ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ37ÖÜ

Ðû²¼Ê±¼ä 2021-09-14

>±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2021Äê09ÔÂ06ÈÕÖÁ09ÔÂ12ÈÕ¹²ÊÕ¼Çå¾²Îó²î58¸ö£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApple iOS Wi-Fi»º³åÇøÒç³ö´úÂëÖ´ÐÐÎó²î£»£»£»£»£»Delta Electronics DOPSoftÏîÄ¿ÎļþÔ½½çдÎó²î£»£»£»£»£»QNAP NAS CVE-2021-34343Õ»Òç³ö´úÂëÖ´ÐÐÎó²î£»£»£»£»£»Google Android Frameworkí§Òâ´úÂëÖ´ÐÐÎó²î£»£»£»£»£»Cisco IOS XR Software CVE-2021-34719ÌØÈ¨ÌáÉýÎó²î¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÐÂÎ÷À¼»¥ÁªÍøÔËÓªÉÌVocusÔâµ½´ó¹æÄ£DDoS¹¥»÷£»£»£»£»£»Google TensorFlowΪÐÞ¸´RCEÎó²î¶ø²»ÔÙÖ§³ÖYAML£»£»£»£»£»FortiGuardÐû²¼2021ÄêH1È«ÇòÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ£»£»£»£»£»Î¢ÈíÐû²¼MSHTMLÖÐRCEÎó²î£¨CVE-2021-40444£©µÄͨ¸æ£»£»£»£»£»Ñо¿Ö°Ô±·¢Ã÷REvilÍÅ»ïµÄÊý¾ÝÐ¹Â¶ÍøÕ¾ÔÙ¶ÈÉÏÏß¡£¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£


>Ö÷ÒªÇå¾²Îó²îÁбí


1.Apple iOS Wi-Fi»º³åÇøÒç³ö´úÂëÖ´ÐÐÎó²î


Apple iOS Wi-Fi±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£


https://support.apple.com/en-us/HT212317


2.Delta Electronics DOPSoftÏîÄ¿ÎļþÔ½½çдÎó²î


Delta Electronics DOPSoft´¦Öóͷ£ÏîÄ¿Îļþ±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬£¬¿ÉʹϵͳÍ߽⻣»£»£»£»òÕßÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£


https://us-cert.cisa.gov/ics/advisories/icsa-21-252-02



3.QNAP NAS CVE-2021-34343Õ»Òç³ö´úÂëÖ´ÐÐÎó²î


QNAP NAS±£´æÕ»Òç³öÎó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬¿ÉʹϵͳÍ߽⻣»£»£»£»òÕßÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£


https://www.qnap.com/en/security-advisory/qsa-21-33



4.Google Android Frameworkí§Òâ´úÂëÖ´ÐÐÎó²î


Google Android Framework±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£


https://source.android.com/security/bulletin/2021-09-01



5.Cisco IOS XR Software CVE-2021-34719ÌØÈ¨ÌáÉýÎó²î


Cisco IOS XR SoftwareÏÂÁîÐвÎÊýʵÏÖ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÍâµØ¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬¿ÉÌáÉýȨÏÞ£¬£¬£¬£¬£¬£¬£¬»ñÈ¡ROOTȨÏÞ¡£¡£¡£¡£¡£¡£


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-privescal-dZYMrKf



>Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢ÐÂÎ÷À¼»¥ÁªÍøÔËÓªÉÌVocusÔâµ½´ó¹æÄ£DDoS¹¥»÷


ÐÂÎ÷À¼»¥ÁªÍøÔËÓªÉÌVocusÔâµ½´ó¹æÄ£DDoS¹¥»÷.jpg


ÐÂÎ÷À¼µÚÈý´ó»¥ÁªÍøÔËÓªÉÌVocus ISP³ÆÆäÔÚ9ÔÂ3ÈÕÔâµ½´ó¹æÄ£DDoS¹¥»÷£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂЧÀÍÖÐÖ¹ÁËÔ¼30·ÖÖÓ¡£¡£¡£¡£¡£¡£VocusÔÚ°Ä´óÀûÑǺÍÐÂÎ÷À¼ÌṩÁãÊÛ¡¢Åú·¢ºÍÆóÒµµçÐÅЧÀÍ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾³Æ£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÏÖÔÚÌìÏ´󲿷ֵØÇø¶¼ÔÚÔ¶³Ì°ì¹«£¬£¬£¬£¬£¬£¬£¬Òò´Ë´Ë´Î¹¥»÷¶Ô¿Í»§±¬·¢ÁËÖØ´óÓ°Ïì¡£¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾Ñ¸ËÙ»Ö¸´ÁËÔËÓª£¬£¬£¬£¬£¬£¬£¬²¢¶Ô¸ø¿Í»§´øÀ´µÄδ±ãÌåÏÖǸÒâ¡£¡£¡£¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.reuters.com/technology/widespread-internet-outages-hits-users-across-new-zealand-2021-09-03/


2¡¢Google TensorFlowΪÐÞ¸´RCEÎó²î¶ø²»ÔÙÖ§³ÖYAML


Google TensorFlowΪÐÞ¸´RCEÎó²î¶ø²»ÔÙÖ§³ÖYAML.jpg


Google¿ª·¢µÄ»ùÓÚPythonµÄ»úеѧϰºÍÈ˹¤ÖÇÄÜÏîÄ¿TensorFlowÒѾ­·ÅÆúÁ˶ÔYAMLµÄÖ§³Ö¡£¡£¡£¡£¡£¡£TensorFlow´úÂëÖеÄyaml.unsafe_load()º¯Êý±£´æÒ»¸öÎó²î£¬£¬£¬£¬£¬£¬£¬×·×ÙΪCVE-2021-37678£¬£¬£¬£¬£¬£¬£¬ÆÀ·ÖΪ9.3¡£¡£¡£¡£¡£¡£µ±Ó¦Ó÷´ÐòÁл¯YAMLÃûÌõÄKerasÄ£×Óʱ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£ÎªÐÞ¸´´ËÎó²î£¬£¬£¬£¬£¬£¬£¬TensorFlow¾öÒéÍêÈ«·ÅÆúYAMLµÄÖ§³Ö£¬£¬£¬£¬£¬£¬£¬×ª¶øÊ¹ÓÃJSON·´ÐòÁл¯¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/googles-tensorflow-drops-yaml-support-due-to-code-execution-flaw/


3¡¢FortiGuardÐû²¼2021ÄêH1È«ÇòÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ


FortiGuardÐû²¼2021ÄêH1È«ÇòÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ.jpg


FortiGuardÓÚ8Ô·ÝÐû²¼ÁË2021ÄêH1È«ÇòÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬£¬2021Äê6ÔÂÆ½¾ùÿÖÜÀÕË÷Èí¼þ»î¶¯±ÈÒ»ÄêǰͬÆÚºá¿ç10.7±¶¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬£¬µçÐÅÐÐÒµÊǹ¥»÷ÕßµÄÖ÷ÒªµÄÄ¿µÄ£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊÇÕþ¸®¡¢ÍйÜÇ徲ЧÀÍÌṩÉÌ¡¢Æû³µºÍÖÆÔìÐÐÒµ¡£¡£¡£¡£¡£¡£½©Ê¬ÍøÂçÒ²ÓÐËùÔöÌí£¬£¬£¬£¬£¬£¬£¬½ñÄêÄêÍ·ÔÚ35%µÄ×éÖ¯Öмì²âµ½Á˽©Ê¬ÍøÂç»î¶¯£¬£¬£¬£¬£¬£¬£¬¶øÕâÒ»±ÈÀýÔÚ6¸öÔºóÔöÌíΪ51%¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õ߸üÇàíùÓÚ¼ì²âÈÆ¹ýÊÖÒÕºÍÌáȨÊÖÒÕ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.fortinet.com/content/dam/fortinet/assets/threat-reports/report-threat-landscape-2021.pdf


4¡¢Î¢ÈíÐû²¼MSHTMLÖÐRCEÎó²î£¨CVE-2021-40444£©µÄͨ¸æ


΢ÈíÐû²¼MSHTMLÖÐRCEÎó²î£¨CVE-2021-40444£©µÄͨ¸æ.jpg


΢ÈíÍŶÓÔÚ9ÔÂ7ÈÕÐû²¼ÁËÕë¶ÔWindowsÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-40444£©µÄ»º½â²½·¥¡£¡£¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚMicrosoft OfficeÎĵµÊ¹ÓõÄä¯ÀÀÆ÷äÖȾÒýÇæMSHTMLÖУ¬£¬£¬£¬£¬£¬£¬ÒÑÔÚÕë¶ÔWindows 10ÉϵÄOffice 365ºÍOffice 2019µÄ¹¥»÷»î¶¯Öб»Ê¹Óᣡ£¡£¡£¡£¡£ÏÖÔÚÉÐÎÞ¿ÉÓõÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬Microsoft½¨Òé½ûÓÃInternet ExplorerÖÐËùÓеÄActiveX¿Ø¼þ×÷Ϊ»º½â²½·¥¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-shares-temp-fix-for-ongoing-office-365-zero-day-attacks/


5¡¢Ñо¿Ö°Ô±·¢Ã÷REvilÍÅ»ïµÄÊý¾ÝÐ¹Â¶ÍøÕ¾ÔÙ¶ÈÉÏÏß


Ñо¿Ö°Ô±·¢Ã÷REvilÍÅ»ïµÄÊý¾ÝÐ¹Â¶ÍøÕ¾ÔÙ¶ÈÉÏÏß.jpg


Ñо¿Ö°Ô±·¢Ã÷REvilÍÅ»ïµÄÊý¾ÝÐ¹Â¶ÍøÕ¾£¨Ò²³ÆÎª Happy Blog£©ÔÚ9ÔÂ7ÈÕÖØÐÂÉÏÏß¡£¡£¡£¡£¡£¡£7ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬£¬REvilʹÓÃKaseya VSAÖеÄÎó²î¹¥»÷ÁËԼĪ60¼ÒMSP¼°Æä1500¶à¸ö¿Í»§£¬£¬£¬£¬£¬£¬£¬²¢ÀÕË÷7000ÍòÃÀÔª¡£¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯ÒýÆðÁËÖ´·¨²¿·ÖµÄ×¢ÖØ£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ7ÔÂ13¹Ø±ÕÁËËùÓеÄTorЧÀÍÆ÷ºÍ»ù´¡ÉèÊ©¡£¡£¡£¡£¡£¡£Éв»ÇåÎú´Ë´ÎÖ§¸¶ºÍÊý¾ÝÐ¹Â¶ÍøÕ¾µÄÖØÐÂÉÏÏߣ¬£¬£¬£¬£¬£¬£¬ÊÇ·ñ´ú±íןÃÍÅ»ïÒª×îÏȸ´³ö¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/revil-ransomwares-servers-mysteriously-come-back-online/