ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ41ÖÜ

Ðû²¼Ê±¼ä 2020-10-13

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2020Äê10ÔÂ05ÈÕÖÁ10ÔÂ11ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´57¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇGoogle Android Qualcomm±ÕÔ´×é¼þCVE-2020-3654´úÂëÖ´ÐЩ¶´£»Google Android Qualcomm±ÕÔ´×é¼þCVE-2020-3657´úÂëÖ´ÐЩ¶´£»Google Android system×é¼þCVE-2020-0416´úÂëÖ´ÐЩ¶´£»D-Link DAP-136 IP²ÎÊýÃüÁîÖ´ÐЩ¶´£»Facebook WhatsApp RTP ExtensionÕ»Òç³ö©¶´ ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇ£ºCISAÐû²¼2019²ÆÄê·çÏÕ©¶´ÆÀ¹ÀµÄÐÅϢͼ£»Äþ¾²¹«Ë¾Arctic WolfÐû²¼Äþ¾²ÔËÓªÄê¶È³ÂËߣ»GoogleÐû²¼µÄChromeÄþ¾²¸üÐÂÐÞ¸´¶à¸ö©¶´£»AdobeÒò·þÎñÖжϵ¼ÖÂÓû§ÎÞ·¨µÇ¼Creative Cloud£»Android°æFacebookÖдæÔÚ©¶´£¬»ò½«µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖÐ ¡£


ÖØÒªÄþ¾²Â©¶´Áбí


1.Google Android Qualcomm±ÕÔ´×é¼þCVE-2020-3654´úÂëÖ´ÐЩ¶´


Google Android Qualcomm±ÕÔ´×é¼þʵÏÖ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿Éʹ·þÎñ·¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë ¡£

https://source.android.com/security/bulletin/2020-10-01


2.Google Android Qualcomm±ÕÔ´×é¼þCVE-2020-3657´úÂëÖ´ÐЩ¶´


Google Android Qualcomm±ÕÔ´×é¼þʵÏÖ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿Éʹ·þÎñ·¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë ¡£

https://source.android.com/security/bulletin/2020-10-01


3.Google Android system×é¼þCVE-2020-0416´úÂëÖ´ÐЩ¶´


Google Android Framework×é¼þʵÏÖ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿Éʹ·þÎñ·¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë ¡£

https://source.android.com/security/bulletin/2020-10-01


4.D-Link DAP-136 IP²ÎÊýÃüÁîÖ´ÐЩ¶´


D-Link DAP-136´¦ÖÃIP²ÎÊý´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâÃüÁî ¡£

https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10191


5.Facebook WhatsApp RTP ExtensionÕ»Òç³ö©¶´


Facebook WhatsApp RTP Extension½âÎö´æÔÚÕ»Òç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë ¡£

https://www.whatsapp.com/security/advisories/2020/


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢CISAÐû²¼2019²ÆÄê·çÏÕ©¶´ÆÀ¹ÀµÄÐÅϢͼ



1.png


ÍøÂçÄþ¾²ºÍÐÅÏ¢Äþ¾²»ú¹¹(CISA)Ðû²¼ÁË2019²ÆÄê½øÐеÄ44Ïî·çÏպͩ¶´ÆÀ¹À£¨RVA£©£¬ÒÔ¼°MITER·´¿¹¼Æı¡¢¼¼ÊõºÍ֪ʶ£¨ATT£¦CK£©¿ò¼ÜµÄ·ÖÎöÐÅϢͼ ¡£¸ÃÐÅϢͼ±íÈ·¶¨ÁËCISAÔÚ¿ç¶à¸ö²¿ÃŵÄRVAsÆÚ¼äÊӲ쵽µÄͨÀýÀֳɹ¥»÷·¾¶£¬ÍøÂç¹¥»÷Õß¿ÉÒÔÀûÓÃÕâЩ¹¥»÷;¾¶À´¹¥»÷×éÖ¯ ¡£CISAÃãÀøÍøÂç¹ÜÀíÔ±ºÍITרҵÈËÔ±¼ì²ìÐÅϢͼ²¢Ó¦ÓÃÍƼöµÄ·ÀÓù¼Æı£¬ÒÔ·ÀÖ¹Êܵ½ÒÑÖªÕ½ÊõºÍ¼¼ÊõµÄ¹¥»÷ ¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/10/07/cisa-releases-fy2019-risk-vulnerability-assessment-infographic


2¡¢Äþ¾²¹«Ë¾Arctic WolfÐû²¼Äþ¾²ÔËÓªÄê¶È³ÂËß


2.png


Äþ¾²¹«Ë¾Arctic WolfÐû²¼ÁËÒ»·ÝÄþ¾²ÔËÓªÄê¶È³ÂËß ¡£³ÂËßÏÔʾ£¬×Ô3ÔÂÒÔÀ´£¬°µÍøÉϹûÈ»µÄ¹«Ë¾Æ¾¾ÝÊýÁ¿Ôö¼ÓÁË429£¥ ¡£ÔÚÊӲ쵽µÄ¸ß·çÏÕÄþ¾²Ê¼þÖУ¬ÓÐ35£¥·¢ÉúÔÚ8:00 PMºÍ8:00 AMÖ®¼ä£¬¶ø14£¥·¢ÉúÔÚÖÜÄ©£¬ÕâÊÇÐí¶àÄÚ²¿Äþ¾²ÍŶӲ»ÔÚÏßµÄʱ¼ä ¡£´ËÍ⣬ÍøÂçµöÓãºÍÀÕË÷Èí¼þ¹¥»÷´ÎÊýÔö¼ÓÁË64£¥£¬ºÚ¿Í¸ü¶àµÄÒÔCOVID-19Ö÷ÌâΪÓÕ¶ü£¬À´Õë¶ÔÔ¶³ÌÊÂÇéÕß ¡£


Ô­ÎÄÁ´½Ó£º

https://arcticwolf.com/resources/analyst-reports/security-operations-annual-report


3¡¢GoogleÐû²¼µÄChromeÄþ¾²¸üÐÂÐÞ¸´¶à¸ö©¶´


3.png


GoogleÐû²¼µÄChromeÄþ¾²¸üÐÂÕë¶ÔWindows¡¢MacºÍLinux°æ±¾ÐÞ¸´ÁË35¸ö©¶´ ¡£ÆäÖнÏΪÑÏÖصÄ©¶´ÎªÖ§¸¶ÖеÄÊͷźóʹÓ鶴£¨CVE-2020-15967£©£¬Æä´ÎΪBlink¡¢WebRTC¡¢NFC¡¢´òÓ¡¡¢ÒôƵ¡¢×Ô¶¯Ìî³äºÍÃÜÂë¹ÜÀíÆ÷ÖеÄÊͷźóʹÓ鶴£¨CVE-2020-15968¡¢CVE-2020-15969¡¢CVE-2020-15970¡¢CVE-2020-15971¡¢CVE-2020-15972¡¢CVE-2020-15990ºÍCVE-2020-15991£© ¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/10/07/google-releases-security-updates-chrome


4¡¢AdobeÒò·þÎñÖжϵ¼ÖÂÓû§ÎÞ·¨µÇ¼Creative Cloud


4.png


AdobeÒò·þÎñÖжÏ£¬µ¼ÖÂÓû§ÎÞ·¨µÇ¼Creative Cloud»ò·ÃÎÊÆ䶩ÔĵÄÓ¦Ó÷¨Ê½»ò´æ´¢µÄÊý¾Ý ¡£×ÔÃÀ¹ú¶«²¿Ê±¼äÉÏÎç9:30ÒÔÀ´£¬Adobe Creative CloudÓû§¿ªÊ¼³ÂËßÎÞ·¨µÇ¼¸Ã·þÎñ»ò·ÃÎÊÉú´æµÄͼÏñºÍÊý¾Ý£¬µ±ËûÃÇÊÔͼµÇ¼µÄʱºò£¬¾Í»áÏÔʾ¡°·¢ÉúÁËһЩ´íÎó¡±µÄÌáʾ ¡£Ä¿Ç°£¬AdobeÒÑÔÚstatus.adobe.comÒ³ÃæÉÏÐû²¼Í¨ÖªÈ·ÈÏÁËÖжÏ£¬µ«²¢Î´ÌṩÈκÎÓйش˴ÎÖжϵÄÏêϸÐÅÏ¢ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/technology/adobe-creative-cloud-down-users-report-login-data-access-issues/


5¡¢Android°æFacebookÖдæÔÚ©¶´£¬»ò½«µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ


5.png


Äþ¾²Ñо¿Ô±Sayed Abdelhafiz·¢ÏÖ£¬Android°æFacebookÖдæÔÚÑÏÖØ©¶´£¬¸Ã©¶´»ò½«µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬ÀûÓø鶴¿ÉÄܵ¼ÖÂÓ¦ÓÃÍß½âÒÔ¼°É豸½Ó¹Ü ¡£FacebookÔÊÐíͨ¹ýÁ½ÖÖ·½Ê½ÏÂÔØÎļþ£¬ÆäÖÐÒ»ÖÖÊÇʹÓá°Îļþ¡±Ñ¡Ï£¬½«ÎļþÏÈÌáÈ¡µ½DownloadManager£¬È»ºóÉú´æµ½Download Director ¡£Abdelhafiz·¢ÏÖ¿ÉÒÔ´´½¨²¢ÏÂÔØÒ»¸ö¶ñÒâÎļþ£¬È»ºóÔÚÄ¿±êÉ豸ÉÏÖ´ÐÐÈÎÒâ´úÂë ¡£FacebookÔڵõ½Â©¶´³ÂËߺó£¬ÒÑÓÚ2020Äê6ÔÂÐÞ¸´Á˸鶴 ¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2020/10/08/code-execution-vulnerability-found-in-facebook-for-android/