ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ3ÖÜ

Ðû²¼Ê±¼ä 2021-01-18

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2021Äê01ÔÂ11ÈÕÖÁ01ÔÂ17ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´70¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Word CVE-2021-1715´úÂëÖ´ÐЩ¶´ £»Siemens JT2Go JT½âÎöÀàÐÍ»ìÏý´úÂëÖ´ÐЩ¶´ £»Cisco Connected Mobile Experiences CVE-2021-1144ȨÏÞÌáÉý©¶´ £»Adobe Photoshop¶Ñ»º³åÇøÒç³ö´úÂëÖ´ÐЩ¶´ £»Xiaomi AX1800µÇ¼ÑéÖ¤Èƹý©¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÐÂÎ÷À¼´¢ÐîÒøÐÐÔâµ½¹¥»÷£¬Ãô¸ÐÐÅÏ¢»òÒÑй¶ £»ÁªºÏ¹ú»·¾³¹æ»®ÊðµÄGit´æ´¢¿âй¶Áè¼Ý10Íò¸öµÄÔ±¹¤ÐÅÏ¢ £»Socialarksй¶400GBÊý¾Ý£¬Ó°ÏìÈ«Çò2ÒÚ¶àÓû§ £»ÐÂSolarLeaksÍøÕ¾³öÊÛSolarWinds¹©Ó¦Á´¹¥»÷ÖеÄÀúÊ·Êý¾Ý £»SkypeÔÚÈ«Çò·¶Î§ÄÚ·þÎñÖжÏ£¬Ô­ÒòÉв»Ã÷È·¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


> ÖØÒªÄþ¾²Â©¶´Áбí


1.Microsoft Word CVE-2021-1715´úÂëÖ´ÐЩ¶´


Microsoft Word´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-1715


2.Siemens JT2Go JT½âÎöÀàÐÍ»ìÏý´úÂëÖ´ÐЩ¶´


Siemens JT2Go JTÎļþ½âÎö´æÔÚÀàÐÍ»ìÏý©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://us-cert.cisa.gov/ics/advisories/icsa-21-012-03


3.Cisco Connected Mobile Experiences CVE-2021-1144ȨÏÞÌáÉý©¶´


Cisco Connected Mobile Experiences¸ü¸ÄÃÜÂëÊÚȨ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɸü¸ÄÈÎÒâÓû§ÃÜÂ룬ÌáÉýÌØȨ¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cmxpe-75Asy9k


4.Adobe Photoshop¶Ñ»º³åÇøÒç³ö´úÂëÖ´ÐЩ¶´


Adobe Photoshop´¦ÖÃÎļþ´æÔڶѻº³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ £»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://helpx.adobe.com/security/products/photoshop/apsb21-01.html


5.Xiaomi AX1800µÇ¼ÑéÖ¤Èƹý©¶´


Xiaomi AX1800´æÔÚ·ÓÉÆ÷ÖØÆôºóʱ¼ä²îÒì²½µÄÎÊÌ⣬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÈƹýµÇ¼Ñé֤δÊÚȨ·ÃÎÊ¡£

https://privacy.mi.com/trust#/security/vulnerability-management/vulnerability-announcement/detail?id=22&locale=en


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢ÐÂÎ÷À¼´¢ÐîÒøÐÐÔâµ½¹¥»÷£¬Ãô¸ÐÐÅÏ¢»òÒÑй¶


1.jpg


λÓÚ»ÝÁé¶ÙµÄÐÂÎ÷À¼´¢ÐîÒøÐÐÓÚÖÜÈÕÉù³ÆÆäÔâµ½¹¥»÷¡£¾ÝϤ£¬¸ÃÒøÐÐÓÃÀ´¹²ÏíºÍ´æ´¢Ãô¸ÐÐÅÏ¢µÄµÚÈý·½Îļþ¹²Ïí·þÎñµÄÊý¾ÝϵͳÔâµ½ÆÆ»µ£¬ºÚ¿Í¿ÉÄÜÒѾ­·ÃÎÊÁËÆäÖеÄÉÌÒµºÍ¸öÈËÃô¸ÐÐÅÏ¢¡£Ä¿Ç°£¬¸ÃϵͳÒѱ»ÍÑ»ú± £»¤£¬Ö±µ½ÒøÐÐÍê³ÉÆä³õ·¨Ê½²éΪֹ²Å»á»Ö¸´¡£¸ÃÒøÐÐÌåÏÖÆäÕýÔÚÈ·¶¨Ð¹Â¶ÐÅÏ¢µÄ·¶Î§£¬¶øÇҾܾø͸¶Óйش˴ι¥»÷¸ü¶àµÄϸ½Ú¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/new-zealand-central-bank-hit-cyber-attack


2¡¢ÁªºÏ¹ú»·¾³¹æ»®ÊðµÄGit´æ´¢¿âй¶Áè¼Ý10Íò¸öµÄÔ±¹¤ÐÅÏ¢


2.png


¸Ã¹ûÈ»µÄgitĿ¼ÖаüÂÞÁË´óÁ¿Ãô¸ÐÎļþ£¬ÈçÓë»·¾³ÊðºÍÁªºÏ¹ú¹ú¼ÊÀ͹¤×éÖ¯ÆäËûÔÚÏßϵͳÏà¹ØµÄ´¿Îı¾Êý¾Ý¿âƾ¾Ý£¬¹ÜÀíÔ±µÄÊý¾Ý¿âƾ¾ÝºÍ»·¾³ÊðµÄÔ´´úÂë¿âµÈ¡£´ËÍ⣬´Ë´Îʼþ»¹Ð¹Â¶ÁËÔ±¹¤µÄPII£¬ÈçÔ±¹¤ÂÃÐÐÀúÊ·¡¢ÈË¿Úͳ¼ÆÊý¾Ý£¨¹ú¼®¡¢ÐÔ±ðºÍн¼¶£©¡¢ÏîÄ¿×ʽðÀ´Ô´¼Ç¼¡¢Ô±¹¤¼Ç¼ºÍ¾ÍÒµÆÀ¹À³ÂËߵȡ£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/united-nations-data-breach-exposed-over-100k-unep-staff-records/


3¡¢Socialarksй¶400GBÊý¾Ý£¬Ó°ÏìÈ«Çò2ÒÚ¶àÓû§


3.png


Äþ¾²¹«Ë¾Safety Detectives·¢ÏÖ£¬Öйú³õ´´¹«Ë¾Socialarks£¨±¿ÄñÉç½»£©Ð¹Â¶ÁË400GBÊý¾Ý¡£´Ë´ÎÊý¾Ýй¶ÊÇÓÉÓÚElasticSearchÊý¾Ý¿âÉèÖôíÎó£¬Ð¹Â¶ÁË×ܼÆ408GB£¬Áè¼Ý3.18ÒÚÌõÓû§¼Ç¼£¬Éæ¼°µ½11651162¸öInstagramÓû§¡¢66117839¸öÁìÓ¢Óû§ºÍ81551567¸öFacebookÓû§¡£ÖµµÃ×¢ÒâµÄÊÇ£¬SocialarksÔÚ2020Äê8ÔÂÒ²·¢ÉúÁËÀàËƵÄʼþ£¬Ð¹Â¶ÁË1.5ÒÚ¸öÓû§µÄ¸öÈËÊý¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.safetydetectives.com/blog/socialarks-leak-report/


4¡¢ÐÂSolarLeaksÍøÕ¾³öÊÛSolarWinds¹©Ó¦Á´¹¥»÷ÖеÄÀúÊ·Êý¾Ý


4.png


ÐÂSolarLeaksÍøÕ¾³öÊÛSolarWinds¹©Ó¦Á´¹¥»÷ÖÐMicrosoft¡¢Cisco¡¢FireEyeºÍSolarWindsµÈ¹«Ë¾µÄʧÇÔÊý¾Ý¡£¸ÃÍøÕ¾ÒÔ60ÍòÃÀÔªµÄ¼Û¸ñ³öÊÛMicrosoftÔ´´úÂëºÍ´æ´¢¿â£¬ÒÔ5ÍòÃÀÔªµÄ¼Û¸ñ³öÊÛFireEyeµÄÔ´´úÂëºÍºì¶Ó¹¤¾ß£¬ÒÔ25ÍòÃÀÔªµÄ¼Û¸ñ³öÊÛSolarWindsÔ´´úÂëºÍ¿Í»§ÃÅ»§£¬²¢ÒÔ100ÍòÃÀÔªµÄ¼Û¸ñ³öÊÛÈ«²¿Ð¹Â¶Êý¾Ý¡£solarleaks.netÓòÊÇͨ¹ý¶íÂÞ˹Fancy BearºÍCozy BearʹÓõÄÒÑ֪ע²áÉÌNJALLA½øÐÐ×¢²á¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/solarleaks-site-claims-to-sell-data-stolen-in-solarwinds-attacks/


5¡¢SkypeÔÚÈ«Çò·¶Î§ÄÚ·þÎñÖжÏ£¬Ô­ÒòÉв»Ã÷È·


5.png


1ÔÂ13ÈÕÉÏÎ磬SkypeÔÚÈ«Çò·¶Î§ÄÚ·þÎñÖжÏ£¬Ä¿Ç°¸ÃÎÊÌâÒѱ»½â¾ö¡£Æ¾¾ÝÔÚÏßÏûϢƽ̨DownDetectorͳ¼Æ£¬ÖжÏÖ÷Òª¼¯ÖÐÔÚÃÀ¹ú¡¢Å·ÖÞ¡¢ÑÇÖÞºÍÊÀ½çÆäËûµØÓò¡£Óû§ÔÚ·ÃÎÊSkypeÍøվʱ£¬»áÏÔʾÎÒÃÇÎÞ·¨Íê³ÉÄúµÄÇëÇóµÄÌáʾ¡£MicrosoftÔÚSkype״̬ҳÉÏÌåÏÖ·¢ÏÖÁ˸ÃÎÊÌ⣬ÆäÓ°ÏìÁËSkypeµÇ¼¡¢ºô½Ð¡¢ÏûÏ¢¡¢ËÑË÷¡¢Òƶ¯¹²Ïí¡¢Ö§¸¶ÏµÍ³¡¢SMSºÍÆäËû·þÎñ¡£ÎÊÌâÏÖÒѻָ´£¬Skype¿ÉÔÙ´ÎÁª»ú¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/skype-is-down-worldwide-microsoft-working-on-issues/