ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ28ÖÜ
°ä²¼¹¦·ò 2021-07-12> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2021Äê07ÔÂ05ÈÕÖÁ07ÔÂ11ÈÕ¹²ÊÕ¼°²È«·ì϶61¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAdvantech WebAccess Node BwFreRPTÕ»Òç³ö´úÂëÖ´Ðзì϶£»Microsoft Teams ElectronJSÖ¡³Á¶¨Ïò´úÂëÖ´Ðзì϶£»NPort IA5000A-I/O Series CVE-2021-32968»Ø¾ø·þÎñ·ì϶£»Phoenix Contact Automationworx BCPÎļþÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶£»Siemens Simcenter Femap FEMAPÔ½½çд´úÂëÖ´Ðзì϶¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÈðµäÁ¬Ëø³¬ÊÐCoopÒòKaseya¹©¸øÁ´¹¥»÷¹Ø¹ØÊý°Ù¼ÒÃŵꣻÃÀ¹ú±£ÏÕ¹«Ë¾AJG³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬¿Í»§ÐÅϢй¶£»CISAºÍFBI°ä²¼Õë¶ÔKaseya¹©¸øÁ´¹¥»÷Êܺ¦ÕßµÄÖ¸ÄÏ£»Î¢Èí°ä²¼µÄPrintNightmareµÄ´¹Î£¸üпɱ»Èƹý£»Kaspersky·¢ÏÖWildPressureÕë¶ÔmacOSµÄ¹¥»÷»î¶¯¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
> ³ÁÒª°²È«·ì϶Áбí
1.Advantech WebAccess Node BwFreRPTÕ»Òç³ö´úÂëÖ´Ðзì϶
Advantech WebAccess Node BwFreRPT´æÔÚÕ»Òç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄ0x2711 IOCTLÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-779/
2.Microsoft Teams ElectronJSÖ¡³Á¶¨Ïò´úÂëÖ´Ðзì϶
Microsoft Teams ElectronJSÖ¡±£»¤´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâÒªÇ󣬿ɳÁ¶¨Ïò¶ñÒâÒ³Ãæ£¬½Ó¼ûÄÚ²¿ÀûÓöÔÏó£¬ÌáÉýȨÏÞ¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-772/
3.NPort IA5000A-I/O Series CVE-2021-32968»Ø¾ø·þÎñ·ì϶
NPort IA5000A-I/O SeriesÄÚ²¿WEB·þÎñ´æÔÚ»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£¡£
https://us-cert.cisa.gov/ics/advisories/icsa-21-187-01
4.Phoenix Contact Automationworx BCPÎļþÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶
Phoenix Contact Automationworx BCPÎļþ´¦ÖôæÔÚÄÚ´æ·ÛËé·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-782/
5.Siemens Simcenter Femap FEMAPÔ½½çд´úÂëÖ´Ðзì϶
Siemens Simcenter Femap FEMAPÎļþ´¦ÖôæÔÚÔ½½çд·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-781/
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢ÈðµäÁ¬Ëø³¬ÊÐCoopÒòKaseya¹©¸øÁ´¹¥»÷¹Ø¹ØÊý°Ù¼ÒÃŵê

ÈðµäÁ¬Ëø³¬ÊÐCoop³ÆÆäÔâµ½ÁËKaseya¹©¸øÁ´¹¥»÷£¬Êý°Ù¼ÒÃÅµê¹Ø¹Ø¡£CoopµÄ½²»°È˰µÊ¾ÆäÓÚÉÏÖÜÎåÍíÉÏ6µã30·Ö×óÓÒ·¢ÏÖÓÐÉÙÊýÃŵê³öÏÖÎÊÌ⣬µ«Ò»Ò¹Ö®ºóÆä´ó²¿ÃÅÃŵ궼±»ÆÈ¹Ø¹Ø£¬Ô̺¬ÊÕÒøÌ¨ºÍ×ÔÖ÷½áÕËÔÚÄÚµÄÕû¸öÖ§¸¶ÏµÍ³¶¼ÖжÏÁË¡£´Ë±í£¬CoopûÓÐʹÓÃKesayaÈí¼þ£¬ÓÉÓÚËûÃǵÄÒ»¸öÈí¼þÌṩÉÌʹÓÃÁ˸ÃÈí¼þ¶øÊܵ½Ó°Ïì¡£°²È«¹«Ë¾HuntressLabs³Æ£¬Õâ´Î¹¥»÷»î¶¯µÄµ÷²éÈÔÔÚ½øÐÐÖУ¬ÖÁÉÙÓÐ200¼Ò×éÖ¯Êܵ½Ó°Ïì¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/119663/cyber-crime/coop-supermarket-kaseya-ransomware-attack.html
2¡¢ÃÀ¹ú±£ÏÕ¹«Ë¾AJG³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬¿Í»§ÐÅϢй¶

ÃÀ¹úArthur J. Gallagher (AJG) ³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬¿Í»§ÐÅϢй¶¡£AJGÊÇÃÀ¹úµÄÈ«Çò±£ÏÕ¾¼ÍºÍ·çÏÕÖÎÀí¹«Ë¾£¬×÷ΪȫÇò×î´óµÄ±£ÏÕ¾¼ÍÉÌÖ®Ò»£¬ÒµÎñ±é¼°49¸ö¹ú¶È/µØÓò¡£¹¥»÷²úÉúÔÚ2020Äê6ÔÂ3ÈÕÖÁ2020Äê9ÔÂ26ÈÕÆÚ¼ä£¬ÆäÔÚ2020Äê9ÔÂ28ÈÕÅû¶¸ÃÊÂÎñ²¢³ÆÃ»º±¼û¾Ýй¶¡£µ«ÔÚËæºóµÄµ÷²é·¢ÏÖ£¬7376È˵ÄÃô¸ÐÐÅϢй¶£¬Ô̺¬Éç»á°²È«ºÅÂë»ò˰ºÅ¡¢¼ÝÕÕ¡¢»¤ÕÕ¡¢µ®ÉúÈÕÆÚ¡¢Óû§ÃûºÍÃÜÂë¡¢Ô±¹¤¼ø±ðºÅ¡¢²ÆÕþÕË»§»òÐÅÓþ¿¨ÐÅÏ¢¡¢µç×ÓÊðÃû¡¢Ò½ÁÆÐÅÏ¢¡¢±£ÏÕÐÅÏ¢ÒÔ¼°ÉúÎï¼ø±ðÐÅÏ¢µÈ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/us-insurance-giant-ajg-reports-data-breach-after-ransomware-attack/
3¡¢CISAºÍFBI°ä²¼Õë¶ÔKaseya¹©¸øÁ´¹¥»÷Êܺ¦ÕßµÄÖ¸ÄÏ

CISAºÍFBI½áºÏ°ä²¼ÁËÕë¶ÔÊܵ½Kaseya¹©¸øÁ´¹¥»÷Ó°ÏìµÄÊܺ¦ÕßµÄÖ¸ÄÏ¡£ÕâÁ½¸ö»ú¹¹½¨Òé×é֯ʹÓÃKaseyaÌṩµÄ¼ì²â¹¤¾ßÀ´²é³ËûÃǵÄϵͳÊÇ·ñ´æÔÚÈëÇÖ¼£Ï󣬲¢ÆôÓöà³É·ÖÉí·ÝÑéÖ¤(MFA)¡£´Ë±í£¬×éÖ¯»¹Ó¦Ê¹Óð×Ãûµ¥À´±í²¿ÏÞ¶È¶ÔÆäÄÚ²¿×ʲúµÄ½Ó¼û£¬²¢Ê¹Ó÷À»ðǽ»òVPN±£»¤ÆäÔ¶³Ì¼à¿Ø¹¤¾ßµÄÖÎÀí½çÃæ¡£¶øÊÜÓ°ÏìµÄMSP¿Í»§±ØÒªÈ·±£±¸·ÝÊÇ×îÐµģ¬²¢ÇÒµ±¼´×°Öù©¸øÉÌÌṩµÄ×îеIJ¹¶¡¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/119728/cyber-crime/cisa-fbi-guidance-kaseya-attack.html
4¡¢Î¢Èí°ä²¼µÄPrintNightmareµÄ´¹Î£¸üпɱ»Èƹý

Microsoft°ä²¼KB5004945´¹Î£°²È«¸üУ¬½¨¸´Ó°ÏìËùÓÐWindows Print Spooler·þÎñÖб»»ý¼«ÀûÓõÄPrintNightmare 0day¡£¸ÃÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-34527£©ÔÊÐí¹¥»÷ÕßʹÓÃSYSTEMȨÏÞµÄÔ¶³ÌÖ´ÐдúÂë²¢ÆëÈ«ÊÕÊÜÖ¸±ê·þÎñÆ÷¡£ÔÚ¸üа䲼ºó£¬×êÑÐÈËÔ±·¢Ïָò¹¶¡½ö½¨¸´ÁËÉæ¼°Ô¶³Ì´úÂëÖ´ÐеÄ×é¼þ£¬Òò¶ø×êÑÐÈËÔ±ÆðÍ·Åú¸Ä·ì϶ÀûÓ÷¨Ê½²¢²âÊÔ²¹¶¡£¬È·¶¨Äܹ»ÆëÈ«ÈÆ¹ýÕû¸ö²¹¶¡À´ÊµÏÖ±¾µØÌáȨºÍÔ¶³Ì´úÂëÖ´ÐС£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-pushes-emergency-update-for-windows-printnightmare-zero-day/
5¡¢Kaspersky·¢ÏÖWildPressureÕë¶ÔmacOSµÄ¹¥»÷»î¶¯

KasperskyµÄ×êÑÐÈËÔ±·¢ÏÖWildPressureÔÚ×î½üµÄ¹¥»÷»î¶¯ÖÐÔö³¤ÁËÕë¶ÔmacOSµÄ¶ñÒâÈí¼þ±äÌå¡£×êÑÐÈËÔ±ÓÚ2020Äê3Ô³õ´Î·¢ÏÖ¸ÃÍŻÆäʱWildPressureʹÓÃÁËC++°æ±¾µÄMilumľÂí¹¥»÷Öж«µÄ×éÖ¯¡£ÔÚ½üÆÚÕë¶ÔÄÜÔ´ÐÐÒµµÄ¹¥»÷ÖУ¬MilumÒѾͨ¹ýPyInstaller°ü½øÐÐÁ˳Á×飬ÆäÖÐÔ̺¬ÁËÓëWindowsºÍmacOSϵͳ¼æÈݵÄľÂí·¨Ê½£¬±»ºÚµÄÍøÕ¾¿É±»APT×éÖ¯ÓÃÀ´ÏÂÔØºÍÉÏ´«Îļþ²¢Ö´ÐкÅÁî¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/macos-wildpressure-apt/167606/


¾©¹«Íø°²±¸11010802024551ºÅ