¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.06.07-2021.06.13£©
2021-06-15
Ò»¡¢ Íþвͨ¸æ
΢Èí2021Äê6ÔÂÇå¾²¸üжà¸ö²úÆ·¸ßΣÎó²î
¡¾Ðû²¼Ê±¼ä¡¿2021-06-10 10:00:00 GMT
¡¾¸ÅÊö¡¿
6ÔÂ9ÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½Î¢ÈíÐû²¼6ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË50¸öÇå¾²Îó²î£¬Éæ¼°Windows¡¢Microsoft Office¡¢Microsoft Edge¡¢Visual Studio ¡¢SharePoint ServerµÈÆÕ±éʹÓõIJúÆ·£¬ÆäÖаüÀ¨Ô¶³Ì´úÂëÖ´ÐкÍȨÏÞÌáÉýµÈ¸ßΣÎó²îÀàÐÍ¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
Windows Print SpoolerȨÏÞÌáÉýÎó²îͨ¸æ
¡¾Ðû²¼Ê±¼ä¡¿2021-06-09 18:50:00 GMT
¡¾¸ÅÊö¡¿
6 ÔÂ9ÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½Î¢ÈíÐû²¼6ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË50¸öÇå¾²Îó²î£¬ÆäÖаüÀ¨Ò»¸öWindows Print SpoolerȨÏÞÌáÉýÎó²î£¨CVE-2021-1675£©£¬´ËÎó²îΪAG¹«Ë¾¿Æ¼¼Ìì»úʵÑéÊÒÏò΢Èí±¨¸æ²¢»ñµÃ¹Ù·½ÖÂл¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. ºÚ¿ÍÏ®»÷Î÷°àÑÀÀͶ¯ºÍÉç»á¾¼Ã²¿
¡¾¸ÅÊö¡¿
Î÷°àÑÀÀͶ¯ºÍÉç»á¾¼Ã²¿£¨MITES£©ÖÜÈýÔâµ½ÍøÂç¹¥»÷£¬ÕýÔÚÆð¾¢»Ö¸´ÊÜÓ°ÏìµÄ·þÎñ¡£
MITES ÊÇÒ»¸ö²¿¼¶²¿·Ö£¬ÄêÔ¤Ëã½ü 3900 ÍòÅ·Ôª£¬ÈÏÕæÐе÷¼àÊÓÎ÷°àÑÀµÄ¾ÍÒµ¡¢Éç»á¾¼ÃºÍÆóÒµÉç»áÔðÈÎÕþ²ß¡£
¸Ã²¿Ëµ£º"ÀͶ¯ºÍÉç»á¾¼Ã²¿Êܵ½ÅÌËã»ú¹¥»÷µÄÓ°Ïì¡£ÎÒ²¿ºÍ¹ú¼ÒÃÜÂëѧÖÐÐĵÄÊÖÒÕ¹ÙÔ±ÕýÔÚÅäºÏÆð¾¢£¬ÒÔÈ·¶¨ÆðÔ´£¬²¢¾¡¿ì»Ö¸´Õý³£¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYKC
2. ÉñÃØ×Ô½ç˵¶ñÒâÈí¼þÍøÂçÊýÊ®ÒÚ±»µÁÊý¾Ýµã
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸ö1.2TBµÄ±»µÁÊý¾ÝÊý¾Ý¿â£¬¸ÃÊý¾Ý¿âÊÇÁ½ÄêÄÚ±»Ò»¸öδ֪µÄ×Ô½ç˵¶ñÒâÈí¼þ´Ó320Íǫ̀»ùÓÚWindowsµÄÅÌËã»úÖÐÈ¡³öµÄÊý¾Ý¡£Ëù°üÀ¨µÄÐÅÏ¢°üÀ¨ 660 Íò·ÝÎļþºÍ 2600 Íò·Ýƾ֤£¬ÒÔ¼° 20 ÒÚ¸ö Web µÇ¼ Cookie£¬ÆäÖÐ 4 ÒÚ¸öÔÚÊý¾Ý¿â·¢Ã÷ʱÈÔÈ»ÓÐÓá£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYKD
3. Exchange·þÎñÆ÷³ÉΪ "Epsilon Red "¶ñÒâÈí¼þµÄ¹¥»÷Ä¿µÄ
¡¾¸ÅÊö¡¿
×î½üµÄÑо¿Åú×¢£¬Íþв¹¥»÷ÕßʹÓÃÁËÒ»Ì×ÓÃ×÷¼ÓÃܵÄPowerShell¾ç±¾°²ÅÅÁËеÄÀÕË÷Èí¼þ£¬ËüʹÓÃδ´ò²¹¶¡µÄExchange·þÎñÆ÷µÄÎó²îÀ´¹¥»÷ÆóÒµÍøÂç¡£
SophosÊ×ϯÑо¿Ô±Andrew BrandtÔÚÍøÉϽÒÏþµÄÒ»·Ý±¨¸æÖÐдµÀ£¬Çå¾²¹«Ë¾SophosµÄÑо¿Ö°Ô±ÔÚÊÓ²ìÒ»¼Ò×ܲ¿ÉèÔÚÃÀ¹úµÄÂùÝÒµ¹«Ë¾µÄ¹¥»÷ʱ·¢Ã÷ÁËÕâÖÖеÄÀÕË÷Èí¼þ£¬²¢ÃüÃûΪEpsilon Red¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYKq
4. NCSC ÖÒÑÔÕë¶ÔѧУµÄÀÕË÷Èí¼þ¹¥»÷¼¤Ôö
¡¾¸ÅÊö¡¿
ÍþвÐÐΪÕß¼ÌÐøÍ¨¹ýʹÓÃÐéÄâרÓÃÍøÂ硢δÐÞ²¹Èí¼þºÍ×°±¸ÖеÄÎó²îÒÔ¼°Ê¹ÓÃÍøÂç´¹ÂÚµç×ÓÓʼþÀ´Õë¶Ô½ÌÓý²¿·ÖµÄ×éÖ¯¡£
ÏÖÔÚ»¹²»ÇåÎúÆù½ñÒѱ¨¸æÁ˼¸¶à°¸Àý£¬µ«2020Äê8ÔºͽñÄê2ÔÂÊ״η¢Ã÷Ï®»÷¼¤Ôö¡£×èÖ¹2021Äê5ÔÂβ/6Ô£¬NCSCÊӲ췢Ã÷Õë¶ÔÓ¢¹úѧУ¡¢Ñ§ÔººÍ´óѧµÄÀÕË÷Èí¼þ¹¥»÷µÄÓÖÒ»´ÎÔöÌí¡£
ÔÚNCSCÊӲ쵽µÄ´ó´ó¶¼ÇéÐÎÏ£¬ÕâЩ¹¥»÷µ¼ÖÂѧÉú¿ÎÒµºÍѧУ²ÆÎñ¼Í¼µÄɥʧ£¬ÒÔ¼°ÓëCOVID-19²âÊÔÓйصÄÊý¾Ý¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYKk
5. Siloscape£ºµÚÒ»¸öÒÑÖªµÄÕë¶ÔWindowsÈÝÆ÷Σº¦ÔÆÇéÐεĶñÒâÈí¼þ
¡¾¸ÅÊö¡¿
2021Äê3Ô£¬ÎÒ·¢Ã÷Á˵ÚÒ»¸öÒÑÖªµÄÕë¶ÔWindowsÈÝÆ÷µÄ¶ñÒâÈí¼þ£¬Ë¼Á¿µ½ÒÑÍù¼¸ÄêÔÆÅÌËãÓ¦Óõļ¤Ôö£¬ÕâÒ»Éú³¤²¢²»Ï£Ææ¡£ÎÒ½«¶ñÒâÈí¼þÃüÃûΪSiloscape£¨ÌýÆðÀ´Ïñsilo escape£©£¬ÓÉÓÚËüµÄÖ÷ҪĿµÄÊÇÌÓÀëÈÝÆ÷£¬¶øÔÚWindowsÖУ¬ÕâÖ÷ÒªÊÇÓÉ·þÎñÆ÷siloʵÏֵġ£
SiloscapeÊÇͨ¹ýWindowsÈÝÆ÷Õë¶ÔKubernetesȺ¼¯µÄÑÏÖØÄ£ºý¶ñÒâÈí¼þ¡£ËüµÄÖ÷ҪĿµÄÊÇ·¿ªÒ»¸öºóÃŽøÈëÉèÖò»Á¼µÄKubernetes¼¯Èº£¬ÒÔ±ãÔËÐжñÒâÈÝÆ÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYK9
6. ºÚ¿ÍɨÃèʹÓÃCVE-2021-21985 RCE¹¥»÷µÄVMware vCenter·þÎñÆ÷
¡¾¸ÅÊö¡¿
ºÚ¿ÍÕýÔÚÆð¾¢É¨Ã軥ÁªÍøÉ쵀 VMware vCenter ·þÎñÆ÷£¬ÕâЩ·þÎñÆ÷ÈÝÒ×Êܵ½ VMware ×î½üÐÞ¸´µÄÒªº¦ RCE ȱÏݵÄÓ°Ïì¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYJW
7. ¹È¸èÉϵÄAnyDesk¹ã¸æÎªÓû§Ìṩ¶ñÒâµÄÓ¦ÓÃ
¡¾¸ÅÊö¡¿
ÖøÃûµÄÔ¶³Ì×ÀÃæÓ¦ÓóÌÐòAnyDeskÔڹȸèËÑË÷Ч¹ûÖÐµÄ¹ã¸æÖÐÌṩÁ˸óÌÐòµÄÒ»¸ö¶ñÒâ°æ±¾¡£¸Ã¶ñÒâ°æ±¾µÄËÑË÷ÅÅÃûÉõÖÁÁè¼ÝÁËÕýµ±µÄAnyDeskÔڹȸèÉÏµÄ¹ã¸æÅÅÃû¡£
¸Ã¹¥»÷Ô˶¯×Ô4ÔÂ22ÈÕÒÔÀ´¾ÍÒ»Ö±ºÜ·Å×Ý£¬ÖµµÃ×¢ÖØµÄÊÇ£¬ÍÆËͶñÒâ¹ã¸æµÄ·¸·¨·Ö×Ó»áÏë·¨±Ü¿ª¹È¸èµÄ·´¶ñÒâ¹ã¸æÉ¸Ñ¡¼à¿Ø¡£Òò´Ë£¬CrowdstrikeµÄÑо¿Ö°Ô±Ô¤¼Æ£¬ÓÐ40%µÄµã»÷¹ã¸æµÄÓû§ÒѾװÖÃÁ˶ñÒâÈí¼þ¡£Æ¾Ö¤ÖÜÈý½ÒÏþµÄÒ»·Ý¹ØÓÚ¸ÃÊÂÎñµÄ±¨¸æ£¬ÆäÖÐÓÐ20%µÄÊܺ¦Õß¿ÉÒÔʹµÃ·¸·¨·Ö×Ó¶Ô²Ù×÷ϵͳ¾ÙÐкóÐøµÄ²Ù×÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYJY
8. ÓëÖйúÓйصĹ¥»÷ÕßʹÓÃPulse Secure 0 dayÇå¾²Îó²îÈëÇÖÁ˴󶼻ύͨÖÎÀí¾Ö£¨MTA£©
¡¾¸ÅÊö¡¿
ÓëÖйúÏà¹ØµÄÍþвÐÐΪÕßʹÓÃÂö³åÇå¾²ÁãÈÕÈëÇÖÁËŦԼÊд󶼻ύͨÖÎÀí¾Ö £¨MTA£© ÍøÂç¡£ÈëÇÖ±¬·¢ÔÚ4Ô£¬µ«Ï®»÷ÕßûÓÐÔì³ÉÈκÎË𺦣¬ÓÉÓÚËûÃÇÎÞ·¨½øÈëMTAÁгµ¿ØÖÆÏµÍ³¡£ÖÎÀí¾ÖÔÚPulse SecureºÍÃÀ¹úCISAÓÚ4ÔÂÐû²¼Í¨¸æ£¬ÖÒÑÔÔÚÒ°ÍâÆð¾¢Ê¹ÓÃÕâһȱÏݵĵڶþÌì¾Í½â¾öÁËÕâ¸öÎÊÌâ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYJV
9. Ó¢ÌØ¶ûÔÚCPU¡¢À¶ÑÀºÍÇ徲ϵͳÖвåÈë29¸ö²¹¶¡
¡¾¸ÅÊö¡¿
Ó¢ÌØ¶ûÐû²¼ÁË 29 ÌõÇå¾²½¨Ò飬ÒÔ¹£ÈûÓ¢ÌØ¶û´¦Öóͷ£Æ÷µÄ BIOS ¹Ì¼þÒÔ¼°À¶ÑÀ²úÆ·¡¢×Ô¶¯ÖÎÀíÊÖÒÕ¹¤¾ß¡¢NUCÃÔÄã PC ϵÁÐÒÔ¼°¾ßÓм¥Ð¦ÒâζµÄÊÇ£¬ÔÚÆä×Ô¼ºµÄÇå¾²¿âÖеÄһЩÑÏÖØ¹ýʧ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYKE
10. ¹È¸èÐÞ²¹ÁËAndroid RCEµÄÒªº¦Îó²î
¡¾¸ÅÊö¡¿
¹È¸è6Ô·ÝÐû²¼µÄÇ徲ͨ¸æ½â¾öÁËAndroidºÍÏñËØ×°±¸ÖÐ90¶à¸öÎó²î¡£
¹È¸èÐÞ²¹ÁËÓ°ÏìÏñËØ×°±¸ºÍµÚÈý·½°²×¿ÊÖ»úµÄ°²×¿²Ù×÷ϵͳÖеÄ90¶à¸öÇå¾²Îó²î£¬ÆäÖаüÀ¨Ò»¸öÒªº¦µÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬¸ÃÎó²î¿ÉÈù¥»÷Õß¹¥¿ËÄ¿µÄÒ×Êܹ¥»÷µÄÒÆ¶¯×°±¸¡£
¹È¸è6ÔÂÐû²¼µÄÇ徲ͨ¸æ³Æ£¬¸ÃÎó²î£¨CVE-2021-0507£©±£´æÓÚAndroid²Ù×÷ϵͳµÄϵͳ×é¼þÖУ¬¿ÉÄÜʹԶ³Ì¹¥»÷ÕßÄܹ»Ê¹ÓÃÌØÖÆµÄ´«ÊäÔÚÌØÈ¨Àú³ÌµÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¸Ã¹«Ë¾ÌåÏÖ£¬ÕâÊǽñÄê6ÔÂÆù½ñΪֹÐÞ²¹¹ýµÄÎó²îÖÐ×îÑÏÖØµÄÒ»¸ö¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYKl

AG¹«Ë¾ÔÆ







