Å·ÖÞEDP??B°ä²¼ÓйØÊý¾Ýй¶֪ͨʾÀýµÄÖ¸ÄÏ£» £»£»£»£»ºÚ¿Í¹«¿ªNitro PDFµÄ14GBÊý¾Ý£¬ £¬ £¬ £¬£¬Éæ¼°7700Íò¸öÓû§

°ä²¼¹¦·ò 2021-01-22
1.Å·ÖÞEDPB°ä²¼ÓйØÊý¾Ýй¶֪ͨʾÀýµÄÖ¸ÄÏ


1.jpg


2021Äê1ÔÂ18ÈÕ£¬ £¬ £¬ £¬£¬Å·ÖÞÊý¾Ý±£» £»£»£»£»¤Î¯Ô±»á£¨EDPB£©°ä²¼ÁËÓйØÊý¾Ýй¶֪ͨʾÀýÖ¸ÄϵIJݰ¸¡£¡£¡£¡£¡£¡£¸Ã²Ý°¸Ë¼¿¼ÁË×ÔGDPR 2018Äê5Ô¼à¹Ü»ú¹¹ÒÔÀ´ÔÚÊý¾Ýй¶·½ÃæµÄ³£¼û¾­Ñ飬 £¬ £¬ £¬£¬Ô̺¬Ò»Ð©³£¼ûµÄÊý¾Ýй¶³¡¾°µÄʾÀý£¬ £¬ £¬ £¬£¬ÈçÀÕË÷Èí¼þ¹¥»÷¡¢·ì϶¹¥»÷¡¢±¨´ðÃýÎó¡¢É豸ºÍÖ½ÖÊÎļþÃÔʧºÍÉç»á¹¤³ÌµÈ¡£¡£¡£¡£¡£¡£¸ÃÖ¸ÄÏ»¹»ØÊ×ÁË×éÖ¯Ó¦ÊÔÂǵö¹Ø¼ü³É·Ö£¬ £¬ £¬ £¬£¬Ô̺¬×Ô¶¯¼ø±ðϵͳ·ì϶¡¢ÆÀ¹Àй¶·çÏÕÒÔ¼°¼Í¼ÿÖÖÇé¿öϵÄй¶ÊÂÎñµÈ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.huntonprivacyblog.com/2021/01/19/edpb-publishes-guidelines-on-examples-regarding-data-breach-notification/


2.Cisco°²È«¸üУ¬ £¬ £¬ £¬£¬½¨¸´¶à¿î²úÆ·ÖеĴúÂëÖ´Ðзì϶


2.png


Cisco°ä²¼°²È«¸üУ¬ £¬ £¬ £¬£¬½¨¸´Æä¶à¸öSD-WAN²úÆ·ºÍCisco Smart Software ManagerÈí¼þÖеÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©·ì϶¡£¡£¡£¡£¡£¡£ÆäÖÐ×îÑϳÁµÄ·ì϶ΪSD-WAN vManage»ùÓÚWebµÄÖÎÀí½çÃæÖеÄCVE-2021-1299·ì϶£¬ £¬ £¬ £¬£¬CVSSÆÀ·Ö9.9£¬ £¬ £¬ £¬£¬¿É±»ÓÃÀ´ÒÔrootÓû§Éí·ÝÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£Æä´ÎΪ¶ÔIPÁ÷Á¿µÄ²»ÕýÈ·´¦Öõ¼ÖµĻº³åÇøÒç¶Âí½Å£¨CVE-2021-1300£©£¬ £¬ £¬ £¬£¬CVSSÆÀ·Ö9.8£¬ £¬ £¬ £¬£¬¿Éµ¼ÖÂËÁÒâºÅÁîÖ´ÐÓ×£¡£¡£¡£¡£¡£´Ë±í£¬ £¬ £¬ £¬£¬»¹½¨¸´ÁËCVE-2021-1138¡¢CVE-2021-1140ºÍCVE-2021-1142µÈ·ì϶¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/critical-cisco-sd-wan-bugs-rce-attacks/163204/


3.VideoLan½¨¸´VLC²¥·ÅÆ÷Öжà¸ö´úÂëÖ´Ðзì϶


3.png


VideoLan°ä²¼Á˺ÏÓÃÓÚWindows¡¢MacºÍLinux°æ±¾µÄVLC Media Player 3.0.12µÄ°²È«¸üУ¬ £¬ £¬ £¬£¬½¨¸´¶à¸ö´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£Õâ´Î½¨¸´Á˶à¸ö»º³åÇøÒç¶Âí½ÅºÍÎÞЧµÄÈ¡µÞÒýÓ÷ì϶£¬ £¬ £¬ £¬£¬¿Éµ¼ÖÂVLC±ÀÀ£» £»£»£»£»òËÁÒâ´úÂëÖ´ÐÓ×£¡£¡£¡£¡£¡£VideoLan°µÊ¾£¬ £¬ £¬ £¬£¬ÕâЩ·ì϶×ÔÉí¿ÉÄܻᵼÖ²¥·ÅÆ÷±ÀÀ££¬ £¬ £¬ £¬£¬×éºÏÔÚһ·ʹÓÿÉÄÜ»áй¶Óû§ÐÅÏ¢»òÔ¶³ÌÖ´ÐдúÂ룬 £¬ £¬ £¬£¬ASLRºÍDEP»òÐí»áÓÐÔ®ÊÖ£¬ £¬ £¬ £¬£¬µ«Ò²¿ÉÄÜ»á±»ÈÆ¹ý¡£¡£¡£¡£¡£¡£Ä¿Ç°ÉÐδ·¢ÏÖ·ì϶±»ÔÚÒ°ÀûÓõÄÇé¿ö¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/software/vlc-media-player-3012-fixes-multiple-remote-code-execution-flaws/


4.ºÚ¿Í¹«¿ªNitro PDFµÄ14GBÊý¾Ý£¬ £¬ £¬ £¬£¬Éæ¼°7700Íò¸öÓû§


4.png


ºÚ¿Í¹«¿ªÁËNitro PDFÓû§µÄÆëÈ«Êý¾Ý¿â£¬ £¬ £¬ £¬£¬Ð¹Â¶ÁË14GBÊý¾Ý£¬ £¬ £¬ £¬£¬×ܼÆ77159696±Ê¼Í¼¡£¡£¡£¡£¡£¡£NitroÊÇÒ»¿î¿ÉÔ®ÊÖ´´½¨¡¢±à×ëºÍÇ©ÊðPDFºÍÊý×ÖÎĵµµÄÀûÓ㬠£¬ £¬ £¬£¬³ÆÕ¼ÓÐ10000¶à¸öóÒ׿ͻ§ºÍ180ÍòÐí¿ÉÓû§¡£¡£¡£¡£¡£¡£Õâ´Îй¶µÄÊý¾ÝÔ̺¬Óû§µÄÓʼþµØÖ·¡¢ÐÕÃû¡¢¹þÏ£ÃÜÂ롢ͷÏΡ¢¹«Ë¾Ãû³Æ¡¢IPµØÖ·ÒÔ¼°ÆäËûÓëϵͳÓйصÄÐÅÏ¢¡£¡£¡£¡£¡£¡£È¥ÄêNitroÒ²²úÉú¹ýÀàËÆÊÂÎñ£¬ £¬ £¬ £¬£¬ºÚ¿ÍÒÔ80000ÃÀÔªµÄ¼ÛÖµÅÄÂôÔ̺¬7000Íò¸öÓû§µÄÐÅÏ¢µÄÊý¾Ý¿âºÍ1TBÎļþ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hacker-leaks-full-database-of-77-million-nitro-pdf-user-records/


5.QNAP·¢ÏÖжñÒâÈí¼þDovecat¶Ô×¼ÆäNASÉ豸


5.png


ÍþÁªÍ¨£¨QNAP£©°ä²¼°²È«²¼¸æ£¬ £¬ £¬ £¬£¬ÖÒ¸æÐÂÐͼÓÃÜ¿ó¹¤Dovecat¶Ô×¼ÆäNASÉ豸¡£¡£¡£¡£¡£¡£QNAP°µÊ¾£¬ £¬ £¬ £¬£¬¸Ã¶ñÒâÈí¼þĿǰʹÓÃÈõÃÜÂëÏνÓ¶³öµÄQNAP NASϵͳ½øÐзַ¢£¬ £¬ £¬ £¬£¬À´ÀûÓÃÓû§µÄ±¾µØ×ÊÔ´ÍÚ¾ò¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·ÖÎö·¢ÏÖ£¬ £¬ £¬ £¬£¬¸Ã¶ñÒâÈí¼þËÆºõÊÇרÃÅΪQNAP NAS¶øÉè¼ÆµÄ£¬ £¬ £¬ £¬£¬µ«¿ÉÄÜϰȾËùÓÐLinuxϵͳ¡£¡£¡£¡£¡£¡£QNAP½¨ÒéÓû§²ÉÈ¡¸üÇ¿µÄÖÎÀíÔ±ÃÜÂë¡¢½ûÓÃSSHºÍTelnet·þÎñ¡¢½ûÓÃδʹÓõķþÎñºÍÀûÓ÷¨Ê½ºÍÔ¤·ÀʹÓÃĬÈ϶˱êÓïµÈ´ëÊ©¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/qnap-warns-users-of-a-new-crypto-miner-named-dovecat-infecting-their-devices/


6.Avira°ä²¼2020ÄêÖØÒªÍøÂç¹¥»÷ºÍÍþвµÄ»ØÊ׻㱨


6.png


Avira°ä²¼ÁË2020ÄêÖØÒªÍøÂç¹¥»÷ºÍÍþвµÄ»ØÊ׻㱨¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬ £¬ £¬ £¬£¬Óë2019ÄêÏà±È£¬ £¬ £¬ £¬£¬2020ÄêÉϰëÄêµÄÍøÂç´¹µö¹¥»÷ÊýÁ¿Ôö³¤ÁËÒ»±¶ÒÔÉÏ£¬ £¬ £¬ £¬£¬¼ì²âµ½Á˳¬¹ý840Íò¸öÍøÂç´¹µöURL£¬ £¬ £¬ £¬£¬±È2019ÄêÉϰëÄêÔö³¤ÁË470Íò¸ö¡£¡£¡£¡£¡£¡£´Ë±í£¬ £¬ £¬ £¬£¬ÀÕË÷Èí¼þ¹¥»÷ÊÇ2020Äê×î³£¼ûµÄÍþв֮һ£¬ £¬ £¬ £¬£¬Covid-19ÆÚ¼ä¹¥»÷Õ߸ü¶àµÄ¶Ô×¼Ò½ÁÆÐÐÒµ£¬ £¬ £¬ £¬£¬³ý²ÆÕþÉϵÄËðʧ±í»¹¿ÉÄܵ¼ÖÂÐÔÃüΣÏÕ£¬ £¬ £¬ £¬£¬Ò»Ð©ºÚ¿Í×éÖ¯»¹Õë¶ÔÃÀ¹ú¡¢¼ÓÄôó¡¢Ó¢¹ú¡¢µÂ¹úºÍÈðÊ¿µÄºÜ¶à´óѧºÍ×êÑÐÖÐÐÄ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.avira.com/en/blog/a-year-in-review-top-cyberattacks-and-common-cyberthreats-in-2020