¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.05.31-2021.06.06£©
2021-06-08
Ò»¡¢ ÈÈÃÅ×ÊѶ
1. FBI֤ʵJBSÊDZ»REvilÀÕË÷Èí¼þÍŻ﹥»÷
¡¾¸ÅÊö¡¿
5 Ô 30 ÈÕ£¬È«Çò×î´óµÄÐÂÏÊÅ£Èâ¼Ó¹¤ÉÌÃÀ¹úʳÎï¼Ó¹¤¾ÞÍ· JBS Foods ÒòÔâÊÜÍøÂç¹¥»÷¶ø±»ÆÈ¹Ø±ÕÈ«Çò¶à¸öËùÔÚµÄÉú²ú¡£ÍøÂç¹¥»÷Ó°ÏìÁ˸ù«Ë¾ÔÚÈ«ÇòµÄ¶à¸öÉú²ú¹¤³§£¬°üÀ¨Î»ÓÚÃÀ¹ú¡¢°Ä´óÀûÑǺͼÓÄôóµÄ¹¤³§£¬¹¥»÷¶ÔλÓÚÕâЩµØ·½µÄ»ù´¡ÉèÊ©Ôì³ÉÁËÑÏÖØÓ°Ïì¡£FBI½«´Ë´Î¹¥»÷¹éÒòÓÚREvil£¨Ò²±»³ÆÎªSodinokibi£©ÀÕË÷Èí¼þÍŻ´ËÍÅ»ïÊÇÓë¶íÂÞ˹Óйء£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYJz
2. NobeliumÍøÂç´¹ÂÚÔ˶¯Ã°³äÃÀ¹ú¹ú¼Ê¿ª·¢Êð
¡¾¸ÅÊö¡¿
΢Èí·¢Ã÷SolarWindsʹÓÃȺ·¢Óʼþ·þÎñConstant Contact²¢Ã°³ä×ܲ¿ÉèÔÚÃÀ¹úµÄ¿ª·¢×éÖ¯£¬Ïò150¶à¸ö»ú¹¹Ìṩ¶ñÒâURL¡£´Ë¹¥»÷ÊÂÎñ¹éÒòÓÚNobeliumÍþв×éÖ¯£¬¸Ã×éÖ¯ÏòÀ´Õë¶Ô¹æÄ£ÆÕ±éµÄ»ú¹¹£¬°üÀ¨Õþ¸®»ú¹¹¡¢·ÇÕþ¸®×éÖ¯¡¢Öǿ⡢¾ü¶Ó¡¢IT ·þÎñÌṩÉÌ¡¢Ò½ÁÆÊÖÒÕÑо¿»ú¹¹¡¢ÒÔ¼°µçÐÅÌṩÉÌ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYIR
3. WordPress²å¼þ¸ßΣÎó²î±»Ê¹ÓÃ
¡¾¸ÅÊö¡¿
¹¥»÷ÕßÕýÔÚʹÓà WordPress ²å¼þ Fancy Product Designer ÖеÄÒ»¸öÒªº¦ÁãÈÕÎó²î£¬¸ÃÎó²îÔÊÐíÔ¶³ÌÖ´ÐдúÂë¡£ÓÉÓÚ²¹¶¡ÉÐδÐû²¼£¬¸ÃÍŶӱ޲ßÓû§Á¬Ã¦Ð¶ÔØÒ×Êܹ¥»÷µÄ²å¼þ¡£¹¥»÷Õß¿ÉÄÜÕýÔÚʹÓòå¼þÖеÄÒªº¦Ô¶³Ì´úÂëÎó²îÉÏ´«¶ñÒâÎļþ£¬Ö»¹Ü WordPress ÓÐÒ»¸öÄÚÖõķÀ»ðǽ£¬µ«¹¥»÷ÕßÕýÔÚÈÆ¹ýËüÀ´Ê¹ÓøÃÎó²î²¢ÔÚʵÑéÍêÈ«½ÓÊÜÍøÕ¾Ö®Ç°ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£ÓÉÓÚÕâÊÇÒ»¸öÊܵ½×Ô¶¯¹¥»÷µÄÒªº¦ÁãÈÕÎó²î£¬×ÝÈ»²å¼þÒÑÍ£Óã¬ÔÚijЩÉèÖÃÖÐÈÔ¿ÉʹÓá£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYJr
4. ¹¥»÷ÕßʹÓÃNativeZoneºóÞÙÐÐÍøÂç´¹ÂÚ
¡¾¸ÅÊö¡¿
΢ÈíÐû²¼ÖÒÑԳƣ¬ÔÚÏë·¨¿ØÖÆÁËÃÀ¹ú¹ú¼Ê¿ª·¢Êð(USAID)µÄµç×ÓÓʼþÓªÏúƽ̨Constant ContactÕË»§ºó£¬Nobelium×é֯Ŀ½ñÕýÔÚ¾ÙÐÐÍøÂç´¹ÂÚÔ˶¯¡£´Ë´ÎÍøÂç´¹ÂÚÐж¯µÄÄ¿µÄÊÇÔ¼3000¸öÕþ¸®»ú¹¹¡¢¾ü¶Ó¡¢Ò½ÁƺͷÇÕþ¸®×éÖ¯ÓйصÄÕË»§£¬´ó²¿·ÖÊܺ¦ÕßλÓÚÃÀ¹ú£¬³ý´ËÖ®ÍâÖÁÉÙ»¹Éæ¼°24¸ö¹ú¼Ò¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYIV
5. Scripps Health»ú¹¹ÖÐÁè¼Ý14,7ÍòÃû»¼ÕßÐÅÏ¢ÔâÇÔÈ¡
¡¾¸ÅÊö¡¿
Scripps Health Ò½ÁÆ»ú¹¹ÔâÀÕË÷Èí¼þ¹¥»÷£¬Áè¼Ý14.7Íò»¼ÕßµÄСÎÒ˽¼Ò²ÆÎñÐÅÏ¢ºÍ¿µ½¡ÐÅÏ¢±»ÀÕË÷Èí¼þ¹¥»÷ÕßÇÔÈ¡£¬±»ÇÔÈ¡µÄÊý¾Ý°üÀ¨ÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢¿µ½¡°ü¹ÜÐÅÏ¢¡¢Ò½ÁƼͼ±àºÅ¡¢»¼ÕßÕʺźÍÁÙ´²ÐÅÏ¢£¬ÀýÈçÒ½ÉúÐÕÃû¡¢·þÎñÈÕÆÚºÍÖÎÁÆÐÅÏ¢£¬Óв»µ½2.5%»¼Õߣ¬Éç»áÇå¾²ºÅÂëºÍ¼ÝʻִÕÕºÅÂëÒ²±»Ð¹Â¶¡£Scripps Health ÌåÏÖ£¬Æù½ñΪֹ£¬Ã»Óм£ÏóÅú×¢Èκα»µÁÊý¾ÝÒѱ»ÓÃÓÚʵÑéڲơ£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYJI
6. Windows HTTPÖиßΣÎó²îÒ²»áÓ°ÏìWinRM·þÎñÆ÷
¡¾¸ÅÊö¡¿
Windows IIS·þÎñÆ÷µÄHTTPÐÒé¿ÍÕ»Öб£´æÒ»¸ö¿É¹¥»÷µÄÎó²î£¬¸ÃÎó²î»¹¿ÉÓÃÓÚ¹¥»÷δÐÞ²¹µÄWindows 10ºÍ¹ûÕæÌ»Â¶WinRM£¨WindowsÔ¶³ÌÖÎÀí£©·þÎñµÄ·þÎñÆ÷ϵͳ¡£Î¢ÈíÒѾÔÚ5Ô²¹¶¡ÖÐÐÞ²¹ÁËÎó²î±àºÅΪCVE-2021-31166µÄÑÏÖØÎó²î¡£Ö»¹Ü¸ÃÎó²î¿ÉÄÜÔÚÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¹¥»÷Öб»ÍþвÀÄÓ㬵«¸ÃÎó²î½öÓ°ÏìWindows 10ºÍWindows ServerµÄ2004ºÍ20H2°æ±¾¡£Microsoft½¨ÒéÓÅÏÈ˼Á¿ÐÞ²¹ËùÓÐÊÜÓ°ÏìµÄ·þÎñÆ÷£¬ÓÉÓÚ¸ÃÎó²î¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õߣ¬ÔÚÒ×Êܹ¥»÷µÄÅÌËã»úÉÏÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYJE
7. CiscoÐÞ¸´ÁËWebexµÈÈí¼þÖеĶà¸ö¸ßΣÎó²î
¡¾¸ÅÊö¡¿
CiscoÒѽâ¾öÆä²úÆ·ÖеĶà¸öÎó²î£¬°üÀ¨ Webex Player¡¢SD-WAN Èí¼þºÍ ASR 5000 ϵÁÐÈí¼þÖеĸßΣº¦È±ÏÝ£¬ÆäÖÐÐÞ¸´ÁËÓ°Ïì Windows ºÍ macOS µÄ Webex ²¥·ÅÆ÷µÄÈý¸ö¸ßÑÏÖØÐÔÎó²î£¨CVE-2021-1503¡¢CVE-2021-1526¡¢CVE-2021-1502£©¡£CVE-2021-1502¡¢CVE-2021-1503 ¶¼ÊÇÓ°Ïì Webex ÍøÂç¼Òô²¥·ÅÆ÷ºÍ Webex ²¥·ÅÆ÷°æ±¾ 41.4 ¼°ÒÔºóµÄÄÚ´æËð»µÎó²î¡£CVE-2021-1526 ÊÇÒ»¸öÄÚ´æËð»µÎÊÌ⣬¹¥»÷Õß¿ÉÒÔʹÓøÃÎÊÌâÔÚÊÜÓ°ÏìµÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYJO
8. ÈÕ±¾ÖÐÑëÊ¡Ìü±»ºÚ£¬¸»Ê¿Í¨SaaSƽ̨³É“¹¥»÷̤°å”
¡¾¸ÅÊö¡¿
ºÚ¿Íͨ¹ýÈëÇÖ¸»Ê¿Í¨µÄProjectWEBƽ̨£¬²»·¨»á¼ûºÍÇÔÈ¡ÈÕ±¾ÖÐÑëÊ¡ÌüºÍÖ÷Òª»ù´¡ÉèÊ©ÆóÒµÊý¾Ý¡£ProjectWEBÊǸ»Ê¿Í¨ÔÚ2000ÄêÔÂÖÐÆÚÍÆ³öµÄ»ùÓÚÔÆµÄÆóÒµÐ×÷ºÍÎļþ¹²ÏíÆ½Ì¨£¬ÏÖÔÚÒѱ»ÈÕ±¾Õþ¸®»ú¹¹ÆÕ±éʹÓ㬴˴ÎÈëÇÖÊÂÎñÒ²µ¼ÖÂÈÕÄÚÇ鹨»ú¹¹ÊÜËðÑÏÖØ¡£Êܵ½Ó°ÏìµÄ»ú¹¹°üÀ¨ÁËÈÕ±¾ÖÐÑëÊ¡ÌüÖ®Ò»µÄÁìÍÁ½»Í¨Ê¡£¨Ministry of Land, Infrastructure, Transport and Tourism £©ÒÔ¼°ÄÚ¸óÃØÊé´¦¡¢³ÉÌï»ú³¡¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYII

AG¹«Ë¾ÔÆ







