NPM¿âNetmask×é¼þ±£´æÎó²î £¬£¬£¬£¬ £¬£¬£¬£¬¿ÉÓ°ÏìÊýÍò¸öÓ¦ÓóÌÐò£» £» £»£»£»£»Ñо¿Ö°Ô±·¢Ã÷ÒÑÒþ²Ø25ÄêµÄWindows 95¸´Éú½Ú²Êµ°

Ðû²¼Ê±¼ä 2021-03-29

1.NPM¿âNetmask×é¼þ±£´æÎó²î £¬£¬£¬£¬ £¬£¬£¬£¬¿ÉÓ°ÏìÊýÍò¸öÓ¦ÓóÌÐò


1.jpg


¸Ã×é¼þÿÖÜÏÂÔØÁ¿Áè¼Ý300Íò´Î £¬£¬£¬£¬ £¬£¬£¬£¬×èÖ¹ÏÖÔÚÀÛ¼ÆÏÂÔØÁ¿ÒÑÁè¼Ý2.38ÒÚ´Î £¬£¬£¬£¬ £¬£¬£¬£¬Ô¼ÓÐ27.8Íò¸öGitHub´æ´¢¿âÒÀÀµÓÚnetmask¡£¡£¡£¡£ ¡£¡£¡£¡£¸ÃÎó²î±»×·×ÙΪCVE-2021-28918 £¬£¬£¬£¬ £¬£¬£¬£¬Ê®½øÖÆIPv4µØµã°üÀ¨Ç°µ¼Áãʱ £¬£¬£¬£¬ £¬£¬£¬£¬ÍøÂçÑÚÂë´¦Öóͷ£»ì¼°ÃûÌÃIPµØµãµÄ·½·¨¡£¡£¡£¡£ ¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÓ°ÏìÓ¦ÓóÌÐòÆÊÎöµÄIPµØµã £¬£¬£¬£¬ £¬£¬£¬£¬Ôò¸ÃÎó²î¿ÉÄÜ»áÒýÆðÖÖÖÖÎó²î £¬£¬£¬£¬ £¬£¬£¬£¬ÀýÈçµ¼ÖÂЧÀÍÆ÷¶ËÇëÇóαÔ죨SSRF£©ºÍµ½Ô¶³ÌÎļþ°üÀ¨£¨RFI£©¡£¡£¡£¡£ ¡£¡£¡£¡£ÏÖÔÚ £¬£¬£¬£¬ £¬£¬£¬£¬¸ÃÎó²îÒѱ»ÐÞ¸´¡£¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/critical-netmask-networking-bug-impacts-thousands-of-applications/


2.ClopÁªÏµÊܺ¦ÕߵĿͻ§µÄÐÂÕ½ÂÔ¶ÔÄ¿µÄʩѹ


2.jpg


ÀÕË÷Èí¼þÍÅ»ïClopÖ±½ÓÏòÊܺ¦ÕߵĿͻ§·¢Ë͵ç×ÓÓʼþ £¬£¬£¬£¬ £¬£¬£¬£¬Í¨ÖªÆäÊý¾ÝÒѱ»Ð¹Â¶¡£¡£¡£¡£ ¡£¡£¡£¡£ÕâÏîÐÂÕ½ÂÔÖ¼ÔÚÌá¸ßÀÕË÷µÄЧÂÊ £¬£¬£¬£¬ £¬£¬£¬£¬´Ó¶øÆÈʹĿµÄ¹«Ë¾Ö§¸¶Êê½ð¡£¡£¡£¡£ ¡£¡£¡£¡£Æ¾Ö¤BleepingComputerµÄ˵·¨ £¬£¬£¬£¬ £¬£¬£¬£¬ÐÂÕ½ÂÔµÄÊܺ¦Õß°üÀ¨Flagstar BankºÍ¿ÆÂÞÀ­¶à´óѧ¡£¡£¡£¡£ ¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬ £¬£¬£¬£¬ÆäËûÍÅ»ïÒ²ÔÚÉú³¤ÐµÄÕ½ÂÔ £¬£¬£¬£¬ £¬£¬£¬£¬REvil½üÆÚÐû²¼ËûÃÇÕýÔÚʹÓÃDDoS¹¥»÷ £¬£¬£¬£¬ £¬£¬£¬£¬²¢ÏòÊܺ¦ÕßµÄÏàÖú¹«Ë¾¼°¼ÇÕß·¢ËÍÓïÒôºô½Ð £¬£¬£¬£¬ £¬£¬£¬£¬ÒÔÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð¡£¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116029/cyber-crime/clop-ransomware-extortion.html


3.Ó¢¹ú¹«Ë¾FatFaceѬȾConti £¬£¬£¬£¬ £¬£¬£¬£¬Áè¼Ý200GBÊý¾Ýй¶


3.jpg


Ó¢¹ú´ò°ç¹«Ë¾FatFaceÔâµ½ContiÀÕË÷Èí¼þ¹¥»÷ £¬£¬£¬£¬ £¬£¬£¬£¬Áè¼Ý200GBÊý¾Ýй¶¡£¡£¡£¡£ ¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚ2021Äê1ÔÂ17ÈÕ £¬£¬£¬£¬ £¬£¬£¬£¬¹¥»÷Õß»á¼ûÁËFatFaceµÄÍøÂçºÍϵͳ £¬£¬£¬£¬ £¬£¬£¬£¬²¢ÀÕË÷850ÍòÃÀÔª £¬£¬£¬£¬ £¬£¬£¬£¬×îÖÕ¾­Ì¸ÅÐÊê½ðÈ·¶¨Îª200ÍòÃÀÔª¡£¡£¡£¡£ ¡£¡£¡£¡£´Ë´Îй¶µÄ¿Í»§ÐÅÏ¢°üÀ¨ÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢ÓʼĵصãºÍ²¿·ÖÐÅÓÿ¨ÐÅÏ¢£¨×îºóËÄλÊý×ÖºÍÓÐÓÃÆÚ£©¡£¡£¡£¡£ ¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬ £¬£¬£¬£¬¸Ã¹«Ë¾ÔÚÊý¾Ýй¶֪ͨÓʼþÖÐÒªÇóÆäÊÕ¼þÈËÎñ±Ø¶Ô´ËÓʼþ¼°ÆäÖаüÀ¨µÄÐÅÏ¢ÑϿᱣÃÜ £¬£¬£¬£¬ £¬£¬£¬£¬ÒÔ´ËÊÔͼÑÚÊÎÊý¾Ýй¶µÄÊÂʵ £¬£¬£¬£¬ £¬£¬£¬£¬´ËÊÂÎñÔÚÍøÉÏÒýÆðÐùÈ»´ó²¨¡£¡£¡£¡£ ¡£¡£¡£¡£    


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fatface-sends-controversial-data-breach-email-after-ransomware-attack/


4.Ñо¿Ö°Ô±·¢Ã÷ÒÑÒþ²Ø25ÄêµÄWindows 95¸´Éú½Ú²Êµ°


4.jpg


ijWindowsÑо¿Ö°Ô±AlbacoreÔÚInternet MailÓ¦ÓóÌÐòÖз¢Ã÷ÁËÒÑÒþ²Ø25ÄêµÄWindows 95¸´Éú½Ú²Êµ°¡£¡£¡£¡£ ¡£¡£¡£¡£¿£¿ £¿£¿ª·¢Ö°Ô±ÔÚ¿ª·¢Èí¼þʱ»áÉèÖòʵ° £¬£¬£¬£¬ £¬£¬£¬£¬Óû§Í¨¹ýÔÚ³ÌÐòÖÐÖ´ÐÐÌØ¶¨²Ù×÷À´·¢Ã÷Òþ²Ø¹¦Ð§¡¢ÐÂÎÅÉõÖÁÊÇÃÔÄãÓÎÏ·¡£¡£¡£¡£ ¡£¡£¡£¡£AlbacoreÌåÏÖ £¬£¬£¬£¬ £¬£¬£¬£¬ÒªÏë»á¼û¸´Éú½Ú²Êµ° £¬£¬£¬£¬ £¬£¬£¬£¬Ö»ÐèÒªÆô¶¯Internet Mail £¬£¬£¬£¬ £¬£¬£¬£¬µ¥»÷×ÊÖúºÍ¹ØÓÚ £¬£¬£¬£¬ £¬£¬£¬£¬ÔÚ¹ØÓڲ˵¥Öе¥»÷comctl32.dll £¬£¬£¬£¬ £¬£¬£¬£¬È»ºóÔÚ¼üÅÌÉϼüÈëMORTIMER £¬£¬£¬£¬ £¬£¬£¬£¬¾Í¿ÉÒÔ·¢Ã÷¿ª·¢Ö°Ô±Ãû³ÆµÄת¶¯Áбí¡£¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/windows-95-easter-egg-discovered-after-being-hidden-for-25-years/


5.WhiteHatÐû²¼Ó¦ÓÃÇå¾²µÄÌ¬ÊÆÆÊÎö±¨¸æ


5.jpg


WhiteHat SecurityÐû²¼ÁËÓйØÓ¦ÓÃÇå¾²µÄÌ¬ÊÆÆÊÎö±¨¸æ¡£¡£¡£¡£ ¡£¡£¡£¡£Ñо¿·¢Ã÷ £¬£¬£¬£¬ £¬£¬£¬£¬ÃæÏòWebµÄÓ¦ÓóÌÐòÈÔÈ»ÊÇ×éÖ¯ÃæÁÙµÄ×î¸ßÇ徲Σº¦Ö®Ò» £¬£¬£¬£¬ £¬£¬£¬£¬Áè¼Ý40£¥µÄÓ¦ÓÃй¶Êý¾Ý¿ÉÄÜ»á¶ÔÆóÒµ¼°ÆäÏàÖúͬ°éÔì³ÉÁ¬Ëø·´Ó¦¡£¡£¡£¡£ ¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬ £¬£¬£¬£¬ÖÆÔìÒµÌØÊâÈÝÒ×Êܵ½Õë¶ÔÓ¦ÓóÌÐòµÄ¹¥»÷ £¬£¬£¬£¬ £¬£¬£¬£¬È¥ÄêÓÐ70£¥µÄÓ¦Óñ£´æÖÁÉÙÒ»¸öÑÏÖØÎó²î¡£¡£¡£¡£ ¡£¡£¡£¡£ÆäÖÐ £¬£¬£¬£¬ £¬£¬£¬£¬ÔÚÓ¦ÓóÌÐòÖз¢Ã÷µÄǰÎå¸öÎó²î°üÀ¨ÐÅϢй¶©²»³ä·ÖµÄ»á»°ÓâÆÚ»úÖÆ¡¢XSSÎó²î¡¢´«Êä²ã±£» £» £»£»£»£»¤È±·¦ºÍÄÚÈÝÓÕÆ­Îó²î¡£¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.whitehatsec.com/appsec-stats-flash/


6.MimecastÐû²¼ÒßÇéʱ´ú¹¥»÷»î¶¯µÄÌ¬ÊÆÆÊÎö±¨¸æ


6.jpg


MimecastÐû²¼ÁËÒßÇéʱ´ú¹¥»÷»î¶¯µÄÌ¬ÊÆÆÊÎö±¨¸æ¡£¡£¡£¡£ ¡£¡£¡£¡£¸Ã±¨¸æÏêϸÏÈÈÝÁËÔÚCOVIDÊ¢ÐеĵÚÒ»Ä꣨2020Äê3ÔÂÖÁ2021Äê2Ô£©ÖÐÕë¶ÔÔ¶³ÌÊÂÇéÕߵĹ¥»÷»î¶¯¡£¡£¡£¡£ ¡£¡£¡£¡£±¨¸æÖ¸³ö £¬£¬£¬£¬ £¬£¬£¬£¬ÔÚÕâÒ»Äê¹¥»÷Á¿¼¤ÔöÁË48£¥ £¬£¬£¬£¬ £¬£¬£¬£¬ÆäÖй¥»÷µÄ·åÖµ·ºÆðÔÚ2020Äê10Ô¡£¡£¡£¡£ ¡£¡£¡£¡£ÔÚ2020Äê3Ô £¬£¬£¬£¬ £¬£¬£¬£¬¾Ó¼Ò°ì¹«Ç÷ÊÆµÄ·ºÆðµÄʱ¼ä £¬£¬£¬£¬ £¬£¬£¬£¬²»Çå¾²µÄµã»÷´ÎÊýÔöÌíÁË3±¶¡£¡£¡£¡£ ¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬ £¬£¬£¬£¬ÃÀ¹úÈË·­¿ª¿ÉÒÉÓʼþµÄ¿ÉÄÜÐÔÊÇÓ¢¹úºÍµÂ¹úÈ˵ÄÁ½±¶£» £» £»£»£»£»¹«Ë¾µÄÅÌËã»úÓÃÓÚСÎÒ˽¼ÒÓªÒµµÄʹÓÃÂÊÔöÌíÁË60£¥¡£¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.mimecast.com/resources/press-releases/dates/2021/3/the-year-of-social-distancing/