÌÖ´ÐдúÂë²¢ÍêÈ«½Ó¹ÜÄ¿±ê·þÎñÆ÷¡£ÔÚ¸üÐÂÐû²¼ºó£¬Ñо¿ÈËÔ±·¢Ïָò¹¶¡½öÐÞ¸´ÁËÉæ¼°Ô¶³Ì´úÂëÖ´ÐеÄ×é¼þ£¬Òò´ËÑо¿ÈËÔ±¿ªÊ¼Ð޸ĩ¶´ÀûÓ÷¨Ê½²¢²âÊÔ²¹¶¡£¬È·¶¨¿ÉÒÔÍêÈ«ÈƹýÕû¸ö²¹¶¡À´ÊµÏÖµ±µØÌáȨºÍÔ¶³Ì´úÂëÖ´ÐС£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-pushes-emergency-update-for-windows-printnightmare-zero-day/
5¡¢Kaspersky·¢ÏÖWildPressureÕë¶ÔmacOSµÄ¹¥»÷»î¶¯
KasperskyµÄÑо¿ÈËÔ±·¢ÏÖWildPressureÔÚ×î½üµÄ¹¥»÷»î¶¯ÖÐÔö¼ÓÁËÕë¶ÔmacOSµÄ¶ñÒâÈí¼þ±äÌå¡£Ñо¿ÈËÔ±ÓÚ2020Äê3ÔÂÊ״η¢ÏÖ¸ÃÍŻÆäʱWildPressureʹÓÃÁËC++°æ±¾µÄMilumľÂí¹¥»÷Öж«µÄ×éÖ¯¡£ÔÚ½üÆÚÕë¶ÔÄÜÔ´ÐÐÒµµÄ¹¥»÷ÖУ¬MilumÒѾͨ¹ýPyInstaller°ü½øÐÐÁËÖØ×飬ÆäÖаüÂÞÁËÓëWindowsºÍmacOSϵͳ¼æÈݵÄľÂí·¨Ê½£¬±»ºÚµÄÍøÕ¾¿É±»APT×éÖ¯ÓÃÀ´ÏÂÔغÍÉÏ´«Îļþ²¢Ö´ÐÐÃüÁî¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/macos-wildpressure-apt/167606/