ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ28ÖÜ
Ðû²¼Ê±¼ä 2021-07-12> ±¾ÖÜÇ徲̬ÊÆ×ÛÊö
2021Äê07ÔÂ05ÈÕÖÁ07ÔÂ11ÈÕ¹²ÊÕ¼Çå¾²Îó²î61¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAdvantech WebAccess Node BwFreRPTÕ»Òç³ö´úÂëÖ´ÐÐÎó²î£»Microsoft Teams ElectronJSÖ¡Öض¨Ïò´úÂëÖ´ÐÐÎó²î£»NPort IA5000A-I/O Series CVE-2021-32968¾Ü¾ø·þÎñÎó²î£»Phoenix Contact Automationworx BCPÎļþÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î£»Siemens Simcenter Femap FEMAPÔ½½çд´úÂëÖ´ÐÐÎó²î¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÈðµäÁ¬Ëø³¬ÊÐCoopÒòKaseya¹©Ó¦Á´¹¥»÷¹Ø±ÕÊý°Ù¼ÒÃŵꣻÃÀ¹ú°ü¹Ü¹«Ë¾AJG³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬¿Í»§ÐÅϢй¶£»CISAºÍFBIÐû²¼Õë¶ÔKaseya¹©Ó¦Á´¹¥»÷Êܺ¦ÕßµÄÖ¸ÄÏ£»Î¢ÈíÐû²¼µÄPrintNightmareµÄ½ôÆȸüпɱ»Èƹý£»Kaspersky·¢Ã÷WildPressureÕë¶ÔmacOSµÄ¹¥»÷Ô˶¯¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£
> Ö÷ÒªÇå¾²Îó²îÁбí
1.Advantech WebAccess Node BwFreRPTÕ»Òç³ö´úÂëÖ´ÐÐÎó²î
Advantech WebAccess Node BwFreRPT±£´æÕ»Òç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄ0x2711 IOCTLÇëÇ󣬿ÉʹӦÓóÌÐò±ÀÀ£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-779/
2.Microsoft Teams ElectronJSÖ¡Öض¨Ïò´úÂëÖ´ÐÐÎó²î
Microsoft Teams ElectronJSÖ¡±£»¤±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâÇëÇ󣬿ÉÖض¨Ïò¶ñÒâÒ³Ã棬»á¼ûÄÚ²¿Ó¦Óù¤¾ß£¬ÌáÉýȨÏÞ¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-772/
3.NPort IA5000A-I/O Series CVE-2021-32968¾Ü¾ø·þÎñÎó²î
NPort IA5000A-I/O SeriesÄÚ²¿WEB·þÎñ±£´æ»º³åÇøÒç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâÇëÇ󣬿ÉʹӦÓóÌÐòÍ߽⡣
https://us-cert.cisa.gov/ics/advisories/icsa-21-187-01
4.Phoenix Contact Automationworx BCPÎļþÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î
Phoenix Contact Automationworx BCPÎļþ´¦Öóͷ£±£´æÄÚ´æÆÆËðÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉʹӦÓóÌÐò±ÀÀ£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-782/
5.Siemens Simcenter Femap FEMAPÔ½½çд´úÂëÖ´ÐÐÎó²î
Siemens Simcenter Femap FEMAPÎļþ´¦Öóͷ£±£´æÔ½½çдÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉʹӦÓóÌÐò±ÀÀ£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-781/
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢ÈðµäÁ¬Ëø³¬ÊÐCoopÒòKaseya¹©Ó¦Á´¹¥»÷¹Ø±ÕÊý°Ù¼ÒÃŵê
ÈðµäÁ¬Ëø³¬ÊÐCoop³ÆÆäÔâµ½ÁËKaseya¹©Ó¦Á´¹¥»÷£¬Êý°Ù¼ÒÃŵê¹Ø±Õ¡£CoopµÄ½²»°ÈËÌåÏÖÆäÓÚÉÏÖÜÎåÍíÉÏ6µã30·Ö×óÓÒ·¢Ã÷ÓÐÉÙÊýÃŵ귺ÆðÎÊÌ⣬µ«Ò»Ò¹Ö®ºóÆä´ó²¿·ÖÃŵ궼±»Æȹرգ¬°üÀ¨ÊÕÒø̨ºÍ×ÔÖú½áÕËÔÚÄÚµÄÕû¸öÖ§¸¶ÏµÍ³¶¼ÖÐÖ¹ÁË¡£±ðµÄ£¬CoopûÓÐʹÓÃKesayaÈí¼þ£¬ÓÉÓÚËûÃǵÄÒ»¸öÈí¼þÌṩÉÌʹÓÃÁ˸ÃÈí¼þ¶øÊܵ½Ó°Ïì¡£Çå¾²¹«Ë¾HuntressLabs³Æ£¬´Ë´Î¹¥»÷Ô˶¯µÄÊÓ²ìÈÔÔÚ¾ÙÐÐÖУ¬ÖÁÉÙÓÐ200¼Ò×éÖ¯Êܵ½Ó°Ïì¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/119663/cyber-crime/coop-supermarket-kaseya-ransomware-attack.html
2¡¢ÃÀ¹ú°ü¹Ü¹«Ë¾AJG³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬¿Í»§ÐÅϢй¶
ÃÀ¹úArthur J. Gallagher (AJG) ³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬¿Í»§ÐÅϢй¶¡£AJGÊÇÃÀ¹úµÄÈ«Çò°ü¹Ü¾¼ÍºÍΣº¦ÖÎÀí¹«Ë¾£¬×÷ΪȫÇò×î´óµÄ°ü¹Ü¾¼ÍÉÌÖ®Ò»£¬ÓªÒµÆÕ±é49¸ö¹ú¼Ò/µØÇø¡£¹¥»÷±¬·¢ÔÚ2020Äê6ÔÂ3ÈÕÖÁ2020Äê9ÔÂ26ÈÕʱ´ú£¬ÆäÔÚ2020Äê9ÔÂ28ÈÕÅû¶¸ÃÊÂÎñ²¢³ÆûÓÐÊý¾Ýй¶¡£µ«ÔÚËæºóµÄÊӲ췢Ã÷£¬7376È˵ÄÃô¸ÐÐÅϢй¶£¬°üÀ¨Éç»áÇå¾²ºÅÂë»òË°ºÅ¡¢¼ÝÕÕ¡¢»¤ÕÕ¡¢³öÉúÈÕÆÚ¡¢Óû§ÃûºÍÃÜÂë¡¢Ô±¹¤Ê¶ÓÖÃû¡¢²ÆÎñÕË»§»òÐÅÓÿ¨ÐÅÏ¢¡¢µç×ÓÊðÃû¡¢Ò½ÁÆÐÅÏ¢¡¢°ü¹ÜÐÅÏ¢ÒÔ¼°ÉúÎïʶ±ðÐÅÏ¢µÈ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/us-insurance-giant-ajg-reports-data-breach-after-ransomware-attack/
3¡¢CISAºÍFBIÐû²¼Õë¶ÔKaseya¹©Ó¦Á´¹¥»÷Êܺ¦ÕßµÄÖ¸ÄÏ
CISAºÍFBIÍŽáÐû²¼ÁËÕë¶ÔÊܵ½Kaseya¹©Ó¦Á´¹¥»÷Ó°ÏìµÄÊܺ¦ÕßµÄÖ¸ÄÏ¡£ÕâÁ½¸ö»ú¹¹½¨Òé×é֯ʹÓÃKaseyaÌṩµÄ¼ì²â¹¤¾ßÀ´¼ì²éËûÃǵÄϵͳÊÇ·ñ±£´æÈëÇÖ¼£Ï󣬲¢ÆôÓöàÒòËØÉí·ÝÑéÖ¤(MFA)¡£±ðµÄ£¬×éÖ¯»¹Ó¦Ê¹Óð×Ãûµ¥À´ÍⲿÏÞÖƶÔÆäÄÚ²¿×ʲúµÄ»á¼û£¬²¢Ê¹Ó÷À»ðǽ»òVPN±£»¤ÆäÔ¶³Ì¼à¿Ø¹¤¾ßµÄÖÎÀí½çÃæ¡£¶øÊÜÓ°ÏìµÄMSP¿Í»§ÐèҪȷ±£±¸·ÝÊÇ×îеģ¬²¢ÇÒÁ¬Ã¦×°Öù©Ó¦ÉÌÌṩµÄ×îеIJ¹¶¡¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/119728/cyber-crime/cisa-fbi-guidance-kaseya-attack.html
4¡¢Î¢ÈíÐû²¼µÄPrintNightmareµÄ½ôÆȸüпɱ»Èƹý
MicrosoftÐû²¼KB5004945½ôÆÈÇå¾²¸üУ¬ÐÞ¸´Ó°ÏìËùÓÐWindows Print Spooler·þÎñÖб»Æð¾¢Ê¹ÓõÄPrintNightmare 0day¡£¸ÃÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-34527£©ÔÊÐí¹¥»÷ÕßʹÓÃSYSTEMȨÏÞµÄÔ¶³ÌÖ´ÐдúÂë²¢ÍêÈ«½ÓÊÜÄ¿µÄ·þÎñÆ÷¡£ÔÚ¸üÐÂÐû²¼ºó£¬Ñо¿Ö°Ô±·¢Ã÷¸Ã²¹¶¡½öÐÞ¸´ÁËÉæ¼°Ô¶³Ì´úÂëÖ´ÐеÄ×é¼þ£¬Òò´ËÑо¿Ö°Ô±×îÏÈÐÞ¸ÄÎó²îʹÓóÌÐò²¢²âÊÔ²¹¶¡£¬È·¶¨¿ÉÒÔÍêÈ«ÈƹýÕû¸ö²¹¶¡À´ÊµÏÖÍâµØÌáȨºÍÔ¶³Ì´úÂëÖ´ÐС£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-pushes-emergency-update-for-windows-printnightmare-zero-day/
5¡¢Kaspersky·¢Ã÷WildPressureÕë¶ÔmacOSµÄ¹¥»÷Ô˶¯
KasperskyµÄÑо¿Ö°Ô±·¢Ã÷WildPressureÔÚ×î½üµÄ¹¥»÷Ô˶¯ÖÐÔöÌíÁËÕë¶ÔmacOSµÄ¶ñÒâÈí¼þ±äÌå¡£Ñо¿Ö°Ô±ÓÚ2020Äê3ÔÂÊ״η¢Ã÷¸ÃÍŻÆäʱWildPressureʹÓÃÁËC++°æ±¾µÄMilumľÂí¹¥»÷Öж«µÄ×éÖ¯¡£ÔÚ½üÆÚÕë¶ÔÄÜÔ´ÐÐÒµµÄ¹¥»÷ÖУ¬MilumÒѾͨ¹ýPyInstaller°ü¾ÙÐÐÁËÖØ×飬ÆäÖаüÀ¨ÁËÓëWindowsºÍmacOSϵͳ¼æÈݵÄľÂí³ÌÐò£¬±»ºÚµÄÍøÕ¾¿É±»APT×éÖ¯ÓÃÀ´ÏÂÔغÍÉÏ´«Îļþ²¢Ö´ÐÐÏÂÁî¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/macos-wildpressure-apt/167606/