ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ39ÖÜ

Ðû²¼Ê±¼ä 2021-09-27

>±¾ÖÜÇ徲̬ÊÆ×ÛÊö


2021Äê09ÔÂ20ÈÕÖÁ09ÔÂ26ÈÕ¹²ÊÕ¼Çå¾²Îó²î42¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇGoogle Chrome Offline useÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î£»Edgecore ECS2020ÏÂÁî×¢ÈëÎó²î£»Hikvision Web ServerÏÂÁî×¢ÈëÎó²î£»Huawei FusionCompute CVE-2021-37106ÏÂÁî×¢ÈëÎó²î£»VMware vCenter Serverí§ÒâÎļþÉÏ´«Îó²î¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇNEW CooperativeÔâBlack Matter¹¥»÷±»ÀÕË÷590ÍòÃÀÔª£»Ñо¿Ö°Ô±·¢Ã÷Áè¼Ý1.06ÒÚÌ©¹úÓο͵ÄСÎÒ˽¼ÒÐÅϢй¶£»VMwareÐÞ¸´vCenter ServerÖÐÑÏÖصÄÎļþÉÏ´«Îó²î£»AppleÐû²¼Çå¾²¸üУ¬ÐÞ¸´¶à¿î²úÆ·ÖеÄRCEµÈÎó²î£»¶íÂÞ˹APT×éÖ¯TurlaʹÓÃкóÃŹ¥»÷ÃÀ¡¢µÂºÍ°¢¸»º¹¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£


>Ö÷ÒªÇå¾²Îó²îÁбí


1.Google Chrome Offline useÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î


Google Chrome Offline use±£´æÊͷźóʹÓÃÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÒ³ÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿É¶ÔÓ¦ÓóÌÐò¾ÙÐоܾø·þÎñ¹¥»÷»òÕßÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£


https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop_21.html



2.Edgecore ECS2020ÏÂÁî×¢ÈëÎó²î


Edgecore ECS2020 command1 HTTPÍ·±£´æÊäÈëÑéÖ¤Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿É×¢Èëí§ÒâÏÂÁî²¢ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐС£


https://twitter.com/r00treaver/status/1232407881464635401


3.Hikvision Web ServerÏÂÁî×¢ÈëÎó²î


Hikvision Web Server±£´æÊäÈëÑéÖ¤Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿É×¢Èëí§ÒâÏÂÁî²¢ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐС£


https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-notification-command-injection-vulnerability-in-some-hikvision-products/



4.Huawei FusionCompute CVE-2021-37106ÏÂÁî×¢ÈëÎó²î


Huawei FusionCompute²úÆ·CMA·þÎñ´¦Öóͷ£Ö¤ÊéÎļþ±£´æÊäÈëÑéÖ¤Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿É×¢Èëí§ÒâÏÂÁî²¢ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐС£


https://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20210922-01-commandinjection-cn


5.VMware vCenter Serverí§ÒâÎļþÉÏ´«Îó²î


VMware vCenter Server Analytics service±£´æí§ÒâÎļþÉÏ´«Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£


https://www.vmware.com/security/advisories/VMSA-2021-0020.html



 >Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢NEW CooperativeÔâBlack Matter¹¥»÷±»ÀÕË÷590ÍòÃÀÔª


NEW CooperativeÔâBlack Matter¹¥»÷±»ÀÕË÷590ÍòÃÀÔª.png


ÃÀ¹úÅ©ÃñÏàÖúÉçNEW CooperativeÔÚÉÏÖÜÄ©Ôâµ½Black MatterµÄÀÕË÷¹¥»÷¡£ÕâÊÇÒ»¼ÒËÇÁϺ͹ÈÎïÏàÖúÉ磬´Ë´Î¹¥»÷Ô˶¯½«µ¼ÖÂÁ¸Ê³¡¢ÖíÈâºÍ¼¦ÈâµÈʳÎ﹩ӦÖÐÖ¹¡£¹¥»÷ÕßÒªÇó¸Ã¹«Ë¾Ö§¸¶590ÍòÃÀÔªÊê½ð£¬²¢ÌåÏÖ5ÈÕºóÊê½ð½ð¶î½«ÔöÌíµ½1180ÍòÃÀÔª¡£BlackMatterÉù³ÆÇÔÈ¡ÁË1000 GBµÄÊý¾Ý£¬°üÀ¨soilmap.comÏîÄ¿µÄÔ´´úÂë¡¢Ñз¢Ð§¹û¡¢Ô±¹¤ÐÅÏ¢¡¢²ÆÎñÎļþÒÔ¼°KeePassÃÜÂëÖÎÀíÆ÷µÄµ¼³öÊý¾Ý¿âµÈ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/122410/cyber-crime/black-matter-new-cooperative.html



2¡¢Ñо¿Ö°Ô±·¢Ã÷Áè¼Ý1.06ÒÚÌ©¹úÓο͵ÄСÎÒ˽¼ÒÐÅϢй¶


Ñо¿Ö°Ô±·¢Ã÷Áè¼Ý1.06ÒÚÌ©¹úÓο͵ÄСÎÒ˽¼ÒÐÅϢй¶.png


ComparitechÑо¿Ö°Ô±Bob DiachenkoÓÚ2021Äê8ÔÂ22ÈÕ·¢Ã÷ÁËδÊܱ£»¤µÄElasticsearchÊý¾Ý¿â¡£¸ÃÊý¾Ý¿â×ܹ²ÓÐ200GBÊý¾Ý£¬°üÀ¨ÁËÁè¼Ý1.06ÒÚÌ©¹úÓο͵ÄСÎÒ˽¼ÒÐÅÏ¢¡£DiachenkoÍƲ⣬¸ÃÊÂÎñÉæ¼°µ½ÒÑÍùÊ®ÄêÖÐÇ°ÍùÌ©¹úÂÃÓεĵÄËùÓÐÍâ¹úÈË¡£Ñо¿Ö°Ô±ÏÖÔÚÎÞ·¨È·¶¨ÕâЩÊý¾Ý鶵Äʱ¼ä£¬¿ÉÊÇÔÚ֪̩ͨ¹úÕþ¸®ºóµÄ24СʱÄھͱ»±£»¤ÁËÆðÀ´¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/data-of-106-million-visitors-to/



3¡¢VMwareÐÞ¸´vCenter ServerÖÐÑÏÖصÄÎļþÉÏ´«Îó²î


VMwareÐÞ¸´vCenter ServerÖÐÑÏÖصÄÎļþÉÏ´«Îó²î.png


VMwareÓÚ±¾ÖܶþÐû²¼Çå¾²¸üУ¬ÐÞ¸´vCenter ServerºÍCloud FoundationÖеÄ19¸öÎó²î¡£ÆäÖÐ×îΪÑÏÖصÄÊÇvCenter ServerÖеÄí§ÒâÎļþÉÏ´«Îó²î(CVE-2021-22005)£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÍøÂç»á¼û¶Ë¿Ú443µÄÉÏ´«ÌØÖÆÎļþÀ´Ö´ÐдúÂë¡£±ðµÄ£¬»¹ÐÞ¸´ÁËÍâµØÌáȨÎó²î£¨CVE-2021-21991£©¡¢·´ÏòÊðÀíÈƹýÎó²î£¨CVE-2021-22006£©¡¢API¶ËµãÎó²î£¨CVE-2021-22011£©ºÍAPIÐÅϢй¶Îó²î£¨CVE-2021-22012£©µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/09/vmware-warns-of-critical-file-upload.html



4¡¢AppleÐû²¼Çå¾²¸üУ¬ÐÞ¸´¶à¿î²úÆ·ÖеÄRCEµÈÎó²î



AppleÐû²¼Çå¾²¸üУ¬ÐÞ¸´¶à¿î²úÆ·ÖеÄRCEµÈÎó²î.png


AppleÓÚ9ÔÂ20ÈÕÐû²¼Çå¾²¸üУ¬ÐÞ¸´ÁËSafari 15¡¢Xcode 13¡¢tvOS 15¡¢watchOS 8¡¢iOS 15¡¢iPadOS 15ºÍiTunes 12.12ÖеĶà¸öÎó²î¡£ÆäÖаüÀ¨Safari 15ÖеÄÄÚ´æË𻵵¼ÖµÄí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-30846ºÍCVE-2021-30851µÈ£©¡¢tvOS 15ÖеÄDoSÎó²î£¨CVE-2013-0340£©ºÍɳºÐÈƹýÎó²î£¨CVE-2021-30854£©£¬ÒÔ¼°iOS 15ºÍiPadOS 15ÖеĴúÂëÖ´ÐÐÎó²î£¨CVE-2021-30837ºÍCVE-2021-30811£©µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/09/21/apple-releases-security-updates-multiple-products



5¡¢¶íÂÞ˹APT×éÖ¯TurlaʹÓÃкóÃŹ¥»÷ÃÀ¡¢µÂºÍ°¢¸»º¹


¶íÂÞ˹APT×éÖ¯TurlaʹÓÃкóÃŹ¥»÷ÃÀ¡¢µÂºÍ°¢¸»º¹.png


Cisco TalosÔÚ9ÔÂ21ÈÕÅû¶Á˶íÂÞ˹APT×éÖ¯TurlaʹÓÃкóÃÅTinyTurla¹¥»÷ÃÀ¡¢µÂºÍ°¢¸»º¹µÄÔ˶¯¡£Turla×Ô2004ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬¹¥»÷ÁËÖж«¡¢ÑÇÖÞ¡¢Å·ÖÞ¡¢±±ÃÀºÍÄÏÃÀµÈµØÇøµÄÄ¿µÄ¡£Ñо¿Ö°Ô±Í¨¹ýÒ£²â·¢Ã÷Á˺óÃÅ£¬µ«Éв»ÇåÎúÆäÈ·ÇеÄ×°Ö÷½·¨£¬½öÖªµÀ¹¥»÷ÕßʹÓÃ.batÎļþÈö²¥ºóÃÅ¡£¸ÃºóÃÅαװ³ÉMicrosoft DLL£¬²¢ÃüÃûΪw64time.dll£¬¿ÉÉÏ´«ºÍÖ´ÐÐÎļþ¡¢½¨Éè×ÓÁ÷³ÌºÍÇÔÈ¡Êý¾ÝµÈ¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2021/09/tinyturla.html