Ó¢¹ú¹ú·À²¿µÄ¹ú·ÀѧԺÔâµ½¹¥»÷£¬ÒÉΪ±í¹úºÚ¿Í£»IoT¹«Ë¾Sierra WirelessϰȾÀÕË÷Èí¼þµ¼Ö³ö²úÖжÏ

°ä²¼¹¦·ò 2021-03-24

1.Ó¢¹ú¹ú·À²¿µÄ¹ú·ÀѧԺÔâµ½¹¥»÷£¬ÒÉΪ±í¹úºÚ¿Í


1.jpg


Ó¢¹ú¹ú·À²¿µÄ¹ú·ÀѧԺÔâµ½ÑϳÁµÄ¹¥»÷£¬ÒÉ»óÊǶíÂÞ˹µÈ±í¹úÈ¨ÊÆËùΪ¡£¸ÃѧԺλÓÚÅ£½ò¿¤Î÷ÄÏʲÀï·òÄÉÄ·£¬ÖØÒªÎªÓ¢¹úÎä×°¶ÓÁÓ×¢¹«ÎñÔ±¡¢ÆäËûµ±²¿ÃÅÃź͹ú¶È·þÎñÈËÔ±Ìṩ¸ßµµ½ÌÓý¡£Õâ´Î¹¥»÷µ¼Ö¸ÃѧԺµÄ¹ÙÍøÖжÏ£¬ÓɳаüÉÌÔËÓªµÄITÍøÂç±»·ÛË飬ѧÌÃϵͳҲÊܵ½Ó°Ï죬¸ÃУԱ¹¤±»ÆÈʹÓÃÓ×ÎÒµçÄÔ½øÐа칫¡£¾ÝϤ£¬Ô¤¼Æ±ØÒª5Öܹ¦·òÄÜÁ¦ÆëÈ«¸´Ô­ÊÜÓ°ÏìµÄÍÆËã»úºÍ·þÎñÆ÷¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/115870/hacking/ministry-of-defence-hacked.html


2.ºÚ¿ÍÀûÓÃAccellionµÄFTAÖзì϶ÈëÇÖ¿ÇÅÆ²¢Î´Ó°ÏìÆäÍøÂç


2.jpg


ºÚ¿ÍÀûÓÃAccellionµÄFile Transfer Appliance£¨FTA£©Öзì϶ÈëÇÖÄÜÔ´¹«Ë¾¿ÇÅÆ¡£¿ÇÅÆ¹«Ë¾Ðû³Æ£¬¸ÃÊÂÎñ½öÓ°ÏìÁËFTAÉ豸£¬ÓÉÓÚÎļþ´«Êä·þÎñÓëÆäËûÊý×Ö»ù´¡ÉèÊ©ÊǸôÀëµÄ£¬Òò¶øÆäÖ÷ÌâITϵͳδÊܵ½ÈκÎÓ°Ïì¡£´Ë±í£¬¹¥»÷Õß¿ÉÄÜÒѾ­ÇÔÈ¡²¿ÃÅÊý¾Ý£¬Ô̺¬Ò»Ð©Ó×ÎÒÐÅÏ¢ÒÔ¼°¿ÇÅÆ¹«Ë¾ºÍÆäÀûÒæÓйØÕßµÄÊý¾Ý¡£Ö»¹Ü¿ÇÅÆ¹«Ë¾Ã»ÓÐÅû¶¹¥»÷ÕßµÄÉí·Ý£¬µ«×êÑÐÈËÔ±´§Ä¦£¬Õâ´Î¹¥»÷ÓëFIN11ºÚ¿ÍÍÅ»ïÓйØ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/energy-giant-shell-discloses-data-breach-after-accellion-hack/


3.IoT¹«Ë¾Sierra WirelessϰȾÀÕË÷Èí¼þµ¼Ö³ö²úÖжÏ


3.jpg


3ÔÂ20ÈÕ£¬¼ÓÄôó¿ç¹úÎÞÏßͨѶÉ豸Ôì×÷ÉÌSierra WirelessϰȾÀÕË÷Èí¼þ£¬ËùÓгö²ú»î¶¯±»ÆÈÖжÏ¡£¸Ã¹«Ë¾ÖØÒªÏúÊÛͨѶÉ豸£¬ÔÚ±±ÃÀ¡¢Å·ÖÞºÍÑÇÖÞ¾ùÉèÓÐÑз¢ÖÐÐÄ¡£Õâ´Î¹¥»÷µ¼Ö¹«Ë¾¹ÙÍøºÍÄÚ²¿ÔËÓªÔâµ½·ÛË飬ȫÇòµÄ³ö²ú¹¤³§±»ÆÈ¹Ø¹Ø¡£µ«ÒòÆäÄÚ²¿ITϵͳÓë¿Í»§µÄ·þÎñÖ®¼ä·Ö¸ô¿ªÁË£¬ËùÒÔ¿Í»§²¢Î´Êܵ½Ó°Ï졣Ŀǰ£¬¸Ã¹«Ë¾ÔÚµÚÈý·½×¨¼ÒµÄЭÖúϵ÷²é´ËÊÂÎñ£¬²¢2ÔÂ23ÈÕ³·»ØÁËÉϸöÔ°䲼µÄ2021ÄêµÚÒ»¼¾¶ÈÁìµ¼»ã±¨¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/115897/malware/sierra-wireless-ransomware.html


4.¹È¸èÅû¶ÀûÓøßͨоƬÖÐÊäÈëÑéÖ¤·ì϶µÄ¹¥»÷»î¶¯


4.jpg


¹È¸èÔÚÒ°·¢ÏÖÀûÓøßͨоƬÖÐÊäÈëÑéÖ¤·ì϶£¨CVE-2020-11261£©À´Õë¶ÔAndroidϵͳµÄ¹¥»÷»î¶¯¡£¸Ã·ì϶λÓÚͼÐÎ×é¼þÖУ¬CVSSÆÀ·ÖΪ8.4£¬µ±ÌØÔìµÄÀûÓ÷¨Ê½ÒªÇó½Ó¼ûÉ豸ÖеĴóÁ¿ÄÚ´æÊ±£¬¿ÉÄܵ¼ÖÂÄÚ´æ·ÛËé¡£¸Ã·ì϶ÓÚ2020Äê8ÔÂ20ÈÕ±»Åû¶£¬²¢ÓÚ2021Äê1Ôµõ½½¨¸´¡£GoogleÔÚ3ÔÂ18ÈÕ¸üеÄ1Ô°²È«²¼¸æÖаµÊ¾£¬CVE-2020-11261¿ÉÄÜÒѾ­±»ÀûÓÃÌáÒéÕë¶ÔÐÔ¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/03/warning-new-android-zero-day.html


5.ͨÓÃµçÆø£¨GE£©µÄURÉ豸´æÔÚ¶à¸öÑϳÁµÄ·ì϶


5.jpg


CISAÖÒ¸æÍ¨ÓÃµçÆø£¨GE£©µÄͨÓü̵çÆ÷£¨UR£©ÏµÁеçÔ´ÖÎÀíÉ豸ÖдæÔÚ9¸öÑϳÁµÄ·ì϶¡£¸Ã¹«Ë¾³ÆURÉ豸ÊǼò»¯µçÔ´ÖÎÀíÒÔ±£»¤¹Ø¼ü×ʲúµÄ»ù´¡£¬ÔÊÐíÓû§½ÚÔì¸÷ÀàÉ豸¿÷ËðµÄµç¹¦ÂÊÁ¿µÄÍÆËãÉ豸¡£ÆäÖÐ×îÑϳÁµÄ·ì϶ÊÇCVE-2021-27426£¬ÓÉĬÈϱäÁ¿³õʼ»¯²»°²È«µ¼Ö£¬CVSSÆÀ·ÖΪ9.8£¬¹¥»÷Õß¿ÉÔ¶³ÌÀûÓø÷ìÏ¶ÈÆ¹ý½Ó¼ûÏÞ¶È¡£Æä´ÎΪ¿ÉÓÃÀ´³ÁÆôURµÄCVE-2021-27430ºÍÊäÈëÑéÖ¤·ì϶£¨CVE-2021-27418ºÍCVE-2021-27420£©µÈ¡£


 Ô­ÎÄÁ´½Ó£º

https://threatpost.com/cisa-security-flaws-ge-power-management/164961/


6.Kaspersky°ä²¼2020ÄêICSÐÐÒµµÄÌ¬ÊÆ·ÖÎö»ã±¨


6.jpg


Kaspersky°ä²¼ÁË2020ÄêICSÐÐÒµµÄÌ¬ÊÆ·ÖÎö»ã±¨¡£¸Ã»ã±¨·ÖÎöÁËÓÃÓÚÉè¼Æ¡¢ÅäÖúÍÊØ»¤¹¤Òµ½ÚÔìÉ豸ºÍÈí¼þµÄÍÆËã»úËùÊܵ½µÄÍøÂçÍþв¡£»ã±¨Ö¸³ö£¬ÔÚ2020ÄêϰëÄ꣬ÔÚICS¹¤³ÌºÍ¼¯³ÉÐÐÒµÖÐ39.3£¥µÄÍÆËã»úÊܵ½Á˶ñÒâÈí¼þ¹¥»÷£¬Óë2020ÄêÉϰëÄ꣨31.5£¥£©Ïà±Å×ÐËùÔö³¤£¬ÆäÖй¹Öþ×Ô¶¯»¯¡¢Æû³µÔì×÷¡¢ÄÜԴʯÓͺÍÌìÈ»ÆøÐÐÒµÔâµ½µÄ¹¥»÷Ôö¶à¡£2020ÄêϰëÄ꣬Õë¶ÔÀ­¶¡ÃÀÖÞ¡¢Öж«¡¢ÑÇÖ޺ͱ±ÃÀµÄ¹¥»÷´ÎÊýÔö¶à£¬Õë¶Ô·ÇÖÞ¡¢¶íÂÞ˹ºÍÅ·Ö޵Ĺ¥»÷ÊýÁ¿ÓÐËùÏ÷¼õ¡£


Ô­ÎÄÁ´½Ó£º

https://ics-cert.kaspersky.com/reports/2021/03/17/threat-landscape-for-the-ics-engineering-and-integration-sector-2020/