ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ28ÖÜ

Ðû²¼Ê±¼ä 2021-07-12

> ±¾ÖÜÇ徲̬ÊÆ×ÛÊö


2021Äê07ÔÂ05ÈÕÖÁ07ÔÂ11ÈÕ¹²ÊÕ¼Çå¾²Îó²î61¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAdvantech WebAccess Node BwFreRPTÕ»Òç³ö´úÂëÖ´ÐÐÎó²î£»Microsoft Teams ElectronJSÖ¡Öض¨Ïò´úÂëÖ´ÐÐÎó²î£»NPort IA5000A-I/O Series CVE-2021-32968¾Ü¾ø·þÎñÎó²î£»Phoenix Contact Automationworx BCPÎļþÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î£»Siemens Simcenter Femap FEMAPÔ½½çд´úÂëÖ´ÐÐÎó²î¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÈðµäÁ¬Ëø³¬ÊÐCoopÒòKaseya¹©Ó¦Á´¹¥»÷¹Ø±ÕÊý°Ù¼ÒÃŵꣻÃÀ¹ú°ü¹Ü¹«Ë¾AJG³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬¿Í»§ÐÅϢй¶£»CISAºÍFBIÐû²¼Õë¶ÔKaseya¹©Ó¦Á´¹¥»÷Êܺ¦ÕßµÄÖ¸ÄÏ£»Î¢ÈíÐû²¼µÄPrintNightmareµÄ½ôÆȸüпɱ»Èƹý£»Kaspersky·¢Ã÷WildPressureÕë¶ÔmacOSµÄ¹¥»÷Ô˶¯¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£


> Ö÷ÒªÇå¾²Îó²îÁбí


1.Advantech WebAccess Node BwFreRPTÕ»Òç³ö´úÂëÖ´ÐÐÎó²î


Advantech WebAccess Node BwFreRPT±£´æÕ»Òç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄ0x2711 IOCTLÇëÇ󣬿ÉʹӦÓóÌÐò±ÀÀ£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-779/


2.Microsoft Teams ElectronJSÖ¡Öض¨Ïò´úÂëÖ´ÐÐÎó²î


Microsoft Teams ElectronJSÖ¡±£»¤±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâÇëÇ󣬿ÉÖض¨Ïò¶ñÒâÒ³Ã棬»á¼ûÄÚ²¿Ó¦Óù¤¾ß£¬ÌáÉýȨÏÞ¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-772/


3.NPort IA5000A-I/O Series CVE-2021-32968¾Ü¾ø·þÎñÎó²î


NPort IA5000A-I/O SeriesÄÚ²¿WEB·þÎñ±£´æ»º³åÇøÒç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâÇëÇ󣬿ÉʹӦÓóÌÐòÍ߽⡣

https://us-cert.cisa.gov/ics/advisories/icsa-21-187-01


4.Phoenix Contact Automationworx BCPÎļþÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î


Phoenix Contact Automationworx BCPÎļþ´¦Öóͷ£±£´æÄÚ´æÆÆËðÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉʹӦÓóÌÐò±ÀÀ£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-782/


5.Siemens Simcenter Femap FEMAPÔ½½çд´úÂëÖ´ÐÐÎó²î


Siemens Simcenter Femap FEMAPÎļþ´¦Öóͷ£±£´æÔ½½çдÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉʹӦÓóÌÐò±ÀÀ£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-781/


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢ÈðµäÁ¬Ëø³¬ÊÐCoopÒòKaseya¹©Ó¦Á´¹¥»÷¹Ø±ÕÊý°Ù¼ÒÃŵê


1.jpg


ÈðµäÁ¬Ëø³¬ÊÐCoop³ÆÆäÔâµ½ÁËKaseya¹©Ó¦Á´¹¥»÷£¬Êý°Ù¼ÒÃŵê¹Ø±Õ¡£CoopµÄ½²»°ÈËÌåÏÖÆäÓÚÉÏÖÜÎåÍíÉÏ6µã30·Ö×óÓÒ·¢Ã÷ÓÐÉÙÊýÃŵ귺ÆðÎÊÌ⣬µ«Ò»Ò¹Ö®ºóÆä´ó²¿·ÖÃŵ궼±»ÆȹرÕ£¬°üÀ¨ÊÕÒø̨ºÍ×ÔÖú½áÕËÔÚÄÚµÄÕû¸öÖ§¸¶ÏµÍ³¶¼ÖÐÖ¹ÁË¡£±ðµÄ£¬CoopûÓÐʹÓÃKesayaÈí¼þ£¬ÓÉÓÚËûÃǵÄÒ»¸öÈí¼þÌṩÉÌʹÓÃÁ˸ÃÈí¼þ¶øÊܵ½Ó°Ïì¡£Çå¾²¹«Ë¾HuntressLabs³Æ£¬´Ë´Î¹¥»÷Ô˶¯µÄÊÓ²ìÈÔÔÚ¾ÙÐÐÖУ¬ÖÁÉÙÓÐ200¼Ò×éÖ¯Êܵ½Ó°Ïì¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/119663/cyber-crime/coop-supermarket-kaseya-ransomware-attack.html


2¡¢ÃÀ¹ú°ü¹Ü¹«Ë¾AJG³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬¿Í»§ÐÅϢй¶


2.jpg


ÃÀ¹úArthur J. Gallagher (AJG) ³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬¿Í»§ÐÅϢй¶¡£AJGÊÇÃÀ¹úµÄÈ«Çò°ü¹Ü¾­¼ÍºÍΣº¦ÖÎÀí¹«Ë¾£¬×÷ΪȫÇò×î´óµÄ°ü¹Ü¾­¼ÍÉÌÖ®Ò»£¬ÓªÒµÆÕ±é49¸ö¹ú¼Ò/µØÇø¡£¹¥»÷±¬·¢ÔÚ2020Äê6ÔÂ3ÈÕÖÁ2020Äê9ÔÂ26ÈÕʱ´ú£¬ÆäÔÚ2020Äê9ÔÂ28ÈÕÅû¶¸ÃÊÂÎñ²¢³ÆûÓÐÊý¾Ýй¶¡£µ«ÔÚËæºóµÄÊӲ췢Ã÷£¬7376È˵ÄÃô¸ÐÐÅϢй¶£¬°üÀ¨Éç»áÇå¾²ºÅÂë»òË°ºÅ¡¢¼ÝÕÕ¡¢»¤ÕÕ¡¢³öÉúÈÕÆÚ¡¢Óû§ÃûºÍÃÜÂë¡¢Ô±¹¤Ê¶ÓÖÃû¡¢²ÆÎñÕË»§»òÐÅÓÿ¨ÐÅÏ¢¡¢µç×ÓÊðÃû¡¢Ò½ÁÆÐÅÏ¢¡¢°ü¹ÜÐÅÏ¢ÒÔ¼°ÉúÎïʶ±ðÐÅÏ¢µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-insurance-giant-ajg-reports-data-breach-after-ransomware-attack/


3¡¢CISAºÍFBIÐû²¼Õë¶ÔKaseya¹©Ó¦Á´¹¥»÷Êܺ¦ÕßµÄÖ¸ÄÏ


3.jpg


CISAºÍFBIÍŽáÐû²¼ÁËÕë¶ÔÊܵ½Kaseya¹©Ó¦Á´¹¥»÷Ó°ÏìµÄÊܺ¦ÕßµÄÖ¸ÄÏ¡£ÕâÁ½¸ö»ú¹¹½¨Òé×é֯ʹÓÃKaseyaÌṩµÄ¼ì²â¹¤¾ßÀ´¼ì²éËûÃǵÄϵͳÊÇ·ñ±£´æÈëÇÖ¼£Ï󣬲¢ÆôÓöàÒòËØÉí·ÝÑéÖ¤(MFA)¡£±ðµÄ£¬×éÖ¯»¹Ó¦Ê¹Óð×Ãûµ¥À´ÍⲿÏÞÖƶÔÆäÄÚ²¿×ʲúµÄ»á¼û£¬²¢Ê¹Ó÷À»ðǽ»òVPN±£»¤ÆäÔ¶³Ì¼à¿Ø¹¤¾ßµÄÖÎÀí½çÃæ¡£¶øÊÜÓ°ÏìµÄMSP¿Í»§ÐèҪȷ±£±¸·ÝÊÇ×îеÄ£¬²¢ÇÒÁ¬Ã¦×°Öù©Ó¦ÉÌÌṩµÄ×îеIJ¹¶¡¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/119728/cyber-crime/cisa-fbi-guidance-kaseya-attack.html


4¡¢Î¢ÈíÐû²¼µÄPrintNightmareµÄ½ôÆȸüпɱ»Èƹý


4.jpg


MicrosoftÐû²¼KB5004945½ôÆÈÇå¾²¸üУ¬ÐÞ¸´Ó°ÏìËùÓÐWindows Print Spooler·þÎñÖб»Æð¾¢Ê¹ÓõÄPrintNightmare 0day¡£¸ÃÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-34527£©ÔÊÐí¹¥»÷ÕßʹÓÃSYSTEMȨÏÞµÄÔ¶³ÌÖ´ÐдúÂë²¢ÍêÈ«½ÓÊÜÄ¿µÄ·þÎñÆ÷¡£ÔÚ¸üÐÂÐû²¼ºó£¬Ñо¿Ö°Ô±·¢Ã÷¸Ã²¹¶¡½öÐÞ¸´ÁËÉæ¼°Ô¶³Ì´úÂëÖ´ÐеÄ×é¼þ£¬Òò´ËÑо¿Ö°Ô±×îÏÈÐÞ¸ÄÎó²îʹÓóÌÐò²¢²âÊÔ²¹¶¡£¬È·¶¨¿ÉÒÔÍêÈ«ÈƹýÕû¸ö²¹¶¡À´ÊµÏÖÍâµØÌáȨºÍÔ¶³Ì´úÂëÖ´ÐС£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-pushes-emergency-update-for-windows-printnightmare-zero-day/


5¡¢Kaspersky·¢Ã÷WildPressureÕë¶ÔmacOSµÄ¹¥»÷Ô˶¯


5.jpg


KasperskyµÄÑо¿Ö°Ô±·¢Ã÷WildPressureÔÚ×î½üµÄ¹¥»÷Ô˶¯ÖÐÔöÌíÁËÕë¶ÔmacOSµÄ¶ñÒâÈí¼þ±äÌå¡£Ñо¿Ö°Ô±ÓÚ2020Äê3ÔÂÊ״η¢Ã÷¸ÃÍŻÆäʱWildPressureʹÓÃÁËC++°æ±¾µÄMilumľÂí¹¥»÷Öж«µÄ×éÖ¯¡£ÔÚ½üÆÚÕë¶ÔÄÜÔ´ÐÐÒµµÄ¹¥»÷ÖУ¬MilumÒѾ­Í¨¹ýPyInstaller°ü¾ÙÐÐÁËÖØ×飬ÆäÖаüÀ¨ÁËÓëWindowsºÍmacOSϵͳ¼æÈݵÄľÂí³ÌÐò£¬±»ºÚµÄÍøÕ¾¿É±»APT×éÖ¯ÓÃÀ´ÏÂÔغÍÉÏ´«Îļþ²¢Ö´ÐÐÏÂÁî¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/macos-wildpressure-apt/167606/