ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ33ÖÜ

°ä²¼¹¦·ò 2021-08-23

>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2021Äê08ÔÂ09ÈÕÖÁ08ÔÂ15ÈÕ¹²ÊÕ¼°²È«·ì϶58¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Dynamics CVE-2021-36946¿çÕ¾¾ç±¾·ì϶£»SAP Business OneËÁÒâÎļþÉÏ´«´úÂëÖ´Ðзì϶£»SapphireIMSºÅÁî×¢Èë·ì϶£»Adobe Connect CVE-2021-36061°²È«Èƹý·ì϶£»Apache ServiceComb Service-Center CVE-2021-21501õè¾¶±éÀú·ì϶ ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ×êÑÐÈËÔ±·¢ÏÖÀûÓÃExchangeÖзì϶ProxyShellµÄ¹¥»÷»î¶¯£»×êÑÐÍŶӷ¢ÏÖÀûÓÃArcadyan¹Ì¼þÖзì϶װÖÃMiraiµÄ»î¶¯£»RansomEXXÍÅ»ïÐû³ÆÒÑÇÔÈ¡ÉÝ³ÞÆ·ÅÆZegna³¬¹ý20GBÊý¾Ý£»Î¢ÈíÖܶþ°²È«¸üУ¬½¨¸´Ô̺¬3¸ö0dayÔÚÄÚµÄ44¸ö·ì϶£»Kaspersky°ä²¼2021ÄêQ2À¬»øÓʼþºÍ´¹µö»î¶¯µÄ»ã±¨ ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖÐ ¡£



>³ÁÒª°²È«·ì϶Áбí


1.Microsoft Dynamics CVE-2021-36946¿çÕ¾¾ç±¾·ì϶


Microsoft Dynamics´æÔÚ¿çÕ¾¾ç±¾·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶עÈë¶ñÒâ¾ç±¾»òHTML´úÂ룬µ±¶ñÒâÊý¾Ý±»²é¿´Ê±£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»ò½Ù³ÖÓû§»á»° ¡£


https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36946



2.SAP Business OneËÁÒâÎļþÉÏ´«´úÂëÖ´Ðзì϶


SAP Business One´æÔÚËÁÒâÎļþÉÏ´«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë ¡£


https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=582222806


3.SapphireIMSºÅÁî×¢Èë·ì϶


SapphireIMS´æÔÚÓ²±àÂëºÍÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÈÆ¹ý°²È«ÏÞ¶È£¬Ö´ÐÐËÁÒâºÅÁî ¡£


https://www.sapphireims.com/patches/


4.Adobe Connect CVE-2021-36061°²È«Èƹý·ì϶


Adobe Connect´æÔÚ°²È«Èƹý·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉδÊÚȨ½Ó¼ûÀûÓà ¡£


https://helpx.adobe.com/security/products/connect/apsb21-66.html


5.Apache ServiceComb Service-Center CVE-2021-21501õè¾¶±éÀú·ì϶


Apache ServiceComb Service-Center´æÔÚÅäÖÃÃýÎó·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ɽøÐÐĿ¼±éÀú¹¥»÷£¬»ñÈ¡Ãô¸ÐÐÅÏ¢ ¡£


https://lists.apache.org/thread.html/r337be65e504eac52a12e89d7de40345e5d335deee9dd7288f7f59b81%40%3Cdev.servicecomb.apache.org%3E


 >³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢×êÑÐÈËÔ±·¢ÏÖÀûÓÃExchangeÖзì϶ProxyShellµÄ¹¥»÷»î¶¯


×êÑÐÈËÔ±·¢ÏÖÀûÓÃExchangeÖзì϶ProxyShellµÄ¹¥»÷»î¶¯.jpg


2021 Black Hat´ó»áÉÏͳ³ÆÎªProxyShellµÄ3¸ö·ì϶µÄϸ½Ú¹«¿ªºó£¬×êÑÐÈËÔ±·¢ÏÖÁË»ý¼«ÀûÓø÷ì϶µÄ»î¶¯ ¡£ProxyShellÔ̺¬ACLÈÆ¹ý·ì϶£¨CVE-2021-34473£©¡¢ Exchange PowerShellºó¶ËµÄÌáȨ·ì϶£¨CVE-2021-34523£©ºÍËÁÒâÎļþдÈëµ¼ÖµÄRCE·ì϶£¨CVE-2021-31207£© ¡£ÕâЩ·ì϶Äܹ»Í¨¹ýIISÖеĶ˿Ú443ÉÏÔËÐеÄMicrosoft Exchange¿Í»§¶Ë½Ó¼û·þÎñ(CAS)Ô¶³ÌÀûÓ㬽áºÏʹÓÿɽøÐÐδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´ÐÐ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-servers-scanned-for-proxyshell-vulnerability-patch-now/


2¡¢×êÑÐÍŶӷ¢ÏÖÀûÓÃArcadyan¹Ì¼þÖзì϶װÖÃMiraiµÄ»î¶¯


×êÑÐÍŶӷ¢ÏÖÀûÓÃArcadyan¹Ì¼þÖзì϶װÖÃMiraiµÄ»î¶¯.jpg


Õ°²©ÍøÂçµÄ×êÑÐÍŶÓÔÚ½üÆÚ·¢ÏÖÁËÀûÓÃArcadyan¹Ì¼þÖзì϶µÄ¹¥»÷»î¶¯ ¡£¸Ã·ì϶ÊÇõè¾¶±éÀú·ì϶£¬×·×ÙΪCVE-2021-20090£¬ÆÀ·ÖΪ9.9 ¡£´æÔÚÓÚʹÓÃArcadyan¹Ì¼þµÄ·ÓÉÆ÷µÄweb½çÃæÉÏ£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÈÆ¹ýÉí·ÝÑéÖ¤£¬Ó°ÏìÁËÊýÊ®ÖÖÐͺŵÄÊý°ÙÍǫ̀·ÓÉÆ÷ ¡£×ÔÉÏÖÜËÄÒÔÀ´£¬×êÑÐÈËÔ±ÔÚÒ°·¢ÏÖÁËÀûÓô˷ì϶µÄ¹¥»÷»î¶¯,Ö¼ÔÚÊÕÊÜÖ¸±êÉ豸²¢×°Öý©Ê¬ÍøÂçMiraiµÄpayload ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/actively-exploited-bug-bypasses-authentication-on-millions-of-routers/


3¡¢RansomEXXÍÅ»ïÐû³ÆÒÑÇÔÈ¡ÉÝ³ÞÆ·ÅÆZegna³¬¹ý20GBÊý¾Ý


RansomEXXÍÅ»ïÐû³ÆÒÑÇÔÈ¡ÉÝ³ÞÆ·ÅÆZegna³¬¹ý20GBÊý¾Ý.jpg


ÀÕË÷ÍÅ»ïRansomEXX½üÆÚÐû³ÆÒÑÇÔÈ¡ÉÝ³ÞÆ·ÅÆZegna³¬¹ý20GBÊý¾Ý ¡£ZegnaÊÇÒâ´óÀû×î³ÛÃûµÄÉݳÞÊ±×°Æ·ÅÆÖ®Ò»£¬ÊÇÈ«ÇòÊÕÈë×î¸ßµÄÄÐ×°Æ·ÅÆ ¡£RansomEXX³ÆÒѴӸù«Ë¾ÇÔÈ¡ÁË20.74GBµÄÊý¾Ý£¬²¢°ä²¼ÁË43¸öÎļþ£¨42¸ö500MBµÄÎļþºÍ1¸ö239.54MBµÄÎļþ£©×÷ΪÑù±¾ ¡£½üÆÚ£¬RansomEXXÍÅ»ïÔøÏ°È¾ÁËÒâ´óÀûÀ­Æë°Â´óÇøµÄϵͳ£¬²¢¹¥»÷ÁËÖйų́ÍåµÄÍÆËã»úÓ²¼þÔì×÷É̼¼¼Î£¨GIGABYTE£© ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/120898/data-breach/ransomexx-ransomware-zegna.html


4¡¢Î¢ÈíÖܶþ°²È«¸üУ¬½¨¸´Ô̺¬3¸ö0dayÔÚÄÚµÄ44¸ö·ì϶


΢ÈíÖܶþ°²È«¸üУ¬½¨¸´Ô̺¬3¸ö0dayÔÚÄÚµÄ44¸ö·ì϶.jpg


΢Èí°ä²¼2021Äê8ÔµÄÖܶþ°²È«¸üУ¬×ܼƽ¨¸´ÁË44¸ö·ì϶ ¡£ÆäÖÐÔ̺¬13¸öÔ¶³Ì´úÂëÖ´Ðзì϶¡¢8¸öÐÅϢй¶·ì϶¡¢2¸ö»Ø¾ø·þÎñ·ì϶ºÍ4¸öºýŪ·ì϶ ¡£Õâ´Î½¨¸´µÄ3¸ö0dayΪWindows Print SpoolerÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-36936£©¡¢ Windows LSAÖеĺýŪ·ì϶£¨CVE-2021-36942£©ÒÔ¼°Windows Update Medic·þÎñÖеÄÌáȨ·ì϶£¨CVE-2021-36948£© ¡£´Ë±í£¬×êÑÐÈËÔ±ÒѾ­·¢ÏÖ×Ô¶¯ÀûÓÃCVE-2021-36948µÄ¹¥»÷»î¶¯ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2021-patch-tuesday-fixes-3-zero-days-44-flaws/


5¡¢Kaspersky°ä²¼2021ÄêQ2À¬»øÓʼþºÍ´¹µö»î¶¯µÄ»ã±¨


Kaspersky°ä²¼2021ÄêQ2À¬»øÓʼþºÍ´¹µö»î¶¯µÄ»ã±¨.jpg


Kaspersky°ä²¼ÁËÓйØ2021ÄêQ2À¬»øÓʼþºÍ´¹µö»î¶¯µÄ·ÖÎö»ã±¨ ¡£2021ÄêQ2£¬ÆóÒµÕË»§ÒÀÈ»Êǹ¥»÷ÕßµÄÖØÒªÖ¸±êÖ®Ò» ¡£ÎªÁËÔö³¤´¹µöÓʼþÖÐÁ´½ÓµÄ¿ÉÐŶÈ£¬¹¥»÷Õß¼Ù×°³ÆÀ´×ÔÔÆ·þÎñµÄÓʼþ£¬ÀýÈçMicrosoft Teams»áÒéµÄ֪ͨµÈ ¡£À¬»øÓʼþÊýÁ¿µÄÕ¼±ÈÔÚ3Ô·ݴ¥µ×£¨45.10%£©ºó£¬ÔÚ4Ô·ÝÓ×·ùÉÏÉý£¨45.29%£©£¬µ½6Ô£¨48.03%£©Óë2020ÄêQ4Ï൱ ¡£À¬»øÓʼþÆðÔ´×î¶àµÄ¹ú¶ÈΪ¶íÂÞ˹£¨26.07%£©£¬Æä´ÎÊǵ¹ú£¨13.97%£©ºÍÃÀ¹ú£¨11.24%£© ¡£×î³£¼ûµÄ¶ñÒ⸽¼þÊÇBadun¼Ò×壨7.09%£© ¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/spam-and-phishing-in-q2-2021/103548/