NPM¿âNetmask×é¼þ´æÔÚ©¶´£¬¿ÉÓ°ÏìÊýÍò¸öÓ¦Ó÷¨Ê½ £»Ñо¿ÈËÔ±·¢ÏÖÒÑÒþ²Ø25ÄêµÄWindows 95¸´Éú½Ú²Êµ°

Ðû²¼Ê±¼ä 2021-03-29

1.NPM¿âNetmask×é¼þ´æÔÚ©¶´£¬¿ÉÓ°ÏìÊýÍò¸öÓ¦Ó÷¨Ê½


1.jpg


¸Ã×é¼þÿÖÜÏÂÔØÁ¿Áè¼Ý300Íò´Î£¬½ØÖÁÏÖÔÚÀÛ¼ÆÏÂÔØÁ¿ÒÑÁè¼Ý2.38ÒڴΣ¬Ô¼ÓÐ27.8Íò¸öGitHub´æ´¢¿âÒÀÀµÓÚnetmask¡£¸Ã©¶´±»×·×ÙΪCVE-2021-28918£¬Ê®½øÖÆIPv4µØÖ·°üÂÞǰµ¼Áãʱ£¬ÍøÂçÑÚÂë´¦ÖûìºÏ¸ñʽIPµØÖ·µÄ·½Ê½¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÓ°ÏìÓ¦Ó÷¨Ê½½âÎöµÄIPµØÖ·£¬Ôò¸Ã©¶´¿ÉÄÜ»áÒýÆðÖÖÖÖ©¶´£¬ÀýÈçµ¼Ö·þÎñÆ÷¶ËÇëÇóαÔ죨SSRF£©ºÍµ½Ô¶³ÌÎļþ°üÂÞ£¨RFI£©¡£Ä¿Ç°£¬¸Ã©¶´Òѱ»ÐÞ¸´¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/critical-netmask-networking-bug-impacts-thousands-of-applications/


2.ClopÁªÏµÊܺ¦ÕߵĿͻ§µÄмÆÄ±¶ÔÄ¿±êʩѹ


2.jpg


ÀÕË÷Èí¼þÍÅ»ïClopÖ±½ÓÏòÊܺ¦ÕߵĿͻ§·¢Ë͵ç×ÓÓʼþ£¬Í¨ÖªÆäÊý¾ÝÒѱ»Ð¹Â¶¡£ÕâÏîмÆÄ±Ö¼ÔÚÌá¸ßÀÕË÷µÄЧÂÊ£¬´Ó¶øÆÈʹĿ±ê¹«Ë¾Ö§¸¶Êê½ð¡£Æ¾¾ÝBleepingComputerµÄ˵·¨£¬Ð¼ÆÄ±µÄÊܺ¦Õß°üÂÞFlagstar BankºÍ¿ÆÂÞÀ­¶à´óѧ¡£´ËÍ⣬ÆäËûÍÅ»ïÒ²ÔÚÉú³¤ÐµļÆÄ±£¬REvil½üÆÚÐû²¼ËûÃÇÕýÔÚʹÓÃDDoS¹¥»÷£¬²¢ÏòÊܺ¦ÕߵĺÏ×÷¹«Ë¾¼°¼ÇÕß·¢ËÍÓïÒôºô½Ð£¬ÒÔÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116029/cyber-crime/clop-ransomware-extortion.html


3.Ó¢¹ú¹«Ë¾FatFaceѬȾConti£¬Áè¼Ý200GBÊý¾Ýй¶


3.jpg


Ó¢¹ú·þ×°¹«Ë¾FatFaceÔâµ½ContiÀÕË÷Èí¼þ¹¥»÷£¬Áè¼Ý200GBÊý¾Ýй¶¡£¹¥»÷·¢ÉúÔÚ2021Äê1ÔÂ17ÈÕ£¬¹¥»÷Õß·ÃÎÊÁËFatFaceµÄÍøÂçºÍϵͳ£¬²¢ÀÕË÷850ÍòÃÀÔª£¬×îÖÕ¾­Ì¸ÅÐÊê½ðÈ·¶¨Îª200ÍòÃÀÔª¡£´Ë´Îй¶µÄ¿Í»§ÐÅÏ¢°üÂÞÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢ÓʼĵØÖ·ºÍ²¿ÃÅÐÅÓÿ¨ÐÅÏ¢£¨×îºóËÄλÊý×ÖºÍÓÐЧÆÚ£©¡£´ËÍ⣬¸Ã¹«Ë¾ÔÚÊý¾Ýй¶֪ͨÓʼþÖÐÒªÇóÆäÊÕ¼þÈËÎñ±Ø¶Ô´ËÓʼþ¼°ÆäÖаüÂÞµÄÐÅÏ¢Ñϸñ±£ÃÜ£¬ÒÔ´ËÊÔͼÑÚ¸ÇÊý¾Ýй¶µÄÊÂʵ£¬´ËʼþÔÚÍøÉÏÒýÆðÐùÈ»´ó²¨¡£    


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fatface-sends-controversial-data-breach-email-after-ransomware-attack/


4.Ñо¿ÈËÔ±·¢ÏÖÒÑÒþ²Ø25ÄêµÄWindows 95¸´Éú½Ú²Êµ°


4.jpg


ijWindowsÑо¿ÈËÔ±AlbacoreÔÚInternet MailÓ¦Ó÷¨Ê½Öз¢ÏÖÁËÒÑÒþ²Ø25ÄêµÄWindows 95¸´Éú½Ú²Êµ°¡£¿ª·¢ÈËÔ±ÔÚ¿ª·¢Èí¼þʱ»áÉèÖòʵ°£¬Óû§Í¨¹ýÔÚ·¨Ê½ÖÐÖ´ÐÐÌØ¶¨²Ù×÷À´·¢ÏÖÒþ²Ø¹¦Ð§¡¢ÏûÏ¢ÉõÖÁÊÇÃÔÄãÓÎÏ·¡£AlbacoreÌåÏÖ£¬ÒªÏë·ÃÎʸ´Éú½Ú²Êµ°£¬Ö»ÐèÒªÆô¶¯Internet Mail£¬µ¥»÷×ÊÖúºÍ¹ØÓÚ£¬ÔÚ¹ØÓڲ˵¥Öе¥»÷comctl32.dll£¬È»ºóÔÚ¼üÅÌÉϼüÈëMORTIMER£¬¾Í¿ÉÒÔ·¢ÏÖ¿ª·¢ÈËÔ±Ãû³ÆµÄ¹ö¶¯Áбí¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/windows-95-easter-egg-discovered-after-being-hidden-for-25-years/


5.WhiteHatÐû²¼Ó¦ÓÃÄþ¾²µÄÌ¬ÊÆ·ÖÎö³ÂËß


5.jpg


WhiteHat SecurityÐû²¼ÁËÓйØÓ¦ÓÃÄþ¾²µÄÌ¬ÊÆ·ÖÎö³ÂËß¡£Ñо¿·¢ÏÖ£¬ÃæÏòWebµÄÓ¦Ó÷¨Ê½ÈÔÈ»ÊÇ×éÖ¯ÃæÁÙµÄ×î¸ßÄþ¾²·çÏÕÖ®Ò»£¬Áè¼Ý40£¥µÄÓ¦ÓÃй¶Êý¾Ý¿ÉÄÜ»á¶ÔÆóÒµ¼°ÆäºÏ×÷»ï°éÔì³ÉÁ¬Ëø·´Ó³¡£´ËÍâ£¬ÖÆÔìÒµÌØ±ðÈÝÒ×Êܵ½Õë¶ÔÓ¦Ó÷¨Ê½µÄ¹¥»÷£¬È¥ÄêÓÐ70£¥µÄÓ¦ÓôæÔÚÖÁÉÙÒ»¸öÑÏÖØÂ©¶´¡£ÆäÖУ¬ÔÚÓ¦Ó÷¨Ê½Öз¢ÏÖµÄǰÎå¸ö©¶´°üÂÞÐÅϢй¶©²»³äʵµÄ»á»°¹ýÆÚ»úÖÆ¡¢XSS©¶´¡¢´«Êä²ã± £»¤²»×ãºÍÄÚÈÝÆÛÆ­Â©¶´¡£


Ô­ÎÄÁ´½Ó£º

https://www.whitehatsec.com/appsec-stats-flash/


6.MimecastÐû²¼ÒßÇéÆÚ¼ä¹¥»÷»î¶¯µÄÌ¬ÊÆ·ÖÎö³ÂËß


6.jpg


MimecastÐû²¼ÁËÒßÇéÆÚ¼ä¹¥»÷»î¶¯µÄÌ¬ÊÆ·ÖÎö³ÂËß¡£¸Ã³ÂËßÏêϸ½éÉÜÁËÔÚCOVIDÁ÷ÐеĵÚÒ»Ä꣨2020Äê3ÔÂÖÁ2021Äê2Ô£©ÖÐÕë¶ÔÔ¶³ÌÊÂÇéÕߵĹ¥»÷»î¶¯¡£³ÂËßÖ¸³ö£¬ÔÚÕâÒ»Äê¹¥»÷Á¿¼¤ÔöÁË48£¥£¬ÆäÖй¥»÷µÄ·åÖµ·ºÆðÔÚ2020Äê10Ô¡£ÔÚ2020Äê3Ô£¬¾Ó¼Ò°ì¹«Ç÷ÊÆµÄ·ºÆðµÄʱºò£¬²»Äþ¾²µÄµã»÷´ÎÊýÔö³¤ÁË3±¶¡£´ËÍ⣬ÃÀ¹úÈË´ò¿ª¿ÉÒÉÓʼþµÄ¿ÉÄÜÐÔÊÇÓ¢¹úºÍµÂ¹úÈ˵ÄÁ½±¶ £»¹«Ë¾µÄ¼ÆËã»úÓÃÓÚ¸öÈËÒµÎñµÄʹÓÃÂÊÔö¼ÓÁË60£¥¡£


Ô­ÎÄÁ´½Ó£º

https://www.mimecast.com/resources/press-releases/dates/2021/3/the-year-of-social-distancing/