ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ36ÖÜ
Ðû²¼Ê±¼ä 2021-09-06>±¾ÖÜÇ徲̬ÊÆ×ÛÊö
2021Äê08ÔÂ30ÈÕÖÁ09ÔÂ05ÈÕ¹²ÊÕ¼Çå¾²Îó²î62¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAruba Networks ArubaOS OS CVE-2021-37716 PAPIÐÒ黺³åÇøÒç³öÎó²î£»Google Chrome BlinkÄÚ´æ¹ýʧ´úÂëÖ´ÐÐÎó²î£»Nature Easy Soft Network Technology ZenTaoÏÂÁîÖ´ÐÐÎó²î£»ZOHO ManageEngine ADSelfService Plus OSÏÂÁî×¢ÈëÎó²î£»Advantech WebAccess CVE-2021-38408»º³åÇø¹ýʧÎó²î¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇMicrosoftÐû²¼½üÆÚÖ¼ÔÚÇÔȡƾ֤µÄ´¹ÂÚÔ˶¯µÄ¾¯±¨£»NFIB³Æ2021ÄêH1Ó¢¹úÒòÍøÂç·¸·¨Ëðʧ¸ß´ï13ÒÚÓ¢°÷£»CNNICÐû²¼µÚ48´Î¡¶Öйú»¥ÁªÍøÂçÉú³¤×´Ì¬Í³¼Æ±¨¸æ¡·£»ÒòGoogleÓ¦ÓÃbug£¬²¿·Ö°²×¿Óû§ÎÞ·¨²¦´òºÍ½ÓÌýµç»°£»Ñо¿Ö°Ô±³Æ16¸öÀ¶ÑÀÎó²îBrakToothÓ°ÏìÊýÊ®ÒÚ×°±¸¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£
>Ö÷ÒªÇå¾²Îó²îÁбí
1.Aruba Networks ArubaOS OS CVE-2021-37716 PAPIÐÒ黺³åÇøÒç³öÎó²î
Aruba Networks ArubaOS OS PAPIÐÒé±£´æ»º³åÇøÒç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓóÌÐò±ÀÀ£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2021-016.txt
2.Google Chrome BlinkÄÚ´æ¹ýʧ´úÂëÖ´ÐÐÎó²î
Google Chrome Blink±£´æÊͷźóʹÓÃÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉʹӦÓóÌÐò±ÀÀ£»ò¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://chromereleases.googleblog.com/2021/08/stable-channel-update-for-desktop_31.html
3.Nature Easy Soft Network Technology ZenTaoÏÂÁîÖ´ÐÐÎó²î
Nature Easy Soft Network Technology ZenTao Cron job Ñ¡Ï±£´æÊäÈëÑéÖ¤Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://privasec.com/blog/zentao-cms-a-monkeys-journey-to-priv-esc-remote-code-execution/
4.ZOHO ManageEngine ADSelfService Plus OSÏÂÁî×¢ÈëÎó²î
ZOHO ManageEngine ADSelfService Plus±£´æÊäÈëÑéÖ¤Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâÏÂÁî¡£
https://blog.stmcyber.com/vulns/cve-2021-33055/
5.Advantech WebAccess CVE-2021-38408»º³åÇø¹ýʧÎó²î
Advantech WebAccess±£´æ»º³åÇøÒç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓóÌÐò±ÀÀ£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://www.advantech.com/support/details/installation?id=1-MS9MJV
>Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢MicrosoftÐû²¼½üÆÚÖ¼ÔÚÇÔȡƾ֤µÄ´¹ÂÚÔ˶¯µÄ¾¯±¨
Microsoft 365 DefenderÍþвÇ鱨ÍŶÓÔÚ8ÔÂ26ÈÕÐû²¼½üÆÚÖ¼ÔÚÇÔȡƾ֤µÄ´¹ÂÚÔ˶¯µÄ¾¯±¨¡£Ñо¿Ö°Ô±³Æ£¬¸ÃÔ˶¯Ê¹Óõç×ÓÓʼþͨѶÖеĿª·ÅÖض¨ÏòÁ´½Ó×÷ΪÔØÌ壬ÓÕʹÓû§»á¼û¶ñÒâÍøÕ¾£¬Í¬Ê±ÈƹýÇå¾²¼ì²âÈí¼þ¡£Î¢ÈíÌåÏÖËüÒѾ·¢Ã÷ÁËÖÁÉÙ350¸öÍøÂç´¹ÂÚURL£¬²¢ÇÒËüÃǾùʹÓÃÁËÁîÈËÐÅ·þµÄÓÕ¶üºÍÈ«ÐÄÉè¼ÆµÄ¼ì²âÈƹýÊÖÒÕ¡£Õâ²»µ«ÏÔʾÁ˴˴ι¥»÷µÄ¹æÄ££¬»¹Åú×¢Îú¹¥»÷ÕßÖØ´óµÄͶÈë¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/08/microsoft-warns-of-widespread-phishing.html
2¡¢NFIB³Æ2021ÄêH1Ó¢¹úÒòÍøÂç·¸·¨Ëðʧ¸ß´ï13ÒÚÓ¢°÷
À´×ÔÓ¢¹ú¹ú¼ÒÚ²ÆÇ鱨¾Ö(NFIB)µÄÊý¾ÝÅú×¢£¬2021ÄêH1Ó¢¹úÒòÍøÂç·¸·¨Ëðʧ¸ß´ï13ÒÚÓ¢°÷¡£Ð¡ÎÒ˽¼ÒºÍ×éÖ¯ÔÚ½ñÄêÉÏ°ëÄêÒòÍøÂç·¸·¨ºÍڲƶøËðʧµÄ×ʽðÊÇ2020ÉÏ°ëÄ꣨4.147ÒÚÓ¢°÷£©µÄÈý±¶¡£2020ÄêH1Ö»ÓÐ39160°¸¼þ£¬¶ø2021ÄêH1¶à´ï289437Æð¡£Ñо¿Ö°Ô±³Æ£¬Õþ¸®Ó¦½ÓÄɸü¶à²½·¥À´½ÌÓýСÎÒ˽¼ÒÓйØÍøÂç´¹ÂÚµÄΣº¦ºÍÍøÂçÇå¾²µÄÖ÷ÒªÐÔ£¬¶ø×éÖ¯Ó¦¸ÃÆð¾¢½µµÍÔ¶³ÌÊÂÇéµÄΣº¦¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/cybercrime-losses-triple-to-13bn/
3¡¢CNNICÐû²¼µÚ48´Î¡¶Öйú»¥ÁªÍøÂçÉú³¤×´Ì¬Í³¼Æ±¨¸æ¡·
Öйú»¥ÁªÍøÂçÐÅÏ¢ÖÐÐÄ£¨CNNIC£©ÓÚ8ÔÂ27ÈÕÔÚ¾©Ðû²¼µÚ48´Î¡¶Öйú»¥ÁªÍøÂçÉú³¤×´Ì¬Í³¼Æ±¨¸æ¡·¡£±¨¸æÏÔʾ£¬×èÖ¹½ñÄê6Ô£¬ÖйúÍøÃñ¹æÄ£´ï10.11ÒÚ£¬½Ï2020Äê12ÔÂÔöÌí2175Íò£¬»¥ÁªÍøÆÕ¼°ÂÊ´ï71.6%£»»¥ÁªÍø»ù´¡×ÊÔ´¼ÓËÙ½¨É裬×èÖ¹6Ô£¬ÖйúIPv6µØµãÊýÄ¿´ï62023¿é/32£»ÖйúÅ©´åÍøÃñ¹æģΪ2.97ÒÚ£¬Å©´åµØÇø»¥ÁªÍøÆÕ¼°ÂÊΪ59.2%£¬½Ï2020Äê12Ô£¬³ÇÏ绥ÁªÍøÆÕ¼°Âʲî±ðËõС4.8%¡£
ÔÎÄÁ´½Ó£º
http://finance.people.com.cn/n1/2021/0828/c1004-32210949.html
4¡¢ÒòGoogleÓ¦ÓÃbug£¬²¿·Ö°²×¿Óû§ÎÞ·¨²¦´òºÍ½ÓÌýµç»°
GoogleÌåÏÖ£¬²¿·ÖAndroidÊÖ»úÐͺŵÄÓû§Êܵ½GoogleÓ¦ÓÃÖÐbugµÄÓ°Ï죬ÎÞ·¨²¦´òºÍ½ÓÌýµç»°¡£ÏÖÔÚGoogleûÓйûÕæÊÜÓ°ÏìÊÖ»úµÄÐͺţ¬µ«±¾ÖÜÄ©ÊÜÓ°ÏìÓû§Ìáµ½ÁËLGµÄ×°±¸£¬ÈçLG G7¡¢LG G7 ThinQ¡¢LG V40 ThinQºÍLG Q70µÈ¡£Google³ÆÆäÕýÔÚÊÓ²ì´ËÊ£¬²¢ÒÑÐû²¼ÁË×îиüÐÂÀ´ÐÞ¸´¸Ãbug£¬½¨ÒéÓû§ÊÖ¶¯×°ÖÃ×îиüС£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/google/google-app-bug-blocks-android-users-from-receiving-making-calls/
5¡¢Ñо¿Ö°Ô±³Æ16¸öÀ¶ÑÀÎó²îBrakToothÓ°ÏìÊýÊ®ÒÚ×°±¸
Ñо¿Ö°Ô±¼ì²âÁËÀ´×Ô11¸ö¹©Ó¦É̵Ä13¸öƬÉÏϵͳ (SoC) µÄÀ¶ÑÀÈí¼þ¿â£¬·¢Ã÷ÁË16¸öÓ°ÏìÀ¶ÑÀÈí¼þ¿ÍÕ»µÄÎó²î²¢Í³³ÆËüÃÇΪBrakTooth¡£¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îʹװ±¸Í߽⣬ÉõÖÁÊÇÖ´ÐжñÒâ´úÂë²¢½ÓÊÜÕû¸öϵͳ¡£ÕâЩÎó²îÖÐ×îÑÏÖصÄΪCVE-2021-28139£¬Ê¹ÓøÃÎó²îÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýÀ¶ÑÀLMPÊý¾Ý°üÔÚÄ¿µÄ×°±¸ÉÏÔËÐжñÒâ´úÂë¡£²¢·ÇËùÓÐËùÓй©Ó¦É̶¼ÊµÊ±Ðû²¼Á˲¹¶¡£¬µ½ÏÖÔÚΪֹ£¬Ö»ÓÐÀÖöΡ¢Ó¢·ÉÁèºÍBluetrumÐû²¼Á˲¹¶¡£¬¶øµÂÖÝÒÇÆ÷ÔòÌåÏ־ܾøÐÞ¸´Îó²î¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/billions-of-devices-impacted-by-new-braktooth-bluetooth-vulnerabilities