΢Èí°ä²¼µÄPrintNightmareµÄ´¹Î£¸üпɱ»Èƹý £»£»£»£»£»£»£»¶íÂÞ˹ºÚ¿Í×éÖ¯APT29ÓÃSynnex¹¥»÷ÃÀ¹ú¹²ºÍµ³RNC

°ä²¼¹¦·ò 2021-07-08

1.΢Èí°ä²¼µÄPrintNightmareµÄ´¹Î£¸üпɱ»Èƹý


1.jpg


Microsoft°ä²¼KB5004945´¹Î£°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´Ó°ÏìËùÓÐWindows Print Spooler·þÎñÖб»»ý¼«ÀûÓõÄPrintNightmare 0day¡£¡£¡£ ¡£¡£¡£¡£¡£¸ÃÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-34527£©ÔÊÐí¹¥»÷ÕßʹÓÃSYSTEMȨÏÞµÄÔ¶³ÌÖ´ÐдúÂë²¢ÆëÈ«ÊÕÊÜÖ¸±ê·þÎñÆ÷¡£¡£¡£ ¡£¡£¡£¡£¡£ÔÚ¸üа䲼ºó£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢Ïָò¹¶¡½ö½¨¸´ÁËÉæ¼°Ô¶³Ì´úÂëÖ´ÐеÄ×é¼þ£¬£¬£¬£¬£¬£¬£¬Òò¶ø×êÑÐÈËÔ±ÆðÍ·Åú¸Ä·ì϶ÀûÓ÷¨Ê½²¢²âÊÔ²¹¶¡£¬£¬£¬£¬£¬£¬£¬È·¶¨Äܹ»ÆëÈ«ÈÆ¹ýÕû¸ö²¹¶¡À´ÊµÏÖ±¾µØÌáȨºÍÔ¶³Ì´úÂëÖ´ÐС£¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-pushes-emergency-update-for-windows-printnightmare-zero-day/


2.Kaspersky·¢ÏÖWildPressureÕë¶ÔmacOSµÄ¹¥»÷»î¶¯


2.jpg


KasperskyµÄ×êÑÐÈËÔ±·¢ÏÖWildPressureÔÚ×î½üµÄ¹¥»÷»î¶¯ÖÐÔö³¤ÁËÕë¶ÔmacOSµÄ¶ñÒâÈí¼þ±äÌå¡£¡£¡£ ¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÓÚ2020Äê3Ô³õ´Î·¢ÏÖ¸ÃÍŻ£¬£¬£¬£¬£¬£¬ÆäʱWildPressureʹÓÃÁËC++°æ±¾µÄMilumľÂí¹¥»÷Öж«µÄ×éÖ¯¡£¡£¡£ ¡£¡£¡£¡£¡£ÔÚ½üÆÚÕë¶ÔÄÜÔ´ÐÐÒµµÄ¹¥»÷ÖУ¬£¬£¬£¬£¬£¬£¬MilumÒѾ­Í¨¹ýPyInstaller°ü½øÐÐÁ˳Á×飬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬ÁËÓëWindowsºÍmacOSϵͳ¼æÈݵÄľÂí·¨Ê½£¬£¬£¬£¬£¬£¬£¬±»ºÚµÄÍøÕ¾¿É±»APT×éÖ¯ÓÃÀ´ÏÂÔØºÍÉÏ´«Îļþ²¢Ö´ÐкÅÁî¡£¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/macos-wildpressure-apt/167606/


3.¶íÂÞ˹ºÚ¿Í×éÖ¯APT29ÀûÓÃSynnex¹¥»÷ÃÀ¹ú¹²ºÍµ³RNC


3.jpg


ÖªÁµÈËʿй©£¬£¬£¬£¬£¬£¬£¬ÉÏÖܶíÂÞ˹ºÚ¿Í×éÖ¯APT29£¨»òCozy Bear£©ÀûÓÃSynnex¹¥»÷ÁËÃÀ¹ú¹²ºÍµ³È«¹úίԱ»á£¨RNC£©¡£¡£¡£ ¡£¡£¡£¡£¡£¸ÃÍÅ»ïÓë¶íÂÞ˹µÄ±í¹úµý±¨»ú¹¹ÓйØÁª£¬£¬£¬£¬£¬£¬£¬´ËÇ°Ôø±»Ö¸¿ØÔÚ2016ÄêÈëÇÖÁËÃñÖ÷µ³È«¹úίԱ»á¡£¡£¡£ ¡£¡£¡£¡£¡£µ«ÊÇ£¬£¬£¬£¬£¬£¬£¬RNCÒ»ÔÙ·ñ¶¨ÆäÔâµ½Á˺ڿÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬²¢³ÆÃ»ÓÐÈκÎÓйØRNCµÄÐÅÏ¢±»µÁ¡£¡£¡£ ¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬£¬RNCµÃÖªÆäµÚÈý·½¹©¸øÉÌSynnex Corp.Ôâµ½Á˹¥»÷£¬£¬£¬£¬£¬£¬£¬²¢°µÊ¾Æä·¢ÏÖºóÁ¢¼´²»ÈÝÁËSynnexÕÊ»§¶ÔËûÃÇÔÆ»·¾³µÄËùÓнӼû¡£¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bloomberg.com/news/articles/2021-07-06/russian-state-hackers-breached-republican-national-committee


4.CISA°ä²¼Õë¶Ô·ÉÀûÆÖVue PACSÖжà¸ö·ì϶µÄ°²È«Õ÷ѯ


4.jpg


ÃÀ¹úCISA°ä²¼ÁËÕë¶Ô·ÉÀûÆÖÁÙ´²ºÏ×÷ƽ̨ÃÅ»§(Vue PACS)ÖÐ15¸ö·ì϶µÄ°²È«Õ÷ѯ¡£¡£¡£ ¡£¡£¡£¡£¡£CISA°µÊ¾£¬£¬£¬£¬£¬£¬£¬ÕâЩ·ì϶ÖеÄ7¸ö´æÔÚÓÚ·ÉÀûÆÖ²úÆ·£¬£¬£¬£¬£¬£¬£¬¶øÆäÓà·ì϶´æÔÚÓÚµÚÈý·½×é¼þ£¬£¬£¬£¬£¬£¬£¬ÈçRedis¡¢7-Zip¡¢OracleÊý¾Ý¿â¡¢jQuery¡¢PythonºÍApache Tomcat£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁË·ÉÀûÆÖVue PACS¶à¸ö²úÆ·£¬£¬£¬£¬£¬£¬£¬Ô̺¬MyVue¡¢Vue SpeechºÍVue Motion¡£¡£¡£ ¡£¡£¡£¡£¡£ÆäÖнÏΪÑϳÁµÄ·ì϶ÊÇÊäÈëÑéÖ¤²»µ±·ì϶£¨CVE-2020-1938£©¡¢»ùÓÚ²Ö¿âµÄ»º³åÇøÒç¶Âí½Å£¨CVE-2018-12326ºÍCVE-2018-11218£©¡¢Éí·ÝÈÏÖ¤²»µ±·ì϶£¨CVE-2020-4670£©ºÍCVE-2018-8014£¬£¬£¬£¬£¬£¬£¬ËüÃǵÄCVSSÆÀ·Ö¾ùΪΪ9.8¡£¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ics/advisories/icsma-21-187-01


5.SonicWall°²È«¸üн¨¸´ÆäNSMÉ豸ÖеĺÅÁî×¢Èë·ì϶


5.jpg


SonicWall°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´ÆäÍøÂ簲ȫÖÎÀíÆ÷ (NSM) É豸ÖеĺÅÁî×¢Èë·ì϶¡£¡£¡£ ¡£¡£¡£¡£¡£¸Ã·ì϶±»×·×ÙΪCVE-2021-20026£¬£¬£¬£¬£¬£¬£¬ÆÀ·ÖΪ8.8£¬£¬£¬£¬£¬£¬£¬¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÀûÓÃÌØÔìµÄHTTPÒªÇóÖ´ÐкÅÁî×¢Èë¡£¡£¡£ ¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏìÁËNSM 2.2.0-R10-H1¼°¸üÔç°æ±¾£¬£¬£¬£¬£¬£¬£¬°²È«³§Ḛ́䲼ÁËNSM 2.2.1-R6ºÍ2.2.1-R6£¨¼ÓÇ¿£©°æ±¾½¨¸´Á˸÷ì϶¡£¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/119767/security/sonicwall-fixes-cve-2021-20026-flaw.html


6.Å·ÖÞENISA°ä²¼Õë¶ÔÖÐÓׯóÒµµÄÍøÂ簲ȫָÄÏ


6.jpg


Å·ÃËÍøÂçºÍÐÅÏ¢°²È«¾Ö£¨ENISA£©°ä²¼ÁËÕë¶ÔÖÐÓׯóÒµµÄÍøÂ簲ȫָÄÏ¡£¡£¡£ ¡£¡£¡£¡£¡£¸ÃÖ¸ÄÏΪÖÐÓ×ÐÍÆóÒµÌṩ¹ØÓÚÈôºÎÌá¸ßÆä»ù´¡ÉèÊ©ºÍÒµÎñ°²È«ÐÔµÄ12Ïî¸ß¼¶½¨Ò飬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬£ºÔì¾ÍÓÅÁ¼µÄÍøÂ簲ȫÎÄ»¯¡¢ÌṩÊʵ±µÄ°²È«Åàѵ¡¢È·±£ÓÐЧµÄµÚÈý·½ÖÎÀí¡¢Ôì¶©±äÂÒÏìÓ¦´òË㡢ȷ±£°²È«µÄ½Ó¼ûϵͳ¡¢È·±£É豸°²È«¡¢± £»£»£»£»£»£»£»¤ÍøÂ簲ȫ¡¢Ìá¸ßÎïÀí°²È«ÐÔ¡¢È·±£±¸·Ý°²È«¡¢²Î¼ÓÔÆÍÆË㡢ȷ±£ÔÚÏßÍøÕ¾°²È«£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°×·ÇóºÍ·ÖÏíÐÅÏ¢¡£¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.enisa.europa.eu/publications/cybersecurity-guide-for-smes