Ó¢¹ú¹ú·À²¿µÄ¹ú·ÀѧԺÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬ÒÉΪ±í¹úºÚ¿Í£»£»£»£»£»£»IoT¹«Ë¾Sierra WirelessϰȾÀÕË÷Èí¼þµ¼Ö³ö²úÖжÏ
°ä²¼¹¦·ò 2021-03-241.Ó¢¹ú¹ú·À²¿µÄ¹ú·ÀѧԺÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬ÒÉΪ±í¹úºÚ¿Í

Ó¢¹ú¹ú·À²¿µÄ¹ú·ÀѧԺÔâµ½ÑϳÁµÄ¹¥»÷£¬£¬£¬£¬£¬£¬ÒÉ»óÊǶíÂÞ˹µÈ±í¹úÈ¨ÊÆËùΪ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃѧԺλÓÚÅ£½ò¿¤Î÷ÄÏʲÀï·òÄÉÄ·£¬£¬£¬£¬£¬£¬ÖØÒªÎªÓ¢¹úÎä×°¶ÓÁÓ×¢¹«ÎñÔ±¡¢ÆäËûµ±²¿ÃÅÃź͹ú¶È·þÎñÈËÔ±Ìṩ¸ßµµ½ÌÓý¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷µ¼Ö¸ÃѧԺµÄ¹ÙÍøÖжϣ¬£¬£¬£¬£¬£¬ÓɳаüÉÌÔËÓªµÄITÍøÂç±»·ÛË飬£¬£¬£¬£¬£¬Ñ§ÌÃϵͳҲÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬¸ÃУԱ¹¤±»ÆÈʹÓÃÓ×ÎÒµçÄÔ½øÐа칫¡£¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬Ô¤¼Æ±ØÒª5Öܹ¦·òÄÜÁ¦ÆëÈ«¸´ÔÊÜÓ°ÏìµÄÍÆËã»úºÍ·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/115870/hacking/ministry-of-defence-hacked.html
2.ºÚ¿ÍÀûÓÃAccellionµÄFTAÖзì϶ÈëÇÖ¿ÇÅÆ²¢Î´Ó°ÏìÆäÍøÂç

ºÚ¿ÍÀûÓÃAccellionµÄFile Transfer Appliance£¨FTA£©Öзì϶ÈëÇÖÄÜÔ´¹«Ë¾¿ÇÅÆ¡£¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿£¿ÇÅÆ¹«Ë¾Ðû³Æ£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñ½öÓ°ÏìÁËFTAÉ豸£¬£¬£¬£¬£¬£¬ÓÉÓÚÎļþ´«Êä·þÎñÓëÆäËûÊý×Ö»ù´¡ÉèÊ©ÊǸôÀëµÄ£¬£¬£¬£¬£¬£¬Òò¶øÆäÖ÷ÌâITϵͳδÊܵ½ÈκÎÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜÒѾÇÔÈ¡²¿ÃÅÊý¾Ý£¬£¬£¬£¬£¬£¬Ô̺¬Ò»Ð©Ó×ÎÒÐÅÏ¢ÒÔ¼°¿ÇÅÆ¹«Ë¾ºÍÆäÀûÒæÓйØÕßµÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£Ö»¹Ü¿ÇÅÆ¹«Ë¾Ã»ÓÐÅû¶¹¥»÷ÕßµÄÉí·Ý£¬£¬£¬£¬£¬£¬µ«×êÑÐÈËÔ±´§Ä¦£¬£¬£¬£¬£¬£¬Õâ´Î¹¥»÷ÓëFIN11ºÚ¿ÍÍÅ»ïÓйء£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/energy-giant-shell-discloses-data-breach-after-accellion-hack/
3.IoT¹«Ë¾Sierra WirelessϰȾÀÕË÷Èí¼þµ¼Ö³ö²úÖжÏ

3ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬¼ÓÄôó¿ç¹úÎÞÏßͨѶÉ豸Ôì×÷ÉÌSierra WirelessϰȾÀÕË÷Èí¼þ£¬£¬£¬£¬£¬£¬ËùÓгö²ú»î¶¯±»ÆÈÖжϡ£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÖØÒªÏúÊÛͨѶÉ豸£¬£¬£¬£¬£¬£¬ÔÚ±±ÃÀ¡¢Å·ÖÞºÍÑÇÖÞ¾ùÉèÓÐÑз¢ÖÐÐÄ¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷µ¼Ö¹«Ë¾¹ÙÍøºÍÄÚ²¿ÔËÓªÔâµ½·ÛË飬£¬£¬£¬£¬£¬È«ÇòµÄ³ö²ú¹¤³§±»ÆÈ¹Ø¹Ø¡£¡£¡£¡£¡£¡£¡£¡£µ«ÒòÆäÄÚ²¿ITϵͳÓë¿Í»§µÄ·þÎñÖ®¼ä·Ö¸ô¿ªÁË£¬£¬£¬£¬£¬£¬ËùÒÔ¿Í»§²¢Î´Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚµÚÈý·½×¨¼ÒµÄÐÖúϵ÷²é´ËÊÂÎñ£¬£¬£¬£¬£¬£¬²¢2ÔÂ23ÈÕ³·»ØÁËÉϸöÔ°䲼µÄ2021ÄêµÚÒ»¼¾¶ÈÁìµ¼»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/115897/malware/sierra-wireless-ransomware.html
4.¹È¸èÅû¶ÀûÓøßͨоƬÖÐÊäÈëÑéÖ¤·ì϶µÄ¹¥»÷»î¶¯

¹È¸èÔÚÒ°·¢ÏÖÀûÓøßͨоƬÖÐÊäÈëÑéÖ¤·ì϶£¨CVE-2020-11261£©À´Õë¶ÔAndroidϵͳµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶λÓÚͼÐÎ×é¼þÖУ¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ8.4£¬£¬£¬£¬£¬£¬µ±ÌØÔìµÄÀûÓ÷¨Ê½ÒªÇó½Ó¼ûÉ豸ÖеĴóÁ¿ÄÚ´æÊ±£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÄÚ´æ·ÛËé¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÓÚ2020Äê8ÔÂ20ÈÕ±»Åû¶£¬£¬£¬£¬£¬£¬²¢ÓÚ2021Äê1Ôµõ½½¨¸´¡£¡£¡£¡£¡£¡£¡£¡£GoogleÔÚ3ÔÂ18ÈÕ¸üеÄ1Ô°²È«²¼¸æÖаµÊ¾£¬£¬£¬£¬£¬£¬CVE-2020-11261¿ÉÄÜÒѾ±»ÀûÓÃÌáÒéÕë¶ÔÐÔ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/03/warning-new-android-zero-day.html
5.ͨÓÃµçÆø£¨GE£©µÄURÉ豸´æÔÚ¶à¸öÑϳÁµÄ·ì϶

CISAÖÒ¸æÍ¨ÓÃµçÆø£¨GE£©µÄͨÓü̵çÆ÷£¨UR£©ÏµÁеçÔ´ÖÎÀíÉ豸ÖдæÔÚ9¸öÑϳÁµÄ·ì϶¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾³ÆURÉ豸ÊǼò»¯µçÔ´ÖÎÀíÒÔ±£»£»£»£»£»£»¤¹Ø¼ü×ʲúµÄ»ù´¡£¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬ÔÊÐíÓû§½ÚÔì¸÷ÀàÉ豸¿÷ËðµÄµç¹¦ÂÊÁ¿µÄÍÆËãÉ豸¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖÐ×îÑϳÁµÄ·ì϶ÊÇCVE-2021-27426£¬£¬£¬£¬£¬£¬ÓÉĬÈϱäÁ¿³õʼ»¯²»°²È«µ¼Ö£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÔ¶³ÌÀûÓø÷ìÏ¶ÈÆ¹ý½Ó¼ûÏÞ¶È¡£¡£¡£¡£¡£¡£¡£¡£Æä´ÎΪ¿ÉÓÃÀ´³ÁÆôURµÄCVE-2021-27430ºÍÊäÈëÑéÖ¤·ì϶£¨CVE-2021-27418ºÍCVE-2021-27420£©µÈ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/cisa-security-flaws-ge-power-management/164961/
6.Kaspersky°ä²¼2020ÄêICSÐÐÒµµÄÌ¬ÊÆ·ÖÎö»ã±¨

Kaspersky°ä²¼ÁË2020ÄêICSÐÐÒµµÄÌ¬ÊÆ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»ã±¨·ÖÎöÁËÓÃÓÚÉè¼Æ¡¢ÅäÖúÍÊØ»¤¹¤Òµ½ÚÔìÉ豸ºÍÈí¼þµÄÍÆËã»úËùÊܵ½µÄÍøÂçÍþв¡£¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬ÔÚ2020ÄêϰëÄ꣬£¬£¬£¬£¬£¬ÔÚICS¹¤³ÌºÍ¼¯³ÉÐÐÒµÖÐ39.3£¥µÄÍÆËã»úÊܵ½Á˶ñÒâÈí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬Óë2020ÄêÉϰëÄ꣨31.5£¥£©Ïà±Å×ÐËùÔö³¤£¬£¬£¬£¬£¬£¬ÆäÖй¹Öþ×Ô¶¯»¯¡¢Æû³µÔì×÷¡¢ÄÜԴʯÓͺÍÌìÈ»ÆøÐÐÒµÔâµ½µÄ¹¥»÷Ôö¶à¡£¡£¡£¡£¡£¡£¡£¡£2020ÄêϰëÄ꣬£¬£¬£¬£¬£¬Õë¶ÔÀ¶¡ÃÀÖÞ¡¢Öж«¡¢ÑÇÖ޺ͱ±ÃÀµÄ¹¥»÷´ÎÊýÔö¶à£¬£¬£¬£¬£¬£¬Õë¶Ô·ÇÖÞ¡¢¶íÂÞ˹ºÍÅ·Ö޵Ĺ¥»÷ÊýÁ¿ÓÐËùÏ÷¼õ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://ics-cert.kaspersky.com/reports/2021/03/17/threat-landscape-for-the-ics-engineering-and-integration-sector-2020/


¾©¹«Íø°²±¸11010802024551ºÅ