ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ34ÖÜ
°ä²¼¹¦·ò 2021-08-30>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2021Äê08ÔÂ016ÈÕÖÁ08ÔÂ22ÈÕ¹²ÊÕ¼°²È«·ì϶60£¬ÖµµÃ¹Ø×¢µÄÊÇGoogle chrome V8 CVE-2021-30598ÀàÐÍ»ìºÏ´úÂëÖ´Ðзì϶£»Motorola MM1000É豸ÅäÖÃWEB·þÎñÆ÷ÌØÈ¨ÌáÉý·ì϶£»Lenovo Smart CameraºÅÁî×¢Èë·ì϶£»Apache HTTP Serverת·¢ÑéÖ¤ÈÆ¹ý·ì϶£»Dell EMC PowerScale OneFSÐÅϢй¶·ì϶¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǺڿÍÐû³ÆÒÑÇÔÈ¡µçÐŹ«Ë¾T-MobileÔ¼1ÒÚ¿Í»§µÄÐÅÏ¢£»Kaspersky°ä²¼2021ÄêµÚ¶þ¼¾¶ÈÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨£»KalayÔÆÆ½Ì¨Öеݲȫ·ì϶ӰÏìÈ«ÇòÊý°ÙÍòIoTÉ豸£»ÐµÄHolesWarmÀûÓÃ20¶à¸öÒÑÖª·ì϶·Ö·¢ÍÚ¿óÈí¼þ£»Cisco·¢ÏÖÕë¶ÔÄ«Î÷¸ç½ðÈÚ»ú¹¹µÄÐÂľÂíNeurevt¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
>³ÁÒª°²È«·ì϶Áбí
1.Google chrome V8 CVE-2021-30598ÀàÐÍ»ìºÏ´úÂëÖ´Ðзì϶
Google chrome V8´æÔÚÀàÐÍ»ìºÏ·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://www.auscert.org.au/bulletins/ESB-2021.2774
2.Motorola MM1000É豸ÅäÖÃWEB·þÎñÆ÷ÌØÈ¨ÌáÉý·ì϶
Motorola MM1000É豸ÅäÖÃWEB·þÎñÆ÷´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÌáÉýȨÏÞ£¬Ö´ÐÐËÁÒâ´úÂë¡£
https://motorolamentor.zendesk.com/hc/en-us/articles/1260804047750
3.Lenovo Smart CameraºÅÁî×¢Èë·ì϶
Lenovo Smart Camera´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÔÊÐíͨ¹ýÉèÖÃÌØÔìµÄÍøÂçÅäÖÃÀ´½øÐкÅÁî×¢Èë¡£
https://iknow.lenovo.com.cn/detail/dc_198417.html
4.Apache HTTP Serverת·¢ÑéÖ¤ÈÆ¹ý·ì϶
Apache HTTP Server´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÈƹýÉí·ÝÑéÖ¤£¬²¢ÓÉmod_proxyת·¢¡£
https://github.com/apache/
5.Dell EMC PowerScale OneFSÐÅϢй¶·ì϶
Dell EMC PowerScale OneFS´¦ÖÃÒªÇó·½Ê½´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ɻñÈ¡Ãô¸ÐÐÅÏ¢¡£
https://www.dell.com/support/kbdoc/zh-cn/000190408/dsa-2021-142-dell-powerscale-onefs-security-
>³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢ºÚ¿ÍÐû³ÆÒÑÇÔÈ¡µçÐŹ«Ë¾T-MobileÔ¼1ÒÚ¿Í»§µÄÐÅÏ¢

¹¥»÷ÕßÐû³ÆÔÚÁ½ÖÜǰÈëÇÖÁËT-MobileµÄÓÃÓÚ³ö²úºÍ¿ª·¢µÄ·þÎñÆ÷£¬ÒÔ¼°Ò»¸öÔ̺¬Á˿ͻ§ÐÅÏ¢µÄOracleÊý¾Ý¿â·þÎñÆ÷¡£Õâ´Îй¶ÁËT-MobileµÄ1ÒÚ¸ö¿Í»§Ô¼106GBµÄÊý¾Ý£¬Ô̺¬IMSI¡¢IMEI¡¢µç»°ºÅÂë¡¢¿Í»§ÐÕÃû¡¢°²È«PIN¡¢Éç»á°²È«ºÅÂë¡¢¼ÝÕÕºÅÂëºÍµ®ÉúÈÕÆÚµÈÐÅÏ¢¡£Íþвµý±¨¹«Ë¾Hudson Rock°µÊ¾£¬Õâ´ÎºÚ¿ÍµÄ¹¥»÷ÐÐΪ¿ÉÄÜÊÇΪÁË·ÛËéÃÀ¹úµÄ»ù´¡ÉèÊ©£¬Ö¼ÔÚ±¨³ðÃÀ¹úÔøÓÚ2019Äê°ó¼Ü²¢ÕÛÄ¥ÁËJohn Erin Binns(CIA Raven-1)¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hacker-claims-to-steal-data-of-100-million-t-mobile-customers/
2¡¢Kaspersky°ä²¼2021ÄêµÚ¶þ¼¾¶ÈÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨

Kaspersky°ä²¼ÁË2021ÄêµÚ¶þ¼¾¶ÈÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¸Ã»ã±¨·ÖÎöÁË2021ÄêQ2µÄ¶à¸öÓÐÕë¶ÔÐԵĹ¥»÷»î¶¯£¬Ô̺¬ÓëCycldekÍÅ»ïÓйصĹ¥»÷»î¶¯£¬ÔÚÒ°±íʹÓÃ×ÀÃæ´°¿ÚÖÎÀíÆ÷ÖÐ0dayµÄ¹¥»÷»î¶¯£¬TunnelSnakeÐж¯£¬PuzzleMaker»î¶¯ºÍFerocious KittenÍÅ»ïÓйػµÈ¡£´Ë±í£¬»ã±¨»¹·ÖÎöÁ˶à¸ö¶ñÒâÈí¼þ£¬Ô̺¬ÀÕË÷Èí¼þJSWormºÍBlack Kingdom¡¢ÒøÐÐľÂíGootkitºÍBizarro¡¢APKPureÀûÓÃÖжñÒâ´úÂëºÍBrowser lockersµÈ¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/it-threat-evolution-q2-2021/103597/
3¡¢KalayÔÆÆ½Ì¨Öеݲȫ·ì϶ӰÏìÈ«ÇòÊý°ÙÍòIoTÉ豸

FireEyeµÄMandiantÔÚ2020Äêµ×·¢ÏÖÁËKalayÔÆÆ½Ì¨Öеķì϶£¬²¢ÓëÃÀ¹úCISAºÍThroughTekºÏ×÷£¬Ðµ÷Åû¶¹æ»®²¢¿ª·¢»º½â²½Öè¡£¸Ã·ì϶ÊÇÒ»¸öÉ豸·ÂÕÕ·ì϶£¬×·×ÙΪCVE-2021-28372£¬ÆÀ·ÖΪ9.6·Ö¡£Ö»±ØÒªÖ¸±êÓû§µÄKalayΨһ±êʶ·û(UID)£¬Ô¶³Ì¹¥»÷Õß¾ÍÄܹ»ÀûÓø÷ì϶À´ÊÕÊÜÎïÁªÍøÉ豸¡£×êÑÐÈ˳ƣ¬»¹Äܹ»½«¸Ã·ì϶ÓëÉ豸RPC½Ó¿ÚÖеķì϶Ïà½áºÏÀ´ÆëÈ«ÈëÇÖÉ豸¡£·ì϶ӰÏìÁËÈ«ÇòÊý°ÙÍòͨ¹ýThroughTekµÄKalay IoTÔÆÆ½Ì¨ÏνӵÄÉ豸¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/121226/hacking/kalay-cloud-platform-critical-flaw.html
4¡¢ÐµÄHolesWarmÀûÓÃ20¶à¸öÒÑÖª·ì϶·Ö·¢ÍÚ¿óÈí¼þ

еĽ©Ê¬ÍøÂçHolesWarm×Ô½ñÄê6ÔÂÒÔÀ´ÆðÍ·»îÔ¾£¬ÀûÓÃÁË20¶à¸öÒÑÖª·ì϶ÈëÇÖWindowsºÍLinux·þÎñÆ÷£¬¶øºó×°ÖÃÍÚ¿ó¶ñÒâÈí¼þ¡£Ä¿Ç°¹¥»÷»î¶¯ÖØÒª²úÉúÔÚÖйú¸÷µØ£¬µ«Æ¾¾Ý×êÑÐÈËÔ±·ÖÎö£¬Ô¤¼ÆHolesWarm»áÀ©´óÆä¹¥»÷ÁìÓò£¬²¢ÔÚ½«À´¼¸¸öÔÂÄÚ¶Ô׼ȫÇò¡£¸Ã½©Ê¬ÍøÂçµÄC2·þÎñÆ÷Ϊm[.] windowsupdatesupsupport [.]org£¬ÆäÀûÓÃÁËDocker¡¢Jenkins¡¢Apache Tomcat¡¢Oracle WebLogicºÍSpring BootµÅצÓÃÖеķì϶¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/new-holeswarm-botnet-targets-windows-and-linux-servers/
5¡¢Cisco·¢ÏÖÕë¶ÔÄ«Î÷¸ç½ðÈÚ»ú¹¹µÄÐÂľÂíNeurevt

Cisco TalosÓÚ2021Äê6Ô¼ì²âµ½ÐÂNeurevtľÂí¡£¸Ã¶ñÒâÈí¼þ½«ºóÃźÍÐÅÏ¢ÇÔÈ¡·¨Ê½½áºÏÔÚһ·£¬ÖØÒªÕë¶ÔÄ«Î÷¸ç½ðÈÚ»ú¹¹µÄÓû§¡£¹¥»÷ÕßÒ»µ©³É¹¦Ï°È¾Ö¸±êÉ豸£¬¾ÍÄܹ»½Ó¼ûÖ¸±êϵͳ²¢Åú¸ÄËûÃǵÄÉèÖÃÒÔ°µ²Ø×Ô¼º¡£¸ÃľÂíÄܹ»Í¨¹ý½Ó¼ûÊܺ¦ÕßµÄϵͳ·þÎñÁîÅÆÀ´ÌáȨ£¬´Ó¶ø½Ó¼û²Ù×÷ϵͳ¡¢Óû§ÕÊ»§ÐÅÏ¢¡¢ÒøÐÐÍøÕ¾Í´´¦¡¢½ØÈ¡ÆÁÄ»½ØÍ¼²¢·¢Ë͵½C2·þÎñÆ÷ÒÔÇÔȡָ±êµÄÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2021/08/neurevt-trojan-takes-aim-at-mexican.html


¾©¹«Íø°²±¸11010802024551ºÅ