ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ3ÖÜ
°ä²¼¹¦·ò 2021-01-18> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2021Äê01ÔÂ11ÈÕÖÁ01ÔÂ17ÈÕ¹²ÊÕ¼°²È«·ì϶70¸ö£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Word CVE-2021-1715´úÂëÖ´Ðзì϶£»Siemens JT2Go JT½âÎöÀàÐÍ»ìºÏ´úÂëÖ´Ðзì϶£»Cisco Connected Mobile Experiences CVE-2021-1144ȨÏÞÌáÉý·ì϶£»Adobe Photoshop¶Ñ»º³åÇøÒç³ö´úÂëÖ´Ðзì϶£»Xiaomi AX1800µÇ¼ÑéÖ¤ÈÆ¹ý·ì϶¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÐÂÎ÷À¼´¢ÐîÒøÐÐÔâµ½¹¥»÷£¬£¬£¬Ãô¸ÐÐÅÏ¢»òÒÑй¶£»½áºÏ¹ú»·¾³¹æ»®ÊðµÄGit´æ´¢¿âй¶³¬¹ý10Íò¸öµÄÔ±¹¤ÐÅÏ¢£»Socialarksй¶400GBÊý¾Ý£¬£¬£¬Ó°ÏìÈ«Çò2ÒÚ¶àÓû§£»ÐÂSolarLeaksÍøÕ¾ÏúÊÛSolarWinds¹©¸øÁ´¹¥»÷Öеĺ¹ÇàÊý¾Ý£»SkypeÔÚÈ«ÇòÁìÓòÄÚ·þÎñÖжϣ¬£¬£¬ÔÒòÉв»Ã÷È·¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£
> ÖØÒª°²È«·ì϶Áбí
1.Microsoft Word CVE-2021-1715´úÂëÖ´Ðзì϶
Microsoft Word´æÔÚ°²È«·ì϶£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-1715
2.Siemens JT2Go JT½âÎöÀàÐÍ»ìºÏ´úÂëÖ´Ðзì϶
Siemens JT2Go JTÎļþ½âÎö´æÔÚÀàÐÍ»ìºÏ·ì϶£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£
https://us-cert.cisa.gov/ics/advisories/icsa-21-012-03
3.Cisco Connected Mobile Experiences CVE-2021-1144ȨÏÞÌáÉý·ì϶
Cisco Connected Mobile Experiences¸ü¸ÄÃÜÂëÊÚȨ´æÔÚ°²È«·ì϶£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬¿É¸ü¸ÄËÁÒâÓû§ÃÜÂ룬£¬£¬ÌáÉýÌØÈ¨¡£¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cmxpe-75Asy9k
4.Adobe Photoshop¶Ñ»º³åÇøÒç³ö´úÂëÖ´Ðзì϶
Adobe Photoshop´¦ÖÃÎļþ´æÔÚ¶Ñ»º³åÇøÒç³ö·ì϶£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£
https://helpx.adobe.com/security/products/photoshop/apsb21-01.html
5.Xiaomi AX1800µÇ¼ÑéÖ¤ÈÆ¹ý·ì϶
Xiaomi AX1800´æÔÚ·ÓÉÆ÷ÖØÆôºó¹¦·ò·ÖÆç²½µÄÎÊÌ⣬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬¿ÉÈÆ¹ýµÇ¼Ñé֤δÊÚȨ½Ó¼û¡£¡£
https://privacy.mi.com/trust#/security/vulnerability-management/vulnerability-announcement/detail?id=22&locale=en
> ÖØÒª°²È«ÊÂÎñ×ÛÊö
1¡¢ÐÂÎ÷À¼´¢ÐîÒøÐÐÔâµ½¹¥»÷£¬£¬£¬Ãô¸ÐÐÅÏ¢»òÒÑй¶

λÓÚ»ÝÁé¶ÙµÄÐÂÎ÷À¼´¢ÐîÒøÐÐÓÚÖÜÈÕÐû³ÆÆäÔâµ½¹¥»÷¡£¡£¾ÝϤ£¬£¬£¬¸ÃÒøÐÐÓÃÀ´¹²ÏíºÍ´æ´¢Ãô¸ÐÐÅÏ¢µÄµÚÈý·½Îļþ¹²Ïí·þÎñµÄÊý¾ÝϵͳÔâµ½·ÛË飬£¬£¬ºÚ¿Í¿ÉÄÜÒѾ½Ó¼ûÁËÆäÖеÄóÒ׺ÍСÎÒÃô¸ÐÐÅÏ¢¡£¡£Ä¿Ç°£¬£¬£¬¸ÃϵͳÒѱ»ÍÑ»ú±£»¤£¬£¬£¬Ö±µ½ÒøÐÐʵÏÖÆä³õ´ëÊ©²éΪֹ²Å»á¸´Ô¡£¡£¸ÃÒøÐаµÊ¾ÆäÕýÔÚÈ·¶¨Ð¹Â¶ÐÅÏ¢µÄÁìÓò£¬£¬£¬²¢ÇһؾøÐ¹Â©ÓйØÕâ´Î¹¥»÷¸ü¶àµÄϸ½Ú¡£¡£
ÔÎÄÁ´½Ó£º£º
https://www.securityweek.com/new-zealand-central-bank-hit-cyber-attack
2¡¢½áºÏ¹ú»·¾³¹æ»®ÊðµÄGit´æ´¢¿âй¶³¬¹ý10Íò¸öµÄÔ±¹¤ÐÅÏ¢

¸Ã¹«¿ªµÄgitĿ¼ÖÐÔ̺¬ÁË´óÁ¿Ãô¸ÐÎļþ£¬£¬£¬ÈçÓë»·¾³ÊðºÍ½áºÏ¹ú¹ú¼ÊÀ͹¤×éÖ¯ÆäËûÔÚÏßϵͳÓйصĴ¿Îı¾Êý¾Ý¿âÍ´´¦£¬£¬£¬ÖÎÀíÔ±µÄÊý¾Ý¿âÍ´´¦ºÍ»·¾³ÊðµÄÔ´´úÂë¿âµÈ¡£¡£´ËÍ⣬£¬£¬Õâ´ÎÊÂÎñ»¹Ð¹Â¶ÁËÔ±¹¤µÄPII£¬£¬£¬ÈçÔ±¹¤¹Û¹âº¹Çà¡¢È˶¡Í³¼ÆÊý¾Ý£¨¹ú¼®¡¢ÐÔ±ðºÍн¼¶£©¡¢ÏîÄ¿×ʽðÆðÔ´¼Í¼¡¢Ô±¹¤¼Í¼ºÍ¾ÍÒµÆÀ¹À»ã±¨µÈ¡£¡£
ÔÎÄÁ´½Ó£º£º
https://www.bleepingcomputer.com/news/security/united-nations-data-breach-exposed-over-100k-unep-staff-records/
3¡¢Socialarksй¶400GBÊý¾Ý£¬£¬£¬Ó°ÏìÈ«Çò2ÒÚ¶àÓû§

°²È«¹«Ë¾Safety Detectives·¢ÏÖ£¬£¬£¬Öйú²Ý´´¹«Ë¾Socialarks£¨±¿ÄñÉç½»£©Ð¹Â¶ÁË400GBÊý¾Ý¡£¡£Õâ´ÎÊý¾Ýй¶ÊÇÓÉÓÚElasticSearchÊý¾Ý¿âÉèÖÃÃýÎ󣬣¬£¬Ð¹Â¶ÁË×ܼÆ408GB£¬£¬£¬³¬¹ý3.18ÒÚÌõÓû§¼Í¼£¬£¬£¬Éæ¼°µ½11651162¸öInstagramÓû§¡¢66117839¸öÁìÓ¢Óû§ºÍ81551567¸öFacebookÓû§¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬SocialarksÔÚ2020Äê8ÔÂÒ²²úÉúÁËÀàËÆµÄÊÂÎñ£¬£¬£¬Ð¹Â¶ÁË1.5ÒÚ¸öÓû§µÄСÎÒÊý¾Ý¡£¡£
ÔÎÄÁ´½Ó£º£º
https://www.safetydetectives.com/blog/socialarks-leak-report/
4¡¢ÐÂSolarLeaksÍøÕ¾ÏúÊÛSolarWinds¹©¸øÁ´¹¥»÷Öеĺ¹ÇàÊý¾Ý

ÐÂSolarLeaksÍøÕ¾ÏúÊÛSolarWinds¹©¸øÁ´¹¥»÷ÖÐMicrosoft¡¢Cisco¡¢FireEyeºÍSolarWindsµÈ¹«Ë¾µÄʧÇÔÊý¾Ý¡£¡£¸ÃÍøÕ¾ÒÔ60ÍòÃÀÔªµÄ¼ÛÖµÏúÊÛMicrosoftÔ´´úÂëºÍ´æ´¢¿â£¬£¬£¬ÒÔ5ÍòÃÀÔªµÄ¼ÛÖµÏúÊÛFireEyeµÄÔ´´úÂëºÍºì¶Ó¹¤¾ß£¬£¬£¬ÒÔ25ÍòÃÀÔªµÄ¼ÛÖµÏúÊÛSolarWindsÔ´´úÂëºÍ¿Í»§ÃÅ»§£¬£¬£¬²¢ÒÔ100ÍòÃÀÔªµÄ¼ÛÖµÏúÊÛÈ«Êýй¶Êý¾Ý¡£¡£solarleaks.netÓòÊÇͨ¹ý¶íÂÞ˹Fancy BearºÍCozy BearʹÓõÄÒÑ֪ע²áÉÌNJALLA½øÐÐ×¢²á¡£¡£
ÔÎÄÁ´½Ó£º£º
https://www.bleepingcomputer.com/news/security/solarleaks-site-claims-to-sell-data-stolen-in-solarwinds-attacks/
5¡¢SkypeÔÚÈ«ÇòÁìÓòÄÚ·þÎñÖжϣ¬£¬£¬ÔÒòÉв»Ã÷È·

1ÔÂ13ÈÕÉÏÎ磬£¬£¬SkypeÔÚÈ«ÇòÁìÓòÄÚ·þÎñÖжϣ¬£¬£¬Ä¿Ç°¸ÃÎÊÌâÒѱ»½â¾ö¡£¡£Æ¾¾ÝÔÚÏßÐÂÎÅÆ½Ì¨DownDetectorͳ¼Æ£¬£¬£¬ÖжÏÖØÒª¼¯ÖÐÔÚÃÀ¹ú¡¢Å·ÖÞ¡¢ÑÇÖÞºÍÊÀ½çÆäËûµØÓò¡£¡£Óû§ÔÚ½Ó¼ûSkypeÍøÕ¾Ê±£¬£¬£¬»áÏÔʾÎÒÃÇÎÞ·¨ÊµÏÖÄúµÄÒªÇóµÄÌáÐÑ¡£¡£MicrosoftÔÚSkype״̬ҳÉϰµÊ¾·¢ÏÖÁ˸ÃÎÊÌ⣬£¬£¬ÆäÓ°ÏìÁËSkypeµÇ¼¡¢ºô½Ð¡¢ÐÂÎÅ¡¢ËÑË÷¡¢Òƶ¯¹²Ïí¡¢Ö§¸¶ÏµÍ³¡¢SMSºÍÆäËû·þÎñ¡£¡£ÎÊÌâÏÖÒѸ´Ô£¬£¬£¬Skype¿ÉÔÙ´ÎÁª»ú¡£¡£
ÔÎÄÁ´½Ó£º£º
https://www.bleepingcomputer.com/news/microsoft/skype-is-down-worldwide-microsoft-working-on-issues/


¾©¹«Íø°²±¸11010802024551ºÅ