ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ52ÖÜ

°ä²¼¹¦·ò 2020-12-28

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2020Äê12ÔÂ21ÈÕÖÁ12ÔÂ27ÈÕ¹²ÊÕ¼°²È«·ì϶56¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇABB Symphony Plus Operations SQL×¢Èë·ì϶ £»D-link DSL-2888A execute_cmd.cgi OSºÅÁî×¢Èë·ì϶ £»Zyxel USG SeriesĬÈÏÍ´´¦·ì϶ £»BrowserUp Proxy Java EL±í°×ʽעÈë·ì϶ £»QNAP QES CVE-2020-2499Ó²±àÂë·ì϶¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇAcronis°ä²¼ÈôºÎÓ¦¶ÔCOVID-19µÄÓ°ÏìµÄ»ã±¨ £»CISA°ä²¼SolarWinds Orion¹¥»÷ÊÂÎñµÄ²¹³äÖ¸ÄÏ £»SolarWinds¹©¸øÁ´¹¥»÷»î¶¯ÖдæÔÚеÄSUPERNOVAºóÃÅ £»NintendoÊý¾Ýй¶£¬½ÒÊ¾Ôø¹ÍÓ¶ºÚ¿ÍΪÆä¹¤×÷ £»Kaspersky°ä²¼LazarusÕë¶ÔCOVID-19µý±¨µÄ·ÖÎö»ã±¨¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£


³ÁÒª°²È«·ì϶Áбí


1.ABB Symphony Plus Operations SQL×¢Èë·ì϶


ABB Symphony Plus Operations´æÔÚSQL×¢Èë·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄSQLÒªÇ󣬲Ù×÷Êý¾Ý¿â£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐËÁÒâ´úÂë¡£

https://search.abb.com/library/Download.aspx?DocumentID=2PAA123980&LanguageCode=en&DocumentPartId=&Action=Launch


2.D-link DSL-2888A execute_cmd.cgi OSºÅÁî×¢Èë·ì϶


D-link DSL-2888A execute_cmd.cgi´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿É×¢Èë¶ñÒâOSºÅÁî²¢Ö´ÐС£

https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/d-link-multiple-security-vulnerabilities-leading-to-rce/


3.Zyxel USG SeriesĬÈÏÍ´´¦·ì϶


Zyxel USG Series´æÔÚzyfwpĬÈÏÕË»§¼°²»³É¸ü¸ÄÆäÃÜÂ룬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Î´ÊÚȨ½Ó¼û·þÎñÆ÷¡£

https://businessforum.zyxel.com/discussion/5254/whats-new-for-zld4-60-patch-1-available-on-dec-15



4.BrowserUp Proxy Java EL±í°×ʽעÈë·ì϶


BrowserUp Proxy´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»×¢ÈëËÁÒâJava EL±í°×ʽ²¢ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://github.com/browserup/browserup-proxy/commit/4b38e7a3e20917e5c3329d0d4e9590bed9d578ab


5.QNAP QES CVE-2020-2499Ó²±àÂë·ì϶


QNAP QES´æÔÚÓ²±àÂë·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Î´ÊÚȨ½Ó¼ûϵͳ¡£

https://www.qnap.com/zh-tw/security-advisory/qsa-20-19


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢Acronis°ä²¼ÈôºÎÓ¦¶ÔCOVID-19µÄÓ°ÏìµÄ»ã±¨


1.png


Acronis°ä²¼ÁËÈôºÎÓ¦¶ÔCOVID-19µÄÓ°ÏìµÄ»ã±¨¡£AcronisÔÚ2020Äê6ÔÂÖÁ7ÔÂÆÚ¼ä¶ÔÈ«Çò3400¼Ò¹«Ë¾ºÍÔ¶³Ì¹¤È˽øÐÐÁ˵÷²é£¬ÒÔ×êÑÐ×éÖ¯ÈôºÎÊÊÓ¦COVID-19¶ÔÆäITÔËÓªºÍÍøÂç°²È«Ì¬ÊÆµÄÓ°Ïì¡£»ã±¨ÏÔʾ£¬31%µÄ¹«Ë¾Ã¿Ìì³ÇÊÐÔâµ½ÍøÂç¹¥»÷£¬69£¥µÄÔ¶³Ì¹¤×÷Õß±ØÒªÒÀ¸½Zoom¡¢Cisco WebexµÈ¹¤¾ß½øÐкÏ×÷£¬¶ø39£¥µÄ¹«Ë¾Ôâ·êÁËÊÓÆµ»áÒé¹¥»÷¡£´Ë±í£¬Ö»ÓÐ2£¥µÄ¹«Ë¾ÔÚÆÀ¹ÀÍøÂ簲ȫ½â¾ö¹æ»®Ê±Ë¼¿¼Ê¹ÓÃURL¹ýÂË¡£


Ô­ÎÄÁ´½Ó£º

https://www.acronis.com/en-us/blog/posts/acronis-cyber-readiness-report-pandemic-reveals-cybersecurity-gaps-need-new-solutions


2¡¢CISA°ä²¼SolarWinds Orion¹¥»÷ÊÂÎñµÄ²¹³äÖ¸ÄÏ


2.png


CISA×î³õÓÚ12ÔÂ17ÈÕ°ä²¼ÁËÓйص±¾Ö»ú¹¹¡¢¹Ø¼ü»ù´¡ÉèÊ©ºÍ¹«Ë¾×éÖ¯µÄAPT¹¥»÷»î¶¯µÄ¾¯±¨£¬Ö®ºóÕë¶Ô¸Ã´¹Î£Ö¸Áî°ä²¼Á˲¹³äÖ¸ÄÏ¡£²¹³äÖ¸ÄÏÔ̺¬ÊÜÓ°Ïì°æ±¾µÄ¸üС¢Õë¶ÔʹÓõÚÈý·½·þÎñÌṩÉ̵ĴúÀíµÄÖ¸ÄÏÒÔ¼°¶ÔËùÐè´ëÊ©µÄ½øÒ»²½×¢Ã÷¡£´Ë±í£¬CISA»¹¸üÐÂÁ˸þ¯±¨£¬ÌṩÁËÐµĻº½â¹æ»®²¢¶©ÕýÁËIOC±í¸ñ¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/12/19/cisa-updates-alert-and-releases-supplemental-guidance-emergency


3¡¢SolarWinds¹©¸øÁ´¹¥»÷»î¶¯ÖдæÔÚеÄSUPERNOVAºóÃÅ


3.png


×êÑÐÈËÔ±·¢ÏÖSolarWinds Orion¹©¸øÁ´¹¥»÷»î¶¯ÖдæÔÚеÄSUPERNOVAºóÃÅ£¬¿ÉÄÜÀ´×ÔÁíÒ»¸öºÚ¿Í×éÖ¯¡£SUPERNOVAÊÇÖ²ÈëOrionÍøÂçºÍÀûÓ÷¨Ê½¼à¶½Æ½Ì¨´úÂëÖеÄWeb shell£¬¹¥»÷Õß¿ÉÀûÓøöñÒâÈí¼þÔÚÍÆËã»úÉÏÔËÐÐËÁÒâ´úÂë¡£¸Ã¶ñÒâ´úÂë½öÔ̺¬Ò»ÖÖDynamicRun²½Ö裬¿É½«²ÎÊý¶¯Ì¬±àÒëµ½ÄÚ´æÖеÄ.NET·¨Ê½¼¯ÖУ¬Òò¶ø²»»áÔÚÊÜϰȾÉ豸ÉÏÁôÏÂÈκκۼ£¡£¾­µ÷²é£¬SUPERNOVAûº±¼û×ÖÊðÃû£¬ÕâÓë×î³õ·¢ÏÖµÄSunBurst·ÖÆç£¬»òÐíÊôÓÚÁíÒ»ºÚ¿Í×éÖ¯¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/a-second-hacking-group-has-targeted-solarwinds-systems/


4¡¢NintendoÊý¾Ýй¶£¬½ÒÊ¾Ôø¹ÍÓ¶ºÚ¿ÍΪÆä¹¤×÷


4.png


NintendoÔٴβúÉúÑϳÁµÄÊý¾Ýй¶ÊÂÎñ£¬½ÒÊ¾Ôø¹ÍÓ¶ºÚ¿ÍΪÆä¹¤×÷¡£Õâ´Îй¶µÄÊý¾ÝÈÔÊÇÊ×Ïȳʴ˿Ì4chanÂÛ̳ÉÏ£¬Ô̺¬ÓëSwitchµÄ¿ª·¢ÓйصÄÎļþ£¬ÀýÈçSwitchÔçÆÚµÄÉè¼Æ²ÎÊý£¬ºÃ±ÈʹÓÃ1GÄÚ´æ¡¢480P·Ö±æÂʵÄÉãÏñÍ·¡¢¼æÈÝ3DSÓÎÏ·¡¢Äܹ»Í¨¹ýMiracastͶÆÁµÈ¡£´Ë±í£¬Õâ´Îй¶»¹½ÒʾÁËÈÎÌìÌÃÔø¹ÍÓ¶³ÛÃûµÄ3DSºÚ¿ÍΪÆä¹¤×÷£¬ÉõÖÁ»¹Ôì¶©ÁËÒ»·Ý¹«¹Ø´òË㣬ÒÔ½â¾öÔÚ·¢ÏָùÍÓ¶¹ØÏµºóÈôºÎ´¦Öù«¼Ò·´Ó³¡£


Ô­ÎÄÁ´½Ó£º

https://www.videogameschronicle.com/news/nintendo-has-reportedly-suffered-another-major-data-leak-now-related-to-switch/


5¡¢Kaspersky°ä²¼LazarusÕë¶ÔCOVID-19µý±¨µÄ·ÖÎö»ã±¨


5.png


Kaspersky°ä²¼ÓйغڿÍ×éÖ¯LazarusÕë¶ÔCOVID-19µý±¨µÄ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬LazarusÓÚ2020Äê9ÔÂ25ÈÕÈëÇÖÁËÒ»¼ÒÔìÒ©¹«Ë¾£¬²¢ÓÚ2020Äê10ÔÂ27ÈÕ¹¥»÷Á˵±¾ÖÎÀÉú²¿£¬²¢°Ü»µÁËÁ½Ì¨Windows·þÎñÆ÷¡£ÕâÁ½´Î¹¥»÷»î¶¯Ê¹ÓÃÁË·ÖÆçµÄÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½£¨TTP£©ÒÔ¼°¶ñÒâÈí¼þ¼¯Èº£¬µ«ÓÐÖ¤¾ÝÅú×¢¶¼ÓëLazarusÓйØ£¬²¢Ö¤Ã÷¸Ã×éÖ¯¶ÔÓëCOVID-19Óйصĵý±¨¸ÐÐËÖ¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/lazarus-covets-covid-19-related-intelligence/99906/