IntelµÄHabana LabsѬȾPay2Key£¬ £¬£¬£¬£¬ÉÌÒµÎĵµºÍÔ´´úÂë±»µÁ£»£»£»AdobeÐû²¼Flash Player×îÖÕ¸üÐÂ

Ðû²¼Ê±¼ä 2020-12-14
1.IntelµÄHabana LabsѬȾPay2Key£¬ £¬£¬£¬£¬ÉÌÒµÎĵµºÍÔ´´úÂë±»µÁ


1.jpg


IntelµÄAI´¦Öóͷ£Æ÷¿ª·¢ÉÌHabana LabsÔâµ½ÁËPay2KeyÀÕË÷Èí¼þ¹¥»÷£¬ £¬£¬£¬£¬ÉÌÒµÎĵµºÍÔ´´úÂë±»µÁ¡£¡£¡£¡£¡£¡£Habana LabsÊÇÒÔÉ«ÁÐAI´¦Öóͷ£Æ÷µÄ¿ª·¢ÉÌ£¬ £¬£¬£¬£¬ÓÚ2019Äê12ÔÂÒÔ20ÒÚÃÀÔªµÄ¼ÛÇ®±»IntelÊÕ¹º¡£¡£¡£¡£¡£¡£Pay2KeyÔÚTwitterÉÏÐû²¼Á˴˴ι¥»÷£¬ £¬£¬£¬£¬²¢Éù³ÆÒÑÇÔÈ¡ÁËÓйØÈ˹¤ÖÇÄÜоƬ´úÂëGaudiµÄÐÅÏ¢Êý¾Ý¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ÉϹûÕæÁ˸ù«Ë¾µÄÔ´´úÂëºÍÄÚ²¿Àú³ÌµÄͼƬ£¬ £¬£¬£¬£¬ÒÔ¼°WindowsÓò¿ØÖÆÆ÷Êý¾ÝºÍGerrit¿ª·¢´úÂë¼ì²éϵͳµÄÎļþÁÐ±í¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/112258/data-breach/pay2key-hacked-habana-labs.html


2.AdobeÐû²¼Flash Player×îÖÕ¸üУ¬ £¬£¬£¬£¬2021Ä꽫ÖÕÖ¹¸üÐÂ


2.jpg


AdobeÐû²¼Flash Player×îÖÕ¸üУ¬ £¬£¬£¬£¬²¢Ðû²¼½«ÓÚ2021ÄêÖÕÖ¹¸üС£¡£¡£¡£¡£¡£µÚÒ»°æAdobe Flash PlayerÓÚ1996Äê1ÔÂÐû²¼£¬ £¬£¬£¬£¬¾­ÓÉ24ÄêµÄʹÓúͺڿ͵ÄÀÄÓ㬠£¬£¬£¬£¬Adobe½«Ðû²¼Flash PlayerµÄ×îÖÕ¸üв¢×èֹά»¤¡£¡£¡£¡£¡£¡£´Ó2021Äê1ÔÂ×îÏÈ£¬ £¬£¬£¬£¬ËùÓÐä¯ÀÀÆ÷µÄ¿ª·¢Õߣ¬ £¬£¬£¬£¬°üÀ¨¹È¸èChrome¡¢Safari¡¢Mozilla Firefox¡¢Microsoft Edge¡¢Internet Explorer 11ºÍÆäËû»ùÓÚChromeµÄä¯ÀÀÆ÷£¬ £¬£¬£¬£¬¶¼½«°ÑAdobe Flash´ÓËûÃǵÄä¯ÀÀÆ÷ÖÐÍêÈ«ÒÆ³ý¡£¡£¡£¡£¡£¡£ÇÒÒ»µ©ÒƳýºó£¬ £¬£¬£¬£¬½«Ã»Óв½·¥ÔÙ¾ÙÐÐ×°Öᣡ£¡£¡£¡£¡£    


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/software/adobe-releases-final-flash-player-update-warns-of-2021-kill-switch/


3.NI CompactRIO¿ØÖÆÆ÷±£´æ¿Éµ¼ÖÂÆóÒµÉú²úÖÐÖ¹µÄÎó²î


3.jpg


National Instruments£¨NI£©CompactRIO¿ØÖÆÆ÷±£´æÑÏÖØµÄÎó²î£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õ߯ÆËð×éÖ¯ÖеÄÉú²úÀú³Ì¡£¡£¡£¡£¡£¡£¸ÃÎó²î±»×·×ÙΪCVE-2020-25191£¬ £¬£¬£¬£¬ÊÇÓÉÓÚÒªº¦×ÊÔ´µÄȨÏÞ·ÖÅɲ»×¼È·£¬ £¬£¬£¬£¬ÎªÌض¨Ð§À͵ÄAPIÈë¿ÚµãÉèÖÃÁ˹ýʧµÄȨÏÞËùµ¼Ö¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÀÖ³ÉʹÓôËÎó²îºó¿ÉÒÔÔ¶³ÌÖØÐÂÆô¶¯×°±¸£¬ £¬£¬£¬£¬ÒÔÖÐÖ¹×éÖ¯µÄÉú²úÀú³Ì¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬ £¬£¬£¬£¬CISAÐû²¼ÁËÇ徲ͨ¸æÒÔÖÒÑÔ×é֝ע֨¸ÃÎó²î£¬ £¬£¬£¬£¬²¢Ìá³öÁË»º½â²½·¥¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/112228/ics-scada/ni-compactrio-flaw.html


4.GlassdoorÍøÕ¾±£´æ¿Éµ¼ÖÂÕË»§±»½ÓÊܵÄCSRFÎó²î


4.jpg


ÇóÖ°ÍøÕ¾Glassdoor±£´æÑÏÖØµÄCSRFÎó²î£¬ £¬£¬£¬£¬¿Éµ¼ÖÂÕË»§±»½ÓÊÜ¡£¡£¡£¡£¡£¡£¸Ãƽ̨ʹÓÃÁËgdTokenÁîÅÆÓÃÓÚ±ÜÃâCSRF¹¥»÷£¬ £¬£¬£¬£¬µ«Ñо¿Ö°Ô±Tabahi·¢Ã÷ÆäÒÀÈ»±£´æÎó²î¡£¡£¡£¡£¡£¡£Tabahi´ÓAÕÊ»§ÌìÉúCSRFÁîÅÆ£¬ £¬£¬£¬£¬È¥µôµÚÒ»¸ö×Ö·ûºóʵÑéʹ֮×÷ΪBÕÊ»§µÄÁîÅÆ£¬ £¬£¬£¬£¬Ð§¹û֤ʵÊÇÀֳɵġ£¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁËGlassdoor webÓò£¬ £¬£¬£¬£¬GlassdoorÇå¾²ÍŶӽ«Æä¹éÀàΪÁîÅÆ³¤¶ÈÑéÖ¤¹ýʧ£¬ £¬£¬£¬£¬²¢ÇÒ»¹±£´æÒì³£´¦Öóͷ£ÎÊÌâ¡£¡£¡£¡£¡£¡£ÇóÖ°Õߺ͹ÍÖ÷µÄÕÊ»§¾ù»áÊܵ½¸ÃÎó²îµÄÓ°Ïì¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/cross-site-request-forgery-vulnerability-found-on-glassdoor-job-hunter-review-platform/


5.а汾µÄÀÕË÷Èí¼þMountLocker¾Þϸ½öΪ46KB


5.jpg


Ñо¿Ö°Ô±ÔÚÒ°Íâ·¢Ã÷ÁËа汾µÄÀÕË÷Èí¼þMountLocker¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þµÄ¿ª·¢Ö°Ô±½«64λµÄ±äÌåËõСµ½46KB£¬ £¬£¬£¬£¬±ÈÒÔǰµÄ°æ±¾Ð¡50£¥¡£¡£¡£¡£¡£¡£Îª´Ë£¬ £¬£¬£¬£¬ËûÃÇɾ³ýÁËÎļþÀ©Õ¹ÃûÁбí£¬ £¬£¬£¬£¬ÆäÖаüÀ¨2600¶à¸öÓÃÓÚ¼ÓÃܵÄÌõÄ¿¡£¡£¡£¡£¡£¡£¸ÃÍŻﻹÌí¼ÓÁËÓëTurboTaxÈí¼þ¹ØÁªµÄÎļþÀ©Õ¹Ãû£¨.tax¡¢.tax2009¡¢.tax2013ºÍ.tax2014£©£¬ £¬£¬£¬£¬ÒÔÃé×¼ÏÂÒ»ÄÉ˰¼¾¡£¡£¡£¡£¡£¡£¸ÃбäÌåÒÀȻʹÓÃÁ˲»Çå¾²µÄWindows APIº¯ÊýGetTickCountÀ´ÌìÉúËæ»ú¼ÓÃÜÃÜÔ¿£¬ £¬£¬£¬£¬¿ÉÄܱ»ÓÃÀ´¾ÙÐб©Á¦¹¥»÷¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/mountlocker-ransomware-gets-slimmer-now-encrypts-fewer-files/


6.CrowdStrikeÐû²¼2020ÄêËê¼þÏìÓ¦ºÍ×Ô¶¯Ð§ÀÍÆÊÎö±¨¸æ


6.jpg


CrowdStrikeÐû²¼ÁË2020ÄêËê¼þÏìÓ¦ºÍ×Ô¶¯Ð§ÀÍÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬ £¬£¬£¬£¬68£¥µÄÊܺ¦×éÖ¯ÔÚÒ»ÄêÄÚ½«ÔâÊܵڶþ´Î¹¥»÷¡£¡£¡£¡£¡£¡£ÔÚ³öÓÚ²ÆÎñÄîÍ·µÄÍøÂç¹¥»÷ÖУ¬ £¬£¬£¬£¬81£¥µÄÊÂÎñÓëÀÕË÷Èí¼þÓйØ£¬ £¬£¬£¬£¬ÆäÓàµÄ19£¥·ÖΪÏúÊÛµãÈëÇÖ¡¢µç×ÓÉÌÎñÍøÕ¾¹¥»÷¡¢ÉÌÒµµç×ÓÓʼþй¶£¨BEC£©ºÍ¼ÓÃÜÇ®±ÒÍڿ󡣡£¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬£¬Óë¹ú¼ÒÓйصĹ¥»÷»î¶¯ÈÔÈ»ÊǸ÷Ðи÷ÒµµÄÑÏÖØÍþв¡£¡£¡£¡£¡£¡£CrowdStrikeµÄCSO Shawn HenryÖ¸³ö£¬ £¬£¬£¬£¬Ô¶³ÌÊÂÇéΪ¹¥»÷ÕßÌṩÁËÐµĹ¥»÷ÃæºÍǰÑÔ£¬ £¬£¬£¬£¬¶øÖÜÈ«µÄЭЭµ÷Ò»Á¬µÄСÐÄÊÇ·¢Ã÷ºÍ×èÖ¹ÖØ´óÈëÇÖµÄÒªº¦¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.crowdstrike.com/resources/reports/cyber-front-lines/