ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ3ÖÜ

Ðû²¼Ê±¼ä 2021-01-18

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2021Äê01ÔÂ11ÈÕÖÁ01ÔÂ17ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´70¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Word CVE-2021-1715´úÂëÖ´ÐЩ¶´ £»Siemens JT2Go JT½âÎöÀàÐÍ»ìÏý´úÂëÖ´ÐЩ¶´ £»Cisco Connected Mobile Experiences CVE-2021-1144ȨÏÞÌáÉý©¶´ £»Adobe Photoshop¶Ñ»º³åÇøÒç³ö´úÂëÖ´ÐЩ¶´ £»Xiaomi AX1800µÇ¼ÑéÖ¤Èƹý©¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÐÂÎ÷À¼´¢ÐîÒøÐÐÔâµ½¹¥»÷ £¬Ãô¸ÐÐÅÏ¢»òÒÑй¶ £»ÁªºÏ¹ú»·¾³¹æ»®ÊðµÄGit´æ´¢¿âй¶Áè¼Ý10Íò¸öµÄÔ±¹¤ÐÅÏ¢ £»Socialarksй¶400GBÊý¾Ý £¬Ó°ÏìÈ«Çò2ÒÚ¶àÓû§ £»ÐÂSolarLeaksÍøÕ¾³öÊÛSolarWinds¹©Ó¦Á´¹¥»÷ÖеÄÀúÊ·Êý¾Ý £»SkypeÔÚÈ«Çò·¶Î§ÄÚ·þÎñÖжÏ £¬Ô­ÒòÉв»Ã÷È·¡£


ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾ÖÜÄþ¾²ÍþвΪÖС£


> ÖØÒªÄþ¾²Â©¶´Áбí


1.Microsoft Word CVE-2021-1715´úÂëÖ´ÐЩ¶´


Microsoft Word´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó £¬ÓÕʹÓû§½âÎö £¬¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-1715


2.Siemens JT2Go JT½âÎöÀàÐÍ»ìÏý´úÂëÖ´ÐЩ¶´


Siemens JT2Go JTÎļþ½âÎö´æÔÚÀàÐÍ»ìÏý©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó £¬¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://us-cert.cisa.gov/ics/advisories/icsa-21-012-03


3.Cisco Connected Mobile Experiences CVE-2021-1144ȨÏÞÌáÉý©¶´


Cisco Connected Mobile Experiences¸ü¸ÄÃÜÂëÊÚȨ´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿É¸ü¸ÄÈÎÒâÓû§ÃÜÂë £¬ÌáÉýÌØȨ¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cmxpe-75Asy9k


4.Adobe Photoshop¶Ñ»º³åÇøÒç³ö´úÂëÖ´ÐЩ¶´


Adobe Photoshop´¦ÖÃÎļþ´æÔڶѻº³åÇøÒç³ö©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó £¬ÓÕʹÓû§½âÎö £¬¿ÉʹӦÓ÷¨Ê½±ÀÀ £»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://helpx.adobe.com/security/products/photoshop/apsb21-01.html


5.Xiaomi AX1800µÇ¼ÑéÖ¤Èƹý©¶´


Xiaomi AX1800´æÔÚ·ÓÉÆ÷ÖØÆôºóʱ¼ä²îÒì²½µÄÎÊÌâ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÈƹýµÇ¼Ñé֤δÊÚȨ·ÃÎÊ¡£

https://privacy.mi.com/trust#/security/vulnerability-management/vulnerability-announcement/detail?id=22&locale=en


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢ÐÂÎ÷À¼´¢ÐîÒøÐÐÔâµ½¹¥»÷ £¬Ãô¸ÐÐÅÏ¢»òÒÑй¶


1.jpg


λÓÚ»ÝÁé¶ÙµÄÐÂÎ÷À¼´¢ÐîÒøÐÐÓÚÖÜÈÕÉù³ÆÆäÔâµ½¹¥»÷¡£¾ÝϤ £¬¸ÃÒøÐÐÓÃÀ´¹²ÏíºÍ´æ´¢Ãô¸ÐÐÅÏ¢µÄµÚÈý·½Îļþ¹²Ïí·þÎñµÄÊý¾ÝϵͳÔâµ½ÆÆ»µ £¬ºÚ¿Í¿ÉÄÜÒѾ­·ÃÎÊÁËÆäÖеÄÉÌÒµºÍ¸öÈËÃô¸ÐÐÅÏ¢¡£Ä¿Ç° £¬¸ÃϵͳÒѱ»ÍÑ»ú± £»¤ £¬Ö±µ½ÒøÐÐÍê³ÉÆä³õ·¨Ê½²éΪֹ²Å»á»Ö¸´¡£¸ÃÒøÐÐÌåÏÖÆäÕýÔÚÈ·¶¨Ð¹Â¶ÐÅÏ¢µÄ·¶Î§ £¬¶øÇҾܾø͸¶Óйش˴ι¥»÷¸ü¶àµÄϸ½Ú¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/new-zealand-central-bank-hit-cyber-attack


2¡¢ÁªºÏ¹ú»·¾³¹æ»®ÊðµÄGit´æ´¢¿âй¶Áè¼Ý10Íò¸öµÄÔ±¹¤ÐÅÏ¢


2.png


¸Ã¹ûÈ»µÄgitĿ¼ÖаüÂÞÁË´óÁ¿Ãô¸ÐÎļþ £¬ÈçÓë»·¾³ÊðºÍÁªºÏ¹ú¹ú¼ÊÀ͹¤×éÖ¯ÆäËûÔÚÏßϵͳÏà¹ØµÄ´¿Îı¾Êý¾Ý¿âƾ¾Ý £¬¹ÜÀíÔ±µÄÊý¾Ý¿âƾ¾ÝºÍ»·¾³ÊðµÄÔ´´úÂë¿âµÈ¡£´ËÍâ £¬´Ë´Îʼþ»¹Ð¹Â¶ÁËÔ±¹¤µÄPII £¬ÈçÔ±¹¤ÂÃÐÐÀúÊ·¡¢ÈË¿Úͳ¼ÆÊý¾Ý£¨¹ú¼®¡¢ÐÔ±ðºÍн¼¶£©¡¢ÏîÄ¿×ʽðÀ´Ô´¼Ç¼¡¢Ô±¹¤¼Ç¼ºÍ¾ÍÒµÆÀ¹À³ÂËߵȡ£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/united-nations-data-breach-exposed-over-100k-unep-staff-records/


3¡¢Socialarksй¶400GBÊý¾Ý £¬Ó°ÏìÈ«Çò2ÒÚ¶àÓû§


3.png


Äþ¾²¹«Ë¾Safety Detectives·¢ÏÖ £¬Öйú³õ´´¹«Ë¾Socialarks£¨±¿ÄñÉç½»£©Ð¹Â¶ÁË400GBÊý¾Ý¡£´Ë´ÎÊý¾Ýй¶ÊÇÓÉÓÚElasticSearchÊý¾Ý¿âÉèÖôíÎó £¬Ð¹Â¶ÁË×ܼÆ408GB £¬Áè¼Ý3.18ÒÚÌõÓû§¼Ç¼ £¬Éæ¼°µ½11651162¸öInstagramÓû§¡¢66117839¸öÁìÓ¢Óû§ºÍ81551567¸öFacebookÓû§¡£ÖµµÃ×¢ÒâµÄÊÇ £¬SocialarksÔÚ2020Äê8ÔÂÒ²·¢ÉúÁËÀàËƵÄʼþ £¬Ð¹Â¶ÁË1.5ÒÚ¸öÓû§µÄ¸öÈËÊý¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.safetydetectives.com/blog/socialarks-leak-report/


4¡¢ÐÂSolarLeaksÍøÕ¾³öÊÛSolarWinds¹©Ó¦Á´¹¥»÷ÖеÄÀúÊ·Êý¾Ý


4.png


ÐÂSolarLeaksÍøÕ¾³öÊÛSolarWinds¹©Ó¦Á´¹¥»÷ÖÐMicrosoft¡¢Cisco¡¢FireEyeºÍSolarWindsµÈ¹«Ë¾µÄʧÇÔÊý¾Ý¡£¸ÃÍøÕ¾ÒÔ60ÍòÃÀÔªµÄ¼Û¸ñ³öÊÛMicrosoftÔ´´úÂëºÍ´æ´¢¿â £¬ÒÔ5ÍòÃÀÔªµÄ¼Û¸ñ³öÊÛFireEyeµÄÔ´´úÂëºÍºì¶Ó¹¤¾ß £¬ÒÔ25ÍòÃÀÔªµÄ¼Û¸ñ³öÊÛSolarWindsÔ´´úÂëºÍ¿Í»§ÃÅ»§ £¬²¢ÒÔ100ÍòÃÀÔªµÄ¼Û¸ñ³öÊÛÈ«²¿Ð¹Â¶Êý¾Ý¡£solarleaks.netÓòÊÇͨ¹ý¶íÂÞ˹Fancy BearºÍCozy BearʹÓõÄÒÑ֪ע²áÉÌNJALLA½øÐÐ×¢²á¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/solarleaks-site-claims-to-sell-data-stolen-in-solarwinds-attacks/


5¡¢SkypeÔÚÈ«Çò·¶Î§ÄÚ·þÎñÖжÏ £¬Ô­ÒòÉв»Ã÷È·


5.png


1ÔÂ13ÈÕÉÏÎç £¬SkypeÔÚÈ«Çò·¶Î§ÄÚ·þÎñÖжÏ £¬Ä¿Ç°¸ÃÎÊÌâÒѱ»½â¾ö¡£Æ¾¾ÝÔÚÏßÏûϢƽ̨DownDetectorͳ¼Æ £¬ÖжÏÖ÷Òª¼¯ÖÐÔÚÃÀ¹ú¡¢Å·ÖÞ¡¢ÑÇÖÞºÍÊÀ½çÆäËûµØÓò¡£Óû§ÔÚ·ÃÎÊSkypeÍøվʱ £¬»áÏÔʾÎÒÃÇÎÞ·¨Íê³ÉÄúµÄÇëÇóµÄÌáʾ¡£MicrosoftÔÚSkype״̬ҳÉÏÌåÏÖ·¢ÏÖÁ˸ÃÎÊÌâ £¬ÆäÓ°ÏìÁËSkypeµÇ¼¡¢ºô½Ð¡¢ÏûÏ¢¡¢ËÑË÷¡¢Òƶ¯¹²Ïí¡¢Ö§¸¶ÏµÍ³¡¢SMSºÍÆäËû·þÎñ¡£ÎÊÌâÏÖÒѻָ´ £¬Skype¿ÉÔÙ´ÎÁª»ú¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/skype-is-down-worldwide-microsoft-working-on-issues/