Adobe½ôÆÈ¸üУ¬£¬£¬£¬ÐÞ¸´ColdFusioní§Òâ´úÂëÖ´ÐÐÎó²î£»£»£»£»£»McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetopVisionProÖжà¸öÎó²î
Ðû²¼Ê±¼ä 2021-03-231.AdobeÐû²¼½ôÆÈ¸üУ¬£¬£¬£¬ÐÞ¸´ColdFusionÖÐí§Òâ´úÂëÖ´ÐÐÎó²î

AdobeÓÚ3ÔÂ22ÈÕÐû²¼½ôÆÈ´øÍâ¸üУ¬£¬£¬£¬ÐÞ¸´ColdFusionÖеÄí§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£¸ÃÎó²îÊÇÓÉÓÚÎÞ·¨ÑéÖ¤ÊäÈëµ¼Öµģ¬£¬£¬£¬±»¸ú×ÙΪCVE-2021-21087£¬£¬£¬£¬Ó°ÏìÁËColdFusion°æ±¾2021¡¢2016ºÍ2018¡£¡£Adobe½¨ÒéÖÎÀíÔ±¾¡¿ì×°ÖÃÇå¾²¸üУ¬£¬£¬£¬²¢Ó¦Óùٷ½Ö¸ÄÏÖÐÐÎòµÄÇå¾²ÉèÖÃ¶ÔÆä¾ÙÐÐÉèÖᣡ£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/critical-code-execution-vulnerability-fixed-in-adobe-coldfusion/
2.McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetop Vision Pro±£´æ¶à¸öÎó²î

McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetop Vision Pro±£´æ¶à¸ö¿ÉÓÃÀ´Ð®ÖÆÄ¿µÄµçÄÔµÄÎó²î¡£¡£ÕâЩÎó²î»®·ÖΪȨÏÞ·ÖÅÉÎó²î£¨CVE-2021-27192£©¡¢Ä¬ÈÏȨÏÞ¹ýʧ£¨CVE-2021-27193£©¡¢ÒÔÃ÷ÎÄ´«ÊäµÄÃô¸ÐÐÅÏ¢£¨CVE-2021-27194£©ºÍÊÚȨÎÊÌ⣨CVE-2021-27195£©¡£¡£ºÚ¿Í¿ÉÓÃÕâЩÎó²î¾ÙÐÐÌáȨºÍÖ´ÐÐÔ¶³Ì´úÂ룬£¬£¬£¬»ñµÃ¶ÔÄ¿µÄϵͳµÄÍêÈ«¿ØÖÆÈ¨²¢ÆôÓÃÍøÂçÉãÏñÍ·ºÍÂó¿Ë·ç¡£¡£ÏÖÔÚ£¬£¬£¬£¬NetopÒÑÐÞ¸´²¿·ÖÎó²î¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/popular-remote-student-learning-program-found-to-be-riddled-with-security-holes/
3.µçÁ¦¹«Ë¾Celg GTÕû¸öÍøÂçÎÞ·¨»á¼û£¬£¬£¬£¬ÊÂÎñÈÔÔÚÊÓ²ìÖÐ

CelgGera??oeTransmiss?o£¨Celg GT£©ÓÚÉÏÖÜÎå(3ÔÂ19ÈÕ)³ÆÆäÔâµ½Á˹¥»÷£¬£¬£¬£¬ËùÓеÄÓ¦ÓóÌÐòºÍÕû¸öÎļþϵͳ¶¼ÎÞ·¨»á¼û¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬¹¥»÷ÊÇ´ÓÆÆÏþ×îÏȵ쬣¬£¬£¬Æä·¢Ã÷ºóÁ¬Ã¦½ÓÄÉÏìÓ¦²½·¥£¬£¬£¬£¬¹Ø±ÕϵͳÒÔ±£»£»£»£»£»¤ÐÅÏ¢ºÍ±¸·Ý×ÊÁÏ¡£¡£ÏÖÔÚ£¬£¬£¬£¬¸ÃÊÂÎñÈÔÔÚÊÓ²ìÖУ¬£¬£¬£¬Éв»¿ÉÈ·¶¨ÏµÍ³Ë𻵵ÄˮƽÒÔ¼°¹¥»÷µÄȪԴ£¬£¬£¬£¬¿ÉÊÇ¿ÉÒÔÈ·¶¨Ã»ÓÐÈκÎСÎÒ˽¼ÒÐÅÏ¢±»Ð¹Â¶£¬£¬£¬£¬¹«Ë¾Ô±¹¤µÄµç×ÓÓʼþЧÀÍÒ²¿ÉÒÔÕý³£ÔËÐС£¡£
ÔÎÄÁ´½Ó£º
https://www.jornalopcao.com.br/ultimas-noticias/ataque-hacker-compromete-funcionamento-de-aplicativos-e-arquivos-da-celg-gt-318176/
4.²®Ã÷º²Òé»áÔ±¹¤Òò²Ù×÷ʧÎó¹ûÕæ´ó×ÚÈõÊÆÈºÌåµÄСÎÒ˽¼ÒÐÅÏ¢

²®Ã÷º²Òé»áÔÚ3ÔÂ19ÈÕÐÇÆÚÎ峯£¬£¬£¬£¬ÒòÔ±¹¤²Ù×÷ʧÎóµ¼Ö´ó×ÚÈõÊÆÈºÌåµÄСÎÒ˽¼ÒÐÅÏ¢±»¹ûÕæ¡£¡£¾Ý³Æ´Ë´Îй¶µÄÊÇÓÐȨ»ñµÃÃâ·Ñ°ÍʿͨÐÐÖ¤µÄ¶ùͯµÄÏêϸÐÅÏ¢¡£¡£¸ÃÊÐÌåÏÖ£¬£¬£¬£¬ÆäÔÚ·¢Ã÷й¶ºóÁ¬Ã¦½ÓÄÉÁ˲½·¥£¬£¬£¬£¬Êý¾Ý»¹Î´±»ÏÂÔØ£¬£¬£¬£¬²¢ÇÒÓÉÓÚ´ËÊÂÎñµÄ¹æÄ£ºÍÑÏÖØÐÔ×Ó£¬£¬£¬£¬ÏÖÒÑ֪ͨÈÏÕæ¼àÊÓµÄÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©¡£¡£
ÔÎÄÁ´½Ó£º
https://www.birminghammail.co.uk/news/midlands-news/details-vulnerable-kids-uploaded-birmingham-20217314
5.Black KiteÐû²¼Îó²î¶ÔÐÅÓÃÏàÖúÉçµÄÓ°ÏìµÄÆÊÎö±¨¸æ

Black KiteÐû²¼ÁËÓйØÎó²î¶ÔÐÅÓÃÏàÖúÉçµÄÓ°ÏìµÄÆÊÎö±¨¸æ¡£¡£±¨¸æÏÔʾ£¬£¬£¬£¬Æ¾Ö¤Ð¹Â¶¡¢Î´¸üеľÉϵͳºÍ¹©Ó¦ÉÌÎó²îÊÇÐÅÓÃÏàÖúÉçËùÃæÁÙµÄ×î´óµÄÍøÂçΣº¦¡£¡£±ðµÄ£¬£¬£¬£¬Õë¶Ô¹©Ó¦É̵Ĺ¥»÷ΪÐÅÓÃÏàÖúÉç¿ÉÄÜ»áÔì³ÉÁè¼Ý100ÍòÃÀÔªµÄDZÔÚ²ÆÎïËðʧ£»£»£»£»£»86%µÄÐÅÓÃÏàÖúÉçºÍ76%µÄ¹©Ó¦É̵ÄÔ±¹¤Æ¾Ö¤Òѱ»ÇÔÈ¡²¢¹ûÕæµ½°µÍøÉÏ£»£»£»£»£»Áè¼Ý66%µÄÐÅÓÃÏàÖúÉçºÍ88%µÄ¹©Ó¦ÉÌȱ·¦Ô¤·ÀÓÕÆºÍ´¹ÂÚ¹¥»÷µÄµç×ÓÓʼþÇå¾²Õ½ÂÔ¡£¡£
ÔÎÄÁ´½Ó£º
https://googleprojectzero.blogspot.com/2021/03/in-wild-series-october-2020-0-day.html
6.VectraÐû²¼ÓйØOffice 365ºÍÔÆµÄÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ

VectraÐû²¼ÁËÓйØOffice 365ºÍÔÆµÄÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£±¨¸æÏÔʾ£¬£¬£¬£¬ÔÚÒÑÍùÒ»Ä꣬£¬£¬£¬Ö»¹Ü½ÓÄÉÁ˶àÒòËØÉí·ÝÑéÖ¤£¨MFA£©£¬£¬£¬£¬µ«ÈÔÓÐ71£¥µÄÆóÒµÈÔÈ»ÂÄÀú¹ýSaaSÕÊ»§Ð®ÖÆ£¬£¬£¬£¬½ü90£¥µÄÆóÒµ»¹ÔÚ¼ÓËÙÔÆÅÌËãºÍÊý×Ö»¯µÄתÐÍ¡£¡£±ðµÄ£¬£¬£¬£¬¸Ã±¨¸æÔÚ90ÌìÄÚ¸ú×ÙÁË400Íò¸öMicrosoft Office 365¿Í»§µÄÐÐΪ£¬£¬£¬£¬·¢Ã÷ÓÐ96£¥µÄÄÚÍø±£´æ¿ÉÒɵĺáÏòÒÆ¶¯ÐÐΪ¡£¡£Îå·ÖÖ®ËĵÄÇ徲רҵְԱÌåÏÖ£¬£¬£¬£¬ÔÚÒÑÍùÒ»ÄêÖÐÍøÂçÇå¾²µÄΣº¦ÓÐËùÔöÌí¡£¡£
ÔÎÄÁ´½Ó£º
https://www.vectra.ai/blogpost/cloud-security-insights


¾©¹«Íø°²±¸11010802024551ºÅ