Adobe½ôÆÈ¸üР£¬£¬£¬ÐÞ¸´ColdFusioní§Òâ´úÂëÖ´ÐÐÎó²î£»£»£»McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetopVisionProÖжà¸öÎó²î

Ðû²¼Ê±¼ä 2021-03-23

1.AdobeÐû²¼½ôÆÈ¸üР£¬£¬£¬ÐÞ¸´ColdFusionÖÐí§Òâ´úÂëÖ´ÐÐÎó²î


1.jpg


AdobeÓÚ3ÔÂ22ÈÕÐû²¼½ôÆÈ´øÍâ¸üР£¬£¬£¬ÐÞ¸´ColdFusionÖеÄí§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÓÉÓÚÎÞ·¨ÑéÖ¤ÊäÈëµ¼Ö嵀 £¬£¬£¬±»¸ú×ÙΪCVE-2021-21087 £¬£¬£¬Ó°ÏìÁËColdFusion°æ±¾2021¡¢2016ºÍ2018¡£¡£¡£¡£¡£Adobe½¨ÒéÖÎÀíÔ±¾¡¿ì×°ÖÃÇå¾²¸üР£¬£¬£¬²¢Ó¦Óùٷ½Ö¸ÄÏÖÐÐÎòµÄÇå¾²ÉèÖÃ¶ÔÆä¾ÙÐÐÉèÖᣡ£¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/critical-code-execution-vulnerability-fixed-in-adobe-coldfusion/


2.McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetop Vision Pro±£´æ¶à¸öÎó²î


2.jpg


McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetop Vision Pro±£´æ¶à¸ö¿ÉÓÃÀ´Ð®ÖÆÄ¿µÄµçÄÔµÄÎó²î¡£¡£¡£¡£¡£ÕâЩÎó²î»®·ÖΪȨÏÞ·ÖÅÉÎó²î£¨CVE-2021-27192£©¡¢Ä¬ÈÏȨÏÞ¹ýʧ£¨CVE-2021-27193£©¡¢ÒÔÃ÷ÎÄ´«ÊäµÄÃô¸ÐÐÅÏ¢£¨CVE-2021-27194£©ºÍÊÚȨÎÊÌ⣨CVE-2021-27195£©¡£¡£¡£¡£¡£ºÚ¿Í¿ÉÓÃÕâЩÎó²î¾ÙÐÐÌáȨºÍÖ´ÐÐÔ¶³Ì´úÂë £¬£¬£¬»ñµÃ¶ÔÄ¿µÄϵͳµÄÍêÈ«¿ØÖÆÈ¨²¢ÆôÓÃÍøÂçÉãÏñÍ·ºÍÂó¿Ë·ç¡£¡£¡£¡£¡£ÏÖÔÚ £¬£¬£¬NetopÒÑÐÞ¸´²¿·ÖÎó²î¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/popular-remote-student-learning-program-found-to-be-riddled-with-security-holes/


3.µçÁ¦¹«Ë¾Celg GTÕû¸öÍøÂçÎÞ·¨»á¼û £¬£¬£¬ÊÂÎñÈÔÔÚÊÓ²ìÖÐ


3.jpg


CelgGera??oeTransmiss?o£¨Celg GT£©ÓÚÉÏÖÜÎå(3ÔÂ19ÈÕ)³ÆÆäÔâµ½Á˹¥»÷ £¬£¬£¬ËùÓеÄÓ¦ÓóÌÐòºÍÕû¸öÎļþϵͳ¶¼ÎÞ·¨»á¼û¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ £¬£¬£¬¹¥»÷ÊÇ´ÓÆÆÏþ×îÏ鵀 £¬£¬£¬Æä·¢Ã÷ºóÁ¬Ã¦½ÓÄÉÏìÓ¦²½·¥ £¬£¬£¬¹Ø±ÕϵͳÒÔ±£»£»£»¤ÐÅÏ¢ºÍ±¸·Ý×ÊÁÏ¡£¡£¡£¡£¡£ÏÖÔÚ £¬£¬£¬¸ÃÊÂÎñÈÔÔÚÊÓ²ìÖÐ £¬£¬£¬Éв»¿ÉÈ·¶¨ÏµÍ³Ë𻵵ÄˮƽÒÔ¼°¹¥»÷µÄȪԴ £¬£¬£¬¿ÉÊÇ¿ÉÒÔÈ·¶¨Ã»ÓÐÈκÎСÎÒ˽¼ÒÐÅÏ¢±»Ð¹Â¶ £¬£¬£¬¹«Ë¾Ô±¹¤µÄµç×ÓÓʼþЧÀÍÒ²¿ÉÒÔÕý³£ÔËÐС£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.jornalopcao.com.br/ultimas-noticias/ataque-hacker-compromete-funcionamento-de-aplicativos-e-arquivos-da-celg-gt-318176/


4.²®Ã÷º²Òé»áÔ±¹¤Òò²Ù×÷ʧÎó¹ûÕæ´ó×ÚÈõÊÆÈºÌåµÄСÎÒ˽¼ÒÐÅÏ¢


4.jpg


²®Ã÷º²Òé»áÔÚ3ÔÂ19ÈÕÐÇÆÚÎ峯 £¬£¬£¬ÒòÔ±¹¤²Ù×÷ʧÎóµ¼Ö´ó×ÚÈõÊÆÈºÌåµÄСÎÒ˽¼ÒÐÅÏ¢±»¹ûÕæ¡£¡£¡£¡£¡£¾Ý³Æ´Ë´Îй¶µÄÊÇÓÐȨ»ñµÃÃâ·Ñ°ÍʿͨÐÐÖ¤µÄ¶ùͯµÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¸ÃÊÐÌåÏÖ £¬£¬£¬ÆäÔÚ·¢Ã÷й¶ºóÁ¬Ã¦½ÓÄÉÁ˲½·¥ £¬£¬£¬Êý¾Ý»¹Î´±»ÏÂÔØ £¬£¬£¬²¢ÇÒÓÉÓÚ´ËÊÂÎñµÄ¹æÄ£ºÍÑÏÖØÐÔ×Ó £¬£¬£¬ÏÖÒÑ֪ͨÈÏÕæ¼àÊÓµÄÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.birminghammail.co.uk/news/midlands-news/details-vulnerable-kids-uploaded-birmingham-20217314


5.Black KiteÐû²¼Îó²î¶ÔÐÅÓÃÏàÖúÉçµÄÓ°ÏìµÄÆÊÎö±¨¸æ


5.jpg


Black KiteÐû²¼ÁËÓйØÎó²î¶ÔÐÅÓÃÏàÖúÉçµÄÓ°ÏìµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£±¨¸æÏÔʾ £¬£¬£¬Æ¾Ö¤Ð¹Â¶¡¢Î´¸üеľÉϵͳºÍ¹©Ó¦ÉÌÎó²îÊÇÐÅÓÃÏàÖúÉçËùÃæÁÙµÄ×î´óµÄÍøÂçΣº¦¡£¡£¡£¡£¡£±ðµÄ £¬£¬£¬Õë¶Ô¹©Ó¦É̵Ĺ¥»÷ΪÐÅÓÃÏàÖúÉç¿ÉÄÜ»áÔì³ÉÁè¼Ý100ÍòÃÀÔªµÄDZÔÚ²ÆÎïËðʧ£»£»£»86%µÄÐÅÓÃÏàÖúÉçºÍ76%µÄ¹©Ó¦É̵ÄÔ±¹¤Æ¾Ö¤Òѱ»ÇÔÈ¡²¢¹ûÕæµ½°µÍøÉÏ£»£»£»Áè¼Ý66%µÄÐÅÓÃÏàÖúÉçºÍ88%µÄ¹©Ó¦ÉÌȱ·¦Ô¤·ÀÓÕÆ­ºÍ´¹ÂÚ¹¥»÷µÄµç×ÓÓʼþÇå¾²Õ½ÂÔ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://googleprojectzero.blogspot.com/2021/03/in-wild-series-october-2020-0-day.html


6.VectraÐû²¼ÓйØOffice 365ºÍÔÆµÄÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ


6.jpg


VectraÐû²¼ÁËÓйØOffice 365ºÍÔÆµÄÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£±¨¸æÏÔʾ £¬£¬£¬ÔÚÒÑÍùÒ»Äê £¬£¬£¬Ö»¹Ü½ÓÄÉÁ˶àÒòËØÉí·ÝÑéÖ¤£¨MFA£© £¬£¬£¬µ«ÈÔÓÐ71£¥µÄÆóÒµÈÔÈ»ÂÄÀú¹ýSaaSÕÊ»§Ð®ÖÆ £¬£¬£¬½ü90£¥µÄÆóÒµ»¹ÔÚ¼ÓËÙÔÆÅÌËãºÍÊý×Ö»¯µÄתÐÍ¡£¡£¡£¡£¡£±ðµÄ £¬£¬£¬¸Ã±¨¸æÔÚ90ÌìÄÚ¸ú×ÙÁË400Íò¸öMicrosoft Office 365¿Í»§µÄÐÐΪ £¬£¬£¬·¢Ã÷ÓÐ96£¥µÄÄÚÍø±£´æ¿ÉÒɵĺáÏòÒÆ¶¯ÐÐΪ¡£¡£¡£¡£¡£Îå·ÖÖ®ËĵÄÇ徲רҵְԱÌåÏÖ £¬£¬£¬ÔÚÒÑÍùÒ»ÄêÖÐÍøÂçÇå¾²µÄΣº¦ÓÐËùÔöÌí¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.vectra.ai/blogpost/cloud-security-insights