ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ26ÖÜ

Ðû²¼Ê±¼ä 2021-06-28

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2021Äê06ÔÂ21ÈÕÖÁ06ÔÂ27ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´53¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇWebAccess HMI DesignerÏîÄ¿ÎļþÔ½½çд´úÂëÖ´ÐЩ¶´£»D-LINK DSL-2888A routerÈÎÒâÃÜÂëÐ޸ĩ¶´£»Zoho ManageEngine ADSelfService PlusÃÜÂë¸ü¸Ä´úÂëÖ´ÐЩ¶´£»Apple macOS CoreText TTF½âÎöÕ»Òç³ö´úÂëÖ´ÐЩ¶´£»WEIDMUELLER Industrial WLAN devices iw_consoleȨÏÞÌáÉý©¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÑо¿ÈËÔ±ÑÝʾÈçºÎͨ¹ýWiFiÈȵãÀ´¹¥»÷iPhoneÊÖ»ú£»Ñо¿ÍŶӳƽüÆÚÀÕË÷Èí¼þ¹¥»÷Á¬Ðø¼¤Ôö £¬Í¬±ÈÔö³¤93%£»Å²Íþ¾¯·½È·ÈÏÆäÔÚ2018ÄêÔâµ½µÄºÚ¿Í¹¥»÷ÓëAPT31ÓйØ£»Ñо¿ÍŶÓÔÚPyPI´æ´¢¿â·¢ÏÖ¶à¸öÓÃÓÚÍÚ¿óµÄ¶ñÒâÈí¼þ°ü£»Zephyrʵʱ²Ù×÷ϵͳ(RTOS)Äþ¾²¸üР£¬ÐÞ¸´¶à¸ö©¶´¡£


ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾ÖÜÄþ¾²ÍþвΪÖС£


> ÖØÒªÄþ¾²Â©¶´Áбí


1.WebAccess HMI DesignerÏîÄ¿ÎļþÔ½½çд´úÂëÖ´ÐЩ¶´


WebAccess HMI Designer´¦ÖÃÏîÄ¿Îļþ´æÔÚÔ½½ç䩶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬ÓÕʹÓû§½âÎö £¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë

https://us-cert.cisa.gov/ics/advisories/icsa-21-173-01


2.D-LINK DSL-2888A routerÈÎÒâÃÜÂëÐ޸ĩ¶´


D-LINK DSL-2888A router´æÔÚÈÎÒâÃÜÂëÐ޸ĩ¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÐ޸ĹÜÀíÔ±ÃÜÂë¡£

https://github.com/EmYiQing/CVE


3.Zoho ManageEngine ADSelfService PlusÃÜÂë¸ü¸Ä´úÂëÖ´ÐЩ¶´


Zoho ManageEngine ADSelfService Plus¸ü¸ÄÃÜÂë´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíµ±µØ¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://www.manageengine.com/products/self-service-password/release-notes.html#6102


4.Apple macOS CoreText TTF½âÎöÕ»Òç³ö´úÂëÖ´ÐЩ¶´


Apple macOS CoreText TTF½âÎö´æÔÚÕ»Òç³ö©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬ÓÕʹÓû§½âÎö £¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://support.apple.com/HT212147


5.WEIDMUELLER Industrial WLAN devices iw_consoleȨÏÞÌáÉý©¶´


WEIDMUELLER Industrial WLAN devices iw_console¹¦Ð§´æÔÚתÒåʧ°Ü©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://cert.vde.com/en-us/advisories/vde-2021-026


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢Ñо¿ÈËÔ±ÑÝʾÈçºÎͨ¹ýWiFiÈȵãÀ´¹¥»÷iPhoneÊÖ»ú


1.jpg


Ñо¿ÈËÔ±Carl SchouÑÝʾÁËÈçºÎͨ¹ýWiFiÈȵãÀ´¹¥»÷iPhoneÊÖ»ú¡£Carl SchouÔÚÁ¬½Ó¸öÈËWiFiÈȵ㡰%p%s%s%s%s%n¡±Ê± £¬·¢ÏÖËûiPhoneµÄWiFi¹¦Ð§±»½ûÓà £¬¶øÇÒÔÙÒ²ÎÞ·¨ÆôÓÃWiFi¹¦Ð§ £¬¼´Ê¹ËûÖØÆôÉ豸»ò¸ü¸ÄÈȵãÃû³Æ¡£Ñо¿ÈËÔ±³Æ £¬Õâ¿ÉÄÜÊÇÊäÈë½âÎöÎÊÌâµ¼ÖµÄ £¬µ±WiFiÈȵãÃû³ÆÖдæÔÚ´øÓС°%¡±µÄ×Ö·û´®Ê± £¬iOS¿ÉÄÜ»á´íÎóµØ½«¡°%¡±ºóÃæµÄ×Öĸ½âÊÍΪ×Ö·û´®¸ñʽ˵Ã÷·û¡£»Ö¸´Wi-Fi¹¦Ð§µÄΨһҪÁìÊÇÖØÖÃiPhoneµÄÍøÂçÉèÖᣴËÍâ £¬¸Ã©¶´ÊÇiPhone¶ÀÕ¼µÄ £¬ÎÞ·¨ÔÚAndroidÊÖ»úÉÏÖØÏÖ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/iphone-bug-breaks-wifi-when-you-join-hotspot-with-unusual-name/


2¡¢Ñо¿ÍŶӳƽüÆÚÀÕË÷Èí¼þ¹¥»÷Á¬Ðø¼¤Ôö £¬Í¬±ÈÔö³¤93%


2.jpg


Check Point ResearchÑо¿ÍŶӳƽüÆÚÀÕË÷Èí¼þ¹¥»÷Á¬Ðø¼¤Ôö¡£2021Äê6ÔÂÿÖÜÊÜÀÕË÷Èí¼þÓ°ÏìµÄ×éÖ¯ÊýÁ¿ÒÑÔöÖÁ1210¸ö £¬×ÔÄê³õÒÔÀ´ £¬ÀÕË÷Èí¼þ¹¥»÷´ÎÊýÔö¼ÓÁË41% £¬Í¬±ÈÔö¼ÓÁË93%¡£ÆäÖÐÀ­¶¡ÃÀÖÞµÄÀÕË÷Èí¼þ¹¥»÷ʵÑéÔö³¤×îΪÏÔ×Å £¬Ôö³¤ÁË62% £¬Æä´ÎÊÇÅ·ÖÞÔö¼ÓÁË59% £¬·ÇÖÞÔö¼ÓÁË34% £¬±±ÃÀÔö¼ÓÁË32%¡£´ËÍâ £¬Õë¶Ô½ÌÓýÐÐÒµµÄ¹¥»÷Ôö³¤ËÙ¶È×î¿ì£¨ÓëÈ¥ÄêͬÆÚÏà±ÈÔö³¤ÁË347%£© £¬Æä´ÎΪÔËÊäÐÐÒµ£¨186%£©¡¢ÁãÊÛºÍÅú¿¯ÐÐÒµ£¨162%£©ÒÔ¼°Ò½ÁƱ£½¡ÐÐÒµ£¨159%£©¡£


Ô­ÎÄÁ´½Ó£º

https://blog.checkpoint.com/2021/06/14/ransomware-attacks-continue-to-surge-hitting-a-93-increase-year-over-year/


3¡¢Å²Íþ¾¯·½È·ÈÏÆäÔÚ2018ÄêÔâµ½µÄºÚ¿Í¹¥»÷ÓëAPT31ÓйØ


3.jpg


ŲÍþ¾¯²ìÄþ¾²¾Ö (PST) ÌåÏÖ £¬ÆäÔÚ2018ÄêÔâµ½µÄÍøÂç¹¥»÷ÓëºÚ¿Í×éÖ¯APT31ÓйØ¡£¾ÝÊÓ²ìÏÔʾ £¬Ôڴ˴ι¥»÷ÖкڿÍÒÑÀֳɻñµÃ¹ÜÀíԱȨÏÞ £¬¿ÉÒÔ·ÃÎʸùúËùÓйú¼ÒÐÐÕþ°ì¹«ÊÒʹÓõÄÖÐÑë¼ÆËã»úϵͳ £¬»¹ÀֳɵشӰ칫ÊÒϵͳÇÔÈ¡ÁËһЩÊý¾Ý¡£´ËÍâ £¬Ñо¿ÈËÔ±³Æ £¬APT31»¹±»ÈÏΪÊÇ2020Äê12ÔÂÕë¶Ô·ÒÀ¼Òé»áµÄÍøÂç¹¥»÷µÄÄ»ºóºÚÊÖ £¬Ôڴ˴ι¥»÷ÖкڿÍÀÖ³ÉÈëÇÖÁËһЩÒé»áÏà¹Øµç×ÓÓʼþµÄÕÊ»§¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/119161/apt/norway-blames-china-apt31.html


4¡¢Ñо¿ÍŶÓÔÚPyPI´æ´¢¿â·¢ÏÖ¶à¸öÓÃÓÚÍÚ¿óµÄ¶ñÒâÈí¼þ°ü


4.jpg


Ñо¿ÍŶÓÔÚPythonÏîÄ¿µÄPyPI¿âÖз¢ÏÖÁË6¸ö¶ñÒâÈí¼þ°ü £¬¿ÉÒÔ½«¿ª·¢ÈËÔ±µÄ¼ÆËã»úÄð³É¿ó»ú¡£ËùÓжñÒâÈí¼þ°ü¾ùÓÉͬһÓû§¡°nedog123¡±Ðû²¼ £¬·Ö±ðΪmaratlib¡¢maratlib1¡¢matplatlib-plus¡¢mllearnlib¡¢mplatlibºÍlearninglib £¬ÆäÖдó²¿ÃŵÄÃû³Æ¶¼ÊǺϷ¨»æͼÈí¼þmatplotlibµÄƴд´íÎó°æ±¾ £¬ºÚ¿Íͨ¹ýÕâÖÖ·½Ê½À´ÆÛÆ­¿ª·¢ÈËÔ±ÏÂÔØ¡£Ñо¿ÈËÔ±³Æ¶ñÒâ´úÂ붼ÔÚsetup.pyÎļþÖÐ £¬Ëü»áÔÚGitHub´æ´¢¿âÏÂÔØBash½Å±¾(aza2.sh) £¬¸Ã½Å±¾µÄ×÷ÓÃÊÇÔÚÄ¿±ê»úÆ÷ÉÏÔËÐеļÓÃÜ¿ó¹¤Ubqminer¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/malicious-pypi-packages-hijack-dev-devices-to-mine-cryptocurrency/


5¡¢Zephyrʵʱ²Ù×÷ϵͳ(RTOS)Äþ¾²¸üР£¬ÐÞ¸´¶à¸ö©¶´


5.jpg


Zephyrʵʱ²Ù×÷ϵͳ(RTOS)Äþ¾²¸üР£¬ÐÞ¸´ÁË8¸ö¿ÉÄܵ¼Ö¾ܾø·þÎñ (DoS) ºÍÔ¶³Ì´úÂëÖ´ÐеÄ©¶´¡£ZephyrÊÇСÐ͵Äʵʱ²Ù×÷ϵͳ £¬ÓÃÓÚ×ÊÔ´ÊÜÏÞµÄǶÈëʽ»¥ÁªÉ豸 £¬µÃµ½ÁËFacebook¡¢¹È¸è¡¢IntelµÈÖªÃû¹«Ë¾µÄÖ§³Ö £¬Ö§³Ö200¶àÖÖ²îÒìCPU¼Ü¹¹£¨ARM¡¢Cortex-MºÍIntel x86µÈ£©¡£´Ë´ÎÐÞ¸´µÄ©¶´´æÔÚÓÚZephyrµÄÀ¶ÑÀLEÁ´Â·²ã (LL) ¼°ÆäÂß¼­Á´Â·¿ØÖƺÍÊÊÅäЭÒé (L2CAP) ÖÐ £¬ÆäÖнÏΪÑÏÖصÄÊÇÐÅϢ鶩¶´£¨CVE-2021-3435£©ºÍDoS©¶´£¨CVE-2021-3455£©¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/zephyr-rtos-fixes-bluetooth-bugs-that-may-lead-to-code-execution/