ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ39ÖÜ

°ä²¼¹¦·ò 2021-09-27

>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2021Äê09ÔÂ20ÈÕÖÁ09ÔÂ26ÈÕ¹²ÊÕ¼°²È«·ì϶42¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇGoogle Chrome Offline useÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶£»Edgecore ECS2020ºÅÁî×¢Èë·ì϶£»Hikvision Web ServerºÅÁî×¢Èë·ì϶£»Huawei FusionCompute CVE-2021-37106ºÅÁî×¢Èë·ì϶£»VMware vCenter ServerËÁÒâÎļþÉÏ´«·ì϶¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇNEW CooperativeÔâBlack Matter¹¥»÷±»ÀÕË÷590ÍòÃÀÔª£»×êÑÐÈËÔ±·¢ÏÖ³¬¹ý1.06ÒÚÌ©¹úÓο͵ÄÓ×ÎÒÐÅϢй¶£»VMware½¨¸´vCenter ServerÖÐÑϳÁµÄÎļþÉÏ´«·ì϶£»Apple°ä²¼°²È«¸üУ¬½¨¸´¶à¿î²úÆ·ÖеÄRCEµÈ·ì϶£»¶íÂÞ˹APT×éÖ¯TurlaÀûÓÃкóÃŹ¥»÷ÃÀ¡¢µÂºÍ°¢¸»º¹¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£


>³ÁÒª°²È«·ì϶Áбí


1.Google Chrome Offline useÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶


Google Chrome Offline use´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒ³ÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿É¶ÔÀûÓ÷¨Ê½½øÐлؾø·þÎñ¹¥»÷»òÕßÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£


https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop_21.html



2.Edgecore ECS2020ºÅÁî×¢Èë·ì϶


Edgecore ECS2020 command1 HTTPÍ·´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿É×¢ÈëËÁÒâºÅÁî²¢ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐС£


https://twitter.com/r00treaver/status/1232407881464635401


3.Hikvision Web ServerºÅÁî×¢Èë·ì϶


Hikvision Web Server´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿É×¢ÈëËÁÒâºÅÁî²¢ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐС£


https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-notification-command-injection-vulnerability-in-some-hikvision-products/



4.Huawei FusionCompute CVE-2021-37106ºÅÁî×¢Èë·ì϶


Huawei FusionCompute²úÆ·CMA·þÎñ´¦ÖÃÖ¤ÊéÎļþ´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿É×¢ÈëËÁÒâºÅÁî²¢ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐС£


https://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20210922-01-commandinjection-cn


5.VMware vCenter ServerËÁÒâÎļþÉÏ´«·ì϶


VMware vCenter Server Analytics service´æÔÚËÁÒâÎļþÉÏ´«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£


https://www.vmware.com/security/advisories/VMSA-2021-0020.html



 >³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢NEW CooperativeÔâBlack Matter¹¥»÷±»ÀÕË÷590ÍòÃÀÔª


NEW CooperativeÔâBlack Matter¹¥»÷±»ÀÕË÷590ÍòÃÀÔª.png


ÃÀ¹úÅ©·òºÏ×÷ÉçNEW CooperativeÔÚÉÏÖÜÄ©Ôâµ½Black MatterµÄÀÕË÷¹¥»÷¡£ÕâÊÇÒ»¼ÒËÇÁϺ͹ÈÎïºÏ×÷É磬Õâ´Î¹¥»÷»î¶¯½«µ¼ÖÂÁ¸Ê³¡¢ÖíÈâºÍ¼¦ÈâµÈʳƷ¹©¸øÖжÏ¡£¹¥»÷ÕßÒªÇó¸Ã¹«Ë¾Ö§¸¶590ÍòÃÀÔªÊê½ð£¬²¢°µÊ¾5ÈÕºóÊê½ð½ð¶î½«Ôö³¤µ½1180ÍòÃÀÔª¡£BlackMatterÐû³ÆÇÔÈ¡ÁË1000 GBµÄÊý¾Ý£¬Ô̺¬soilmap.comÏîÖ÷ÕÅÔ´´úÂë¡¢Ñз¢Á˾֡¢Ô±¹¤ÐÅÏ¢¡¢²ÆÕþÎļþÒÔ¼°KeePassÃÜÂëÖÎÀíÆ÷µÄµ¼³öÊý¾Ý¿âµÈ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/122410/cyber-crime/black-matter-new-cooperative.html



2¡¢×êÑÐÈËÔ±·¢ÏÖ³¬¹ý1.06ÒÚÌ©¹úÓο͵ÄÓ×ÎÒÐÅϢй¶


×êÑÐÈËÔ±·¢ÏÖ³¬¹ý1.06ÒÚÌ©¹úÓο͵ÄÓ×ÎÒÐÅϢй¶.png


Comparitech×êÑÐÈËÔ±Bob DiachenkoÓÚ2021Äê8ÔÂ22ÈÕ·¢ÏÖÁËδÊܱ£»¤µÄElasticsearchÊý¾Ý¿â¡£¸ÃÊý¾Ý¿â×ܹ²ÓÐ200GBÊý¾Ý£¬Ô̺¬Á˳¬¹ý1.06ÒÚÌ©¹úÓο͵ÄÓ×ÎÒÐÅÏ¢¡£Diachenko´§Ä¦£¬¸ÃÊÂÎñÉæ¼°µ½´ÓǰʮÄêÖÐǰÍùÌ©¹úÓÎÀÀµÄµÄËùÓбí¹úÈË¡£×êÑÐÈËԱĿǰÎÞ·¨È·¶¨ÕâЩÊý¾Ýй¶µÄ¹¦·ò£¬µ«ÊÇÔÚ֪̩ͨ¹úµ±¾ÖºóµÄ24Ó×ʱÄھͱ»±£»¤ÁËÆðÀ´¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/data-of-106-million-visitors-to/



3¡¢VMware½¨¸´vCenter ServerÖÐÑϳÁµÄÎļþÉÏ´«·ì϶


VMware½¨¸´vCenter ServerÖÐÑϳÁµÄÎļþÉÏ´«·ì϶.png


VMwareÓÚ±¾Öܶþ°ä²¼°²È«¸üУ¬½¨¸´vCenter ServerºÍCloud FoundationÖеÄ19¸ö·ì϶¡£ÆäÖÐ×îΪÑϳÁµÄÊÇvCenter ServerÖеÄËÁÒâÎļþÉÏ´«·ì϶(CVE-2021-22005)£¬¹¥»÷ÕßÄܹ»Í¨¹ýÍøÂç½Ó¼û¶Ë¿Ú443µÄÉÏ´«ÌØÔìÎļþÀ´Ö´ÐдúÂë¡£´Ë±í£¬»¹½¨¸´Á˱¾µØÌáȨ·ì϶£¨CVE-2021-21991£©¡¢·´Ïò´úÀíÈÆ¹ý·ì϶£¨CVE-2021-22006£©¡¢API¶Ëµã·ì϶£¨CVE-2021-22011£©ºÍAPIÐÅϢй¶·ì϶£¨CVE-2021-22012£©µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/09/vmware-warns-of-critical-file-upload.html



4¡¢Apple°ä²¼°²È«¸üУ¬½¨¸´¶à¿î²úÆ·ÖеÄRCEµÈ·ì϶



Apple°ä²¼°²È«¸üУ¬½¨¸´¶à¿î²úÆ·ÖеÄRCEµÈ·ì϶.png


AppleÓÚ9ÔÂ20ÈÕ°ä²¼°²È«¸üУ¬½¨¸´ÁËSafari 15¡¢Xcode 13¡¢tvOS 15¡¢watchOS 8¡¢iOS 15¡¢iPadOS 15ºÍiTunes 12.12ÖеĶà¸ö·ì϶¡£ÆäÖÐÔ̺¬Safari 15ÖеÄÄÚ´æ°Ü»µµ¼ÖµÄËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-30846ºÍCVE-2021-30851µÈ£©¡¢tvOS 15ÖеÄDoS·ì϶£¨CVE-2013-0340£©ºÍɳºÐÈÆ¹ý·ì϶£¨CVE-2021-30854£©£¬ÒÔ¼°iOS 15ºÍiPadOS 15ÖеĴúÂëÖ´Ðзì϶£¨CVE-2021-30837ºÍCVE-2021-30811£©µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/09/21/apple-releases-security-updates-multiple-products



5¡¢¶íÂÞ˹APT×éÖ¯TurlaÀûÓÃкóÃŹ¥»÷ÃÀ¡¢µÂºÍ°¢¸»º¹


¶íÂÞ˹APT×éÖ¯TurlaÀûÓÃкóÃŹ¥»÷ÃÀ¡¢µÂºÍ°¢¸»º¹.png


Cisco TalosÔÚ9ÔÂ21ÈÕÅû¶Á˶íÂÞ˹APT×éÖ¯TurlaÀûÓÃкóÃÅTinyTurla¹¥»÷ÃÀ¡¢µÂºÍ°¢¸»º¹µÄ»î¶¯¡£Turla×Ô2004ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬¹¥»÷ÁËÖж«¡¢ÑÇÖÞ¡¢Å·ÖÞ¡¢±±ÃÀºÍÄÏÃÀµÈµØÓòµÄÖ¸±ê¡£×êÑÐÈËԱͨ¹ýÒ£²â·¢ÏÖÁ˺óÃÅ£¬µ«Éв»Ã÷ÏÔÆäÈ·ÇеÄ×°Ö÷½Ê½£¬½ö֪·¹¥»÷ÕßʹÓÃ.batÎļþ´«²¼ºóÃÅ¡£¸ÃºóÃżÙ×°³ÉMicrosoft DLL£¬²¢¶¨ÃûΪw64time.dll£¬¿ÉÉÏ´«ºÍÖ´ÐÐÎļþ¡¢´´½¨×ÓÁ÷³ÌºÍÇÔÈ¡Êý¾ÝµÈ¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2021/09/tinyturla.html