ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ28ÖÜ
Ðû²¼Ê±¼ä 2021-07-12> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2021Äê07ÔÂ05ÈÕÖÁ07ÔÂ11ÈÕ¹²ÊÕ¼Çå¾²Îó²î61¸ö£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇAdvantech WebAccess Node BwFreRPTÕ»Òç³ö´úÂëÖ´ÐÐÎó²î£»£»£»£»£»Microsoft Teams ElectronJSÖ¡ÖØ¶¨Ïò´úÂëÖ´ÐÐÎó²î£»£»£»£»£»NPort IA5000A-I/O Series CVE-2021-32968¾Ü¾øÐ§ÀÍÎó²î£»£»£»£»£»Phoenix Contact Automationworx BCPÎļþÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î£»£»£»£»£»Siemens Simcenter Femap FEMAPÔ½½çд´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÈðµäÁ¬Ëø³¬ÊÐCoopÒòKaseya¹©Ó¦Á´¹¥»÷¹Ø±ÕÊý°Ù¼ÒÃŵꣻ£»£»£»£»ÃÀ¹ú°ü¹Ü¹«Ë¾AJG³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬¿Í»§ÐÅϢй¶£»£»£»£»£»CISAºÍFBIÐû²¼Õë¶ÔKaseya¹©Ó¦Á´¹¥»÷Êܺ¦ÕßµÄÖ¸ÄÏ£»£»£»£»£»Î¢ÈíÐû²¼µÄPrintNightmareµÄ½ôÆÈ¸üпɱ»Èƹý£»£»£»£»£»Kaspersky·¢Ã÷WildPressureÕë¶ÔmacOSµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£
> Ö÷ÒªÇå¾²Îó²îÁбí
1.Advantech WebAccess Node BwFreRPTÕ»Òç³ö´úÂëÖ´ÐÐÎó²î
Advantech WebAccess Node BwFreRPT±£´æÕ»Òç³öÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄ0x2711 IOCTLÇëÇ󣬣¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-779/
2.Microsoft Teams ElectronJSÖ¡ÖØ¶¨Ïò´úÂëÖ´ÐÐÎó²î
Microsoft Teams ElectronJSÖ¡±£»£»£»£»£»¤±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâÇëÇ󣬣¬£¬£¬¿ÉÖØ¶¨Ïò¶ñÒâÒ³Ãæ£¬£¬£¬£¬»á¼ûÄÚ²¿Ó¦Óù¤¾ß£¬£¬£¬£¬ÌáÉýȨÏÞ¡£¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-772/
3.NPort IA5000A-I/O Series CVE-2021-32968¾Ü¾øÐ§ÀÍÎó²î
NPort IA5000A-I/O SeriesÄÚ²¿WEBЧÀͱ£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâÇëÇ󣬣¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⡣¡£¡£¡£¡£¡£
https://us-cert.cisa.gov/ics/advisories/icsa-21-187-01
4.Phoenix Contact Automationworx BCPÎļþÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î
Phoenix Contact Automationworx BCPÎļþ´¦Öóͷ£±£´æÄÚ´æÆÆËðÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-782/
5.Siemens Simcenter Femap FEMAPÔ½½çд´úÂëÖ´ÐÐÎó²î
Siemens Simcenter Femap FEMAPÎļþ´¦Öóͷ£±£´æÔ½½çдÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-781/
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢ÈðµäÁ¬Ëø³¬ÊÐCoopÒòKaseya¹©Ó¦Á´¹¥»÷¹Ø±ÕÊý°Ù¼ÒÃŵê

ÈðµäÁ¬Ëø³¬ÊÐCoop³ÆÆäÔâµ½ÁËKaseya¹©Ó¦Á´¹¥»÷£¬£¬£¬£¬Êý°Ù¼ÒÃÅµê¹Ø±Õ¡£¡£¡£¡£¡£¡£CoopµÄ½²»°ÈËÌåÏÖÆäÓÚÉÏÖÜÎåÍíÉÏ6µã30·Ö×óÓÒ·¢Ã÷ÓÐÉÙÊýÃŵ귺ÆðÎÊÌ⣬£¬£¬£¬µ«Ò»Ò¹Ö®ºóÆä´ó²¿·ÖÃŵ궼±»ÆÈ¹Ø±Õ£¬£¬£¬£¬°üÀ¨ÊÕÒøÌ¨ºÍ×ÔÖú½áÕËÔÚÄÚµÄÕû¸öÖ§¸¶ÏµÍ³¶¼ÖÐÖ¹ÁË¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬CoopûÓÐʹÓÃKesayaÈí¼þ£¬£¬£¬£¬ÓÉÓÚËûÃǵÄÒ»¸öÈí¼þÌṩÉÌʹÓÃÁ˸ÃÈí¼þ¶øÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£Çå¾²¹«Ë¾HuntressLabs³Æ£¬£¬£¬£¬´Ë´Î¹¥»÷»î¶¯µÄÊÓ²ìÈÔÔÚ¾ÙÐÐÖУ¬£¬£¬£¬ÖÁÉÙÓÐ200¼Ò×éÖ¯Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/119663/cyber-crime/coop-supermarket-kaseya-ransomware-attack.html
2¡¢ÃÀ¹ú°ü¹Ü¹«Ë¾AJG³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬¿Í»§ÐÅϢй¶

ÃÀ¹úArthur J. Gallagher (AJG) ³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬¿Í»§ÐÅϢй¶¡£¡£¡£¡£¡£¡£AJGÊÇÃÀ¹úµÄÈ«Çò°ü¹Ü¾¼ÍºÍΣº¦ÖÎÀí¹«Ë¾£¬£¬£¬£¬×÷ΪȫÇò×î´óµÄ°ü¹Ü¾¼ÍÉÌÖ®Ò»£¬£¬£¬£¬ÓªÒµÆÕ±é49¸ö¹ú¼Ò/µØÇø¡£¡£¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚ2020Äê6ÔÂ3ÈÕÖÁ2020Äê9ÔÂ26ÈÕʱ´ú£¬£¬£¬£¬ÆäÔÚ2020Äê9ÔÂ28ÈÕÅû¶¸ÃÊÂÎñ²¢³ÆÃ»ÓÐÊý¾Ýй¶¡£¡£¡£¡£¡£¡£µ«ÔÚËæºóµÄÊӲ췢Ã÷£¬£¬£¬£¬7376È˵ÄÃô¸ÐÐÅϢй¶£¬£¬£¬£¬°üÀ¨Éç»áÇå¾²ºÅÂë»ò˰ºÅ¡¢¼ÝÕÕ¡¢»¤ÕÕ¡¢³öÉúÈÕÆÚ¡¢Óû§ÃûºÍÃÜÂë¡¢Ô±¹¤Ê¶ÓÖÃû¡¢²ÆÎñÕË»§»òÐÅÓÿ¨ÐÅÏ¢¡¢µç×ÓÊðÃû¡¢Ò½ÁÆÐÅÏ¢¡¢°ü¹ÜÐÅÏ¢ÒÔ¼°ÉúÎïʶ±ðÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/us-insurance-giant-ajg-reports-data-breach-after-ransomware-attack/
3¡¢CISAºÍFBIÐû²¼Õë¶ÔKaseya¹©Ó¦Á´¹¥»÷Êܺ¦ÕßµÄÖ¸ÄÏ

CISAºÍFBIÁªºÏÐû²¼ÁËÕë¶ÔÊܵ½Kaseya¹©Ó¦Á´¹¥»÷Ó°ÏìµÄÊܺ¦ÕßµÄÖ¸ÄÏ¡£¡£¡£¡£¡£¡£ÕâÁ½¸ö»ú¹¹½¨Òé×é֯ʹÓÃKaseyaÌṩµÄ¼ì²â¹¤¾ßÀ´¼ì²éËûÃǵÄϵͳÊÇ·ñ±£´æÈëÇÖ¼£Ï󣬣¬£¬£¬²¢ÆôÓöàÒòËØÉí·ÝÑéÖ¤(MFA)¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬×éÖ¯»¹Ó¦Ê¹Óð×Ãûµ¥À´ÍⲿÏÞÖÆ¶ÔÆäÄÚ²¿×ʲúµÄ»á¼û£¬£¬£¬£¬²¢Ê¹Ó÷À»ðǽ»òVPN±£»£»£»£»£»¤ÆäÔ¶³Ì¼à¿Ø¹¤¾ßµÄÖÎÀí½çÃæ¡£¡£¡£¡£¡£¡£¶øÊÜÓ°ÏìµÄMSP¿Í»§ÐèҪȷ±£±¸·ÝÊÇ×îÐµģ¬£¬£¬£¬²¢ÇÒÁ¬Ã¦×°Öù©Ó¦ÉÌÌṩµÄ×îеIJ¹¶¡¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/119728/cyber-crime/cisa-fbi-guidance-kaseya-attack.html
4¡¢Î¢ÈíÐû²¼µÄPrintNightmareµÄ½ôÆÈ¸üпɱ»Èƹý

MicrosoftÐû²¼KB5004945½ôÆÈÇå¾²¸üУ¬£¬£¬£¬ÐÞ¸´Ó°ÏìËùÓÐWindows Print SpoolerЧÀÍÖб»Æð¾¢Ê¹ÓõÄPrintNightmare 0day¡£¡£¡£¡£¡£¡£¸ÃÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-34527£©ÔÊÐí¹¥»÷ÕßʹÓÃSYSTEMȨÏÞµÄÔ¶³ÌÖ´ÐдúÂë²¢ÍêÈ«½ÓÊÜÄ¿µÄЧÀÍÆ÷¡£¡£¡£¡£¡£¡£ÔÚ¸üÐÂÐû²¼ºó£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷¸Ã²¹¶¡½öÐÞ¸´ÁËÉæ¼°Ô¶³Ì´úÂëÖ´ÐеÄ×é¼þ£¬£¬£¬£¬Òò´ËÑо¿Ö°Ô±×îÏÈÐÞ¸ÄÎó²îʹÓóÌÐò²¢²âÊÔ²¹¶¡£¡£¡£¡£¡£¡£¬£¬£¬£¬È·¶¨¿ÉÒÔÍêÈ«ÈÆ¹ýÕû¸ö²¹¶¡À´ÊµÏÖÍâµØÌáȨºÍÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-pushes-emergency-update-for-windows-printnightmare-zero-day/
5¡¢Kaspersky·¢Ã÷WildPressureÕë¶ÔmacOSµÄ¹¥»÷»î¶¯

KasperskyµÄÑо¿Ö°Ô±·¢Ã÷WildPressureÔÚ×î½üµÄ¹¥»÷»î¶¯ÖÐÔöÌíÁËÕë¶ÔmacOSµÄ¶ñÒâÈí¼þ±äÌå¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÓÚ2020Äê3ÔÂÊ״η¢Ã÷¸ÃÍŻ£¬£¬£¬ÆäʱWildPressureʹÓÃÁËC++°æ±¾µÄMilumľÂí¹¥»÷Öж«µÄ×éÖ¯¡£¡£¡£¡£¡£¡£ÔÚ½üÆÚÕë¶ÔÄÜÔ´ÐÐÒµµÄ¹¥»÷ÖУ¬£¬£¬£¬MilumÒѾͨ¹ýPyInstaller°ü¾ÙÐÐÁËÖØ×飬£¬£¬£¬ÆäÖаüÀ¨ÁËÓëWindowsºÍmacOSϵͳ¼æÈݵÄľÂí³ÌÐò£¬£¬£¬£¬±»ºÚµÄÍøÕ¾¿É±»APT×éÖ¯ÓÃÀ´ÏÂÔØºÍÉÏ´«Îļþ²¢Ö´ÐÐÏÂÁî¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/macos-wildpressure-apt/167606/


¾©¹«Íø°²±¸11010802024551ºÅ