ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ7ÖÜ

°ä²¼¹¦·ò 2021-02-18

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2021Äê02ÔÂ08ÈÕÖÁ02ÔÂ14ÈÕ¹²ÊÕ¼°²È«·ì϶62¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇHPE Apollo 70 System BMC¹Ì¼þLibifc.so WebStartFlash»º³åÇøÒç¶Âí½Å £»£»£»£»£»Micro Focus Operation Bridge´úÂëÖ´Ðзì϶ £»£»£»£»£»Microsoft Windows DNS·þÎñÆ÷Ô¶³Ì´úÂëÖ´Ðзì϶ £»£»£»£»£»Advantech iView SQL×¢Èë·ì϶ £»£»£»£»£»Adobe Animate CVE-2021-21052Ô½½çд´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇMozilla°ä²¼Firefox°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´NTFS°Ü»µÎÊÌâ £»£»£»£»£»ÏÂÔØ³¬¹ý200Íò´ÎµÄChromeÀ©´óGreat SuspenderÔ̺¬¶ñÒâ´úÂë £»£»£»£»£»WordPressµÄ²å¼þÖÐ佨¸´µÄXSS·ì϶¿ÉÓ°ÏìÊýÍò¸öÍøÕ¾ £»£»£»£»£»ÀÕË÷ÍÅ»ïZiggy°ä·¢Í˳ö£¬£¬£¬£¬£¬£¬£¬£¬²¢°ä²¼Æä½âÃÜÃÜÔ¿ £»£»£»£»£»Kaspersky°ä²¼2020ÄêÕÊ»§ÊÕÊܹ¥»÷ÊÂÎñµÄ»ØÊ׻㱨¡£¡£¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£¡£


> ³ÁÒª°²È«·ì϶Áбí


1.HPE Apollo 70 System BMC¹Ì¼þLibifc.so WebStartFlash»º³åÇøÒç¶Âí½Å


HPE Apollo 70 System BMC¹Ì¼þLibifc.so WebStartFlash´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ £»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£

https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf04080en_us


2.Micro Focus Operation Bridge´úÂëÖ´Ðзì϶


Micro Focus Operation Bridge´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£

https://softwaresupport.softwaregrp.com/doc/KM03775947


3.Microsoft Windows DNS·þÎñÆ÷Ô¶³Ì´úÂëÖ´Ðзì϶


Microsoft Windows DNS·þÎñÆ÷´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿Éʹϵͳ±ÀÀ £»£»£»£»£»òÕßÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-24078


4.Advantech iView SQL×¢Èë·ì϶


Advantech Iview´æÔÚSQL×¢Èë·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄSQLÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬²Ù×÷Êý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£

https://us-cert.cisa.gov/ics/advisories/icsa-21-040-02


5.Adobe Animate CVE-2021-21052Ô½½çд´úÂëÖ´Ðзì϶


Adobe Animate´¦ÖÃÎļþ´æÔÚÔ½½çд·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶¹¹½¨¶ñÒâÎļþ£¬£¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ £»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£

https://helpx.adobe.com/security/products/animate/apsb21-11.html


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢Mozilla°ä²¼Firefox°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´NTFS°Ü»µÎÊÌâ


1.png


Mozilla°ä²¼ÁËFirefox 85.0.1£¬£¬£¬£¬£¬£¬£¬£¬½¨¸´Á˿ɴ¥·¢NTFS°Ü»µµÄÎÊÌâ¡£¡£¡£¡£¡£¡£Windows 10ºÍWindows XPÖдæÔÚÔÊÐí·ÇÌØÈ¨Óû§½«NTFS·ÖÇøÏóÕ÷Ϊ¡°ÔࡱµÄ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬Õâ»áµ¼ÖÂÇý¶¯Æ÷°Ü»µ²¢±ØÒªÓû§³ÁÐÂÆô¶¯ÒÔ½¨¸´¡£¡£¡£¡£¡£¡£FirefoxÄܹ»Í¨¹ý½Ó¼ûÌØÔìõè¾¶À´´¥·¢NTFS°Ü»µÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°¸Ãõè¾¶Òѱ»²»ÈÝ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬Õâ´Î°²È«¸üл¹½¨¸´Á˶à¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÈçmacOSÉ豸ÉÏʹÓÃSPNEGO¶ÔÍøÕ¾½øÐÐÉí·ÝÑé֤ʱµÄ±ÀÀ£ÎÊÌâµÈ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/software/mozilla-fixes-windows-10-ntfs-corruption-bug-in-firefox/


2¡¢ÏÂÔØ³¬¹ý200Íò´ÎµÄChromeÀ©´óGreat SuspenderÔ̺¬¶ñÒâ´úÂë


2.png


Ê¢ÐеÄChromeÀ©´óThe Great SuspenderÔ̺¬¶ñÒâ´úÂ룬£¬£¬£¬£¬£¬£¬£¬Òѱ»ÏÂÔØ³¬¹ý200Íò´Î¡£¡£¡£¡£¡£¡£¸ÃÀ©´óÓÃÓÚÔÝͣδʹÓõÄÑ¡Ï£¬£¬£¬£¬£¬£¬£¬£¬²¢½«ÔÝÍ£µÄÒ³Ãæ´úÌæÎª¿ÕÈ±Ò³ÃæÖ±µ½Óû§ÔÙ´ÎʹÓÃΪֹ£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚ½Ú¼ó×ÊÔ´¡£¡£¡£¡£¡£¡£Google×êÑÐÈËÔ±·¢ÏÖ¿ª·¢ÕßÔö³¤ÁËÐÂÖ°ÄÜ£¬£¬£¬£¬£¬£¬£¬£¬¿É´ÓÔ¶³Ì·þÎñÆ÷Ö´ÐÐËÁÒâ´úÂ룬£¬£¬£¬£¬£¬£¬£¬ÕâÄܱ»ÓÃÀ´½øÐиæ°×ڲƭºÍ¸ú×ٵȶñÒâ»î¶¯¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬GoogleÒÑÓÚÉÏÖÜËĽ«¸ÃÀ©´ó´ÓÍøÉÏÉ̵êÖÐɾ³ý£¬£¬£¬£¬£¬£¬£¬£¬»¹½«Æä´ÓÓû§µÄÍÆËã»úÖнûÓᣡ£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/the-great-suspender-chrome-extension-malware/


3¡¢WordPressµÄ²å¼þÖÐ佨¸´µÄXSS·ì϶¿ÉÓ°ÏìÊýÍò¸öÍøÕ¾


3.png


WordPressµÄ²å¼þContact Form 7 StyleÖÐ佨¸´µÄXSS·ì϶¿ÉÓ°Ï쳬¹ý5Íò¸öÍøÕ¾¡£¡£¡£¡£¡£¡£¸Ã²å¼þÓÃÓÚ´´½¨ÍøÕ¾Ê¹ÓõÄÁªÏµ±íµ¥£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÓû§×Ô½çËµÍøÕ¾µÄ¼¶ÁªÐÎ×´±í(CSS)´úÂëÀ´Ö¸¶¨wordpressµÄÍøÕ¾µÄ±í¹Û¡£¡£¡£¡£¡£¡£¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.8£¬£¬£¬£¬£¬£¬£¬£¬ÊÇÓÉÓÚ×Ô½ç˵CSS´úÂëµÄÖ°ÄܶÌȱ¶ÔÊý¾ÝµÄËãÕʺͶÔËæ»úÊýµÄ± £»£»£»£»£»¤»úÔ죬£¬£¬£¬£¬£¬£¬£¬Ê¹¹¥»÷ÕßÄܹ»Ìá½»ÏòÍøÕ¾×¢Èë¶ñÒâJavaScriptµÄÒªÇ󡣡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬»¹Î´°ä²¼Õë¶Ô¸Ã·ì϶µÄ²¹¶¡·¨Ê½¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/unpatched-wordpress-plugin-code-injection/163706/


4¡¢ÀÕË÷ÍÅ»ïZiggy°ä·¢Í˳ö£¬£¬£¬£¬£¬£¬£¬£¬²¢°ä²¼Æä½âÃÜÃÜÔ¿


4.png


ÖÜÄ©£¬£¬£¬£¬£¬£¬£¬£¬ÀÕË÷ÍÅ»ïZiggyÔÚTelegramÉϰ䷢Æä½«Í˳ö£¬£¬£¬£¬£¬£¬£¬£¬²¢°ä²¼ËùÓнâÃÜÃÜÔ¿¡£¡£¡£¡£¡£¡£2ÔÂ7ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬ZiggyÍÅ»ï°ä²¼ÁËÒ»¸öÔ̺¬ÁË922¸ö½âÃÜÃÜÔ¿µÄSQLÎļþºÍÓë½âÃÜÃÜԿһ·ʹÓõĽâÃÜÆ÷¡£¡£¡£¡£¡£¡£³ý´ËÖ®±í£¬£¬£¬£¬£¬£¬£¬£¬Ziggy»¹°ä²¼ÁËÀëÏߵĽâÃÜÃÜÔ¿ºÍ·ÖÆç½âÃÜÆ÷µÄÔ´´úÂ룬£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚÒòÔâµ½¹¥»÷¶øÎÞ·¨Ïνӵ½Internet»òC&CÎÞ·¨½Ó¼ûµÄÊܺ¦Õß½øÐнâÃÜ¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ×î½üµ·»ÙEmotetºÍNetwalkerÐж¯¿ÉÄÜ»áʹ¸ü¶àÍÅ»ï¸ÐӦΣÏÕ²¢Í˳ö£¬£¬£¬£¬£¬£¬£¬£¬EmsisoftÒ²¼´½«°ä²¼Æä½âÃÜÆ÷¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ziggy-ransomware-shuts-down-and-releases-victims-decryption-keys/


5¡¢Kaspersky°ä²¼2020ÄêÕÊ»§ÊÕÊܹ¥»÷ÊÂÎñµÄ»ØÊ׻㱨


5.png


Kaspersky°ä²¼ÁËÓйØ2020ÄêÕÊ»§ÊÕÊܹ¥»÷ÊÂÎñµÄ»ØÊ׻㱨¡£¡£¡£¡£¡£¡£»ã±¨ÏÔʾ£¬£¬£¬£¬£¬£¬£¬£¬ÕË»§ÊÕÊÜÊÂÎñÕ¼½ðÈÚ·þÎñÐÐҵڲƭ»î¶¯µÄ±ÈÀýÉÏÉýÁË19%£¬£¬£¬£¬£¬£¬£¬£¬´Ó2019ÄêµÄ34£¥¼¤ÔöÖÁ2020ÄêµÄ54£¥¡£¡£¡£¡£¡£¡£³ýÁËÊÕÊÜÕÊ»§Ö®±í£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹ÀÄÓÃÖîÈçTeamViewerÖ®ÀàµÄºÏ·¨Ô¶³ÌÖÎÀí¹¤¾ß£¨RAT£©À´³¢ÊÔ½Ó¼ûÓû§ÕÊ»§¡£¡£¡£¡£¡£¡£Kaspersky½¨Òé×é֯ͨ¹ýÏÞ¶ÈÂòÂôµÄ³¢ÊÔ´ÎÊý¡¢½øÐÐÄê¶È°²È«ÉóºËºÍÉøÈë²âÊÔÒÔ¼°Ö´Ðжà³É·ÖÉí·ÝÑéÖ¤µÄ·½Ê½À´Ô¤·À´ËÀ๥»÷¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.kaspersky.com/about/press-releases/2021_share-of-account-takeover-incidents-increased-by-20-percentage-points