ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ50ÖÜ
°ä²¼¹¦·ò 2021-12-13>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
±¾Öܹ²ÊÕ¼°²È«·ì϶60¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApache Log4j2ËÁÒâ´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»£»Tencent WeChat WXAM DecoderÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶£»£»£»£»£»£»£»£»Google golang ForrkExec»Ø¾ø·þÎñ·ì϶£»£»£»£»£»£»£»£»Mozilla Firefox file picker dialogÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶£»£»£»£»£»£»£»£»Veritas Enterprise Vault CVE-2021-44680´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇmagnatÀûÓÃαÔìµÄWeChatµÈ×°Ö÷¨Ê½·Ö·¢ºóÃÅ£»£»£»£»£»£»£»£»MailGuard·¢ÏÖÒÔ΢ÈíÀ¬»øÓʼþ֪ͨΪÖ÷ÌâµÄ´¹µö»î¶¯£»£»£»£»£»£»£»£»Googleµ·»Ù½ÚÔì×ų¬¹ý100Íǫ̀É豸µÄ½©Ê¬ÍøÂçGlupteba£»£»£»£»£»£»£»£»SonicWall°ä²¼¸üУ¬£¬£¬£¬£¬½¨¸´SMA 100ϵÁÐÖжà¸ö·ì϶£»£»£»£»£»£»£»£»ÐÂÀÕË÷Èí¼þCerber¶Ô×¼ConfluenceºÍGitLab·þÎñÆ÷¡£¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£¡£
>³ÁÒª°²È«·ì϶Áбí
1. Apache Log4j2ËÁÒâ´úÂëÖ´Ðзì϶
Apache Log4j2´æÔÚJava JNDI×¢Èë·ì϶£¬£¬£¬£¬£¬µ±·¨Ê½½«Óû§ÊäÈëµÄÊý¾Ý½øÐÐÈÕÖ¾¼Í¼£¬£¬£¬£¬£¬¼´¿É´¥·¢´Ë·ì϶£¬£¬£¬£¬£¬³É¹¦ÀûÓô˷ì϶Äܹ»ÔÚÖ¸±ê·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
https://github.com/apache/logging-log4j2/commit/7fe72d6
2. Tencent WeChat WXAM DecoderÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶
Tencent WeChat WXAM Decoder´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-1446/
3. Google golang ForrkExec»Ø¾ø·þÎñ·ì϶
Google golang ForrkExec´¦ÖôæÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿Éʹ·þÎñ·¨Ê½±ÀÀ££¬£¬£¬£¬£¬Ôì³É»Ø¾ø·þÎñ¹¥»÷¡£¡£¡£¡£¡£¡£
https://github.com/golang/go/commit/99950270f3cf52cccc6966d8668ff21b573bb6f5
4. Mozilla Firefox file picker dialogÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶
Mozilla Firefox file picker dialog´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄwebÒ³ÒªÇ󣬣¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
https://www.mozilla.org/en-US/security/advisories/mfsa2021-48/
5. SVeritas Enterprise Vault CVE-2021-44680´úÂëÖ´Ðзì϶
Veritas Enterprise VaultÀûÓÃÆô¶¯·þÎñ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
https://www.veritas.com/content/support/en_US/security/VTS21-003
>³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢magnatÀûÓÃαÔìµÄWeChatµÈ×°Ö÷¨Ê½·Ö·¢ºóÃÅ
Cisco TalosÔÚ12ÔÂ3ÈÕ¹«¿ªÁËmagnatµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷ʼÓÚ2018Äêµ×£¬£¬£¬£¬£¬×Ô2021Äê4ÔÂÒÔÀ´´ïµ½·åÖµ£¬£¬£¬£¬£¬ÖØÒªÕë¶Ô¼ÓÄô󣬣¬£¬£¬£¬Æä´ÎÊÇÃÀ¹ú¡¢°Ä´óÀûÑÇ¡¢Òâ´óÀû¡¢Î÷°àÑÀ¡¢Å²ÍþµÈ¹ú¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓÃαÔìµÄViber¡¢WeChat¡¢NoxPlayerºÍBattlefieldµÅצÓúÍÓÎÏ·µÄ×°Ö÷¨Ê½£¬£¬£¬£¬£¬ÓÕʹָ±êÏÂÔØºóÃÅ·¨Ê½ºÍ¶ñÒâChromeÀ©´ó·¨Ê½£¬£¬£¬£¬£¬×îÖÕ»áÇÔȡʹ´¦¡¢ÏµÍ³ÖеÄÃô¸ÐÊý¾ÝÒÔ¼°Ô¶³Ì½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2021/12/magnat-campaigns-use-malvertising-to.html
2¡¢MailGuard·¢ÏÖÒÔ΢ÈíÀ¬»øÓʼþ֪ͨΪÖ÷ÌâµÄ´¹µö»î¶¯
Óʼþ°²È«¹«Ë¾MailGuardÔÚ12ÔÂ2ÈÕ·¢ÏÖÒÔ΢ÈíÀ¬»øÓʼþ֪ͨΪÖ÷ÌâµÄ´¹µö»î¶¯¡£¡£¡£¡£¡£¡£ÕâЩÓʼþ·¢ËÍ×Ôquarantine[at]messaging.microsoft.com£¬£¬£¬£¬£¬ÏÔʾµÄÃû³ÆÊÇÊÕ¼þÈ˵ÄÓò£¬£¬£¬£¬£¬Í¨¹ýÕâÖÖ·½Ê½À´Ôö³¤Æä¿ÉÐŶȡ£¡£¡£¡£¡£¡£¸Ã´¹µöÓʼþÌáÐÑÖ¸±êÓб»¸ôÀëµÄÀ¬»øÓʼþ£¬£¬£¬£¬£¬µ±Ö¸±êµã»÷²é¿´ºó»á±»³Á¶¨Ïòµ½´¹µöÍøÕ¾²¢±»ÒªÇóÊäÈëOffice 365ƾ֤¡£¡£¡£¡£¡£¡£Î¢Èí¹«Ë¾ÔÚ8Ô·Ýй©£¬£¬£¬£¬£¬×Ô2020Äê7ÔÂÆðÍ·µÄÓã²æÊ½´¹µö»î¶¯ÂÅ´ÎÕë¶ÔOffice 365Óû§¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.mailguard.com.au/blog/scammers-mimic-microsoft-with-spam-notification-phishing-email
3¡¢Googleµ·»Ù½ÚÔì×ų¬¹ý100Íǫ̀É豸µÄ½©Ê¬ÍøÂçGlupteba
GoogleÔÚ12ÔÂ7ÈÕ°ä·¢ÆäÒѵ·»Ù½ÚÔì×ų¬¹ý100Íǫ̀É豸µÄ½©Ê¬ÍøÂçGlupteba¡£¡£¡£¡£¡£¡£Glupteba×Ô2011ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬£¬£¬£¬£¬ÊÇÒ»ÖÖÖ§³ÖÇø¿éÁ´µÄÄ£¿£¿£¿£¿£¿é»¯¶ñÒâÈí¼þ£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÃÀ¹ú¡¢Ó¡¶È¡¢°ÍÎ÷ºÍ¶«ÄÏÑǵĹú¶È£¬£¬£¬£¬£¬Ã¿ÌìÐÂÔöϰȾÉ豸µÄÊýÁ¿¸ß´ïÊýǧ̨¡£¡£¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂçÖØÒªÍ¨¹ýÆÆ½â»òµÁ°æÈí¼þºÍPPI¹æ»®´«²¼£¬£¬£¬£¬£¬Ï°È¾Ö¸±êºó»áÇÔÈ¡¼ÓÃÜÇ®±Ò¡¢Óû§Í´´¦ºÍcookie£¬£¬£¬£¬£¬²¢ÔÚÖ¸±êÉ豸Éϲ¿Êð´úÀí£¬£¬£¬£¬£¬ËæºóÏúÊÛ¸øÆäËû¹¥»÷Õß¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/google-disrupts-massive-glupteba-botnet-sues-russian-operators/
4¡¢SonicWall°ä²¼¸üУ¬£¬£¬£¬£¬½¨¸´SMA 100ϵÁÐÖжà¸ö·ì϶
SonicWallÔÚ12ÔÂ7ÈÕ°ä²¼¸üУ¬£¬£¬£¬£¬½¨¸´SMA 100ϵÁÐÉ豸ÖеĶà¸ö·ì϶¡£¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ×îΪÑϳÁµÄ·ì϶ÊÇ»ùÓÚ²Ö¿âµÄ»º³åÇøÒç¶Âí½Å£¨CVE-2021-20038£©£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬ÓÉÓÚÉ豸µÄApache httpd·þÎñÆ÷ÖеÄHTTP GET²½ÖèµÄ»·¾³±äÁ¿Ê¹ÓÃÁËstrcat()º¯Êýµ¼Öµģ»£»£»£»£»£»£»£»Æä´ÎÊÇ»º³åÇøÒç¶Âí½Å£¨CVE-2021-20045£©£¬£¬£¬£¬£¬CVSSÆÀ·Ö9.4¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬»¹½¨¸´ÁË»º³åÇøÒç¶Âí½Å£¨CVE-2021-20043£©ºÍÈÏÖ¤ºÅÁî×¢Èë·ì϶£¨CVE-2021-20039£©µÈ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.cisa.gov/uscert/ncas/current-activity/2021/12/08/sonicwall-releases-security-advisory-sma-100-series-appliances
5¡¢ÐÂÀÕË÷Èí¼þCerber¶Ô×¼ConfluenceºÍGitLab·þÎñÆ÷
12ÔÂ7ÈÕ£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖʹÓÃÁ˾ÉÃû³ÆµÄÐÂÀÕË÷Èí¼þCerber¡£¡£¡£¡£¡£¡£ÀÕË÷Èí¼þCerberÓÚ2016Äê³öÏÖ£¬£¬£¬£¬£¬Ö±µ½2019Äêµ×Òþû¡£¡£¡£¡£¡£¡£´ÓÉϸöÔÂÆðÍ·£¬£¬£¬£¬£¬Cerbe»Ø¹é£¬£¬£¬£¬£¬µ«ÊÇËüÓë¾É°æ²¢²»Ò»Ñù£¬£¬£¬£¬£¬´úÂ벻ƥÅ䣬£¬£¬£¬£¬Ð°æÊ¹ÓÃCrypto+++¿â¶ø¾É°æ±¾Ê¹ÓÃWindows CryptoAPI¿â£¬£¬£¬£¬£¬²¢ÇҾɰæCerberҲûÓÐLinux±äÌå¡£¡£¡£¡£¡£¡£ÐÂCerberµÄÊê½ðÒªÇó´Ó1000ÃÀÔªµ½3000ÃÀÔª²»µÈ£¬£¬£¬£¬£¬ÀûÓÃÁËCVE-2021-26084ºÍCVE-2021-22205·ì϶¶Ô×¼ConfluenceºÍGitLab·þÎñÆ÷£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÃÀ¹ú¡¢µÂ¹úºÍÖйú¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-cerber-ransomware-targets-confluence-and-gitlab-servers/


¾©¹«Íø°²±¸11010802024551ºÅ