ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ38ÖÜ
Ðû²¼Ê±¼ä 2020-09-21> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2020Äê09ÔÂ14ÈÕÖÁ09ÔÂ20ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´57¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe Media Encoder CVE-2020-9745Ô½½ç¶ÁÐÅϢ鶩¶´£»Gallagher Group Command Centre¿Í»§¶Ë¹ÒÆ𩶴£»Hyland OnBase CVE-2020-25248Ŀ¼±éÀú©¶´£»IPTV/H.264/H.265ÊÓƵ±àÂëÆ÷ºóÃÅÃÜÂë¹ÜÀíÔ±·ÃÎÊ©¶´£»Google Android Framework CVE-2020-0275ȨÏÞÌáÉý©¶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇRazerÊý¾Ý¿â̻¶µ¼ÖÂÆäÔ¼10ÍòÓû§ÐÅϢй¶£»RedgateÐû²¼2020Äê¶ÈÊý¾Ý¿â״̬¼à²â³ÂËߣ»Ó¢¹ú¹ú¼ÒÍøÂçÄþ¾²ÖÐÐÄ£¨NCSC£©Ðû²¼Â©¶´Åû¶ָÄÏ£»¿¨°Í˹»ùÐû²¼2020Ä깤ҵÍøÂçÄþ¾²ÊÓ²ìÑо¿³ÂËߣ»µÂ¹ú¹ºÎïÍøÕ¾windeln.deÊý¾Ý¿â̻¶£¬Ð¹Â¶60ÒÚÌõ¼Ç¼¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
> ÖØÒªÄþ¾²Â©¶´Áбí
1.Adobe Media Encoder CVE-2020-9745Ô½½ç¶ÁÐÅϢ鶩¶´
Adobe Media Encoder´æÔÚÔ½½ç¶ÁÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɻñÈ¡Ãô¸ÐÐÅÏ¢¡£
https://helpx.adobe.com/security/products/media-encoder/apsb20-57.html
2. Gallagher Group Command Centre¿Í»§¶Ë¹ÒÆ𩶴
Gallagher Group Command Centre´´½¨Guard Tourʼþ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿Éʹ¿Í»§¶ËÔÝʱ¹ÒÆð»ò¶Ï¿ªÁ¬½Ó¡£
https://security.gallagher.com/Security-Advisories/CVE-2020-16099
3.Hyland OnBase CVE-2020-25248Ŀ¼±éÀú©¶´
Hyland OnBase´æÔÚ·¾¶±éÀú©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎĶÁȡϵͳÎļþ»òдÈëϵͳµ½Îļþ¡£
https://seclists.org/fulldisclosure/2020/Sep/21
4. IPTV/H.264/H.265ÊÓƵ±àÂëÆ÷ºóÃÅÃÜÂë¹ÜÀíÔ±·ÃÎÊ©¶´
IPTV/H.264/H.265ÊÓƵ±àÂëÆ÷´æÔÚºóÃÅÃÜÂ멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉδÊÚȨÍêÈ«¿ØÖÆÓ¦Óá£
https://www.kb.cert.org/vuls/id/896979
5. Google Android Framework CVE-2020-0275ȨÏÞÌáÉý©¶´
Google Android Framework´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://source.android.com/security/bulletin/android-11
> ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢RazerÊý¾Ý¿â̻¶µ¼ÖÂÆäÔ¼10ÍòÓû§ÐÅϢй¶
8ÔÂ19ÈÕ£¬Ñо¿Ô±Bob Diachenko·¢ÏÖÓÎÏ·Ó²¼þÖÆÔìÉÌRazerµÄÔÚÏßÉ̵êµÄÊý¾Ý¿â̻¶£¬µ¼ÖÂÆäÔ¼10ÍòÓû§ÐÅϢй¶¡£´Ë´Î鶵ÄÐÅÏ¢°üÂÞ¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢¶©µ¥ºÅ¡¢¶©µ¥Ã÷ϸÒÔ¼°Õʵ¥ºÍËÍ»õµØÖ·µÈ¡£RazerÓÚÔÚ9ÔÂ9ÈÕÐÞ¸´Á˸ÃÊý¾Ý¿â·þÎñÆ÷£¬²¢ÌåÏÖ¸ÃʼþÖв¢Ã»ÓÐÆäËûÃô¸ÐÊý¾Ýй¶£¬ÀýÈçÐÅÓÿ¨ºÅ»òÃÜÂëµÈÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/razer-data-leak-exposes-personal-information-of-gamers/
2¡¢RedgateÐû²¼2020Äê¶ÈÊý¾Ý¿â״̬¼à²â³ÂËß
Redgate×îÐÂÐû²¼ÁË2020Äê¶ÈÊý¾Ý¿â״̬¼à²â³ÂËß¡£³ÂËßÏÔʾ£¬ÎÞÂÛÊÇÔÚ½ÓÄÉÊý¾Ý¿âDevOps·½Ã棬»¹ÊÇÔÚʹÓüà¿ØÀ´¸ú×ÙÊý¾Ý¿âÐÔÄܺͲ¿Êð·½Ã棬½ðÈÚ·þÎñÐÐÒµµÄÌåÏÖ¶¼ÓÅÓÚÆäËûÐÐÒµ¡£ÆäÖУ¬61%µÄ½ðÈÚ·þÎñÐÐÒµÔ±¹¤Ã¿ÖܸüÐÂÖÁÉÙÒ»´ÎÊý¾Ý¿â£¬¶øÆäËûÐÐÒµÖ»ÓÐ43%µÄÔ±¹¤»áÕâÑù×ö¡£½ðÈÚ·þÎñµÄ·þÎñÆ÷ÊýÁ¿Ò²¸ü¶à£¬36%µÄ·þÎñÆ÷ÓµÓÐ50µ½500¸öʵÀý£¬¶øÆäËû²¿ÃÅÖ»ÓÐ26%¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/09/14/database-monitoring-improves-devops-success/
3¡¢Ó¢¹ú¹ú¼ÒÍøÂçÄþ¾²ÖÐÐÄ£¨NCSC£©Ðû²¼Â©¶´Åû¶ָÄÏ
Ó¢¹ú¹ú¼ÒÍøÂçÄþ¾²ÖÐÐÄ£¨NCSC£©Ðû²¼ÁË©¶´Åû¶ָÄÏ£¬ÒÔ×ÊÖú¹«Ë¾ÊµÊ©Â©¶´Åû¶Á÷³Ì»òÔÚÒѾ½¨Á¢Â©¶´Åû¶Á÷³ÌµÄÇé¿ö϶ÔÆä½øÐиïС£NCSCÌåÏÖ£¬¸ÃÖ¸Äϲ¢²»ÊÇÒ»¸ö©¶´Åû¶µÄ¹æÔòÊֲᣬ¶øÊÇΪ¸üºÃµÄʵʩÌṩÁËÐëÒªµÄÐÅÏ¢¡£ÆäÖ÷Òª·ÖΪÈý¸öÖ÷Òª²¿ÃÅ£¬ÃèÊöÁËÈçºÎ½«Íⲿ©¶´ÐÅÏ¢¶¨Ïò¸øºÏÊʵÄÈË£¬ÒÔ¼°³ÂËßÐè×ñѹرÕ©¶´µÄ¿ò¼Ü³ß¶È¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/uk-government-releases-toolkit-to-easily-disclose-vulnerabilities/
4¡¢¿¨°Í˹»ùÐû²¼2020Ä깤ҵÍøÂçÄþ¾²ÊÓ²ìÑо¿³ÂËß
¿¨°Í˹»ù¶ÔÒßÇéÆÚ¼äµÄ¹¤ÒµÍøÂçÄþ¾²×´¿ö½øÐÐÁËÑо¿£¬²¢Ðû²¼ÁË2020Ä깤ҵÍøÂçÄþ¾²ÊÓ²ìÑо¿³ÂËß¡£³ÂËßÏÔʾ£¬Áè¼ÝÒ»°ë(53%)µÄÊÜ·ÃÕßÈÏ¿É£¬COVID-19µ¼Ö¸ü¶àÔ±¹¤ÔڼҰ칫£¬ÕâÒѳÉΪ¶ÔÐÅÏ¢Äþ¾²·þÎñµÄÒ»ÖÖѹÁ¦²âÊÔ¡£ÓÉÓÚÍⲿÁ¬½ÓÊýÁ¿Öڶ࣬ÏÖÔÚ¾ø´ó¶àÊý¹«Ë¾¶¼ÔÚ¶ÔOTÍøÂçµÄÄþ¾²¼¶±ð½øÐж¨ÆÚÆÀ¹À¡£Ðí¶à×éÖ¯²»µÃ²»ÖØп¼ÂÇËûÃÇÄÚÍøµÄ±£»¤ÒªÁ죬ֻÓÐ7%µÄÊÜ·ÃÕßÌåÏÖ£¬ËûÃǵÄÍøÂçÄþ¾²Õ½ÂÔÔÚCOVID-19ÆÚ¼äÏ൱ÓÐЧ¡£
ÔÎÄÁ´½Ó£º
https://www.kaspersky.com/blog/industrial-cybersecurity-2020/37031/
5¡¢µÂ¹ú¹ºÎïÍøÕ¾windeln.deÊý¾Ý¿â̻¶£¬Ð¹Â¶60ÒÚÌõ¼Ç¼
Safety DetectivesµÄÑо¿ÈËÔ±ÔÚÍøÂçÉÏ·¢ÏÖÁËÒ»¸ö̻¶µÄÊý¾Ý¿â£¬¾ÊÓ²ì¸ÃÊý¾Ý¿âÊôÓڵ¹úÔÚÏß¹ºÎïÍøÕ¾windeln.de¡£Æä̻¶ÁË6.4TBµÄÊý¾Ý£¬ÆäÖаüÂÞ60ÒÚÌõ¼Ç¼£¬Ð¹Â¶ÁËÁè¼Ý700000Ãû¿Í»§µÄ¸öÈËÐÅÏ¢¡£´Ë´ÎʼþµÄй¶ÐÅÏ¢°üÂÞ¸öÈËÉí·ÝÐÅÏ¢£¨PII£©ºÍÆäËûÊý¾Ý£¬ÀýÈ緢Ʊ¡¢È«Ãû¡¢IPµØÖ·¡¢ÄÚ²¿ÈÕÖ¾¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢¼ÒÍ¥µØÖ·¡¢É¢ÁÐÃÜÂë¡¢¸¶¿î·½Ê½ºÍÓû§µÄº¢×Ó¸öÈËÐÅÏ¢µÈ¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/shopping-site-leaks-miners-data-database-mess-up/