ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ25ÖÜ

Ðû²¼Ê±¼ä 2021-06-21

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2021Äê06ÔÂ14ÈÕÖÁ06ÔÂ20ÈÕ¹²ÊÕ¼Çå¾²Îó²î55¸ö£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇBandai Namco FromSoftware Dark Souls III´úÂëÖ´ÐÐÎó²î£»£»£»£»Apache Chainsaw·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î£»£»£»£»Contiki-NG 6LoWPANʵÏÖÔ½½ç¶ÁÎó²î£»£»£»£»QEMU SLiRPÍøÂçʵÏÖtftp_input()Ô½½ç¶Á¾Ü½ÓЧÀÍÎó²î£»£»£»£»SonicOS»º³åÇøÒç³ö¾Ü¾øÐ§ÀÍÎó²î¡£¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÃÀ¹úºËÎäÆ÷³Ð°üÉÌSol OriensÔâREvilÀÕË÷Èí¼þ¹¥»÷£»£»£»£»APWGÐû²¼2021ÄêQ1ÍøÂç´¹ÂÚ»î¶¯Ì¬ÊÆµÄÆÊÎö±¨¸æ£»£»£»£»Çå¾²¹«Ë¾CognyteÊý¾Ý¿âÉèÖùýʧй¶Áè¼Ý50ÒÚÌõ¼Í¼£»£»£»£»Apple½ôÆÈ¸üУ¬£¬£¬£¬ÐÞ¸´iOSÖÐÒѱ»ÔÚҰʹÓõÄ2¸ö0day£»£»£»£»Ò˼ҷ¨¹ú¹«Ë¾ÓÃÌØ¹¤Èí¼þ²»·¨¼à¿ØÔ±¹¤±»·£¿£¿£¿£¿î120ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£¡£


> Ö÷ÒªÇå¾²Îó²îÁбí


1.Bandai Namco FromSoftware Dark Souls III´úÂëÖ´ÐÐÎó²î


Bandai Namco FromSoftware Dark Souls III±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

https://www.reddit.com/r/darksouls3/comments/n1235k/potential_pc_security_exploit_spreading/


2.Apache Chainsaw·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î


Apache Chainsaw±£´æ·´ÐòÁл¯Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

http://www.openwall.com/lists/oss-security/2021/06/16/1


3.Contiki-NG 6LoWPANʵÏÖÔ½½ç¶ÁÎó²î


Contiki-NG 6LoWPANʵÏÖ±£´æÔ½½ç¶ÁÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉʹЧÀͳÌÐòÍ߽⡣¡£¡£¡£¡£¡£¡£

https://github.com/contiki-ng/contiki-ng/security/advisories/GHSA-hhwj-2p59-v8p9


4.QEMU SLiRPÍøÂçʵÏÖtftp_input()Ô½½ç¶Á¾Ü½ÓЧÀÍÎó²î



QEMU SLiRPÍøÂçʵÏÖtftp_input()±£´æÔ½½ç¶ÁÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⡣¡£¡£¡£¡£¡£¡£

https://bugzilla.redhat.com/show_bug.cgi?id=1970489


5.SonicOS»º³åÇøÒç³ö¾Ü¾øÐ§ÀÍÎó²î



SonicOS±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë»òʹӦÓóÌÐòÍ߽⡣¡£¡£¡£¡£¡£¡£

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0016


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢ÃÀ¹úºËÎäÆ÷³Ð°üÉÌSol OriensÔâREvilÀÕË÷Èí¼þ¹¥»÷


1.jpg


ÃÀ¹úºËÎäÆ÷³Ð°üÉÌSol OriensÔâµ½ÁËREvilÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾³ÆÆäÖ÷ҪЭÖú¹ú·À²¿¡¢ÄÜÔ´²¿¡¢º½¿Õº½Ìì³Ð°üÉ̺ÍÊÖÒÕ¹«Ë¾¿ªÕ¹ÖØ´óµÄÏîÄ¿¡£¡£¡£¡£¡£¡£¡£REvilÍÅ»ïÕýÔÚÅÄÂô¹¥»÷ʱ´úÇÔÈ¡µÄÊý¾Ý£¬£¬£¬£¬ÆäÖаüÀ¨ÓªÒµÊý¾ÝºÍÔ±¹¤ÐÅÏ¢£¬£¬£¬£¬ÀýÈçÔ±¹¤Éç»áÇå¾²ºÅÂë¡¢ÕÐÆ¸¸ÅÀÀÎļþ¡¢ÈËΪµ¥ÎļþºÍÈËΪ±¨¸æµÈ¡£¡£¡£¡£¡£¡£¡£Sols OriensҲ֤ʵÁËÆäÔÚ2021Äê5ÔÂÔâµ½ÁËÍøÂç¹¥»÷£¬£¬£¬£¬¿ÉÄÜÒѾ­Ð¹Â¶²¿·ÖÊý¾Ý£¬£¬£¬£¬ÏÖÔÚÊÓ²ìÈÔÔÚ¾ÙÐÐÖС£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/revil-ransomware-hits-us-nuclear-weapons-contractor/


2¡¢APWGÐû²¼2021ÄêQ1ÍøÂç´¹ÂÚ»î¶¯Ì¬ÊÆµÄÆÊÎö±¨¸æ


2.jpg


APWGÐû²¼ÁË2021ÄêQ1ÍøÂç´¹ÂÚ»î¶¯Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£±¨¸æÏÔʾ£¬£¬£¬£¬ÍøÂç´¹ÂÚÍøÕ¾ÊýÄ¿ÔÚ2021Äê1Ôµִï·åÖµ£¬£¬£¬£¬´´ÏÂÁË245771¸öµÄÀúʷиߣ¬£¬£¬£¬È»ºóÔÚ±¾¼¾¶ÈµÄºóÆÚ×îÏÈϽµ¡£¡£¡£¡£¡£¡£¡£ÉÌÒµµç×ÓÓʼþ(BEC)Õ©Æ­µÄ±¾Ç®Ô½À´Ô½¸ß£¬£¬£¬£¬´Ó2020ÄêQ3µÄ48000ÃÀÔªÔöÌíµ½ÁË2021ÄêQ1µÄ85000ÃÀÔª¡£¡£¡£¡£¡£¡£¡£Õë¶Ô½ðÈÚ»ú¹¹µÄÍøÂç´¹ÂÚÊÇQ1Õ¼±È×î´óµÄÀàÐÍ£¬£¬£¬£¬Õ¼ËùÓй¥»÷µÄ24.9%¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬Õë¶ÔÉ罻ýÌåÐÐÒµµÄÍøÂç´¹ÂÚÔÚËùÓй¥»÷ÖÐËùÕ¼±ÈÀý´Ó2020ÄêQ4µÄ11.8%¼¤ÔöÖÁ23.6%¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.prnewswire.com/news-releases/apwg-q1-2021-report-detected-phishing-websites-maintain-historic-high-in-q1-2021-after-doubling-in-2020-301309187.html


3¡¢Çå¾²¹«Ë¾CognyteÊý¾Ý¿âÉèÖùýʧй¶Áè¼Ý50ÒÚÌõ¼Í¼


3.jpg


ComparitechÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÍøÂçÇå¾²ÆÊÎö¹«Ë¾CognyteδÊܱ£»£»£»£»¤µÄÊý¾Ý¿â¡£¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿â×÷ΪCognyteÍøÂçÇ鱨ЧÀ͵ÄÒ»²¿·Ö£¬£¬£¬£¬ÓÃÓÚÌáÐÑÆä¿Í»§µÚÈý·½µÄÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£¾ßÓм¥Ð¦ÒâζµÄÊÇ£¬£¬£¬£¬ÓÃÓÚ½»Ö¯¼ì²éй¶µÄСÎÒ˽¼ÒÐÅÏ¢µÄÊý¾Ý¿â×Ô¼ºÒÑй¶¡£¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿â×ܹ²ÓÐ5085132102Ìõ¼Í¼£¬£¬£¬£¬°üÀ¨Ãû³Æ¡¢µç×ÓÓʼþµØµã¡¢ÃÜÂëºÍÊý¾ÝÔ´£¬£¬£¬£¬ÓÚ2021Äê5ÔÂ29ÈÕ±»·¢Ã÷£¬£¬£¬£¬ºóÓÚ6ÔÂ2ÈÕ±»±£»£»£»£»¤ÆðÀ´¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬Éв»È·¶¨ÕâЩÊý¾ÝÔÚ̻¶ʱ´úÊÇ·ñÓб»ÈκεÚÈý·½»á¼û¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.comparitech.com/blog/information-security/breach-database-leak/


4¡¢Apple½ôÆÈ¸üУ¬£¬£¬£¬ÐÞ¸´iOSÖÐÒѱ»ÔÚҰʹÓõÄ2¸ö0day


4.jpg


AppleÐû²¼½ôÆÈ¸üУ¬£¬£¬£¬ÐÞ¸´iOS 12.5.3ÖÐÒѱ»ÔÚҰʹÓõÄ2¸ö0day¡£¡£¡£¡£¡£¡£¡£ÕâÁ½¸ö0dayΪWebKitä¯ÀÀÆ÷ÒýÇæÖеÄÄÚ´æËð»µÎó²î£¨CVE-2021-30761£©ºÍÊͷźóʹÓÃÎó²î£¨CVE-2021-30762£©£¬£¬£¬£¬¾ù¿É±»ÓÃÀ´Ô¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£AppleÌåÏÖ¸ÃÎó²î¿ÉÄÜÒѱ»Æð¾¢Ê¹Ó㬣¬£¬£¬µ«²¢Î´Í¸Â¶ÈκÎÓйشËÀ๥»÷µÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬´Ë´Î¸üл¹ÐÞ¸´ÁËASN.1½âÂëÆ÷ÖеÄÄÚ´æËð»µÎó²î(CVE-2021-30737)¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/06/apple-issues-urgent-patches-for-2-zero.html


5¡¢Ò˼ҷ¨¹ú¹«Ë¾ÓÃÌØ¹¤Èí¼þ²»·¨¼à¿ØÔ±¹¤±»·£¿£¿£¿£¿î120ÍòÃÀÔª


5.jpg


Èðµä¼Ò¾ß¼¯ÍÅÒ˼ҷ¨¹ú·Ö¹«Ë¾ÒòʹÓÃÌØ¹¤Èí¼þ²»·¨¼à¿ØÔ±¹¤±»·£¿£¿£¿£¿î120ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñ±¬·¢ÔÚ2009ÄêÖÁ2012Äê¼ä£¬£¬£¬£¬Ò˼ҷ¨¹ú¹«Ë¾¿ª·¢ÁËÒ»¸öÌØ¹¤ÏµÍ³À´¼à¿ØÔ±¹¤ºÍÌá³ö¾À·×µÄ¿Í»§¡£¡£¡£¡£¡£¡£¡£¸ÃϵͳΪ¹«Ë¾1996ÄêÖÁ2002ÄêµÄÈÏÕæÈËJean-Louis Baillot½¨ÉèµÄ£¬£¬£¬£¬Æä±»´¦ÒÔÁ½Ä껺Ð̺Í60630ÃÀÔª·£¿£¿£¿£¿î¡£¡£¡£¡£¡£¡£¡£Éó²é¹ÙÌåÏÖ£¬£¬£¬£¬Ò˼ҷ¨¹ú¹«Ë¾Ê¹Óþ¯·½ÐÂÎÅȪԴ£¬£¬£¬£¬Ô¼ÇëÁËÒ»¼Ò˽È˱£°²¹«Ë¾ºÍ˽ÈËÕì̽²»·¨»ñÈ¡ÆäÔ±¹¤µÄÉñÃØÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¸ÃÐÌÊÂÊÓ²ìÓÚ2012ÄêÆô¶¯£¬£¬£¬£¬Ö±µ½±¾Öܶþ²ÅÏÂÁî·£¿£¿£¿£¿î¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/ikea-fined-12m-for-spying-on/