ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ37ÖÜ

Ðû²¼Ê±¼ä 2021-09-14

>±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2021Äê09ÔÂ06ÈÕÖÁ09ÔÂ12ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´58¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇApple iOS Wi-Fi»º³åÇøÒç³ö´úÂëÖ´ÐЩ¶´£»Delta Electronics DOPSoftÏîÄ¿ÎļþÔ½½ç䩶´£»QNAP NAS CVE-2021-34343Õ»Òç³ö´úÂëÖ´ÐЩ¶´£»Google Android FrameworkÈÎÒâ´úÂëÖ´ÐЩ¶´£»Cisco IOS XR Software CVE-2021-34719ÌØȨÌáÉý©¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÐÂÎ÷À¼»¥ÁªÍøÔËÓªÉÌVocusÔâµ½´ó¹æÄ£DDoS¹¥»÷£»Google TensorFlowΪÐÞ¸´RCE©¶´¶ø²»ÔÙÖ§³ÖYAML£»FortiGuardÐû²¼2021ÄêH1È«ÇòÍþв̬ÊƵķÖÎö³ÂËߣ»Î¢ÈíÐû²¼MSHTMLÖÐRCE©¶´£¨CVE-2021-40444£©µÄͨ¸æ£»Ñо¿ÈËÔ±·¢ÏÖREvilÍÅ»ïµÄÊý¾Ýй¶ÍøÕ¾ÔÙ¶ÈÉÏÏß¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


>ÖØÒªÄþ¾²Â©¶´Áбí


1.Apple iOS Wi-Fi»º³åÇøÒç³ö´úÂëÖ´ÐЩ¶´


Apple iOS Wi-Fi´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://support.apple.com/en-us/HT212317


2.Delta Electronics DOPSoftÏîÄ¿ÎļþÔ½½ç䩶´


Delta Electronics DOPSoft´¦ÖÃÏîÄ¿Îļþ´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿Éʹϵͳ±ÀÀ£»òÕßÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://us-cert.cisa.gov/ics/advisories/icsa-21-252-02



3.QNAP NAS CVE-2021-34343Õ»Òç³ö´úÂëÖ´ÐЩ¶´


QNAP NAS´æÔÚÕ»Òç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿Éʹϵͳ±ÀÀ£»òÕßÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://www.qnap.com/en/security-advisory/qsa-21-33



4.Google Android FrameworkÈÎÒâ´úÂëÖ´ÐЩ¶´


Google Android Framework´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£


https://source.android.com/security/bulletin/2021-09-01



5.Cisco IOS XR Software CVE-2021-34719ÌØȨÌáÉý©¶´


Cisco IOS XR SoftwareÃüÁîÐвÎÊýʵÏÖ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíµ±µØ¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÌáÉýȨÏÞ£¬»ñÈ¡ROOTȨÏÞ¡£


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-privescal-dZYMrKf



>ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢ÐÂÎ÷À¼»¥ÁªÍøÔËÓªÉÌVocusÔâµ½´ó¹æÄ£DDoS¹¥»÷


ÐÂÎ÷À¼»¥ÁªÍøÔËÓªÉÌVocusÔâµ½´ó¹æÄ£DDoS¹¥»÷.jpg


ÐÂÎ÷À¼µÚÈý´ó»¥ÁªÍøÔËÓªÉÌVocus ISP³ÆÆäÔÚ9ÔÂ3ÈÕÔâµ½´ó¹æÄ£DDoS¹¥»÷£¬µ¼Ö·þÎñÖжÏÁËÔ¼30·ÖÖÓ¡£VocusÔÚ°Ä´óÀûÑǺÍÐÂÎ÷À¼ÌṩÁãÊÛ¡¢Åú·¢ºÍÆóÒµµçÐÅ·þÎñ¡£¸Ã¹«Ë¾³Æ£¬ÓÉÓÚÄ¿Ç°È«¹ú´ó²¿ÃŵØÓò¶¼ÔÚÔ¶³Ì°ì¹«£¬Òò´Ë´Ë´Î¹¥»÷¶Ô¿Í»§·¢ÉúÁËÖØ´óÓ°Ïì¡£Ö®ºó£¬¸Ã¹«Ë¾Ñ¸ËÙ»Ö¸´ÁËÔËÓª£¬²¢¶Ô¸ø¿Í»§´øÀ´µÄδ±ãÌåÏÖǸÒâ¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.reuters.com/technology/widespread-internet-outages-hits-users-across-new-zealand-2021-09-03/


2¡¢Google TensorFlowΪÐÞ¸´RCE©¶´¶ø²»ÔÙÖ§³ÖYAML


Google TensorFlowΪÐÞ¸´RCE©¶´¶ø²»ÔÙÖ§³ÖYAML.jpg


Google¿ª·¢µÄ»ùÓÚPythonµÄ»úÆ÷ѧϰºÍÈ˹¤ÖÇÄÜÏîÄ¿TensorFlowÒѾ­·ÅÆúÁ˶ÔYAMLµÄÖ§³Ö¡£TensorFlow´úÂëÖеÄyaml.unsafe_load()º¯Êý´æÔÚÒ»¸ö©¶´£¬×·×ÙΪCVE-2021-37678£¬ÆÀ·ÖΪ9.3¡£µ±Ó¦Ó÷´ÐòÁл¯YAML¸ñʽµÄKerasÄ£ÐÍʱ£¬¹¥»÷Õß¿ÉÀûÓø鶴ִÐÐÈÎÒâ´úÂ롣ΪÐÞ¸´´Ë©¶´£¬TensorFlow¾ö¶¨ÍêÈ«·ÅÆúYAMLµÄÖ§³Ö£¬×ª¶øʹÓÃJSON·´ÐòÁл¯¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/googles-tensorflow-drops-yaml-support-due-to-code-execution-flaw/


3¡¢FortiGuardÐû²¼2021ÄêH1È«ÇòÍþв̬ÊƵķÖÎö³ÂËß


FortiGuardÐû²¼2021ÄêH1È«ÇòÍþв̬ÊƵķÖÎö³ÂËß.jpg


FortiGuardÓÚ8Ô·ÝÐû²¼ÁË2021ÄêH1È«ÇòÍþв̬ÊƵķÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬2021Äê6ÔÂƽ¾ùÿÖÜÀÕË÷Èí¼þ»î¶¯±ÈÒ»ÄêǰͬÆڸ߳ö10.7±¶¡£ÆäÖУ¬µçÐÅÐÐÒµÊǹ¥»÷ÕßµÄÊ×ÒªµÄÄ¿±ê£¬Æä´ÎÊÇÕþ¸®¡¢ÍйÜÄþ¾²·þÎñÌṩÉÌ¡¢Æû³µºÍÖÆÔìÐÐÒµ¡£½©Ê¬ÍøÂçÒ²ÓÐËùÔö¼Ó£¬½ñÄêÄê³õÔÚ35%µÄ×éÖ¯Öмì²âµ½Á˽©Ê¬ÍøÂç»î¶¯£¬¶øÕâÒ»±ÈÀýÔÚ6¸öÔºóÔö¼ÓΪ51%¡£´ËÍ⣬¹¥»÷Õ߸üÇàíùÓÚ¼ì²âÈƹý¼¼ÊõºÍÌáȨ¼¼Êõ¡£


Ô­ÎÄÁ´½Ó£º

https://www.fortinet.com/content/dam/fortinet/assets/threat-reports/report-threat-landscape-2021.pdf


4¡¢Î¢ÈíÐû²¼MSHTMLÖÐRCE©¶´£¨CVE-2021-40444£©µÄͨ¸æ


΢ÈíÐû²¼MSHTMLÖÐRCE©¶´£¨CVE-2021-40444£©µÄͨ¸æ.jpg


΢ÈíÍŶÓÔÚ9ÔÂ7ÈÕÐû²¼ÁËÕë¶ÔWindowsÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-40444£©µÄ»º½â´ëÊ©¡£¸Ã©¶´´æÔÚÓÚMicrosoft OfficeÎĵµÊ¹ÓõÄä¯ÀÀÆ÷äÖȾÒýÇæMSHTMLÖУ¬ÒÑÔÚÕë¶ÔWindows 10ÉϵÄOffice 365ºÍOffice 2019µÄ¹¥»÷»î¶¯Öб»ÀûÓá£Ä¿Ç°ÉÐÎÞ¿ÉÓõÄÄþ¾²¸üУ¬Microsoft½¨Òé½ûÓÃInternet ExplorerÖÐËùÓеÄActiveX¿Ø¼þ×÷Ϊ»º½â´ëÊ©¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-shares-temp-fix-for-ongoing-office-365-zero-day-attacks/


5¡¢Ñо¿ÈËÔ±·¢ÏÖREvilÍÅ»ïµÄÊý¾Ýй¶ÍøÕ¾ÔÙ¶ÈÉÏÏß


Ñо¿ÈËÔ±·¢ÏÖREvilÍÅ»ïµÄÊý¾Ýй¶ÍøÕ¾ÔÙ¶ÈÉÏÏß.jpg


Ñо¿ÈËÔ±·¢ÏÖREvilÍÅ»ïµÄÊý¾Ýй¶ÍøÕ¾£¨Ò²³ÆΪ Happy Blog£©ÔÚ9ÔÂ7ÈÕÖØÐÂÉÏÏß¡£7ÔÂ2ÈÕ£¬REvilÀûÓÃKaseya VSAÖеÄ©¶´¹¥»÷ÁËԼĪ60¼ÒMSP¼°Æä1500¶à¸ö¿Í»§£¬²¢ÀÕË÷7000ÍòÃÀÔª¡£Ö®ºó£¬¸Ã×éÖ¯ÒýÆðÁËÖ´·¨²¿ÃŵÄ×¢Ò⣬²¢ÔÚ7ÔÂ13¹Ø±ÕÁËËùÓеÄTor·þÎñÆ÷ºÍ»ù´¡ÉèÊ©¡£Éв»Çå³þ´Ë´ÎÖ§¸¶ºÍÊý¾Ýй¶ÍøÕ¾µÄÖØÐÂÉÏÏߣ¬ÊÇ·ñ´ú±íןÃÍÅ»ïÒª¿ªÊ¼¸´³ö¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/revil-ransomwares-servers-mysteriously-come-back-online/