ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ23ÖÜ
°ä²¼¹¦·ò 2021-06-07> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2021Äê05ÔÂ31ÈÕÖÁ06ÔÂ06ÈÕ¹²ÊÕ¼°²È«·ì϶59¸ö£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMozilla Firefox CVE-2021-29966»º³åÇøÒç¶Âí½Å£»£»£»£»£»Cisco Common Services Platform Collector OSºÅÁîÖ´Ðзì϶£»£»£»£»£»Synology Photo Station SQL×¢Èë·ì϶£»£»£»£»£»F5 BIG-IQ Centralized ManagementºÅÁî×¢Èë·ì϶£»£»£»£»£»OpenText Brava Desktop PDFÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇSophos·¢ÏÖÕë¶ÔExchangeµÄÐÂÀÕË÷Èí¼þEpsilon Red£»£»£»£»£»È«Çò×î´óÈâÀà³ö²úÉÌJBSÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬¶à¸ö·Ö¹«Ë¾Í£²ú£»£»£»£»£»×êÑÐÍŶӷ¢ÏÖкóÃÅFacefish£¬£¬£¬£¬£¬£¬¿ÉÇÔÈ¡LinuxϵͳÐÅÏ¢£»£»£»£»£»ÃÀ¹úÒѲé·âNOBELIUMÔÚÕë¶ÔUSAIDµÄ¹¥»÷ÖÐʹÓõÄÓòÃû£»£»£»£»£»Check Point°ä²¼2021ÄêÑÇÌ«µØÓòÍøÂç¹¥»÷·ÖÎö»ã±¨¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£
> ³ÁÒª°²È«·ì϶Áбí
1.Mozilla Firefox CVE-2021-29966»º³åÇøÒç¶Âí½Å
Mozilla Firefox´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇ󣬣¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»ò¿ÉÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
https://www.mozilla.org/en-US/security/advisories/mfsa2021-23/
2.Cisco Common Services Platform Collector OSºÅÁîÖ´Ðзì϶
Cisco Common Services Platform Collector CSPCÅäÖôæÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâOSºÅÁî¡£¡£¡£¡£¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-CSPC-CIV-kDuBfNfu
3.Synology Photo Station SQL×¢Èë·ì϶
Snology Photo Station´æÔÚSQL×¢Èë·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄSQLÒªÇ󣬣¬£¬£¬£¬£¬²Ù×÷Êý¾Ý¿â£¬£¬£¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
https://www.synology.cn/zh-cn/security/advisory/Synology_SA_20_20
4.F5 BIG-IQ Centralized ManagementºÅÁî×¢Èë·ì϶
F5 BIG-IQ Centralized Managementij¸öÒ³Ãæ´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâOSºÅÁî¡£¡£¡£¡£¡£
https://support.f5.com/csp/article/K06024431
5.OpenText Brava Desktop PDFÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶
OpenText Brava Desktop PDF´¦ÖôæÔÚ¿ªÊͺóʹÓ÷ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÄܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-642/
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢Sophos·¢ÏÖÕë¶ÔExchangeµÄÐÂÀÕË÷Èí¼þEpsilon Red

°²È«¹«Ë¾Sophos·¢ÏÖÐÂÀÕË÷Èí¼þEpsilon Red£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔMicrosoft Exchange·þÎñÆ÷¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÔÚµ÷²éÕë¶ÔÃÀ¹úij¾ÆµêµÄ¹¥»÷»î¶¯Ê±·¢ÏֵĸöñÒâÈí¼þ¡£¡£¡£¡£¡£Epsilon RedÓÃGolang£¨Go£©±àд£¬£¬£¬£¬£¬£¬ÓÐÒ»×é¹ÖÒìµÄPowerShell¾ç±¾£¬£¬£¬£¬£¬£¬ÆäÖÐÿ¸ö¾ç±¾¶¼ÓÐÌØ¶¨×÷Ó㬣¬£¬£¬£¬£¬ÈçÖÕÖ¹°²È«¹¤¾ß¡¢É¾³ý¸±±¾¡¢ÇÔÈ¡°²È«ÕÊ»§ÖÎÀíÆ÷£¨SAM£©ÎļþµÈ¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬£¬¸ÃÍÅ»ïʹÓÃÁËREvilÊê½ð¼Í¼µÄÄ£°å£¨¸üÕýÁËÆäÖеÄÓï·¨ºÍƴдÃýÎ󣩣¬£¬£¬£¬£¬£¬²¢ÇÒEpsilon RedÊÇÂþÍþÖжíÂÞ˹³¬µÈÊ¿±øµÄ½ÇÉ«Ãû£¬£¬£¬£¬£¬£¬Òò¶ø´§¶È¸ÃÍÅ»ïÓë¶íÂÞ˹Óйء£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-epsilon-red-ransomware-hunts-unpatched-microsoft-exchange-servers/
2¡¢È«Çò×î´óÈâÀà³ö²úÉÌJBSÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬¶à¸ö·Ö¹«Ë¾Í£²ú

JBSʳƷ¹«Ë¾ÓÚÉÏÖÜÄ©Ôâµ½¹¥»÷£¬£¬£¬£¬£¬£¬Ó°ÏìÃÀ¹ú¡¢°Ä´óÀûÑǺͼÓÄôóµÈµØµÄ·Ö¹«Ë¾¡£¡£¡£¡£¡£JBSÊÇÈ«Çò×î´óµÄÅ£ÈâºÍ¼ÒÇݳö²úÉÌ£¬£¬£¬£¬£¬£¬Ò²ÊÇÈ«ÇòµÚ¶þ´óÖíÈâ³ö²úÉÌ£¬£¬£¬£¬£¬£¬ÔÚÁù´óÖÞµÄ190¸ö¹ú¶È/µØÓò¶¼ÓÐÒµÎñ¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬°Ä´óÀûÑǵ±¾ÖÒÑ»ñϤÕâÒ»ÊÂÎñ£¬£¬£¬£¬£¬£¬²¢ÔÚÓëJBSºÏ×÷ÊÔͼ¸´Ô¾³Äڵijö²ú»î¶¯¡£¡£¡£¡£¡£´Ë¿ÌÉв»Ã÷ÏÔÕâ´Î¹¥»÷µÄÐÔÖʵȾßÌåÐÅÏ¢£¬£¬£¬£¬£¬£¬ÓÉÓÚ¹¥»÷²úÉúÓÚÖÜÄ©£¬£¬£¬£¬£¬£¬Òò¶ø×êÑÐÈËÔ±´§¶È¼«ÓпÉÄÜÓëÀÕË÷Èí¼þÓйء£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/food-giant-jbs-foods-shuts-down-production-after-cyberattack/
3¡¢×êÑÐÍŶӷ¢ÏÖкóÃÅFacefish£¬£¬£¬£¬£¬£¬¿ÉÇÔÈ¡LinuxϵͳÐÅÏ¢

×êÑÐÍŶӷ¢ÏÖÁËÒ»¸öеĺóÃÅFacefish£¬£¬£¬£¬£¬£¬¿É½ÚÔìLinuxϵͳ²¢ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£FacefishÓÉDropperºÍRootkitÁ½²¿ÃÅ×é³É£¬£¬£¬£¬£¬£¬ÆäÖØÒªÖ°ÄÜÓÉRootkitÄ£¿£¿£¿£¿£¿£¿£¿éÈ·¶¨£¬£¬£¬£¬£¬£¬¸ÃÄ£¿£¿£¿£¿£¿£¿£¿éÔÚRing3²ã¹¤×÷£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃLD_PRELOADÖ°ÄܽøÐмÓÔØ¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÖ§³Ö¶àÖÖÖ°ÄÜ£¬£¬£¬£¬£¬£¬Ô̺¬:ÉÏ´«É豸ÐÅÏ¢¡¢ÇÔÈ¡Óû§Æ¾Ö¤¡¢µ¯»ØshellºÍÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±°µÊ¾FacefishѡȡÁ˸´ÔÓµÄͨѶºÍ̸ºÍ¼ÓÃÜËã·¨£¬£¬£¬£¬£¬£¬ËüʹÓÃÒÔ0x2XX¿ªÍ·µÄÖ¸ÁîÀ´»¥»»¹«Ô¿£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃBlowFishÓëC2·þÎñÆ÷¼ÓÃÜͨѶÊý¾Ý¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/118388/malware/facefish-backdoor.html
4¡¢ÃÀ¹úÒѲé·âNOBELIUMÔÚÕë¶ÔUSAIDµÄ¹¥»÷ÖÐʹÓõÄÓòÃû

ÃÀ¹ú˾·¨²¿ÒѲé·âNOBELIUMÔÚÕë¶ÔÃÀ¹ú¹ú¼Ê¿ª·¢Êð (USAID) µÄ¹¥»÷ÖÐʹÓõÄÓòÃû¡£¡£¡£¡£¡£Î¢ÈíÓÚÉÏÖÜËijõ´ÎÅû¶ÁËÕâ´Î´¹µö¹¥»÷£¬£¬£¬£¬£¬£¬´ÓÊôÓÚ¶íÂÞ˹µý±¨»ú¹¹SVRµÄNOBELIUM£¨±ðÃûAPT29£©¼ÙÒâUSAID£¬£¬£¬£¬£¬£¬ Ïò150 ¶à¸ö×éÖ¯·¢ËÍÁË3000¶à·â´¹µöÓʼþ¡£¡£¡£¡£¡£Õâ´Î²é·âµÄÁ½¸öÓòÃû±ðÀëΪtheyardservice[.]comºÍworldhomeoutlet[.]com£¬£¬£¬£¬£¬£¬ÖØÒªÓÃÓڽӹܴÓÊܺ¦ÕßÄÇÀïй¶µÄÊý¾Ý£¬£¬£¬£¬£¬£¬²¢·¢ËͺÅÁî¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/us-seizes-domains-used-by-apt29-in-recent-usaid-phishing-attacks/
5¡¢Check Point°ä²¼2021ÄêÑÇÌ«µØÓòÍøÂç¹¥»÷·ÖÎö»ã±¨

Check Point°ä²¼ÁË2021ÄêÑÇÌ«µØÓòÍøÂç¹¥»÷µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬Óë2020Äê5ÔÂÏà±È£¬£¬£¬£¬£¬£¬ÑÇÌ«µØÓò (APAC) µÄÍøÂç¹¥»÷ÊýÁ¿Í¬±ÈÔö³¤ÁË168%£¬£¬£¬£¬£¬£¬¶øÔÚ2021Äê4ÔÂÖÁ5ÔÂÆÚ¼ä¾ÍÔö³¤ÁË53%¡£¡£¡£¡£¡£Ôö·ù×î´óµÄ¶ñÒâÈí¼þÀàÐÍÊÇÀÕË÷Èí¼þºÍÔ¶³Ì½Ó¼ûľÂí (RAT)£¬£¬£¬£¬£¬£¬Óë½ñÄêËêÊ×Ïà±È£¬£¬£¬£¬£¬£¬¶¼Ôö³¤ÁË26%£¬£¬£¬£¬£¬£¬¶øÒøÐÐľÂíºÍÐÅÏ¢ÇÔÈ¡¹¤¾ßÒ²Ôö³¤ÁË10%¡£¡£¡£¡£¡£ÍøÂç¹¥»÷´ÎÊýÔö·ù×î´óµÄǰ5¸ö¹ú¶È/µØÓòÊÇÈÕ±¾£¨40%£©¡¢ÐÂ¼ÓÆÂ£¨30%£©¡¢Ó¡¶ÈÄáÎ÷ÑÇ£¨25%£©¡¢ÂíÀ´Î÷ÑÇ£¨22%£©ºÍÖйų́Í壨17%£©¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.checkpoint.com/2021/05/27/check-point-research-asia-pacific-experiencing-a-168-year-on-year-increase-in-cyberattacks-in-may-2021/


¾©¹«Íø°²±¸11010802024551ºÅ