ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ38ÖÜ
°ä²¼¹¦·ò 2020-09-21> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2020Äê09ÔÂ14ÈÕÖÁ09ÔÂ20ÈÕ¹²ÊÕ¼°²È«·ì϶57¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe Media Encoder CVE-2020-9745Ô½½ç¶ÁÐÅϢй¶·ì϶£»Gallagher Group Command Centre¿Í»§¶Ë¹ÒÆð·ì϶£»Hyland OnBase CVE-2020-25248Ŀ¼±éÀú·ì϶£»IPTV/H.264/H.265ÊÓÆµ±àÂëÆ÷ºóÃÅÃÜÂëÖÎÀíÔ±½Ó¼û·ì϶£»Google Android Framework CVE-2020-0275ȨÏÞÌáÉý·ì϶¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇRazerÊý¾Ý¿â¶³öµ¼ÖÂÆäÔ¼10ÍòÓû§ÐÅϢй¶£»Redgate°ä²¼2020Äê¶ÈÊý¾Ý¿â״̬¼à²â»ã±¨£»Ó¢¹ú¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©°ä²¼·ì϶Åû¶ָÄÏ£»¿¨°Í˹»ù°ä²¼2020Äê¹¤ÒµÍøÂ簲ȫµ÷²é×êÑл㱨£»µÂ¹ú¹ºÎïÍøÕ¾windeln.deÊý¾Ý¿â¶³ö£¬Ð¹Â¶60Òڱʼͼ¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
> ³ÁÒª°²È«·ì϶Áбí
1.Adobe Media Encoder CVE-2020-9745Ô½½ç¶ÁÐÅϢй¶·ì϶
Adobe Media Encoder´æÔÚÔ½½ç¶Á°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ɻñÈ¡Ãô¸ÐÐÅÏ¢¡£
https://helpx.adobe.com/security/products/media-encoder/apsb20-57.html
2. Gallagher Group Command Centre¿Í»§¶Ë¹ÒÆð·ì϶
Gallagher Group Command Centre´´½¨Guard TourÊÂÎñ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿Éʹ¿Í»§¶ËÁÙʱ¹ÒÆð»ò¶Ï¿ªÏνӡ£
https://security.gallagher.com/Security-Advisories/CVE-2020-16099
3.Hyland OnBase CVE-2020-25248Ŀ¼±éÀú·ì϶
Hyland OnBase´æÔÚõè¾¶±éÀú·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎĶÁȡϵͳÎļþ»òдÈëϵͳµ½Îļþ¡£
https://seclists.org/fulldisclosure/2020/Sep/21
4. IPTV/H.264/H.265ÊÓÆµ±àÂëÆ÷ºóÃÅÃÜÂëÖÎÀíÔ±½Ó¼û·ì϶
IPTV/H.264/H.265ÊÓÆµ±àÂëÆ÷´æÔÚºóÃÅÃÜÂë·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉδÊÚȨÆëÈ«½ÚÔìÀûÓá£
https://www.kb.cert.org/vuls/id/896979
5. Google Android Framework CVE-2020-0275ȨÏÞÌáÉý·ì϶
Google Android Framework´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://source.android.com/security/bulletin/android-11
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢RazerÊý¾Ý¿â¶³öµ¼ÖÂÆäÔ¼10ÍòÓû§ÐÅϢй¶

8ÔÂ19ÈÕ£¬×êÑÐÔ±Bob Diachenko·¢ÏÖÓÎÏ·Ó²¼þÔì×÷ÉÌRazerµÄÔÚÏßÉ̵êµÄÊý¾Ý¿â¶³ö£¬µ¼ÖÂÆäÔ¼10ÍòÓû§ÐÅϢй¶¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢¶©µ¥ºÅ¡¢¶©µ¥Ã÷ϸÒÔ¼°Õʵ¥ºÍËÍ»õµØÖ·µÈ¡£RazerÓÚÔÚ9ÔÂ9ÈÕ½¨¸´Á˸ÃÊý¾Ý¿â·þÎñÆ÷£¬²¢°µÊ¾¸ÃÊÂÎñÖв¢Ã»ÓÐÆäËûÃô¸ÐÊý¾Ýй¶£¬ÀýÈçÐÅÓþ¿¨ºÅ»òÃÜÂëµÈÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/razer-data-leak-exposes-personal-information-of-gamers/
2¡¢Redgate°ä²¼2020Äê¶ÈÊý¾Ý¿â״̬¼à²â»ã±¨

Redgate×îа䲼ÁË2020Äê¶ÈÊý¾Ý¿â״̬¼à²â»ã±¨¡£»ã±¨ÏÔʾ£¬ÎÞÂÛÊÇÔÚѡȡÊý¾Ý¿âDevOps·½Ã棬»¹ÊÇÔÚʹÓÃ¼à¿ØÀ´¸ú×ÙÊý¾Ý¿â»úÄܺͲ¿Êð·½Ã棬½ðÈÚ·þÎñÐÐÒµµÄ²û·¢¶¼ÓÅÓÚÆäËûÐÐÒµ¡£ÆäÖУ¬61%µÄ½ðÈÚ·þÎñÐÐÒµÔ±¹¤Ã¿ÖܸüÐÂÖÁÉÙÒ»´ÎÊý¾Ý¿â£¬¶øÆäËûÐÐÒµÖ»ÓÐ43%µÄÔ±¹¤»áÕâÑù×ö¡£½ðÈÚ·þÎñµÄ·þÎñÆ÷ÊýÁ¿Ò²¸ü¶à£¬36%µÄ·þÎñÆ÷Õ¼ÓÐ50µ½500¸öÊ·ý£¬¶øÆäËû²¿ÃÅÖ»ÓÐ26%¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/09/14/database-monitoring-improves-devops-success/
3¡¢Ó¢¹ú¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©°ä²¼·ì϶Åû¶ָÄÏ

Ó¢¹ú¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©°ä²¼ÁË·ì϶Åû¶ָÄÏ£¬ÒÔÔ®ÊÖ¹«Ë¾Ö´Ðзì϶Åû¶Á÷³Ì»òÔÚÒѾ³ÉÁ¢·ì϶Åû¶Á÷³ÌµÄÇé¿öÏÂ¶ÔÆä½øÐиĽø¡£NCSC°µÊ¾£¬¸ÃÖ¸Äϲ¢²»ÊÇÒ»¸ö·ì϶Åû¶µÄ¹æ¶¨Êֲᣬ¶øÊÇΪ¸üºÃµÄÖ´ÐÐÌṩÁ˱ØÒªµÄÐÅÏ¢¡£ÆäÖØÒª·ÖΪÈý¸öÖØÒª²¿ÃÅ£¬ÃèÊöÁËÈôºÎ½«±í²¿·ì϶ÐÅÏ¢¶¨Ïò¸øÏàÒ˵ÄÈË£¬ÒÔ¼°»ã±¨Ðè×ñѹعطì϶µÄ¿ò¼Ü³ß¶È¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/uk-government-releases-toolkit-to-easily-disclose-vulnerabilities/
4¡¢¿¨°Í˹»ù°ä²¼2020Äê¹¤ÒµÍøÂ簲ȫµ÷²é×êÑл㱨

¿¨°Í˹»ù¶ÔÒßÇéÆÚ¼äµÄ¹¤ÒµÍøÂ簲ȫÇé¿ö½øÐÐÁË×êÑУ¬²¢°ä²¼ÁË2020Äê¹¤ÒµÍøÂ簲ȫµ÷²é×êÑл㱨¡£»ã±¨ÏÔʾ£¬³¬¹ýÒ»°ë(53%)µÄÊÜ·ÃÕßÈϿɣ¬COVID-19µ¼Ö¸ü¶àÔ±¹¤ÔڼҰ칫£¬ÕâÒѳÉΪ¶ÔÐÅÏ¢°²È«·þÎñµÄÒ»ÖÖѹÁ¦²âÊÔ¡£ÓÉÓÚ±í²¿ÏνÓÊýÁ¿¶à¶à£¬´Ë¿Ì¾ø´óÎÞÊý¹«Ë¾¶¼ÔÚ¶ÔOTÍøÂçµÄ°²È«¼¶±ð½øÐж¨ÆÚÆÀ¹À¡£ºÜ¶à×éÖ¯²»µÃ²»³ÁÐÂ˼¿¼ËûÃÇÄÚÍøµÄ±£»¤²½Ö裬ֻÓÐ7%µÄÊÜ·ÃÕß°µÊ¾£¬ËûÃǵÄÍøÂ簲ȫսÊõÔÚCOVID-19ÆÚ¼äÏ൱ÓÐЧ¡£
ÔÎÄÁ´½Ó£º
https://www.kaspersky.com/blog/industrial-cybersecurity-2020/37031/
5¡¢µÂ¹ú¹ºÎïÍøÕ¾windeln.deÊý¾Ý¿â¶³ö£¬Ð¹Â¶60Òڱʼͼ

Safety DetectivesµÄ×êÑÐÈËÔ±ÔÚÍøÂçÉÏ·¢ÏÖÁËÒ»¸ö¶³öµÄÊý¾Ý¿â£¬¾µ÷²é¸ÃÊý¾Ý¿âÊôÓڵ¹úÔÚÏß¹ºÎïÍøÕ¾windeln.de¡£Æä¶³öÁË6.4TBµÄÊý¾Ý£¬ÆäÖÐÔ̺¬60Òڱʼͼ£¬Ð¹Â¶Á˳¬¹ý700000Ãû¿Í»§µÄÓ×ÎÒÐÅÏ¢¡£Õâ´ÎÊÂÎñµÄй¶ÐÅÏ¢Ô̺¬Ó×ÎÒÉí·ÝÐÅÏ¢£¨PII£©ºÍÆäËûÊý¾Ý£¬ÀýÈ緢Ʊ¡¢È«Ãû¡¢IPµØÖ·¡¢ÄÚ²¿ÈÕÖ¾¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢¼ÒÍ¥µØÖ·¡¢É¢ÁÐÃÜÂë¡¢¸¶¿î·½Ê½ºÍÓû§µÄº¢×ÓÓ×ÎÒÐÅÏ¢µÈ¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/shopping-site-leaks-miners-data-database-mess-up/


¾©¹«Íø°²±¸11010802024551ºÅ