Adobe½ô¼±¸üУ¬ÐÞ¸´ColdFusionÈÎÒâ´úÂëÖ´ÐЩ¶´£»McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetopVisionProÖжà¸ö©¶´
Ðû²¼Ê±¼ä 2021-03-231.AdobeÐû²¼½ô¼±¸üУ¬ÐÞ¸´ColdFusionÖÐÈÎÒâ´úÂëÖ´ÐЩ¶´
AdobeÓÚ3ÔÂ22ÈÕÐû²¼½ô¼±´øÍâ¸üУ¬ÐÞ¸´ColdFusionÖеÄÈÎÒâ´úÂëÖ´ÐЩ¶´¡£¸Ã©¶´ÊÇÓÉÓÚÎÞ·¨ÑéÖ¤ÊäÈëµ¼Öµģ¬±»¸ú×ÙΪCVE-2021-21087£¬Ó°ÏìÁËColdFusion°æ±¾2021¡¢2016ºÍ2018¡£Adobe½¨Òé¹ÜÀíÔ±¾¡¿ì°²×°Äþ¾²¸üУ¬²¢Ó¦Óùٷ½Ö¸ÄÏÖÐÃèÊöµÄÄþ¾²ÅäÖÃ¶ÔÆä½øÐÐÉèÖá£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/critical-code-execution-vulnerability-fixed-in-adobe-coldfusion/
2.McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetop Vision Pro´æÔÚ¶à¸ö©¶´
McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetop Vision Pro´æÔÚ¶à¸ö¿ÉÓÃÀ´½Ù³ÖÄ¿±êµçÄԵĩ¶´¡£ÕâЩ©¶´·Ö±ðΪȨÏÞ·ÖÅä©¶´£¨CVE-2021-27192£©¡¢Ä¬ÈÏȨÏÞ´íÎó£¨CVE-2021-27193£©¡¢ÒÔÃ÷ÎÄ´«ÊäµÄÃô¸ÐÐÅÏ¢£¨CVE-2021-27194£©ºÍÊÚȨÎÊÌ⣨CVE-2021-27195£©¡£ºÚ¿Í¿ÉÓÃÕâЩ©¶´½øÐÐÌáȨºÍÖ´ÐÐÔ¶³Ì´úÂ룬»ñµÃ¶ÔÄ¿±êϵͳµÄÍêÈ«¿ØÖÆÈ¨²¢ÆôÓÃÍøÂçÉãÏñÍ·ºÍÂó¿Ë·ç¡£Ä¿Ç°£¬NetopÒÑÐÞ¸´²¿ÃÅ©¶´¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/popular-remote-student-learning-program-found-to-be-riddled-with-security-holes/
3.µçÁ¦¹«Ë¾Celg GTÕû¸öÍøÂçÎÞ·¨·ÃÎÊ£¬Ê¼þÈÔÔÚÊÓ²ìÖÐ
CelgGera??oeTransmiss?o£¨Celg GT£©ÓÚÉÏÖÜÎå(3ÔÂ19ÈÕ)³ÆÆäÔâµ½Á˹¥»÷£¬ËùÓеÄÓ¦Ó÷¨Ê½ºÍÕû¸öÎļþϵͳ¶¼ÎÞ·¨·ÃÎÊ¡£¸Ã¹«Ë¾ÌåÏÖ£¬¹¥»÷ÊÇ´ÓÁ賿¿ªÊ¼µÄ£¬Æä·¢ÏÖºóÁ¢¼´½ÓÄÉÏìÓ¦´ëÊ©£¬¹Ø±ÕϵͳÒÔ±£»¤ÐÅÏ¢ºÍ±¸·Ý×ÊÁÏ¡£Ä¿Ç°£¬¸ÃʼþÈÔÔÚÊÓ²ìÖУ¬Éв»ÄÜÈ·¶¨ÏµÍ³Ë𻵵ÄˮƽÒÔ¼°¹¥»÷µÄÀ´Ô´£¬µ«ÊÇ¿ÉÒÔÈ·¶¨Ã»ÓÐÈκθöÈËÐÅÏ¢±»Ð¹Â¶£¬¹«Ë¾Ô±¹¤µÄµç×ÓÓʼþ·þÎñÒ²¿ÉÒÔÕý³£ÔËÐС£
ÔÎÄÁ´½Ó£º
https://www.jornalopcao.com.br/ultimas-noticias/ataque-hacker-compromete-funcionamento-de-aplicativos-e-arquivos-da-celg-gt-318176/
4.²®Ã÷º²Òé»áÔ±¹¤Òò²Ù×÷ʧÎó¹ûÈ»´óÁ¿ÈõÊÆÈºÌåµÄ¸öÈËÐÅÏ¢
²®Ã÷º²Òé»áÔÚ3ÔÂ19ÈÕÐÇÆÚÎ峯£¬ÒòÔ±¹¤²Ù×÷ʧÎóµ¼Ö´óÁ¿ÈõÊÆÈºÌåµÄ¸öÈËÐÅÏ¢±»¹ûÈ»¡£¾Ý³Æ´Ë´Îй¶µÄÊÇÓÐȨ»ñµÃÃâ·Ñ°ÍʿͨÐÐÖ¤µÄ¶ùͯµÄÏêϸÐÅÏ¢¡£¸ÃÊÐÌåÏÖ£¬ÆäÔÚ·¢ÏÖй¶ºóÁ¢¿Ì½ÓÄÉÁË´ëÊ©£¬Êý¾Ý»¹Î´±»ÏÂÔØ£¬¶øÇÒÓÉÓÚ´ËʼþµÄ¹æÄ£ºÍÑÏÖØÐÔÖÊ£¬ÏÖÒÑ֪ͨÂôÁ¦¼à¶½µÄÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©¡£
ÔÎÄÁ´½Ó£º
https://www.birminghammail.co.uk/news/midlands-news/details-vulnerable-kids-uploaded-birmingham-20217314
5.Black KiteÐû²¼Â©¶´¶ÔÐÅÓúÏ×÷ÉçµÄÓ°ÏìµÄ·ÖÎö³ÂËß
Black KiteÐû²¼ÁËÓйØÂ©¶´¶ÔÐÅÓúÏ×÷ÉçµÄÓ°ÏìµÄ·ÖÎö³ÂËß¡£³ÂËßÏÔʾ£¬Æ¾¾Ýй¶¡¢Î´¸üеľÉϵͳºÍ¹©Ó¦ÉÌ©¶´ÊÇÐÅÓúÏ×÷ÉçËùÃæÁÙµÄ×î´óµÄÍøÂç·çÏÕ¡£´ËÍ⣬Õë¶Ô¹©Ó¦É̵Ĺ¥»÷ΪÐÅÓúÏ×÷Éç¿ÉÄÜ»áÔì³ÉÁè¼Ý100ÍòÃÀÔªµÄDZÔÚ²ÆÎïËðʧ£»86%µÄÐÅÓúÏ×÷ÉçºÍ76%µÄ¹©Ó¦É̵ÄÔ±¹¤Æ¾¾ÝÒѱ»ÇÔÈ¡²¢¹ûÈ»µ½°µÍøÉÏ£»Áè¼Ý66%µÄÐÅÓúÏ×÷ÉçºÍ88%µÄ¹©Ó¦ÉÌȱ·¦Ô¤·ÀÆÛƺ͵öÓã¹¥»÷µÄµç×ÓÓʼþÄþ¾²¼ÆÄ±¡£
ÔÎÄÁ´½Ó£º
https://googleprojectzero.blogspot.com/2021/03/in-wild-series-october-2020-0-day.html
6.VectraÐû²¼ÓйØOffice 365ºÍÔÆµÄÄþ¾²Ì¬ÊƵķÖÎö³ÂËß
VectraÐû²¼ÁËÓйØOffice 365ºÍÔÆµÄÄþ¾²Ì¬ÊƵķÖÎö³ÂËß¡£³ÂËßÏÔʾ£¬ÔÚ¹ýÈ¥Ò»Ä꣬¾¡¹Ü½ÓÄÉÁ˶àÒòËØÉí·ÝÑéÖ¤£¨MFA£©£¬µ«ÈÔÓÐ71£¥µÄÆóÒµÈÔÈ»¾Àú¹ýSaaSÕÊ»§½Ù³Ö£¬½ü90£¥µÄÆóÒµ»¹ÔÚ¼ÓËÙÔÆ¼ÆËãºÍÊý×Ö»¯µÄתÐÍ¡£´ËÍ⣬¸Ã³ÂËßÔÚ90ÌìÄÚ¸ú×ÙÁË400Íò¸öMicrosoft Office 365¿Í»§µÄÐÐΪ£¬·¢ÏÖÓÐ96£¥µÄÄÚÍø´æÔÚ¿ÉÒɵĺáÏòÒÆ¶¯ÐÐΪ¡£Îå·ÖÖ®ËĵÄÄþ¾²×¨ÒµÈËÔ±ÌåÏÖ£¬ÔÚ¹ýÈ¥Ò»ÄêÖÐÍøÂçÄþ¾²µÄ·çÏÕÓÐËùÔö¼Ó¡£
ÔÎÄÁ´½Ó£º
https://www.vectra.ai/blogpost/cloud-security-insights