ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ26ÖÜ

Ðû²¼Ê±¼ä 2021-06-28

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2021Äê06ÔÂ21ÈÕÖÁ06ÔÂ27ÈÕ¹²ÊÕ¼Çå¾²Îó²î53¸ö£¬£¬£¬£¬ £¬ÖµµÃ¹Ø×¢µÄÊÇWebAccess HMI DesignerÏîÄ¿ÎļþÔ½½çд´úÂëÖ´ÐÐÎó²î£»£» £»£»£»£»£»D-LINK DSL-2888A routerí§ÒâÃÜÂëÐÞ¸ÄÎó²î£»£» £»£»£»£»£»Zoho ManageEngine ADSelfService PlusÃÜÂë¸ü¸Ä´úÂëÖ´ÐÐÎó²î£»£» £»£»£»£»£»Apple macOS CoreText TTFÆÊÎöÕ»Òç³ö´úÂëÖ´ÐÐÎó²î£»£» £»£»£»£»£»WEIDMUELLER Industrial WLAN devices iw_consoleȨÏÞÌáÉýÎó²î¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÑо¿Ö°Ô±ÑÝʾÔõÑùͨ¹ýWiFiÈÈÃÅÀ´¹¥»÷iPhoneÊÖ»ú£»£» £»£»£»£»£»Ñо¿ÍŶӳƽüÆÚÀÕË÷Èí¼þ¹¥»÷Ò»Á¬¼¤Ôö£¬£¬£¬£¬ £¬Í¬±ÈÔöÌí93%£»£» £»£»£»£»£»Å²Íþ¾¯·½È·ÈÏÆäÔÚ2018ÄêÔâµ½µÄºÚ¿Í¹¥»÷ÓëAPT31ÓйØ£»£» £»£»£»£»£»Ñо¿ÍŶÓÔÚPyPI´æ´¢¿â·¢Ã÷¶à¸öÓÃÓÚÍÚ¿óµÄ¶ñÒâÈí¼þ°ü£»£» £»£»£»£»£»Zephyrʵʱ²Ù×÷ϵͳ(RTOS)Çå¾²¸üУ¬£¬£¬£¬ £¬ÐÞ¸´¶à¸öÎó²î¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬ £¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£


> Ö÷ÒªÇå¾²Îó²îÁбí


1.WebAccess HMI DesignerÏîÄ¿ÎļþÔ½½çд´úÂëÖ´ÐÐÎó²î


WebAccess HMI Designer´¦Öóͷ£ÏîÄ¿Îļþ±£´æÔ½½çдÎó²î£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ £¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬ £¬¿ÉʹӦÓóÌÐò±ÀÀ£»£» £»£»£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë

https://us-cert.cisa.gov/ics/advisories/icsa-21-173-01


2.D-LINK DSL-2888A routerí§ÒâÃÜÂëÐÞ¸ÄÎó²î


D-LINK DSL-2888A router±£´æí§ÒâÃÜÂëÐÞ¸ÄÎó²î£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ £¬¿ÉÐÞ¸ÄÖÎÀíÔ±ÃÜÂë¡£¡£¡£¡£¡£

https://github.com/EmYiQing/CVE


3.Zoho ManageEngine ADSelfService PlusÃÜÂë¸ü¸Ä´úÂëÖ´ÐÐÎó²î


Zoho ManageEngine ADSelfService Plus¸ü¸ÄÃÜÂë±£´æÇå¾²Îó²î£¬£¬£¬£¬ £¬ÔÊÐíÍâµØ¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ £¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

https://www.manageengine.com/products/self-service-password/release-notes.html#6102


4.Apple macOS CoreText TTFÆÊÎöÕ»Òç³ö´úÂëÖ´ÐÐÎó²î


Apple macOS CoreText TTFÆÊÎö±£´æÕ»Òç³öÎó²î£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ £¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬ £¬¿ÉʹӦÓóÌÐò±ÀÀ£»£» £»£»£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

https://support.apple.com/HT212147


5.WEIDMUELLER Industrial WLAN devices iw_consoleȨÏÞÌáÉýÎó²î


WEIDMUELLER Industrial WLAN devices iw_console¹¦Ð§±£´æ×ªÒåʧ°ÜÎó²î£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ £¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

https://cert.vde.com/en-us/advisories/vde-2021-026


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Ñо¿Ö°Ô±ÑÝʾÔõÑùͨ¹ýWiFiÈÈÃÅÀ´¹¥»÷iPhoneÊÖ»ú


1.jpg


Ñо¿Ö°Ô±Carl SchouÑÝʾÁËÔõÑùͨ¹ýWiFiÈÈÃÅÀ´¹¥»÷iPhoneÊÖ»ú¡£¡£¡£¡£¡£Carl SchouÔÚÅþÁ¬Ð¡ÎÒ˽¼ÒWiFiÈÈÃÅ¡°%p%s%s%s%s%n¡±Ê±£¬£¬£¬£¬ £¬·¢Ã÷ËûiPhoneµÄWiFi¹¦Ð§±»½ûÓ㬣¬£¬£¬ £¬²¢ÇÒÔÙÒ²ÎÞ·¨ÆôÓÃWiFi¹¦Ð§£¬£¬£¬£¬ £¬×ÝÈ»ËûÖØÆô×°±¸»ò¸ü¸ÄÈÈÃÅÃû³Æ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬ £¬Õâ¿ÉÄÜÊÇÊäÈëÆÊÎöÎÊÌ⵼ֵ쬣¬£¬£¬ £¬µ±WiFiÈÈÃÅÃû³ÆÖб£´æ´øÓС°%¡±µÄ×Ö·û´®Ê±£¬£¬£¬£¬ £¬iOS¿ÉÄÜ»á¹ýʧµØ½«¡°%¡±ºóÃæµÄ×ÖĸڹÊÍΪ×Ö·û´®ÃûÌÃ˵Ã÷·û¡£¡£¡£¡£¡£»£» £»£»£»£»£»Ö¸´Wi-Fi¹¦Ð§µÄΨһҪÁìÊÇÖØÖÃiPhoneµÄÍøÂçÉèÖᣡ£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬¸ÃÎó²îÊÇiPhone¶ÀÍ̵Ä£¬£¬£¬£¬ £¬ÎÞ·¨ÔÚAndroidÊÖ»úÉÏÖØÏÖ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/iphone-bug-breaks-wifi-when-you-join-hotspot-with-unusual-name/


2¡¢Ñо¿ÍŶӳƽüÆÚÀÕË÷Èí¼þ¹¥»÷Ò»Á¬¼¤Ôö£¬£¬£¬£¬ £¬Í¬±ÈÔöÌí93%


2.jpg


Check Point ResearchÑо¿ÍŶӳƽüÆÚÀÕË÷Èí¼þ¹¥»÷Ò»Á¬¼¤Ôö¡£¡£¡£¡£¡£2021Äê6ÔÂÿÖÜÊÜÀÕË÷Èí¼þÓ°ÏìµÄ×éÖ¯ÊýÄ¿ÒÑÔöÖÁ1210¸ö£¬£¬£¬£¬ £¬×ÔÄêÍ·ÒÔÀ´£¬£¬£¬£¬ £¬ÀÕË÷Èí¼þ¹¥»÷´ÎÊýÔöÌíÁË41%£¬£¬£¬£¬ £¬Í¬±ÈÔöÌíÁË93%¡£¡£¡£¡£¡£ÆäÖÐÀ­¶¡ÃÀÖÞµÄÀÕË÷Èí¼þ¹¥»÷ʵÑéÔöÌí×îΪÏÔ×Å£¬£¬£¬£¬ £¬ÔöÌíÁË62%£¬£¬£¬£¬ £¬Æä´ÎÊÇÅ·ÖÞÔöÌíÁË59%£¬£¬£¬£¬ £¬·ÇÖÞÔöÌíÁË34%£¬£¬£¬£¬ £¬±±ÃÀÔöÌíÁË32%¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬Õë¶Ô½ÌÓýÐÐÒµµÄ¹¥»÷ÔöÌíËÙÂÊ×î¿ì£¨ÓëÈ¥ÄêͬÆÚÏà±ÈÔöÌíÁË347%£©£¬£¬£¬£¬ £¬Æä´ÎΪÔËÊäÐÐÒµ£¨186%£©¡¢ÁãÊÛºÍÅú¿¯ÐÐÒµ£¨162%£©ÒÔ¼°Ò½ÁƱ£½¡ÐÐÒµ£¨159%£©¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.checkpoint.com/2021/06/14/ransomware-attacks-continue-to-surge-hitting-a-93-increase-year-over-year/


3¡¢Å²Íþ¾¯·½È·ÈÏÆäÔÚ2018ÄêÔâµ½µÄºÚ¿Í¹¥»÷ÓëAPT31ÓйØ


3.jpg


ŲÍþ¾¯Ô±Çå¾²¾Ö (PST) ÌåÏÖ£¬£¬£¬£¬ £¬ÆäÔÚ2018ÄêÔâµ½µÄÍøÂç¹¥»÷ÓëºÚ¿Í×éÖ¯APT31ÓйØ¡£¡£¡£¡£¡£¾ÝÊÓ²ìÏÔʾ£¬£¬£¬£¬ £¬Ôڴ˴ι¥»÷ÖкڿÍÒÑÀֳɻñµÃÖÎÀíԱȨÏÞ£¬£¬£¬£¬ £¬¿ÉÒÔ»á¼û¸Ã¹úËùÓйú¼ÒÐÐÕþ°ì¹«ÊÒʹÓõÄÖÐÑëÅÌËã»úϵͳ£¬£¬£¬£¬ £¬»¹ÀֳɵشӰ칫ÊÒϵͳÇÔÈ¡ÁËһЩÊý¾Ý¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬ £¬APT31»¹±»ÒÔΪÊÇ2020Äê12ÔÂÕë¶Ô·ÒÀ¼Òé»áµÄÍøÂç¹¥»÷µÄÄ»ºóºÚÊÖ£¬£¬£¬£¬ £¬Ôڴ˴ι¥»÷ÖкڿÍÀÖ³ÉÈëÇÖÁËһЩÒé»áÏà¹Øµç×ÓÓʼþµÄÕÊ»§¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/119161/apt/norway-blames-china-apt31.html


4¡¢Ñо¿ÍŶÓÔÚPyPI´æ´¢¿â·¢Ã÷¶à¸öÓÃÓÚÍÚ¿óµÄ¶ñÒâÈí¼þ°ü


4.jpg


Ñо¿ÍŶÓÔÚPythonÏîÄ¿µÄPyPI¿âÖз¢Ã÷ÁË6¸ö¶ñÒâÈí¼þ°ü£¬£¬£¬£¬ £¬¿ÉÒÔ½«¿ª·¢Ö°Ô±µÄÅÌËã»úÄð³É¿ó»ú¡£¡£¡£¡£¡£ËùÓжñÒâÈí¼þ°ü¾ùÓÉͳһÓû§¡°nedog123¡±Ðû²¼£¬£¬£¬£¬ £¬»®·ÖΪmaratlib¡¢maratlib1¡¢matplatlib-plus¡¢mllearnlib¡¢mplatlibºÍlearninglib£¬£¬£¬£¬ £¬ÆäÖд󲿷ֵÄÃû³Æ¶¼ÊÇÕýµ±»æÍ¼Èí¼þmatplotlibµÄƴд¹ýʧ°æ±¾£¬£¬£¬£¬ £¬ºÚ¿Íͨ¹ýÕâÖÖ·½·¨À´ÓÕÆ­¿ª·¢Ö°Ô±ÏÂÔØ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ¶ñÒâ´úÂë¶¼ÔÚsetup.pyÎļþÖУ¬£¬£¬£¬ £¬Ëü»áÔÚGitHub´æ´¢¿âÏÂÔØBash¾ç±¾(aza2.sh)£¬£¬£¬£¬ £¬¸Ã¾ç±¾µÄ×÷ÓÃÊÇÔÚÄ¿µÄ»úеÉÏÔËÐеļÓÃÜ¿ó¹¤Ubqminer¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/malicious-pypi-packages-hijack-dev-devices-to-mine-cryptocurrency/


5¡¢Zephyrʵʱ²Ù×÷ϵͳ(RTOS)Çå¾²¸üУ¬£¬£¬£¬ £¬ÐÞ¸´¶à¸öÎó²î


5.jpg


Zephyrʵʱ²Ù×÷ϵͳ(RTOS)Çå¾²¸üУ¬£¬£¬£¬ £¬ÐÞ¸´ÁË8¸ö¿ÉÄܵ¼Ö¾ܾøÐ§ÀÍ (DoS) ºÍÔ¶³Ì´úÂëÖ´ÐеÄÎó²î¡£¡£¡£¡£¡£ZephyrÊÇСÐ͵Äʵʱ²Ù×÷ϵͳ£¬£¬£¬£¬ £¬ÓÃÓÚ×ÊÔ´ÊÜÏÞµÄǶÈëʽ»¥Áª×°±¸£¬£¬£¬£¬ £¬»ñµÃÁËFacebook¡¢¹È¸è¡¢IntelµÈ×ÅÃû¹«Ë¾µÄÖ§³Ö£¬£¬£¬£¬ £¬Ö§³Ö200¶àÖÖ²î±ðCPU¼Ü¹¹£¨ARM¡¢Cortex-MºÍIntel x86µÈ£©¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄÎó²î±£´æÓÚZephyrµÄÀ¶ÑÀLEÁ´Â·²ã (LL) ¼°ÆäÂß¼­Á´Â·¿ØÖƺÍÊÊÅäЭÒé (L2CAP) ÖУ¬£¬£¬£¬ £¬ÆäÖнÏΪÑÏÖØµÄÊÇÐÅϢй¶Îó²î£¨CVE-2021-3435£©ºÍDoSÎó²î£¨CVE-2021-3455£©¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/zephyr-rtos-fixes-bluetooth-bugs-that-may-lead-to-code-execution/