ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ28ÖÜ
°ä²¼¹¦·ò 2021-07-12> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2021Äê07ÔÂ05ÈÕÖÁ07ÔÂ11ÈÕ¹²ÊÕ¼°²È«·ì϶61¸ö£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇAdvantech WebAccess Node BwFreRPTÕ»Òç³ö´úÂëÖ´Ðзì϶£»£»£»£»£»Microsoft Teams ElectronJSÖ¡³Á¶¨Ïò´úÂëÖ´Ðзì϶£»£»£»£»£»NPort IA5000A-I/O Series CVE-2021-32968»Ø¾ø·þÎñ·ì϶£»£»£»£»£»Phoenix Contact Automationworx BCPÎļþÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶£»£»£»£»£»Siemens Simcenter Femap FEMAPÔ½½çд´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÈðµäÁ¬Ëø³¬ÊÐCoopÒòKaseya¹©¸øÁ´¹¥»÷¹Ø¹ØÊý°Ù¼ÒÃŵꣻ£»£»£»£»ÃÀ¹ú±£ÏÕ¹«Ë¾AJG³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬¿Í»§ÐÅϢй¶£»£»£»£»£»CISAºÍFBI°ä²¼Õë¶ÔKaseya¹©¸øÁ´¹¥»÷Êܺ¦ÕßµÄÖ¸ÄÏ£»£»£»£»£»Î¢Èí°ä²¼µÄPrintNightmareµÄ´¹Î£¸üпɱ»Èƹý£»£»£»£»£»Kaspersky·¢ÏÖWildPressureÕë¶ÔmacOSµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£¡£¡£
> ³ÁÒª°²È«·ì϶Áбí
1.Advantech WebAccess Node BwFreRPTÕ»Òç³ö´úÂëÖ´Ðзì϶
Advantech WebAccess Node BwFreRPT´æÔÚÕ»Òç¶Âí½Å£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄ0x2711 IOCTLÒªÇ󣬣¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-779/
2.Microsoft Teams ElectronJSÖ¡³Á¶¨Ïò´úÂëÖ´Ðзì϶
Microsoft Teams ElectronJSÖ¡±£»£»£»£»£»¤´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâÒªÇ󣬣¬£¬£¬£¬£¬¿É³Á¶¨Ïò¶ñÒâÒ³Ãæ£¬£¬£¬£¬£¬£¬½Ó¼ûÄÚ²¿ÀûÓöÔÏ󣬣¬£¬£¬£¬£¬ÌáÉýȨÏÞ¡£¡£¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-772/
3.NPort IA5000A-I/O Series CVE-2021-32968»Ø¾ø·þÎñ·ì϶
NPort IA5000A-I/O SeriesÄÚ²¿WEB·þÎñ´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâÒªÇ󣬣¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£¡£¡£¡£¡£¡£¡£¡£
https://us-cert.cisa.gov/ics/advisories/icsa-21-187-01
4.Phoenix Contact Automationworx BCPÎļþÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶
Phoenix Contact Automationworx BCPÎļþ´¦ÖôæÔÚÄÚ´æ·ÛËé·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-782/
5.Siemens Simcenter Femap FEMAPÔ½½çд´úÂëÖ´Ðзì϶
Siemens Simcenter Femap FEMAPÎļþ´¦ÖôæÔÚÔ½½çд·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-781/
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢ÈðµäÁ¬Ëø³¬ÊÐCoopÒòKaseya¹©¸øÁ´¹¥»÷¹Ø¹ØÊý°Ù¼ÒÃŵê

ÈðµäÁ¬Ëø³¬ÊÐCoop³ÆÆäÔâµ½ÁËKaseya¹©¸øÁ´¹¥»÷£¬£¬£¬£¬£¬£¬Êý°Ù¼ÒÃÅµê¹Ø¹Ø¡£¡£¡£¡£¡£¡£¡£CoopµÄ½²»°È˰µÊ¾ÆäÓÚÉÏÖÜÎåÍíÉÏ6µã30·Ö×óÓÒ·¢ÏÖÓÐÉÙÊýÃŵê³öÏÖÎÊÌ⣬£¬£¬£¬£¬£¬µ«Ò»Ò¹Ö®ºóÆä´ó²¿ÃÅÃŵ궼±»ÆÈ¹Ø¹Ø£¬£¬£¬£¬£¬£¬Ô̺¬ÊÕÒøÌ¨ºÍ×ÔÖ÷½áÕËÔÚÄÚµÄÕû¸öÖ§¸¶ÏµÍ³¶¼ÖжÏÁË¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬CoopûÓÐʹÓÃKesayaÈí¼þ£¬£¬£¬£¬£¬£¬ÓÉÓÚËûÃǵÄÒ»¸öÈí¼þÌṩÉÌʹÓÃÁ˸ÃÈí¼þ¶øÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£°²È«¹«Ë¾HuntressLabs³Æ£¬£¬£¬£¬£¬£¬Õâ´Î¹¥»÷»î¶¯µÄµ÷²éÈÔÔÚ½øÐÐÖУ¬£¬£¬£¬£¬£¬ÖÁÉÙÓÐ200¼Ò×éÖ¯Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/119663/cyber-crime/coop-supermarket-kaseya-ransomware-attack.html
2¡¢ÃÀ¹ú±£ÏÕ¹«Ë¾AJG³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬¿Í»§ÐÅϢй¶

ÃÀ¹úArthur J. Gallagher (AJG) ³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬¿Í»§ÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£AJGÊÇÃÀ¹úµÄÈ«Çò±£ÏÕ¾¼ÍºÍ·çÏÕÖÎÀí¹«Ë¾£¬£¬£¬£¬£¬£¬×÷ΪȫÇò×î´óµÄ±£ÏÕ¾¼ÍÉÌÖ®Ò»£¬£¬£¬£¬£¬£¬ÒµÎñ±é¼°49¸ö¹ú¶È/µØÓò¡£¡£¡£¡£¡£¡£¡£¹¥»÷²úÉúÔÚ2020Äê6ÔÂ3ÈÕÖÁ2020Äê9ÔÂ26ÈÕÆÚ¼ä£¬£¬£¬£¬£¬£¬ÆäÔÚ2020Äê9ÔÂ28ÈÕÅû¶¸ÃÊÂÎñ²¢³ÆÃ»º±¼û¾Ýй¶¡£¡£¡£¡£¡£¡£¡£µ«ÔÚËæºóµÄµ÷²é·¢ÏÖ£¬£¬£¬£¬£¬£¬7376È˵ÄÃô¸ÐÐÅϢй¶£¬£¬£¬£¬£¬£¬Ô̺¬Éç»á°²È«ºÅÂë»ò˰ºÅ¡¢¼ÝÕÕ¡¢»¤ÕÕ¡¢µ®ÉúÈÕÆÚ¡¢Óû§ÃûºÍÃÜÂë¡¢Ô±¹¤¼ø±ðºÅ¡¢²ÆÕþÕË»§»òÐÅÓþ¿¨ÐÅÏ¢¡¢µç×ÓÊðÃû¡¢Ò½ÁÆÐÅÏ¢¡¢±£ÏÕÐÅÏ¢ÒÔ¼°ÉúÎï¼ø±ðÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/us-insurance-giant-ajg-reports-data-breach-after-ransomware-attack/
3¡¢CISAºÍFBI°ä²¼Õë¶ÔKaseya¹©¸øÁ´¹¥»÷Êܺ¦ÕßµÄÖ¸ÄÏ

CISAºÍFBI½áºÏ°ä²¼ÁËÕë¶ÔÊܵ½Kaseya¹©¸øÁ´¹¥»÷Ó°ÏìµÄÊܺ¦ÕßµÄÖ¸ÄÏ¡£¡£¡£¡£¡£¡£¡£ÕâÁ½¸ö»ú¹¹½¨Òé×é֯ʹÓÃKaseyaÌṩµÄ¼ì²â¹¤¾ßÀ´²é³ËûÃǵÄϵͳÊÇ·ñ´æÔÚÈëÇÖ¼£Ï󣬣¬£¬£¬£¬£¬²¢ÆôÓöà³É·ÖÉí·ÝÑéÖ¤(MFA)¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬×éÖ¯»¹Ó¦Ê¹Óð×Ãûµ¥À´±í²¿ÏÞ¶È¶ÔÆäÄÚ²¿×ʲúµÄ½Ó¼û£¬£¬£¬£¬£¬£¬²¢Ê¹Ó÷À»ðǽ»òVPN±£»£»£»£»£»¤ÆäÔ¶³Ì¼à¿Ø¹¤¾ßµÄÖÎÀí½çÃæ¡£¡£¡£¡£¡£¡£¡£¶øÊÜÓ°ÏìµÄMSP¿Í»§±ØÒªÈ·±£±¸·ÝÊÇ×îÐµģ¬£¬£¬£¬£¬£¬²¢ÇÒÁ¢¼´×°Öù©¸øÉÌÌṩµÄ×îеIJ¹¶¡¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/119728/cyber-crime/cisa-fbi-guidance-kaseya-attack.html
4¡¢Î¢Èí°ä²¼µÄPrintNightmareµÄ´¹Î£¸üпɱ»Èƹý

Microsoft°ä²¼KB5004945´¹Î£°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´Ó°ÏìËùÓÐWindows Print Spooler·þÎñÖб»»ý¼«ÀûÓõÄPrintNightmare 0day¡£¡£¡£¡£¡£¡£¡£¸ÃÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-34527£©ÔÊÐí¹¥»÷ÕßʹÓÃSYSTEMȨÏÞµÄÔ¶³ÌÖ´ÐдúÂë²¢ÆëÈ«ÊÕÊÜÖ¸±ê·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£ÔÚ¸üа䲼ºó£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢Ïָò¹¶¡½ö½¨¸´ÁËÉæ¼°Ô¶³Ì´úÂëÖ´ÐеÄ×é¼þ£¬£¬£¬£¬£¬£¬Òò¶ø×êÑÐÈËÔ±ÆðÍ·Åú¸Ä·ì϶ÀûÓ÷¨Ê½²¢²âÊÔ²¹¶¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬È·¶¨Äܹ»ÆëÈ«ÈÆ¹ýÕû¸ö²¹¶¡À´ÊµÏÖ±¾µØÌáȨºÍÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-pushes-emergency-update-for-windows-printnightmare-zero-day/
5¡¢Kaspersky·¢ÏÖWildPressureÕë¶ÔmacOSµÄ¹¥»÷»î¶¯

KasperskyµÄ×êÑÐÈËÔ±·¢ÏÖWildPressureÔÚ×î½üµÄ¹¥»÷»î¶¯ÖÐÔö³¤ÁËÕë¶ÔmacOSµÄ¶ñÒâÈí¼þ±äÌå¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÓÚ2020Äê3Ô³õ´Î·¢ÏÖ¸ÃÍŻ£¬£¬£¬£¬£¬ÆäʱWildPressureʹÓÃÁËC++°æ±¾µÄMilumľÂí¹¥»÷Öж«µÄ×éÖ¯¡£¡£¡£¡£¡£¡£¡£ÔÚ½üÆÚÕë¶ÔÄÜÔ´ÐÐÒµµÄ¹¥»÷ÖУ¬£¬£¬£¬£¬£¬MilumÒѾͨ¹ýPyInstaller°ü½øÐÐÁ˳Á×飬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬ÁËÓëWindowsºÍmacOSϵͳ¼æÈݵÄľÂí·¨Ê½£¬£¬£¬£¬£¬£¬±»ºÚµÄÍøÕ¾¿É±»APT×éÖ¯ÓÃÀ´ÏÂÔØºÍÉÏ´«Îļþ²¢Ö´ÐкÅÁî¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/macos-wildpressure-apt/167606/


¾©¹«Íø°²±¸11010802024551ºÅ