ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ07ÖÜ
Ðû²¼Ê±¼ä 2020-02-17> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2020Äê02ÔÂ10ÈÕÖÁ16ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´94¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇApache Dubbo·´ÐòÁл¯´úÂëÖ´ÐЩ¶´; OpenVPN Access Server LDAPÑéÖ¤Èƹý©¶´£»IstioÑéÖ¤¼Æıexact-pathÂ߼ƥÅäÄþ¾²Èƹý©¶´£»Adobe Framemaker CVE-2020-3731ÄÚ´æÒýÓôúÂëÖ´ÐЩ¶´£»Microsoft Exchange Server CVE-2020-0692ȨÏÞÌáÉý©¶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇ˼¿ÆTalosÅû¶Apple Safariä¯ÀÀÆ÷ÖеÄRCE©¶´£»ÃÀµÂÇ鱨²¿ÃÅ¿ØÖÆÈðÊ¿¹«Ë¾ÊýÊ®Ä꣬ÇÔÈ¡120¹ú»úÃÜÇ鱨£»MalwarebytesÐû²¼2020Äê¶ñÒâÈí¼þ×´¿ö³ÂËߣ»ÑÅÊ«À¼÷ìÔÆÊý¾Ý¿â̻¶4.4ÒÚÌõÄÚ²¿¼Ç¼£»Palo Alto NetworksÐû²¼2020Äê´º¼¾ÔÆÍþв³ÂËß¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
>ÖØÒªÄþ¾²Â©¶´Áбí
1. Apache Dubbo·´ÐòÁл¯´úÂëÖ´ÐЩ¶´
Apache DubboÆôÓÃHTTPÐÒé½øÐÐͨÐÅʱ´æÔÚ·´ÐòÁл¯Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄPOSTÇëÇó£¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://github.com/apache/dubbo/releases/tag/dubbo-2.7.5
2. OpenVPN Access Server LDAPÑéÖ¤Èƹý©¶´
OpenVPN Access Server ʹÓÃLDAPÑé֤ϵͳµÇ¼´¦ÖôæÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇóÈƹýÑéÖ¤£¬Î´ÊÚȨ·ÃÎÊ¡£
https://openvpn.net/security-advisories/
3. IstioÑéÖ¤¼Æıexact-pathÂ߼ƥÅäÄþ¾²Èƹý©¶´
IstioÑéÖ¤¼Æıexact-pathÂß¼´¦ÖôæÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄ°üÂÞ?»ò#×Ö·ûµÄÇëÇ󣬿ÉÈƹýÑéÖ¤¡£
https://istio.io/news/security/istio-security-2020-001/
4. Adobe Framemaker CVE-2020-3731ÄÚ´æÒýÓôúÂëÖ´ÐЩ¶´
Adobe Framemaker´æÔÚÄÚ´æÆÆ»µÂ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴¹¹½¨¶ñÒâÎļþ£¬ÓÕʹÓû§ÇëÇ󣬿ÉÒÔÄ¿±êÓû§ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://helpx.adobe.com/security/products/framemaker/apsb20-04.html
5. Microsoft Exchange Server CVE-2020-0692ȨÏÞÌáÉý©¶´
Microsoft Exchange Server´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔ»ñµÃÓë Exchange Server µÄÆäËûÈκÎÓû§ÏàͬµÄȨÏÞ¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2020-0692
> ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢Ë¼¿ÆTalosÅû¶Apple Safariä¯ÀÀÆ÷ÖеÄRCE©¶´
˼¿ÆTalosÍŶÓÅû¶Apple Safariä¯ÀÀÆ÷ÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´(CVE-2020-3868)£¬µ±Óû§ÔÚSafariÖдò¿ª¶ñÒâÍøҳʱ£¬¿ÉÄܻᴥ·¢ÀàÐÍ»ìÏý£¬´Ó¶øµ¼ÖÂÄÚ´æË𻵺ÍÖ´ÐÐÈÎÒâ´úÂë¡£¹¥»÷ÕßÐèҪͨ¹ýijÖÖ·½Ê½ÓÕʹÓû§·ÃÎʶñÒâÍøÒ³À´´¥·¢´Ë©¶´¡£¸Ã©¶´´æÔÚÓÚSafariµÄ¡°×ÖÌ塱¹¦Ð§ÖУ¬Talos²âÊÔ²¢È·ÈÏ´Ë©¶´Ó°ÏìSafari°æ±¾13.0.3£¨15608.3.10.1.4£©¡¢Safari¼¼ÊõÔ¤ÀÀ°æ96£¨Safari 13.1£¬WebKit 15609.1.9.7£©ºÍWebkit GIT e4cd3b4fab6166d1288984ded40c588439dab925£¬½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁ×îа汾¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2020/02/vuln-spotlight-apple-safari-code-execution-feb-2020.html
2¡¢ÃÀµÂÇ鱨²¿ÃÅ¿ØÖÆÈðÊ¿¹«Ë¾ÊýÊ®Ä꣬ÇÔÈ¡120¹ú»úÃÜÇ鱨
¾ÝÃÀ¹ú¡¶»ªÊ¢¶ÙÓʱ¨¡·±¨µÀ£¬ÃÀµÂÇ鱨²¿ÃÅÊýÊ®Äê¼äͨ¹ý¿ØÖÆÈðÊ¿¼ÓÃܹ«Ë¾Crypto AG£¬ÇÔÈ¡ÁËÈ«ÇòÔ¼120¹úÕþ¸®µÄ×î¸ß»úÃÜͨѶÇ鱨¡£¾ÝϤ£¬µÚ¶þ´ÎÊÀ½ç´óÕ½Õ½ºóµ½±¾ÊÀ¼Í³õ£¬Crypto AG¹«Ë¾ÎªÔ¼120¸ö¹ú¼ÒµÄÕþ¸®Ìṩ¼ÓÃÜͨѶװÖã¬ÒÁÀÊ¡¢ÄÏÃÀ¶à¹úÕþ¸®¡¢Ó¡¶ÈÓë°Í»ù˹̹½ÔΪ·þÎñ¹¤¾ß¡£µ«Crypto AGÄ»ºóÀÏ°åÆäʵÊÇÃÀ¹úÖÐÑëÇ鱨¾Ö£¨CIA£©ÒÔ¼°µÂ¹úÁª°îÇ鱨¾Ö£¨BND£©¡£ÕâÁ½¸öÇ鱨²¿ÃŶÔCrypto×°Öö¯Êֽţ¬ÈÃ×°ÖÿÉÇáÒ×±»Æƽ⣬½ø¶ø½â¶ÁÊý¾Ý¡£±¨µÀ³Æ£¬ÖÐÇé¾ÖÄÚ²¿ÓйØÓÚÕâ¸ö×î¸ß»úÃܼƻ®µÄÀúÊ·»úÃܵµ°¸£¬µµ°¸Ö¸³öCrypto AG¿¿×ÅÈÃÎ÷·½Ç鱨»ú¹ØÈ¡µÃ¿Í»§»úÃÜ£¬×¬½øÊýÒÔ°ÙÍò¼ÆÃÀÔª¡£Í¬Ê±£¬µµ°¸Ò²Ö¸³ö£¬¾¡¹ÜʹÓÃCrypto AG²úÎïµÄ¹ú¼Ò²»ÉÙ£¬µ«ËÕÁª/¶íÂÞ˹ºÍÖйú£¬È´´ÓÀ´¶¼²»ÊǸù«Ë¾µÄ¿Í»§¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/us-german-spies-plundered-global-secrets-swiss-encryption-firm-report
3¡¢MalwarebytesÐû²¼2020Äê¶ñÒâÈí¼þ×´¿ö³ÂËß
Malwarebytes LabsÐû²¼2020Äê¶ñÒâÈí¼þ×´¿ö³ÂËߣ¬³ÂËßÖ¸³öÓëÕë¶ÔWindows PCµÄÍþвÏà±È£¬MacÍþв³ÊÖ¸Êý¼¶Ôö³¤¡£MacÍþвµÄ×ÜÊýÁ¿Í¬±ÈÔö³¤ÁË400£¥ÒÔÉÏ£¬µ«ÕâÒ»Êý×ÖÒ»¶¨Ë®Æ½ÉÏ¿ÉÄÜÊܵ½2019ÄêMalwarebytes MacÓû§ÈºÔö³¤µÄÓ°Ïì¡£¶Ôµ¥¸öÖն˶øÑÔ£¬MacÍþвÈÔÈ»±ÈWindows¸ß£¬¼¸ºõΪ2£º1¡£³ÂËß»¹Ö¸³ö¹¥»÷ÐÔ¹ã¸æÈí¼þ¡¢Ä¾ÂíºÍHackToolsÖ÷µ¼ÁËÕë¶ÔÒµÎñ¶ËµãµÄÈ«ÇòÍþв£¬±ÈÈ¥ÄêͬÆÚÔö³¤ÁË13£¥¡£¹¥»÷ÆóÒµµÄÀÕË÷Èí¼þ»î¶¯µ½´ïÀúÊ·×î¸ßˮƽ£¬RyukºÍSodinokibiµÈ¼Ò×å·Ö±ðÔö³¤ÁË543£¥ºÍ820£¥¡£EmotetºÍTrickBotÈÔÈ»ÊÇÕë¶ÔÆóÒµµÄÖ÷ÒªÍþв֮һ¡£
ÔÎÄÁ´½Ó£º
https://blog.malwarebytes.com/reports/2020/02/malwarebytes-labs-releases-2020-state-of-malware-report/
4¡¢ÑÅÊ«À¼÷ìÔÆÊý¾Ý¿â̻¶4.4ÒÚÌõÄÚ²¿¼Ç¼
Äþ¾²Ñо¿Ô±Jeremiah Fowler·¢ÏÖÑÅÊ«À¼÷ìµÄÒ»¸öÔÆÊý¾Ý¿âδÉèÃÜÂ룬µ¼ÖÂ4.4ÒÚÌõÄÚ²¿¼Ç¼й¶£¬ÆäÖаüÂÞ´¿Îı¾µç×ÓÓʼþµØÖ·£¨°üÂÞÀ´×Ô@estee.comÓòµÄÄÚ²¿µç×ÓÓʼþµØÖ·£©ºÍCMS¡¢Öмä¼þµÄ»î¶¯ÈÕÖ¾µÈÄÚÈÝ¡£µ«¼Ç¼ÖÐûÓаüÂÞ¿Í»§µÄ¸¶¿îÊý¾Ý»òÃô¸ÐµÄÔ±¹¤ÐÅÏ¢¡£FowlerÖ¸³öÕâЩÈÕÖ¾Êý¾Ý¿ÉÒÔÓÃ×÷¸ü´óµÄÍøÂç¹¥»÷µÄÕì²ì£¬ÀýÈçÈÕÖ¾ÖаüÂÞIPµØÖ·¡¢¶Ë¿Ú¡¢Â·¾¶ºÍ´æ´¢ÐÅÏ¢£¬¿ÉÓÃÓÚÓ³É乫˾µÄÄÚ²¿ÍøÂç¡£ÑÅÊ«À¼÷ìÔÚ½Óµ½³ÂËߺóµ±Ìì¹Ø±ÕÁ˶ÔÊý¾Ý¿âµÄ·ÃÎÊ£¬µ«Ä¿Ç°Éв»Çå³þ¸ÃÊý¾Ý¿âÔÚÍøÂçÉÏ̻¶Á˶೤ʱ¼äÒÔ¼°ÊÇ·ñÒÑÔâµ½ºÚ¿Í·ÃÎÊ¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/estee-lauder-440m-records-email-network-info/152789/
5¡¢Palo Alto NetworksÐû²¼2020Äê´º¼¾ÔÆÍþв³ÂËß
Palo Alto NetworksµÄUnit 42½üÈÕÐû²¼ÁË°ëÄêÒ»´ÎµÄ¡¶ÔÆÍþв³ÂËß¡·2020Äê´º¼¾°æ¡£ÎªÁËÔÚÔÆÖÐÔ½À´Ô½¶àµØ×Ô¶¯»¯¹¹½¨Á÷³Ì£¬Ðí¶à×éÖ¯¶¼ÔÚ½ÓÄÉ»ù´¡¼Ü¹¹¼´´úÂ루IaC£©À´×ÊÖú¼ò»¯ÆäÔËÓª¡£Unit 42·ÖÎöÁ˳ÉǧÉÏÍò¸öIaCÄ£°å£¬ËûÃǵķ¢ÏÖ±íÃ÷IaCÄ£°åÖÐÓÐ199000¶à¸öDZÔÚ©¶´£¬×îÖØÒªµÄÊÇÄ¿Ç°ÓÐÁè¼Ý43£¥µÄÔÆÊý¾Ý¿âδ¼ÓÃÜ£¬¶øÇÒÖ»ÓÐ60£¥µÄÔÆ´æ´¢·þÎñÒÑÆôÓÃÈÕÖ¾¼Ç¼¡£
ÔÎÄÁ´½Ó£º
https://start.paloaltonetworks.com/unit-42-cloud-threat-report