Å·ÖÞEDP??BÐû²¼ÓйØÊý¾Ýй¶֪ͨʾÀýµÄÖ¸ÄÏ£»£»£»ºÚ¿Í¹ûÕæNitro PDFµÄ14GBÊý¾Ý£¬£¬£¬£¬£¬Éæ¼°7700Íò¸öÓû§

Ðû²¼Ê±¼ä 2021-01-22
1.Å·ÖÞEDPBÐû²¼ÓйØÊý¾Ýй¶֪ͨʾÀýµÄÖ¸ÄÏ


1.jpg


2021Äê1ÔÂ18ÈÕ£¬£¬£¬£¬£¬Å·ÖÞÊý¾Ý±£»£»£»¤Î¯Ô±»á£¨EDPB£©Ðû²¼ÁËÓйØÊý¾Ýй¶֪ͨʾÀýÖ¸ÄϵIJݰ¸¡£¡£¡£¡£¡£¡£¸Ã²Ý°¸Ë¼Á¿ÁË×ÔGDPR 2018Äê5ÔÂî¿Ïµ»ú¹¹ÒÔÀ´ÔÚÊý¾Ýй¶·½ÃæµÄ³£¼ûÂÄÀú£¬£¬£¬£¬£¬°üÀ¨Ò»Ð©³£¼ûµÄÊý¾Ýй¶³¡¾°µÄʾÀý£¬£¬£¬£¬£¬ÈçÀÕË÷Èí¼þ¹¥»÷¡¢Îó²î¹¥»÷¡¢ÈËΪ¹ýʧ¡¢×°±¸ºÍÖ½ÖÊÎļþɥʧºÍÉç»á¹¤³ÌµÈ¡£¡£¡£¡£¡£¡£¸ÃÖ¸ÄÏ»¹»ØÊ×ÁË×é֯Ӧ˼Á¿µÄ¼¸¸öÒªº¦ÒòËØ£¬£¬£¬£¬£¬°üÀ¨×Ô¶¯Ê¶±ðϵͳÎó²î¡¢ÆÀ¹Àй¶Σº¦ÒÔ¼°¼Í¼ÿÖÖÇéÐÎϵÄй¶ÊÂÎñµÈ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.huntonprivacyblog.com/2021/01/19/edpb-publishes-guidelines-on-examples-regarding-data-breach-notification/


2.CiscoÇå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´¶à¿î²úÆ·ÖеĴúÂëÖ´ÐÐÎó²î


2.png


CiscoÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´Æä¶à¸öSD-WAN²úÆ·ºÍCisco Smart Software ManagerÈí¼þÖеÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©Îó²î¡£¡£¡£¡£¡£¡£ÆäÖÐ×îÑÏÖØµÄÎó²îΪSD-WAN vManage»ùÓÚWebµÄÖÎÀí½çÃæÖеÄCVE-2021-1299Îó²î£¬£¬£¬£¬£¬CVSSÆÀ·Ö9.9£¬£¬£¬£¬£¬¿É±»ÓÃÀ´ÒÔrootÓû§Éí·ÝÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£Æä´ÎΪ¶ÔIPÁ÷Á¿µÄ²»×¼È·´¦Öóͷ£µ¼ÖµĻº³åÇøÒç³öÎó²î£¨CVE-2021-1300£©£¬£¬£¬£¬£¬CVSSÆÀ·Ö9.8£¬£¬£¬£¬£¬¿Éµ¼ÖÂí§ÒâÏÂÁîÖ´ÐС£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬»¹ÐÞ¸´ÁËCVE-2021-1138¡¢CVE-2021-1140ºÍCVE-2021-1142µÈÎó²î¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/critical-cisco-sd-wan-bugs-rce-attacks/163204/


3.VideoLanÐÞ¸´VLC²¥·ÅÆ÷Öжà¸ö´úÂëÖ´ÐÐÎó²î


3.png


VideoLanÐû²¼ÁËÊÊÓÃÓÚWindows¡¢MacºÍLinux°æ±¾µÄVLC Media Player 3.0.12µÄÇå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´¶à¸ö´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´Á˶à¸ö»º³åÇøÒç³öÎó²îºÍÎÞЧµÄ×÷·ÏÒýÓÃÎó²î£¬£¬£¬£¬£¬¿Éµ¼ÖÂVLC±ÀÀ£»£»£»òí§Òâ´úÂëÖ´ÐС£¡£¡£¡£¡£¡£VideoLanÌåÏÖ£¬£¬£¬£¬£¬ÕâЩÎó²î×Ô¼º¿ÉÄܻᵼÖ²¥·ÅÆ÷Í߽⣬£¬£¬£¬£¬×éºÏÔÚÒ»ÆðʹÓÿÉÄÜ»áй¶Óû§ÐÅÏ¢»òÔ¶³ÌÖ´ÐдúÂ룬£¬£¬£¬£¬ASLRºÍDEP»òÐí»áÓÐ×ÊÖú£¬£¬£¬£¬£¬µ«Ò²¿ÉÄÜ»á±»ÈÆ¹ý¡£¡£¡£¡£¡£¡£ÏÖÔÚÉÐδ·¢Ã÷Îó²î±»ÔÚҰʹÓõÄÇéÐΡ£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/software/vlc-media-player-3012-fixes-multiple-remote-code-execution-flaws/


4.ºÚ¿Í¹ûÕæNitro PDFµÄ14GBÊý¾Ý£¬£¬£¬£¬£¬Éæ¼°7700Íò¸öÓû§


4.png


ºÚ¿Í¹ûÕæÁËNitro PDFÓû§µÄÍêÕûÊý¾Ý¿â£¬£¬£¬£¬£¬Ð¹Â¶ÁË14GBÊý¾Ý£¬£¬£¬£¬£¬×ܼÆ77159696Ìõ¼Í¼¡£¡£¡£¡£¡£¡£NitroÊÇÒ»¿î¿É×ÊÖú½¨Éè¡¢±à¼­ºÍÇ©ÊðPDFºÍÊý×ÖÎĵµµÄÓ¦Ó㬣¬£¬£¬£¬³ÆÓµÓÐ10000¶à¸öÉÌÒµ¿Í»§ºÍ180ÍòÔÊÐíÓû§¡£¡£¡£¡£¡£¡£´Ë´Îй¶µÄÊý¾Ý°üÀ¨Óû§µÄÓʼþµØµã¡¢ÐÕÃû¡¢¹þÏ£ÃÜÂ롢ͷÏΡ¢¹«Ë¾Ãû³Æ¡¢IPµØµãÒÔ¼°ÆäËûÓëϵͳÏà¹ØµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£È¥ÄêNitroÒ²±¬·¢¹ýÀàËÆÊÂÎñ£¬£¬£¬£¬£¬ºÚ¿ÍÒÔ80000ÃÀÔªµÄ¼ÛÇ®ÅÄÂô°üÀ¨7000Íò¸öÓû§µÄÐÅÏ¢µÄÊý¾Ý¿âºÍ1TBÎļþ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hacker-leaks-full-database-of-77-million-nitro-pdf-user-records/


5.QNAP·¢Ã÷жñÒâÈí¼þDovecatÃé×¼ÆäNAS×°±¸


5.png


ÍþÁªÍ¨£¨QNAP£©Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬ÖÒÑÔÐÂÐͼÓÃÜ¿ó¹¤DovecatÃé×¼ÆäNAS×°±¸¡£¡£¡£¡£¡£¡£QNAPÌåÏÖ£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÏÖÔÚʹÓÃÈõÃÜÂëÅþÁ¬Ì»Â¶µÄQNAP NASϵͳ¾ÙÐзַ¢£¬£¬£¬£¬£¬À´Ê¹ÓÃÓû§µÄÍâµØ×ÊÔ´ÍÚ¾ò¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÆÊÎö·¢Ã÷£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þËÆºõÊÇרÃÅΪQNAP NAS¶øÉè¼ÆµÄ£¬£¬£¬£¬£¬µ«Äܹ»Ñ¬È¾ËùÓÐLinuxϵͳ¡£¡£¡£¡£¡£¡£QNAP½¨ÒéÓû§½ÓÄɸüÇ¿µÄÖÎÀíÔ±ÃÜÂë¡¢½ûÓÃSSHºÍTelnetЧÀÍ¡¢½ûÓÃδʹÓõÄЧÀͺÍÓ¦ÓóÌÐòºÍ×èֹʹÓÃĬÈ϶˿ںŵȲ½·¥¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/qnap-warns-users-of-a-new-crypto-miner-named-dovecat-infecting-their-devices/


6.AviraÐû²¼2020ÄêÖ÷ÒªÍøÂç¹¥»÷ºÍÍþвµÄ»ØÊ×±¨¸æ


6.png


AviraÐû²¼ÁË2020ÄêÖ÷ÒªÍøÂç¹¥»÷ºÍÍþвµÄ»ØÊ×±¨¸æ¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬Óë2019ÄêÏà±È£¬£¬£¬£¬£¬2020ÄêÉϰëÄêµÄÍøÂç´¹ÂÚ¹¥»÷ÊýÄ¿ÔöÌíÁËÒ»±¶ÒÔÉÏ£¬£¬£¬£¬£¬¼ì²âµ½ÁËÁè¼Ý840Íò¸öÍøÂç´¹ÂÚURL£¬£¬£¬£¬£¬±È2019ÄêÉϰëÄêÔöÌíÁË470Íò¸ö¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬ÀÕË÷Èí¼þ¹¥»÷ÊÇ2020Äê×î³£¼ûµÄÍþв֮һ£¬£¬£¬£¬£¬Covid-19ʱ´ú¹¥»÷Õ߸ü¶àµÄÃé×¼Ò½ÁÆÐÐÒµ£¬£¬£¬£¬£¬³ý²ÆÎñÉϵÄËðʧÍ⻹¿ÉÄܵ¼ÖÂÉúÃüΣÏÕ£¬£¬£¬£¬£¬Ò»Ð©ºÚ¿Í×éÖ¯»¹Õë¶ÔÃÀ¹ú¡¢¼ÓÄôó¡¢Ó¢¹ú¡¢µÂ¹úºÍÈðÊ¿µÄÐí¶à´óѧºÍÑо¿ÖÐÐÄ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.avira.com/en/blog/a-year-in-review-top-cyberattacks-and-common-cyberthreats-in-2020