ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ42ÖÜ
Ðû²¼Ê±¼ä 2020-10-19> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2020Äê10ÔÂ12ÈÕÖÁ10ÔÂ18ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´62¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe Flash Player¿ÕÖ¸ÕëÒýÓÃÔ¶³Ì´úÂëÖ´ÐЩ¶´£»Microsoft Windows Hyper-V CVE-2020-1047ȨÏÞÌáÉý©¶´£»SAP Solution Manager OSÃüÁî×¢È멶´£»Microhard Bullet-LTE PingÃüÁî×¢Èë´úÂëÖ´ÐЩ¶´£»Veritas APTAREÊÚȨ¼ì²é´úÂëÖ´ÐЩ¶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇBlackBerryÐû²¼¹ØÓÚBAHAMUT×éÖ¯µÄ·ÖÎö³ÂËߣ»LumuÐû²¼2020Äê¶ÈÀÕË÷Èí¼þÓ°Ïì·ÖÎöµÄÐÅϢͼ£»AdobeÐÞ¸´Flash PlayerÖеÄÔ¶³ÌÖ´ÐдúÂ멶´£»AgariÐû²¼BECÔÚÈ«Çò·¶Î§ÄÚÂþÑܺÍÇ÷ÊƵķÖÎö³ÂËߣ»CNSAÐû²¼¡¶2020ÖйúÍøÂçÊÓÌýÉú³¤Ñо¿³ÂËß¡·¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
> ÖØÒªÄþ¾²Â©¶´Áбí
1.Adobe Flash Player¿ÕÖ¸ÕëÒýÓÃÔ¶³Ì´úÂëÖ´ÐЩ¶´
Adobe Flash Player´¦ÖÃSWF´æÔÚ¿ÕÖ¸ÕëÒýÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÕßÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://helpx.adobe.com/security/products/flash-player/apsb20-58.html
2.Microsoft Windows Hyper-V CVE-2020-1047ȨÏÞÌáÉý©¶´
Microsoft Windows Hyper-V´¦ÖÃÄڴ湤¾ß´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉÌáÉýȨÏÞ¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2020-1047
3.SAP Solution Manager OSÃüÁî×¢È멶´
SAP Solution ManagerµÄCA Introscope Enterprise Manager´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâOSÃüÁî¡£
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=558632196
4.Microhard Bullet-LTE PingÃüÁî×¢Èë´úÂëÖ´ÐЩ¶´
Microhard Bullet-LTE tools.sh´¦ÖÃping²ÎÊý´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâÃüÁî¡£
https://www.zerodayinitiative.com/advisories/ZDI-20-1205/
5.Veritas APTAREÊÚȨ¼ì²é´úÂëÖ´ÐЩ¶´
Veritas APTAREÊÚȨ¼ì²é´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.veritas.com/content/support/en_US/security/VTS20-006#issue1
> ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢BlackBerryÐû²¼¹ØÓÚBAHAMUT×éÖ¯µÄ·ÖÎö³ÂËß
BlackBerryÐû²¼Á˹ØÓÚBAHAMUTÍøÂç¼äµý×éÖ¯µÄ·ÖÎö³ÂËߣ¬·¢ÏÖÆä¶ÔÕþ¸®¹ÙÔ±ºÍÖ÷ÒªÐÐÒµÌᳫÁË´óÁ¿¸ß¶ÈÅÓ´óµÄ¹¥»÷¡£Ñо¿±íÃ÷£¬¸ÃÍÅ»ïµÄ»î¶¯·¶Î§±ÈÒÔÇ°ÈÏΪµÄÒª¹ã·ºµÃ¶à£¬°üÂÞÁËGoogle PlayÉ̵êºÍApp StoreÖеÄÊ®¼¸¸ö¶ñÒâÓ¦Ó÷¨Ê½¡£´ËÍ⣬BlackBerry»¹ÈÏΪ£¬BAHAMUT¿ÉÒÔÓëÖÁÉÙÒ»Ãû0day¿ª·¢ÈËÔ±½Ó´¥£¬²¢ÀûÓÃ0day¹¥»÷¶à¸öÄ¿±ê£¬ÕâÔ¶Ô¶³¬³öÁË´ó¶àÊýÆäËûºÚ¿Í×éÖ¯µÄ¹¥»÷ˮƽ¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/cyber-espionage-bahamut-staggering/
2¡¢LumuÐû²¼2020Äê¶ÈÀÕË÷Èí¼þÓ°Ïì·ÖÎöµÄÐÅϢͼ
LumuÐû²¼ÁËÒ»ÕÅÐÅϢͼ£¬Ïêϸ˵Ã÷ÁËÀÕË÷Èí¼þµÄ³É±¾ºÍ·¶Î§£¬ÒÔ×ÊÖúÆóÒµºâÁ¿ËûÃǵÄÊܺ¦·çÏÕ¡£¾Ý·ÖÎö£¬½ñÄêÈ«ÇòÀÕË÷Èí¼þµÄ³É±¾Îª200ÒÚÃÀÔª£¬Æ½¾ùÿ´ÎµÄ¹¥»÷³É±¾Áè¼Ý400ÍòÃÀÔª£¬¶øÇÒÓÐ36£¥µÄÊܺ¦ÕßÖ§¸¶ÁËÊê½ð£¬ÆäÖÐ17£¥»¹Ã»ÄÜÍì»ØËûÃǵÄÊý¾Ý¡£´ËÍ⣬ÔÚ±±ÃÀÓÐ69%µÄ¹«Ë¾³ÂËß³ÆÊܵ½ÁËÀÕË÷Èí¼þµÄÓ°Ï죬¶øÔÚÅ·ÖÞÓÐ57%¡£Ïà½Ï¶øÑÔ£¬±±ÃÀµÄÕþ¸®»ú¹¹Êܵ½µÄ¹¥»÷×îΪÑÏÖØ£¬Æä´ÎÊÇÖÆÔìÒµºÍ½¨ÖþÒµ¡£
ÔÎÄÁ´½Ó£º
https://lumu.io/resources/2020-ransomware-flashcard/
3¡¢AdobeÐÞ¸´Flash PlayerÖеÄÔ¶³ÌÖ´ÐдúÂ멶´
AdobeÐÞ¸´ÁËFlash PlayerÖÐÑÏÖصÄÔ¶³ÌÖ´ÐдúÂ멶´£¨³ÆΪCVE-2020-9746£©¡£AdobeÖ¸³ö£¬ÔÚĬÈÏÇé¿öÏ£¬ºÚ¿Í¿ÉÒÔͨ¹ýÔÚÓû§·ÃÎÊÍøվʱÔÚTLS / SSLͨ±¨µÄHTTPÏìÓ¦ÖвåÈë¶ñÒâ×Ö·û´®À´ÀûÓôË©¶´¡£ÀÖ³ÉÀûÓôË©¶´ºó£¬¿ÉÄܵ¼ÖÂÓ¦ÓÃÍ߽⣬´Ó¶øʹ¹¥»÷Õß¿ÉÒÔÔÚ·ÃÎÊÕߵļÆËã»úÉÏÔ¶³ÌÖ´ÐÐÃüÁî¡£ÕâЩÃüÁÔÚÓû§µÄÄþ¾²»·¾³ÖÐÖ´ÐУ¬²¢²»ÐèÒª¹ÜÀíԱȨÏÞ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-security-vulnerability-in-flash-player/
4¡¢AgariÐû²¼BECÔÚÈ«Çò·¶Î§ÄÚÂþÑܺÍÇ÷ÊƵķÖÎö³ÂËß
AgariÍøÂçÇ鱨²¿£¨ACID£©Ðû²¼ÁËBECÔÚÈ«Çò·¶Î§ÄÚÂþÑܺÍÇ÷ÊƵķÖÎö³ÂËߣ¬ÒÔ¸üºÃµØÁ˽âBEC¹¥»÷»î¶¯¡£³ÂËß°üÂÞÁË2019Äê5ÔÂÖÁ2020Äê7ÔÂÖ®¼äµÄ9000¶à´Î·ÀÓù»î¶¯µÄÊý¾Ý£¬·¢ÏÖÓÐ60£¥µÄ¹¥»÷ÕßÀ´×Ô·ÇÖÞµÄ11¸ö¹ú¼Ò£¬ÆäÖÐ83£¥Î»ÓÚÄáÈÕÀûÑÇ¡£½ü30£¥µÄ¹¥»÷ÕßÀ´×ÔÃÀÖÞ£¬ÆäÖеÄ89£¥À´×ÔÃÀ¹ú£¬¶øÇÒ¹¥»÷ÕßÖ÷Òª¾Û¼¯ÔÚһЩ¶àÊýÊУ¬°üÂÞÑÇÌØÀ¼´ó¡¢Å¦Ô¼¡¢ÂåÉ¼í¶¡¢ÐÝ˹¶ØºÍÂõ°¢ÃÜ¡£
ÔÎÄÁ´½Ó£º
https://www.agari.com/email-security-blog/business-email-compromise-geography/
5¡¢CNSAÐû²¼¡¶2020ÖйúÍøÂçÊÓÌýÉú³¤Ñо¿³ÂËß¡·
10ÔÂ12ÈÕ£¬ÖйúÍøÂçÊÓÌý½ÚÄ¿·þÎñлáÐû²¼¡¶2020ÖйúÍøÂçÊÓÌýÉú³¤Ñо¿³ÂËß¡·£¬Ê׶ȹûÈ»ÎÒ¹úÍøÂçÊÓÌýÓû§¹æÄ£ºÍ¹¤Òµ¹æÄ£¡£¸Ã³ÂËß»ùÓÚÊý¾ÝÍÚ¾ò¡¢µ÷ÑÐÒÔ¼°µÚÈý·½Êý¾Ý£¬¶Ô2019-2020ÄêµÄÍøÂçÊÓÌýÐÐÒµÏÖ×´ºÍÉú³¤Ç÷ÊƽøÐÐȨÍþ¡¢È«ÃæµÄÑÐÅС£³ÂËßÏÔʾ£¬½ØÖÁ2020Äê6Ô£¬ÎÒ¹úÍøÂçÊÓÌýÓû§¹æÄ£´ï9.01ÒÚ£¬ 2019ÄêÍøÂçÊÓÌý¹¤Òµ¹æÄ£´ï4541.3ÒÚ¡£ÆäÖжÌÊÓƵµÄÓû§Ê¹ÓÃÂÊ×î¸ß£¬´ï87.0%£¬Óû§¹æÄ£8.18ÒÚ£»×ÛºÏÊÓƵµÄÓû§Ê¹ÓÃÂÊΪ77.1%£¬Óû§¹æÄ£7.24ÒÚ¡£
ÔÎÄÁ´½Ó£º
http://www.xinhuanet.com/info/2020-10/13/c_139436283.htm