ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ23ÖÜ

Ðû²¼Ê±¼ä 2021-06-07

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2021Äê05ÔÂ31ÈÕÖÁ06ÔÂ06ÈÕ¹²ÊÕ¼Çå¾²Îó²î59¸ö£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMozilla Firefox CVE-2021-29966»º³åÇøÒç³öÎó²î£»£»£»£»Cisco Common Services Platform Collector OSÏÂÁîÖ´ÐÐÎó²î£»£»£»£»Synology Photo Station SQL×¢ÈëÎó²î£»£»£»£»F5 BIG-IQ Centralized ManagementÏÂÁî×¢ÈëÎó²î£»£»£»£»OpenText Brava Desktop PDFÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇSophos·¢Ã÷Õë¶ÔExchangeµÄÐÂÀÕË÷Èí¼þEpsilon Red£»£»£»£»È«Çò×î´óÈâÀàÉú²úÉÌJBSÔâµ½¹¥»÷£¬£¬£¬¶à¸ö·Ö¹«Ë¾Í£²ú£»£»£»£»Ñо¿ÍŶӷ¢Ã÷кóÃÅFacefish£¬£¬£¬¿ÉÇÔÈ¡LinuxϵͳÐÅÏ¢£»£»£»£»ÃÀ¹úÒѲé·âNOBELIUMÔÚÕë¶ÔUSAIDµÄ¹¥»÷ÖÐʹÓõÄÓòÃû£»£»£»£»Check PointÐû²¼2021ÄêÑÇÌ«µØÇøÍøÂç¹¥»÷ÆÊÎö±¨¸æ¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£


> Ö÷ÒªÇå¾²Îó²îÁбí


1.Mozilla Firefox CVE-2021-29966»º³åÇøÒç³öÎó²î


Mozilla Firefox±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇ󣬣¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»ò¿ÉÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£

https://www.mozilla.org/en-US/security/advisories/mfsa2021-23/


2.Cisco Common Services Platform Collector OSÏÂÁîÖ´ÐÐÎó²î


Cisco Common Services Platform Collector CSPCÉèÖñ£´æÇå¾²Îó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâOSÏÂÁî¡£¡£¡£¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-CSPC-CIV-kDuBfNfu


3.Synology Photo Station SQL×¢ÈëÎó²î


Snology Photo Station±£´æSQL×¢ÈëÎó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄSQLÇëÇ󣬣¬£¬²Ù×÷Êý¾Ý¿â£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£

https://www.synology.cn/zh-cn/security/advisory/Synology_SA_20_20


4.F5 BIG-IQ Centralized ManagementÏÂÁî×¢ÈëÎó²î


F5 BIG-IQ Centralized Managementij¸öÒ³Ãæ±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâOSÏÂÁî¡£¡£¡£¡£

https://support.f5.com/csp/article/K06024431


5.OpenText Brava Desktop PDFÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î


OpenText Brava Desktop PDF´¦Öóͷ£±£´æÊͷźóʹÓÃÎó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»ò¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-642/


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Sophos·¢Ã÷Õë¶ÔExchangeµÄÐÂÀÕË÷Èí¼þEpsilon Red


1.jpg


Çå¾²¹«Ë¾Sophos·¢Ã÷ÐÂÀÕË÷Èí¼þEpsilon Red£¬£¬£¬Ö÷ÒªÕë¶ÔMicrosoft ExchangeЧÀÍÆ÷¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚÊÓ²ìÕë¶ÔÃÀ¹úijÂùݵĹ¥»÷»î¶¯Ê±·¢Ã÷µÄ¸Ã¶ñÒâÈí¼þ¡£¡£¡£¡£Epsilon RedÓÃGolang£¨Go£©±àд£¬£¬£¬ÓÐÒ»×鯿ÒìµÄPowerShell¾ç±¾£¬£¬£¬ÆäÖÐÿ¸ö¾ç±¾¶¼ÓÐÌØ¶¨×÷Ó㬣¬£¬ÈçÖÕÖ¹Çå¾²¹¤¾ß¡¢É¾³ý¸±±¾¡¢ÇÔÈ¡Çå¾²ÕÊ»§ÖÎÀíÆ÷£¨SAM£©ÎļþµÈ¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬¸ÃÍÅ»ïʹÓÃÁËREvilÊê½ð¼Í¼µÄÄ£°å£¨¾ÀÕýÁËÆäÖеÄÓï·¨ºÍƴд¹ýʧ£©£¬£¬£¬²¢ÇÒEpsilon RedÊÇÂþÍþÖжíÂÞ˹³¬µÈÊ¿±øµÄ½ÇÉ«Ãû£¬£¬£¬Òò´ËÍÆ¶Ï¸ÃÍÅ»ïÓë¶íÂÞ˹Óйء£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-epsilon-red-ransomware-hunts-unpatched-microsoft-exchange-servers/


2¡¢È«Çò×î´óÈâÀàÉú²úÉÌJBSÔâµ½¹¥»÷£¬£¬£¬¶à¸ö·Ö¹«Ë¾Í£²ú


2.jpg


JBSʳÎ﹫˾ÓÚÉÏÖÜÄ©Ôâµ½¹¥»÷£¬£¬£¬Ó°ÏìÃÀ¹ú¡¢°Ä´óÀûÑǺͼÓÄôóµÈµØµÄ·Ö¹«Ë¾¡£¡£¡£¡£JBSÊÇÈ«Çò×î´óµÄÅ£ÈâºÍ¼ÒÇÝÉú²úÉÌ£¬£¬£¬Ò²ÊÇÈ«ÇòµÚ¶þ´óÖíÈâÉú²úÉÌ£¬£¬£¬ÔÚÁù´óÖÞµÄ190¸ö¹ú¼Ò/µØÇø¶¼ÓÐÓªÒµ¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬°Ä´óÀûÑÇÕþ¸®ÒÑ»ñϤÕâÒ»ÊÂÎñ£¬£¬£¬²¢ÕýÔÚÓëJBSÏàÖúÊÔͼ»Ö¸´¾³ÄÚµÄÉú²ú»î¶¯¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎú´Ë´Î¹¥»÷µÄÐÔ×ÓµÈÏêϸÐÅÏ¢£¬£¬£¬ÓÉÓÚ¹¥»÷±¬·¢ÓÚÖÜÄ©£¬£¬£¬Òò´ËÑо¿Ö°Ô±Íƶϼ«ÓпÉÄÜÓëÀÕË÷Èí¼þÓйء£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/food-giant-jbs-foods-shuts-down-production-after-cyberattack/


3¡¢Ñо¿ÍŶӷ¢Ã÷кóÃÅFacefish£¬£¬£¬¿ÉÇÔÈ¡LinuxϵͳÐÅÏ¢


3.jpg


Ñо¿ÍŶӷ¢Ã÷ÁËÒ»¸öеĺóÃÅFacefish£¬£¬£¬¿É¿ØÖÆLinuxϵͳ²¢ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£FacefishÓÉDropperºÍRootkitÁ½²¿·Ö×é³É£¬£¬£¬ÆäÖ÷Òª¹¦Ð§ÓÉRootkitÄ£¿£¿£¿£¿£¿éÈ·¶¨£¬£¬£¬¸ÃÄ£¿£¿£¿£¿£¿éÔÚRing3²ãÊÂÇ飬£¬£¬²¢Ê¹ÓÃLD_PRELOAD¹¦Ð§¾ÙÐмÓÔØ¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÖ§³Ö¶àÖÖ¹¦Ð§£¬£¬£¬°üÀ¨:ÉÏ´«×°±¸ÐÅÏ¢¡¢ÇÔÈ¡Óû§Æ¾Ö¤¡¢µ¯»ØshellºÍÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£±ðµÄ£¬£¬£¬Ñо¿Ö°Ô±ÌåÏÖFacefish½ÓÄÉÁËÖØ´óµÄͨѶЭæÅºÍ¼ÓÃÜËã·¨£¬£¬£¬ËüʹÓÃÒÔ0x2XX¿ªÍ·µÄÖ¸ÁîÀ´½»Á÷¹«Ô¿£¬£¬£¬²¢Ê¹ÓÃBlowFishÓëC2ЧÀÍÆ÷¼ÓÃÜͨѶÊý¾Ý¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/118388/malware/facefish-backdoor.html


4¡¢ÃÀ¹úÒѲé·âNOBELIUMÔÚÕë¶ÔUSAIDµÄ¹¥»÷ÖÐʹÓõÄÓòÃû


4.jpg


ÃÀ¹ú˾·¨²¿ÒѲé·âNOBELIUMÔÚÕë¶ÔÃÀ¹ú¹ú¼Ê¿ª·¢Êð (USAID) µÄ¹¥»÷ÖÐʹÓõÄÓòÃû¡£¡£¡£¡£Î¢ÈíÓÚÉÏÖÜËÄÊ×´ÎÅû¶Á˴˴δ¹ÂÚ¹¥»÷£¬£¬£¬Á¥ÊôÓÚ¶íÂÞ˹Ç鱨»ú¹¹SVRµÄNOBELIUM£¨ÓÖÃûAPT29£©Ã°³äUSAID£¬£¬£¬ Ïò150 ¶à¸ö×éÖ¯·¢ËÍÁË3000¶à·â´¹ÂÚÓʼþ¡£¡£¡£¡£´Ë´Î²é·âµÄÁ½¸öÓòÃû»®·ÖΪtheyardservice[.]comºÍworldhomeoutlet[.]com£¬£¬£¬Ö÷ÒªÓÃÓÚÎüÊÕ´ÓÊܺ¦ÕßÄÇÀïй¶µÄÊý¾Ý£¬£¬£¬²¢·¢ËÍÏÂÁî¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-seizes-domains-used-by-apt29-in-recent-usaid-phishing-attacks/


5¡¢Check PointÐû²¼2021ÄêÑÇÌ«µØÇøÍøÂç¹¥»÷ÆÊÎö±¨¸æ


5.jpg


Check PointÐû²¼ÁË2021ÄêÑÇÌ«µØÇøÍøÂç¹¥»÷µÄÆÊÎö±¨¸æ¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬Óë2020Äê5ÔÂÏà±È£¬£¬£¬ÑÇÌ«µØÇø (APAC) µÄÍøÂç¹¥»÷ÊýĿͬ±ÈÔöÌíÁË168%£¬£¬£¬¶øÔÚ2021Äê4ÔÂÖÁ5ÔÂʱ´ú¾ÍÔöÌíÁË53%¡£¡£¡£¡£Ôö·ù×î´óµÄ¶ñÒâÈí¼þÀàÐÍÊÇÀÕË÷Èí¼þºÍÔ¶³Ì»á¼ûľÂí (RAT)£¬£¬£¬Óë½ñÄêÄêÍ·Ïà±È£¬£¬£¬¶¼ÔöÌíÁË26%£¬£¬£¬¶øÒøÐÐľÂíºÍÐÅÏ¢ÇÔÈ¡¹¤¾ßÒ²ÔöÌíÁË10%¡£¡£¡£¡£ÍøÂç¹¥»÷´ÎÊýÔö·ù×î´óµÄǰ5¸ö¹ú¼Ò/µØÇøÊÇÈÕ±¾£¨40%£©¡¢ÐÂ¼ÓÆÂ£¨30%£©¡¢Ó¡¶ÈÄáÎ÷ÑÇ£¨25%£©¡¢ÂíÀ´Î÷ÑÇ£¨22%£©ºÍÖйų́Í壨17%£©¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.checkpoint.com/2021/05/27/check-point-research-asia-pacific-experiencing-a-168-year-on-year-increase-in-cyberattacks-in-may-2021/