ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ16ÖÜ
°ä²¼¹¦·ò 2020-04-20> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2020Äê04ÔÂ13ÈÕÖÁ19ÈÕ¹²ÊÕ¼°²È«·ì϶72¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇGoogle Chrome speech recognizer´úÂëÖ´Ðзì϶; VeeamOne Agent PerformHandshake´úÂëÖ´Ðзì϶£»Apache Heron·´ÐòÁл¯´úÂëÖ´Ðзì϶£»Cisco UCS Director ApplianceStorageUtil unzipĿ¼±éÀú´úÂëÖ´Ðзì϶£»Triangle MicroWorks SCADA Data Gateway DNP3 GET_FILE_INFOÕ»Òç¶Âí½Å¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǰͻù˹̹1.15ÒÚÒÆ¶¯Óû§Êý¾ÝÔÚ°µÍøÏúÊÛ£»µ¤ÂóË®±ÃÔì×÷ÉÌDESMIÔâÍøÂç¹¥»÷£¬ÏµÍ³ÈÔδ¸´Ô£»Oracle°ä²¼4Ô³ÁÒª²¹¶¡¸üУ¬½¨¸´397¸ö·ì϶£»Ó¢Ìضû°ä²¼4Ô°²È«¸üУ¬½¨¸´¶à¿î²úÆ·ÖеÄ9¸ö·ì϶£»EA SportsÔâ´ó¹æÄ£DDoS¹¥»÷£¬È«Çò·þÎñÖжϡ£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
>³ÁÒª°²È«·ì϶Áбí
1. Google Chrome speech recognizer´úÂëÖ´Ðзì϶
Google Chrome speech recognizer´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_15.html
2. Veeam One Agent PerformHandshake´úÂëÖ´Ðзì϶
Veeam One Agent PerformHandshake²½Öè´æÔÚ·´ÐòÁл¯·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-20-545/
3. Apache Heron·´ÐòÁл¯´úÂëÖ´Ðзì϶
Apache Heron´æÔÚ·´ÐòÁл¯·ì϶£¬ÔÊÐíͨ¹ýÑéÖ¤µÄÖÎÀíÔ±Óû§ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://lists.apache.org/thread.html/r16dd39f4180e4443ef4ca774a3a5a3d7ac69f91812c183ed2a99e959%40%3Cdev.heron.apache.org%3E
4. Cisco UCS Director ApplianceStorageUtil unzipĿ¼±éÀú´úÂëÖ´Ðзì϶
Cisco UCS Director ApplianceStorageUtil unzip´¦ÖÃÎļþ²Ù×÷´æÔÚĿ¼±éÀú·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»rootÕË»§¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-20-539/
5. Triangle MicroWorks SCADA Data Gateway DNP3 GET_FILE_INFOÕ»Òç¶Âí½Å
Triangle MicroWorks SCADA Data Gateway´¦ÖÃDNP3 GET_FILE_INFO´æÔÚÕ»Òç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-20-547
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢°Í»ù˹̹1.15ÒÚÒÆ¶¯Óû§Êý¾ÝÔÚ°µÍøÏúÊÛ
°Í»ù˹̹°²È«³§ÉÌRewterz·¢ÏÖ£¬Ä¿Ç°ÓÐ1.15ÒÚ°Í»ùË¹Ì¹ÒÆ¶¯Óû§µÄÊý¾ÝÔÚ°µÍøÂÛ̳ÏúÊÛ£¬¼ÛֵΪ300 BTC£¨Ô¼ºÏ210ÍòÃÀÔª£©¡£ÕâЩÊý¾ÝÔ̺¬Óû§µÄ¾ßÌåÓ×ÎÒÐÅÏ¢£¬ÀýÈçÐÕÃû¡¢ÆëÈ«µØÖ·¡¢ÊÖ»úºÅÂëÒÔ¼°NICºÅºÍ˰ÎñºÅÂë¡£RewterzÍþвµý±¨×¨¼ÒÒÔΪÕâЩÊý¾Ý¿ÉÄÜÊÇÒ»´Î»òÂÅ´Îй¶µÄÁ˾֣¬Ä¿Ç°»¹²»Ã÷ÏÔÊÇ·ñÓÐÈκÎÌØ¶¨µÄµçÐÅÔËÓªÉÌ»òÊÇËùÓеçÐÅÔËÓªÉ̳ÉΪÕâ´Î¹¥»÷µÄÊܺ¦Õß¡£¸Ãй¶Êý¾ÝµÄ¹æÄ£Òý·¢Á˶ԵçÐŹ«Ë¾Êý¾Ý°²È«ÐÔºÍÒþÖÔÐÔµÄÓÇÓô¡£
ÔÎÄÁ´½Ó£º
http://www.rewterz.com/articles/115-million-pakistani-mobile-users-data-go-on-sale-on-dark-web
2¡¢µ¤ÂóË®±ÃÔì×÷ÉÌDESMIÔâÍøÂç¹¥»÷£¬ÏµÍ³ÈÔδ¸´Ô
µ¤ÂóË®±ÃÔì×÷ÉÌDESMIÔâµ½ÍøÂç¹¥»÷£¬¸Ã¹¥»÷ÊÂÎñ²úÉúÔÚÉÏÖÜËĵÄÍíÉÏ£¬Ôâµ½¹¥»÷ºó¹«Ë¾µÄËùÓÐϵͳ¾ù±»¹Ø¹Ø¡£Æ¾¾Ý¸Ã¹«Ë¾ÔÚ¹ÙÍøÉϰ䲼µÄÖҸ棬¹«Ë¾µÄËùÓÐϵͳ¾ù±»¹Ø¹Ø£¬²¢ÇÒÔÚ»¹Ô¹ý³ÌÖУ¬Ê×Åú²¿ÃÅϵͳ½«ÔÚ¼¸ÌìÄÚÆô¶¯²¢ÔËÐУ¬ÆäÓàµÄϵͳ½«ÔÚ¼¸ÖÜÖ®ÄÚÔËÐС£Ä¿Ç°µ÷²éÈÔÔÚ½øÐÐÖ®ÖУ¬Éв»Ã÷ÏÔ¹¥»÷µÄˮƽ£¬DESMIÒѽ«ÊÂÎñ»ã±¨¸øµ¤Â󵱾ֺ;¯Ô±¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/101495/hacking/desmi-discloses-cyber-attack.html
3¡¢Oracle°ä²¼4Ô³ÁÒª²¹¶¡¸üУ¬½¨¸´397¸ö·ì϶
OracleÔÚÆä4Ô³ÁÒª²¹¶¡¸üÐÂÖн¨¸´ÁË397¸ö·ì϶£¬ÆäÖÐOracle Database Server²úÆ·Öн¨¸´ÁË8¸ö·ì϶£»µç×ÓÉÌÎñÌ×¼þÖн¨¸´ÁË74¸ö·ì϶£¬Ô̺¬70¸öÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓõķì϶£»OracleÈÚºÏÖÐÑë¼þÖн¨¸´ÁË51¸ö·ì϶£¬ÆäÖÐ44¸öÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓã»Java SEÖн¨¸´ÁË15¸ö·ì϶£¬ËùÓзì϶¾ùÄܹ»ÔÚ²»½øÐÐÉí·ÝÑéÖ¤µÄÇé¿öϽøÐÐÔ¶³ÌÀûÓã»MySQLÖн¨¸´ÁË45¸ö·ì϶£¬ÆäÖÐ9¸ö·ì϶ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓá£ÆëÈ«·ì϶ÁбíÇë²Î¿¼ÒÔϹٷ½Á´½Ó£¬½¨ÒéÓû§¾¡¿ìÀûÓøüС£
ÔÎÄÁ´½Ó£º
https://www.oracle.com/security-alerts/cpuapr2020.html
4¡¢Ó¢Ìضû°ä²¼4Ô°²È«¸üУ¬½¨¸´¶à¿î²úÆ·ÖеÄ9¸ö·ì϶
Ó¢ÌØ¶ûÔÚ4Ô²¹¶¡¸üÐÂÖн¨¸´ÁË9¸ö·ì϶£¬ÕâЩ·ì϶¾ùΪÖиßΣ·ì϶£¬Ó°Ïì¶à¸öÈí¼þ¡¢¹Ì¼þ¼°Æ½Ì¨¡£Ó¢Ìضû½¨¸´ÁËPROSet/ÎÞÏßWiFi²úÆ·ÔÚWindows 10ÉϵÄÁ½¸ö·ì϶-¾¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓÉÓÚ²»°²È«µÄ¼Ì³ÐȨÏÞ¶ø¿ÉÄÜͨ¹ý±¾µØ½Ó¼û½øÐÐÌØÈ¨Éý¼¶£¨CVE-2020-0557£©£»ÓÉÓÚÄÚºËÇý¶¯·¨Ê½ÖеĻº³åÇøÏ޶Ȳ»µ±£¬ÎÞÌØÈ¨µÄ¹¥»÷Õß¿ÉÄÜͨ¹ýÏàÁÚÍøÂç½Ó¼ûÀ´µ¼Ö»ؾø·þÎñ£¨CVE-2020-0558£©¡£Ó¢Ìضû»¹½¨¸´ÁËNUC mini PCµÄϵͳ¹Ì¼þÖкÍÄ£¿é»¯·þÎñÆ÷MFS2600KISPPÍÆËãÄ£¿éÖеÄÁ½¸ö·ì϶£¬Ô̺¬²»ÕýÈ·µÄ»º³åÇøÏ޶ȵ¼ÖµÄLPE·ì϶£¨CVE-2020-0600£©ºÍǰÌá²é³²»µ±µ¼ÖµÄÌáȨ·ì϶£¨CVE-2020-0578£©¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/intel-april-platform-update-fixes-high-severity-security-issues/
5¡¢EA SportsÔâ´ó¹æÄ£DDoS¹¥»÷£¬È«Çò·þÎñÖжÏ
ÓÎÏ·¹«Ë¾EA SportsÓÖÒ»´ÎÔâµ½´ó¹æÄ£µÄDDoS¹¥»÷£¬µ¼Ö¸ù«Ë¾µÄ·þÎñÆ÷ÔÚÈ«ÇòÁìÓòÄÚÍÑ»ú¡£Õâ´Î¹¥»÷²úÉúÔÚ4ÔÂ14ÈÕÏÂÎç4:19¡£Æ¾¾ÝDown DetectorµÄʵʱµØÍ¼£¬Õâ´Î¹¥»÷ÖØÒªÓ°ÏìÁËÅ·ÖÞµØÓòµÄ¿Í»§£¬µ«¼ÓÄô󡢰£¼°¡¢ÄϷǵȵصĿͻ§Ò²Êܵ½ÁË»ò¶à»òÉÙµÄÓ°Ïì¡£4ÔÂ15ÈÕÁ賿1µã25·Ö£¬EA SportsÈϿɸù«Ë¾¡°¾ÀúÁËһϵÁÐDDoS¹¥»÷¡±¡£ÔÚ°ä²¼±¾ÎÄʱ£¬EA SportsµÄ¿Í»§ÈÔÔÚ±§Ô¹·þÎñå´»ú£¬ÕâÅú×¢¸Ã¹«Ë¾ÈÔÔÚÔâ·ê¹¥»÷¡£ÖµÍ×ÌùÐĵÄÊÇ£¬±©Ñ©Ò²ÔÚ4ÔÂ14ÈÕÁ賿4µã15·Ö×óÓÒÔ⵽һϵÁÐDDoS¹¥»÷£¬µ¼ÖÂÈ«Çò·þÎñÖжϡ£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/ea-sports-down-gaming-giant-hit-by-ddos-attacks/


¾©¹«Íø°²±¸11010802024551ºÅ