ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ28ÖÜ

°ä²¼¹¦·ò 2021-07-12

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2021Äê07ÔÂ05ÈÕÖÁ07ÔÂ11ÈÕ¹²ÊÕ¼°²È«·ì϶61¸ö£¬£¬£¬£¬ £¬£¬ÖµµÃ¹Ø×¢µÄÊÇAdvantech WebAccess Node BwFreRPTÕ»Òç³ö´úÂëÖ´Ðзì϶£»£»£»£»£»Microsoft Teams ElectronJSÖ¡³Á¶¨Ïò´úÂëÖ´Ðзì϶£»£»£»£»£»NPort IA5000A-I/O Series CVE-2021-32968»Ø¾ø·þÎñ·ì϶£»£»£»£»£»Phoenix Contact Automationworx BCPÎļþÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶£»£»£»£»£»Siemens Simcenter Femap FEMAPÔ½½çд´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÈðµäÁ¬Ëø³¬ÊÐCoopÒòKaseya¹©¸øÁ´¹¥»÷¹Ø¹ØÊý°Ù¼ÒÃŵꣻ£»£»£»£»ÃÀ¹ú±£ÏÕ¹«Ë¾AJG³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬ £¬£¬¿Í»§ÐÅϢй¶£»£»£»£»£»CISAºÍFBI°ä²¼Õë¶ÔKaseya¹©¸øÁ´¹¥»÷Êܺ¦ÕßµÄÖ¸ÄÏ£»£»£»£»£»Î¢Èí°ä²¼µÄPrintNightmareµÄ´¹Î£¸üпɱ»Èƹý£»£»£»£»£»Kaspersky·¢ÏÖWildPressureÕë¶ÔmacOSµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬ £¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£¡£¡£


> ³ÁÒª°²È«·ì϶Áбí


1.Advantech WebAccess Node BwFreRPTÕ»Òç³ö´úÂëÖ´Ðзì϶


Advantech WebAccess Node BwFreRPT´æÔÚÕ»Òç¶Âí½Å£¬£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄ0x2711 IOCTLÒªÇ󣬣¬£¬£¬ £¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-779/


2.Microsoft Teams ElectronJSÖ¡³Á¶¨Ïò´úÂëÖ´Ðзì϶


Microsoft Teams ElectronJSÖ¡±£»£»£»£»£»¤´æÔÚ°²È«·ì϶£¬£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâÒªÇ󣬣¬£¬£¬ £¬£¬¿É³Á¶¨Ïò¶ñÒâÒ³Ãæ£¬£¬£¬£¬ £¬£¬½Ó¼ûÄÚ²¿ÀûÓöÔÏ󣬣¬£¬£¬ £¬£¬ÌáÉýȨÏÞ¡£¡£¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-772/


3.NPort IA5000A-I/O Series CVE-2021-32968»Ø¾ø·þÎñ·ì϶


NPort IA5000A-I/O SeriesÄÚ²¿WEB·þÎñ´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâÒªÇ󣬣¬£¬£¬ £¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£¡£¡£¡£¡£¡£¡£¡£

https://us-cert.cisa.gov/ics/advisories/icsa-21-187-01


4.Phoenix Contact Automationworx BCPÎļþÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶


Phoenix Contact Automationworx BCPÎļþ´¦ÖôæÔÚÄÚ´æ·ÛËé·ì϶£¬£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬ £¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬ £¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-782/


5.Siemens Simcenter Femap FEMAPÔ½½çд´úÂëÖ´Ðзì϶


Siemens Simcenter Femap FEMAPÎļþ´¦ÖôæÔÚÔ½½çд·ì϶£¬£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬ £¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬ £¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-781/


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢ÈðµäÁ¬Ëø³¬ÊÐCoopÒòKaseya¹©¸øÁ´¹¥»÷¹Ø¹ØÊý°Ù¼ÒÃŵê


1.jpg


ÈðµäÁ¬Ëø³¬ÊÐCoop³ÆÆäÔâµ½ÁËKaseya¹©¸øÁ´¹¥»÷£¬£¬£¬£¬ £¬£¬Êý°Ù¼ÒÃÅµê¹Ø¹Ø¡£¡£¡£¡£¡£¡£¡£CoopµÄ½²»°È˰µÊ¾ÆäÓÚÉÏÖÜÎåÍíÉÏ6µã30·Ö×óÓÒ·¢ÏÖÓÐÉÙÊýÃŵê³öÏÖÎÊÌ⣬£¬£¬£¬ £¬£¬µ«Ò»Ò¹Ö®ºóÆä´ó²¿ÃÅÃŵ궼±»ÆÈ¹Ø¹Ø£¬£¬£¬£¬ £¬£¬Ô̺¬ÊÕÒøÌ¨ºÍ×ÔÖ÷½áÕËÔÚÄÚµÄÕû¸öÖ§¸¶ÏµÍ³¶¼ÖжÏÁË¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬ £¬£¬CoopûÓÐʹÓÃKesayaÈí¼þ£¬£¬£¬£¬ £¬£¬ÓÉÓÚËûÃǵÄÒ»¸öÈí¼þÌṩÉÌʹÓÃÁ˸ÃÈí¼þ¶øÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£°²È«¹«Ë¾HuntressLabs³Æ£¬£¬£¬£¬ £¬£¬Õâ´Î¹¥»÷»î¶¯µÄµ÷²éÈÔÔÚ½øÐÐÖУ¬£¬£¬£¬ £¬£¬ÖÁÉÙÓÐ200¼Ò×éÖ¯Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/119663/cyber-crime/coop-supermarket-kaseya-ransomware-attack.html


2¡¢ÃÀ¹ú±£ÏÕ¹«Ë¾AJG³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬ £¬£¬¿Í»§ÐÅϢй¶


2.jpg


ÃÀ¹úArthur J. Gallagher (AJG) ³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬ £¬£¬¿Í»§ÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£AJGÊÇÃÀ¹úµÄÈ«Çò±£ÏÕ¾­¼ÍºÍ·çÏÕÖÎÀí¹«Ë¾£¬£¬£¬£¬ £¬£¬×÷ΪȫÇò×î´óµÄ±£ÏÕ¾­¼ÍÉÌÖ®Ò»£¬£¬£¬£¬ £¬£¬ÒµÎñ±é¼°49¸ö¹ú¶È/µØÓò¡£¡£¡£¡£¡£¡£¡£¹¥»÷²úÉúÔÚ2020Äê6ÔÂ3ÈÕÖÁ2020Äê9ÔÂ26ÈÕÆÚ¼ä£¬£¬£¬£¬ £¬£¬ÆäÔÚ2020Äê9ÔÂ28ÈÕÅû¶¸ÃÊÂÎñ²¢³ÆÃ»º±¼û¾Ýй¶¡£¡£¡£¡£¡£¡£¡£µ«ÔÚËæºóµÄµ÷²é·¢ÏÖ£¬£¬£¬£¬ £¬£¬7376È˵ÄÃô¸ÐÐÅϢй¶£¬£¬£¬£¬ £¬£¬Ô̺¬Éç»á°²È«ºÅÂë»ò˰ºÅ¡¢¼ÝÕÕ¡¢»¤ÕÕ¡¢µ®ÉúÈÕÆÚ¡¢Óû§ÃûºÍÃÜÂë¡¢Ô±¹¤¼ø±ðºÅ¡¢²ÆÕþÕË»§»òÐÅÓþ¿¨ÐÅÏ¢¡¢µç×ÓÊðÃû¡¢Ò½ÁÆÐÅÏ¢¡¢±£ÏÕÐÅÏ¢ÒÔ¼°ÉúÎï¼ø±ðÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-insurance-giant-ajg-reports-data-breach-after-ransomware-attack/


3¡¢CISAºÍFBI°ä²¼Õë¶ÔKaseya¹©¸øÁ´¹¥»÷Êܺ¦ÕßµÄÖ¸ÄÏ


3.jpg


CISAºÍFBI½áºÏ°ä²¼ÁËÕë¶ÔÊܵ½Kaseya¹©¸øÁ´¹¥»÷Ó°ÏìµÄÊܺ¦ÕßµÄÖ¸ÄÏ¡£¡£¡£¡£¡£¡£¡£ÕâÁ½¸ö»ú¹¹½¨Òé×é֯ʹÓÃKaseyaÌṩµÄ¼ì²â¹¤¾ßÀ´²é³­ËûÃǵÄϵͳÊÇ·ñ´æÔÚÈëÇÖ¼£Ï󣬣¬£¬£¬ £¬£¬²¢ÆôÓöà³É·ÖÉí·ÝÑéÖ¤(MFA)¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬ £¬£¬×éÖ¯»¹Ó¦Ê¹Óð×Ãûµ¥À´±í²¿ÏÞ¶È¶ÔÆäÄÚ²¿×ʲúµÄ½Ó¼û£¬£¬£¬£¬ £¬£¬²¢Ê¹Ó÷À»ðǽ»òVPN±£»£»£»£»£»¤ÆäÔ¶³Ì¼à¿Ø¹¤¾ßµÄÖÎÀí½çÃæ¡£¡£¡£¡£¡£¡£¡£¶øÊÜÓ°ÏìµÄMSP¿Í»§±ØÒªÈ·±£±¸·ÝÊÇ×îе쬣¬£¬£¬ £¬£¬²¢ÇÒÁ¢¼´×°Öù©¸øÉÌÌṩµÄ×îеIJ¹¶¡¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/119728/cyber-crime/cisa-fbi-guidance-kaseya-attack.html


4¡¢Î¢Èí°ä²¼µÄPrintNightmareµÄ´¹Î£¸üпɱ»Èƹý


4.jpg


Microsoft°ä²¼KB5004945´¹Î£°²È«¸üУ¬£¬£¬£¬ £¬£¬½¨¸´Ó°ÏìËùÓÐWindows Print Spooler·þÎñÖб»»ý¼«ÀûÓõÄPrintNightmare 0day¡£¡£¡£¡£¡£¡£¡£¸ÃÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-34527£©ÔÊÐí¹¥»÷ÕßʹÓÃSYSTEMȨÏÞµÄÔ¶³ÌÖ´ÐдúÂë²¢ÆëÈ«ÊÕÊÜÖ¸±ê·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£ÔÚ¸üа䲼ºó£¬£¬£¬£¬ £¬£¬×êÑÐÈËÔ±·¢Ïָò¹¶¡½ö½¨¸´ÁËÉæ¼°Ô¶³Ì´úÂëÖ´ÐеÄ×é¼þ£¬£¬£¬£¬ £¬£¬Òò¶ø×êÑÐÈËÔ±ÆðÍ·Åú¸Ä·ì϶ÀûÓ÷¨Ê½²¢²âÊÔ²¹¶¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬ £¬£¬È·¶¨Äܹ»ÆëÈ«ÈÆ¹ýÕû¸ö²¹¶¡À´ÊµÏÖ±¾µØÌáȨºÍÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-pushes-emergency-update-for-windows-printnightmare-zero-day/


5¡¢Kaspersky·¢ÏÖWildPressureÕë¶ÔmacOSµÄ¹¥»÷»î¶¯


5.jpg


KasperskyµÄ×êÑÐÈËÔ±·¢ÏÖWildPressureÔÚ×î½üµÄ¹¥»÷»î¶¯ÖÐÔö³¤ÁËÕë¶ÔmacOSµÄ¶ñÒâÈí¼þ±äÌå¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÓÚ2020Äê3Ô³õ´Î·¢ÏÖ¸ÃÍŻ£¬£¬£¬ £¬£¬ÆäʱWildPressureʹÓÃÁËC++°æ±¾µÄMilumľÂí¹¥»÷Öж«µÄ×éÖ¯¡£¡£¡£¡£¡£¡£¡£ÔÚ½üÆÚÕë¶ÔÄÜÔ´ÐÐÒµµÄ¹¥»÷ÖУ¬£¬£¬£¬ £¬£¬MilumÒѾ­Í¨¹ýPyInstaller°ü½øÐÐÁ˳Á×飬£¬£¬£¬ £¬£¬ÆäÖÐÔ̺¬ÁËÓëWindowsºÍmacOSϵͳ¼æÈݵÄľÂí·¨Ê½£¬£¬£¬£¬ £¬£¬±»ºÚµÄÍøÕ¾¿É±»APT×éÖ¯ÓÃÀ´ÏÂÔØºÍÉÏ´«Îļþ²¢Ö´ÐкÅÁî¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/macos-wildpressure-apt/167606/