ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ29ÖÜ
°ä²¼¹¦·ò 2021-07-19> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2021Äê07ÔÂ12ÈÕÖÁ07ÔÂ18ÈÕ¹²ÊÕ¼°²È«·ì϶70¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows Defender CVE-2021-34522´úÂë×¢Èë·ì϶£»SAP NetWeaver ABAP Server²»ÕýÈ·ÑéÖ¤·ì϶£»Adobe Illustrator CVE-2021-28591Ô½½çд´úÂëÖ´Ðзì϶£»Fortinet FortiSandbox OSºÅÁî×¢Èë·ì϶£»Schneider Electric EVlink Charging StationsÓ²±àÂëÑéÖ¤ÈÆ¹ý·ì϶¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇMint Mobile³ÆÆä²úÉúÊý¾Ýй¶£¬ÇÒ²¿Ãſͻ§±»×ªÍø£»×êÑÐÈËÔ±Åû¶½üÆÚ¼ÙÒâ¶íÂÞ˹µ±¾ÖµÄ´¹µö¹¥»÷»î¶¯£»Kaseya°²È«¸üн¨¸´REvilÔÚ¹©¸øÁ´¹¥»÷ÖÐÓõÄ0day£»Î¢Èí°ä²¼7Ô·ݰ²È«¸üУ¬½¨¸´9¸ö0dayÔÚÄÚµÄ117¸ö·ì϶£»SolarWinds½¨¸´Serv-UÖÐÒѱ»ÀûÓõÄÔ¶³Ì´úÂëÖ´Ðзì϶¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
> ³ÁÒª°²È«·ì϶Áбí
1.Microsoft Windows Defender CVE-2021-34522´úÂë×¢Èë·ì϶
Microsoft Windows Defender´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-34522
2.SAP NetWeaver ABAP Server²»ÕýÈ·ÑéÖ¤·ì϶
SAP NetWeaver ABAP Server´æÔÚ²»ÕýÈ·ÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉδÊÚȨ½Ó¼ûÀûÓá£
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=580617506
3.Adobe Illustrator CVE-2021-28591Ô½½çд´úÂëÖ´Ðзì϶
Adobe Illustrator´æÔÚÔ½½çд·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://helpx.adobe.com/security/products/illustrator/apsb21-42.html
4.Fortinet FortiSandbox OSºÅÁî×¢Èë·ì϶
Fortinet FortiSandboxÐá̽ģ¿é´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓøߵÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://www.auscert.org.au/bulletins/ESB-2021.2385
5.Schneider Electric EVlink Charging StationsÓ²±àÂëÑéÖ¤ÈÆ¹ý·ì϶
Schneider Electric EVlink Charging Stations COOKIE´æÔÚÓ²±àÂë·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉδÊÚȨÒÔÖÎÀíÔ±¸ßµÍÎĽӼûϵͳ¡£
https://packetstormsecurity.com/files/163505/Schneider-Electric-EVlink-Charging-Stations-Authentication-Bypass-Code-Execution.html
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢Mint Mobile³ÆÆä²úÉúÊý¾Ýй¶£¬ÇÒ²¿Ãſͻ§±»×ªÍø

Mint Mobile³Æ½üÆÚ²úÉúÊý¾Ýй¶ÊÂÎñ£¬ÇÒ²¿Ãſͻ§±»×ªµ½ÁíÒ»¼ÒÔËÓªÉ̵ÄÍøÂçÏ¡£¹¥»÷²úÉúÔÚ6ÔÂ8ÈÕÖÁ10ÈÕÖ®¼ä£¬ÓÐδ¾ÊÚȨµÄ¹¥»÷Õß½Ó¼ûÁËMint MobileÓû§µÄÐÅÏ¢£¬Ô̺¬Í¨»°¼Í¼¡¢ÐÕÃû¡¢µØÖ·¡¢Õ˵¥½ð¶î¡¢¹ú¼Êµç»°¾ßÌåÐÅÏ¢ÐÅÏ¢¡¢µç×ÓÓʼþºÍÃÜÂëµÈ¡£ÔçÔÚ1Ô·ݣ¬USCellularÒ²¾ÀúÁËÒ»´ÎÀàËÆµÄ¹¥»÷£¬¹¥»÷ÕßÓÕʹÔËÓªÉÌÔ±¹¤ÏÂÔØÄܹ»Ô¶³Ì½Ó¼û¹«Ë¾É豸µÄÈí¼þ£¬¶øºóͨ¹ý¿Í»§¹ØÏµÖÎÀí (CRM) Èí¼þ½Ó¼ûÓû§µÄÓ×ÎÒÐÅÏ¢²¢×ªÍø¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/mint-mobile-hit-by-a-data-breach-after-numbers-ported-data-accessed/
2¡¢×êÑÐÈËÔ±Åû¶½üÆÚ¼ÙÒâ¶íÂÞ˹µ±¾ÖµÄ´¹µö¹¥»÷»î¶¯

×êÑÐÈËÔ±Åû¶Á˽üÆÚ´óÁ¿¼ÙÒâ¶íÂÞ˹µ±¾ÖµÄ´¹µö¹¥»÷»î¶¯¡£ÆäÖУ¬Kaspersky·¢ÏÖ¼Ù×°³ÉÀ´×Ô¶íÂÞ˹µ±¾ÖµÄºÏ·¨Óòwebmaster@gov.ruµÄ´¹µö»î¶¯£¬²¢°µÊ¾ÕâÀ๥»÷ͨ³£±È´ó¹æÄ£¹¥»÷¸ü¸´ÔÓ£¬»¹Ê¹ÓÃÁË×éÖ¯ÖÐÔ±¹¤µÄÕæÊµÐÕÃûºÍµç»°ºÅÂë¡£SearchInformÐÅÏ¢°²È«ÊýÃÅ·¢ÏÖÁ˼Ù×°³É˰Îñ»ú¹ØµÄ´¹µöÓʼþ¡£Í¬Ê±£¬¶íÂÞ˹¹ú¶ÈÍøÂçRSNetµÄÖÎÀí²¿ÃÅÒ²°ä²¼ÖҸ棬½¨Òé²»Òª´ò¿ªÀ´×ÔRSNetºÏ·¨Óû§»òRSNetÖÎÀíÈËÔ±µÄÓʼþ¡£
ÔÎÄÁ´½Ó£º
https://www.ehackingnews.com/2021/07/cyber-criminals-sending-phishing-mails.html
3¡¢Kaseya°²È«¸üн¨¸´REvilÔÚ¹©¸øÁ´¹¥»÷ÖÐÓõÄ0day

Kaseya°ä²¼°²È«¸üУ¬½¨¸´REvilÔÚ¹©¸øÁ´¹¥»÷ÖÐÓõÄ0day¡£4Ô£¬ºÉÀ¼·ì϶Åû¶×êÑÐËù (DIVD)Åû¶ÁËKaseyaµÄ7¸ö·ì϶¡£Ö®ºó£¬Kaseya¶ÔÆäVSA SaaS·þÎñÉϵĴó²¿ÃÅ·ì϶°ä²¼Á˲¹¶¡£¬µ«ÉÐδʵÏÖÄÚ²¿°æ±¾VSAµÄ²¹¶¡¡£¶øREvilÍÅ»ïÏÈÒ»²½ÀûÓÃÁËÕâЩ·ì϶£¬ÓÚ7ÔÂ2ÈÕ¶ÔԼĪ60¸öMSPºÍ1500¼ÒÆóÒµ¿Í»§ÌáÒéÁË´ó¹æÄ£¹¥»÷¡£Ä¿Ç°£¬Kaseya°ä²¼ÁËVSA 9.5.7a (9.5.7.2994) ¸üÐÂÒÔ½¨¸´REvilʹÓõķì϶£¬Ô̺¬CVE-2021-30116¡¢CVE-2021-30119ºÍCVE-2021-30120µÈ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/kaseya-patches-vsa-vulnerabilities-used-in-revil-ransomware-attack/
4¡¢Î¢Èí°ä²¼7Ô·ݰ²È«¸üУ¬½¨¸´9¸ö0dayÔÚÄÚµÄ117¸ö·ì϶

΢Èí°ä²¼ÁË2021Äê7Ô·ݵÄÖܶþ²¹¶¡£¬½¨¸´ÁËÔ̺¬9¸ö0dayÔÚÄÚµÄ117¸ö·ì϶¡£ÕâЩ·ì϶ÖУ¬44¸öΪԶ³Ì´úÂëÖ´ÐУ¬32¸öΪÌáȨ·ì϶£¬14¸öΪÐÅϢй¶·ì϶£¬12¸öΪ»Ø¾ø·þÎñ·ì϶£¬8¸öΪ°²È«Ö°ÄÜÈÆ¹ý·ì϶£¬7¸öΪºýŪ·ì϶¡£Õâ´Î½¨¸´µÄ9¸ö0dayÖУ¬ÓÐ4¸öÒѱ»ÔÚÔÚÒ°ÀûÓã¬Ô̺¬PrintNightmare·ì϶£¨CVE-2021-34527£©¡¢WindowsÄÚºËÌáȨ·ì϶£¨CVE-2021-33771ºÍCVE-2021-31979£©ÒÔ¼°¾ç±¾ÒýÇæÄÚ´æ°Ü»µ·ì϶£¨CVE-2021-34448£©¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2021-patch-tuesday-fixes-9-zero-days-117-flaws/
5¡¢SolarWinds½¨¸´Serv-UÖÐÒѱ»ÀûÓõÄÔ¶³Ì´úÂëÖ´Ðзì϶

SolarWindsÔÚ7ÔÂ9ÈÕ°ä²¼µÄServ-U 15.2.3 HF2Öн¨¸´ÁËÒ»¸öÒѱ»ÀûÓõÄ0day¡£MicrosoftÅû¶ÁËServ-U²úÆ·µÄÔ¶³Ì´úÂëÖ´ÐÐ0day£¨CVE-2021-35211£©£¬Ô¶³Ì¹¥»÷ÕßÀûÓô˷ì϶¿ÉÄÜÒÔÌØÊâȨÏÞÖ´ÐÐËÁÒâ´úÂ룬ÔÚÖ¸±êϵͳÉÏ×°Öò¢ÔËÐз¨Ê½¡¢²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾ÝµÈ¡£Ä¿Ç°¸Ã·ì϶ÒѾ³ö±»Ò°ÀûÓ㬵«SolarWinds°µÊ¾£¬ÈôÊÇServ-U»·¾³ÖÐδÆôÓÃSSH£¬Ôò¸Ã·ì϶²»´æÔÚ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/solarwinds-patches-critical-serv-u-vulnerability-exploited-in-the-wild/


¾©¹«Íø°²±¸11010802024551ºÅ