ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ42ÖÜ
°ä²¼¹¦·ò 2020-10-19> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2020Äê10ÔÂ12ÈÕÖÁ10ÔÂ18ÈÕ¹²ÊÕ¼°²È«·ì϶62¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe Flash Player¿ÕÖ¸ÕëÒýÓÃÔ¶³Ì´úÂëÖ´Ðзì϶£»Microsoft Windows Hyper-V CVE-2020-1047ȨÏÞÌáÉý·ì϶£»SAP Solution Manager OSºÅÁî×¢Èë·ì϶£»Microhard Bullet-LTE PingºÅÁî×¢Èë´úÂëÖ´Ðзì϶£»Veritas APTAREÊÚȨ²é³´úÂëÖ´Ðзì϶¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇBlackBerry°ä²¼¹ØÓÚBAHAMUT×éÖ¯µÄ·ÖÎö»ã±¨£»Lumu°ä²¼2020Äê¶ÈÀÕË÷Èí¼þÓ°Ïì·ÖÎöµÄÐÅϢͼ£»Adobe½¨¸´Flash PlayerÖеÄÔ¶³ÌÖ´ÐдúÂë·ì϶£»Agari°ä²¼BECÔÚÈ«ÇòÁìÓòÄÚÉ¢²¼ºÍÇ÷ÏòµÄ·ÖÎö»ã±¨£»CNSA°ä²¼¡¶2020ÖйúÍøÂçÊÓÌý·¢Õ¹×êÑл㱨¡·¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
> ³ÁÒª°²È«·ì϶Áбí
1.Adobe Flash Player¿ÕÖ¸ÕëÒýÓÃÔ¶³Ì´úÂëÖ´Ðзì϶
Adobe Flash Player´¦ÖÃSWF´æÔÚ¿ÕÖ¸ÕëÒýÓ÷ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÕßÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://helpx.adobe.com/security/products/flash-player/apsb20-58.html
2.Microsoft Windows Hyper-V CVE-2020-1047ȨÏÞÌáÉý·ì϶
Microsoft Windows Hyper-V´¦ÖÃÄÚ´æ¶ÔÏó´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉÌáÉýȨÏÞ¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2020-1047
3.SAP Solution Manager OSºÅÁî×¢Èë·ì϶
SAP Solution ManagerµÄCA Introscope Enterprise Manager´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâOSºÅÁî¡£
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=558632196
4.Microhard Bullet-LTE PingºÅÁî×¢Èë´úÂëÖ´Ðзì϶
Microhard Bullet-LTE tools.sh´¦ÖÃping²ÎÊý´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâºÅÁî¡£
https://www.zerodayinitiative.com/advisories/ZDI-20-1205/
5.Veritas APTAREÊÚȨ²é³´úÂëÖ´Ðзì϶
Veritas APTAREÊÚȨ²é³´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://www.veritas.com/content/support/en_US/security/VTS20-006#issue1
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢BlackBerry°ä²¼¹ØÓÚBAHAMUT×éÖ¯µÄ·ÖÎö»ã±¨

BlackBerry°ä²¼Á˹ØÓÚBAHAMUTÍøÂç¼äµý×éÖ¯µÄ·ÖÎö»ã±¨£¬·¢ÏÔìä¶Ôµ±¾Ö¹ÙÔ±ºÍÖØÒªÐÐÒµÌáÒéÁË´óÁ¿¸ß¶È¸´ÔӵĹ¥»÷¡£×êÑÐÅú×¢£¬¸ÃÍÅ»ïµÄ»î¶¯ÁìÓò±ÈÒÔǰÒÔΪµÄÒª¿í·ºµÃ¶à£¬Ô̺¬ÁËGoogle PlayÉ̵êºÍApp StoreÖеÄÊ®¼¸¸ö¶ñÒâÀûÓ÷¨Ê½¡£´Ë±í£¬BlackBerry»¹ÒÔΪ£¬BAHAMUTÄܹ»ÓëÖÁÉÙÒ»Ãû0day¿ª·¢ÈËÔ±½Ó´¥£¬²¢ÀûÓÃ0day¹¥»÷¶à¸öÖ¸±ê£¬ÕâÔ¶Ô¶³¬³öÁË´óÎÞÊýÆäËûºÚ¿Í×éÖ¯µÄ¹¥»÷ˮƽ¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/cyber-espionage-bahamut-staggering/
2¡¢Lumu°ä²¼2020Äê¶ÈÀÕË÷Èí¼þÓ°Ïì·ÖÎöµÄÐÅϢͼ

Lumu°ä²¼ÁËÒ»ÕÅÐÅϢͼ£¬¾ßÌå˵ÁËÈ»ÀÕË÷Èí¼þµÄ³É±¾ºÍÁìÓò£¬ÒÔÔ®ÊÔìóÒµºâÁ¿ËûÃǵÄÊܺ¦·çÏÕ¡£¾Ý·ÖÎö£¬½ñÄêÈ«ÇòÀÕË÷Èí¼þµÄ³É±¾Îª200ÒÚÃÀÔª£¬¾ùÔÈÿ´ÎµÄ¹¥»÷³É±¾³¬¹ý400ÍòÃÀÔª£¬²¢ÇÒÓÐ36£¥µÄÊܺ¦ÕßÖ§¸¶ÁËÊê½ð£¬ÆäÖÐ17£¥»¹Ã»ÄÜÍì»ØËûÃǵÄÊý¾Ý¡£´Ë±í£¬ÔÚ±±ÃÀÓÐ69%µÄ¹«Ë¾»ã±¨³ÆÊܵ½ÁËÀÕË÷Èí¼þµÄÓ°Ï죬¶øÔÚÅ·ÖÞÓÐ57%¡£Ïà½Ï¶øÑÔ£¬±±ÃÀÈ·µ±¾Ö»ú¹¹Êܵ½µÄ¹¥»÷×îΪÑϳÁ£¬Æä´ÎÊÇÔì×÷ÒµºÍ¹¹ÖþÒµ¡£
ÔÎÄÁ´½Ó£º
https://lumu.io/resources/2020-ransomware-flashcard/
3¡¢Adobe½¨¸´Flash PlayerÖеÄÔ¶³ÌÖ´ÐдúÂë·ì϶

Adobe½¨¸´ÁËFlash PlayerÖÐÑϳÁµÄÔ¶³ÌÖ´ÐдúÂë·ì϶£¨³ÆÎªCVE-2020-9746£©¡£AdobeÖ¸³ö£¬ÔÚĬÈÏÇé¿öÏ£¬ºÚ¿ÍÄܹ»Í¨¹ýÔÚÓû§½Ó¼ûÍøÕ¾Ê±ÔÚTLS / SSL´«µÝµÄHTTPÏìÓ¦ÖвåÈë¶ñÒâ×Ö·û´®À´ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶ºó£¬¿ÉÄܵ¼ÖÂÀûÓñÀÀ££¬´Ó¶øÊ¹¹¥»÷ÕßÄܹ»ÔÚ½Ó¼ûÕßµÄÍÆËã»úÉÏÔ¶³ÌÖ´ÐкÅÁî¡£ÕâЩºÅÁÔÚÓû§µÄ°²È«»·¾³ÖÐÖ´ÐУ¬²¢²»±ØÒªÖÎÀíԱȨÏÞ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-security-vulnerability-in-flash-player/
4¡¢Agari°ä²¼BECÔÚÈ«ÇòÁìÓòÄÚÉ¢²¼ºÍÇ÷ÏòµÄ·ÖÎö»ã±¨

AgariÍøÂçµý±¨²¿£¨ACID£©°ä²¼ÁËBECÔÚÈ«ÇòÁìÓòÄÚÉ¢²¼ºÍÇ÷ÏòµÄ·ÖÎö»ã±¨£¬ÒÔ¸üºÃµØÏàʶBEC¹¥»÷»î¶¯¡£»ã±¨Ô̺¬ÁË2019Äê5ÔÂÖÁ2020Äê7ÔÂÖ®¼äµÄ9000ÂŴηÀÓù»î¶¯µÄÊý¾Ý£¬·¢ÏÖÓÐ60£¥µÄ¹¥»÷ÕßÀ´×Ô·ÇÖÞµÄ11¸ö¹ú¶È£¬ÆäÖÐ83£¥Î»ÓÚÄáÈÕÀûÑÇ¡£½ü30£¥µÄ¹¥»÷ÕßÀ´×ÔÃÀÖÞ£¬ÆäÖеÄ89£¥À´×ÔÃÀ¹ú£¬²¢ÇÒ¹¥»÷ÕßÖØÒªÜöÝÍÔÚһЩ¶àÊý»á£¬Ô̺¬ÑÇÌØÀ¼´ó¡¢Å¦Ô¼¡¢ÂåÉ¼í¶¡¢ÐÝ˹¶ØºÍÂõ°¢ÃÜ¡£
ÔÎÄÁ´½Ó£º
https://www.agari.com/email-security-blog/business-email-compromise-geography/
5¡¢CNSA°ä²¼¡¶2020ÖйúÍøÂçÊÓÌý·¢Õ¹×êÑл㱨¡·

10ÔÂ12ÈÕ£¬ÖйúÍøÂçÊÓÌý½ÚÄ¿·þÎñлá°ä²¼¡¶2020ÖйúÍøÂçÊÓÌý·¢Õ¹×êÑл㱨¡·£¬Ê׶ȹ«¿ªÎÒ¹úÍøÂçÊÓÌýÓû§¹æÄ£ºÍ²úÒµ¹æÄ£¡£¸Ã»ã±¨»ùÓÚÊý¾ÝÍÚ¾ò¡¢µ÷ÑÐÒÔ¼°µÚÈý·½Êý¾Ý£¬¶Ô2019-2020ÄêµÄÍøÂçÊÓÌýÐÐÒµ½ü¿öºÍ·¢Õ¹Ç÷Ïò½øÐÐȨÍþ¡¢È«ÃæµÄÑÐÅС£»ã±¨ÏÔʾ£¬½ØÖÁ2020Äê6Ô£¬ÎÒ¹úÍøÂçÊÓÌýÓû§¹æÄ£´ï9.01ÒÚ£¬ 2019ÄêÍøÂçÊÓÌý²úÒµ¹æÄ£´ï4541.3ÒÚ¡£ÆäÖжÌÊÓÆµµÄÓû§Ê¹ÓÃÂÊ×î¸ß£¬´ï87.0%£¬Óû§¹æÄ£8.18ÒÚ£»×ÛºÏÊÓÆµµÄÓû§Ê¹ÓÃÂÊΪ77.1%£¬Óû§¹æÄ£7.24ÒÚ¡£
ÔÎÄÁ´½Ó£º
http://www.xinhuanet.com/info/2020-10/13/c_139436283.htm


¾©¹«Íø°²±¸11010802024551ºÅ