жñÒâÈí¼þαװ³ÉBrowserify NPM£¬£¬£¬£¬£¬£¬ÒÑÏÂÔØ³¬1.6ÒڴΣ»£»£»£»£»Ñо¿Ö°Ô±Åû¶±¾Öܵĵڶþ¸öChromiumÖÐRCE 0day
Ðû²¼Ê±¼ä 2021-04-151.жñÒâÈí¼þαװ³ÉBrowserify NPM£¬£¬£¬£¬£¬£¬ÒÑÏÂÔØ³¬1.6ÒÚ´Î

SonatypeÑо¿ÍŶӷ¢Ã÷£¬£¬£¬£¬£¬£¬ÃûΪweb-browserifyµÄ¶ñÒâÈí¼þ°üαװ³ÉÕýµ±µÄBrowserify npm×é¼þ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÓÉ×Ô³ÆÎªSteve JobsµÄÄäÃûÕß¿ª·¢£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔʹÓÃLinuxºÍApplemacOSµÄNodeJS¿ª·¢Ö°Ô±£¬£¬£¬£¬£¬£¬ÆäÿÖܵÄÏÂÔØÁè¼Ý130Íò´Î£¬£¬£¬£¬£¬£¬×èÖ¹ÏÖÔÚ×ܼÆÏÂÔØÁ¿Áè¼Ý1.6ÒÚ¶à´Î¡£¡£¡£¡£¡£¡£¡£¡£´Ë¶ñÒâÈí¼þ°ü°üÀ¨Çåµ¥Îļþ¡¢package.json¡¢postinstall.js ¾ç±¾ºÍÃûΪrunµÄELF¿ÉÖ´ÐÐÎļþ¡£¡£¡£¡£¡£¡£¡£¡£Êܺ¦Õß×°ÖÃweb-browserifyºó£¬£¬£¬£¬£¬£¬¸Ã¾ç±¾¾Í»áÌáÈ¡²¢Ö´ÐÐrun Linux¶þ½øÖÆÎļþ£¬£¬£¬£¬£¬£¬²¢ÇëÇórootȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-linux-macos-malware-hidden-in-fake-browserify-npm-package/
2.eSentireÔÚGoogleÔÚÏß±í¸ñÉÏ·¢Ã÷10Íò¶à¸ö¶ñÒâÒ³Ãæ

Çå¾²¹«Ë¾eSentireÔÚGoogleÔÚÏß±í¸ñÉÏ·¢Ã÷ÁËÁè¼Ý10Íò¸ö¶ñÒâÒ³Ãæ¡£¡£¡£¡£¡£¡£¡£¡£eSentire·¢Ã÷Á˶àÆð´ËÀà¶ñÒâ»î¶¯£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁËËÑË÷ÖØ¶¨ÏòºÍÇý¶¯ÏÂÔØµÄÒªÁì¡£¡£¡£¡£¡£¡£¡£¡£µ±Êܺ¦ÕßËÑË÷ÖîÈçÄ£°å¡¢·¢Æ±¡¢ÊÕÌõ¡¢ÎʾíºÍ¼òÀúÖ®ÀàµÄÌØ¶¨Òªº¦×Öʱ£¬£¬£¬£¬£¬£¬²¢ÊµÑéÏÂÔØËùνµÄÎĵµÄ£°åºó£¬£¬£¬£¬£¬£¬»áÔÚ²»Öª²»¾õÖб»Öض¨Ïòµ½ÍйÜÓÐRATµÄ¶ñÒâÍøÕ¾¡£¡£¡£¡£¡£¡£¡£¡£´ËÀà»î¶¯Ê¹ÓÃÁËSolarMarker¡¢Jupyter¡¢Yellow CockatooºÍPolazertµÈRAT£¬£¬£¬£¬£¬£¬²¢½«Slim PDF×÷ΪÓÕ¶ü¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.esentire.com/security-advisories/hackers-flood-the-web-with-100-000-malicious-pages-promising-professionals-free-business-forms-but-are-delivering-malware-reports-esentire
3.AdobeÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´4¿î²úÆ·ÖеĶà¸öÎó²î

AdobeÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËPhotoshop¡¢Digital Editions¡¢BridgeºÍRoboHelpÖеĶà¸öÎó²î¡£¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄ½ÏΪÑÏÖØµÄÎó²îΪPhotoshopÖеĻº³åÇøÒç³öµ¼ÖµÄí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-28548ºÍCVE-2021-28549£©¡£¡£¡£¡£¡£¡£¡£¡£´Ë´Î»¹ÐÞ¸´ÁËBridgeÖеÄÔ½½çдµ¼ÖµĴúÂëÖ´ÐÐÎó²î£¨CVE-2021-21094ºÍCVE-2021-21095£©ºÍÄÚ´æË𻵵¼ÖµĴúÂëÖ´ÐÐÎó²î£¨CVE-2021-21093ºÍCVE-2021-21092£©µÈ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/adobe-patches-critical-code-execution-vulnerabilities-photoshop-bridge
4.Ñо¿ÍŶÓÅû¶QNAP NAS×°±¸ÖеÄÔ¶³ÌÖ´ÐдúÂëÎó²î

Çå¾²¹«Ë¾SSD Secure DisclosureÅû¶ÁËQNAP NAS×°±¸ÖеÄÔ¶³ÌÖ´ÐдúÂëÎó²î£¬£¬£¬£¬£¬£¬²¢Ðû²¼ÁËÕë¶Ô¸ÃÎó²îµÄPoC´úÂë¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î±»×·×ÙΪCVE-2020-2501£¬£¬£¬£¬£¬£¬ÊÇÒ»¸ö»ùÓÚ¿ÍÕ»µÄ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬Ó°ÏìÁËÔËÐÐSurveillance StationµÄQNAP NAS×°±¸¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚȱ·¦Êʵ±µÄ½çÏß¼ì²é£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÌØÖÆµÄHTTPÇëÇóʹ¿ÍÕ»»º³åÇøÒç³ö£¬£¬£¬£¬£¬£¬²¢Ö´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£QNAP»ØÓ¦µÀ£¬£¬£¬£¬£¬£¬ÏÖÒÑÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/116750/hacking/qnap-rce-exploit.html
5.Ñо¿Ö°Ô±Åû¶±¾Öܵĵڶþ¸öChromiumÖÐRCE 0day

Ñо¿Ö°Ô±FrustÅû¶Á˱¾Öܵĵڶþ¸öChromiumÖÐRCE 0day£¬£¬£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìÁËChromeºÍEdgeµÈ»ùÓÚChromiumµÄä¯ÀÀÆ÷¡£¡£¡£¡£¡£¡£¡£¡£¹È¸è×îÐÂÐû²¼ÁËChrome 89.0.4389.128ÒÔÐÞ¸´±¾ÖÜÒ»¹ûÕæµÄChromium 0day£¬£¬£¬£¬£¬£¬Ê±¸ôÒ»ÌìºóFrustÐû²¼Á˸ÃÐÂ0day¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÐèÒªÓëɳÏäÌÓÒÝÎó²îÁ¬ÏµÊ¹Ó㬣¬£¬£¬£¬£¬»òÕßÐèÒªÓû§½ûÓÃɳÏ书Ч¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/second-google-chrome-zero-day-exploit-dropped-on-twitter-this-week/
6.NetscoutÐû²¼2020ϰëÄêÍþвÇ鱨µÄÆÊÎö±¨¸æ

NetscoutÐû²¼ÁË2020ϰëÄêÍþвÇ鱨µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£¡£NetscoutÔÚ2020Äê¹²·¢Ã÷ÁË10089687´ÎÂþÑÜʽ¾Ü¾øÐ§ÀÍ£¨DDoS£©¹¥»÷£¬£¬£¬£¬£¬£¬Ã¿ÔµÄDDoS¹¥»÷´ÎÊýÒÑÁè¼Ý80Íò¡£¡£¡£¡£¡£¡£¡£¡£Óë2019ÄêÏà±È£¬£¬£¬£¬£¬£¬¹¥»÷ƵÂÊͬ±ÈÔöÌíÁË20£¥£¬£¬£¬£¬£¬£¬ÔÚ2020ÄêµÄϰëÄêÔöÌíÁË22£¥¡£¡£¡£¡£¡£¡£¡£¡£DDoSÀÕË÷¹¥»÷µÄÊܺ¦ÕßÊýÄ¿ÔöÌíÁË125£¥£¬£¬£¬£¬£¬£¬ÆäÖÐ83£¥µÄÆóÒµÒòDDoS¹¥»÷µ¼ÖÂÁËЧÀÍÖÐÖ¹£¬£¬£¬£¬£¬£¬±È2019ÄêÔöÌíÁË21£¥¡£¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬ÖîÈçµç×ÓÉÌÎñ¡¢Á÷ýÌåЧÀÍ¡¢ÔÚÏßѧϰºÍÒ½ÁƱ£½¡µÈÖ÷ÒªµÄÐÐÒµ£¬£¬£¬£¬£¬£¬Êܵ½Á˹¥»÷ÕßÔ½À´Ô½¶àµÄ¹Ø×¢¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.netscout.com/blog/latest-netscout-threat-intelligence-report-highlights


¾©¹«Íø°²±¸11010802024551ºÅ