AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2020.10.19-2020.10.25£©
2020-10-26
Ò»¡¢ Íþвͨ¸æ
VMware ESXi Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-3992£©
¡¾Ðû²¼Ê±¼ä¡¿2020-10-22 12:00:00 GMT
¡¾¸ÅÊö¡¿
10 ÔÂ21 ÈÕ£¬AG¹«Ë¾¿Æ¼¼¼à²âµ½VMware ¹Ù·½Ðû²¼Ç徲ͨ¸æÐÞ¸´ÁËÒ»¸öVMware ESXi Ô¶³Ì´ú ÂëÖ´ÐÐÎó²î£¨CVE-2020-3992£©¡£Îó²îȪԴÓÚESXi ÖÐʹÓõÄOpenSLP ±£´æ“use-after-free”Êͷźó ÖØÊ¹ÓÃÎÊÌ⣬µ±¹¥»÷ÕßÔÚÖÎÀíÍøÂ磨management network£©ÖÐʱ£¬¿ÉÒÔͨ¹ý»á¼ûESXi ËÞÖ÷»ú µÄ427 ¶Ë¿Ú´¥·¢OpenSLP ·þÎñµÄuser-after-free£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£CVSS ÆÀ·ÖΪ9.8£¬ ÇëÏà¹ØÓû§½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
Weblogic ¶à¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-14825¡¢CVE-2020-14841¡¢CVE-2020-14859……£©
¡¾Ðû²¼Ê±¼ä¡¿2020-10-22 17:00:00 GMT
¡¾¸ÅÊö¡¿
10 ÔÂ21 ÈÕ£¬AG¹«Ë¾¿Æ¼¼¼à²âµ½Oracle ¹Ù·½Ðû²¼2020 Äê10 ÔÂÒªº¦²¹¶¡¸üУ¨Critical Patch U pdate£©£¬ÐÞ¸´ÁË402 ¸öΣº¦Ë®Æ½²î±ðµÄÇå¾²Îó²î¡£ÆäÖаüÀ¨5 ¸öWebLogic µÄÑÏÖØÎó²î£¨CVE -2020-14825¡¢CVE-2020-14841¡¢CVE-2020-14859¡¢CVE-2020-14882¡¢CVE-2019-17267£©£¬Î´¾ Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ý´Ë´ÎµÄÎó²îʵÏÖÔ¶³Ì´úÂëÖ´ÐС£CVSS ÆÀ·Ö¾ùΪ9.8£¬Ê¹ÓÃÖØÆ¯ºóµÍ¡£ ½¨ÒéÓû§¾¡¿ì½ÓÄɲ½·¥£¬¶ÔÉÏÊöÎó²î¾ÙÐзÀ»¤¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
Oracle ȫϵ²úÆ·2020 Äê10 ÔÂÒªº¦ ²¹¶¡¸üÐÂͨ¸æ£¨CVE-2020-14841¡¢CVE-2020-14825¡¢CVE-2020-14859£©
¡¾Ðû²¼Ê±¼ä¡¿2020-10-22 17:00:00 GMT
¡¾¸ÅÊö¡¿
2020 Äê10 ÔÂ21 ÈÕ£¬AG¹«Ë¾¿Æ¼¼¼à²âµ½Oracle ¹Ù·½Ðû²¼ÁË2020 Äê10 ÔÂÒªº¦²¹¶¡¸üÐÂͨ¸æ CPU£¨Critical Patch Update£©£¬´Ë´Î¸üÐÂÐÞ¸´ÁË402 ¸ö²î±ðˮƽµÄÎó²î£¬ÆäÖÐ271 ¸öÎó²î¿É±» Ô¶³Ìδ¾Éí·ÝÈÏÖ¤µÄ¹¥»÷ÕßʹÓᣴ˴θüÐÂÉæ¼°Oracle Database Server¡¢Oracle Weblogic Serv er¡¢Oracle Java SE¡¢Oracle MySQL µÈ¶à¸ö²úÆ·¡£¸÷²úÆ·ÊÜÓ°ÏìÇéÐμ°¿ÉÓò¹¶¡Çë¼û¸½Â¼¡£Oracl e Ç¿ÁÒ½¨Òé¿Í»§¾¡¿ìÓ¦ÓÃÒªº¦²¹¶¡¸üÐÂÐÞ¸´³ÌÐò£¬¶ÔÎó²î¾ÙÐÐÐÞ¸´¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. VMwareÐÞ²¹ÁËESXi£¬Workstation£¬FusionºÍNSX-T²úÆ·ÖеĶà¸öÎó²î£¬°üÀ¨Ò»¸öÒªº¦µÄ´úÂëÖ´ÐÐÎó²î
¡¾¸ÅÊö¡¿
VMwareÒÑÐÞ¸´ÆäESXi£¬Workstation£¬FusionºÍNSX-T²úÆ·ÖеĶà¸öÎó²î£¬ÆäÖаüÀ¨Ò»¸öÔÊÐíí§Òâ´úÂëÖ´ÐеÄÑÏÖØÈ±ÏÝ¡£¸ú×ÙΪCVE-2020-3992µÄÑÏÖØÎó²îÊÇÒ»¸öÏÈʹÓúóʹÓõÄÎÊÌ⣬Ëü»áÓ°ÏìESXiÖеÄOpenSLP·þÎñ¡£¸ÃÎó²î¿ÉÄÜÔÊÐíÔ¶³Ì¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄESXi²úÆ·×°ÖÃÉÏÖ´ÐÐí§Òâ´úÂë¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/109843/security/vmware-critical-flaws.html
2. Instagram±»ÊÓ²ìÆØ¹âδ³ÉÄêÈËϸ½Ú
¡¾¸ÅÊö¡¿
°®¶ûÀ¼µÄÊý¾Ý±£»¤×¨Ô±ÒÑ×îÏÈÊÓ²ìFacebookµÄInstagram·þÎñÊÇ·ñÔÚÆäÆ½Ì¨ÉÏδ׼ȷÏÔʾδ³ÉÄêÈ˵ĵç×ÓÓʼþµØµãºÍµç»°ºÅÂë¡£Stier·¢Ã÷£¬È«ÇòÖÁÉÙÓÐ200Íò¸ö12ÖÁ15ËêµÄ¶ùͯºÍ300Íò¸ö16»ò17ËêµÄº¢×Ó½«ÆäInstagramСÎÒ˽¼Ò×ÊÁÏת»»Îª“ÆóÒµ”×ÊÁÏ¡£ÕâÑù»á×Ô¶¯½«Óû§µÄµç×ÓÓʼþµØµã»òµç»°ºÅÂ루»òÁ½Õß¶¼¹ûÕæ£©¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.inforisktoday.com/instagram-investigated-for-exposure-minors-details-a-15197
3. 2020ÄêÔÆÇå¾²µÄ¾Å´ó¸Åº¦Ç÷ÊÆ
¡¾¸ÅÊö¡¿
2020ÄêйÚÒßÇé¼ÓËÙÁË“ÔÆÅÌËãÓëÇå¾²”¡¢“ÍøÂçÓëÇå¾²”µÄÈÚºÏÇ÷ÊÆ¡£“ÔÆÓÅÏȔʱ´ú£¬ÆóÒµÔ½À´Ô½ÒÀÀµÔÆÅÌËã¡£¿ÉÊǹØÓÚ´ó´ó¶¼ÆóÒµÀ´Ëµ£¬ÓªÒµÉÏÔÆ²¢²»ÁÏζ×ÅÇå¾²ÉÏÔÆ£¬“¿¿É½É½µ¹”£¬ÒªÏëÈ·±£ÔÆ·þÎñµÄÇå¾²£¬½ö½öÒÀÀµ»òÐÅÍÐÔÆ·þÎñÉÌÊÇÔ¶Ô¶²»·óµÄ¡£ÆóÒµ»¹ÐèÒªÍê³É¹Å°åÍøÂçÇ徲ͷÄÔµÄת±ä£º“ÔÆÇ徲ʼÓÚÔÆÔÉúÍ·ÄÔ·½·¨£¬ÕâÖÖÍ·ÄÔ·½·¨²»ÔÙÃæÏòÍøÂ磬¶ø¸ü¶àµØÃæÏòÉí·Ý¡¢Êý¾ÝºÍÓ¦ÓóÌÐò¡£”
¡¾²Î¿¼Á´½Ó¡¿
https://www.aqniu.com/industry/70748.html
4. Gartner2020ÄêÊ®´óÇå¾²ÏîÄ¿Ïê½â
¡¾¸ÅÊö¡¿
ÊÜÒßÇéµÄÓ°Ï죬2020ÄêÖÐÀýÐеÄGartnerÇå¾²ÓëΣº¦ÖÎÀí·å»á±»ÆÈ×÷·Ï¡£ÖÕÓÚ£¬ÔÚ2020Äê9ÔÂ14~17ÈÕ£¬2020ÄêGartnerÇ徲Σº¦ÓëÖÎÀí·å»áÒÔÏßÉϾۻáµÄÐÎʽ²¹ÉÏÁË¡£»áÉÏ£¬ÕýʽÐû²¼ÁË2020Äê¶ÈµÄÊ®´óÇå¾²ÏîÄ¿£¬Ðû²¼ÈËÕÕ¾ÉBrian Reed¡£ÕâÊ®´óÏîÄ¿ÏÈÈÝGartnerÖйúµÄ¹Ù΢×öÁËÏÈÈÝ£¬µ«±¾ÎÄÒÔΪÓм¸´¦·Òë²»µ±¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.anquanke.com/post/id/220104
5. ¹È¸èÔÚLinuxÄں˷¢Ã÷À¶ÑÀÎó²î ¹¥»÷Õß¿Éí§Òâ»á¼ûÃô¸ÐÐÅÏ¢
¡¾¸ÅÊö¡¿
¾ÝÍâý±¨µÀ£¬¿ËÈչȸèÇå¾²Ñо¿Ö°Ô±ÔÚLinuxÄÚºËÖз¢Ã÷ÁËÒ»×éÀ¶ÑÀÎó²î£¨BleedingTooth£©£¬¸ÃÎó²î¿ÉÄÜÔÊÐí¹¥»÷Õß¾ÙÐÐÁãµã»÷¹¥»÷£¬ÔËÐÐí§Òâ´úÂë»ò»á¼ûÃô¸ÐÐÅÏ¢¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.easyaq.com/news/2147307904.shtml
6. ΢ÈíÆô¶¯Õë¶ÔChromiumµÄÁãÈÕÎó²îÍýÏë
¡¾¸ÅÊö¡¿
ÔÚ2020Äê1Ô·ÝÐû²¼Ê¹ÓÿªÔ´´úÂë¿âÖØÐÞEdgeä¯ÀÀÆ÷Ö®ºó£¬Î¢Èí¿ËÈÕÐû²¼Æô¶¯ÁËÕë¶ÔChromiumµÄÀàËÆGoogle Project ZeroÆø¸ÅµÄÁãÈÕÎó²îÇå¾²Ñо¿ÍýÏë¡£Ò»×éä¯ÀÀÆ÷Ç徲ר¼Ò½«¶ÔGoogleµÄä¯ÀÀÆ÷¿ª·¢¿â¾ÙÐÐÉîÈëÑо¿¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.aqniu.com/industry/70777.html
7. °×¹¬·ñ¶¨ÌØÀÊÆÕµÄTwitterÕÊ»§±»ºÚ¿ÍÈëÇÖ
¡¾¸ÅÊö¡¿
ºÉÀ¼Ò»ÃûºÚ¿ÍÉù³ÆËû±¾Ô³õͨ¹ýÍÆ²âÃÜÂë»á¼ûÁËÌÆÄÉµÂ·ÌØÀÊÆÕ×ÜͳµÄÍÆÌØÕÊ»§£¬´Ó¶øÊ¹ËûÄܹ»»ñµÃËùÓÐÌØÈ¨²¢²¶»ñÆÁÄ»½ØÍ¼¡£µ«TwitterÌåÏÖûÓÐÖ¤¾ÝÅú×¢ÒѾ¾ÙÐÐÁËÕÊ»§»á¼û¡£¡¾²Î¿¼Á´½Ó¡¿
https://www.inforisktoday.com/white-house-denies-trumps-twitter-account-was-hacked-a-15228
8. ÈðµäեȡÔÚ5GÍøÂçÖÐʹÓûªÎªºÍÖÐÐË×°±¸
¡¾¸ÅÊö¡¿
ÈÕǰ£¬ÈðµäÒÑեȡÔÚÆä5GÍøÂçÖÐʹÓûªÎªºÍÖÐÐ˵ĵçÐÅ×°±¸¡£µçÐÅ»ú¹¹ÈðµäÓʵçÖÎÀí¾Ö£¨PTS£©ÔÚ¾ÙÐÐÇå¾²ÆÀ¹Àºó×ö³öÁËÕâÒ»¾öÒé¡£ÕâÏîÆÀ¹ÀÒÔΪ»ªÎªºÍÖÐÐ˵Ť¾ß°ü¿ÉÄÜ»áËðº¦ÈðµäµÄÇå¾²¡£¾ÝϤ£¬Çå¾²ÆÀ¹ÀÊÇÈðµäÎä×°²½¶ÓºÍÈðµäÇå¾²¾ÖÍŽá¾ÙÐеġ£
¡¾²Î¿¼Á´½Ó¡¿
https://www.freebuf.com/news/252576.html
9. ÌÚѶÖ÷»úÇå¾²£¨Ôƾµ£©²¶»ñ8220ÍÚ¿óÍÅ»ï×îбäÖÖʹÓÃÐÂÎó²î¶ÔÆóÒµÔÆ·þÎñÆ÷µÄ¹¥»÷
¡¾¸ÅÊö¡¿
ÌÚѶÇå¾²½Óµ½Óû§ÇóÖú£¬±¨¸æÌÚÑ¶ÔÆÖ÷»úÇå¾²£¨Ôƾµ£©ÍøÂç·ÀÓù¹¦Ð§¼ì²âµ½¹¥»÷ÊÂÎñ¡£ÌÚѶÇ徲ר¼Òͨ¹ý¹¥»÷ÈÕÖ¾ÆÊÎö£¬·¢Ã÷ÕâÊÇ8220ÍÚ¿óÍÅ»ï×îбäÖÖÕë¶ÔÆóÒµÔÆ·þÎñÆ÷µÄ¹¥»÷Ô˶¯£¬¸ÃÓû§¶ÔÌÚѶÖ÷»úÇå¾²£¨Ôƾµ£©ÈÕÖ¾¸æ¾¯ÊµÊ±´¦Öóͷ££¬Òѳ¹µ×Ïû³ý¸ÃÍÚ¿óÍÅ»ïµÄÍþв¡£
¡¾²Î¿¼Á´½Ó¡¿
https://s.tencent.com//research/report/1155.html

AG¹«Ë¾ÔÆ







