Google TensorFlowΪÐÞ¸´RCE©¶´¶ø²»ÔÙÖ§³ÖYAML£ºNetgearÐû²¼Äþ¾²¸üÐÂ
Ðû²¼Ê±¼ä 2021-09-08Google TensorFlowΪÐÞ¸´RCE©¶´¶ø²»ÔÙÖ§³ÖYAML
Google¿ª·¢µÄ»ùÓÚPythonµÄ»úÆ÷ѧϰºÍÈ˹¤ÖÇÄÜÏîÄ¿TensorFlowÒѾ·ÅÆúÁ˶ÔYAMLµÄÖ§³Ö¡£TensorFlow´úÂëÖеÄyaml.unsafe_load()º¯Êý´æÔÚÒ»¸ö©¶´£¬×·×ÙΪCVE-2021-37678£¬ÆÀ·ÖΪ9.3¡£µ±Ó¦Ó÷´ÐòÁл¯YAML¸ñʽµÄKerasÄ£ÐÍʱ£¬¹¥»÷Õß¿ÉÀûÓøÃ©¶´Ö´ÐÐÈÎÒâ´úÂ롣ΪÐÞ¸´´Ë©¶´£¬TensorFlow¾ö¶¨ÍêÈ«·ÅÆúYAMLµÄÖ§³Ö£¬×ª¶øÊ¹ÓÃJSON·´ÐòÁл¯¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/googles-tensorflow-drops-yaml-support-due-to-code-execution-flaw/
NetgearÐû²¼Äþ¾²¸üУ¬ÐÞ¸´Ó°ÏìÆä20¿î²úÎïµÄ©¶´
ÍøÂçÉ豸¹©Ó¦ÉÌNetgearÓÚÉÏÖÜ9ÔÂ3ÈÕÐû²¼ÁËÄþ¾²¸üУ¬ÐÞ¸´Ó°ÏìÆä20¿î²úÎïµÄ3¸ö©¶´¡£ÕâЩ©¶´µÄ´úºÅ·Ö±ðΪDemon's Cries¡¢Draconian FearºÍSeventh Inferno£¬Ä¿Ç°Ç°Á½¸ö©¶´µÄPoCÒѾ¹ûÈ»¡£ÆäÖУ¬×îÑÏÖØµÄÊÇDemon's Cries£¬CVSSv3ÆÀ·ÖΪ9.8£¬¿ÉÓÃÓÚÈÆ¹ýÉí·ÝÑéÖ¤²¢½Ó¹ÜÉ豸¡£Draconian FearÒ²ÊÇÉí·ÝÑéÖ¤ÈÆ¹ý©¶´£¬µ«Ö»ÄÜÓÃÓڽٳֵǼµÄ¹ÜÀíÔ±»á»°¡£Ñо¿ÈËÔ±Ô¤¼ÆÔÚÏÂÖÜÒ»£¬¼´9ÔÂ13ÈÕÐû²¼¹ØÂ©¶´Seventh InfernoµÄ¼¼Êõϸ½Ú¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/demons-cries-authentication-bypass-patched-in-netgear-switches/
Node.js¿ª·¢ÍŶÓÐÞ¸´NPM°ünode-tarÖеĶà¸ö©¶´
Node.js¿ª·¢ÍŶÓÐÞ¸´ÁËNPM°ü¡°tar¡±£¨ÓÖÃûnode-tar£©ÖеÄ5¸ö©¶´¡£ÆäÖнÏΪÑÏÖØµÄÊÇ©¶´CVE-2021-37712ºÍCVE-2021-37701¡£Èç¹ú¼Ò©¶´Êý¾Ý¿â(NVD)ÖÐËùÊö£¬ÕâÁ½¸ö©¶´¿ÉÓÃÀ´´´½¨ºÍÁýÕÖÈÎÒâÎļþ£¬»òÖ´ÐÐÈÎÒâ´úÂ룬CVSSÆÀ·Ö¾ùΪ8.2¡£´Ë´ÎÐÞ¸´µÄ©¶´Ó°ÏìÁ˸ÃNPM°ü°æ±¾5.0.0֮ǰµÄ°æ±¾¡£
ÔÎÄÁ´½Ó£º
https://www.ehackingnews.com/2021/09/critical-flaws-in-npm-package-patched.html
ÖйúÏã¸ÛBilaxyÔâµ½¹¥»÷£¬Ô¤¼ÆËðʧÁè¼Ý2100ÍòÃÀÔª
8ÔÂ29ÈÕ£¬ÖйúÏã¸ÛµÄ¼ÓÃÜ»õ±Ò½»Ò×ËùBilaxy³ÆÆäÔâµ½¹¥»÷£¬Ô¤¼ÆËðʧÁè¼Ý2100ÍòÃÀÔª¡£BilaxyÌåÏÖ£¬¹¥»÷·¢ÉúÔÚ8ÔÂ28ÈÕÏÂÎç6µãµ½7µãÖ®¼ä£¬¹¥»÷ÕßÇÔÈ¡ÁË295¸öERC-20±Ò¡£Ä¿Ç°£¬BilaxyÒÑÍ£Ö¹ÁËÆäÍøÕ¾ÉÏÕýÔÚ½øÐн»Ò×£¬¶øÇÒ½¨Òé¿Í»§ÔÝʱ²»Òª½«ÓÃÓÚ½»Ò׵ļÓÃÜ»õ±Ò´æÈë½»Ò×Ëù¡£´ËÍ⣬¸ÃÍøÕ¾½«ÔÝÍ£·þÎñÖÁÉÙ2ÖÜ£¬ÓÃÀ´·ÖÎöºÚ¿ÍÐÐΪºÍ¸üÐÂϵͳ£¬²¢ÊµÑéÈ¡»Ø±»µÁµÄERC-20±Ò¡£
ÔÎÄÁ´½Ó£º
https://www.ehackingnews.com/2021/09/cryptocurrency-exchange-bilaxy-under.html
FortiGuardÐû²¼2021ÄêH1È«ÇòÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß
FortiGuardÓÚ8Ô·ÝÐû²¼ÁË2021ÄêH1È«ÇòÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬2021Äê6ÔÂÆ½¾ùÿÖÜÀÕË÷Èí¼þ»î¶¯±ÈÒ»ÄêǰͬÆÚ¸ß³ö10.7±¶¡£ÆäÖУ¬µçÐÅÐÐÒµÊǹ¥»÷ÕßµÄÊ×ÒªµÄÄ¿±ê£¬Æä´ÎÊÇÕþ¸®¡¢ÍйÜÄþ¾²·þÎñÌṩÉÌ¡¢Æû³µºÍÖÆÔìÐÐÒµ¡£½©Ê¬ÍøÂçÒ²ÓÐËùÔö¼Ó£¬½ñÄêÄê³õÔÚ35%µÄ×éÖ¯Öмì²âµ½Á˽©Ê¬ÍøÂç»î¶¯£¬¶øÕâÒ»±ÈÀýÔÚ6¸öÔºóÔö¼ÓΪ51%¡£´ËÍ⣬¹¥»÷Õ߸üÇàíùÓÚ¼ì²âÈÆ¹ý¼¼ÊõºÍÌáȨ¼¼Êõ¡£
ÔÎÄÁ´½Ó£º
https://www.fortinet.com/content/dam/fortinet/assets/threat-reports/report-threat-landscape-2021.pdf
Positive TechnologiesÐû²¼2021Ä깤ҵ·çÏյijÂËß
Positive TechnologiesÓÚ9ÔÂ1ÈÕÐû²¼ÁË2021Ä깤ҵÐÅÏ¢Äþ¾²·çÏյķÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬2020Ä꣬¹¤Òµ²¿ÃÅÊǽö´ÎÓÚÕþ¸®µÄµÚ¶þ´ó¹¥»÷Ä¿±ê£¬ÓÐ12%µÄ¹¥»÷Õë¶Ô¹¤Òµ¹«Ë¾¡£ÔÚ91%µÄ¹¤Òµ¹«Ë¾ÖУ¬¹¥»÷Õß¿ÉÒÔÉøÍ¸½øÈëÄÚÍø£¬Ö®ºó¹¥»÷Õ߾ͿÉÒÔ»ñµÃÓû§Æ¾¾Ý²¢ÍêÈ«¿ØÖÆ»ù´¡ÉèÊ©¡£2021Äê5Ô£¬ÔÚThe Standoff 2021µÄÐéÄâ°Ð³¡Õ¹Ê¾ÁËÐÅÏ¢Äþ¾²¶Ô¹¤Òµ×éÖ¯µÄÓ°Ï죬¹¥»÷ÕßÔÚÁ½ÌìÄÚ¿ØÖÆÁ˼ÓÓÍÕ¾£¬Í£Ö¹ÁËÌìÈ»Æø¹©Ó¦²¢Òý·¢Á˱¬Õ¨¡£
ÔÎÄÁ´½Ó£º
https://www.ptsecurity.com/ww-en/analytics/ics-risks-2021/