ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ37ÖÜ
Ðû²¼Ê±¼ä 2021-09-14>±¾ÖÜÇ徲̬ÊÆ×ÛÊö
2021Äê09ÔÂ06ÈÕÖÁ09ÔÂ12ÈÕ¹²ÊÕ¼Çå¾²Îó²î58¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇApple iOS Wi-Fi»º³åÇøÒç³ö´úÂëÖ´ÐÐÎó²î£»Delta Electronics DOPSoftÏîÄ¿ÎļþÔ½½çдÎó²î£»QNAP NAS CVE-2021-34343Õ»Òç³ö´úÂëÖ´ÐÐÎó²î£»Google Android Frameworkí§Òâ´úÂëÖ´ÐÐÎó²î£»Cisco IOS XR Software CVE-2021-34719ÌØȨÌáÉýÎó²î¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÐÂÎ÷À¼»¥ÁªÍøÔËÓªÉÌVocusÔâµ½´ó¹æÄ£DDoS¹¥»÷£»Google TensorFlowΪÐÞ¸´RCEÎó²î¶ø²»ÔÙÖ§³ÖYAML£»FortiGuardÐû²¼2021ÄêH1È«ÇòÍþв̬ÊƵÄÆÊÎö±¨¸æ£»Î¢ÈíÐû²¼MSHTMLÖÐRCEÎó²î£¨CVE-2021-40444£©µÄͨ¸æ£»Ñо¿Ö°Ô±·¢Ã÷REvilÍÅ»ïµÄÊý¾Ýй¶ÍøÕ¾ÔÙ¶ÈÉÏÏß¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£
>Ö÷ÒªÇå¾²Îó²îÁбí
1.Apple iOS Wi-Fi»º³åÇøÒç³ö´úÂëÖ´ÐÐÎó²î
Apple iOS Wi-Fi±£´æ»º³åÇøÒç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓóÌÐò±ÀÀ£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://support.apple.com/en-us/HT212317
2.Delta Electronics DOPSoftÏîÄ¿ÎļþÔ½½çдÎó²î
Delta Electronics DOPSoft´¦Öóͷ£ÏîÄ¿Îļþ±£´æ»º³åÇøÒç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿Éʹϵͳ±ÀÀ£»òÕßÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://us-cert.cisa.gov/ics/advisories/icsa-21-252-02
3.QNAP NAS CVE-2021-34343Õ»Òç³ö´úÂëÖ´ÐÐÎó²î
QNAP NAS±£´æÕ»Òç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿Éʹϵͳ±ÀÀ£»òÕßÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://www.qnap.com/en/security-advisory/qsa-21-33
4.Google Android Frameworkí§Òâ´úÂëÖ´ÐÐÎó²î
Google Android Framework±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉʹӦÓóÌÐò±ÀÀ£»òÖ´ÐÐí§Òâ´úÂë¡£
https://source.android.com/security/bulletin/2021-09-01
5.Cisco IOS XR Software CVE-2021-34719ÌØȨÌáÉýÎó²î
Cisco IOS XR SoftwareÏÂÁîÐвÎÊýʵÏÖ±£´æÇå¾²Îó²î£¬ÔÊÐíÍâµØ¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÌáÉýȨÏÞ£¬»ñÈ¡ROOTȨÏÞ¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-privescal-dZYMrKf
>Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢ÐÂÎ÷À¼»¥ÁªÍøÔËÓªÉÌVocusÔâµ½´ó¹æÄ£DDoS¹¥»÷
ÐÂÎ÷À¼µÚÈý´ó»¥ÁªÍøÔËÓªÉÌVocus ISP³ÆÆäÔÚ9ÔÂ3ÈÕÔâµ½´ó¹æÄ£DDoS¹¥»÷£¬µ¼Ö·þÎñÖÐÖ¹ÁËÔ¼30·ÖÖÓ¡£VocusÔÚ°Ä´óÀûÑǺÍÐÂÎ÷À¼ÌṩÁãÊÛ¡¢Åú·¢ºÍÆóÒµµçÐÅ·þÎñ¡£¸Ã¹«Ë¾³Æ£¬ÓÉÓÚÏÖÔÚÌìÏ´󲿷ֵØÇø¶¼ÔÚÔ¶³Ì°ì¹«£¬Òò´Ë´Ë´Î¹¥»÷¶Ô¿Í»§±¬·¢ÁËÖØ´óÓ°Ïì¡£Ö®ºó£¬¸Ã¹«Ë¾Ñ¸ËÙ»Ö¸´ÁËÔËÓª£¬²¢¶Ô¸ø¿Í»§´øÀ´µÄδ±ãÌåÏÖǸÒâ¡£
ÔÎÄÁ´½Ó£º
https://www.reuters.com/technology/widespread-internet-outages-hits-users-across-new-zealand-2021-09-03/
2¡¢Google TensorFlowΪÐÞ¸´RCEÎó²î¶ø²»ÔÙÖ§³ÖYAML
Google¿ª·¢µÄ»ùÓÚPythonµÄ»úеѧϰºÍÈ˹¤ÖÇÄÜÏîÄ¿TensorFlowÒѾ·ÅÆúÁ˶ÔYAMLµÄÖ§³Ö¡£TensorFlow´úÂëÖеÄyaml.unsafe_load()º¯Êý±£´æÒ»¸öÎó²î£¬×·×ÙΪCVE-2021-37678£¬ÆÀ·ÖΪ9.3¡£µ±Ó¦Ó÷´ÐòÁл¯YAMLÃûÌõÄKerasÄ£×Óʱ£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂ롣ΪÐÞ¸´´ËÎó²î£¬TensorFlow¾öÒéÍêÈ«·ÅÆúYAMLµÄÖ§³Ö£¬×ª¶øʹÓÃJSON·´ÐòÁл¯¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/googles-tensorflow-drops-yaml-support-due-to-code-execution-flaw/
3¡¢FortiGuardÐû²¼2021ÄêH1È«ÇòÍþв̬ÊƵÄÆÊÎö±¨¸æ
FortiGuardÓÚ8Ô·ÝÐû²¼ÁË2021ÄêH1È«ÇòÍþв̬ÊƵÄÆÊÎö±¨¸æ¡£±¨¸æÖ¸³ö£¬2021Äê6ÔÂƽ¾ùÿÖÜÀÕË÷Èí¼þÔ˶¯±ÈÒ»ÄêǰͬÆÚºá¿ç10.7±¶¡£ÆäÖУ¬µçÐÅÐÐÒµÊǹ¥»÷ÕßµÄÖ÷ÒªµÄÄ¿µÄ£¬Æä´ÎÊÇÕþ¸®¡¢ÍйÜÇå¾²·þÎñÌṩÉÌ¡¢Æû³µºÍÖÆÔìÐÐÒµ¡£½©Ê¬ÍøÂçÒ²ÓÐËùÔöÌí£¬½ñÄêÄêÍ·ÔÚ35%µÄ×éÖ¯Öмì²âµ½Á˽©Ê¬ÍøÂçÔ˶¯£¬¶øÕâÒ»±ÈÀýÔÚ6¸öÔºóÔöÌíΪ51%¡£±ðµÄ£¬¹¥»÷Õ߸üÇàíùÓÚ¼ì²âÈƹýÊÖÒÕºÍÌáȨÊÖÒÕ¡£
ÔÎÄÁ´½Ó£º
https://www.fortinet.com/content/dam/fortinet/assets/threat-reports/report-threat-landscape-2021.pdf
4¡¢Î¢ÈíÐû²¼MSHTMLÖÐRCEÎó²î£¨CVE-2021-40444£©µÄͨ¸æ
΢ÈíÍŶÓÔÚ9ÔÂ7ÈÕÐû²¼ÁËÕë¶ÔWindowsÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-40444£©µÄ»º½â²½·¥¡£¸ÃÎó²î±£´æÓÚMicrosoft OfficeÎĵµÊ¹ÓõÄä¯ÀÀÆ÷äÖȾÒýÇæMSHTMLÖУ¬ÒÑÔÚÕë¶ÔWindows 10ÉϵÄOffice 365ºÍOffice 2019µÄ¹¥»÷Ô˶¯Öб»Ê¹Óá£ÏÖÔÚÉÐÎÞ¿ÉÓõÄÇå¾²¸üУ¬Microsoft½¨Òé½ûÓÃInternet ExplorerÖÐËùÓеÄActiveX¿Ø¼þ×÷Ϊ»º½â²½·¥¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-shares-temp-fix-for-ongoing-office-365-zero-day-attacks/
5¡¢Ñо¿Ö°Ô±·¢Ã÷REvilÍÅ»ïµÄÊý¾Ýй¶ÍøÕ¾ÔÙ¶ÈÉÏÏß
Ñо¿Ö°Ô±·¢Ã÷REvilÍÅ»ïµÄÊý¾Ýй¶ÍøÕ¾£¨Ò²³ÆΪ Happy Blog£©ÔÚ9ÔÂ7ÈÕÖØÐÂÉÏÏß¡£7ÔÂ2ÈÕ£¬REvilʹÓÃKaseya VSAÖеÄÎó²î¹¥»÷ÁËԼĪ60¼ÒMSP¼°Æä1500¶à¸ö¿Í»§£¬²¢ÀÕË÷7000ÍòÃÀÔª¡£Ö®ºó£¬¸Ã×éÖ¯ÒýÆðÁËÖ´·¨²¿·ÖµÄ×¢ÖØ£¬²¢ÔÚ7ÔÂ13¹Ø±ÕÁËËùÓеÄTor·þÎñÆ÷ºÍ»ù´¡ÉèÊ©¡£Éв»ÇåÎú´Ë´ÎÖ§¸¶ºÍÊý¾Ýй¶ÍøÕ¾µÄÖØÐÂÉÏÏߣ¬ÊÇ·ñ´ú±íןÃÍÅ»ïÒª×îÏȸ´³ö¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/revil-ransomwares-servers-mysteriously-come-back-online/