Adobe½ôÆÈ¸üУ¬£¬£¬£¬£¬ÐÞ¸´ColdFusioní§Òâ´úÂëÖ´ÐÐÎó²î£»£»£»£» £»£»McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetopVisionProÖжà¸öÎó²î

Ðû²¼Ê±¼ä 2021-03-23

1.AdobeÐû²¼½ôÆÈ¸üУ¬£¬£¬£¬£¬ÐÞ¸´ColdFusionÖÐí§Òâ´úÂëÖ´ÐÐÎó²î


1.jpg


AdobeÓÚ3ÔÂ22ÈÕÐû²¼½ôÆÈ´øÍâ¸üУ¬£¬£¬£¬£¬ÐÞ¸´ColdFusionÖеÄí§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£¡£¸ÃÎó²îÊÇÓÉÓÚÎÞ·¨ÑéÖ¤ÊäÈ뵼ֵ쬣¬£¬£¬£¬±»¸ú×ÙΪCVE-2021-21087£¬£¬£¬£¬£¬Ó°ÏìÁËColdFusion°æ±¾2021¡¢2016ºÍ2018¡£¡£¡£Adobe½¨ÒéÖÎÀíÔ±¾¡¿ì×°ÖÃÇå¾²¸üУ¬£¬£¬£¬£¬²¢Ó¦Óùٷ½Ö¸ÄÏÖÐÐÎòµÄÇå¾²ÉèÖÃ¶ÔÆä¾ÙÐÐÉèÖᣡ£¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/critical-code-execution-vulnerability-fixed-in-adobe-coldfusion/


2.McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetop Vision Pro±£´æ¶à¸öÎó²î


2.jpg


McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetop Vision Pro±£´æ¶à¸ö¿ÉÓÃÀ´Ð®ÖÆÄ¿µÄµçÄÔµÄÎó²î¡£¡£¡£ÕâЩÎó²î»®·ÖΪȨÏÞ·ÖÅÉÎó²î£¨CVE-2021-27192£©¡¢Ä¬ÈÏȨÏÞ¹ýʧ£¨CVE-2021-27193£©¡¢ÒÔÃ÷ÎÄ´«ÊäµÄÃô¸ÐÐÅÏ¢£¨CVE-2021-27194£©ºÍÊÚȨÎÊÌ⣨CVE-2021-27195£©¡£¡£¡£ºÚ¿Í¿ÉÓÃÕâЩÎó²î¾ÙÐÐÌáȨºÍÖ´ÐÐÔ¶³Ì´úÂ룬£¬£¬£¬£¬»ñµÃ¶ÔÄ¿µÄϵͳµÄÍêÈ«¿ØÖÆÈ¨²¢ÆôÓÃÍøÂçÉãÏñÍ·ºÍÂó¿Ë·ç¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬NetopÒÑÐÞ¸´²¿·ÖÎó²î¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/popular-remote-student-learning-program-found-to-be-riddled-with-security-holes/


3.µçÁ¦¹«Ë¾Celg GTÕû¸öÍøÂçÎÞ·¨»á¼û£¬£¬£¬£¬£¬ÊÂÎñÈÔÔÚÊÓ²ìÖÐ


3.jpg


CelgGera??oeTransmiss?o£¨Celg GT£©ÓÚÉÏÖÜÎå(3ÔÂ19ÈÕ)³ÆÆäÔâµ½Á˹¥»÷£¬£¬£¬£¬£¬ËùÓеÄÓ¦ÓóÌÐòºÍÕû¸öÎļþϵͳ¶¼ÎÞ·¨»á¼û¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬¹¥»÷ÊÇ´ÓÆÆÏþ×îÏȵÄ£¬£¬£¬£¬£¬Æä·¢Ã÷ºóÁ¬Ã¦½ÓÄÉÏìÓ¦²½·¥£¬£¬£¬£¬£¬¹Ø±ÕϵͳÒÔ±£»£»£»£» £»£»¤ÐÅÏ¢ºÍ±¸·Ý×ÊÁÏ¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬¸ÃÊÂÎñÈÔÔÚÊÓ²ìÖУ¬£¬£¬£¬£¬Éв»¿ÉÈ·¶¨ÏµÍ³Ë𻵵ÄˮƽÒÔ¼°¹¥»÷µÄȪԴ£¬£¬£¬£¬£¬¿ÉÊÇ¿ÉÒÔÈ·¶¨Ã»ÓÐÈκÎСÎÒ˽¼ÒÐÅÏ¢±»Ð¹Â¶£¬£¬£¬£¬£¬¹«Ë¾Ô±¹¤µÄµç×ÓÓʼþЧÀÍÒ²¿ÉÒÔÕý³£ÔËÐС£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.jornalopcao.com.br/ultimas-noticias/ataque-hacker-compromete-funcionamento-de-aplicativos-e-arquivos-da-celg-gt-318176/


4.²®Ã÷º²Òé»áÔ±¹¤Òò²Ù×÷ʧÎó¹ûÕæ´ó×ÚÈõÊÆÈºÌåµÄСÎÒ˽¼ÒÐÅÏ¢


4.jpg


²®Ã÷º²Òé»áÔÚ3ÔÂ19ÈÕÐÇÆÚÎ峯£¬£¬£¬£¬£¬ÒòÔ±¹¤²Ù×÷ʧÎóµ¼Ö´ó×ÚÈõÊÆÈºÌåµÄСÎÒ˽¼ÒÐÅÏ¢±»¹ûÕæ¡£¡£¡£¾Ý³Æ´Ë´Îй¶µÄÊÇÓÐȨ»ñµÃÃâ·Ñ°ÍʿͨÐÐÖ¤µÄ¶ùͯµÄÏêϸÐÅÏ¢¡£¡£¡£¸ÃÊÐÌåÏÖ£¬£¬£¬£¬£¬ÆäÔÚ·¢Ã÷й¶ºóÁ¬Ã¦½ÓÄÉÁ˲½·¥£¬£¬£¬£¬£¬Êý¾Ý»¹Î´±»ÏÂÔØ£¬£¬£¬£¬£¬²¢ÇÒÓÉÓÚ´ËÊÂÎñµÄ¹æÄ£ºÍÑÏÖØÐÔ×Ó£¬£¬£¬£¬£¬ÏÖÒÑ֪ͨÈÏÕæ¼àÊÓµÄÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.birminghammail.co.uk/news/midlands-news/details-vulnerable-kids-uploaded-birmingham-20217314


5.Black KiteÐû²¼Îó²î¶ÔÐÅÓÃÏàÖúÉçµÄÓ°ÏìµÄÆÊÎö±¨¸æ


5.jpg


Black KiteÐû²¼ÁËÓйØÎó²î¶ÔÐÅÓÃÏàÖúÉçµÄÓ°ÏìµÄÆÊÎö±¨¸æ¡£¡£¡£±¨¸æÏÔʾ£¬£¬£¬£¬£¬Æ¾Ö¤Ð¹Â¶¡¢Î´¸üеľÉϵͳºÍ¹©Ó¦ÉÌÎó²îÊÇÐÅÓÃÏàÖúÉçËùÃæÁÙµÄ×î´óµÄÍøÂçΣº¦¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬Õë¶Ô¹©Ó¦É̵Ĺ¥»÷ΪÐÅÓÃÏàÖúÉç¿ÉÄÜ»áÔì³ÉÁè¼Ý100ÍòÃÀÔªµÄDZÔÚ²ÆÎïËðʧ£»£»£»£» £»£»86%µÄÐÅÓÃÏàÖúÉçºÍ76%µÄ¹©Ó¦É̵ÄÔ±¹¤Æ¾Ö¤Òѱ»ÇÔÈ¡²¢¹ûÕæµ½°µÍøÉÏ£»£»£»£» £»£»Áè¼Ý66%µÄÐÅÓÃÏàÖúÉçºÍ88%µÄ¹©Ó¦ÉÌȱ·¦Ô¤·ÀÓÕÆ­ºÍ´¹ÂÚ¹¥»÷µÄµç×ÓÓʼþÇå¾²Õ½ÂÔ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://googleprojectzero.blogspot.com/2021/03/in-wild-series-october-2020-0-day.html


6.VectraÐû²¼ÓйØOffice 365ºÍÔÆµÄÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ


6.jpg


VectraÐû²¼ÁËÓйØOffice 365ºÍÔÆµÄÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£±¨¸æÏÔʾ£¬£¬£¬£¬£¬ÔÚÒÑÍùÒ»Ä꣬£¬£¬£¬£¬Ö»¹Ü½ÓÄÉÁ˶àÒòËØÉí·ÝÑéÖ¤£¨MFA£©£¬£¬£¬£¬£¬µ«ÈÔÓÐ71£¥µÄÆóÒµÈÔÈ»ÂÄÀú¹ýSaaSÕÊ»§Ð®ÖÆ£¬£¬£¬£¬£¬½ü90£¥µÄÆóÒµ»¹ÔÚ¼ÓËÙÔÆÅÌËãºÍÊý×Ö»¯µÄתÐÍ¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬¸Ã±¨¸æÔÚ90ÌìÄÚ¸ú×ÙÁË400Íò¸öMicrosoft Office 365¿Í»§µÄÐÐΪ£¬£¬£¬£¬£¬·¢Ã÷ÓÐ96£¥µÄÄÚÍø±£´æ¿ÉÒɵĺáÏòÒÆ¶¯ÐÐΪ¡£¡£¡£Îå·ÖÖ®ËĵÄÇ徲רҵְԱÌåÏÖ£¬£¬£¬£¬£¬ÔÚÒÑÍùÒ»ÄêÖÐÍøÂçÇå¾²µÄΣº¦ÓÐËùÔöÌí¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.vectra.ai/blogpost/cloud-security-insights