Proofpoint·¢ÏÖÕë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£´¹µö»î¶¯

°ä²¼¹¦·ò 2021-12-10

Google°ä²¼12Ô·ݸüУ¬£¬£¬£¬ £¬£¬ £¬½¨¸´chromeÖеĶà¸ö·ì϶


Google°ä²¼12Ô·ݸüУ¬£¬£¬£¬£¬£¬£¬½¨¸´chromeÖеĶà¸ö·ì϶.png


GoogleÔÚ12ÔÂ6ÈÕ°ä²¼chrome°²È«¸üУ¬£¬£¬£¬ £¬£¬ £¬×ܼƽ¨¸´22¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£ÆäÖнÏΪÑϳÁµÄÊÇWebÀûÓ÷¨Ê½ÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2021-4052£©¡¢UI×é¼þÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2021-4053£©¡¢WebRTCÖеÄÔ½½çдÈë·ì϶£¨CVE-2021-4079£©ÒÔ¼°V8ÖеÄÀàÐÍ»ìºÏ·ì϶£¨CVE-2021-4078£©¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬ £¬£¬ £¬»¹½¨¸´ÁËÀ©´óÖеĶѻº³åÇøÒç¶Âí½Å£¨CVE-2021-4055£©ºÍANGLEÖеĶѻº³åÇøÒç¶Âí½Å£¨CVE-2021-4058£©µÈ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop.html


SonicWall°ä²¼¸üУ¬£¬£¬£¬ £¬£¬ £¬½¨¸´SMA 100ϵÁÐÖжà¸ö·ì϶


SonicWall°ä²¼¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´SMA 100ϵÁÐÖжà¸ö·ì϶.png


SonicWallÔÚ12ÔÂ7ÈÕ°ä²¼¸üУ¬£¬£¬£¬ £¬£¬ £¬½¨¸´SMA 100ϵÁÐÉ豸ÖеĶà¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ×îΪÑϳÁµÄ·ì϶ÊÇ»ùÓÚ²Ö¿âµÄ»º³åÇøÒç¶Âí½Å£¨CVE-2021-20038£©£¬£¬£¬£¬ £¬£¬ £¬CVSSÆÀ·ÖΪ9.8£¬£¬£¬£¬ £¬£¬ £¬ÓÉÓÚÉ豸µÄApache httpd·þÎñÆ÷ÖеÄHTTP GET²½ÖèµÄ»·¾³±äÁ¿Ê¹ÓÃÁËstrcat()º¯Êýµ¼Öµģ»£»£»£»£»£»£»Æä´ÎÊÇ»º³åÇøÒç¶Âí½Å£¨CVE-2021-20045£©£¬£¬£¬£¬ £¬£¬ £¬CVSSÆÀ·Ö9.4¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬ £¬£¬ £¬»¹½¨¸´ÁË»º³åÇøÒç¶Âí½Å£¨CVE-2021-20043£©ºÍÈÏÖ¤ºÅÁî×¢Èë·ì϶£¨CVE-2021-20039£©µÈ¡£¡£¡£¡£¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.cisa.gov/uscert/ncas/current-activity/2021/12/08/sonicwall-releases-security-advisory-sma-100-series-appliances


ÑÇÂíÑ·AWSÔÆ·þÎñå´»úÓ°ÏìNetflixµÈ¶à¸öÀûÓÃ


ÑÇÂíÑ·AWSÔÆ·þÎñå´»úÓ°ÏìNetflixµÈ¶à¸öÀûÓÃ.png


12ÔÂ7ÈÕÏÂÎç12µã×óÓÒ£¬£¬£¬£¬ £¬£¬ £¬ÃÀ¹úUS-EAST-1ÇøÓòµÄÑÇÂíÑ·AWSÔÆ·þÎñå´»ú¡£¡£¡£¡£¡£¡£¡£Õâ´ÎÊÂÎñÓ°ÏìÁËRing¡¢Netflix¡¢Amazon Prime Video¡¢RobinhoodºÍRokuµÅצÓ㬣¬£¬£¬ £¬£¬ £¬ÒÔ¼°PUBG¡¢ValorantºÍÓ¢ÐÛÁªÃ˵Å×ÎÏ·¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚµ±Ìì12:34È·ÈÏÁËÖжÏÊÂÎñ£¬£¬£¬£¬ £¬£¬ £¬²¢³Æµ××ÓÔ­ÒòÊǶà¸öÍøÂçÉ豸ÊÜË𡣡£¡£¡£¡£¡£¡£12ÔÂ7ÈÕÏÂÎç4:35£¬£¬£¬£¬ £¬£¬ £¬ÑÇÂíÑ·°µÊ¾ÍøÂçÉ豸ÎÊÌâÒѾ­½â¾ö£¬£¬£¬£¬ £¬£¬ £¬ËûÃÇÔÚÖÂÁ¦¸´Ô­ÊÜËð·þÎñ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/amazon-web-service-outage-impact-major-websites/


Proofpoint·¢ÏÖÕë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£´¹µö»î¶¯


Proofpoint·¢ÏÖÕë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£´¹µö»î¶¯.png


Proofpoint¹«¿ªÁ˽üÆÚ´ó¹æÄ£´¹µö»î¶¯ÖÐʹÓõÄÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½(TTP)µÄ¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯ÆðÍ·ÓÚ½ñÄê10Ô·Ý£¬£¬£¬£¬ £¬£¬ £¬À´×Ô¶à¸öºÚ¿ÍÍŻ£¬£¬£¬ £¬£¬ £¬ÖØÒªÕë¶ÔÃÀ¹úµÄ´óѧ¡£¡£¡£¡£¡£¡£¡£ÕâЩ¹¥»÷ͨ¹ýÒÔOmicron±äÌå¡¢COVID-19²âÊÔÁË¾ÖºÍÆäËü²âÊÔÒªÇóΪÖ÷ÌâµÄ´¹µöÓʼþ£¬£¬£¬£¬ £¬£¬ £¬ÓÕʹָ±ê´ò¿ª¸½¼þÖеÄHTMÎļþ£¬£¬£¬£¬ £¬£¬ £¬²¢½«Æä³Á¶¨Ïòµ½¼Ù×°³ÉËûÃÇ´óѧµÇÂ¼ÍøÕ¾µÄ´¹µöÒ³Ãæ£¬£¬£¬£¬ £¬£¬ £¬Ö¼ÔÚÇÔÊØÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÎªÁËÈÆ¹ýMFA±£»£»£»£»£»£»£»¤£¬£¬£¬£¬ £¬£¬ £¬¹¥»÷Õß»¹´´½¨ÁËαÔìµÄDUO MFAÍøÕ¾ÒÔÇÔÈ¡Óû§µÄOTP¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-universities-targeted-by-office-365-phishing-attacks/


QNAPÌáÐѿͻ§°ÑÎȽüÆÚÕë¶ÔÆäNASÉ豸µÄÍÚ¿ó»î¶¯


QNAPÌáÐѿͻ§°ÑÎȽüÆÚÕë¶ÔÆäNASÉ豸µÄÍÚ¿ó»î¶¯.png


Öйų́ÍåµÄNASÉ豸Ôì×÷ÉÌQNAPÔÚ12ÔÂ7ÈÕ°ä²¼¹«¸æ£¬£¬£¬£¬ £¬£¬ £¬ÌáÐÑÓû§°ÑÎȽüÆÚµÄ¶ñÒâÍÚ¿ó»î¶¯¡£¡£¡£¡£¡£¡£¡£¹«¸æ³Æ£¬£¬£¬£¬ £¬£¬ £¬Õâ´Î»î¶¯¶Ô×¼ÁËQNAP NAS¡£¡£¡£¡£¡£¡£¡£Ò»µ©NAS±»Ï°È¾£¬£¬£¬£¬ £¬£¬ £¬CPUʹÓÃÂÊ»á±äµÃÒì³£¸ß£¬£¬£¬£¬ £¬£¬ £¬ÆäÖÐÃûΪ¡°[oom_reaper]¡±µÄ¹ý³Ì¿ÉÄÜ»áÕ¼ÓÃ×ÜCPUʹÓÃÂʵÄ50%×óÓÒ¡£¡£¡£¡£¡£¡£¡£Õâ¸ö¹ý³Ì·ÂÕÕÁËÒ»¸öºÏ·¨µÄͬÃûÄں˹ý³Ì£¬£¬£¬£¬ £¬£¬ £¬µ«ÊÇÕý³£Äں˹ý³ÌPIDͨ³£µÍÓÚ1000£¬£¬£¬£¬ £¬£¬ £¬¶ø¸Ã¿ó¹¤PIDͨ³£´óÓÚ1000¡£¡£¡£¡£¡£¡£¡£QNAP½¨ÒéÓû§½«QTS¸üе½×îа汾£¬£¬£¬£¬ £¬£¬ £¬²¢Ê¹ÓÃÇ¿ÃÜÂë¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/12/warning-yet-another-bitcoin-mining.html


ÐÂÀÕË÷Èí¼þCerber¶Ô×¼ConfluenceºÍGitLab·þÎñÆ÷


ÐÂÀÕË÷Èí¼þCerber¶Ô×¼ConfluenceºÍGitLab·þÎñÆ÷.png


12ÔÂ7ÈÕ£¬£¬£¬£¬ £¬£¬ £¬×êÑÐÈËÔ±·¢ÏÖʹÓÃÁ˾ÉÃû³ÆµÄÐÂÀÕË÷Èí¼þCerber¡£¡£¡£¡£¡£¡£¡£ÀÕË÷Èí¼þCerberÓÚ2016Äê³öÏÖ£¬£¬£¬£¬ £¬£¬ £¬Ö±µ½2019Äêµ×Òþû¡£¡£¡£¡£¡£¡£¡£´ÓÉϸöÔÂÆðÍ·£¬£¬£¬£¬ £¬£¬ £¬Cerbe»Ø¹é£¬£¬£¬£¬ £¬£¬ £¬µ«ÊÇËüÓë¾É°æ²¢²»Ò»Ñù£¬£¬£¬£¬ £¬£¬ £¬´úÂ벻ƥÅ䣬£¬£¬£¬ £¬£¬ £¬Ð°æÊ¹ÓÃCrypto+++¿â¶ø¾É°æ±¾Ê¹ÓÃWindows CryptoAPI¿â£¬£¬£¬£¬ £¬£¬ £¬²¢ÇҾɰæCerberҲûÓÐLinux±äÌå¡£¡£¡£¡£¡£¡£¡£ÐÂCerberµÄÊê½ðÒªÇó´Ó1000ÃÀÔªµ½3000ÃÀÔª²»µÈ£¬£¬£¬£¬ £¬£¬ £¬ÀûÓÃÁËCVE-2021-26084ºÍCVE-2021-22205·ì϶¶Ô×¼ConfluenceºÍGitLab·þÎñÆ÷£¬£¬£¬£¬ £¬£¬ £¬ÖØÒªÕë¶ÔÃÀ¹ú¡¢µÂ¹úºÍÖйú¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-cerber-ransomware-targets-confluence-and-gitlab-servers/