ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ39ÖÜ
Ðû²¼Ê±¼ä 2021-09-27>±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2021Äê09ÔÂ20ÈÕÖÁ09ÔÂ26ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´42¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇGoogle Chrome Offline useÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´£»Edgecore ECS2020ÃüÁî×¢È멶´£»Hikvision Web ServerÃüÁî×¢È멶´£»Huawei FusionCompute CVE-2021-37106ÃüÁî×¢È멶´£»VMware vCenter ServerÈÎÒâÎļþÉÏ´«Â©¶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇNEW CooperativeÔâBlack Matter¹¥»÷±»ÀÕË÷590ÍòÃÀÔª£»Ñо¿ÈËÔ±·¢ÏÖÁè¼Ý1.06ÒÚÌ©¹úÓο͵ĸöÈËÐÅϢй¶£»VMwareÐÞ¸´vCenter ServerÖÐÑÏÖصÄÎļþÉÏ´«Â©¶´£»AppleÐû²¼Äþ¾²¸üУ¬ÐÞ¸´¶à¿î²úÎïÖеÄRCEµÈ©¶´£»¶íÂÞ˹APT×éÖ¯TurlaÀûÓÃкóÃŹ¥»÷ÃÀ¡¢µÂºÍ°¢¸»º¹¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
>ÖØÒªÄþ¾²Â©¶´Áбí
1.Google Chrome Offline useÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´
Google Chrome Offline use´æÔÚÊͷźóʹÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄWEBÒ³ÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿É¶ÔÓ¦Ó÷¨Ê½½øÐоܾø·þÎñ¹¥»÷»òÕßÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop_21.html
2.Edgecore ECS2020ÃüÁî×¢È멶´
Edgecore ECS2020 command1 HTTPÍ·´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿É×¢ÈëÈÎÒâÃüÁî²¢ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐС£
https://twitter.com/r00treaver/status/1232407881464635401
3.Hikvision Web ServerÃüÁî×¢È멶´
Hikvision Web Server´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿É×¢ÈëÈÎÒâÃüÁî²¢ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐС£
https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-notification-command-injection-vulnerability-in-some-hikvision-products/
4.Huawei FusionCompute CVE-2021-37106ÃüÁî×¢È멶´
Huawei FusionCompute²úÎïCMA·þÎñ´¦ÖÃÖ¤ÊéÎļþ´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿É×¢ÈëÈÎÒâÃüÁî²¢ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐС£
https://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20210922-01-commandinjection-cn
5.VMware vCenter ServerÈÎÒâÎļþÉÏ´«Â©¶´
VMware vCenter Server Analytics service´æÔÚÈÎÒâÎļþÉÏ´«Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.vmware.com/security/advisories/VMSA-2021-0020.html
>ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢NEW CooperativeÔâBlack Matter¹¥»÷±»ÀÕË÷590ÍòÃÀÔª
ÃÀ¹úÅ©ÃñºÏ×÷ÉçNEW CooperativeÔÚÉÏÖÜÄ©Ôâµ½Black MatterµÄÀÕË÷¹¥»÷¡£ÕâÊÇÒ»¼ÒËÇÁϺ͹ÈÎïºÏ×÷É磬´Ë´Î¹¥»÷»î¶¯½«µ¼ÖÂÁ¸Ê³¡¢ÖíÈâºÍ¼¦ÈâµÈʳƷ¹©Ó¦Öжϡ£¹¥»÷ÕßÒªÇó¸Ã¹«Ë¾Ö§¸¶590ÍòÃÀÔªÊê½ð£¬²¢ÌåÏÖ5ÈÕºóÊê½ð½ð¶î½«Ôö¼Óµ½1180ÍòÃÀÔª¡£BlackMatterÉù³ÆÇÔÈ¡ÁË1000 GBµÄÊý¾Ý£¬°üÂÞsoilmap.comÏîÄ¿µÄÔ´´úÂë¡¢Ñз¢½á¹û¡¢Ô±¹¤ÐÅÏ¢¡¢²ÆÕþÎļþÒÔ¼°KeePassÃÜÂë¹ÜÀíÆ÷µÄµ¼³öÊý¾Ý¿âµÈ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/122410/cyber-crime/black-matter-new-cooperative.html
2¡¢Ñо¿ÈËÔ±·¢ÏÖÁè¼Ý1.06ÒÚÌ©¹úÓο͵ĸöÈËÐÅϢй¶
ComparitechÑо¿ÈËÔ±Bob DiachenkoÓÚ2021Äê8ÔÂ22ÈÕ·¢ÏÖÁËδÊܱ£»¤µÄElasticsearchÊý¾Ý¿â¡£¸ÃÊý¾Ý¿â×ܹ²ÓÐ200GBÊý¾Ý£¬°üÂÞÁËÁè¼Ý1.06ÒÚÌ©¹úÓο͵ĸöÈËÐÅÏ¢¡£DiachenkoÍƲ⣬¸ÃʼþÉæ¼°µ½¹ýȥʮÄêÖÐÇ°ÍùÌ©¹úÂÃÓεĵÄËùÓÐÍâ¹úÈË¡£Ñо¿ÈËԱĿǰÎÞ·¨È·¶¨ÕâЩÊý¾Ý鶵Äʱ¼ä£¬µ«ÊÇÔÚ֪̩ͨ¹úÕþ¸®ºóµÄ24СʱÄھͱ»±£»¤ÁËÆðÀ´¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/data-of-106-million-visitors-to/
3¡¢VMwareÐÞ¸´vCenter ServerÖÐÑÏÖصÄÎļþÉÏ´«Â©¶´
VMwareÓÚ±¾ÖܶþÐû²¼Äþ¾²¸üУ¬ÐÞ¸´vCenter ServerºÍCloud FoundationÖеÄ19¸ö©¶´¡£ÆäÖÐ×îΪÑÏÖصÄÊÇvCenter ServerÖеÄÈÎÒâÎļþÉÏ´«Â©¶´(CVE-2021-22005)£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÍøÂç·ÃÎʶ˿Ú443µÄÉÏ´«ÌØÖÆÎļþÀ´Ö´ÐдúÂë¡£´ËÍ⣬»¹ÐÞ¸´Á˵±µØÌáȨ©¶´£¨CVE-2021-21991£©¡¢·´ÏòÊðÀíÈƹý©¶´£¨CVE-2021-22006£©¡¢API¶Ëµã©¶´£¨CVE-2021-22011£©ºÍAPIÐÅϢ鶩¶´£¨CVE-2021-22012£©µÈ¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/09/vmware-warns-of-critical-file-upload.html
4¡¢AppleÐû²¼Äþ¾²¸üУ¬ÐÞ¸´¶à¿î²úÎïÖеÄRCEµÈ©¶´
AppleÓÚ9ÔÂ20ÈÕÐû²¼Äþ¾²¸üУ¬ÐÞ¸´ÁËSafari 15¡¢Xcode 13¡¢tvOS 15¡¢watchOS 8¡¢iOS 15¡¢iPadOS 15ºÍiTunes 12.12ÖеĶà¸ö©¶´¡£ÆäÖаüÂÞSafari 15ÖеÄÄÚ´æË𻵵¼ÖµÄÈÎÒâ´úÂëÖ´ÐЩ¶´£¨CVE-2021-30846ºÍCVE-2021-30851µÈ£©¡¢tvOS 15ÖеÄDoS©¶´£¨CVE-2013-0340£©ºÍɳºÐÈƹý©¶´£¨CVE-2021-30854£©£¬ÒÔ¼°iOS 15ºÍiPadOS 15ÖеĴúÂëÖ´ÐЩ¶´£¨CVE-2021-30837ºÍCVE-2021-30811£©µÈ¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2021/09/21/apple-releases-security-updates-multiple-products
5¡¢¶íÂÞ˹APT×éÖ¯TurlaÀûÓÃкóÃŹ¥»÷ÃÀ¡¢µÂºÍ°¢¸»º¹
Cisco TalosÔÚ9ÔÂ21ÈÕÅû¶Á˶íÂÞ˹APT×éÖ¯TurlaÀûÓÃкóÃÅTinyTurla¹¥»÷ÃÀ¡¢µÂºÍ°¢¸»º¹µÄ»î¶¯¡£Turla×Ô2004ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬¹¥»÷ÁËÖж«¡¢ÑÇÖÞ¡¢Å·ÖÞ¡¢±±ÃÀºÍÄÏÃÀµÈµØÓòµÄÄ¿±ê¡£Ñо¿ÈËԱͨ¹ýÒ£²â·¢ÏÖÁ˺óÃÅ£¬µ«Éв»Çå³þÆäÈ·Çеݲװ·½Ê½£¬½öÖªµÀ¹¥»÷ÕßʹÓÃ.batÎļþÁ÷´«ºóÃÅ¡£¸ÃºóÃÅαװ³ÉMicrosoft DLL£¬²¢ÃüÃûΪw64time.dll£¬¿ÉÉÏ´«ºÍÖ´ÐÐÎļþ¡¢´´½¨×ÓÁ÷³ÌºÍÇÔÈ¡Êý¾ÝµÈ¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2021/09/tinyturla.html