IntelµÄHabana LabsϰȾPay2Key£¬£¬£¬£¬£¬£¬£¬£¬Ã³Ò×ÎĵµºÍÔ´´úÂë±»µÁ£»£»£»£»£»£»Adobe°ä²¼Flash Player×îÖÕ¸üÐÂ
°ä²¼¹¦·ò 2020-12-14
IntelµÄAI´¦ÖÃÆ÷¿ª·¢ÉÌHabana LabsÔâµ½ÁËPay2KeyÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Ã³Ò×ÎĵµºÍÔ´´úÂë±»µÁ¡£¡£¡£¡£¡£¡£¡£Habana LabsÊÇÒÔÉ«ÁÐAI´¦ÖÃÆ÷µÄ¿ª·¢ÉÌ£¬£¬£¬£¬£¬£¬£¬£¬ÓÚ2019Äê12ÔÂÒÔ20ÒÚÃÀÔªµÄ¼ÛÖµ±»IntelÊÕ¹º¡£¡£¡£¡£¡£¡£¡£Pay2KeyÔÚTwitterÉϰ䷢ÁËÕâ´Î¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬²¢Ðû³ÆÒÑÇÔÈ¡ÁËÓйØÈËΪÖÇÄÜоƬ´úÂëGaudiµÄÐÅÏ¢Êý¾Ý¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ÉϹ«¿ªÁ˸ù«Ë¾µÄÔ´´úÂëºÍÄÚ²¿¹ý³ÌµÄͼƬ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°WindowsÓò½ÚÔìÆ÷Êý¾ÝºÍGerrit¿ª·¢´úÂë²é³ÏµÍ³µÄÎļþÁÐ±í¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/112258/data-breach/pay2key-hacked-habana-labs.html
2.Adobe°ä²¼Flash Player×îÖÕ¸üУ¬£¬£¬£¬£¬£¬£¬£¬2021Ä꽫ÖÕÖ¹¸üÐÂ

Adobe°ä²¼Flash Player×îÖÕ¸üУ¬£¬£¬£¬£¬£¬£¬£¬²¢°ä·¢½«ÓÚ2021ÄêÖÕÖ¹¸üС£¡£¡£¡£¡£¡£¡£³õ°æAdobe Flash PlayerÓÚ1996Äê1Ô°䲼£¬£¬£¬£¬£¬£¬£¬£¬¾¹ý24ÄêµÄʹÓúͺڿ͵ÄÀÄÓ㬣¬£¬£¬£¬£¬£¬£¬Adobe½«°ä²¼Flash PlayerµÄ×îÖÕ¸üв¢ÖÕ³¡ÊØ»¤¡£¡£¡£¡£¡£¡£¡£´Ó2021Äê1ÔÂÆðÍ·£¬£¬£¬£¬£¬£¬£¬£¬ËùÓÐä¯ÀÀÆ÷µÄ¿ª·¢Õߣ¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬¹È¸èChrome¡¢Safari¡¢Mozilla Firefox¡¢Microsoft Edge¡¢Internet Explorer 11ºÍÆäËû»ùÓÚChromeµÄä¯ÀÀÆ÷£¬£¬£¬£¬£¬£¬£¬£¬¶¼½«°ÑAdobe Flash´ÓËûÃǵÄä¯ÀÀÆ÷ÖÐÆëÈ«ÒÆ³ý¡£¡£¡£¡£¡£¡£¡£ÇÒÒ»µ©ÒƳýºó£¬£¬£¬£¬£¬£¬£¬£¬½«Ã»Óз¨×ÓÔÙ½øÐÐ×°Öᣡ£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/software/adobe-releases-final-flash-player-update-warns-of-2021-kill-switch/
3.NI CompactRIO½ÚÔìÆ÷´æÔڿɵ¼ÖÂÆóÒµ³ö²úÖжϵķì϶

National Instruments£¨NI£©CompactRIO½ÚÔìÆ÷´æÔÚÑϳÁµÄ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß·ÛËé×éÖ¯Öеijö²ú¹ý³Ì¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶±»×·×ÙΪCVE-2020-25191£¬£¬£¬£¬£¬£¬£¬£¬ÊÇÓÉÓڹؼü×ÊÔ´µÄȨÏÞ·ÖÅä²»ÕýÈ·£¬£¬£¬£¬£¬£¬£¬£¬ÎªÌض¨·þÎñµÄAPIÈë¿ÚµãÉèÖÃÁËÃýÎóµÄȨÏÞËùµ¼Ö¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õ߳ɹ¦ÀûÓô˷ì϶ºóÄܹ»Ô¶³Ì³ÁÐÂÆô¶¯É豸£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÖжÏ×éÖ¯µÄ³ö²ú¹ý³Ì¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬CISA°ä²¼Á˰²È«²¼¸æÒÔÖÒ¸æ×éÖ¯°ÑÎȸ÷ì϶£¬£¬£¬£¬£¬£¬£¬£¬²¢Ìá³öÁË»º½â´ëÊ©¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/112228/ics-scada/ni-compactrio-flaw.html
4.GlassdoorÍøÕ¾´æÔڿɵ¼ÖÂÕË»§±»ÊÕÊܵÄCSRF·ì϶

ÇóÖ°ÍøÕ¾Glassdoor´æÔÚÑϳÁµÄCSRF·ì϶£¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÕË»§±»ÊÕÊÜ¡£¡£¡£¡£¡£¡£¡£¸Ãƽ̨ʹÓÃÁËgdTokenÁîÅÆÓÃÓÚÔ¤·ÀCSRF¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬µ«×êÑÐÈËÔ±Tabahi·¢ÏÔìäÒÀÈ»´æÔÚ·ì϶¡£¡£¡£¡£¡£¡£¡£Tabahi´ÓAÕÊ»§ÌìÉúCSRFÁîÅÆ£¬£¬£¬£¬£¬£¬£¬£¬È¥µôµÚÒ»¸ö×Ö·ûºó³¢ÊÔʹ֮×÷ΪBÕÊ»§µÄÁîÅÆ£¬£¬£¬£¬£¬£¬£¬£¬Á˾ÖÖ¤Ã÷Êdzɹ¦µÄ¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏìÁËGlassdoor webÓò£¬£¬£¬£¬£¬£¬£¬£¬Glassdoor°²È«ÍŶӽ«Æä¹éÀàΪÁîÅÆ³¤¶ÈÑéÖ¤ÃýÎ󣬣¬£¬£¬£¬£¬£¬£¬²¢ÇÒ»¹´æÔÚÒì³£´¦ÖÃÎÊÌâ¡£¡£¡£¡£¡£¡£¡£ÇóÖ°Õߺ͹ÍÖ÷µÄÕÊ»§¾ù»áÊܵ½¸Ã·ì϶µÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/cross-site-request-forgery-vulnerability-found-on-glassdoor-job-hunter-review-platform/
5.а汾µÄÀÕË÷Èí¼þMountLocker´óÓ×½öΪ46KB

×êÑÐÈËÔ±ÔÚÒ°±í·¢ÏÖÁËа汾µÄÀÕË÷Èí¼þMountLocker¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þµÄ¿ª·¢ÈËÔ±½«64λµÄ±äÌåËõÓ×µ½46KB£¬£¬£¬£¬£¬£¬£¬£¬±ÈÒÔǰµÄ°æ±¾Ó×50£¥¡£¡£¡£¡£¡£¡£¡£Îª´Ë£¬£¬£¬£¬£¬£¬£¬£¬ËûÃÇɾ³ýÁËÎļþÀ©´óÃûÁÐ±í£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬2600¶à¸öÓÃÓÚ¼ÓÃܵÄÌõ¿î¡£¡£¡£¡£¡£¡£¡£¸ÃÍŻﻹÔö³¤ÁËÓëTurboTaxÈí¼þ¹ØÁªµÄÎļþÀ©´óÃû£¨.tax¡¢.tax2009¡¢.tax2013ºÍ.tax2014£©£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¶Ô×¼ÏÂÒ»ÄÉ˰¼¾¡£¡£¡£¡£¡£¡£¡£¸ÃбäÌåÒÀȻʹÓÃÁ˲»°²È«µÄWindows APIº¯ÊýGetTickCountÀ´ÌìÉúËæ»ú¼ÓÃÜÃÜÔ¿£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄܱ»ÓÃÀ´½øÐб©Á¦¹¥»÷¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/mountlocker-ransomware-gets-slimmer-now-encrypts-fewer-files/
6.CrowdStrike°ä²¼2020ÄêÁäÎñÏìÓ¦ºÍ×Ô¶¯·þÎñ·ÖÎö»ã±¨

CrowdStrike°ä²¼ÁË2020ÄêÁäÎñÏìÓ¦ºÍ×Ô¶¯·þÎñ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬£¬£¬68£¥µÄÊܺ¦×éÖ¯ÔÚÒ»ÄêÄÚ½«Ôâ·êµÚ¶þ´Î¹¥»÷¡£¡£¡£¡£¡£¡£¡£ÔÚ³öÓÚ²ÆÕþ¶¯»úµÄÍøÂç¹¥»÷ÖУ¬£¬£¬£¬£¬£¬£¬£¬81£¥µÄÊÂÎñÓëÀÕË÷Èí¼þÓйأ¬£¬£¬£¬£¬£¬£¬£¬ÆäÓàµÄ19£¥·ÖΪÏúÊÛµãÈëÇÖ¡¢µç×ÓÉÌÎñÍøÕ¾¹¥»÷¡¢Ã³Ò×µç×ÓÓʼþй¶£¨BEC£©ºÍ¼ÓÃÜÇ®±ÒÍڿ󡣡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬Óë¹ú¶ÈÓйصĹ¥»÷»î¶¯ÒÀÈ»ÊǸ÷Ðи÷ÒµµÄÑϳÁÍþв¡£¡£¡£¡£¡£¡£¡£CrowdStrikeµÄCSO Shawn HenryÖ¸³ö£¬£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¤×÷Ϊ¹¥»÷ÕßÌṩÁËÐµĹ¥»÷ÃæºÍý½é£¬£¬£¬£¬£¬£¬£¬£¬¶øÈ«ÃæµÄкÍг³ÖÐøµÄ¾¯ÌèÊÇ·¢ÏÖºÍ×èÖ¹¸´ÔÓÈëÇֵĹؼü¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.crowdstrike.com/resources/reports/cyber-front-lines/


¾©¹«Íø°²±¸11010802024551ºÅ