ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ47ÖÜ

Ðû²¼Ê±¼ä 2021-11-22

>±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


±¾Öܹ²ÊÕ¼Äþ¾²Â©¶´67¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAdvantech WebAccess HMI Designer CVE-2021-33000ÏîÄ¿Îļþ¶ÑÒç³ö©¶´£»Google Chrome mediaÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´£»Lantronix PremierWave 2050 CVE-2021-21888ÃüÁî×¢È멶´£»Adobe Media Encoder M4A»º³åÇøÒç³ö©¶´£»Apache ShenYuδÊÚȨ·ÃÎÊ©¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇFBIÓʼþϵͳÔâµ½ÈëÇÖ·¢ËÍÊýÊ®ÍòÌõÐé¼ÙµÄ¹¥»÷¾¯±¨£»ÍøÐÅ°ìÐû²¼¡¶ÍøÂçÊý¾ÝÄþ¾²¹ÜÀíÌõÀý£¨Õ÷ÇóÒâ¼û¸å£©¡·£»Facebook·¢ÏÖSideCopyαÔìAndroidÓ¦ÓÃÉ̵êµÄ¹¥»÷£»GoogleÐû²¼11Ô¸üУ¬ÐÞ¸´ChromeÖеĶà¸ö©¶´£»CloudflareÐû²¼ÆäµÖÓùÁ˸ߴï2 TbpsµÄDDoS¹¥»÷¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


>ÖØÒªÄþ¾²Â©¶´Áбí


1. Advantech WebAccess HMI Designer CVE-2021-33000ÏîÄ¿Îļþ¶ÑÒç³ö©¶´


Advantech WebAccess HMI DesignerÏîÄ¿Îļþ´¦ÖôæÔÚ¶ÑÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»ò¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://us-cert.cisa.gov/ics/advisories/icsa-21-173-01


2. Google Chrome mediaÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´


Google Chrome media´æÔÚÊͷźóʹÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄWEBÒ³ÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»ò¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://chromereleases.googleblog.com/2021/11/stable-channel-update-for-desktop.html


3. Lantronix PremierWave 2050 CVE-2021-21888ÃüÁî×¢È멶´


Lantronix PremierWave 2050´¦ÖÃHTTPÇëÇóÑéÖ¤´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâÃüÁî¡£


https://talosintelligence.com/vulnerability_reports/TALOS-2021-1332


4. Adobe Media Encoder M4A»º³åÇøÒç³ö©¶´


Adobe Media Encoder M4A´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://helpx.adobe.com/security/products/media-encoder/apsb21-70.html


5. Apache ShenYuδÊÚȨ·ÃÎÊ©¶´


Apache ShenYu Admin ShenyuAdminBootstrap´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÈƹýÄþ¾²ÏÞÖÆδÊÚȨ·ÃÎÊ¡£


https://lists.apache.org/thread/o15j25qwtpcw62k48xw1tnv48skh3zgb


>ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢FBIÓʼþϵͳÔâµ½ÈëÇÖ·¢ËÍÊýÊ®ÍòÌõÐé¼ÙµÄ¹¥»÷¾¯±¨


FBIÓʼþϵͳÔÚ11ÔÂ13ÈÕÔâµ½ÈëÇÖ£¬±»ÓÃÀ´·¢ËÍÊýÊ®ÍòÌõÐé¼ÙµÄ¹¥»÷¾¯±¨¡£ÕâЩÓʼþð³ä¹úÍÁÄþ¾²²¿ (DHS)£¬Éù³ÆÊÕ¼þÈËÔâµ½ÁËÀ´×ÔVinny TroiaµÄÁ´Ê½¹¥»÷¡£µ«´ËÈËÊÇÄþ¾²¹«Ë¾NightLionºÍShadowbyteµÄÂôÁ¦ÈË£¬Ñо¿ÈËÔ±Íƶϴ˴λּÔÚÚ®»ÙÄþ¾²ÈËÔ±Troia¡£Spamhaus¹«Ë¾ÌåÏÖ£¬ÕâЩÓʼþ¶¼À´×ÔFBIÖ´·¨ÆóÒµÃÅ»§£¨LEEP£©µÄºÏ·¨µØÖ·eims@ic.fbi.gov£¬IPµØַΪ153.31.119.142(mx-east-ic.fbi.gov)¡£FBI³ÆÓÉÓÚÈí¼þ°´ÅäÖôíÎó£¬Ê¹µÃ¹¥»÷Õß¿ÉÒÔÀûÓÃLEEP·¢ËÍαÔìµÄÓʼþ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/124570/cyber-crime/fbi-hacked-email-server.html


2¡¢ÍøÐÅ°ìÐû²¼¡¶ÍøÂçÊý¾ÝÄþ¾²¹ÜÀíÌõÀý£¨Õ÷ÇóÒâ¼û¸å£©¡·


¹ú¼ÒÍøÐÅ°ìÓÚ11ÔÂ14ÈÕÐû²¼ÁË¡¶ÍøÂçÊý¾ÝÄþ¾²¹ÜÀíÌõÀý£¨Õ÷ÇóÒâ¼û¸å£©¡·µÄ¹ûÈ»Õ÷ÇóÒâ¼û֪ͨ¡£½ØÖÁ½ñÄê6Ô£¬ÎÒ¹úÍøÃñ¹æÄ£´ï10.11ÒÚ£¬ÓÉ´Ë·¢ÉúµÄÍøÂçÊý¾ÝÁ¿¸üÊÇÌìÎÄÊý×Ö¡£¸ÃÌõÀý¹æ·¶ÍøÂçÊý¾Ý´¦Öû£¬±£»¤¸öÈË¡¢×éÖ¯ÔÚÍøÂç¿Õ¼äµÄºÏ·¨È¨Ò棬ά»¤¹ú¼ÒÄþ¾²ºÍ¹«¹²ÀûÒæ¡£Öйú»¥ÁªÍøЭ»á·¨¹¤Î¯¸±ÃØÊ鳤ºú¸ÖÖ¸³ö£¬ÕâÊÇÐÂʱ´ú¹æ·¶»¥ÁªÍøƽ̨ÆóÒµ£¬Ç¿»¯·´Â¢¶ÏºÍ×ʱ¾ÎÞÐòÀ©ÕŵÄÓ¦ÓÐÖ®Ò壬ҲÊÇά»¤¹ú¼ÒÄþ¾²¡¢±£»¤Éç»á¹«¹²ÀûÒæµÄÐèÒª¡£


Ô­ÎÄÁ´½Ó£º

http://www.cac.gov.cn/2021-11/14/c_1638501991577898.htm


3¡¢Facebook·¢ÏÖSideCopyαÔìAndroidÓ¦ÓÃÉ̵êµÄ¹¥»÷


FacebookµÄÄþ¾²ÍŶÓÔÚ11ÔÂ16ÈÕÅû¶ÁË°Í»ù˹̹ºÚ¿ÍÍÅ»ïSideCopyÐÂÒ»ÂֵĵöÓã»î¶¯¡£´Ë´Î»î¶¯ÔÚ½ñÄê4ÔÂÖÁ8ÔÂÖ®¼ä£¬½¨Á¢²¢ÔËÓªÁËÒ»¸öαÔìµÄAndroidÓ¦ÓÃÉ̵ê¡£¹¥»÷ÕßÖ÷Ҫͨ³£»áð³äÄêÇáÅ®ÐÔÀ´½Ó½üÄ¿±ê£¬ÓÕʹÆä´ò¿ªÓÃÀ´ÓÃÀ´ÊÕ¼¯ÐÅÏ¢µÄµöÓãÍøÕ¾»òÕßαÔìµÄAndroidÓ¦ÓÃÉ̵ꡣȻºóͨ¹ýαװ³ÉÁÄÌìÓ¦ÓõĶñÒâÈí¼þ£¬·Ö·¢PJobRATºÍMayhemµÈ¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/pakistani-hackers-operated-a-fake-app-store-to-target-former-afghan-officials/


4¡¢GoogleÐû²¼11Ô¸üУ¬ÐÞ¸´ChromeÖеĶà¸ö©¶´


11ÔÂ16ÈÕ£¬GoogleÐû²¼Á˱¾ÔÂChromeµÄÄþ¾²¸üУ¬×ܼÆÐÞ¸´ÁË25¸ö©¶´¡£ÆäÖУ¬½ÏΪÑÏÖصÄÊÇÔÚýÌåÖеÄÊͷźóʹÓ鶴£¨CVE-2021-38008£©¡¢V8ÖеÄÀàÐÍ»ìÏý©¶´£¨CVE-2021-38007£©ºÍ¼ÓÔØÆ÷ÖÐÊͷźóʹÓ鶴£¨CVE-2021-38005£©µÈ¡£´ËÍ⣬»¹ÐÞ¸´ÁËÖ¸ÎÆʶ±ðÖеĶѻº³åÇøÒç³ö©¶´£¨CVE-2021-38013£©ºÍSwiftshaderÖеÄÔ½½çдÈ루CVE-2021-38014£©µÈ©¶´¡£


Ô­ÎÄÁ´½Ó£º

https://chromereleases.googleblog.com/2021/11/stable-channel-update-for-desktop.html


5¡¢CloudflareÐû²¼ÆäµÖÓùÁ˸ߴï2 TbpsµÄDDoS¹¥»÷


ÃÀ¹úÍøÂçÄþ¾²¹«Ë¾CloudflareÔÚ11ÔÂ15ÈÕÐû²¼ÆäµÖÓùÁËÆù½ñΪֹÓöµ½µÄ×î´ó¹¥»÷DDoS¹¥»÷£¬·åÖµÂÔµÍÓÚ2 Tbps¡£´Ë´Î¹¥»÷»î¶¯ÊǽáºÏÁËDNS·Å´ó¹¥»÷ºÍUDP·ººéµÄ¶àÏòÁ¿¹¥»÷£¬Õû¸ö¹ý³ÌÖ»Á¬ÐøÁËÒ»·ÖÖÓ£¬À´×ÔÔ¼15000¸ö»úÆ÷ÈË×é³ÉµÄ½©Ê¬ÍøÂçMirai±äÖÖ¡£Cloudflare³ÂË߳ƵÚÈý¼¾¶ÈÍøÂç²ãDDoS¹¥»÷»î¶¯±ÈÉÏÒ»¼¾¶ÈÔö¼ÓÁË44%£¬¸Ã¹«Ë¾ÔÚ8ÔµÖÓùÁËÿÃë1720Íò´ÎÇëÇóµÄDDoS¹¥»÷£¬Î¢ÈíÔÚ10Ô³ÆÆäÔÆ·þÎñAzureµÖÓùÁË2.4 TbpsµÄDDoS¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/124634/security/cloudflare-mitigated-ddos-2-tbps.html