ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ47ÖÜ
Ðû²¼Ê±¼ä 2021-11-22>±¾ÖÜÇ徲̬ÊÆ×ÛÊö
±¾Öܹ²ÊÕ¼Çå¾²Îó²î67¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAdvantech WebAccess HMI Designer CVE-2021-33000ÏîÄ¿Îļþ¶ÑÒç³öÎó²î£»Google Chrome mediaÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î£»Lantronix PremierWave 2050 CVE-2021-21888ÏÂÁî×¢ÈëÎó²î£»Adobe Media Encoder M4A»º³åÇøÒç³öÎó²î£»Apache ShenYuδÊÚȨ»á¼ûÎó²î¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇFBIÓʼþϵͳÔâµ½ÈëÇÖ·¢ËÍÊýÊ®ÍòÌõÐéαµÄ¹¥»÷¾¯±¨£»ÍøÐÅ°ìÐû²¼¡¶ÍøÂçÊý¾ÝÇå¾²ÖÎÀíÌõÀý£¨Õ÷ÇóÒâ¼û¸å£©¡·£»Facebook·¢Ã÷SideCopyαÔìAndroidÓ¦ÓÃÊÐËÁµÄ¹¥»÷£»GoogleÐû²¼11Ô¸üУ¬ÐÞ¸´ChromeÖеĶà¸öÎó²î£»CloudflareÐû²¼ÆäµÖÓùÁ˸ߴï2 TbpsµÄDDoS¹¥»÷¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£
>Ö÷ÒªÇå¾²Îó²îÁбí
1. Advantech WebAccess HMI Designer CVE-2021-33000ÏîÄ¿Îļþ¶ÑÒç³öÎó²î
Advantech WebAccess HMI DesignerÏîÄ¿Îļþ´¦Öóͷ£±£´æ¶ÑÒç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉʹӦÓóÌÐò±ÀÀ£»ò¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://us-cert.cisa.gov/ics/advisories/icsa-21-173-01
2. Google Chrome mediaÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î
Google Chrome media±£´æÊͷźóʹÓÃÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÒ³ÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉʹӦÓóÌÐò±ÀÀ£»ò¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://chromereleases.googleblog.com/2021/11/stable-channel-update-for-desktop.html
3. Lantronix PremierWave 2050 CVE-2021-21888ÏÂÁî×¢ÈëÎó²î
Lantronix PremierWave 2050´¦Öóͷ£HTTPÇëÇóÑéÖ¤±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâÏÂÁî¡£
https://talosintelligence.com/vulnerability_reports/TALOS-2021-1332
4. Adobe Media Encoder M4A»º³åÇøÒç³öÎó²î
Adobe Media Encoder M4A±£´æ»º³åÇøÒç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉʹӦÓóÌÐò±ÀÀ£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://helpx.adobe.com/security/products/media-encoder/apsb21-70.html
5. Apache ShenYuδÊÚȨ»á¼ûÎó²î
Apache ShenYu Admin ShenyuAdminBootstrap±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÈƹýÇå¾²ÏÞÖÆδÊÚȨ»á¼û¡£
https://lists.apache.org/thread/o15j25qwtpcw62k48xw1tnv48skh3zgb
>Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢FBIÓʼþϵͳÔâµ½ÈëÇÖ·¢ËÍÊýÊ®ÍòÌõÐéαµÄ¹¥»÷¾¯±¨
FBIÓʼþϵͳÔÚ11ÔÂ13ÈÕÔâµ½ÈëÇÖ£¬±»ÓÃÀ´·¢ËÍÊýÊ®ÍòÌõÐéαµÄ¹¥»÷¾¯±¨¡£ÕâЩÓʼþð³äÁìÍÁÇå¾²²¿ (DHS)£¬Éù³ÆÊÕ¼þÈËÔâµ½ÁËÀ´×ÔVinny TroiaµÄÁ´Ê½¹¥»÷¡£µ«´ËÈËÊÇÇå¾²¹«Ë¾NightLionºÍShadowbyteµÄÈÏÕæÈË£¬Ñо¿Ö°Ô±Íƶϴ˴ÎÔ˶¯Ö¼ÔÚÚ®»ÙÇå¾²Ö°Ô±Troia¡£Spamhaus¹«Ë¾ÌåÏÖ£¬ÕâЩÓʼþ¶¼À´×ÔFBIÖ´·¨ÆóÒµÃÅ»§£¨LEEP£©µÄÕýÍâµØµãeims@ic.fbi.gov£¬IPµØµãΪ153.31.119.142(mx-east-ic.fbi.gov)¡£FBI³ÆÓÉÓÚÈí¼þ°´ÉèÖùýʧ£¬Ê¹µÃ¹¥»÷Õß¿ÉÒÔʹÓÃLEEP·¢ËÍαÔìµÄÓʼþ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/124570/cyber-crime/fbi-hacked-email-server.html
2¡¢ÍøÐÅ°ìÐû²¼¡¶ÍøÂçÊý¾ÝÇå¾²ÖÎÀíÌõÀý£¨Õ÷ÇóÒâ¼û¸å£©¡·
¹ú¼ÒÍøÐÅ°ìÓÚ11ÔÂ14ÈÕÐû²¼ÁË¡¶ÍøÂçÊý¾ÝÇå¾²ÖÎÀíÌõÀý£¨Õ÷ÇóÒâ¼û¸å£©¡·µÄ¹ûÕæÕ÷ÇóÒâ¼û֪ͨ¡£×èÖ¹½ñÄê6Ô£¬ÎÒ¹úÍøÃñ¹æÄ£´ï10.11ÒÚ£¬Óɴ˱¬·¢µÄÍøÂçÊý¾ÝÁ¿¸üÊÇÌìÎÄÊý×Ö¡£¸ÃÌõÀý¹æ·¶ÍøÂçÊý¾Ý´¦Öóͷ£Ô˶¯£¬±£»¤Ð¡ÎÒ˽¼Ò¡¢×éÖ¯ÔÚÍøÂç¿Õ¼äµÄÕýµ±È¨Ò棬ά»¤¹ú¼ÒÇå¾²ºÍ¹«¹²ÀûÒæ¡£Öйú»¥ÁªÍøлᷨ¹¤Î¯¸±ÃØÊ鳤ºú¸ÖÖ¸³ö£¬ÕâÊÇÐÂʱ´ú¹æ·¶»¥ÁªÍøƽ̨ÆóÒµ£¬Ç¿»¯·´Â¢¶ÏºÍ×ÊÔ´ÎÞÐòÀ©ÕŵÄÓ¦ÓÐÖ®Ò壬ҲÊÇά»¤¹ú¼ÒÇå¾²¡¢±£»¤Éç»á¹«¹²ÀûÒæµÄÐèÒª¡£
ÔÎÄÁ´½Ó£º
http://www.cac.gov.cn/2021-11/14/c_1638501991577898.htm
3¡¢Facebook·¢Ã÷SideCopyαÔìAndroidÓ¦ÓÃÊÐËÁµÄ¹¥»÷
FacebookµÄÇå¾²ÍŶÓÔÚ11ÔÂ16ÈÕÅû¶ÁË°Í»ù˹̹ºÚ¿ÍÍÅ»ïSideCopyÐÂÒ»ÂֵĴ¹ÂÚÔ˶¯¡£´Ë´ÎÔ˶¯ÔÚ½ñÄê4ÔÂÖÁ8ÔÂÖ®¼ä£¬½¨Éè²¢ÔËÓªÁËÒ»¸öαÔìµÄAndroidÓ¦ÓÃÊÐËÁ¡£¹¥»÷ÕßÖ÷Ҫͨ³£»áð³äÄêÇáÅ®ÐÔÀ´¿¿½üÄ¿µÄ£¬ÓÕʹÆä·¿ªÓÃÀ´ÓÃÀ´ÍøÂçÐÅÏ¢µÄ´¹ÂÚÍøÕ¾»òÕßαÔìµÄAndroidÓ¦ÓÃÊÐËÁ¡£È»ºóͨ¹ýαװ³É̸ÌìÓ¦ÓõĶñÒâÈí¼þ£¬·Ö·¢PJobRATºÍMayhemµÈ¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/pakistani-hackers-operated-a-fake-app-store-to-target-former-afghan-officials/
4¡¢GoogleÐû²¼11Ô¸üУ¬ÐÞ¸´ChromeÖеĶà¸öÎó²î
11ÔÂ16ÈÕ£¬GoogleÐû²¼Á˱¾ÔÂChromeµÄÇå¾²¸üУ¬×ܼÆÐÞ¸´ÁË25¸öÎó²î¡£ÆäÖУ¬½ÏΪÑÏÖصÄÊÇÔÚýÌåÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2021-38008£©¡¢V8ÖеÄÀàÐÍ»ìÏýÎó²î£¨CVE-2021-38007£©ºÍ¼ÓÔØÆ÷ÖÐÊͷźóʹÓÃÎó²î£¨CVE-2021-38005£©µÈ¡£±ðµÄ£¬»¹ÐÞ¸´ÁËÖ¸ÎÆʶ±ðÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2021-38013£©ºÍSwiftshaderÖеÄÔ½½çдÈ루CVE-2021-38014£©µÈÎó²î¡£
ÔÎÄÁ´½Ó£º
https://chromereleases.googleblog.com/2021/11/stable-channel-update-for-desktop.html
5¡¢CloudflareÐû²¼ÆäµÖÓùÁ˸ߴï2 TbpsµÄDDoS¹¥»÷
ÃÀ¹úÍøÂçÇå¾²¹«Ë¾CloudflareÔÚ11ÔÂ15ÈÕÐû²¼ÆäµÖÓùÁËÆù½ñΪֹÓöµ½µÄ×î´ó¹¥»÷DDoS¹¥»÷£¬·åÖµÂÔµÍÓÚ2 Tbps¡£´Ë´Î¹¥»÷Ô˶¯ÊÇÍŽáÁËDNS·Å´ó¹¥»÷ºÍUDP·ººéµÄ¶àÏòÁ¿¹¥»÷£¬Õû¸öÀú³ÌÖ»Ò»Á¬ÁËÒ»·ÖÖÓ£¬À´×ÔÔ¼15000¸ö»úеÈË×é³ÉµÄ½©Ê¬ÍøÂçMirai±äÖÖ¡£Cloudflare±¨¸æ³ÆµÚÈý¼¾¶ÈÍøÂç²ãDDoS¹¥»÷Ô˶¯±ÈÉÏÒ»¼¾¶ÈÔöÌíÁË44%£¬¸Ã¹«Ë¾ÔÚ8ÔµÖÓùÁËÿÃë1720Íò´ÎÇëÇóµÄDDoS¹¥»÷£¬Î¢ÈíÔÚ10Ô³ÆÆäÔÆ·þÎñAzureµÖÓùÁË2.4 TbpsµÄDDoS¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/124634/security/cloudflare-mitigated-ddos-2-tbps.html