΢Èí°ä²¼×î´ó¹æÄ£Öܶþ²¹¶¡½¨¸´129¸ö·ì϶£»UPnPºÍ̸Öеķì϶CallStranger£¬¿Éµ¼ÖÂÊý¾Ýй¶»òDDoS¹¥»÷

°ä²¼¹¦·ò 2020-06-10

1.΢Èí°ä²¼×î´ó¹æÄ£µÄÖܶþ²¹¶¡·¨Ê½£¬¹²½¨¸´129¸ö·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


΢ÈíÓÚ6ÔÂ9ÈÕ°ä²¼ÁË×î´ó¹æÄ£µÄÐÇÆÚ¶þ²¹¶¡·¨Ê½£¬¹²½¨¸´ÁËMicrosoft²úÆ·ÖеÄ129¸ö·ì϶¡£ÆäÖУ¬Microsoft EdgeºÍVBScriptÒýÇæÖдæÔÚÈý¸ö½ÏΪÑϳÁµÄ·ì϶£¬±ðÀëÊÇMicrosoftä¯ÀÀÆ÷ÄÚ´æ°Ü»µ·ì϶£¨CVE-2020-1219£©¡¢VBScriptÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-1216£©ºÍVBScriptÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-1216£©£¬ÕâЩ·ì϶¿É±»ÀûÓÃÀ´Ö´ÐÐÔ¶³Ì´úÂëÖ´ÐС£»¹ÓÐһЩ½ÏΪÑϳÁµÄ·ì϶¿É±»ÓÃÓÚÍøÂç´¹µö¹¥»÷ÒÔÓÕʹÓû§ÏÂÔØ¶ñÒâÎļþ£¬±ðÀëÊÇGDI +Ô¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-1248£©¡¢Windows OLEÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-1281£©¡¢ºÍLNKÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-1299£©¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2020-patch-tuesday-largest-ever-with-129-fixes/


2.UPnPºÍ̸Öеķì϶CallStranger£¬¿Éµ¼ÖÂÊý¾Ýй¶»òDDoS¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«¹¤³ÌʦYunus?adirci·¢´Ë¿ÌͨÓü´²å¼´ÓúÍ̸£¨Universal Plug and Play£¬UPnP£©ÖдæÔÚÃûΪCallStrangerµÄ·ì϶£¨CVE-2020-12695£©£¬¿ÉÄܵ¼ÖÂÊý¾Ýй¶¡¢DDoS¹¥»÷ÒÔ¼°¶ÔÉ豸ÄÚ²¿¶Ë¿ÚµÄɨÃè¡£¸Ã·ì϶¿ÉÄÜ»áÓ°ÏìËùÓÐ4ÔÂ17ÈÕ֮ǰ°æ±¾µÄUPnPÉ豸£¬Ô̺¬Windows 10ϵͳ¡¢Â·ÓÉÆ÷¡¢½ÓÈëµã¡¢´òÓ¡»ú¡¢ÓÎÏ·»ú¡¢ÃÅÁåµç»°¡¢Ã½ÌåÀûÓ÷¨Ê½ºÍÉ豸¡¢Ïà»ú¡¢µçÊÓ»úµÈ¡£¸Ã·ì϶ÊÇÓÉUPnP SUBSCRIBEº¯ÊýÖеıêÍ·Öµ»Øµ÷ÒýÆðµÄ£¬¹¥»÷ÕßÄܹ»»ú¹ØÒ»¸öº¬ÓÐÌåʽÃýÎóµÄ±êÍ·Öµ»Øµ÷µÄTCPÊý¾Ý°ü·¢Ë͵½Ô¶¶ËÉ豸£¬À´ÀûÓû¥ÁªÍøÉÏÖ§³ÖUPnPºÍ̸µÄÖÇÄÜÉ豸¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/callstranger-upnp-bug-allows-data-theft-ddos-attacks-lan-scans/


3.ÀûÓÃDigilocker´æÔÚ·ì϶£¬¿É±»ÀûÓÃÈÆ¹ýÉí·ÝÑéÖ¤


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÓÉÓ¡¶Èµç×ÓºÍIT²¿ÃÅÆ¾¾ÝÆäDigital India´òËãÌṩµÄÔÚÏß·þÎñ·¨Ê½Digilocker´æÔÚ·ì϶£¬¸Ã·ì϶¿ÉÄÜÒѾ­±»ÀûÓÃÈÆ¹ýÉí·ÝÑéÖ¤¡£°²È«×êÑÐÔ±Mohesh Mohan°µÊ¾£¬DigilockerµÄOTPÖ°Äܲ»×ãÊÚȨ£¬µ¼Ö¹¥»÷ÕßÄܹ»Í¨¹ýÌá½»ÈκÎÓÐЧÓû§µÄ¾ßÌåÐÅÏ¢½øÐÐOTPÑéÖ¤²¢µÇ¼£¬Ò²¾ÍÊÇ˵¹¥»÷ÕßÖ»Ðè֪·Óû§Aadhaar ID»òÓйصÄÊÖ»úºÅÂë»òÓû§Ãû¼´¿É½Ó¼ûÈκÎDigilockerÕÊ»§¡£5ÔÂ10ÈÕ×êÑÐÈËÔ±ÏòCERT-In»ã±¨ÁË´Ë·ì϶£¬5ÔÂ28ÈÕÓ¡¶Èµ±¾ÖÒѽ«Æä½¨¸´¡£        


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/104459/breaking-news/digilocker-critical-falw.html


4.±¾Ì﹫˾Ôâµ½ÀÕË÷Èí¼þSNAKE¹¥»÷£¬ÆäÈÕ±¾ºÍÅ·ÖÞ·Ö¹«Ë¾Êܵ½Ó°Ïì


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


±¾Ì﹫˾ÓÚ±¾ÖÜÒ»·¢ÏÖ£¬ÆäÅ·ÖÞºÍÈÕ±¾µÄ·Ö¹«Ë¾Ôâµ½ÁËÀÕË÷²¡¶¾SNAKEµÄ¹¥»÷£¬²¢µ¼ÖÂITÍøÂçÎÞ·¨Õý³£ÔËÐС£¸Ã¹«Ë¾½²»°È˰µÊ¾£¬Õâ´Î¹¥»÷²¢Î´Ó°ÏìÈÕ±¾µÄ³ö²ú»ò¾­ÏúÉ̻£¬Ò²Ã»ÓÐÓ°ÏìÆä¿Í»§¡£×êÑÐÈËÔ±¶ÔÀÕË÷²¡¶¾Ñù±¾½øÐзÖÎöºó·¢ÏÖ£¬¸ÃÀÕË÷Èí¼þÊ×ÏÈ»áÊÔͼ½âÎömds.honda.comÓò£¬ÈôÊÇûÓн«µ±¼´Í˳ö²¢²»¼ÓÃÜÈκÎÎļþ¡£Ä¿Ç°£¬¸Ã¹«Ë¾°µÊ¾ÔÚµ÷²éÊÂÎñÔ­Òò£¬²¢»Ø¾øÐ¹Â©¸ü¶àϸ½Ú¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/honda-investigates-possible-ransomware-attack-networks-impacted/


5.º«¹úÐÅÓþЭ»á°µÊ¾£¬Ô¼90ÍòÕź«¹úÐÅÓþ¿¨ÐÅÏ¢ÔÚ°µÍøÐ¹Â¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


º«¹úÐÅÓþЭ»á±¾ÖÜÒ»°µÊ¾£¬Ô¼ÓÐ90ÍòÕź«¹úÐÅÓþ¿¨ÐÅÏ¢Òѱ»Ð¹Â¶£¬²¢ÔÚ°µÍøÉϽøÐÐÊÛÂô¡£º«¹úÖÕÉó·¨Ôº×¢Ã÷£¬±»Ð¹Â¶µÄÐÅÓþ¿¨ÖÐԼĪÓÐ41ÍòÕÅÈÔÔÚʹÓÃÖУ¬Ð¹Â©µÄÐÅÏ¢Ô̺¬¿¨ºÅ¡¢ÓÐЧÆÚºÍÑéÖ¤Âë¡¢¿¨±³ÃæµÄÈýλÊý°²È«Â룬²¢²»Ô̺¬ÃÜÂë¡£º«¹úµ±¾ÖĿǰÉÐδŪÇåÕâЩÐÅÏ¢ÊÇÈôºÎй©µÄ£¬ÐÅÓþ¿¨ÒøÐÐÔò°µÊ¾»á½«ÐÅϢй¶ÎÊÌâ֪ͨÊÜÓ°ÏìµÄÓû§£¬²¢½¨ÒéËûÃǸü»»Ð¿¨¡£


Ô­ÎÄÁ´½Ó£º

https://en.yna.co.kr/view/AEN20200608011200325?&web_view=true


6.¼ÓÄôó¹«Ë¾Fitness DepotÔâµ½Magecart¹¥»÷£¬Óû§Ö§¸¶ÐÅϢй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¼ÓÄôó»î¶¯Æ÷²Ä¹«Ë¾Fitness Depot°ä·¢£¬ÉϸöÔ¹«Ë¾µÄµçÉÌÆ½Ì¨Ôâµ½¹¥»÷£¬Æä¿Í»§µÄÓ×ÎÒÐÅÏ¢ºÍÖ§¸¶ÐÅϢй¶¡£Õâ´Îй¶ÐÅÏ¢Ô̺¬¿Í»§µÄÐÕÃû¡¢µØÖ·¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂëºÍÐÅÓþ¿¨ºÅ¡£Fitness Depot°µÊ¾£¬¸Ãй¶ÊÂÎñ¿É×·Òäµ½2020Äê2ÔÂ18ÈÕ£¬ºÚ¿Í½«¶ñÒâ´úÂë×¢ÈëÍøÕ¾£¬Ê¹µÃÓû§Ò»µ©±»³Á¶¨Ïòµ½´Ë±íµ¥¾Í»áÔÚ²»ÖªÇéµÄÇé¿öϱ»¸´ÔìÐÅÏ¢¡£×êÑÐÈËÔ±·ÖÎö£¬Õâ´Î¹¥»÷ºÜ¿ÉÄÜÊÇÀ´×ÔºÚ¿Í×éÖ¯Magecart£¬ÆäÏÈÈëÇÖÁ˸ù«Ë¾µÄµçÉÌÆ½Ì¨£¬²¢½«»ùÓÚJavaScriptµÄ¶ñÒâ´úÂë×¢ÈëÆä½áÕÊÒ³Ãæ£¬×îÖÕÖ¸±êÊÇÇÔÈ¡¸Ã¹«Ë¾¿Í»§ËùÌá½»µÄËùÓи¶¿î»òÓ×ÎÒÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fitness-depot-hit-by-data-breach-after-isp-fails-to-activate-the-antivirus/