ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ23ÖÜ

°ä²¼¹¦·ò 2021-06-07

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2021Äê05ÔÂ31ÈÕÖÁ06ÔÂ06ÈÕ¹²ÊÕ¼°²È«·ì϶59¸ö£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMozilla Firefox CVE-2021-29966»º³åÇøÒç¶Âí½Å£»£»£»£»£»Cisco Common Services Platform Collector OSºÅÁîÖ´Ðзì϶£»£»£»£»£»Synology Photo Station SQL×¢Èë·ì϶£»£»£»£»£»F5 BIG-IQ Centralized ManagementºÅÁî×¢Èë·ì϶£»£»£»£»£»OpenText Brava Desktop PDFÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇSophos·¢ÏÖÕë¶ÔExchangeµÄÐÂÀÕË÷Èí¼þEpsilon Red£»£»£»£»£»È«Çò×î´óÈâÀà³ö²úÉÌJBSÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬¶à¸ö·Ö¹«Ë¾Í£²ú£»£»£»£»£»×êÑÐÍŶӷ¢ÏÖкóÃÅFacefish£¬£¬£¬£¬£¬£¬¿ÉÇÔÈ¡LinuxϵͳÐÅÏ¢£»£»£»£»£»ÃÀ¹úÒѲé·âNOBELIUMÔÚÕë¶ÔUSAIDµÄ¹¥»÷ÖÐʹÓõÄÓòÃû£»£»£»£»£»Check Point°ä²¼2021ÄêÑÇÌ«µØÓòÍøÂç¹¥»÷·ÖÎö»ã±¨¡£¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£


> ³ÁÒª°²È«·ì϶Áбí


1.Mozilla Firefox CVE-2021-29966»º³åÇøÒç¶Âí½Å


Mozilla Firefox´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇ󣬣¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»ò¿ÉÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£

https://www.mozilla.org/en-US/security/advisories/mfsa2021-23/


2.Cisco Common Services Platform Collector OSºÅÁîÖ´Ðзì϶


Cisco Common Services Platform Collector CSPCÅäÖôæÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâOSºÅÁî¡£¡£¡£¡£¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-CSPC-CIV-kDuBfNfu


3.Synology Photo Station SQL×¢Èë·ì϶


Snology Photo Station´æÔÚSQL×¢Èë·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄSQLÒªÇ󣬣¬£¬£¬£¬£¬²Ù×÷Êý¾Ý¿â£¬£¬£¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£

https://www.synology.cn/zh-cn/security/advisory/Synology_SA_20_20


4.F5 BIG-IQ Centralized ManagementºÅÁî×¢Èë·ì϶


F5 BIG-IQ Centralized Managementij¸öÒ³Ãæ´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâOSºÅÁî¡£¡£¡£¡£¡£

https://support.f5.com/csp/article/K06024431


5.OpenText Brava Desktop PDFÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶


OpenText Brava Desktop PDF´¦ÖôæÔÚ¿ªÊͺóʹÓ÷ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÄܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-642/


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢Sophos·¢ÏÖÕë¶ÔExchangeµÄÐÂÀÕË÷Èí¼þEpsilon Red


1.jpg


°²È«¹«Ë¾Sophos·¢ÏÖÐÂÀÕË÷Èí¼þEpsilon Red£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔMicrosoft Exchange·þÎñÆ÷¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÔÚµ÷²éÕë¶ÔÃÀ¹úij¾ÆµêµÄ¹¥»÷»î¶¯Ê±·¢ÏֵĸöñÒâÈí¼þ¡£¡£¡£¡£¡£Epsilon RedÓÃGolang£¨Go£©±àд£¬£¬£¬£¬£¬£¬ÓÐÒ»×é¹ÖÒìµÄPowerShell¾ç±¾£¬£¬£¬£¬£¬£¬ÆäÖÐÿ¸ö¾ç±¾¶¼ÓÐÌØ¶¨×÷Ó㬣¬£¬£¬£¬£¬ÈçÖÕÖ¹°²È«¹¤¾ß¡¢É¾³ý¸±±¾¡¢ÇÔÈ¡°²È«ÕÊ»§ÖÎÀíÆ÷£¨SAM£©ÎļþµÈ¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬£¬¸ÃÍÅ»ïʹÓÃÁËREvilÊê½ð¼Í¼µÄÄ£°å£¨¸üÕýÁËÆäÖеÄÓï·¨ºÍƴдÃýÎ󣩣¬£¬£¬£¬£¬£¬²¢ÇÒEpsilon RedÊÇÂþÍþÖжíÂÞ˹³¬µÈÊ¿±øµÄ½ÇÉ«Ãû£¬£¬£¬£¬£¬£¬Òò¶ø´§¶È¸ÃÍÅ»ïÓë¶íÂÞ˹Óйء£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-epsilon-red-ransomware-hunts-unpatched-microsoft-exchange-servers/


2¡¢È«Çò×î´óÈâÀà³ö²úÉÌJBSÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬¶à¸ö·Ö¹«Ë¾Í£²ú


2.jpg


JBSʳƷ¹«Ë¾ÓÚÉÏÖÜÄ©Ôâµ½¹¥»÷£¬£¬£¬£¬£¬£¬Ó°ÏìÃÀ¹ú¡¢°Ä´óÀûÑǺͼÓÄôóµÈµØµÄ·Ö¹«Ë¾¡£¡£¡£¡£¡£JBSÊÇÈ«Çò×î´óµÄÅ£ÈâºÍ¼ÒÇݳö²úÉÌ£¬£¬£¬£¬£¬£¬Ò²ÊÇÈ«ÇòµÚ¶þ´óÖíÈâ³ö²úÉÌ£¬£¬£¬£¬£¬£¬ÔÚÁù´óÖÞµÄ190¸ö¹ú¶È/µØÓò¶¼ÓÐÒµÎñ¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬°Ä´óÀûÑǵ±¾ÖÒÑ»ñϤÕâÒ»ÊÂÎñ£¬£¬£¬£¬£¬£¬²¢ÔÚÓëJBSºÏ×÷ÊÔͼ¸´Ô­¾³Äڵijö²ú»î¶¯¡£¡£¡£¡£¡£´Ë¿ÌÉв»Ã÷ÏÔÕâ´Î¹¥»÷µÄÐÔÖʵȾßÌåÐÅÏ¢£¬£¬£¬£¬£¬£¬ÓÉÓÚ¹¥»÷²úÉúÓÚÖÜÄ©£¬£¬£¬£¬£¬£¬Òò¶ø×êÑÐÈËÔ±´§¶È¼«ÓпÉÄÜÓëÀÕË÷Èí¼þÓйء£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/food-giant-jbs-foods-shuts-down-production-after-cyberattack/


3¡¢×êÑÐÍŶӷ¢ÏÖкóÃÅFacefish£¬£¬£¬£¬£¬£¬¿ÉÇÔÈ¡LinuxϵͳÐÅÏ¢


3.jpg


×êÑÐÍŶӷ¢ÏÖÁËÒ»¸öеĺóÃÅFacefish£¬£¬£¬£¬£¬£¬¿É½ÚÔìLinuxϵͳ²¢ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£FacefishÓÉDropperºÍRootkitÁ½²¿ÃÅ×é³É£¬£¬£¬£¬£¬£¬ÆäÖØÒªÖ°ÄÜÓÉRootkitÄ£¿£¿£¿£¿£¿£¿£¿éÈ·¶¨£¬£¬£¬£¬£¬£¬¸ÃÄ£¿£¿£¿£¿£¿£¿£¿éÔÚRing3²ã¹¤×÷£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃLD_PRELOADÖ°ÄܽøÐмÓÔØ¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÖ§³Ö¶àÖÖÖ°ÄÜ£¬£¬£¬£¬£¬£¬Ô̺¬:ÉÏ´«É豸ÐÅÏ¢¡¢ÇÔÈ¡Óû§Æ¾Ö¤¡¢µ¯»ØshellºÍÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±°µÊ¾FacefishѡȡÁ˸´ÔÓµÄͨѶºÍ̸ºÍ¼ÓÃÜËã·¨£¬£¬£¬£¬£¬£¬ËüʹÓÃÒÔ0x2XX¿ªÍ·µÄÖ¸ÁîÀ´»¥»»¹«Ô¿£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃBlowFishÓëC2·þÎñÆ÷¼ÓÃÜͨѶÊý¾Ý¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/118388/malware/facefish-backdoor.html


4¡¢ÃÀ¹úÒѲé·âNOBELIUMÔÚÕë¶ÔUSAIDµÄ¹¥»÷ÖÐʹÓõÄÓòÃû


4.jpg


ÃÀ¹ú˾·¨²¿ÒѲé·âNOBELIUMÔÚÕë¶ÔÃÀ¹ú¹ú¼Ê¿ª·¢Êð (USAID) µÄ¹¥»÷ÖÐʹÓõÄÓòÃû¡£¡£¡£¡£¡£Î¢ÈíÓÚÉÏÖÜËijõ´ÎÅû¶ÁËÕâ´Î´¹µö¹¥»÷£¬£¬£¬£¬£¬£¬´ÓÊôÓÚ¶íÂÞ˹µý±¨»ú¹¹SVRµÄNOBELIUM£¨±ðÃûAPT29£©¼ÙÒâUSAID£¬£¬£¬£¬£¬£¬ Ïò150 ¶à¸ö×éÖ¯·¢ËÍÁË3000¶à·â´¹µöÓʼþ¡£¡£¡£¡£¡£Õâ´Î²é·âµÄÁ½¸öÓòÃû±ðÀëΪtheyardservice[.]comºÍworldhomeoutlet[.]com£¬£¬£¬£¬£¬£¬ÖØÒªÓÃÓڽӹܴÓÊܺ¦ÕßÄÇÀïй¶µÄÊý¾Ý£¬£¬£¬£¬£¬£¬²¢·¢ËͺÅÁî¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-seizes-domains-used-by-apt29-in-recent-usaid-phishing-attacks/


5¡¢Check Point°ä²¼2021ÄêÑÇÌ«µØÓòÍøÂç¹¥»÷·ÖÎö»ã±¨


5.jpg


Check Point°ä²¼ÁË2021ÄêÑÇÌ«µØÓòÍøÂç¹¥»÷µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬Óë2020Äê5ÔÂÏà±È£¬£¬£¬£¬£¬£¬ÑÇÌ«µØÓò (APAC) µÄÍøÂç¹¥»÷ÊýÁ¿Í¬±ÈÔö³¤ÁË168%£¬£¬£¬£¬£¬£¬¶øÔÚ2021Äê4ÔÂÖÁ5ÔÂÆÚ¼ä¾ÍÔö³¤ÁË53%¡£¡£¡£¡£¡£Ôö·ù×î´óµÄ¶ñÒâÈí¼þÀàÐÍÊÇÀÕË÷Èí¼þºÍÔ¶³Ì½Ó¼ûľÂí (RAT)£¬£¬£¬£¬£¬£¬Óë½ñÄêËêÊ×Ïà±È£¬£¬£¬£¬£¬£¬¶¼Ôö³¤ÁË26%£¬£¬£¬£¬£¬£¬¶øÒøÐÐľÂíºÍÐÅÏ¢ÇÔÈ¡¹¤¾ßÒ²Ôö³¤ÁË10%¡£¡£¡£¡£¡£ÍøÂç¹¥»÷´ÎÊýÔö·ù×î´óµÄǰ5¸ö¹ú¶È/µØÓòÊÇÈÕ±¾£¨40%£©¡¢ÐÂ¼ÓÆÂ£¨30%£©¡¢Ó¡¶ÈÄáÎ÷ÑÇ£¨25%£©¡¢ÂíÀ´Î÷ÑÇ£¨22%£©ºÍÖйų́Í壨17%£©¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.checkpoint.com/2021/05/27/check-point-research-asia-pacific-experiencing-a-168-year-on-year-increase-in-cyberattacks-in-may-2021/