ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ38ÖÜ

°ä²¼¹¦·ò 2020-09-21

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2020Äê09ÔÂ14ÈÕÖÁ09ÔÂ20ÈÕ¹²ÊÕ¼°²È«·ì϶57¸ö£¬ £¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe Media Encoder CVE-2020-9745Ô½½ç¶ÁÐÅϢй¶·ì϶£»£»£»£»£»£»Gallagher Group Command Centre¿Í»§¶Ë¹ÒÆð·ì϶£»£»£»£»£»£»Hyland OnBase CVE-2020-25248Ŀ¼±éÀú·ì϶£»£»£»£»£»£»IPTV/H.264/H.265ÊÓÆµ±àÂëÆ÷ºóÃÅÃÜÂëÖÎÀíÔ±½Ó¼û·ì϶£»£»£»£»£»£»Google Android Framework CVE-2020-0275ȨÏÞÌáÉý·ì϶¡£ ¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇRazerÊý¾Ý¿â¶³öµ¼ÖÂÆäÔ¼10ÍòÓû§ÐÅϢй¶£»£»£»£»£»£»Redgate°ä²¼2020Äê¶ÈÊý¾Ý¿â״̬¼à²â»ã±¨£»£»£»£»£»£»Ó¢¹ú¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©°ä²¼·ì϶Åû¶ָÄÏ£»£»£»£»£»£»¿¨°Í˹»ù°ä²¼2020Äê¹¤ÒµÍøÂ簲ȫµ÷²é×êÑл㱨£»£»£»£»£»£»µÂ¹ú¹ºÎïÍøÕ¾windeln.deÊý¾Ý¿â¶³ö£¬ £¬£¬£¬£¬Ð¹Â¶60Òڱʼͼ¡£ ¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬ £¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£ ¡£¡£¡£¡£


³ÁÒª°²È«·ì϶Áбí


1.Adobe Media Encoder CVE-2020-9745Ô½½ç¶ÁÐÅϢй¶·ì϶


Adobe Media Encoder´æÔÚÔ½½ç¶Á°²È«·ì϶£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ £¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢¡£ ¡£¡£¡£¡£

https://helpx.adobe.com/security/products/media-encoder/apsb20-57.html


2. Gallagher Group Command Centre¿Í»§¶Ë¹ÒÆð·ì϶


Gallagher Group Command Centre´´½¨Guard TourÊÂÎñ´æÔÚ°²È«·ì϶£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ £¬£¬£¬£¬¿Éʹ¿Í»§¶ËÁÙʱ¹ÒÆð»ò¶Ï¿ªÏνÓ¡£ ¡£¡£¡£¡£

https://security.gallagher.com/Security-Advisories/CVE-2020-16099


3.Hyland OnBase CVE-2020-25248Ŀ¼±éÀú·ì϶


Hyland OnBase´æÔÚõè¾¶±éÀú·ì϶£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ £¬£¬£¬£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎĶÁȡϵͳÎļþ»òдÈëϵͳµ½Îļþ¡£ ¡£¡£¡£¡£

https://seclists.org/fulldisclosure/2020/Sep/21


4. IPTV/H.264/H.265ÊÓÆµ±àÂëÆ÷ºóÃÅÃÜÂëÖÎÀíÔ±½Ó¼û·ì϶


IPTV/H.264/H.265ÊÓÆµ±àÂëÆ÷´æÔÚºóÃÅÃÜÂë·ì϶£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ £¬£¬£¬£¬¿ÉδÊÚȨÆëÈ«½ÚÔìÀûÓᣠ¡£¡£¡£¡£

https://www.kb.cert.org/vuls/id/896979


5. Google Android Framework CVE-2020-0275ȨÏÞÌáÉý·ì϶


Google Android Framework´æÔÚ°²È«·ì϶£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ £¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£ ¡£¡£¡£¡£

https://source.android.com/security/bulletin/android-11


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢RazerÊý¾Ý¿â¶³öµ¼ÖÂÆäÔ¼10ÍòÓû§ÐÅϢй¶


1.jpg


8ÔÂ19ÈÕ£¬ £¬£¬£¬£¬×êÑÐÔ±Bob Diachenko·¢ÏÖÓÎÏ·Ó²¼þÔì×÷ÉÌRazerµÄÔÚÏßÉ̵êµÄÊý¾Ý¿â¶³ö£¬ £¬£¬£¬£¬µ¼ÖÂÆäÔ¼10ÍòÓû§ÐÅϢй¶¡£ ¡£¡£¡£¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢¶©µ¥ºÅ¡¢¶©µ¥Ã÷ϸÒÔ¼°Õʵ¥ºÍËÍ»õµØÖ·µÈ¡£ ¡£¡£¡£¡£RazerÓÚÔÚ9ÔÂ9ÈÕ½¨¸´Á˸ÃÊý¾Ý¿â·þÎñÆ÷£¬ £¬£¬£¬£¬²¢°µÊ¾¸ÃÊÂÎñÖв¢Ã»ÓÐÆäËûÃô¸ÐÊý¾Ýй¶£¬ £¬£¬£¬£¬ÀýÈçÐÅÓþ¿¨ºÅ»òÃÜÂëµÈÐÅÏ¢¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/razer-data-leak-exposes-personal-information-of-gamers/


2¡¢Redgate°ä²¼2020Äê¶ÈÊý¾Ý¿â״̬¼à²â»ã±¨


2.jpg


Redgate×îа䲼ÁË2020Äê¶ÈÊý¾Ý¿â״̬¼à²â»ã±¨¡£ ¡£¡£¡£¡£»ã±¨ÏÔʾ£¬ £¬£¬£¬£¬ÎÞÂÛÊÇÔÚѡȡÊý¾Ý¿âDevOps·½Ã棬 £¬£¬£¬£¬»¹ÊÇÔÚʹÓÃ¼à¿ØÀ´¸ú×ÙÊý¾Ý¿â»úÄܺͲ¿Êð·½Ã棬 £¬£¬£¬£¬½ðÈÚ·þÎñÐÐÒµµÄ²û·¢¶¼ÓÅÓÚÆäËûÐÐÒµ¡£ ¡£¡£¡£¡£ÆäÖУ¬ £¬£¬£¬£¬61%µÄ½ðÈÚ·þÎñÐÐÒµÔ±¹¤Ã¿ÖܸüÐÂÖÁÉÙÒ»´ÎÊý¾Ý¿â£¬ £¬£¬£¬£¬¶øÆäËûÐÐÒµÖ»ÓÐ43%µÄÔ±¹¤»áÕâÑù×ö¡£ ¡£¡£¡£¡£½ðÈÚ·þÎñµÄ·þÎñÆ÷ÊýÁ¿Ò²¸ü¶à£¬ £¬£¬£¬£¬36%µÄ·þÎñÆ÷Õ¼ÓÐ50µ½500¸öÊ·ý£¬ £¬£¬£¬£¬¶øÆäËû²¿ÃÅÖ»ÓÐ26%¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/09/14/database-monitoring-improves-devops-success/


3¡¢Ó¢¹ú¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©°ä²¼·ì϶Åû¶ָÄÏ


3.jpg


Ó¢¹ú¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©°ä²¼ÁË·ì϶Åû¶ָÄÏ£¬ £¬£¬£¬£¬ÒÔÔ®ÊÖ¹«Ë¾Ö´Ðзì϶Åû¶Á÷³Ì»òÔÚÒѾ­³ÉÁ¢·ì϶Åû¶Á÷³ÌµÄÇé¿öÏÂ¶ÔÆä½øÐиĽø¡£ ¡£¡£¡£¡£NCSC°µÊ¾£¬ £¬£¬£¬£¬¸ÃÖ¸Äϲ¢²»ÊÇÒ»¸ö·ì϶Åû¶µÄ¹æ¶¨Êֲᣬ £¬£¬£¬£¬¶øÊÇΪ¸üºÃµÄÖ´ÐÐÌṩÁ˱ØÒªµÄÐÅÏ¢¡£ ¡£¡£¡£¡£ÆäÖØÒª·ÖΪÈý¸öÖØÒª²¿ÃÅ£¬ £¬£¬£¬£¬ÃèÊöÁËÈôºÎ½«±í²¿·ì϶ÐÅÏ¢¶¨Ïò¸øÏàÒ˵ÄÈË£¬ £¬£¬£¬£¬ÒÔ¼°»ã±¨Ðè×ñÑ­¹Ø¹Ø·ì϶µÄ¿ò¼Ü³ß¶È¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/uk-government-releases-toolkit-to-easily-disclose-vulnerabilities/


4¡¢¿¨°Í˹»ù°ä²¼2020Äê¹¤ÒµÍøÂ簲ȫµ÷²é×êÑл㱨


4.jpg


¿¨°Í˹»ù¶ÔÒßÇéÆÚ¼äµÄ¹¤ÒµÍøÂ簲ȫÇé¿ö½øÐÐÁË×êÑУ¬ £¬£¬£¬£¬²¢°ä²¼ÁË2020Äê¹¤ÒµÍøÂ簲ȫµ÷²é×êÑл㱨¡£ ¡£¡£¡£¡£»ã±¨ÏÔʾ£¬ £¬£¬£¬£¬³¬¹ýÒ»°ë(53%)µÄÊÜ·ÃÕßÈϿɣ¬ £¬£¬£¬£¬COVID-19µ¼Ö¸ü¶àÔ±¹¤ÔڼҰ칫£¬ £¬£¬£¬£¬ÕâÒѳÉΪ¶ÔÐÅÏ¢°²È«·þÎñµÄÒ»ÖÖѹÁ¦²âÊÔ¡£ ¡£¡£¡£¡£ÓÉÓÚ±í²¿ÏνÓÊýÁ¿¶à¶à£¬ £¬£¬£¬£¬´Ë¿Ì¾ø´óÎÞÊý¹«Ë¾¶¼ÔÚ¶ÔOTÍøÂçµÄ°²È«¼¶±ð½øÐж¨ÆÚÆÀ¹À¡£ ¡£¡£¡£¡£ºÜ¶à×éÖ¯²»µÃ²»³ÁÐÂ˼¿¼ËûÃÇÄÚÍøµÄ±£»£»£»£»£»£»¤²½Ö裬 £¬£¬£¬£¬Ö»ÓÐ7%µÄÊÜ·ÃÕß°µÊ¾£¬ £¬£¬£¬£¬ËûÃǵÄÍøÂ簲ȫսÊõÔÚCOVID-19ÆÚ¼äÏ൱ÓÐЧ¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.kaspersky.com/blog/industrial-cybersecurity-2020/37031/


5¡¢µÂ¹ú¹ºÎïÍøÕ¾windeln.deÊý¾Ý¿â¶³ö£¬ £¬£¬£¬£¬Ð¹Â¶60Òڱʼͼ


5.jpg


Safety DetectivesµÄ×êÑÐÈËÔ±ÔÚÍøÂçÉÏ·¢ÏÖÁËÒ»¸ö¶³öµÄÊý¾Ý¿â£¬ £¬£¬£¬£¬¾­µ÷²é¸ÃÊý¾Ý¿âÊôÓڵ¹úÔÚÏß¹ºÎïÍøÕ¾windeln.de¡£ ¡£¡£¡£¡£Æä¶³öÁË6.4TBµÄÊý¾Ý£¬ £¬£¬£¬£¬ÆäÖÐÔ̺¬60Òڱʼͼ£¬ £¬£¬£¬£¬Ð¹Â¶Á˳¬¹ý700000Ãû¿Í»§µÄÓ×ÎÒÐÅÏ¢¡£ ¡£¡£¡£¡£Õâ´ÎÊÂÎñµÄй¶ÐÅÏ¢Ô̺¬Ó×ÎÒÉí·ÝÐÅÏ¢£¨PII£©ºÍÆäËûÊý¾Ý£¬ £¬£¬£¬£¬ÀýÈ緢Ʊ¡¢È«Ãû¡¢IPµØÖ·¡¢ÄÚ²¿ÈÕÖ¾¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢¼ÒÍ¥µØÖ·¡¢É¢ÁÐÃÜÂë¡¢¸¶¿î·½Ê½ºÍÓû§µÄº¢×ÓÓ×ÎÒÐÅÏ¢µÈ¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/shopping-site-leaks-miners-data-database-mess-up/