ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ52ÖÜ

Ðû²¼Ê±¼ä 2020-12-28

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2020Äê12ÔÂ21ÈÕÖÁ12ÔÂ27ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´56¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇABB Symphony Plus Operations SQL×¢È멶´£»D-link DSL-2888A execute_cmd.cgi OSÃüÁî×¢È멶´£»Zyxel USG SeriesĬÈÏƾ¾Ý©¶´£»BrowserUp Proxy Java EL±í´ïʽעÈ멶´£»QNAP QES CVE-2020-2499Ó²±àÂ멶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇAcronisÐû²¼ÈçºÎÓ¦¶ÔCOVID-19µÄÓ°ÏìµÄ³ÂËߣ»CISAÐû²¼SolarWinds Orion¹¥»÷ʼþµÄÔö²¹Ö¸ÄÏ£»SolarWinds¹©Ó¦Á´¹¥»÷»î¶¯ÖдæÔÚеÄSUPERNOVAºóÃÅ£»NintendoÊý¾Ýй¶ £¬½ÒʾÔø¹ÍÓ¶ºÚ¿ÍΪÆäÊÂÇ飻KasperskyÐû²¼LazarusÕë¶ÔCOVID-19Ç鱨µÄ·ÖÎö³ÂËß¡£


ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾ÖÜÄþ¾²ÍþвΪÖС£


ÖØÒªÄþ¾²Â©¶´Áбí


1.ABB Symphony Plus Operations SQL×¢È멶´


ABB Symphony Plus Operations´æÔÚSQL×¢È멶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄSQLÇëÇó £¬²Ù×÷Êý¾Ý¿â £¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐÈÎÒâ´úÂë¡£

https://search.abb.com/library/Download.aspx?DocumentID=2PAA123980&LanguageCode=en&DocumentPartId=&Action=Launch


2.D-link DSL-2888A execute_cmd.cgi OSÃüÁî×¢È멶´


D-link DSL-2888A execute_cmd.cgi´æÔÚÊäÈëÑé֤©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿É×¢Èë¶ñÒâOSÃüÁî²¢Ö´ÐС£

https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/d-link-multiple-security-vulnerabilities-leading-to-rce/


3.Zyxel USG SeriesĬÈÏƾ¾Ý©¶´


Zyxel USG Series´æÔÚzyfwpĬÈÏÕË»§¼°²»Ðиü¸ÄÆäÃÜÂë £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬Î´ÊÚȨ·ÃÎÊ·þÎñÆ÷¡£

https://businessforum.zyxel.com/discussion/5254/whats-new-for-zld4-60-patch-1-available-on-dec-15



4.BrowserUp Proxy Java EL±í´ïʽעÈ멶´


BrowserUp Proxy´æÔÚÊäÈëÑé֤©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔ×¢ÈëÈÎÒâJava EL±í´ïʽ²¢ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://github.com/browserup/browserup-proxy/commit/4b38e7a3e20917e5c3329d0d4e9590bed9d578ab


5.QNAP QES CVE-2020-2499Ó²±àÂ멶´


QNAP QES´æÔÚÓ²±àÂ멶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬Î´ÊÚȨ·ÃÎÊϵͳ¡£

https://www.qnap.com/zh-tw/security-advisory/qsa-20-19


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢AcronisÐû²¼ÈçºÎÓ¦¶ÔCOVID-19µÄÓ°ÏìµÄ³ÂËß


1.png


AcronisÐû²¼ÁËÈçºÎÓ¦¶ÔCOVID-19µÄÓ°ÏìµÄ³ÂËß¡£AcronisÔÚ2020Äê6ÔÂÖÁ7ÔÂÆÚ¼ä¶ÔÈ«Çò3400¼Ò¹«Ë¾ºÍÔ¶³Ì¹¤È˽øÐÐÁËÊÓ²ì £¬ÒÔÑо¿×éÖ¯ÈçºÎÊÊÓ¦COVID-19¶ÔÆäITÔËÓªºÍÍøÂçÄþ¾²Ì¬ÊƵÄÓ°Ïì¡£³ÂËßÏÔʾ £¬31%µÄ¹«Ë¾Ã¿Ì춼ÊÐÔâµ½ÍøÂç¹¥»÷ £¬69£¥µÄÔ¶³ÌÊÂÇéÕßÐèÒªÒÀ¿¿Zoom¡¢Cisco WebexµÈ¹¤¾ß½øÐÐЭ×÷ £¬¶ø39£¥µÄ¹«Ë¾ÔâÊÜÁËÊÓƵ»áÒé¹¥»÷¡£´ËÍâ £¬Ö»ÓÐ2£¥µÄ¹«Ë¾ÔÚÆÀ¹ÀÍøÂçÄþ¾²½â¾ö·½°¸Ê±¿¼ÂÇʹÓÃURL¹ýÂË¡£


Ô­ÎÄÁ´½Ó£º

https://www.acronis.com/en-us/blog/posts/acronis-cyber-readiness-report-pandemic-reveals-cybersecurity-gaps-need-new-solutions


2¡¢CISAÐû²¼SolarWinds Orion¹¥»÷ʼþµÄÔö²¹Ö¸ÄÏ


2.png


CISA×î³õÓÚ12ÔÂ17ÈÕÐû²¼ÁËÓйØÕþ¸®»ú¹¹¡¢Òªº¦»ù´¡ÉèÊ©ºÍ¹«Ë¾×éÖ¯µÄAPT¹¥»÷»î¶¯µÄ¾¯±¨ £¬Ö®ºóÕë¶Ô¸Ã½ô¼±Ö¸ÁîÐû²¼ÁËÔö²¹Ö¸ÄÏ¡£Ôö²¹Ö¸ÄÏ°üÂÞÊÜÓ°Ïì°æ±¾µÄ¸üС¢Õë¶ÔʹÓõÚÈý·½·þÎñÌṩÉ̵ÄÊðÀíµÄÖ¸ÄÏÒÔ¼°¶ÔËùÐè´ëÊ©µÄ½øÒ»²½ËµÃ÷¡£´ËÍâ £¬CISA»¹¸üÐÂÁ˸þ¯±¨ £¬ÌṩÁËеĻº½â·½°¸²¢ÐÞ¶©ÁËIOC±í¸ñ¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/12/19/cisa-updates-alert-and-releases-supplemental-guidance-emergency


3¡¢SolarWinds¹©Ó¦Á´¹¥»÷»î¶¯ÖдæÔÚеÄSUPERNOVAºóÃÅ


3.png


Ñо¿ÈËÔ±·¢ÏÖSolarWinds Orion¹©Ó¦Á´¹¥»÷»î¶¯ÖдæÔÚеÄSUPERNOVAºóÃÅ £¬¿ÉÄÜÀ´×ÔÁíÒ»¸öºÚ¿Í×éÖ¯¡£SUPERNOVAÊÇÖ²ÈëOrionÍøÂçºÍÓ¦Ó÷¨Ê½¼àÊÓƽ̨´úÂëÖеÄWeb shell £¬¹¥»÷Õß¿ÉÀûÓøöñÒâÈí¼þÔÚ¼ÆËã»úÉÏÔËÐÐÈÎÒâ´úÂë¡£¸Ã¶ñÒâ´úÂë½ö°üÂÞÒ»ÖÖDynamicRunÒªÁì £¬¿É½«²ÎÊý¶¯Ì¬±àÒëµ½ÄÚ´æÖеÄ.NET·¨Ê½¼¯ÖÐ £¬Òò´Ë²»»áÔÚÊÜѬȾÉ豸ÉÏÁôÏÂÈκκۼ£¡£¾­ÊÓ²ì £¬SUPERNOVAûÓÐÊý×ÖÇ©Ãû £¬ÕâÓë×î³õ·¢ÏÖµÄSunBurst²îÒì £¬»òÐíÊôÓÚÁíÒ»ºÚ¿Í×éÖ¯¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/a-second-hacking-group-has-targeted-solarwinds-systems/


4¡¢NintendoÊý¾Ýй¶ £¬½ÒʾÔø¹ÍÓ¶ºÚ¿ÍΪÆäÊÂÇé


4.png


NintendoÔٴη¢ÉúÑÏÖصÄÊý¾Ýй¶Ê¼þ £¬½ÒʾÔø¹ÍÓ¶ºÚ¿ÍΪÆäÊÂÇé¡£´Ë´Î鶵ÄÊý¾ÝÈÔÊÇÊ×ÏÈ·ºÆðÔÚ4chanÂÛ̳ÉÏ £¬°üÂÞÓëSwitchµÄ¿ª·¢Ïà¹ØµÄÎļþ £¬ÀýÈçSwitchÔçÆÚµÄÉè¼Æ²ÎÊý £¬ºÃ±ÈʹÓÃ1GÄÚ´æ¡¢480P·Ö±æÂʵÄÉãÏñÍ·¡¢¼æÈÝ3DSÓÎÏ·¡¢¿ÉÒÔͨ¹ýMiracastͶÆÁµÈ¡£´ËÍâ £¬´Ë´Î鶻¹½ÒʾÁËÈÎÌìÌÃÔø¹ÍÓ¶ÖªÃûµÄ3DSºÚ¿ÍΪÆäÊÂÇé £¬ÉõÖÁ»¹Öƶ¨ÁËÒ»·Ý¹«¹Ø¼Æ»® £¬ÒÔ½â¾öÔÚ·¢ÏָùÍÓ¶¹ØϵºóÈçºÎ´¦Öù«ÖÚ·´Ó³¡£


Ô­ÎÄÁ´½Ó£º

https://www.videogameschronicle.com/news/nintendo-has-reportedly-suffered-another-major-data-leak-now-related-to-switch/


5¡¢KasperskyÐû²¼LazarusÕë¶ÔCOVID-19Ç鱨µÄ·ÖÎö³ÂËß


5.png


KasperskyÐû²¼ÓйغڿÍ×éÖ¯LazarusÕë¶ÔCOVID-19Ç鱨µÄ¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö £¬LazarusÓÚ2020Äê9ÔÂ25ÈÕÈëÇÖÁËÒ»¼ÒÖÆÒ©¹«Ë¾ £¬²¢ÓÚ2020Äê10ÔÂ27ÈÕ¹¥»÷ÁËÕþ¸®ÎÀÉú²¿ £¬²¢Ëð»µÁËÁ½Ì¨Windows·þÎñÆ÷¡£ÕâÁ½´Î¹¥»÷»î¶¯Ê¹ÓÃÁ˲îÒìµÄÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½£¨TTP£©ÒÔ¼°¶ñÒâÈí¼þ¼¯Èº £¬µ«ÓÐÖ¤¾Ý±íÃ÷¶¼ÓëLazarusÓйØ £¬²¢Ö¤Ã÷¸Ã×éÖ¯¶ÔÓëCOVID-19Ïà¹ØµÄÇ鱨¸ÐÐËȤ¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/lazarus-covets-covid-19-related-intelligence/99906/