ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ37ÖÜ
°ä²¼¹¦·ò 2021-09-14>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2021Äê09ÔÂ06ÈÕÖÁ09ÔÂ12ÈÕ¹²ÊÕ¼°²È«·ì϶58¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇApple iOS Wi-Fi»º³åÇøÒç³ö´úÂëÖ´Ðзì϶£»Delta Electronics DOPSoftÏîÄ¿ÎļþÔ½½çд·ì϶£»QNAP NAS CVE-2021-34343Õ»Òç³ö´úÂëÖ´Ðзì϶£»Google Android FrameworkËÁÒâ´úÂëÖ´Ðзì϶£»Cisco IOS XR Software CVE-2021-34719ÌØÈ¨ÌáÉý·ì϶¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÐÂÎ÷À¼»¥ÁªÍøÔËÓªÉÌVocusÔâµ½´ó¹æÄ£DDoS¹¥»÷£»Google TensorFlowΪ½¨¸´RCE·ì϶¶ø²»ÔÙÖ§³ÖYAML£»FortiGuard°ä²¼2021ÄêH1È«ÇòÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨£»Î¢Èí°ä²¼MSHTMLÖÐRCE·ì϶£¨CVE-2021-40444£©µÄ¹«¸æ£»×êÑÐÈËÔ±·¢ÏÖREvilÍÅ»ïµÄÊý¾ÝÐ¹Â¶ÍøÕ¾ÔÙ¶ÈÉÏÏß¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
>³ÁÒª°²È«·ì϶Áбí
1.Apple iOS Wi-Fi»º³åÇøÒç³ö´úÂëÖ´Ðзì϶
Apple iOS Wi-Fi´æÔÚ»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://support.apple.com/en-us/HT212317
2.Delta Electronics DOPSoftÏîÄ¿ÎļþÔ½½çд·ì϶
Delta Electronics DOPSoft´¦ÖÃÏîÄ¿Îļþ´æÔÚ»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿Éʹϵͳ±ÀÀ£»òÕßÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://us-cert.cisa.gov/ics/advisories/icsa-21-252-02
3.QNAP NAS CVE-2021-34343Õ»Òç³ö´úÂëÖ´Ðзì϶
QNAP NAS´æÔÚÕ»Òç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿Éʹϵͳ±ÀÀ£»òÕßÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://www.qnap.com/en/security-advisory/qsa-21-33
4.Google Android FrameworkËÁÒâ´úÂëÖ´Ðзì϶
Google Android Framework´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
https://source.android.com/security/bulletin/2021-09-01
5.Cisco IOS XR Software CVE-2021-34719ÌØÈ¨ÌáÉý·ì϶
Cisco IOS XR SoftwareºÅÁîÐвÎÊýʵÏÖ´æÔÚ°²È«·ì϶£¬ÔÊÐí±¾µØ¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÌáÉýȨÏÞ£¬»ñÈ¡ROOTȨÏÞ¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-privescal-dZYMrKf
>³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢ÐÂÎ÷À¼»¥ÁªÍøÔËÓªÉÌVocusÔâµ½´ó¹æÄ£DDoS¹¥»÷

ÐÂÎ÷À¼µÚÈý´ó»¥ÁªÍøÔËÓªÉÌVocus ISP³ÆÆäÔÚ9ÔÂ3ÈÕÔâµ½´ó¹æÄ£DDoS¹¥»÷£¬µ¼Ö·þÎñÖжÏÁËÔ¼30·ÖÖÓ¡£VocusÔÚ°Ä´óÀûÑǺÍÐÂÎ÷À¼ÌṩÁãÊÛ¡¢Åú·¢ºÍÆóÒµµçÕÛ·þÎñ¡£¸Ã¹«Ë¾³Æ£¬ÓÉÓÚĿǰȫ¹ú´ó²¿ÃŵØÓò¶¼ÔÚÔ¶³Ì°ì¹«£¬Òò¶øÕâ´Î¹¥»÷¶Ô¿Í»§²úÉúÁ˳Á´óÓ°Ïì¡£Ö®ºó£¬¸Ã¹«Ë¾Ñ¸¿ì¸´ÔÁËÔËÓª£¬²¢¶Ô¸ø¿Í»§´øÀ´µÄ²»±ã°µÊ¾Ç¸Òâ¡£
ÔÎÄÁ´½Ó£º
https://www.reuters.com/technology/widespread-internet-outages-hits-users-across-new-zealand-2021-09-03/
2¡¢Google TensorFlowΪ½¨¸´RCE·ì϶¶ø²»ÔÙÖ§³ÖYAML

Google¿ª·¢µÄ»ùÓÚPythonµÄ»úе½ø½¨ºÍÈËΪÖÇÄÜÏîÄ¿TensorFlowÒѾÉÕ»ÙÁ˶ÔYAMLµÄÖ§³Ö¡£TensorFlow´úÂëÖеÄyaml.unsafe_load()º¯Êý´æÔÚÒ»¸ö·ì϶£¬×·×ÙΪCVE-2021-37678£¬ÆÀ·ÖΪ9.3¡£µ±ÀûÓ÷´ÐòÁл¯YAMLÌåʽµÄKerasÄ£ÐÍʱ£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐÐËÁÒâ´úÂ롣Ϊ½¨¸´´Ë·ì϶£¬TensorFlow¾ö¶¨ÆëÈ«ÉÕ»ÙYAMLµÄÖ§³Ö£¬×ª¶øÊ¹ÓÃJSON·´ÐòÁл¯¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/googles-tensorflow-drops-yaml-support-due-to-code-execution-flaw/
3¡¢FortiGuard°ä²¼2021ÄêH1È«ÇòÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨

FortiGuardÓÚ8Ô·ݰ䲼ÁË2021ÄêH1È«ÇòÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬2021Äê6Ô¾ùÔÈÿÖÜÀÕË÷Èí¼þ»î¶¯±ÈÒ»ÄêǰͬÆÚÓâÔ½10.7±¶¡£ÆäÖУ¬µçÐÅÐÐÒµÊǹ¥»÷ÕßµÄÊ×ÒªµÄÖ¸±ê£¬Æä´ÎÊǵ±¾Ö¡¢Íйܰ²È«·þÎñÌṩÉÌ¡¢Æû³µºÍÔì×÷ÐÐÒµ¡£½©Ê¬ÍøÂçÒ²ÓÐËùÔö³¤£¬½ñÄêËêÊ×ÔÚ35%µÄ×éÖ¯Öмì²âµ½Á˽©Ê¬ÍøÂç»î¶¯£¬¶øÕâÒ»±ÈÀýÔÚ6¸öÔºóÔö³¤Îª51%¡£´Ë±í£¬¹¥»÷Õ߸üÇàíùÓÚ¼ì²âÈÆ¹ý¼¼ÊõºÍÌáȨ¼¼Êõ¡£
ÔÎÄÁ´½Ó£º
https://www.fortinet.com/content/dam/fortinet/assets/threat-reports/report-threat-landscape-2021.pdf
4¡¢Î¢Èí°ä²¼MSHTMLÖÐRCE·ì϶£¨CVE-2021-40444£©µÄ¹«¸æ

΢ÈíÍŶÓÔÚ9ÔÂ7ÈÕ°ä²¼ÁËÕë¶ÔWindowsÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-40444£©µÄ»º½â´ëÊ©¡£¸Ã·ì϶´æÔÚÓÚMicrosoft OfficeÎĵµÊ¹ÓõÄä¯ÀÀÆ÷äÖȾÒýÇæMSHTMLÖУ¬ÒÑÔÚÕë¶ÔWindows 10ÉϵÄOffice 365ºÍOffice 2019µÄ¹¥»÷»î¶¯Öб»ÀûÓá£Ä¿Ç°ÉÐÎÞ¿ÉÓõݲȫ¸üУ¬Microsoft½¨Òé½ûÓÃInternet ExplorerÖÐËùÓеÄActiveX¿Ø¼þ×÷Ϊ»º½â´ëÊ©¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-shares-temp-fix-for-ongoing-office-365-zero-day-attacks/
5¡¢×êÑÐÈËÔ±·¢ÏÖREvilÍÅ»ïµÄÊý¾ÝÐ¹Â¶ÍøÕ¾ÔÙ¶ÈÉÏÏß

×êÑÐÈËÔ±·¢ÏÖREvilÍÅ»ïµÄÊý¾ÝÐ¹Â¶ÍøÕ¾£¨Ò²³ÆÎª Happy Blog£©ÔÚ9ÔÂ7ÈÕ³ÁÐÂÉÏÏß¡£7ÔÂ2ÈÕ£¬REvilÀûÓÃKaseya VSAÖеķì϶¹¥»÷ÁËԼĪ60¼ÒMSP¼°Æä1500¶à¸ö¿Í»§£¬²¢ÀÕË÷7000ÍòÃÀÔª¡£Ö®ºó£¬¸Ã×éÖ¯ÒýÆðÁË·¨Âɲ¿ÃÅÈ·°ÑÎÈ£¬²¢ÔÚ7ÔÂ13¹Ø¹ØÁËËùÓеÄTor·þÎñÆ÷ºÍ»ù´¡ÉèÊ©¡£Éв»Ã÷ÏÔÕâ´ÎÖ§¸¶ºÍÊý¾ÝÐ¹Â¶ÍøÕ¾µÄ³ÁÐÂÉÏÏߣ¬ÊÇ·ñ´ú±íןÃÍÅ»ïÒªÆðÍ·¸´³ö¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/revil-ransomwares-servers-mysteriously-come-back-online/


¾©¹«Íø°²±¸11010802024551ºÅ