ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ42ÖÜ

°ä²¼¹¦·ò 2020-10-19

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2020Äê10ÔÂ12ÈÕÖÁ10ÔÂ18ÈÕ¹²ÊÕ¼°²È«·ì϶62¸ö£¬£¬£¬£¬£¬£¬£¬ £¬ÖµµÃ¹Ø×¢µÄÊÇAdobe Flash Player¿ÕÖ¸ÕëÒýÓÃÔ¶³Ì´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»£»Microsoft Windows Hyper-V CVE-2020-1047ȨÏÞÌáÉý·ì϶£»£»£»£»£»£»£»£»SAP Solution Manager OSºÅÁî×¢Èë·ì϶£»£»£»£»£»£»£»£»Microhard Bullet-LTE PingºÅÁî×¢Èë´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»£»Veritas APTAREÊÚȨ²é³­´úÂëÖ´Ðзì϶ ¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇBlackBerry°ä²¼¹ØÓÚBAHAMUT×éÖ¯µÄ·ÖÎö»ã±¨£»£»£»£»£»£»£»£»Lumu°ä²¼2020Äê¶ÈÀÕË÷Èí¼þÓ°Ïì·ÖÎöµÄÐÅϢͼ£»£»£»£»£»£»£»£»Adobe½¨¸´Flash PlayerÖеÄÔ¶³ÌÖ´ÐдúÂë·ì϶£»£»£»£»£»£»£»£»Agari°ä²¼BECÔÚÈ«ÇòÁìÓòÄÚÉ¢²¼ºÍÇ÷ÏòµÄ·ÖÎö»ã±¨£»£»£»£»£»£»£»£»CNSA°ä²¼¡¶2020ÖйúÍøÂçÊÓÌý·¢Õ¹×êÑл㱨¡· ¡£¡£¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬ £¬±¾Öܰ²È«ÍþвΪÖÐ ¡£¡£¡£¡£¡£¡£


³ÁÒª°²È«·ì϶Áбí


1.Adobe Flash Player¿ÕÖ¸ÕëÒýÓÃÔ¶³Ì´úÂëÖ´Ðзì϶


Adobe Flash Player´¦ÖÃSWF´æÔÚ¿ÕÖ¸ÕëÒýÓ÷ì϶£¬£¬£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬ £¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬ £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»£»£»òÕßÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë ¡£¡£¡£¡£¡£¡£

https://helpx.adobe.com/security/products/flash-player/apsb20-58.html


2.Microsoft Windows Hyper-V CVE-2020-1047ȨÏÞÌáÉý·ì϶


Microsoft Windows Hyper-V´¦ÖÃÄÚ´æ¶ÔÏó´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬ £¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬ £¬¿ÉÌáÉýȨÏÞ ¡£¡£¡£¡£¡£¡£

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2020-1047


3.SAP Solution Manager OSºÅÁî×¢Èë·ì϶


SAP Solution ManagerµÄCA Introscope Enterprise Manager´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬ £¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâOSºÅÁî ¡£¡£¡£¡£¡£¡£

https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=558632196


4.Microhard Bullet-LTE PingºÅÁî×¢Èë´úÂëÖ´Ðзì϶


Microhard Bullet-LTE tools.sh´¦ÖÃping²ÎÊý´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬ £¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâºÅÁî ¡£¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-20-1205/


5.Veritas APTAREÊÚȨ²é³­´úÂëÖ´Ðзì϶


Veritas APTAREÊÚȨ²é³­´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬ £¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë ¡£¡£¡£¡£¡£¡£


https://www.veritas.com/content/support/en_US/security/VTS20-006#issue1


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢BlackBerry°ä²¼¹ØÓÚBAHAMUT×éÖ¯µÄ·ÖÎö»ã±¨


1.jpg


BlackBerry°ä²¼Á˹ØÓÚBAHAMUTÍøÂç¼äµý×éÖ¯µÄ·ÖÎö»ã±¨£¬£¬£¬£¬£¬£¬£¬ £¬·¢ÏÔìä¶Ôµ±¾Ö¹ÙÔ±ºÍÖØÒªÐÐÒµÌáÒéÁË´óÁ¿¸ß¶È¸´ÔӵĹ¥»÷ ¡£¡£¡£¡£¡£¡£×êÑÐÅú×¢£¬£¬£¬£¬£¬£¬£¬ £¬¸ÃÍÅ»ïµÄ»î¶¯ÁìÓò±ÈÒÔǰÒÔΪµÄÒª¿í·ºµÃ¶à£¬£¬£¬£¬£¬£¬£¬ £¬Ô̺¬ÁËGoogle PlayÉ̵êºÍApp StoreÖеÄÊ®¼¸¸ö¶ñÒâÀûÓ÷¨Ê½ ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬ £¬BlackBerry»¹ÒÔΪ£¬£¬£¬£¬£¬£¬£¬ £¬BAHAMUTÄܹ»ÓëÖÁÉÙÒ»Ãû0day¿ª·¢ÈËÔ±½Ó´¥£¬£¬£¬£¬£¬£¬£¬ £¬²¢ÀûÓÃ0day¹¥»÷¶à¸öÖ¸±ê£¬£¬£¬£¬£¬£¬£¬ £¬ÕâÔ¶Ô¶³¬³öÁË´óÎÞÊýÆäËûºÚ¿Í×éÖ¯µÄ¹¥»÷ˮƽ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/cyber-espionage-bahamut-staggering/


2¡¢Lumu°ä²¼2020Äê¶ÈÀÕË÷Èí¼þÓ°Ïì·ÖÎöµÄÐÅϢͼ


2.jpg


Lumu°ä²¼ÁËÒ»ÕÅÐÅϢͼ£¬£¬£¬£¬£¬£¬£¬ £¬¾ßÌå˵ÁËÈ»ÀÕË÷Èí¼þµÄ³É±¾ºÍÁìÓò£¬£¬£¬£¬£¬£¬£¬ £¬ÒÔÔ®ÊÔìóÒµºâÁ¿ËûÃǵÄÊܺ¦·çÏÕ ¡£¡£¡£¡£¡£¡£¾Ý·ÖÎö£¬£¬£¬£¬£¬£¬£¬ £¬½ñÄêÈ«ÇòÀÕË÷Èí¼þµÄ³É±¾Îª200ÒÚÃÀÔª£¬£¬£¬£¬£¬£¬£¬ £¬¾ùÔÈÿ´ÎµÄ¹¥»÷³É±¾³¬¹ý400ÍòÃÀÔª£¬£¬£¬£¬£¬£¬£¬ £¬²¢ÇÒÓÐ36£¥µÄÊܺ¦ÕßÖ§¸¶ÁËÊê½ð£¬£¬£¬£¬£¬£¬£¬ £¬ÆäÖÐ17£¥»¹Ã»ÄÜÍì»ØËûÃǵÄÊý¾Ý ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬ £¬ÔÚ±±ÃÀÓÐ69%µÄ¹«Ë¾»ã±¨³ÆÊܵ½ÁËÀÕË÷Èí¼þµÄÓ°Ï죬£¬£¬£¬£¬£¬£¬ £¬¶øÔÚÅ·ÖÞÓÐ57% ¡£¡£¡£¡£¡£¡£Ïà½Ï¶øÑÔ£¬£¬£¬£¬£¬£¬£¬ £¬±±ÃÀÈ·µ±¾Ö»ú¹¹Êܵ½µÄ¹¥»÷×îΪÑϳÁ£¬£¬£¬£¬£¬£¬£¬ £¬Æä´ÎÊÇÔì×÷ÒµºÍ¹¹ÖþÒµ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://lumu.io/resources/2020-ransomware-flashcard/


3¡¢Adobe½¨¸´Flash PlayerÖеÄÔ¶³ÌÖ´ÐдúÂë·ì϶


3.jpg


Adobe½¨¸´ÁËFlash PlayerÖÐÑϳÁµÄÔ¶³ÌÖ´ÐдúÂë·ì϶£¨³ÆÎªCVE-2020-9746£© ¡£¡£¡£¡£¡£¡£AdobeÖ¸³ö£¬£¬£¬£¬£¬£¬£¬ £¬ÔÚĬÈÏÇé¿öÏ£¬£¬£¬£¬£¬£¬£¬ £¬ºÚ¿ÍÄܹ»Í¨¹ýÔÚÓû§½Ó¼ûÍøÕ¾Ê±ÔÚTLS / SSL´«µÝµÄHTTPÏìÓ¦ÖвåÈë¶ñÒâ×Ö·û´®À´ÀûÓô˷ì϶ ¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶ºó£¬£¬£¬£¬£¬£¬£¬ £¬¿ÉÄܵ¼ÖÂÀûÓñÀÀ££¬£¬£¬£¬£¬£¬£¬ £¬´Ó¶øÊ¹¹¥»÷ÕßÄܹ»ÔÚ½Ó¼ûÕßµÄÍÆËã»úÉÏÔ¶³ÌÖ´ÐкÅÁî ¡£¡£¡£¡£¡£¡£ÕâЩºÅÁÔÚÓû§µÄ°²È«»·¾³ÖÐÖ´ÐУ¬£¬£¬£¬£¬£¬£¬ £¬²¢²»±ØÒªÖÎÀíԱȨÏÞ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-security-vulnerability-in-flash-player/


4¡¢Agari°ä²¼BECÔÚÈ«ÇòÁìÓòÄÚÉ¢²¼ºÍÇ÷ÏòµÄ·ÖÎö»ã±¨


4.jpg


AgariÍøÂçµý±¨²¿£¨ACID£©°ä²¼ÁËBECÔÚÈ«ÇòÁìÓòÄÚÉ¢²¼ºÍÇ÷ÏòµÄ·ÖÎö»ã±¨£¬£¬£¬£¬£¬£¬£¬ £¬ÒÔ¸üºÃµØÏàʶBEC¹¥»÷»î¶¯ ¡£¡£¡£¡£¡£¡£»ã±¨Ô̺¬ÁË2019Äê5ÔÂÖÁ2020Äê7ÔÂÖ®¼äµÄ9000ÂŴηÀÓù»î¶¯µÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬ £¬·¢ÏÖÓÐ60£¥µÄ¹¥»÷ÕßÀ´×Ô·ÇÖÞµÄ11¸ö¹ú¶È£¬£¬£¬£¬£¬£¬£¬ £¬ÆäÖÐ83£¥Î»ÓÚÄáÈÕÀûÑÇ ¡£¡£¡£¡£¡£¡£½ü30£¥µÄ¹¥»÷ÕßÀ´×ÔÃÀÖÞ£¬£¬£¬£¬£¬£¬£¬ £¬ÆäÖеÄ89£¥À´×ÔÃÀ¹ú£¬£¬£¬£¬£¬£¬£¬ £¬²¢ÇÒ¹¥»÷ÕßÖØÒªÜöÝÍÔÚһЩ¶àÊý»á£¬£¬£¬£¬£¬£¬£¬ £¬Ô̺¬ÑÇÌØÀ¼´ó¡¢Å¦Ô¼¡¢ÂåÉ¼í¶¡¢ÐÝ˹¶ØºÍÂõ°¢ÃÜ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.agari.com/email-security-blog/business-email-compromise-geography/


5¡¢CNSA°ä²¼¡¶2020ÖйúÍøÂçÊÓÌý·¢Õ¹×êÑл㱨¡·


5.jpg


10ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬£¬ £¬ÖйúÍøÂçÊÓÌý½ÚÄ¿·þÎñЭ»á°ä²¼¡¶2020ÖйúÍøÂçÊÓÌý·¢Õ¹×êÑл㱨¡·£¬£¬£¬£¬£¬£¬£¬ £¬Ê׶ȹ«¿ªÎÒ¹úÍøÂçÊÓÌýÓû§¹æÄ£ºÍ²úÒµ¹æÄ£ ¡£¡£¡£¡£¡£¡£¸Ã»ã±¨»ùÓÚÊý¾ÝÍÚ¾ò¡¢µ÷ÑÐÒÔ¼°µÚÈý·½Êý¾Ý£¬£¬£¬£¬£¬£¬£¬ £¬¶Ô2019-2020ÄêµÄÍøÂçÊÓÌýÐÐÒµ½ü¿öºÍ·¢Õ¹Ç÷Ïò½øÐÐȨÍþ¡¢È«ÃæµÄÑÐÅÐ ¡£¡£¡£¡£¡£¡£»ã±¨ÏÔʾ£¬£¬£¬£¬£¬£¬£¬ £¬½ØÖÁ2020Äê6Ô£¬£¬£¬£¬£¬£¬£¬ £¬ÎÒ¹úÍøÂçÊÓÌýÓû§¹æÄ£´ï9.01ÒÚ£¬£¬£¬£¬£¬£¬£¬ £¬ 2019ÄêÍøÂçÊÓÌý²úÒµ¹æÄ£´ï4541.3ÒÚ ¡£¡£¡£¡£¡£¡£ÆäÖжÌÊÓÆµµÄÓû§Ê¹ÓÃÂÊ×î¸ß£¬£¬£¬£¬£¬£¬£¬ £¬´ï87.0%£¬£¬£¬£¬£¬£¬£¬ £¬Óû§¹æÄ£8.18ÒÚ£»£»£»£»£»£»£»£»×ÛºÏÊÓÆµµÄÓû§Ê¹ÓÃÂÊΪ77.1%£¬£¬£¬£¬£¬£¬£¬ £¬Óû§¹æÄ£7.24ÒÚ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

http://www.xinhuanet.com/info/2020-10/13/c_139436283.htm