Proofpoint·¢Ã÷Õë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£´¹Âڻ
Ðû²¼Ê±¼ä 2021-12-10GoogleÐû²¼12Ô·ݸüУ¬£¬£¬£¬£¬ÐÞ¸´chromeÖеĶà¸öÎó²î
GoogleÔÚ12ÔÂ6ÈÕÐû²¼chromeÇå¾²¸üУ¬£¬£¬£¬£¬×ܼÆÐÞ¸´22¸öÎó²î¡£¡£¡£ÆäÖнÏΪÑÏÖØµÄÊÇWebÓ¦ÓóÌÐòÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2021-4052£©¡¢UI×é¼þÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2021-4053£©¡¢WebRTCÖеÄÔ½½çдÈëÎó²î£¨CVE-2021-4079£©ÒÔ¼°V8ÖеÄÀàÐÍ»ìÏýÎó²î£¨CVE-2021-4078£©¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬»¹ÐÞ¸´ÁËÀ©Õ¹ÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2021-4055£©ºÍANGLEÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2021-4058£©µÈ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop.html
SonicWallÐû²¼¸üУ¬£¬£¬£¬£¬ÐÞ¸´SMA 100ϵÁÐÖжà¸öÎó²î
SonicWallÔÚ12ÔÂ7ÈÕÐû²¼¸üУ¬£¬£¬£¬£¬ÐÞ¸´SMA 100ϵÁÐ×°±¸ÖеĶà¸öÎó²î¡£¡£¡£´Ë´ÎÐÞ¸´µÄ×îΪÑÏÖØµÄÎó²îÊÇ»ùÓÚ¿ÍÕ»µÄ»º³åÇøÒç³öÎó²î£¨CVE-2021-20038£©£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬ÓÉÓÚ×°±¸µÄApache httpdЧÀÍÆ÷ÖеÄHTTP GETÒªÁìµÄÇéÐαäÁ¿Ê¹ÓÃÁËstrcat()º¯Êýµ¼Öµģ»£»£»£»£»£»£»Æä´ÎÊÇ»º³åÇøÒç³öÎó²î£¨CVE-2021-20045£©£¬£¬£¬£¬£¬CVSSÆÀ·Ö9.4¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬»¹ÐÞ¸´ÁË»º³åÇøÒç³öÎó²î£¨CVE-2021-20043£©ºÍÈÏÖ¤ÏÂÁî×¢ÈëÎó²î£¨CVE-2021-20039£©µÈ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.cisa.gov/uscert/ncas/current-activity/2021/12/08/sonicwall-releases-security-advisory-sma-100-series-appliances
ÑÇÂíÑ·AWSÔÆÐ§ÀÍå´»úÓ°ÏìNetflixµÈ¶à¸öÓ¦ÓÃ
12ÔÂ7ÈÕÏÂÖç12µã×óÓÒ£¬£¬£¬£¬£¬ÃÀ¹úUS-EAST-1ÇøÓòµÄÑÇÂíÑ·AWSÔÆÐ§ÀÍå´»ú¡£¡£¡£´Ë´ÎÊÂÎñÓ°ÏìÁËRing¡¢Netflix¡¢Amazon Prime Video¡¢RobinhoodºÍRokuµÈÓ¦Ó㬣¬£¬£¬£¬ÒÔ¼°PUBG¡¢ValorantºÍÓ¢ÐÛͬÃ˵ÈÓÎÏ·¡£¡£¡£¸Ã¹«Ë¾ÔÚµ±Ìì12:34È·ÈÏÁËÖÐÖ¹ÊÂÎñ£¬£¬£¬£¬£¬²¢³Æ»ù´¡Ôµ¹ÊÔÓÉÊǶà¸öÍøÂç×°±¸ÊÜË𡣡£¡£12ÔÂ7ÈÕÏÂÖç4:35£¬£¬£¬£¬£¬ÑÇÂíÑ·ÌåÏÖÍøÂç×°±¸ÎÊÌâÒѾ½â¾ö£¬£¬£¬£¬£¬ËûÃÇÕýÔÚÆð¾¢»Ö¸´ÊÜËðЧÀÍ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/amazon-web-service-outage-impact-major-websites/
Proofpoint·¢Ã÷Õë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£´¹Âڻ
Proofpoint¹ûÕæÁ˽üÆÚ´ó¹æÄ£´¹ÂڻÖÐʹÓõÄÕ½ÂÔ¡¢ÊÖÒպͳÌÐò(TTP)µÄÏêϸÐÅÏ¢¡£¡£¡£´Ë´Î»î¶¯×îÏÈÓÚ½ñÄê10Ô·ݣ¬£¬£¬£¬£¬À´×Ô¶à¸öºÚ¿ÍÍŻ£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹úµÄ´óѧ¡£¡£¡£ÕâЩ¹¥»÷ͨ¹ýÒÔOmicron±äÌå¡¢COVID-19²âÊÔЧ¹ûºÍÆäËü²âÊÔÒªÇóΪÖ÷ÌâµÄ´¹ÂÚÓʼþ£¬£¬£¬£¬£¬ÓÕʹĿµÄ·¿ª¸½¼þÖеÄHTMÎļþ£¬£¬£¬£¬£¬²¢½«ÆäÖØ¶¨Ïòµ½Î±×°³ÉËûÃÇ´óѧµÇÂ¼ÍøÕ¾µÄ´¹ÂÚÒ³Ãæ£¬£¬£¬£¬£¬Ö¼ÔÚÇÔÊØÐÅÏ¢¡£¡£¡£ÎªÁËÈÆ¹ýMFA±£»£»£»£»£»£»£»¤£¬£¬£¬£¬£¬¹¥»÷Õß»¹½¨ÉèÁËαÔìµÄDUO MFAÍøÕ¾ÒÔÇÔÈ¡Óû§µÄOTP¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/us-universities-targeted-by-office-365-phishing-attacks/
QNAPÌáÐѿͻ§×¢ÖؽüÆÚÕë¶ÔÆäNAS×°±¸µÄÍÚ¿ó»î¶¯
Öйų́ÍåµÄNAS×°±¸ÖÆÔìÉÌQNAPÔÚ12ÔÂ7ÈÕÐû²¼Í¨¸æ£¬£¬£¬£¬£¬ÌáÐÑÓû§×¢ÖؽüÆÚµÄ¶ñÒâÍÚ¿ó»î¶¯¡£¡£¡£Í¨¸æ³Æ£¬£¬£¬£¬£¬´Ë´Î»î¶¯Ãé×¼ÁËQNAP NAS¡£¡£¡£Ò»µ©NAS±»Ñ¬È¾£¬£¬£¬£¬£¬CPUʹÓÃÂÊ»á±äµÃÒì³£¸ß£¬£¬£¬£¬£¬ÆäÖÐÃûΪ¡°[oom_reaper]¡±µÄÀú³Ì¿ÉÄÜ»áÕ¼ÓÃ×ÜCPUʹÓÃÂʵÄ50%×óÓÒ¡£¡£¡£Õâ¸öÀú³ÌÄ£ÄâÁËÒ»¸öÕýµ±µÄͬÃûÄÚºËÀú³Ì£¬£¬£¬£¬£¬¿ÉÊÇÕý³£ÄÚºËÀú³ÌPIDͨ³£µÍÓÚ1000£¬£¬£¬£¬£¬¶ø¸Ã¿ó¹¤PIDͨ³£´óÓÚ1000¡£¡£¡£QNAP½¨ÒéÓû§½«QTS¸üе½×îа汾£¬£¬£¬£¬£¬²¢Ê¹ÓÃÇ¿ÃÜÂë¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/12/warning-yet-another-bitcoin-mining.html
ÐÂÀÕË÷Èí¼þCerberÃé×¼ConfluenceºÍGitLabЧÀÍÆ÷
12ÔÂ7ÈÕ£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ʹÓÃÁ˾ÉÃû³ÆµÄÐÂÀÕË÷Èí¼þCerber¡£¡£¡£ÀÕË÷Èí¼þCerberÓÚ2016Äê·ºÆð£¬£¬£¬£¬£¬Ö±µ½2019Äêµ×ÏûÊÅ¡£¡£¡£´ÓÉϸöÔÂ×îÏÈ£¬£¬£¬£¬£¬Cerbe»Ø¹é£¬£¬£¬£¬£¬¿ÉÊÇËüÓë¾É°æ²¢²»Ïàͬ£¬£¬£¬£¬£¬´úÂ벻ƥÅ䣬£¬£¬£¬£¬Ð°æÊ¹ÓÃCrypto+++¿â¶ø¾É°æ±¾Ê¹ÓÃWindows CryptoAPI¿â£¬£¬£¬£¬£¬²¢ÇҾɰæCerberҲûÓÐLinux±äÌå¡£¡£¡£ÐÂCerberµÄÊê½ðÒªÇó´Ó1000ÃÀÔªµ½3000ÃÀÔª²»µÈ£¬£¬£¬£¬£¬Ê¹ÓÃÁËCVE-2021-26084ºÍCVE-2021-22205Îó²îÃé×¼ConfluenceºÍGitLabЧÀÍÆ÷£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹ú¡¢µÂ¹úºÍÖйú¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-cerber-ransomware-targets-confluence-and-gitlab-servers/