Adobe´¹Î£¸üУ¬½¨¸´ColdFusionËÁÒâ´úÂëÖ´Ðзì϶£»McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetopVisionProÖжà¸ö·ì϶

°ä²¼¹¦·ò 2021-03-23

1.Adobe°ä²¼´¹Î£¸üУ¬½¨¸´ColdFusionÖÐËÁÒâ´úÂëÖ´Ðзì϶


1.jpg


AdobeÓÚ3ÔÂ22ÈÕ°ä²¼´¹Î£´ø±í¸üУ¬½¨¸´ColdFusionÖеÄËÁÒâ´úÂëÖ´Ðзì϶¡£¸Ã·ì϶ÊÇÓÉÓÚÎÞ·¨ÑéÖ¤ÊäÈ뵼ֵ쬱»¸ú×ÙΪCVE-2021-21087£¬Ó°ÏìÁËColdFusion°æ±¾2021¡¢2016ºÍ2018¡£Adobe½¨ÒéÖÎÀíÔ±¾¡¿ì×°Öð²È«¸üУ¬²¢ÀûÓùٷ½Ö¸ÄÏÖÐÃèÊöµÄ°²È«ÅäÖÃ¶ÔÆä½øÐÐÉèÖᣠ


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/critical-code-execution-vulnerability-fixed-in-adobe-coldfusion/


2.McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetop Vision Pro´æÔÚ¶à¸ö·ì϶


2.jpg


McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetop Vision Pro´æÔÚ¶à¸ö¿ÉÓÃÀ´½Ù³ÖÖ¸±êµçÄԵķì϶¡£ÕâЩ·ì϶±ðÀëΪȨÏÞ·ÖÅä·ì϶£¨CVE-2021-27192£©¡¢Ä¬ÈÏȨÏÞÃýÎó£¨CVE-2021-27193£©¡¢ÒÔÃ÷ÎÄ´«ÊäµÄÃô¸ÐÐÅÏ¢£¨CVE-2021-27194£©ºÍÊÚȨÎÊÌ⣨CVE-2021-27195£©¡£ºÚ¿Í¿ÉÓÃÕâЩ·ì϶½øÐÐÌáȨºÍÖ´ÐÐÔ¶³Ì´úÂ룬»ñµÃ¶ÔÖ¸±êϵͳµÄÆëÈ«½ÚÔìȨ²¢ÆôÓÃÍøÂçÉãÏñÍ·ºÍÂó¿Ë·ç¡£Ä¿Ç°£¬NetopÒѽ¨¸´²¿ÃÅ·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/popular-remote-student-learning-program-found-to-be-riddled-with-security-holes/


3.µçÁ¦¹«Ë¾Celg GTÕû¸öÍøÂçÎÞ·¨½Ó¼û£¬ÊÂÎñÈÔÔÚµ÷²éÖÐ


3.jpg


CelgGera??oeTransmiss?o£¨Celg GT£©ÓÚÉÏÖÜÎå(3ÔÂ19ÈÕ)³ÆÆäÔâµ½Á˹¥»÷£¬ËùÓеÄÀûÓ÷¨Ê½ºÍÕû¸öÎļþϵͳ¶¼ÎÞ·¨½Ó¼û¡£¸Ã¹«Ë¾°µÊ¾£¬¹¥»÷ÊÇ´ÓÁ賿ÆðÍ·µÄ£¬Æä·¢ÏÖºóµ±¼´²ÉÈ¡ÏìÓ¦´ëÊ©£¬¹Ø¹ØÏµÍ³ÒÔ±£»¤ÐÅÏ¢ºÍ±¸·Ý×ÊÁÏ¡£Ä¿Ç°£¬¸ÃÊÂÎñÈÔÔÚµ÷²éÖУ¬Éв»ÄÜÈ·¶¨ÏµÍ³°Ü»µµÄˮƽÒÔ¼°¹¥»÷µÄÆðÔ´£¬µ«ÊÇÄܹ»È·¶¨Ã»ÓÐÈκÎÓ×ÎÒÐÅÏ¢±»Ð¹Â¶£¬¹«Ë¾Ô±¹¤µÄµç×ÓÓʼþ·þÎñÒ²Äܹ»Õý³£ÔËÐС£


Ô­ÎÄÁ´½Ó£º

https://www.jornalopcao.com.br/ultimas-noticias/ataque-hacker-compromete-funcionamento-de-aplicativos-e-arquivos-da-celg-gt-318176/


4.²®Ã÷º²Òé»áÔ±¹¤Òò²Ù×÷ʧÎ󹫿ª´óÁ¿ÈõÊÆÈºÌåµÄÓ×ÎÒÐÅÏ¢


4.jpg


²®Ã÷º²Òé»áÔÚ3ÔÂ19ÈÕÐÇÆÚÎ峯£¬ÒòÔ±¹¤²Ù×÷ʧÎóµ¼Ö´óÁ¿ÈõÊÆÈºÌåµÄÓ×ÎÒÐÅÏ¢±»¹«¿ª¡£¾Ý³ÆÕâ´Îй¶µÄÊÇÓÐȨ»ñµÃÃâ·Ñ°Íʿͨ³©Ö¤µÄ¶ùͯµÄ¾ßÌåÐÅÏ¢¡£¸ÃÊаµÊ¾£¬ÆäÔÚ·¢ÏÖй¶ºóÂíÉϲÉÈ¡ÁË´ëÊ©£¬Êý¾Ý»¹Î´±»ÏÂÔØ£¬²¢ÇÒÓÉÓÚ´ËÊÂÎñµÄ¹æÄ£ºÍÑϳÁÐÔÖÊ£¬ÏÖÒÑÍ¨ÖªÕÆ¹Ü¼à¶½µÄÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©¡£


Ô­ÎÄÁ´½Ó£º

https://www.birminghammail.co.uk/news/midlands-news/details-vulnerable-kids-uploaded-birmingham-20217314


5.Black Kite°ä²¼·ì϶¶ÔÐÅÓþºÏ×÷ÉçµÄÓ°ÏìµÄ·ÖÎö»ã±¨


5.jpg


Black Kite°ä²¼ÁËÓйطì϶¶ÔÐÅÓþºÏ×÷ÉçµÄÓ°ÏìµÄ·ÖÎö»ã±¨¡£»ã±¨ÏÔʾ£¬Í´´¦Ð¹Â¶¡¢Î´¸üеľÉϵͳºÍ¹©¸øÉÌ·ì϶ÊÇÐÅÓþºÏ×÷ÉçËùÃæ¶ÔµÄ×î´óµÄÍøÂç·çÏÕ¡£´Ë±í£¬Õë¶Ô¹©¸øÉ̵Ĺ¥»÷ΪÐÅÓþºÏ×÷Éç¿ÉÄÜ»áÔì³É³¬¹ý100ÍòÃÀÔªµÄDZÔÚ²ÆÎïËðʧ£»86%µÄÐÅÓþºÏ×÷ÉçºÍ76%µÄ¹©¸øÉ̵ÄÔ±¹¤Í´´¦Òѱ»ÇÔÈ¡²¢¹«¿ªµ½°µÍøÉÏ£»³¬¹ý66%µÄÐÅÓþºÏ×÷ÉçºÍ88%µÄ¹©¸øÉ̲»×ãÔ¤·ÀºýŪºÍ´¹µö¹¥»÷µÄµç×ÓÓʼþ°²È«Õ½Êõ¡£


Ô­ÎÄÁ´½Ó£º

https://googleprojectzero.blogspot.com/2021/03/in-wild-series-october-2020-0-day.html


6.Vectra°ä²¼ÓйØOffice 365ºÍÔÆµÄ°²È«Ì¬ÊƵķÖÎö»ã±¨


6.jpg


Vectra°ä²¼ÁËÓйØOffice 365ºÍÔÆµÄ°²È«Ì¬ÊƵķÖÎö»ã±¨¡£»ã±¨ÏÔʾ£¬ÔÚ´ÓǰһÄֻ꣬¹ÜѡȡÁ˶à³É·ÖÉí·ÝÑéÖ¤£¨MFA£©£¬µ«ÈÔÓÐ71£¥µÄÆóÒµÒÀÈ»¾­Àú¹ýSaaSÕÊ»§½Ù³Ö£¬½ü90£¥µÄÆóÒµ»¹ÔÚ¼Ó¿ìÔÆÍÆËãºÍÊý×Ö»¯µÄתÐÍ¡£´Ë±í£¬¸Ã»ã±¨ÔÚ90ÌìÄÚ¸ú×ÙÁË400Íò¸öMicrosoft Office 365¿Í»§µÄÐÐΪ£¬·¢ÏÖÓÐ96£¥µÄÄÚÍø´æÔÚ¿ÉÒɵĺáÏòÒÆ¶¯ÐÐΪ¡£Îå·ÖÖ®ËĵݲȫרҵÈËÔ±°µÊ¾£¬ÔÚ´ÓǰһÄêÖÐÍøÂ簲ȫµÄ·çÏÕÓÐËùÔö³¤¡£


Ô­ÎÄÁ´½Ó£º

https://www.vectra.ai/blogpost/cloud-security-insights