NPM¿âNetmask×é¼þ´æÔÚ·ì϶£¬¿ÉÓ°ÏìÊýÍò¸öÀûÓ÷¨Ê½ £»×êÑÐÈËÔ±·¢ÏÖÒѰµ²Ø25ÄêµÄWindows 95ÐÂÉú½Ú²Êµ°

°ä²¼¹¦·ò 2021-03-29

1.NPM¿âNetmask×é¼þ´æÔÚ·ì϶£¬¿ÉÓ°ÏìÊýÍò¸öÀûÓ÷¨Ê½


1.jpg


¸Ã×é¼þÿÖÜÏÂÔØÁ¿³¬¹ý300Íò´Î£¬½ØÖÁ´Ë¿ÌÀÛ¼ÆÏÂÔØÁ¿Òѳ¬¹ý2.38ÒڴΣ¬Ô¼ÓÐ27.8Íò¸öGitHub´æ´¢¿âÒÀÀµÓÚnetmask¡£¸Ã·ì϶±»×·×ÙΪCVE-2021-28918£¬Ê®½øÔìIPv4µØÖ·Ô̺¬Ç°µ¼Áãʱ£¬ÍøÂçÑÚÂë´¦ÖûìºÏÌåʽIPµØÖ·µÄ·½Ê½¡£¹¥»÷ÕßÄܹ»Í¨¹ýÓ°ÏìÀûÓ÷¨Ê½½âÎöµÄIPµØÖ·£¬Ôò¸Ã·ì϶¿ÉÄÜ»áÒýÆð¸÷Àà·ì϶£¬ÀýÈçµ¼Ö·þÎñÆ÷¶ËÒªÇóαÔ죨SSRF£©ºÍµ½Ô¶³ÌÎļþÔ̺¬£¨RFI£©¡£Ä¿Ç°£¬¸Ã·ì϶Òѱ»½¨¸´¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/critical-netmask-networking-bug-impacts-thousands-of-applications/


2.ClopÁªÏµÊܺ¦ÕߵĿͻ§µÄÐÂÕ½Êõ¶ÔÖ¸±êʩѹ


2.jpg


ÀÕË÷Èí¼þÍÅ»ïClopÖ±½ÓÏòÊܺ¦ÕߵĿͻ§·¢Ë͵ç×ÓÓʼþ£¬Í¨ÖªÆäÊý¾ÝÒѱ»Ð¹Â¶¡£ÕâÏîÐÂÕ½ÊõÖ¼ÔÚÌá¸ßÀÕË÷µÄЧÄÜ£¬´Ó¶øÆÈʹָ±ê¹«Ë¾Ö§¸¶Êê½ð¡£Æ¾¾ÝBleepingComputerµÄ˵·¨£¬ÐÂÕ½ÊõµÄÊܺ¦ÕßÔ̺¬Flagstar BankºÍ¿ÆÂÞÀ­¶à´óѧ¡£´Ë±í£¬ÆäËûÍÅ»ïÒ²ÔÚ·¢Õ¹ÐµÄÕ½Êõ£¬REvil½üÆÚ°ä·¢ËûÃÇÔÚʹÓÃDDoS¹¥»÷£¬²¢ÏòÊܺ¦ÕߵĺÏ×÷¹«Ë¾¼°¼ÇÕß·¢ËÍÓïÒôºô½Ð£¬ÒÔÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116029/cyber-crime/clop-ransomware-extortion.html


3.Ó¢¹ú¹«Ë¾FatFaceϰȾConti£¬³¬¹ý200GBÊý¾Ýй¶


3.jpg


Ó¢¹ú·þ×°¹«Ë¾FatFaceÔâµ½ContiÀÕË÷Èí¼þ¹¥»÷£¬³¬¹ý200GBÊý¾Ýй¶¡£¹¥»÷²úÉúÔÚ2021Äê1ÔÂ17ÈÕ£¬¹¥»÷Õß½Ó¼ûÁËFatFaceµÄÍøÂçºÍϵͳ£¬²¢ÀÕË÷850ÍòÃÀÔª£¬×îÖÕ¾­½»ÉæÊê½ðÈ·¶¨Îª200ÍòÃÀÔª¡£Õâ´Îй¶µÄ¿Í»§ÐÅÏ¢Ô̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢ÓʼĵØÖ·ºÍ²¿ÃÅÐÅÓþ¿¨ÐÅÏ¢£¨×îºóËÄλÊý×ÖºÍÓÐЧÆÚ£©¡£´Ë±í£¬¸Ã¹«Ë¾ÔÚÊý¾Ýй¶֪ͨÓʼþÖÐÒªÇóÆäÊÕ¼þÈËÎñ±Ø¶Ô´ËÓʼþ¼°ÆäÖÐÔ̺¬µÄÐÅÏ¢Ñϸñ±£ÃÜ£¬ÒÔ´ËÊÔͼ¸²¸ÇÊý¾Ýй¶µÄÊÂʵ£¬´ËÊÂÎñÔÚÍøÉÏÒýÆðÐùÈ»´ó²¨¡£    


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fatface-sends-controversial-data-breach-email-after-ransomware-attack/


4.×êÑÐÈËÔ±·¢ÏÖÒѰµ²Ø25ÄêµÄWindows 95ÐÂÉú½Ú²Êµ°


4.jpg


ijWindows×êÑÐÈËÔ±AlbacoreÔÚInternet MailÀûÓ÷¨Ê½Öз¢ÏÖÁËÒѰµ²Ø25ÄêµÄWindows 95ÐÂÉú½Ú²Êµ°¡ £¿ª·¢ÈËÔ±ÔÚ¿ª·¢Èí¼þʱ»áÉèÖòʵ°£¬Óû§Í¨¹ýÔÚ·¨Ê½ÖÐÖ´ÐÐÌØ¶¨²Ù×÷À´·¢ÏÖ°µ²ØÖ°ÄÜ¡¢ÐÂÎÅÉõÖÁÊÇÃÔÄãÓÎÏ·¡£Albacore°µÊ¾£¬ÒªÏë½Ó¼ûÐÂÉú½Ú²Êµ°£¬Ö»±ØÒªÆô¶¯Internet Mail£¬µ¥»÷Ô®Êֺ͹ØÓÚ£¬ÔÚ¹ØÓڲ˵¥Öе¥»÷comctl32.dll£¬¶øºóÔÚ¼üÅÌÉϼüÈëMORTIMER£¬¾ÍÄܹ»·¢ÏÖ¿ª·¢ÈËÔ±Ãû³ÆµÄ¹ö¶¯Áбí¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/windows-95-easter-egg-discovered-after-being-hidden-for-25-years/


5.WhiteHat°ä²¼ÀûÓð²È«µÄÌ¬ÊÆ·ÖÎö»ã±¨


5.jpg


WhiteHat Security°ä²¼ÁËÓйØÀûÓð²È«µÄÌ¬ÊÆ·ÖÎö»ã±¨¡£×êÑз¢ÏÖ£¬ÃæÏòWebµÄÀûÓ÷¨Ê½ÒÀÈ»ÊÇ×éÖ¯Ãæ¶ÔµÄ×î¸ß°²È«·çÏÕÖ®Ò»£¬³¬¹ý40£¥µÄÀûÓÃй¶Êý¾Ý¿ÉÄÜ»á¶ÔÆóÒµ¼°ÆäºÏ×÷ͬ°éÔì³ÉÁ¬Ëø·´Ó³¡£´Ë±í£¬Ôì×÷Òµ³ö¸ñÈÝÒ×Êܵ½Õë¶ÔÀûÓ÷¨Ê½µÄ¹¥»÷£¬È¥ÄêÓÐ70£¥µÄÀûÓôæÔÚÖÁÉÙÒ»¸öÑϳÁ·ì϶¡£ÆäÖУ¬ÔÚÀûÓ÷¨Ê½Öз¢ÏÖµÄǰÎå¸ö·ì϶Ô̺¬ÐÅϢй¶©²»³ä·ÖµÄ»á»°¹ýÆÚ»úÔì¡¢XSS·ì϶¡¢´«Êä²ã± £»¤²»¼°ºÍÄÚÈݺýŪ·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://www.whitehatsec.com/appsec-stats-flash/


6.Mimecast°ä²¼ÒßÇéÆÚ¼ä¹¥»÷»î¶¯µÄÌ¬ÊÆ·ÖÎö»ã±¨


6.jpg


Mimecast°ä²¼ÁËÒßÇéÆÚ¼ä¹¥»÷»î¶¯µÄÌ¬ÊÆ·ÖÎö»ã±¨¡£¸Ã»ã±¨¾ßÌå½éÉÜÁËÔÚCOVIDÊ¢ÐеĵÚÒ»Ä꣨2020Äê3ÔÂÖÁ2021Äê2Ô£©ÖÐÕë¶ÔÔ¶³Ì¹¤×÷ÕߵĹ¥»÷»î¶¯¡£»ã±¨Ö¸³ö£¬ÔÚÕâÒ»Äê¹¥»÷Á¿¼¤ÔöÁË48£¥£¬ÆäÖй¥»÷µÄ·åÖµ³Ê´Ë¿Ì2020Äê10Ô¡£ÔÚ2020Äê3Ô£¬¾Ó¼Ò°ì¹«Ç÷ÏòµÄ³öÏÖµÄʱ³½£¬²»°²È«µÄµã»÷´ÎÊýÔö³¤ÁË3±¶¡£´Ë±í£¬ÃÀ¹úÈË´ò¿ª¿ÉÒÉÓʼþµÄ¿ÉÄÜÐÔÊÇÓ¢¹úºÍµÂ¹úÈ˵ÄÁ½±¶ £»¹«Ë¾µÄÍÆËã»úÓÃÓÚÓ×ÎÒÒµÎñµÄʹÓÃÂÊÔö³¤ÁË60£¥¡£


Ô­ÎÄÁ´½Ó£º

https://www.mimecast.com/resources/press-releases/dates/2021/3/the-year-of-social-distancing/