ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ26ÖÜ
Ðû²¼Ê±¼ä 2021-06-28> ±¾ÖÜÇ徲̬ÊÆ×ÛÊö
2021Äê06ÔÂ21ÈÕÖÁ06ÔÂ27ÈÕ¹²ÊÕ¼Çå¾²Îó²î53¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇWebAccess HMI DesignerÏîÄ¿ÎļþÔ½½çд´úÂëÖ´ÐÐÎó²î£»D-LINK DSL-2888A routerí§ÒâÃÜÂëÐÞ¸ÄÎó²î£»Zoho ManageEngine ADSelfService PlusÃÜÂë¸ü¸Ä´úÂëÖ´ÐÐÎó²î£»Apple macOS CoreText TTFÆÊÎöÕ»Òç³ö´úÂëÖ´ÐÐÎó²î£»WEIDMUELLER Industrial WLAN devices iw_consoleȨÏÞÌáÉýÎó²î¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÑо¿Ö°Ô±ÑÝʾÔõÑùͨ¹ýWiFiÈÈÃÅÀ´¹¥»÷iPhoneÊÖ»ú£»Ñо¿ÍŶӳƽüÆÚÀÕË÷Èí¼þ¹¥»÷Ò»Á¬¼¤Ôö£¬Í¬±ÈÔöÌí93%£»Å²Íþ¾¯·½È·ÈÏÆäÔÚ2018ÄêÔâµ½µÄºÚ¿Í¹¥»÷ÓëAPT31Óйأ»Ñо¿ÍŶÓÔÚPyPI´æ´¢¿â·¢Ã÷¶à¸öÓÃÓÚÍÚ¿óµÄ¶ñÒâÈí¼þ°ü£»Zephyrʵʱ²Ù×÷ϵͳ(RTOS)Çå¾²¸üУ¬ÐÞ¸´¶à¸öÎó²î¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£
> Ö÷ÒªÇå¾²Îó²îÁбí
1.WebAccess HMI DesignerÏîÄ¿ÎļþÔ½½çд´úÂëÖ´ÐÐÎó²î
WebAccess HMI Designer´¦Öóͷ£ÏîÄ¿Îļþ±£´æÔ½½çдÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉʹӦÓóÌÐò±ÀÀ£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë
https://us-cert.cisa.gov/ics/advisories/icsa-21-173-01
2.D-LINK DSL-2888A routerí§ÒâÃÜÂëÐÞ¸ÄÎó²î
D-LINK DSL-2888A router±£´æí§ÒâÃÜÂëÐÞ¸ÄÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÐÞ¸ÄÖÎÀíÔ±ÃÜÂë¡£
https://github.com/EmYiQing/CVE
3.Zoho ManageEngine ADSelfService PlusÃÜÂë¸ü¸Ä´úÂëÖ´ÐÐÎó²î
Zoho ManageEngine ADSelfService Plus¸ü¸ÄÃÜÂë±£´æÇå¾²Îó²î£¬ÔÊÐíÍâµØ¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://www.manageengine.com/products/self-service-password/release-notes.html#6102
4.Apple macOS CoreText TTFÆÊÎöÕ»Òç³ö´úÂëÖ´ÐÐÎó²î
Apple macOS CoreText TTFÆÊÎö±£´æÕ»Òç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉʹӦÓóÌÐò±ÀÀ£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://support.apple.com/HT212147
5.WEIDMUELLER Industrial WLAN devices iw_consoleȨÏÞÌáÉýÎó²î
WEIDMUELLER Industrial WLAN devices iw_console¹¦Ð§±£´æתÒåʧ°ÜÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://cert.vde.com/en-us/advisories/vde-2021-026
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢Ñо¿Ö°Ô±ÑÝʾÔõÑùͨ¹ýWiFiÈÈÃÅÀ´¹¥»÷iPhoneÊÖ»ú
Ñо¿Ö°Ô±Carl SchouÑÝʾÁËÔõÑùͨ¹ýWiFiÈÈÃÅÀ´¹¥»÷iPhoneÊÖ»ú¡£Carl SchouÔÚÅþÁ¬Ð¡ÎÒ˽¼ÒWiFiÈÈÃÅ¡°%p%s%s%s%s%n¡±Ê±£¬·¢Ã÷ËûiPhoneµÄWiFi¹¦Ð§±»½ûÓ㬲¢ÇÒÔÙÒ²ÎÞ·¨ÆôÓÃWiFi¹¦Ð§£¬×ÝÈ»ËûÖØÆô×°±¸»ò¸ü¸ÄÈÈÃÅÃû³Æ¡£Ñо¿Ö°Ô±³Æ£¬Õâ¿ÉÄÜÊÇÊäÈëÆÊÎöÎÊÌâµ¼Öµģ¬µ±WiFiÈÈÃÅÃû³ÆÖб£´æ´øÓС°%¡±µÄ×Ö·û´®Ê±£¬iOS¿ÉÄÜ»á¹ýʧµØ½«¡°%¡±ºóÃæµÄ×ÖĸڹÊÍΪ×Ö·û´®ÃûÌÃ˵Ã÷·û¡£»Ö¸´Wi-Fi¹¦Ð§µÄΨһҪÁìÊÇÖØÖÃiPhoneµÄÍøÂçÉèÖᣱðµÄ£¬¸ÃÎó²îÊÇiPhone¶ÀÍ̵ģ¬ÎÞ·¨ÔÚAndroidÊÖ»úÉÏÖØÏÖ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/iphone-bug-breaks-wifi-when-you-join-hotspot-with-unusual-name/
2¡¢Ñо¿ÍŶӳƽüÆÚÀÕË÷Èí¼þ¹¥»÷Ò»Á¬¼¤Ôö£¬Í¬±ÈÔöÌí93%
Check Point ResearchÑо¿ÍŶӳƽüÆÚÀÕË÷Èí¼þ¹¥»÷Ò»Á¬¼¤Ôö¡£2021Äê6ÔÂÿÖÜÊÜÀÕË÷Èí¼þÓ°ÏìµÄ×éÖ¯ÊýÄ¿ÒÑÔöÖÁ1210¸ö£¬×ÔÄêÍ·ÒÔÀ´£¬ÀÕË÷Èí¼þ¹¥»÷´ÎÊýÔöÌíÁË41%£¬Í¬±ÈÔöÌíÁË93%¡£ÆäÖÐÀ¶¡ÃÀÖÞµÄÀÕË÷Èí¼þ¹¥»÷ʵÑéÔöÌí×îΪÏÔ×Å£¬ÔöÌíÁË62%£¬Æä´ÎÊÇÅ·ÖÞÔöÌíÁË59%£¬·ÇÖÞÔöÌíÁË34%£¬±±ÃÀÔöÌíÁË32%¡£±ðµÄ£¬Õë¶Ô½ÌÓýÐÐÒµµÄ¹¥»÷ÔöÌíËÙÂÊ×î¿ì£¨ÓëÈ¥ÄêͬÆÚÏà±ÈÔöÌíÁË347%£©£¬Æä´ÎΪÔËÊäÐÐÒµ£¨186%£©¡¢ÁãÊÛºÍÅú¿¯ÐÐÒµ£¨162%£©ÒÔ¼°Ò½ÁƱ£½¡ÐÐÒµ£¨159%£©¡£
ÔÎÄÁ´½Ó£º
https://blog.checkpoint.com/2021/06/14/ransomware-attacks-continue-to-surge-hitting-a-93-increase-year-over-year/
3¡¢Å²Íþ¾¯·½È·ÈÏÆäÔÚ2018ÄêÔâµ½µÄºÚ¿Í¹¥»÷ÓëAPT31ÓйØ
ŲÍþ¾¯Ô±Çå¾²¾Ö (PST) ÌåÏÖ£¬ÆäÔÚ2018ÄêÔâµ½µÄÍøÂç¹¥»÷ÓëºÚ¿Í×éÖ¯APT31Óйء£¾ÝÊÓ²ìÏÔʾ£¬Ôڴ˴ι¥»÷ÖкڿÍÒÑÀֳɻñµÃÖÎÀíԱȨÏÞ£¬¿ÉÒÔ»á¼û¸Ã¹úËùÓйú¼ÒÐÐÕþ°ì¹«ÊÒʹÓõÄÖÐÑëÅÌËã»úϵͳ£¬»¹ÀֳɵشӰ칫ÊÒϵͳÇÔÈ¡ÁËһЩÊý¾Ý¡£±ðµÄ£¬Ñо¿Ö°Ô±³Æ£¬APT31»¹±»ÒÔΪÊÇ2020Äê12ÔÂÕë¶Ô·ÒÀ¼Òé»áµÄÍøÂç¹¥»÷µÄÄ»ºóºÚÊÖ£¬Ôڴ˴ι¥»÷ÖкڿÍÀÖ³ÉÈëÇÖÁËһЩÒé»áÏà¹Øµç×ÓÓʼþµÄÕÊ»§¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/119161/apt/norway-blames-china-apt31.html
4¡¢Ñо¿ÍŶÓÔÚPyPI´æ´¢¿â·¢Ã÷¶à¸öÓÃÓÚÍÚ¿óµÄ¶ñÒâÈí¼þ°ü
Ñо¿ÍŶÓÔÚPythonÏîÄ¿µÄPyPI¿âÖз¢Ã÷ÁË6¸ö¶ñÒâÈí¼þ°ü£¬¿ÉÒÔ½«¿ª·¢Ö°Ô±µÄÅÌËã»úÄð³É¿ó»ú¡£ËùÓжñÒâÈí¼þ°ü¾ùÓÉͳһÓû§¡°nedog123¡±Ðû²¼£¬»®·ÖΪmaratlib¡¢maratlib1¡¢matplatlib-plus¡¢mllearnlib¡¢mplatlibºÍlearninglib£¬ÆäÖд󲿷ֵÄÃû³Æ¶¼ÊÇÕýµ±»æͼÈí¼þmatplotlibµÄƴд¹ýʧ°æ±¾£¬ºÚ¿Íͨ¹ýÕâÖÖ·½·¨À´ÓÕÆ¿ª·¢Ö°Ô±ÏÂÔØ¡£Ñо¿Ö°Ô±³Æ¶ñÒâ´úÂ붼ÔÚsetup.pyÎļþÖУ¬Ëü»áÔÚGitHub´æ´¢¿âÏÂÔØBash¾ç±¾(aza2.sh)£¬¸Ã¾ç±¾µÄ×÷ÓÃÊÇÔÚÄ¿µÄ»úеÉÏÔËÐеļÓÃÜ¿ó¹¤Ubqminer¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/malicious-pypi-packages-hijack-dev-devices-to-mine-cryptocurrency/
5¡¢Zephyrʵʱ²Ù×÷ϵͳ(RTOS)Çå¾²¸üУ¬ÐÞ¸´¶à¸öÎó²î
Zephyrʵʱ²Ù×÷ϵͳ(RTOS)Çå¾²¸üУ¬ÐÞ¸´ÁË8¸ö¿ÉÄܵ¼Ö¾ܾø·þÎñ (DoS) ºÍÔ¶³Ì´úÂëÖ´ÐеÄÎó²î¡£ZephyrÊÇСÐ͵Äʵʱ²Ù×÷ϵͳ£¬ÓÃÓÚ×ÊÔ´ÊÜÏÞµÄǶÈëʽ»¥Áª×°±¸£¬»ñµÃÁËFacebook¡¢¹È¸è¡¢IntelµÈ×ÅÃû¹«Ë¾µÄÖ§³Ö£¬Ö§³Ö200¶àÖÖ²î±ðCPU¼Ü¹¹£¨ARM¡¢Cortex-MºÍIntel x86µÈ£©¡£´Ë´ÎÐÞ¸´µÄÎó²î±£´æÓÚZephyrµÄÀ¶ÑÀLEÁ´Â·²ã (LL) ¼°ÆäÂß¼Á´Â·¿ØÖƺÍÊÊÅäÐÒé (L2CAP) ÖУ¬ÆäÖнÏΪÑÏÖصÄÊÇÐÅϢй¶Îó²î£¨CVE-2021-3435£©ºÍDoSÎó²î£¨CVE-2021-3455£©¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/zephyr-rtos-fixes-bluetooth-bugs-that-may-lead-to-code-execution/