Proofpoint·¢ÏÖÕë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£´¹µö»î¶¯

°ä²¼¹¦·ò 2021-12-10

Google°ä²¼12Ô·ݸüУ¬½¨¸´chromeÖеĶà¸ö·ì϶


Google°ä²¼12Ô·ݸüУ¬½¨¸´chromeÖеĶà¸ö·ì϶.png


GoogleÔÚ12ÔÂ6ÈÕ°ä²¼chrome°²È«¸üУ¬×ܼƽ¨¸´22¸ö·ì϶ ¡£ÆäÖнÏΪÑϳÁµÄÊÇWebÀûÓ÷¨Ê½ÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2021-4052£©¡¢UI×é¼þÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2021-4053£©¡¢WebRTCÖеÄÔ½½çдÈë·ì϶£¨CVE-2021-4079£©ÒÔ¼°V8ÖеÄÀàÐÍ»ìºÏ·ì϶£¨CVE-2021-4078£© ¡£´Ë±í£¬»¹½¨¸´ÁËÀ©´óÖеĶѻº³åÇøÒç¶Âí½Å£¨CVE-2021-4055£©ºÍANGLEÖеĶѻº³åÇøÒç¶Âí½Å£¨CVE-2021-4058£©µÈ ¡£


Ô­ÎÄÁ´½Ó£º

https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop.html


SonicWall°ä²¼¸üУ¬½¨¸´SMA 100ϵÁÐÖжà¸ö·ì϶


SonicWall°ä²¼¸üУ¬½¨¸´SMA 100ϵÁÐÖжà¸ö·ì϶.png


SonicWallÔÚ12ÔÂ7ÈÕ°ä²¼¸üУ¬½¨¸´SMA 100ϵÁÐÉ豸ÖеĶà¸ö·ì϶ ¡£Õâ´Î½¨¸´µÄ×îΪÑϳÁµÄ·ì϶ÊÇ»ùÓÚ²Ö¿âµÄ»º³åÇøÒç¶Âí½Å£¨CVE-2021-20038£©£¬CVSSÆÀ·ÖΪ9.8£¬ÓÉÓÚÉ豸µÄApache httpd·þÎñÆ÷ÖеÄHTTP GET²½ÖèµÄ»·¾³±äÁ¿Ê¹ÓÃÁËstrcat()º¯Êýµ¼ÖµÄ£»Æä´ÎÊÇ»º³åÇøÒç¶Âí½Å£¨CVE-2021-20045£©£¬CVSSÆÀ·Ö9.4 ¡£´Ë±í£¬»¹½¨¸´ÁË»º³åÇøÒç¶Âí½Å£¨CVE-2021-20043£©ºÍÈÏÖ¤ºÅÁî×¢Èë·ì϶£¨CVE-2021-20039£©µÈ ¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.cisa.gov/uscert/ncas/current-activity/2021/12/08/sonicwall-releases-security-advisory-sma-100-series-appliances


ÑÇÂíÑ·AWSÔÆ·þÎñå´»úÓ°ÏìNetflixµÈ¶à¸öÀûÓÃ


ÑÇÂíÑ·AWSÔÆ·þÎñå´»úÓ°ÏìNetflixµÈ¶à¸öÀûÓÃ.png


12ÔÂ7ÈÕÏÂÎç12µã×óÓÒ£¬ÃÀ¹úUS-EAST-1ÇøÓòµÄÑÇÂíÑ·AWSÔÆ·þÎñå´»ú ¡£Õâ´ÎÊÂÎñÓ°ÏìÁËRing¡¢Netflix¡¢Amazon Prime Video¡¢RobinhoodºÍRokuµÅצÓã¬ÒÔ¼°PUBG¡¢ValorantºÍÓ¢ÐÛͬÃ˵Å×ÎÏ· ¡£¸Ã¹«Ë¾ÔÚµ±Ìì12:34È·ÈÏÁËÖжÏÊÂÎñ£¬²¢³Æµ××ÓÔ­ÒòÊǶà¸öÍøÂçÉ豸ÊÜËð ¡£12ÔÂ7ÈÕÏÂÎç4:35£¬ÑÇÂíÑ·°µÊ¾ÍøÂçÉ豸ÎÊÌâÒѾ­½â¾ö£¬ËûÃÇÔÚÖÂÁ¦¸´Ô­ÊÜËð·þÎñ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/amazon-web-service-outage-impact-major-websites/


Proofpoint·¢ÏÖÕë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£´¹µö»î¶¯


Proofpoint·¢ÏÖÕë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£´¹µö»î¶¯.png


Proofpoint¹«¿ªÁ˽üÆÚ´ó¹æÄ£´¹µö»î¶¯ÖÐʹÓõÄÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½(TTP)µÄ¾ßÌåÐÅÏ¢ ¡£Õâ´Î»î¶¯ÆðÍ·ÓÚ½ñÄê10Ô·Ý£¬À´×Ô¶à¸öºÚ¿ÍÍÅ»ï£¬ÖØÒªÕë¶ÔÃÀ¹úµÄ´óѧ ¡£ÕâЩ¹¥»÷ͨ¹ýÒÔOmicron±äÌå¡¢COVID-19²âÊÔÁË¾ÖºÍÆäËü²âÊÔÒªÇóΪÖ÷ÌâµÄ´¹µöÓʼþ£¬ÓÕʹָ±ê´ò¿ª¸½¼þÖеÄHTMÎļþ£¬²¢½«Æä³Á¶¨Ïòµ½¼Ù×°³ÉËûÃÇ´óѧµÇÂ¼ÍøÕ¾µÄ´¹µöÒ³Ãæ£¬Ö¼ÔÚÇÔÊØÐÅÏ¢ ¡£ÎªÁËÈÆ¹ýMFA±£»¤£¬¹¥»÷Õß»¹´´½¨ÁËαÔìµÄDUO MFAÍøÕ¾ÒÔÇÔÈ¡Óû§µÄOTP ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-universities-targeted-by-office-365-phishing-attacks/


QNAPÌáÐѿͻ§°ÑÎȽüÆÚÕë¶ÔÆäNASÉ豸µÄÍÚ¿ó»î¶¯


QNAPÌáÐѿͻ§°ÑÎȽüÆÚÕë¶ÔÆäNASÉ豸µÄÍÚ¿ó»î¶¯.png


Öйų́ÍåµÄNASÉ豸Ôì×÷ÉÌQNAPÔÚ12ÔÂ7ÈÕ°ä²¼¹«¸æ£¬ÌáÐÑÓû§°ÑÎȽüÆÚµÄ¶ñÒâÍÚ¿ó»î¶¯ ¡£¹«¸æ³Æ£¬Õâ´Î»î¶¯¶Ô×¼ÁËQNAP NAS ¡£Ò»µ©NAS±»Ï°È¾£¬CPUʹÓÃÂÊ»á±äµÃÒì³£¸ß£¬ÆäÖÐÃûΪ¡°[oom_reaper]¡±µÄ¹ý³Ì¿ÉÄÜ»áÕ¼ÓÃ×ÜCPUʹÓÃÂʵÄ50%×óÓÒ ¡£Õâ¸ö¹ý³Ì·ÂÕÕÁËÒ»¸öºÏ·¨µÄͬÃûÄں˹ý³Ì£¬µ«ÊÇÕý³£Äں˹ý³ÌPIDͨ³£µÍÓÚ1000£¬¶ø¸Ã¿ó¹¤PIDͨ³£´óÓÚ1000 ¡£QNAP½¨ÒéÓû§½«QTS¸üе½×îа汾£¬²¢Ê¹ÓÃÇ¿ÃÜÂë ¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/12/warning-yet-another-bitcoin-mining.html


ÐÂÀÕË÷Èí¼þCerber¶Ô×¼ConfluenceºÍGitLab·þÎñÆ÷


ÐÂÀÕË÷Èí¼þCerber¶Ô×¼ConfluenceºÍGitLab·þÎñÆ÷.png


12ÔÂ7ÈÕ£¬×êÑÐÈËÔ±·¢ÏÖʹÓÃÁ˾ÉÃû³ÆµÄÐÂÀÕË÷Èí¼þCerber ¡£ÀÕË÷Èí¼þCerberÓÚ2016Äê³öÏÖ£¬Ö±µ½2019Äêµ×Òþû ¡£´ÓÉϸöÔÂÆðÍ·£¬Cerbe»Ø¹é£¬µ«ÊÇËüÓë¾É°æ²¢²»Ò»Ñù£¬´úÂ벻ƥÅ䣬аæÊ¹ÓÃCrypto+++¿â¶ø¾É°æ±¾Ê¹ÓÃWindows CryptoAPI¿â£¬²¢ÇҾɰæCerberҲûÓÐLinux±äÌå ¡£ÐÂCerberµÄÊê½ðÒªÇó´Ó1000ÃÀÔªµ½3000ÃÀÔª²»µÈ£¬ÀûÓÃÁËCVE-2021-26084ºÍCVE-2021-22205·ì϶¶Ô×¼ConfluenceºÍGitLab·þÎñÆ÷£¬ÖØÒªÕë¶ÔÃÀ¹ú¡¢µÂ¹úºÍÖйú ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-cerber-ransomware-targets-confluence-and-gitlab-servers/