ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ45ÖÜ
Ðû²¼Ê±¼ä 2021-11-08>±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
±¾Öܹ²ÊÕ¼Äþ¾²Â©¶´60¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇCisco Policy Suite¾²Ì¬SSHÃÜԿ©¶´£»Mozilla Firefox ESR HTTP2 session objectÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´£»Apache Traffic Server stats-over-http²å¼þÄÚ´æÁýÕÖ©¶´£»D-Link DIR-823G HNAP1ÃüÁî×¢È멶´£»Beckhoff Automation TwinCAT OPC UA ServerĿ¼±éÀú©¶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊDz¿ÃÅMacÉ豸Éý¼¶ÖÁmacOS MontereyºóÎÞ·¨Õý³£Æô¶¯£»Ñо¿ÍŶӷ¢ÏÖ¼¸ºõÍþвËùÓдúÂëµÄ©¶´Trojan Source£»Ñо¿ÍŶӳƽ©Ê¬ÍøÂçPinkÒÑѬȾÁè¼Ý160Íǫ̀ÖйúµÄÉ豸£»GoogleÐû²¼Android 11Ô¸üУ¬×ܼÆÐÞ¸´39¸ö©¶´£»BlackMatterÍÅ»ïÐû²¼ÆÈÓÚÖ´·¨²¿ÃŵÄѹÁ¦½«Í£Ö¹ÔËÓª¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
>ÖØÒªÄþ¾²Â©¶´Áбí
1. Cisco Policy Suite¾²Ì¬SSHÃÜԿ©¶´
Cisco Policy Suite´æÔÚ¾²Ì¬SSHÃÜԿ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬Î´ÊÚȨ·ÃÎÊϵͳ¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cps-static-key-JmS92hNv
2. Mozilla Firefox ESR HTTP2 session objectÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´
Mozilla Firefox ESR HTTP2 session object´æÔÚÊͷźóʹÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄWEBÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.mozilla.org/en-US/security/advisories/mfsa2021-49/
3. Apache Traffic Server stats-over-http²å¼þÄÚ´æÁýÕÖ©¶´
Apache Traffic Server stats-over-http²å¼þ´æÔÚÄÚ´æÁýÕÖ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://lists.apache.org/thread/k01797hyncx53659wr3o72s5cvkc3164
4. D-Link DIR-823G HNAP1ÃüÁî×¢È멶´
D-Link DIR-823G HNAP1´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâSHELLÃüÁî¡£
https://www.dlink.com/en/security-bulletin/
5. Beckhoff Automation TwinCAT OPC UA ServerĿ¼±éÀú©¶´
Beckhoff Automation TwinCAT OPC UA Server´æÔÚĿ¼±éÀú©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄ´´½¨»òɾ³ýϵͳÉϵÄÈκÎÎļþ¡£
https://download.beckhoff.com/download/document/product-security/Advisories/advisory-2021-003.pdf
>ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢²¿ÃÅMacÉ豸Éý¼¶ÖÁmacOS MontereyºóÎÞ·¨Õý³£Æô¶¯
½üÆÚ£¬Ô½À´Ô½¶àµÄMacºÍMacbookÓû§³ÂËߣ¬µ±Æä¸üе½ÉÏÖÜÐû²¼µÄ×îаæmacOS Montereyºó£¬É豸ÎÞ·¨Õý³£Æô¶¯¡£´ËÎÊÌâËƺõ½öÓ°ÏìÁË2019Äê֮ǰµÄMacÉ豸£¬²»»áÓ°ÏìʹÓÃM1оƬµÄпîMac¡£´ËÍ⣬ËäÈ»²¿ÃÅÓû§³ÆËûÃǵÄϵͳÒѾ±äש£¬µ«´ó¶àÊýÓû§¿ÉÒÔͨ¹ýApple Configurator¹¤¾ß»Ö¸´É豸¡£ÆäËûÓû§ÔòÕÒµ½ÁËÁíÒ»ÖÖÒªÁ죬¾ÍÊÇͨ¹ýÆô¶¯DFUÀ´»Ö¸´É豸¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/apple/macos-monterey-update-causes-some-macs-to-become-unbootable/
2¡¢Ñо¿ÍŶӷ¢ÏÖ¼¸ºõÍþвËùÓдúÂëµÄ©¶´Trojan Source
½£ÇÅ´óѧµÄÑо¿ÈËÔ±ÔÚ11ÔÂ1ÈÕ¹ûÈ»ÁËÒ»¸öÓ°Ïì´ó¶àÊý¼ÆËã»ú´úÂë±àÒëÆ÷ºÍÐí¶àÈí¼þ¿ª·¢»·¾³µÄ©¶´Trojan Source¡£¸Ã©¶´´æÔÚÓÚUnicodeÖУ¬ÓÐÁ½ÖÖÀûÓÃÒªÁ죺ÆäÒ»ÊÇʹÓÃUnicodeµÄBidiËã·¨£¨CVE-2021-42574£©£¬¶Ô×Ö·û½øÐÐÊÓ¾õÉϵÄÖØÐÂÅÅÐò£¬Ê¹Æä·ºÆðÓë±àÒëÆ÷ºÍ½âÊÍÆ÷Ëù²îÒìµÄÂ߼˳Ðò£»ÁíÒ»ÖÖÊÇͬÐÎÎÄ×Ö¹¥»÷(CVE-2021-42694)£¬¼´ÀûÓÃÔÚÊÓ¾õÉÏ¿´ÆðÀ´ÏàËƵIJîÒì×Ö·û¡£¸Ã©¶´ÊÊÓÃÓÚC¡¢C++¡¢C#¡¢JavaScript¡¢JavaµÈ¹ã·ºÊ¹ÓõÄÓïÑÔ£¬¿ÉÓÃÓÚ¹©Ó¦Á´¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.trojansource.codes/
3¡¢Ñо¿ÍŶӳƽ©Ê¬ÍøÂçPinkÒÑѬȾÁè¼Ý160Íǫ̀ÖйúµÄÉ豸
Ñо¿ÍŶÓÔÚ10ÔÂ29ÈÕÅû¶ÁËÔÚ¹ýÈ¥ÁùÄê·¢ÏÖµÄ×î´ó½©Ê¬ÍøÂçµÄϸ½Ú¡£ÒòΪÆä´óÁ¿µÄº¯ÊýÃû³ÆÒÔpinkΪÊ×£¬ËùÒÔÈ¡ÃûPinkbot¡£¸Ã½©Ê¬ÍøÂçÒÑѬȾÁËÁè¼Ý160Íǫ̀É豸£¬ÆäÖÐ96%λÓÚÖйú¡£ËüÖ÷ÒªÕë¶Ô»ùÓÚMIPSµÄ¹âÏË·ÓÉÆ÷£¬ÀûÓõÚÈý·½·þÎñµÄ×éºÏ£¬ÀýÈçGitHub¡¢P2PÍøÂçºÍC2·þÎñÆ÷£¬»¹¶Ô²¿ÃÅÓòÃûµÄ½âÎö²éѯ½ÓÄÉÁËDNS-Over-HTTPSµÄ·½Ê½¡£Ñо¿ÈËÔ±³Æ£¬Æù½ñΪֹ£¬PinkBotÌᳫÁ˽ü°Ù´ÎDDoS¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/11/researchers-uncover-pink-botnet-malware.html
4¡¢GoogleÐû²¼Android 11Ô¸üУ¬×ܼÆÐÞ¸´39¸ö©¶´
GoogleÔÚ±¾ÖÜÒ»Ðû²¼ÁËAndroid 11Ô·ݵĸüУ¬×ܼÆÐÞ¸´39¸ö©¶´¡£´Ë´Î¸üÐÂÐÞ¸´ÁËÒ»¸öÒѱ»ÔÚÒ°ÀûÓõÄ0day£¬ÊÇÓÉÊͷźóʹÓõ¼Öµĵ±µØÌáȨ©¶´CVE-2021-1048¡£´ËÍ⣬»¹ÐÞ¸´Á˶à¸öÑÏÖصÄ©¶´£¬°üÂÞÔ¶³Ì´úÂëÖ´ÐЩ¶´CVE-2021-0918ºÍCVE-2021-0930£¬Ó°Ïì¸ßͨ×é¼þµÄCVE-2021-1924ºÍCVE-2021-1975£¬ÒÔ¼°Android TVÔ¶³Ì·þÎñÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´CVE-2021-0889µÈ¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/android-patches-exploited-kernel-bug/175931/
5¡¢BlackMatterÍÅ»ïÐû²¼ÆÈÓÚÖ´·¨²¿ÃŵÄѹÁ¦½«Í£Ö¹ÔËÓª
11ÔÂ1ÈÕ£¬ÀÕË÷ÔËÓªÍÅ»ïBlackMatterÔÚÆäÊý¾Ýй¶ÍøÕ¾ÉÏÐû²¼ÏûÏ¢£¬³ÆÆÈÓÚÖ´·¨²¿ÃŵÄѹÁ¦ËûÃǽ«ÔÚ48СʱÄڹرÕÕû¸ö»ù´¡ÉèÊ©¡£Ñо¿ÍŶÓÌåÏÖ£¬Õâ¿ÉÄÜÓë×î½üµÄÒ»´Î¹ú¼ÊÖ´·¨Ðж¯Óйأ¬´Ë´ÎÐж¯¹²´þ²¶ÁË12¸öÉæ¼°1800ÆðÀÕË÷¹¥»÷»î¶¯µÄÏÓÒÉÈË¡£È»¶ø£¬¼´Ê¹BlackMatterÏÖÔÚÍ£Ö¹ÆäÔËÓª£¬ÔÚδÀ´Ò²½«»áÒÔеÄÃû³Æ»Ø¹é£¬ÕýÈçBlackMatter×Ô¼º¾ÍÊÇDarkSideÔÚ¹¥»÷Colonial PipelineºóÆÈÓÚѹÁ¦¸üÃû¶øÀ´µÄ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/124135/cyber-crime/blackmatter-ransomware-shutting-down-operations.html