ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ41ÖÜ
Ðû²¼Ê±¼ä 2020-10-13> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2020Äê10ÔÂ05ÈÕÖÁ10ÔÂ11ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´57¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇGoogle Android Qualcomm±ÕÔ´×é¼þCVE-2020-3654´úÂëÖ´ÐЩ¶´£»Google Android Qualcomm±ÕÔ´×é¼þCVE-2020-3657´úÂëÖ´ÐЩ¶´£»Google Android system×é¼þCVE-2020-0416´úÂëÖ´ÐЩ¶´£»D-Link DAP-136 IP²ÎÊýÃüÁîÖ´ÐЩ¶´£»Facebook WhatsApp RTP ExtensionÕ»Òç³ö©¶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇ£ºCISAÐû²¼2019²ÆÄê·çÏÕ©¶´ÆÀ¹ÀµÄÐÅϢͼ£»Äþ¾²¹«Ë¾Arctic WolfÐû²¼Äþ¾²ÔËÓªÄê¶È³ÂËߣ»GoogleÐû²¼µÄChromeÄþ¾²¸üÐÂÐÞ¸´¶à¸ö©¶´£»AdobeÒò·þÎñÖжϵ¼ÖÂÓû§ÎÞ·¨µÇ¼Creative Cloud£»Android°æFacebookÖдæÔÚ©¶´£¬»ò½«µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
> ÖØÒªÄþ¾²Â©¶´Áбí
1.Google Android Qualcomm±ÕÔ´×é¼þCVE-2020-3654´úÂëÖ´ÐЩ¶´
Google Android Qualcomm±ÕÔ´×é¼þʵÏÖ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿Éʹ·þÎñ·¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://source.android.com/security/bulletin/2020-10-01
2.Google Android Qualcomm±ÕÔ´×é¼þCVE-2020-3657´úÂëÖ´ÐЩ¶´
Google Android Qualcomm±ÕÔ´×é¼þʵÏÖ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿Éʹ·þÎñ·¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://source.android.com/security/bulletin/2020-10-01
3.Google Android system×é¼þCVE-2020-0416´úÂëÖ´ÐЩ¶´
Google Android Framework×é¼þʵÏÖ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿Éʹ·þÎñ·¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://source.android.com/security/bulletin/2020-10-01
4.D-Link DAP-136 IP²ÎÊýÃüÁîÖ´ÐЩ¶´
D-Link DAP-136´¦ÖÃIP²ÎÊý´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâÃüÁî¡£
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10191
5.Facebook WhatsApp RTP ExtensionÕ»Òç³ö©¶´
Facebook WhatsApp RTP Extension½âÎö´æÔÚÕ»Òç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.whatsapp.com/security/advisories/2020/
> ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢CISAÐû²¼2019²ÆÄê·çÏÕ©¶´ÆÀ¹ÀµÄÐÅϢͼ
ÍøÂçÄþ¾²ºÍÐÅÏ¢Äþ¾²»ú¹¹(CISA)Ðû²¼ÁË2019²ÆÄê½øÐеÄ44Ïî·çÏպͩ¶´ÆÀ¹À£¨RVA£©£¬ÒÔ¼°MITER·´¿¹¼Æı¡¢¼¼ÊõºÍ֪ʶ£¨ATT£¦CK£©¿ò¼ÜµÄ·ÖÎöÐÅϢͼ¡£¸ÃÐÅϢͼ±íÈ·¶¨ÁËCISAÔÚ¿ç¶à¸ö²¿ÃŵÄRVAsÆÚ¼äÊӲ쵽µÄͨÀýÀֳɹ¥»÷·¾¶£¬ÍøÂç¹¥»÷Õß¿ÉÒÔÀûÓÃÕâЩ¹¥»÷;¾¶À´¹¥»÷×éÖ¯¡£CISAÃãÀøÍøÂç¹ÜÀíÔ±ºÍITרҵÈËÔ±¼ì²ìÐÅϢͼ²¢Ó¦ÓÃÍƼöµÄ·ÀÓù¼Æı£¬ÒÔ·ÀÖ¹Êܵ½ÒÑÖªÕ½ÊõºÍ¼¼ÊõµÄ¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2020/10/07/cisa-releases-fy2019-risk-vulnerability-assessment-infographic
2¡¢Äþ¾²¹«Ë¾Arctic WolfÐû²¼Äþ¾²ÔËÓªÄê¶È³ÂËß
Äþ¾²¹«Ë¾Arctic WolfÐû²¼ÁËÒ»·ÝÄþ¾²ÔËÓªÄê¶È³ÂËß¡£³ÂËßÏÔʾ£¬×Ô3ÔÂÒÔÀ´£¬°µÍøÉϹûÈ»µÄ¹«Ë¾Æ¾¾ÝÊýÁ¿Ôö¼ÓÁË429£¥¡£ÔÚÊӲ쵽µÄ¸ß·çÏÕÄþ¾²Ê¼þÖУ¬ÓÐ35£¥·¢ÉúÔÚ8:00 PMºÍ8:00 AMÖ®¼ä£¬¶ø14£¥·¢ÉúÔÚÖÜÄ©£¬ÕâÊÇÐí¶àÄÚ²¿Äþ¾²ÍŶӲ»ÔÚÏßµÄʱ¼ä¡£´ËÍ⣬ÍøÂçµöÓãºÍÀÕË÷Èí¼þ¹¥»÷´ÎÊýÔö¼ÓÁË64£¥£¬ºÚ¿Í¸ü¶àµÄÒÔCOVID-19Ö÷ÌâΪÓÕ¶ü£¬À´Õë¶ÔÔ¶³ÌÊÂÇéÕß¡£
ÔÎÄÁ´½Ó£º
https://arcticwolf.com/resources/analyst-reports/security-operations-annual-report
3¡¢GoogleÐû²¼µÄChromeÄþ¾²¸üÐÂÐÞ¸´¶à¸ö©¶´
GoogleÐû²¼µÄChromeÄþ¾²¸üÐÂÕë¶ÔWindows¡¢MacºÍLinux°æ±¾ÐÞ¸´ÁË35¸ö©¶´¡£ÆäÖнÏΪÑÏÖصÄ©¶´ÎªÖ§¸¶ÖеÄÊͷźóʹÓ鶴£¨CVE-2020-15967£©£¬Æä´ÎΪBlink¡¢WebRTC¡¢NFC¡¢´òÓ¡¡¢ÒôƵ¡¢×Ô¶¯Ìî³äºÍÃÜÂë¹ÜÀíÆ÷ÖеÄÊͷźóʹÓ鶴£¨CVE-2020-15968¡¢CVE-2020-15969¡¢CVE-2020-15970¡¢CVE-2020-15971¡¢CVE-2020-15972¡¢CVE-2020-15990ºÍCVE-2020-15991£©¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2020/10/07/google-releases-security-updates-chrome
4¡¢AdobeÒò·þÎñÖжϵ¼ÖÂÓû§ÎÞ·¨µÇ¼Creative Cloud
AdobeÒò·þÎñÖжϣ¬µ¼ÖÂÓû§ÎÞ·¨µÇ¼Creative Cloud»ò·ÃÎÊÆ䶩ÔĵÄÓ¦Ó÷¨Ê½»ò´æ´¢µÄÊý¾Ý¡£×ÔÃÀ¹ú¶«²¿Ê±¼äÉÏÎç9:30ÒÔÀ´£¬Adobe Creative CloudÓû§¿ªÊ¼³ÂËßÎÞ·¨µÇ¼¸Ã·þÎñ»ò·ÃÎÊÉú´æµÄͼÏñºÍÊý¾Ý£¬µ±ËûÃÇÊÔͼµÇ¼µÄʱºò£¬¾Í»áÏÔʾ¡°·¢ÉúÁËһЩ´íÎó¡±µÄÌáʾ¡£Ä¿Ç°£¬AdobeÒÑÔÚstatus.adobe.comÒ³ÃæÉÏÐû²¼Í¨ÖªÈ·ÈÏÁËÖжϣ¬µ«²¢Î´ÌṩÈκÎÓйش˴ÎÖжϵÄÏêϸÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/technology/adobe-creative-cloud-down-users-report-login-data-access-issues/
5¡¢Android°æFacebookÖдæÔÚ©¶´£¬»ò½«µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ
Äþ¾²Ñо¿Ô±Sayed Abdelhafiz·¢ÏÖ£¬Android°æFacebookÖдæÔÚÑÏÖØ©¶´£¬¸Ã©¶´»ò½«µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬ÀûÓø鶴¿ÉÄܵ¼ÖÂÓ¦ÓÃÍß½âÒÔ¼°É豸½Ó¹Ü¡£FacebookÔÊÐíͨ¹ýÁ½ÖÖ·½Ê½ÏÂÔØÎļþ£¬ÆäÖÐÒ»ÖÖÊÇʹÓá°Îļþ¡±Ñ¡Ï£¬½«ÎļþÏÈÌáÈ¡µ½DownloadManager£¬È»ºóÉú´æµ½Download Director¡£Abdelhafiz·¢ÏÖ¿ÉÒÔ´´½¨²¢ÏÂÔØÒ»¸ö¶ñÒâÎļþ£¬È»ºóÔÚÄ¿±êÉ豸ÉÏÖ´ÐÐÈÎÒâ´úÂë¡£FacebookÔڵõ½Â©¶´³ÂËߺó£¬ÒÑÓÚ2020Äê6ÔÂÐÞ¸´Á˸鶴¡£
ÔÎÄÁ´½Ó£º
https://latesthackingnews.com/2020/10/08/code-execution-vulnerability-found-in-facebook-for-android/