ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ28ÖÜ

Ðû²¼Ê±¼ä 2021-07-12

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2021Äê07ÔÂ05ÈÕÖÁ07ÔÂ11ÈÕ¹²ÊÕ¼Çå¾²Îó²î61¸ö £¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇAdvantech WebAccess Node BwFreRPTÕ»Òç³ö´úÂëÖ´ÐÐÎó²î£»£»£»£»£» £»£»Microsoft Teams ElectronJSÖ¡ÖØ¶¨Ïò´úÂëÖ´ÐÐÎó²î£»£»£»£»£» £»£»NPort IA5000A-I/O Series CVE-2021-32968¾Ü¾øÐ§ÀÍÎó²î£»£»£»£»£» £»£»Phoenix Contact Automationworx BCPÎļþÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î£»£»£»£»£» £»£»Siemens Simcenter Femap FEMAPÔ½½çд´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÈðµäÁ¬Ëø³¬ÊÐCoopÒòKaseya¹©Ó¦Á´¹¥»÷¹Ø±ÕÊý°Ù¼ÒÃŵꣻ£»£»£»£» £»£»ÃÀ¹ú°ü¹Ü¹«Ë¾AJG³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷ £¬£¬£¬£¬¿Í»§ÐÅϢй¶£»£»£»£»£» £»£»CISAºÍFBIÐû²¼Õë¶ÔKaseya¹©Ó¦Á´¹¥»÷Êܺ¦ÕßµÄÖ¸ÄÏ£»£»£»£»£» £»£»Î¢ÈíÐû²¼µÄPrintNightmareµÄ½ôÆÈ¸üпɱ»Èƹý£»£»£»£»£» £»£»Kaspersky·¢Ã÷WildPressureÕë¶ÔmacOSµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö £¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£


> Ö÷ÒªÇå¾²Îó²îÁбí


1.Advantech WebAccess Node BwFreRPTÕ»Òç³ö´úÂëÖ´ÐÐÎó²î


Advantech WebAccess Node BwFreRPT±£´æÕ»Òç³öÎó²î £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄ0x2711 IOCTLÇëÇó £¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£» £»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-779/


2.Microsoft Teams ElectronJSÖ¡ÖØ¶¨Ïò´úÂëÖ´ÐÐÎó²î


Microsoft Teams ElectronJSÖ¡±£»£»£»£»£» £»£»¤±£´æÇå¾²Îó²î £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâÇëÇó £¬£¬£¬£¬¿ÉÖØ¶¨Ïò¶ñÒâÒ³Ãæ £¬£¬£¬£¬»á¼ûÄÚ²¿Ó¦Óù¤¾ß £¬£¬£¬£¬ÌáÉýȨÏÞ¡£¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-772/


3.NPort IA5000A-I/O Series CVE-2021-32968¾Ü¾øÐ§ÀÍÎó²î


NPort IA5000A-I/O SeriesÄÚ²¿WEBЧÀͱ£´æ»º³åÇøÒç³öÎó²î £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâÇëÇó £¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⡣¡£¡£¡£¡£¡£

https://us-cert.cisa.gov/ics/advisories/icsa-21-187-01


4.Phoenix Contact Automationworx BCPÎļþÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î


Phoenix Contact Automationworx BCPÎļþ´¦Öóͷ£±£´æÄÚ´æÆÆËðÎó²î £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇó £¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö £¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£» £»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-782/


5.Siemens Simcenter Femap FEMAPÔ½½çд´úÂëÖ´ÐÐÎó²î


Siemens Simcenter Femap FEMAPÎļþ´¦Öóͷ£±£´æÔ½½çдÎó²î £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇó £¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö £¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£» £»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-781/


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢ÈðµäÁ¬Ëø³¬ÊÐCoopÒòKaseya¹©Ó¦Á´¹¥»÷¹Ø±ÕÊý°Ù¼ÒÃŵê


1.jpg


ÈðµäÁ¬Ëø³¬ÊÐCoop³ÆÆäÔâµ½ÁËKaseya¹©Ó¦Á´¹¥»÷ £¬£¬£¬£¬Êý°Ù¼ÒÃÅµê¹Ø±Õ¡£¡£¡£¡£¡£¡£CoopµÄ½²»°ÈËÌåÏÖÆäÓÚÉÏÖÜÎåÍíÉÏ6µã30·Ö×óÓÒ·¢Ã÷ÓÐÉÙÊýÃŵ귺ÆðÎÊÌâ £¬£¬£¬£¬µ«Ò»Ò¹Ö®ºóÆä´ó²¿·ÖÃŵ궼±»ÆÈ¹Ø±Õ £¬£¬£¬£¬°üÀ¨ÊÕÒøÌ¨ºÍ×ÔÖú½áÕËÔÚÄÚµÄÕû¸öÖ§¸¶ÏµÍ³¶¼ÖÐÖ¹ÁË¡£¡£¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬CoopûÓÐʹÓÃKesayaÈí¼þ £¬£¬£¬£¬ÓÉÓÚËûÃǵÄÒ»¸öÈí¼þÌṩÉÌʹÓÃÁ˸ÃÈí¼þ¶øÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£Çå¾²¹«Ë¾HuntressLabs³Æ £¬£¬£¬£¬´Ë´Î¹¥»÷»î¶¯µÄÊÓ²ìÈÔÔÚ¾ÙÐÐÖÐ £¬£¬£¬£¬ÖÁÉÙÓÐ200¼Ò×éÖ¯Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/119663/cyber-crime/coop-supermarket-kaseya-ransomware-attack.html


2¡¢ÃÀ¹ú°ü¹Ü¹«Ë¾AJG³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷ £¬£¬£¬£¬¿Í»§ÐÅϢй¶


2.jpg


ÃÀ¹úArthur J. Gallagher (AJG) ³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷ £¬£¬£¬£¬¿Í»§ÐÅϢй¶¡£¡£¡£¡£¡£¡£AJGÊÇÃÀ¹úµÄÈ«Çò°ü¹Ü¾­¼ÍºÍΣº¦ÖÎÀí¹«Ë¾ £¬£¬£¬£¬×÷ΪȫÇò×î´óµÄ°ü¹Ü¾­¼ÍÉÌÖ®Ò» £¬£¬£¬£¬ÓªÒµÆÕ±é49¸ö¹ú¼Ò/µØÇø¡£¡£¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚ2020Äê6ÔÂ3ÈÕÖÁ2020Äê9ÔÂ26ÈÕʱ´ú £¬£¬£¬£¬ÆäÔÚ2020Äê9ÔÂ28ÈÕÅû¶¸ÃÊÂÎñ²¢³ÆÃ»ÓÐÊý¾Ýй¶¡£¡£¡£¡£¡£¡£µ«ÔÚËæºóµÄÊӲ췢Ã÷ £¬£¬£¬£¬7376È˵ÄÃô¸ÐÐÅϢй¶ £¬£¬£¬£¬°üÀ¨Éç»áÇå¾²ºÅÂë»ò˰ºÅ¡¢¼ÝÕÕ¡¢»¤ÕÕ¡¢³öÉúÈÕÆÚ¡¢Óû§ÃûºÍÃÜÂë¡¢Ô±¹¤Ê¶ÓÖÃû¡¢²ÆÎñÕË»§»òÐÅÓÿ¨ÐÅÏ¢¡¢µç×ÓÊðÃû¡¢Ò½ÁÆÐÅÏ¢¡¢°ü¹ÜÐÅÏ¢ÒÔ¼°ÉúÎïʶ±ðÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-insurance-giant-ajg-reports-data-breach-after-ransomware-attack/


3¡¢CISAºÍFBIÐû²¼Õë¶ÔKaseya¹©Ó¦Á´¹¥»÷Êܺ¦ÕßµÄÖ¸ÄÏ


3.jpg


CISAºÍFBIÁªºÏÐû²¼ÁËÕë¶ÔÊܵ½Kaseya¹©Ó¦Á´¹¥»÷Ó°ÏìµÄÊܺ¦ÕßµÄÖ¸ÄÏ¡£¡£¡£¡£¡£¡£ÕâÁ½¸ö»ú¹¹½¨Òé×é֯ʹÓÃKaseyaÌṩµÄ¼ì²â¹¤¾ßÀ´¼ì²éËûÃǵÄϵͳÊÇ·ñ±£´æÈëÇÖ¼£Ïó £¬£¬£¬£¬²¢ÆôÓöàÒòËØÉí·ÝÑéÖ¤(MFA)¡£¡£¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬×éÖ¯»¹Ó¦Ê¹Óð×Ãûµ¥À´ÍⲿÏÞÖÆ¶ÔÆäÄÚ²¿×ʲúµÄ»á¼û £¬£¬£¬£¬²¢Ê¹Ó÷À»ðǽ»òVPN±£»£»£»£»£» £»£»¤ÆäÔ¶³Ì¼à¿Ø¹¤¾ßµÄÖÎÀí½çÃæ¡£¡£¡£¡£¡£¡£¶øÊÜÓ°ÏìµÄMSP¿Í»§ÐèҪȷ±£±¸·ÝÊÇ×îÐ嵀 £¬£¬£¬£¬²¢ÇÒÁ¬Ã¦×°Öù©Ó¦ÉÌÌṩµÄ×îеIJ¹¶¡¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/119728/cyber-crime/cisa-fbi-guidance-kaseya-attack.html


4¡¢Î¢ÈíÐû²¼µÄPrintNightmareµÄ½ôÆÈ¸üпɱ»Èƹý


4.jpg


MicrosoftÐû²¼KB5004945½ôÆÈÇå¾²¸üР£¬£¬£¬£¬ÐÞ¸´Ó°ÏìËùÓÐWindows Print SpoolerЧÀÍÖб»Æð¾¢Ê¹ÓõÄPrintNightmare 0day¡£¡£¡£¡£¡£¡£¸ÃÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-34527£©ÔÊÐí¹¥»÷ÕßʹÓÃSYSTEMȨÏÞµÄÔ¶³ÌÖ´ÐдúÂë²¢ÍêÈ«½ÓÊÜÄ¿µÄЧÀÍÆ÷¡£¡£¡£¡£¡£¡£ÔÚ¸üÐÂÐû²¼ºó £¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷¸Ã²¹¶¡½öÐÞ¸´ÁËÉæ¼°Ô¶³Ì´úÂëÖ´ÐеÄ×é¼þ £¬£¬£¬£¬Òò´ËÑо¿Ö°Ô±×îÏÈÐÞ¸ÄÎó²îʹÓóÌÐò²¢²âÊÔ²¹¶¡ £¬£¬£¬£¬È·¶¨¿ÉÒÔÍêÈ«ÈÆ¹ýÕû¸ö²¹¶¡À´ÊµÏÖÍâµØÌáȨºÍÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-pushes-emergency-update-for-windows-printnightmare-zero-day/


5¡¢Kaspersky·¢Ã÷WildPressureÕë¶ÔmacOSµÄ¹¥»÷»î¶¯


5.jpg


KasperskyµÄÑо¿Ö°Ô±·¢Ã÷WildPressureÔÚ×î½üµÄ¹¥»÷»î¶¯ÖÐÔöÌíÁËÕë¶ÔmacOSµÄ¶ñÒâÈí¼þ±äÌå¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÓÚ2020Äê3ÔÂÊ״η¢Ã÷¸ÃÍÅ»ï £¬£¬£¬£¬ÆäʱWildPressureʹÓÃÁËC++°æ±¾µÄMilumľÂí¹¥»÷Öж«µÄ×éÖ¯¡£¡£¡£¡£¡£¡£ÔÚ½üÆÚÕë¶ÔÄÜÔ´ÐÐÒµµÄ¹¥»÷ÖÐ £¬£¬£¬£¬MilumÒѾ­Í¨¹ýPyInstaller°ü¾ÙÐÐÁËÖØ×é £¬£¬£¬£¬ÆäÖаüÀ¨ÁËÓëWindowsºÍmacOSϵͳ¼æÈݵÄľÂí³ÌÐò £¬£¬£¬£¬±»ºÚµÄÍøÕ¾¿É±»APT×éÖ¯ÓÃÀ´ÏÂÔØºÍÉÏ´«Îļþ²¢Ö´ÐÐÏÂÁî¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/macos-wildpressure-apt/167606/