Adobe½ô¼±¸üУ¬ÐÞ¸´ColdFusionÈÎÒâ´úÂëÖ´ÐЩ¶´£»McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetopVisionProÖжà¸ö©¶´

Ðû²¼Ê±¼ä 2021-03-23

1.AdobeÐû²¼½ô¼±¸üУ¬ÐÞ¸´ColdFusionÖÐÈÎÒâ´úÂëÖ´ÐЩ¶´


1.jpg


AdobeÓÚ3ÔÂ22ÈÕÐû²¼½ô¼±´øÍâ¸üУ¬ÐÞ¸´ColdFusionÖеÄÈÎÒâ´úÂëÖ´ÐЩ¶´¡£¸Ã©¶´ÊÇÓÉÓÚÎÞ·¨ÑéÖ¤ÊäÈ뵼ֵ쬱»¸ú×ÙΪCVE-2021-21087£¬Ó°ÏìÁËColdFusion°æ±¾2021¡¢2016ºÍ2018¡£Adobe½¨Òé¹ÜÀíÔ±¾¡¿ì°²×°Äþ¾²¸üУ¬²¢Ó¦Óùٷ½Ö¸ÄÏÖÐÃèÊöµÄÄþ¾²ÅäÖÃ¶ÔÆä½øÐÐÉèÖᣠ


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/critical-code-execution-vulnerability-fixed-in-adobe-coldfusion/


2.McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetop Vision Pro´æÔÚ¶à¸ö©¶´


2.jpg


McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetop Vision Pro´æÔÚ¶à¸ö¿ÉÓÃÀ´½Ù³ÖÄ¿±êµçÄԵĩ¶´¡£ÕâЩ©¶´·Ö±ðΪȨÏÞ·ÖÅä©¶´£¨CVE-2021-27192£©¡¢Ä¬ÈÏȨÏÞ´íÎó£¨CVE-2021-27193£©¡¢ÒÔÃ÷ÎÄ´«ÊäµÄÃô¸ÐÐÅÏ¢£¨CVE-2021-27194£©ºÍÊÚȨÎÊÌ⣨CVE-2021-27195£©¡£ºÚ¿Í¿ÉÓÃÕâЩ©¶´½øÐÐÌáȨºÍÖ´ÐÐÔ¶³Ì´úÂ룬»ñµÃ¶ÔÄ¿±êϵͳµÄÍêÈ«¿ØÖÆÈ¨²¢ÆôÓÃÍøÂçÉãÏñÍ·ºÍÂó¿Ë·ç¡£Ä¿Ç°£¬NetopÒÑÐÞ¸´²¿ÃÅ©¶´¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/popular-remote-student-learning-program-found-to-be-riddled-with-security-holes/


3.µçÁ¦¹«Ë¾Celg GTÕû¸öÍøÂçÎÞ·¨·ÃÎÊ£¬Ê¼þÈÔÔÚÊÓ²ìÖÐ


3.jpg


CelgGera??oeTransmiss?o£¨Celg GT£©ÓÚÉÏÖÜÎå(3ÔÂ19ÈÕ)³ÆÆäÔâµ½Á˹¥»÷£¬ËùÓеÄÓ¦Ó÷¨Ê½ºÍÕû¸öÎļþϵͳ¶¼ÎÞ·¨·ÃÎÊ¡£¸Ã¹«Ë¾ÌåÏÖ£¬¹¥»÷ÊÇ´ÓÁ賿¿ªÊ¼µÄ£¬Æä·¢ÏÖºóÁ¢¼´½ÓÄÉÏìÓ¦´ëÊ©£¬¹Ø±ÕϵͳÒÔ±£»¤ÐÅÏ¢ºÍ±¸·Ý×ÊÁÏ¡£Ä¿Ç°£¬¸ÃʼþÈÔÔÚÊÓ²ìÖУ¬Éв»ÄÜÈ·¶¨ÏµÍ³Ë𻵵ÄˮƽÒÔ¼°¹¥»÷µÄÀ´Ô´£¬µ«ÊÇ¿ÉÒÔÈ·¶¨Ã»ÓÐÈκθöÈËÐÅÏ¢±»Ð¹Â¶£¬¹«Ë¾Ô±¹¤µÄµç×ÓÓʼþ·þÎñÒ²¿ÉÒÔÕý³£ÔËÐС£


Ô­ÎÄÁ´½Ó£º

https://www.jornalopcao.com.br/ultimas-noticias/ataque-hacker-compromete-funcionamento-de-aplicativos-e-arquivos-da-celg-gt-318176/


4.²®Ã÷º²Òé»áÔ±¹¤Òò²Ù×÷ʧÎó¹ûÈ»´óÁ¿ÈõÊÆÈºÌåµÄ¸öÈËÐÅÏ¢


4.jpg


²®Ã÷º²Òé»áÔÚ3ÔÂ19ÈÕÐÇÆÚÎ峯£¬ÒòÔ±¹¤²Ù×÷ʧÎóµ¼Ö´óÁ¿ÈõÊÆÈºÌåµÄ¸öÈËÐÅÏ¢±»¹ûÈ»¡£¾Ý³Æ´Ë´Îй¶µÄÊÇÓÐȨ»ñµÃÃâ·Ñ°ÍʿͨÐÐÖ¤µÄ¶ùͯµÄÏêϸÐÅÏ¢¡£¸ÃÊÐÌåÏÖ£¬ÆäÔÚ·¢ÏÖй¶ºóÁ¢¿Ì½ÓÄÉÁË´ëÊ©£¬Êý¾Ý»¹Î´±»ÏÂÔØ£¬¶øÇÒÓÉÓÚ´ËʼþµÄ¹æÄ£ºÍÑÏÖØÐÔÖÊ£¬ÏÖÒÑ֪ͨÂôÁ¦¼à¶½µÄÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©¡£


Ô­ÎÄÁ´½Ó£º

https://www.birminghammail.co.uk/news/midlands-news/details-vulnerable-kids-uploaded-birmingham-20217314


5.Black KiteÐû²¼Â©¶´¶ÔÐÅÓúÏ×÷ÉçµÄÓ°ÏìµÄ·ÖÎö³ÂËß


5.jpg


Black KiteÐû²¼ÁËÓйØÂ©¶´¶ÔÐÅÓúÏ×÷ÉçµÄÓ°ÏìµÄ·ÖÎö³ÂËß¡£³ÂËßÏÔʾ£¬Æ¾¾Ýй¶¡¢Î´¸üеľÉϵͳºÍ¹©Ó¦ÉÌ©¶´ÊÇÐÅÓúÏ×÷ÉçËùÃæÁÙµÄ×î´óµÄÍøÂç·çÏÕ¡£´ËÍ⣬Õë¶Ô¹©Ó¦É̵Ĺ¥»÷ΪÐÅÓúÏ×÷Éç¿ÉÄÜ»áÔì³ÉÁè¼Ý100ÍòÃÀÔªµÄDZÔÚ²ÆÎïËðʧ£»86%µÄÐÅÓúÏ×÷ÉçºÍ76%µÄ¹©Ó¦É̵ÄÔ±¹¤Æ¾¾ÝÒѱ»ÇÔÈ¡²¢¹ûÈ»µ½°µÍøÉÏ£»Áè¼Ý66%µÄÐÅÓúÏ×÷ÉçºÍ88%µÄ¹©Ó¦ÉÌȱ·¦Ô¤·ÀÆÛÆ­ºÍµöÓã¹¥»÷µÄµç×ÓÓʼþÄþ¾²¼ÆÄ±¡£


Ô­ÎÄÁ´½Ó£º

https://googleprojectzero.blogspot.com/2021/03/in-wild-series-october-2020-0-day.html


6.VectraÐû²¼ÓйØOffice 365ºÍÔÆµÄÄþ¾²Ì¬ÊƵķÖÎö³ÂËß


6.jpg


VectraÐû²¼ÁËÓйØOffice 365ºÍÔÆµÄÄþ¾²Ì¬ÊƵķÖÎö³ÂËß¡£³ÂËßÏÔʾ£¬ÔÚ¹ýÈ¥Ò»Ä꣬¾¡¹Ü½ÓÄÉÁ˶àÒòËØÉí·ÝÑéÖ¤£¨MFA£©£¬µ«ÈÔÓÐ71£¥µÄÆóÒµÈÔÈ»¾­Àú¹ýSaaSÕÊ»§½Ù³Ö£¬½ü90£¥µÄÆóÒµ»¹ÔÚ¼ÓËÙÔÆ¼ÆËãºÍÊý×Ö»¯µÄתÐÍ¡£´ËÍ⣬¸Ã³ÂËßÔÚ90ÌìÄÚ¸ú×ÙÁË400Íò¸öMicrosoft Office 365¿Í»§µÄÐÐΪ£¬·¢ÏÖÓÐ96£¥µÄÄÚÍø´æÔÚ¿ÉÒɵĺáÏòÒÆ¶¯ÐÐΪ¡£Îå·ÖÖ®ËĵÄÄþ¾²×¨ÒµÈËÔ±ÌåÏÖ£¬ÔÚ¹ýÈ¥Ò»ÄêÖÐÍøÂçÄþ¾²µÄ·çÏÕÓÐËùÔö¼Ó¡£


Ô­ÎÄÁ´½Ó£º

https://www.vectra.ai/blogpost/cloud-security-insights