ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ17ÖÜ
°ä²¼¹¦·ò 2021-04-27> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2021Äê04ÔÂ19ÈÕÖÁ04ÔÂ25ÈÕ¹²ÊÕ¼°²È«·ì϶60¸ö£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇGoogle Chrome V8¶ÑÒç³ö´úÂëÖ´Ðзì϶£»£»£»£»£»FIBARO Home Center 2 8000¶Ë¿ÚδÊÚȨ½Ó¼û·ì϶£»£»£»£»£»Oracle Cloud Infrastructure Storage Gateway CVE-2021-2318´úÂëÖ´Ðзì϶£»£»£»£»£»Cisco SD-WAN vManage CVE-2021-1484²ÎÊý×¢Èë·ì϶£»£»£»£»£»Dell Technologies Dell PowerScale OneFSδÊÚȨ½Ó¼û·ì϶¡£¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇTwitterÔÚÈ«ÇòÁìÓòÄÚ·þÎñÖжϣ¬£¬£¬£¬£¬£¬£¬ÊÂÎñÈÔÔÚµ÷²éÖУ»£»£»£»£»AdvIntel·¢ÏÖRyukÀûÓÃKeeThiefµÈй¤¾ßµÄ¹¥»÷»î¶¯£»£»£»£»£»ÃÀ¹úÔì²Ã28¸öÓë¶íÂÞ˹¹¥»÷»î¶¯ÓйصļÓÃÜÇ®±ÒµØÖ·£»£»£»£»£»Oracle°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´¶à¸ö²úÆ·ÖеÄ390¸ö·ì϶£»£»£»£»£»McAfee°ä²¼2020ϰëÄêÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£¡£¡£
> ³ÁÒª°²È«·ì϶Áбí
1.Google Chrome V8¶ÑÒç³ö´úÂëÖ´Ðзì϶
Google Chrome V8ÒýÇæ´æÔÚ¶ÑÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇ󣬣¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÄܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_20.html
2.FIBARO Home Center 2 8000¶Ë¿ÚδÊÚȨ½Ó¼û·ì϶
FIBARO Home Center 2 8000¶Ë¿Ú´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿ÉδÊÚȨִÐжñÒâ²Ù×÷£¬£¬£¬£¬£¬£¬£¬Èç¹Ø»ú¡¢³ÁÆô»ò³ÁÆôµ½¸´Ôģʽ¡£¡£¡£¡£¡£¡£¡£
http://seclists.org/fulldisclosure/2021/Apr/27
3.Oracle Cloud Infrastructure Storage Gateway CVE-2021-2318´úÂëÖ´Ðзì϶
Oracle Cloud Infrastructure Storage Gateway´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÄܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://www.oracle.com/security-alerts/cpuapr2021.html
4.Cisco SD-WAN vManage CVE-2021-1484²ÎÊý×¢Èë·ì϶
Cisco SD-WAN vManageÉ豸ģ°åÅäÖôæÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿É×¢ÈëËÁÒâºÅÁ£¬£¬£¬£¬£¬£¬»ò¿É½øÐлؾø·þÎñ¹¥»÷¡£¡£¡£¡£¡£¡£¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vman-cmdinj-nRHKgfHX
5.Dell Technologies Dell PowerScale OneFSδÊÚȨ½Ó¼û·ì϶
Dell Technologies Dell PowerScale OneFS¶ÔÃÜÔ¿¹ýÆÚ´¦ÖôæÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬Õ¼ÓÐISI_PRIV_LOGIN_SSHµÄ¹ýÆÚÓû§¿É³ÖÐøµÇ¼ϵͳ¡£¡£¡£¡£¡£¡£¡£
https://www.dell.com/support/kbdoc/en-sg/000185202/dsa-2021-048-dell-emc-powerscale-onefs-security-update-for-multiple-vulnerabilities
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢TwitterÔÚÈ«ÇòÁìÓòÄÚ·þÎñÖжϣ¬£¬£¬£¬£¬£¬£¬ÊÂÎñÈÔÔÚµ÷²éÖÐ

TwitterÔÚÉÏÖÜÎåÍíÉϲúÉúÁ˵ÄÖжϣ¬£¬£¬£¬£¬£¬£¬²¢Ò»Ïò³ÖÐøµ½ÖÜÁùÉÏÎç¡£¡£¡£¡£¡£¡£¡£Óû§·´Ó³µÄÎÊÌâÔ̺¬ÎÞ·¨Õý³£ËÑË÷¡¢ÄÚÈÝÎÞ·¨¼ÓÔØ¡¢Í¼ÏñÎÞ·¨ÏÔʾÉõÖÁÎÞ·¨µÇÂ¼ÍøÕ¾¡£¡£¡£¡£¡£¡£¡£¾Ýͳ¼ÆÕâ´ÎÖжÏÓ°ÏìÁËÈ«ÇòÁìÓòÄÚµÄÓû§£¬£¬£¬£¬£¬£¬£¬µ«ÂÞÂíÄáÑǵÈһЩ¹ú¶ÈËÆºõ²¢Î´Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£Twitter°µÊ¾Õâ´ÎÖжÏÊÇÆä·þÎñÆ÷ÉϵÄÎÊÌ⣬£¬£¬£¬£¬£¬£¬²¢ÒѾÔÚÖÂÁ¦½â¾öʹËùÓо¡¿ì¸´ÔÕý³££¬£¬£¬£¬£¬£¬£¬µ«ÊDz¢Î´ÌṩÓйØÕâ´Î¹ÊÕϵľßÌåÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/technology/twitter-is-suffering-from-another-worldwide-outage-today/
2¡¢AdvIntel·¢ÏÖRyukÀûÓÃKeeThiefµÈй¤¾ßµÄ¹¥»÷»î¶¯

°²È«¹«Ë¾Advanced Intelligence·¢ÏÖRyukÀûÓÃKeeThiefµÈй¤¾ßµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±¹Û²ìµ½£¬£¬£¬£¬£¬£¬£¬½ñÄêRyukÀÕË÷Èí¼þ¸ü¶àµØÒÀÀµÓÚ¶ÔRDP¶³öµÄÖ÷»ú½øÐдó¹æÄ£±©Á¦ÆÆ½âºÍÃÜÂëÅçÈ÷¹¥»÷À´ÈëÇÖÖ¸±êÍøÂç¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬ÔÚÕâЩ¹¥»÷Öл¹·¢ÏÖÁËм¼Êõ£¬£¬£¬£¬£¬£¬£¬Ô̺¬Ê¹ÓôÓKeePassÃÜÂëÖÎÀíÆ÷ÇÔȡƾ֤µÄ¿ªÔ´¹¤¾ßKeeThief£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°×°ÖñãЯʽ°æ±¾µÄNotepad ++£¬£¬£¬£¬£¬£¬£¬ÔÚPowerShellÖ´ÐÐÊÜÏÞµÄϵͳÉÏÔËÐÐPowerShell¾ç±¾¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ryuk-ransomware-operation-updates-hacking-techniques/
3¡¢ÃÀ¹úÔì²Ã28¸öÓë¶íÂÞ˹¹¥»÷»î¶¯ÓйصļÓÃÜÇ®±ÒµØÖ·

ÃÀ¹úµ±¾ÖÔÚ±¾ÖÜÔì²ÃÁË28¸ö¼ÓÃÜÇ®±ÒµØÖ·£¬£¬£¬£¬£¬£¬£¬¾Ý³ÆÕâЩµØÖ·ÓëÉæ¼°¶íÂÞË¹ÍøÂç¹¥»÷»ò×ÌÈÅÑ¡¾Ù»î¶¯µÄ×éÖ¯ºÍÓ×ÎÒÓйء£¡£¡£¡£¡£¡£¡£ÃÀ¹úµ±¾Ö»¹°µÊ¾£¬£¬£¬£¬£¬£¬£¬ÕâЩ»î¶¯ÊÇÓɶíÂÞ˹Áª¹ú°²È«¾Ö£¨FSB£©ºÍ¶íÂÞË¹ÖØÒªµý±¨¾Ö£¨GRU£©·¢Õ¹µÄ£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÒѾµÃµ½ÁËÁù¼ÒÓë¶íÂÞ˹ÓкÏ×÷µÄ¹«Ë¾µÄÔ®ÊÖ¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬ÃûΪSESµÄ°Í»ù˹̹¹«Ë¾Ïò»¥ÁªÍø×êÑлú¹¹(IRA)ÌṩÐéαÉí·ÝÀ´ÌÓ±ÜÃÀ¹úµÄÔì²Ã£¬£¬£¬£¬£¬£¬£¬Æä¼ÓÃÜÇ®±ÒµØÖ·ÒÑͨ¹ý26900±ÊÂòÂôÊÕµ½Á˼ÛÖµ³¬¹ý250ÍòÃÀÔªµÄÊý×ÖÇ®±Ò¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/us-sanctions-cryptocurrency-addresses-linked-to-russian-cyberactivities/
4¡¢Oracle°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´¶à¸ö²úÆ·ÖеÄ390¸ö·ì϶

OracleÒÑÓÚ2021Äê4Ô°䲼Á˳ÁÒª²¹¶¡¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´Á˶à¸ö²úÆ·ÖеÄ390¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ½ÏΪÑϳÁµÄ·ì϶ΪOracleͨѶÀûÓ÷¨Ê½ÖÐCVSSÆÀ·ÖΪ9.8µÄCVE-2020-11612¡¢CVE-2019-0228¡¢CVE-2020-11612ºÍCVE-2020-28052£¬£¬£¬£¬£¬£¬£¬Instantis EnterpriseTrackÖеÄCVE-2019-0219£¬£¬£¬£¬£¬£¬£¬ÆóÒµÖÎÀíÆ÷»ù´¡Æ½Ì¨ÖеÄCVE-2019-17195ÒÔ¼°OracleóÒ×ÖÇÄÜÆóÒµ°æÖеÄCVE-2020-9480µÈ·ì϶¡£¡£¡£¡£¡£¡£¡£OracleÇ¿ÁÒ½¨Òé¿Í»§¾¡¿ìÀûÓð²È«²¹¶¡¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.oracle.com/security-alerts/cpuapr2021.html
5¡¢McAfee°ä²¼2020ϰëÄêÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨

McAfee°ä²¼ÁË2020ϰëÄêÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£»ã±¨³Æ£¬£¬£¬£¬£¬£¬£¬2020ÄêQ4¾ùÔÈÿ·ÖÖӿɼì²âµ½648¸öÍþв£¬£¬£¬£¬£¬£¬£¬±ÈQ3Ôö³¤ÁË10£¥£¬£¬£¬£¬£¬£¬£¬±ÈQ2Ôö³¤ÁË40£¥£¬£¬£¬£¬£¬£¬£¬Ê¼ÖճʳÖÐøÉÏÉýÇ÷Ïò¡£¡£¡£¡£¡£¡£¡£»ã±¨»¹Ö¸³ö2020ÄêϰëÄêÔÚÒ°±í·¢ÏֵĹ¥»÷ÊýÁ¿¼¤ÔöµÄÖØÒªÔÒòÊÇÒÔCOVIDΪÖ÷ÌâµÄ¹¥»÷ºÍPowerShellľÂíµÄ¼¤Ôö£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°SolarWinds·ì϶ºÍSunburst¶ñÒâÈí¼þµÄ³ÖÐøÊæÕ¹¡£¡£¡£¡£¡£¡£¡£Ïà±Å×ÚQ3 £¬£¬£¬£¬£¬£¬£¬Q4µÄPowerShellÊýÁ¿Ôö³¤ÁË208%£¬£¬£¬£¬£¬£¬£¬Õë¶ÔofficeµÄ¶ñÒâÈí¼þÊýÁ¿Ôö³¤ÁË199%¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.mcafee.com/enterprise/en-us/lp/threats-reports/apr-2021.html


¾©¹«Íø°²±¸11010802024551ºÅ