ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ32ÖÜ

Ðû²¼Ê±¼ä 2021-08-09

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2021Äê08ÔÂ02ÈÕÖÁ08ÔÂ08ÈÕ¹²ÊÕ¼Çå¾²Îó²î63¸ö£¬£¬£¬£¬ £¬£¬ÖµµÃ¹Ø×¢µÄÊÇGoogle Android¸ßͨ×é¼þCVE-2021-1972´úÂëÖ´ÐÐÎó²î£»£» £»£»£»£»Cisco Connected Mobile Experiences¸ü¸ÄÃÜÂëÑéÖ¤ÈÆ¹ýÎó²î£»£» £»£»£»£»Claroty Secure Remote Access SQL×¢ÈëÎó²î£»£» £»£»£»£»Advantech WebAccess/SCADA CVE-2021-32943Õ»Òç³öÎó²î£»£» £»£»£»£»Pulse Connect Secure CVE-2021-22933·¾¶±éÀúÎó²î ¡£¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǺڿ͹ûÕæµç×ÓÒÕ½çEAµÄÊý¾Ý£¬£¬£¬£¬ £¬£¬°üÀ¨FIFA 21ÓÎÏ·Ô´Â룻£» £»£»£»£»Ñо¿ÍŶӳÆDarkSide»òÒÔBlackMatterÖ®ÃûÖØÐ»ع飻£» £»£»£»£»PythonÐû²¼Çå¾²¸üУ¬£¬£¬£¬ £¬£¬ÐÞ¸´PyPI´æ´¢¿âÖжà¸öÎó²î£»£» £»£»£»£»KasperskyÅû¶ÐµÄGhostEmperorÍÅ»ïÕë¶Ô¶«ÄÏÑÇ£»£» £»£»£»£»Ñо¿Ö°Ô±Åû¶TCP/IPÖÐͳ³ÆÎªINFRA:HALTµÄ14¸öÎó²î ¡£¡£¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬ £¬£¬±¾ÖÜÇå¾²ÍþвΪÖÐ ¡£¡£¡£¡£¡£¡£¡£


> Ö÷ÒªÇå¾²Îó²îÁбí


1.Google Android¸ßͨ×é¼þCVE-2021-1972´úÂëÖ´ÐÐÎó²î


Google Android¸ßͨ×é¼þ±£´æÇå¾²Îó²î£¬£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ £¬£¬¿Éʹϵͳ±ÀÀ£»£» £»£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë ¡£¡£¡£¡£¡£¡£¡£

https://source.android.com/security/bulletin/2021-08-01


2.Cisco Connected Mobile Experiences¸ü¸ÄÃÜÂëÑéÖ¤ÈÆ¹ýÎó²î


Cisco Connected Mobile Experiences¸ü¸ÄÃÜÂëʵÏÖ±£´æÇå¾²Îó²î£¬£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ £¬£¬¿ÉÈÆ¹ýÑé֤δÊÚȨ»á¼û ¡£¡£¡£¡£¡£¡£¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cmx-GkCvfd4


3.Claroty Secure Remote Access SQL×¢ÈëÎó²î


Claroty Secure Remote Access±£´æSQL×¢ÈëÎó²î£¬£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄSQLÇëÇ󣬣¬£¬£¬ £¬£¬²Ù×÷Êý¾Ý¿â£¬£¬£¬£¬ £¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐí§Òâ´úÂë ¡£¡£¡£¡£¡£¡£¡£

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0017


4.Advantech WebAccess/SCADA CVE-2021-32943Õ»Òç³öÎó²î


Advantech WebAccess/SCADA±£´æÕ»Òç³öÎó²î£¬£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ £¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£» £»£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë ¡£¡£¡£¡£¡£¡£¡£

https://us-cert.cisa.gov/ics/advisories/icsa-21-217-04


5.Pulse Connect Secure CVE-2021-22933·¾¶±éÀúÎó²î


Pulse Connect Secure±£´æÄ¿Â¼±éÀúÎó²î£¬£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ £¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄɾ³ýϵͳí§ÒâÎļþ ¡£¡£¡£¡£¡£¡£¡£

https://www.pulsesecure.net/products/remote-access-overview/


 > Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢ºÚ¿Í¹ûÕæµç×ÓÒÕ½çEAµÄÊý¾Ý£¬£¬£¬£¬ £¬£¬°üÀ¨FIFA 21ÓÎÏ·Ô´Âë


1


7ÔÂ26ÈÕÐÇÆÚÒ»£¬£¬£¬£¬ £¬£¬ºÚ¿ÍÔÚ°µÍø¹ûÕæµç×ÓÒÕ½çEAµÄÊý¾Ý£¬£¬£¬£¬ £¬£¬°üÀ¨FIFA 21ÓÎÏ·Ô´Âë¡¢FrostBiteÓÎÏ·ÒýÇæºÍµ÷ÊÔ¹¤¾ßÔ´´úÂëµÈÐÅÏ¢ ¡£¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñ×î³õÓÚ6ÔÂ10ÈÕÅû¶£¬£¬£¬£¬ £¬£¬ÆäʱºÚ¿ÍÉù³ÆÇÔÈ¡Á˸ù«Ë¾780GBµÄÊý¾Ý£¬£¬£¬£¬ £¬£¬²¢Ô¸ÒâÒÔ2800ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛ ¡£¡£¡£¡£¡£¡£¡£µ«ÓÉÓÚ±»µÁÊý¾Ý´ó¶àÊÇÔ´´úÂë¶ÔÍøÂç·¸·¨ÍÅ»ïÀ´ËµÃ»ÓÐÈκμÛÖµ£¬£¬£¬£¬ £¬£¬Òò´Ë²¢Î´ÕÒµ½Âò¼Ò ¡£¡£¡£¡£¡£¡£¡£Ö®ºóºÚ¿ÍÊÔͼÀÕË÷EA£¬£¬£¬£¬ £¬£¬ÔÚ7ÔÂ14ÈÕÐû²¼ÁË1.3GBµÄFIFAÔ´´úÂë×÷ΪÑù±¾£¬£¬£¬£¬ £¬£¬²¢ÔÚ2ÖÜЧ¹ûÕæÁËËùÓÐÊý¾Ý ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/hackers-leak-full-ea-data-after-failed-extortion-attempt/


2¡¢Ñо¿ÍŶӳÆDarkSide»òÒÔBlackMatterÖ®ÃûÖØÐ»عé


2.jpg


Ñо¿ÍŶӳÆÀÕË÷ÍÅ»ïDarkSide¿ÉÄÜÒÑÖØÐÂÃüÃûΪеÄBlackMatterÖØÐÂ»Ø¹é ¡£¡£¡£¡£¡£¡£¡£DarkSideÔÚ¹¥»÷ÃÀ¹ú×î´óµÄȼÁϹܵÀColonial Pipelineºó£¬£¬£¬£¬ £¬£¬ÓÚ½ñÄê5ÔÂͻȻ¹Ø±Õ ¡£¡£¡£¡£¡£¡£¡£ÉÏÖÜ£¬£¬£¬£¬ £¬£¬Ñо¿Ö°Ô±·¢Ã÷еÄÀÕË÷Èí¼þBlackMatter ¡£¡£¡£¡£¡£¡£¡£ÆÊÎö·¢Ã÷£¬£¬£¬£¬ £¬£¬¶þÕßʹÓõļÓÃܳÌÐòÏÕЩÏàͬ£¬£¬£¬£¬ £¬£¬°üÀ¨DarkSideËùÌØÓеÄ×Ô½ç˵Salsa20¾ØÕó ¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬£¬¶þÕß¶¼Ê¹ÓÃÁËDarkSide¶ÀÍ̵ÄRSA-1024ʵÏÖ¡¢½ÓÄÉÁËÏàͬµÄ¼ÓÃÜËã·¨²¢ÇÒÊý¾ÝÐ¹Â¶ÍøÕ¾¶¼Ê¹ÓÃÁËÀàËÆµÄÓïÑÔ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/darkside-ransomware-gang-returns-as-new-blackmatter-operation/


3¡¢PythonÐû²¼Çå¾²¸üУ¬£¬£¬£¬ £¬£¬ÐÞ¸´PyPI´æ´¢¿âÖжà¸öÎó²î


3.jpg


PythonÍŶÓÐû²¼Çå¾²¸üУ¬£¬£¬£¬ £¬£¬ÐÞ¸´ÁËPython Package Index (PyPI)´æ´¢¿âÖеÄ3¸öÎó²î ¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄÎó²îÖУ¬£¬£¬£¬ £¬£¬×îÑÏÖØµÄÒ»¸öÔÊÐí¹¥»÷ÕßÔÚPyPIµÄ»ù´¡ÉèÊ©ÉÏÔËÐÐÏÂÁ£¬£¬£¬ £¬£¬À´ÇÔÈ¡´úÂë¿âÖеÄÁîÅÆ»òÆäËüÃÜÂ룬£¬£¬£¬ £¬£¬²¢ÇÒÕâЩÁîÅÆ»òÃÜÂ뻹¿É±»ÓÃÀ´»á¼ûºÍ¸Ä¶¯PyPI´úÂë ¡£¡£¡£¡£¡£¡£¡£ÁíÍâÁ½¸öÎó²îÖУ¬£¬£¬£¬ £¬£¬Ò»¸öÔÊÐí¹¥»÷Õßɾ³ý²»ÔÚÆä¿ØÖÆÏµÄÏîÄ¿µÄÎĵµ£¬£¬£¬£¬ £¬£¬¶øÁíÒ»¸öÔÊÐí¹¥»÷Õßɾ³ý²»ÔÚÆä¿ØÖÆÏµÄÏîÄ¿ÖеĽÇÉ« ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/python-team-fixes-bug-that-allowed-takeover-of-pypi-repository/


4¡¢KasperskyÅû¶ÐµÄGhostEmperorÍÅ»ïÕë¶Ô¶«ÄÏÑÇ


4.jpg


KasperskyÅû¶ÁËÒ»¸öеĺڿÍÍÅ»ïGhostEmperor£¬£¬£¬£¬ £¬£¬Ö÷ÒªÕë¶Ô¶«ÄÏÑǵØÇøµÄÄ¿µÄ£¬£¬£¬£¬ £¬£¬°üÀ¨Õþ¸®»ú¹¹ºÍ¼¸¼ÒµçÐŹ«Ë¾ ¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïµÄÈëÇֻÒÀÀµÓÚCheat Engine¿ªÔ´ÏîÄ¿µÄÒ»¸ö×é¼þ£¬£¬£¬£¬ £¬£¬ËüÄܹ»ÈƹýWindowsÇý¶¯³ÌÐòÇ¿ÖÆÊðÃû»úÖÆ ¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïÖ®ÒÔÊÇÓëÖÚ²î±ð£¬£¬£¬£¬ £¬£¬ÊÇÓÉÓÚËüʹÓÃÁËÒ»¸öÒÔǰ²»ÎªÈËÖªµÄWindowsÄÚºËģʽµÄrootkit£¬£¬£¬£¬ £¬£¬²¢ÇÒ½ÓÄÉÁËÖØ´óµÄ¶à½×¶Î¶ñÒâÈí¼þ¿ò¼Ü£¬£¬£¬£¬ £¬£¬Ö¼ÔÚ¶ÔÄ¿µÄЧÀÍÆ÷¾ÙÐÐÔ¶³Ì¿ØÖÆ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/120721/apt/ghostemperor-chinese-speaking-threat-actor.html


5¡¢Ñо¿Ö°Ô±Åû¶TCP/IPÖÐͳ³ÆÎªINFRA:HALTµÄ14¸öÎó²î


5.jpg


Ñо¿Ö°Ô±Åû¶ÁËÔÚNicheStack TCP/IP¿ÍÕ»Öз¢Ã÷µÄͳ³ÆÎªINFRA:HALTµÄ14¸öÇå¾²Îó²î£¬£¬£¬£¬ £¬£¬Ó°ÏìÁËÁè¼Ý200¼Ò¹©Ó¦ÉÌÖÆÔìµÄOT×°±¸ ¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²î¿ÉÒÔµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС¢¾Ü¾øÐ§ÀÍ (DoS)ºÍÐÅϢй¶¡¢TCPÓÕÆ­ºÍDNS»º´æÖж¾ ¡£¡£¡£¡£¡£¡£¡£ÆäÖÐ×îÑÏÖØµÄÎó²îΪCVE-2020-25928ºÍCVE-2020-31226£¬£¬£¬£¬ £¬£¬ÆÀ·Ö»®·ÖΪ9.8ºÍ9.1£¬£¬£¬£¬ £¬£¬Ó°ÏìÁË¿ÍÕ»µÄDNS¿Í»§¶ËºÍHTTPЧÀÍÆ÷×é¼þ£¬£¬£¬£¬ £¬£¬¿ÉÓÃÀ´ÔÚÄ¿µÄ×°±¸ÉÏÖ´ÐдúÂë²¢ÍêÈ«¿ØÖÆËü ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/08/critical-flaws-affect-embedded-tcpip.html