Proofpoint·¢Ã÷Õë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£´¹ÂÚÔ˶¯

Ðû²¼Ê±¼ä 2021-12-10

GoogleÐû²¼12Ô·ݸüР£¬ÐÞ¸´chromeÖеĶà¸öÎó²î


GoogleÐû²¼12Ô·ݸüÐÂ£¬ÐÞ¸´chromeÖеĶà¸öÎó²î.png


GoogleÔÚ12ÔÂ6ÈÕÐû²¼chromeÇå¾²¸üР£¬×ܼÆÐÞ¸´22¸öÎó²î¡£ÆäÖнÏΪÑÏÖØµÄÊÇWebÓ¦ÓóÌÐòÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2021-4052£©¡¢UI×é¼þÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2021-4053£©¡¢WebRTCÖеÄÔ½½çдÈëÎó²î£¨CVE-2021-4079£©ÒÔ¼°V8ÖеÄÀàÐÍ»ìÏýÎó²î£¨CVE-2021-4078£©¡£±ðµÄ £¬»¹ÐÞ¸´ÁËÀ©Õ¹ÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2021-4055£©ºÍANGLEÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2021-4058£©µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop.html


SonicWallÐû²¼¸üР£¬ÐÞ¸´SMA 100ϵÁÐÖжà¸öÎó²î


SonicWallÐû²¼¸üÐÂ£¬ÐÞ¸´SMA 100ϵÁÐÖжà¸öÎó²î.png


SonicWallÔÚ12ÔÂ7ÈÕÐû²¼¸üР£¬ÐÞ¸´SMA 100ϵÁÐ×°±¸ÖеĶà¸öÎó²î¡£´Ë´ÎÐÞ¸´µÄ×îΪÑÏÖØµÄÎó²îÊÇ»ùÓÚ¿ÍÕ»µÄ»º³åÇøÒç³öÎó²î£¨CVE-2021-20038£© £¬CVSSÆÀ·ÖΪ9.8 £¬ÓÉÓÚ×°±¸µÄApache httpd·þÎñÆ÷ÖеÄHTTP GETÒªÁìµÄÇéÐαäÁ¿Ê¹ÓÃÁËstrcat()º¯Êýµ¼ÖµÄ £»Æä´ÎÊÇ»º³åÇøÒç³öÎó²î£¨CVE-2021-20045£© £¬CVSSÆÀ·Ö9.4¡£±ðµÄ £¬»¹ÐÞ¸´ÁË»º³åÇøÒç³öÎó²î£¨CVE-2021-20043£©ºÍÈÏÖ¤ÏÂÁî×¢ÈëÎó²î£¨CVE-2021-20039£©µÈ¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.cisa.gov/uscert/ncas/current-activity/2021/12/08/sonicwall-releases-security-advisory-sma-100-series-appliances


ÑÇÂíÑ·AWSÔÆ·þÎñå´»úÓ°ÏìNetflixµÈ¶à¸öÓ¦ÓÃ


ÑÇÂíÑ·AWSÔÆ·þÎñå´»úÓ°ÏìNetflixµÈ¶à¸öÓ¦ÓÃ.png


12ÔÂ7ÈÕÏÂÖç12µã×óÓÒ £¬ÃÀ¹úUS-EAST-1ÇøÓòµÄÑÇÂíÑ·AWSÔÆ·þÎñå´»ú¡£´Ë´ÎÊÂÎñÓ°ÏìÁËRing¡¢Netflix¡¢Amazon Prime Video¡¢RobinhoodºÍRokuµÈÓ¦Óà £¬ÒÔ¼°PUBG¡¢ValorantºÍÓ¢ÐÛͬÃ˵ÈÓÎÏ·¡£¸Ã¹«Ë¾ÔÚµ±Ìì12:34È·ÈÏÁËÖÐÖ¹ÊÂÎñ £¬²¢³Æ»ù´¡Ôµ¹ÊÔ­ÓÉÊǶà¸öÍøÂç×°±¸ÊÜËð¡£12ÔÂ7ÈÕÏÂÖç4:35 £¬ÑÇÂíÑ·ÌåÏÖÍøÂç×°±¸ÎÊÌâÒѾ­½â¾ö £¬ËûÃÇÕýÔÚÆð¾¢»Ö¸´ÊÜËð·þÎñ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/amazon-web-service-outage-impact-major-websites/


Proofpoint·¢Ã÷Õë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£´¹ÂÚÔ˶¯


Proofpoint·¢Ã÷Õë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£´¹ÂÚÔ˶¯.png


Proofpoint¹ûÕæÁ˽üÆÚ´ó¹æÄ£´¹ÂÚÔ˶¯ÖÐʹÓõÄÕ½ÂÔ¡¢ÊÖÒպͳÌÐò(TTP)µÄÏêϸÐÅÏ¢¡£´Ë´ÎÔ˶¯×îÏÈÓÚ½ñÄê10ÔÂ·Ý £¬À´×Ô¶à¸öºÚ¿ÍÍÅ»ï £¬Ö÷ÒªÕë¶ÔÃÀ¹úµÄ´óѧ¡£ÕâЩ¹¥»÷ͨ¹ýÒÔOmicron±äÌå¡¢COVID-19²âÊÔЧ¹ûºÍÆäËü²âÊÔÒªÇóΪÖ÷ÌâµÄ´¹ÂÚÓʼþ £¬ÓÕʹĿµÄ·­¿ª¸½¼þÖеÄHTMÎļþ £¬²¢½«ÆäÖØ¶¨Ïòµ½Î±×°³ÉËûÃÇ´óѧµÇÂ¼ÍøÕ¾µÄ´¹ÂÚÒ³Ãæ £¬Ö¼ÔÚÇÔÊØÐÅÏ¢¡£ÎªÁËÈÆ¹ýMFA± £»¤ £¬¹¥»÷Õß»¹½¨ÉèÁËαÔìµÄDUO MFAÍøÕ¾ÒÔÇÔÈ¡Óû§µÄOTP¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-universities-targeted-by-office-365-phishing-attacks/


QNAPÌáÐѿͻ§×¢ÖؽüÆÚÕë¶ÔÆäNAS×°±¸µÄÍÚ¿óÔ˶¯


QNAPÌáÐѿͻ§×¢ÖؽüÆÚÕë¶ÔÆäNAS×°±¸µÄÍÚ¿óÔ˶¯.png


Öйų́ÍåµÄNAS×°±¸ÖÆÔìÉÌQNAPÔÚ12ÔÂ7ÈÕÐû²¼Í¨¸æ £¬ÌáÐÑÓû§×¢ÖؽüÆÚµÄ¶ñÒâÍÚ¿óÔ˶¯¡£Í¨¸æ³Æ £¬´Ë´ÎÔ˶¯Ãé×¼ÁËQNAP NAS¡£Ò»µ©NAS±»Ñ¬È¾ £¬CPUʹÓÃÂÊ»á±äµÃÒì³£¸ß £¬ÆäÖÐÃûΪ¡°[oom_reaper]¡±µÄÀú³Ì¿ÉÄÜ»áÕ¼ÓÃ×ÜCPUʹÓÃÂʵÄ50%×óÓÒ¡£Õâ¸öÀú³ÌÄ£ÄâÁËÒ»¸öÕýµ±µÄͬÃûÄÚºËÀú³Ì £¬¿ÉÊÇÕý³£ÄÚºËÀú³ÌPIDͨ³£µÍÓÚ1000 £¬¶ø¸Ã¿ó¹¤PIDͨ³£´óÓÚ1000¡£QNAP½¨ÒéÓû§½«QTS¸üе½×îа汾 £¬²¢Ê¹ÓÃÇ¿ÃÜÂë¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/12/warning-yet-another-bitcoin-mining.html


ÐÂÀÕË÷Èí¼þCerberÃé×¼ConfluenceºÍGitLab·þÎñÆ÷


ÐÂÀÕË÷Èí¼þCerberÃé×¼ConfluenceºÍGitLab·þÎñÆ÷.png


12ÔÂ7ÈÕ £¬Ñо¿Ö°Ô±·¢Ã÷ʹÓÃÁ˾ÉÃû³ÆµÄÐÂÀÕË÷Èí¼þCerber¡£ÀÕË÷Èí¼þCerberÓÚ2016Äê·ºÆð £¬Ö±µ½2019Äêµ×ÏûÊÅ¡£´ÓÉϸöÔÂ×îÏÈ £¬Cerbe»Ø¹é £¬¿ÉÊÇËüÓë¾É°æ²¢²»Ïàͬ £¬´úÂ벻ƥÅä £¬Ð°æÊ¹ÓÃCrypto+++¿â¶ø¾É°æ±¾Ê¹ÓÃWindows CryptoAPI¿â £¬²¢ÇҾɰæCerberҲûÓÐLinux±äÌå¡£ÐÂCerberµÄÊê½ðÒªÇó´Ó1000ÃÀÔªµ½3000ÃÀÔª²»µÈ £¬Ê¹ÓÃÁËCVE-2021-26084ºÍCVE-2021-22205Îó²îÃé×¼ConfluenceºÍGitLab·þÎñÆ÷ £¬Ö÷ÒªÕë¶ÔÃÀ¹ú¡¢µÂ¹úºÍÖйú¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-cerber-ransomware-targets-confluence-and-gitlab-servers/