Ó¢¹ú¹ú·À²¿µÄ¹ú·ÀѧԺÔâµ½¹¥»÷ £¬ÒÉΪÍâ¹úºÚ¿Í£»IoT¹«Ë¾Sierra WirelessѬȾÀÕË÷Èí¼þµ¼ÖÂÉú²úÖÐÖ¹

Ðû²¼Ê±¼ä 2021-03-24

1.Ó¢¹ú¹ú·À²¿µÄ¹ú·ÀѧԺÔâµ½¹¥»÷ £¬ÒÉΪÍâ¹úºÚ¿Í


1.jpg


Ó¢¹ú¹ú·À²¿µÄ¹ú·ÀѧԺÔâµ½ÑÏÖØµÄ¹¥»÷ £¬ÏÓÒÉÊǶíÂÞ˹µÈÍâ¹úÊÆÁ¦ËùΪ¡£¸ÃѧԺλÓÚÅ£½ò¿¤Î÷ÄÏʲÀï·òÄÉÄ· £¬Ö÷ҪΪӢ¹úÎä×°²½¶Ó¡¢¹«ÎñÔ±¡¢ÆäËûÕþ¸®²¿·ÖºÍ¹ú¼Ò·þÎñÖ°Ô±Ìṩ¸ßµÈ½ÌÓý¡£´Ë´Î¹¥»÷µ¼Ö¸ÃѧԺµÄ¹ÙÍøÖÐÖ¹ £¬ÓɳаüÉÌÔËÓªµÄITÍøÂç±»ÆÆË𠣬ѧУϵͳҲÊܵ½Ó°Ïì £¬¸ÃУԱ¹¤±»ÆÈʹÓÃСÎÒ˽¼ÒµçÄÔ¾ÙÐа칫¡£¾ÝϤ £¬Ô¤¼ÆÐèÒª5ÖÜʱ¼ä²Å»ªÍêÈ«»Ö¸´ÊÜÓ°ÏìµÄÅÌËã»úºÍ·þÎñÆ÷¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/115870/hacking/ministry-of-defence-hacked.html


2.ºÚ¿ÍʹÓÃAccellionµÄFTAÖÐÎó²îÈëÇÖ¿ÇÅÆ²¢Î´Ó°ÏìÆäÍøÂç


2.jpg


ºÚ¿ÍʹÓÃAccellionµÄFile Transfer Appliance£¨FTA£©ÖÐÎó²îÈëÇÖÄÜÔ´¹«Ë¾¿ÇÅÆ¡£¿ÇÅÆ¹«Ë¾Éù³Æ £¬¸ÃÊÂÎñ½öÓ°ÏìÁËFTA×°±¸ £¬ÓÉÓÚÎļþ´«Êä·þÎñÓëÆäËûÊý×Ö»ù´¡ÉèÊ©ÊǸôÀëµÄ £¬Òò´ËÆä½¹µãITϵͳδÊܵ½ÈκÎÓ°Ïì¡£±ðµÄ £¬¹¥»÷Õß¿ÉÄÜÒѾ­ÇÔÈ¡²¿·ÖÊý¾Ý £¬°üÀ¨Ò»Ð©Ð¡ÎÒ˽¼ÒÐÅÏ¢ÒÔ¼°¿ÇÅÆ¹«Ë¾ºÍÆäÀûÒæÏà¹ØÕßµÄÊý¾Ý¡£Ö»¹Ü¿ÇÅÆ¹«Ë¾Ã»ÓÐÅû¶¹¥»÷ÕßµÄÉí·Ý £¬µ«Ñо¿Ö°Ô±ÍƲ⠣¬´Ë´Î¹¥»÷ÓëFIN11ºÚ¿ÍÍÅ»ïÓйØ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/energy-giant-shell-discloses-data-breach-after-accellion-hack/


3.IoT¹«Ë¾Sierra WirelessѬȾÀÕË÷Èí¼þµ¼ÖÂÉú²úÖÐÖ¹


3.jpg


3ÔÂ20ÈÕ £¬¼ÓÄôó¿ç¹úÎÞÏßͨѶװ±¸ÖÆÔìÉÌSierra WirelessѬȾÀÕË÷Èí¼þ £¬ËùÓÐÉú²úÔ˶¯±»ÆÈÖÐÖ¹¡£¸Ã¹«Ë¾Ö÷ÒªÏúÊÛͨѶװ±¸ £¬ÔÚ±±ÃÀ¡¢Å·ÖÞºÍÑÇÖÞ¾ùÉèÓÐÑз¢ÖÐÐÄ¡£´Ë´Î¹¥»÷µ¼Ö¹«Ë¾¹ÙÍøºÍÄÚ²¿ÔËÓªÔâµ½ÆÆË𠣬ȫÇòµÄÉú²ú¹¤³§±»ÆÈ¹Ø±Õ¡£µ«ÒòÆäÄÚ²¿ITϵͳÓë¿Í»§µÄ·þÎñÖ®¼äÍÑÀ뿪ÁË £¬ÒÔÊǿͻ§²¢Î´Êܵ½Ó°Ïì¡£ÏÖÔÚ £¬¸Ã¹«Ë¾ÕýÔÚµÚÈý·½×¨¼ÒµÄЭÖúÏÂÊÓ²ì´ËÊÂÎñ £¬²¢2ÔÂ23ÈÕ³·»ØÁËÉϸöÔÂÐû²¼µÄ2021ÄêµÚÒ»¼¾¶ÈÖ¸µ¼±¨¸æ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/115897/malware/sierra-wireless-ransomware.html


4.¹È¸èÅû¶ʹÓøßͨоƬÖÐÊäÈëÑéÖ¤Îó²îµÄ¹¥»÷Ô˶¯


4.jpg


¹È¸èÔÚÒ°·¢Ã÷ʹÓøßͨоƬÖÐÊäÈëÑéÖ¤Îó²î£¨CVE-2020-11261£©À´Õë¶ÔAndroidϵͳµÄ¹¥»÷Ô˶¯¡£¸ÃÎó²îλÓÚͼÐÎ×é¼þÖÐ £¬CVSSÆÀ·ÖΪ8.4 £¬µ±ÌØÖƵÄÓ¦ÓóÌÐòÇëÇó»á¼û×°±¸ÖеĴó×ÚÄÚ´æÊ± £¬¿ÉÄܵ¼ÖÂÄÚ´æÆÆË𡣸ÃÎó²îÓÚ2020Äê8ÔÂ20ÈÕ±»Åû¶ £¬²¢ÓÚ2021Äê1Ô»ñµÃÐÞ¸´¡£GoogleÔÚ3ÔÂ18ÈÕ¸üеÄ1ÔÂÇ徲ͨ¸æÖÐÌåÏÖ £¬CVE-2020-11261¿ÉÄÜÒѾ­±»Ê¹ÓÃÌᳫÕë¶ÔÐÔ¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/03/warning-new-android-zero-day.html


5.ͨÓÃµçÆø£¨GE£©µÄUR×°±¸±£´æ¶à¸öÑÏÖØµÄÎó²î


5.jpg


CISAÖÒÑÔͨÓÃµçÆø£¨GE£©µÄͨÓü̵çÆ÷£¨UR£©ÏµÁеçÔ´ÖÎÀí×°±¸Öб£´æ9¸öÑÏÖØµÄÎó²î¡£¸Ã¹«Ë¾³ÆUR×°±¸ÊǼò»¯µçÔ´ÖÎÀíÒÔ±£»¤Òªº¦×ʲúµÄ»ù´¡ £¬ÔÊÐíÓû§¿ØÖÆÖÖÖÖ×°±¸ÏûºÄµÄµç¹¦ÂÊÁ¿µÄÅÌËã×°±¸¡£ÆäÖÐ×îÑÏÖØµÄÎó²îÊÇCVE-2021-27426 £¬ÓÉĬÈϱäÁ¿³õʼ»¯²»Çå¾²µ¼Ö £¬CVSSÆÀ·ÖΪ9.8 £¬¹¥»÷Õß¿ÉÔ¶³ÌʹÓøÃÎó²îÈÆ¹ý»á¼ûÏÞÖÆ¡£Æä´ÎΪ¿ÉÓÃÀ´ÖØÆôURµÄCVE-2021-27430ºÍÊäÈëÑéÖ¤Îó²î£¨CVE-2021-27418ºÍCVE-2021-27420£©µÈ¡£


 Ô­ÎÄÁ´½Ó£º

https://threatpost.com/cisa-security-flaws-ge-power-management/164961/


6.KasperskyÐû²¼2020ÄêICSÐÐÒµµÄÌ¬ÊÆÆÊÎö±¨¸æ


6.jpg


KasperskyÐû²¼ÁË2020ÄêICSÐÐÒµµÄÌ¬ÊÆÆÊÎö±¨¸æ¡£¸Ã±¨¸æÆÊÎöÁËÓÃÓÚÉè¼Æ¡¢ÉèÖúÍά»¤¹¤Òµ¿ØÖÆ×°±¸ºÍÈí¼þµÄÅÌËã»úËùÊܵ½µÄÍøÂçÍþв¡£±¨¸æÖ¸³ö £¬ÔÚ2020ÄêϰëÄê £¬ÔÚICS¹¤³ÌºÍ¼¯³ÉÐÐÒµÖÐ39.3£¥µÄÅÌËã»úÊܵ½Á˶ñÒâÈí¼þ¹¥»÷ £¬Óë2020ÄêÉϰëÄ꣨31.5£¥£©Ïà±ÈÓÐËùÔöÌí £¬ÆäÖÐÐÞ½¨×Ô¶¯»¯¡¢Æû³µÖÆÔì¡¢ÄÜԴʯÓͺÍ×ÔÈ»ÆøÐÐÒµÔâµ½µÄ¹¥»÷Ôö¶à¡£2020ÄêϰëÄê £¬Õë¶ÔÀ­¶¡ÃÀÖÞ¡¢Öж«¡¢ÑÇÖ޺ͱ±ÃÀµÄ¹¥»÷´ÎÊýÔö¶à £¬Õë¶Ô·ÇÖÞ¡¢¶íÂÞ˹ºÍÅ·Ö޵Ĺ¥»÷ÊýÄ¿ÓÐËùïÔÌ­¡£


Ô­ÎÄÁ´½Ó£º

https://ics-cert.kaspersky.com/reports/2021/03/17/threat-landscape-for-the-ics-engineering-and-integration-sector-2020/