Google TensorFlowΪÐÞ¸´RCE©¶´¶ø²»ÔÙÖ§³ÖYAML£ºNetgearÐû²¼Äþ¾²¸üÐÂ

Ðû²¼Ê±¼ä 2021-09-08

Google TensorFlowΪÐÞ¸´RCE©¶´¶ø²»ÔÙÖ§³ÖYAML


Google TensorFlowΪÐÞ¸´RCE©¶´¶ø²»ÔÙÖ§³ÖYAML.jpg

 

Google¿ª·¢µÄ»ùÓÚPythonµÄ»úÆ÷ѧϰºÍÈ˹¤ÖÇÄÜÏîÄ¿TensorFlowÒѾ­·ÅÆúÁ˶ÔYAMLµÄÖ§³Ö ¡£TensorFlow´úÂëÖеÄyaml.unsafe_load()º¯Êý´æÔÚÒ»¸ö©¶´ £¬×·×ÙΪCVE-2021-37678 £¬ÆÀ·ÖΪ9.3 ¡£µ±Ó¦Ó÷´ÐòÁл¯YAML¸ñʽµÄKerasÄ£ÐÍʱ £¬¹¥»÷Õß¿ÉÀûÓøÃ©¶´Ö´ÐÐÈÎÒâ´úÂë ¡£ÎªÐÞ¸´´Ë©¶´ £¬TensorFlow¾ö¶¨ÍêÈ«·ÅÆúYAMLµÄÖ§³Ö £¬×ª¶øÊ¹ÓÃJSON·´ÐòÁл¯ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/googles-tensorflow-drops-yaml-support-due-to-code-execution-flaw/


NetgearÐû²¼Äþ¾²¸üР£¬ÐÞ¸´Ó°ÏìÆä20¿î²úÎïµÄ©¶´


NetgearÐû²¼Äþ¾²¸üÐÂ£¬ÐÞ¸´Ó°ÏìÆä20¿î²úÎïµÄ©¶´.jpg


ÍøÂçÉ豸¹©Ó¦ÉÌNetgearÓÚÉÏÖÜ9ÔÂ3ÈÕÐû²¼ÁËÄþ¾²¸üР£¬ÐÞ¸´Ó°ÏìÆä20¿î²úÎïµÄ3¸ö©¶´ ¡£ÕâЩ©¶´µÄ´úºÅ·Ö±ðΪDemon's Cries¡¢Draconian FearºÍSeventh Inferno £¬Ä¿Ç°Ç°Á½¸ö©¶´µÄPoCÒѾ­¹ûÈ» ¡£ÆäÖÐ £¬×îÑÏÖØµÄÊÇDemon's Cries £¬CVSSv3ÆÀ·ÖΪ9.8 £¬¿ÉÓÃÓÚÈÆ¹ýÉí·ÝÑéÖ¤²¢½Ó¹ÜÉ豸 ¡£Draconian FearÒ²ÊÇÉí·ÝÑéÖ¤ÈÆ¹ý©¶´ £¬µ«Ö»ÄÜÓÃÓڽٳֵǼµÄ¹ÜÀíÔ±»á»° ¡£Ñо¿ÈËÔ±Ô¤¼ÆÔÚÏÂÖÜÒ» £¬¼´9ÔÂ13ÈÕÐû²¼¹ØÂ©¶´Seventh InfernoµÄ¼¼Êõϸ½Ú ¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/demons-cries-authentication-bypass-patched-in-netgear-switches/


Node.js¿ª·¢ÍŶÓÐÞ¸´NPM°ünode-tarÖеĶà¸ö©¶´


Node.js¿ª·¢ÍŶÓÐÞ¸´NPM°ünode-tarÖеĶà¸ö©¶´.png


Node.js¿ª·¢ÍŶÓÐÞ¸´ÁËNPM°ü¡°tar¡±£¨ÓÖÃûnode-tar£©ÖеÄ5¸ö©¶´ ¡£ÆäÖнÏΪÑÏÖØµÄÊÇ©¶´CVE-2021-37712ºÍCVE-2021-37701 ¡£Èç¹ú¼Ò©¶´Êý¾Ý¿â(NVD)ÖÐËùÊö £¬ÕâÁ½¸ö©¶´¿ÉÓÃÀ´´´½¨ºÍÁýÕÖÈÎÒâÎļþ £¬»òÖ´ÐÐÈÎÒâ´úÂë £¬CVSSÆÀ·Ö¾ùΪ8.2 ¡£´Ë´ÎÐÞ¸´µÄ©¶´Ó°ÏìÁ˸ÃNPM°ü°æ±¾5.0.0֮ǰµÄ°æ±¾ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/09/critical-flaws-in-npm-package-patched.html


ÖйúÏã¸ÛBilaxyÔâµ½¹¥»÷ £¬Ô¤¼ÆËðʧÁè¼Ý2100ÍòÃÀÔª


ÖйúÏã¸ÛBilaxyÔâµ½¹¥»÷£¬Ô¤¼ÆËðʧÁè¼Ý2100ÍòÃÀÔª.jpg


8ÔÂ29ÈÕ £¬ÖйúÏã¸ÛµÄ¼ÓÃÜ»õ±Ò½»Ò×ËùBilaxy³ÆÆäÔâµ½¹¥»÷ £¬Ô¤¼ÆËðʧÁè¼Ý2100ÍòÃÀÔª ¡£BilaxyÌåÏÖ £¬¹¥»÷·¢ÉúÔÚ8ÔÂ28ÈÕÏÂÎç6µãµ½7µãÖ®¼ä £¬¹¥»÷ÕßÇÔÈ¡ÁË295¸öERC-20±Ò ¡£Ä¿Ç° £¬BilaxyÒÑÍ£Ö¹ÁËÆäÍøÕ¾ÉÏÕýÔÚ½øÐн»Ò× £¬¶øÇÒ½¨Òé¿Í»§ÔÝʱ²»Òª½«ÓÃÓÚ½»Ò׵ļÓÃÜ»õ±Ò´æÈë½»Ò×Ëù ¡£´ËÍâ £¬¸ÃÍøÕ¾½«ÔÝÍ£·þÎñÖÁÉÙ2ÖÜ £¬ÓÃÀ´·ÖÎöºÚ¿ÍÐÐΪºÍ¸üÐÂϵͳ £¬²¢ÊµÑéÈ¡»Ø±»µÁµÄERC-20±Ò ¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/09/cryptocurrency-exchange-bilaxy-under.html


FortiGuardÐû²¼2021ÄêH1È«ÇòÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß


FortiGuardÐû²¼2021ÄêH1È«ÇòÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß.png


FortiGuardÓÚ8Ô·ÝÐû²¼ÁË2021ÄêH1È«ÇòÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß ¡£³ÂËßÖ¸³ö £¬2021Äê6ÔÂÆ½¾ùÿÖÜÀÕË÷Èí¼þ»î¶¯±ÈÒ»ÄêǰͬÆÚ¸ß³ö10.7±¶ ¡£ÆäÖÐ £¬µçÐÅÐÐÒµÊǹ¥»÷ÕßµÄÊ×ÒªµÄÄ¿±ê £¬Æä´ÎÊÇÕþ¸®¡¢ÍйÜÄþ¾²·þÎñÌṩÉÌ¡¢Æû³µºÍÖÆÔìÐÐÒµ ¡£½©Ê¬ÍøÂçÒ²ÓÐËùÔö¼Ó £¬½ñÄêÄê³õÔÚ35%µÄ×éÖ¯Öмì²âµ½Á˽©Ê¬ÍøÂç»î¶¯ £¬¶øÕâÒ»±ÈÀýÔÚ6¸öÔºóÔö¼ÓΪ51% ¡£´ËÍâ £¬¹¥»÷Õ߸üÇàíùÓÚ¼ì²âÈÆ¹ý¼¼ÊõºÍÌáȨ¼¼Êõ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.fortinet.com/content/dam/fortinet/assets/threat-reports/report-threat-landscape-2021.pdf


Positive TechnologiesÐû²¼2021Ä깤ҵ·çÏյijÂËß


Positive TechnologiesÐû²¼2021Ä깤ҵ·çÏյijÂËß.jpg


Positive TechnologiesÓÚ9ÔÂ1ÈÕÐû²¼ÁË2021Ä깤ҵÐÅÏ¢Äþ¾²·çÏյķÖÎö³ÂËß ¡£³ÂËßÖ¸³ö £¬2020Äê £¬¹¤Òµ²¿ÃÅÊǽö´ÎÓÚÕþ¸®µÄµÚ¶þ´ó¹¥»÷Ä¿±ê £¬ÓÐ12%µÄ¹¥»÷Õë¶Ô¹¤Òµ¹«Ë¾ ¡£ÔÚ91%µÄ¹¤Òµ¹«Ë¾ÖÐ £¬¹¥»÷Õß¿ÉÒÔÉøÍ¸½øÈëÄÚÍø £¬Ö®ºó¹¥»÷Õ߾ͿÉÒÔ»ñµÃÓû§Æ¾¾Ý²¢ÍêÈ«¿ØÖÆ»ù´¡ÉèÊ© ¡£2021Äê5Ô £¬ÔÚThe Standoff 2021µÄÐéÄâ°Ð³¡Õ¹Ê¾ÁËÐÅÏ¢Äþ¾²¶Ô¹¤Òµ×éÖ¯µÄÓ°Ïì £¬¹¥»÷ÕßÔÚÁ½ÌìÄÚ¿ØÖÆÁ˼ÓÓÍÕ¾ £¬Í£Ö¹ÁËÌìÈ»Æø¹©Ó¦²¢Òý·¢Á˱¬Õ¨ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.ptsecurity.com/ww-en/analytics/ics-risks-2021/