Google TensorFlowΪ½¨¸´RCE·ì϶¶ø²»ÔÙÖ§³ÖYAML£ºNetgear°ä²¼°²È«¸üÐÂ

°ä²¼¹¦·ò 2021-09-08

Google TensorFlowΪ½¨¸´RCE·ì϶¶ø²»ÔÙÖ§³ÖYAML


Google TensorFlowΪ½¨¸´RCE·ì϶¶ø²»ÔÙÖ§³ÖYAML.jpg

 

Google¿ª·¢µÄ»ùÓÚPythonµÄ»úе½ø½¨ºÍÈËΪÖÇÄÜÏîÄ¿TensorFlowÒѾ­ÉÕ»ÙÁ˶ÔYAMLµÄÖ§³Ö¡£TensorFlow´úÂëÖеÄyaml.unsafe_load()º¯Êý´æÔÚÒ»¸ö·ì϶ £¬×·×ÙΪCVE-2021-37678 £¬ÆÀ·ÖΪ9.3¡£µ±ÀûÓ÷´ÐòÁл¯YAMLÌåʽµÄKerasÄ£ÐÍʱ £¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐÐËÁÒâ´úÂ롣Ϊ½¨¸´´Ë·ì϶ £¬TensorFlow¾ö¶¨ÆëÈ«ÉÕ»ÙYAMLµÄÖ§³Ö £¬×ª¶øÊ¹ÓÃJSON·´ÐòÁл¯¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/googles-tensorflow-drops-yaml-support-due-to-code-execution-flaw/


Netgear°ä²¼°²È«¸üР£¬½¨¸´Ó°ÏìÆä20¿î²úÆ·µÄ·ì϶


Netgear°ä²¼°²È«¸üÐÂ£¬½¨¸´Ó°ÏìÆä20¿î²úÆ·µÄ·ì϶.jpg


ÍøÂçÉ豸¹©¸øÉÌNetgearÓÚÉÏÖÜ9ÔÂ3ÈÕ°ä²¼Á˰²È«¸üР£¬½¨¸´Ó°ÏìÆä20¿î²úÆ·µÄ3¸ö·ì϶¡£ÕâЩ·ì϶µÄ´úºÅ±ðÀëΪDemon's Cries¡¢Draconian FearºÍSeventh Inferno £¬Ä¿Ç°Ç°Á½¸ö·ì϶µÄPoCÒѾ­¹«¿ª¡£ÆäÖÐ £¬×îÑϳÁµÄÊÇDemon's Cries £¬CVSSv3ÆÀ·ÖΪ9.8 £¬¿ÉÓÃÓÚÈÆ¹ýÉí·ÝÑéÖ¤²¢ÊÕÊÜÉ豸¡£Draconian FearÒ²ÊÇÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶ £¬µ«Ö»ÄÜÓÃÓڽٳֵǼµÄÖÎÀíÔ±»á»°¡£×êÑÐÈËÔ±Ô¤¼Æ±ÉÈËÖÜÒ» £¬¼´9ÔÂ13ÈÕ°ä²¼¹Ø·ì϶Seventh InfernoµÄ¼¼Êõϸ½Ú¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/demons-cries-authentication-bypass-patched-in-netgear-switches/


Node.js¿ª·¢ÍŶӽ¨¸´NPM°ünode-tarÖеĶà¸ö·ì϶


Node.js¿ª·¢ÍŶӽ¨¸´NPM°ünode-tarÖеĶà¸ö·ì϶.png


Node.js¿ª·¢ÍŶӽ¨¸´ÁËNPM°ü¡°tar¡±£¨±ðÃûnode-tar£©ÖеÄ5¸ö·ì϶¡£ÆäÖнÏΪÑϳÁµÄÊÇ·ì϶CVE-2021-37712ºÍCVE-2021-37701¡£Èç¹ú¶È·ì϶Êý¾Ý¿â(NVD)ÖÐËùÊö £¬ÕâÁ½¸ö·ì϶¿ÉÓÃÀ´´´½¨ºÍ¸²¸ÇËÁÒâÎļþ £¬»òÖ´ÐÐËÁÒâ´úÂë £¬CVSSÆÀ·Ö¾ùΪ8.2¡£Õâ´Î½¨¸´µÄ·ì϶ӰÏìÁ˸ÃNPM°ü°æ±¾5.0.0֮ǰµÄ°æ±¾¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/09/critical-flaws-in-npm-package-patched.html


ÖйúÏã¸ÛBilaxyÔâµ½¹¥»÷ £¬Ô¤¼ÆËðʧ³¬¹ý2100ÍòÃÀÔª


ÖйúÏã¸ÛBilaxyÔâµ½¹¥»÷£¬Ô¤¼ÆËðʧ³¬¹ý2100ÍòÃÀÔª.jpg


8ÔÂ29ÈÕ £¬ÖйúÏã¸ÛµÄ¼ÓÃÜÇ®±ÒÂòÂôËùBilaxy³ÆÆäÔâµ½¹¥»÷ £¬Ô¤¼ÆËðʧ³¬¹ý2100ÍòÃÀÔª¡£Bilaxy°µÊ¾ £¬¹¥»÷²úÉúÔÚ8ÔÂ28ÈÕÏÂÎç6µãµ½7µãÖ®¼ä £¬¹¥»÷ÕßÇÔÈ¡ÁË295¸öERC-20±Ò¡£Ä¿Ç° £¬BilaxyÒÑÖÕ³¡ÁËÆäÍøÕ¾ÉÏÔÚ½øÐÐÂòÂô £¬²¢ÇÒ½¨Òé¿Í»§ÁÙʱ²»Òª½«ÓÃÓÚÂòÂôµÄ¼ÓÃÜÇ®±Ò´æÈëÂòÂôËù¡£´Ë±í £¬¸ÃÍøÕ¾½«ÔÝÍ£·þÎñÖÁÉÙ2ÖÜ £¬ÓÃÀ´·ÖÎöºÚ¿ÍÐÐΪºÍ¸üÐÂϵͳ £¬²¢³¢ÊÔÈ¡»Ø±»µÁµÄERC-20±Ò¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/09/cryptocurrency-exchange-bilaxy-under.html


FortiGuard°ä²¼2021ÄêH1È«ÇòÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨


FortiGuard°ä²¼2021ÄêH1È«ÇòÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨.png


FortiGuardÓÚ8Ô·ݰ䲼ÁË2021ÄêH1È«ÇòÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö £¬2021Äê6Ô¾ùÔÈÿÖÜÀÕË÷Èí¼þ»î¶¯±ÈÒ»ÄêǰͬÆÚÓâÔ½10.7±¶¡£ÆäÖÐ £¬µçÐÅÐÐÒµÊǹ¥»÷ÕßµÄÊ×ÒªµÄÖ¸±ê £¬Æä´ÎÊǵ±¾Ö¡¢Íйܰ²È«·þÎñÌṩÉÌ¡¢Æû³µºÍÔì×÷ÐÐÒµ¡£½©Ê¬ÍøÂçÒ²ÓÐËùÔö³¤ £¬½ñÄêËêÊ×ÔÚ35%µÄ×éÖ¯Öмì²âµ½Á˽©Ê¬ÍøÂç»î¶¯ £¬¶øÕâÒ»±ÈÀýÔÚ6¸öÔºóÔö³¤Îª51%¡£´Ë±í £¬¹¥»÷Õ߸üÇàíùÓÚ¼ì²âÈÆ¹ý¼¼ÊõºÍÌáȨ¼¼Êõ¡£


Ô­ÎÄÁ´½Ó£º

https://www.fortinet.com/content/dam/fortinet/assets/threat-reports/report-threat-landscape-2021.pdf


Positive Technologies°ä²¼2021Ä깤ҵ·çÏյĻ㱨


Positive Technologies°ä²¼2021Ä깤ҵ·çÏյĻ㱨.jpg


Positive TechnologiesÓÚ9ÔÂ1ÈÕ°ä²¼ÁË2021Ä깤ҵÐÅÏ¢°²È«·çÏյķÖÎö»ã±¨¡£»ã±¨Ö¸³ö £¬2020Äê £¬¹¤Òµ²¿ÃÅÊǽö´ÎÓÚµ±¾ÖµÄµÚ¶þ´ó¹¥»÷Ö¸±ê £¬ÓÐ12%µÄ¹¥»÷Õë¶Ô¹¤Òµ¹«Ë¾¡£ÔÚ91%µÄ¹¤Òµ¹«Ë¾ÖÐ £¬¹¥»÷ÕßÄܹ»ÉøÈë½øÈëÄÚÍø £¬Ö®ºó¹¥»÷Õß¾ÍÄܹ»»ñµÃÓû§Í´´¦²¢ÆëÈ«½ÚÔì»ù´¡ÉèÊ©¡£2021Äê5Ô £¬ÔÚThe Standoff 2021µÄÐé¹¹°Ð³¡Õ¹Ê¾ÁËÐÅÏ¢°²È«¶Ô¹¤Òµ×éÖ¯µÄÓ°Ïì £¬¹¥»÷ÕßÔÚÁ½ÌìÄÚ½ÚÔìÁ˼ÓÓÍÕ¾ £¬ÖÕ³¡ÁËÌìÈ»Æø¹©¸ø²¢Òý·¢Á˱¬Õ¨¡£


Ô­ÎÄÁ´½Ó£º

https://www.ptsecurity.com/ww-en/analytics/ics-risks-2021/