ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ23ÖÜ
°ä²¼¹¦·ò 2021-06-07> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2021Äê05ÔÂ31ÈÕÖÁ06ÔÂ06ÈÕ¹²ÊÕ¼°²È«·ì϶59¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMozilla Firefox CVE-2021-29966»º³åÇøÒç¶Âí½Å£»Cisco Common Services Platform Collector OSºÅÁîÖ´Ðзì϶£»Synology Photo Station SQL×¢Èë·ì϶£»F5 BIG-IQ Centralized ManagementºÅÁî×¢Èë·ì϶£»OpenText Brava Desktop PDFÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇSophos·¢ÏÖÕë¶ÔExchangeµÄÐÂÀÕË÷Èí¼þEpsilon Red£»È«Çò×î´óÈâÀà³ö²úÉÌJBSÔâµ½¹¥»÷£¬¶à¸ö·Ö¹«Ë¾Í£²ú£»×êÑÐÍŶӷ¢ÏÖкóÃÅFacefish£¬¿ÉÇÔÈ¡LinuxϵͳÐÅÏ¢£»ÃÀ¹úÒѲé·âNOBELIUMÔÚÕë¶ÔUSAIDµÄ¹¥»÷ÖÐʹÓõÄÓòÃû£»Check Point°ä²¼2021ÄêÑÇÌ«µØÓòÍøÂç¹¥»÷·ÖÎö»ã±¨¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
> ³ÁÒª°²È«·ì϶Áбí
1.Mozilla Firefox CVE-2021-29966»º³åÇøÒç¶Âí½Å
Mozilla Firefox´æÔÚ»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»ò¿ÉÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://www.mozilla.org/en-US/security/advisories/mfsa2021-23/
2.Cisco Common Services Platform Collector OSºÅÁîÖ´Ðзì϶
Cisco Common Services Platform Collector CSPCÅäÖôæÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâOSºÅÁî¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-CSPC-CIV-kDuBfNfu
3.Synology Photo Station SQL×¢Èë·ì϶
Snology Photo Station´æÔÚSQL×¢Èë·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄSQLÒªÇ󣬲Ù×÷Êý¾Ý¿â£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐËÁÒâ´úÂë¡£
https://www.synology.cn/zh-cn/security/advisory/Synology_SA_20_20
4.F5 BIG-IQ Centralized ManagementºÅÁî×¢Èë·ì϶
F5 BIG-IQ Centralized Managementij¸öÒ³Ãæ´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâOSºÅÁî¡£
https://support.f5.com/csp/article/K06024431
5.OpenText Brava Desktop PDFÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶
OpenText Brava Desktop PDF´¦ÖôæÔÚ¿ªÊͺóʹÓ÷ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÄܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-642/
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢Sophos·¢ÏÖÕë¶ÔExchangeµÄÐÂÀÕË÷Èí¼þEpsilon Red

°²È«¹«Ë¾Sophos·¢ÏÖÐÂÀÕË÷Èí¼þEpsilon Red£¬ÖØÒªÕë¶ÔMicrosoft Exchange·þÎñÆ÷¡£×êÑÐÈËÔ±ÔÚµ÷²éÕë¶ÔÃÀ¹úij¾ÆµêµÄ¹¥»÷»î¶¯Ê±·¢ÏֵĸöñÒâÈí¼þ¡£Epsilon RedÓÃGolang£¨Go£©±àд£¬ÓÐÒ»×é¹ÖÒìµÄPowerShell¾ç±¾£¬ÆäÖÐÿ¸ö¾ç±¾¶¼ÓÐÌØ¶¨×÷Óã¬ÈçÖÕÖ¹°²È«¹¤¾ß¡¢É¾³ý¸±±¾¡¢ÇÔÈ¡°²È«ÕÊ»§ÖÎÀíÆ÷£¨SAM£©ÎļþµÈ¡£×êÑÐÈËÔ±°µÊ¾£¬¸ÃÍÅ»ïʹÓÃÁËREvilÊê½ð¼Í¼µÄÄ£°å£¨¸üÕýÁËÆäÖеÄÓï·¨ºÍƴдÃýÎ󣩣¬²¢ÇÒEpsilon RedÊÇÂþÍþÖжíÂÞ˹³¬µÈÊ¿±øµÄ½ÇÉ«Ãû£¬Òò¶ø´§¶È¸ÃÍÅ»ïÓë¶íÂÞ˹Óйء£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-epsilon-red-ransomware-hunts-unpatched-microsoft-exchange-servers/
2¡¢È«Çò×î´óÈâÀà³ö²úÉÌJBSÔâµ½¹¥»÷£¬¶à¸ö·Ö¹«Ë¾Í£²ú

JBSʳƷ¹«Ë¾ÓÚÉÏÖÜÄ©Ôâµ½¹¥»÷£¬Ó°ÏìÃÀ¹ú¡¢°Ä´óÀûÑǺͼÓÄôóµÈµØµÄ·Ö¹«Ë¾¡£JBSÊÇÈ«Çò×î´óµÄÅ£ÈâºÍ¼ÒÇݳö²úÉÌ£¬Ò²ÊÇÈ«ÇòµÚ¶þ´óÖíÈâ³ö²úÉÌ£¬ÔÚÁù´óÖÞµÄ190¸ö¹ú¶È/µØÓò¶¼ÓÐÒµÎñ¡£Ä¿Ç°£¬°Ä´óÀûÑǵ±¾ÖÒÑ»ñϤÕâÒ»ÊÂÎñ£¬²¢ÔÚÓëJBSºÏ×÷ÊÔͼ¸´Ô¾³Äڵijö²ú»î¶¯¡£´Ë¿ÌÉв»Ã÷ÏÔÕâ´Î¹¥»÷µÄÐÔÖʵȾßÌåÐÅÏ¢£¬ÓÉÓÚ¹¥»÷²úÉúÓÚÖÜÄ©£¬Òò¶ø×êÑÐÈËÔ±´§¶È¼«ÓпÉÄÜÓëÀÕË÷Èí¼þÓйء£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/food-giant-jbs-foods-shuts-down-production-after-cyberattack/
3¡¢×êÑÐÍŶӷ¢ÏÖкóÃÅFacefish£¬¿ÉÇÔÈ¡LinuxϵͳÐÅÏ¢

×êÑÐÍŶӷ¢ÏÖÁËÒ»¸öеĺóÃÅFacefish£¬¿É½ÚÔìLinuxϵͳ²¢ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£FacefishÓÉDropperºÍRootkitÁ½²¿ÃÅ×é³É£¬ÆäÖØÒªÖ°ÄÜÓÉRootkitÄ£¿éÈ·¶¨£¬¸ÃÄ£¿éÔÚRing3²ã¹¤×÷£¬²¢Ê¹ÓÃLD_PRELOADÖ°ÄܽøÐмÓÔØ¡£¸Ã¶ñÒâÈí¼þÖ§³Ö¶àÖÖÖ°ÄÜ£¬Ô̺¬:ÉÏ´«É豸ÐÅÏ¢¡¢ÇÔÈ¡Óû§Æ¾Ö¤¡¢µ¯»ØshellºÍÖ´ÐÐËÁÒâºÅÁî¡£´Ë±í£¬×êÑÐÈËÔ±°µÊ¾FacefishѡȡÁ˸´ÔÓµÄͨѶºÍ̸ºÍ¼ÓÃÜËã·¨£¬ËüʹÓÃÒÔ0x2XX¿ªÍ·µÄÖ¸ÁîÀ´»¥»»¹«Ô¿£¬²¢Ê¹ÓÃBlowFishÓëC2·þÎñÆ÷¼ÓÃÜͨѶÊý¾Ý¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/118388/malware/facefish-backdoor.html
4¡¢ÃÀ¹úÒѲé·âNOBELIUMÔÚÕë¶ÔUSAIDµÄ¹¥»÷ÖÐʹÓõÄÓòÃû

ÃÀ¹ú˾·¨²¿ÒѲé·âNOBELIUMÔÚÕë¶ÔÃÀ¹ú¹ú¼Ê¿ª·¢Êð (USAID) µÄ¹¥»÷ÖÐʹÓõÄÓòÃû¡£Î¢ÈíÓÚÉÏÖÜËijõ´ÎÅû¶ÁËÕâ´Î´¹µö¹¥»÷£¬´ÓÊôÓÚ¶íÂÞ˹µý±¨»ú¹¹SVRµÄNOBELIUM£¨±ðÃûAPT29£©¼ÙÒâUSAID£¬ Ïò150 ¶à¸ö×éÖ¯·¢ËÍÁË3000¶à·â´¹µöÓʼþ¡£Õâ´Î²é·âµÄÁ½¸öÓòÃû±ðÀëΪtheyardservice[.]comºÍworldhomeoutlet[.]com£¬ÖØÒªÓÃÓڽӹܴÓÊܺ¦ÕßÄÇÀïй¶µÄÊý¾Ý£¬²¢·¢ËͺÅÁî¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/us-seizes-domains-used-by-apt29-in-recent-usaid-phishing-attacks/
5¡¢Check Point°ä²¼2021ÄêÑÇÌ«µØÓòÍøÂç¹¥»÷·ÖÎö»ã±¨

Check Point°ä²¼ÁË2021ÄêÑÇÌ«µØÓòÍøÂç¹¥»÷µÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬Óë2020Äê5ÔÂÏà±È£¬ÑÇÌ«µØÓò (APAC) µÄÍøÂç¹¥»÷ÊýÁ¿Í¬±ÈÔö³¤ÁË168%£¬¶øÔÚ2021Äê4ÔÂÖÁ5ÔÂÆÚ¼ä¾ÍÔö³¤ÁË53%¡£Ôö·ù×î´óµÄ¶ñÒâÈí¼þÀàÐÍÊÇÀÕË÷Èí¼þºÍÔ¶³Ì½Ó¼ûľÂí (RAT)£¬Óë½ñÄêËêÊ×Ïà±È£¬¶¼Ôö³¤ÁË26%£¬¶øÒøÐÐľÂíºÍÐÅÏ¢ÇÔÈ¡¹¤¾ßÒ²Ôö³¤ÁË10%¡£ÍøÂç¹¥»÷´ÎÊýÔö·ù×î´óµÄǰ5¸ö¹ú¶È/µØÓòÊÇÈÕ±¾£¨40%£©¡¢ÐÂ¼ÓÆÂ£¨30%£©¡¢Ó¡¶ÈÄáÎ÷ÑÇ£¨25%£©¡¢ÂíÀ´Î÷ÑÇ£¨22%£©ºÍÖйų́Í壨17%£©¡£
ÔÎÄÁ´½Ó£º
https://blog.checkpoint.com/2021/05/27/check-point-research-asia-pacific-experiencing-a-168-year-on-year-increase-in-cyberattacks-in-may-2021/


¾©¹«Íø°²±¸11010802024551ºÅ