ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ23ÖÜ

°ä²¼¹¦·ò 2021-06-07

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2021Äê05ÔÂ31ÈÕÖÁ06ÔÂ06ÈÕ¹²ÊÕ¼°²È«·ì϶59¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇMozilla Firefox CVE-2021-29966»º³åÇøÒç¶Âí½Å£»Cisco Common Services Platform Collector OSºÅÁîÖ´Ðзì϶£»Synology Photo Station SQL×¢Èë·ì϶£»F5 BIG-IQ Centralized ManagementºÅÁî×¢Èë·ì϶£»OpenText Brava Desktop PDFÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇSophos·¢ÏÖÕë¶ÔExchangeµÄÐÂÀÕË÷Èí¼þEpsilon Red£»È«Çò×î´óÈâÀà³ö²úÉÌJBSÔâµ½¹¥»÷ £¬¶à¸ö·Ö¹«Ë¾Í£²ú£»×êÑÐÍŶӷ¢ÏÖкóÃÅFacefish £¬¿ÉÇÔÈ¡LinuxϵͳÐÅÏ¢£»ÃÀ¹úÒѲé·âNOBELIUMÔÚÕë¶ÔUSAIDµÄ¹¥»÷ÖÐʹÓõÄÓòÃû£»Check Point°ä²¼2021ÄêÑÇÌ«µØÓòÍøÂç¹¥»÷·ÖÎö»ã±¨¡£


ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾Öܰ²È«ÍþвΪÖС£


> ³ÁÒª°²È«·ì϶Áбí


1.Mozilla Firefox CVE-2021-29966»º³åÇøÒç¶Âí½Å


Mozilla Firefox´æÔÚ»º³åÇøÒç¶Âí½Å £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇó £¬ÓÕʹÓû§½âÎö £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»ò¿ÉÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://www.mozilla.org/en-US/security/advisories/mfsa2021-23/


2.Cisco Common Services Platform Collector OSºÅÁîÖ´Ðзì϶


Cisco Common Services Platform Collector CSPCÅäÖôæÔÚ°²È«·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâOSºÅÁî¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-CSPC-CIV-kDuBfNfu


3.Synology Photo Station SQL×¢Èë·ì϶


Snology Photo Station´æÔÚSQL×¢Èë·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄSQLÒªÇó £¬²Ù×÷Êý¾Ý¿â £¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐËÁÒâ´úÂë¡£

https://www.synology.cn/zh-cn/security/advisory/Synology_SA_20_20


4.F5 BIG-IQ Centralized ManagementºÅÁî×¢Èë·ì϶


F5 BIG-IQ Centralized Managementij¸öÒ³Ãæ´æÔÚÊäÈëÑéÖ¤·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâOSºÅÁî¡£

https://support.f5.com/csp/article/K06024431


5.OpenText Brava Desktop PDFÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶


OpenText Brava Desktop PDF´¦ÖôæÔÚ¿ªÊͺóʹÓ÷ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó £¬ÓÕʹÓû§½âÎö £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÄܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-642/


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢Sophos·¢ÏÖÕë¶ÔExchangeµÄÐÂÀÕË÷Èí¼þEpsilon Red


1.jpg


°²È«¹«Ë¾Sophos·¢ÏÖÐÂÀÕË÷Èí¼þEpsilon Red £¬ÖØÒªÕë¶ÔMicrosoft Exchange·þÎñÆ÷¡£×êÑÐÈËÔ±ÔÚµ÷²éÕë¶ÔÃÀ¹úij¾ÆµêµÄ¹¥»÷»î¶¯Ê±·¢ÏֵĸöñÒâÈí¼þ¡£Epsilon RedÓÃGolang£¨Go£©±àд £¬ÓÐÒ»×é¹ÖÒìµÄPowerShell¾ç±¾ £¬ÆäÖÐÿ¸ö¾ç±¾¶¼ÓÐÌØ¶¨×÷Óà £¬ÈçÖÕÖ¹°²È«¹¤¾ß¡¢É¾³ý¸±±¾¡¢ÇÔÈ¡°²È«ÕÊ»§ÖÎÀíÆ÷£¨SAM£©ÎļþµÈ¡£×êÑÐÈËÔ±°µÊ¾ £¬¸ÃÍÅ»ïʹÓÃÁËREvilÊê½ð¼Í¼µÄÄ£°å£¨¸üÕýÁËÆäÖеÄÓï·¨ºÍƴдÃýÎó£© £¬²¢ÇÒEpsilon RedÊÇÂþÍþÖжíÂÞ˹³¬µÈÊ¿±øµÄ½ÇÉ«Ãû £¬Òò¶ø´§¶È¸ÃÍÅ»ïÓë¶íÂÞ˹ÓйØ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-epsilon-red-ransomware-hunts-unpatched-microsoft-exchange-servers/


2¡¢È«Çò×î´óÈâÀà³ö²úÉÌJBSÔâµ½¹¥»÷ £¬¶à¸ö·Ö¹«Ë¾Í£²ú


2.jpg


JBSʳƷ¹«Ë¾ÓÚÉÏÖÜÄ©Ôâµ½¹¥»÷ £¬Ó°ÏìÃÀ¹ú¡¢°Ä´óÀûÑǺͼÓÄôóµÈµØµÄ·Ö¹«Ë¾¡£JBSÊÇÈ«Çò×î´óµÄÅ£ÈâºÍ¼ÒÇݳö²úÉÌ £¬Ò²ÊÇÈ«ÇòµÚ¶þ´óÖíÈâ³ö²úÉÌ £¬ÔÚÁù´óÖÞµÄ190¸ö¹ú¶È/µØÓò¶¼ÓÐÒµÎñ¡£Ä¿Ç° £¬°Ä´óÀûÑǵ±¾ÖÒÑ»ñϤÕâÒ»ÊÂÎñ £¬²¢ÔÚÓëJBSºÏ×÷ÊÔͼ¸´Ô­¾³Äڵijö²ú»î¶¯¡£´Ë¿ÌÉв»Ã÷ÏÔÕâ´Î¹¥»÷µÄÐÔÖʵȾßÌåÐÅÏ¢ £¬ÓÉÓÚ¹¥»÷²úÉúÓÚÖÜÄ© £¬Òò¶ø×êÑÐÈËÔ±´§¶È¼«ÓпÉÄÜÓëÀÕË÷Èí¼þÓйØ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/food-giant-jbs-foods-shuts-down-production-after-cyberattack/


3¡¢×êÑÐÍŶӷ¢ÏÖкóÃÅFacefish £¬¿ÉÇÔÈ¡LinuxϵͳÐÅÏ¢


3.jpg


×êÑÐÍŶӷ¢ÏÖÁËÒ»¸öеĺóÃÅFacefish £¬¿É½ÚÔìLinuxϵͳ²¢ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£FacefishÓÉDropperºÍRootkitÁ½²¿ÃÅ×é³É £¬ÆäÖØÒªÖ°ÄÜÓÉRootkitÄ £¿éÈ·¶¨ £¬¸ÃÄ £¿éÔÚRing3²ã¹¤×÷ £¬²¢Ê¹ÓÃLD_PRELOADÖ°ÄܽøÐмÓÔØ¡£¸Ã¶ñÒâÈí¼þÖ§³Ö¶àÖÖÖ°ÄÜ £¬Ô̺¬:ÉÏ´«É豸ÐÅÏ¢¡¢ÇÔÈ¡Óû§Æ¾Ö¤¡¢µ¯»ØshellºÍÖ´ÐÐËÁÒâºÅÁî¡£´Ë±í £¬×êÑÐÈËÔ±°µÊ¾FacefishѡȡÁ˸´ÔÓµÄͨѶºÍ̸ºÍ¼ÓÃÜËã·¨ £¬ËüʹÓÃÒÔ0x2XX¿ªÍ·µÄÖ¸ÁîÀ´»¥»»¹«Ô¿ £¬²¢Ê¹ÓÃBlowFishÓëC2·þÎñÆ÷¼ÓÃÜͨѶÊý¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/118388/malware/facefish-backdoor.html


4¡¢ÃÀ¹úÒѲé·âNOBELIUMÔÚÕë¶ÔUSAIDµÄ¹¥»÷ÖÐʹÓõÄÓòÃû


4.jpg


ÃÀ¹ú˾·¨²¿ÒѲé·âNOBELIUMÔÚÕë¶ÔÃÀ¹ú¹ú¼Ê¿ª·¢Êð (USAID) µÄ¹¥»÷ÖÐʹÓõÄÓòÃû¡£Î¢ÈíÓÚÉÏÖÜËijõ´ÎÅû¶ÁËÕâ´Î´¹µö¹¥»÷ £¬´ÓÊôÓÚ¶íÂÞ˹µý±¨»ú¹¹SVRµÄNOBELIUM£¨±ðÃûAPT29£©¼ÙÒâUSAID £¬ Ïò150 ¶à¸ö×éÖ¯·¢ËÍÁË3000¶à·â´¹µöÓʼþ¡£Õâ´Î²é·âµÄÁ½¸öÓòÃû±ðÀëΪtheyardservice[.]comºÍworldhomeoutlet[.]com £¬ÖØÒªÓÃÓڽӹܴÓÊܺ¦ÕßÄÇÀïй¶µÄÊý¾Ý £¬²¢·¢ËͺÅÁî¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-seizes-domains-used-by-apt29-in-recent-usaid-phishing-attacks/


5¡¢Check Point°ä²¼2021ÄêÑÇÌ«µØÓòÍøÂç¹¥»÷·ÖÎö»ã±¨


5.jpg


Check Point°ä²¼ÁË2021ÄêÑÇÌ«µØÓòÍøÂç¹¥»÷µÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö £¬Óë2020Äê5ÔÂÏà±È £¬ÑÇÌ«µØÓò (APAC) µÄÍøÂç¹¥»÷ÊýÁ¿Í¬±ÈÔö³¤ÁË168% £¬¶øÔÚ2021Äê4ÔÂÖÁ5ÔÂÆÚ¼ä¾ÍÔö³¤ÁË53%¡£Ôö·ù×î´óµÄ¶ñÒâÈí¼þÀàÐÍÊÇÀÕË÷Èí¼þºÍÔ¶³Ì½Ó¼ûľÂí (RAT) £¬Óë½ñÄêËêÊ×Ïà±È £¬¶¼Ôö³¤ÁË26% £¬¶øÒøÐÐľÂíºÍÐÅÏ¢ÇÔÈ¡¹¤¾ßÒ²Ôö³¤ÁË10%¡£ÍøÂç¹¥»÷´ÎÊýÔö·ù×î´óµÄǰ5¸ö¹ú¶È/µØÓòÊÇÈÕ±¾£¨40%£©¡¢ÐÂ¼ÓÆÂ£¨30%£©¡¢Ó¡¶ÈÄáÎ÷ÑÇ£¨25%£©¡¢ÂíÀ´Î÷ÑÇ£¨22%£©ºÍÖйų́Í壨17%£©¡£


Ô­ÎÄÁ´½Ó£º

https://blog.checkpoint.com/2021/05/27/check-point-research-asia-pacific-experiencing-a-168-year-on-year-increase-in-cyberattacks-in-may-2021/