ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ52ÖÜ

Ðû²¼Ê±¼ä 2020-12-28

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2020Äê12ÔÂ21ÈÕÖÁ12ÔÂ27ÈÕ¹²ÊÕ¼Çå¾²Îó²î56¸ö£¬ £¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇABB Symphony Plus Operations SQL×¢ÈëÎó²î£»£»£»£»£»£»D-link DSL-2888A execute_cmd.cgi OSÏÂÁî×¢ÈëÎó²î£»£»£»£»£»£»Zyxel USG SeriesĬÈÏÆ¾Ö¤Îó²î£»£»£»£»£»£»BrowserUp Proxy Java EL±í´ïʽעÈëÎó²î£»£»£»£»£»£»QNAP QES CVE-2020-2499Ó²±àÂëÎó²î ¡£¡£¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇAcronisÐû²¼ÔõÑùÓ¦¶ÔCOVID-19µÄÓ°ÏìµÄ±¨¸æ£»£»£»£»£»£»CISAÐû²¼SolarWinds Orion¹¥»÷ÊÂÎñµÄÔö²¹Ö¸ÄÏ£»£»£»£»£»£»SolarWinds¹©Ó¦Á´¹¥»÷»î¶¯Öб£´æÐµÄSUPERNOVAºóÃÅ£»£»£»£»£»£»NintendoÊý¾Ýй¶£¬ £¬£¬£¬Õ¹ÏÖÔø¹ÍÓ¶ºÚ¿ÍΪÆäÊÂÇ飻£»£»£»£»£»KasperskyÐû²¼LazarusÕë¶ÔCOVID-19Ç鱨µÄÆÊÎö±¨¸æ ¡£¡£¡£¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬ £¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖÐ ¡£¡£¡£¡£¡£¡£¡£¡£


Ö÷ÒªÇå¾²Îó²îÁбí


1.ABB Symphony Plus Operations SQL×¢ÈëÎó²î


ABB Symphony Plus Operations±£´æSQL×¢ÈëÎó²î£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄSQLÇëÇó£¬ £¬£¬£¬²Ù×÷Êý¾Ý¿â£¬ £¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐí§Òâ´úÂë ¡£¡£¡£¡£¡£¡£¡£¡£

https://search.abb.com/library/Download.aspx?DocumentID=2PAA123980&LanguageCode=en&DocumentPartId=&Action=Launch


2.D-link DSL-2888A execute_cmd.cgi OSÏÂÁî×¢ÈëÎó²î


D-link DSL-2888A execute_cmd.cgi±£´æÊäÈëÑéÖ¤Îó²î£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬£¬¿É×¢Èë¶ñÒâOSÏÂÁî²¢Ö´ÐÐ ¡£¡£¡£¡£¡£¡£¡£¡£

https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/d-link-multiple-security-vulnerabilities-leading-to-rce/


3.Zyxel USG SeriesĬÈÏÆ¾Ö¤Îó²î


Zyxel USG Series±£´æzyfwpĬÈÏÕË»§¼°²»¿É¸ü¸ÄÆäÃÜÂ룬 £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬£¬Î´ÊÚȨ»á¼ûЧÀÍÆ÷ ¡£¡£¡£¡£¡£¡£¡£¡£

https://businessforum.zyxel.com/discussion/5254/whats-new-for-zld4-60-patch-1-available-on-dec-15



4.BrowserUp Proxy Java EL±í´ïʽעÈëÎó²î


BrowserUp Proxy±£´æÊäÈëÑéÖ¤Îó²î£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬£¬¿ÉÒÔ×¢Èëí§ÒâJava EL±í´ïʽ²¢ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë ¡£¡£¡£¡£¡£¡£¡£¡£

https://github.com/browserup/browserup-proxy/commit/4b38e7a3e20917e5c3329d0d4e9590bed9d578ab


5.QNAP QES CVE-2020-2499Ó²±àÂëÎó²î


QNAP QES±£´æÓ²±àÂëÎó²î£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬£¬Î´ÊÚȨ»á¼ûϵͳ ¡£¡£¡£¡£¡£¡£¡£¡£

https://www.qnap.com/zh-tw/security-advisory/qsa-20-19


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢AcronisÐû²¼ÔõÑùÓ¦¶ÔCOVID-19µÄÓ°ÏìµÄ±¨¸æ


1.png


AcronisÐû²¼ÁËÔõÑùÓ¦¶ÔCOVID-19µÄÓ°ÏìµÄ±¨¸æ ¡£¡£¡£¡£¡£¡£¡£¡£AcronisÔÚ2020Äê6ÔÂÖÁ7ÔÂʱ´ú¶ÔÈ«Çò3400¼Ò¹«Ë¾ºÍÔ¶³Ì¹¤È˾ÙÐÐÁËÊӲ죬 £¬£¬£¬ÒÔÑо¿×éÖ¯ÔõÑù˳ӦCOVID-19¶ÔÆäITÔËÓªºÍÍøÂçÇå¾²Ì¬ÊÆµÄÓ°Ïì ¡£¡£¡£¡£¡£¡£¡£¡£±¨¸æÏÔʾ£¬ £¬£¬£¬31%µÄ¹«Ë¾ÌìÌì¶¼»áÔâµ½ÍøÂç¹¥»÷£¬ £¬£¬£¬69£¥µÄÔ¶³ÌÊÂÇéÕßÐèÒªÒÀÀµZoom¡¢Cisco WebexµÈ¹¤¾ß¾ÙÐÐЭ×÷£¬ £¬£¬£¬¶ø39£¥µÄ¹«Ë¾ÔâÊÜÁËÊÓÆµ¾Û»á¹¥»÷ ¡£¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬Ö»ÓÐ2£¥µÄ¹«Ë¾ÔÚÆÀ¹ÀÍøÂçÇå¾²½â¾ö¼Æ»®Ê±Ë¼Á¿Ê¹ÓÃURL¹ýÂË ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.acronis.com/en-us/blog/posts/acronis-cyber-readiness-report-pandemic-reveals-cybersecurity-gaps-need-new-solutions


2¡¢CISAÐû²¼SolarWinds Orion¹¥»÷ÊÂÎñµÄÔö²¹Ö¸ÄÏ


2.png


CISA×î³õÓÚ12ÔÂ17ÈÕÐû²¼ÁËÓйØÕþ¸®»ú¹¹¡¢Òªº¦»ù´¡ÉèÊ©ºÍ¹«Ë¾×éÖ¯µÄAPT¹¥»÷»î¶¯µÄ¾¯±¨£¬ £¬£¬£¬Ö®ºóÕë¶Ô¸Ã½ôÆÈÖ¸ÁîÐû²¼ÁËÔö²¹Ö¸ÄÏ ¡£¡£¡£¡£¡£¡£¡£¡£Ôö²¹Ö¸ÄϰüÀ¨ÊÜÓ°Ïì°æ±¾µÄ¸üС¢Õë¶ÔʹÓõÚÈý·½Ð§ÀÍÌṩÉ̵ÄÊðÀíµÄÖ¸ÄÏÒÔ¼°¶ÔËùÐè²½·¥µÄ½øÒ»²½ËµÃ÷ ¡£¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬CISA»¹¸üÐÂÁ˸þ¯±¨£¬ £¬£¬£¬ÌṩÁËÐµĻº½â¼Æ»®²¢ÐÞ¶©ÁËIOC±í¸ñ ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/12/19/cisa-updates-alert-and-releases-supplemental-guidance-emergency


3¡¢SolarWinds¹©Ó¦Á´¹¥»÷»î¶¯Öб£´æÐµÄSUPERNOVAºóÃÅ


3.png


Ñо¿Ö°Ô±·¢Ã÷SolarWinds Orion¹©Ó¦Á´¹¥»÷»î¶¯Öб£´æÐµÄSUPERNOVAºóÃÅ£¬ £¬£¬£¬¿ÉÄÜÀ´×ÔÁíÒ»¸öºÚ¿Í×éÖ¯ ¡£¡£¡£¡£¡£¡£¡£¡£SUPERNOVAÊÇÖ²ÈëOrionÍøÂçºÍÓ¦ÓóÌÐò¼àÊÓÆ½Ì¨´úÂëÖеÄWeb shell£¬ £¬£¬£¬¹¥»÷Õß¿ÉʹÓøöñÒâÈí¼þÔÚÅÌËã»úÉÏÔËÐÐí§Òâ´úÂë ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâ´úÂë½ö°üÀ¨Ò»ÖÖDynamicRunÒªÁ죬 £¬£¬£¬¿É½«²ÎÊý¶¯Ì¬±àÒëµ½ÄÚ´æÖеÄ.NET³ÌÐò¼¯ÖУ¬ £¬£¬£¬Òò´Ë²»»áÔÚÊÜѬȾװ±¸ÉÏÁôÏÂÈκκۼ£ ¡£¡£¡£¡£¡£¡£¡£¡£¾­ÊӲ죬 £¬£¬£¬SUPERNOVAûÓÐÊý×ÖÊðÃû£¬ £¬£¬£¬ÕâÓë×î³õ·¢Ã÷µÄSunBurst²î±ð£¬ £¬£¬£¬»òÐíÊôÓÚÁíÒ»ºÚ¿Í×éÖ¯ ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/a-second-hacking-group-has-targeted-solarwinds-systems/


4¡¢NintendoÊý¾Ýй¶£¬ £¬£¬£¬Õ¹ÏÖÔø¹ÍÓ¶ºÚ¿ÍΪÆäÊÂÇé


4.png


NintendoÔٴα¬·¢ÑÏÖØµÄÊý¾Ýй¶ÊÂÎñ£¬ £¬£¬£¬Õ¹ÏÖÔø¹ÍÓ¶ºÚ¿ÍΪÆäÊÂÇé ¡£¡£¡£¡£¡£¡£¡£¡£´Ë´Îй¶µÄÊý¾ÝÈÔÊÇÊ×ÏÈ·ºÆðÔÚ4chanÂÛ̳ÉÏ£¬ £¬£¬£¬°üÀ¨ÓëSwitchµÄ¿ª·¢Ïà¹ØµÄÎļþ£¬ £¬£¬£¬ÀýÈçSwitchÔçÆÚµÄÉè¼Æ²ÎÊý£¬ £¬£¬£¬ºÃ±ÈʹÓÃ1GÄÚ´æ¡¢480PÇø·ÖÂʵÄÉãÏñÍ·¡¢¼æÈÝ3DSÓÎÏ·¡¢¿ÉÒÔͨ¹ýMiracastͶÆÁµÈ ¡£¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬´Ë´Îй¶»¹Õ¹ÏÖÁËÈÎÌìÌÃÔø¹ÍÓ¶×ÅÃûµÄ3DSºÚ¿ÍΪÆäÊÂÇ飬 £¬£¬£¬ÉõÖÁ»¹Öƶ©ÁËÒ»·Ý¹«¹ØÍýÏ룬 £¬£¬£¬ÒÔ½â¾öÔÚ·¢Ã÷¸Ã¹ÍÓ¶¹ØÏµºóÈçÄÇÀïÖù«ÖÚ·´Ó¦ ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.videogameschronicle.com/news/nintendo-has-reportedly-suffered-another-major-data-leak-now-related-to-switch/


5¡¢KasperskyÐû²¼LazarusÕë¶ÔCOVID-19Ç鱨µÄÆÊÎö±¨¸æ


5.png


KasperskyÐû²¼ÓйغڿÍ×éÖ¯LazarusÕë¶ÔCOVID-19Ç鱨µÄ¹¥»÷»î¶¯µÄÆÊÎö±¨¸æ ¡£¡£¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬ £¬£¬£¬LazarusÓÚ2020Äê9ÔÂ25ÈÕÈëÇÖÁËÒ»¼ÒÖÆÒ©¹«Ë¾£¬ £¬£¬£¬²¢ÓÚ2020Äê10ÔÂ27ÈÕ¹¥»÷ÁËÕþ¸®ÎÀÉú²¿£¬ £¬£¬£¬²¢Ëð»µÁËÁ½Ì¨WindowsЧÀÍÆ÷ ¡£¡£¡£¡£¡£¡£¡£¡£ÕâÁ½´Î¹¥»÷»î¶¯Ê¹ÓÃÁ˲î±ðµÄÕ½Êõ¡¢ÊÖÒպͳÌÐò£¨TTP£©ÒÔ¼°¶ñÒâÈí¼þ¼¯Èº£¬ £¬£¬£¬µ«ÓÐÖ¤¾ÝÅú×¢¶¼ÓëLazarusÓйØ£¬ £¬£¬£¬²¢Ö¤Êµ¸Ã×éÖ¯¶ÔÓëCOVID-19Ïà¹ØµÄÇ鱨¸ÐÐËȤ ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/lazarus-covets-covid-19-related-intelligence/99906/