ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ40ÖÜ
Ðû²¼Ê±¼ä 2021-10-08>±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2021Äê09ÔÂ27ÈÕÖÁ10ÔÂ03ÈÕ¹²ÊÕ¼Çå¾²Îó²î59¸ö£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicro Focus ArcSight Enterprise Security ManagerÔ¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»£»Nagios XI repairmysql.sh²»×¼È·È¨ÏÞÖ¸ÅÉ´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»£»ECOA BAS controllerÃô¸ÐÐÅϢй¶Îó²î£»£»£»£»£»£»£»Tenda AC9 httpd»º³åÇøÒç³öÎó²î£»£»£»£»£»£»£»Siemens Solid Edge OBJÎļþCVE-2021-41535ÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇWindows WPBTÖеÄÐÂÎó²îÓ°ÏìWin8¼°Ö®ºóËùÓÐϵͳ£»£»£»£»£»£»£»Å·ÖÞºô½ÐÖÐÐũӦÉÌGSSÔâµ½ContiÍÅ»ïµÄÀÕË÷¹¥»÷£»£»£»£»£»£»£»ÃÀ¹úVoIPÌṩÉÌBandwidth.comÔâµ½DDoS¹¥»÷£»£»£»£»£»£»£»Î¢Èí·¢Ã÷Ö¼ÔÚÇÔÈ¡AD FSÖÎÀíԱƾ֤µÄºóÃÅFoggyWeb£»£»£»£»£»£»£»CISAºÍNSAÁªºÏÐû²¼ÓйØÑ¡ÔñºÍ¼Ó¹ÌVPNµÄÇå¾²Ö¸ÄÏ¡£¡£¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£
>Ö÷ÒªÇå¾²Îó²îÁбí
1.Micro Focus ArcSight Enterprise Security ManagerÔ¶³Ì´úÂëÖ´ÐÐÎó²î
Micro Focus ArcSight Enterprise Security Manager±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
https://portal.microfocus.com/s/article/KM000001960?language=en_US
2.Nagios XI repairmysql.sh²»×¼È·È¨ÏÞÖ¸ÅÉ´úÂëÖ´ÐÐÎó²î
Nagios XI repairmysql.sh±£´æ²»×¼È·È¨ÏÞÖ¸ÅÉÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
https://www.nagios.com/downloads/nagios-xi/change-log/
3.ECOA BAS controllerÃô¸ÐÐÅϢй¶Îó²î
ECOA BAS controller´¦Öóͷ£HTTP GETÇëÇó±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£
https://www.twcert.org.tw/tw/cp-132-5137-730a6-1.html
4.Tenda AC9 httpd»º³åÇøÒç³öÎó²î
Tenda AC9 httpd /goform/SetStaticRouteCfg±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
https://github.com/grapefruitvul/vulinfo/blob/master/tenda/vul1.md
5.Siemens Solid Edge OBJÎļþCVE-2021-41535ÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î
Siemens Solid Edge SE2021 OBJÎļþ±£´æÊͷźóʹÓÃÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£»£»£»òÕßÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
https://cert-portal.siemens.com/productcert/pdf/ssa-728618.pdf
>Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢Windows WPBTÖеÄÐÂÎó²îÓ°ÏìWin8¼°Ö®ºóËùÓÐϵͳ

EclypsiumÑо¿ÍŶӷ¢Ã÷Microsoft Windowsƽ̨¶þ½øÖƱí(WPBT)Öб£´æÒ»¸öÎó²î£¬£¬£¬£¬¿ÉÓÃÀ´ÔÚϵͳÉÏ×°ÖÃRootkit¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁË2012ÄêÖ®ºó¿¯ÐеÄWindows 8¼°¸ü¸ß°æ±¾µÄËùÓÐϵͳ£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚϵͳÆô¶¯Ê±ÒÔÄÚºËȨÏÞÔËÐжñÒâ´úÂë¡£¡£¡£¡£¡£¡£Î¢ÈíÌá³öµÄ»º½â²½·¥°üÀ¨Ê¹ÓÃWindows DefenderÓ¦ÓóÌÐò¿ØÖÆ£¨WDAC£©Õ½ÂÔÀ´¿ØÖÆÔÚϵͳÖÐÔËÐеĶþ½øÖÆÎļþ£¬£¬£¬£¬»òʹÓÃAppLockerÕ½ÂÔÀ´¿ØÖÆÔÊÐíÔËÐеÄÓ¦Óᣡ£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-wpbt-flaw-lets-hackers-install-rootkits-on-windows-devices/
2¡¢Å·ÖÞºô½ÐÖÐÐũӦÉÌGSSÔâµ½ContiÍÅ»ïµÄÀÕË÷¹¥»÷

Covisian½²»°È˳ƣ¬£¬£¬£¬ÆäÎ÷°àÑÀºÍÀ¶¡ÃÀÖÞ·Ö²¿GSSÓÚ9ÔÂ18ÈÕÔâµ½ÁËContiÍÅ»ïµÄÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£CovisianÊÇÅ·ÖÞ×î´óµÄ¿Í»§Ð§Àͺͺô½ÐÖÐÐũӦÉÌÖ®Ò»£¬£¬£¬£¬´Ë´Î¹¥»÷µ¼ÖÂÆä´ó²¿·ÖϵͳÖÐÖ¹£¬£¬£¬£¬Ó°ÏìÁËVodafone Spain¡¢MasMovil ISP¡¢ÂíµÂÀïµÄ¹©Ë®¹«Ë¾ºÍµçÊǪ́µÈ¹«Ë¾ºÍ×éÖ¯¡£¡£¡£¡£¡£¡£²»¾Ãǰ£¬£¬£¬£¬ÃÀ¹úµÄºô½ÐÖÐÐĺͿͻ§Ö§³ÖЧÀ͹©Ó¦ÉÌTTECÒ²Ôâµ½ÁËÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/122570/cyber-crime/gss-ransomware-attack.html
3¡¢ÃÀ¹úVoIPÌṩÉÌBandwidth.comÔâµ½DDoS¹¥»÷

ÃÀ¹úVoIPÌṩÉÌBandwidth.comÔÚ½üÆÚÔâµ½ÁËDDoS¹¥»÷£¬£¬£¬£¬µ¼ÖÂÒÑÍù¼¸ÌìÄÚÆäÔÚÈ«ÃÀµÄÓïÒôЧÀÍÖÐÖ¹¡£¡£¡£¡£¡£¡£Bandwidth´ÓÃÀ¹ú¶«²¿Ê±¼ä9ÔÂ25ÈÕÏÂÖç3:31×îÏȱ¨¸æÆäϵͳ·ºÆð¹ÊÕÏ£¬£¬£¬£¬Ó°ÏìÁËÓïÒô¡¢ÔöÇ¿ÐÍ911(E911)ЧÀÍ¡¢ÐÂÎÅ·¢Ëͺ͹ÙÍø»á¼û¡£¡£¡£¡£¡£¡£Bandwidthδ¹ûÕæÐ§ÀÍÖÐÖ¹µÄÔµ¹ÊÔÓÉ£¬£¬£¬£¬µ«ÆäÔ±¹¤³ÆÊÇDDoS¹¥»÷µ¼Öµġ£¡£¡£¡£¡£¡£±¾ÔÂVoIP.msÔøÔ⵽ΪÆÚÒ»ÖܵÄDDoS¹¥»÷²¢±»ÀÕË÷450ÍòÃÀÔª£¬£¬£¬£¬Éв»ÇåÎúBandwidthÊÇ·ñÒ²Ôâµ½ÁËÀàËÆµÄÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/bandwidthcom-is-latest-victim-of-ddos-attacks-against-voip-providers/
4¡¢Î¢Èí·¢Ã÷Ö¼ÔÚÇÔÈ¡AD FSÖÎÀíԱƾ֤µÄºóÃÅFoggyWeb

΢ÈíÍþвÇ鱨ÖÐÐÄ(MSTIC)ÓÚ9ÔÂ27ÈÕÅû¶ÁËÖ¼ÔÚÇÔÈ¡Active DirectoryÁªºÏÉí·ÝÑé֤ЧÀÍ(AD FS)ÖÎÀíԱƾ֤µÄºóÃÅFoggyWeb¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÓë¶íÂÞ˹Íâ¹úÇ鱨¾Ö(SVR)µÄºÚ¿ÍÍÅ»ïNobeliumÓйأ¬£¬£¬£¬ÀÄÓÃÁËSAMLÁîÅÆ¡£¡£¡£¡£¡£¡£Ëü¿ÉÒÔΪ¹¥»÷Õß½ç˵µÄURIÉèÖÃHTTP¼àÌýÆ÷£¨ÕâЩURIÄ£ÄâÁËÄ¿µÄAD FSʹÓõÄÕýµ±URIµÄ½á¹¹£©£¬£¬£¬£¬À´¼àÌý·¢Ë͵½AD FSµÄHTTP GETºÍPOSTÇëÇ󣬣¬£¬£¬²¢×èµ²Óë×Ô½ç˵URIģʽƥÅäµÄHTTPÇëÇ󡣡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.microsoft.com/security/blog/2021/09/27/foggyweb-targeted-nobelium-malware-leads-to-persistent-backdoor/
5¡¢CISAºÍNSAÁªºÏÐû²¼ÓйØÑ¡ÔñºÍ¼Ó¹ÌVPNµÄÇå¾²Ö¸ÄÏ

ÃÀ¹úCISAºÍNSAÔÚ9ÔÂ28ÈÕÁªºÏÐû²¼ÁËÓйØÑ¡ÔñºÍ¼Ó¹ÌVPNµÄÇå¾²Ö¸ÄÏ¡£¡£¡£¡£¡£¡£Ö¸ÄÏÖ¸³ö£¬£¬£¬£¬×éÖ¯Ó¦¸Ã´ÓÐÅÓþÓÅÒìµÄ¹©Ó¦ÉÌÄÇÀïÑ¡Ôñ²úÆ·£¬£¬£¬£¬ÓÉÓÚËûÃÇ»áÒÔ×î¿ìµÄËÙÂÊÐÞ¸´ÒÑÖªÎó²î¡£¡£¡£¡£¡£¡£Çå¾²»ú¹¹³Æ£¬£¬£¬£¬VPN×°±¸¿ÉÒÔÍøÂçÆ¾Ö¤¡¢ÓÃÀ´Ô¶³ÌÖ´ÐдúÂë¡¢Ï÷Èõ¼ÓÃÜÁ÷Á¿»á»°µÄ¼ÓÃÜ¡¢Ð®ÖƻỰÒÔ¼°¶ÁÈ¡Ãô¸ÐÐÅÏ¢£¬£¬£¬£¬½¨Òé×éÖ¯ÉèÖÃÇ¿¼ÓÃܺÍÉí·ÝÑéÖ¤¡¢½öÔËÐÐÐëÒªµÄ¹¦Ð§ÒÔ¼°±£»£»£»£»£»£»£»¤ºÍ¼à¿Ø¶ÔVPNµÄ»á¼û¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2021/09/28/cisa-and-nsa-release-guidance-selecting-and-hardening-vpns


¾©¹«Íø°²±¸11010802024551ºÅ