Proofpoint·¢ÏÖÕë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£µöÓã»î¶¯

Ðû²¼Ê±¼ä 2021-12-10

GoogleÐû²¼12Ô·ݸüУ¬ÐÞ¸´chromeÖеĶà¸ö©¶´


GoogleÐû²¼12Ô·ݸüУ¬ÐÞ¸´chromeÖеĶà¸ö©¶´.png


GoogleÔÚ12ÔÂ6ÈÕÐû²¼chromeÄþ¾²¸üУ¬×ܼÆÐÞ¸´22¸ö©¶´¡£ÆäÖнÏΪÑÏÖØµÄÊÇWebÓ¦Ó÷¨Ê½ÖеÄÊͷźóʹÓé¶´£¨CVE-2021-4052£©¡¢UI×é¼þÖеÄÊͷźóʹÓé¶´£¨CVE-2021-4053£©¡¢WebRTCÖеÄÔ½½çдÈë©¶´£¨CVE-2021-4079£©ÒÔ¼°V8ÖеÄÀàÐÍ»ìÏý©¶´£¨CVE-2021-4078£©¡£´ËÍ⣬»¹ÐÞ¸´ÁËÀ©Õ¹ÖеĶѻº³åÇøÒç³ö©¶´£¨CVE-2021-4055£©ºÍANGLEÖеĶѻº³åÇøÒç³ö©¶´£¨CVE-2021-4058£©µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop.html


SonicWallÐû²¼¸üУ¬ÐÞ¸´SMA 100ϵÁÐÖжà¸ö©¶´


SonicWallÐû²¼¸üУ¬ÐÞ¸´SMA 100ϵÁÐÖжà¸ö©¶´.png


SonicWallÔÚ12ÔÂ7ÈÕÐû²¼¸üУ¬ÐÞ¸´SMA 100ϵÁÐÉ豸ÖеĶà¸ö©¶´¡£´Ë´ÎÐÞ¸´µÄ×îΪÑÏÖØµÄ©¶´ÊÇ»ùÓÚ¶ÑÕ»µÄ»º³åÇøÒç³ö©¶´£¨CVE-2021-20038£©£¬CVSSÆÀ·ÖΪ9.8£¬ÓÉÓÚÉ豸µÄApache httpd·þÎñÆ÷ÖеÄHTTP GETÒªÁìµÄ»·¾³±äÁ¿Ê¹ÓÃÁËstrcat()º¯Êýµ¼ÖµÄ£»Æä´ÎÊÇ»º³åÇøÒç³ö©¶´£¨CVE-2021-20045£©£¬CVSSÆÀ·Ö9.4¡£´ËÍ⣬»¹ÐÞ¸´ÁË»º³åÇøÒç³ö©¶´£¨CVE-2021-20043£©ºÍÈÏÖ¤ÃüÁî×¢Èë©¶´£¨CVE-2021-20039£©µÈ¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.cisa.gov/uscert/ncas/current-activity/2021/12/08/sonicwall-releases-security-advisory-sma-100-series-appliances


ÑÇÂíÑ·AWSÔÆ·þÎñå´»úÓ°ÏìNetflixµÈ¶à¸öÓ¦ÓÃ


ÑÇÂíÑ·AWSÔÆ·þÎñå´»úÓ°ÏìNetflixµÈ¶à¸öÓ¦ÓÃ.png


12ÔÂ7ÈÕÏÂÎç12µã×óÓÒ£¬ÃÀ¹úUS-EAST-1ÇøÓòµÄÑÇÂíÑ·AWSÔÆ·þÎñå´»ú¡£´Ë´ÎʼþÓ°ÏìÁËRing¡¢Netflix¡¢Amazon Prime Video¡¢RobinhoodºÍRokuµÈÓ¦Óã¬ÒÔ¼°PUBG¡¢ValorantºÍÓ¢ÐÛÁªÃ˵ÈÓÎÏ·¡£¸Ã¹«Ë¾ÔÚµ±Ìì12:34È·ÈÏÁËÖжÏʼþ£¬²¢³Æ»ù´¡Ô­ÒòÊǶà¸öÍøÂçÉ豸ÊÜËð¡£12ÔÂ7ÈÕÏÂÎç4:35£¬ÑÇÂíÑ·ÌåÏÖÍøÂçÉ豸ÎÊÌâÒѾ­½â¾ö£¬ËûÃÇÕýÔÚŬÁ¦»Ö¸´ÊÜËð·þÎñ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/amazon-web-service-outage-impact-major-websites/


Proofpoint·¢ÏÖÕë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£µöÓã»î¶¯


Proofpoint·¢ÏÖÕë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£µöÓã»î¶¯.png


Proofpoint¹ûÈ»Á˽üÆÚ´ó¹æÄ£µöÓã»î¶¯ÖÐʹÓõļÆÄ±¡¢¼¼ÊõºÍ·¨Ê½(TTP)µÄÏêϸÐÅÏ¢¡£´Ë´Î»î¶¯¿ªÊ¼ÓÚ½ñÄê10Ô·Ý£¬À´×Ô¶à¸öºÚ¿ÍÍŻÖ÷ÒªÕë¶ÔÃÀ¹úµÄ´óѧ¡£ÕâЩ¹¥»÷ͨ¹ýÒÔOmicron±äÌå¡¢COVID-19²âÊÔ½á¹ûºÍÆäËü²âÊÔÒªÇóΪÖ÷ÌâµÄµöÓãÓʼþ£¬ÓÕʹĿ±ê´ò¿ª¸½¼þÖеÄHTMÎļþ£¬²¢½«ÆäÖØ¶¨Ïòµ½Î±×°³ÉËûÃÇ´óѧµÇÂ¼ÍøÕ¾µÄµöÓãÒ³Ãæ£¬Ö¼ÔÚÇÔÈ¡ÐÅÏ¢¡£ÎªÁËÈÆ¹ýMFA±£»¤£¬¹¥»÷Õß»¹´´½¨ÁËαÔìµÄDUO MFAÍøÕ¾ÒÔÇÔÈ¡Óû§µÄOTP¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-universities-targeted-by-office-365-phishing-attacks/


QNAPÌáÐѿͻ§×¢Òâ½üÆÚÕë¶ÔÆäNASÉ豸µÄÍÚ¿ó»î¶¯


QNAPÌáÐѿͻ§×¢Òâ½üÆÚÕë¶ÔÆäNASÉ豸µÄÍÚ¿ó»î¶¯.png


Öйų́ÍåµÄNASÉè±¸ÖÆÔìÉÌQNAPÔÚ12ÔÂ7ÈÕÐû²¼Í¨¸æ£¬ÌáÐÑÓû§×¢Òâ½üÆÚµÄ¶ñÒâÍÚ¿ó»î¶¯¡£Í¨¸æ³Æ£¬´Ë´Î»î¶¯Ãé×¼ÁËQNAP NAS¡£Ò»µ©NAS±»Ñ¬È¾£¬CPUʹÓÃÂÊ»á±äµÃÒì³£¸ß£¬ÆäÖÐÃûΪ¡°[oom_reaper]¡±µÄ½ø³Ì¿ÉÄÜ»áÕ¼ÓÃ×ÜCPUʹÓÃÂʵÄ50%×óÓÒ¡£Õâ¸ö½ø³ÌÄ£·ÂÁËÒ»¸öºÏ·¨µÄͬÃûÄں˽ø³Ì£¬µ«ÊÇÕý³£Äں˽ø³ÌPIDͨ³£µÍÓÚ1000£¬¶ø¸Ã¿ó¹¤PIDͨ³£´óÓÚ1000¡£QNAP½¨ÒéÓû§½«QTS¸üе½×îа汾£¬²¢Ê¹ÓÃÇ¿ÃÜÂë¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/12/warning-yet-another-bitcoin-mining.html


ÐÂÀÕË÷Èí¼þCerberÃé×¼ConfluenceºÍGitLab·þÎñÆ÷


ÐÂÀÕË÷Èí¼þCerberÃé×¼ConfluenceºÍGitLab·þÎñÆ÷.png


12ÔÂ7ÈÕ£¬Ñо¿ÈËÔ±·¢ÏÖʹÓÃÁ˾ÉÃû³ÆµÄÐÂÀÕË÷Èí¼þCerber¡£ÀÕË÷Èí¼þCerberÓÚ2016Äê·ºÆð£¬Ö±µ½2019Äêµ×Ïûʧ¡£´ÓÉϸöÔ¿ªÊ¼£¬Cerbe»Ø¹é£¬µ«ÊÇËüÓë¾É°æ²¢²»Ïàͬ£¬´úÂ벻ƥÅ䣬аæÊ¹ÓÃCrypto+++¿â¶ø¾É°æ±¾Ê¹ÓÃWindows CryptoAPI¿â£¬¶øÇҾɰæCerberҲûÓÐLinux±äÌå¡£ÐÂCerberµÄÊê½ðÒªÇó´Ó1000ÃÀÔªµ½3000ÃÀÔª²»µÈ£¬ÀûÓÃÁËCVE-2021-26084ºÍCVE-2021-22205©¶´Ãé×¼ConfluenceºÍGitLab·þÎñÆ÷£¬Ö÷ÒªÕë¶ÔÃÀ¹ú¡¢µÂ¹úºÍÖйú¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-cerber-ransomware-targets-confluence-and-gitlab-servers/