ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ45ÖÜ

°ä²¼¹¦·ò 2021-11-08

>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


±¾Öܹ²ÊÕ¼°²È«·ì϶60¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇCisco Policy Suite¾²Ì¬SSHÃÜÔ¿·ì϶£»Mozilla Firefox ESR  HTTP2 session objectÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶£»Apache Traffic Server stats-over-http²å¼þÄڴ渲¸Ç·ì϶£»D-Link DIR-823G HNAP1ºÅÁî×¢Èë·ì϶£»Beckhoff Automation TwinCAT OPC UA ServerĿ¼±éÀú·ì϶¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊDz¿ÃÅMacÉ豸Éý¼¶ÖÁmacOS MontereyºóÎÞ·¨Õý³£Æô¶¯£»×êÑÐÍŶӷ¢ÏÖÏÕЩÍþвËùÓдúÂëµÄ·ì϶Trojan Source£»×êÑÐÍŶӳƽ©Ê¬ÍøÂçPinkÒÑϰȾ³¬¹ý160Íǫ̀ÖйúµÄÉ豸£»Google°ä²¼Android 11Ô¸üР£¬×ܼƽ¨¸´39¸ö·ì϶£»BlackMatterÍÅ»ï°ä·¢ÆÅ×Ú·¨Âɲ¿ÃŵÄѹÁ¦½«ÖÕ³¡ÔËÓª¡£


ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾Öܰ²È«ÍþвΪÖС£


>³ÁÒª°²È«·ì϶Áбí


1. Cisco Policy Suite¾²Ì¬SSHÃÜÔ¿·ì϶


Cisco Policy Suite´æÔÚ¾²Ì¬SSHÃÜÔ¿·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬Î´ÊÚȨ½Ó¼ûϵͳ¡£


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cps-static-key-JmS92hNv



2. Mozilla Firefox ESR  HTTP2 session objectÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶


Mozilla Firefox ESR  HTTP2 session object´æÔÚ¿ªÊͺóʹÓ÷ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇó £¬ÓÕʹÓû§½âÎö £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£


https://www.mozilla.org/en-US/security/advisories/mfsa2021-49/



3. Apache Traffic Server stats-over-http²å¼þÄڴ渲¸Ç·ì϶


Apache Traffic Server stats-over-http²å¼þ´æÔÚÄڴ渲¸Ç·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£


https://lists.apache.org/thread/k01797hyncx53659wr3o72s5cvkc3164



4. D-Link DIR-823G HNAP1ºÅÁî×¢Èë·ì϶


D-Link DIR-823G HNAP1´æÔÚÊäÈëÑéÖ¤·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâSHELLºÅÁî¡£


https://www.dlink.com/en/security-bulletin/



5. Beckhoff Automation TwinCAT OPC UA ServerĿ¼±éÀú·ì϶


Beckhoff Automation TwinCAT OPC UA Server´æÔÚĿ¼±éÀú·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄ´´½¨»òɾ³ýϵͳÉϵÄÈκÎÎļþ¡£


https://download.beckhoff.com/download/document/product-security/Advisories/advisory-2021-003.pdf



>³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢²¿ÃÅMacÉ豸Éý¼¶ÖÁmacOS MontereyºóÎÞ·¨Õý³£Æô¶¯


½üÆÚ £¬Ô½À´Ô½¶àµÄMacºÍMacbookÓû§»ã±¨ £¬µ±Æä¸üе½ÉÏÖܰ䲼µÄ×îаæmacOS Montereyºó £¬É豸ÎÞ·¨Õý³£Æô¶¯¡£´ËÎÊÌâËÆºõ½öÓ°ÏìÁË2019Äê֮ǰµÄMacÉ豸 £¬²»»áÓ°ÏìʹÓÃM1оƬµÄпîMac¡£´Ë±í £¬¹ÌÈ»²¿ÃÅÓû§³ÆËûÃǵÄϵͳÒѾ­±äש £¬µ«´óÎÞÊýÓû§Äܹ»Í¨¹ýApple Configurator¹¤¾ß¸´Ô­É豸¡£ÆäËûÓû§ÔòÕÒµ½ÁËÁíÒ»ÖÖ²½Öè £¬¾ÍÊÇͨ¹ýÆô¶¯DFUÀ´¸´Ô­É豸¡£    


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/apple/macos-monterey-update-causes-some-macs-to-become-unbootable/


2¡¢×êÑÐÍŶӷ¢ÏÖÏÕЩÍþвËùÓдúÂëµÄ·ì϶Trojan Source


½£ÇÅ´óѧµÄ×êÑÐÈËÔ±ÔÚ11ÔÂ1ÈÕ¹«¿ªÁËÒ»¸öÓ°Ïì´óÎÞÊýÍÆËã»ú´úÂë±àÒëÆ÷ºÍºÜ¶àÈí¼þ¿ª·¢»·¾³µÄ·ì϶Trojan Source¡£¸Ã·ì϶´æÔÚÓÚUnicodeÖÐ £¬ÓÐÁ½ÖÖÀûÓò½Ö裺ÆäÒ»ÊÇʹÓÃUnicodeµÄBidiËã·¨£¨CVE-2021-42574£© £¬¶Ô×Ö·û½øÐÐÊÓ¾õÉϵijÁÐÂÅÅÐò £¬Ê¹Æä³öÏÖÓë±àÒëÆ÷ºÍÚ¹ÊÍÆ÷Ëù·ÖÆçµÄÂß¼­°¤´Î£»ÁíÒ»ÖÖÊÇͬÐÎÎÄ×Ö¹¥»÷(CVE-2021-42694) £¬¼´ÀûÓÃÔÚÊÓ¾õÉÏ¿´ÆðÀ´ÀàËÆµÄ·ÖÆç×Ö·û¡£¸Ã·ì϶ºÏÓÃÓÚC¡¢C++¡¢C#¡¢JavaScript¡¢JavaµÈ¿í·ºÊ¹ÓõÄ˵»° £¬¿ÉÓÃÓÚ¹©¸øÁ´¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.trojansource.codes/


3¡¢×êÑÐÍŶӳƽ©Ê¬ÍøÂçPinkÒÑϰȾ³¬¹ý160Íǫ̀ÖйúµÄÉ豸


×êÑÐÍŶÓÔÚ10ÔÂ29ÈÕÅû¶ÁËÔÚ´ÓǰÁùÄê·¢ÏÖµÄ×î´ó½©Ê¬ÍøÂçµÄϸ½Ú¡£ÓÉÓÚÆä´óÁ¿µÄº¯ÊýÃû³ÆÒÔpinkΪÊ× £¬ËùÒÔÈ¡ÃûPinkbot¡£¸Ã½©Ê¬ÍøÂçÒÑϰȾÁ˳¬¹ý160Íǫ̀É豸 £¬ÆäÖÐ96%λÓÚÖйú¡£ËüÖØÒªÕë¶Ô»ùÓÚMIPSµÄ¹âÏË·ÓÉÆ÷ £¬ÀûÓõÚÈý·½·þÎñµÄ×éºÏ £¬ÀýÈçGitHub¡¢P2PÍøÂçºÍC2·þÎñÆ÷ £¬»¹¶Ô²¿ÃÅÓòÃûµÄ½âÎö²éÎʲÉÈ¡ÁËDNS-Over-HTTPSµÄ·½Ê½¡£×êÑÐÈËÔ±³Æ £¬Æù½ñΪֹ £¬PinkBotÌáÒéÁ˽ü°Ù´ÎDDoS¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/11/researchers-uncover-pink-botnet-malware.html


4¡¢Google°ä²¼Android 11Ô¸üР£¬×ܼƽ¨¸´39¸ö·ì϶


GoogleÔÚ±¾ÖÜÒ»°ä²¼ÁËAndroid 11Ô·ݵĸüР£¬×ܼƽ¨¸´39¸ö·ì϶¡£Õâ´Î¸üн¨¸´ÁËÒ»¸öÒѱ»ÔÚÒ°ÀûÓõÄ0day £¬ÊÇÓÉ¿ªÊͺóʹÓõ¼Öµı¾µØÌáȨ·ì϶CVE-2021-1048¡£´Ë±í £¬»¹½¨¸´Á˶à¸öÑϳÁµÄ·ì϶ £¬Ô̺¬Ô¶³Ì´úÂëÖ´Ðзì϶CVE-2021-0918ºÍCVE-2021-0930 £¬Ó°Ïì¸ßͨ×é¼þµÄCVE-2021-1924ºÍCVE-2021-1975 £¬ÒÔ¼°Android TVÔ¶³Ì·þÎñÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶CVE-2021-0889µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/android-patches-exploited-kernel-bug/175931/


5¡¢BlackMatterÍÅ»ï°ä·¢ÆÅ×Ú·¨Âɲ¿ÃŵÄѹÁ¦½«ÖÕ³¡ÔËÓª


11ÔÂ1ÈÕ £¬ÀÕË÷ÔËÓªÍÅ»ïBlackMatterÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾Éϰ䲼ÐÂÎÅ £¬³ÆÆÅ×Ú·¨Âɲ¿ÃŵÄѹÁ¦ËûÃǽ«ÔÚ48Ó×ʱÄڹعØÕû¸ö»ù´¡ÉèÊ©¡£×êÑÐÍŶӰµÊ¾ £¬Õâ¿ÉÄÜÓë×î½üµÄÒ»´Î¹ú¼Ê·¨ÂÉÐж¯ÓйØ £¬Õâ´ÎÐж¯¹²¿ÛÁôÁË12¸öÉæ¼°1800ÆðÀÕË÷¹¥»÷»î¶¯µÄÏÓÒÉÈË¡£È»¶ø £¬¼´±ãBlackMatter´Ë¿ÌÖÕ³¡ÆäÔËÓª £¬ÔÚ½«À´Ò²½«»áÒÔеÄÃû³Æ»Ø¹é £¬ÕýÈçBlackMatter×ÔÉí¾ÍÊÇDarkSideÔÚ¹¥»÷Colonial PipelineºóÆÅ×ÚѹÁ¦¸ÄÃû¶øÀ´µÄ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/124135/cyber-crime/blackmatter-ransomware-shutting-down-operations.html