ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ3ÖÜ

Ðû²¼Ê±¼ä 2021-01-18

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2021Äê01ÔÂ11ÈÕÖÁ01ÔÂ17ÈÕ¹²ÊÕ¼Çå¾²Îó²î70¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Word CVE-2021-1715´úÂëÖ´ÐÐÎó²î£»£»£»£»£»Siemens JT2Go JTÆÊÎöÀàÐÍ»ìÏý´úÂëÖ´ÐÐÎó²î£»£»£»£»£»Cisco Connected Mobile Experiences CVE-2021-1144ȨÏÞÌáÉýÎó²î£»£»£»£»£»Adobe Photoshop¶Ñ»º³åÇøÒç³ö´úÂëÖ´ÐÐÎó²î£»£»£»£»£»Xiaomi AX1800µÇ¼ÑéÖ¤ÈÆ¹ýÎó²î¡£¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÐÂÎ÷À¼´¢±¸ÒøÐÐÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Ãô¸ÐÐÅÏ¢»òÒÑй¶£»£»£»£»£»ÁªºÏ¹úÇéÐÎÍýÏëÊðµÄGit´æ´¢¿âй¶Áè¼Ý10Íò¸öµÄÔ±¹¤ÐÅÏ¢£»£»£»£»£»Socialarksй¶400GBÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÈ«Çò2ÒÚ¶àÓû§£»£»£»£»£»ÐÂSolarLeaksÍøÕ¾³öÊÛSolarWinds¹©Ó¦Á´¹¥»÷ÖеÄÀúÊ·Êý¾Ý£»£»£»£»£»SkypeÔÚÈ«Çò¹æÄ£ÄÚЧÀÍÖÐÖ¹£¬£¬£¬£¬£¬£¬£¬£¬Ôµ¹ÊÔ­ÓÉÉв»Ã÷È·¡£¡£¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£¡£


> Ö÷ÒªÇå¾²Îó²îÁбí


1.Microsoft Word CVE-2021-1715´úÂëÖ´ÐÐÎó²î


Microsoft Word±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-1715


2.Siemens JT2Go JTÆÊÎöÀàÐÍ»ìÏý´úÂëÖ´ÐÐÎó²î


Siemens JT2Go JTÎļþÆÊÎö±£´æÀàÐÍ»ìÏýÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

https://us-cert.cisa.gov/ics/advisories/icsa-21-012-03


3.Cisco Connected Mobile Experiences CVE-2021-1144ȨÏÞÌáÉýÎó²î


Cisco Connected Mobile Experiences¸ü¸ÄÃÜÂëÊÚȨ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿É¸ü¸Äí§ÒâÓû§ÃÜÂ룬£¬£¬£¬£¬£¬£¬£¬ÌáÉýÌØÈ¨¡£¡£¡£¡£¡£¡£¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cmxpe-75Asy9k


4.Adobe Photoshop¶Ñ»º³åÇøÒç³ö´úÂëÖ´ÐÐÎó²î


Adobe Photoshop´¦Öóͷ£Îļþ±£´æ¶Ñ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

https://helpx.adobe.com/security/products/photoshop/apsb21-01.html


5.Xiaomi AX1800µÇ¼ÑéÖ¤ÈÆ¹ýÎó²î


Xiaomi AX1800±£´æÂ·ÓÉÖØÊÓÆôºóʱ¼ä²î±ð²½µÄÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÈÆ¹ýµÇ¼Ñé֤δÊÚȨ»á¼û¡£¡£¡£¡£¡£¡£¡£

https://privacy.mi.com/trust#/security/vulnerability-management/vulnerability-announcement/detail?id=22&locale=en


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢ÐÂÎ÷À¼´¢±¸ÒøÐÐÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Ãô¸ÐÐÅÏ¢»òÒÑй¶


1.jpg


λÓÚ»ÝÁé¶ÙµÄÐÂÎ÷À¼´¢±¸ÒøÐÐÓÚÖÜÈÕÉù³ÆÆäÔâµ½¹¥»÷¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÒøÐÐÓÃÀ´¹²ÏíºÍ´æ´¢Ãô¸ÐÐÅÏ¢µÄµÚÈý·½Îļþ¹²ÏíЧÀ͵ÄÊý¾ÝϵͳÔâµ½ÆÆË𣬣¬£¬£¬£¬£¬£¬£¬ºÚ¿Í¿ÉÄÜÒѾ­»á¼ûÁËÆäÖеÄÉÌÒµºÍСÎÒ˽¼ÒÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃϵͳÒѱ»ÍÑ»ú±£»£»£»£»£»¤£¬£¬£¬£¬£¬£¬£¬£¬Ö±µ½ÒøÐÐÍê³ÉÆä³õ³ÌÐò²éΪֹ²Å»á»Ö¸´¡£¡£¡£¡£¡£¡£¡£¸ÃÒøÐÐÌåÏÖÆäÕýÔÚÈ·¶¨Ð¹Â¶ÐÅÏ¢µÄ¹æÄ££¬£¬£¬£¬£¬£¬£¬£¬²¢ÇҾܾøÍ¸Â¶Óйش˴ι¥»÷¸ü¶àµÄϸ½Ú¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/new-zealand-central-bank-hit-cyber-attack


2¡¢ÁªºÏ¹úÇéÐÎÍýÏëÊðµÄGit´æ´¢¿âй¶Áè¼Ý10Íò¸öµÄÔ±¹¤ÐÅÏ¢


2.png


¸Ã¹ûÕæµÄgitĿ¼ÖаüÀ¨ÁË´ó×ÚÃô¸ÐÎļþ£¬£¬£¬£¬£¬£¬£¬£¬ÈçÓëÇéÐÎÊðºÍÁªºÏ¹ú¹ú¼ÊÀ͹¤×éÖ¯ÆäËûÔÚÏßϵͳÏà¹ØµÄ´¿Îı¾Êý¾Ý¿âƾ֤£¬£¬£¬£¬£¬£¬£¬£¬ÖÎÀíÔ±µÄÊý¾Ý¿âƾ֤ºÍÇéÐÎÊðµÄÔ´´úÂë¿âµÈ¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬´Ë´ÎÊÂÎñ»¹Ð¹Â¶ÁËÔ±¹¤µÄPII£¬£¬£¬£¬£¬£¬£¬£¬ÈçÔ±¹¤ÂÃÐÐÀúÊ·¡¢Éú³Ýͳ¼ÆÊý¾Ý£¨¹ú¼®¡¢ÐÔ±ðºÍн¼¶£©¡¢ÏîÄ¿×ʽðȪԴ¼Í¼¡¢Ô±¹¤¼Í¼ºÍ¾ÍÒµÆÀ¹À±¨¸æµÈ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/united-nations-data-breach-exposed-over-100k-unep-staff-records/


3¡¢Socialarksй¶400GBÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÈ«Çò2ÒÚ¶àÓû§


3.png


Çå¾²¹«Ë¾Safety Detectives·¢Ã÷£¬£¬£¬£¬£¬£¬£¬£¬ÖйúÊ×´´¹«Ë¾Socialarks£¨±¿ÄñÉç½»£©Ð¹Â¶ÁË400GBÊý¾Ý¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÊý¾Ýй¶ÊÇÓÉÓÚElasticSearchÊý¾Ý¿âÉèÖùýʧ£¬£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶ÁË×ܼÆ408GB£¬£¬£¬£¬£¬£¬£¬£¬Áè¼Ý3.18ÒÚÌõÓû§¼Í¼£¬£¬£¬£¬£¬£¬£¬£¬Éæ¼°µ½11651162¸öInstagramÓû§¡¢66117839¸öÁìÓ¢Óû§ºÍ81551567¸öFacebookÓû§¡£¡£¡£¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬£¬£¬£¬£¬£¬SocialarksÔÚ2020Äê8ÔÂÒ²±¬·¢ÁËÀàËÆµÄÊÂÎñ£¬£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶ÁË1.5ÒÚ¸öÓû§µÄСÎÒ˽¼ÒÊý¾Ý¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.safetydetectives.com/blog/socialarks-leak-report/


4¡¢ÐÂSolarLeaksÍøÕ¾³öÊÛSolarWinds¹©Ó¦Á´¹¥»÷ÖеÄÀúÊ·Êý¾Ý


4.png


ÐÂSolarLeaksÍøÕ¾³öÊÛSolarWinds¹©Ó¦Á´¹¥»÷ÖÐMicrosoft¡¢Cisco¡¢FireEyeºÍSolarWindsµÈ¹«Ë¾µÄʧÔôÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¸ÃÍøÕ¾ÒÔ60ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛMicrosoftÔ´´úÂëºÍ´æ´¢¿â£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ5ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛFireEyeµÄÔ´´úÂëºÍºì¶Ó¹¤¾ß£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ25ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛSolarWindsÔ´´úÂëºÍ¿Í»§ÃÅ»§£¬£¬£¬£¬£¬£¬£¬£¬²¢ÒÔ100ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛËùÓÐй¶Êý¾Ý¡£¡£¡£¡£¡£¡£¡£solarleaks.netÓòÊÇͨ¹ý¶íÂÞ˹Fancy BearºÍCozy BearʹÓõÄÒÑ֪ע²áÉÌNJALLA¾ÙÐÐ×¢²á¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/solarleaks-site-claims-to-sell-data-stolen-in-solarwinds-attacks/


5¡¢SkypeÔÚÈ«Çò¹æÄ£ÄÚЧÀÍÖÐÖ¹£¬£¬£¬£¬£¬£¬£¬£¬Ôµ¹ÊÔ­ÓÉÉв»Ã÷È·


5.png


1ÔÂ13ÈÕÉÏÎ磬£¬£¬£¬£¬£¬£¬£¬SkypeÔÚÈ«Çò¹æÄ£ÄÚЧÀÍÖÐÖ¹£¬£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚ¸ÃÎÊÌâÒѱ»½â¾ö¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤ÔÚÏßÐÂÎÅÆ½Ì¨DownDetectorͳ¼Æ£¬£¬£¬£¬£¬£¬£¬£¬ÖÐÖ¹Ö÷Òª¼¯ÖÐÔÚÃÀ¹ú¡¢Å·ÖÞ¡¢ÑÇÖÞºÍÌìÏÂÆäËûµØÇø¡£¡£¡£¡£¡£¡£¡£Óû§ÔÚ»á¼ûSkypeÍøÕ¾Ê±£¬£¬£¬£¬£¬£¬£¬£¬»áÏÔʾÎÒÃÇÎÞ·¨Íê³ÉÄúµÄÇëÇóµÄÌáÐÑ¡£¡£¡£¡£¡£¡£¡£MicrosoftÔÚSkype״̬ҳÉÏÌåÏÖ·¢Ã÷Á˸ÃÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬ÆäÓ°ÏìÁËSkypeµÇ¼¡¢ºô½Ð¡¢ÐÂÎÅ¡¢ËÑË÷¡¢Òƶ¯¹²Ïí¡¢Ö§¸¶ÏµÍ³¡¢SMSºÍÆäËûЧÀÍ¡£¡£¡£¡£¡£¡£¡£ÎÊÌâÏÖÒѻָ´£¬£¬£¬£¬£¬£¬£¬£¬Skype¿ÉÔÙ´ÎÁª»ú¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/skype-is-down-worldwide-microsoft-working-on-issues/