ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ36ÖÜ

Ðû²¼Ê±¼ä 2021-09-06

>±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö

2021Äê08ÔÂ30ÈÕÖÁ09ÔÂ05ÈÕ¹²ÊÕ¼Çå¾²Îó²î62¸ö£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇAruba Networks ArubaOS OS CVE-2021-37716 PAPIЭÒ黺³åÇøÒç³öÎó²î£»£»£»£» £»£»Google Chrome BlinkÄÚ´æ¹ýʧ´úÂëÖ´ÐÐÎó²î£»£»£»£» £»£»Nature Easy Soft Network Technology ZenTaoÏÂÁîÖ´ÐÐÎó²î£»£»£»£» £»£»ZOHO ManageEngine ADSelfService Plus OSÏÂÁî×¢ÈëÎó²î£»£»£»£» £»£»Advantech WebAccess CVE-2021-38408»º³åÇø¹ýʧÎó²î ¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇMicrosoftÐû²¼½üÆÚÖ¼ÔÚÇÔȡƾ֤µÄ´¹ÂڻµÄ¾¯±¨£»£»£»£» £»£»NFIB³Æ2021ÄêH1Ó¢¹úÒòÍøÂç·¸·¨Ëðʧ¸ß´ï13ÒÚÓ¢°÷£»£»£»£» £»£»CNNICÐû²¼µÚ48´Î¡¶Öйú»¥ÁªÍøÂçÉú³¤×´Ì¬Í³¼Æ±¨¸æ¡·£»£»£»£» £»£»ÒòGoogleÓ¦ÓÃbug£¬£¬£¬£¬²¿·Ö°²×¿Óû§ÎÞ·¨²¦´òºÍ½ÓÌýµç»°£»£»£»£» £»£»Ñо¿Ö°Ô±³Æ16¸öÀ¶ÑÀÎó²îBrakToothÓ°ÏìÊýÊ®ÒÚ×°±¸ ¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖÐ ¡£¡£¡£¡£


>Ö÷ÒªÇå¾²Îó²îÁбí


1.Aruba Networks ArubaOS OS CVE-2021-37716 PAPIЭÒ黺³åÇøÒç³öÎó²î


Aruba Networks ArubaOS OS PAPIЭÒé±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£» £»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë ¡£¡£¡£¡£


https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2021-016.txt



2.Google Chrome BlinkÄÚ´æ¹ýʧ´úÂëÖ´ÐÐÎó²î


Google Chrome Blink±£´æÊͷźóʹÓÃÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇ󣬣¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£» £»£»ò¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë ¡£¡£¡£¡£


https://chromereleases.googleblog.com/2021/08/stable-channel-update-for-desktop_31.html


3.Nature Easy Soft Network Technology ZenTaoÏÂÁîÖ´ÐÐÎó²î


Nature Easy Soft Network Technology ZenTao Cron job Ñ¡Ï±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë ¡£¡£¡£¡£


https://privasec.com/blog/zentao-cms-a-monkeys-journey-to-priv-esc-remote-code-execution/


4.ZOHO ManageEngine ADSelfService Plus OSÏÂÁî×¢ÈëÎó²î


ZOHO ManageEngine ADSelfService Plus±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâÏÂÁî ¡£¡£¡£¡£


https://blog.stmcyber.com/vulns/cve-2021-33055/


5.Advantech WebAccess CVE-2021-38408»º³åÇø¹ýʧÎó²î


Advantech WebAccess±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£» £»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë ¡£¡£¡£¡£


https://www.advantech.com/support/details/installation?id=1-MS9MJV


>Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢MicrosoftÐû²¼½üÆÚÖ¼ÔÚÇÔȡƾ֤µÄ´¹ÂڻµÄ¾¯±¨


Microsoft 365 DefenderÍþвÇ鱨ÍŶÓÔÚ8ÔÂ26ÈÕÐû²¼½üÆÚÖ¼ÔÚÇÔȡƾ֤µÄ´¹ÂڻµÄ¾¯±¨ ¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬¸Ã»î¶¯Ê¹Óõç×ÓÓʼþͨѶÖеĿª·ÅÖØ¶¨ÏòÁ´½Ó×÷ÎªÔØÌ壬£¬£¬£¬ÓÕʹÓû§»á¼û¶ñÒâÍøÕ¾£¬£¬£¬£¬Í¬Ê±ÈƹýÇå¾²¼ì²âÈí¼þ ¡£¡£¡£¡£Î¢ÈíÌåÏÖËüÒѾ­·¢Ã÷ÁËÖÁÉÙ350¸öÍøÂç´¹ÂÚURL£¬£¬£¬£¬²¢ÇÒËüÃǾùʹÓÃÁËÁîÈËÐÅ·þµÄÓÕ¶üºÍÈ«ÐÄÉè¼ÆµÄ¼ì²âÈÆ¹ýÊÖÒÕ ¡£¡£¡£¡£Õâ²»µ«ÏÔʾÁ˴˴ι¥»÷µÄ¹æÄ££¬£¬£¬£¬»¹Åú×¢Îú¹¥»÷ÕßÖØ´óµÄͶÈë ¡£¡£¡£¡£


MicrosoftÐû²¼½üÆÚÖ¼ÔÚÇÔȡƾ֤µÄ´¹ÂڻµÄ¾¯±¨.jpg


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/08/microsoft-warns-of-widespread-phishing.html



2¡¢NFIB³Æ2021ÄêH1Ó¢¹úÒòÍøÂç·¸·¨Ëðʧ¸ß´ï13ÒÚÓ¢°÷


ÍøÂç·¸·¨.png


À´×ÔÓ¢¹ú¹ú¼ÒڲƭÇ鱨¾Ö(NFIB)µÄÊý¾ÝÅú×¢£¬£¬£¬£¬2021ÄêH1Ó¢¹úÒòÍøÂç·¸·¨Ëðʧ¸ß´ï13ÒÚÓ¢°÷ ¡£¡£¡£¡£Ð¡ÎÒ˽¼ÒºÍ×éÖ¯ÔÚ½ñÄêÉϰëÄêÒòÍøÂç·¸·¨ºÍڲƭ¶øËðʧµÄ×ʽðÊÇ2020ÉϰëÄ꣨4.147ÒÚÓ¢°÷£©µÄÈý±¶ ¡£¡£¡£¡£2020ÄêH1Ö»ÓÐ39160°¸¼þ£¬£¬£¬£¬¶ø2021ÄêH1¶à´ï289437Æð ¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬Õþ¸®Ó¦½ÓÄɸü¶à²½·¥À´½ÌÓýСÎÒ˽¼ÒÓйØÍøÂç´¹ÂÚµÄΣº¦ºÍÍøÂçÇå¾²µÄÖ÷ÒªÐÔ£¬£¬£¬£¬¶ø×éÖ¯Ó¦¸ÃÆð¾¢½µµÍÔ¶³ÌÊÂÇéµÄΣº¦ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/cybercrime-losses-triple-to-13bn/



3¡¢CNNICÐû²¼µÚ48´Î¡¶Öйú»¥ÁªÍøÂçÉú³¤×´Ì¬Í³¼Æ±¨¸æ¡·


CNNICÐû²¼µÚ48´Î¡¶Öйú»¥ÁªÍøÂçÉú³¤×´Ì¬Í³¼Æ±¨¸æ¡·.jpg


Öйú»¥ÁªÍøÂçÐÅÏ¢ÖÐÐÄ£¨CNNIC£©ÓÚ8ÔÂ27ÈÕÔÚ¾©Ðû²¼µÚ48´Î¡¶Öйú»¥ÁªÍøÂçÉú³¤×´Ì¬Í³¼Æ±¨¸æ¡· ¡£¡£¡£¡£±¨¸æÏÔʾ£¬£¬£¬£¬×èÖ¹½ñÄê6Ô£¬£¬£¬£¬ÖйúÍøÃñ¹æÄ£´ï10.11ÒÚ£¬£¬£¬£¬½Ï2020Äê12ÔÂÔöÌí2175Íò£¬£¬£¬£¬»¥ÁªÍøÆÕ¼°ÂÊ´ï71.6%£»£»£»£» £»£»»¥ÁªÍø»ù´¡×ÊÔ´¼ÓËÙ½¨É裬£¬£¬£¬×èÖ¹6Ô£¬£¬£¬£¬ÖйúIPv6µØµãÊýÄ¿´ï62023¿é/32£»£»£»£» £»£»ÖйúÅ©´åÍøÃñ¹æÄ£Îª2.97ÒÚ£¬£¬£¬£¬Å©´åµØÇø»¥ÁªÍøÆÕ¼°ÂÊΪ59.2%£¬£¬£¬£¬½Ï2020Äê12Ô£¬£¬£¬£¬³ÇÏ绥ÁªÍøÆÕ¼°Âʲî±ðËõС4.8% ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

http://finance.people.com.cn/n1/2021/0828/c1004-32210949.html



4¡¢ÒòGoogleÓ¦ÓÃbug£¬£¬£¬£¬²¿·Ö°²×¿Óû§ÎÞ·¨²¦´òºÍ½ÓÌýµç»°


ÒòGoogleÓ¦ÓÃbug£¬£¬£¬£¬²¿·Ö°²×¿Óû§ÎÞ·¨²¦´òºÍ½ÓÌýµç»°.jpg


GoogleÌåÏÖ£¬£¬£¬£¬²¿·ÖAndroidÊÖ»úÐͺŵÄÓû§Êܵ½GoogleÓ¦ÓÃÖÐbugµÄÓ°Ï죬£¬£¬£¬ÎÞ·¨²¦´òºÍ½ÓÌýµç»° ¡£¡£¡£¡£ÏÖÔÚGoogleûÓйûÕæÊÜÓ°ÏìÊÖ»úµÄÐͺÅ£¬£¬£¬£¬µ«±¾ÖÜÄ©ÊÜÓ°ÏìÓû§Ìáµ½ÁËLGµÄ×°±¸£¬£¬£¬£¬ÈçLG G7¡¢LG G7 ThinQ¡¢LG V40 ThinQºÍLG Q70µÈ ¡£¡£¡£¡£Google³ÆÆäÕýÔÚÊÓ²ì´ËÊ£¬£¬£¬£¬²¢ÒÑÐû²¼ÁË×îиüÐÂÀ´ÐÞ¸´¸Ãbug£¬£¬£¬£¬½¨ÒéÓû§ÊÖ¶¯×°ÖÃ×îиüР¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/google/google-app-bug-blocks-android-users-from-receiving-making-calls/


5¡¢Ñо¿Ö°Ô±³Æ16¸öÀ¶ÑÀÎó²îBrakToothÓ°ÏìÊýÊ®ÒÚ×°±¸


Ñо¿Ö°Ô±³Æ16¸öÀ¶ÑÀÎó²îBrakToothÓ°ÏìÊýÊ®ÒÚ×°±¸.jpg


Ñо¿Ö°Ô±¼ì²âÁËÀ´×Ô11¸ö¹©Ó¦É̵Ä13¸öƬÉÏϵͳ (SoC) µÄÀ¶ÑÀÈí¼þ¿â£¬£¬£¬£¬·¢Ã÷ÁË16¸öÓ°ÏìÀ¶ÑÀÈí¼þ¿ÍÕ»µÄÎó²î²¢Í³³ÆËüÃÇΪBrakTooth ¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îʹװ±¸Í߽⣬£¬£¬£¬ÉõÖÁÊÇÖ´ÐжñÒâ´úÂë²¢½ÓÊÜÕû¸öϵͳ ¡£¡£¡£¡£ÕâЩÎó²îÖÐ×îÑÏÖØµÄΪCVE-2021-28139£¬£¬£¬£¬Ê¹ÓøÃÎó²îÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýÀ¶ÑÀLMPÊý¾Ý°üÔÚÄ¿µÄ×°±¸ÉÏÔËÐжñÒâ´úÂë ¡£¡£¡£¡£²¢·ÇËùÓÐËùÓй©Ó¦É̶¼ÊµÊ±Ðû²¼Á˲¹¶¡£¬£¬£¬£¬µ½ÏÖÔÚΪֹ£¬£¬£¬£¬Ö»ÓÐÀÖöΡ¢Ó¢·ÉÁèºÍBluetrumÐû²¼Á˲¹¶¡£¬£¬£¬£¬¶øµÂÖÝÒÇÆ÷ÔòÌåÏ־ܾøÐÞ¸´Îó²î ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/billions-of-devices-impacted-by-new-braktooth-bluetooth-vulnerabilities