ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ50ÖÜ
Ðû²¼Ê±¼ä 2021-12-13>±¾ÖÜÇ徲̬ÊÆ×ÛÊö
±¾Öܹ²ÊÕ¼Çå¾²Îó²î60¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇApache Log4j2í§Òâ´úÂëÖ´ÐÐÎó²î£»Tencent WeChat WXAM DecoderÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î£»Google golang ForrkExec¾Ü¾ø·þÎñÎó²î£»Mozilla Firefox file picker dialogÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î£»Veritas Enterprise Vault CVE-2021-44680´úÂëÖ´ÐÐÎó²î¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇmagnatʹÓÃαÔìµÄWeChatµÈ×°ÖóÌÐò·Ö·¢ºóÃÅ£»MailGuard·¢Ã÷ÒÔ΢ÈíÀ¬»øÓʼþ֪ͨΪÖ÷ÌâµÄ´¹ÂÚÔ˶¯£»Googleµ·»Ù¿ØÖÆ×ÅÁè¼Ý100Íǫ̀װ±¸µÄ½©Ê¬ÍøÂçGlupteba£»SonicWallÐû²¼¸üУ¬ÐÞ¸´SMA 100ϵÁÐÖжà¸öÎó²î£»ÐÂÀÕË÷Èí¼þCerberÃé×¼ConfluenceºÍGitLab·þÎñÆ÷¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£
>Ö÷ÒªÇå¾²Îó²îÁбí
1. Apache Log4j2í§Òâ´úÂëÖ´ÐÐÎó²î
Apache Log4j2±£´æJava JNDI×¢ÈëÎó²î£¬µ±³ÌÐò½«Óû§ÊäÈëµÄÊý¾Ý¾ÙÐÐÈÕÖ¾¼Í¼£¬¼´¿É´¥·¢´ËÎó²î£¬ÀÖ³ÉʹÓôËÎó²î¿ÉÒÔÔÚÄ¿µÄ·þÎñÆ÷ÉÏÖ´ÐÐí§Òâ´úÂë¡£
https://github.com/apache/logging-log4j2/commit/7fe72d6
2. Tencent WeChat WXAM DecoderÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î
Tencent WeChat WXAM Decoder±£´æÊͷźóʹÓÃÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉʹӦÓóÌÐò±ÀÀ£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-1446/
3. Google golang ForrkExec¾Ü¾ø·þÎñÎó²î
Google golang ForrkExec´¦Öóͷ£±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿Éʹ·þÎñ³ÌÐòÍ߽⣬Ôì³É¾Ü¾ø·þÎñ¹¥»÷¡£
https://github.com/golang/go/commit/99950270f3cf52cccc6966d8668ff21b573bb6f5
4. Mozilla Firefox file picker dialogÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î
Mozilla Firefox file picker dialog±£´æÊͷźóʹÓÃÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄwebÒ³ÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉʹӦÓóÌÐò±ÀÀ£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://www.mozilla.org/en-US/security/advisories/mfsa2021-48/
5. SVeritas Enterprise Vault CVE-2021-44680´úÂëÖ´ÐÐÎó²î
Veritas Enterprise VaultÓ¦ÓÃÆô¶¯·þÎñ±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://www.veritas.com/content/support/en_US/security/VTS21-003
>Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢magnatʹÓÃαÔìµÄWeChatµÈ×°ÖóÌÐò·Ö·¢ºóÃÅ
Cisco TalosÔÚ12ÔÂ3ÈÕ¹ûÕæÁËmagnatµÄ¹¥»÷Ô˶¯¡£´Ë´Î¹¥»÷ʼÓÚ2018Äêµ×£¬×Ô2021Äê4ÔÂÒÔÀ´µÖ´ï·åÖµ£¬Ö÷ÒªÕë¶Ô¼ÓÄôó£¬Æä´ÎÊÇÃÀ¹ú¡¢°Ä´óÀûÑÇ¡¢Òâ´óÀû¡¢Î÷°àÑÀ¡¢Å²ÍþµÈ¹ú¡£¹¥»÷ÕßʹÓÃαÔìµÄViber¡¢WeChat¡¢NoxPlayerºÍBattlefieldµÈÓ¦ÓúÍÓÎÏ·µÄ×°ÖóÌÐò£¬ÓÕʹĿµÄÏÂÔغóÃųÌÐòºÍ¶ñÒâChromeÀ©Õ¹³ÌÐò£¬×îÖÕ»áÇÔȡƾ֤¡¢ÏµÍ³ÖеÄÃô¸ÐÊý¾ÝÒÔ¼°Ô¶³Ì»á¼ûȨÏÞ¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2021/12/magnat-campaigns-use-malvertising-to.html
2¡¢MailGuard·¢Ã÷ÒÔ΢ÈíÀ¬»øÓʼþ֪ͨΪÖ÷ÌâµÄ´¹ÂÚÔ˶¯
ÓʼþÇå¾²¹«Ë¾MailGuardÔÚ12ÔÂ2ÈÕ·¢Ã÷ÒÔ΢ÈíÀ¬»øÓʼþ֪ͨΪÖ÷ÌâµÄ´¹ÂÚÔ˶¯¡£ÕâЩÓʼþ·¢ËÍ×Ôquarantine[at]messaging.microsoft.com£¬ÏÔʾµÄÃû³ÆÊÇÊÕ¼þÈ˵ÄÓò£¬Í¨¹ýÕâÖÖ·½·¨À´ÔöÌíÆä¿ÉÐŶȡ£¸Ã´¹ÂÚÓʼþÌáÐÑÄ¿µÄÓб»¸ôÀëµÄÀ¬»øÓʼþ£¬µ±Ä¿µÄµã»÷Éó²éºó»á±»Öض¨Ïòµ½´¹ÂÚÍøÕ¾²¢±»ÒªÇóÊäÈëOffice 365ƾ֤¡£Î¢Èí¹«Ë¾ÔÚ8Ô·Ý͸¶£¬×Ô2020Äê7ÔÂ×îÏȵÄÓã²æʽ´¹ÂÚÔ˶¯¶à´ÎÕë¶ÔOffice 365Óû§¡£
ÔÎÄÁ´½Ó£º
https://www.mailguard.com.au/blog/scammers-mimic-microsoft-with-spam-notification-phishing-email
3¡¢Googleµ·»Ù¿ØÖÆ×ÅÁè¼Ý100Íǫ̀װ±¸µÄ½©Ê¬ÍøÂçGlupteba
GoogleÔÚ12ÔÂ7ÈÕÐû²¼ÆäÒѵ·»Ù¿ØÖÆ×ÅÁè¼Ý100Íǫ̀װ±¸µÄ½©Ê¬ÍøÂçGlupteba¡£Glupteba×Ô2011ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬ÊÇÒ»ÖÖÖ§³ÖÇø¿éÁ´µÄÄ£¿é»¯¶ñÒâÈí¼þ£¬Ö÷ÒªÕë¶ÔÃÀ¹ú¡¢Ó¡¶È¡¢°ÍÎ÷ºÍ¶«ÄÏÑǵĹú¼Ò£¬ÌìÌìÐÂÔöѬȾװ±¸µÄÊýÄ¿¸ß´ïÊýǧ̨¡£¸Ã½©Ê¬ÍøÂçÖ÷Ҫͨ¹ýÆƽâ»òµÁ°æÈí¼þºÍPPI¼Æ»®Èö²¥£¬Ñ¬È¾Ä¿µÄºó»áÇÔÈ¡¼ÓÃÜÇ®±Ò¡¢Óû§Æ¾Ö¤ºÍcookie£¬²¢ÔÚÄ¿µÄ×°±¸ÉÏ°²ÅÅÊðÀí£¬Ëæºó³öÊÛ¸øÆäËû¹¥»÷Õß¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/google-disrupts-massive-glupteba-botnet-sues-russian-operators/
4¡¢SonicWallÐû²¼¸üУ¬ÐÞ¸´SMA 100ϵÁÐÖжà¸öÎó²î
SonicWallÔÚ12ÔÂ7ÈÕÐû²¼¸üУ¬ÐÞ¸´SMA 100ϵÁÐ×°±¸ÖеĶà¸öÎó²î¡£´Ë´ÎÐÞ¸´µÄ×îΪÑÏÖصÄÎó²îÊÇ»ùÓÚ¿ÍÕ»µÄ»º³åÇøÒç³öÎó²î£¨CVE-2021-20038£©£¬CVSSÆÀ·ÖΪ9.8£¬ÓÉÓÚ×°±¸µÄApache httpd·þÎñÆ÷ÖеÄHTTP GETÒªÁìµÄÇéÐαäÁ¿Ê¹ÓÃÁËstrcat()º¯Êýµ¼Öµģ»Æä´ÎÊÇ»º³åÇøÒç³öÎó²î£¨CVE-2021-20045£©£¬CVSSÆÀ·Ö9.4¡£±ðµÄ£¬»¹ÐÞ¸´ÁË»º³åÇøÒç³öÎó²î£¨CVE-2021-20043£©ºÍÈÏÖ¤ÏÂÁî×¢ÈëÎó²î£¨CVE-2021-20039£©µÈ¡£
ÔÎÄÁ´½Ó£º
https://www.cisa.gov/uscert/ncas/current-activity/2021/12/08/sonicwall-releases-security-advisory-sma-100-series-appliances
5¡¢ÐÂÀÕË÷Èí¼þCerberÃé×¼ConfluenceºÍGitLab·þÎñÆ÷
12ÔÂ7ÈÕ£¬Ñо¿Ö°Ô±·¢Ã÷ʹÓÃÁ˾ÉÃû³ÆµÄÐÂÀÕË÷Èí¼þCerber¡£ÀÕË÷Èí¼þCerberÓÚ2016Äê·ºÆð£¬Ö±µ½2019Äêµ×ÏûÊÅ¡£´ÓÉϸöÔÂ×îÏÈ£¬Cerbe»Ø¹é£¬¿ÉÊÇËüÓë¾É°æ²¢²»Ïàͬ£¬´úÂ벻ƥÅ䣬аæʹÓÃCrypto+++¿â¶ø¾É°æ±¾Ê¹ÓÃWindows CryptoAPI¿â£¬²¢ÇҾɰæCerberҲûÓÐLinux±äÌå¡£ÐÂCerberµÄÊê½ðÒªÇó´Ó1000ÃÀÔªµ½3000ÃÀÔª²»µÈ£¬Ê¹ÓÃÁËCVE-2021-26084ºÍCVE-2021-22205Îó²îÃé×¼ConfluenceºÍGitLab·þÎñÆ÷£¬Ö÷ÒªÕë¶ÔÃÀ¹ú¡¢µÂ¹úºÍÖйú¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-cerber-ransomware-targets-confluence-and-gitlab-servers/