ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ37ÖÜ
°ä²¼¹¦·ò 2021-09-14>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2021Äê09ÔÂ06ÈÕÖÁ09ÔÂ12ÈÕ¹²ÊÕ¼°²È«·ì϶58¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApple iOS Wi-Fi»º³åÇøÒç³ö´úÂëÖ´Ðзì϶£»£»£»£»£»Delta Electronics DOPSoftÏîÄ¿ÎļþÔ½½çд·ì϶£»£»£»£»£»QNAP NAS CVE-2021-34343Õ»Òç³ö´úÂëÖ´Ðзì϶£»£»£»£»£»Google Android FrameworkËÁÒâ´úÂëÖ´Ðзì϶£»£»£»£»£»Cisco IOS XR Software CVE-2021-34719ÌØÈ¨ÌáÉý·ì϶¡£¡£¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÐÂÎ÷À¼»¥ÁªÍøÔËÓªÉÌVocusÔâµ½´ó¹æÄ£DDoS¹¥»÷£»£»£»£»£»Google TensorFlowΪ½¨¸´RCE·ì϶¶ø²»ÔÙÖ§³ÖYAML£»£»£»£»£»FortiGuard°ä²¼2021ÄêH1È«ÇòÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨£»£»£»£»£»Î¢Èí°ä²¼MSHTMLÖÐRCE·ì϶£¨CVE-2021-40444£©µÄ¹«¸æ£»£»£»£»£»×êÑÐÈËÔ±·¢ÏÖREvilÍÅ»ïµÄÊý¾ÝÐ¹Â¶ÍøÕ¾ÔÙ¶ÈÉÏÏß¡£¡£¡£¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£¡£¡£¡£
>³ÁÒª°²È«·ì϶Áбí
1.Apple iOS Wi-Fi»º³åÇøÒç³ö´úÂëÖ´Ðзì϶
Apple iOS Wi-Fi´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
https://support.apple.com/en-us/HT212317
2.Delta Electronics DOPSoftÏîÄ¿ÎļþÔ½½çд·ì϶
Delta Electronics DOPSoft´¦ÖÃÏîÄ¿Îļþ´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬£¬¿Éʹϵͳ±ÀÀ£»£»£»£»£»òÕßÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
https://us-cert.cisa.gov/ics/advisories/icsa-21-252-02
3.QNAP NAS CVE-2021-34343Õ»Òç³ö´úÂëÖ´Ðзì϶
QNAP NAS´æÔÚÕ»Òç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿Éʹϵͳ±ÀÀ£»£»£»£»£»òÕßÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
https://www.qnap.com/en/security-advisory/qsa-21-33
4.Google Android FrameworkËÁÒâ´úÂëÖ´Ðзì϶
Google Android Framework´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
https://source.android.com/security/bulletin/2021-09-01
5.Cisco IOS XR Software CVE-2021-34719ÌØÈ¨ÌáÉý·ì϶
Cisco IOS XR SoftwareºÅÁîÐвÎÊýʵÏÖ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐí±¾µØ¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÌáÉýȨÏÞ£¬£¬£¬£¬£¬£¬£¬£¬»ñÈ¡ROOTȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-privescal-dZYMrKf
>³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢ÐÂÎ÷À¼»¥ÁªÍøÔËÓªÉÌVocusÔâµ½´ó¹æÄ£DDoS¹¥»÷

ÐÂÎ÷À¼µÚÈý´ó»¥ÁªÍøÔËÓªÉÌVocus ISP³ÆÆäÔÚ9ÔÂ3ÈÕÔâµ½´ó¹æÄ£DDoS¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬µ¼Ö·þÎñÖжÏÁËÔ¼30·ÖÖÓ¡£¡£¡£¡£¡£¡£¡£¡£VocusÔÚ°Ä´óÀûÑǺÍÐÂÎ÷À¼ÌṩÁãÊÛ¡¢Åú·¢ºÍÆóÒµµçÕÛ·þÎñ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾³Æ£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚĿǰȫ¹ú´ó²¿ÃŵØÓò¶¼ÔÚÔ¶³Ì°ì¹«£¬£¬£¬£¬£¬£¬£¬£¬Òò¶øÕâ´Î¹¥»÷¶Ô¿Í»§²úÉúÁ˳Á´óÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾Ñ¸ËÙ¸´ÔÁËÔËÓª£¬£¬£¬£¬£¬£¬£¬£¬²¢¶Ô¸ø¿Í»§´øÀ´µÄ²»±ã°µÊ¾Ç¸Òâ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.reuters.com/technology/widespread-internet-outages-hits-users-across-new-zealand-2021-09-03/
2¡¢Google TensorFlowΪ½¨¸´RCE·ì϶¶ø²»ÔÙÖ§³ÖYAML

Google¿ª·¢µÄ»ùÓÚPythonµÄ»úе½ø½¨ºÍÈËΪÖÇÄÜÏîÄ¿TensorFlowÒѾÉÕ»ÙÁ˶ÔYAMLµÄÖ§³Ö¡£¡£¡£¡£¡£¡£¡£¡£TensorFlow´úÂëÖеÄyaml.unsafe_load()º¯Êý´æÔÚÒ»¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬£¬×·×ÙΪCVE-2021-37678£¬£¬£¬£¬£¬£¬£¬£¬ÆÀ·ÖΪ9.3¡£¡£¡£¡£¡£¡£¡£¡£µ±ÀûÓ÷´ÐòÁл¯YAMLÌåʽµÄKerasÄ£ÐÍʱ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£Îª½¨¸´´Ë·ì϶£¬£¬£¬£¬£¬£¬£¬£¬TensorFlow¾ö¶¨ÆëÈ«ÉÕ»ÙYAMLµÄÖ§³Ö£¬£¬£¬£¬£¬£¬£¬£¬×ª¶øÊ¹ÓÃJSON·´ÐòÁл¯¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/googles-tensorflow-drops-yaml-support-due-to-code-execution-flaw/
3¡¢FortiGuard°ä²¼2021ÄêH1È«ÇòÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨

FortiGuardÓÚ8Ô·ݰ䲼ÁË2021ÄêH1È«ÇòÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬£¬£¬2021Äê6Ô¾ùÔÈÿÖÜÀÕË÷Èí¼þ»î¶¯±ÈÒ»ÄêǰͬÆÚÓâÔ½10.7±¶¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬£¬£¬µçÐÅÐÐÒµÊǹ¥»÷ÕßµÄÊ×ÒªµÄÖ¸±ê£¬£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊǵ±¾Ö¡¢Íйܰ²È«·þÎñÌṩÉÌ¡¢Æû³µºÍÔì×÷ÐÐÒµ¡£¡£¡£¡£¡£¡£¡£¡£½©Ê¬ÍøÂçÒ²ÓÐËùÔö³¤£¬£¬£¬£¬£¬£¬£¬£¬½ñÄêËêÊ×ÔÚ35%µÄ×éÖ¯Öмì²âµ½Á˽©Ê¬ÍøÂç»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬¶øÕâÒ»±ÈÀýÔÚ6¸öÔºóÔö³¤Îª51%¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õ߸üÇàíùÓÚ¼ì²âÈÆ¹ý¼¼ÊõºÍÌáȨ¼¼Êõ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.fortinet.com/content/dam/fortinet/assets/threat-reports/report-threat-landscape-2021.pdf
4¡¢Î¢Èí°ä²¼MSHTMLÖÐRCE·ì϶£¨CVE-2021-40444£©µÄ¹«¸æ

΢ÈíÍŶÓÔÚ9ÔÂ7ÈÕ°ä²¼ÁËÕë¶ÔWindowsÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-40444£©µÄ»º½â´ëÊ©¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶´æÔÚÓÚMicrosoft OfficeÎĵµÊ¹ÓõÄä¯ÀÀÆ÷äÖȾÒýÇæMSHTMLÖУ¬£¬£¬£¬£¬£¬£¬£¬ÒÑÔÚÕë¶ÔWindows 10ÉϵÄOffice 365ºÍOffice 2019µÄ¹¥»÷»î¶¯Öб»ÀûÓᣡ£¡£¡£¡£¡£¡£¡£Ä¿Ç°ÉÐÎÞ¿ÉÓõݲȫ¸üУ¬£¬£¬£¬£¬£¬£¬£¬Microsoft½¨Òé½ûÓÃInternet ExplorerÖÐËùÓеÄActiveX¿Ø¼þ×÷Ϊ»º½â´ëÊ©¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-shares-temp-fix-for-ongoing-office-365-zero-day-attacks/
5¡¢×êÑÐÈËÔ±·¢ÏÖREvilÍÅ»ïµÄÊý¾ÝÐ¹Â¶ÍøÕ¾ÔÙ¶ÈÉÏÏß

×êÑÐÈËÔ±·¢ÏÖREvilÍÅ»ïµÄÊý¾ÝÐ¹Â¶ÍøÕ¾£¨Ò²³ÆÎª Happy Blog£©ÔÚ9ÔÂ7ÈÕ³ÁÐÂÉÏÏß¡£¡£¡£¡£¡£¡£¡£¡£7ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬REvilÀûÓÃKaseya VSAÖеķì϶¹¥»÷ÁËԼĪ60¼ÒMSP¼°Æä1500¶à¸ö¿Í»§£¬£¬£¬£¬£¬£¬£¬£¬²¢ÀÕË÷7000ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯ÒýÆðÁË·¨Âɲ¿ÃÅÈ·°ÑÎÈ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ7ÔÂ13¹Ø¹ØÁËËùÓеÄTor·þÎñÆ÷ºÍ»ù´¡ÉèÊ©¡£¡£¡£¡£¡£¡£¡£¡£Éв»Ã÷ÏÔÕâ´ÎÖ§¸¶ºÍÊý¾ÝÐ¹Â¶ÍøÕ¾µÄ³ÁÐÂÉÏÏߣ¬£¬£¬£¬£¬£¬£¬£¬ÊÇ·ñ´ú±íןÃÍÅ»ïÒªÆðÍ·¸´³ö¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/revil-ransomwares-servers-mysteriously-come-back-online/


¾©¹«Íø°²±¸11010802024551ºÅ