Ó¢¹ú¹ú·À²¿µÄ¹ú·ÀѧԺÔâµ½¹¥»÷£¬ÒÉΪÍâ¹úºÚ¿Í£»IoT¹«Ë¾Sierra WirelessѬȾÀÕË÷Èí¼þµ¼ÖÂÉú²úÖжÏ

Ðû²¼Ê±¼ä 2021-03-24

1.Ó¢¹ú¹ú·À²¿µÄ¹ú·ÀѧԺÔâµ½¹¥»÷£¬ÒÉΪÍâ¹úºÚ¿Í


1.jpg


Ó¢¹ú¹ú·À²¿µÄ¹ú·ÀѧԺÔâµ½ÑÏÖØµÄ¹¥»÷£¬»³ÒÉÊǶíÂÞ˹µÈÍâ¹úÊÆÁ¦ËùΪ¡£¸ÃѧԺλÓÚÅ£½ò¿¤Î÷ÄÏʲÀï·òÄÉÄ·£¬Ö÷ҪΪӢ¹úÎä×°¶ÓÎé¡¢¹«ÎñÔ±¡¢ÆäËûÕþ¸®²¿Ãź͹ú¼Ò·þÎñÈËÔ±Ìṩ¸ßµÈ½ÌÓý¡£´Ë´Î¹¥»÷µ¼Ö¸ÃѧԺµÄ¹ÙÍøÖжÏ£¬ÓɳаüÉÌÔËÓªµÄITÍøÂç±»ÆÆ»µ£¬Ñ§Ð£ÏµÍ³Ò²Êܵ½Ó°Ï죬¸ÃУԱ¹¤±»ÆÈʹÓøöÈ˵çÄÔ½øÐа칫¡£¾ÝϤ£¬Ô¤¼ÆÐèÒª5ÖÜʱ¼ä²ÅÆøÍêÈ«»Ö¸´ÊÜÓ°ÏìµÄ¼ÆËã»úºÍ·þÎñÆ÷¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/115870/hacking/ministry-of-defence-hacked.html


2.ºÚ¿ÍÀûÓÃAccellionµÄFTAÖЩ¶´ÈëÇÖ¿ÇÅÆ²¢Î´Ó°ÏìÆäÍøÂç


2.jpg


ºÚ¿ÍÀûÓÃAccellionµÄFile Transfer Appliance£¨FTA£©ÖЩ¶´ÈëÇÖÄÜÔ´¹«Ë¾¿ÇÅÆ¡ £¿ÇÅÆ¹«Ë¾Éù³Æ£¬¸Ãʼþ½öÓ°ÏìÁËFTAÉ豸£¬ÒòΪÎļþ´«Êä·þÎñÓëÆäËûÊý×Ö»ù´¡ÉèÊ©ÊǸôÀëµÄ£¬Òò´ËÆäºËÐÄITϵͳδÊܵ½ÈκÎÓ°Ïì¡£´ËÍ⣬¹¥»÷Õß¿ÉÄÜÒѾ­ÇÔÈ¡²¿ÃÅÊý¾Ý£¬°üÂÞһЩ¸öÈËÐÅÏ¢ÒÔ¼°¿ÇÅÆ¹«Ë¾ºÍÆäÀûÒæÏà¹ØÕßµÄÊý¾Ý¡£¾¡¹Ü¿ÇÅÆ¹«Ë¾Ã»ÓÐÅû¶¹¥»÷ÕßµÄÉí·Ý£¬µ«Ñо¿ÈËÔ±ÍÆ²â£¬´Ë´Î¹¥»÷ÓëFIN11ºÚ¿ÍÍÅ»ïÓйØ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/energy-giant-shell-discloses-data-breach-after-accellion-hack/


3.IoT¹«Ë¾Sierra WirelessѬȾÀÕË÷Èí¼þµ¼ÖÂÉú²úÖжÏ


3.jpg


3ÔÂ20ÈÕ£¬¼ÓÄôó¿ç¹úÎÞÏßͨÐÅÉè±¸ÖÆÔìÉÌSierra WirelessѬȾÀÕË÷Èí¼þ£¬ËùÓÐÉú²ú»î¶¯±»ÆÈÖжÏ¡£¸Ã¹«Ë¾Ö÷ÒªÏúÊÛͨÐÅÉ豸£¬ÔÚ±±ÃÀ¡¢Å·ÖÞºÍÑÇÖÞ¾ùÉèÓÐÑз¢ÖÐÐÄ¡£´Ë´Î¹¥»÷µ¼Ö¹«Ë¾¹ÙÍøºÍÄÚ²¿ÔËÓªÔâµ½ÆÆ»µ£¬È«ÇòµÄÉú²ú¹¤³§±»ÆÈ¹Ø±Õ¡£µ«ÒòÆäÄÚ²¿ITϵͳÓë¿Í»§µÄ·þÎñÖ®¼äÀ뿪¿ªÁË£¬ËùÒÔ¿Í»§²¢Î´Êܵ½Ó°Ï졣Ŀǰ£¬¸Ã¹«Ë¾ÕýÔÚµÚÈý·½×¨¼ÒµÄЭÖúÏÂÊÓ²ì´Ëʼþ£¬²¢2ÔÂ23ÈÕ³·»ØÁËÉϸöÔÂÐû²¼µÄ2021ÄêµÚÒ»¼¾¶ÈÖ¸µ¼³ÂËß¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/115897/malware/sierra-wireless-ransomware.html


4.¹È¸èÅû¶ÀûÓøßͨоƬÖÐÊäÈëÑé֤©¶´µÄ¹¥»÷»î¶¯


4.jpg


¹È¸èÔÚÒ°·¢ÏÖÀûÓøßͨоƬÖÐÊäÈëÑé֤©¶´£¨CVE-2020-11261£©À´Õë¶ÔAndroidϵͳµÄ¹¥»÷»î¶¯¡£¸Ã©¶´Î»ÓÚͼÐÎ×é¼þÖУ¬CVSSÆÀ·ÖΪ8.4£¬µ±ÌØÖƵÄÓ¦Ó÷¨Ê½ÇëÇó·ÃÎÊÉ豸ÖеĴóÁ¿ÄÚ´æÊ±£¬¿ÉÄܵ¼ÖÂÄÚ´æÆÆ»µ¡£¸Ã©¶´ÓÚ2020Äê8ÔÂ20ÈÕ±»Åû¶£¬²¢ÓÚ2021Äê1Ôµõ½ÐÞ¸´¡£GoogleÔÚ3ÔÂ18ÈÕ¸üеÄ1ÔÂÄþ¾²Í¨¸æÖÐÌåÏÖ£¬CVE-2020-11261¿ÉÄÜÒѾ­±»ÀûÓÃÌᳫÕë¶ÔÐÔ¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/03/warning-new-android-zero-day.html


5.ͨÓÃµçÆø£¨GE£©µÄURÉ豸´æÔÚ¶à¸öÑÏÖØµÄ©¶´


5.jpg


CISA¾¯¸æÍ¨ÓÃµçÆø£¨GE£©µÄͨÓü̵çÆ÷£¨UR£©ÏµÁеçÔ´¹ÜÀíÉ豸ÖдæÔÚ9¸öÑÏÖØµÄ©¶´¡£¸Ã¹«Ë¾³ÆURÉ豸ÊǼò»¯µçÔ´¹ÜÀíÒÔ±£»¤Òªº¦×ʲúµÄ»ù´¡£¬ÔÊÐíÓû§¿ØÖÆÖÖÖÖÉ豸ÏûºÄµÄµç¹¦ÂÊÁ¿µÄ¼ÆËãÉ豸¡£ÆäÖÐ×îÑÏÖØµÄ©¶´ÊÇCVE-2021-27426£¬ÓÉĬÈϱäÁ¿³õʼ»¯²»Äþ¾²µ¼Ö£¬CVSSÆÀ·ÖΪ9.8£¬¹¥»÷Õß¿ÉÔ¶³ÌÀûÓøÃ©¶´Èƹý·ÃÎÊÏÞÖÆ¡£Æä´ÎΪ¿ÉÓÃÀ´ÖØÆôURµÄCVE-2021-27430ºÍÊäÈëÑé֤©¶´£¨CVE-2021-27418ºÍCVE-2021-27420£©µÈ¡£


 Ô­ÎÄÁ´½Ó£º

https://threatpost.com/cisa-security-flaws-ge-power-management/164961/


6.KasperskyÐû²¼2020ÄêICSÐÐÒµµÄÌ¬ÊÆ·ÖÎö³ÂËß


6.jpg


KasperskyÐû²¼ÁË2020ÄêICSÐÐÒµµÄÌ¬ÊÆ·ÖÎö³ÂËß¡£¸Ã³ÂËß·ÖÎöÁËÓÃÓÚÉè¼Æ¡¢ÅäÖúÍά»¤¹¤Òµ¿ØÖÆÉ豸ºÍÈí¼þµÄ¼ÆËã»úËùÊܵ½µÄÍøÂçÍþв¡£³ÂËßÖ¸³ö£¬ÔÚ2020ÄêϰëÄ꣬ÔÚICS¹¤³ÌºÍ¼¯³ÉÐÐÒµÖÐ39.3£¥µÄ¼ÆËã»úÊܵ½Á˶ñÒâÈí¼þ¹¥»÷£¬Óë2020ÄêÉϰëÄ꣨31.5£¥£©Ïà±ÈÓÐËùÔö¼Ó£¬ÆäÖн¨Öþ×Ô¶¯»¯¡¢Æû³µÖÆÔì¡¢ÄÜԴʯÓͺÍÌìÈ»ÆøÐÐÒµÔâµ½µÄ¹¥»÷Ôö¶à¡£2020ÄêϰëÄ꣬Õë¶ÔÀ­¶¡ÃÀÖÞ¡¢Öж«¡¢ÑÇÖ޺ͱ±ÃÀµÄ¹¥»÷´ÎÊýÔö¶à£¬Õë¶Ô·ÇÖÞ¡¢¶íÂÞ˹ºÍÅ·Ö޵Ĺ¥»÷ÊýÁ¿ÓÐËù¼õÉÙ¡£


Ô­ÎÄÁ´½Ó£º

https://ics-cert.kaspersky.com/reports/2021/03/17/threat-landscape-for-the-ics-engineering-and-integration-sector-2020/