ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ17ÖÜ
°ä²¼¹¦·ò 2021-04-27> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2021Äê04ÔÂ19ÈÕÖÁ04ÔÂ25ÈÕ¹²ÊÕ¼°²È«·ì϶60¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇGoogle Chrome V8¶ÑÒç³ö´úÂëÖ´Ðзì϶£»FIBARO Home Center 2 8000¶Ë¿ÚδÊÚȨ½Ó¼û·ì϶£»Oracle Cloud Infrastructure Storage Gateway CVE-2021-2318´úÂëÖ´Ðзì϶£»Cisco SD-WAN vManage CVE-2021-1484²ÎÊý×¢Èë·ì϶£»Dell Technologies Dell PowerScale OneFSδÊÚȨ½Ó¼û·ì϶¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇTwitterÔÚÈ«ÇòÁìÓòÄÚ·þÎñÖжϣ¬ÊÂÎñÈÔÔÚµ÷²éÖУ»AdvIntel·¢ÏÖRyukÀûÓÃKeeThiefµÈй¤¾ßµÄ¹¥»÷»î¶¯£»ÃÀ¹úÔì²Ã28¸öÓë¶íÂÞ˹¹¥»÷»î¶¯ÓйصļÓÃÜÇ®±ÒµØÖ·£»Oracle°ä²¼°²È«¸üУ¬½¨¸´¶à¸ö²úÆ·ÖеÄ390¸ö·ì϶£»McAfee°ä²¼2020ϰëÄêÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
> ³ÁÒª°²È«·ì϶Áбí
1.Google Chrome V8¶ÑÒç³ö´úÂëÖ´Ðзì϶
Google Chrome V8ÒýÇæ´æÔÚ¶ÑÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÄܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_20.html
2.FIBARO Home Center 2 8000¶Ë¿ÚδÊÚȨ½Ó¼û·ì϶
FIBARO Home Center 2 8000¶Ë¿Ú´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉδÊÚȨִÐжñÒâ²Ù×÷£¬Èç¹Ø»ú¡¢³ÁÆô»ò³ÁÆôµ½¸´Ôģʽ¡£
http://seclists.org/fulldisclosure/2021/Apr/27
3.Oracle Cloud Infrastructure Storage Gateway CVE-2021-2318´úÂëÖ´Ðзì϶
Oracle Cloud Infrastructure Storage Gateway´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÄܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://www.oracle.com/security-alerts/cpuapr2021.html
4.Cisco SD-WAN vManage CVE-2021-1484²ÎÊý×¢Èë·ì϶
Cisco SD-WAN vManageÉ豸ģ°åÅäÖôæÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿É×¢ÈëËÁÒâºÅÁ»ò¿É½øÐлؾø·þÎñ¹¥»÷¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vman-cmdinj-nRHKgfHX
5.Dell Technologies Dell PowerScale OneFSδÊÚȨ½Ó¼û·ì϶
Dell Technologies Dell PowerScale OneFS¶ÔÃÜÔ¿¹ýÆÚ´¦ÖôæÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Õ¼ÓÐISI_PRIV_LOGIN_SSHµÄ¹ýÆÚÓû§¿É³ÖÐøµÇ¼ϵͳ¡£
https://www.dell.com/support/kbdoc/en-sg/000185202/dsa-2021-048-dell-emc-powerscale-onefs-security-update-for-multiple-vulnerabilities
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢TwitterÔÚÈ«ÇòÁìÓòÄÚ·þÎñÖжϣ¬ÊÂÎñÈÔÔÚµ÷²éÖÐ

TwitterÔÚÉÏÖÜÎåÍíÉϲúÉúÁ˵ÄÖжϣ¬²¢Ò»Ïò³ÖÐøµ½ÖÜÁùÉÏÎç¡£Óû§·´Ó³µÄÎÊÌâÔ̺¬ÎÞ·¨Õý³£ËÑË÷¡¢ÄÚÈÝÎÞ·¨¼ÓÔØ¡¢Í¼ÏñÎÞ·¨ÏÔʾÉõÖÁÎÞ·¨µÇÂ¼ÍøÕ¾¡£¾Ýͳ¼ÆÕâ´ÎÖжÏÓ°ÏìÁËÈ«ÇòÁìÓòÄÚµÄÓû§£¬µ«ÂÞÂíÄáÑǵÈһЩ¹ú¶ÈËÆºõ²¢Î´Êܵ½Ó°Ïì¡£Twitter°µÊ¾Õâ´ÎÖжÏÊÇÆä·þÎñÆ÷ÉϵÄÎÊÌ⣬²¢ÒѾÔÚÖÂÁ¦½â¾öʹËùÓо¡¿ì¸´ÔÕý³££¬µ«ÊDz¢Î´ÌṩÓйØÕâ´Î¹ÊÕϵľßÌåÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/technology/twitter-is-suffering-from-another-worldwide-outage-today/
2¡¢AdvIntel·¢ÏÖRyukÀûÓÃKeeThiefµÈй¤¾ßµÄ¹¥»÷»î¶¯

°²È«¹«Ë¾Advanced Intelligence·¢ÏÖRyukÀûÓÃKeeThiefµÈй¤¾ßµÄ¹¥»÷»î¶¯¡£×êÑÐÈËÔ±¹Û²ìµ½£¬½ñÄêRyukÀÕË÷Èí¼þ¸ü¶àµØÒÀÀµÓÚ¶ÔRDP¶³öµÄÖ÷»ú½øÐдó¹æÄ£±©Á¦ÆÆ½âºÍÃÜÂëÅçÈ÷¹¥»÷À´ÈëÇÖÖ¸±êÍøÂç¡£´Ë±í£¬ÔÚÕâЩ¹¥»÷Öл¹·¢ÏÖÁËм¼Êõ£¬Ô̺¬Ê¹ÓôÓKeePassÃÜÂëÖÎÀíÆ÷ÇÔȡƾ֤µÄ¿ªÔ´¹¤¾ßKeeThief£¬ÒÔ¼°×°ÖñãЯʽ°æ±¾µÄNotepad ++£¬ÔÚPowerShellÖ´ÐÐÊÜÏÞµÄϵͳÉÏÔËÐÐPowerShell¾ç±¾¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ryuk-ransomware-operation-updates-hacking-techniques/
3¡¢ÃÀ¹úÔì²Ã28¸öÓë¶íÂÞ˹¹¥»÷»î¶¯ÓйصļÓÃÜÇ®±ÒµØÖ·

ÃÀ¹úµ±¾ÖÔÚ±¾ÖÜÔì²ÃÁË28¸ö¼ÓÃÜÇ®±ÒµØÖ·£¬¾Ý³ÆÕâЩµØÖ·ÓëÉæ¼°¶íÂÞË¹ÍøÂç¹¥»÷»ò×ÌÈÅÑ¡¾Ù»î¶¯µÄ×éÖ¯ºÍÓ×ÎÒÓйء£ÃÀ¹úµ±¾Ö»¹°µÊ¾£¬ÕâЩ»î¶¯ÊÇÓɶíÂÞ˹Áª¹ú°²È«¾Ö£¨FSB£©ºÍ¶íÂÞË¹ÖØÒªµý±¨¾Ö£¨GRU£©·¢Õ¹µÄ£¬²¢ÇÒÒѾµÃµ½ÁËÁù¼ÒÓë¶íÂÞ˹ÓкÏ×÷µÄ¹«Ë¾µÄÔ®ÊÖ¡£´Ë±í£¬ÃûΪSESµÄ°Í»ù˹̹¹«Ë¾Ïò»¥ÁªÍø×êÑлú¹¹(IRA)ÌṩÐéαÉí·ÝÀ´ÌÓ±ÜÃÀ¹úµÄÔì²Ã£¬Æä¼ÓÃÜÇ®±ÒµØÖ·ÒÑͨ¹ý26900±ÊÂòÂôÊÕµ½Á˼ÛÖµ³¬¹ý250ÍòÃÀÔªµÄÊý×ÖÇ®±Ò¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/us-sanctions-cryptocurrency-addresses-linked-to-russian-cyberactivities/
4¡¢Oracle°ä²¼°²È«¸üУ¬½¨¸´¶à¸ö²úÆ·ÖеÄ390¸ö·ì϶

OracleÒÑÓÚ2021Äê4Ô°䲼Á˳ÁÒª²¹¶¡¸üУ¬½¨¸´Á˶à¸ö²úÆ·ÖеÄ390¸ö·ì϶¡£Õâ´Î½¨¸´µÄ½ÏΪÑϳÁµÄ·ì϶ΪOracleͨѶÀûÓ÷¨Ê½ÖÐCVSSÆÀ·ÖΪ9.8µÄCVE-2020-11612¡¢CVE-2019-0228¡¢CVE-2020-11612ºÍCVE-2020-28052£¬Instantis EnterpriseTrackÖеÄCVE-2019-0219£¬ÆóÒµÖÎÀíÆ÷»ù´¡Æ½Ì¨ÖеÄCVE-2019-17195ÒÔ¼°OracleóÒ×ÖÇÄÜÆóÒµ°æÖеÄCVE-2020-9480µÈ·ì϶¡£OracleÇ¿ÁÒ½¨Òé¿Í»§¾¡¿ìÀûÓð²È«²¹¶¡¡£
ÔÎÄÁ´½Ó£º
https://www.oracle.com/security-alerts/cpuapr2021.html
5¡¢McAfee°ä²¼2020ϰëÄêÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨

McAfee°ä²¼ÁË2020ϰëÄêÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£»ã±¨³Æ£¬2020ÄêQ4¾ùÔÈÿ·ÖÖӿɼì²âµ½648¸öÍþв£¬±ÈQ3Ôö³¤ÁË10£¥£¬±ÈQ2Ôö³¤ÁË40£¥£¬Ê¼ÖճʳÖÐøÉÏÉýÇ÷Ïò¡£»ã±¨»¹Ö¸³ö2020ÄêϰëÄêÔÚÒ°±í·¢ÏֵĹ¥»÷ÊýÁ¿¼¤ÔöµÄÖØÒªÔÒòÊÇÒÔCOVIDΪÖ÷ÌâµÄ¹¥»÷ºÍPowerShellľÂíµÄ¼¤Ôö£¬ÒÔ¼°SolarWinds·ì϶ºÍSunburst¶ñÒâÈí¼þµÄ³ÖÐøÊæÕ¹¡£Ïà±Å×ÚQ3 £¬Q4µÄPowerShellÊýÁ¿Ôö³¤ÁË208%£¬Õë¶ÔofficeµÄ¶ñÒâÈí¼þÊýÁ¿Ôö³¤ÁË199%¡£
ÔÎÄÁ´½Ó£º
https://www.mcafee.com/enterprise/en-us/lp/threats-reports/apr-2021.html


¾©¹«Íø°²±¸11010802024551ºÅ