ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ39ÖÜ
Ðû²¼Ê±¼ä 2020-09-28> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2020Äê09ÔÂ21ÈÕÖÁ09ÔÂ27ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´60¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇChrome storageÔ½½ç¶Á´úÂëÖ´ÐЩ¶´£»Chrome Extensions¼ÆıÈƹý´úÂëÖ´ÐЩ¶´£»Chrome V8´úÂëÖ´ÐЩ¶´£»Chrome mediaÊý¾ÝÑéÖ¤´úÂëÖ´ÐЩ¶´£»IBM Data Risk Manager FasterXML jackson-databind´úÂëÖ´ÐЩ¶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊǵ¹úTutanotaÔâµ½DDoS¹¥»÷µ¼Ö·þÎñÔÝʱÖжϣ»PradeoÐû²¼¡¶ÊÖ»úÒøÐУº¹æÔò¡¢ÍþвºÍÆÛÕ©Ô¤·À¡·°×ƤÊ飻NSAÐû²¼Õë¶ÔÔ¶³ÌÊÂÇéÕߺÍϵͳ¹ÜÀíÔ±µÄÍøÂçÄþ¾²Ö¸ÄÏ£»2020ÄêQ2 DDoS¹¥»÷µÄ´ÎÊý±ÈÈ¥Äêͬ±ÈÔö¼Ó570£¥£»Î¢Èí³ÆÒѼì²âµ½ÀûÓÃZerologon©¶´ÌᳫµÄÖ÷¶¯¹¥»÷¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
> ÖØÒªÄþ¾²Â©¶´Áбí
1.Chrome storageÔ½½ç¶Á´úÂëÖ´ÐЩ¶´
Chrome storage´æÔÚÔ½½ç¶Á©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄWEBÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»ò¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop_21.html
2. Chrome Extensions¼ÆıÈƹý´úÂëÖ´ÐЩ¶´
Chrome Extensions´æÔÚ¼ÆıÈƹý©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄWEBÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»ò¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop_21.html
3.Chrome V8´úÂëÖ´ÐЩ¶´
Chrome V8ÒýÇæ´æÔÚÔ½½ç䩶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄWEBÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»ò¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop_21.html
4. Chrome mediaÊý¾ÝÑéÖ¤´úÂëÖ´ÐЩ¶´
Chrome media´æÔÚÊý¾ÝÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄWEBÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»ò¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop_21.html
5.IBM Data Risk Manager FasterXML jackson-databind´úÂëÖ´ÐЩ¶´
IBM Data Risk Manager FasterXML jackson-databind´æÔÚ·´ÐòÁл¯Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.ibm.com/support/pages/node/6335281
> ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢µÂ¹úTutanotaÔâµ½DDoS¹¥»÷µ¼Ö·þÎñÔÝʱÖжÏ
µÂ¹ú¶Ëµ½¶Ë¼ÓÃܵç×ÓÓʼþ·þÎñÌṩÉÌTutanotaÔâµ½DDoS¹¥»÷£¬µ¼Ö·þÎñÔÝʱÖжÏÊýСʱ¡£Ê×´ÎÖ±½ÓÕë¶ÔTutanotaµÄDDoS¹¥»÷·¢ÉúÔÚ9ÔÂ14ÈÕ֮ǰµÄÄǸöÖÜÄ©£¬µ¼ÖÂÊý°ÙÃûÓû§ÎÞ·¨·ÃÎÊ·þÎñ£¬µ«¸ÃÎÊÌâºÜ¿ìµÃµ½Á˽â¾ö¡£Ö®ºóÔÚTutanotaµÄ·þÎñÆ÷¹Ø±Õºó£¬ºÚ¿Í¹¥»÷ÁËÍйÜTutanota¼Ç¼µÄDNSÌṩ·¨Ê½£¬ÕâʹÊý°ÙÍòÓû§ÎÞ·¨·ÃÎÊÆäTutanotaÕÊ»§¡£Ä¿Ç°£¬¸Ã¹«Ë¾ÕýÔÚʵÑé¸üÐÂÆäDNS¼Ç¼£¬²¢½«ËüÃÇÍйÜÔÚÁíÒ»¸öÌṩÉÌ´¦¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/tutanota-encrypted-email-service-suffers-ddos-cyberattacks/
2¡¢PradeoÐû²¼¡¶ÊÖ»úÒøÐУº¹æÔò¡¢ÍþвºÍÆÛÕ©Ô¤·À¡·°×ƤÊé
PradeoÐû²¼ÁË¡¶ÊÖ»úÒøÐУº¹æÔò¡¢ÍþвºÍÆÛÕ©Ô¤·À¡·°×ƤÊ飬½éÉÜÁËÓйØÒƶ¯ÒøÐеÄʹÓá¢Ö´·¨¿ò¼Ü¡¢·çÏÕÒÔ¼°±£»¤Òƶ¯ÒøÐÐÓ¦Ó÷¨Ê½Äþ¾²µÄ½â¾ö·½°¸£¨´Ó¿ª·¢µ½Ö´ÐУ©µÄÏêϸÐÅÏ¢¡£ÆäÖÐдµÀ£¬Òƶ¯ÒøÐзþÎñѸËÙÊܵ½Ïû·ÑÕßµÄϲ°®£¬µ½2019Äêµ×£¬74%µÄÓ¢¹úÈ˺Í75%µÄÃÀ¹úÈËʹÓÃÒƶ¯É豸À´¹ÜÀíÆä²ÆÕþ¡£µ«ÊÇÑо¿±íÃ÷£¬ÊÖ»úÒøÐÐÓ¦ÓÃÍùÍùûÓÐÔ¤ÆÚµÄÄÇôÄþ¾²£¬¾ÝRSAµÄÆÛÕ©ºÍ·çÏÕÇ鱨ÍŶÓ×î½üÊÕ¼¯µÄÊý¾Ý·ÖÎöÏÔʾ£¬ÓëÊÖ»úÓ¦ÓÃÏà¹ØµÄÆÛÕ©ÐÐΪÔÚ2020ÄêµÚÒ»¼¾¶È·ÁËÒ»·¬¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/09/21/whitepaper-mobile-banking-regulations-threats-and-fraud-prevention
3¡¢NSAÐû²¼Õë¶ÔÔ¶³ÌÊÂÇéÕߺÍϵͳ¹ÜÀíÔ±µÄÍøÂçÄþ¾²Ö¸ÄÏ
ÃÀ¹ú¹ú¼ÒÄþ¾²¾Ö(NSA)Ðû²¼ÁËÁ½·ÝÍøÂçÄþ¾²ÐÅÏ¢±í(CSIs)£¬Îª¹ú¼ÒÄþ¾²ÏµÍ³(NSS)ºÍ¹ú·À²¿(DoD)ÊÂÇéÈËÔ±ºÍϵͳ¹ÜÀíÔ±ÌṩÁ˹ØÓÚÔÚ¼ÒÊÂÇéÆڼ䱣»¤ÍøÂçÄþ¾²ºÍÓ¦¶ÔʼþµÄ½¨Òé¡£µÚÒ»·ÝÃûΪÊÜËð¸öÈËÍøÂçÖ¸±êºÍ»º½â´ëÊ©£¬Ö¼ÔÚÌṩÓйØÔ¶³ÌÊÂÇéÕßÈçºÎʶ±ðºÍ¼õÇáÆä¸öÈËÍøÂçΣº¦µÄÏêϸÐÅÏ¢¡£µÚ¶þ·ÝÃûΪִÐдøÍâÍøÂç¹ÜÀí£¬ÆäÏòϵͳ¹ÜÀíÔ±ÌṩÁËÈçºÎ¸ôÀë¹ÜÀíÁ÷Á¿ºÍÔËÓªÁ÷Á¿µÄÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/nsa-issues-cybersecurity-guidance-remote-workers-system-admins
4¡¢2020ÄêQ2 DDoS¹¥»÷µÄ´ÎÊý±ÈÈ¥Äêͬ±ÈÔö¼Ó570£¥
ƾ¾ÝNexusguard³ÂËߣ¬DDoS¹¥»÷µÄ´ÎÊýÓëÈ¥ÄêͬÆÚÏà±ÈÔö¼ÓÁË570£¥¡£¹¥»÷Õß½ÓÄÉÁ˸ü¾«Ï¸µÄ¹¥»÷·½Ê½£¬ÒÔ·¢¶¯ÖÖÖÖ·Å´óºÍ»ùÓÚUDPµÄ¹¥»÷£¬ÓÃÁ÷Á¿ÑÍûĿ±êÍøÂ磬ÕâʹCSPºÜÄÑͨ¹ý´«Í³µÄ»ùÓÚãÐÖµµÄÒªÁì½øÐмì²âºÍ»º½â¡£Nexusguard»¹·¢ÏÖÁËÒ»ÖÖеÄÇ÷ÊÆ£¬¼´¹¥»÷Õß½ÓÄÉ»ìºÏ¹¥»÷ý½éÀ´Ìᳫ¸ü¹ã·ºµÄ»ùÓÚUDPµÄ¹¥»÷£¬Ä¿µÄÊÇÌá¸ßCSP¼ì²âºÍÇø·Ö¶ñÒâÁ÷Á¿ÓëºÏ·¨Á÷Á¿µÄÄѶȡ£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/09/23/bit-and-piece-ddos-attacks-increased-570-in-q2-2020/
5¡¢Î¢Èí³ÆÒѼì²âµ½ÀûÓÃZerologon©¶´ÌᳫµÄÖ÷¶¯¹¥»÷
΢ÈíÄþ¾²Ç鱨ÍŶÓÌåÏÖ£¬ÆäÒѼì²âµ½ÀûÓÃZerologon©¶´£¨CVE-2020-1472 £©ÌᳫµÄÖ÷¶¯¹¥»÷¡£×ÔºÉÀ¼Äþ¾²¹«Ë¾Secura BVÔÚ9ÔÂ14ÈÕÅû¶ÁËÓйØZerologon©¶´µÄÏêϸÐÅÏ¢ºó£¬ÒÑÓжà¸öÎäÆ÷»¯µÄPoC¿ª·¢´úÂëÔÚÍøÉϹûÈ»¡£Î¢Èí²¢Ã»ÓÐÐû²¼Óйش˴ι¥»÷µÄϸ½Ú£¬µ«ÊÇÐû²¼ÁËÓÃÓÚ¹¥»÷µÄÎļþÉ¢ÁС£Òò´ËÄþ¾²×¨¼Ò¾Í½¨Ò飬ÄÇЩÓòÃû¿ØÖÆÆ÷̻¶µÄ¹«Ë¾Ó¦¾¡¿ìÈÃϵͳÀëÏߣ¬ÒÔ±ã¶ÔÆä½øÐв¹¶¡¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/microsoft-says-it-detected-active-attacks-leveraging-zerologon-vulnerability/