Proofpoint·¢Ã÷Õë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£´¹Âڻ

Ðû²¼Ê±¼ä 2021-12-10

GoogleÐû²¼12Ô·ݸüУ¬£¬£¬£¬£¬£¬ÐÞ¸´chromeÖеĶà¸öÎó²î


GoogleÐû²¼12Ô·ݸüУ¬£¬£¬£¬£¬£¬ÐÞ¸´chromeÖеĶà¸öÎó²î.png


GoogleÔÚ12ÔÂ6ÈÕÐû²¼chromeÇå¾²¸üУ¬£¬£¬£¬£¬£¬×ܼÆÐÞ¸´22¸öÎó²î¡£¡£¡£¡£¡£ ¡£ÆäÖнÏΪÑÏÖØµÄÊÇWebÓ¦ÓóÌÐòÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2021-4052£©¡¢UI×é¼þÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2021-4053£©¡¢WebRTCÖеÄÔ½½çдÈëÎó²î£¨CVE-2021-4079£©ÒÔ¼°V8ÖеÄÀàÐÍ»ìÏýÎó²î£¨CVE-2021-4078£©¡£¡£¡£¡£¡£ ¡£±ðµÄ£¬£¬£¬£¬£¬£¬»¹ÐÞ¸´ÁËÀ©Õ¹ÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2021-4055£©ºÍANGLEÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2021-4058£©µÈ¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop.html


SonicWallÐû²¼¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´SMA 100ϵÁÐÖжà¸öÎó²î


SonicWallÐû²¼¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´SMA 100ϵÁÐÖжà¸öÎó²î.png


SonicWallÔÚ12ÔÂ7ÈÕÐû²¼¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´SMA 100ϵÁÐ×°±¸ÖеĶà¸öÎó²î¡£¡£¡£¡£¡£ ¡£´Ë´ÎÐÞ¸´µÄ×îΪÑÏÖØµÄÎó²îÊÇ»ùÓÚ¿ÍÕ»µÄ»º³åÇøÒç³öÎó²î£¨CVE-2021-20038£©£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬£¬ÓÉÓÚ×°±¸µÄApache httpdЧÀÍÆ÷ÖеÄHTTP GETÒªÁìµÄÇéÐαäÁ¿Ê¹ÓÃÁËstrcat()º¯Êýµ¼ÖµÄ£»£»£»£»£»£»£»Æä´ÎÊÇ»º³åÇøÒç³öÎó²î£¨CVE-2021-20045£©£¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö9.4¡£¡£¡£¡£¡£ ¡£±ðµÄ£¬£¬£¬£¬£¬£¬»¹ÐÞ¸´ÁË»º³åÇøÒç³öÎó²î£¨CVE-2021-20043£©ºÍÈÏÖ¤ÏÂÁî×¢ÈëÎó²î£¨CVE-2021-20039£©µÈ¡£¡£¡£¡£¡£ ¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.cisa.gov/uscert/ncas/current-activity/2021/12/08/sonicwall-releases-security-advisory-sma-100-series-appliances


ÑÇÂíÑ·AWSÔÆÐ§ÀÍå´»úÓ°ÏìNetflixµÈ¶à¸öÓ¦ÓÃ


ÑÇÂíÑ·AWSÔÆÐ§ÀÍå´»úÓ°ÏìNetflixµÈ¶à¸öÓ¦ÓÃ.png


12ÔÂ7ÈÕÏÂÖç12µã×óÓÒ£¬£¬£¬£¬£¬£¬ÃÀ¹úUS-EAST-1ÇøÓòµÄÑÇÂíÑ·AWSÔÆÐ§ÀÍå´»ú¡£¡£¡£¡£¡£ ¡£´Ë´ÎÊÂÎñÓ°ÏìÁËRing¡¢Netflix¡¢Amazon Prime Video¡¢RobinhoodºÍRokuµÈÓ¦Ó㬣¬£¬£¬£¬£¬ÒÔ¼°PUBG¡¢ValorantºÍÓ¢ÐÛͬÃ˵ÈÓÎÏ·¡£¡£¡£¡£¡£ ¡£¸Ã¹«Ë¾ÔÚµ±Ìì12:34È·ÈÏÁËÖÐÖ¹ÊÂÎñ£¬£¬£¬£¬£¬£¬²¢³Æ»ù´¡Ôµ¹ÊÔ­ÓÉÊǶà¸öÍøÂç×°±¸ÊÜË𡣡£¡£¡£¡£ ¡£12ÔÂ7ÈÕÏÂÖç4:35£¬£¬£¬£¬£¬£¬ÑÇÂíÑ·ÌåÏÖÍøÂç×°±¸ÎÊÌâÒѾ­½â¾ö£¬£¬£¬£¬£¬£¬ËûÃÇÕýÔÚÆð¾¢»Ö¸´ÊÜËðЧÀÍ¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/amazon-web-service-outage-impact-major-websites/


Proofpoint·¢Ã÷Õë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£´¹Âڻ


Proofpoint·¢Ã÷Õë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£´¹Âڻ.png


Proofpoint¹ûÕæÁ˽üÆÚ´ó¹æÄ£´¹ÂڻÖÐʹÓõÄÕ½ÂÔ¡¢ÊÖÒպͳÌÐò(TTP)µÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£ ¡£´Ë´Î»î¶¯×îÏÈÓÚ½ñÄê10Ô·Ý£¬£¬£¬£¬£¬£¬À´×Ô¶à¸öºÚ¿ÍÍŻ£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹úµÄ´óѧ¡£¡£¡£¡£¡£ ¡£ÕâЩ¹¥»÷ͨ¹ýÒÔOmicron±äÌå¡¢COVID-19²âÊÔЧ¹ûºÍÆäËü²âÊÔÒªÇóΪÖ÷ÌâµÄ´¹ÂÚÓʼþ£¬£¬£¬£¬£¬£¬ÓÕʹĿµÄ·­¿ª¸½¼þÖеÄHTMÎļþ£¬£¬£¬£¬£¬£¬²¢½«ÆäÖØ¶¨Ïòµ½Î±×°³ÉËûÃÇ´óѧµÇÂ¼ÍøÕ¾µÄ´¹ÂÚÒ³Ãæ£¬£¬£¬£¬£¬£¬Ö¼ÔÚÇÔÊØÐÅÏ¢¡£¡£¡£¡£¡£ ¡£ÎªÁËÈÆ¹ýMFA±£»£»£»£»£»£»£»¤£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹½¨ÉèÁËαÔìµÄDUO MFAÍøÕ¾ÒÔÇÔÈ¡Óû§µÄOTP¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-universities-targeted-by-office-365-phishing-attacks/


QNAPÌáÐѿͻ§×¢ÖؽüÆÚÕë¶ÔÆäNAS×°±¸µÄÍÚ¿ó»î¶¯


QNAPÌáÐѿͻ§×¢ÖؽüÆÚÕë¶ÔÆäNAS×°±¸µÄÍÚ¿ó»î¶¯.png


Öйų́ÍåµÄNAS×°±¸ÖÆÔìÉÌQNAPÔÚ12ÔÂ7ÈÕÐû²¼Í¨¸æ£¬£¬£¬£¬£¬£¬ÌáÐÑÓû§×¢ÖؽüÆÚµÄ¶ñÒâÍÚ¿ó»î¶¯¡£¡£¡£¡£¡£ ¡£Í¨¸æ³Æ£¬£¬£¬£¬£¬£¬´Ë´Î»î¶¯Ãé×¼ÁËQNAP NAS¡£¡£¡£¡£¡£ ¡£Ò»µ©NAS±»Ñ¬È¾£¬£¬£¬£¬£¬£¬CPUʹÓÃÂÊ»á±äµÃÒì³£¸ß£¬£¬£¬£¬£¬£¬ÆäÖÐÃûΪ¡°[oom_reaper]¡±µÄÀú³Ì¿ÉÄÜ»áÕ¼ÓÃ×ÜCPUʹÓÃÂʵÄ50%×óÓÒ¡£¡£¡£¡£¡£ ¡£Õâ¸öÀú³ÌÄ£ÄâÁËÒ»¸öÕýµ±µÄͬÃûÄÚºËÀú³Ì£¬£¬£¬£¬£¬£¬¿ÉÊÇÕý³£ÄÚºËÀú³ÌPIDͨ³£µÍÓÚ1000£¬£¬£¬£¬£¬£¬¶ø¸Ã¿ó¹¤PIDͨ³£´óÓÚ1000¡£¡£¡£¡£¡£ ¡£QNAP½¨ÒéÓû§½«QTS¸üе½×îа汾£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃÇ¿ÃÜÂë¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/12/warning-yet-another-bitcoin-mining.html


ÐÂÀÕË÷Èí¼þCerberÃé×¼ConfluenceºÍGitLabЧÀÍÆ÷


ÐÂÀÕË÷Èí¼þCerberÃé×¼ConfluenceºÍGitLabЧÀÍÆ÷.png


12ÔÂ7ÈÕ£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ʹÓÃÁ˾ÉÃû³ÆµÄÐÂÀÕË÷Èí¼þCerber¡£¡£¡£¡£¡£ ¡£ÀÕË÷Èí¼þCerberÓÚ2016Äê·ºÆð£¬£¬£¬£¬£¬£¬Ö±µ½2019Äêµ×ÏûÊÅ¡£¡£¡£¡£¡£ ¡£´ÓÉϸöÔÂ×îÏÈ£¬£¬£¬£¬£¬£¬Cerbe»Ø¹é£¬£¬£¬£¬£¬£¬¿ÉÊÇËüÓë¾É°æ²¢²»Ïàͬ£¬£¬£¬£¬£¬£¬´úÂ벻ƥÅ䣬£¬£¬£¬£¬£¬Ð°æÊ¹ÓÃCrypto+++¿â¶ø¾É°æ±¾Ê¹ÓÃWindows CryptoAPI¿â£¬£¬£¬£¬£¬£¬²¢ÇҾɰæCerberҲûÓÐLinux±äÌå¡£¡£¡£¡£¡£ ¡£ÐÂCerberµÄÊê½ðÒªÇó´Ó1000ÃÀÔªµ½3000ÃÀÔª²»µÈ£¬£¬£¬£¬£¬£¬Ê¹ÓÃÁËCVE-2021-26084ºÍCVE-2021-22205Îó²îÃé×¼ConfluenceºÍGitLabЧÀÍÆ÷£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹ú¡¢µÂ¹úºÍÖйú¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-cerber-ransomware-targets-confluence-and-gitlab-servers/