ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ12ÖÜ

Ðû²¼Ê±¼ä 2020-03-24

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2020Äê03ÔÂ16ÈÕÖÁ22ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´77¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇInsulet Omnipod Insulin Management SystemδÊÚȨ·ÃÎÊ©¶´; Google Chrome WebGL CVE-2020-6422ÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´£»Foxit Studio Photo TIF¶ÑÒç³ö´úÂëÖ´ÐЩ¶´£»Docker DesktopÈÎÒâÎļþдÈ멶´£»Adobe ColdFusionÔ¶³ÌÎļþ°üÂÞ©¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÄþ¾²³§ÉÌÐû²¼Turla APT»ù´¡ÉèÊ©µÄ¸ú×Ù³ÂËߣ»2019Ä꿪Դ´úÂ멶´ÊýÁ¿Ê×´ÎÁè¼Ý6000¸ö£¬Ôö³¤½ü50£¥£»Intel CPUÒ×ÊÜÐÂSnoop¹¥»÷£¬¿É鶻º´æÊý¾Ý£»½ðÈÚ¹«Ë¾AdvantageºÍArgusÔÆÊý¾Ý¿âй¶425GBÊý¾Ý£»µÂ¹úÍâÂôƽ̨Lieferando.deÔâDDoS¹¥»÷µ¼Ö·þÎṉ̃»¾¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


>ÖØÒªÄþ¾²Â©¶´Áбí


1. Insulet Omnipod Insulin Management SystemδÊÚȨ·ÃÎÊ©¶´


Insulet Omnipod Insulin Management SystemµÄwireless RFͨÐÅЭÒéȱÉÙÕýÈ·µÄÑéÖ¤ÊÚȨ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÈƹýÄþ¾²ÏÞÖÆ£¬Ö´ÐжñÒâ²Ù×÷¡£

https://www.us-cert.gov/ics/advisories/icsma-20-079-01


2. Google Chrome WebGL CVE-2020-6422ÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´


Google Chrome WebGL´æÔÚÊͷźóʹÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴¹¹½¨¶ñÒâWEBÒ³£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£

https://chromereleases.googleblog.com/2020/03/stable-channel-update-for-desktop_18.html


3. Foxit Studio Photo TIF¶ÑÒç³ö´úÂëÖ´ÐЩ¶´


Foxit Studio Photo TIF½âÎö´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-20-311/


4. Docker DesktopÈÎÒâÎļþдÈ멶´

Docker Desktop´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíµ±µØ¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÁýÕÖÈÎÒâµÄDACLȨÏÞ²¢Ð´ÈëÈÎÒâÎļþ¡£

https://github.com/active-labs/Advisories/blob/master/2020/ACTIVE-2020-002.md


5. Adobe ColdFusionÔ¶³ÌÎļþ°üÂÞ©¶´


Adobe ColdFusion´æÔÚÎļþ°üÂÞ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɻñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐÈÎÒâ´úÂë¡£

https://helpx.adobe.com/security/products/coldfusion/apsb20-16.html


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢Äþ¾²³§ÉÌÐû²¼Turla APT»ù´¡ÉèÊ©µÄ¸ú×Ù³ÂËß


×ðÁú¶¶È¦ - Ϊdu¶øÉú


Turla APTÊÇÒ»¸ö³ÉÊì¡¢ÅÓ´óÇÒ¾ßÓÐÕ½ÂÔÖصãµÄÍøÂç¼äµý×éÖ¯£¬¸Ã×éÖ¯Õë¶ÔÈ«Çò¿ÆÑС¢Íâ½»ºÍ¾üÊ»ú¹¹µÄ¹¥»÷ÒÑÓÐÊ®¶àÄêµÄÀúÊ·£¬¶øÇÒÒ»Ö±ÔÚÕë¶Ô±±´óÎ÷ÑóÌõÔ¼×éÖ¯£¨NATO£©ºÍ¶ÀÁªÌ壨CIS£©¹ú¼Ò¡£Turla²»Í£¿ª·¢×Ô¼º¶ÀÕ¼µÄ¡¢ÏȽøµÄ¶ñÒâÈí¼þºÍ¹¤¾ß£¬²¢½ÓÄÉÐµĹ¥»÷ºÍ»ìÏýÒªÁ죬Insikt GroupÆÀ¹ÀÈÏΪTurlaÔÚδÀ´¼¸ÄêÄÚÈÔ½«ÊÇÒ»¸ö»îÔ¾µÄ¡¢ÏȽøµÄÍþв¡£Recorded FutureµÄÐÂÑо¿ÌṩÁËÖ÷¶¯¸ú×ÙºÍʶ±ðTurla»ù´¡¼Ü¹¹µÄÒªÁ죬Öصã¹Ø×¢¼¸ÖÖÓëTurlaÓйصĶñÒâÈí¼þÀàÐÍ£¬°üÂÞMosquitoºóÃźͽٳֵÄÒÁÀÊTwoFace ASPX Web Shell¡£


Ô­ÎÄÁ´½Ó£º

https://www.recordedfuture.com/turla-apt-infrastructure/


2¡¢2019Ä꿪Դ´úÂ멶´ÊýÁ¿Ê×´ÎÁè¼Ý6000¸ö£¬Ôö³¤½ü50£¥


×ðÁú¶¶È¦ - Ϊdu¶øÉú


ƾ¾Ý¿ªÔ´Äþ¾²ÓëºÏ¹æ¹«Ë¾WhiteSourceµÄÒ»·Ý³ÂËߣ¬È¥Ä꿪Դ´úÂëÖеÄ©¶´¼¤Ôö¡£¸Ã³ÂË߳ƣ¬2017ÄêºÍ2018Ä꿪Դ©¶´µÄÊýÁ¿Îȶ¨ÔÚ4000¶à¸ö£¬Óë2017Äê֮ǰ´ÓδͻÆÆ2000¸öµÄÊý×ÖÏà±È£¬Â©¶´ÊýÁ¿Ôö¼ÓÁËÒ»±¶ÒÔÉÏ¡£È»ºóÔÚ2019Ä꣬¿ªÔ´Â©¶´ÊýÁ¿ÔÙ´Îì­Éý£¬Ê×´ÎÁè¼Ý6000¸ö£¬Õâ´ú±íÁ˽ü50£¥µÄÔö³¤¡£µ½Ä¿Ç°ÎªÖ¹¿ªÔ´Â©¶´ÖÐ×î³£¼ûµÄÀàÐÍÊÇ¿çÕ¾µã½Å±¾£¨XSS£©£¬¸ÃÀàÐͼ¸ºõÕ¼ËùÓЩ¶´µÄËÄ·ÖÖ®Ò»£¬Æä´ÎÊÇÊäÈëÑéÖ¤²»ÕýÈ·¡¢»º³åÇø´íÎó¡¢Ô½½ç¶ÁÈ¡ºÍÐÅϢй¶¡£


Ô­ÎÄÁ´½Ó£º

https://nakedsecurity.sophos.com/2020/03/16/open-source-bugs-have-soared-in-the-past-year/


3¡¢Intel CPUÒ×ÊÜÐÂSnoop¹¥»÷£¬¿É鶻º´æÊý¾Ý


×ðÁú¶¶È¦ - Ϊdu¶øÉú


Intel CPUÈÝÒ×Êܵ½Ðµġ°Snoop¡±¹¥»÷Ó°Ï죬¸Ã¹¥»÷¿ÉÄÜ»áй©CPUÄÚ²¿´æ´¢Æ÷£¨»º´æ£©ÖеÄÊý¾Ý¡£IntelÌåÏÖ2018Äê8ÔÂÕë¶ÔForeshadow£¨L1TF£©Â©¶´Ðû²¼µÄ²¹¶¡Ò²ÊÊÓÃÓÚ´Ëй¥»÷¡£AWSÈí¼þ¹¤³ÌʦPawel Wieczorkiewicz·¢ÏÖ²¢³ÂËßÁ˴˹¥»÷ÒªÁ죬¸Ã¹¥»÷±»ÃèÊöΪ¡°Snoop¸¨ÖúL1Êý¾ÝÊÕÂÞ¡±£¬»òÖ»ÊÇ¡°Snoop¡±£¨CVE-2020-0550£©¡£ÔÚ¼¼Êõ²ãÃæÉÏ£¬ÐµÄSnoop¹¥»÷ÀûÓÃÁ˶༶»º´æ¡¢»º´æÒ»ÖÂÐÔºÍ×ÜÏß¼àÌýµÈCPU»úÖÆ¡£IntelÁгöÁËÒ×Êܹ¥»÷µÄCPUÁбí£¬¸ÃÁбíÖаüÂÞCoreºÍXeon´¦ÖÃÆ÷µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/intel-cpus-vulnerable-to-new-snoop-attack/


4¡¢½ðÈÚ¹«Ë¾AdvantageºÍArgusÔÆÊý¾Ý¿âй¶425GBÊý¾Ý


×ðÁú¶¶È¦ - Ϊdu¶øÉú


vpnMentorÑо¿ÈËÔ±·¢ÏÖÒ»¸öÊôÓÚ½ðÈÚ¹«Ë¾Advantage Capital FundingºÍArgus Capital FundingµÄ¿É¹ûÈ»·ÃÎʵÄÊý¾Ý¿âй¶ÁË425GBÃô¸ÐÎļþ¡£¸ÃÊý¾Ý¿âÓëÕâÁ½¸ö¹«Ë¾¿ª·¢µÄMCA WizardÓ¦ÓÃÓйØ£¬¸ÃÓ¦ÓÃÏÖÔÚÒѲ»ÔÙÔÚ¹Ù·½Ó¦ÓÃÉ̵êÖÐÌṩ¡£vpnMentorÊ×´ÎÔÚ2019Äê12Ô·¢ÏÖÁ˸ÃÊý¾Ý¿â£¬Êý¾Ý¿âÖаüÂÞÀ´×ÔAdvantageºÍArgusµÄ˽ÈËÖ´·¨ºÍ²ÆÕþÎļþ£¬°üÂÞÐÅÓóÂËß¡¢ÒøÐжÔÕʵ¥¡¢ºÏͬ¡¢Ö´·¨Îļþ¡¢¼ÝʻִÕÕ¸±±¾¡¢¹ºÖö©µ¥ºÍÊվݡ¢ÄÉË°É걨±í¡¢Éç»á±£ÏÕÐÅÏ¢ÒÔ¼°½»Ò׳ÂËß¡£ÕâЩ¼Ç¼²»½öÓëAdvantageºÍArgusÓйØ£¬»¹Ó°ÏìÁËËûÃǵĿͻ§¡¢³Ð°üÉÌ¡¢Ô±¹¤ºÍºÏ×÷»ï°é¡£vpnMentorʵÑéÓëAdvantageºÍArgusÁªÏµ£¬µ«²¢Î´µÃµ½»Ø¸´£¬Ñо¿ÈËÔ±×îÖÕÖ±½ÓÓëAWSÁªÏµ£¬¸ÃÊý¾Ý¿âÓÚ2020Äê1ÔÂ9ÈչرÕ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/financial-apps-leak-425gb-in-company-data-through-open-database/


5¡¢µÂ¹úÍâÂôƽ̨Lieferando.deÔâDDoS¹¥»÷µ¼Ö·þÎṉ̃»¾


×ðÁú¶¶È¦ - Ϊdu¶øÉú


µÂ¹úÍâÂôƽ̨Lieferando.deÔâDDoS¹¥»÷µ¼Ö·þÎṉ̃»¾¡£¸Ãƽ̨¹ØÁªÁË1.5Íò¶à¼ÒµÂ¹ú²Í¹Ý£¬ÓÉÓÚCOVID-19ÆÚ¼äµÂ¹ú¶Ô²ÍÌü½øÐÐÁËÑϸñµÄÏÞÖÆ£¬ÀýÈçÏÞÖÆ¿ÍÈ˵ÄÈËÊý¡¢Ôö´ó×À×ÓÖ®¼äµÄ¾àÀë¡¢ÔÚÏÂÎç6µãÖÁÔçÉÏ6µãÖ®¼ä±ØÐë¹ØÃŵÈ£¬Òò´ËÕâ´ÎDDoS¹¥»÷Ó°ÏìÁË´óÁ¿Ñ¡ÔñʹÓÃÍâÂô¶©²ÍµÄÓû§¡£Ò»Ð©¿Í»§Ëß¿à³Æ¾¡¹Ü¸Ãƽ̨µÄϵͳÒò¹¥»÷¶ø̱»¾£¬µ«¸Ã·þÎñÈÔ½ÓÊÜж©µ¥£¬Ö»ÊÇûÓжÔÆä½øÐд¦Ö᣸Ãƽ̨³Æ½«ÍË»¹ÒÑÖ§¸¶ÇÒδ½»¸¶µÄ¶©µ¥£¬µ«¿Í»§±ØÐëͨ¹ýµç×ÓÓʼþÓëËûÃÇÁªÏµ¡£¾Ý³Æ¹¥»÷ÕßÒªÇó2±ÈÌرң¨Ô¼ºÏ1.1ÍòÃÀÔª£©µÄÊê½ðÀ´Í£Ö¹¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/food-delivery-service-in-germany-under-ddos-attack/