Proofpoint·¢Ã÷Õë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£´¹Âڻ

Ðû²¼Ê±¼ä 2021-12-10

GoogleÐû²¼12Ô·ݸüР£¬£¬£¬£¬£¬£¬ÐÞ¸´chromeÖеĶà¸öÎó²î


GoogleÐû²¼12Ô·ݸüÐÂ£¬£¬£¬£¬£¬£¬ÐÞ¸´chromeÖеĶà¸öÎó²î.png


GoogleÔÚ12ÔÂ6ÈÕÐû²¼chromeÇå¾²¸üР£¬£¬£¬£¬£¬£¬×ܼÆÐÞ¸´22¸öÎó²î¡£¡£¡£¡£¡£ÆäÖнÏΪÑÏÖØµÄÊÇWebÓ¦ÓóÌÐòÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2021-4052£©¡¢UI×é¼þÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2021-4053£©¡¢WebRTCÖеÄÔ½½çдÈëÎó²î£¨CVE-2021-4079£©ÒÔ¼°V8ÖеÄÀàÐÍ»ìÏýÎó²î£¨CVE-2021-4078£©¡£¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬£¬£¬»¹ÐÞ¸´ÁËÀ©Õ¹ÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2021-4055£©ºÍANGLEÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2021-4058£©µÈ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop.html


SonicWallÐû²¼¸üР£¬£¬£¬£¬£¬£¬ÐÞ¸´SMA 100ϵÁÐÖжà¸öÎó²î


SonicWallÐû²¼¸üÐÂ£¬£¬£¬£¬£¬£¬ÐÞ¸´SMA 100ϵÁÐÖжà¸öÎó²î.png


SonicWallÔÚ12ÔÂ7ÈÕÐû²¼¸üР£¬£¬£¬£¬£¬£¬ÐÞ¸´SMA 100ϵÁÐ×°±¸ÖеĶà¸öÎó²î¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄ×îΪÑÏÖØµÄÎó²îÊÇ»ùÓÚ¿ÍÕ»µÄ»º³åÇøÒç³öÎó²î£¨CVE-2021-20038£© £¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.8 £¬£¬£¬£¬£¬£¬ÓÉÓÚ×°±¸µÄApache httpdЧÀÍÆ÷ÖеÄHTTP GETÒªÁìµÄÇéÐαäÁ¿Ê¹ÓÃÁËstrcat()º¯Êýµ¼Öµģ»£» £»£»£»£»Æä´ÎÊÇ»º³åÇøÒç³öÎó²î£¨CVE-2021-20045£© £¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö9.4¡£¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬£¬£¬»¹ÐÞ¸´ÁË»º³åÇøÒç³öÎó²î£¨CVE-2021-20043£©ºÍÈÏÖ¤ÏÂÁî×¢ÈëÎó²î£¨CVE-2021-20039£©µÈ¡£¡£¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.cisa.gov/uscert/ncas/current-activity/2021/12/08/sonicwall-releases-security-advisory-sma-100-series-appliances


ÑÇÂíÑ·AWSÔÆÐ§ÀÍå´»úÓ°ÏìNetflixµÈ¶à¸öÓ¦ÓÃ


ÑÇÂíÑ·AWSÔÆÐ§ÀÍå´»úÓ°ÏìNetflixµÈ¶à¸öÓ¦ÓÃ.png


12ÔÂ7ÈÕÏÂÖç12µã×óÓÒ £¬£¬£¬£¬£¬£¬ÃÀ¹úUS-EAST-1ÇøÓòµÄÑÇÂíÑ·AWSÔÆÐ§ÀÍå´»ú¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñÓ°ÏìÁËRing¡¢Netflix¡¢Amazon Prime Video¡¢RobinhoodºÍRokuµÈÓ¦Óà £¬£¬£¬£¬£¬£¬ÒÔ¼°PUBG¡¢ValorantºÍÓ¢ÐÛͬÃ˵ÈÓÎÏ·¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚµ±Ìì12:34È·ÈÏÁËÖÐÖ¹ÊÂÎñ £¬£¬£¬£¬£¬£¬²¢³Æ»ù´¡Ôµ¹ÊÔ­ÓÉÊǶà¸öÍøÂç×°±¸ÊÜË𡣡£¡£¡£¡£12ÔÂ7ÈÕÏÂÖç4:35 £¬£¬£¬£¬£¬£¬ÑÇÂíÑ·ÌåÏÖÍøÂç×°±¸ÎÊÌâÒѾ­½â¾ö £¬£¬£¬£¬£¬£¬ËûÃÇÕýÔÚÆð¾¢»Ö¸´ÊÜËðЧÀÍ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/amazon-web-service-outage-impact-major-websites/


Proofpoint·¢Ã÷Õë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£´¹Âڻ


Proofpoint·¢Ã÷Õë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£´¹Âڻ.png


Proofpoint¹ûÕæÁ˽üÆÚ´ó¹æÄ£´¹ÂڻÖÐʹÓõÄÕ½ÂÔ¡¢ÊÖÒպͳÌÐò(TTP)µÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£´Ë´Î»î¶¯×îÏÈÓÚ½ñÄê10ÔÂ·Ý £¬£¬£¬£¬£¬£¬À´×Ô¶à¸öºÚ¿ÍÍÅ»ï £¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹úµÄ´óѧ¡£¡£¡£¡£¡£ÕâЩ¹¥»÷ͨ¹ýÒÔOmicron±äÌå¡¢COVID-19²âÊÔЧ¹ûºÍÆäËü²âÊÔÒªÇóΪÖ÷ÌâµÄ´¹ÂÚÓʼþ £¬£¬£¬£¬£¬£¬ÓÕʹĿµÄ·­¿ª¸½¼þÖеÄHTMÎļþ £¬£¬£¬£¬£¬£¬²¢½«ÆäÖØ¶¨Ïòµ½Î±×°³ÉËûÃÇ´óѧµÇÂ¼ÍøÕ¾µÄ´¹ÂÚÒ³Ãæ £¬£¬£¬£¬£¬£¬Ö¼ÔÚÇÔÊØÐÅÏ¢¡£¡£¡£¡£¡£ÎªÁËÈÆ¹ýMFA±£»£» £»£»£»£»¤ £¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹½¨ÉèÁËαÔìµÄDUO MFAÍøÕ¾ÒÔÇÔÈ¡Óû§µÄOTP¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-universities-targeted-by-office-365-phishing-attacks/


QNAPÌáÐѿͻ§×¢ÖؽüÆÚÕë¶ÔÆäNAS×°±¸µÄÍÚ¿ó»î¶¯


QNAPÌáÐѿͻ§×¢ÖؽüÆÚÕë¶ÔÆäNAS×°±¸µÄÍÚ¿ó»î¶¯.png


Öйų́ÍåµÄNAS×°±¸ÖÆÔìÉÌQNAPÔÚ12ÔÂ7ÈÕÐû²¼Í¨¸æ £¬£¬£¬£¬£¬£¬ÌáÐÑÓû§×¢ÖؽüÆÚµÄ¶ñÒâÍÚ¿ó»î¶¯¡£¡£¡£¡£¡£Í¨¸æ³Æ £¬£¬£¬£¬£¬£¬´Ë´Î»î¶¯Ãé×¼ÁËQNAP NAS¡£¡£¡£¡£¡£Ò»µ©NAS±»Ñ¬È¾ £¬£¬£¬£¬£¬£¬CPUʹÓÃÂÊ»á±äµÃÒì³£¸ß £¬£¬£¬£¬£¬£¬ÆäÖÐÃûΪ¡°[oom_reaper]¡±µÄÀú³Ì¿ÉÄÜ»áÕ¼ÓÃ×ÜCPUʹÓÃÂʵÄ50%×óÓÒ¡£¡£¡£¡£¡£Õâ¸öÀú³ÌÄ£ÄâÁËÒ»¸öÕýµ±µÄͬÃûÄÚºËÀú³Ì £¬£¬£¬£¬£¬£¬¿ÉÊÇÕý³£ÄÚºËÀú³ÌPIDͨ³£µÍÓÚ1000 £¬£¬£¬£¬£¬£¬¶ø¸Ã¿ó¹¤PIDͨ³£´óÓÚ1000¡£¡£¡£¡£¡£QNAP½¨ÒéÓû§½«QTS¸üе½×îа汾 £¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃÇ¿ÃÜÂë¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/12/warning-yet-another-bitcoin-mining.html


ÐÂÀÕË÷Èí¼þCerberÃé×¼ConfluenceºÍGitLabЧÀÍÆ÷


ÐÂÀÕË÷Èí¼þCerberÃé×¼ConfluenceºÍGitLabЧÀÍÆ÷.png


12ÔÂ7ÈÕ £¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ʹÓÃÁ˾ÉÃû³ÆµÄÐÂÀÕË÷Èí¼þCerber¡£¡£¡£¡£¡£ÀÕË÷Èí¼þCerberÓÚ2016Äê·ºÆð £¬£¬£¬£¬£¬£¬Ö±µ½2019Äêµ×ÏûÊÅ¡£¡£¡£¡£¡£´ÓÉϸöÔÂ×îÏÈ £¬£¬£¬£¬£¬£¬Cerbe»Ø¹é £¬£¬£¬£¬£¬£¬¿ÉÊÇËüÓë¾É°æ²¢²»Ïàͬ £¬£¬£¬£¬£¬£¬´úÂ벻ƥÅä £¬£¬£¬£¬£¬£¬Ð°æÊ¹ÓÃCrypto+++¿â¶ø¾É°æ±¾Ê¹ÓÃWindows CryptoAPI¿â £¬£¬£¬£¬£¬£¬²¢ÇҾɰæCerberҲûÓÐLinux±äÌå¡£¡£¡£¡£¡£ÐÂCerberµÄÊê½ðÒªÇó´Ó1000ÃÀÔªµ½3000ÃÀÔª²»µÈ £¬£¬£¬£¬£¬£¬Ê¹ÓÃÁËCVE-2021-26084ºÍCVE-2021-22205Îó²îÃé×¼ConfluenceºÍGitLabЧÀÍÆ÷ £¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹ú¡¢µÂ¹úºÍÖйú¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-cerber-ransomware-targets-confluence-and-gitlab-servers/