ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ12ÖÜ

°ä²¼¹¦·ò 2020-03-24

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2020Äê03ÔÂ16ÈÕÖÁ22ÈÕ¹²ÊÕ¼°²È«·ì϶77¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇInsulet Omnipod Insulin Management SystemδÊÚȨ½Ó¼û·ì϶; Google Chrome WebGL CVE-2020-6422ÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶£»£»£» £»£»Foxit Studio Photo TIF¶ÑÒç³ö´úÂëÖ´Ðзì϶£»£»£» £»£»Docker DesktopËÁÒâÎļþдÈë·ì϶£»£»£» £»£»Adobe ColdFusionÔ¶³ÌÎļþÔ̺¬·ì϶¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǰ²È«³§Ḛ́䲼Turla APT»ù´¡ÉèÊ©µÄ¸ú×ٻ㱨£»£»£» £»£»2019Ä꿪Դ´úÂë·ì϶ÊýÁ¿³õ´Î³¬¹ý6000¸ö£¬£¬£¬£¬£¬£¬£¬£¬Ôö³¤½ü50£¥£»£»£» £»£»Intel CPUÒ×ÊÜÐÂSnoop¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬¿Éй¶»º´æÊý¾Ý£»£»£» £»£»½ðÈÚ¹«Ë¾AdvantageºÍArgusÔÆÊý¾Ý¿âй¶425GBÊý¾Ý£»£»£» £»£»µÂ¹ú±íÂôƽ̨Lieferando.deÔâDDoS¹¥»÷µ¼Ö·þÎṉ̃»¾¡£¡£¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£¡£


>³ÁÒª°²È«·ì϶Áбí


1. Insulet Omnipod Insulin Management SystemδÊÚȨ½Ó¼û·ì϶


Insulet Omnipod Insulin Management SystemµÄwireless RFͨѶºÍ̸¶ÌȱÕýÈ·µÄÑéÖ¤ÊÚȨ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÈÆ¹ý°²È«ÏÞ¶È£¬£¬£¬£¬£¬£¬£¬£¬Ö´ÐжñÒâ²Ù×÷¡£¡£¡£¡£¡£¡£

https://www.us-cert.gov/ics/advisories/icsma-20-079-01


2. Google Chrome WebGL CVE-2020-6422ÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶


Google Chrome WebGL´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶¹¹½¨¶ñÒâWEBÒ³£¬£¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£» £»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£

https://chromereleases.googleblog.com/2020/03/stable-channel-update-for-desktop_18.html


3. Foxit Studio Photo TIF¶ÑÒç³ö´úÂëÖ´Ðзì϶


Foxit Studio Photo TIF½âÎö´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£» £»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-20-311/


4. Docker DesktopËÁÒâÎļþдÈë·ì϶

Docker Desktop´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐí±¾µØ¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¸²¸ÇËÁÒâµÄDACLȨÏÞ²¢Ð´ÈëËÁÒâÎļþ¡£¡£¡£¡£¡£¡£

https://github.com/active-labs/Advisories/blob/master/2020/ACTIVE-2020-002.md


5. Adobe ColdFusionÔ¶³ÌÎļþÔ̺¬·ì϶


Adobe ColdFusion´æÔÚÎļþÔ̺¬·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£

https://helpx.adobe.com/security/products/coldfusion/apsb20-16.html


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢°²È«³§Ḛ́䲼Turla APT»ù´¡ÉèÊ©µÄ¸ú×ٻ㱨


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Turla APTÊÇÒ»¸ö³ÉÊì¡¢¸´ÔÓÇÒÓµÓÐÕ½Êõ³ÁµãµÄÍøÂç¼äµý×éÖ¯£¬£¬£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯Õë¶ÔÈ«Çò¿ÆÑÓ×¢±í½»ºÍ¾üÊ»ú¹¹µÄ¹¥»÷ÒÑÓÐÊ®¶àÄêµÄº¹Ç࣬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÒ»ÏòÔÚÕë¶Ô±±´óÎ÷ÑóЭÒé×éÖ¯£¨NATO£©ºÍ¶ÀÁªÌ壨CIS£©¹ú¶È¡£¡£¡£¡£¡£¡£Turla²»ÐÝ¿ª·¢×Ô¼º¶ÀÓеġ¢ÏȽøµÄ¶ñÒâÈí¼þºÍ¹¤¾ß£¬£¬£¬£¬£¬£¬£¬£¬²¢Ñ¡È¡ÐµĹ¥»÷ºÍ»ìºÏ²½Ö裬£¬£¬£¬£¬£¬£¬£¬Insikt GroupÆÀ¹ÀÒÔΪTurlaÔÚ½«À´¼¸ÄêÄÚÈÔ½«ÊÇÒ»¸ö»îÔ¾µÄ¡¢ÏȽøµÄÍþв¡£¡£¡£¡£¡£¡£Recorded FutureµÄÐÂ×êÑÐÌṩÁË×Ô¶¯¸ú×ٺͼø±ðTurla»ù´¡¼Ü¹¹µÄ²½Ö裬£¬£¬£¬£¬£¬£¬£¬³Áµã¹Ø×¢¼¸ÖÖÓëTurlaÓйصĶñÒâÈí¼þÀàÐÍ£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬MosquitoºóÃźͽٳֵÄÒÁÀÊTwoFace ASPX Web Shell¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.recordedfuture.com/turla-apt-infrastructure/


2¡¢2019Ä꿪Դ´úÂë·ì϶ÊýÁ¿³õ´Î³¬¹ý6000¸ö£¬£¬£¬£¬£¬£¬£¬£¬Ôö³¤½ü50£¥


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ƾ¾Ý¿ªÔ´°²È«ÓëºÏ¹æ¹«Ë¾WhiteSourceµÄÒ»·Ý»ã±¨£¬£¬£¬£¬£¬£¬£¬£¬È¥Ä꿪Դ´úÂëÖеķì϶¼¤Ôö¡£¡£¡£¡£¡£¡£¸Ã»ã±¨³Æ£¬£¬£¬£¬£¬£¬£¬£¬2017ÄêºÍ2018Ä꿪Դ·ì϶µÄÊýÁ¿²»±äÔÚ4000¶à¸ö£¬£¬£¬£¬£¬£¬£¬£¬Óë2017Äê֮ǰ´ÓÎ´Í»ÆÆ2000¸öµÄÊý×ÖÏà±È£¬£¬£¬£¬£¬£¬£¬£¬·ì϶ÊýÁ¿Ôö³¤ÁËÒ»±¶ÒÔÉÏ¡£¡£¡£¡£¡£¡£¶øºóÔÚ2019Ä꣬£¬£¬£¬£¬£¬£¬£¬¿ªÔ´·ì϶ÊýÁ¿ÔÙ´Îì­Éý£¬£¬£¬£¬£¬£¬£¬£¬³õ´Î³¬¹ý6000¸ö£¬£¬£¬£¬£¬£¬£¬£¬Õâ´ú±íÁ˽ü50£¥µÄÔö³¤¡£¡£¡£¡£¡£¡£µ½Ä¿Ç°ÎªÖ¹¿ªÔ´·ì϶ÖÐ×î³£¼ûµÄÀàÐÍÊÇ¿çÕ¾µã¾ç±¾£¨XSS£©£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÀàÐÍÏÕЩռËùÓзì϶µÄËÄ·ÖÖ®Ò»£¬£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊÇÊäÈëÑéÖ¤²»ÕýÈ·¡¢»º³åÇøÃýÎó¡¢Ô½½ç¶ÁÈ¡ºÍÐÅϢй¶¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://nakedsecurity.sophos.com/2020/03/16/open-source-bugs-have-soared-in-the-past-year/


3¡¢Intel CPUÒ×ÊÜÐÂSnoop¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬¿Éй¶»º´æÊý¾Ý


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Intel CPUÈÝÒ×Êܵ½Ðµġ°Snoop¡±¹¥»÷Ó°Ï죬£¬£¬£¬£¬£¬£¬£¬¸Ã¹¥»÷¿ÉÄÜ»áй©CPUÄÚ²¿´æ´¢Æ÷£¨»º´æ£©ÖеÄÊý¾Ý¡£¡£¡£¡£¡£¡£Intel°µÊ¾2018Äê8ÔÂÕë¶ÔForeshadow£¨L1TF£©·ì϶°ä²¼µÄ²¹¶¡Ò²ºÏÓÃÓÚ´Ëй¥»÷¡£¡£¡£¡£¡£¡£AWSÈí¼þ¹¤³ÌʦPawel Wieczorkiewicz·¢ÏÖ²¢»ã±¨Á˴˹¥»÷²½Ö裬£¬£¬£¬£¬£¬£¬£¬¸Ã¹¥»÷±»ÃèÊöΪ¡°Snoop¸¨ÖúL1Êý¾Ý²É¼¯¡±£¬£¬£¬£¬£¬£¬£¬£¬»òÖ»ÊÇ¡°Snoop¡±£¨CVE-2020-0550£©¡£¡£¡£¡£¡£¡£ÔÚ¼¼Êõ²ãÃæÉÏ£¬£¬£¬£¬£¬£¬£¬£¬ÐµÄSnoop¹¥»÷ÀûÓÃÁ˶༶»º´æ¡¢»º´æÒ»ÖÂÐÔºÍ×ÜÏß¼àÌýµÈCPU»úÔì¡£¡£¡£¡£¡£¡£IntelÁгöÁËÒ×Êܹ¥»÷µÄCPUÁбí£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÁбíÖÐÔ̺¬CoreºÍXeon´¦ÖÃÆ÷µÈ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/intel-cpus-vulnerable-to-new-snoop-attack/


4¡¢½ðÈÚ¹«Ë¾AdvantageºÍArgusÔÆÊý¾Ý¿âй¶425GBÊý¾Ý


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


vpnMentor×êÑÐÈËÔ±·¢ÏÖÒ»¸öÊôÓÚ½ðÈÚ¹«Ë¾Advantage Capital FundingºÍArgus Capital FundingµÄ¿É¹«¿ª½Ó¼ûµÄÊý¾Ý¿âй¶ÁË425GBÃô¸ÐÎļþ¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÓëÕâÁ½¸ö¹«Ë¾¿ª·¢µÄMCA WizardÀûÓÃÓйØ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÀûÓô˿ÌÒѲ»ÔÙÔÚ¹Ù·½ÀûÓÃÉ̵êÖÐÌṩ¡£¡£¡£¡£¡£¡£vpnMentor³õ´ÎÔÚ2019Äê12Ô·¢ÏÖÁ˸ÃÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬£¬Êý¾Ý¿âÖÐÔ̺¬À´×ÔAdvantageºÍArgusµÄ¸öÈË˾·¨ºÍ²ÆÕþÎļþ£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÐÅÓþ»ã±¨¡¢ÒøÐжÔÕʵ¥¡¢ºÏͬ¡¢Ë¾·¨Îļþ¡¢¼ÝÊ»ÅÆÕÕ¸±±¾¡¢²É°ì¶©µ¥ºÍÊÕÌõ¡¢ÄÉ˰É걨±í¡¢Éç»á±£ÏÕÐÅÏ¢ÒÔ¼°ÂòÂô»ã±¨¡£¡£¡£¡£¡£¡£ÕâЩ¼Í¼²»½öÓëAdvantageºÍArgusÓйØ£¬£¬£¬£¬£¬£¬£¬£¬»¹Ó°ÏìÁËËûÃǵĿͻ§¡¢³Ð°üÉÌ¡¢Ô±¹¤ºÍºÏ×÷ͬ°é¡£¡£¡£¡£¡£¡£vpnMentor³¢ÊÔÓëAdvantageºÍArgusÁªÏµ£¬£¬£¬£¬£¬£¬£¬£¬µ«²¢Î´µÃµ½»Ø¸´£¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±×îÖÕÖ±½ÓÓëAWSÁªÏµ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âÓÚ2020Äê1ÔÂ9Èչعء£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/financial-apps-leak-425gb-in-company-data-through-open-database/


5¡¢µÂ¹ú±íÂôƽ̨Lieferando.deÔâDDoS¹¥»÷µ¼Ö·þÎṉ̃»¾


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


µÂ¹ú±íÂôƽ̨Lieferando.deÔâDDoS¹¥»÷µ¼Ö·þÎṉ̃»¾¡£¡£¡£¡£¡£¡£¸Ãƽ̨¹ØÁªÁË1.5Íò¶à¼ÒµÂ¹ú²Í¹Ý£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚCOVID-19ÆÚ¼äµÂ¹ú¶Ô²ÍÌü½øÐÐÁËÑϸñµÄÏÞ¶È£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈçÏÞ¶È¿ÍÈ˵ÄÈËÊý¡¢Ôö´ó×À×ÓÖ®¼äµÄ¾àÀë¡¢±ÉÈËÎç6µãÖÁÔçÉÏ6µãÖ®¼ä±ØÐë¹ØÃŵÈ£¬£¬£¬£¬£¬£¬£¬£¬Òò¶øÕâ´ÎDDoS¹¥»÷Ó°ÏìÁË´óÁ¿Ñ¡ÔñʹÓñíÂô¶©²ÍµÄÓû§¡£¡£¡£¡£¡£¡£Ò»Ð©¿Í»§±§Ô¹³ÆÖ»¹Ü¸Ãƽ̨µÄϵͳÒò¹¥»÷¶øÌ±»¾£¬£¬£¬£¬£¬£¬£¬£¬µ«¸Ã·þÎñÈÔ½ÓÊÜж©µ¥£¬£¬£¬£¬£¬£¬£¬£¬Ö»ÊÇûÓÐ¶ÔÆä½øÐд¦Öᣡ£¡£¡£¡£¡£¸Ãƽ̨³Æ½«ÍË»¹ÒÑÖ§¸¶ÇÒδ½»¸¶µÄ¶©µ¥£¬£¬£¬£¬£¬£¬£¬£¬µ«¿Í»§±ØÐëͨ¹ýµç×ÓÓʼþÓëËûÃÇÁªÏµ¡£¡£¡£¡£¡£¡£¾Ý³Æ¹¥»÷ÕßÒªÇó2±ÈÌØ±Ò£¨Ô¼ºÏ1.1ÍòÃÀÔª£©µÄÊê½ðÀ´ÖÕ³¡¹¥»÷¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/food-delivery-service-in-germany-under-ddos-attack/