ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ29ÖÜ

°ä²¼¹¦·ò 2021-07-19

±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2021Äê07ÔÂ12ÈÕÖÁ07ÔÂ18ÈÕ¹²ÊÕ¼°²È«·ì϶70¸ö£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows Defender CVE-2021-34522´úÂë×¢Èë·ì϶£»£»SAP NetWeaver ABAP Server²»ÕýÈ·ÑéÖ¤·ì϶£»£»Adobe Illustrator CVE-2021-28591Ô½½çд´úÂëÖ´Ðзì϶£»£»Fortinet FortiSandbox OSºÅÁî×¢Èë·ì϶£»£»Schneider Electric EVlink Charging StationsÓ²±àÂëÑéÖ¤ÈÆ¹ý·ì϶¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇMint Mobile³ÆÆä²úÉúÊý¾Ýй¶£¬£¬ÇÒ²¿Ãſͻ§±»×ªÍø£»£»×êÑÐÈËÔ±Åû¶½üÆÚ¼ÙÒâ¶íÂÞ˹µ±¾ÖµÄ´¹µö¹¥»÷»î¶¯£»£»Kaseya°²È«¸üÐÂÐÞ¸´REvilÔÚ¹©¸øÁ´¹¥»÷ÖÐÓõÄ0day£»£»Î¢Èí°ä²¼7Ô·ݰ²È«¸üУ¬£¬ÐÞ¸´9¸ö0dayÔÚÄÚµÄ117¸ö·ì϶£»£»SolarWindsÐÞ¸´Serv-UÖÐÒѱ»ÀûÓõÄÔ¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£


> ÖØÒª°²È«·ì϶Áбí


1.Microsoft Windows Defender CVE-2021-34522´úÂë×¢Èë·ì϶


Microsoft Windows Defender´æÔÚ°²È«·ì϶£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-34522


2.SAP NetWeaver ABAP Server²»ÕýÈ·ÑéÖ¤·ì϶


SAP NetWeaver ABAP Server´æÔÚ²»ÕýÈ·ÑéÖ¤·ì϶£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬¿ÉδÊÚȨ½Ó¼ûÀûÓᣡ£¡£

https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=580617506


3.Adobe Illustrator CVE-2021-28591Ô½½çд´úÂëÖ´Ðзì϶


Adobe Illustrator´æÔÚÔ½½çд·ì϶£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬ÓÕʹÓû§½âÎö£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£

https://helpx.adobe.com/security/products/illustrator/apsb21-42.html


4.Fortinet FortiSandbox OSºÅÁî×¢Èë·ì϶


Fortinet FortiSandboxÐá̽Ä£¿£¿£¿é´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬Äܹ»ÀûÓøߵÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£

https://www.auscert.org.au/bulletins/ESB-2021.2385


5.Schneider Electric EVlink Charging StationsÓ²±àÂëÑéÖ¤ÈÆ¹ý·ì϶


Schneider Electric EVlink Charging Stations COOKIE´æÔÚÓ²±àÂë·ì϶£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬¿ÉδÊÚȨÒÔÖÎÀíÔ±¸ßµÍÎĽӼûϵͳ¡£¡£¡£

https://packetstormsecurity.com/files/163505/Schneider-Electric-EVlink-Charging-Stations-Authentication-Bypass-Code-Execution.html


> ÖØÒª°²È«ÊÂÎñ×ÛÊö


1¡¢ ¡¢Mint Mobile³ÆÆä²úÉúÊý¾Ýй¶£¬£¬ÇÒ²¿Ãſͻ§±»×ªÍø


1.jpg


Mint Mobile³Æ½üÆÚ²úÉúÊý¾Ýй¶ÊÂÎñ£¬£¬ÇÒ²¿Ãſͻ§±»×ªµ½ÁíÒ»¼ÒÔËÓªÉ̵ÄÍøÂçÏ¡£¡£¡£¹¥»÷²úÉúÔÚ6ÔÂ8ÈÕÖÁ10ÈÕÖ®¼ä£¬£¬ÓÐδ¾­ÊÚȨµÄ¹¥»÷Õß½Ó¼ûÁËMint MobileÓû§µÄÐÅÏ¢£¬£¬Ô̺¬Í¨»°¼Í¼¡¢ ¡¢ÐÕÃû¡¢ ¡¢µØÖ·¡¢ ¡¢Õ˵¥½ð¶î¡¢ ¡¢¹ú¼Êµç»°¾ßÌåÐÅÏ¢ÐÅÏ¢¡¢ ¡¢µç×ÓÓʼþºÍÃÜÂëµÈ¡£¡£¡£ÔçÔÚ1Ô·Ý£¬£¬USCellularÒ²¾­ÀúÁËÒ»´ÎÀàËÆµÄ¹¥»÷£¬£¬¹¥»÷ÕßÓÕʹÔËÓªÉÌÔ±¹¤ÏÂÔØÄܹ»Ô¶³Ì½Ó¼û¹«Ë¾É豸µÄÈí¼þ£¬£¬¶øºóͨ¹ý¿Í»§¹ØÏµÖÎÀí (CRM) Èí¼þ½Ó¼ûÓû§µÄСÎÒÐÅÏ¢²¢×ªÍø¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/mint-mobile-hit-by-a-data-breach-after-numbers-ported-data-accessed/


2¡¢ ¡¢×êÑÐÈËÔ±Åû¶½üÆÚ¼ÙÒâ¶íÂÞ˹µ±¾ÖµÄ´¹µö¹¥»÷»î¶¯


2.jpg


×êÑÐÈËÔ±Åû¶Á˽üÆÚ´óÁ¿¼ÙÒâ¶íÂÞ˹µ±¾ÖµÄ´¹µö¹¥»÷»î¶¯¡£¡£¡£ÆäÖУ¬£¬Kaspersky·¢ÏÖ¼Ù×°³ÉÀ´×Ô¶íÂÞ˹µ±¾ÖµÄºÏ·¨Óòwebmaster@gov.ruµÄ´¹µö»î¶¯£¬£¬²¢°µÊ¾ÕâÀ๥»÷ͨ³£±È´ó¹æÄ£¹¥»÷¸ü¸´ÔÓ£¬£¬»¹Ê¹ÓÃÁË×éÖ¯ÖÐÔ±¹¤µÄÕæÊµÐÕÃûºÍµç»°ºÅÂë¡£¡£¡£SearchInformÐÅÏ¢°²È«ÊýÃÅ·¢ÏÖÁ˼Ù×°³É˰Îñ»ú¹ØµÄ´¹µöÓʼþ¡£¡£¡£Í¬Ê±£¬£¬¶íÂÞ˹¹ú¶ÈÍøÂçRSNetµÄÖÎÀí²¿ÃÅÒ²°ä²¼ÖҸ棬£¬½¨Òé²»Òª´ò¿ªÀ´×ÔRSNetºÏ·¨Óû§»òRSNetÖÎÀíÈËÔ±µÄÓʼþ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/07/cyber-criminals-sending-phishing-mails.html


3¡¢ ¡¢Kaseya°²È«¸üÐÂÐÞ¸´REvilÔÚ¹©¸øÁ´¹¥»÷ÖÐÓõÄ0day


3.jpg


Kaseya°ä²¼°²È«¸üУ¬£¬ÐÞ¸´REvilÔÚ¹©¸øÁ´¹¥»÷ÖÐÓõÄ0day¡£¡£¡£4Ô£¬£¬ºÉÀ¼·ì϶Åû¶×êÑÐËù (DIVD)Åû¶ÁËKaseyaµÄ7¸ö·ì϶¡£¡£¡£Ö®ºó£¬£¬Kaseya¶ÔÆäVSA SaaS·þÎñÉϵĴó²¿ÃÅ·ì϶°ä²¼Á˲¹¶¡£¬£¬µ«ÉÐδʵÏÖÄÚ²¿°æ±¾VSAµÄ²¹¶¡¡£¡£¡£¶øREvilÍÅ»ïÏÈÒ»²½ÀûÓÃÁËÕâЩ·ì϶£¬£¬ÓÚ7ÔÂ2ÈÕ¶ÔԼĪ60¸öMSPºÍ1500¼ÒÆóÒµ¿Í»§ÌáÒéÁË´ó¹æÄ£¹¥»÷¡£¡£¡£Ä¿Ç°£¬£¬Kaseya°ä²¼ÁËVSA 9.5.7a (9.5.7.2994) ¸üÐÂÒÔÐÞ¸´REvilʹÓõķì϶£¬£¬Ô̺¬CVE-2021-30116¡¢ ¡¢CVE-2021-30119ºÍCVE-2021-30120µÈ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/kaseya-patches-vsa-vulnerabilities-used-in-revil-ransomware-attack/


4¡¢ ¡¢Î¢Èí°ä²¼7Ô·ݰ²È«¸üУ¬£¬ÐÞ¸´9¸ö0dayÔÚÄÚµÄ117¸ö·ì϶


4.jpg


΢Èí°ä²¼ÁË2021Äê7Ô·ݵÄÖܶþ²¹¶¡£¬£¬ÐÞ¸´ÁËÔ̺¬9¸ö0dayÔÚÄÚµÄ117¸ö·ì϶¡£¡£¡£ÕâЩ·ì϶ÖУ¬£¬44¸öΪԶ³Ì´úÂëÖ´ÐУ¬£¬32¸öΪÌáȨ·ì϶£¬£¬14¸öΪÐÅϢй¶·ì϶£¬£¬12¸öΪ»Ø¾ø·þÎñ·ì϶£¬£¬8¸öΪ°²È«Ö°ÄÜÈÆ¹ý·ì϶£¬£¬7¸öΪºýŪ·ì϶¡£¡£¡£Õâ´ÎÐÞ¸´µÄ9¸ö0dayÖУ¬£¬ÓÐ4¸öÒѱ»ÔÚÔÚÒ°ÀûÓ㬣¬Ô̺¬PrintNightmare·ì϶£¨CVE-2021-34527£©¡¢ ¡¢WindowsÄÚºËÌáȨ·ì϶£¨CVE-2021-33771ºÍCVE-2021-31979£©ÒÔ¼°¾ç±¾ÒýÇæÄÚ´æ°Ü»µ·ì϶£¨CVE-2021-34448£©¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2021-patch-tuesday-fixes-9-zero-days-117-flaws/


5¡¢ ¡¢SolarWindsÐÞ¸´Serv-UÖÐÒѱ»ÀûÓõÄÔ¶³Ì´úÂëÖ´Ðзì϶


5.jpg


SolarWindsÔÚ7ÔÂ9ÈÕ°ä²¼µÄServ-U 15.2.3 HF2ÖÐÐÞ¸´ÁËÒ»¸öÒѱ»ÀûÓõÄ0day¡£¡£¡£MicrosoftÅû¶ÁËServ-U²úÆ·µÄÔ¶³Ì´úÂëÖ´ÐÐ0day£¨CVE-2021-35211£©£¬£¬Ô¶³Ì¹¥»÷ÕßÀûÓô˷ì϶¿ÉÄÜÒÔÌØÊâȨÏÞÖ´ÐÐËÁÒâ´úÂ룬£¬ÔÚÖ¸±êϵͳÉÏ×°Öò¢ÔËÐз¨Ê½¡¢ ¡¢²é¿´¡¢ ¡¢¸ü¸Ä»òɾ³ýÊý¾ÝµÈ¡£¡£¡£Ä¿Ç°¸Ã·ì϶ÒѾ­³ö±»Ò°ÀûÓ㬣¬µ«SolarWinds°µÊ¾£¬£¬ÈôÊÇServ-U»·¾³ÖÐδÆôÓÃSSH£¬£¬Ôò¸Ã·ì϶²»´æÔÚ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/solarwinds-patches-critical-serv-u-vulnerability-exploited-in-the-wild/