Agari°ä²¼BECÔÚÈ«ÇòÁìÓòÄÚÉ¢²¼ºÍÇ÷ÏòµÄ·ÖÎö»ã±¨ £»Google×êÑÐÈËÔ±Åû¶LinuxÄÚºËÖÐBleedingTooth·ì϶

°ä²¼¹¦·ò 2020-10-15
1.Agari°ä²¼BECÔÚÈ«ÇòÁìÓòÄÚÉ¢²¼ºÍÇ÷ÏòµÄ·ÖÎö»ã±¨


1.jpg


AgariÍøÂçµý±¨²¿£¨ACID£©°ä²¼ÁËBECÔÚÈ«ÇòÁìÓòÄÚÉ¢²¼ºÍÇ÷ÏòµÄ·ÖÎö»ã±¨£¬ÒÔ¸üºÃµØÏàʶBEC¹¥»÷»î¶¯¡£»ã±¨Ô̺¬ÁË2019Äê5ÔÂÖÁ2020Äê7ÔÂÖ®¼äµÄ9000ÂŴηÀÓù»î¶¯µÄÊý¾Ý£¬·¢ÏÖÓÐ60£¥µÄ¹¥»÷ÕßÀ´×Ô·ÇÖÞµÄ11¸ö¹ú¶È£¬ÆäÖÐ83£¥Î»ÓÚÄáÈÕÀûÑÇ¡£½ü30£¥µÄ¹¥»÷ÕßÀ´×ÔÃÀÖÞ£¬ÆäÖеÄ89£¥À´×ÔÃÀ¹ú£¬²¢ÇÒ¹¥»÷ÕßÖØÒªÜöÝÍÔÚһЩ¶àÊý»á£¬Ô̺¬ÑÇÌØÀ¼´ó¡¢Å¦Ô¼¡¢ÂåÉ¼í¶¡¢ÐÝ˹¶ØºÍÂõ°¢ÃÜ¡£


Ô­ÎÄÁ´½Ó£º

https://www.agari.com/email-security-blog/business-email-compromise-geography/


2.Google×êÑÐÈËÔ±Åû¶LinuxÄÚºËÖÐBleedingTooth·ì϶


2.jpg


¹È¸è°²È«×êÑÐÈËÔ±Andy NguyenÔÚLinuxÄÚºËÖз¢ÏÖÁËÀ¶ÑÀ·ì϶£¬³ÆÎªBleedingTooth£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔËÐÐËÁÒâ´úÂë»ò½Ó¼ûÃô¸ÐÐÅÏ¢¡£¸Ã·ì϶±»×·×ÙΪCVE-2020-12351¡¢CVE-2020-12352ºÍCVE-2020-24490¡£ÔÚÊܺ¦ÕßÀ¶ÑÀÁìÓòÄÚ£¬Ô¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËÍÒ»¸ö¶ñÒâµÄl2cap°üÀ´´¥·¢¸Ã·ì϶£¬¿Éµ¼Ö»ؾø·þÎñ£¬ÉõÖÁʹÓÃÄÚºËȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£²¢ÇÒÕâÊÇÒ»¸öÁãµã»÷·ì϶£¬¼´ÎÞÐèÓëÓû§½»»¥¼´¿ÉÀûÓá£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/109500/hacking/bluetooth-bleedingtooth-vulnerabilities.html


3.Hindotech HK1»ú¶¥ºÐ´æÔÚÌáȨ·ì϶£¬¿ÉÓÃÀ´ÇÔÈ¡Êý¾Ý


3.png


×êÑÐÈËÔ±·¢ÏÖHindotech HK1»ú¶¥ºÐ´æÔÚÌáȨ·ì϶£¬¿ÉÓÃÀ´ÇÔÈ¡Êý¾Ý¡£¸Ã·ì϶ԴÓÚ½Ó¼û½ÚÔì²»µ±£¬³ö¸ñÊǵ±Í¨¹ý´®¿Ú(UART)Ïνӵ½É豸ʱ£¬»òÕßµ±×÷Ϊ·ÇÌØÈ¨Óû§Ê¹ÓÃAndroidµ÷ÊÔÇŽÓ(adb)ʱ£¬ÔÊÐí±¾µØÎÞÌØÈ¨Óû§Éý¼¶ÎªrootÓû§¡£¹¥»÷Õ߳ɹ¦µÄÀûÓø÷ì϶¿ÉÇÔÈ¡Éç½»ÍøÂçÕÊ»§ÁîÅÆ¡¢Wi-FiÃÜÂë¡¢Cookie¡¢Òѱ£ÁôµÄÃÜÂë¡¢Óû§µØÎ»Êý¾Ý¡¢ÐÂÎź¹Çà¼Í¼¡¢µç×ÓÓʼþºÍÁªÏµÈ˵È¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/authentication-bug-android-smart-tv-data-theft/160025/


4.΢Èí°ä²¼10Ô·ÝÖܶþ²¹¶¡£¬×ܼƽ¨¸´87¸ö°²È«·ì϶


4.png


΢Èí°ä²¼10Ô·ÝÖܶþ²¹¶¡£¬×ܼƽ¨¸´87¸ö°²È«·ì϶¡£Õâ´Î¸üÐÂÖн¨¸´ÁË6¸öÒѱ»¹«¿ªµÄ·ì϶£¬Ô̺¬WindowsÄÚºËÐÅϢй¶·ì϶£¨CVE-2020-16938£©¡¢Windows Storage VSPÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶£¨CVE-2020-16885£©¡¢WindowsÄÚºËÐÅϢй¶·ì϶£¨CVE-2020-16901£©¡¢Windows×°Ö÷¨Ê½ÌØÈ¨ÌáÉý·ì϶£¨CVE-2020-16908£©¡¢WindowsÃýÎó»ã±¨ÌØÈ¨ÌáÉý·ì϶£¨CVE-2020-16909£©ºÍ.NET FrameworkÐÅϢй¶·ì϶£¨CVE-2020-16937£©


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-october-2020-patch-tuesday-fixes-87-security-bugs/


5.ŲÍþµ±¾Ö³ÆÆä8ÔÂÔâµ½µÄÍøÂç¹¥»÷Óë¶íÂÞ˹ºÚ¿ÍÓйØ


5.png


ŲÍþµ±¾Ö³Æ8ÔÂ·ÝÆäÒé»á£¨Stortinget£©µç×ÓÓʼþϵͳÔâµ½µÄÍøÂç¹¥»÷Óë¶íÂÞ˹ºÚ¿ÍÓйØ¡£StortingÓÚ8ÔÂ24ÈÕ°ä·¢Æäµç×ÓÓʼþϵͳ²úÉúÊý¾Ýй¶£¬¸ÃÊÂÎñÓ°ÏìÁ˸ùúÖÐÐĵ³ºÍ¹¤µ³µÄ´ú±í¼°³ÉÔ±¡£Å²Íþ±í½»²¿³¤Ine EriksenS?reideÓÚ10ÔÂ13ÈÕ°µÊ¾£¬¶íÂÞ˹ÊÇÕâ´ÎÍøÂç¹¥»÷µÄÄ»ºóºÚÊÖ¡£Ëæºó£¬Æ¾¾ÝÐÂÎÅÉçTASSµÄ±¨Â·£¬¶íÂÞ˹Õýʽ·ñ¶¨Ö¸¿Ø£¬³ÆÆäûÓÐÖ¤¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/norway-says-russia-behind-cyber-attack-parliament


6.¹ú¼ÊÂÉËùSeyfarthÔâÀÕË÷Èí¼þ¹¥»÷£¬ÓʼþϵÍÂäÙʱ¹Ø¹Ø


6.png


¹ú¼ÊÂÉËùSeyfarth°ä·¢ÆäÓÚÖÜÄ©Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬ÓʼþϵÍÂäÙʱ¹Ø¹Ø¡£¸ÃÊÂÎñ²úÉúÔÚÉÏÖÜÁù£¬SeyfarthÔ޺ܶàÆäËû¹«Ë¾Ò²Í¬Ê±Ôâµ½Á˹¥»÷¡£¸Ã¹«Ë¾µÄ¶à¸öϵͳ±»¼ÓÃÜ£¬×÷ΪԤ·À´ëÊ©£¬Æä¹Ø¹ØÁ˱»¼ÓÃÜÍÆËã»ú£¬Ô̺¬µç×ÓÓʼþϵͳ¡£Ä¿Ç°Éв»Ã÷ÏÔÕâ´Î¹¥»÷µÄ·çÏÕˮƽ£¬µ«ÊÇSeyfarth³ÆÃ»Óпͻ§»ò¹«Ë¾Êý¾Ýй¶¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/international-law-firm-seyfarth-discloses-ransomware-attack/