ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ36ÖÜ

Ðû²¼Ê±¼ä 2021-09-06

>±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö

2021Äê08ÔÂ30ÈÕÖÁ09ÔÂ05ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´62¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAruba Networks ArubaOS OS CVE-2021-37716 PAPIЭÒ黺³åÇøÒç³ö©¶´£»Google Chrome BlinkÄÚ´æ´íÎó´úÂëÖ´ÐЩ¶´£»Nature Easy Soft Network Technology ZenTaoÃüÁîÖ´ÐЩ¶´£»ZOHO ManageEngine ADSelfService Plus OSÃüÁî×¢È멶´£»Advantech WebAccess CVE-2021-38408»º³åÇø´íÎ󩶴¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇMicrosoftÐû²¼½üÆÚÖ¼ÔÚÇÔȡƾ¾ÝµÄµöÓã»î¶¯µÄ¾¯±¨£»NFIB³Æ2021ÄêH1Ó¢¹úÒòÍøÂç·¸×ïËðʧ¸ß´ï13ÒÚÓ¢°÷£»CNNICÐû²¼µÚ48´Î¡¶Öйú»¥ÁªÍøÂçÉú³¤×´¿öͳ¼Æ³ÂËß¡·£»ÒòGoogleÓ¦ÓÃbug£¬²¿ÃÅ°²×¿Óû§ÎÞ·¨²¦´òºÍ½ÓÌýµç»°£»Ñо¿ÈËÔ±³Æ16¸öÀ¶ÑÀ©¶´BrakToothÓ°ÏìÊýÊ®ÒÚÉ豸¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


>ÖØÒªÄþ¾²Â©¶´Áбí


1.Aruba Networks ArubaOS OS CVE-2021-37716 PAPIЭÒ黺³åÇøÒç³ö©¶´


Aruba Networks ArubaOS OS PAPIЭÒé´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2021-016.txt



2.Google Chrome BlinkÄÚ´æ´íÎó´úÂëÖ´ÐЩ¶´


Google Chrome Blink´æÔÚÊͷźóʹÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄWEBÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»ò¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://chromereleases.googleblog.com/2021/08/stable-channel-update-for-desktop_31.html


3.Nature Easy Soft Network Technology ZenTaoÃüÁîÖ´ÐЩ¶´


Nature Easy Soft Network Technology ZenTao Cron job Ñ¡Ï´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://privasec.com/blog/zentao-cms-a-monkeys-journey-to-priv-esc-remote-code-execution/


4.ZOHO ManageEngine ADSelfService Plus OSÃüÁî×¢È멶´


ZOHO ManageEngine ADSelfService Plus´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâÃüÁî¡£


https://blog.stmcyber.com/vulns/cve-2021-33055/


5.Advantech WebAccess CVE-2021-38408»º³åÇø´íÎ󩶴


Advantech WebAccess´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://www.advantech.com/support/details/installation?id=1-MS9MJV


>ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢MicrosoftÐû²¼½üÆÚÖ¼ÔÚÇÔȡƾ¾ÝµÄµöÓã»î¶¯µÄ¾¯±¨


Microsoft 365 DefenderÍþвÇ鱨ÍŶÓÔÚ8ÔÂ26ÈÕÐû²¼½üÆÚÖ¼ÔÚÇÔȡƾ¾ÝµÄµöÓã»î¶¯µÄ¾¯±¨¡£Ñо¿ÈËÔ±³Æ£¬¸Ã»î¶¯ÀûÓõç×ÓÓʼþͨÐÅÖеĿª·ÅÖض¨ÏòÁ´½Ó×÷ΪÔØÌ壬ÓÕʹÓû§·ÃÎʶñÒâÍøÕ¾£¬Í¬Ê±ÈƹýÄþ¾²¼ì²âÈí¼þ¡£Î¢ÈíÌåÏÖËüÒѾ­·¢ÏÖÁËÖÁÉÙ350¸öÍøÂçµöÓãURL£¬¶øÇÒËüÃǾùʹÓÃÁËÁîÈËÐÅ·þµÄÓÕ¶üºÍ¾«ÐÄÉè¼ÆµÄ¼ì²âÈƹý¼¼Êõ¡£Õâ²»½öÏÔʾÁ˴˴ι¥»÷µÄ¹æÄ££¬»¹±íÃ÷Á˹¥»÷Õß¾Þ´óµÄͶÈë¡£


MicrosoftÐû²¼½üÆÚÖ¼ÔÚÇÔȡƾ¾ÝµÄµöÓã»î¶¯µÄ¾¯±¨.jpg


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/08/microsoft-warns-of-widespread-phishing.html



2¡¢NFIB³Æ2021ÄêH1Ó¢¹úÒòÍøÂç·¸×ïËðʧ¸ß´ï13ÒÚÓ¢°÷


ÍøÂç·¸×ï.png


À´×ÔÓ¢¹ú¹ú¼ÒÆÛÕ©Ç鱨¾Ö(NFIB)µÄÊý¾Ý±íÃ÷£¬2021ÄêH1Ó¢¹úÒòÍøÂç·¸×ïËðʧ¸ß´ï13ÒÚÓ¢°÷¡£¸öÈ˺Í×éÖ¯ÔÚ½ñÄêÉÏ°ëÄêÒòÍøÂç·¸×ïºÍÆÛÕ©¶øËðʧµÄ×ʽðÊÇ2020ÉÏ°ëÄ꣨4.147ÒÚÓ¢°÷£©µÄÈý±¶¡£2020ÄêH1Ö»ÓÐ39160°¸¼þ£¬¶ø2021ÄêH1¶à´ï289437Æð¡£Ñо¿ÈËÔ±³Æ£¬Õþ¸®Ó¦½ÓÄɸü¶à´ëÊ©À´½ÌÓý¸öÈËÓйØÍøÂçµöÓãµÄ·çÏÕºÍÍøÂçÄþ¾²µÄÖØÒªÐÔ£¬¶ø×éÖ¯Ó¦¸Ã¾¡Á¦½µµÍÔ¶³ÌÊÂÇéµÄ·çÏÕ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/cybercrime-losses-triple-to-13bn/



3¡¢CNNICÐû²¼µÚ48´Î¡¶Öйú»¥ÁªÍøÂçÉú³¤×´¿öͳ¼Æ³ÂËß¡·


CNNICÐû²¼µÚ48´Î¡¶Öйú»¥ÁªÍøÂçÉú³¤×´¿öͳ¼Æ³ÂËß¡·.jpg


Öйú»¥ÁªÍøÂçÐÅÏ¢ÖÐÐÄ£¨CNNIC£©ÓÚ8ÔÂ27ÈÕÔÚ¾©Ðû²¼µÚ48´Î¡¶Öйú»¥ÁªÍøÂçÉú³¤×´¿öͳ¼Æ³ÂËß¡·¡£³ÂËßÏÔʾ£¬½ØÖÁ½ñÄê6Ô£¬ÖйúÍøÃñ¹æÄ£´ï10.11ÒÚ£¬½Ï2020Äê12ÔÂÔö³¤2175Íò£¬»¥ÁªÍøÆÕ¼°ÂÊ´ï71.6%£»»¥ÁªÍø»ù´¡×ÊÔ´¼ÓËÙ½¨É裬½ØÖÁ6Ô£¬ÖйúIPv6µØÖ·ÊýÁ¿´ï62023¿é/32£»ÖйúÅ©´åÍøÃñ¹æģΪ2.97ÒÚ£¬Å©´åµØÓò»¥ÁªÍøÆÕ¼°ÂÊΪ59.2%£¬½Ï2020Äê12Ô£¬³ÇÏ绥ÁªÍøÆÕ¼°ÂʲîÒìËõС4.8%¡£


Ô­ÎÄÁ´½Ó£º

http://finance.people.com.cn/n1/2021/0828/c1004-32210949.html



4¡¢ÒòGoogleÓ¦ÓÃbug£¬²¿ÃÅ°²×¿Óû§ÎÞ·¨²¦´òºÍ½ÓÌýµç»°


ÒòGoogleÓ¦ÓÃbug£¬²¿ÃÅ°²×¿Óû§ÎÞ·¨²¦´òºÍ½ÓÌýµç»°.jpg


GoogleÌåÏÖ£¬²¿ÃÅAndroidÊÖ»úÐͺŵÄÓû§Êܵ½GoogleÓ¦ÓÃÖÐbugµÄÓ°Ï죬ÎÞ·¨²¦´òºÍ½ÓÌýµç»°¡£Ä¿Ç°GoogleûÓйûÈ»ÊÜÓ°ÏìÊÖ»úµÄÐͺÅ£¬µ«±¾ÖÜÄ©ÊÜÓ°ÏìÓû§Ìáµ½ÁËLGµÄÉ豸£¬ÈçLG G7¡¢LG G7 ThinQ¡¢LG V40 ThinQºÍLG Q70µÈ¡£Google³ÆÆäÕýÔÚÊÓ²ì´ËÊ£¬²¢ÒÑÐû²¼ÁË×îиüÐÂÀ´ÐÞ¸´¸Ãbug£¬½¨ÒéÓû§ÊÖ¶¯°²×°×îиüС£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/google/google-app-bug-blocks-android-users-from-receiving-making-calls/


5¡¢Ñо¿ÈËÔ±³Æ16¸öÀ¶ÑÀ©¶´BrakToothÓ°ÏìÊýÊ®ÒÚÉ豸


Ñо¿ÈËÔ±³Æ16¸öÀ¶ÑÀ©¶´BrakToothÓ°ÏìÊýÊ®ÒÚÉ豸.jpg


Ñо¿ÈËÔ±¼ì²âÁËÀ´×Ô11¸ö¹©Ó¦É̵Ä13¸öƬÉÏϵͳ (SoC) µÄÀ¶ÑÀÈí¼þ¿â£¬·¢ÏÖÁË16¸öÓ°ÏìÀ¶ÑÀÈí¼þ¶ÑÕ»µÄ©¶´²¢Í³³ÆËüÃÇΪBrakTooth¡£¹¥»÷Õß¿ÉÒÔÀûÓÃÕâЩ©¶´Ê¹É豸Í߽⣬ÉõÖÁÊÇÖ´ÐжñÒâ´úÂë²¢½Ó¹ÜÕû¸öϵͳ¡£ÕâЩ©¶´ÖÐ×îÑÏÖصÄΪCVE-2021-28139£¬ÀûÓø鶴Զ³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýÀ¶ÑÀLMPÊý¾Ý°üÔÚÄ¿±êÉ豸ÉÏÔËÐжñÒâ´úÂë¡£²¢·ÇËùÓÐËùÓй©Ó¦É̶¼¼°Ê±Ðû²¼Á˲¹¶¡£¬µ½Ä¿Ç°ÎªÖ¹£¬Ö»ÓÐÀÖöΡ¢Ó¢·ÉÁèºÍBluetrumÐû²¼Á˲¹¶¡£¬¶øµÂÖÝÒÇÆ÷ÔòÌåÏ־ܾøÐÞ¸´Â©¶´¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/billions-of-devices-impacted-by-new-braktooth-bluetooth-vulnerabilities