ºÚ¿ÍÔÚ°µÍø¹«¿ªwattpadµÄ2.7ÒÚÌõÓû§Êý¾Ý;ºÚ¿Í½Ù³Ö±È¶û¸Ç´ÄºÍ°Â°ÍÂíµÈÈËTwitterÕÊ»§½øÐмÓÃÜÇ®±ÒÚ¿Æ­

°ä²¼¹¦·ò 2020-07-16

1.ºÚ¿ÍÔÚ°µÍø¹«¿ªwattpadµÄ2.7ÒÚÌõÓû§Êý¾Ý


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ŀǰ£¬ºÚ¿ÍÔÚ°µÍøÃâ·Ñ¹«¿ªwattpadµÄ2.7ÒÚÌõÓû§Êý¾Ý ¡£Æð³õ£¬×Ô7ÔÂ7ÈÕÆðÍ·Shiny HuntersÔÚ°µÍøÉÏÒÔÊ®¸ö±ÈÌØ±Ò£¨³¬¹ý100,000ÃÀÔª£©µÄ¼ÛÖµÏúÊÛÕâ¸öÔ̺¬2ÒÚ¶à±Ê¼Í¼µÄWattpadÊý¾Ý¿â ¡£¸ÃÊý¾Ý¿âµÄ¼Í¼Ô̺¬Óû§Ãû¡¢Ãû³Æ¡¢¹þÏ£ÃÜÂë¡¢µç×ÓÓʼþµØÖ·ºÍͨ³£µØÀíµØÎ» ¡£Í¨¹ýÓëй¶Êý¾ÝµÄÓû§ÁªÏµ£¬Äܹ»È·ÈÏÁгöµÄÐÅÏ¢ÊÇÕýÈ·µÄ ¡£7ÔÂ14ÈÕ£¬Wattpad³ÆÆäÔÚÖÂÁ¦½¨¸´¸Ã·ì϶£¬²¢°µÊ¾¸ÃÊÂÎñ²¢Î´Ð¹Â¶ÈκβÆÕþÐÅÏ¢¡¢µç»°ºÅÂë¡¢¹ÊÊ»ò¸öÈËÐÂÎÅ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/wattpad-data-breach-exposes-account-info-for-millions-of-users/


2.ºÚ¿Í½Ù³Ö±È¶û¸Ç´ÄºÍ°Â°ÍÂíµÈÈËTwitterÕÊ»§½øÐмÓÃÜÇ®±ÒÚ¿Æ­


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


7ÔÂ15ÈÕÖÜÈý£¬ºÚ¿Í½Ù³ÖÁËÊýǧ¸öÊôÓÚ¾«Ó¢Óû§ºÍ³ÛÃû¹«Ë¾µÄ¾­¹ýÑéÖ¤µÄTwitterÕÊ»§£¬ÓÃÀ´½øÐмÓÃÜÇ®±ÒÚ¿Æ­£¬Ô̺¬±È¶û¡¤¸Ç´Ä¡¢°£Â¡¡¤Âí˹¿Ë¡¢½Ü·ò¡¤±´×ô˹¡¢Âõ¿Ë¡¤Åí²©¸ñ¡¢°ÝµÇ¡¢°Â°ÍÂí¡¢Æ»¹ûºÍÓŲ½µÈ ¡£Ö®ºó£¬ºÚ¿ÍÀûÓÃÕâЩÕË»§°ä²¼ÍÆÎÄ£¬ÓÕʹÊܺ¦Õ߲ɰì±ÈÌØ±Ò ¡£½ØÖÁÃÀ¹ú¹¦·òÖÜÈýÏÂÎç4:45£¬¸ÃµØÖ·ÒÑÊÕµ½³¬¹ý110000ÃÀÔªµÄBTC ¡£Ä¿Ç°£¬Éв»Ã÷ÏÔÕÊ»§ÊÇÈôºÎ±»½Ù³ÖµÄ£¬Twitter°µÊ¾ÆäÔÚµ÷²é²¢½â¾ö´ËÊÂÎñ ¡£


Ô­ÎÄÁ´½Ó£º

theregister.com/2020/07/15/mass_twitter_account_hacking_bitcoin/


3.Oracle°ä²¼7Ô°²È«¸üУ¬×ܼƽ¨¸´433¸ö·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Oracle¹Ù·½°ä²¼°²È«¸üУ¬×ܼƽ¨¸´ÁË433¸ö°²È«·ì϶£¬Ó°ÏìÁËOracle Weblogic¡¢Oracle SD-WAN AwareºÍOracle SD-WAN EdgeµÈ¶à¿î²úÆ· ¡£Õâ´Î¸üн¨¸´ÁËËĸöÆÀ·ÖΪ9.8µÄOracle WebLogic Server·´ÐòÁл¯·ì϶£¨CVE-2020-14625¡¢CVE-2020-14644¡¢CVE-2020-14645 ¡¢CVE-2020-14687£©£¬ÒÔ¼°Á½¸öÆÀ·ÖΪ10µÄOracle Communications Applications°²È«·ì϶£¨CVE-2020-14701¡¢CVE-2020-14606£© ¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/07/14/oracle-releases-july-2020-security-bulletin


4.Adobe°ä²¼7Ô°²È«¸üУ¬½¨¸´ËÁÒâ´úÂëÖ´Ðзì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Adobe°ä²¼Á˰²È«¸üУ¬½¨¸´ÁË13¸ö°²È«·ì϶£¬Ô̺¬Ó°ÏìÁËWindows°æ±¾µÄCreative Cloud¡¢Adobe Download ManagerºÍAdobe Media EncoderµÄ´úÂëÖ´Ðзì϶ ¡£Õâ´Î¸üÐÂÖÐÖØÒª½¨¸´ÁË4¸ö½ÏΪÑϳÁµÄ·ì϶£¬±ðÀëΪDownload ManagerÖкÅÁî×¢Èëµ¼ÖµÄËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2020-9688£©£¬Media EncoderÖÐÔ½½çдµ¼ÖµÄËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2020-9650ºÍCVE-2020-9646£©£¬ÒÔ¼°Symlink·ì϶µ¼ÖµÄËÁÒâÎļþϵͳдÈë·ì϶£¨CVE-2020-9682£© ¡£´Ë±í£¬»¹½¨¸´Á˲»°²È«µÄÎļþȨÏÞ¡¢DLLËÑË÷°¤´Î½Ù³Ö¡¢²»°²È«µÄ¿â¼ÓÔØºÍ·ûºÅÁ´½Ó·ì϶ÒÔ¼°Ô½½ç¶ÁÈ¡¶øµ¼ÖÂÌáȨ·ì϶µÈÎÊÌâ ¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/07/14/adobe-releases-security-updates-multiple-products


5.GoogleΪChrome°ä²¼°²È«¸üУ¬½¨¸´38¸ö°²È«·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


GoogleΪChrome°ä²¼°²È«¸üУ¬×ܼƽ¨¸´ÁË38¸ö°²È«·ì϶ ¡£Õâ´Î°²È«¸üÐÂÖн¨¸´µÄ½ÏΪÑϳÁµÄ·ì϶Ϊºó¶ÜÌáÈ¡Öжѻº³åÇøÒç¶Âí½Å£¨CVE-2020-6510£©¡¢ÄÚÈݰ²È«Õ½ÊõÖеIJàÐÅ·ÐÅϢй©·ì϶£¨CVE-2020-6511£©¡¢ V8ÖеÄÀàÐÍ»ìºÏ·ì϶£¨CVE-2020-6512£©¡¢PDFiumÖеĶѻº³åÇøÒç¶Âí½Å£¨CVE-2020-6513£©¡¢WebRTCÖеIJ»Êʵ±ÊµÏÖ£¨CVE-2020-6514£©¡¢±êÇ©ÌõÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2020-6515£©¡¢ CORSÖеÄÕ½ÊõÈÆ¹ý·ì϶£¨CVE-2020-6516 £©ºÍº¹Çà¼Í¼Öжѻº³åÇøÒç¶Âí½Å£¨CVE-2020-6517£© ¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/07/14/google-releases-security-updates-chrome


6.VMwareµ÷²é·¢ÏÖ£¬2020ÄêÍøÂç¹¥»÷¸´ÔÓÐÔ´ó·ùÔö³¤


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


VMwareµ÷²é·¢ÏÖ£¬2020ÄêÍøÂç¹¥»÷µÄÊýÁ¿ºÍ¸´ÔÓÐÔ¾ù´ó·ùÔö³¤ ¡£µ÷²é·¢ÏÖ£¬ÓÐ92£¥µÄÈ˰µÊ¾ÔÚ´Óǰ12¸öÔÂÖй¥»÷Á¿ÓÐËùÔö³¤£¬97£¥µÄÈ˰µÊ¾ËûÃÇÔÚ´Óǰ12¸öÔÂÖÐÔâ·êÁ˹¥»÷£¬¾ùÔÈÿ¸ö×éÖ¯¾­ÀúÁË2.70´Î¹¥»÷£»ÓÐ84£¥µÄÈ˰µÊ¾¹¥»÷±äµÃÔ½·¢¸´ÔÓ£¬95£¥µÄÈ˰µÊ¾ËûÃÇ´òËãÔÚÃ÷ÄêÔö³¤ÍøÂç·ÀÓùÖ§³ö ¡£´Ë±í£¬²Ù×÷ϵͳ·ì϶ÊÇÍøÂç¹¥»÷ÖеÄÖØÒªÔ­Òò£¬Æä´ÎÊÇWebÀûÓ÷¨Ê½¹¥»÷ºÍÀÕË÷Èí¼þ ¡£ÃÀ¹úÆóÒµÒѾ­¾ùÔÈʹÓó¬¹ý¾ÅÖÖ·ÖÆçµÄÍøÂ簲ȫ¹¤¾ßÀ´±£»¤ËûÃǵÄϵͳ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/07/15/2020-increased-attack-sophistication/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+HelpNetSecurity+%28Help+Net+Security%29