ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ47ÖÜ
°ä²¼¹¦·ò 2021-11-22>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
±¾Öܹ²ÊÕ¼°²È«·ì϶67¸ö£¬£¬ÖµµÃ¹Ø×¢µÄÊÇAdvantech WebAccess HMI Designer CVE-2021-33000ÏîÄ¿Îļþ¶ÑÒç³ö·ì϶£»£»Google Chrome mediaÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶£»£»Lantronix PremierWave 2050 CVE-2021-21888ºÅÁî×¢Èë·ì϶£»£»Adobe Media Encoder M4A»º³åÇøÒç³ö·ì϶£»£»Apache ShenYuδÊÚȨ½Ó¼û·ì϶¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇFBIÓʼþϵͳÔâµ½ÈëÇÖ·¢ËÍÊýÊ®ÍòÌõÐéαµÄ¹¥»÷¾¯±¨£»£»ÍøÐŰì°ä²¼¡¶ÍøÂçÊý¾Ý°²È«ÖÎÀíÌõÀý£¨Õ÷Ç󶨼û¸å£©¡·£»£»Facebook·¢ÏÖSideCopyαÔìAndroidÀûÓÃÉ̵êµÄ¹¥»÷£»£»Google°ä²¼11Ô¸üУ¬£¬ÐÞ¸´ChromeÖеĶà¸ö·ì϶£»£»Cloudflare°ä·¢ÆäÕмÜÁ˸ߴï2 TbpsµÄDDoS¹¥»÷¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£
>ÖØÒª°²È«·ì϶Áбí
1. Advantech WebAccess HMI Designer CVE-2021-33000ÏîÄ¿Îļþ¶ÑÒç³ö·ì϶
Advantech WebAccess HMI DesignerÏîÄ¿Îļþ´¦ÖôæÔÚ¶ÑÒç³ö·ì϶£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬ÓÕʹÓû§½âÎö£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»òÄܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£
https://us-cert.cisa.gov/ics/advisories/icsa-21-173-01
2. Google Chrome mediaÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶
Google Chrome media´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒ³ÒªÇ󣬣¬ÓÕʹÓû§½âÎö£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»òÄܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£
https://chromereleases.googleblog.com/2021/11/stable-channel-update-for-desktop.html
3. Lantronix PremierWave 2050 CVE-2021-21888ºÅÁî×¢Èë·ì϶
Lantronix PremierWave 2050´¦ÖÃHTTPÒªÇóÑéÖ¤´æÔÚ°²È«·ì϶£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£
https://talosintelligence.com/vulnerability_reports/TALOS-2021-1332
4. Adobe Media Encoder M4A»º³åÇøÒç³ö·ì϶
Adobe Media Encoder M4A´æÔÚ»º³åÇøÒç³ö·ì϶£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬ÓÕʹÓû§½âÎö£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£
https://helpx.adobe.com/security/products/media-encoder/apsb21-70.html
5. Apache ShenYuδÊÚȨ½Ó¼û·ì϶
Apache ShenYu Admin ShenyuAdminBootstrap´æÔÚ°²È«·ì϶£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬¿ÉÈÆ¹ý°²È«ÏÞ¶ÈδÊÚȨ½Ó¼û¡£¡£¡£
https://lists.apache.org/thread/o15j25qwtpcw62k48xw1tnv48skh3zgb
>ÖØÒª°²È«ÊÂÎñ×ÛÊö
1¡¢¡¢¡¢FBIÓʼþϵͳÔâµ½ÈëÇÖ·¢ËÍÊýÊ®ÍòÌõÐéαµÄ¹¥»÷¾¯±¨
FBIÓʼþϵͳÔÚ11ÔÂ13ÈÕÔâµ½ÈëÇÖ£¬£¬±»ÓÃÀ´·¢ËÍÊýÊ®ÍòÌõÐéαµÄ¹¥»÷¾¯±¨¡£¡£¡£ÕâЩÓʼþ¼ÙÒâºÓɽ°²È«Êý (DHS)£¬£¬Ðû³ÆÊÕ¼þÈËÔâµ½ÁËÀ´×ÔVinny TroiaµÄÁ´Ê½¹¥»÷¡£¡£¡£µ«´ËÈËÊǰ²È«¹«Ë¾NightLionºÍShadowbyteµÄÕÆ¹ÜÈË£¬£¬×êÑÐÈËÔ±´§¶ÈÕâ´Î»î¶¯Ö¼Ôڷ̰ù°²È«ÈËÔ±Troia¡£¡£¡£Spamhaus¹«Ë¾°µÊ¾£¬£¬ÕâЩÓʼþ¶¼À´×ÔFBI·¨ÂÉÆóÒµÃÅ»§£¨LEEP£©µÄºÏ·¨µØÖ·eims@ic.fbi.gov£¬£¬IPµØÖ·Îª153.31.119.142(mx-east-ic.fbi.gov)¡£¡£¡£FBI³ÆÓÉÓÚÈí¼þ°´ÅäÖÃÃýÎ󣬣¬Ê¹µÃ¹¥»÷ÕßÄܹ»ÀûÓÃLEEP·¢ËÍαÔìµÄÓʼþ¡£¡£¡£
ÔÎÄÁ´½Ó£º£º
https://securityaffairs.co/wordpress/124570/cyber-crime/fbi-hacked-email-server.html
2¡¢¡¢¡¢ÍøÐŰì°ä²¼¡¶ÍøÂçÊý¾Ý°²È«ÖÎÀíÌõÀý£¨Õ÷Ç󶨼û¸å£©¡·
¹ú¶ÈÍøÐŰìÓÚ11ÔÂ14ÈÕ°ä²¼ÁË¡¶ÍøÂçÊý¾Ý°²È«ÖÎÀíÌõÀý£¨Õ÷Ç󶨼û¸å£©¡·µÄ¹«¿ªÕ÷Ç󶨼û֪ͨ¡£¡£¡£½ØÖÁ½ñÄê6Ô£¬£¬ÎÒ¹úÍøÃñ¹æÄ£´ï10.11ÒÚ£¬£¬Óɴ˲úÉúµÄÍøÂçÊý¾ÝÁ¿¸üÊÇÌìÎÄÊý×Ö¡£¡£¡£¸ÃÌõÀý¹æ·¶ÍøÂçÊý¾Ý´¦Öû£¬£¬±£»£»¤Ð¡ÎÒ¡¢¡¢¡¢×éÖ¯ÔÚÍøÂç¿Õ¼äµÄºÏ·¨È¨Àû£¬£¬ÊØ»¤¹ú¶È°²È«ºÍ¹«¹²ÀûÒæ¡£¡£¡£Öйú»¥ÁªÍøÐ»á·¨¹¤Î¯¸±ÃØÊ鳤ºú¸ÖÖ¸³ö£¬£¬ÕâÊÇÐÂʱÆÚ¹æ·¶»¥ÁªÍøÆ½Ì¨ÆóÒµ£¬£¬Ç¿»¯·´Â¢¶ÏºÍ±¾Ç®ÎÞÐòÀ©ÕŵÄÓ¦ÓÐÖ®Ò壬£¬Ò²ÊÇÊØ»¤¹ú¶È°²È«¡¢¡¢¡¢±£»£»¤Éç»á¹«¹²ÀûÒæµÄ±ØÒª¡£¡£¡£
ÔÎÄÁ´½Ó£º£º
http://www.cac.gov.cn/2021-11/14/c_1638501991577898.htm
3¡¢¡¢¡¢Facebook·¢ÏÖSideCopyαÔìAndroidÀûÓÃÉ̵êµÄ¹¥»÷
FacebookµÄ°²È«ÍŶÓÔÚ11ÔÂ16ÈÕÅû¶Á˰ͻù˹̹ºÚ¿ÍÍÅ»ïSideCopyÐÂÒ»ÂֵĴ¹µö»î¶¯¡£¡£¡£Õâ´Î»î¶¯ÔÚ½ñÄê4ÔÂÖÁ8ÔÂÖ®¼ä£¬£¬³ÉÁ¢²¢ÔËÓªÁËÒ»¸öαÔìµÄAndroidÀûÓÃÉ̵ꡣ¡£¡£¹¥»÷ÕßÖØÒªÍ¨³£»£»á¼ÙÒâÄêÇáÅ®ÐÔÀ´¿¿½üÖ¸±ê£¬£¬ÓÕʹÆä´ò¿ªÓÃÀ´ÓÃÀ´ÍøÂçÐÅÏ¢µÄ´¹µöÍøÕ¾»òÕßαÔìµÄAndroidÀûÓÃÉ̵ꡣ¡£¡£¶øºóͨ¹ý¼Ù×°³É̸ÌìÀûÓõĶñÒâÈí¼þ£¬£¬·Ö·¢PJobRATºÍMayhemµÈ¡£¡£¡£
ÔÎÄÁ´½Ó£º£º
https://therecord.media/pakistani-hackers-operated-a-fake-app-store-to-target-former-afghan-officials/
4¡¢¡¢¡¢Google°ä²¼11Ô¸üУ¬£¬ÐÞ¸´ChromeÖеĶà¸ö·ì϶
11ÔÂ16ÈÕ£¬£¬Google°ä²¼Á˱¾ÔÂChromeµÄ°²È«¸üУ¬£¬×ܼÆÐÞ¸´ÁË25¸ö·ì϶¡£¡£¡£ÆäÖУ¬£¬½ÏΪÑÏÖØµÄÊÇÔÚýÌåÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2021-38008£©¡¢¡¢¡¢V8ÖеÄÀàÐÍ»ìºÏ·ì϶£¨CVE-2021-38007£©ºÍ¼ÓÔØÆ÷ÖпªÊͺóʹÓ÷ì϶£¨CVE-2021-38005£©µÈ¡£¡£¡£´ËÍ⣬£¬»¹ÐÞ¸´ÁËÖ¸ÎÆ¼ø±ðÖеĶѻº³åÇøÒç³ö·ì϶£¨CVE-2021-38013£©ºÍSwiftshaderÖеÄÔ½½çдÈ루CVE-2021-38014£©µÈ·ì϶¡£¡£¡£
ÔÎÄÁ´½Ó£º£º
https://chromereleases.googleblog.com/2021/11/stable-channel-update-for-desktop.html
5¡¢¡¢¡¢Cloudflare°ä·¢ÆäÕмÜÁ˸ߴï2 TbpsµÄDDoS¹¥»÷
ÃÀ¹úÍøÂ簲ȫ¹«Ë¾CloudflareÔÚ11ÔÂ15ÈÕ°ä·¢ÆäÕмÜÁËÆù½ñΪֹÓöµ½µÄ×î´ó¹¥»÷DDoS¹¥»÷£¬£¬·åÖµÂÔµÍÓÚ2 Tbps¡£¡£¡£Õâ´Î¹¥»÷»î¶¯ÊǽáºÏÁËDNS·Å´ó¹¥»÷ºÍUDP·ººéµÄ¶àÏòÁ¿¹¥»÷£¬£¬Õû¸ö¹ý³ÌÖ»³ÖÐøÁËÒ»·ÖÖÓ£¬£¬À´×ÔÔ¼15000¸ö»úеÈË×é³ÉµÄ½©Ê¬ÍøÂçMirai±äÖÖ¡£¡£¡£Cloudflare»ã±¨³ÆµÚÈý¼¾¶ÈÍøÂç²ãDDoS¹¥»÷»î¶¯±ÈÉÏÒ»¼¾¶ÈÔö³¤ÁË44%£¬£¬¸Ã¹«Ë¾ÔÚ8ÔÂÕмÜÁËÿÃë1720Íò´ÎÒªÇóµÄDDoS¹¥»÷£¬£¬Î¢ÈíÔÚ10ÔÂ³ÆÆäÔÆ·þÎñAzureÕмÜÁË2.4 TbpsµÄDDoS¹¥»÷¡£¡£¡£
ÔÎÄÁ´½Ó£º£º
https://securityaffairs.co/wordpress/124634/security/cloudflare-mitigated-ddos-2-tbps.html


¾©¹«Íø°²±¸11010802024551ºÅ