Adobe´¹Î£¸üУ¬½¨¸´ColdFusionËÁÒâ´úÂëÖ´Ðзì϶£»McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetopVisionProÖжà¸ö·ì϶
°ä²¼¹¦·ò 2021-03-231.Adobe°ä²¼´¹Î£¸üУ¬½¨¸´ColdFusionÖÐËÁÒâ´úÂëÖ´Ðзì϶

AdobeÓÚ3ÔÂ22ÈÕ°ä²¼´¹Î£´ø±í¸üУ¬½¨¸´ColdFusionÖеÄËÁÒâ´úÂëÖ´Ðзì϶¡£¸Ã·ì϶ÊÇÓÉÓÚÎÞ·¨ÑéÖ¤ÊäÈëµ¼Öµģ¬±»¸ú×ÙΪCVE-2021-21087£¬Ó°ÏìÁËColdFusion°æ±¾2021¡¢2016ºÍ2018¡£Adobe½¨ÒéÖÎÀíÔ±¾¡¿ì×°Öð²È«¸üУ¬²¢ÀûÓùٷ½Ö¸ÄÏÖÐÃèÊöµÄ°²È«ÅäÖÃ¶ÔÆä½øÐÐÉèÖá£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/critical-code-execution-vulnerability-fixed-in-adobe-coldfusion/
2.McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetop Vision Pro´æÔÚ¶à¸ö·ì϶

McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetop Vision Pro´æÔÚ¶à¸ö¿ÉÓÃÀ´½Ù³ÖÖ¸±êµçÄԵķì϶¡£ÕâЩ·ì϶±ðÀëΪȨÏÞ·ÖÅä·ì϶£¨CVE-2021-27192£©¡¢Ä¬ÈÏȨÏÞÃýÎó£¨CVE-2021-27193£©¡¢ÒÔÃ÷ÎÄ´«ÊäµÄÃô¸ÐÐÅÏ¢£¨CVE-2021-27194£©ºÍÊÚȨÎÊÌ⣨CVE-2021-27195£©¡£ºÚ¿Í¿ÉÓÃÕâЩ·ì϶½øÐÐÌáȨºÍÖ´ÐÐÔ¶³Ì´úÂ룬»ñµÃ¶ÔÖ¸±êϵͳµÄÆëÈ«½ÚÔìȨ²¢ÆôÓÃÍøÂçÉãÏñÍ·ºÍÂó¿Ë·ç¡£Ä¿Ç°£¬NetopÒѽ¨¸´²¿ÃÅ·ì϶¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/popular-remote-student-learning-program-found-to-be-riddled-with-security-holes/
3.µçÁ¦¹«Ë¾Celg GTÕû¸öÍøÂçÎÞ·¨½Ó¼û£¬ÊÂÎñÈÔÔÚµ÷²éÖÐ

CelgGera??oeTransmiss?o£¨Celg GT£©ÓÚÉÏÖÜÎå(3ÔÂ19ÈÕ)³ÆÆäÔâµ½Á˹¥»÷£¬ËùÓеÄÀûÓ÷¨Ê½ºÍÕû¸öÎļþϵͳ¶¼ÎÞ·¨½Ó¼û¡£¸Ã¹«Ë¾°µÊ¾£¬¹¥»÷ÊÇ´ÓÁ賿ÆðÍ·µÄ£¬Æä·¢ÏÖºóµ±¼´²ÉÈ¡ÏìÓ¦´ëÊ©£¬¹Ø¹ØÏµÍ³ÒÔ±£»¤ÐÅÏ¢ºÍ±¸·Ý×ÊÁÏ¡£Ä¿Ç°£¬¸ÃÊÂÎñÈÔÔÚµ÷²éÖУ¬Éв»ÄÜÈ·¶¨ÏµÍ³°Ü»µµÄˮƽÒÔ¼°¹¥»÷µÄÆðÔ´£¬µ«ÊÇÄܹ»È·¶¨Ã»ÓÐÈκÎÓ×ÎÒÐÅÏ¢±»Ð¹Â¶£¬¹«Ë¾Ô±¹¤µÄµç×ÓÓʼþ·þÎñÒ²Äܹ»Õý³£ÔËÐС£
ÔÎÄÁ´½Ó£º
https://www.jornalopcao.com.br/ultimas-noticias/ataque-hacker-compromete-funcionamento-de-aplicativos-e-arquivos-da-celg-gt-318176/
4.²®Ã÷º²Òé»áÔ±¹¤Òò²Ù×÷ʧÎ󹫿ª´óÁ¿ÈõÊÆÈºÌåµÄÓ×ÎÒÐÅÏ¢

²®Ã÷º²Òé»áÔÚ3ÔÂ19ÈÕÐÇÆÚÎ峯£¬ÒòÔ±¹¤²Ù×÷ʧÎóµ¼Ö´óÁ¿ÈõÊÆÈºÌåµÄÓ×ÎÒÐÅÏ¢±»¹«¿ª¡£¾Ý³ÆÕâ´Îй¶µÄÊÇÓÐȨ»ñµÃÃâ·Ñ°Íʿͨ³©Ö¤µÄ¶ùͯµÄ¾ßÌåÐÅÏ¢¡£¸ÃÊаµÊ¾£¬ÆäÔÚ·¢ÏÖй¶ºóÂíÉϲÉÈ¡ÁË´ëÊ©£¬Êý¾Ý»¹Î´±»ÏÂÔØ£¬²¢ÇÒÓÉÓÚ´ËÊÂÎñµÄ¹æÄ£ºÍÑϳÁÐÔÖÊ£¬ÏÖÒÑÍ¨ÖªÕÆ¹Ü¼à¶½µÄÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©¡£
ÔÎÄÁ´½Ó£º
https://www.birminghammail.co.uk/news/midlands-news/details-vulnerable-kids-uploaded-birmingham-20217314
5.Black Kite°ä²¼·ì϶¶ÔÐÅÓþºÏ×÷ÉçµÄÓ°ÏìµÄ·ÖÎö»ã±¨

Black Kite°ä²¼ÁËÓйطì϶¶ÔÐÅÓþºÏ×÷ÉçµÄÓ°ÏìµÄ·ÖÎö»ã±¨¡£»ã±¨ÏÔʾ£¬Í´´¦Ð¹Â¶¡¢Î´¸üеľÉϵͳºÍ¹©¸øÉÌ·ì϶ÊÇÐÅÓþºÏ×÷ÉçËùÃæ¶ÔµÄ×î´óµÄÍøÂç·çÏÕ¡£´Ë±í£¬Õë¶Ô¹©¸øÉ̵Ĺ¥»÷ΪÐÅÓþºÏ×÷Éç¿ÉÄÜ»áÔì³É³¬¹ý100ÍòÃÀÔªµÄDZÔÚ²ÆÎïËðʧ£»86%µÄÐÅÓþºÏ×÷ÉçºÍ76%µÄ¹©¸øÉ̵ÄÔ±¹¤Í´´¦Òѱ»ÇÔÈ¡²¢¹«¿ªµ½°µÍøÉÏ£»³¬¹ý66%µÄÐÅÓþºÏ×÷ÉçºÍ88%µÄ¹©¸øÉ̲»×ãÔ¤·ÀºýŪºÍ´¹µö¹¥»÷µÄµç×ÓÓʼþ°²È«Õ½Êõ¡£
ÔÎÄÁ´½Ó£º
https://googleprojectzero.blogspot.com/2021/03/in-wild-series-october-2020-0-day.html
6.Vectra°ä²¼ÓйØOffice 365ºÍÔÆµÄ°²È«Ì¬ÊƵķÖÎö»ã±¨

Vectra°ä²¼ÁËÓйØOffice 365ºÍÔÆµÄ°²È«Ì¬ÊƵķÖÎö»ã±¨¡£»ã±¨ÏÔʾ£¬ÔÚ´ÓǰһÄֻ꣬¹ÜѡȡÁ˶à³É·ÖÉí·ÝÑéÖ¤£¨MFA£©£¬µ«ÈÔÓÐ71£¥µÄÆóÒµÒÀÈ»¾Àú¹ýSaaSÕÊ»§½Ù³Ö£¬½ü90£¥µÄÆóÒµ»¹ÔÚ¼Ó¿ìÔÆÍÆËãºÍÊý×Ö»¯µÄתÐÍ¡£´Ë±í£¬¸Ã»ã±¨ÔÚ90ÌìÄÚ¸ú×ÙÁË400Íò¸öMicrosoft Office 365¿Í»§µÄÐÐΪ£¬·¢ÏÖÓÐ96£¥µÄÄÚÍø´æÔÚ¿ÉÒɵĺáÏòÒÆ¶¯ÐÐΪ¡£Îå·ÖÖ®ËĵݲȫרҵÈËÔ±°µÊ¾£¬ÔÚ´ÓǰһÄêÖÐÍøÂ簲ȫµÄ·çÏÕÓÐËùÔö³¤¡£
ÔÎÄÁ´½Ó£º
https://www.vectra.ai/blogpost/cloud-security-insights


¾©¹«Íø°²±¸11010802024551ºÅ