ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ36ÖÜ

Ðû²¼Ê±¼ä 2021-09-06

>±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö

2021Äê08ÔÂ30ÈÕÖÁ09ÔÂ05ÈÕ¹²ÊÕ¼Çå¾²Îó²î62¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇAruba Networks ArubaOS OS CVE-2021-37716 PAPIЭÒ黺³åÇøÒç³öÎó²î £»Google Chrome BlinkÄÚ´æ¹ýʧ´úÂëÖ´ÐÐÎó²î £»Nature Easy Soft Network Technology ZenTaoÏÂÁîÖ´ÐÐÎó²î £»ZOHO ManageEngine ADSelfService Plus OSÏÂÁî×¢ÈëÎó²î £»Advantech WebAccess CVE-2021-38408»º³åÇø¹ýʧÎó²î ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇMicrosoftÐû²¼½üÆÚÖ¼ÔÚÇÔȡƾ֤µÄ´¹ÂÚÔ˶¯µÄ¾¯±¨ £»NFIB³Æ2021ÄêH1Ó¢¹úÒòÍøÂç·¸·¨Ëðʧ¸ß´ï13ÒÚÓ¢°÷ £»CNNICÐû²¼µÚ48´Î¡¶Öйú»¥ÁªÍøÂçÉú³¤×´Ì¬Í³¼Æ±¨¸æ¡· £»ÒòGoogleÓ¦ÓÃbug £¬²¿·Ö°²×¿Óû§ÎÞ·¨²¦´òºÍ½ÓÌýµç»° £»Ñо¿Ö°Ô±³Æ16¸öÀ¶ÑÀÎó²îBrakToothÓ°ÏìÊýÊ®ÒÚ×°±¸ ¡£


ƾ֤ÒÔÉÏ×ÛÊö £¬±¾ÖÜÇå¾²ÍþвΪÖÐ ¡£


>Ö÷ÒªÇå¾²Îó²îÁбí


1.Aruba Networks ArubaOS OS CVE-2021-37716 PAPIЭÒ黺³åÇøÒç³öÎó²î


Aruba Networks ArubaOS OS PAPIЭÒé±£´æ»º³åÇøÒç³öÎó²î £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬¿ÉʹӦÓóÌÐò±ÀÀ £»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë ¡£


https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2021-016.txt



2.Google Chrome BlinkÄÚ´æ¹ýʧ´úÂëÖ´ÐÐÎó²î


Google Chrome Blink±£´æÊͷźóʹÓÃÎó²î £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇó £¬ÓÕʹÓû§ÆÊÎö £¬¿ÉʹӦÓóÌÐò±ÀÀ £»ò¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë ¡£


https://chromereleases.googleblog.com/2021/08/stable-channel-update-for-desktop_31.html


3.Nature Easy Soft Network Technology ZenTaoÏÂÁîÖ´ÐÐÎó²î


Nature Easy Soft Network Technology ZenTao Cron job Ñ¡Ï±£´æÊäÈëÑéÖ¤Îó²î £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë ¡£


https://privasec.com/blog/zentao-cms-a-monkeys-journey-to-priv-esc-remote-code-execution/


4.ZOHO ManageEngine ADSelfService Plus OSÏÂÁî×¢ÈëÎó²î


ZOHO ManageEngine ADSelfService Plus±£´æÊäÈëÑéÖ¤Îó²î £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâÏÂÁî ¡£


https://blog.stmcyber.com/vulns/cve-2021-33055/


5.Advantech WebAccess CVE-2021-38408»º³åÇø¹ýʧÎó²î


Advantech WebAccess±£´æ»º³åÇøÒç³öÎó²î £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬¿ÉʹӦÓóÌÐò±ÀÀ £»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë ¡£


https://www.advantech.com/support/details/installation?id=1-MS9MJV


>Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢MicrosoftÐû²¼½üÆÚÖ¼ÔÚÇÔȡƾ֤µÄ´¹ÂÚÔ˶¯µÄ¾¯±¨


Microsoft 365 DefenderÍþвÇ鱨ÍŶÓÔÚ8ÔÂ26ÈÕÐû²¼½üÆÚÖ¼ÔÚÇÔȡƾ֤µÄ´¹ÂÚÔ˶¯µÄ¾¯±¨ ¡£Ñо¿Ö°Ô±³Æ £¬¸ÃÔ˶¯Ê¹Óõç×ÓÓʼþͨѶÖеĿª·ÅÖØ¶¨ÏòÁ´½Ó×÷ÎªÔØÌå £¬ÓÕʹÓû§»á¼û¶ñÒâÍøÕ¾ £¬Í¬Ê±ÈƹýÇå¾²¼ì²âÈí¼þ ¡£Î¢ÈíÌåÏÖËüÒѾ­·¢Ã÷ÁËÖÁÉÙ350¸öÍøÂç´¹ÂÚURL £¬²¢ÇÒËüÃǾùʹÓÃÁËÁîÈËÐÅ·þµÄÓÕ¶üºÍÈ«ÐÄÉè¼ÆµÄ¼ì²âÈÆ¹ýÊÖÒÕ ¡£Õâ²»µ«ÏÔʾÁ˴˴ι¥»÷µÄ¹æÄ£ £¬»¹Åú×¢Îú¹¥»÷ÕßÖØ´óµÄͶÈë ¡£


MicrosoftÐû²¼½üÆÚÖ¼ÔÚÇÔȡƾ֤µÄ´¹ÂÚÔ˶¯µÄ¾¯±¨.jpg


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/08/microsoft-warns-of-widespread-phishing.html



2¡¢NFIB³Æ2021ÄêH1Ó¢¹úÒòÍøÂç·¸·¨Ëðʧ¸ß´ï13ÒÚÓ¢°÷


ÍøÂç·¸·¨.png


À´×ÔÓ¢¹ú¹ú¼ÒڲƭÇ鱨¾Ö(NFIB)µÄÊý¾ÝÅú×¢ £¬2021ÄêH1Ó¢¹úÒòÍøÂç·¸·¨Ëðʧ¸ß´ï13ÒÚÓ¢°÷ ¡£Ð¡ÎÒ˽¼ÒºÍ×éÖ¯ÔÚ½ñÄêÉϰëÄêÒòÍøÂç·¸·¨ºÍڲƭ¶øËðʧµÄ×ʽðÊÇ2020ÉϰëÄ꣨4.147ÒÚÓ¢°÷£©µÄÈý±¶ ¡£2020ÄêH1Ö»ÓÐ39160°¸¼þ £¬¶ø2021ÄêH1¶à´ï289437Æð ¡£Ñо¿Ö°Ô±³Æ £¬Õþ¸®Ó¦½ÓÄɸü¶à²½·¥À´½ÌÓýСÎÒ˽¼ÒÓйØÍøÂç´¹ÂÚµÄΣº¦ºÍÍøÂçÇå¾²µÄÖ÷ÒªÐÔ £¬¶ø×éÖ¯Ó¦¸ÃÆð¾¢½µµÍÔ¶³ÌÊÂÇéµÄΣº¦ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/cybercrime-losses-triple-to-13bn/



3¡¢CNNICÐû²¼µÚ48´Î¡¶Öйú»¥ÁªÍøÂçÉú³¤×´Ì¬Í³¼Æ±¨¸æ¡·


CNNICÐû²¼µÚ48´Î¡¶Öйú»¥ÁªÍøÂçÉú³¤×´Ì¬Í³¼Æ±¨¸æ¡·.jpg


Öйú»¥ÁªÍøÂçÐÅÏ¢ÖÐÐÄ£¨CNNIC£©ÓÚ8ÔÂ27ÈÕÔÚ¾©Ðû²¼µÚ48´Î¡¶Öйú»¥ÁªÍøÂçÉú³¤×´Ì¬Í³¼Æ±¨¸æ¡· ¡£±¨¸æÏÔʾ £¬×èÖ¹½ñÄê6Ô £¬ÖйúÍøÃñ¹æÄ£´ï10.11ÒÚ £¬½Ï2020Äê12ÔÂÔöÌí2175Íò £¬»¥ÁªÍøÆÕ¼°ÂÊ´ï71.6% £»»¥ÁªÍø»ù´¡×ÊÔ´¼ÓËÙ½¨Éè £¬×èÖ¹6Ô £¬ÖйúIPv6µØµãÊýÄ¿´ï62023¿é/32 £»ÖйúÅ©´åÍøÃñ¹æÄ£Îª2.97ÒÚ £¬Å©´åµØÇø»¥ÁªÍøÆÕ¼°ÂÊΪ59.2% £¬½Ï2020Äê12Ô £¬³ÇÏ绥ÁªÍøÆÕ¼°Âʲî±ðËõС4.8% ¡£


Ô­ÎÄÁ´½Ó£º

http://finance.people.com.cn/n1/2021/0828/c1004-32210949.html



4¡¢ÒòGoogleÓ¦ÓÃbug £¬²¿·Ö°²×¿Óû§ÎÞ·¨²¦´òºÍ½ÓÌýµç»°


ÒòGoogleÓ¦ÓÃbug£¬²¿·Ö°²×¿Óû§ÎÞ·¨²¦´òºÍ½ÓÌýµç»°.jpg


GoogleÌåÏÖ £¬²¿·ÖAndroidÊÖ»úÐͺŵÄÓû§Êܵ½GoogleÓ¦ÓÃÖÐbugµÄÓ°Ïì £¬ÎÞ·¨²¦´òºÍ½ÓÌýµç»° ¡£ÏÖÔÚGoogleûÓйûÕæÊÜÓ°ÏìÊÖ»úµÄÐͺÅ £¬µ«±¾ÖÜÄ©ÊÜÓ°ÏìÓû§Ìáµ½ÁËLGµÄ×°±¸ £¬ÈçLG G7¡¢LG G7 ThinQ¡¢LG V40 ThinQºÍLG Q70µÈ ¡£Google³ÆÆäÕýÔÚÊÓ²ì´ËÊ £¬²¢ÒÑÐû²¼ÁË×îиüÐÂÀ´ÐÞ¸´¸Ãbug £¬½¨ÒéÓû§ÊÖ¶¯×°ÖÃ×îиüР¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/google/google-app-bug-blocks-android-users-from-receiving-making-calls/


5¡¢Ñо¿Ö°Ô±³Æ16¸öÀ¶ÑÀÎó²îBrakToothÓ°ÏìÊýÊ®ÒÚ×°±¸


Ñо¿Ö°Ô±³Æ16¸öÀ¶ÑÀÎó²îBrakToothÓ°ÏìÊýÊ®ÒÚ×°±¸.jpg


Ñо¿Ö°Ô±¼ì²âÁËÀ´×Ô11¸ö¹©Ó¦É̵Ä13¸öƬÉÏϵͳ (SoC) µÄÀ¶ÑÀÈí¼þ¿â £¬·¢Ã÷ÁË16¸öÓ°ÏìÀ¶ÑÀÈí¼þ¿ÍÕ»µÄÎó²î²¢Í³³ÆËüÃÇΪBrakTooth ¡£¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îʹװ±¸Í߽⠣¬ÉõÖÁÊÇÖ´ÐжñÒâ´úÂë²¢½ÓÊÜÕû¸öϵͳ ¡£ÕâЩÎó²îÖÐ×îÑÏÖØµÄΪCVE-2021-28139 £¬Ê¹ÓøÃÎó²îÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýÀ¶ÑÀLMPÊý¾Ý°üÔÚÄ¿µÄ×°±¸ÉÏÔËÐжñÒâ´úÂë ¡£²¢·ÇËùÓÐËùÓй©Ó¦É̶¼ÊµÊ±Ðû²¼Á˲¹¶¡ £¬µ½ÏÖÔÚΪֹ £¬Ö»ÓÐÀÖöΡ¢Ó¢·ÉÁèºÍBluetrumÐû²¼Á˲¹¶¡ £¬¶øµÂÖÝÒÇÆ÷ÔòÌåÏ־ܾøÐÞ¸´Îó²î ¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/billions-of-devices-impacted-by-new-braktooth-bluetooth-vulnerabilities