ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ15ÖÜ
Ðû²¼Ê±¼ä 2021-04-13> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2021Äê04ÔÂ05ÈÕÖÁ04ÔÂ11ÈÕ¹²ÊÕ¼Çå¾²Îó²î41¸ö£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇCisco RV345P Dual WAN Gigabit VPN Routers CVE-2021-1414í§Òâ´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»LiteSpeed Technologies OpenLiteSpeed web serverȨÏÞÌáÉýÎó²î£»£»£»£»£»£»OpenIAM Groovy Script´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»SonicWall GMSÔ¶³ÌȨÏÞÌáÉýÎó²î£»£»£»£»£»£»Skyworth Digital Technology RN510»º³åÇøÒç³öÎó²î¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇTIMÍŶÓÅû¶CA Technologies²úÆ·ÖеĶà¸ö0day£»£»£»£»£»£»KasperskyÅû¶Õë¶ÔÔ½Ä϶à¸ö×éÖ¯µÄÍøÂçÌØ¹¤»î¶¯£»£»£»£»£»£»ÐÂ¼ÓÆÂ¹¤»áe2iÔâµ½´¹ÂÚ¹¥»÷£¬£¬£¬£¬Ð¹Â¶ÊýÍò¹«ÃñµÄÐÅÏ¢£»£»£»£»£»£»Å·ÃË³ÆÆä¶à¸ö»ú¹¹ÔÚÉÏÖÜÔâµ½¹¥»÷£¬£¬£¬£¬ÊÂÎñÈÔÔÚÊÓ²ìÖУ»£»£»£»£»£»ESETÅû¶Õë¶ÔÀ¶¡ÃÀÖÞµØÇøÓû§µÄÐÂÒøÐÐľÂíJaneleiro¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£
> Ö÷ÒªÇå¾²Îó²îÁбí
1.Cisco RV345P Dual WAN Gigabit VPN Routers CVE-2021-1414í§Òâ´úÂëÖ´ÐÐÎó²î
CCisco RV345P Dual WAN Gigabit VPN Routers WEBÖÎÀí½Ó¿Ú±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÌáÉýȨÏÞ¡£¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv34x-rce-8bfG2h6b
2.LiteSpeed Technologies OpenLiteSpeed web serverȨÏÞÌáÉýÎó²î
LiteSpeed Technologies OpenLiteSpeed web server±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÔÚÖ÷»úÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£
https://github.com/litespeedtech/openlitespeed/issues/217
3.OpenIAM Groovy Script´úÂëÖ´ÐÐÎó²î
OpenIAM Groovy Script±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£
https://github.com/Accenture/AARO-Bugs/blob/master/AARO-CVE-List.md
4.SonicWall GMSÔ¶³ÌȨÏÞÌáÉýÎó²î
SonicWall GMS±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔROOTȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0009
5.Skyworth Digital Technology RN510»º³åÇøÒç³öÎó²î
Skyworth Digital Technology RN510 /cgi-bin/app-staticIP.asp»º³åÇøÒç³öÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£
https://s3curityb3ast.github.io/KSA-Dev-011.md
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢TIMÍŶÓÅû¶CA Technologies²úÆ·ÖеĶà¸ö0day

CA TechnologiesÊÇÃÀ¹úÒ»¼ÒרעÓÚB2BÈí¼þµÄ¿ç¹ú¹«Ë¾£¬£¬£¬£¬ÏúÊÛ½ü200ÖÖ²úÆ·£¬£¬£¬£¬Éæ¼°ÂþÑÜʽÅÌËã¡¢ÔÆÅÌËã¡¢DevOpsºÍÅÌËã»úÇå¾²Èí¼þÒÔ¼°Òƶ¯×°±¸¡£¡£TIMµÄRed Team ResearchÍŶÓÅû¶ÁËCA eHealth Performance Manager²úÆ·ÖеÄ5¸öÐÂÎó²î¡£¡£»®·ÖΪÌáȨÎó²î£¨CVE-2021-28246ºÍCVE-2021-28249£©¡¢¿çÕ¾µã¾ç±¾Îó²î£¨CVE-2021-28247£©¡¢Í¨¹ýSUID/GUIDÎļþµÄÌáȨÎó²î£¨CVE-2021-28250£©ºÍÉí·ÝÑéÖ¤Îó²î£¨CVE-2021-28248£©¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/116268/security/ca-ehealth-performance-manager-flaws.html
2¡¢KasperskyÅû¶Õë¶ÔÔ½Ä϶à¸ö×éÖ¯µÄÍøÂçÌØ¹¤»î¶¯

KasperskyÅû¶ÁËAPT×éÖ¯CycldekÕë¶ÔÔ½ÄÏÕþ¸®ºÍ¾üÊÂ×éÖ¯µÄÍøÂçÌØ¹¤»î¶¯¡£¡£¸Ã»î¶¯Ê¹ÓÃÁËÃûΪFoundCoreµÄ¶ñÒâÈí¼þ£¬£¬£¬£¬¿É¾ÙÐÐÎļþϵͳʹÓá¢Àú³ÌʹÓá¢ÆÁÄ»½ØÍ¼²¶»ñºÍí§ÒâÏÂÁîÖ´ÐС£¡£±ðµÄ£¬£¬£¬£¬Kaspersky³Æ¸Ã×éÖ¯ÔÚÖØ´óÐÔ·½ÃæÈ¡µÃÁËÖØ´óǰ½ø£¬£¬£¬£¬ÀýÈ磬£¬£¬£¬ÆäpayloadµÄ±êÍ·£¨´úÂëµÄÄ¿µÄºÍÔ´£©±»ÍêÈ«°þÀ룬£¬£¬£¬Ê£ÏµÄÉÙÊý²¿·ÖµÄÖµÊDz»Á¬¹áµÄ£¬£¬£¬£¬Õâ´ó´óÔöÌíÁËÑо¿Ö°Ô±¶ÔÆä¾ÙÐÐÆÊÎöµÄÄѶȡ£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/spy-operations-vietnam-rat/165243/
3¡¢ÐÂ¼ÓÆÂ¹¤»áe2iÔâµ½´¹ÂÚ¹¥»÷£¬£¬£¬£¬Ð¹Â¶ÊýÍò¹«ÃñµÄÐÅÏ¢

ÐÂ¼ÓÆÂÌìϹ¤»á´ú±í´ó»á¾ÍÒµÓë¾ÍÒµÑо¿Ëù£¨e2i£©ÔÚ±¾ÖÜÒ»£¨4ÔÂ5ÈÕ£©Ðû²¼ÉùÃ÷³Æ£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜÒѾ»á¼ûÆäÓû§µÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨Óû§µÄÐÕÃû¡¢½ÌÓý×ʸñºÍNRIC¡¢ÁªÏµ·½·¨ºÍ¾Íҵϸ½ÚµÈ¡£¡£ÊÂÎñ±¬·¢ÔÚ3ÔÂ12ÈÕ£¬£¬£¬£¬ÆäµÚÈý·½¹©Ó¦ÉÌ¡ª¡ªÁªÂçÖÐÐÄÕÛÎñ¹«Ë¾i-vic InternationalÔ±¹¤µÄÓÊÏäÔâµ½´¹ÂÚ¹¥»÷£¬£¬£¬£¬¸ÃÓÊÏäµÄÔÆ¶Ë°üÀ¨ÁËÔ¼3Íò¸ö¼ÓÈëÁËe2i»î¶¯µÄÓû§ÐÅÏ¢£¬£¬£¬£¬¿ÉÊǸûú¹¹¾Ü¾øÍ¸Â¶×ܹ²Óм¸¶àÈËÔøÊ¹Óùýe2iµÄЧÀÍ¡£¡£
ÔÎÄÁ´½Ó£º
https://www.straitstimes.com/tech/tech-news/personal-data-of-30000-people-who-use-ntucs-e2i-services-may-have-been-breached
4¡¢Å·ÃË³ÆÆä¶à¸ö»ú¹¹ÔÚÉÏÖÜÔâµ½¹¥»÷£¬£¬£¬£¬ÊÂÎñÈÔÔÚÊÓ²ìÖÐ

Å·ÃËίԱ»á½²»°È˳ƣ¬£¬£¬£¬°üÀ¨Î¯Ô±»áÔÚÄڵĶà¸öÅ·ÃË×éÖ¯ÔÚÉÏÖÜÔâµ½ÁËÍøÂç¹¥»÷¡£¡£ÏÖÔÚ¶Ô¸ÃÊÂÎñµÄȡ֤ÆÊÎöÈÔ´¦ÓÚ³õÆÚ½×¶Î£¬£¬£¬£¬ÉÐδ¼ì²âµ½±£´æÐÅϢй¶ÎÊÌâ¡£¡£Åí²©ÉçÌåÏÖ£¬£¬£¬£¬´Ë´ÎÊÂÎñ±ÈÅ·ÃËÒÔÍùÔâµ½µÄ¹¥»÷¸üΪÑÏÖØ£¬£¬£¬£¬Å·ÃËij¹ÙÔ±»¹Í¸Â¶£¬£¬£¬£¬ÆäÊÂÇéÖ°Ô±½üÆÚÊÕµ½ÁËÓйØÕë¶ÔÅ·Ã˵Ĵ¹ÂÚ¹¥»÷Ô¤¾¯¡£¡£ÏÖÔÚ£¬£¬£¬£¬Å·ÃËÈÔδ¹ûÕæÓйش˴ÎÊÂÎñµÄÐÔ×Ó»òÆä±³ºóµÄ¹¥»÷ÕßÉí·ÝµÄÐÅÏ¢¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bloomberg.com/news/articles/2021-04-06/european-institutions-were-targeted-in-a-cyber-attack-last-week
5¡¢ESETÅû¶Õë¶ÔÀ¶¡ÃÀÖÞµØÇøÓû§µÄÐÂÒøÐÐľÂíJaneleiro

ESETµÄÑо¿Ö°Ô±Åû¶ÁËÕë¶ÔÀ¶¡ÃÀÖÞµØÇøÓû§µÄÐÂÐÍÒøÐÐľÂíJaneleiro¡£¡£¸ÃľÂíÖÁÉÙ´Ó2019ÄêÒÔÀ´¾Í×îÏÈÕë¶Ô°ÍÎ÷µÄÆóÒµ£¬£¬£¬£¬Éæ¼°¹¤³Ì¡¢Ò½ÁƱ£½¡¡¢ÁãÊÛ¡¢ÖÆÔìÒµ¡¢½ðÈÚ¡¢ÔËÊäºÍÕþ¸®µÈ¸÷¸öÁìÓò¡£¡£Janeleiroͨ¹ýαÔì´óÐÍÒøÐÐÍøÕ¾£¨SantanderºÍBanco do BrasilµÈ£©µÄµ¯´°À´ÓÕ»óÄ¿µÄ£¬£¬£¬£¬ÕâЩµ¯´°°üÀ¨ÐéαµÄ±í¸ñÀ´ÓÕʹĿµÄÊäÈëÒøÐÐÆ¾Ö¤ºÍСÎÒ˽¼ÒÐÅÏ¢¡£¡£±ðµÄ£¬£¬£¬£¬JaneleiroÊÇÓÉVisual Basic .NET±àдµÄ£¬£¬£¬£¬ÕâÓë¸ÃµØÇøµÄºÚ¿ÍËùϲ»¶µÄDelphiÓкܴóµÄÊÕÖ§¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/04/experts-uncover-new-banking-trojan.html


¾©¹«Íø°²±¸11010802024551ºÅ