ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ42ÖÜ

Ðû²¼Ê±¼ä 2020-10-19

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2020Äê10ÔÂ12ÈÕÖÁ10ÔÂ18ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´62¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe Flash Player¿ÕÖ¸ÕëÒýÓÃÔ¶³Ì´úÂëÖ´ÐЩ¶´£»Microsoft Windows Hyper-V CVE-2020-1047ȨÏÞÌáÉý©¶´£»SAP Solution Manager OSÃüÁî×¢È멶´£»Microhard Bullet-LTE PingÃüÁî×¢Èë´úÂëÖ´ÐЩ¶´£»Veritas APTAREÊÚȨ¼ì²é´úÂëÖ´ÐЩ¶´ ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇBlackBerryÐû²¼¹ØÓÚBAHAMUT×éÖ¯µÄ·ÖÎö³ÂËߣ»LumuÐû²¼2020Äê¶ÈÀÕË÷Èí¼þÓ°Ïì·ÖÎöµÄÐÅϢͼ£»AdobeÐÞ¸´Flash PlayerÖеÄÔ¶³ÌÖ´ÐдúÂ멶´£»AgariÐû²¼BECÔÚÈ«Çò·¶Î§ÄÚÂþÑܺÍÇ÷ÊƵķÖÎö³ÂËߣ»CNSAÐû²¼¡¶2020ÖйúÍøÂçÊÓÌýÉú³¤Ñо¿³ÂËß¡· ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖÐ ¡£


ÖØÒªÄþ¾²Â©¶´Áбí


1.Adobe Flash Player¿ÕÖ¸ÕëÒýÓÃÔ¶³Ì´úÂëÖ´ÐЩ¶´


Adobe Flash Player´¦ÖÃSWF´æÔÚ¿ÕÖ¸ÕëÒýÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÕßÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë ¡£

https://helpx.adobe.com/security/products/flash-player/apsb20-58.html


2.Microsoft Windows Hyper-V CVE-2020-1047ȨÏÞÌáÉý©¶´


Microsoft Windows Hyper-V´¦ÖÃÄڴ湤¾ß´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉÌáÉýȨÏÞ ¡£

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2020-1047


3.SAP Solution Manager OSÃüÁî×¢È멶´


SAP Solution ManagerµÄCA Introscope Enterprise Manager´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâOSÃüÁî ¡£

https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=558632196


4.Microhard Bullet-LTE PingÃüÁî×¢Èë´úÂëÖ´ÐЩ¶´


Microhard Bullet-LTE tools.sh´¦ÖÃping²ÎÊý´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâÃüÁî ¡£

https://www.zerodayinitiative.com/advisories/ZDI-20-1205/


5.Veritas APTAREÊÚȨ¼ì²é´úÂëÖ´ÐЩ¶´


Veritas APTAREÊÚȨ¼ì²é´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë ¡£


https://www.veritas.com/content/support/en_US/security/VTS20-006#issue1


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢BlackBerryÐû²¼¹ØÓÚBAHAMUT×éÖ¯µÄ·ÖÎö³ÂËß


1.jpg


BlackBerryÐû²¼Á˹ØÓÚBAHAMUTÍøÂç¼äµý×éÖ¯µÄ·ÖÎö³ÂËߣ¬·¢ÏÖÆä¶ÔÕþ¸®¹ÙÔ±ºÍÖ÷ÒªÐÐÒµÌᳫÁË´óÁ¿¸ß¶ÈÅÓ´óµÄ¹¥»÷ ¡£Ñо¿±íÃ÷£¬¸ÃÍÅ»ïµÄ»î¶¯·¶Î§±ÈÒÔÇ°ÈÏΪµÄÒª¹ã·ºµÃ¶à£¬°üÂÞÁËGoogle PlayÉ̵êºÍApp StoreÖеÄÊ®¼¸¸ö¶ñÒâÓ¦Ó÷¨Ê½ ¡£´ËÍ⣬BlackBerry»¹ÈÏΪ£¬BAHAMUT¿ÉÒÔÓëÖÁÉÙÒ»Ãû0day¿ª·¢ÈËÔ±½Ó´¥£¬²¢ÀûÓÃ0day¹¥»÷¶à¸öÄ¿±ê£¬ÕâÔ¶Ô¶³¬³öÁË´ó¶àÊýÆäËûºÚ¿Í×éÖ¯µÄ¹¥»÷ˮƽ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/cyber-espionage-bahamut-staggering/


2¡¢LumuÐû²¼2020Äê¶ÈÀÕË÷Èí¼þÓ°Ïì·ÖÎöµÄÐÅϢͼ


2.jpg


LumuÐû²¼ÁËÒ»ÕÅÐÅϢͼ£¬Ïêϸ˵Ã÷ÁËÀÕË÷Èí¼þµÄ³É±¾ºÍ·¶Î§£¬ÒÔ×ÊÖúÆóÒµºâÁ¿ËûÃǵÄÊܺ¦·çÏÕ ¡£¾Ý·ÖÎö£¬½ñÄêÈ«ÇòÀÕË÷Èí¼þµÄ³É±¾Îª200ÒÚÃÀÔª£¬Æ½¾ùÿ´ÎµÄ¹¥»÷³É±¾Áè¼Ý400ÍòÃÀÔª£¬¶øÇÒÓÐ36£¥µÄÊܺ¦ÕßÖ§¸¶ÁËÊê½ð£¬ÆäÖÐ17£¥»¹Ã»ÄÜÍì»ØËûÃǵÄÊý¾Ý ¡£´ËÍ⣬ÔÚ±±ÃÀÓÐ69%µÄ¹«Ë¾³ÂËß³ÆÊܵ½ÁËÀÕË÷Èí¼þµÄÓ°Ï죬¶øÔÚÅ·ÖÞÓÐ57% ¡£Ïà½Ï¶øÑÔ£¬±±ÃÀµÄÕþ¸®»ú¹¹Êܵ½µÄ¹¥»÷×îΪÑÏÖØ£¬Æä´ÎÊÇÖÆÔìÒµºÍ½¨ÖþÒµ ¡£


Ô­ÎÄÁ´½Ó£º

https://lumu.io/resources/2020-ransomware-flashcard/


3¡¢AdobeÐÞ¸´Flash PlayerÖеÄÔ¶³ÌÖ´ÐдúÂ멶´


3.jpg


AdobeÐÞ¸´ÁËFlash PlayerÖÐÑÏÖصÄÔ¶³ÌÖ´ÐдúÂ멶´£¨³ÆΪCVE-2020-9746£© ¡£AdobeÖ¸³ö£¬ÔÚĬÈÏÇé¿öÏ£¬ºÚ¿Í¿ÉÒÔͨ¹ýÔÚÓû§·ÃÎÊÍøվʱÔÚTLS / SSLͨ±¨µÄHTTPÏìÓ¦ÖвåÈë¶ñÒâ×Ö·û´®À´ÀûÓôË©¶´ ¡£ÀÖ³ÉÀûÓôË©¶´ºó£¬¿ÉÄܵ¼ÖÂÓ¦ÓÃÍ߽⣬´Ó¶øʹ¹¥»÷Õß¿ÉÒÔÔÚ·ÃÎÊÕߵļÆËã»úÉÏÔ¶³ÌÖ´ÐÐÃüÁî ¡£ÕâЩÃüÁÔÚÓû§µÄÄþ¾²»·¾³ÖÐÖ´ÐУ¬²¢²»ÐèÒª¹ÜÀíԱȨÏÞ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-security-vulnerability-in-flash-player/


4¡¢AgariÐû²¼BECÔÚÈ«Çò·¶Î§ÄÚÂþÑܺÍÇ÷ÊƵķÖÎö³ÂËß


4.jpg


AgariÍøÂçÇ鱨²¿£¨ACID£©Ðû²¼ÁËBECÔÚÈ«Çò·¶Î§ÄÚÂþÑܺÍÇ÷ÊƵķÖÎö³ÂËߣ¬ÒÔ¸üºÃµØÁ˽âBEC¹¥»÷»î¶¯ ¡£³ÂËß°üÂÞÁË2019Äê5ÔÂÖÁ2020Äê7ÔÂÖ®¼äµÄ9000¶à´Î·ÀÓù»î¶¯µÄÊý¾Ý£¬·¢ÏÖÓÐ60£¥µÄ¹¥»÷ÕßÀ´×Ô·ÇÖÞµÄ11¸ö¹ú¼Ò£¬ÆäÖÐ83£¥Î»ÓÚÄáÈÕÀûÑÇ ¡£½ü30£¥µÄ¹¥»÷ÕßÀ´×ÔÃÀÖÞ£¬ÆäÖеÄ89£¥À´×ÔÃÀ¹ú£¬¶øÇÒ¹¥»÷ÕßÖ÷Òª¾Û¼¯ÔÚһЩ¶àÊýÊУ¬°üÂÞÑÇÌØÀ¼´ó¡¢Å¦Ô¼¡¢ÂåÉ¼í¶¡¢ÐÝ˹¶ØºÍÂõ°¢ÃÜ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.agari.com/email-security-blog/business-email-compromise-geography/


5¡¢CNSAÐû²¼¡¶2020ÖйúÍøÂçÊÓÌýÉú³¤Ñо¿³ÂËß¡·


5.jpg


10ÔÂ12ÈÕ£¬ÖйúÍøÂçÊÓÌý½ÚÄ¿·þÎñЭ»áÐû²¼¡¶2020ÖйúÍøÂçÊÓÌýÉú³¤Ñо¿³ÂËß¡·£¬Ê׶ȹûÈ»ÎÒ¹úÍøÂçÊÓÌýÓû§¹æÄ£ºÍ¹¤Òµ¹æÄ£ ¡£¸Ã³ÂËß»ùÓÚÊý¾ÝÍÚ¾ò¡¢µ÷ÑÐÒÔ¼°µÚÈý·½Êý¾Ý£¬¶Ô2019-2020ÄêµÄÍøÂçÊÓÌýÐÐÒµÏÖ×´ºÍÉú³¤Ç÷ÊƽøÐÐȨÍþ¡¢È«ÃæµÄÑÐÅÐ ¡£³ÂËßÏÔʾ£¬½ØÖÁ2020Äê6Ô£¬ÎÒ¹úÍøÂçÊÓÌýÓû§¹æÄ£´ï9.01ÒÚ£¬ 2019ÄêÍøÂçÊÓÌý¹¤Òµ¹æÄ£´ï4541.3ÒÚ ¡£ÆäÖжÌÊÓƵµÄÓû§Ê¹ÓÃÂÊ×î¸ß£¬´ï87.0%£¬Óû§¹æÄ£8.18ÒÚ£»×ÛºÏÊÓƵµÄÓû§Ê¹ÓÃÂÊΪ77.1%£¬Óû§¹æÄ£7.24ÒÚ ¡£


Ô­ÎÄÁ´½Ó£º

http://www.xinhuanet.com/info/2020-10/13/c_139436283.htm