ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ25ÖÜ

Ðû²¼Ê±¼ä 2021-06-21

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2021Äê06ÔÂ14ÈÕÖÁ06ÔÂ20ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´55¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇBandai Namco FromSoftware Dark Souls III´úÂëÖ´ÐЩ¶´£»Apache Chainsaw·´ÐòÁл¯´úÂëÖ´ÐЩ¶´£»Contiki-NG 6LoWPANʵÏÖÔ½½ç¶Á©¶´£»QEMU SLiRPÍøÂçʵÏÖtftp_input()Ô½½ç¶Á¾Ü½Ó·þÎñ©¶´£»SonicOS»º³åÇøÒç³ö¾Ü¾ø·þÎñ©¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÃÀ¹úºËÎäÆ÷³Ð°üÉÌSol OriensÔâREvilÀÕË÷Èí¼þ¹¥»÷£»APWGÐû²¼2021ÄêQ1ÍøÂçµöÓã»î¶¯Ì¬ÊƵķÖÎö³ÂËߣ»Äþ¾²¹«Ë¾CognyteÊý¾Ý¿âÅäÖôíÎóй¶Áè¼Ý50ÒÚÌõ¼Ç¼£»Apple½ô¼±¸üУ¬ÐÞ¸´iOSÖÐÒѱ»ÔÚÒ°ÀûÓõÄ2¸ö0day£»Ò˼ҷ¨¹ú¹«Ë¾ÓüäµýÈí¼þ·Ç·¨¼à¿ØÔ±¹¤±»·£¿î120ÍòÃÀÔª¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


> ÖØÒªÄþ¾²Â©¶´Áбí


1.Bandai Namco FromSoftware Dark Souls III´úÂëÖ´ÐЩ¶´


Bandai Namco FromSoftware Dark Souls III´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://www.reddit.com/r/darksouls3/comments/n1235k/potential_pc_security_exploit_spreading/


2.Apache Chainsaw·´ÐòÁл¯´úÂëÖ´ÐЩ¶´


Apache Chainsaw´æÔÚ·´ÐòÁл¯Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

http://www.openwall.com/lists/oss-security/2021/06/16/1


3.Contiki-NG 6LoWPANʵÏÖÔ½½ç¶Á©¶´


Contiki-NG 6LoWPANʵÏÖ´æÔÚÔ½½ç¶Á©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿Éʹ·þÎñ·¨Ê½Í߽⡣

https://github.com/contiki-ng/contiki-ng/security/advisories/GHSA-hhwj-2p59-v8p9


4.QEMU SLiRPÍøÂçʵÏÖtftp_input()Ô½½ç¶Á¾Ü½Ó·þÎñ©¶´



QEMU SLiRPÍøÂçʵÏÖtftp_input()´æÔÚÔ½½ç¶Á©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½Í߽⡣

https://bugzilla.redhat.com/show_bug.cgi?id=1970489


5.SonicOS»º³åÇøÒç³ö¾Ü¾ø·þÎñ©¶´



SonicOS´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë»òʹӦÓ÷¨Ê½Í߽⡣

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0016


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢ÃÀ¹úºËÎäÆ÷³Ð°üÉÌSol OriensÔâREvilÀÕË÷Èí¼þ¹¥»÷


1.jpg


ÃÀ¹úºËÎäÆ÷³Ð°üÉÌSol OriensÔâµ½ÁËREvilÀÕË÷Èí¼þ¹¥»÷¡£¸Ã¹«Ë¾³ÆÆäÖ÷ҪЭÖú¹ú·À²¿¡¢ÄÜÔ´²¿¡¢º½¿Õº½Ìì³Ð°üÉ̺ͼ¼Êõ¹«Ë¾¿ªÕ¹ÅÓ´óµÄÏîÄ¿¡£REvilÍÅ»ïÕýÔÚÅÄÂô¹¥»÷ÆÚ¼äÇÔÈ¡µÄÊý¾Ý£¬ÆäÖаüÂÞÒµÎñÊý¾ÝºÍÔ±¹¤ÐÅÏ¢£¬ÀýÈçÔ±¹¤Éç»áÄþ¾²ºÅÂë¡¢ÕÐƸ¸ÅÀÀÎļþ¡¢ÈËΪµ¥ÎļþºÍÈËΪ³ÂËߵȡ£Sols OriensҲ֤ʵÁËÆäÔÚ2021Äê5ÔÂÔâµ½ÁËÍøÂç¹¥»÷£¬¿ÉÄÜÒѾ­Ð¹Â¶²¿ÃÅÊý¾Ý£¬Ä¿Ç°ÊÓ²ìÈÔÔÚ½øÐÐÖС£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/revil-ransomware-hits-us-nuclear-weapons-contractor/


2¡¢APWGÐû²¼2021ÄêQ1ÍøÂçµöÓã»î¶¯Ì¬ÊƵķÖÎö³ÂËß


2.jpg


APWGÐû²¼ÁË2021ÄêQ1ÍøÂçµöÓã»î¶¯Ì¬ÊƵķÖÎö³ÂËß¡£³ÂËßÏÔʾ£¬ÍøÂçµöÓãÍøÕ¾ÊýÁ¿ÔÚ2021Äê1Ôµ½´ï·åÖµ£¬´´ÏÂÁË245771¸öµÄÀúʷиߣ¬È»ºóÔÚ±¾¼¾¶ÈµÄºóÆÚ¿ªÊ¼Ï½µ¡£ÉÌÒµµç×ÓÓʼþ(BEC)Õ©Æ­µÄ³É±¾Ô½À´Ô½¸ß£¬´Ó2020ÄêQ3µÄ48000ÃÀÔªÔö¼Óµ½ÁË2021ÄêQ1µÄ85000ÃÀÔª¡£Õë¶Ô½ðÈÚ»ú¹¹µÄÍøÂçµöÓãÊÇQ1Õ¼±È×î´óµÄÀàÐÍ£¬Õ¼ËùÓй¥»÷µÄ24.9%¡£´ËÍ⣬Õë¶ÔÉ罻ýÌåÐÐÒµµÄÍøÂçµöÓãÔÚËùÓй¥»÷ÖÐËùÕ¼±ÈÀý´Ó2020ÄêQ4µÄ11.8%¼¤ÔöÖÁ23.6%¡£


Ô­ÎÄÁ´½Ó£º

https://www.prnewswire.com/news-releases/apwg-q1-2021-report-detected-phishing-websites-maintain-historic-high-in-q1-2021-after-doubling-in-2020-301309187.html


3¡¢Äþ¾²¹«Ë¾CognyteÊý¾Ý¿âÅäÖôíÎóй¶Áè¼Ý50ÒÚÌõ¼Ç¼


3.jpg


ComparitechÄþ¾²Ñо¿ÈËÔ±·¢ÏÖÁËÍøÂçÄþ¾²·ÖÎö¹«Ë¾CognyteδÊܱ£»¤µÄÊý¾Ý¿â¡£¸ÃÊý¾Ý¿â×÷ΪCognyteÍøÂçÇ鱨·þÎñµÄÒ»²¿ÃÅ£¬ÓÃÓÚÌáÐÑÆä¿Í»§µÚÈý·½µÄÊý¾Ýй¶¡£¾ßÓм¥Ð¦ÒâζµÄÊÇ£¬ÓÃÓÚ½»²æ¼ì²éй¶µÄ¸öÈËÐÅÏ¢µÄÊý¾Ý¿â×Ô¼ºÒÑй¶¡£¸ÃÊý¾Ý¿â×ܹ²ÓÐ5085132102Ìõ¼Ç¼£¬°üÂÞÃû³Æ¡¢µç×ÓÓʼþµØÖ·¡¢ÃÜÂëºÍÊý¾ÝÔ´£¬ÓÚ2021Äê5ÔÂ29ÈÕ±»·¢ÏÖ£¬ºóÓÚ6ÔÂ2ÈÕ±»±£»¤ÆðÀ´¡£Ä¿Ç°£¬Éв»È·¶¨ÕâЩÊý¾ÝÔÚ̻¶ÆÚ¼äÊÇ·ñÓб»ÈκεÚÈý·½·ÃÎÊ¡£


Ô­ÎÄÁ´½Ó£º

https://www.comparitech.com/blog/information-security/breach-database-leak/


4¡¢Apple½ô¼±¸üУ¬ÐÞ¸´iOSÖÐÒѱ»ÔÚÒ°ÀûÓõÄ2¸ö0day


4.jpg


AppleÐû²¼½ô¼±¸üУ¬ÐÞ¸´iOS 12.5.3ÖÐÒѱ»ÔÚÒ°ÀûÓõÄ2¸ö0day¡£ÕâÁ½¸ö0dayΪWebKitä¯ÀÀÆ÷ÒýÇæÖеÄÄÚ´æËð»µÂ©¶´£¨CVE-2021-30761£©ºÍÊͷźóʹÓ鶴£¨CVE-2021-30762£©£¬¾ù¿É±»ÓÃÀ´Ô¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£AppleÌåÏָ鶴¿ÉÄÜÒѱ»»ý¼«ÀûÓ㬵«²¢Î´Í¸Â¶ÈκÎÓйشËÀ๥»÷µÄÏêϸÐÅÏ¢¡£´ËÍ⣬´Ë´Î¸üл¹ÐÞ¸´ÁËASN.1½âÂëÆ÷ÖеÄÄÚ´æËð»µÂ©¶´(CVE-2021-30737)¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/06/apple-issues-urgent-patches-for-2-zero.html


5¡¢Ò˼ҷ¨¹ú¹«Ë¾ÓüäµýÈí¼þ·Ç·¨¼à¿ØÔ±¹¤±»·£¿î120ÍòÃÀÔª


5.jpg


Èðµä¼Ò¾ß¼¯ÍÅÒ˼ҷ¨¹ú·Ö¹«Ë¾ÒòʹÓüäµýÈí¼þ·Ç·¨¼à¿ØÔ±¹¤±»·£¿î120ÍòÃÀÔª¡£¸Ãʼþ·¢ÉúÔÚ2009ÄêÖÁ2012Äê¼ä£¬Ò˼ҷ¨¹ú¹«Ë¾¿ª·¢ÁËÒ»¸ö¼äµýϵͳÀ´¼à¿ØÔ±¹¤ºÍÌá³ö¾À·×µÄ¿Í»§¡£¸ÃϵͳΪ¹«Ë¾1996ÄêÖÁ2002ÄêµÄÂôÁ¦ÈËJean-Louis Baillot½¨Á¢µÄ£¬Æä±»´¦ÒÔÁ½Ä껺Ð̺Í60630ÃÀÔª·£¿î¡£¼ì²ì¹ÙÌåÏÖ£¬Ò˼ҷ¨¹ú¹«Ë¾ÀûÓþ¯·½ÏûÏ¢À´Ô´£¬Æ¸ÇëÁËÒ»¼Ò˽È˱£°²¹«Ë¾ºÍ˽ÈËÕì̽·Ç·¨»ñÈ¡ÆäÔ±¹¤µÄ»úÃÜÐÅÏ¢¡£¸ÃÐÌÊÂÊÓ²ìÓÚ2012ÄêÆô¶¯£¬Ö±µ½±¾Öܶþ²ÅÏÂÁî·£¿î¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/ikea-fined-12m-for-spying-on/