ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ45ÖÜ
°ä²¼¹¦·ò 2021-11-08>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
±¾Öܹ²ÊÕ¼°²È«·ì϶60¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇCisco Policy Suite¾²Ì¬SSHÃÜÔ¿·ì϶£»Mozilla Firefox ESR HTTP2 session objectÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶£»Apache Traffic Server stats-over-http²å¼þÄڴ渲¸Ç·ì϶£»D-Link DIR-823G HNAP1ºÅÁî×¢Èë·ì϶£»Beckhoff Automation TwinCAT OPC UA ServerĿ¼±éÀú·ì϶¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊDz¿ÃÅMacÉ豸Éý¼¶ÖÁmacOS MontereyºóÎÞ·¨Õý³£Æô¶¯£»×êÑÐÍŶӷ¢ÏÖÏÕЩÍþвËùÓдúÂëµÄ·ì϶Trojan Source£»×êÑÐÍŶӳƽ©Ê¬ÍøÂçPinkÒÑϰȾ³¬¹ý160Íǫ̀ÖйúµÄÉ豸£»Google°ä²¼Android 11Ô¸üУ¬×ܼƽ¨¸´39¸ö·ì϶£»BlackMatterÍÅ»ï°ä·¢ÆÅ×Ú·¨Âɲ¿ÃŵÄѹÁ¦½«ÖÕ³¡ÔËÓª¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
>³ÁÒª°²È«·ì϶Áбí
1. Cisco Policy Suite¾²Ì¬SSHÃÜÔ¿·ì϶
Cisco Policy Suite´æÔÚ¾²Ì¬SSHÃÜÔ¿·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Î´ÊÚȨ½Ó¼ûϵͳ¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cps-static-key-JmS92hNv
2. Mozilla Firefox ESR HTTP2 session objectÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶
Mozilla Firefox ESR HTTP2 session object´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://www.mozilla.org/en-US/security/advisories/mfsa2021-49/
3. Apache Traffic Server stats-over-http²å¼þÄڴ渲¸Ç·ì϶
Apache Traffic Server stats-over-http²å¼þ´æÔÚÄڴ渲¸Ç·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://lists.apache.org/thread/k01797hyncx53659wr3o72s5cvkc3164
4. D-Link DIR-823G HNAP1ºÅÁî×¢Èë·ì϶
D-Link DIR-823G HNAP1´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâSHELLºÅÁî¡£
https://www.dlink.com/en/security-bulletin/
5. Beckhoff Automation TwinCAT OPC UA ServerĿ¼±éÀú·ì϶
Beckhoff Automation TwinCAT OPC UA Server´æÔÚĿ¼±éÀú·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄ´´½¨»òɾ³ýϵͳÉϵÄÈκÎÎļþ¡£
https://download.beckhoff.com/download/document/product-security/Advisories/advisory-2021-003.pdf
>³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢²¿ÃÅMacÉ豸Éý¼¶ÖÁmacOS MontereyºóÎÞ·¨Õý³£Æô¶¯
½üÆÚ£¬Ô½À´Ô½¶àµÄMacºÍMacbookÓû§»ã±¨£¬µ±Æä¸üе½ÉÏÖܰ䲼µÄ×îаæmacOS Montereyºó£¬É豸ÎÞ·¨Õý³£Æô¶¯¡£´ËÎÊÌâËÆºõ½öÓ°ÏìÁË2019Äê֮ǰµÄMacÉ豸£¬²»»áÓ°ÏìʹÓÃM1оƬµÄпîMac¡£´Ë±í£¬¹ÌÈ»²¿ÃÅÓû§³ÆËûÃǵÄϵͳÒѾ±äש£¬µ«´óÎÞÊýÓû§Äܹ»Í¨¹ýApple Configurator¹¤¾ß¸´ÔÉ豸¡£ÆäËûÓû§ÔòÕÒµ½ÁËÁíÒ»ÖÖ²½Ö裬¾ÍÊÇͨ¹ýÆô¶¯DFUÀ´¸´ÔÉ豸¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/apple/macos-monterey-update-causes-some-macs-to-become-unbootable/
2¡¢×êÑÐÍŶӷ¢ÏÖÏÕЩÍþвËùÓдúÂëµÄ·ì϶Trojan Source
½£ÇÅ´óѧµÄ×êÑÐÈËÔ±ÔÚ11ÔÂ1ÈÕ¹«¿ªÁËÒ»¸öÓ°Ïì´óÎÞÊýÍÆËã»ú´úÂë±àÒëÆ÷ºÍºÜ¶àÈí¼þ¿ª·¢»·¾³µÄ·ì϶Trojan Source¡£¸Ã·ì϶´æÔÚÓÚUnicodeÖУ¬ÓÐÁ½ÖÖÀûÓò½Ö裺ÆäÒ»ÊÇʹÓÃUnicodeµÄBidiËã·¨£¨CVE-2021-42574£©£¬¶Ô×Ö·û½øÐÐÊÓ¾õÉϵijÁÐÂÅÅÐò£¬Ê¹Æä³öÏÖÓë±àÒëÆ÷ºÍÚ¹ÊÍÆ÷Ëù·ÖÆçµÄÂß¼°¤´Î£»ÁíÒ»ÖÖÊÇͬÐÎÎÄ×Ö¹¥»÷(CVE-2021-42694)£¬¼´ÀûÓÃÔÚÊÓ¾õÉÏ¿´ÆðÀ´ÀàËÆµÄ·ÖÆç×Ö·û¡£¸Ã·ì϶ºÏÓÃÓÚC¡¢C++¡¢C#¡¢JavaScript¡¢JavaµÈ¿í·ºÊ¹ÓõÄ˵»°£¬¿ÉÓÃÓÚ¹©¸øÁ´¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.trojansource.codes/
3¡¢×êÑÐÍŶӳƽ©Ê¬ÍøÂçPinkÒÑϰȾ³¬¹ý160Íǫ̀ÖйúµÄÉ豸
×êÑÐÍŶÓÔÚ10ÔÂ29ÈÕÅû¶ÁËÔÚ´ÓǰÁùÄê·¢ÏÖµÄ×î´ó½©Ê¬ÍøÂçµÄϸ½Ú¡£ÓÉÓÚÆä´óÁ¿µÄº¯ÊýÃû³ÆÒÔpinkΪÊ×£¬ËùÒÔÈ¡ÃûPinkbot¡£¸Ã½©Ê¬ÍøÂçÒÑϰȾÁ˳¬¹ý160Íǫ̀É豸£¬ÆäÖÐ96%λÓÚÖйú¡£ËüÖØÒªÕë¶Ô»ùÓÚMIPSµÄ¹âÏË·ÓÉÆ÷£¬ÀûÓõÚÈý·½·þÎñµÄ×éºÏ£¬ÀýÈçGitHub¡¢P2PÍøÂçºÍC2·þÎñÆ÷£¬»¹¶Ô²¿ÃÅÓòÃûµÄ½âÎö²éÎʲÉÈ¡ÁËDNS-Over-HTTPSµÄ·½Ê½¡£×êÑÐÈËÔ±³Æ£¬Æù½ñΪֹ£¬PinkBotÌáÒéÁ˽ü°Ù´ÎDDoS¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/11/researchers-uncover-pink-botnet-malware.html
4¡¢Google°ä²¼Android 11Ô¸üУ¬×ܼƽ¨¸´39¸ö·ì϶
GoogleÔÚ±¾ÖÜÒ»°ä²¼ÁËAndroid 11Ô·ݵĸüУ¬×ܼƽ¨¸´39¸ö·ì϶¡£Õâ´Î¸üн¨¸´ÁËÒ»¸öÒѱ»ÔÚÒ°ÀûÓõÄ0day£¬ÊÇÓÉ¿ªÊͺóʹÓõ¼Öµı¾µØÌáȨ·ì϶CVE-2021-1048¡£´Ë±í£¬»¹½¨¸´Á˶à¸öÑϳÁµÄ·ì϶£¬Ô̺¬Ô¶³Ì´úÂëÖ´Ðзì϶CVE-2021-0918ºÍCVE-2021-0930£¬Ó°Ïì¸ßͨ×é¼þµÄCVE-2021-1924ºÍCVE-2021-1975£¬ÒÔ¼°Android TVÔ¶³Ì·þÎñÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶CVE-2021-0889µÈ¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/android-patches-exploited-kernel-bug/175931/
5¡¢BlackMatterÍÅ»ï°ä·¢ÆÅ×Ú·¨Âɲ¿ÃŵÄѹÁ¦½«ÖÕ³¡ÔËÓª
11ÔÂ1ÈÕ£¬ÀÕË÷ÔËÓªÍÅ»ïBlackMatterÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾Éϰ䲼ÐÂÎÅ£¬³ÆÆÅ×Ú·¨Âɲ¿ÃŵÄѹÁ¦ËûÃǽ«ÔÚ48Ó×ʱÄڹعØÕû¸ö»ù´¡ÉèÊ©¡£×êÑÐÍŶӰµÊ¾£¬Õâ¿ÉÄÜÓë×î½üµÄÒ»´Î¹ú¼Ê·¨ÂÉÐж¯Óйأ¬Õâ´ÎÐж¯¹²¿ÛÁôÁË12¸öÉæ¼°1800ÆðÀÕË÷¹¥»÷»î¶¯µÄÏÓÒÉÈË¡£È»¶ø£¬¼´±ãBlackMatter´Ë¿ÌÖÕ³¡ÆäÔËÓª£¬ÔÚ½«À´Ò²½«»áÒÔеÄÃû³Æ»Ø¹é£¬ÕýÈçBlackMatter×ÔÉí¾ÍÊÇDarkSideÔÚ¹¥»÷Colonial PipelineºóÆÅ×ÚѹÁ¦¸ÄÃû¶øÀ´µÄ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/124135/cyber-crime/blackmatter-ransomware-shutting-down-operations.html


¾©¹«Íø°²±¸11010802024551ºÅ