Proofpoint·¢ÏÖÕë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£´¹µö»î¶¯

°ä²¼¹¦·ò 2021-12-10

Google°ä²¼12Ô·ݸüР£¬½¨¸´chromeÖеĶà¸ö·ì϶


Google°ä²¼12Ô·ݸüÐÂ£¬½¨¸´chromeÖеĶà¸ö·ì϶.png


GoogleÔÚ12ÔÂ6ÈÕ°ä²¼chrome°²È«¸üР£¬×ܼƽ¨¸´22¸ö·ì϶¡£ÆäÖнÏΪÑϳÁµÄÊÇWebÀûÓ÷¨Ê½ÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2021-4052£©¡¢UI×é¼þÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2021-4053£©¡¢WebRTCÖеÄÔ½½çдÈë·ì϶£¨CVE-2021-4079£©ÒÔ¼°V8ÖеÄÀàÐÍ»ìºÏ·ì϶£¨CVE-2021-4078£©¡£´Ë±í £¬»¹½¨¸´ÁËÀ©´óÖеĶѻº³åÇøÒç¶Âí½Å£¨CVE-2021-4055£©ºÍANGLEÖеĶѻº³åÇøÒç¶Âí½Å£¨CVE-2021-4058£©µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop.html


SonicWall°ä²¼¸üР£¬½¨¸´SMA 100ϵÁÐÖжà¸ö·ì϶


SonicWall°ä²¼¸üÐÂ£¬½¨¸´SMA 100ϵÁÐÖжà¸ö·ì϶.png


SonicWallÔÚ12ÔÂ7ÈÕ°ä²¼¸üР£¬½¨¸´SMA 100ϵÁÐÉ豸ÖеĶà¸ö·ì϶¡£Õâ´Î½¨¸´µÄ×îΪÑϳÁµÄ·ì϶ÊÇ»ùÓÚ²Ö¿âµÄ»º³åÇøÒç¶Âí½Å£¨CVE-2021-20038£© £¬CVSSÆÀ·ÖΪ9.8 £¬ÓÉÓÚÉ豸µÄApache httpd·þÎñÆ÷ÖеÄHTTP GET²½ÖèµÄ»·¾³±äÁ¿Ê¹ÓÃÁËstrcat()º¯Êýµ¼ÖµÄ£»Æä´ÎÊÇ»º³åÇøÒç¶Âí½Å£¨CVE-2021-20045£© £¬CVSSÆÀ·Ö9.4¡£´Ë±í £¬»¹½¨¸´ÁË»º³åÇøÒç¶Âí½Å£¨CVE-2021-20043£©ºÍÈÏÖ¤ºÅÁî×¢Èë·ì϶£¨CVE-2021-20039£©µÈ¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.cisa.gov/uscert/ncas/current-activity/2021/12/08/sonicwall-releases-security-advisory-sma-100-series-appliances


ÑÇÂíÑ·AWSÔÆ·þÎñå´»úÓ°ÏìNetflixµÈ¶à¸öÀûÓÃ


ÑÇÂíÑ·AWSÔÆ·þÎñå´»úÓ°ÏìNetflixµÈ¶à¸öÀûÓÃ.png


12ÔÂ7ÈÕÏÂÎç12µã×óÓÒ £¬ÃÀ¹úUS-EAST-1ÇøÓòµÄÑÇÂíÑ·AWSÔÆ·þÎñå´»ú¡£Õâ´ÎÊÂÎñÓ°ÏìÁËRing¡¢Netflix¡¢Amazon Prime Video¡¢RobinhoodºÍRokuµÅצÓà £¬ÒÔ¼°PUBG¡¢ValorantºÍÓ¢ÐÛͬÃ˵Å×ÎÏ·¡£¸Ã¹«Ë¾ÔÚµ±Ìì12:34È·ÈÏÁËÖжÏÊÂÎñ £¬²¢³Æµ××ÓÔ­ÒòÊǶà¸öÍøÂçÉ豸ÊÜËð¡£12ÔÂ7ÈÕÏÂÎç4:35 £¬ÑÇÂíÑ·°µÊ¾ÍøÂçÉ豸ÎÊÌâÒѾ­½â¾ö £¬ËûÃÇÔÚÖÂÁ¦¸´Ô­ÊÜËð·þÎñ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/amazon-web-service-outage-impact-major-websites/


Proofpoint·¢ÏÖÕë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£´¹µö»î¶¯


Proofpoint·¢ÏÖÕë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£´¹µö»î¶¯.png


Proofpoint¹«¿ªÁ˽üÆÚ´ó¹æÄ£´¹µö»î¶¯ÖÐʹÓõÄÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½(TTP)µÄ¾ßÌåÐÅÏ¢¡£Õâ´Î»î¶¯ÆðÍ·ÓÚ½ñÄê10Ô·Ý £¬À´×Ô¶à¸öºÚ¿ÍÍÅ»ï £¬ÖØÒªÕë¶ÔÃÀ¹úµÄ´óѧ¡£ÕâЩ¹¥»÷ͨ¹ýÒÔOmicron±äÌå¡¢COVID-19²âÊÔÁË¾ÖºÍÆäËü²âÊÔÒªÇóΪÖ÷ÌâµÄ´¹µöÓʼþ £¬ÓÕʹָ±ê´ò¿ª¸½¼þÖеÄHTMÎļþ £¬²¢½«Æä³Á¶¨Ïòµ½¼Ù×°³ÉËûÃÇ´óѧµÇÂ¼ÍøÕ¾µÄ´¹µöÒ³Ãæ £¬Ö¼ÔÚÇÔÊØÐÅÏ¢¡£ÎªÁËÈÆ¹ýMFA±£»¤ £¬¹¥»÷Õß»¹´´½¨ÁËαÔìµÄDUO MFAÍøÕ¾ÒÔÇÔÈ¡Óû§µÄOTP¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-universities-targeted-by-office-365-phishing-attacks/


QNAPÌáÐѿͻ§°ÑÎȽüÆÚÕë¶ÔÆäNASÉ豸µÄÍÚ¿ó»î¶¯


QNAPÌáÐѿͻ§°ÑÎȽüÆÚÕë¶ÔÆäNASÉ豸µÄÍÚ¿ó»î¶¯.png


Öйų́ÍåµÄNASÉ豸Ôì×÷ÉÌQNAPÔÚ12ÔÂ7ÈÕ°ä²¼¹«¸æ £¬ÌáÐÑÓû§°ÑÎȽüÆÚµÄ¶ñÒâÍÚ¿ó»î¶¯¡£¹«¸æ³Æ £¬Õâ´Î»î¶¯¶Ô×¼ÁËQNAP NAS¡£Ò»µ©NAS±»Ï°È¾ £¬CPUʹÓÃÂÊ»á±äµÃÒì³£¸ß £¬ÆäÖÐÃûΪ¡°[oom_reaper]¡±µÄ¹ý³Ì¿ÉÄÜ»áÕ¼ÓÃ×ÜCPUʹÓÃÂʵÄ50%×óÓÒ¡£Õâ¸ö¹ý³Ì·ÂÕÕÁËÒ»¸öºÏ·¨µÄͬÃûÄں˹ý³Ì £¬µ«ÊÇÕý³£Äں˹ý³ÌPIDͨ³£µÍÓÚ1000 £¬¶ø¸Ã¿ó¹¤PIDͨ³£´óÓÚ1000¡£QNAP½¨ÒéÓû§½«QTS¸üе½×îа汾 £¬²¢Ê¹ÓÃÇ¿ÃÜÂë¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/12/warning-yet-another-bitcoin-mining.html


ÐÂÀÕË÷Èí¼þCerber¶Ô×¼ConfluenceºÍGitLab·þÎñÆ÷


ÐÂÀÕË÷Èí¼þCerber¶Ô×¼ConfluenceºÍGitLab·þÎñÆ÷.png


12ÔÂ7ÈÕ £¬×êÑÐÈËÔ±·¢ÏÖʹÓÃÁ˾ÉÃû³ÆµÄÐÂÀÕË÷Èí¼þCerber¡£ÀÕË÷Èí¼þCerberÓÚ2016Äê³öÏÖ £¬Ö±µ½2019Äêµ×Òþû¡£´ÓÉϸöÔÂÆðÍ· £¬Cerbe»Ø¹é £¬µ«ÊÇËüÓë¾É°æ²¢²»Ò»Ñù £¬´úÂ벻ƥÅä £¬Ð°æÊ¹ÓÃCrypto+++¿â¶ø¾É°æ±¾Ê¹ÓÃWindows CryptoAPI¿â £¬²¢ÇҾɰæCerberҲûÓÐLinux±äÌå¡£ÐÂCerberµÄÊê½ðÒªÇó´Ó1000ÃÀÔªµ½3000ÃÀÔª²»µÈ £¬ÀûÓÃÁËCVE-2021-26084ºÍCVE-2021-22205·ì϶¶Ô×¼ConfluenceºÍGitLab·þÎñÆ÷ £¬ÖØÒªÕë¶ÔÃÀ¹ú¡¢µÂ¹úºÍÖйú¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-cerber-ransomware-targets-confluence-and-gitlab-servers/