ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ42ÖÜ

Ðû²¼Ê±¼ä 2020-10-19

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2020Äê10ÔÂ12ÈÕÖÁ10ÔÂ18ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´62¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇAdobe Flash Player¿ÕÖ¸ÕëÒýÓÃÔ¶³Ì´úÂëÖ´ÐЩ¶´£»Microsoft Windows Hyper-V CVE-2020-1047ȨÏÞÌáÉý©¶´£»SAP Solution Manager OSÃüÁî×¢È멶´£»Microhard Bullet-LTE PingÃüÁî×¢Èë´úÂëÖ´ÐЩ¶´£»Veritas APTAREÊÚȨ¼ì²é´úÂëÖ´ÐЩ¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇBlackBerryÐû²¼¹ØÓÚBAHAMUT×éÖ¯µÄ·ÖÎö³ÂËߣ»LumuÐû²¼2020Äê¶ÈÀÕË÷Èí¼þÓ°Ïì·ÖÎöµÄÐÅϢͼ£»AdobeÐÞ¸´Flash PlayerÖеÄÔ¶³ÌÖ´ÐдúÂ멶´£»AgariÐû²¼BECÔÚÈ«Çò·¶Î§ÄÚÂþÑܺÍÇ÷ÊƵķÖÎö³ÂËߣ»CNSAÐû²¼¡¶2020ÖйúÍøÂçÊÓÌýÉú³¤Ñо¿³ÂËß¡·¡£


ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾ÖÜÄþ¾²ÍþвΪÖС£


ÖØÒªÄþ¾²Â©¶´Áбí


1.Adobe Flash Player¿ÕÖ¸ÕëÒýÓÃÔ¶³Ì´úÂëÖ´ÐЩ¶´


Adobe Flash Player´¦ÖÃSWF´æÔÚ¿ÕÖ¸ÕëÒýÓ鶴 £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬ÓÕʹÓû§½âÎö £¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÕßÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://helpx.adobe.com/security/products/flash-player/apsb20-58.html


2.Microsoft Windows Hyper-V CVE-2020-1047ȨÏÞÌáÉý©¶´


Microsoft Windows Hyper-V´¦ÖÃÄڴ湤¾ß´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬ÓÕʹÓû§½âÎö £¬¿ÉÌáÉýȨÏÞ¡£

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2020-1047


3.SAP Solution Manager OSÃüÁî×¢È멶´


SAP Solution ManagerµÄCA Introscope Enterprise Manager´æÔÚÊäÈëÑé֤©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâOSÃüÁî¡£

https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=558632196


4.Microhard Bullet-LTE PingÃüÁî×¢Èë´úÂëÖ´ÐЩ¶´


Microhard Bullet-LTE tools.sh´¦ÖÃping²ÎÊý´æÔÚÊäÈëÑé֤©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâÃüÁî¡£

https://www.zerodayinitiative.com/advisories/ZDI-20-1205/


5.Veritas APTAREÊÚȨ¼ì²é´úÂëÖ´ÐЩ¶´


Veritas APTAREÊÚȨ¼ì²é´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://www.veritas.com/content/support/en_US/security/VTS20-006#issue1


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢BlackBerryÐû²¼¹ØÓÚBAHAMUT×éÖ¯µÄ·ÖÎö³ÂËß


1.jpg


BlackBerryÐû²¼Á˹ØÓÚBAHAMUTÍøÂç¼äµý×éÖ¯µÄ·ÖÎö³ÂËß £¬·¢ÏÖÆä¶ÔÕþ¸®¹ÙÔ±ºÍÖ÷ÒªÐÐÒµÌᳫÁË´óÁ¿¸ß¶ÈÅÓ´óµÄ¹¥»÷¡£Ñо¿±íÃ÷ £¬¸ÃÍÅ»ïµÄ»î¶¯·¶Î§±ÈÒÔÇ°ÈÏΪµÄÒª¹ã·ºµÃ¶à £¬°üÂÞÁËGoogle PlayÉ̵êºÍApp StoreÖеÄÊ®¼¸¸ö¶ñÒâÓ¦Ó÷¨Ê½¡£´ËÍâ £¬BlackBerry»¹ÈÏΪ £¬BAHAMUT¿ÉÒÔÓëÖÁÉÙÒ»Ãû0day¿ª·¢ÈËÔ±½Ó´¥ £¬²¢ÀûÓÃ0day¹¥»÷¶à¸öÄ¿±ê £¬ÕâÔ¶Ô¶³¬³öÁË´ó¶àÊýÆäËûºÚ¿Í×éÖ¯µÄ¹¥»÷ˮƽ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/cyber-espionage-bahamut-staggering/


2¡¢LumuÐû²¼2020Äê¶ÈÀÕË÷Èí¼þÓ°Ïì·ÖÎöµÄÐÅϢͼ


2.jpg


LumuÐû²¼ÁËÒ»ÕÅÐÅϢͼ £¬Ïêϸ˵Ã÷ÁËÀÕË÷Èí¼þµÄ³É±¾ºÍ·¶Î§ £¬ÒÔ×ÊÖúÆóÒµºâÁ¿ËûÃǵÄÊܺ¦·çÏÕ¡£¾Ý·ÖÎö £¬½ñÄêÈ«ÇòÀÕË÷Èí¼þµÄ³É±¾Îª200ÒÚÃÀÔª £¬Æ½¾ùÿ´ÎµÄ¹¥»÷³É±¾Áè¼Ý400ÍòÃÀÔª £¬¶øÇÒÓÐ36£¥µÄÊܺ¦ÕßÖ§¸¶ÁËÊê½ð £¬ÆäÖÐ17£¥»¹Ã»ÄÜÍì»ØËûÃǵÄÊý¾Ý¡£´ËÍâ £¬ÔÚ±±ÃÀÓÐ69%µÄ¹«Ë¾³ÂËß³ÆÊܵ½ÁËÀÕË÷Èí¼þµÄÓ°Ïì £¬¶øÔÚÅ·ÖÞÓÐ57%¡£Ïà½Ï¶øÑÔ £¬±±ÃÀµÄÕþ¸®»ú¹¹Êܵ½µÄ¹¥»÷×îΪÑÏÖØ £¬Æä´ÎÊÇÖÆÔìÒµºÍ½¨ÖþÒµ¡£


Ô­ÎÄÁ´½Ó£º

https://lumu.io/resources/2020-ransomware-flashcard/


3¡¢AdobeÐÞ¸´Flash PlayerÖеÄÔ¶³ÌÖ´ÐдúÂ멶´


3.jpg


AdobeÐÞ¸´ÁËFlash PlayerÖÐÑÏÖصÄÔ¶³ÌÖ´ÐдúÂ멶´£¨³ÆΪCVE-2020-9746£©¡£AdobeÖ¸³ö £¬ÔÚĬÈÏÇé¿öÏ £¬ºÚ¿Í¿ÉÒÔͨ¹ýÔÚÓû§·ÃÎÊÍøվʱÔÚTLS / SSLͨ±¨µÄHTTPÏìÓ¦ÖвåÈë¶ñÒâ×Ö·û´®À´ÀûÓôË©¶´¡£ÀÖ³ÉÀûÓôË©¶´ºó £¬¿ÉÄܵ¼ÖÂÓ¦ÓÃÍ߽⠣¬´Ó¶øʹ¹¥»÷Õß¿ÉÒÔÔÚ·ÃÎÊÕߵļÆËã»úÉÏÔ¶³ÌÖ´ÐÐÃüÁî¡£ÕâЩÃüÁÔÚÓû§µÄÄþ¾²»·¾³ÖÐÖ´ÐÐ £¬²¢²»ÐèÒª¹ÜÀíԱȨÏÞ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-security-vulnerability-in-flash-player/


4¡¢AgariÐû²¼BECÔÚÈ«Çò·¶Î§ÄÚÂþÑܺÍÇ÷ÊƵķÖÎö³ÂËß


4.jpg


AgariÍøÂçÇ鱨²¿£¨ACID£©Ðû²¼ÁËBECÔÚÈ«Çò·¶Î§ÄÚÂþÑܺÍÇ÷ÊƵķÖÎö³ÂËß £¬ÒÔ¸üºÃµØÁ˽âBEC¹¥»÷»î¶¯¡£³ÂËß°üÂÞÁË2019Äê5ÔÂÖÁ2020Äê7ÔÂÖ®¼äµÄ9000¶à´Î·ÀÓù»î¶¯µÄÊý¾Ý £¬·¢ÏÖÓÐ60£¥µÄ¹¥»÷ÕßÀ´×Ô·ÇÖÞµÄ11¸ö¹ú¼Ò £¬ÆäÖÐ83£¥Î»ÓÚÄáÈÕÀûÑÇ¡£½ü30£¥µÄ¹¥»÷ÕßÀ´×ÔÃÀÖÞ £¬ÆäÖеÄ89£¥À´×ÔÃÀ¹ú £¬¶øÇÒ¹¥»÷ÕßÖ÷Òª¾Û¼¯ÔÚһЩ¶àÊýÊÐ £¬°üÂÞÑÇÌØÀ¼´ó¡¢Å¦Ô¼¡¢ÂåÉ¼í¶¡¢ÐÝ˹¶ØºÍÂõ°¢ÃÜ¡£


Ô­ÎÄÁ´½Ó£º

https://www.agari.com/email-security-blog/business-email-compromise-geography/


5¡¢CNSAÐû²¼¡¶2020ÖйúÍøÂçÊÓÌýÉú³¤Ñо¿³ÂËß¡·


5.jpg


10ÔÂ12ÈÕ £¬ÖйúÍøÂçÊÓÌý½ÚÄ¿·þÎñЭ»áÐû²¼¡¶2020ÖйúÍøÂçÊÓÌýÉú³¤Ñо¿³ÂËß¡· £¬Ê׶ȹûÈ»ÎÒ¹úÍøÂçÊÓÌýÓû§¹æÄ£ºÍ¹¤Òµ¹æÄ£¡£¸Ã³ÂËß»ùÓÚÊý¾ÝÍÚ¾ò¡¢µ÷ÑÐÒÔ¼°µÚÈý·½Êý¾Ý £¬¶Ô2019-2020ÄêµÄÍøÂçÊÓÌýÐÐÒµÏÖ×´ºÍÉú³¤Ç÷ÊƽøÐÐȨÍþ¡¢È«ÃæµÄÑÐÅС£³ÂËßÏÔʾ £¬½ØÖÁ2020Äê6Ô £¬ÎÒ¹úÍøÂçÊÓÌýÓû§¹æÄ£´ï9.01ÒÚ £¬ 2019ÄêÍøÂçÊÓÌý¹¤Òµ¹æÄ£´ï4541.3ÒÚ¡£ÆäÖжÌÊÓƵµÄÓû§Ê¹ÓÃÂÊ×î¸ß £¬´ï87.0% £¬Óû§¹æÄ£8.18ÒÚ£»×ÛºÏÊÓƵµÄÓû§Ê¹ÓÃÂÊΪ77.1% £¬Óû§¹æÄ£7.24ÒÚ¡£


Ô­ÎÄÁ´½Ó£º

http://www.xinhuanet.com/info/2020-10/13/c_139436283.htm