ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ15ÖÜ
°ä²¼¹¦·ò 2021-04-13> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2021Äê04ÔÂ05ÈÕÖÁ04ÔÂ11ÈÕ¹²ÊÕ¼°²È«·ì϶41¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇCisco RV345P Dual WAN Gigabit VPN Routers CVE-2021-1414ËÁÒâ´úÂëÖ´Ðзì϶£»£»£»£»£»£»LiteSpeed Technologies OpenLiteSpeed web serverȨÏÞÌáÉý·ì϶£»£»£»£»£»£»OpenIAM Groovy Script´úÂëÖ´Ðзì϶£»£»£»£»£»£»SonicWall GMSÔ¶³ÌȨÏÞÌáÉý·ì϶£»£»£»£»£»£»Skyworth Digital Technology RN510»º³åÇøÒç¶Âí½Å¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇTIMÍŶÓÅû¶CA Technologies²úÆ·ÖеĶà¸ö0day£»£»£»£»£»£»KasperskyÅû¶Õë¶ÔÔ½Ä϶à¸ö×éÖ¯µÄÍøÂç¼äµý»î¶¯£»£»£»£»£»£»ÐÂ¼ÓÆÂ¹¤»áe2iÔâµ½´¹µö¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶ÊýÍò¹«ÃñµÄÐÅÏ¢£»£»£»£»£»£»Å·ÃË³ÆÆä¶à¸ö»ú¹¹ÔÚÉÏÖÜÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÊÂÎñÈÔÔÚµ÷²éÖУ»£»£»£»£»£»ESETÅû¶Õë¶ÔÀ¶¡ÃÀÖÞµØÓòÓû§µÄÐÂÒøÐÐľÂíJaneleiro¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£
> ³ÁÒª°²È«·ì϶Áбí
1.Cisco RV345P Dual WAN Gigabit VPN Routers CVE-2021-1414ËÁÒâ´úÂëÖ´Ðзì϶
CCisco RV345P Dual WAN Gigabit VPN Routers WEBÖÎÀí½Ó¿Ú´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÌáÉýȨÏÞ¡£¡£¡£¡£¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv34x-rce-8bfG2h6b
2.LiteSpeed Technologies OpenLiteSpeed web serverȨÏÞÌáÉý·ì϶
LiteSpeed Technologies OpenLiteSpeed web server´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÔÚÖ÷»úÉÏÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£
https://github.com/litespeedtech/openlitespeed/issues/217
3.OpenIAM Groovy Script´úÂëÖ´Ðзì϶
OpenIAM Groovy Script´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
https://github.com/Accenture/AARO-Bugs/blob/master/AARO-CVE-List.md
4.SonicWall GMSÔ¶³ÌȨÏÞÌáÉý·ì϶
SonicWall GMS´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬Äܹ»ROOTȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0009
5.Skyworth Digital Technology RN510»º³åÇøÒç¶Âí½Å
Skyworth Digital Technology RN510 /cgi-bin/app-staticIP.asp»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
https://s3curityb3ast.github.io/KSA-Dev-011.md
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢TIMÍŶÓÅû¶CA Technologies²úÆ·ÖеĶà¸ö0day

CA TechnologiesÊÇÃÀ¹úÒ»¼ÒרһÓÚB2BÈí¼þµÄ¿ç¹ú¹«Ë¾£¬£¬£¬£¬£¬£¬£¬£¬ÏúÊÛ½ü200ÖÖ²úÆ·£¬£¬£¬£¬£¬£¬£¬£¬Éæ¼°É¢²¼Ê½ÍÆËã¡¢ÔÆÍÆËã¡¢DevOpsºÍÍÆËã»ú°²È«Èí¼þÒÔ¼°Òƶ¯É豸¡£¡£¡£¡£¡£TIMµÄRed Team ResearchÍŶÓÅû¶ÁËCA eHealth Performance Manager²úÆ·ÖеÄ5¸öзì϶¡£¡£¡£¡£¡£±ðÀëΪÌáȨ·ì϶£¨CVE-2021-28246ºÍCVE-2021-28249£©¡¢¿çÕ¾µã¾ç±¾·ì϶£¨CVE-2021-28247£©¡¢Í¨¹ýSUID/GUIDÎļþµÄÌáȨ·ì϶£¨CVE-2021-28250£©ºÍÉí·ÝÑéÖ¤·ì϶£¨CVE-2021-28248£©¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/116268/security/ca-ehealth-performance-manager-flaws.html
2¡¢KasperskyÅû¶Õë¶ÔÔ½Ä϶à¸ö×éÖ¯µÄÍøÂç¼äµý»î¶¯

KasperskyÅû¶ÁËAPT×éÖ¯CycldekÕë¶ÔÔ½Äϵ±¾ÖºÍ¾üÊÂ×éÖ¯µÄÍøÂç¼äµý»î¶¯¡£¡£¡£¡£¡£¸Ã»î¶¯Ê¹ÓÃÁËÃûΪFoundCoreµÄ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬¿É½øÐÐÎļþϵͳ°Ñ³Ö¡¢¹ý³Ì°Ñ³Ö¡¢ÆÁÄ»½ØÍ¼²¶»ñºÍËÁÒâºÅÁîÖ´ÐС£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬Kaspersky³Æ¸Ã×éÖ¯ÔÚ¸´ÔÓÐÔ·½Ãæ»ñµÃÁ˳ÁÃͽøÈ¡£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈ磬£¬£¬£¬£¬£¬£¬£¬ÆäpayloadµÄ±êÍ·£¨´úÂëµÄÖ¸±êºÍÔ´£©±»ÆëÈ«°þÀ룬£¬£¬£¬£¬£¬£¬£¬Ê£ÏµÄÉÙÊý²¿ÃŵÄÖµÊDz»Á¬¹áµÄ£¬£¬£¬£¬£¬£¬£¬£¬Õâ´ó´óÔö³¤ÁË×êÑÐÈËÔ±¶ÔÆä½øÐзÖÎöµÄÄѶȡ£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/spy-operations-vietnam-rat/165243/
3¡¢ÐÂ¼ÓÆÂ¹¤»áe2iÔâµ½´¹µö¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶ÊýÍò¹«ÃñµÄÐÅÏ¢

ÐÂ¼ÓÆÂÈ«¹ú¹¤»á´ú±í´ó»á¾ÍÒµÓë¾ÍÒµ×êÑÐËù£¨e2i£©ÔÚ±¾ÖÜÒ»£¨4ÔÂ5ÈÕ£©°ä²¼ÉêÃ÷³Æ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜÒѾ½Ó¼ûÆäÓû§µÄÓ×ÎÒÐÅÏ¢¡£¡£¡£¡£¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬Óû§µÄÐÕÃû¡¢½ÌÓý×ʸñºÍNRIC¡¢ÁªÏµ·½Ê½ºÍ¾Íҵϸ½ÚµÈ¡£¡£¡£¡£¡£ÊÂÎñ²úÉúÔÚ3ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬ÆäµÚÈý·½¹©¸øÉÌ¡ª¡ªÁªÏµÖÐÐÄ·þÎñ¹«Ë¾i-vic InternationalÔ±¹¤µÄÓÊÏäÔâµ½´¹µö¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÓÊÏäµÄÔÆ¶ËÔ̺¬ÁËÔ¼3Íò¸ö²ÎÓëÁËe2i»î¶¯µÄÓû§ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬µ«ÊǸûú¹¹»Ø¾øÐ¹Â©×ܹ²Óм¸¶àÈËÔøÊ¹Óùýe2iµÄ·þÎñ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.straitstimes.com/tech/tech-news/personal-data-of-30000-people-who-use-ntucs-e2i-services-may-have-been-breached
4¡¢Å·ÃË³ÆÆä¶à¸ö»ú¹¹ÔÚÉÏÖÜÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÊÂÎñÈÔÔÚµ÷²éÖÐ

Å·ÃËίԱ»á½²»°È˳ƣ¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬Î¯Ô±»áÔÚÄڵĶà¸öÅ·ÃË×éÖ¯ÔÚÉÏÖÜÔâµ½ÁËÍøÂç¹¥»÷¡£¡£¡£¡£¡£´Ë¿Ì¶Ô¸ÃÊÂÎñµÄȡ֤·ÖÎöÈÔ´¦ÓÚ³õÆÚ½×¶Î£¬£¬£¬£¬£¬£¬£¬£¬ÉÐδ¼ì²âµ½´æÔÚÐÅϢй¶ÎÊÌâ¡£¡£¡£¡£¡£Åí²©É簵ʾ£¬£¬£¬£¬£¬£¬£¬£¬Õâ´ÎÊÂÎñ±ÈÅ·ÃËÒÔÍùÔâµ½µÄ¹¥»÷¸üΪÑϳÁ£¬£¬£¬£¬£¬£¬£¬£¬Å·ÃËij¹ÙÔ±»¹Ð¹Â©£¬£¬£¬£¬£¬£¬£¬£¬Æä¹¤×÷ÈËÔ±½üÆÚÊÕµ½ÁËÓйØÕë¶ÔÅ·Ã˵Ĵ¹µö¹¥»÷Ô¤¾¯¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬Å·ÃËÈÔδ¹«¿ªÓйØÕâ´ÎÊÂÎñµÄÐÔÖÊ»òÆä±³ºóµÄ¹¥»÷ÕßÉí·ÝµÄÐÅÏ¢¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bloomberg.com/news/articles/2021-04-06/european-institutions-were-targeted-in-a-cyber-attack-last-week
5¡¢ESETÅû¶Õë¶ÔÀ¶¡ÃÀÖÞµØÓòÓû§µÄÐÂÒøÐÐľÂíJaneleiro

ESETµÄ×êÑÐÈËÔ±Åû¶ÁËÕë¶ÔÀ¶¡ÃÀÖÞµØÓòÓû§µÄÐÂÐÍÒøÐÐľÂíJaneleiro¡£¡£¡£¡£¡£¸ÃľÂíÖÁÉÙ´Ó2019ÄêÒÔÀ´¾ÍÆðÍ·Õë¶Ô°ÍÎ÷µÄÆóÒµ£¬£¬£¬£¬£¬£¬£¬£¬Éæ¼°¹¤³Ì¡¢Ò½ÁƱ£½¡¡¢ÁãÊÛ¡¢Ôì×÷Òµ¡¢½ðÈÚ¡¢ÔËÊäºÍµ±¾ÖµÈ¸÷¸öÁìÓò¡£¡£¡£¡£¡£Janeleiroͨ¹ýαÔì´óÐÍÒøÐÐÍøÕ¾£¨SantanderºÍBanco do BrasilµÈ£©µÄµ¯´°À´ÒýÓÕÖ¸±ê£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩµ¯´°Ô̺¬ÐéαµÄ±í¸ñÀ´ÓÕʹָ±êÊäÈëÒøÐÐÆ¾Ö¤ºÍÓ×ÎÒÐÅÏ¢¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬JaneleiroÊÇÓÉVisual Basic .NET±àдµÄ£¬£¬£¬£¬£¬£¬£¬£¬ÕâÓë¸ÃµØÓòµÄºÚ¿ÍËùϲ»¶µÄDelphiÓкܴóµÄ³öÈë¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/04/experts-uncover-new-banking-trojan.html


¾©¹«Íø°²±¸11010802024551ºÅ