ÄϹ¬

EN
  • »ØÊ×£º2021Äê¶ÈÆß´ó´ú±íÐÔÍøÂ簲ȫÊÂÎñ

    °ä²¼¹¦·ò£º2022-01-08
    ä¯ÀÀÁ¿£º 15594

    2021Äêµ×¹«¿ªÂ¶³öµÄ Log4j ·ì϶Ѹ¿ì³ÉΪ¸ÃÄêÓ°ÏìÁ¦×î´óµÄ°²È«Íþв¡£È»¶ø£¬Õâ²¢²»ÊÇÆóÒµ°²È«ÍŶÓÃæ¶ÔµÄΨһÄÑÌ⣬¾ÝÉí·Ý͵ÇÔ×ÊÔ´ÖÐÐÄ£¨ ITRC £©µÄÊý¾ÝÏÔʾ£¬½ö 2021 ÄêǰÈý¼¾¶È¹«¿ª»ã±¨µÄÊý¾Ýй¶ÊÂÎñ¾Í¶à´ï 1,291 Æð£»Redscan ¶ÔÃÀ¹ú¹ú¶ÈͨÓ÷ì϶Êý¾Ý¿â£¨ NVD £©µÄÒ»Ïîе÷ÑÐÏÔʾ£¬ 2021 ÄêÅû¶µÄ·ì϶ÊýÁ¿£¨ 18,439 ¸ö£©±ÈÒÔÍùÈκÎÒ»Äê¶¼¶à¡£¸üÔã¸âµÄÊÇ£¬ÆäÖоø´ó²¿ÃŶ¼Äܹ»±»ºÚ¿ÍÉõÖÁ¼¼ÊõÄÜÁ¦ÓÐÏ޵Ĺ¥»÷ÕßÀûÓá£

    ÒÔÏÂÁгöÁË 2021 Äê×î¾ß´ú±íÐ﵀ 7 ÆðÍøÂ簲ȫÊÂÎñ£¬ÆäÖÐÔ̺¬Êý¾Ýй¶¡¢¹¥»÷ºÍ·ì϶µÈ¡£

    1. Õð¾ªÒµ½çµÄ Log4j ·ì϶

    2021Äê12Ô³õ£¬ Log4j ÈÕÖ¾¿ò¼ÜÖÐÒ»¸öÑϳÁµÄÔ¶³Ì´úÂëÖ´Ðзì϶Õð¾ªÁËÕû¸öÐÐÒµ£¬Äܹ»Ëµ£¬½üÄêÀ´ºÜÉÙÓÐÆäËû·ì϶¾ß±¸Èç´ËÕðÉåÁ¦¡£ÕâÖÖÓÇÓôÔ´ÓÚÕâÑùÒ»¸öÊÂʵ£¬¼´¸Ã¹¤¾ßÔÚÆóÒµÔËÓª£¨ OT £©¡¢Èí¼þ¼´·þÎñ£¨ SaaS £©ºÍÔÆ·þÎñÌṩÉÌ£¨ CSP £©»·¾³ÖÐÆÕ±é´æÔÚ£¬ÇÒÏà¶ÔÈÝÒ×ÀûÓ᣸÷ì϶Ϊ¹¥»÷ÕßÌṩÁËÒ»ÖÖÔ¶³Ì½ÚÔì·þÎñÆ÷¡¢ PC ºÍÈÎºÎÆäËûÉ豸µÄ²½Ö裬Ô̺¬´æÔÚÈÕÖ¾¹¤¾ßµÄ¹Ø¼üÔËÓª£¨ OT£©ºÍ¹¤Òµ½ÚÔìϵͳ£¨ ICS £©»·¾³ÖеÄÉ豸¡£

    ¸Ã·ì϶£¨ CVE-2021-44228 £©´æÔÚÓÚ´Ó Log4j 2.0-beta9 µ½ Log4j 2.14.1 °æ±¾ÖУ¬Äܹ»Í¨¹ý¶àÖÖ·½Ê½ÀûÓá£Apache »ù½ð»á×î³õ°ä²¼Á˸ù¤¾ßµÄа汾£¨ Apache Log4j 2.15.0 £©ÊÔͼ½â¾öÎÊÌ⣬µ«¶ûºó²»¾ÃÓÖ²»µÃ²»°ä²¼ÁíÒ»¸ö¸üУ¬ÓÉÓÚµÚÒ»¸ö¸üÐÂûÄÜÆëȫԤ·À»Ø¾ø·þÎñ£¨ DoS £©¹¥»÷ºÍÊý¾Ý͵ÇÔ¡£

    ½ØÖÁ 2021 Äê 12 Ô 17 ÈÕ£¬ÔÝδ³öÏÖÓë´Ë·ì϶ÓйصijÁ´óÊý¾Ýй¶ÊÂÎñ¡£È»¶ø£¬°²È«×¨¼Ò¼áÐŹ¥»÷Õ߿϶¨»áÀûÓø÷ì϶£¬²¢ÔÚ¿ÉÔ¤¸ÐµÄ½«À´³ÖÐøÕâÑù×ö£¬ÓÉÓÚÆóÒµºÜÄÑÕÒµ½Ò×Êܹ¥»÷ϵͳµÄÿһ¸öÊ·ý²¢ÓÐЧ·À±¸¸Ã·ì϶¡£ºÜ¶à°²È«³§É̻㱨ÁËÕë¶Ô¸÷Àà IT ºÍ OT ϵͳ£¨Ô̺¬·þÎñÆ÷¡¢Ðé¹¹»ú¡¢Òƶ¯É豸¡¢ÈË»ú½çÃæÏµÍ³ºÍ SCADA É豸µÈ£©µÄ¿í·ºÉ¨Ãè»î¶¯£¬ÆäÖÐºÜ¶à¶¼Éæ¼°³¢ÊÔͶ±ÒÍÚ¾ò¹¤¾ß¡¢Ô¶³Ì½Ó¼ûľÂí¡¢ÀÕË÷Èí¼þºÍ Web shell £»Éæ¼°µÄ¶ñÒâÐÐΪÕßÔòÔ̺¬ÒÑÖªµÄ³öÓÚ¾­¼Ã¶¯»úµÄÍþв×éÖ¯£¬ÒÔ¼°À´×ÔÒÁÀʺÍÍÁ¶úÆäµÈ¹ú¶ÈÖ§³ÖµÄ APT ×éÖ¯¡£

    2. Colonial Pipeline ¹¥»÷½«ÀÕË÷Èí¼þÌáÉýÖÁ¹ú¶È°²È«

    2021 Äê 5 Ô£¬Õë¶ÔÃÀ¹ú¹Ü·ÔËÓªÉÌ Colonial Pipeline µÄÀÕË÷Èí¼þ¹¥»÷Õ¼¾ÝÁËÐÂÎÅÍ·Ìõ£¬´Ë¾Ù¶ÔÃÀ¹ú¿í´óÃñ¶àÔì³ÉÁË¿í·ºÓ°Ï죺ÖжÏÁËÊý°ÙÍò¼ÓÂØÈ¼ÁϵÄÔËÊ䣬²¢Òý·¢ÁËÃÀ¹ú¶«º£°¶´ó²¿ÃŵØÓòµÄ¶ÌÔÝÐÔÌìÈ»ÆøÇ·È±¡£ÕâÆðÊÂÎñÒ²³É¹¦½«ÀÕË÷Èí¼þÌáÉýΪ¹ú¶È°²È«¼¶´ËÍâÎÊÌ⣬²¢ÒýÆðÁ˰׹¬µÄ¹Ø×¢¡£ÊÂÎñ²úÉú¼¸Ììºó£¬°ÝµÇ×Üͳ°ä²¼ÁËÒ»ÏîÐÐÕþºÅÁҪÇóÁª¹ú»ú¹¹Ö´ÐÐеĽÚÔì´ëÊ©ÒÔ¼ÓÇ¿ÍøÂ簲ȫ¡£

    ¾ÝϤ£¬Õâ´ÎÊÂÎñµÄÔ­ÒòÊǺڿÍ×é֯ʹÓÃÁ˱»µÁµÄ¾É VPN Í´´¦»ñµÃÁË¶Ô Colonial Pipeline ÍøÂçµÄ½Ó¼ûȨÏÞ¡£ÕâÖÖ¹¥»÷²½Öè×ÔÉí²¢·Ç³ö¸ñÖµÍ×ÌùÐÄ£¬µ«·ÛËé×ÔÉíÈ´ÊǿɼûµÄ¡¢ÓÐÒâ˼µÄ£¬²¢ÇҺܶ൱¾Ö¹ÙÔ±¶¼ÄÜÇ××Ըд¥µ½¡£ÕâÒ²´ÙʹÃÀ¹úÁ½µ³ºÍµ±¾ÖÌá¸ßÁËʹÓÿɳÁÓÃÃÜÂëµÈÎÊÌâµÄÃż÷¡£Ëä˵¸ß¶È¹Ø×¢¿ÉÄܲ»»á²úÉúÁ¢¸Í¼ûÓ°µÄ½øÕ¹£¬µ«ËüÒѾ­Íƶ¯Á˹ú¶È²ãÃæ¶ÔÍøÂ簲ȫµÄ¹Ø×¢¡£

    3.  Kaseya ÊÂÎñ½«ÈËÃÇÈ·°ÑÎÈÁ¦¼¯ÖÐÔÚ¹©¸øÁ´·çÏÕÉÏ

    2021 Äê 7 Ô³õ£¬ IT ÖÎÀíÈí¼þ¹©¸øÉÌ Kaseya ²úÉúµÄ°²È«ÊÂÎñ£¬ÔÙ´Î͹ÏÔÁËÆóÒµÃæ¶ÔÀ´×Ô IT ¹©¸øÁ´Öй©¸øÉ̵ÄÍþвÕýÈÕÒæ¼Ó¾ç¡£

    ¸ÃÊÂÎñºóÀ´¹éÒòÓÚ REvil/Sodinokibi ÀÕË÷Èí¼þ×éÖ¯µÄÒ»¸ö´ÓÊô»ú¹¹£¬ÆäÖÐÉæ¼°ÍþвÐÐΪÕßÀûÓà Kaseya Ð鹹ϵͳÖÎÀíÔ±£¨ VSA £©¼¼ÊõÖеÄÈý¸ö·ì϶£¬¶øºÜ¶àÍйܷþÎñÌṩÉÌ£¨ MSP £©Ê¹Óøü¼ÊõÀ´ÖÎÀíÆä¿Í»§µÄÍøÂç¡£¹¥»÷ÕßÀûÓÃÕâЩ·ì϶£¬Ê¹Óà Kaseya VSA ÔÚÊôÓÚ MSP ÏÂÓοͻ§µÄÊýǧ¸öϵͳÉÏ·Ö·¢ÀÕË÷Èí¼þ¡£

    Kaseya ¹¥»÷͹ÏÔÁËÍþвÐÐΪÕß¶ÔÒ»´ÎÐÔ·ÛËé¶à¸öÖ¸±ê£¨ÈçÈí¼þ¹©¸øÉ̺ͷþÎñÌṩÉÌ£©µÄÐËÖÂÈÕ񾁬ÃÜ¡£¹ÌÈ»Õâ²»ÊǵäÐ͵Ĺ©¸øÁ´¹¥»÷¡ª¡ªÓÉÓÚËüÀûÓÃÁËÒѲ¿ÊðµÄ Kaseya VSA ·þÎñÆ÷·ì϶£¬µ« MSP ÏòÆä¿Í»§·Ö·¢Èí¼þµÄ Kaseya »úÔìÊÇÀ©´ó¹¥»÷ÁìÓòºÍ¿ìÂʵĹؼü¡£¸ÃÊÂÎñ´ÙʹÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨ CISA £©·¢³ö¶à¸öÍþв¾¯±¨£¬²¢Îª MSP ¼°Æä¿Í»§ÌṩÁìµ¼¡£

    4.  Exchange Server ¹¥»÷Òý·¢½¨²¹Å­³±

    2021Äê3Ô³õ£¬µ±Î¢ÈíÕë¶ÔÆä Exchange Server ¼¼ÊõÖеÄËĸö·ì϶£¨Í³³ÆÎª¡° ProxyLogon ¡±£©°ä²¼´¹Î£½¨¸´·¨Ê½Ê±£¬Òý·¢ÁËÒ»³¡Ç°ËùδÓеĽ¨²¹Å­³±¡£

    ProxyLogon ·ì϶ΪÍþвÐÐΪÕßÌṩÁËÒ»ÖÖδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì½Ó¼û Exchange ·þÎñÆ÷µÄ²½Öè¡£ËüÐÔÖÊÉÏÊÇÒ»¸öµç×Ó°æ±¾£¬´ÓÆóÒµµÄÖØÒªÈë¿ÚÉÏÒÆ³ýËùÓнӼû½ÚÔì¡¢¾¯ÎÀºÍËø£¬ÕâÑùÈκÎÈ˶¼Äܹ»½øÈ롣һЩ°²È«³§É̵ĵ÷²éÅú×¢£¬¼¸¸öÍþв×éÖ¯ÔÚ²¹¶¡°ä²¼Ö®Ç°¾ÍÒѾ­¶Ô×¼ÁËÕâЩ·ì϶£¬²¢ÇÒÔÚ΢ÈíÅû¶·ì϶ºó£¬ºÜ¶àÆäËû×éÖ¯Ò²²ÎÓëÁËÕâÒ»Ðж¯¡£¹¥»÷ÊýÁ¿Èç´ËÖ®¶à£¬ÒÔÖÁÓÚ F-Secure ³Æ¡° Exchange Server ±»ºÚ¿ÍÈëÇֵĿìÂʱÈÎÒÃÇÉèÏëµÄÒª¿ì¡±¡£

    ÓëºÜ¶àÆäËû¹©¸øÉÌÒ»Ñù£¬Î¢ÈíÆäʱҲ½¨ÒéÆóÒµÈç¹û×Ô¼ºÒѱ»·ÛËé²¢×ö³öÏìÓ¦¡£ÔÚ·ì϶Åû¶ºó²»µ½ÈýÖÜ£¬Î¢Èí»ã±¨³Æ£¬È«ÇòÔ¼ 92% µÄ Exchange ·þÎñ IP Òѱ»½¨²¹»ò»º½â¡£µ«ÊÇ£¬ÆóÒµ¶Ô¹¥»÷ÕßÔÚ½¨²¹Ö®Ç°×°ÖÃÔÚ Exchange Server É쵀 Web shell µÄÓÇÓôÒÀÈ»»ÓÖ®²»È¥£¬´ÙʹÃÀ¹ú˾·¨²¿²ÉÈ¡ÁËǰËùδÓеĴëÊ©£¬ºÅÁî FBI ×Ô¶¯´ÓºóÃÅ Exchange Server ÖÐɾ³ý Web shell ¡£

    5.  PrintNightmare Ç¿µ÷ Windows Print Spooler ¼¼ÊõµÄ³ÖÐø·çÏÕ

    ºÜÉÙÓзì϶ÄÜ±È PrintNightmare £¨ CVE-2021-34527 £©¸üÄÜ·´Ó³Î¢ÈíµÄ Windows Print Spooler ¼¼Êõ¸øÆóÒµ´øÀ´µÄ³ÖÐø·çÏÕ¡£¸Ã·ì϶ÓÚ 2021 Äê 7 ÔÂÅû¶£¬Óë Spooler ·þÎñÖÐÓÃÓÚ×°ÖôòÓ¡»úÇý¶¯·¨Ê½ÏµÍ³µÄÌØ¶¨Ö°ÄÜÓйØ¡£¸ÃÎÊÌâÓ°ÏìÁËËùÓÐ Windows °æ±¾£¬²¢Îª¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÌṩÁËÒ»ÖÖÔÚÖ°ºÎ´æÔÚ·ì϶µÄϵͳÉÏÔ¶³ÌÖ´ÐжñÒâ´úÂëµÄ²½Öè¡£ÕâÔ̺¬¹Ø¼üµÄ Active Directory ÖÎÀíϵͳºÍÖ÷ÌâÓò½ÚÔìÆ÷¡£Î¢ÈíÖÒ¸æ³Æ£¬¶Ô¸Ã·ì϶µÄÀûÓûᵼÖ»·¾³µÄ»úÃÜÐÔ¡¢ÆëÈ«ÐԺͿÉÓÃÐÔÊÜËð¡£

    ΢Èí¶Ô PrintNightmare µÄÅû¶´Ùʹ CISA ¡¢ CERT Эµ÷ÖÐÐÄ£¨ CC £©ºÍÆäËû»ú¹¹°ä²¼´¹Î£½¨Ò飬¶½´ÙÆóҵѸ¿ì½ûÓùؼüϵͳÉ쵀 Print Spooler ·þÎñ¡£PrintNightmare ÊÇ΢Èí³Ö¾Ã´æÔÚȱµãµÄ Print Spooler ¼¼ÊõÖÓ×¢¼¸¸ö±ØÐ뽨²¹µÄȱµãÖнÏÑϳÁµÄÒ»¸ö¡£PrintNightmare Ö®ËùÒÔ¼«¶È³ÁÒª£¬ÊÇÓÉÓڸ÷ì϶´æÔÚÓÚÏÕЩÿ¸ö Windows ϵͳÉϳÇÊÐ×°Öõġ° Print Spoole ¡±·þÎñÖС£ÕâÒâζ׏¥»÷ÕßÓÐÒ»¸ö¾Þ´óµÄ¹¥»÷Ãæ×÷Ϊָ±ê£¬²¢ÇÒ½ûÓÃÕâЩ·þÎñ²¢²»×ÜÊÇ¿ÉÐеÄ£¬ÓÉÓÚ±ØÒªËüÀ´·½±ã´òÓ¡¡£

    6.  Accellion ÈëÇÖÊÇÂŴηÛËé¹¥»÷Ç÷ÏòµÄÀý×Ó

    ÃÀ¹ú¡¢¼ÓÄôó¡¢ÐÂ¼ÓÆÂ¡¢ºÉÀ¼ºÍÆäËû¹ú¶È/µØÓò¶à¸ö×éÖ¯ÔÚ 2021 Äê 2 ÔÂÔâ·êÁËÑϳÁµÄÊý¾Ýй¶ÊÂÎñ£¬ÓÉÓÚËûÃÇʹÓÃµÄ Accellion Îļþ´«Êä·þÎñ´æÔÚ·ì϶¡£ÁãÊÛÆóÒµ Kroger ÊÇ×î´óµÄÊܺ¦ÕßÖ®Ò»£¬ÆäÒ©·¿ºÍÕïËùÔ±¹¤ºÍÊý°ÙÍò¿Í»§µÄÊý¾Ý²ÒÔâй¶¡£ÆäËû³ÛÃûµÄÊܺ¦Õß»¹Ô̺¬¶à´ïÂÉʦÊÂÎñËù¡¢ÐÂ¼ÓÆÂµçÐÅ¡¢»ªÊ¢¶ÙÖݺÍÐÂÎ÷À¼´¢ÐîÒøÐС£

    Accellion ½«¸ÃÎÊÌâÃèÊöΪ¡°ÓëÆä½üºõ¹ýÆÚµÄÎļþ´«ÊäÉ豸¼¼ÊõÖеÄÁãÈÕ·ì϶Óйء±£¬ÆäʱºÜ¶à×éÖ¯ÔÚʹÓøü¼ÊõÔÚÆäÄÚ²¿ºÍ±í²¿´«Êä´óÐÍÎļþ¡£°²È«³§ÉÌ Mandiant µÄµ÷²éÏÔʾ£¬¹¥»÷ÕßʹÓà Accellion ¼¼ÊõÖÐ 4 ¸öÁãÈÕ·ì϶×÷Ϊ¹¥»÷Á´µÄÒ»²¿ÃÅ¡£Mandiant ºóÀ´½«Õâ´Î¹¥»÷¹éÒòÓÚÓë Clop ÀÕË÷Èí¼þ¼Ò×åºÍ FIN11 £¨Ò»¸ö³öÓÚ¾­¼Ã¶¯»úµÄ APT ×éÖ¯£©ÓйØÁªµÄÍþвÐÐΪÕß¡£

    Digital Shadows ÍøÂçÍþвµý±¨·ÖÎöʦ Ivan Righi °µÊ¾£¬ Accellion ¹¥»÷ÊÇ 2021 ËêÊ׵ijÁ´ó°²È«ÊÂÎñ£¬ÓÉÓÚËüչʾÁËÀÕË÷Èí¼þ¹©¸øÁ´¹¥»÷µÄΣÏÕÐÔ¡£Clop ÀÕË÷Èí¼þÍÅ»ï¿ÉÄÜÀûÓà Accellion Îļþ´«ÊäÉ豸£¨ FTP £©Èí¼þÖеÄÁãÈÕ·ì϶һ´ÎËø¶¨¶à¶àÆóÒµ£¬Õâ´ó´óÏ÷¼õÁ˹¥»÷ÕßʵÏÖ³õʼ½Ó¼ûËùÐèµÄ¹¤×÷ºÍ¾«Á¦¡£

    7. ·ðÂÞÀï´ïË®Îñ¹«Ë¾¹¥»÷ÊÂÎñÌáÐÑÈËÃǰÑÎȹؼü»ù´¡ÉèÊ©

    2021 Äê 2 Ô£¬Ò»Ãû¹¥»÷ÕßÈëÇÖ·ðÂÞÀï´ïÖݰÂ×ÈÂíÊÐÒ»¼ÒË®´¦Öó§µÄϵͳ£¬²¢ÊÔͼŤתһÖÖÃûΪ¼îÒºµÄ»¯Ñ§ÎïÖÊŨ¶È£¬¸Ã»¯Ñ§ÎïÖÊÓÃÓÚ½ÚÔìË®µÄËá¶È¡£µ±ÈëÇÖÕßÊÔͼ½«¼îҺˮƽÌá¸ß 111 ±¶Ê±±»·¢ÏÖ£¬ÔÚÆäÔì³É°Ü»µÖ®Ç°£¬ºÜ¿ìµÃµ½Á˸´Ô­¡£Ëæºó¶Ô¸ÃÊÂÎñµÄ·ÖÎöÏÔʾ£¬ÈëÇÖÕß»ñµÃÁËÊôÓÚË®´¦ÖÃÉèÊ©²Ù×÷Ô±µÄϵͳ½Ó¼ûȨÏÞ£¬¿ÉÄÜʹÓñ»µÁµÄ TeamViewer Í´´¦Ô¶³ÌµÇ¼Á˸Ãϵͳ¡£

    Õâ´ÎÈëÇÖʹÃÀ¹ú¹Ø¼ü»ù´¡ÉèÊ©ÔÚÍøÂç¹¥»÷¿ÌϵijÖÐø´àÈõÐÔ¶³öÎÞÒÅ£¬ÔÙ´ÎչʾÁËÈëÇÖÒûÓÃË®´¦ÖÃÉèÊ©µÄ¼à¿ØºÍÊý¾Ý²É¼¯£¨ SCADA £©ÏµÍ³ÊǶàôµ¥Ò»µÄʼþ¡£¸ÃÊÂÎñ»¹´Ùʹ CISA ÖÒ¸æ¹Ø¼ü»ù´¡ÉèÊ©ÔËÓªÉÌ£¬ÔÚ»·¾³ÖÐʹÓÃ×ÀÃæ¹²ÏíÈí¼þºÍ¹ýÆÚ»ò¿¿½ü±¨·ÏÈí¼þ£¨Èç Windows 7£©µÄΣÏÕÐÔ¡£



    ÈȵãÄÚÈÝ

    ÆðÍ·ÊÔÓÃÄϹ¬²úÆ·
    ÉêÇëÊÔÓÃ

    20Ä깫°²·þÎñ¾­Ñé

    7*24Ó×ʱӦ¼±ÏìÓ¦ÖÐÐÄ

    ×ÔÖ÷֪ʶ²úȨµÄ²úÆ·É豸

    ר¼Ò¼¶°²È«·þÎñÍŶÓ

    ÍøÂç¿Õ¼äÊý¾ÝÖÎÀíר¼Ò

    ÈÙ»ñ¹ú¶È¿ÆÑ§¼¼Êõ¶þµÈ½±

    Öö¥
    µç»°

    400-700-1218

    ¹Ù·½ÈÈÏߵ绰

    Õ÷ѯ
    ÁôÑÔ
    ¶þάÂë
    767c1a96394fd651d8ff50290509ddbe ΢ÐŹ«¼ÒºÅ
    ba7d00456f0791d9575d17b722e3b66e ¹«Ë¾Î¢²©
    ¡¾ÍøÕ¾µØÍ¼¡¿