ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ47ÖÜ
Ðû²¼Ê±¼ä 2021-11-22>±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
±¾Öܹ²ÊÕ¼Çå¾²Îó²î67¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇAdvantech WebAccess HMI Designer CVE-2021-33000ÏîÄ¿Îļþ¶ÑÒç³öÎó²î£»£»£»£»£»£»Google Chrome mediaÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î£»£»£»£»£»£»Lantronix PremierWave 2050 CVE-2021-21888ÏÂÁî×¢ÈëÎó²î£»£»£»£»£»£»Adobe Media Encoder M4A»º³åÇøÒç³öÎó²î£»£»£»£»£»£»Apache ShenYuδÊÚȨ»á¼ûÎó²î¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇFBIÓʼþϵͳÔâµ½ÈëÇÖ·¢ËÍÊýÊ®ÍòÌõÐéαµÄ¹¥»÷¾¯±¨£»£»£»£»£»£»ÍøÐŰìÐû²¼¡¶ÍøÂçÊý¾ÝÇå¾²ÖÎÀíÌõÀý£¨Õ÷ÇóÒâ¼û¸å£©¡·£»£»£»£»£»£»Facebook·¢Ã÷SideCopyαÔìAndroidÓ¦ÓÃÊÐËÁµÄ¹¥»÷£»£»£»£»£»£»GoogleÐû²¼11Ô¸üУ¬£¬£¬£¬£¬ÐÞ¸´ChromeÖеĶà¸öÎó²î£»£»£»£»£»£»CloudflareÐû²¼ÆäµÖÓùÁ˸ߴï2 TbpsµÄDDoS¹¥»÷¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£
>Ö÷ÒªÇå¾²Îó²îÁбí
1. Advantech WebAccess HMI Designer CVE-2021-33000ÏîÄ¿Îļþ¶ÑÒç³öÎó²î
Advantech WebAccess HMI DesignerÏîÄ¿Îļþ´¦Öóͷ£±£´æ¶ÑÒç³öÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£»£»ò¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://us-cert.cisa.gov/ics/advisories/icsa-21-173-01
2. Google Chrome mediaÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î
Google Chrome media±£´æÊͷźóʹÓÃÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÒ³ÇëÇ󣬣¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£»£»ò¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://chromereleases.googleblog.com/2021/11/stable-channel-update-for-desktop.html
3. Lantronix PremierWave 2050 CVE-2021-21888ÏÂÁî×¢ÈëÎó²î
Lantronix PremierWave 2050´¦Öóͷ£HTTPÇëÇóÑéÖ¤±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£
https://talosintelligence.com/vulnerability_reports/TALOS-2021-1332
4. Adobe Media Encoder M4A»º³åÇøÒç³öÎó²î
Adobe Media Encoder M4A±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://helpx.adobe.com/security/products/media-encoder/apsb21-70.html
5. Apache ShenYuδÊÚȨ»á¼ûÎó²î
Apache ShenYu Admin ShenyuAdminBootstrap±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉÈÆ¹ýÇå¾²ÏÞÖÆÎ´ÊÚȨ»á¼û¡£¡£¡£¡£
https://lists.apache.org/thread/o15j25qwtpcw62k48xw1tnv48skh3zgb
>Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢FBIÓʼþϵͳÔâµ½ÈëÇÖ·¢ËÍÊýÊ®ÍòÌõÐéαµÄ¹¥»÷¾¯±¨
FBIÓʼþϵͳÔÚ11ÔÂ13ÈÕÔâµ½ÈëÇÖ£¬£¬£¬£¬£¬±»ÓÃÀ´·¢ËÍÊýÊ®ÍòÌõÐéαµÄ¹¥»÷¾¯±¨¡£¡£¡£¡£ÕâЩÓʼþð³äÁìÍÁÇå¾²²¿ (DHS)£¬£¬£¬£¬£¬Éù³ÆÊÕ¼þÈËÔâµ½ÁËÀ´×ÔVinny TroiaµÄÁ´Ê½¹¥»÷¡£¡£¡£¡£µ«´ËÈËÊÇÇå¾²¹«Ë¾NightLionºÍShadowbyteµÄÈÏÕæÈË£¬£¬£¬£¬£¬Ñо¿Ö°Ô±Íƶϴ˴ÎÔ˶¯Ö¼ÔÚÚ®»ÙÇå¾²Ö°Ô±Troia¡£¡£¡£¡£Spamhaus¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬ÕâЩÓʼþ¶¼À´×ÔFBIÖ´·¨ÆóÒµÃÅ»§£¨LEEP£©µÄÕýÍâµØµãeims@ic.fbi.gov£¬£¬£¬£¬£¬IPµØµãΪ153.31.119.142(mx-east-ic.fbi.gov)¡£¡£¡£¡£FBI³ÆÓÉÓÚÈí¼þ°´ÉèÖùýʧ£¬£¬£¬£¬£¬Ê¹µÃ¹¥»÷Õß¿ÉÒÔʹÓÃLEEP·¢ËÍαÔìµÄÓʼþ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/124570/cyber-crime/fbi-hacked-email-server.html
2¡¢ÍøÐŰìÐû²¼¡¶ÍøÂçÊý¾ÝÇå¾²ÖÎÀíÌõÀý£¨Õ÷ÇóÒâ¼û¸å£©¡·
¹ú¼ÒÍøÐŰìÓÚ11ÔÂ14ÈÕÐû²¼ÁË¡¶ÍøÂçÊý¾ÝÇå¾²ÖÎÀíÌõÀý£¨Õ÷ÇóÒâ¼û¸å£©¡·µÄ¹ûÕæÕ÷ÇóÒâ¼û֪ͨ¡£¡£¡£¡£×èÖ¹½ñÄê6Ô£¬£¬£¬£¬£¬ÎÒ¹úÍøÃñ¹æÄ£´ï10.11ÒÚ£¬£¬£¬£¬£¬Óɴ˱¬·¢µÄÍøÂçÊý¾ÝÁ¿¸üÊÇÌìÎÄÊý×Ö¡£¡£¡£¡£¸ÃÌõÀý¹æ·¶ÍøÂçÊý¾Ý´¦Öóͷ£Ô˶¯£¬£¬£¬£¬£¬±£»£»£»£»£»£»¤Ð¡ÎÒ˽¼Ò¡¢×éÖ¯ÔÚÍøÂç¿Õ¼äµÄÕýµ±È¨Ò棬£¬£¬£¬£¬Î¬»¤¹ú¼ÒÇå¾²ºÍ¹«¹²ÀûÒæ¡£¡£¡£¡£Öйú»¥ÁªÍøÐ»á·¨¹¤Î¯¸±ÃØÊ鳤ºú¸ÖÖ¸³ö£¬£¬£¬£¬£¬ÕâÊÇÐÂʱ´ú¹æ·¶»¥ÁªÍøÆ½Ì¨ÆóÒµ£¬£¬£¬£¬£¬Ç¿»¯·´Â¢¶ÏºÍ×ÊÔ´ÎÞÐòÀ©ÕŵÄÓ¦ÓÐÖ®Ò壬£¬£¬£¬£¬Ò²ÊÇά»¤¹ú¼ÒÇå¾²¡¢±£»£»£»£»£»£»¤Éç»á¹«¹²ÀûÒæµÄÐèÒª¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
http://www.cac.gov.cn/2021-11/14/c_1638501991577898.htm
3¡¢Facebook·¢Ã÷SideCopyαÔìAndroidÓ¦ÓÃÊÐËÁµÄ¹¥»÷
FacebookµÄÇå¾²ÍŶÓÔÚ11ÔÂ16ÈÕÅû¶Á˰ͻù˹̹ºÚ¿ÍÍÅ»ïSideCopyÐÂÒ»ÂֵĴ¹ÂÚÔ˶¯¡£¡£¡£¡£´Ë´ÎÔ˶¯ÔÚ½ñÄê4ÔÂÖÁ8ÔÂÖ®¼ä£¬£¬£¬£¬£¬½¨Éè²¢ÔËÓªÁËÒ»¸öαÔìµÄAndroidÓ¦ÓÃÊÐËÁ¡£¡£¡£¡£¹¥»÷ÕßÖ÷Ҫͨ³£»£»£»£»£»£»áð³äÄêÇáÅ®ÐÔÀ´¿¿½üÄ¿µÄ£¬£¬£¬£¬£¬ÓÕʹÆä·¿ªÓÃÀ´ÓÃÀ´ÍøÂçÐÅÏ¢µÄ´¹ÂÚÍøÕ¾»òÕßαÔìµÄAndroidÓ¦ÓÃÊÐËÁ¡£¡£¡£¡£È»ºóͨ¹ýαװ³É̸ÌìÓ¦ÓõĶñÒâÈí¼þ£¬£¬£¬£¬£¬·Ö·¢PJobRATºÍMayhemµÈ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/pakistani-hackers-operated-a-fake-app-store-to-target-former-afghan-officials/
4¡¢GoogleÐû²¼11Ô¸üУ¬£¬£¬£¬£¬ÐÞ¸´ChromeÖеĶà¸öÎó²î
11ÔÂ16ÈÕ£¬£¬£¬£¬£¬GoogleÐû²¼Á˱¾ÔÂChromeµÄÇå¾²¸üУ¬£¬£¬£¬£¬×ܼÆÐÞ¸´ÁË25¸öÎó²î¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬½ÏΪÑÏÖØµÄÊÇÔÚýÌåÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2021-38008£©¡¢V8ÖеÄÀàÐÍ»ìÏýÎó²î£¨CVE-2021-38007£©ºÍ¼ÓÔØÆ÷ÖÐÊͷźóʹÓÃÎó²î£¨CVE-2021-38005£©µÈ¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬»¹ÐÞ¸´ÁËÖ¸ÎÆÊ¶±ðÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2021-38013£©ºÍSwiftshaderÖеÄÔ½½çдÈ루CVE-2021-38014£©µÈÎó²î¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://chromereleases.googleblog.com/2021/11/stable-channel-update-for-desktop.html
5¡¢CloudflareÐû²¼ÆäµÖÓùÁ˸ߴï2 TbpsµÄDDoS¹¥»÷
ÃÀ¹úÍøÂçÇå¾²¹«Ë¾CloudflareÔÚ11ÔÂ15ÈÕÐû²¼ÆäµÖÓùÁËÆù½ñΪֹÓöµ½µÄ×î´ó¹¥»÷DDoS¹¥»÷£¬£¬£¬£¬£¬·åÖµÂÔµÍÓÚ2 Tbps¡£¡£¡£¡£´Ë´Î¹¥»÷Ô˶¯ÊÇÁ¬ÏµÁËDNS·Å´ó¹¥»÷ºÍUDP·ººéµÄ¶àÏòÁ¿¹¥»÷£¬£¬£¬£¬£¬Õû¸öÀú³ÌÖ»Ò»Á¬ÁËÒ»·ÖÖÓ£¬£¬£¬£¬£¬À´×ÔÔ¼15000¸ö»úеÈË×é³ÉµÄ½©Ê¬ÍøÂçMirai±äÖÖ¡£¡£¡£¡£Cloudflare±¨¸æ³ÆµÚÈý¼¾¶ÈÍøÂç²ãDDoS¹¥»÷Ô˶¯±ÈÉÏÒ»¼¾¶ÈÔöÌíÁË44%£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚ8ÔµÖÓùÁËÿÃë1720Íò´ÎÇëÇóµÄDDoS¹¥»÷£¬£¬£¬£¬£¬Î¢ÈíÔÚ10ÔÂ³ÆÆäÔÆÐ§ÀÍAzureµÖÓùÁË2.4 TbpsµÄDDoS¹¥»÷¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/124634/security/cloudflare-mitigated-ddos-2-tbps.html