жñÒâÈí¼þ¼Ù×°³ÉBrowserify NPM£¬£¬£¬£¬£¬ £¬£¬ÒÑÏÂÔØ³¬1.6ÒڴΣ»£»£»£»£»×êÑÐÈËÔ±Åû¶±¾Öܵĵڶþ¸öChromiumÖÐRCE 0day

°ä²¼¹¦·ò 2021-04-15

1.жñÒâÈí¼þ¼Ù×°³ÉBrowserify NPM£¬£¬£¬£¬£¬ £¬£¬ÒÑÏÂÔØ³¬1.6ÒÚ´Î


1.jpg


Sonatype×êÑÐÍŶӷ¢ÏÖ£¬£¬£¬£¬£¬ £¬£¬ÃûΪweb-browserifyµÄ¶ñÒâÈí¼þ°ü¼Ù×°³ÉºÏ·¨µÄBrowserify npm×é¼þ¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÓÉ×Ô³ÆÎªSteve JobsµÄÄäÃûÕß¿ª·¢£¬£¬£¬£¬£¬ £¬£¬ÖØÒªÕë¶ÔʹÓÃLinuxºÍApplemacOSµÄNodeJS¿ª·¢ÈËÔ±£¬£¬£¬£¬£¬ £¬£¬ÆäÿÖܵÄÏÂÔØ³¬¹ý130Íò´Î£¬£¬£¬£¬£¬ £¬£¬½ØÖÁĿǰ×ܼÆÏÂÔØÁ¿³¬¹ý1.6ÒÚÂŴΡ£¡£¡£¡£¡£´Ë¶ñÒâÈí¼þ°üÔ̺¬Çåµ¥Îļþ¡¢package.json¡¢postinstall.js ¾ç±¾ºÍÃûΪrunµÄELF¿ÉÖ´ÐÐÎļþ¡£¡£¡£¡£¡£Êܺ¦Õß×°ÖÃweb-browserifyºó£¬£¬£¬£¬£¬ £¬£¬¸Ã¾ç±¾¾Í»áÌáÈ¡²¢Ö´ÐÐrun Linux¶þ½øÔìÎļþ£¬£¬£¬£¬£¬ £¬£¬²¢ÒªÇórootȨÏÞ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-linux-macos-malware-hidden-in-fake-browserify-npm-package/


2.eSentireÔÚGoogleÔÚÏß±í¸ñÉÏ·¢ÏÖ10Íò¶à¸ö¶ñÒâÒ³Ãæ


2.jpg


°²È«¹«Ë¾eSentireÔÚGoogleÔÚÏß±í¸ñÉÏ·¢ÏÖÁ˳¬¹ý10Íò¸ö¶ñÒâÒ³Ãæ¡£¡£¡£¡£¡£eSentire·¢ÏÖÁ˶àÆð´ËÀà¶ñÒâ»î¶¯£¬£¬£¬£¬£¬ £¬£¬¹¥»÷ÕßʹÓÃÁËËÑË÷³Á¶¨ÏòºÍÇý¶¯ÏÂÔØµÄ²½Öè¡£¡£¡£¡£¡£µ±Êܺ¦ÕßËÑË÷ÖîÈçÄ£°å¡¢·¢Æ±¡¢ÊÕÌõ¡¢ÎʾíºÍ¼òÀúÖ®ÀàµÄÌØ¶¨¹Ø¼ü×Öʱ£¬£¬£¬£¬£¬ £¬£¬²¢³¢ÊÔÏÂÔØËùνµÄÎĵµÄ£°åºó£¬£¬£¬£¬£¬ £¬£¬»áÔÚ²»Öª²»¾õÖб»³Á¶¨Ïòµ½ÍйÜÓÐRATµÄ¶ñÒâÍøÕ¾¡£¡£¡£¡£¡£´ËÀà»î¶¯Ê¹ÓÃÁËSolarMarker¡¢Jupyter¡¢Yellow CockatooºÍPolazertµÈRAT£¬£¬£¬£¬£¬ £¬£¬²¢½«Slim PDF×÷Ϊµö¶ü¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.esentire.com/security-advisories/hackers-flood-the-web-with-100-000-malicious-pages-promising-professionals-free-business-forms-but-are-delivering-malware-reports-esentire


3.Adobe°ä²¼°²È«¸üУ¬£¬£¬£¬£¬ £¬£¬½¨¸´4¿î²úÆ·ÖеĶà¸ö·ì϶


3.jpg


Adobe°ä²¼°²È«¸üУ¬£¬£¬£¬£¬ £¬£¬½¨¸´ÁËPhotoshop¡¢Digital Editions¡¢BridgeºÍRoboHelpÖеĶà¸ö·ì϶¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ½ÏΪÑϳÁµÄ·ì϶ΪPhotoshopÖеĻº³åÇøÒç³öµ¼ÖµÄËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-28548ºÍCVE-2021-28549£©¡£¡£¡£¡£¡£Õâ´Î»¹½¨¸´ÁËBridgeÖеÄÔ½½çдµ¼ÖµĴúÂëÖ´Ðзì϶£¨CVE-2021-21094ºÍCVE-2021-21095£©ºÍÄÚ´æ°Ü»µµ¼ÖµĴúÂëÖ´Ðзì϶£¨CVE-2021-21093ºÍCVE-2021-21092£©µÈ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/adobe-patches-critical-code-execution-vulnerabilities-photoshop-bridge


4.×êÑÐÍŶÓÅû¶QNAP NASÉ豸ÖеÄÔ¶³ÌÖ´ÐдúÂë·ì϶


4.jpg


°²È«¹«Ë¾SSD Secure DisclosureÅû¶ÁËQNAP NASÉ豸ÖеÄÔ¶³ÌÖ´ÐдúÂë·ì϶£¬£¬£¬£¬£¬ £¬£¬²¢°ä²¼ÁËÕë¶Ô¸Ã·ì϶µÄPoC´úÂë¡£¡£¡£¡£¡£¸Ã·ì϶±»×·×ÙΪCVE-2020-2501£¬£¬£¬£¬£¬ £¬£¬ÊÇÒ»¸ö»ùÓÚ²Ö¿âµÄ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬ £¬£¬Ó°ÏìÁËÔËÐÐSurveillance StationµÄQNAP NASÉ豸¡£¡£¡£¡£¡£ÓÉÓÚ²»×ãÊʵ±µÄÌìǵ²é³­£¬£¬£¬£¬£¬ £¬£¬Ô¶³Ì¹¥»÷ÕßÄܹ»ÀûÓÃÌØÔìµÄHTTPÒªÇóʹ²Ö¿â»º³åÇøÒç³ö£¬£¬£¬£¬£¬ £¬£¬²¢Ö´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£QNAP»ØÓ¦Â·£¬£¬£¬£¬£¬ £¬£¬ÏÖÒѽ¨¸´¸Ã·ì϶¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116750/hacking/qnap-rce-exploit.html


5.×êÑÐÈËÔ±Åû¶±¾Öܵĵڶþ¸öChromiumÖÐRCE 0day


5.jpg


×êÑÐÈËÔ±FrustÅû¶Á˱¾Öܵĵڶþ¸öChromiumÖÐRCE 0day£¬£¬£¬£¬£¬ £¬£¬¸Ã·ì϶ӰÏìÁËChromeºÍEdgeµÈ»ùÓÚChromiumµÄä¯ÀÀÆ÷¡£¡£¡£¡£¡£¹È¸è×îа䲼ÁËChrome 89.0.4389.128ÒÔ½¨¸´±¾ÖÜÒ»¹«¿ªµÄChromium 0day£¬£¬£¬£¬£¬ £¬£¬Ê±¸ôÒ»ÌìºóFrust°ä²¼Á˸ÃÐÂ0day¡£¡£¡£¡£¡£¸Ã·ì϶±ØÒªÓëɳÏäÌÓÒÝ·ì϶½áºÏʹÓ㬣¬£¬£¬£¬ £¬£¬»òÕß±ØÒªÓû§½ûÓÃɳÏäÖ°ÄÜ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/second-google-chrome-zero-day-exploit-dropped-on-twitter-this-week/


6.Netscout°ä²¼2020ϰëÄêÍþвµý±¨µÄ·ÖÎö»ã±¨


6.jpg


Netscout°ä²¼ÁË2020ϰëÄêÍþвµý±¨µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£NetscoutÔÚ2020Äê¹²·¢ÏÖÁË10089687´ÎÉ¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷£¬£¬£¬£¬£¬ £¬£¬Ã¿ÔµÄDDoS¹¥»÷´ÎÊýÒѳ¬¹ý80Íò¡£¡£¡£¡£¡£Óë2019ÄêÏà±È£¬£¬£¬£¬£¬ £¬£¬¹¥»÷ƵÂÊͬ±ÈÔö³¤ÁË20£¥£¬£¬£¬£¬£¬ £¬£¬ÔÚ2020ÄêµÄϰëÄêÔö³¤ÁË22£¥¡£¡£¡£¡£¡£DDoSÀÕË÷¹¥»÷µÄÊܺ¦ÕßÊýÁ¿Ôö³¤ÁË125£¥£¬£¬£¬£¬£¬ £¬£¬ÆäÖÐ83£¥µÄÆóÒµÒòDDoS¹¥»÷µ¼ÖÂÁË·þÎñÖжÏ£¬£¬£¬£¬£¬ £¬£¬±È2019ÄêÔö³¤ÁË21£¥¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ £¬£¬ÖîÈçµç×ÓÉÌÎñ¡¢Á÷ýÌå·þÎñ¡¢ÔÚÏß½ø½¨ºÍÒ½ÁƱ£½¡µÈ³ÁÒªµÄÐÐÒµ£¬£¬£¬£¬£¬ £¬£¬Êܵ½Á˹¥»÷ÕßÔ½À´Ô½¶àµÄ¹Ø×¢¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.netscout.com/blog/latest-netscout-threat-intelligence-report-highlights