Adobe½ôÆÈ¸üУ¬£¬£¬£¬£¬ÐÞ¸´ColdFusioní§Òâ´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetopVisionProÖжà¸öÎó²î
Ðû²¼Ê±¼ä 2021-03-231.AdobeÐû²¼½ôÆÈ¸üУ¬£¬£¬£¬£¬ÐÞ¸´ColdFusionÖÐí§Òâ´úÂëÖ´ÐÐÎó²î

AdobeÓÚ3ÔÂ22ÈÕÐû²¼½ôÆÈ´øÍâ¸üУ¬£¬£¬£¬£¬ÐÞ¸´ColdFusionÖеÄí§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£¡£¸ÃÎó²îÊÇÓÉÓÚÎÞ·¨ÑéÖ¤ÊäÈëµ¼Öµģ¬£¬£¬£¬£¬±»¸ú×ÙΪCVE-2021-21087£¬£¬£¬£¬£¬Ó°ÏìÁËColdFusion°æ±¾2021¡¢2016ºÍ2018¡£¡£¡£Adobe½¨ÒéÖÎÀíÔ±¾¡¿ì×°ÖÃÇå¾²¸üУ¬£¬£¬£¬£¬²¢Ó¦Óùٷ½Ö¸ÄÏÖÐÐÎòµÄÇå¾²ÉèÖÃ¶ÔÆä¾ÙÐÐÉèÖᣡ£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/critical-code-execution-vulnerability-fixed-in-adobe-coldfusion/
2.McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetop Vision Pro±£´æ¶à¸öÎó²î

McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetop Vision Pro±£´æ¶à¸ö¿ÉÓÃÀ´Ð®ÖÆÄ¿µÄµçÄÔµÄÎó²î¡£¡£¡£ÕâЩÎó²î»®·ÖΪȨÏÞ·ÖÅÉÎó²î£¨CVE-2021-27192£©¡¢Ä¬ÈÏȨÏÞ¹ýʧ£¨CVE-2021-27193£©¡¢ÒÔÃ÷ÎÄ´«ÊäµÄÃô¸ÐÐÅÏ¢£¨CVE-2021-27194£©ºÍÊÚȨÎÊÌ⣨CVE-2021-27195£©¡£¡£¡£ºÚ¿Í¿ÉÓÃÕâЩÎó²î¾ÙÐÐÌáȨºÍÖ´ÐÐÔ¶³Ì´úÂ룬£¬£¬£¬£¬»ñµÃ¶ÔÄ¿µÄϵͳµÄÍêÈ«¿ØÖÆÈ¨²¢ÆôÓÃÍøÂçÉãÏñÍ·ºÍÂó¿Ë·ç¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬NetopÒÑÐÞ¸´²¿·ÖÎó²î¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/popular-remote-student-learning-program-found-to-be-riddled-with-security-holes/
3.µçÁ¦¹«Ë¾Celg GTÕû¸öÍøÂçÎÞ·¨»á¼û£¬£¬£¬£¬£¬ÊÂÎñÈÔÔÚÊÓ²ìÖÐ

CelgGera??oeTransmiss?o£¨Celg GT£©ÓÚÉÏÖÜÎå(3ÔÂ19ÈÕ)³ÆÆäÔâµ½Á˹¥»÷£¬£¬£¬£¬£¬ËùÓеÄÓ¦ÓóÌÐòºÍÕû¸öÎļþϵͳ¶¼ÎÞ·¨»á¼û¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬¹¥»÷ÊÇ´ÓÆÆÏþ×îÏȵ쬣¬£¬£¬£¬Æä·¢Ã÷ºóÁ¬Ã¦½ÓÄÉÏìÓ¦²½·¥£¬£¬£¬£¬£¬¹Ø±ÕϵͳÒÔ±£»£»£»£»£»£»¤ÐÅÏ¢ºÍ±¸·Ý×ÊÁÏ¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬¸ÃÊÂÎñÈÔÔÚÊÓ²ìÖУ¬£¬£¬£¬£¬Éв»¿ÉÈ·¶¨ÏµÍ³Ë𻵵ÄˮƽÒÔ¼°¹¥»÷µÄȪԴ£¬£¬£¬£¬£¬¿ÉÊÇ¿ÉÒÔÈ·¶¨Ã»ÓÐÈκÎСÎÒ˽¼ÒÐÅÏ¢±»Ð¹Â¶£¬£¬£¬£¬£¬¹«Ë¾Ô±¹¤µÄµç×ÓÓʼþЧÀÍÒ²¿ÉÒÔÕý³£ÔËÐС£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.jornalopcao.com.br/ultimas-noticias/ataque-hacker-compromete-funcionamento-de-aplicativos-e-arquivos-da-celg-gt-318176/
4.²®Ã÷º²Òé»áÔ±¹¤Òò²Ù×÷ʧÎó¹ûÕæ´ó×ÚÈõÊÆÈºÌåµÄСÎÒ˽¼ÒÐÅÏ¢

²®Ã÷º²Òé»áÔÚ3ÔÂ19ÈÕÐÇÆÚÎ峯£¬£¬£¬£¬£¬ÒòÔ±¹¤²Ù×÷ʧÎóµ¼Ö´ó×ÚÈõÊÆÈºÌåµÄСÎÒ˽¼ÒÐÅÏ¢±»¹ûÕæ¡£¡£¡£¾Ý³Æ´Ë´Îй¶µÄÊÇÓÐȨ»ñµÃÃâ·Ñ°ÍʿͨÐÐÖ¤µÄ¶ùͯµÄÏêϸÐÅÏ¢¡£¡£¡£¸ÃÊÐÌåÏÖ£¬£¬£¬£¬£¬ÆäÔÚ·¢Ã÷й¶ºóÁ¬Ã¦½ÓÄÉÁ˲½·¥£¬£¬£¬£¬£¬Êý¾Ý»¹Î´±»ÏÂÔØ£¬£¬£¬£¬£¬²¢ÇÒÓÉÓÚ´ËÊÂÎñµÄ¹æÄ£ºÍÑÏÖØÐÔ×Ó£¬£¬£¬£¬£¬ÏÖÒÑ֪ͨÈÏÕæ¼àÊÓµÄÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.birminghammail.co.uk/news/midlands-news/details-vulnerable-kids-uploaded-birmingham-20217314
5.Black KiteÐû²¼Îó²î¶ÔÐÅÓÃÏàÖúÉçµÄÓ°ÏìµÄÆÊÎö±¨¸æ

Black KiteÐû²¼ÁËÓйØÎó²î¶ÔÐÅÓÃÏàÖúÉçµÄÓ°ÏìµÄÆÊÎö±¨¸æ¡£¡£¡£±¨¸æÏÔʾ£¬£¬£¬£¬£¬Æ¾Ö¤Ð¹Â¶¡¢Î´¸üеľÉϵͳºÍ¹©Ó¦ÉÌÎó²îÊÇÐÅÓÃÏàÖúÉçËùÃæÁÙµÄ×î´óµÄÍøÂçΣº¦¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬Õë¶Ô¹©Ó¦É̵Ĺ¥»÷ΪÐÅÓÃÏàÖúÉç¿ÉÄÜ»áÔì³ÉÁè¼Ý100ÍòÃÀÔªµÄDZÔÚ²ÆÎïËðʧ£»£»£»£»£»£»86%µÄÐÅÓÃÏàÖúÉçºÍ76%µÄ¹©Ó¦É̵ÄÔ±¹¤Æ¾Ö¤Òѱ»ÇÔÈ¡²¢¹ûÕæµ½°µÍøÉÏ£»£»£»£»£»£»Áè¼Ý66%µÄÐÅÓÃÏàÖúÉçºÍ88%µÄ¹©Ó¦ÉÌȱ·¦Ô¤·ÀÓÕÆºÍ´¹ÂÚ¹¥»÷µÄµç×ÓÓʼþÇå¾²Õ½ÂÔ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://googleprojectzero.blogspot.com/2021/03/in-wild-series-october-2020-0-day.html
6.VectraÐû²¼ÓйØOffice 365ºÍÔÆµÄÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ

VectraÐû²¼ÁËÓйØOffice 365ºÍÔÆµÄÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£±¨¸æÏÔʾ£¬£¬£¬£¬£¬ÔÚÒÑÍùÒ»Ä꣬£¬£¬£¬£¬Ö»¹Ü½ÓÄÉÁ˶àÒòËØÉí·ÝÑéÖ¤£¨MFA£©£¬£¬£¬£¬£¬µ«ÈÔÓÐ71£¥µÄÆóÒµÈÔÈ»ÂÄÀú¹ýSaaSÕÊ»§Ð®ÖÆ£¬£¬£¬£¬£¬½ü90£¥µÄÆóÒµ»¹ÔÚ¼ÓËÙÔÆÅÌËãºÍÊý×Ö»¯µÄתÐÍ¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬¸Ã±¨¸æÔÚ90ÌìÄÚ¸ú×ÙÁË400Íò¸öMicrosoft Office 365¿Í»§µÄÐÐΪ£¬£¬£¬£¬£¬·¢Ã÷ÓÐ96£¥µÄÄÚÍø±£´æ¿ÉÒɵĺáÏòÒÆ¶¯ÐÐΪ¡£¡£¡£Îå·ÖÖ®ËĵÄÇ徲רҵְԱÌåÏÖ£¬£¬£¬£¬£¬ÔÚÒÑÍùÒ»ÄêÖÐÍøÂçÇå¾²µÄΣº¦ÓÐËùÔöÌí¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.vectra.ai/blogpost/cloud-security-insights


¾©¹«Íø°²±¸11010802024551ºÅ