ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ7ÖÜ
Ðû²¼Ê±¼ä 2021-02-18> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2021Äê02ÔÂ08ÈÕÖÁ02ÔÂ14ÈÕ¹²ÊÕ¼Çå¾²Îó²î62¸ö£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇHPE Apollo 70 System BMC¹Ì¼þLibifc.so WebStartFlash»º³åÇøÒç³öÎó²î£»£»£»Micro Focus Operation Bridge´úÂëÖ´ÐÐÎó²î£»£»£»Microsoft Windows DNSЧÀÍÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»Advantech iView SQL×¢ÈëÎó²î£»£»£»Adobe Animate CVE-2021-21052Ô½½çд´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇMozillaÐû²¼FirefoxÇå¾²¸üУ¬£¬£¬£¬ÐÞ¸´NTFSËð»µÎÊÌ⣻£»£»ÏÂÔØÁè¼Ý200Íò´ÎµÄChromeÀ©Õ¹Great Suspender°üÀ¨¶ñÒâ´úÂ룻£»£»WordPressµÄ²å¼þÖÐδÐÞ¸´µÄXSSÎó²î¿ÉÓ°ÏìÊýÍò¸öÍøÕ¾£»£»£»ÀÕË÷ÍÅ»ïZiggyÐû²¼Í˳ö£¬£¬£¬£¬²¢Ðû²¼Æä½âÃÜÃÜÔ¿£»£»£»KasperskyÐû²¼2020ÄêÕÊ»§½ÓÊܹ¥»÷ÊÂÎñµÄ»ØÊ×±¨¸æ¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£
> Ö÷ÒªÇå¾²Îó²îÁбí
1.HPE Apollo 70 System BMC¹Ì¼þLibifc.so WebStartFlash»º³åÇøÒç³öÎó²î
HPE Apollo 70 System BMC¹Ì¼þLibifc.so WebStartFlash±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf04080en_us
2.Micro Focus Operation Bridge´úÂëÖ´ÐÐÎó²î
Micro Focus Operation Bridge±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://softwaresupport.softwaregrp.com/doc/KM03775947
3.Microsoft Windows DNSЧÀÍÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î
Microsoft Windows DNSЧÀÍÆ÷±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿Éʹϵͳ±ÀÀ£»£»£»òÕßÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-24078
4.Advantech iView SQL×¢ÈëÎó²î
Advantech Iview±£´æSQL×¢ÈëÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄSQLÇëÇ󣬣¬£¬£¬²Ù×÷Êý¾Ý¿â£¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://us-cert.cisa.gov/ics/advisories/icsa-21-040-02
5.Adobe Animate CVE-2021-21052Ô½½çд´úÂëÖ´ÐÐÎó²î
Adobe Animate´¦Öóͷ£Îļþ±£´æÔ½½çдÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨¶ñÒâÎļþ£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://helpx.adobe.com/security/products/animate/apsb21-11.html
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢MozillaÐû²¼FirefoxÇå¾²¸üУ¬£¬£¬£¬ÐÞ¸´NTFSËð»µÎÊÌâ

MozillaÐû²¼ÁËFirefox 85.0.1£¬£¬£¬£¬ÐÞ¸´Á˿ɴ¥·¢NTFSË𻵵ÄÎÊÌâ¡£¡£¡£¡£Windows 10ºÍWindows XPÖб£´æÔÊÐí·ÇÌØÈ¨Óû§½«NTFS·ÖÇø±ê¼ÇΪ¡°ÔࡱµÄÎó²î£¬£¬£¬£¬Õâ»áµ¼ÖÂÇý¶¯Æ÷Ë𻵲¢ÐèÒªÓû§ÖØÐÂÆô¶¯ÒÔÐÞ¸´¡£¡£¡£¡£Firefox¿ÉÒÔͨ¹ý»á¼ûÌØÖÆÂ·¾¶À´´¥·¢NTFSËð»µÎÊÌ⣬£¬£¬£¬ÏÖÔڸ÷¾¶Òѱ»Õ¥È¡¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬´Ë´ÎÇå¾²¸üл¹ÐÞ¸´Á˶à¸öÎó²î£¬£¬£¬£¬ÈçmacOS×°±¸ÉÏʹÓÃSPNEGO¶ÔÍøÕ¾¾ÙÐÐÉí·ÝÑé֤ʱµÄÍß½âÎÊÌâµÈ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/software/mozilla-fixes-windows-10-ntfs-corruption-bug-in-firefox/
2¡¢ÏÂÔØÁè¼Ý200Íò´ÎµÄChromeÀ©Õ¹Great Suspender°üÀ¨¶ñÒâ´úÂë

Ê¢ÐеÄChromeÀ©Õ¹The Great Suspender°üÀ¨¶ñÒâ´úÂ룬£¬£¬£¬Òѱ»ÏÂÔØÁè¼Ý200Íò´Î¡£¡£¡£¡£¸ÃÀ©Õ¹ÓÃÓÚÔÝͣδʹÓõÄÑ¡Ï£¬£¬£¬£¬²¢½«ÔÝÍ£µÄÒ³ÃæÌæ»»Îª¿ÕÈ±Ò³ÃæÖ±µ½Óû§ÔÙ´ÎʹÓÃΪֹ£¬£¬£¬£¬Ö¼ÔÚ½ÚÔ¼×ÊÔ´¡£¡£¡£¡£GoogleÑо¿Ö°Ô±·¢Ã÷¿ª·¢ÕßÌí¼ÓÁËй¦Ð§£¬£¬£¬£¬¿É´ÓÔ¶³ÌЧÀÍÆ÷Ö´ÐÐí§Òâ´úÂ룬£¬£¬£¬ÕâÄܱ»ÓÃÀ´¾ÙÐÐ¹ã¸æÚ²ÆºÍ¸ú×ٵȶñÒâ»î¶¯¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬GoogleÒÑÓÚÉÏÖÜËĽ«¸ÃÀ©Õ¹´ÓÍøÉÏÊÐËÁÖÐɾ³ý£¬£¬£¬£¬»¹½«Æä´ÓÓû§µÄÅÌËã»úÖнûÓᣡ£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/the-great-suspender-chrome-extension-malware/
3¡¢WordPressµÄ²å¼þÖÐδÐÞ¸´µÄXSSÎó²î¿ÉÓ°ÏìÊýÍò¸öÍøÕ¾

WordPressµÄ²å¼þContact Form 7 StyleÖÐδÐÞ¸´µÄXSSÎó²î¿ÉÓ°ÏìÁè¼Ý5Íò¸öÍøÕ¾¡£¡£¡£¡£¸Ã²å¼þÓÃÓÚ½¨ÉèÍøÕ¾Ê¹ÓõÄÁªÏµ±íµ¥£¬£¬£¬£¬ÔÊÐíÓû§×Ô½çËµÍøÕ¾µÄ¼¶ÁªÑùʽ±í(CSS)´úÂëÀ´Ö¸¶¨wordpressµÄÍøÕ¾µÄÍâ¹Û¡£¡£¡£¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.8£¬£¬£¬£¬ÊÇÓÉÓÚ×Ô½ç˵CSS´úÂëµÄ¹¦Ð§È±ÉÙ¶ÔÊý¾ÝµÄÕûÀíºÍ¶ÔËæ»úÊýµÄ±£»£»£»¤»úÖÆ£¬£¬£¬£¬Ê¹¹¥»÷Õß¿ÉÒÔÌá½»ÏòÍøÕ¾×¢Èë¶ñÒâJavaScriptµÄÇëÇ󡣡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬»¹Î´Ðû²¼Õë¶Ô¸ÃÎó²îµÄ²¹¶¡³ÌÐò¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/unpatched-wordpress-plugin-code-injection/163706/
4¡¢ÀÕË÷ÍÅ»ïZiggyÐû²¼Í˳ö£¬£¬£¬£¬²¢Ðû²¼Æä½âÃÜÃÜÔ¿

ÖÜÄ©£¬£¬£¬£¬ÀÕË÷ÍÅ»ïZiggyÔÚTelegramÉÏÐû²¼Æä½«Í˳ö£¬£¬£¬£¬²¢Ðû²¼ËùÓнâÃÜÃÜÔ¿¡£¡£¡£¡£2ÔÂ7ÈÕ£¬£¬£¬£¬ZiggyÍÅ»ïÐû²¼ÁËÒ»¸ö°üÀ¨ÁË922¸ö½âÃÜÃÜÔ¿µÄSQLÎļþºÍÓë½âÃÜÃÜÔ¿Ò»ÆðʹÓõĽâÃÜÆ÷¡£¡£¡£¡£³ý´ËÖ®Í⣬£¬£¬£¬Ziggy»¹Ðû²¼ÁËÀëÏߵĽâÃÜÃÜÔ¿ºÍ²î±ð½âÃÜÆ÷µÄÔ´´úÂ룬£¬£¬£¬ÓÃÓÚÒòÔâµ½¹¥»÷¶øÎÞ·¨ÅþÁ¬µ½Internet»òC&CÎÞ·¨»á¼ûµÄÊܺ¦Õß¾ÙÐнâÃÜ¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ×î½üµ·»ÙEmotetºÍNetwalkerÐж¯¿ÉÄÜ»áʹ¸ü¶àÍÅ»ï¸ÐӦΣÏÕ²¢Í˳ö£¬£¬£¬£¬EmsisoftÒ²¼´½«Ðû²¼Æä½âÃÜÆ÷¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ziggy-ransomware-shuts-down-and-releases-victims-decryption-keys/
5¡¢KasperskyÐû²¼2020ÄêÕÊ»§½ÓÊܹ¥»÷ÊÂÎñµÄ»ØÊ×±¨¸æ

KasperskyÐû²¼ÁËÓйØ2020ÄêÕÊ»§½ÓÊܹ¥»÷ÊÂÎñµÄ»ØÊ×±¨¸æ¡£¡£¡£¡£±¨¸æÏÔʾ£¬£¬£¬£¬ÕË»§½ÓÊÜÊÂÎñÕ¼½ðÈÚЧÀÍÐÐҵڲƻµÄ±ÈÀýÉÏÉýÁË19%£¬£¬£¬£¬´Ó2019ÄêµÄ34£¥¼¤ÔöÖÁ2020ÄêµÄ54£¥¡£¡£¡£¡£³ýÁË½Ó»á¼Æ»§Ö®Í⣬£¬£¬£¬¹¥»÷Õß»¹ÀÄÓÃÖîÈçTeamViewerÖ®ÀàµÄÕýµ±Ô¶³ÌÖÎÀí¹¤¾ß£¨RAT£©À´ÊµÑé»á¼ûÓû§ÕÊ»§¡£¡£¡£¡£Kaspersky½¨Òé×é֯ͨ¹ýÏÞÖÆÉúÒâµÄʵÑé´ÎÊý¡¢¾ÙÐÐÄê¶ÈÇå¾²ÉóºËºÍÉøÍ¸²âÊÔÒÔ¼°ÊµÑé¶àÒòËØÉí·ÝÑéÖ¤µÄ·½·¨À´Ô¤·À´ËÀ๥»÷¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.kaspersky.com/about/press-releases/2021_share-of-account-takeover-incidents-increased-by-20-percentage-points


¾©¹«Íø°²±¸11010802024551ºÅ