Google TensorFlowΪ½¨¸´RCE·ì϶¶ø²»ÔÙÖ§³ÖYAML£ºNetgear°ä²¼°²È«¸üÐÂ

°ä²¼¹¦·ò 2021-09-08

Google TensorFlowΪ½¨¸´RCE·ì϶¶ø²»ÔÙÖ§³ÖYAML


Google TensorFlowΪ½¨¸´RCE·ì϶¶ø²»ÔÙÖ§³ÖYAML.jpg

 

Google¿ª·¢µÄ»ùÓÚPythonµÄ»úе½ø½¨ºÍÈËΪÖÇÄÜÏîÄ¿TensorFlowÒѾ­ÉÕ»ÙÁ˶ÔYAMLµÄÖ§³Ö¡£TensorFlow´úÂëÖеÄyaml.unsafe_load()º¯Êý´æÔÚÒ»¸ö·ì϶£¬×·×ÙΪCVE-2021-37678£¬ÆÀ·ÖΪ9.3¡£µ±ÀûÓ÷´ÐòÁл¯YAMLÌåʽµÄKerasÄ£ÐÍʱ£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐÐËÁÒâ´úÂ롣Ϊ½¨¸´´Ë·ì϶£¬TensorFlow¾ö¶¨ÆëÈ«ÉÕ»ÙYAMLµÄÖ§³Ö£¬×ª¶øÊ¹ÓÃJSON·´ÐòÁл¯¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/googles-tensorflow-drops-yaml-support-due-to-code-execution-flaw/


Netgear°ä²¼°²È«¸üУ¬½¨¸´Ó°ÏìÆä20¿î²úÆ·µÄ·ì϶


Netgear°ä²¼°²È«¸üУ¬½¨¸´Ó°ÏìÆä20¿î²úÆ·µÄ·ì϶.jpg


ÍøÂçÉ豸¹©¸øÉÌNetgearÓÚÉÏÖÜ9ÔÂ3ÈÕ°ä²¼Á˰²È«¸üУ¬½¨¸´Ó°ÏìÆä20¿î²úÆ·µÄ3¸ö·ì϶¡£ÕâЩ·ì϶µÄ´úºÅ±ðÀëΪDemon's Cries¡¢Draconian FearºÍSeventh Inferno£¬Ä¿Ç°Ç°Á½¸ö·ì϶µÄPoCÒѾ­¹«¿ª¡£ÆäÖУ¬×îÑϳÁµÄÊÇDemon's Cries£¬CVSSv3ÆÀ·ÖΪ9.8£¬¿ÉÓÃÓÚÈÆ¹ýÉí·ÝÑéÖ¤²¢ÊÕÊÜÉ豸¡£Draconian FearÒ²ÊÇÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¬µ«Ö»ÄÜÓÃÓڽٳֵǼµÄÖÎÀíÔ±»á»°¡£×êÑÐÈËÔ±Ô¤¼Æ±ÉÈËÖÜÒ»£¬¼´9ÔÂ13ÈÕ°ä²¼¹Ø·ì϶Seventh InfernoµÄ¼¼Êõϸ½Ú¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/demons-cries-authentication-bypass-patched-in-netgear-switches/


Node.js¿ª·¢ÍŶӽ¨¸´NPM°ünode-tarÖеĶà¸ö·ì϶


Node.js¿ª·¢ÍŶӽ¨¸´NPM°ünode-tarÖеĶà¸ö·ì϶.png


Node.js¿ª·¢ÍŶӽ¨¸´ÁËNPM°ü¡°tar¡±£¨±ðÃûnode-tar£©ÖеÄ5¸ö·ì϶¡£ÆäÖнÏΪÑϳÁµÄÊÇ·ì϶CVE-2021-37712ºÍCVE-2021-37701¡£Èç¹ú¶È·ì϶Êý¾Ý¿â(NVD)ÖÐËùÊö£¬ÕâÁ½¸ö·ì϶¿ÉÓÃÀ´´´½¨ºÍ¸²¸ÇËÁÒâÎļþ£¬»òÖ´ÐÐËÁÒâ´úÂ룬CVSSÆÀ·Ö¾ùΪ8.2¡£Õâ´Î½¨¸´µÄ·ì϶ӰÏìÁ˸ÃNPM°ü°æ±¾5.0.0֮ǰµÄ°æ±¾¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/09/critical-flaws-in-npm-package-patched.html


ÖйúÏã¸ÛBilaxyÔâµ½¹¥»÷£¬Ô¤¼ÆËðʧ³¬¹ý2100ÍòÃÀÔª


ÖйúÏã¸ÛBilaxyÔâµ½¹¥»÷£¬Ô¤¼ÆËðʧ³¬¹ý2100ÍòÃÀÔª.jpg


8ÔÂ29ÈÕ£¬ÖйúÏã¸ÛµÄ¼ÓÃÜÇ®±ÒÂòÂôËùBilaxy³ÆÆäÔâµ½¹¥»÷£¬Ô¤¼ÆËðʧ³¬¹ý2100ÍòÃÀÔª¡£Bilaxy°µÊ¾£¬¹¥»÷²úÉúÔÚ8ÔÂ28ÈÕÏÂÎç6µãµ½7µãÖ®¼ä£¬¹¥»÷ÕßÇÔÈ¡ÁË295¸öERC-20±Ò¡£Ä¿Ç°£¬BilaxyÒÑÖÕ³¡ÁËÆäÍøÕ¾ÉÏÔÚ½øÐÐÂòÂô£¬²¢ÇÒ½¨Òé¿Í»§ÁÙʱ²»Òª½«ÓÃÓÚÂòÂôµÄ¼ÓÃÜÇ®±Ò´æÈëÂòÂôËù¡£´Ë±í£¬¸ÃÍøÕ¾½«ÔÝÍ£·þÎñÖÁÉÙ2ÖÜ£¬ÓÃÀ´·ÖÎöºÚ¿ÍÐÐΪºÍ¸üÐÂϵͳ£¬²¢³¢ÊÔÈ¡»Ø±»µÁµÄERC-20±Ò¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/09/cryptocurrency-exchange-bilaxy-under.html


FortiGuard°ä²¼2021ÄêH1È«ÇòÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨


FortiGuard°ä²¼2021ÄêH1È«ÇòÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨.png


FortiGuardÓÚ8Ô·ݰ䲼ÁË2021ÄêH1È«ÇòÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬2021Äê6Ô¾ùÔÈÿÖÜÀÕË÷Èí¼þ»î¶¯±ÈÒ»ÄêǰͬÆÚÓâÔ½10.7±¶¡£ÆäÖУ¬µçÐÅÐÐÒµÊǹ¥»÷ÕßµÄÊ×ÒªµÄÖ¸±ê£¬Æä´ÎÊǵ±¾Ö¡¢Íйܰ²È«·þÎñÌṩÉÌ¡¢Æû³µºÍÔì×÷ÐÐÒµ¡£½©Ê¬ÍøÂçÒ²ÓÐËùÔö³¤£¬½ñÄêËêÊ×ÔÚ35%µÄ×éÖ¯Öмì²âµ½Á˽©Ê¬ÍøÂç»î¶¯£¬¶øÕâÒ»±ÈÀýÔÚ6¸öÔºóÔö³¤Îª51%¡£´Ë±í£¬¹¥»÷Õ߸üÇàíùÓÚ¼ì²âÈÆ¹ý¼¼ÊõºÍÌáȨ¼¼Êõ¡£


Ô­ÎÄÁ´½Ó£º

https://www.fortinet.com/content/dam/fortinet/assets/threat-reports/report-threat-landscape-2021.pdf


Positive Technologies°ä²¼2021Ä깤ҵ·çÏյĻ㱨


Positive Technologies°ä²¼2021Ä깤ҵ·çÏյĻ㱨.jpg


Positive TechnologiesÓÚ9ÔÂ1ÈÕ°ä²¼ÁË2021Ä깤ҵÐÅÏ¢°²È«·çÏյķÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬2020Ä꣬¹¤Òµ²¿ÃÅÊǽö´ÎÓÚµ±¾ÖµÄµÚ¶þ´ó¹¥»÷Ö¸±ê£¬ÓÐ12%µÄ¹¥»÷Õë¶Ô¹¤Òµ¹«Ë¾¡£ÔÚ91%µÄ¹¤Òµ¹«Ë¾ÖУ¬¹¥»÷ÕßÄܹ»ÉøÈë½øÈëÄÚÍø£¬Ö®ºó¹¥»÷Õß¾ÍÄܹ»»ñµÃÓû§Í´´¦²¢ÆëÈ«½ÚÔì»ù´¡ÉèÊ©¡£2021Äê5Ô£¬ÔÚThe Standoff 2021µÄÐé¹¹°Ð³¡Õ¹Ê¾ÁËÐÅÏ¢°²È«¶Ô¹¤Òµ×éÖ¯µÄÓ°Ï죬¹¥»÷ÕßÔÚÁ½ÌìÄÚ½ÚÔìÁ˼ÓÓÍÕ¾£¬ÖÕ³¡ÁËÌìÈ»Æø¹©¸ø²¢Òý·¢Á˱¬Õ¨¡£


Ô­ÎÄÁ´½Ó£º

https://www.ptsecurity.com/ww-en/analytics/ics-risks-2021/