Ó¢¹ú¹ú·À²¿µÄ¹ú·ÀѧԺÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÒÉΪÍâ¹úºÚ¿Í£»£»£»£»£»IoT¹«Ë¾Sierra WirelessѬȾÀÕË÷Èí¼þµ¼ÖÂÉú²úÖÐÖ¹
Ðû²¼Ê±¼ä 2021-03-241.Ó¢¹ú¹ú·À²¿µÄ¹ú·ÀѧԺÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÒÉΪÍâ¹úºÚ¿Í

Ó¢¹ú¹ú·À²¿µÄ¹ú·ÀѧԺÔâµ½ÑÏÖØµÄ¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÏÓÒÉÊǶíÂÞ˹µÈÍâ¹úÊÆÁ¦ËùΪ¡£¡£¡£¡£¡£¡£¡£¸ÃѧԺλÓÚÅ£½ò¿¤Î÷ÄÏʲÀï·òÄÉÄ·£¬£¬£¬£¬£¬£¬£¬Ö÷ҪΪӢ¹úÎä×°²½¶Ó¡¢¹«ÎñÔ±¡¢ÆäËûÕþ¸®²¿·ÖºÍ¹ú¼ÒЧÀÍÖ°Ô±Ìṩ¸ßµÈ½ÌÓý¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷µ¼Ö¸ÃѧԺµÄ¹ÙÍøÖÐÖ¹£¬£¬£¬£¬£¬£¬£¬ÓɳаüÉÌÔËÓªµÄITÍøÂç±»ÆÆË𣬣¬£¬£¬£¬£¬£¬Ñ§Ð£ÏµÍ³Ò²Êܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬¸ÃУԱ¹¤±»ÆÈʹÓÃСÎÒ˽¼ÒµçÄÔ¾ÙÐа칫¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬£¬Ô¤¼ÆÐèÒª5ÖÜʱ¼ä²Å»ªÍêÈ«»Ö¸´ÊÜÓ°ÏìµÄÅÌËã»úºÍЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/115870/hacking/ministry-of-defence-hacked.html
2.ºÚ¿ÍʹÓÃAccellionµÄFTAÖÐÎó²îÈëÇÖ¿ÇÅÆ²¢Î´Ó°ÏìÆäÍøÂç

ºÚ¿ÍʹÓÃAccellionµÄFile Transfer Appliance£¨FTA£©ÖÐÎó²îÈëÇÖÄÜÔ´¹«Ë¾¿ÇÅÆ¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿ÇÅÆ¹«Ë¾Éù³Æ£¬£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñ½öÓ°ÏìÁËFTA×°±¸£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÎļþ´«ÊäЧÀÍÓëÆäËûÊý×Ö»ù´¡ÉèÊ©ÊǸôÀëµÄ£¬£¬£¬£¬£¬£¬£¬Òò´ËÆä½¹µãITϵͳδÊܵ½ÈκÎÓ°Ïì¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜÒѾÇÔÈ¡²¿·ÖÊý¾Ý£¬£¬£¬£¬£¬£¬£¬°üÀ¨Ò»Ð©Ð¡ÎÒ˽¼ÒÐÅÏ¢ÒÔ¼°¿ÇÅÆ¹«Ë¾ºÍÆäÀûÒæÏà¹ØÕßµÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£Ö»¹Ü¿ÇÅÆ¹«Ë¾Ã»ÓÐÅû¶¹¥»÷ÕßµÄÉí·Ý£¬£¬£¬£¬£¬£¬£¬µ«Ñо¿Ö°Ô±ÍƲ⣬£¬£¬£¬£¬£¬£¬´Ë´Î¹¥»÷ÓëFIN11ºÚ¿ÍÍÅ»ïÓйء£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/energy-giant-shell-discloses-data-breach-after-accellion-hack/
3.IoT¹«Ë¾Sierra WirelessѬȾÀÕË÷Èí¼þµ¼ÖÂÉú²úÖÐÖ¹

3ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬£¬¼ÓÄôó¿ç¹úÎÞÏßͨѶװ±¸ÖÆÔìÉÌSierra WirelessѬȾÀÕË÷Èí¼þ£¬£¬£¬£¬£¬£¬£¬ËùÓÐÉú²ú»î¶¯±»ÆÈÖÐÖ¹¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ö÷ÒªÏúÊÛͨѶװ±¸£¬£¬£¬£¬£¬£¬£¬ÔÚ±±ÃÀ¡¢Å·ÖÞºÍÑÇÖÞ¾ùÉèÓÐÑз¢ÖÐÐÄ¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷µ¼Ö¹«Ë¾¹ÙÍøºÍÄÚ²¿ÔËÓªÔâµ½ÆÆË𣬣¬£¬£¬£¬£¬£¬È«ÇòµÄÉú²ú¹¤³§±»ÆÈ¹Ø±Õ¡£¡£¡£¡£¡£¡£¡£µ«ÒòÆäÄÚ²¿ITϵͳÓë¿Í»§µÄЧÀÍÖ®¼äÍÑÀ뿪ÁË£¬£¬£¬£¬£¬£¬£¬ÒÔÊǿͻ§²¢Î´Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÕýÔÚµÚÈý·½×¨¼ÒµÄÐÖúÏÂÊÓ²ì´ËÊÂÎñ£¬£¬£¬£¬£¬£¬£¬²¢2ÔÂ23ÈÕ³·»ØÁËÉϸöÔÂÐû²¼µÄ2021ÄêµÚÒ»¼¾¶ÈÖ¸µ¼±¨¸æ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/115897/malware/sierra-wireless-ransomware.html
4.¹È¸èÅû¶ʹÓøßͨоƬÖÐÊäÈëÑéÖ¤Îó²îµÄ¹¥»÷»î¶¯

¹È¸èÔÚÒ°·¢Ã÷ʹÓøßͨоƬÖÐÊäÈëÑéÖ¤Îó²î£¨CVE-2020-11261£©À´Õë¶ÔAndroidϵͳµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îλÓÚͼÐÎ×é¼þÖУ¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ8.4£¬£¬£¬£¬£¬£¬£¬µ±ÌØÖƵÄÓ¦ÓóÌÐòÇëÇó»á¼û×°±¸ÖеĴó×ÚÄÚ´æÊ±£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÄÚ´æÆÆË𡣡£¡£¡£¡£¡£¡£¸ÃÎó²îÓÚ2020Äê8ÔÂ20ÈÕ±»Åû¶£¬£¬£¬£¬£¬£¬£¬²¢ÓÚ2021Äê1Ô»ñµÃÐÞ¸´¡£¡£¡£¡£¡£¡£¡£GoogleÔÚ3ÔÂ18ÈÕ¸üеÄ1ÔÂÇ徲ͨ¸æÖÐÌåÏÖ£¬£¬£¬£¬£¬£¬£¬CVE-2020-11261¿ÉÄÜÒѾ±»Ê¹ÓÃÌᳫÕë¶ÔÐÔ¹¥»÷¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/03/warning-new-android-zero-day.html
5.ͨÓÃµçÆø£¨GE£©µÄUR×°±¸±£´æ¶à¸öÑÏÖØµÄÎó²î

CISAÖÒÑÔͨÓÃµçÆø£¨GE£©µÄͨÓü̵çÆ÷£¨UR£©ÏµÁеçÔ´ÖÎÀí×°±¸Öб£´æ9¸öÑÏÖØµÄÎó²î¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾³ÆUR×°±¸ÊǼò»¯µçÔ´ÖÎÀíÒÔ±£»£»£»£»£»¤Òªº¦×ʲúµÄ»ù´¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÓû§¿ØÖÆÖÖÖÖ×°±¸ÏûºÄµÄµç¹¦ÂÊÁ¿µÄÅÌËã×°±¸¡£¡£¡£¡£¡£¡£¡£ÆäÖÐ×îÑÏÖØµÄÎó²îÊÇCVE-2021-27426£¬£¬£¬£¬£¬£¬£¬ÓÉĬÈϱäÁ¿³õʼ»¯²»Çå¾²µ¼Ö£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÔ¶³ÌʹÓøÃÎó²îÈÆ¹ý»á¼ûÏÞÖÆ¡£¡£¡£¡£¡£¡£¡£Æä´ÎΪ¿ÉÓÃÀ´ÖØÆôURµÄCVE-2021-27430ºÍÊäÈëÑéÖ¤Îó²î£¨CVE-2021-27418ºÍCVE-2021-27420£©µÈ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/cisa-security-flaws-ge-power-management/164961/
6.KasperskyÐû²¼2020ÄêICSÐÐÒµµÄÌ¬ÊÆÆÊÎö±¨¸æ

KasperskyÐû²¼ÁË2020ÄêICSÐÐÒµµÄÌ¬ÊÆÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£¸Ã±¨¸æÆÊÎöÁËÓÃÓÚÉè¼Æ¡¢ÉèÖúÍά»¤¹¤Òµ¿ØÖÆ×°±¸ºÍÈí¼þµÄÅÌËã»úËùÊܵ½µÄÍøÂçÍþв¡£¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬£¬ÔÚ2020ÄêϰëÄ꣬£¬£¬£¬£¬£¬£¬ÔÚICS¹¤³ÌºÍ¼¯³ÉÐÐÒµÖÐ39.3£¥µÄÅÌËã»úÊܵ½Á˶ñÒâÈí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬Óë2020ÄêÉϰëÄ꣨31.5£¥£©Ïà±ÈÓÐËùÔöÌí£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÐÞ½¨×Ô¶¯»¯¡¢Æû³µÖÆÔì¡¢ÄÜԴʯÓͺÍ×ÔÈ»ÆøÐÐÒµÔâµ½µÄ¹¥»÷Ôö¶à¡£¡£¡£¡£¡£¡£¡£2020ÄêϰëÄ꣬£¬£¬£¬£¬£¬£¬Õë¶ÔÀ¶¡ÃÀÖÞ¡¢Öж«¡¢ÑÇÖ޺ͱ±ÃÀµÄ¹¥»÷´ÎÊýÔö¶à£¬£¬£¬£¬£¬£¬£¬Õë¶Ô·ÇÖÞ¡¢¶íÂÞ˹ºÍÅ·Ö޵Ĺ¥»÷ÊýÄ¿ÓÐËùïÔÌ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://ics-cert.kaspersky.com/reports/2021/03/17/threat-landscape-for-the-ics-engineering-and-integration-sector-2020/


¾©¹«Íø°²±¸11010802024551ºÅ