ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ17ÖÜ

°ä²¼¹¦·ò 2021-04-27

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2021Äê04ÔÂ19ÈÕÖÁ04ÔÂ25ÈÕ¹²ÊÕ¼°²È«·ì϶60¸ö£¬£¬£¬ £¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇGoogle Chrome V8¶ÑÒç³ö´úÂëÖ´Ðзì϶£»£»£»£»£»FIBARO Home Center 2 8000¶Ë¿ÚδÊÚȨ½Ó¼û·ì϶£»£»£»£»£»Oracle Cloud Infrastructure Storage Gateway CVE-2021-2318´úÂëÖ´Ðзì϶£»£»£»£»£»Cisco SD-WAN vManage CVE-2021-1484²ÎÊý×¢Èë·ì϶£»£»£»£»£»Dell Technologies Dell PowerScale OneFSδÊÚȨ½Ó¼û·ì϶¡£¡£¡£ ¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇTwitterÔÚÈ«ÇòÁìÓòÄÚ·þÎñÖжϣ¬£¬£¬ £¬£¬£¬£¬ÊÂÎñÈÔÔÚµ÷²éÖУ»£»£»£»£»AdvIntel·¢ÏÖRyukÀûÓÃKeeThiefµÈй¤¾ßµÄ¹¥»÷»î¶¯£»£»£»£»£»ÃÀ¹úÔì²Ã28¸öÓë¶íÂÞ˹¹¥»÷»î¶¯ÓйصļÓÃÜÇ®±ÒµØÖ·£»£»£»£»£»Oracle°ä²¼°²È«¸üУ¬£¬£¬ £¬£¬£¬£¬½¨¸´¶à¸ö²úÆ·ÖеÄ390¸ö·ì϶£»£»£»£»£»McAfee°ä²¼2020ϰëÄêÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£ ¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬ £¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£ ¡£¡£¡£¡£


> ³ÁÒª°²È«·ì϶Áбí


1.Google Chrome V8¶ÑÒç³ö´úÂëÖ´Ðзì϶


Google Chrome V8ÒýÇæ´æÔÚ¶ÑÒç¶Âí½Å£¬£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇ󣬣¬£¬ £¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬ £¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÄܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£ ¡£¡£¡£¡£

https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_20.html


2.FIBARO Home Center 2 8000¶Ë¿ÚδÊÚȨ½Ó¼û·ì϶


FIBARO Home Center 2 8000¶Ë¿Ú´æÔÚ°²È«·ì϶£¬£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬ £¬£¬£¬£¬¿ÉδÊÚȨִÐжñÒâ²Ù×÷£¬£¬£¬ £¬£¬£¬£¬Èç¹Ø»ú¡¢³ÁÆô»ò³ÁÆôµ½¸´Ô­Ä£Ê½¡£¡£¡£ ¡£¡£¡£¡£

http://seclists.org/fulldisclosure/2021/Apr/27


3.Oracle Cloud Infrastructure Storage Gateway CVE-2021-2318´úÂëÖ´Ðзì϶


Oracle Cloud Infrastructure Storage Gateway´æÔÚ°²È«·ì϶£¬£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬ £¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÄܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£ ¡£¡£¡£¡£

https://www.oracle.com/security-alerts/cpuapr2021.html


4.Cisco SD-WAN vManage CVE-2021-1484²ÎÊý×¢Èë·ì϶


Cisco SD-WAN vManageÉ豸ģ°åÅäÖôæÔÚ°²È«·ì϶£¬£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬ £¬£¬£¬£¬¿É×¢ÈëËÁÒâºÅÁ£¬£¬ £¬£¬£¬£¬»ò¿É½øÐлؾø·þÎñ¹¥»÷¡£¡£¡£ ¡£¡£¡£¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vman-cmdinj-nRHKgfHX


5.Dell Technologies Dell PowerScale OneFSδÊÚȨ½Ó¼û·ì϶


Dell Technologies Dell PowerScale OneFS¶ÔÃÜÔ¿¹ýÆÚ´¦ÖôæÔÚ°²È«·ì϶£¬£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬ £¬£¬£¬£¬Õ¼ÓÐISI_PRIV_LOGIN_SSHµÄ¹ýÆÚÓû§¿É³ÖÐøµÇ¼ϵͳ¡£¡£¡£ ¡£¡£¡£¡£

https://www.dell.com/support/kbdoc/en-sg/000185202/dsa-2021-048-dell-emc-powerscale-onefs-security-update-for-multiple-vulnerabilities


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢TwitterÔÚÈ«ÇòÁìÓòÄÚ·þÎñÖжϣ¬£¬£¬ £¬£¬£¬£¬ÊÂÎñÈÔÔÚµ÷²éÖÐ


1.jpg


TwitterÔÚÉÏÖÜÎåÍíÉϲúÉúÁ˵ÄÖжϣ¬£¬£¬ £¬£¬£¬£¬²¢Ò»Ïò³ÖÐøµ½ÖÜÁùÉÏÎç¡£¡£¡£ ¡£¡£¡£¡£Óû§·´Ó³µÄÎÊÌâÔ̺¬ÎÞ·¨Õý³£ËÑË÷¡¢ÄÚÈÝÎÞ·¨¼ÓÔØ¡¢Í¼ÏñÎÞ·¨ÏÔʾÉõÖÁÎÞ·¨µÇÂ¼ÍøÕ¾¡£¡£¡£ ¡£¡£¡£¡£¾Ýͳ¼ÆÕâ´ÎÖжÏÓ°ÏìÁËÈ«ÇòÁìÓòÄÚµÄÓû§£¬£¬£¬ £¬£¬£¬£¬µ«ÂÞÂíÄáÑǵÈһЩ¹ú¶ÈËÆºõ²¢Î´Êܵ½Ó°Ïì¡£¡£¡£ ¡£¡£¡£¡£Twitter°µÊ¾Õâ´ÎÖжÏÊÇÆä·þÎñÆ÷ÉϵÄÎÊÌ⣬£¬£¬ £¬£¬£¬£¬²¢ÒѾ­ÔÚÖÂÁ¦½â¾öʹËùÓо¡¿ì¸´Ô­Õý³££¬£¬£¬ £¬£¬£¬£¬µ«ÊDz¢Î´ÌṩÓйØÕâ´Î¹ÊÕϵľßÌåÐÅÏ¢¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/technology/twitter-is-suffering-from-another-worldwide-outage-today/


2¡¢AdvIntel·¢ÏÖRyukÀûÓÃKeeThiefµÈй¤¾ßµÄ¹¥»÷»î¶¯


2.jpg


°²È«¹«Ë¾Advanced Intelligence·¢ÏÖRyukÀûÓÃKeeThiefµÈй¤¾ßµÄ¹¥»÷»î¶¯¡£¡£¡£ ¡£¡£¡£¡£×êÑÐÈËÔ±¹Û²ìµ½£¬£¬£¬ £¬£¬£¬£¬½ñÄêRyukÀÕË÷Èí¼þ¸ü¶àµØÒÀÀµÓÚ¶ÔRDP¶³öµÄÖ÷»ú½øÐдó¹æÄ£±©Á¦ÆÆ½âºÍÃÜÂëÅçÈ÷¹¥»÷À´ÈëÇÖÖ¸±êÍøÂç¡£¡£¡£ ¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬£¬£¬ÔÚÕâЩ¹¥»÷Öл¹·¢ÏÖÁËм¼Êõ£¬£¬£¬ £¬£¬£¬£¬Ô̺¬Ê¹ÓôÓKeePassÃÜÂëÖÎÀíÆ÷ÇÔȡƾ֤µÄ¿ªÔ´¹¤¾ßKeeThief£¬£¬£¬ £¬£¬£¬£¬ÒÔ¼°×°ÖñãЯʽ°æ±¾µÄNotepad ++£¬£¬£¬ £¬£¬£¬£¬ÔÚPowerShellÖ´ÐÐÊÜÏÞµÄϵͳÉÏÔËÐÐPowerShell¾ç±¾¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ryuk-ransomware-operation-updates-hacking-techniques/


3¡¢ÃÀ¹úÔì²Ã28¸öÓë¶íÂÞ˹¹¥»÷»î¶¯ÓйصļÓÃÜÇ®±ÒµØÖ·


3.jpg


ÃÀ¹úµ±¾ÖÔÚ±¾ÖÜÔì²ÃÁË28¸ö¼ÓÃÜÇ®±ÒµØÖ·£¬£¬£¬ £¬£¬£¬£¬¾Ý³ÆÕâЩµØÖ·ÓëÉæ¼°¶íÂÞË¹ÍøÂç¹¥»÷»ò×ÌÈÅÑ¡¾Ù»î¶¯µÄ×éÖ¯ºÍÓ×ÎÒÓйØ¡£¡£¡£ ¡£¡£¡£¡£ÃÀ¹úµ±¾Ö»¹°µÊ¾£¬£¬£¬ £¬£¬£¬£¬ÕâЩ»î¶¯ÊÇÓɶíÂÞ˹Áª¹ú°²È«¾Ö£¨FSB£©ºÍ¶íÂÞË¹ÖØÒªµý±¨¾Ö£¨GRU£©·¢Õ¹µÄ£¬£¬£¬ £¬£¬£¬£¬²¢ÇÒÒѾ­µÃµ½ÁËÁù¼ÒÓë¶íÂÞ˹ÓкÏ×÷µÄ¹«Ë¾µÄÔ®ÊÖ¡£¡£¡£ ¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬£¬£¬ÃûΪSESµÄ°Í»ù˹̹¹«Ë¾Ïò»¥ÁªÍø×êÑлú¹¹(IRA)ÌṩÐéαÉí·ÝÀ´ÌÓ±ÜÃÀ¹úµÄÔì²Ã£¬£¬£¬ £¬£¬£¬£¬Æä¼ÓÃÜÇ®±ÒµØÖ·ÒÑͨ¹ý26900±ÊÂòÂôÊÕµ½Á˼ÛÖµ³¬¹ý250ÍòÃÀÔªµÄÊý×ÖÇ®±Ò¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-sanctions-cryptocurrency-addresses-linked-to-russian-cyberactivities/


4¡¢Oracle°ä²¼°²È«¸üУ¬£¬£¬ £¬£¬£¬£¬½¨¸´¶à¸ö²úÆ·ÖеÄ390¸ö·ì϶


4.jpg


OracleÒÑÓÚ2021Äê4Ô°䲼Á˳ÁÒª²¹¶¡¸üУ¬£¬£¬ £¬£¬£¬£¬½¨¸´Á˶à¸ö²úÆ·ÖеÄ390¸ö·ì϶¡£¡£¡£ ¡£¡£¡£¡£Õâ´Î½¨¸´µÄ½ÏΪÑϳÁµÄ·ì϶ΪOracleͨѶÀûÓ÷¨Ê½ÖÐCVSSÆÀ·ÖΪ9.8µÄCVE-2020-11612¡¢CVE-2019-0228¡¢CVE-2020-11612ºÍCVE-2020-28052£¬£¬£¬ £¬£¬£¬£¬Instantis EnterpriseTrackÖеÄCVE-2019-0219£¬£¬£¬ £¬£¬£¬£¬ÆóÒµÖÎÀíÆ÷»ù´¡Æ½Ì¨ÖеÄCVE-2019-17195ÒÔ¼°OracleóÒ×ÖÇÄÜÆóÒµ°æÖеÄCVE-2020-9480µÈ·ì϶¡£¡£¡£ ¡£¡£¡£¡£OracleÇ¿ÁÒ½¨Òé¿Í»§¾¡¿ìÀûÓð²È«²¹¶¡¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.oracle.com/security-alerts/cpuapr2021.html


5¡¢McAfee°ä²¼2020ϰëÄêÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨


5.jpg


McAfee°ä²¼ÁË2020ϰëÄêÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£ ¡£¡£¡£¡£»ã±¨³Æ£¬£¬£¬ £¬£¬£¬£¬2020ÄêQ4¾ùÔÈÿ·ÖÖӿɼì²âµ½648¸öÍþв£¬£¬£¬ £¬£¬£¬£¬±ÈQ3Ôö³¤ÁË10£¥£¬£¬£¬ £¬£¬£¬£¬±ÈQ2Ôö³¤ÁË40£¥£¬£¬£¬ £¬£¬£¬£¬Ê¼ÖճʳÖÐøÉÏÉýÇ÷Ïò¡£¡£¡£ ¡£¡£¡£¡£»ã±¨»¹Ö¸³ö2020ÄêϰëÄêÔÚÒ°±í·¢ÏֵĹ¥»÷ÊýÁ¿¼¤ÔöµÄÖØÒªÔ­ÒòÊÇÒÔCOVIDΪÖ÷ÌâµÄ¹¥»÷ºÍPowerShellľÂíµÄ¼¤Ôö£¬£¬£¬ £¬£¬£¬£¬ÒÔ¼°SolarWinds·ì϶ºÍSunburst¶ñÒâÈí¼þµÄ³ÖÐøÊæÕ¹¡£¡£¡£ ¡£¡£¡£¡£Ïà±Å×ÚQ3 £¬£¬£¬ £¬£¬£¬£¬Q4µÄPowerShellÊýÁ¿Ôö³¤ÁË208%£¬£¬£¬ £¬£¬£¬£¬Õë¶ÔofficeµÄ¶ñÒâÈí¼þÊýÁ¿Ôö³¤ÁË199%¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.mcafee.com/enterprise/en-us/lp/threats-reports/apr-2021.html