Proofpoint·¢Ã÷Õë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£´¹Âڻ

Ðû²¼Ê±¼ä 2021-12-10

GoogleÐû²¼12Ô·ݸüУ¬£¬£¬£¬ÐÞ¸´chromeÖеĶà¸öÎó²î


GoogleÐû²¼12Ô·ݸüУ¬£¬£¬£¬ÐÞ¸´chromeÖеĶà¸öÎó²î.png


GoogleÔÚ12ÔÂ6ÈÕÐû²¼chromeÇå¾²¸üУ¬£¬£¬£¬×ܼÆÐÞ¸´22¸öÎó²î¡£¡£ ¡£ÆäÖнÏΪÑÏÖØµÄÊÇWebÓ¦ÓóÌÐòÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2021-4052£©¡¢UI×é¼þÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2021-4053£©¡¢WebRTCÖеÄÔ½½çдÈëÎó²î£¨CVE-2021-4079£©ÒÔ¼°V8ÖеÄÀàÐÍ»ìÏýÎó²î£¨CVE-2021-4078£©¡£¡£ ¡£±ðµÄ£¬£¬£¬£¬»¹ÐÞ¸´ÁËÀ©Õ¹ÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2021-4055£©ºÍANGLEÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2021-4058£©µÈ¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop.html


SonicWallÐû²¼¸üУ¬£¬£¬£¬ÐÞ¸´SMA 100ϵÁÐÖжà¸öÎó²î


SonicWallÐû²¼¸üУ¬£¬£¬£¬ÐÞ¸´SMA 100ϵÁÐÖжà¸öÎó²î.png


SonicWallÔÚ12ÔÂ7ÈÕÐû²¼¸üУ¬£¬£¬£¬ÐÞ¸´SMA 100ϵÁÐ×°±¸ÖеĶà¸öÎó²î¡£¡£ ¡£´Ë´ÎÐÞ¸´µÄ×îΪÑÏÖØµÄÎó²îÊÇ»ùÓÚ¿ÍÕ»µÄ»º³åÇøÒç³öÎó²î£¨CVE-2021-20038£©£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.8£¬£¬£¬£¬ÓÉÓÚ×°±¸µÄApache httpdЧÀÍÆ÷ÖеÄHTTP GETÒªÁìµÄÇéÐαäÁ¿Ê¹ÓÃÁËstrcat()º¯Êýµ¼ÖµÄ£»£» £»£»£»£»£»Æä´ÎÊÇ»º³åÇøÒç³öÎó²î£¨CVE-2021-20045£©£¬£¬£¬£¬CVSSÆÀ·Ö9.4¡£¡£ ¡£±ðµÄ£¬£¬£¬£¬»¹ÐÞ¸´ÁË»º³åÇøÒç³öÎó²î£¨CVE-2021-20043£©ºÍÈÏÖ¤ÏÂÁî×¢ÈëÎó²î£¨CVE-2021-20039£©µÈ¡£¡£ ¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.cisa.gov/uscert/ncas/current-activity/2021/12/08/sonicwall-releases-security-advisory-sma-100-series-appliances


ÑÇÂíÑ·AWSÔÆÐ§ÀÍå´»úÓ°ÏìNetflixµÈ¶à¸öÓ¦ÓÃ


ÑÇÂíÑ·AWSÔÆÐ§ÀÍå´»úÓ°ÏìNetflixµÈ¶à¸öÓ¦ÓÃ.png


12ÔÂ7ÈÕÏÂÖç12µã×óÓÒ£¬£¬£¬£¬ÃÀ¹úUS-EAST-1ÇøÓòµÄÑÇÂíÑ·AWSÔÆÐ§ÀÍå´»ú¡£¡£ ¡£´Ë´ÎÊÂÎñÓ°ÏìÁËRing¡¢Netflix¡¢Amazon Prime Video¡¢RobinhoodºÍRokuµÈÓ¦Ó㬣¬£¬£¬ÒÔ¼°PUBG¡¢ValorantºÍÓ¢ÐÛͬÃ˵ÈÓÎÏ·¡£¡£ ¡£¸Ã¹«Ë¾ÔÚµ±Ìì12:34È·ÈÏÁËÖÐÖ¹ÊÂÎñ£¬£¬£¬£¬²¢³Æ»ù´¡Ôµ¹ÊÔ­ÓÉÊǶà¸öÍøÂç×°±¸ÊÜË𡣡£ ¡£12ÔÂ7ÈÕÏÂÖç4:35£¬£¬£¬£¬ÑÇÂíÑ·ÌåÏÖÍøÂç×°±¸ÎÊÌâÒѾ­½â¾ö£¬£¬£¬£¬ËûÃÇÕýÔÚÆð¾¢»Ö¸´ÊÜËðЧÀÍ¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/amazon-web-service-outage-impact-major-websites/


Proofpoint·¢Ã÷Õë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£´¹Âڻ


Proofpoint·¢Ã÷Õë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£´¹Âڻ.png


Proofpoint¹ûÕæÁ˽üÆÚ´ó¹æÄ£´¹ÂڻÖÐʹÓõÄÕ½ÂÔ¡¢ÊÖÒպͳÌÐò(TTP)µÄÏêϸÐÅÏ¢¡£¡£ ¡£´Ë´Î»î¶¯×îÏÈÓÚ½ñÄê10Ô·Ý£¬£¬£¬£¬À´×Ô¶à¸öºÚ¿ÍÍŻ£¬£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹úµÄ´óѧ¡£¡£ ¡£ÕâЩ¹¥»÷ͨ¹ýÒÔOmicron±äÌå¡¢COVID-19²âÊÔЧ¹ûºÍÆäËü²âÊÔÒªÇóΪÖ÷ÌâµÄ´¹ÂÚÓʼþ£¬£¬£¬£¬ÓÕʹĿµÄ·­¿ª¸½¼þÖеÄHTMÎļþ£¬£¬£¬£¬²¢½«ÆäÖØ¶¨Ïòµ½Î±×°³ÉËûÃÇ´óѧµÇÂ¼ÍøÕ¾µÄ´¹ÂÚÒ³Ãæ£¬£¬£¬£¬Ö¼ÔÚÇÔÊØÐÅÏ¢¡£¡£ ¡£ÎªÁËÈÆ¹ýMFA±£»£» £»£»£»£»£»¤£¬£¬£¬£¬¹¥»÷Õß»¹½¨ÉèÁËαÔìµÄDUO MFAÍøÕ¾ÒÔÇÔÈ¡Óû§µÄOTP¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-universities-targeted-by-office-365-phishing-attacks/


QNAPÌáÐѿͻ§×¢ÖؽüÆÚÕë¶ÔÆäNAS×°±¸µÄÍÚ¿ó»î¶¯


QNAPÌáÐѿͻ§×¢ÖؽüÆÚÕë¶ÔÆäNAS×°±¸µÄÍÚ¿ó»î¶¯.png


Öйų́ÍåµÄNAS×°±¸ÖÆÔìÉÌQNAPÔÚ12ÔÂ7ÈÕÐû²¼Í¨¸æ£¬£¬£¬£¬ÌáÐÑÓû§×¢ÖؽüÆÚµÄ¶ñÒâÍÚ¿ó»î¶¯¡£¡£ ¡£Í¨¸æ³Æ£¬£¬£¬£¬´Ë´Î»î¶¯Ãé×¼ÁËQNAP NAS¡£¡£ ¡£Ò»µ©NAS±»Ñ¬È¾£¬£¬£¬£¬CPUʹÓÃÂÊ»á±äµÃÒì³£¸ß£¬£¬£¬£¬ÆäÖÐÃûΪ¡°[oom_reaper]¡±µÄÀú³Ì¿ÉÄÜ»áÕ¼ÓÃ×ÜCPUʹÓÃÂʵÄ50%×óÓÒ¡£¡£ ¡£Õâ¸öÀú³ÌÄ£ÄâÁËÒ»¸öÕýµ±µÄͬÃûÄÚºËÀú³Ì£¬£¬£¬£¬¿ÉÊÇÕý³£ÄÚºËÀú³ÌPIDͨ³£µÍÓÚ1000£¬£¬£¬£¬¶ø¸Ã¿ó¹¤PIDͨ³£´óÓÚ1000¡£¡£ ¡£QNAP½¨ÒéÓû§½«QTS¸üе½×îа汾£¬£¬£¬£¬²¢Ê¹ÓÃÇ¿ÃÜÂë¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/12/warning-yet-another-bitcoin-mining.html


ÐÂÀÕË÷Èí¼þCerberÃé×¼ConfluenceºÍGitLabЧÀÍÆ÷


ÐÂÀÕË÷Èí¼þCerberÃé×¼ConfluenceºÍGitLabЧÀÍÆ÷.png


12ÔÂ7ÈÕ£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ʹÓÃÁ˾ÉÃû³ÆµÄÐÂÀÕË÷Èí¼þCerber¡£¡£ ¡£ÀÕË÷Èí¼þCerberÓÚ2016Äê·ºÆð£¬£¬£¬£¬Ö±µ½2019Äêµ×ÏûÊÅ¡£¡£ ¡£´ÓÉϸöÔÂ×îÏÈ£¬£¬£¬£¬Cerbe»Ø¹é£¬£¬£¬£¬¿ÉÊÇËüÓë¾É°æ²¢²»Ïàͬ£¬£¬£¬£¬´úÂ벻ƥÅ䣬£¬£¬£¬Ð°æÊ¹ÓÃCrypto+++¿â¶ø¾É°æ±¾Ê¹ÓÃWindows CryptoAPI¿â£¬£¬£¬£¬²¢ÇҾɰæCerberҲûÓÐLinux±äÌå¡£¡£ ¡£ÐÂCerberµÄÊê½ðÒªÇó´Ó1000ÃÀÔªµ½3000ÃÀÔª²»µÈ£¬£¬£¬£¬Ê¹ÓÃÁËCVE-2021-26084ºÍCVE-2021-22205Îó²îÃé×¼ConfluenceºÍGitLabЧÀÍÆ÷£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹ú¡¢µÂ¹úºÍÖйú¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-cerber-ransomware-targets-confluence-and-gitlab-servers/