Adobe½ôÆÈ¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´ColdFusioní§Òâ´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»£»McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetopVisionProÖжà¸öÎó²î

Ðû²¼Ê±¼ä 2021-03-23

1.AdobeÐû²¼½ôÆÈ¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´ColdFusionÖÐí§Òâ´úÂëÖ´ÐÐÎó²î


1.jpg


AdobeÓÚ3ÔÂ22ÈÕÐû²¼½ôÆÈ´øÍâ¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´ColdFusionÖеÄí§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÓÉÓÚÎÞ·¨ÑéÖ¤ÊäÈ뵼ֵ쬣¬£¬£¬£¬£¬±»¸ú×ÙΪCVE-2021-21087£¬£¬£¬£¬£¬£¬Ó°ÏìÁËColdFusion°æ±¾2021¡¢2016ºÍ2018¡£¡£¡£¡£¡£¡£Adobe½¨ÒéÖÎÀíÔ±¾¡¿ì×°ÖÃÇå¾²¸üУ¬£¬£¬£¬£¬£¬²¢Ó¦Óùٷ½Ö¸ÄÏÖÐÐÎòµÄÇå¾²ÉèÖÃ¶ÔÆä¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/critical-code-execution-vulnerability-fixed-in-adobe-coldfusion/


2.McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetop Vision Pro±£´æ¶à¸öÎó²î


2.jpg


McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetop Vision Pro±£´æ¶à¸ö¿ÉÓÃÀ´Ð®ÖÆÄ¿µÄµçÄÔµÄÎó²î¡£¡£¡£¡£¡£¡£ÕâЩÎó²î»®·ÖΪȨÏÞ·ÖÅÉÎó²î£¨CVE-2021-27192£©¡¢Ä¬ÈÏȨÏÞ¹ýʧ£¨CVE-2021-27193£©¡¢ÒÔÃ÷ÎÄ´«ÊäµÄÃô¸ÐÐÅÏ¢£¨CVE-2021-27194£©ºÍÊÚȨÎÊÌ⣨CVE-2021-27195£©¡£¡£¡£¡£¡£¡£ºÚ¿Í¿ÉÓÃÕâЩÎó²î¾ÙÐÐÌáȨºÍÖ´ÐÐÔ¶³Ì´úÂ룬£¬£¬£¬£¬£¬»ñµÃ¶ÔÄ¿µÄϵͳµÄÍêÈ«¿ØÖÆÈ¨²¢ÆôÓÃÍøÂçÉãÏñÍ·ºÍÂó¿Ë·ç¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬NetopÒÑÐÞ¸´²¿·ÖÎó²î¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/popular-remote-student-learning-program-found-to-be-riddled-with-security-holes/


3.µçÁ¦¹«Ë¾Celg GTÕû¸öÍøÂçÎÞ·¨»á¼û£¬£¬£¬£¬£¬£¬ÊÂÎñÈÔÔÚÊÓ²ìÖÐ


3.jpg


CelgGera??oeTransmiss?o£¨Celg GT£©ÓÚÉÏÖÜÎå(3ÔÂ19ÈÕ)³ÆÆäÔâµ½Á˹¥»÷£¬£¬£¬£¬£¬£¬ËùÓеÄÓ¦ÓóÌÐòºÍÕû¸öÎļþϵͳ¶¼ÎÞ·¨»á¼û¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬£¬¹¥»÷ÊÇ´ÓÆÆÏþ×îÏȵÄ£¬£¬£¬£¬£¬£¬Æä·¢Ã÷ºóÁ¬Ã¦½ÓÄÉÏìÓ¦²½·¥£¬£¬£¬£¬£¬£¬¹Ø±ÕϵͳÒÔ±£»£»£»£»£»£»£»¤ÐÅÏ¢ºÍ±¸·Ý×ÊÁÏ¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñÈÔÔÚÊÓ²ìÖУ¬£¬£¬£¬£¬£¬Éв»¿ÉÈ·¶¨ÏµÍ³Ë𻵵ÄˮƽÒÔ¼°¹¥»÷µÄȪԴ£¬£¬£¬£¬£¬£¬¿ÉÊÇ¿ÉÒÔÈ·¶¨Ã»ÓÐÈκÎСÎÒ˽¼ÒÐÅÏ¢±»Ð¹Â¶£¬£¬£¬£¬£¬£¬¹«Ë¾Ô±¹¤µÄµç×ÓÓʼþЧÀÍÒ²¿ÉÒÔÕý³£ÔËÐС£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.jornalopcao.com.br/ultimas-noticias/ataque-hacker-compromete-funcionamento-de-aplicativos-e-arquivos-da-celg-gt-318176/


4.²®Ã÷º²Òé»áÔ±¹¤Òò²Ù×÷ʧÎó¹ûÕæ´ó×ÚÈõÊÆÈºÌåµÄСÎÒ˽¼ÒÐÅÏ¢


4.jpg


²®Ã÷º²Òé»áÔÚ3ÔÂ19ÈÕÐÇÆÚÎ峯£¬£¬£¬£¬£¬£¬ÒòÔ±¹¤²Ù×÷ʧÎóµ¼Ö´ó×ÚÈõÊÆÈºÌåµÄСÎÒ˽¼ÒÐÅÏ¢±»¹ûÕæ¡£¡£¡£¡£¡£¡£¾Ý³Æ´Ë´Îй¶µÄÊÇÓÐȨ»ñµÃÃâ·Ñ°ÍʿͨÐÐÖ¤µÄ¶ùͯµÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¡£¸ÃÊÐÌåÏÖ£¬£¬£¬£¬£¬£¬ÆäÔÚ·¢Ã÷й¶ºóÁ¬Ã¦½ÓÄÉÁ˲½·¥£¬£¬£¬£¬£¬£¬Êý¾Ý»¹Î´±»ÏÂÔØ£¬£¬£¬£¬£¬£¬²¢ÇÒÓÉÓÚ´ËÊÂÎñµÄ¹æÄ£ºÍÑÏÖØÐÔ×Ó£¬£¬£¬£¬£¬£¬ÏÖÒÑ֪ͨÈÏÕæ¼àÊÓµÄÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.birminghammail.co.uk/news/midlands-news/details-vulnerable-kids-uploaded-birmingham-20217314


5.Black KiteÐû²¼Îó²î¶ÔÐÅÓÃÏàÖúÉçµÄÓ°ÏìµÄÆÊÎö±¨¸æ


5.jpg


Black KiteÐû²¼ÁËÓйØÎó²î¶ÔÐÅÓÃÏàÖúÉçµÄÓ°ÏìµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£±¨¸æÏÔʾ£¬£¬£¬£¬£¬£¬Æ¾Ö¤Ð¹Â¶¡¢Î´¸üеľÉϵͳºÍ¹©Ó¦ÉÌÎó²îÊÇÐÅÓÃÏàÖúÉçËùÃæÁÙµÄ×î´óµÄÍøÂçΣº¦¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬Õë¶Ô¹©Ó¦É̵Ĺ¥»÷ΪÐÅÓÃÏàÖúÉç¿ÉÄÜ»áÔì³ÉÁè¼Ý100ÍòÃÀÔªµÄDZÔÚ²ÆÎïËðʧ£»£»£»£»£»£»£»86%µÄÐÅÓÃÏàÖúÉçºÍ76%µÄ¹©Ó¦É̵ÄÔ±¹¤Æ¾Ö¤Òѱ»ÇÔÈ¡²¢¹ûÕæµ½°µÍøÉÏ£»£»£»£»£»£»£»Áè¼Ý66%µÄÐÅÓÃÏàÖúÉçºÍ88%µÄ¹©Ó¦ÉÌȱ·¦Ô¤·ÀÓÕÆ­ºÍ´¹ÂÚ¹¥»÷µÄµç×ÓÓʼþÇå¾²Õ½ÂÔ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://googleprojectzero.blogspot.com/2021/03/in-wild-series-october-2020-0-day.html


6.VectraÐû²¼ÓйØOffice 365ºÍÔÆµÄÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ


6.jpg


VectraÐû²¼ÁËÓйØOffice 365ºÍÔÆµÄÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£±¨¸æÏÔʾ£¬£¬£¬£¬£¬£¬ÔÚÒÑÍùÒ»Ä꣬£¬£¬£¬£¬£¬Ö»¹Ü½ÓÄÉÁ˶àÒòËØÉí·ÝÑéÖ¤£¨MFA£©£¬£¬£¬£¬£¬£¬µ«ÈÔÓÐ71£¥µÄÆóÒµÈÔÈ»ÂÄÀú¹ýSaaSÕÊ»§Ð®ÖÆ£¬£¬£¬£¬£¬£¬½ü90£¥µÄÆóÒµ»¹ÔÚ¼ÓËÙÔÆÅÌËãºÍÊý×Ö»¯µÄתÐÍ¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬¸Ã±¨¸æÔÚ90ÌìÄÚ¸ú×ÙÁË400Íò¸öMicrosoft Office 365¿Í»§µÄÐÐΪ£¬£¬£¬£¬£¬£¬·¢Ã÷ÓÐ96£¥µÄÄÚÍø±£´æ¿ÉÒɵĺáÏòÒÆ¶¯ÐÐΪ¡£¡£¡£¡£¡£¡£Îå·ÖÖ®ËĵÄÇ徲רҵְԱÌåÏÖ£¬£¬£¬£¬£¬£¬ÔÚÒÑÍùÒ»ÄêÖÐÍøÂçÇå¾²µÄΣº¦ÓÐËùÔöÌí¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.vectra.ai/blogpost/cloud-security-insights