жñÒâÈí¼þαװ³ÉBrowserify NPM £¬ÒÑÏÂÔØ³¬1.6ÒÚ´Î £»Ñо¿ÈËÔ±Åû¶±¾Öܵĵڶþ¸öChromiumÖÐRCE 0day

Ðû²¼Ê±¼ä 2021-04-15

1.жñÒâÈí¼þαװ³ÉBrowserify NPM £¬ÒÑÏÂÔØ³¬1.6ÒÚ´Î


1.jpg


SonatypeÑо¿ÍŶӷ¢ÏÖ £¬ÃûΪweb-browserifyµÄ¶ñÒâÈí¼þ°üαװ³ÉºÏ·¨µÄBrowserify npm×é¼þ¡£¸Ã¶ñÒâÈí¼þÓÉ×Ô³ÆÎªSteve JobsµÄÄäÃûÕß¿ª·¢ £¬Ö÷ÒªÕë¶ÔʹÓÃLinuxºÍApplemacOSµÄNodeJS¿ª·¢ÈËÔ± £¬ÆäÿÖܵÄÏÂÔØÁè¼Ý130Íò´Î £¬½ØÖÁĿǰ×ܼÆÏÂÔØÁ¿Áè¼Ý1.6ÒÚ¶à´Î¡£´Ë¶ñÒâÈí¼þ°ü°üÂÞÇåµ¥Îļþ¡¢package.json¡¢postinstall.js ½Å±¾ºÍÃûΪrunµÄELF¿ÉÖ´ÐÐÎļþ¡£Êܺ¦Õß°²×°web-browserifyºó £¬¸Ã½Å±¾¾Í»áÌáÈ¡²¢Ö´ÐÐrun Linux¶þ½øÖÆÎļþ £¬²¢ÇëÇórootȨÏÞ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-linux-macos-malware-hidden-in-fake-browserify-npm-package/


2.eSentireÔÚGoogleÔÚÏß±í¸ñÉÏ·¢ÏÖ10Íò¶à¸ö¶ñÒâÒ³Ãæ


2.jpg


Äþ¾²¹«Ë¾eSentireÔÚGoogleÔÚÏß±í¸ñÉÏ·¢ÏÖÁËÁè¼Ý10Íò¸ö¶ñÒâÒ³Ãæ¡£eSentire·¢ÏÖÁ˶àÆð´ËÀà¶ñÒâ»î¶¯ £¬¹¥»÷ÕßʹÓÃÁËËÑË÷ÖØ¶¨ÏòºÍÇý¶¯ÏÂÔØµÄÒªÁì¡£µ±Êܺ¦ÕßËÑË÷ÖîÈçÄ£°å¡¢·¢Æ±¡¢Êվݡ¢ÎʾíºÍ¼òÀúÖ®ÀàµÄÌØ¶¨Òªº¦×Öʱ £¬²¢ÊµÑéÏÂÔØËùνµÄÎĵµÄ£°åºó £¬»áÔÚ²»Öª²»¾õÖб»Öض¨Ïòµ½ÍйÜÓÐRATµÄ¶ñÒâÍøÕ¾¡£´ËÀà»î¶¯Ê¹ÓÃÁËSolarMarker¡¢Jupyter¡¢Yellow CockatooºÍPolazertµÈRAT £¬²¢½«Slim PDF×÷ΪÓÕ¶ü¡£


Ô­ÎÄÁ´½Ó£º

https://www.esentire.com/security-advisories/hackers-flood-the-web-with-100-000-malicious-pages-promising-professionals-free-business-forms-but-are-delivering-malware-reports-esentire


3.AdobeÐû²¼Äþ¾²¸üР£¬ÐÞ¸´4¿î²úÎïÖеĶà¸ö©¶´


3.jpg


AdobeÐû²¼Äþ¾²¸üР£¬ÐÞ¸´ÁËPhotoshop¡¢Digital Editions¡¢BridgeºÍRoboHelpÖеĶà¸ö©¶´¡£´Ë´ÎÐÞ¸´µÄ½ÏΪÑÏÖØµÄ©¶´ÎªPhotoshopÖеĻº³åÇøÒç³öµ¼ÖµÄÈÎÒâ´úÂëÖ´ÐЩ¶´£¨CVE-2021-28548ºÍCVE-2021-28549£©¡£´Ë´Î»¹ÐÞ¸´ÁËBridgeÖеÄÔ½½çдµ¼ÖµĴúÂëÖ´ÐЩ¶´£¨CVE-2021-21094ºÍCVE-2021-21095£©ºÍÄÚ´æË𻵵¼ÖµĴúÂëÖ´ÐЩ¶´£¨CVE-2021-21093ºÍCVE-2021-21092£©µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/adobe-patches-critical-code-execution-vulnerabilities-photoshop-bridge


4.Ñо¿ÍŶÓÅû¶QNAP NASÉ豸ÖеÄÔ¶³ÌÖ´ÐдúÂë©¶´


4.jpg


Äþ¾²¹«Ë¾SSD Secure DisclosureÅû¶ÁËQNAP NASÉ豸ÖеÄÔ¶³ÌÖ´ÐдúÂë©¶´ £¬²¢Ðû²¼ÁËÕë¶Ô¸Ã©¶´µÄPoC´úÂë¡£¸Ã©¶´±»×·×ÙΪCVE-2020-2501 £¬ÊÇÒ»¸ö»ùÓÚ¶ÑÕ»µÄ»º³åÇøÒç³ö©¶´ £¬Ó°ÏìÁËÔËÐÐSurveillance StationµÄQNAP NASÉ豸¡£ÓÉÓÚȱ·¦Êʵ±µÄ½çÏÞ¼ì²é £¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓÃÌØÖÆµÄHTTPÇëÇóʹ¶ÑÕ»»º³åÇøÒç³ö £¬²¢Ö´ÐÐÈÎÒâ´úÂë¡£QNAP»ØÓ¦µÀ £¬ÏÖÒÑÐÞ¸´¸Ã©¶´¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116750/hacking/qnap-rce-exploit.html


5.Ñо¿ÈËÔ±Åû¶±¾Öܵĵڶþ¸öChromiumÖÐRCE 0day


5.jpg


Ñо¿ÈËÔ±FrustÅû¶Á˱¾Öܵĵڶþ¸öChromiumÖÐRCE 0day £¬¸Ã©¶´Ó°ÏìÁËChromeºÍEdgeµÈ»ùÓÚChromiumµÄä¯ÀÀÆ÷¡£¹È¸è×îÐÂÐû²¼ÁËChrome 89.0.4389.128ÒÔÐÞ¸´±¾ÖÜÒ»¹ûÈ»µÄChromium 0day £¬Ê±¸ôÒ»ÌìºóFrustÐû²¼Á˸ÃÐÂ0day¡£¸Ã©¶´ÐèÒªÓëɳÏäÌÓÒÝ©¶´½áºÏʹÓà £¬»òÕßÐèÒªÓû§½ûÓÃɳÏ书Ч¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/second-google-chrome-zero-day-exploit-dropped-on-twitter-this-week/


6.NetscoutÐû²¼2020ϰëÄêÍþвÇ鱨µÄ·ÖÎö³ÂËß


6.jpg


NetscoutÐû²¼ÁË2020ϰëÄêÍþвÇ鱨µÄ·ÖÎö³ÂËß¡£NetscoutÔÚ2020Äê¹²·¢ÏÖÁË10089687´ÎÂþÑÜʽ¾Ü¾ø·þÎñ£¨DDoS£©¹¥»÷ £¬Ã¿ÔµÄDDoS¹¥»÷´ÎÊýÒÑÁè¼Ý80Íò¡£Óë2019ÄêÏà±È £¬¹¥»÷ƵÂÊͬ±ÈÔö³¤ÁË20£¥ £¬ÔÚ2020ÄêµÄϰëÄêÔö³¤ÁË22£¥¡£DDoSÀÕË÷¹¥»÷µÄÊܺ¦ÕßÊýÁ¿Ôö¼ÓÁË125£¥ £¬ÆäÖÐ83£¥µÄÆóÒµÒòDDoS¹¥»÷µ¼ÖÂÁË·þÎñÖжÏ £¬±È2019ÄêÔö¼ÓÁË21£¥¡£´ËÍâ £¬ÖîÈçµç×ÓÉÌÎñ¡¢Á÷ýÌå·þÎñ¡¢ÔÚÏßѧϰºÍÒ½ÁƱ£½¡µÈÖØÒªµÄÐÐÒµ £¬Êܵ½Á˹¥»÷ÕßÔ½À´Ô½¶àµÄ¹Ø×¢¡£


Ô­ÎÄÁ´½Ó£º

https://www.netscout.com/blog/latest-netscout-threat-intelligence-report-highlights