ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ28ÖÜ
Ðû²¼Ê±¼ä 2021-07-12> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2021Äê07ÔÂ05ÈÕÖÁ07ÔÂ11ÈÕ¹²ÊÕ¼Çå¾²Îó²î61¸ö£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇAdvantech WebAccess Node BwFreRPTÕ»Òç³ö´úÂëÖ´ÐÐÎó²î£»£»£»£»Microsoft Teams ElectronJSÖ¡ÖØ¶¨Ïò´úÂëÖ´ÐÐÎó²î£»£»£»£»NPort IA5000A-I/O Series CVE-2021-32968¾Ü¾øÐ§ÀÍÎó²î£»£»£»£»Phoenix Contact Automationworx BCPÎļþÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î£»£»£»£»Siemens Simcenter Femap FEMAPÔ½½çд´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÈðµäÁ¬Ëø³¬ÊÐCoopÒòKaseya¹©Ó¦Á´¹¥»÷¹Ø±ÕÊý°Ù¼ÒÃŵꣻ£»£»£»ÃÀ¹ú°ü¹Ü¹«Ë¾AJG³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬¿Í»§ÐÅϢй¶£»£»£»£»CISAºÍFBIÐû²¼Õë¶ÔKaseya¹©Ó¦Á´¹¥»÷Êܺ¦ÕßµÄÖ¸ÄÏ£»£»£»£»Î¢ÈíÐû²¼µÄPrintNightmareµÄ½ôÆÈ¸üпɱ»Èƹý£»£»£»£»Kaspersky·¢Ã÷WildPressureÕë¶ÔmacOSµÄ¹¥»÷»î¶¯¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£
> Ö÷ÒªÇå¾²Îó²îÁбí
1.Advantech WebAccess Node BwFreRPTÕ»Òç³ö´úÂëÖ´ÐÐÎó²î
Advantech WebAccess Node BwFreRPT±£´æÕ»Òç³öÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄ0x2711 IOCTLÇëÇ󣬣¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-779/
2.Microsoft Teams ElectronJSÖ¡ÖØ¶¨Ïò´úÂëÖ´ÐÐÎó²î
Microsoft Teams ElectronJSÖ¡±£»£»£»£»¤±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâÇëÇ󣬣¬£¬£¬¿ÉÖØ¶¨Ïò¶ñÒâÒ³Ãæ£¬£¬£¬£¬»á¼ûÄÚ²¿Ó¦Óù¤¾ß£¬£¬£¬£¬ÌáÉýȨÏÞ¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-772/
3.NPort IA5000A-I/O Series CVE-2021-32968¾Ü¾øÐ§ÀÍÎó²î
NPort IA5000A-I/O SeriesÄÚ²¿WEBЧÀͱ£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâÇëÇ󣬣¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⡣¡£¡£¡£
https://us-cert.cisa.gov/ics/advisories/icsa-21-187-01
4.Phoenix Contact Automationworx BCPÎļþÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î
Phoenix Contact Automationworx BCPÎļþ´¦Öóͷ£±£´æÄÚ´æÆÆËðÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-782/
5.Siemens Simcenter Femap FEMAPÔ½½çд´úÂëÖ´ÐÐÎó²î
Siemens Simcenter Femap FEMAPÎļþ´¦Öóͷ£±£´æÔ½½çдÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-781/
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢ÈðµäÁ¬Ëø³¬ÊÐCoopÒòKaseya¹©Ó¦Á´¹¥»÷¹Ø±ÕÊý°Ù¼ÒÃŵê
ÈðµäÁ¬Ëø³¬ÊÐCoop³ÆÆäÔâµ½ÁËKaseya¹©Ó¦Á´¹¥»÷£¬£¬£¬£¬Êý°Ù¼ÒÃÅµê¹Ø±Õ¡£¡£¡£¡£CoopµÄ½²»°ÈËÌåÏÖÆäÓÚÉÏÖÜÎåÍíÉÏ6µã30·Ö×óÓÒ·¢Ã÷ÓÐÉÙÊýÃŵ귺ÆðÎÊÌ⣬£¬£¬£¬µ«Ò»Ò¹Ö®ºóÆä´ó²¿·ÖÃŵ궼±»ÆÈ¹Ø±Õ£¬£¬£¬£¬°üÀ¨ÊÕÒøÌ¨ºÍ×ÔÖú½áÕËÔÚÄÚµÄÕû¸öÖ§¸¶ÏµÍ³¶¼ÖÐÖ¹ÁË¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬CoopûÓÐʹÓÃKesayaÈí¼þ£¬£¬£¬£¬ÓÉÓÚËûÃǵÄÒ»¸öÈí¼þÌṩÉÌʹÓÃÁ˸ÃÈí¼þ¶øÊܵ½Ó°Ïì¡£¡£¡£¡£Çå¾²¹«Ë¾HuntressLabs³Æ£¬£¬£¬£¬´Ë´Î¹¥»÷»î¶¯µÄÊÓ²ìÈÔÔÚ¾ÙÐÐÖУ¬£¬£¬£¬ÖÁÉÙÓÐ200¼Ò×éÖ¯Êܵ½Ó°Ïì¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/119663/cyber-crime/coop-supermarket-kaseya-ransomware-attack.html
2¡¢ÃÀ¹ú°ü¹Ü¹«Ë¾AJG³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬¿Í»§ÐÅϢй¶
ÃÀ¹úArthur J. Gallagher (AJG) ³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬¿Í»§ÐÅϢй¶¡£¡£¡£¡£AJGÊÇÃÀ¹úµÄÈ«Çò°ü¹Ü¾¼ÍºÍΣº¦ÖÎÀí¹«Ë¾£¬£¬£¬£¬×÷ΪȫÇò×î´óµÄ°ü¹Ü¾¼ÍÉÌÖ®Ò»£¬£¬£¬£¬ÓªÒµÆÕ±é49¸ö¹ú¼Ò/µØÇø¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚ2020Äê6ÔÂ3ÈÕÖÁ2020Äê9ÔÂ26ÈÕʱ´ú£¬£¬£¬£¬ÆäÔÚ2020Äê9ÔÂ28ÈÕÅû¶¸ÃÊÂÎñ²¢³ÆÃ»ÓÐÊý¾Ýй¶¡£¡£¡£¡£µ«ÔÚËæºóµÄÊӲ췢Ã÷£¬£¬£¬£¬7376È˵ÄÃô¸ÐÐÅϢй¶£¬£¬£¬£¬°üÀ¨Éç»áÇå¾²ºÅÂë»ò˰ºÅ¡¢¼ÝÕÕ¡¢»¤ÕÕ¡¢³öÉúÈÕÆÚ¡¢Óû§ÃûºÍÃÜÂë¡¢Ô±¹¤Ê¶ÓÖÃû¡¢²ÆÎñÕË»§»òÐÅÓÿ¨ÐÅÏ¢¡¢µç×ÓÊðÃû¡¢Ò½ÁÆÐÅÏ¢¡¢°ü¹ÜÐÅÏ¢ÒÔ¼°ÉúÎïʶ±ðÐÅÏ¢µÈ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/us-insurance-giant-ajg-reports-data-breach-after-ransomware-attack/
3¡¢CISAºÍFBIÐû²¼Õë¶ÔKaseya¹©Ó¦Á´¹¥»÷Êܺ¦ÕßµÄÖ¸ÄÏ
CISAºÍFBIÁªºÏÐû²¼ÁËÕë¶ÔÊܵ½Kaseya¹©Ó¦Á´¹¥»÷Ó°ÏìµÄÊܺ¦ÕßµÄÖ¸ÄÏ¡£¡£¡£¡£ÕâÁ½¸ö»ú¹¹½¨Òé×é֯ʹÓÃKaseyaÌṩµÄ¼ì²â¹¤¾ßÀ´¼ì²éËûÃǵÄϵͳÊÇ·ñ±£´æÈëÇÖ¼£Ï󣬣¬£¬£¬²¢ÆôÓöàÒòËØÉí·ÝÑéÖ¤(MFA)¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬×éÖ¯»¹Ó¦Ê¹Óð×Ãûµ¥À´ÍⲿÏÞÖÆ¶ÔÆäÄÚ²¿×ʲúµÄ»á¼û£¬£¬£¬£¬²¢Ê¹Ó÷À»ðǽ»òVPN±£»£»£»£»¤ÆäÔ¶³Ì¼à¿Ø¹¤¾ßµÄÖÎÀí½çÃæ¡£¡£¡£¡£¶øÊÜÓ°ÏìµÄMSP¿Í»§ÐèҪȷ±£±¸·ÝÊÇ×îÐµģ¬£¬£¬£¬²¢ÇÒÁ¬Ã¦×°Öù©Ó¦ÉÌÌṩµÄ×îеIJ¹¶¡¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/119728/cyber-crime/cisa-fbi-guidance-kaseya-attack.html
4¡¢Î¢ÈíÐû²¼µÄPrintNightmareµÄ½ôÆÈ¸üпɱ»Èƹý
MicrosoftÐû²¼KB5004945½ôÆÈÇå¾²¸üУ¬£¬£¬£¬ÐÞ¸´Ó°ÏìËùÓÐWindows Print SpoolerЧÀÍÖб»Æð¾¢Ê¹ÓõÄPrintNightmare 0day¡£¡£¡£¡£¸ÃÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-34527£©ÔÊÐí¹¥»÷ÕßʹÓÃSYSTEMȨÏÞµÄÔ¶³ÌÖ´ÐдúÂë²¢ÍêÈ«½ÓÊÜÄ¿µÄЧÀÍÆ÷¡£¡£¡£¡£ÔÚ¸üÐÂÐû²¼ºó£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷¸Ã²¹¶¡½öÐÞ¸´ÁËÉæ¼°Ô¶³Ì´úÂëÖ´ÐеÄ×é¼þ£¬£¬£¬£¬Òò´ËÑо¿Ö°Ô±×îÏÈÐÞ¸ÄÎó²îʹÓóÌÐò²¢²âÊÔ²¹¶¡£¬£¬£¬£¬È·¶¨¿ÉÒÔÍêÈ«ÈÆ¹ýÕû¸ö²¹¶¡À´ÊµÏÖÍâµØÌáȨºÍÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-pushes-emergency-update-for-windows-printnightmare-zero-day/
5¡¢Kaspersky·¢Ã÷WildPressureÕë¶ÔmacOSµÄ¹¥»÷»î¶¯
KasperskyµÄÑо¿Ö°Ô±·¢Ã÷WildPressureÔÚ×î½üµÄ¹¥»÷»î¶¯ÖÐÔöÌíÁËÕë¶ÔmacOSµÄ¶ñÒâÈí¼þ±äÌå¡£¡£¡£¡£Ñо¿Ö°Ô±ÓÚ2020Äê3ÔÂÊ״η¢Ã÷¸ÃÍŻ£¬£¬£¬ÆäʱWildPressureʹÓÃÁËC++°æ±¾µÄMilumľÂí¹¥»÷Öж«µÄ×éÖ¯¡£¡£¡£¡£ÔÚ½üÆÚÕë¶ÔÄÜÔ´ÐÐÒµµÄ¹¥»÷ÖУ¬£¬£¬£¬MilumÒѾͨ¹ýPyInstaller°ü¾ÙÐÐÁËÖØ×飬£¬£¬£¬ÆäÖаüÀ¨ÁËÓëWindowsºÍmacOSϵͳ¼æÈݵÄľÂí³ÌÐò£¬£¬£¬£¬±»ºÚµÄÍøÕ¾¿É±»APT×éÖ¯ÓÃÀ´ÏÂÔØºÍÉÏ´«Îļþ²¢Ö´ÐÐÏÂÁî¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/macos-wildpressure-apt/167606/