ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ36ÖÜ

°ä²¼¹¦·ò 2021-09-06

>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö

2021Äê08ÔÂ30ÈÕÖÁ09ÔÂ05ÈÕ¹²ÊÕ¼°²È«·ì϶62¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇAruba Networks ArubaOS OS CVE-2021-37716 PAPIºÍ̸»º³åÇøÒç¶Âí½Å£»£»£»£»£»Google Chrome BlinkÄÚ´æÃýÎó´úÂëÖ´Ðзì϶£»£»£»£»£»Nature Easy Soft Network Technology ZenTaoºÅÁîÖ´Ðзì϶£»£»£»£»£»ZOHO ManageEngine ADSelfService Plus OSºÅÁî×¢Èë·ì϶£»£»£»£»£»Advantech WebAccess CVE-2021-38408»º³åÇøÃýÎó·ì϶¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇMicrosoft°ä²¼½üÆÚÖ¼ÔÚÇÔȡʹ´¦µÄ´¹µö»î¶¯µÄ¾¯±¨£»£»£»£»£»NFIB³Æ2021ÄêH1Ó¢¹úÒòÍøÂç·¸×ïËðʧ¸ß´ï13ÒÚÓ¢°÷£»£»£»£»£»CNNIC°ä²¼µÚ48´Î¡¶Öйú»¥ÁªÍøÂç·¢Õ¹Çé¿öͳ¼Æ»ã±¨¡·£»£»£»£»£»ÒòGoogleÀûÓÃbug£¬£¬£¬£¬£¬£¬£¬£¬²¿ÃŰ²×¿Óû§ÎÞ·¨²¦´òºÍ½ÓÌýµç»°£»£»£»£»£»×êÑÐÈËÔ±³Æ16¸öÀ¶ÑÀ·ì϶BrakToothÓ°ÏìÊýÊ®ÒÚÉ豸¡£¡£¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£¡£


>³ÁÒª°²È«·ì϶Áбí


1.Aruba Networks ArubaOS OS CVE-2021-37716 PAPIºÍ̸»º³åÇøÒç¶Âí½Å


Aruba Networks ArubaOS OS PAPIºÍ̸´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£


https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2021-016.txt



2.Google Chrome BlinkÄÚ´æÃýÎó´úÂëÖ´Ðзì϶


Google Chrome Blink´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÄܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£


https://chromereleases.googleblog.com/2021/08/stable-channel-update-for-desktop_31.html


3.Nature Easy Soft Network Technology ZenTaoºÅÁîÖ´Ðзì϶


Nature Easy Soft Network Technology ZenTao Cron job Ñ¡Ï´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£


https://privasec.com/blog/zentao-cms-a-monkeys-journey-to-priv-esc-remote-code-execution/


4.ZOHO ManageEngine ADSelfService Plus OSºÅÁî×¢Èë·ì϶


ZOHO ManageEngine ADSelfService Plus´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£


https://blog.stmcyber.com/vulns/cve-2021-33055/


5.Advantech WebAccess CVE-2021-38408»º³åÇøÃýÎó·ì϶


Advantech WebAccess´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£


https://www.advantech.com/support/details/installation?id=1-MS9MJV


>³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢Microsoft°ä²¼½üÆÚÖ¼ÔÚÇÔȡʹ´¦µÄ´¹µö»î¶¯µÄ¾¯±¨


Microsoft 365 DefenderÍþвµý±¨ÍŶÓÔÚ8ÔÂ26ÈÕ°ä²¼½üÆÚÖ¼ÔÚÇÔȡʹ´¦µÄ´¹µö»î¶¯µÄ¾¯±¨¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã»î¶¯ÀûÓõç×ÓÓʼþͨѶÖеÄÊ¢¿ª³Á¶¨ÏòÁ´½Ó×÷ÎªÔØÌ壬£¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§½Ó¼û¶ñÒâÍøÕ¾£¬£¬£¬£¬£¬£¬£¬£¬Í¬Ê±Èƹý°²È«¼ì²âÈí¼þ¡£¡£¡£¡£¡£¡£Î¢Èí°µÊ¾ËüÒѾ­·¢ÏÖÁËÖÁÉÙ350¸öÍøÂç´¹µöURL£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒËüÃǾùʹÓÃÁËÁîÈËÕÛ·þµÄµö¶üºÍ¾«ÐÄÉè¼ÆµÄ¼ì²âÈÆ¹ý¼¼Êõ¡£¡£¡£¡£¡£¡£Õâ²»½öÏÔʾÁËÕâ´Î¹¥»÷µÄ¹æÄ££¬£¬£¬£¬£¬£¬£¬£¬»¹½²ÁËÈ»¹¥»÷Õß¾Þ´óµÄͶÈë¡£¡£¡£¡£¡£¡£


Microsoft°ä²¼½üÆÚÖ¼ÔÚÇÔȡʹ´¦µÄ´¹µö»î¶¯µÄ¾¯±¨.jpg


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/08/microsoft-warns-of-widespread-phishing.html



2¡¢NFIB³Æ2021ÄêH1Ó¢¹úÒòÍøÂç·¸×ïËðʧ¸ß´ï13ÒÚÓ¢°÷


ÍøÂç·¸×ï.png


À´×ÔÓ¢¹ú¹ú¶Èڲƭµý±¨¾Ö(NFIB)µÄÊý¾ÝÅú×¢£¬£¬£¬£¬£¬£¬£¬£¬2021ÄêH1Ó¢¹úÒòÍøÂç·¸×ïËðʧ¸ß´ï13ÒÚÓ¢°÷¡£¡£¡£¡£¡£¡£Ó×ÎÒºÍ×éÖ¯ÔÚ½ñÄêÉϰëÄêÒòÍøÂç·¸×ïºÍڲƭ¶øËðʧµÄ×ʽðÊÇ2020ÉϰëÄ꣨4.147ÒÚÓ¢°÷£©µÄÈý±¶¡£¡£¡£¡£¡£¡£2020ÄêH1Ö»ÓÐ39160°¸¼þ£¬£¬£¬£¬£¬£¬£¬£¬¶ø2021ÄêH1¶à´ï289437Æð¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬£¬£¬£¬µ±¾ÖÓ¦²ÉÈ¡¸ü¶à´ëÊ©À´½ÌÓýÓ×ÎÒÓйØÍøÂç´¹µöµÄ·çÏÕºÍÍøÂ簲ȫµÄ³ÁÒªÐÔ£¬£¬£¬£¬£¬£¬£¬£¬¶ø×éÖ¯Ó¦¸ÃÈ«Á¦½µµÍÔ¶³Ì¹¤×÷µÄ·çÏÕ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/cybercrime-losses-triple-to-13bn/



3¡¢CNNIC°ä²¼µÚ48´Î¡¶Öйú»¥ÁªÍøÂç·¢Õ¹Çé¿öͳ¼Æ»ã±¨¡·


CNNIC°ä²¼µÚ48´Î¡¶Öйú»¥ÁªÍøÂç·¢Õ¹Çé¿öͳ¼Æ»ã±¨¡·.jpg


Öйú»¥ÁªÍøÂçÐÅÏ¢ÖÐÐÄ£¨CNNIC£©ÓÚ8ÔÂ27ÈÕÔÚ¾©°ä²¼µÚ48´Î¡¶Öйú»¥ÁªÍøÂç·¢Õ¹Çé¿öͳ¼Æ»ã±¨¡·¡£¡£¡£¡£¡£¡£»ã±¨ÏÔʾ£¬£¬£¬£¬£¬£¬£¬£¬½ØÖÁ½ñÄê6Ô£¬£¬£¬£¬£¬£¬£¬£¬ÖйúÍøÃñ¹æÄ£´ï10.11ÒÚ£¬£¬£¬£¬£¬£¬£¬£¬½Ï2020Äê12ÔÂÔö³¤2175Íò£¬£¬£¬£¬£¬£¬£¬£¬»¥ÁªÍø±é¼°ÂÊ´ï71.6%£»£»£»£»£»»¥ÁªÍø»ù´¡×ÊÔ´¼Ó¿ì½¨É裬£¬£¬£¬£¬£¬£¬£¬½ØÖÁ6Ô£¬£¬£¬£¬£¬£¬£¬£¬ÖйúIPv6µØÖ·ÊýÁ¿´ï62023¿é/32£»£»£»£»£»Öйú´åÂäÍøÃñ¹æÄ£Îª2.97ÒÚ£¬£¬£¬£¬£¬£¬£¬£¬´åÂ䵨Óò»¥ÁªÍø±é¼°ÂÊΪ59.2%£¬£¬£¬£¬£¬£¬£¬£¬½Ï2020Äê12Ô£¬£¬£¬£¬£¬£¬£¬£¬³ÇÏ绥ÁªÍø±é¼°Âʲî¾àËõÓ×4.8%¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

http://finance.people.com.cn/n1/2021/0828/c1004-32210949.html



4¡¢ÒòGoogleÀûÓÃbug£¬£¬£¬£¬£¬£¬£¬£¬²¿ÃŰ²×¿Óû§ÎÞ·¨²¦´òºÍ½ÓÌýµç»°


ÒòGoogleÀûÓÃbug£¬£¬£¬£¬£¬£¬£¬£¬²¿ÃŰ²×¿Óû§ÎÞ·¨²¦´òºÍ½ÓÌýµç»°.jpg


Google°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬²¿ÃÅAndroidÊÖ»úÐͺŵÄÓû§Êܵ½GoogleÀûÓÃÖÐbugµÄÓ°Ï죬£¬£¬£¬£¬£¬£¬£¬ÎÞ·¨²¦´òºÍ½ÓÌýµç»°¡£¡£¡£¡£¡£¡£Ä¿Ç°GoogleûÓй«¿ªÊÜÓ°ÏìÊÖ»úµÄÐͺţ¬£¬£¬£¬£¬£¬£¬£¬µ«±¾ÖÜÄ©ÊÜÓ°ÏìÓû§Ìáµ½ÁËLGµÄÉ豸£¬£¬£¬£¬£¬£¬£¬£¬ÈçLG G7¡¢LG G7 ThinQ¡¢LG V40 ThinQºÍLG Q70µÈ¡£¡£¡£¡£¡£¡£Google³ÆÆäÔÚµ÷²é´ËÊ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÒѰ䲼ÁË×îиüÐÂÀ´½¨¸´¸Ãbug£¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§ÊÖ¶¯×°ÖÃ×îиüС£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/google/google-app-bug-blocks-android-users-from-receiving-making-calls/


5¡¢×êÑÐÈËÔ±³Æ16¸öÀ¶ÑÀ·ì϶BrakToothÓ°ÏìÊýÊ®ÒÚÉ豸


×êÑÐÈËÔ±³Æ16¸öÀ¶ÑÀ·ì϶BrakToothÓ°ÏìÊýÊ®ÒÚÉ豸.jpg


×êÑÐÈËÔ±¼ì²âÁËÀ´×Ô11¸ö¹©¸øÉ̵Ä13¸öƬÉÏϵͳ (SoC) µÄÀ¶ÑÀÈí¼þ¿â£¬£¬£¬£¬£¬£¬£¬£¬·¢ÏÖÁË16¸öÓ°ÏìÀ¶ÑÀÈí¼þ²Ö¿âµÄ·ì϶²¢Í³³ÆËüÃÇΪBrakTooth¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ì϶ʹÉ豸±ÀÀ££¬£¬£¬£¬£¬£¬£¬£¬ÉõÖÁÊÇÖ´ÐжñÒâ´úÂë²¢ÊÕÊÜÕû¸öϵͳ¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶ÖÐ×îÑϳÁµÄΪCVE-2021-28139£¬£¬£¬£¬£¬£¬£¬£¬ÀûÓø÷ì϶Զ³Ì¹¥»÷ÕßÄܹ»Í¨¹ýÀ¶ÑÀLMPÊý¾Ý°üÔÚÖ¸±êÉ豸ÉÏÔËÐжñÒâ´úÂë¡£¡£¡£¡£¡£¡£²¢·ÇËùÓÐËùÓй©¸øÉ̶¼ÊµÊ±°ä²¼Á˲¹¶¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬£¬µ½Ä¿Ç°ÎªÖ¹£¬£¬£¬£¬£¬£¬£¬£¬Ö»ÓÐÀÖöΡ¢Ó¢·ÉÁèºÍBluetrum°ä²¼Á˲¹¶¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬£¬¶øµÂÖÝÒÇÆ÷Ôò°µÊ¾»Ø¾ø½¨¸´·ì϶¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/billions-of-devices-impacted-by-new-braktooth-bluetooth-vulnerabilities