AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2020.10.26-2020.11.01£©
2020-11-03
Ò»¡¢ Íþвͨ¸æ
Weblogic ¶à¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-14825¡¢CVE-2020-14841¡¢CVE-2020-14859……£©
¡¾Ðû²¼Ê±¼ä¡¿2020-10-28 22:00:00 GMT
¡¾¸ÅÊö¡¿
10 ÔÂ21 ÈÕ£¬AG¹«Ë¾¿Æ¼¼¼à²âµ½Oracle ¹Ù·½Ðû²¼2020 Äê10 ÔÂÒªº¦²¹¶¡¸üУ¨Critical Patch Update£©£¬ÐÞ¸´ÁË402 ¸öΣº¦Ë®Æ½²î±ðµÄÇå¾²Îó²î¡£ÆäÖаüÀ¨5 ¸öWebLogic µÄÑÏÖØÎó²î£¨CVE-2020-14825¡¢CVE-2020-14841¡¢CVE-2020-14859¡¢CVE-2020-14882¡¢CVE-2019-17267£©£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ý´Ë´ÎµÄÎó²îʵÏÖÔ¶³Ì´úÂëÖ´ÐС£CVSS ÆÀ·Ö¾ùΪ9.8£¬Ê¹ÓÃÖØÆ¯ºóµÍ¡£½¨ÒéÓû§¾¡¿ì½ÓÄɲ½·¥£¬¶ÔÉÏÊöÎó²î¾ÙÐзÀ»¤¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. »ªÎªÏò¹È¸èÌᳫ¾ªÈ˵ÄÐÂÒ»»÷£¬»÷°Ü°²×¿
¡¾¸ÅÊö¡¿
»ªÎªMate 40ÖÕÓÚÉÏÊÐÁË¡£ÔÚÃÀ¹úÏÞÖÆÎª»ªÎª×°±¸¹©µçµÄоƬ×éÉèÖÃÏÞÖÆµÄÅä¾°Ï£¬ÓÉÓÚGoogleÈÔȻȱʧ£¬ÖйúÁìÏȵÄÖÇÄÜÊÖ»úÖÆÔìÉÌÐû²¼ÁËÁíÒ»¿î¾«²ÊµÄ×°±¸£¬¸Ã×°±¸½«Æ¾Ö¤ÆäÎÞ·¨¿ØÖƵÄÒòËØÔÚÖйúÒÔÍâµØÇøÍ£ÊÛ¡£Ö»¹ÜÃÀ¹úºÚÃûµ¥ÊÇÕæÕý±£´æµÄÎÊÌ⣬µ«¹È¸èµÄËðʧÔٴγÉΪÐÂÎÅÍ·Ìõ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.forbes.com/sites/zakdoffman/2020/10/25/huawei-premium-smartphone-search-replaces-google-apple-iphone-and-samsung-galaxy-alternative/?ss=cybersecurity
2. ΢ÈíÍŶÓÒÀ¸½¾«²ÊµÄй¦Ð§ÓëZoomÕö¿ªÕ½¶·
¡¾¸ÅÊö¡¿
ÔÚÒÑÍùµÄ¼¸¸öÔÂÖУ¬Microsoft TeamsÒ»Ö± Ó¿ÏÖй¦Ð§£¬ÒÔ»÷°Ü×î´óµÄ¾ºÕùµÐÊÖZoom¡£ÕâЩ¹¦Ð§°üÀ¨Ìí¼Ó×Ô½ç˵Åä¾°ºÍÅäºÏģʽµÄÄÜÁ¦£¬ÒÔʹÊÓÆµ¾Û»áÌåÑ龡¿ÉÄÜ¿¿½üÕæÊµÉúÑÄ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.forbes.com/sites/kateoflahertyuk/2020/10/25/microsoft-teams-battles-zoom-with-superb-new-features/
3. VastaamoÍ»ÆÆ£ººÚ¿ÍÀÕË÷ÐÄÀíÖÎÁÆ»¼Õß
¡¾¸ÅÊö¡¿
¾Ý±¨µÀ£¬ÍøÂç·¸·¨·Ö×ÓÒѾÐû²¼ÁË300ÃûVastaamo»¼ÕßµÄÏêϸÐÅÏ¢-²¢ÍþвҪ¹ûÕæÆäËûÈ˵ÄÊý¾Ý£¬³ý·ÇÖ§¸¶Êê½ð¡£
¡¾²Î¿¼Á´½Ó¡¿
https://threatpost.com/vastaamo-hackers-blackmailing-therapy-patients/160536/
4. ÃÀ¹ú²ÆÎñ²¿Õ¥È¡ÆóÒµÖ§¸¶ÀÕË÷Èí¼þÊê½ð
¡¾¸ÅÊö¡¿
±¾Ô³õ£¬ÃÀ¹ú²ÆÎñ²¿Íâ¹ú×ʲú¿ØÖư칫ÊÒ£¨OFAC£©Ðû²¼×ÉÎÄÖÒÑÔ×éÖ¯²»ÒªÏòÀÕË÷Èí¼þÖ§¸¶Êê½ð£¬²¢Éù³Æ´Ë¾Ù±£´æÎ¥·´Õþ¸®¶ÔÍøÂç·¸·¨¼¯ÍÅ»ò¹ú¼ÒºÚ¿ÍÊ©¼ÓµÄ¾¼ÃÖÆ²ÃµÄÖ´·¨Î£º¦¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.aqniu.com/industry/70827.html
5. ³öÊÛÃÀ¹úÖØ´óµÄÑ¡ÃñÊý¾Ý¿â
¡¾¸ÅÊö¡¿
ƾ֤TrustwaveµÄÒ»·Ý±¨¸æ£¬ÔÚÒ»¸öÔÚÏßÂÛ̳ÉϳöÊÛÁ˶à´ï1.86ÒÚÃÀ¹úÈ˵ÄÑ¡ÃñÐÅÏ¢¡£TrustwaveµÄSpiderLabs²¿·ÖÌåÏÖ£¬ÕâЩÐÅÏ¢ÏÔÈ»À´×Ô¹«¹²×ÊÔ´ÒÔ¼°Êý¾Ý×ß©¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.inforisktoday.com/massive-us-voter-database-offered-for-sale-a-15239
6. Èë¿Ú¿ªÔ´Èí¼þ·×·×ÖÐÕУ¬¹ú²úÁ¢Òì·Ôںη½£¿
¡¾¸ÅÊö¡¿
8 Ô 13 ÈÕ£¬Docker ¸üÐÂÁË¡¶·þÎñÌõ¿î¡·²¢ÓÚµ±ÈÕÉúЧ£¬Õ¥È¡ËùÓÐÃÀ¹ú½ûÔ˹ú¼ÒºÍ±»ÁÐÈ롾ÃÀ¹ú²ÆÎñ²¿Ö¸¶¨¹úÃñÇåµ¥¡¿¡¢¡¾ÃÀ¹úÉÌÎñ²¿ÊµÌåÇåµ¥¡¿¡¾±»¾Ü¾øÈËÇåµ¥¡¿¡¢¡¾Î´ºËʵÇåµ¥¡¿ºÍ¡¾ÃÀ¹úÖݽç·ÀÀ©É¢ÖƲÃÇåµ¥¡¿£¨Í³³ÆÎª¡¾Ö¸¶¨¹úÃñÇåµ¥¡¿£©µÄСÎÒ˽¼Ò»òʵÌåʹÓôøÓи÷þÎñÐÒéÁ´½ÓµÄ Docker ÍøÕ¾ÒÔ¼°ËùÓÐÏà¹ØÍøÕ¾¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.aqniu.com/vendor/70873.html
7. 1.6ÒÚСĿµÄ£ººÚ¿Í´ÓHarvest FinanceÇÔÈ¡¼ÛÖµ1.6ÒÚµÄÊý×ÖÇ®±Ò
¡¾¸ÅÊö¡¿
10ÔÂ26ÈÕ£¬ºÚ¿Í´ÓDeFi ÍÚ¿óÏîÄ¿ Harvest.financeÇÔÈ¡Á˼ÛÖµ2400ÍòÃÀÔªµÄÊý×ÖÇ®±Ò£¬Ëæºó¹«Ë¾ÖÎÀí²ãÔÚ¹«Ë¾¹Ù·½ÍÆÌغÍDiscord È·ÈÏÁ˱»ºÚµÄÊÂʵ¡£Æ¾Ö¤¹Ù·½Ðû²¼µÄÐÂÎÅ£¬ºÚ¿ÍÔÚHarvest.finance ÏîÄ¿ÖÐͶÈëÁË´ó×ÚµÄÊý×ÖÇ®±Ò×ʲú£¬È»ºóʹÓÃÊý×ÖÇ®±ÒÎó²îʹÓý²Æ½Ì¨×ʽ𲻷¨×ªÒƵ½ÆäÇ®°üÖС£ºÚ¿Í×ܹ²ÇÔÈ¡Á˼ÛÖµ2400ÍòÃÀÔªµÄÊý×ÖÇ®±Ò£¬ÆäÖаüÀ¨¼ÛÖµ1300ÍòÃÀÔªµÄUSD Coin (USDC)ºÍ¼ÛÖµ1100ÍòÃÀÔªµÄTether (USDT)¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.4hou.com/posts/wZWz
8. ÎʵÀлù½¨£¬´ó¿§Ö¸µã2021ÔÆÇå¾²Ç÷ÊÆÐ¶¯Ïò
¡¾¸ÅÊö¡¿
10ÔÂ26ÈÕ£¬ÌÚѶÇ徲͎áInfoQÅäºÏ¾ÙÐеÄÔÆÇå¾²Ç÷ÊÆ×êÑлᣬ»ã¾ÛÖйúÐÅϢͨѶÑо¿ÔºÔÆ´óËùÔÆÅÌË㲿¸±Ö÷ÈγÂÒÙÁ¦¡¢ÌÚÑ¶ÔÆÇå¾²×Ü˾Àí¶Ö¾Ç¿¡¢ÌÚÑ¶ÔÆÇå¾²¸±×Ü˾ÀíÀî±õ¡¢ÆÕ»ªÓÀµÀÖйúÇøÐÅÏ¢Çå¾²ÓëÒþ˽±£»¤ºÏ×ÊÈËÍò±ò¡¢ÊýÊÀ×ÉѯÊ×´´ÈËÀîÉÙÅôµÈÀ´×Ô¿ÆÑÐÔºËù¡¢ÆÀ²â»ú¹¹ºÍÒ»Ïß³§É̵Äר¼Ò£¬Î§ÈƓлù½¨¿ìËÙÉú³¤£¬½«ÃæÁÙÄÄЩеÄÇå¾²ÌôÕ½”ΪÖ÷Ì⣬¹²»°ÔÆÉÏÇ徲δÀ´Ç÷ÊÆ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.freebuf.com/articles/neopoints/253411.html
9. ÍþвÆÀ¹À£ºRyuk RansomwareºÍTrickbotÕë¶ÔÃÀ¹úÒ½ÁƱ£½¡ºÍ¹«¹²ÎÀÉúÁìÓò
¡¾¸ÅÊö¡¿
2020Äê10ÔÂ28ÈÕ£¬ÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©£¬Áª°îÊÓ²ì¾Ö£¨FBI£©ºÍÎÀÉúÓ빫¹²·þÎñ²¿£¨HHS£©Ðû²¼ÁËÍŽáÍøÂçÇå¾²¾¯±¨£¬ÄÚÈÝÉæ¼°¶ÔÃÀ¹úÈÕÒæÑÏÖØµÄÍøÂçÇå¾²Íþв¡£ÍþвÔËÓªÉ̶ÔÒÔÒ½ÁƱ£½¡ºÍ¹«¹²ÎÀÉú²¿·ÖΪĿµÄµÄÐËȤÈÕÒæÅ¨ÖØ£¬ÓпÉÄÜÆÆËðÒ½ÁƱ£½¡·þÎñºÍÔËÓª¡£ÊӲ쵽µÄÔ˶¯°üÀ¨Ê¹ÓÃTrickbot¶ñÒâÈí¼þ£¬ÕâÊÇÒ»ÖÖÖÚËùÖÜÖªµÄÐÅÏ¢ÇÔÈ¡Õߣ¬¿ÉÄܵ¼ÖÂ×°ÖÃÆäËû¶ñÒâÎļþ£¬°üÀ¨RyukÀÕË÷Èí¼þ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://unit42.paloaltonetworks.com/ryuk-ransomware/

AG¹«Ë¾ÔÆ







