ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ9ÖÜ
Ðû²¼Ê±¼ä 2021-03-01> ±¾ÖÜÇ徲̬ÊÆ×ÛÊö
2021Äê02ÔÂ22ÈÕÖÁ02ÔÂ28ÈÕ¹²ÊÕ¼Çå¾²Îó²î53¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇNETGEAR Nighthawk R7800Ó²±àÂëÑéÖ¤ÈƹýÎó²î£»Siemens SINEC NMS FirmwareFileUtils extractToFolderĿ¼±éÀú´úÂëÖ´ÐÐÎó²î£»TP-Link AC1750 sync-serverÕ»Òç³öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£»On Netshield NANO CVE-2021-3149ÏÂÁî×¢ÈëÎó²î£»Adobe Bridge CVE-2021-21065Ô½½çд´úÂëÖ´ÐÐÎó²î¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇ΢Èí·¢Ã÷Windows Win32kÌáȨ0dayÒѱ»ÔÚҰʹÓã»Ð¶ñÒâÈí¼þSilver SparrowÒÑѬȾ½ü3Íǫ̀Mac×°±¸£»FireEye³ÆÕë¶ÔAccellion FTAµÄ¹¥»÷ÓëFIN11Óйأ»·É»úÖÆÔìÉÌBombardier³ÆÆäÊý¾ÝÒÑÔÚClopÍøÕ¾ÉϹûÕ棻·ÒÀ¼TietoEVRYÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬¿Í»§·þÎñÔÝʱÖÐÖ¹¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£
> Ö÷ÒªÇå¾²Îó²îÁбí
1.NETGEAR Nighthawk R7800Ó²±àÂëÑéÖ¤ÈƹýÎó²î
NETGEAR Nighthawk R7800 apply_save.cgiʹÓÃÓ²±àÂëÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔROOTȨÏÞÖ´ÐÐí§Òâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-252/
2.Siemens SINEC NMS FirmwareFileUtils extractToFolderĿ¼±éÀú´úÂëÖ´ÐÐÎó²î
Siemens SINEC NMS FirmwareFileUtils extractToFolder±£´æĿ¼±éÀúÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔWEBÓ¦ÓóÌÐòÉÏÏÂÎĶÁÈ¡Ãô¸ÐÐÅÏ¢¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-253/
3.TP-Link AC1750 sync-serverÕ»Òç³öÔ¶³Ì´úÂëÖ´ÐÐÎó²î
TP-Link AC1750 sync-server MACµØµã´¦Öóͷ£±£´æÕ»Òç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔROOTȨÏÞÖ´ÐÐí§Òâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-215/
4.On Netshield NANO CVE-2021-3149ÏÂÁî×¢ÈëÎó²î
On Netshield NANO /usr/local/webmin/System/manual_ping.cgi±£´æÊäÈëÑéÖ¤Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔWEBÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://www.digitaldefense.com/resources/vulnerability-research/netshield-corporation-nano-25/
5.Adobe Bridge CVE-2021-21065Ô½½çд´úÂëÖ´ÐÐÎó²î
Adobe Bridge´¦Öóͷ£Îļþ±£´æÔ½½çдÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉʹӦÓóÌÐò±ÀÀ£»ò¿ÉÖ´ÐÐí§Òâ´úÂë¡£
https://helpx.adobe.com/security/products/bridge/apsb21-07.html
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢Î¢Èí·¢Ã÷Windows Win32kÌáȨ0dayÒѱ»ÔÚҰʹÓÃ
΢Èí·¢Ã÷Windows Win32kÖеÄÌáȨ0day£¨CVE-2021-1732£©Òѱ»ÔÚҰʹÓ᣸ÃÎó²î±£´æÓÚwin32k.sys½¹µãÄÚºË×é¼þÖУ¬¹¥»÷Õß¿Éͨ¹ý´¥·¢ÊͷźóʹÓÃÎó²î½«ÆäȨÏÞÌáÉýµ½admin¼¶±ð£¬¾ßÓлù±¾Óû§È¨Ï޵Ĺ¥»÷Õß²»ÐèÒªÓëÓû§½»»¥¼´¿ÉʹÓøÃÎó²î¡£¾ÝÊӲ죬¸ÃÎó²îÒѱ»APT×éÖ¯BitterºÍT-APT-17ʹÓã¬DBAPPSecurityÔò³ÆÆäÓÚ12Ô·¢Ã÷ÁË¿ª·¢ÈÕÆÚΪ2020Äê5ÔµÄÑù±¾¡£¶ø×Ô2021Äê2ÔÂ×îÏÈ£¬ºÚ¿ÍÖ»ÔÚÉÙÊýÕë¶ÔÖж«µÄ¹¥»÷ÖÐʹÓÃÁËCVE-2021-1732Îó²î¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/recently-fixed-windows-zero-day-actively-exploited-since-mid-2020/
2¡¢Ð¶ñÒâÈí¼þSilver SparrowÒÑѬȾ½ü3Íǫ̀Mac×°±¸
Red CanaryÑо¿Ö°Ô±·¢Ã÷Õë¶ÔMac×°±¸µÄжñÒâÈí¼þSilver Sparrow¡£×èÖ¹2ÔÂ17ÈÕ£¬Silver SparrowÒÑÔÚ153¸ö¹ú¼ÒºÍµØÇøѬȾÁË29139¸ömacOSÖնˣ¬²¢ÔÚÃÀ¹ú¡¢Ó¢¹ú¡¢¼ÓÄô󡢷¨¹úºÍµÂ¹ú´ó×ÚÈö²¥¡£Óë´ó´ó¶¼Ê¹ÓÃ'preinstall'ºÍ'postinstall'¾ç±¾µÄ¶ñÒâÈí¼þ²î±ð£¬Silver SparrowʹÓÃJavaScriptÖ´ÐÐÏÂÁ´Ó¶øºÜÄÑƾ֤ÏÂÁîÐвÎÊý¼ì²â¶ñÒâÔ˶¯¡£±ðµÄ£¬¸Ã¶ñÒâÈí¼þµÄÕæÕýÄ¿µÄÏÖÔÚÈÔÈ»ÊǸöÃÕ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/30000-macs-infected-with-new-silver-sparrow-malware/
3¡¢FireEye³ÆÕë¶ÔAccellion FTAµÄ¹¥»÷ÓëFIN11ÓйØ
Çå¾²¹«Ë¾FireEye³Æ£¬2020Äê12Ôµ½2021Äê1ÔÂÖ®¼äʹÓÃAccellion FTA·þÎñÆ÷ÖÐ0dayµÄ¹¥»÷Ô˶¯ÓëFIN11Óйأ¬²¨¼°ÁËÈ«ÇòÔ¼100¼Ò¹«Ë¾¡£ºÚ¿ÍÖ÷ҪʹÓÃÁËËĸöÎó²îÀ´¹¥»÷FTA·þÎñÆ÷£¬²¢×°ÖÃÁËÒ»¸öÃûΪDEWMODEµÄWeb Shell£¬À´ÏÂÔØÊܺ¦ÕßFTA×°±¸ÉÏ´æ´¢µÄÎļþ¡£ÊÜÓ°ÏìµÄ¹«Ë¾ºÍ×éÖ¯°üÀ¨Fugro¡¢Danaher¡¢Singtel¡¢Jones¡¢ÐÂÎ÷À¼´¢±¸ÒøÐкͰĴóÀûÑÇ֤ȯºÍͶ×ÊίԱ»á£¨ASIC£©µÈ¡£±ðµÄ£¬ºÚ¿ÍÔÚClopµÄÊý¾Ýй¶ÍøÕ¾ÉÏÁгöÁ˲¿·Ö¹«Ë¾£¬ÒÔÚ²ÆÀÕË÷¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/attacks-targeting-accellion-product-linked-fin11-cybercrime-group
4¡¢·É»úÖÆÔìÉÌBombardier³ÆÆäÊý¾ÝÒÑÔÚClopÍøÕ¾ÉϹûÕæ
¼ÓÄôó·É»úÖÆÔìÉÌBombardier³ÆÆäÊý¾ÝÒÑÔÚClopÍøÕ¾ÉϹûÕæ¡£¸Ã¹«Ë¾ÔÚͨ¸æÖÐÌåÏÖ£¬¾³õ³ÌÐò²é£¬ºÚ¿ÍʹÓÃÁ˵ÚÈý·½Îļþ´«ÊäÓ¦ÓÃÖеÄÎó²îÀ´»á¼ûºÍÇÔÈ¡Êý¾Ý¡£Ö»¹Ü²¢Ã»ÓÐÏêϸָ³ö¸Ã×°±¸µÄÃû³Æ£¬µ«¾ÝÍƲâºÜ¿ÉÄÜÊÇÖ¸µÄAccellion FTA¡£±»µÁÊý¾ÝÒÑÔÚÀÕË÷ÍÅ»ïClopµÄÊý¾Ýй¶ÍøÕ¾¹ûÕ棬°üÀ¨BombardierÖÖÖÖ·É»úºÍ·É»úÁã¼þµÄÉè¼ÆÎļþ£¬²¢Ã»ÓÐÈκÎСÎÒ˽¼ÒÊý¾Ýй¶¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/airplane-maker-bombardier-data-posted-on-ransomware-leak-site-following-fta-hack/
5¡¢·ÒÀ¼TietoEVRYÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬¿Í»§·þÎñÔÝʱÖÐÖ¹
·ÒÀ¼IT·þÎñ¹«Ë¾TietoEVRYÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬¿Í»§·þÎñÔÝʱÖÐÖ¹¡£TietoEVRYÊÇÒ»¼ÒÈí¼þ¿ª·¢ºÍIT·þÎñ¹«Ë¾£¬ÔÚ80¸ö¹ú¼ÒºÍµØÇøÓµÓÐ24000ÃûÔ±¹¤£¬2019ÄêµÄÊÕÈëΪ29.5ÒÚÅ·Ôª¡£±¾ÖÜÒ»£¬TietoEVRYµÄÁãÊÛ¡¢ÖÆÔìºÍ·þÎñÏà¹ØÐÐÒµµÄ25¸ö¿Í»§ÌåÏÖÆäÓöµ½ÁËÊÖÒÕÎÊÌ⣬ØʺóµÃÖªÕâЩÎÊÌâÊÇÓÉÀÕË÷Èí¼þ¹¥»÷ÒýÆðµÄ¡£TietoEVRY·¢Ã÷¹¥»÷ºóÁ¬Ã¦¹Ø±ÕÁËÊÜÓ°ÏìµÄϵͳºÍ·þÎñ£¬²¢ÓëµØ·½Õþ¸®¶Ô´ËÊÂÕö¿ªÊӲ졣
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/finnish-it-services-giant-tietoevry-discloses-ransomware-attack/