IntelµÄHabana LabsϰȾPay2Key£¬Ã³Ò×ÎĵµºÍÔ´´úÂë±»µÁ £»Adobe°ä²¼Flash Player×îÖÕ¸üÐÂ

°ä²¼¹¦·ò 2020-12-14
1.IntelµÄHabana LabsϰȾPay2Key£¬Ã³Ò×ÎĵµºÍÔ´´úÂë±»µÁ


1.jpg


IntelµÄAI´¦ÖÃÆ÷¿ª·¢ÉÌHabana LabsÔâµ½ÁËPay2KeyÀÕË÷Èí¼þ¹¥»÷£¬Ã³Ò×ÎĵµºÍÔ´´úÂë±»µÁ¡£Habana LabsÊÇÒÔÉ«ÁÐAI´¦ÖÃÆ÷µÄ¿ª·¢ÉÌ£¬ÓÚ2019Äê12ÔÂÒÔ20ÒÚÃÀÔªµÄ¼ÛÖµ±»IntelÊÕ¹º¡£Pay2KeyÔÚTwitterÉϰ䷢ÁËÕâ´Î¹¥»÷£¬²¢Ðû³ÆÒÑÇÔÈ¡ÁËÓйØÈËΪÖÇÄÜоƬ´úÂëGaudiµÄÐÅÏ¢Êý¾Ý¡£¸ÃÍÅ»ïÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ÉϹ«¿ªÁ˸ù«Ë¾µÄÔ´´úÂëºÍÄÚ²¿¹ý³ÌµÄͼƬ£¬ÒÔ¼°WindowsÓò½ÚÔìÆ÷Êý¾ÝºÍGerrit¿ª·¢´úÂë²é³­ÏµÍ³µÄÎļþÁбí¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/112258/data-breach/pay2key-hacked-habana-labs.html


2.Adobe°ä²¼Flash Player×îÖÕ¸üУ¬2021Ä꽫ÖÕÖ¹¸üÐÂ


2.jpg


Adobe°ä²¼Flash Player×îÖÕ¸üУ¬²¢°ä·¢½«ÓÚ2021ÄêÖÕÖ¹¸üС£³õ°æAdobe Flash PlayerÓÚ1996Äê1Ô°䲼£¬¾­¹ý24ÄêµÄʹÓúͺڿ͵ÄÀÄÓã¬Adobe½«°ä²¼Flash PlayerµÄ×îÖÕ¸üв¢ÖÕ³¡ÊØ»¤¡£´Ó2021Äê1ÔÂÆðÍ·£¬ËùÓÐä¯ÀÀÆ÷µÄ¿ª·¢Õߣ¬Ô̺¬¹È¸èChrome¡¢Safari¡¢Mozilla Firefox¡¢Microsoft Edge¡¢Internet Explorer 11ºÍÆäËû»ùÓÚChromeµÄä¯ÀÀÆ÷£¬¶¼½«°ÑAdobe Flash´ÓËûÃǵÄä¯ÀÀÆ÷ÖÐÆëÈ«ÒÆ³ý¡£ÇÒÒ»µ©ÒƳýºó£¬½«Ã»Óз¨×ÓÔÙ½øÐÐ×°Öᣠ   


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/software/adobe-releases-final-flash-player-update-warns-of-2021-kill-switch/


3.NI CompactRIO½ÚÔìÆ÷´æÔڿɵ¼ÖÂÆóÒµ³ö²úÖжϵķì϶


3.jpg


National Instruments£¨NI£©CompactRIO½ÚÔìÆ÷´æÔÚÑϳÁµÄ·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß·ÛËé×éÖ¯Öеijö²ú¹ý³Ì¡£¸Ã·ì϶±»×·×ÙΪCVE-2020-25191£¬ÊÇÓÉÓڹؼü×ÊÔ´µÄȨÏÞ·ÖÅä²»ÕýÈ·£¬ÎªÌض¨·þÎñµÄAPIÈë¿ÚµãÉèÖÃÁËÃýÎóµÄȨÏÞËùµ¼Ö¡£¹¥»÷Õ߳ɹ¦ÀûÓô˷ì϶ºóÄܹ»Ô¶³Ì³ÁÐÂÆô¶¯É豸£¬ÒÔÖжÏ×éÖ¯µÄ³ö²ú¹ý³Ì¡£Ä¿Ç°£¬CISA°ä²¼Á˰²È«²¼¸æÒÔÖÒ¸æ×éÖ¯°ÑÎȸ÷ì϶£¬²¢Ìá³öÁË»º½â´ëÊ©¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/112228/ics-scada/ni-compactrio-flaw.html


4.GlassdoorÍøÕ¾´æÔڿɵ¼ÖÂÕË»§±»ÊÕÊܵÄCSRF·ì϶


4.jpg


ÇóÖ°ÍøÕ¾Glassdoor´æÔÚÑϳÁµÄCSRF·ì϶£¬¿Éµ¼ÖÂÕË»§±»ÊÕÊÜ¡£¸Ãƽ̨ʹÓÃÁËgdTokenÁîÅÆÓÃÓÚÔ¤·ÀCSRF¹¥»÷£¬µ«×êÑÐÈËÔ±Tabahi·¢ÏÔìäÒÀÈ»´æÔÚ·ì϶¡£Tabahi´ÓAÕÊ»§ÌìÉúCSRFÁîÅÆ£¬È¥µôµÚÒ»¸ö×Ö·ûºó³¢ÊÔʹ֮×÷ΪBÕÊ»§µÄÁîÅÆ£¬Á˾ÖÖ¤Ã÷Êdzɹ¦µÄ¡£¸Ã·ì϶ӰÏìÁËGlassdoor webÓò£¬Glassdoor°²È«ÍŶӽ«Æä¹éÀàΪÁîÅÆ³¤¶ÈÑéÖ¤ÃýÎ󣬲¢ÇÒ»¹´æÔÚÒì³£´¦ÖÃÎÊÌâ¡£ÇóÖ°Õߺ͹ÍÖ÷µÄÕÊ»§¾ù»áÊܵ½¸Ã·ì϶µÄÓ°Ïì¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/cross-site-request-forgery-vulnerability-found-on-glassdoor-job-hunter-review-platform/


5.а汾µÄÀÕË÷Èí¼þMountLocker´óÓ×½öΪ46KB


5.jpg


×êÑÐÈËÔ±ÔÚÒ°±í·¢ÏÖÁËа汾µÄÀÕË÷Èí¼þMountLocker¡£¸Ã¶ñÒâÈí¼þµÄ¿ª·¢ÈËÔ±½«64λµÄ±äÌåËõÓ×µ½46KB£¬±ÈÒÔǰµÄ°æ±¾Ó×50£¥¡£Îª´Ë£¬ËûÃÇɾ³ýÁËÎļþÀ©´óÃûÁбí£¬ÆäÖÐÔ̺¬2600¶à¸öÓÃÓÚ¼ÓÃܵÄÌõ¿î¡£¸ÃÍŻﻹÔö³¤ÁËÓëTurboTaxÈí¼þ¹ØÁªµÄÎļþÀ©´óÃû£¨.tax¡¢.tax2009¡¢.tax2013ºÍ.tax2014£©£¬ÒÔ¶Ô×¼ÏÂÒ»ÄÉ˰¼¾¡£¸ÃбäÌåÒÀȻʹÓÃÁ˲»°²È«µÄWindows APIº¯ÊýGetTickCountÀ´ÌìÉúËæ»ú¼ÓÃÜÃÜÔ¿£¬¿ÉÄܱ»ÓÃÀ´½øÐб©Á¦¹¥»÷¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/mountlocker-ransomware-gets-slimmer-now-encrypts-fewer-files/


6.CrowdStrike°ä²¼2020ÄêÁäÎñÏìÓ¦ºÍ×Ô¶¯·þÎñ·ÖÎö»ã±¨


6.jpg


CrowdStrike°ä²¼ÁË2020ÄêÁäÎñÏìÓ¦ºÍ×Ô¶¯·þÎñ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬68£¥µÄÊܺ¦×éÖ¯ÔÚÒ»ÄêÄÚ½«Ôâ·êµÚ¶þ´Î¹¥»÷¡£ÔÚ³öÓÚ²ÆÕþ¶¯»úµÄÍøÂç¹¥»÷ÖУ¬81£¥µÄÊÂÎñÓëÀÕË÷Èí¼þÓйØ£¬ÆäÓàµÄ19£¥·ÖΪÏúÊÛµãÈëÇÖ¡¢µç×ÓÉÌÎñÍøÕ¾¹¥»÷¡¢Ã³Ò×µç×ÓÓʼþй¶£¨BEC£©ºÍ¼ÓÃÜÇ®±ÒÍÚ¿ó¡£´Ë±í£¬Óë¹ú¶ÈÓйصĹ¥»÷»î¶¯ÒÀÈ»ÊǸ÷Ðи÷ÒµµÄÑϳÁÍþв¡£CrowdStrikeµÄCSO Shawn HenryÖ¸³ö£¬Ô¶³Ì¹¤×÷Ϊ¹¥»÷ÕßÌṩÁËÐµĹ¥»÷ÃæºÍý½é£¬¶øÈ«ÃæµÄЭºÍг³ÖÐøµÄ¾¯ÌèÊÇ·¢ÏÖºÍ×èÖ¹¸´ÔÓÈëÇֵĹؼü¡£


Ô­ÎÄÁ´½Ó£º

https://www.crowdstrike.com/resources/reports/cyber-front-lines/