ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ39ÖÜ

Ðû²¼Ê±¼ä 2021-09-27

>±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2021Äê09ÔÂ20ÈÕÖÁ09ÔÂ26ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´42¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇGoogle Chrome Offline useÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´£»Edgecore ECS2020ÃüÁî×¢È멶´£»Hikvision Web ServerÃüÁî×¢È멶´£»Huawei FusionCompute CVE-2021-37106ÃüÁî×¢È멶´£»VMware vCenter ServerÈÎÒâÎļþÉÏ´«Â©¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇNEW CooperativeÔâBlack Matter¹¥»÷±»ÀÕË÷590ÍòÃÀÔª£»Ñо¿ÈËÔ±·¢ÏÖÁè¼Ý1.06ÒÚÌ©¹úÓο͵ĸöÈËÐÅϢй¶£»VMwareÐÞ¸´vCenter ServerÖÐÑÏÖصÄÎļþÉÏ´«Â©¶´£»AppleÐû²¼Äþ¾²¸üУ¬ÐÞ¸´¶à¿î²úÎïÖеÄRCEµÈ©¶´£»¶íÂÞ˹APT×éÖ¯TurlaÀûÓÃкóÃŹ¥»÷ÃÀ¡¢µÂºÍ°¢¸»º¹¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


>ÖØÒªÄþ¾²Â©¶´Áбí


1.Google Chrome Offline useÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´


Google Chrome Offline use´æÔÚÊͷźóʹÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄWEBÒ³ÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿É¶ÔÓ¦Ó÷¨Ê½½øÐоܾø·þÎñ¹¥»÷»òÕßÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop_21.html



2.Edgecore ECS2020ÃüÁî×¢È멶´


Edgecore ECS2020 command1 HTTPÍ·´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿É×¢ÈëÈÎÒâÃüÁî²¢ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐС£


https://twitter.com/r00treaver/status/1232407881464635401


3.Hikvision Web ServerÃüÁî×¢È멶´


Hikvision Web Server´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿É×¢ÈëÈÎÒâÃüÁî²¢ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐС£


https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-notification-command-injection-vulnerability-in-some-hikvision-products/



4.Huawei FusionCompute CVE-2021-37106ÃüÁî×¢È멶´


Huawei FusionCompute²úÎïCMA·þÎñ´¦ÖÃÖ¤ÊéÎļþ´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿É×¢ÈëÈÎÒâÃüÁî²¢ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐС£


https://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20210922-01-commandinjection-cn


5.VMware vCenter ServerÈÎÒâÎļþÉÏ´«Â©¶´


VMware vCenter Server Analytics service´æÔÚÈÎÒâÎļþÉÏ´«Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://www.vmware.com/security/advisories/VMSA-2021-0020.html



 >ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢NEW CooperativeÔâBlack Matter¹¥»÷±»ÀÕË÷590ÍòÃÀÔª


NEW CooperativeÔâBlack Matter¹¥»÷±»ÀÕË÷590ÍòÃÀÔª.png


ÃÀ¹úÅ©ÃñºÏ×÷ÉçNEW CooperativeÔÚÉÏÖÜÄ©Ôâµ½Black MatterµÄÀÕË÷¹¥»÷¡£ÕâÊÇÒ»¼ÒËÇÁϺ͹ÈÎïºÏ×÷É磬´Ë´Î¹¥»÷»î¶¯½«µ¼ÖÂÁ¸Ê³¡¢ÖíÈâºÍ¼¦ÈâµÈʳƷ¹©Ó¦ÖжÏ¡£¹¥»÷ÕßÒªÇó¸Ã¹«Ë¾Ö§¸¶590ÍòÃÀÔªÊê½ð£¬²¢ÌåÏÖ5ÈÕºóÊê½ð½ð¶î½«Ôö¼Óµ½1180ÍòÃÀÔª¡£BlackMatterÉù³ÆÇÔÈ¡ÁË1000 GBµÄÊý¾Ý£¬°üÂÞsoilmap.comÏîÄ¿µÄÔ´´úÂë¡¢Ñз¢½á¹û¡¢Ô±¹¤ÐÅÏ¢¡¢²ÆÕþÎļþÒÔ¼°KeePassÃÜÂë¹ÜÀíÆ÷µÄµ¼³öÊý¾Ý¿âµÈ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/122410/cyber-crime/black-matter-new-cooperative.html



2¡¢Ñо¿ÈËÔ±·¢ÏÖÁè¼Ý1.06ÒÚÌ©¹úÓο͵ĸöÈËÐÅϢй¶


Ñо¿ÈËÔ±·¢ÏÖÁè¼Ý1.06ÒÚÌ©¹úÓο͵ĸöÈËÐÅϢй¶.png


ComparitechÑо¿ÈËÔ±Bob DiachenkoÓÚ2021Äê8ÔÂ22ÈÕ·¢ÏÖÁËδÊܱ£»¤µÄElasticsearchÊý¾Ý¿â¡£¸ÃÊý¾Ý¿â×ܹ²ÓÐ200GBÊý¾Ý£¬°üÂÞÁËÁè¼Ý1.06ÒÚÌ©¹úÓο͵ĸöÈËÐÅÏ¢¡£DiachenkoÍƲ⣬¸ÃʼþÉæ¼°µ½¹ýȥʮÄêÖÐÇ°ÍùÌ©¹úÂÃÓεĵÄËùÓÐÍâ¹úÈË¡£Ñо¿ÈËԱĿǰÎÞ·¨È·¶¨ÕâЩÊý¾Ý鶵Äʱ¼ä£¬µ«ÊÇÔÚ֪̩ͨ¹úÕþ¸®ºóµÄ24СʱÄھͱ»±£»¤ÁËÆðÀ´¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/data-of-106-million-visitors-to/



3¡¢VMwareÐÞ¸´vCenter ServerÖÐÑÏÖصÄÎļþÉÏ´«Â©¶´


VMwareÐÞ¸´vCenter ServerÖÐÑÏÖصÄÎļþÉÏ´«Â©¶´.png


VMwareÓÚ±¾ÖܶþÐû²¼Äþ¾²¸üУ¬ÐÞ¸´vCenter ServerºÍCloud FoundationÖеÄ19¸ö©¶´¡£ÆäÖÐ×îΪÑÏÖصÄÊÇvCenter ServerÖеÄÈÎÒâÎļþÉÏ´«Â©¶´(CVE-2021-22005)£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÍøÂç·ÃÎʶ˿Ú443µÄÉÏ´«ÌØÖÆÎļþÀ´Ö´ÐдúÂë¡£´ËÍ⣬»¹ÐÞ¸´Á˵±µØÌáȨ©¶´£¨CVE-2021-21991£©¡¢·´ÏòÊðÀíÈƹý©¶´£¨CVE-2021-22006£©¡¢API¶Ëµã©¶´£¨CVE-2021-22011£©ºÍAPIÐÅϢ鶩¶´£¨CVE-2021-22012£©µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/09/vmware-warns-of-critical-file-upload.html



4¡¢AppleÐû²¼Äþ¾²¸üУ¬ÐÞ¸´¶à¿î²úÎïÖеÄRCEµÈ©¶´



AppleÐû²¼Äþ¾²¸üУ¬ÐÞ¸´¶à¿î²úÎïÖеÄRCEµÈ©¶´.png


AppleÓÚ9ÔÂ20ÈÕÐû²¼Äþ¾²¸üУ¬ÐÞ¸´ÁËSafari 15¡¢Xcode 13¡¢tvOS 15¡¢watchOS 8¡¢iOS 15¡¢iPadOS 15ºÍiTunes 12.12ÖеĶà¸ö©¶´¡£ÆäÖаüÂÞSafari 15ÖеÄÄÚ´æË𻵵¼ÖµÄÈÎÒâ´úÂëÖ´ÐЩ¶´£¨CVE-2021-30846ºÍCVE-2021-30851µÈ£©¡¢tvOS 15ÖеÄDoS©¶´£¨CVE-2013-0340£©ºÍɳºÐÈƹý©¶´£¨CVE-2021-30854£©£¬ÒÔ¼°iOS 15ºÍiPadOS 15ÖеĴúÂëÖ´ÐЩ¶´£¨CVE-2021-30837ºÍCVE-2021-30811£©µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/09/21/apple-releases-security-updates-multiple-products



5¡¢¶íÂÞ˹APT×éÖ¯TurlaÀûÓÃкóÃŹ¥»÷ÃÀ¡¢µÂºÍ°¢¸»º¹


¶íÂÞ˹APT×éÖ¯TurlaÀûÓÃкóÃŹ¥»÷ÃÀ¡¢µÂºÍ°¢¸»º¹.png


Cisco TalosÔÚ9ÔÂ21ÈÕÅû¶Á˶íÂÞ˹APT×éÖ¯TurlaÀûÓÃкóÃÅTinyTurla¹¥»÷ÃÀ¡¢µÂºÍ°¢¸»º¹µÄ»î¶¯¡£Turla×Ô2004ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬¹¥»÷ÁËÖж«¡¢ÑÇÖÞ¡¢Å·ÖÞ¡¢±±ÃÀºÍÄÏÃÀµÈµØÓòµÄÄ¿±ê¡£Ñо¿ÈËԱͨ¹ýÒ£²â·¢ÏÖÁ˺óÃÅ£¬µ«Éв»Çå³þÆäÈ·Çеݲװ·½Ê½£¬½öÖªµÀ¹¥»÷ÕßʹÓÃ.batÎļþÁ÷´«ºóÃÅ¡£¸ÃºóÃÅαװ³ÉMicrosoft DLL£¬²¢ÃüÃûΪw64time.dll£¬¿ÉÉÏ´«ºÍÖ´ÐÐÎļþ¡¢´´½¨×ÓÁ÷³ÌºÍÇÔÈ¡Êý¾ÝµÈ¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2021/09/tinyturla.html