ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ26ÖÜ

°ä²¼¹¦·ò 2021-06-28

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2021Äê06ÔÂ21ÈÕÖÁ06ÔÂ27ÈÕ¹²ÊÕ¼°²È«·ì϶53¸ö  £¬ÖµµÃ¹Ø×¢µÄÊÇWebAccess HMI DesignerÏîÄ¿ÎļþÔ½½çд´úÂëÖ´Ðзì϶ £»D-LINK DSL-2888A routerËÁÒâÃÜÂëÅú¸Ä·ì϶ £»Zoho ManageEngine ADSelfService PlusÃÜÂë¸ü¸Ä´úÂëÖ´Ðзì϶ £»Apple macOS CoreText TTF½âÎöÕ»Òç³ö´úÂëÖ´Ðзì϶ £»WEIDMUELLER Industrial WLAN devices iw_consoleȨÏÞÌáÉý·ì϶¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ×êÑÐÈËÔ±ÑÝʾÈôºÎͨ¹ýWiFiÈȵãÀ´¹¥»÷iPhoneÊÖ»ú £»×êÑÐÍŶӳƽüÆÚÀÕË÷Èí¼þ¹¥»÷³ÖÐø¼¤Ôö  £¬Í¬±ÈÔö³¤93% £»Å²Íþ¾¯·½È·ÈÏÆäÔÚ2018ÄêÔâµ½µÄºÚ¿Í¹¥»÷ÓëAPT31ÓйØ £»×êÑÐÍŶÓÔÚPyPI´æ´¢¿â·¢ÏÖ¶à¸öÓÃÓÚÍÚ¿óµÄ¶ñÒâÈí¼þ°ü £»Zephyrʵʱ²Ù×÷ϵͳ(RTOS)°²È«¸üР £¬½¨¸´¶à¸ö·ì϶¡£


ƾ¾ÝÒÔÉÏ×ÛÊö  £¬±¾Öܰ²È«ÍþвΪÖС£


> ³ÁÒª°²È«·ì϶Áбí


1.WebAccess HMI DesignerÏîÄ¿ÎļþÔ½½çд´úÂëÖ´Ðзì϶


WebAccess HMI Designer´¦ÖÃÏîÄ¿Îļþ´æÔÚÔ½½çд·ì϶  £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó  £¬ÓÕʹÓû§½âÎö  £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ £»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë

https://us-cert.cisa.gov/ics/advisories/icsa-21-173-01


2.D-LINK DSL-2888A routerËÁÒâÃÜÂëÅú¸Ä·ì϶


D-LINK DSL-2888A router´æÔÚËÁÒâÃÜÂëÅú¸Ä·ì϶  £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó  £¬¿ÉÅú¸ÄÖÎÀíÔ±ÃÜÂë¡£

https://github.com/EmYiQing/CVE


3.Zoho ManageEngine ADSelfService PlusÃÜÂë¸ü¸Ä´úÂëÖ´Ðзì϶


Zoho ManageEngine ADSelfService Plus¸ü¸ÄÃÜÂë´æÔÚ°²È«·ì϶  £¬ÔÊÐí±¾µØ¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó  £¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://www.manageengine.com/products/self-service-password/release-notes.html#6102


4.Apple macOS CoreText TTF½âÎöÕ»Òç³ö´úÂëÖ´Ðзì϶


Apple macOS CoreText TTF½âÎö´æÔÚÕ»Òç¶Âí½Å  £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó  £¬ÓÕʹÓû§½âÎö  £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ £»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://support.apple.com/HT212147


5.WEIDMUELLER Industrial WLAN devices iw_consoleȨÏÞÌáÉý·ì϶


WEIDMUELLER Industrial WLAN devices iw_consoleÖ°ÄÜ´æÔÚתÒåʧ°Ü·ì϶  £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó  £¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://cert.vde.com/en-us/advisories/vde-2021-026


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢×êÑÐÈËÔ±ÑÝʾÈôºÎͨ¹ýWiFiÈȵãÀ´¹¥»÷iPhoneÊÖ»ú


1.jpg


×êÑÐÈËÔ±Carl SchouÑÝʾÁËÈôºÎͨ¹ýWiFiÈȵãÀ´¹¥»÷iPhoneÊÖ»ú¡£Carl SchouÔÚÏνÓÓ×ÎÒWiFiÈȵ㡰%p%s%s%s%s%n¡±Ê±  £¬·¢ÏÖËûiPhoneµÄWiFiÖ°Äܱ»½ûÓà  £¬²¢ÇÒÔÙÒ²ÎÞ·¨ÆôÓÃWiFiÖ°ÄÜ  £¬¼´±ãËû³ÁÆôÉ豸»ò¸ü¸ÄÈȵãÃû³Æ¡£×êÑÐÈËÔ±³Æ  £¬Õâ¿ÉÄÜÊÇÊäÈë½âÎöÎÊÌâµ¼Ö嵀  £¬µ±WiFiÈȵãÃû³ÆÖдæÔÚ´øÓÓ×°%¡±µÄ×Ö·û´®Ê±  £¬iOS¿ÉÄÜ»áÃýÎ󵨽«¡°%¡±ºóÃæµÄ×ÖĸڹÊÍΪ×Ö·û´®ÌåʽעÃ÷·û¡ £¸´Ô­Wi-FiÖ°ÄܵÄΨһ²½ÖèÊdzÁÖÃiPhoneµÄÍøÂçÉèÖá£´Ë±í  £¬¸Ã·ì϶ÊÇiPhone¶ÀÓÐµÄ  £¬ÎÞ·¨ÔÚAndroidÊÖ»úÉϳÁÏÖ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/iphone-bug-breaks-wifi-when-you-join-hotspot-with-unusual-name/


2¡¢×êÑÐÍŶӳƽüÆÚÀÕË÷Èí¼þ¹¥»÷³ÖÐø¼¤Ôö  £¬Í¬±ÈÔö³¤93%


2.jpg


Check Point Research×êÑÐÍŶӳƽüÆÚÀÕË÷Èí¼þ¹¥»÷³ÖÐø¼¤Ôö¡£2021Äê6ÔÂÿÖÜÊÜÀÕË÷Èí¼þÓ°ÏìµÄ×éÖ¯ÊýÁ¿ÒÑÔöÖÁ1210¸ö  £¬×ÔËêÊ×ÒÔÀ´  £¬ÀÕË÷Èí¼þ¹¥»÷´ÎÊýÔö³¤ÁË41%  £¬Í¬±ÈÔö³¤ÁË93%¡£ÆäÖÐÀ­¶¡ÃÀÖÞµÄÀÕË÷Èí¼þ¹¥»÷³¢ÊÔÔö³¤×îΪÏÔ×Å  £¬Ôö³¤ÁË62%  £¬Æä´ÎÊÇÅ·ÖÞÔö³¤ÁË59%  £¬·ÇÖÞÔö³¤ÁË34%  £¬±±ÃÀÔö³¤ÁË32%¡£´Ë±í  £¬Õë¶Ô½ÌÓýÐÐÒµµÄ¹¥»÷Ôö³¤¿ìÂÊ×î¿ì£¨ÓëÈ¥ÄêͬÆÚÏà±ÈÔö³¤ÁË347%£©  £¬Æä´ÎΪÔËÊäÐÐÒµ£¨186%£©¡¢ÁãÊÛºÍÅú¿¯ÐÐÒµ£¨162%£©ÒÔ¼°Ò½ÁƱ£½¡ÐÐÒµ£¨159%£©¡£


Ô­ÎÄÁ´½Ó£º

https://blog.checkpoint.com/2021/06/14/ransomware-attacks-continue-to-surge-hitting-a-93-increase-year-over-year/


3¡¢Å²Íþ¾¯·½È·ÈÏÆäÔÚ2018ÄêÔâµ½µÄºÚ¿Í¹¥»÷ÓëAPT31ÓйØ


3.jpg


ŲÍþ¾¯Ô±°²È«¾Ö (PST) °µÊ¾  £¬ÆäÔÚ2018ÄêÔâµ½µÄÍøÂç¹¥»÷ÓëºÚ¿Í×éÖ¯APT31ÓйØ¡£¾Ýµ÷²éÏÔʾ  £¬ÔÚÕâ´Î¹¥»÷ÖкڿÍÒѳɹ¦»ñµÃÖÎÀíԱȨÏÞ  £¬Äܹ»½Ó¼û¸Ã¹úËùÓйú¶ÈÐÐÕþ°ì¹«ÊÒʹÓõÄÖÐÑëÍÆËã»úϵͳ  £¬»¹³É¹¦µØ´Ó°ì¹«ÊÒϵͳÇÔÈ¡ÁËһЩÊý¾Ý¡£´Ë±í  £¬×êÑÐÈËÔ±³Æ  £¬APT31»¹±»ÒÔΪÊÇ2020Äê12ÔÂÕë¶Ô·ÒÀ¼Òé»áµÄÍøÂç¹¥»÷µÄÄ»ºóºÚÊÖ  £¬ÔÚÕâ´Î¹¥»÷Öкڿͳɹ¦ÈëÇÖÁËһЩÒé»áÓйصç×ÓÓʼþµÄÕÊ»§¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/119161/apt/norway-blames-china-apt31.html


4¡¢×êÑÐÍŶÓÔÚPyPI´æ´¢¿â·¢ÏÖ¶à¸öÓÃÓÚÍÚ¿óµÄ¶ñÒâÈí¼þ°ü


4.jpg


×êÑÐÍŶÓÔÚPythonÏîÖ÷ÕÅPyPI¿âÖз¢ÏÖÁË6¸ö¶ñÒâÈí¼þ°ü  £¬Äܹ»½«¿ª·¢ÈËÔ±µÄÍÆËã»úÔì³É¿ó»ú¡£ËùÓжñÒâÈí¼þ°ü¾ùÓÉͳһÓû§¡°nedog123¡±°ä²¼  £¬±ðÀëΪmaratlib¡¢maratlib1¡¢matplatlib-plus¡¢mllearnlib¡¢mplatlibºÍlearninglib  £¬ÆäÖдó²¿ÃŵÄÃû³Æ¶¼ÊǺϷ¨»­Í¼Èí¼þmatplotlibµÄƴдÃýÎó°æ±¾  £¬ºÚ¿Íͨ¹ýÕâÖÖ·½Ê½À´ºýŪ¿ª·¢ÈËÔ±ÏÂÔØ¡£×êÑÐÈËÔ±³Æ¶ñÒâ´úÂë¶¼ÔÚsetup.pyÎļþÖÐ  £¬Ëü»áÔÚGitHub´æ´¢¿âÏÂÔØBash¾ç±¾(aza2.sh)  £¬¸Ã¾ç±¾µÄ×÷ÓÃÊÇÔÚÖ¸±ê»úеÉÏÔËÐеļÓÃÜ¿ó¹¤Ubqminer¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/malicious-pypi-packages-hijack-dev-devices-to-mine-cryptocurrency/


5¡¢Zephyrʵʱ²Ù×÷ϵͳ(RTOS)°²È«¸üР £¬½¨¸´¶à¸ö·ì϶


5.jpg


Zephyrʵʱ²Ù×÷ϵͳ(RTOS)°²È«¸üР £¬½¨¸´ÁË8¸ö¿ÉÄܵ¼Ö»ؾø·þÎñ (DoS) ºÍÔ¶³Ì´úÂëÖ´Ðеķì϶¡£ZephyrÊÇÓ×Ð͵Äʵʱ²Ù×÷ϵͳ  £¬ÓÃÓÚ×ÊÔ´ÊÜÏÞµÄǶÈëʽ»¥ÁªÉ豸  £¬µÃµ½ÁËFacebook¡¢¹È¸è¡¢IntelµÈ³ÛÃû¹«Ë¾µÄÖ§³Ö  £¬Ö§³Ö200¶àÖÖ·ÖÆçCPU¼Ü¹¹£¨ARM¡¢Cortex-MºÍIntel x86µÈ£©¡£Õâ´Î½¨¸´µÄ·ì϶´æÔÚÓÚZephyrµÄÀ¶ÑÀLEÁ´Â·²ã (LL) ¼°ÆäÂß¼­Á´Â·½ÚÔìºÍÊÊÅäºÍ̸ (L2CAP) ÖÐ  £¬ÆäÖнÏΪÑϳÁµÄÊÇÐÅϢй¶·ì϶£¨CVE-2021-3435£©ºÍDoS·ì϶£¨CVE-2021-3455£©¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/zephyr-rtos-fixes-bluetooth-bugs-that-may-lead-to-code-execution/