ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ28ÖÜ

°ä²¼¹¦·ò 2021-07-12

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2021Äê07ÔÂ05ÈÕÖÁ07ÔÂ11ÈÕ¹²ÊÕ¼°²È«·ì϶61¸ö  £¬ÖµµÃ¹Ø×¢µÄÊÇAdvantech WebAccess Node BwFreRPTÕ»Òç³ö´úÂëÖ´Ðзì϶£»Microsoft Teams ElectronJSÖ¡³Á¶¨Ïò´úÂëÖ´Ðзì϶£»NPort IA5000A-I/O Series CVE-2021-32968»Ø¾ø·þÎñ·ì϶£»Phoenix Contact Automationworx BCPÎļþÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶£»Siemens Simcenter Femap FEMAPÔ½½çд´úÂëÖ´Ðзì϶¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÈðµäÁ¬Ëø³¬ÊÐCoopÒòKaseya¹©¸øÁ´¹¥»÷¹Ø¹ØÊý°Ù¼ÒÃŵꣻÃÀ¹ú±£ÏÕ¹«Ë¾AJG³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷  £¬¿Í»§ÐÅϢй¶£»CISAºÍFBI°ä²¼Õë¶ÔKaseya¹©¸øÁ´¹¥»÷Êܺ¦ÕßµÄÖ¸ÄÏ£»Î¢Èí°ä²¼µÄPrintNightmareµÄ´¹Î£¸üпɱ»Èƹý£»Kaspersky·¢ÏÖWildPressureÕë¶ÔmacOSµÄ¹¥»÷»î¶¯¡£


ƾ¾ÝÒÔÉÏ×ÛÊö  £¬±¾Öܰ²È«ÍþвΪÖС£


> ³ÁÒª°²È«·ì϶Áбí


1.Advantech WebAccess Node BwFreRPTÕ»Òç³ö´úÂëÖ´Ðзì϶


Advantech WebAccess Node BwFreRPT´æÔÚÕ»Òç¶Âí½Å  £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄ0x2711 IOCTLÒªÇó  £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-779/


2.Microsoft Teams ElectronJSÖ¡³Á¶¨Ïò´úÂëÖ´Ðзì϶


Microsoft Teams ElectronJSÖ¡±£»¤´æÔÚ°²È«·ì϶  £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâÒªÇó  £¬¿É³Á¶¨Ïò¶ñÒâÒ³Ãæ  £¬½Ó¼ûÄÚ²¿ÀûÓöÔÏó  £¬ÌáÉýȨÏÞ¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-772/


3.NPort IA5000A-I/O Series CVE-2021-32968»Ø¾ø·þÎñ·ì϶


NPort IA5000A-I/O SeriesÄÚ²¿WEB·þÎñ´æÔÚ»º³åÇøÒç¶Âí½Å  £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâÒªÇó  £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£¡£

https://us-cert.cisa.gov/ics/advisories/icsa-21-187-01


4.Phoenix Contact Automationworx BCPÎļþÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶


Phoenix Contact Automationworx BCPÎļþ´¦ÖôæÔÚÄÚ´æ·ÛËé·ì϶  £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó  £¬ÓÕʹÓû§½âÎö  £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-782/


5.Siemens Simcenter Femap FEMAPÔ½½çд´úÂëÖ´Ðзì϶


Siemens Simcenter Femap FEMAPÎļþ´¦ÖôæÔÚÔ½½çд·ì϶  £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó  £¬ÓÕʹÓû§½âÎö  £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-781/


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢ÈðµäÁ¬Ëø³¬ÊÐCoopÒòKaseya¹©¸øÁ´¹¥»÷¹Ø¹ØÊý°Ù¼ÒÃŵê


1.jpg


ÈðµäÁ¬Ëø³¬ÊÐCoop³ÆÆäÔâµ½ÁËKaseya¹©¸øÁ´¹¥»÷  £¬Êý°Ù¼ÒÃÅµê¹Ø¹Ø¡£CoopµÄ½²»°È˰µÊ¾ÆäÓÚÉÏÖÜÎåÍíÉÏ6µã30·Ö×óÓÒ·¢ÏÖÓÐÉÙÊýÃŵê³öÏÖÎÊÌâ  £¬µ«Ò»Ò¹Ö®ºóÆä´ó²¿ÃÅÃŵ궼±»ÆÈ¹Ø¹Ø  £¬Ô̺¬ÊÕÒøÌ¨ºÍ×ÔÖ÷½áÕËÔÚÄÚµÄÕû¸öÖ§¸¶ÏµÍ³¶¼ÖжÏÁË¡£´Ë±í  £¬CoopûÓÐʹÓÃKesayaÈí¼þ  £¬ÓÉÓÚËûÃǵÄÒ»¸öÈí¼þÌṩÉÌʹÓÃÁ˸ÃÈí¼þ¶øÊܵ½Ó°Ïì¡£°²È«¹«Ë¾HuntressLabs³Æ  £¬Õâ´Î¹¥»÷»î¶¯µÄµ÷²éÈÔÔÚ½øÐÐÖÐ  £¬ÖÁÉÙÓÐ200¼Ò×éÖ¯Êܵ½Ó°Ïì¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/119663/cyber-crime/coop-supermarket-kaseya-ransomware-attack.html


2¡¢ÃÀ¹ú±£ÏÕ¹«Ë¾AJG³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷  £¬¿Í»§ÐÅϢй¶


2.jpg


ÃÀ¹úArthur J. Gallagher (AJG) ³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷  £¬¿Í»§ÐÅϢй¶¡£AJGÊÇÃÀ¹úµÄÈ«Çò±£ÏÕ¾­¼ÍºÍ·çÏÕÖÎÀí¹«Ë¾  £¬×÷ΪȫÇò×î´óµÄ±£ÏÕ¾­¼ÍÉÌÖ®Ò»  £¬ÒµÎñ±é¼°49¸ö¹ú¶È/µØÓò¡£¹¥»÷²úÉúÔÚ2020Äê6ÔÂ3ÈÕÖÁ2020Äê9ÔÂ26ÈÕÆÚ¼ä  £¬ÆäÔÚ2020Äê9ÔÂ28ÈÕÅû¶¸ÃÊÂÎñ²¢³ÆÃ»º±¼û¾Ýй¶¡£µ«ÔÚËæºóµÄµ÷²é·¢ÏÖ  £¬7376È˵ÄÃô¸ÐÐÅϢй¶  £¬Ô̺¬Éç»á°²È«ºÅÂë»ò˰ºÅ¡¢¼ÝÕÕ¡¢»¤ÕÕ¡¢µ®ÉúÈÕÆÚ¡¢Óû§ÃûºÍÃÜÂë¡¢Ô±¹¤¼ø±ðºÅ¡¢²ÆÕþÕË»§»òÐÅÓþ¿¨ÐÅÏ¢¡¢µç×ÓÊðÃû¡¢Ò½ÁÆÐÅÏ¢¡¢±£ÏÕÐÅÏ¢ÒÔ¼°ÉúÎï¼ø±ðÐÅÏ¢µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-insurance-giant-ajg-reports-data-breach-after-ransomware-attack/


3¡¢CISAºÍFBI°ä²¼Õë¶ÔKaseya¹©¸øÁ´¹¥»÷Êܺ¦ÕßµÄÖ¸ÄÏ


3.jpg


CISAºÍFBI½áºÏ°ä²¼ÁËÕë¶ÔÊܵ½Kaseya¹©¸øÁ´¹¥»÷Ó°ÏìµÄÊܺ¦ÕßµÄÖ¸ÄÏ¡£ÕâÁ½¸ö»ú¹¹½¨Òé×é֯ʹÓÃKaseyaÌṩµÄ¼ì²â¹¤¾ßÀ´²é³­ËûÃǵÄϵͳÊÇ·ñ´æÔÚÈëÇÖ¼£Ïó  £¬²¢ÆôÓöà³É·ÖÉí·ÝÑéÖ¤(MFA)¡£´Ë±í  £¬×éÖ¯»¹Ó¦Ê¹Óð×Ãûµ¥À´±í²¿ÏÞ¶È¶ÔÆäÄÚ²¿×ʲúµÄ½Ó¼û  £¬²¢Ê¹Ó÷À»ðǽ»òVPN±£»¤ÆäÔ¶³Ì¼à¿Ø¹¤¾ßµÄÖÎÀí½çÃæ¡£¶øÊÜÓ°ÏìµÄMSP¿Í»§±ØÒªÈ·±£±¸·ÝÊÇ×îеÄ  £¬²¢ÇÒÁ¢¼´×°Öù©¸øÉÌÌṩµÄ×îеIJ¹¶¡¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/119728/cyber-crime/cisa-fbi-guidance-kaseya-attack.html


4¡¢Î¢Èí°ä²¼µÄPrintNightmareµÄ´¹Î£¸üпɱ»Èƹý


4.jpg


Microsoft°ä²¼KB5004945´¹Î£°²È«¸üР £¬½¨¸´Ó°ÏìËùÓÐWindows Print Spooler·þÎñÖб»»ý¼«ÀûÓõÄPrintNightmare 0day¡£¸ÃÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-34527£©ÔÊÐí¹¥»÷ÕßʹÓÃSYSTEMȨÏÞµÄÔ¶³ÌÖ´ÐдúÂë²¢ÆëÈ«ÊÕÊÜÖ¸±ê·þÎñÆ÷¡£ÔÚ¸üа䲼ºó  £¬×êÑÐÈËÔ±·¢Ïָò¹¶¡½ö½¨¸´ÁËÉæ¼°Ô¶³Ì´úÂëÖ´ÐеÄ×é¼þ  £¬Òò¶ø×êÑÐÈËÔ±ÆðÍ·Åú¸Ä·ì϶ÀûÓ÷¨Ê½²¢²âÊÔ²¹¶¡  £¬È·¶¨Äܹ»ÆëÈ«ÈÆ¹ýÕû¸ö²¹¶¡À´ÊµÏÖ±¾µØÌáȨºÍÔ¶³Ì´úÂëÖ´ÐС£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-pushes-emergency-update-for-windows-printnightmare-zero-day/


5¡¢Kaspersky·¢ÏÖWildPressureÕë¶ÔmacOSµÄ¹¥»÷»î¶¯


5.jpg


KasperskyµÄ×êÑÐÈËÔ±·¢ÏÖWildPressureÔÚ×î½üµÄ¹¥»÷»î¶¯ÖÐÔö³¤ÁËÕë¶ÔmacOSµÄ¶ñÒâÈí¼þ±äÌå¡£×êÑÐÈËÔ±ÓÚ2020Äê3Ô³õ´Î·¢ÏÖ¸ÃÍÅ»ï  £¬ÆäʱWildPressureʹÓÃÁËC++°æ±¾µÄMilumľÂí¹¥»÷Öж«µÄ×éÖ¯¡£ÔÚ½üÆÚÕë¶ÔÄÜÔ´ÐÐÒµµÄ¹¥»÷ÖÐ  £¬MilumÒѾ­Í¨¹ýPyInstaller°ü½øÐÐÁ˳Á×é  £¬ÆäÖÐÔ̺¬ÁËÓëWindowsºÍmacOSϵͳ¼æÈݵÄľÂí·¨Ê½  £¬±»ºÚµÄÍøÕ¾¿É±»APT×éÖ¯ÓÃÀ´ÏÂÔØºÍÉÏ´«Îļþ²¢Ö´ÐкÅÁî¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/macos-wildpressure-apt/167606/