ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ27ÖÜ
Ðû²¼Ê±¼ä 2020-07-06> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2020Äê06ÔÂ29ÈÕÖÁ07ÔÂ05ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´65¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇApache GuacamoleÌض¨PDUÄÚ´æÆÆ»µ´úÂëÖ´ÐЩ¶´; Palo Alto Networks PAN-OS SAMLÑéÖ¤Èƹý©¶´£»F5 BIG-IP Traffic Management User½Ó¿Ú´úÂëÖ´ÐЩ¶´£»ZyXEL CloudCNM SecuManagerÓ²±àÂ멶´£»TOBESOFT Nexacro14/17 ExtCommonApiV13 Library API²»ÍײÎÊý´¦ÖôúÂëÖ´ÐЩ¶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇApacheÐû²¼Äþ¾²Í¨¸æ£¬ÐÞ¸´ÆäTomcatÖеÄDoS©¶´£»ºÚ¿Íй¶°ÍÎ÷×Üͳ¼°20Íò¹«ÎñÔ±¸öÈËÐÅÏ¢£¬¾¯·½ÈÔÔÚÊÓ²ìÖУ»Î¢ÈíÐû²¼´øÍâ¸üУ¬ÐÞ¸´Windows 10ÖеĴúÂëÖ´ÐЩ¶´£»¶ñÒâÈí¼þTrickBotͨ¹ý¼ì²éÆÁÄ»·Ö±æÂÊÒÔÌӱܲ¡¶¾·ÖÎö£»¶ñÒâÈí¼þAlina»Ø¹é£¬ÀûÓÃDNSËíµÀÇÔÈ¡ÐÅÓÿ¨Êý¾Ý¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
>ÖØÒªÄþ¾²Â©¶´Áбí
1.Apache GuacamoleÌض¨PDUÄÚ´æÆÆ»µ´úÂëÖ´ÐЩ¶´
Apache GuacamoleδÕýÈ·Ñé֤ͨ¹ý¾²Ì¬ÐéÄâͨµÀ´ÓRDP·þÎñÆ÷½ÓÊÕµÄÊý¾ÝÖ¸Õ룬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄPDUÇëÇ󣬿ɴ¥·¢ÄÚ´æÆÆ»µ£¬Ö´ÐÐÈÎÒâ´úÂë¡£
https://lists.apache.org/thread.html/r26fb170edebff842c74aacdb1333c1338f0e19e5ec7854d72e4680fc@%3Cannounce.apache.org%3E
2. Palo Alto Networks PAN-OS SAMLÑéÖ¤Èƹý©¶´
Palo Alto Networks PAN-OS SAMLÉí·ÝÑéÖ¤´æÔÚÊý¾ÝαÔìÎÊÌ⩶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉδÊÚȨ·ÃÎÊ£¬¿ØÖÆÉ豸¡£
https://security.paloaltonetworks.com/CVE-2020-2021
3. F5 BIG-IP Traffic Management User½Ó¿Ú´úÂëÖ´ÐЩ¶´
F5 BIG-IP Traffic Management User½Ó¿Ú´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://support.f5.com/csp/article/K52145254
4. ZyXEL CloudCNM SecuManagerÓ²±àÂ멶´
ZyXEL CloudCNM SecuManagerʹÓÃÃÜÂëaxirosµÄrootÕË»§£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉδÊÚȨ·ÃÎÊϵͳ¡£
https://www.zyxel.com/support/vulnerabilities-of-CloudCNM-SecuManager.shtml
5. TOBESOFT Nexacro14/17 ExtCommonApiV13 Library API²»ÍײÎÊý´¦ÖôúÂëÖ´ÐЩ¶´
TOBESOFT Nexacro14/17 ExtCommonApiV13 Library API´¦ÖòÎÊý´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35491
> ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢ApacheÐû²¼Äþ¾²Í¨¸æ£¬ÐÞ¸´ÆäTomcatÖеÄDoS©¶´
ÔÎÄÁ´½Ó£º
https://www.us-cert.gov/ncas/current-activity/2020/06/26/apache-releases-security-advisory-apache-tomcat
2¡¢ºÚ¿Íй¶°ÍÎ÷×Üͳ¼°20Íò¹«ÎñÔ±¸öÈËÐÅÏ¢£¬¾¯·½ÈÔÔÚÊÓ²ìÖÐ
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/brazilian-federal-police-investigates-presidential-data-leak/
3¡¢Î¢ÈíÐû²¼´øÍâ¸üУ¬ÐÞ¸´Windows 10ÖеĴúÂëÖ´ÐЩ¶´
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-releases-oob-security-updates-for-windows-10-rce-bugs/
4¡¢¶ñÒâÈí¼þTrickBotͨ¹ý¼ì²éÆÁÄ»·Ö±æÂÊÒÔÌӱܲ¡¶¾·ÖÎö
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/trickbot-malware-now-checks-screen-resolution-to-evade-analysis/
5¡¢¶ñÒâÈí¼þAlina»Ø¹é£¬ÀûÓÃDNSËíµÀÇÔÈ¡ÐÅÓÿ¨Êý¾Ý
ÔÎÄÁ´½Ó£º
https://threatpost.com/alina-point-sale-malware-ongoing-campaign/157087/