ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ3ÖÜ

°ä²¼¹¦·ò 2021-01-18

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2021Äê01ÔÂ11ÈÕÖÁ01ÔÂ17ÈÕ¹²ÊÕ¼°²È«·ì϶70¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Word CVE-2021-1715´úÂëÖ´Ðзì϶ £»Siemens JT2Go JT½âÎöÀàÐÍ»ìºÏ´úÂëÖ´Ðзì϶ £»Cisco Connected Mobile Experiences CVE-2021-1144ȨÏÞÌáÉý·ì϶ £»Adobe Photoshop¶Ñ»º³åÇøÒç³ö´úÂëÖ´Ðзì϶ £»Xiaomi AX1800µÇ¼ÑéÖ¤ÈÆ¹ý·ì϶¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÐÂÎ÷À¼´¢ÐîÒøÐÐÔâµ½¹¥»÷ £¬Ãô¸ÐÐÅÏ¢»òÒÑй¶ £»½áºÏ¹ú»·¾³¹æ»®ÊðµÄGit´æ´¢¿âй¶³¬¹ý10Íò¸öµÄÔ±¹¤ÐÅÏ¢ £»Socialarksй¶400GBÊý¾Ý £¬Ó°ÏìÈ«Çò2ÒÚ¶àÓû§ £»ÐÂSolarLeaksÍøÕ¾ÏúÊÛSolarWinds¹©¸øÁ´¹¥»÷Öеĺ¹ÇàÊý¾Ý £»SkypeÔÚÈ«ÇòÁìÓòÄÚ·þÎñÖжÏ £¬Ô­ÒòÉв»Ã÷È·¡£


ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾Öܰ²È«ÍþвΪÖС£


> ³ÁÒª°²È«·ì϶Áбí


1.Microsoft Word CVE-2021-1715´úÂëÖ´Ðзì϶


Microsoft Word´æÔÚ°²È«·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó £¬ÓÕʹÓû§½âÎö £¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-1715


2.Siemens JT2Go JT½âÎöÀàÐÍ»ìºÏ´úÂëÖ´Ðзì϶


Siemens JT2Go JTÎļþ½âÎö´æÔÚÀàÐÍ»ìºÏ·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó £¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://us-cert.cisa.gov/ics/advisories/icsa-21-012-03


3.Cisco Connected Mobile Experiences CVE-2021-1144ȨÏÞÌáÉý·ì϶


Cisco Connected Mobile Experiences¸ü¸ÄÃÜÂëÊÚȨ´æÔÚ°²È«·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬¿É¸ü¸ÄËÁÒâÓû§ÃÜÂë £¬ÌáÉýÌØÈ¨¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cmxpe-75Asy9k


4.Adobe Photoshop¶Ñ»º³åÇøÒç³ö´úÂëÖ´Ðзì϶


Adobe Photoshop´¦ÖÃÎļþ´æÔÚ¶Ñ»º³åÇøÒç¶Âí½Å £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó £¬ÓÕʹÓû§½âÎö £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ £»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://helpx.adobe.com/security/products/photoshop/apsb21-01.html


5.Xiaomi AX1800µÇ¼ÑéÖ¤ÈÆ¹ý·ì϶


Xiaomi AX1800´æÔÚ·ÓÉÆ÷³ÁÆôºó¹¦·ò·ÖÆç²½µÄÎÊÌâ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬¿ÉÈÆ¹ýµÇ¼Ñé֤δÊÚȨ½Ó¼û¡£

https://privacy.mi.com/trust#/security/vulnerability-management/vulnerability-announcement/detail?id=22&locale=en


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢ÐÂÎ÷À¼´¢ÐîÒøÐÐÔâµ½¹¥»÷ £¬Ãô¸ÐÐÅÏ¢»òÒÑй¶


1.jpg


λÓÚ»ÝÁé¶ÙµÄÐÂÎ÷À¼´¢ÐîÒøÐÐÓÚÖÜÈÕÐû³ÆÆäÔâµ½¹¥»÷¡£¾ÝϤ £¬¸ÃÒøÐÐÓÃÀ´¹²ÏíºÍ´æ´¢Ãô¸ÐÐÅÏ¢µÄµÚÈý·½Îļþ¹²Ïí·þÎñµÄÊý¾ÝϵͳÔâµ½·ÛËé £¬ºÚ¿Í¿ÉÄÜÒѾ­½Ó¼ûÁËÆäÖеÄóÒ׺ÍÓ×ÎÒÃô¸ÐÐÅÏ¢¡£Ä¿Ç° £¬¸ÃϵͳÒѱ»ÍÑ»ú± £»¤ £¬Ö±µ½ÒøÐÐʵÏÖÆä³õ´ëÊ©²éΪֹ²Å»á¸´Ô­¡£¸ÃÒøÐаµÊ¾ÆäÔÚÈ·¶¨Ð¹Â¶ÐÅÏ¢µÄÁìÓò £¬²¢ÇһؾøÐ¹Â©ÓйØÕâ´Î¹¥»÷¸ü¶àµÄϸ½Ú¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/new-zealand-central-bank-hit-cyber-attack


2¡¢½áºÏ¹ú»·¾³¹æ»®ÊðµÄGit´æ´¢¿âй¶³¬¹ý10Íò¸öµÄÔ±¹¤ÐÅÏ¢


2.png


¸Ã¹«¿ªµÄgitĿ¼ÖÐÔ̺¬ÁË´óÁ¿Ãô¸ÐÎļþ £¬ÈçÓë»·¾³ÊðºÍ½áºÏ¹ú¹ú¼ÊÀ͹¤×éÖ¯ÆäËûÔÚÏßϵͳÓйصĴ¿Îı¾Êý¾Ý¿âÍ´´¦ £¬ÖÎÀíÔ±µÄÊý¾Ý¿âÍ´´¦ºÍ»·¾³ÊðµÄÔ´´úÂë¿âµÈ¡£´Ë±í £¬Õâ´ÎÊÂÎñ»¹Ð¹Â¶ÁËÔ±¹¤µÄPII £¬ÈçÔ±¹¤¹Û¹âº¹Çà¡¢È˶¡Í³¼ÆÊý¾Ý£¨¹ú¼®¡¢ÐÔ±ðºÍн¼¶£©¡¢ÏîÄ¿×ʽðÆðÔ´¼Í¼¡¢Ô±¹¤¼Í¼ºÍ¾ÍÒµÆÀ¹À»ã±¨µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/united-nations-data-breach-exposed-over-100k-unep-staff-records/


3¡¢Socialarksй¶400GBÊý¾Ý £¬Ó°ÏìÈ«Çò2ÒÚ¶àÓû§


3.png


°²È«¹«Ë¾Safety Detectives·¢ÏÖ £¬Öйú²Ý´´¹«Ë¾Socialarks£¨±¿ÄñÉç½»£©Ð¹Â¶ÁË400GBÊý¾Ý¡£Õâ´ÎÊý¾Ýй¶ÊÇÓÉÓÚElasticSearchÊý¾Ý¿âÉèÖÃÃýÎó £¬Ð¹Â¶ÁË×ܼÆ408GB £¬³¬¹ý3.18ÒÚÌõÓû§¼Í¼ £¬Éæ¼°µ½11651162¸öInstagramÓû§¡¢66117839¸öÁìÓ¢Óû§ºÍ81551567¸öFacebookÓû§¡£ÖµÍ×ÌùÐĵÄÊÇ £¬SocialarksÔÚ2020Äê8ÔÂÒ²²úÉúÁËÀàËÆµÄÊÂÎñ £¬Ð¹Â¶ÁË1.5ÒÚ¸öÓû§µÄÓ×ÎÒÊý¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.safetydetectives.com/blog/socialarks-leak-report/


4¡¢ÐÂSolarLeaksÍøÕ¾ÏúÊÛSolarWinds¹©¸øÁ´¹¥»÷Öеĺ¹ÇàÊý¾Ý


4.png


ÐÂSolarLeaksÍøÕ¾ÏúÊÛSolarWinds¹©¸øÁ´¹¥»÷ÖÐMicrosoft¡¢Cisco¡¢FireEyeºÍSolarWindsµÈ¹«Ë¾µÄʧÇÔÊý¾Ý¡£¸ÃÍøÕ¾ÒÔ60ÍòÃÀÔªµÄ¼ÛÖµÏúÊÛMicrosoftÔ´´úÂëºÍ´æ´¢¿â £¬ÒÔ5ÍòÃÀÔªµÄ¼ÛÖµÏúÊÛFireEyeµÄÔ´´úÂëºÍºì¶Ó¹¤¾ß £¬ÒÔ25ÍòÃÀÔªµÄ¼ÛÖµÏúÊÛSolarWindsÔ´´úÂëºÍ¿Í»§ÃÅ»§ £¬²¢ÒÔ100ÍòÃÀÔªµÄ¼ÛÖµÏúÊÛÈ«Êýй¶Êý¾Ý¡£solarleaks.netÓòÊÇͨ¹ý¶íÂÞ˹Fancy BearºÍCozy BearʹÓõÄÒÑ֪ע²áÉÌNJALLA½øÐÐ×¢²á¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/solarleaks-site-claims-to-sell-data-stolen-in-solarwinds-attacks/


5¡¢SkypeÔÚÈ«ÇòÁìÓòÄÚ·þÎñÖжÏ £¬Ô­ÒòÉв»Ã÷È·


5.png


1ÔÂ13ÈÕÉÏÎç £¬SkypeÔÚÈ«ÇòÁìÓòÄÚ·þÎñÖжÏ £¬Ä¿Ç°¸ÃÎÊÌâÒѱ»½â¾ö¡£Æ¾¾ÝÔÚÏßÐÂÎÅÆ½Ì¨DownDetectorͳ¼Æ £¬ÖжÏÖØÒª¼¯ÖÐÔÚÃÀ¹ú¡¢Å·ÖÞ¡¢ÑÇÖÞºÍÊÀ½çÆäËûµØÓò¡£Óû§ÔÚ½Ó¼ûSkypeÍøÕ¾Ê± £¬»áÏÔʾÎÒÃÇÎÞ·¨ÊµÏÖÄúµÄÒªÇóµÄÌáÐÑ¡£MicrosoftÔÚSkype״̬ҳÉϰµÊ¾·¢ÏÖÁ˸ÃÎÊÌâ £¬ÆäÓ°ÏìÁËSkypeµÇ¼¡¢ºô½Ó×¢ÐÂÎÅ¡¢ËÑË÷¡¢Òƶ¯¹²Ïí¡¢Ö§¸¶ÏµÍ³¡¢SMSºÍÆäËû·þÎñ¡£ÎÊÌâÏÖÒѸ´Ô­ £¬Skype¿ÉÔÙ´ÎÁª»ú¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/skype-is-down-worldwide-microsoft-working-on-issues/