΢ÈíÐû²¼µÄPrintNightmareµÄ½ôÆÈ¸üпɱ»Èƹý£»£»£»£»£»¶íÂÞ˹ºÚ¿Í×éÖ¯APT29ÓÃSynnex¹¥»÷ÃÀ¹ú¹²ºÍµ³RNC

Ðû²¼Ê±¼ä 2021-07-08

1.΢ÈíÐû²¼µÄPrintNightmareµÄ½ôÆÈ¸üпɱ»Èƹý


1.jpg


MicrosoftÐû²¼KB5004945½ôÆÈÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´Ó°ÏìËùÓÐWindows Print SpoolerЧÀÍÖб»Æð¾¢Ê¹ÓõÄPrintNightmare 0day¡£¡£¡£¡£¡£¡£ ¡£¸ÃÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-34527£©ÔÊÐí¹¥»÷ÕßʹÓÃSYSTEMȨÏÞµÄÔ¶³ÌÖ´ÐдúÂë²¢ÍêÈ«½ÓÊÜÄ¿µÄЧÀÍÆ÷¡£¡£¡£¡£¡£¡£ ¡£ÔÚ¸üÐÂÐû²¼ºó£¬£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷¸Ã²¹¶¡½öÐÞ¸´ÁËÉæ¼°Ô¶³Ì´úÂëÖ´ÐеÄ×é¼þ£¬£¬£¬£¬£¬£¬£¬£¬Òò´ËÑо¿Ö°Ô±×îÏÈÐÞ¸ÄÎó²îʹÓóÌÐò²¢²âÊÔ²¹¶¡£¡£¡£¡£¡£¡£ ¡£¬£¬£¬£¬£¬£¬£¬£¬È·¶¨¿ÉÒÔÍêÈ«ÈÆ¹ýÕû¸ö²¹¶¡À´ÊµÏÖÍâµØÌáȨºÍÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-pushes-emergency-update-for-windows-printnightmare-zero-day/


2.Kaspersky·¢Ã÷WildPressureÕë¶ÔmacOSµÄ¹¥»÷»î¶¯


2.jpg


KasperskyµÄÑо¿Ö°Ô±·¢Ã÷WildPressureÔÚ×î½üµÄ¹¥»÷»î¶¯ÖÐÔöÌíÁËÕë¶ÔmacOSµÄ¶ñÒâÈí¼þ±äÌå¡£¡£¡£¡£¡£¡£ ¡£Ñо¿Ö°Ô±ÓÚ2020Äê3ÔÂÊ״η¢Ã÷¸ÃÍŻ£¬£¬£¬£¬£¬£¬£¬ÆäʱWildPressureʹÓÃÁËC++°æ±¾µÄMilumľÂí¹¥»÷Öж«µÄ×éÖ¯¡£¡£¡£¡£¡£¡£ ¡£ÔÚ½üÆÚÕë¶ÔÄÜÔ´ÐÐÒµµÄ¹¥»÷ÖУ¬£¬£¬£¬£¬£¬£¬£¬MilumÒѾ­Í¨¹ýPyInstaller°ü¾ÙÐÐÁËÖØ×飬£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨ÁËÓëWindowsºÍmacOSϵͳ¼æÈݵÄľÂí³ÌÐò£¬£¬£¬£¬£¬£¬£¬£¬±»ºÚµÄÍøÕ¾¿É±»APT×éÖ¯ÓÃÀ´ÏÂÔØºÍÉÏ´«Îļþ²¢Ö´ÐÐÏÂÁî¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/macos-wildpressure-apt/167606/


3.¶íÂÞ˹ºÚ¿Í×éÖ¯APT29ʹÓÃSynnex¹¥»÷ÃÀ¹ú¹²ºÍµ³RNC


3.jpg


ÖªÇéÈËʿ͸¶£¬£¬£¬£¬£¬£¬£¬£¬ÉÏÖܶíÂÞ˹ºÚ¿Í×éÖ¯APT29£¨»òCozy Bear£©Ê¹ÓÃSynnex¹¥»÷ÁËÃÀ¹ú¹²ºÍµ³ÌìÏÂίԱ»á£¨RNC£©¡£¡£¡£¡£¡£¡£ ¡£¸ÃÍÅ»ïÓë¶íÂÞ˹µÄÍâ¹úÇ鱨»ú¹¹ÓйØÁª£¬£¬£¬£¬£¬£¬£¬£¬´ËÇ°Ôø±»Ö¸¿ØÔÚ2016ÄêÈëÇÖÁËÃñÖ÷µ³ÌìÏÂίԱ»á¡£¡£¡£¡£¡£¡£ ¡£¿ÉÊÇ£¬£¬£¬£¬£¬£¬£¬£¬RNCÒ»ÔÙ·ñ¶¨ÆäÔâµ½Á˺ڿÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬²¢³ÆÃ»ÓÐÈκÎÓйØRNCµÄÐÅÏ¢±»µÁ¡£¡£¡£¡£¡£¡£ ¡£Ö®ºó£¬£¬£¬£¬£¬£¬£¬£¬RNCµÃÖªÆäµÚÈý·½¹©Ó¦ÉÌSynnex Corp.Ôâµ½Á˹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬²¢ÌåÏÖÆä·¢Ã÷ºóÁ¬Ã¦Õ¥È¡ÁËSynnexÕÊ»§¶ÔËûÃÇÔÆÇéÐεÄËùÓлá¼û¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bloomberg.com/news/articles/2021-07-06/russian-state-hackers-breached-republican-national-committee


4.CISAÐû²¼Õë¶Ô·ÉÀûÆÖVue PACSÖжà¸öÎó²îµÄÇå¾²×Éѯ


4.jpg


ÃÀ¹úCISAÐû²¼ÁËÕë¶Ô·ÉÀûÆÖÁÙ´²Ð­×÷ƽ̨ÃÅ»§(Vue PACS)ÖÐ15¸öÎó²îµÄÇå¾²×Éѯ¡£¡£¡£¡£¡£¡£ ¡£CISAÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩÎó²îÖеÄ7¸ö±£´æÓÚ·ÉÀûÆÖ²úÆ·£¬£¬£¬£¬£¬£¬£¬£¬¶øÆäÓàÎó²î±£´æÓÚµÚÈý·½×é¼þ£¬£¬£¬£¬£¬£¬£¬£¬ÈçRedis¡¢7-Zip¡¢OracleÊý¾Ý¿â¡¢jQuery¡¢PythonºÍApache Tomcat£¬£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁË·ÉÀûÆÖVue PACS¶à¸ö²úÆ·£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨MyVue¡¢Vue SpeechºÍVue Motion¡£¡£¡£¡£¡£¡£ ¡£ÆäÖнÏΪÑÏÖØµÄÎó²îÊÇÊäÈëÑéÖ¤²»µ±Îó²î£¨CVE-2020-1938£©¡¢»ùÓÚ¿ÍÕ»µÄ»º³åÇøÒç³öÎó²î£¨CVE-2018-12326ºÍCVE-2018-11218£©¡¢Éí·ÝÈÏÖ¤²»µ±Îó²î£¨CVE-2020-4670£©ºÍCVE-2018-8014£¬£¬£¬£¬£¬£¬£¬£¬ËüÃǵÄCVSSÆÀ·Ö¾ùΪΪ9.8¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ics/advisories/icsma-21-187-01


5.SonicWallÇå¾²¸üÐÂÐÞ¸´ÆäNSM×°±¸ÖеÄÏÂÁî×¢ÈëÎó²î


5.jpg


SonicWallÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÆäÍøÂçÇå¾²ÖÎÀíÆ÷ (NSM) ×°±¸ÖеÄÏÂÁî×¢ÈëÎó²î¡£¡£¡£¡£¡£¡£ ¡£¸ÃÎó²î±»×·×ÙΪCVE-2021-20026£¬£¬£¬£¬£¬£¬£¬£¬ÆÀ·ÖΪ8.8£¬£¬£¬£¬£¬£¬£¬£¬¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉʹÓÃÌØÖÆµÄHTTPÇëÇóÖ´ÐÐÏÂÁî×¢Èë¡£¡£¡£¡£¡£¡£ ¡£¸ÃÎó²îÓ°ÏìÁËNSM 2.2.0-R10-H1¼°¸üÔç°æ±¾£¬£¬£¬£¬£¬£¬£¬£¬Çå¾²³§ÉÌÐû²¼ÁËNSM 2.2.1-R6ºÍ2.2.1-R6£¨ÔöÇ¿£©°æ±¾ÐÞ¸´Á˸ÃÎó²î¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/119767/security/sonicwall-fixes-cve-2021-20026-flaw.html


6.Å·ÖÞENISAÐû²¼Õë¶ÔÖÐСÆóÒµµÄÍøÂçÇå¾²Ö¸ÄÏ


6.jpg


Å·ÃËÍøÂçºÍÐÅÏ¢Çå¾²¾Ö£¨ENISA£©Ðû²¼ÁËÕë¶ÔÖÐСÆóÒµµÄÍøÂçÇå¾²Ö¸ÄÏ¡£¡£¡£¡£¡£¡£ ¡£¸ÃÖ¸ÄÏΪÖÐСÐÍÆóÒµÌṩ¹ØÓÚÔõÑùÌá¸ßÆä»ù´¡ÉèÊ©ºÍÓªÒµÇå¾²ÐÔµÄ12Ïî¸ß¼¶½¨Ò飬£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨£º×÷ÓýÓÅÒìµÄÍøÂçÇå¾²ÎÄ»¯¡¢ÌṩÊʵ±µÄÇå¾²Åàѵ¡¢È·±£ÓÐÓõĵÚÈý·½ÖÎÀí¡¢ÖÆ¶©Ê¹ÊÏìÓ¦ÍýÏ롢ȷ±£Çå¾²µÄ»á¼ûϵͳ¡¢È·±£×°±¸Çå¾²¡¢±£»£»£»£»£»¤ÍøÂçÇå¾²¡¢Ìá¸ßÎïÀíÇå¾²ÐÔ¡¢È·±£±¸·ÝÇå¾²¡¢¼ÓÈëÔÆÅÌË㡢ȷ±£ÔÚÏßÍøÕ¾Çå¾²£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°×·ÇóºÍ·ÖÏíÐÅÏ¢¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.enisa.europa.eu/publications/cybersecurity-guide-for-smes