NPM¿âNetmask×é¼þ±£´æÎó²î£¬¿ÉÓ°ÏìÊýÍò¸öÓ¦ÓóÌÐò£»Ñо¿Ö°Ô±·¢Ã÷ÒÑÒþ²Ø25ÄêµÄWindows 95¸´Éú½Ú²Êµ°
Ðû²¼Ê±¼ä 2021-03-291.NPM¿âNetmask×é¼þ±£´æÎó²î£¬¿ÉÓ°ÏìÊýÍò¸öÓ¦ÓóÌÐò

¸Ã×é¼þÿÖÜÏÂÔØÁ¿Áè¼Ý300Íò´Î£¬×èÖ¹ÏÖÔÚÀÛ¼ÆÏÂÔØÁ¿ÒÑÁè¼Ý2.38ÒڴΣ¬Ô¼ÓÐ27.8Íò¸öGitHub´æ´¢¿âÒÀÀµÓÚnetmask¡£¸ÃÎó²î±»×·×ÙΪCVE-2021-28918£¬Ê®½øÖÆIPv4µØµã°üÀ¨Ç°µ¼Áãʱ£¬ÍøÂçÑÚÂë´¦Öóͷ£»ì¼°ÃûÌÃIPµØµãµÄ·½·¨¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÓ°ÏìÓ¦ÓóÌÐòÆÊÎöµÄIPµØµã£¬Ôò¸ÃÎó²î¿ÉÄÜ»áÒýÆðÖÖÖÖÎó²î£¬ÀýÈçµ¼Ö·þÎñÆ÷¶ËÇëÇóαÔ죨SSRF£©ºÍµ½Ô¶³ÌÎļþ°üÀ¨£¨RFI£©¡£ÏÖÔÚ£¬¸ÃÎó²îÒѱ»ÐÞ¸´¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/critical-netmask-networking-bug-impacts-thousands-of-applications/
2.ClopÁªÏµÊܺ¦ÕߵĿͻ§µÄÐÂÕ½ÂÔ¶ÔÄ¿µÄʩѹ

ÀÕË÷Èí¼þÍÅ»ïClopÖ±½ÓÏòÊܺ¦ÕߵĿͻ§·¢Ë͵ç×ÓÓʼþ£¬Í¨ÖªÆäÊý¾ÝÒѱ»Ð¹Â¶¡£ÕâÏîÐÂÕ½ÂÔÖ¼ÔÚÌá¸ßÀÕË÷µÄЧÂÊ£¬´Ó¶øÆÈʹĿµÄ¹«Ë¾Ö§¸¶Êê½ð¡£Æ¾Ö¤BleepingComputerµÄ˵·¨£¬ÐÂÕ½ÂÔµÄÊܺ¦Õß°üÀ¨Flagstar BankºÍ¿ÆÂÞÀ¶à´óѧ¡£±ðµÄ£¬ÆäËûÍÅ»ïÒ²ÔÚÉú³¤ÐµÄÕ½ÂÔ£¬REvil½üÆÚÐû²¼ËûÃÇÕýÔÚʹÓÃDDoS¹¥»÷£¬²¢ÏòÊܺ¦ÕßµÄÏàÖú¹«Ë¾¼°¼ÇÕß·¢ËÍÓïÒôºô½Ð£¬ÒÔÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/116029/cyber-crime/clop-ransomware-extortion.html
3.Ó¢¹ú¹«Ë¾FatFaceѬȾConti£¬Áè¼Ý200GBÊý¾Ýй¶

Ó¢¹ú´ò°ç¹«Ë¾FatFaceÔâµ½ContiÀÕË÷Èí¼þ¹¥»÷£¬Áè¼Ý200GBÊý¾Ýй¶¡£¹¥»÷±¬·¢ÔÚ2021Äê1ÔÂ17ÈÕ£¬¹¥»÷Õß»á¼ûÁËFatFaceµÄÍøÂçºÍϵͳ£¬²¢ÀÕË÷850ÍòÃÀÔª£¬×îÖվ̸ÅÐÊê½ðÈ·¶¨Îª200ÍòÃÀÔª¡£´Ë´Îй¶µÄ¿Í»§ÐÅÏ¢°üÀ¨ÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢ÓʼĵصãºÍ²¿·ÖÐÅÓÿ¨ÐÅÏ¢£¨×îºóËÄλÊý×ÖºÍÓÐÓÃÆÚ£©¡£±ðµÄ£¬¸Ã¹«Ë¾ÔÚÊý¾Ýй¶֪ͨÓʼþÖÐÒªÇóÆäÊÕ¼þÈËÎñ±Ø¶Ô´ËÓʼþ¼°ÆäÖаüÀ¨µÄÐÅÏ¢ÑϿᱣÃÜ£¬ÒÔ´ËÊÔͼÑÚÊÎÊý¾Ýй¶µÄÊÂʵ£¬´ËÊÂÎñÔÚÍøÉÏÒýÆðÐùÈ»´ó²¨¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/fatface-sends-controversial-data-breach-email-after-ransomware-attack/
4.Ñо¿Ö°Ô±·¢Ã÷ÒÑÒþ²Ø25ÄêµÄWindows 95¸´Éú½Ú²Êµ°

ijWindowsÑо¿Ö°Ô±AlbacoreÔÚInternet MailÓ¦ÓóÌÐòÖз¢Ã÷ÁËÒÑÒþ²Ø25ÄêµÄWindows 95¸´Éú½Ú²Êµ°¡£¿ª·¢Ö°Ô±ÔÚ¿ª·¢Èí¼þʱ»áÉèÖòʵ°£¬Óû§Í¨¹ýÔÚ³ÌÐòÖÐÖ´ÐÐÌØ¶¨²Ù×÷À´·¢Ã÷Òþ²Ø¹¦Ð§¡¢ÐÂÎÅÉõÖÁÊÇÃÔÄãÓÎÏ·¡£AlbacoreÌåÏÖ£¬ÒªÏë»á¼û¸´Éú½Ú²Êµ°£¬Ö»ÐèÒªÆô¶¯Internet Mail£¬µ¥»÷×ÊÖúºÍ¹ØÓÚ£¬ÔÚ¹ØÓڲ˵¥Öе¥»÷comctl32.dll£¬È»ºóÔÚ¼üÅÌÉϼüÈëMORTIMER£¬¾Í¿ÉÒÔ·¢Ã÷¿ª·¢Ö°Ô±Ãû³ÆµÄת¶¯ÁÐ±í¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/windows-95-easter-egg-discovered-after-being-hidden-for-25-years/
5.WhiteHatÐû²¼Ó¦ÓÃÇå¾²µÄÌ¬ÊÆÆÊÎö±¨¸æ

WhiteHat SecurityÐû²¼ÁËÓйØÓ¦ÓÃÇå¾²µÄÌ¬ÊÆÆÊÎö±¨¸æ¡£Ñо¿·¢Ã÷£¬ÃæÏòWebµÄÓ¦ÓóÌÐòÈÔÈ»ÊÇ×éÖ¯ÃæÁÙµÄ×î¸ßÇ徲Σº¦Ö®Ò»£¬Áè¼Ý40£¥µÄÓ¦ÓÃй¶Êý¾Ý¿ÉÄÜ»á¶ÔÆóÒµ¼°ÆäÏàÖúͬ°éÔì³ÉÁ¬Ëø·´Ó¦¡£±ðµÄ£¬ÖÆÔìÒµÌØÊâÈÝÒ×Êܵ½Õë¶ÔÓ¦ÓóÌÐòµÄ¹¥»÷£¬È¥ÄêÓÐ70£¥µÄÓ¦Óñ£´æÖÁÉÙÒ»¸öÑÏÖØÎó²î¡£ÆäÖУ¬ÔÚÓ¦ÓóÌÐòÖз¢Ã÷µÄǰÎå¸öÎó²î°üÀ¨ÐÅϢй¶©²»³ä·ÖµÄ»á»°ÓâÆÚ»úÖÆ¡¢XSSÎó²î¡¢´«Êä²ã±£»¤È±·¦ºÍÄÚÈÝÓÕÆÎó²î¡£
ÔÎÄÁ´½Ó£º
https://www.whitehatsec.com/appsec-stats-flash/
6.MimecastÐû²¼ÒßÇéʱ´ú¹¥»÷Ô˶¯µÄÌ¬ÊÆÆÊÎö±¨¸æ

MimecastÐû²¼ÁËÒßÇéʱ´ú¹¥»÷Ô˶¯µÄÌ¬ÊÆÆÊÎö±¨¸æ¡£¸Ã±¨¸æÏêϸÏÈÈÝÁËÔÚCOVIDÊ¢ÐеĵÚÒ»Ä꣨2020Äê3ÔÂÖÁ2021Äê2Ô£©ÖÐÕë¶ÔÔ¶³ÌÊÂÇéÕߵĹ¥»÷Ô˶¯¡£±¨¸æÖ¸³ö£¬ÔÚÕâÒ»Äê¹¥»÷Á¿¼¤ÔöÁË48£¥£¬ÆäÖй¥»÷µÄ·åÖµ·ºÆðÔÚ2020Äê10Ô¡£ÔÚ2020Äê3Ô£¬¾Ó¼Ò°ì¹«Ç÷ÊÆµÄ·ºÆðµÄʱ¼ä£¬²»Çå¾²µÄµã»÷´ÎÊýÔöÌíÁË3±¶¡£±ðµÄ£¬ÃÀ¹úÈË·¿ª¿ÉÒÉÓʼþµÄ¿ÉÄÜÐÔÊÇÓ¢¹úºÍµÂ¹úÈ˵ÄÁ½±¶£»¹«Ë¾µÄÅÌËã»úÓÃÓÚСÎÒ˽¼ÒÓªÒµµÄʹÓÃÂÊÔöÌíÁË60£¥¡£
ÔÎÄÁ´½Ó£º
https://www.mimecast.com/resources/press-releases/dates/2021/3/the-year-of-social-distancing/


¾©¹«Íø°²±¸11010802024551ºÅ