NPM¿âNetmask×é¼þ´æÔÚ·ì϶£¬£¬ £¬£¬£¬£¬£¬£¬¿ÉÓ°ÏìÊýÍò¸öÀûÓ÷¨Ê½£» £»£»£»£»£»£»£»×êÑÐÈËÔ±·¢ÏÖÒѰµ²Ø25ÄêµÄWindows 95ÐÂÉú½Ú²Êµ°

°ä²¼¹¦·ò 2021-03-29

1.NPM¿âNetmask×é¼þ´æÔÚ·ì϶£¬£¬ £¬£¬£¬£¬£¬£¬¿ÉÓ°ÏìÊýÍò¸öÀûÓ÷¨Ê½


1.jpg


¸Ã×é¼þÿÖÜÏÂÔØÁ¿³¬¹ý300Íò´Î£¬£¬ £¬£¬£¬£¬£¬£¬½ØÖÁ´Ë¿ÌÀÛ¼ÆÏÂÔØÁ¿Òѳ¬¹ý2.38ÒڴΣ¬£¬ £¬£¬£¬£¬£¬£¬Ô¼ÓÐ27.8Íò¸öGitHub´æ´¢¿âÒÀÀµÓÚnetmask¡£¡£¡£ ¡£¡£¡£¡£¸Ã·ì϶±»×·×ÙΪCVE-2021-28918£¬£¬ £¬£¬£¬£¬£¬£¬Ê®½øÔìIPv4µØÖ·Ô̺¬Ç°µ¼Áãʱ£¬£¬ £¬£¬£¬£¬£¬£¬ÍøÂçÑÚÂë´¦ÖûìºÏÌåʽIPµØÖ·µÄ·½Ê½¡£¡£¡£ ¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Í¨¹ýÓ°ÏìÀûÓ÷¨Ê½½âÎöµÄIPµØÖ·£¬£¬ £¬£¬£¬£¬£¬£¬Ôò¸Ã·ì϶¿ÉÄÜ»áÒýÆð¸÷Àà·ì϶£¬£¬ £¬£¬£¬£¬£¬£¬ÀýÈçµ¼Ö·þÎñÆ÷¶ËÒªÇóαÔ죨SSRF£©ºÍµ½Ô¶³ÌÎļþÔ̺¬£¨RFI£©¡£¡£¡£ ¡£¡£¡£¡£Ä¿Ç°£¬£¬ £¬£¬£¬£¬£¬£¬¸Ã·ì϶Òѱ»½¨¸´¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/critical-netmask-networking-bug-impacts-thousands-of-applications/


2.ClopÁªÏµÊܺ¦ÕߵĿͻ§µÄÐÂÕ½Êõ¶ÔÖ¸±êʩѹ


2.jpg


ÀÕË÷Èí¼þÍÅ»ïClopÖ±½ÓÏòÊܺ¦ÕߵĿͻ§·¢Ë͵ç×ÓÓʼþ£¬£¬ £¬£¬£¬£¬£¬£¬Í¨ÖªÆäÊý¾ÝÒѱ»Ð¹Â¶¡£¡£¡£ ¡£¡£¡£¡£ÕâÏîÐÂÕ½ÊõÖ¼ÔÚÌá¸ßÀÕË÷µÄЧÄÜ£¬£¬ £¬£¬£¬£¬£¬£¬´Ó¶øÆÈʹָ±ê¹«Ë¾Ö§¸¶Êê½ð¡£¡£¡£ ¡£¡£¡£¡£Æ¾¾ÝBleepingComputerµÄ˵·¨£¬£¬ £¬£¬£¬£¬£¬£¬ÐÂÕ½ÊõµÄÊܺ¦ÕßÔ̺¬Flagstar BankºÍ¿ÆÂÞÀ­¶à´óѧ¡£¡£¡£ ¡£¡£¡£¡£´Ë±í£¬£¬ £¬£¬£¬£¬£¬£¬ÆäËûÍÅ»ïÒ²ÔÚ·¢Õ¹ÐµÄÕ½Êõ£¬£¬ £¬£¬£¬£¬£¬£¬REvil½üÆÚ°ä·¢ËûÃÇÔÚʹÓÃDDoS¹¥»÷£¬£¬ £¬£¬£¬£¬£¬£¬²¢ÏòÊܺ¦ÕߵĺÏ×÷¹«Ë¾¼°¼ÇÕß·¢ËÍÓïÒôºô½Ð£¬£¬ £¬£¬£¬£¬£¬£¬ÒÔÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116029/cyber-crime/clop-ransomware-extortion.html


3.Ó¢¹ú¹«Ë¾FatFaceϰȾConti£¬£¬ £¬£¬£¬£¬£¬£¬³¬¹ý200GBÊý¾Ýй¶


3.jpg


Ó¢¹ú·þ×°¹«Ë¾FatFaceÔâµ½ContiÀÕË÷Èí¼þ¹¥»÷£¬£¬ £¬£¬£¬£¬£¬£¬³¬¹ý200GBÊý¾Ýй¶¡£¡£¡£ ¡£¡£¡£¡£¹¥»÷²úÉúÔÚ2021Äê1ÔÂ17ÈÕ£¬£¬ £¬£¬£¬£¬£¬£¬¹¥»÷Õß½Ó¼ûÁËFatFaceµÄÍøÂçºÍϵͳ£¬£¬ £¬£¬£¬£¬£¬£¬²¢ÀÕË÷850ÍòÃÀÔª£¬£¬ £¬£¬£¬£¬£¬£¬×îÖÕ¾­½»ÉæÊê½ðÈ·¶¨Îª200ÍòÃÀÔª¡£¡£¡£ ¡£¡£¡£¡£Õâ´Îй¶µÄ¿Í»§ÐÅÏ¢Ô̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢ÓʼĵØÖ·ºÍ²¿ÃÅÐÅÓþ¿¨ÐÅÏ¢£¨×îºóËÄλÊý×ÖºÍÓÐЧÆÚ£©¡£¡£¡£ ¡£¡£¡£¡£´Ë±í£¬£¬ £¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚÊý¾Ýй¶֪ͨÓʼþÖÐÒªÇóÆäÊÕ¼þÈËÎñ±Ø¶Ô´ËÓʼþ¼°ÆäÖÐÔ̺¬µÄÐÅÏ¢Ñϸñ±£ÃÜ£¬£¬ £¬£¬£¬£¬£¬£¬ÒÔ´ËÊÔͼ¸²¸ÇÊý¾Ýй¶µÄÊÂʵ£¬£¬ £¬£¬£¬£¬£¬£¬´ËÊÂÎñÔÚÍøÉÏÒýÆðÐùÈ»´ó²¨¡£¡£¡£ ¡£¡£¡£¡£    


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fatface-sends-controversial-data-breach-email-after-ransomware-attack/


4.×êÑÐÈËÔ±·¢ÏÖÒѰµ²Ø25ÄêµÄWindows 95ÐÂÉú½Ú²Êµ°


4.jpg


ijWindows×êÑÐÈËÔ±AlbacoreÔÚInternet MailÀûÓ÷¨Ê½Öз¢ÏÖÁËÒѰµ²Ø25ÄêµÄWindows 95ÐÂÉú½Ú²Êµ°¡£¡£¡£ ¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿£¿ª·¢ÈËÔ±ÔÚ¿ª·¢Èí¼þʱ»áÉèÖòʵ°£¬£¬ £¬£¬£¬£¬£¬£¬Óû§Í¨¹ýÔÚ·¨Ê½ÖÐÖ´ÐÐÌØ¶¨²Ù×÷À´·¢ÏÖ°µ²ØÖ°ÄÜ¡¢ÐÂÎÅÉõÖÁÊÇÃÔÄãÓÎÏ·¡£¡£¡£ ¡£¡£¡£¡£Albacore°µÊ¾£¬£¬ £¬£¬£¬£¬£¬£¬ÒªÏë½Ó¼ûÐÂÉú½Ú²Êµ°£¬£¬ £¬£¬£¬£¬£¬£¬Ö»±ØÒªÆô¶¯Internet Mail£¬£¬ £¬£¬£¬£¬£¬£¬µ¥»÷Ô®Êֺ͹ØÓÚ£¬£¬ £¬£¬£¬£¬£¬£¬ÔÚ¹ØÓڲ˵¥Öе¥»÷comctl32.dll£¬£¬ £¬£¬£¬£¬£¬£¬¶øºóÔÚ¼üÅÌÉϼüÈëMORTIMER£¬£¬ £¬£¬£¬£¬£¬£¬¾ÍÄܹ»·¢ÏÖ¿ª·¢ÈËÔ±Ãû³ÆµÄ¹ö¶¯Áбí¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/windows-95-easter-egg-discovered-after-being-hidden-for-25-years/


5.WhiteHat°ä²¼ÀûÓð²È«µÄÌ¬ÊÆ·ÖÎö»ã±¨


5.jpg


WhiteHat Security°ä²¼ÁËÓйØÀûÓð²È«µÄÌ¬ÊÆ·ÖÎö»ã±¨¡£¡£¡£ ¡£¡£¡£¡£×êÑз¢ÏÖ£¬£¬ £¬£¬£¬£¬£¬£¬ÃæÏòWebµÄÀûÓ÷¨Ê½ÒÀÈ»ÊÇ×éÖ¯Ãæ¶ÔµÄ×î¸ß°²È«·çÏÕÖ®Ò»£¬£¬ £¬£¬£¬£¬£¬£¬³¬¹ý40£¥µÄÀûÓÃй¶Êý¾Ý¿ÉÄÜ»á¶ÔÆóÒµ¼°ÆäºÏ×÷ͬ°éÔì³ÉÁ¬Ëø·´Ó³¡£¡£¡£ ¡£¡£¡£¡£´Ë±í£¬£¬ £¬£¬£¬£¬£¬£¬Ôì×÷Òµ³ö¸ñÈÝÒ×Êܵ½Õë¶ÔÀûÓ÷¨Ê½µÄ¹¥»÷£¬£¬ £¬£¬£¬£¬£¬£¬È¥ÄêÓÐ70£¥µÄÀûÓôæÔÚÖÁÉÙÒ»¸öÑϳÁ·ì϶¡£¡£¡£ ¡£¡£¡£¡£ÆäÖУ¬£¬ £¬£¬£¬£¬£¬£¬ÔÚÀûÓ÷¨Ê½Öз¢ÏÖµÄǰÎå¸ö·ì϶Ô̺¬ÐÅϢй¶©²»³ä·ÖµÄ»á»°¹ýÆÚ»úÔì¡¢XSS·ì϶¡¢´«Êä²ã±£» £»£»£»£»£»£»£»¤²»¼°ºÍÄÚÈݺýŪ·ì϶¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.whitehatsec.com/appsec-stats-flash/


6.Mimecast°ä²¼ÒßÇéÆÚ¼ä¹¥»÷»î¶¯µÄÌ¬ÊÆ·ÖÎö»ã±¨


6.jpg


Mimecast°ä²¼ÁËÒßÇéÆÚ¼ä¹¥»÷»î¶¯µÄÌ¬ÊÆ·ÖÎö»ã±¨¡£¡£¡£ ¡£¡£¡£¡£¸Ã»ã±¨¾ßÌå½éÉÜÁËÔÚCOVIDÊ¢ÐеĵÚÒ»Ä꣨2020Äê3ÔÂÖÁ2021Äê2Ô£©ÖÐÕë¶ÔÔ¶³Ì¹¤×÷ÕߵĹ¥»÷»î¶¯¡£¡£¡£ ¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬ £¬£¬£¬£¬£¬£¬ÔÚÕâÒ»Äê¹¥»÷Á¿¼¤ÔöÁË48£¥£¬£¬ £¬£¬£¬£¬£¬£¬ÆäÖй¥»÷µÄ·åÖµ³Ê´Ë¿Ì2020Äê10Ô¡£¡£¡£ ¡£¡£¡£¡£ÔÚ2020Äê3Ô£¬£¬ £¬£¬£¬£¬£¬£¬¾Ó¼Ò°ì¹«Ç÷ÏòµÄ³öÏÖµÄʱ³½£¬£¬ £¬£¬£¬£¬£¬£¬²»°²È«µÄµã»÷´ÎÊýÔö³¤ÁË3±¶¡£¡£¡£ ¡£¡£¡£¡£´Ë±í£¬£¬ £¬£¬£¬£¬£¬£¬ÃÀ¹úÈË´ò¿ª¿ÉÒÉÓʼþµÄ¿ÉÄÜÐÔÊÇÓ¢¹úºÍµÂ¹úÈ˵ÄÁ½±¶£» £»£»£»£»£»£»£»¹«Ë¾µÄÍÆËã»úÓÃÓÚÓ×ÎÒÒµÎñµÄʹÓÃÂÊÔö³¤ÁË60£¥¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.mimecast.com/resources/press-releases/dates/2021/3/the-year-of-social-distancing/