ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ9ÖÜ
Ðû²¼Ê±¼ä 2021-03-01> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2021Äê02ÔÂ22ÈÕÖÁ02ÔÂ28ÈÕ¹²ÊÕ¼Çå¾²Îó²î53¸ö£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇNETGEAR Nighthawk R7800Ó²±àÂëÑéÖ¤ÈÆ¹ýÎó²î£»£»£»Siemens SINEC NMS FirmwareFileUtils extractToFolderĿ¼±éÀú´úÂëÖ´ÐÐÎó²î£»£»£»TP-Link AC1750 sync-serverÕ»Òç³öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»On Netshield NANO CVE-2021-3149ÏÂÁî×¢ÈëÎó²î£»£»£»Adobe Bridge CVE-2021-21065Ô½½çд´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇ΢Èí·¢Ã÷Windows Win32kÌáȨ0dayÒѱ»ÔÚҰʹÓ㻣»£»Ð¶ñÒâÈí¼þSilver SparrowÒÑѬȾ½ü3Íǫ̀Mac×°±¸£»£»£»FireEye³ÆÕë¶ÔAccellion FTAµÄ¹¥»÷ÓëFIN11Óйأ»£»£»·É»úÖÆÔìÉÌBombardier³ÆÆäÊý¾ÝÒÑÔÚClopÍøÕ¾ÉϹûÕæ£»£»£»·ÒÀ¼TietoEVRYÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬¿Í»§Ð§ÀÍÔÝʱÖÐÖ¹¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£
> Ö÷ÒªÇå¾²Îó²îÁбí
1.NETGEAR Nighthawk R7800Ó²±àÂëÑéÖ¤ÈÆ¹ýÎó²î
NETGEAR Nighthawk R7800 apply_save.cgiʹÓÃÓ²±àÂëÎó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬¿ÉÒÔROOTȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-252/
2.Siemens SINEC NMS FirmwareFileUtils extractToFolderĿ¼±éÀú´úÂëÖ´ÐÐÎó²î
Siemens SINEC NMS FirmwareFileUtils extractToFolder±£´æÄ¿Â¼±éÀúÎó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬¿ÉÒÔWEBÓ¦ÓóÌÐòÉÏÏÂÎĶÁÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-253/
3.TP-Link AC1750 sync-serverÕ»Òç³öÔ¶³Ì´úÂëÖ´ÐÐÎó²î
TP-Link AC1750 sync-server MACµØµã´¦Öóͷ£±£´æÕ»Òç³öÎó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬¿ÉÒÔROOTȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-215/
4.On Netshield NANO CVE-2021-3149ÏÂÁî×¢ÈëÎó²î
On Netshield NANO /usr/local/webmin/System/manual_ping.cgi±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬¿ÉÒÔWEBÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://www.digitaldefense.com/resources/vulnerability-research/netshield-corporation-nano-25/
5.Adobe Bridge CVE-2021-21065Ô½½çд´úÂëÖ´ÐÐÎó²î
Adobe Bridge´¦Öóͷ£Îļþ±£´æÔ½½çдÎó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»ò¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://helpx.adobe.com/security/products/bridge/apsb21-07.html
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢Î¢Èí·¢Ã÷Windows Win32kÌáȨ0dayÒѱ»ÔÚҰʹÓÃ

΢Èí·¢Ã÷Windows Win32kÖеÄÌáȨ0day£¨CVE-2021-1732£©Òѱ»ÔÚҰʹÓᣡ£¡£¡£¸ÃÎó²î±£´æÓÚwin32k.sys½¹µãÄÚºË×é¼þÖУ¬£¬£¬¹¥»÷Õß¿Éͨ¹ý´¥·¢ÊͷźóʹÓÃÎó²î½«ÆäȨÏÞÌáÉýµ½admin¼¶±ð£¬£¬£¬¾ßÓлù±¾Óû§È¨Ï޵Ĺ¥»÷Õß²»ÐèÒªÓëÓû§½»»¥¼´¿ÉʹÓøÃÎó²î¡£¡£¡£¡£¾ÝÊӲ죬£¬£¬¸ÃÎó²îÒѱ»APT×éÖ¯BitterºÍT-APT-17ʹÓ㬣¬£¬DBAPPSecurityÔò³ÆÆäÓÚ12Ô·¢Ã÷ÁË¿ª·¢ÈÕÆÚΪ2020Äê5ÔµÄÑù±¾¡£¡£¡£¡£¶ø×Ô2021Äê2ÔÂ×îÏÈ£¬£¬£¬ºÚ¿ÍÖ»ÔÚÉÙÊýÕë¶ÔÖж«µÄ¹¥»÷ÖÐʹÓÃÁËCVE-2021-1732Îó²î¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/recently-fixed-windows-zero-day-actively-exploited-since-mid-2020/
2¡¢Ð¶ñÒâÈí¼þSilver SparrowÒÑѬȾ½ü3Íǫ̀Mac×°±¸

Red CanaryÑо¿Ö°Ô±·¢Ã÷Õë¶ÔMac×°±¸µÄжñÒâÈí¼þSilver Sparrow¡£¡£¡£¡£×èÖ¹2ÔÂ17ÈÕ£¬£¬£¬Silver SparrowÒÑÔÚ153¸ö¹ú¼ÒºÍµØÇøÑ¬È¾ÁË29139¸ömacOSÖÕ¶Ë£¬£¬£¬²¢ÔÚÃÀ¹ú¡¢Ó¢¹ú¡¢¼ÓÄô󡢷¨¹úºÍµÂ¹ú´ó×ÚÈö²¥¡£¡£¡£¡£Óë´ó´ó¶¼Ê¹ÓÃ'preinstall'ºÍ'postinstall'¾ç±¾µÄ¶ñÒâÈí¼þ²î±ð£¬£¬£¬Silver SparrowʹÓÃJavaScriptÖ´ÐÐÏÂÁ£¬£¬´Ó¶øºÜÄÑÆ¾Ö¤ÏÂÁîÐвÎÊý¼ì²â¶ñÒâ»î¶¯¡£¡£¡£¡£±ðµÄ£¬£¬£¬¸Ã¶ñÒâÈí¼þµÄÕæÕýÄ¿µÄÏÖÔÚÈÔÈ»ÊǸöÃÕ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/30000-macs-infected-with-new-silver-sparrow-malware/
3¡¢FireEye³ÆÕë¶ÔAccellion FTAµÄ¹¥»÷ÓëFIN11ÓйØ

Çå¾²¹«Ë¾FireEye³Æ£¬£¬£¬2020Äê12Ôµ½2021Äê1ÔÂÖ®¼äʹÓÃAccellion FTAЧÀÍÆ÷ÖÐ0dayµÄ¹¥»÷»î¶¯ÓëFIN11Óйأ¬£¬£¬²¨¼°ÁËÈ«ÇòÔ¼100¼Ò¹«Ë¾¡£¡£¡£¡£ºÚ¿ÍÖ÷ҪʹÓÃÁËËĸöÎó²îÀ´¹¥»÷FTAЧÀÍÆ÷£¬£¬£¬²¢×°ÖÃÁËÒ»¸öÃûΪDEWMODEµÄWeb Shell£¬£¬£¬À´ÏÂÔØÊܺ¦ÕßFTA×°±¸ÉÏ´æ´¢µÄÎļþ¡£¡£¡£¡£ÊÜÓ°ÏìµÄ¹«Ë¾ºÍ×éÖ¯°üÀ¨Fugro¡¢Danaher¡¢Singtel¡¢Jones¡¢ÐÂÎ÷À¼´¢±¸ÒøÐкͰĴóÀûÑÇ֤ȯºÍͶ×ÊίԱ»á£¨ASIC£©µÈ¡£¡£¡£¡£±ðµÄ£¬£¬£¬ºÚ¿ÍÔÚClopµÄÊý¾ÝÐ¹Â¶ÍøÕ¾ÉÏÁгöÁ˲¿·Ö¹«Ë¾£¬£¬£¬ÒÔÚ²ÆÀÕË÷¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/attacks-targeting-accellion-product-linked-fin11-cybercrime-group
4¡¢·É»úÖÆÔìÉÌBombardier³ÆÆäÊý¾ÝÒÑÔÚClopÍøÕ¾ÉϹûÕæ

¼ÓÄôó·É»úÖÆÔìÉÌBombardier³ÆÆäÊý¾ÝÒÑÔÚClopÍøÕ¾ÉϹûÕæ¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚͨ¸æÖÐÌåÏÖ£¬£¬£¬¾³õ³ÌÐò²é£¬£¬£¬ºÚ¿ÍʹÓÃÁ˵ÚÈý·½Îļþ´«ÊäÓ¦ÓÃÖеÄÎó²îÀ´»á¼ûºÍÇÔÈ¡Êý¾Ý¡£¡£¡£¡£Ö»¹Ü²¢Ã»ÓÐÏêϸָ³ö¸Ã×°±¸µÄÃû³Æ£¬£¬£¬µ«¾ÝÍÆ²âºÜ¿ÉÄÜÊÇÖ¸µÄAccellion FTA¡£¡£¡£¡£±»µÁÊý¾ÝÒÑÔÚÀÕË÷ÍÅ»ïClopµÄÊý¾ÝÐ¹Â¶ÍøÕ¾¹ûÕæ£¬£¬£¬°üÀ¨BombardierÖÖÖÖ·É»úºÍ·É»úÁã¼þµÄÉè¼ÆÎļþ£¬£¬£¬²¢Ã»ÓÐÈκÎСÎÒ˽¼ÒÊý¾Ýй¶¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/airplane-maker-bombardier-data-posted-on-ransomware-leak-site-following-fta-hack/
5¡¢·ÒÀ¼TietoEVRYÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬¿Í»§Ð§ÀÍÔÝʱÖÐÖ¹

·ÒÀ¼ITЧÀ͹«Ë¾TietoEVRYÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬¿Í»§Ð§ÀÍÔÝʱÖÐÖ¹¡£¡£¡£¡£TietoEVRYÊÇÒ»¼ÒÈí¼þ¿ª·¢ºÍITЧÀ͹«Ë¾£¬£¬£¬ÔÚ80¸ö¹ú¼ÒºÍµØÇøÓµÓÐ24000ÃûÔ±¹¤£¬£¬£¬2019ÄêµÄÊÕÈëΪ29.5ÒÚÅ·Ôª¡£¡£¡£¡£±¾ÖÜÒ»£¬£¬£¬TietoEVRYµÄÁãÊÛ¡¢ÖÆÔìºÍЧÀÍÏà¹ØÐÐÒµµÄ25¸ö¿Í»§ÌåÏÖÆäÓöµ½ÁËÊÖÒÕÎÊÌ⣬£¬£¬ØÊºóµÃÖªÕâЩÎÊÌâÊÇÓÉÀÕË÷Èí¼þ¹¥»÷ÒýÆðµÄ¡£¡£¡£¡£TietoEVRY·¢Ã÷¹¥»÷ºóÁ¬Ã¦¹Ø±ÕÁËÊÜÓ°ÏìµÄϵͳºÍЧÀÍ£¬£¬£¬²¢ÓëµØ·½Õþ¸®¶Ô´ËÊÂÕö¿ªÊӲ졣¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/finnish-it-services-giant-tietoevry-discloses-ransomware-attack/


¾©¹«Íø°²±¸11010802024551ºÅ