ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ32ÖÜ
Ðû²¼Ê±¼ä 2021-08-09> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2021Äê08ÔÂ02ÈÕÖÁ08ÔÂ08ÈÕ¹²ÊÕ¼Çå¾²Îó²î63¸ö£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇGoogle Android¸ßͨ×é¼þCVE-2021-1972´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»Cisco Connected Mobile Experiences¸ü¸ÄÃÜÂëÑéÖ¤ÈÆ¹ýÎó²î£»£»£»£»£»£»Claroty Secure Remote Access SQL×¢ÈëÎó²î£»£»£»£»£»£»Advantech WebAccess/SCADA CVE-2021-32943Õ»Òç³öÎó²î£»£»£»£»£»£»Pulse Connect Secure CVE-2021-22933·¾¶±éÀúÎó²î¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǺڿ͹ûÕæµç×ÓÒÕ½çEAµÄÊý¾Ý£¬£¬£¬£¬°üÀ¨FIFA 21ÓÎÏ·Ô´Â룻£»£»£»£»£»Ñо¿ÍŶӳÆDarkSide»òÒÔBlackMatterÖ®ÃûÖØÐ»ع飻£»£»£»£»£»PythonÐû²¼Çå¾²¸üУ¬£¬£¬£¬ÐÞ¸´PyPI´æ´¢¿âÖжà¸öÎó²î£»£»£»£»£»£»KasperskyÅû¶ÐµÄGhostEmperorÍÅ»ïÕë¶Ô¶«ÄÏÑÇ£»£»£»£»£»£»Ñо¿Ö°Ô±Åû¶TCP/IPÖÐͳ³ÆÎªINFRA:HALTµÄ14¸öÎó²î¡£¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£
> Ö÷ÒªÇå¾²Îó²îÁбí
1.Google Android¸ßͨ×é¼þCVE-2021-1972´úÂëÖ´ÐÐÎó²î
Google Android¸ßͨ×é¼þ±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿Éʹϵͳ±ÀÀ£»£»£»£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
https://source.android.com/security/bulletin/2021-08-01
2.Cisco Connected Mobile Experiences¸ü¸ÄÃÜÂëÑéÖ¤ÈÆ¹ýÎó²î
Cisco Connected Mobile Experiences¸ü¸ÄÃÜÂëʵÏÖ±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÈÆ¹ýÑé֤δÊÚȨ»á¼û¡£¡£¡£¡£¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cmx-GkCvfd4
3.Claroty Secure Remote Access SQL×¢ÈëÎó²î
Claroty Secure Remote Access±£´æSQL×¢ÈëÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄSQLÇëÇ󣬣¬£¬£¬²Ù×÷Êý¾Ý¿â£¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0017
4.Advantech WebAccess/SCADA CVE-2021-32943Õ»Òç³öÎó²î
Advantech WebAccess/SCADA±£´æÕ»Òç³öÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
https://us-cert.cisa.gov/ics/advisories/icsa-21-217-04
5.Pulse Connect Secure CVE-2021-22933·¾¶±éÀúÎó²î
Pulse Connect Secure±£´æÄ¿Â¼±éÀúÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄɾ³ýϵͳí§ÒâÎļþ¡£¡£¡£¡£¡£
https://www.pulsesecure.net/products/remote-access-overview/
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢ºÚ¿Í¹ûÕæµç×ÓÒÕ½çEAµÄÊý¾Ý£¬£¬£¬£¬°üÀ¨FIFA 21ÓÎÏ·Ô´Âë

7ÔÂ26ÈÕÐÇÆÚÒ»£¬£¬£¬£¬ºÚ¿ÍÔÚ°µÍø¹ûÕæµç×ÓÒÕ½çEAµÄÊý¾Ý£¬£¬£¬£¬°üÀ¨FIFA 21ÓÎÏ·Ô´Âë¡¢FrostBiteÓÎÏ·ÒýÇæºÍµ÷ÊÔ¹¤¾ßÔ´´úÂëµÈÐÅÏ¢¡£¡£¡£¡£¡£¸ÃÊÂÎñ×î³õÓÚ6ÔÂ10ÈÕÅû¶£¬£¬£¬£¬ÆäʱºÚ¿ÍÉù³ÆÇÔÈ¡Á˸ù«Ë¾780GBµÄÊý¾Ý£¬£¬£¬£¬²¢Ô¸ÒâÒÔ2800ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛ¡£¡£¡£¡£¡£µ«ÓÉÓÚ±»µÁÊý¾Ý´ó¶àÊÇÔ´´úÂë¶ÔÍøÂç·¸·¨ÍÅ»ïÀ´ËµÃ»ÓÐÈκμÛÖµ£¬£¬£¬£¬Òò´Ë²¢Î´ÕÒµ½Âò¼Ò¡£¡£¡£¡£¡£Ö®ºóºÚ¿ÍÊÔͼÀÕË÷EA£¬£¬£¬£¬ÔÚ7ÔÂ14ÈÕÐû²¼ÁË1.3GBµÄFIFAÔ´´úÂë×÷ΪÑù±¾£¬£¬£¬£¬²¢ÔÚ2ÖÜЧ¹ûÕæÁËËùÓÐÊý¾Ý¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/hackers-leak-full-ea-data-after-failed-extortion-attempt/
2¡¢Ñо¿ÍŶӳÆDarkSide»òÒÔBlackMatterÖ®ÃûÖØÐ»عé

Ñо¿ÍŶӳÆÀÕË÷ÍÅ»ïDarkSide¿ÉÄÜÒÑÖØÐÂÃüÃûΪеÄBlackMatterÖØÐ»ع顣¡£¡£¡£¡£DarkSideÔÚ¹¥»÷ÃÀ¹ú×î´óµÄȼÁϹܵÀColonial Pipelineºó£¬£¬£¬£¬ÓÚ½ñÄê5ÔÂͻȻ¹Ø±Õ¡£¡£¡£¡£¡£ÉÏÖÜ£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷еÄÀÕË÷Èí¼þBlackMatter¡£¡£¡£¡£¡£ÆÊÎö·¢Ã÷£¬£¬£¬£¬¶þÕßʹÓõļÓÃܳÌÐòÏÕЩÏàͬ£¬£¬£¬£¬°üÀ¨DarkSideËùÌØÓеÄ×Ô½ç˵Salsa20¾ØÕ󡣡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬¶þÕß¶¼Ê¹ÓÃÁËDarkSide¶ÀÍ̵ÄRSA-1024ʵÏÖ¡¢½ÓÄÉÁËÏàͬµÄ¼ÓÃÜËã·¨²¢ÇÒÊý¾ÝÐ¹Â¶ÍøÕ¾¶¼Ê¹ÓÃÁËÀàËÆµÄÓïÑÔ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/darkside-ransomware-gang-returns-as-new-blackmatter-operation/
3¡¢PythonÐû²¼Çå¾²¸üУ¬£¬£¬£¬ÐÞ¸´PyPI´æ´¢¿âÖжà¸öÎó²î

PythonÍŶÓÐû²¼Çå¾²¸üУ¬£¬£¬£¬ÐÞ¸´ÁËPython Package Index (PyPI)´æ´¢¿âÖеÄ3¸öÎó²î¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄÎó²îÖУ¬£¬£¬£¬×îÑÏÖØµÄÒ»¸öÔÊÐí¹¥»÷ÕßÔÚPyPIµÄ»ù´¡ÉèÊ©ÉÏÔËÐÐÏÂÁ£¬£¬£¬À´ÇÔÈ¡´úÂë¿âÖеÄÁîÅÆ»òÆäËüÃÜÂ룬£¬£¬£¬²¢ÇÒÕâЩÁîÅÆ»òÃÜÂ뻹¿É±»ÓÃÀ´»á¼ûºÍ¸Ä¶¯PyPI´úÂë¡£¡£¡£¡£¡£ÁíÍâÁ½¸öÎó²îÖУ¬£¬£¬£¬Ò»¸öÔÊÐí¹¥»÷Õßɾ³ý²»ÔÚÆä¿ØÖÆÏµÄÏîÄ¿µÄÎĵµ£¬£¬£¬£¬¶øÁíÒ»¸öÔÊÐí¹¥»÷Õßɾ³ý²»ÔÚÆä¿ØÖÆÏµÄÏîÄ¿ÖеĽÇÉ«¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/python-team-fixes-bug-that-allowed-takeover-of-pypi-repository/
4¡¢KasperskyÅû¶ÐµÄGhostEmperorÍÅ»ïÕë¶Ô¶«ÄÏÑÇ

KasperskyÅû¶ÁËÒ»¸öеĺڿÍÍÅ»ïGhostEmperor£¬£¬£¬£¬Ö÷ÒªÕë¶Ô¶«ÄÏÑǵØÇøµÄÄ¿µÄ£¬£¬£¬£¬°üÀ¨Õþ¸®»ú¹¹ºÍ¼¸¼ÒµçÐŹ«Ë¾¡£¡£¡£¡£¡£¸ÃÍÅ»ïµÄÈëÇֻÒÀÀµÓÚCheat Engine¿ªÔ´ÏîÄ¿µÄÒ»¸ö×é¼þ£¬£¬£¬£¬ËüÄܹ»ÈƹýWindowsÇý¶¯³ÌÐòÇ¿ÖÆÊðÃû»úÖÆ¡£¡£¡£¡£¡£¸ÃÍÅ»ïÖ®ÒÔÊÇÓëÖÚ²î±ð£¬£¬£¬£¬ÊÇÓÉÓÚËüʹÓÃÁËÒ»¸öÒÔǰ²»ÎªÈËÖªµÄWindowsÄÚºËģʽµÄrootkit£¬£¬£¬£¬²¢ÇÒ½ÓÄÉÁËÖØ´óµÄ¶à½×¶Î¶ñÒâÈí¼þ¿ò¼Ü£¬£¬£¬£¬Ö¼ÔÚ¶ÔÄ¿µÄЧÀÍÆ÷¾ÙÐÐÔ¶³Ì¿ØÖÆ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/120721/apt/ghostemperor-chinese-speaking-threat-actor.html
5¡¢Ñо¿Ö°Ô±Åû¶TCP/IPÖÐͳ³ÆÎªINFRA:HALTµÄ14¸öÎó²î

Ñо¿Ö°Ô±Åû¶ÁËÔÚNicheStack TCP/IP¿ÍÕ»Öз¢Ã÷µÄͳ³ÆÎªINFRA:HALTµÄ14¸öÇå¾²Îó²î£¬£¬£¬£¬Ó°ÏìÁËÁè¼Ý200¼Ò¹©Ó¦ÉÌÖÆÔìµÄOT×°±¸¡£¡£¡£¡£¡£ÕâЩÎó²î¿ÉÒÔµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС¢¾Ü¾øÐ§ÀÍ (DoS)ºÍÐÅϢй¶¡¢TCPÓÕÆºÍDNS»º´æÖж¾¡£¡£¡£¡£¡£ÆäÖÐ×îÑÏÖØµÄÎó²îΪCVE-2020-25928ºÍCVE-2020-31226£¬£¬£¬£¬ÆÀ·Ö»®·ÖΪ9.8ºÍ9.1£¬£¬£¬£¬Ó°ÏìÁË¿ÍÕ»µÄDNS¿Í»§¶ËºÍHTTPЧÀÍÆ÷×é¼þ£¬£¬£¬£¬¿ÉÓÃÀ´ÔÚÄ¿µÄ×°±¸ÉÏÖ´ÐдúÂë²¢ÍêÈ«¿ØÖÆËü¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/08/critical-flaws-affect-embedded-tcpip.html


¾©¹«Íø°²±¸11010802024551ºÅ