Proofpoint·¢Ã÷Õë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£´¹Âڻ

Ðû²¼Ê±¼ä 2021-12-10

GoogleÐû²¼12Ô·ݸüУ¬£¬£¬£¬ÐÞ¸´chromeÖеĶà¸öÎó²î


GoogleÐû²¼12Ô·ݸüУ¬£¬£¬£¬ÐÞ¸´chromeÖеĶà¸öÎó²î.png


GoogleÔÚ12ÔÂ6ÈÕÐû²¼chromeÇå¾²¸üУ¬£¬£¬£¬×ܼÆÐÞ¸´22¸öÎó²î¡£¡£¡£¡£ÆäÖнÏΪÑÏÖØµÄÊÇWebÓ¦ÓóÌÐòÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2021-4052£©¡¢UI×é¼þÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2021-4053£©¡¢WebRTCÖеÄÔ½½çдÈëÎó²î£¨CVE-2021-4079£©ÒÔ¼°V8ÖеÄÀàÐÍ»ìÏýÎó²î£¨CVE-2021-4078£©¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬»¹ÐÞ¸´ÁËÀ©Õ¹ÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2021-4055£©ºÍANGLEÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2021-4058£©µÈ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop.html


SonicWallÐû²¼¸üУ¬£¬£¬£¬ÐÞ¸´SMA 100ϵÁÐÖжà¸öÎó²î


SonicWallÐû²¼¸üУ¬£¬£¬£¬ÐÞ¸´SMA 100ϵÁÐÖжà¸öÎó²î.png


SonicWallÔÚ12ÔÂ7ÈÕÐû²¼¸üУ¬£¬£¬£¬ÐÞ¸´SMA 100ϵÁÐ×°±¸ÖеĶà¸öÎó²î¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄ×îΪÑÏÖØµÄÎó²îÊÇ»ùÓÚ¿ÍÕ»µÄ»º³åÇøÒç³öÎó²î£¨CVE-2021-20038£©£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.8£¬£¬£¬£¬ÓÉÓÚ×°±¸µÄApache httpdЧÀÍÆ÷ÖеÄHTTP GETÒªÁìµÄÇéÐαäÁ¿Ê¹ÓÃÁËstrcat()º¯Êýµ¼ÖµÄ£»£»£»£»£»£»Æä´ÎÊÇ»º³åÇøÒç³öÎó²î£¨CVE-2021-20045£©£¬£¬£¬£¬CVSSÆÀ·Ö9.4¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬»¹ÐÞ¸´ÁË»º³åÇøÒç³öÎó²î£¨CVE-2021-20043£©ºÍÈÏÖ¤ÏÂÁî×¢ÈëÎó²î£¨CVE-2021-20039£©µÈ¡£¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.cisa.gov/uscert/ncas/current-activity/2021/12/08/sonicwall-releases-security-advisory-sma-100-series-appliances


ÑÇÂíÑ·AWSÔÆÐ§ÀÍå´»úÓ°ÏìNetflixµÈ¶à¸öÓ¦ÓÃ


ÑÇÂíÑ·AWSÔÆÐ§ÀÍå´»úÓ°ÏìNetflixµÈ¶à¸öÓ¦ÓÃ.png


12ÔÂ7ÈÕÏÂÖç12µã×óÓÒ£¬£¬£¬£¬ÃÀ¹úUS-EAST-1ÇøÓòµÄÑÇÂíÑ·AWSÔÆÐ§ÀÍå´»ú¡£¡£¡£¡£´Ë´ÎÊÂÎñÓ°ÏìÁËRing¡¢Netflix¡¢Amazon Prime Video¡¢RobinhoodºÍRokuµÈÓ¦Ó㬣¬£¬£¬ÒÔ¼°PUBG¡¢ValorantºÍÓ¢ÐÛͬÃ˵ÈÓÎÏ·¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚµ±Ìì12:34È·ÈÏÁËÖÐÖ¹ÊÂÎñ£¬£¬£¬£¬²¢³Æ»ù´¡Ôµ¹ÊÔ­ÓÉÊǶà¸öÍøÂç×°±¸ÊÜË𡣡£¡£¡£12ÔÂ7ÈÕÏÂÖç4:35£¬£¬£¬£¬ÑÇÂíÑ·ÌåÏÖÍøÂç×°±¸ÎÊÌâÒѾ­½â¾ö£¬£¬£¬£¬ËûÃÇÕýÔÚÆð¾¢»Ö¸´ÊÜËðЧÀÍ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/amazon-web-service-outage-impact-major-websites/


Proofpoint·¢Ã÷Õë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£´¹Âڻ


Proofpoint·¢Ã÷Õë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£´¹Âڻ.png


Proofpoint¹ûÕæÁ˽üÆÚ´ó¹æÄ£´¹ÂڻÖÐʹÓõÄÕ½ÂÔ¡¢ÊÖÒպͳÌÐò(TTP)µÄÏêϸÐÅÏ¢¡£¡£¡£¡£´Ë´Î»î¶¯×îÏÈÓÚ½ñÄê10Ô·ݣ¬£¬£¬£¬À´×Ô¶à¸öºÚ¿ÍÍŻ£¬£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹úµÄ´óѧ¡£¡£¡£¡£ÕâЩ¹¥»÷ͨ¹ýÒÔOmicron±äÌå¡¢COVID-19²âÊÔЧ¹ûºÍÆäËü²âÊÔÒªÇóΪÖ÷ÌâµÄ´¹ÂÚÓʼþ£¬£¬£¬£¬ÓÕʹĿµÄ·­¿ª¸½¼þÖеÄHTMÎļþ£¬£¬£¬£¬²¢½«ÆäÖØ¶¨Ïòµ½Î±×°³ÉËûÃÇ´óѧµÇÂ¼ÍøÕ¾µÄ´¹ÂÚÒ³Ãæ£¬£¬£¬£¬Ö¼ÔÚÇÔÊØÐÅÏ¢¡£¡£¡£¡£ÎªÁËÈÆ¹ýMFA±£»£»£»£»£»£»¤£¬£¬£¬£¬¹¥»÷Õß»¹½¨ÉèÁËαÔìµÄDUO MFAÍøÕ¾ÒÔÇÔÈ¡Óû§µÄOTP¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-universities-targeted-by-office-365-phishing-attacks/


QNAPÌáÐѿͻ§×¢ÖؽüÆÚÕë¶ÔÆäNAS×°±¸µÄÍÚ¿ó»î¶¯


QNAPÌáÐѿͻ§×¢ÖؽüÆÚÕë¶ÔÆäNAS×°±¸µÄÍÚ¿ó»î¶¯.png


Öйų́ÍåµÄNAS×°±¸ÖÆÔìÉÌQNAPÔÚ12ÔÂ7ÈÕÐû²¼Í¨¸æ£¬£¬£¬£¬ÌáÐÑÓû§×¢ÖؽüÆÚµÄ¶ñÒâÍÚ¿ó»î¶¯¡£¡£¡£¡£Í¨¸æ³Æ£¬£¬£¬£¬´Ë´Î»î¶¯Ãé×¼ÁËQNAP NAS¡£¡£¡£¡£Ò»µ©NAS±»Ñ¬È¾£¬£¬£¬£¬CPUʹÓÃÂÊ»á±äµÃÒì³£¸ß£¬£¬£¬£¬ÆäÖÐÃûΪ¡°[oom_reaper]¡±µÄÀú³Ì¿ÉÄÜ»áÕ¼ÓÃ×ÜCPUʹÓÃÂʵÄ50%×óÓÒ¡£¡£¡£¡£Õâ¸öÀú³ÌÄ£ÄâÁËÒ»¸öÕýµ±µÄͬÃûÄÚºËÀú³Ì£¬£¬£¬£¬¿ÉÊÇÕý³£ÄÚºËÀú³ÌPIDͨ³£µÍÓÚ1000£¬£¬£¬£¬¶ø¸Ã¿ó¹¤PIDͨ³£´óÓÚ1000¡£¡£¡£¡£QNAP½¨ÒéÓû§½«QTS¸üе½×îа汾£¬£¬£¬£¬²¢Ê¹ÓÃÇ¿ÃÜÂë¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/12/warning-yet-another-bitcoin-mining.html


ÐÂÀÕË÷Èí¼þCerberÃé×¼ConfluenceºÍGitLabЧÀÍÆ÷


ÐÂÀÕË÷Èí¼þCerberÃé×¼ConfluenceºÍGitLabЧÀÍÆ÷.png


12ÔÂ7ÈÕ£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ʹÓÃÁ˾ÉÃû³ÆµÄÐÂÀÕË÷Èí¼þCerber¡£¡£¡£¡£ÀÕË÷Èí¼þCerberÓÚ2016Äê·ºÆð£¬£¬£¬£¬Ö±µ½2019Äêµ×ÏûÊÅ¡£¡£¡£¡£´ÓÉϸöÔÂ×îÏÈ£¬£¬£¬£¬Cerbe»Ø¹é£¬£¬£¬£¬¿ÉÊÇËüÓë¾É°æ²¢²»Ïàͬ£¬£¬£¬£¬´úÂ벻ƥÅ䣬£¬£¬£¬Ð°æÊ¹ÓÃCrypto+++¿â¶ø¾É°æ±¾Ê¹ÓÃWindows CryptoAPI¿â£¬£¬£¬£¬²¢ÇҾɰæCerberҲûÓÐLinux±äÌå¡£¡£¡£¡£ÐÂCerberµÄÊê½ðÒªÇó´Ó1000ÃÀÔªµ½3000ÃÀÔª²»µÈ£¬£¬£¬£¬Ê¹ÓÃÁËCVE-2021-26084ºÍCVE-2021-22205Îó²îÃé×¼ConfluenceºÍGitLabЧÀÍÆ÷£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹ú¡¢µÂ¹úºÍÖйú¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-cerber-ransomware-targets-confluence-and-gitlab-servers/