΢Èí°ä²¼9Ô·ݰ²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬×ܼƽ¨¸´129¸ö·ì϶£»£»£»£»£»£»£»£»Digital PointÊý¾Ý¿âÅäÖÃÃýÎ󹫿ª³¬¹ý80ÍòÓû§µÄ¼Í¼
°ä²¼¹¦·ò 2020-09-091.΢Èí°ä²¼9Ô·ݰ²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬×ܼƽ¨¸´129¸ö·ì϶

΢Èí°ä²¼ÁË9Ô·ݰ²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬×ܼƽ¨¸´129¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬23¸öÑϳÁ·ì϶¡£¡£¡£¡£¡£¡£Ö»¹ÜÕâ´Î¸üÐÂÖв¢Ã»ÓÐ0day£¬£¬£¬£¬£¬£¬£¬£¬µ«ÈÔÓкܶà·ì϶¿É±»Ô¶³ÌÀûÓᣡ£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ¾ÍΪÑϳÁµÄÈý¸ö·ì϶±ðÀëΪMicrosoft ExchangeÄÚ´æ°Ü»µ·ì϶£¨CVE-2020-16875£©£¬£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷ÕßÀûÓø÷ì϶Äܹ»½öͨ¹ýÏòExchange·þÎñÆ÷·¢ËÍÌØÔìµç×ÓÓʼþÔ¶³ÌÖ´ÐдúÂ룬£¬£¬£¬£¬£¬£¬£¬WindowsÔ¶³ÌÖ´ÐдúÂëµÄMicrosoft COM·ì϶£¨CVE-2020-0922£©£¬£¬£¬£¬£¬£¬£¬£¬Äܹ»Í¨¹ýÓÕʹÓû§½Ó¼û´øÓжñÒâJavaScriptµÄÕ¾µãÀ´¼ÓÒÔÀûÓ㬣¬£¬£¬£¬£¬£¬£¬ÒÔ¼°WindowsÎı¾·þÎñÄ£¿£¿£¿£¿£¿éÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-0908£©£¬£¬£¬£¬£¬£¬£¬£¬Äܹ»Í¨¹ýÓÕʹÓû§½Ó¼ûÔ̺¬¶ñÒâ¸æ°×µÄÍøÕ¾À´¼ÓÒÔÀûÓᣡ£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2020-patch-tuesday-fixes-129-vulnerabilities/
2.ºÚ¿Í¿ÉÓÃÌØÔìµÄWin10Ö÷ÌâÌáÒéHash´«µÝ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÇÔÈ¡Óû§Æ¾Ö¤

ºÚ¿Í¿ÉÓÃÌØÔìµÄWin10Ö÷ÌâºÍÖ÷Ìâ°üÌáÒéHash´«µÝ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÇÔÈ¡Óû§Æ¾Ö¤¡£¡£¡£¡£¡£¡£°²È«×êÑÐÔ±Jimmy Bayne·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»´´½¨ÌØÔìµÄ.themeÎļþ£¨Win10Ö÷ÌâÉèÖÃÎļþ£©£¬£¬£¬£¬£¬£¬£¬£¬²¢½«Ö÷ÌâÉèÖøü¸ÄΪʹÓÃÔ¶³ÌÉí·ÝÑéÖ¤ËùÐèµÄ×ÊÔ´¡£¡£¡£¡£¡£¡£µ±Windows³¢ÊÔ½Ó¼û±ØÒª½øÐÐÉí·ÝÑéÖ¤µÄÔ¶³Ì×ÊԴʱ£¬£¬£¬£¬£¬£¬£¬£¬Ëü½«Í¨¹ý·¢ËÍÒѵǼÕÊ»§µÄNTLMÉ¢Áк͵ǼÃûÀ´×Ô¶¯³¢ÊԵǼ¹²Ïí¡£¡£¡£¡£¡£¡£¶øºó£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Ê¹ÓÃÌØÊâ¾ç±¾ÍøÂçÍ´´¦²¢¶ÔÆä½øÐÐÉ¢Áд¦Ö㬣¬£¬£¬£¬£¬£¬£¬»ñµÃÃ÷ÎÄ´ó¾ÖµÄÃÜÂë¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/windows-10-themes-can-be-abused-to-steal-windows-passwords/
3.·¨¹ú¡¢ÈÕ±¾ºÍÐÂÎ÷À¼ÖÒ¸æÕë¶ÔÈ«ÇòµÄEmotet¹¥»÷»î¶¯¼¤Ôö

À´×Ô·¨¹ú¡¢ÈÕ±¾ºÍÐÂÎ÷À¼µÄÍøÂ簲ȫ»ú¹¹°ä²¼Á˰²È«¾¯±¨£¬£¬£¬£¬£¬£¬£¬£¬ÖÒ¸æÀûÓÃEmotet¶ñÒâÈí¼þ¶ÔÕâÈý¸ö¹ú¶ÈµÄ¹«Ë¾ºÍµ±¾Ö»ú¹¹ÌáÒéµÄÀ¬»øÓʼþ»î¶¯¼¤Ôö¡£¡£¡£¡£¡£¡£Æ¾¾ÝÈý¼Ò»ú¹¹µÄ¾¯±¨£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ×î½üÕë¶Ô·¨¹ú¡¢ÈÕ±¾ºÍÐÂÎ÷À¼µÄ¹¥»÷»î¶¯ÖУ¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍʹÓÃÁËÒ»ÑùµÄÕ½Êõ£¬£¬£¬£¬£¬£¬£¬£¬¼´Ï°È¾Ò»¸öÊܺ¦Õߣ¬£¬£¬£¬£¬£¬£¬£¬ÇÔÈ¡¾ÉµÄÓʼþỊ̈߳¬£¬£¬£¬£¬£¬£¬£¬¶øºó¸´ÔÕâЩ¾ÉµÄ¶Ô»°£¬£¬£¬£¬£¬£¬£¬£¬½«¶ñÒâÎļþÔö³¤Îª¸½¼þϰȾÐÂÓû§¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬Emotet»¹Ê¹ÓÃÁËWindows WordÎĵµ(.doc)ºÍÊÜÃÜÂë±£»£»£»£»£»£»£»£»¤µÄZIP´æµµÎļþ×÷Ϊ¶ñÒâµç×ÓÓʼþ¸½¼þ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/france-japan-new-zealand-warn-of-sudden-spike-in-emotet-attacks/
4.Digital PointÊý¾Ý¿âÅäÖÃÃýÎ󹫿ª³¬¹ý80ÍòÓû§µÄ¼Í¼

WebsitePlane×êÑÐÈËÔ±ÓÚ7ÔÂ1ÈÕ·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ÍøÕ¾ÖÎÀíÔ±ÂÛ̳Digital PointÊý¾Ý¿âÅäÖÃÃýÎ󹫿ª863412ÃûÓû§µÄ¼Í¼¡£¡£¡£¡£¡£¡£Õâ´Î×ܹ²Ð¹Â¶Á˳¬¹ý6200ÍòÌõÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬Óû§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢ÄÚ²¿Óû§IDºÅ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÄÚ²¿¼Í¼ºÍÓû§Ìû×ӵľßÌåÐÅÏ¢¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚÊÕµ½»ã±¨ºóµÄÊýÓ×ʱÄÚ¶Ô¸ÃÊý¾Ý¿â²ÉÈ¡Á˱£»£»£»£»£»£»£»£»¤´ëÊ©£¬£¬£¬£¬£¬£¬£¬£¬µ«ÊÇĿǰ²¢Î´»ØÓ¦¸ÃÊÂÎñ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/webmaster-forum-database-exposed-data-of-800000-users/
5.Ŧ¿¨Ë¹¶ûÃͽø½¨È¾DoppelPaymerµ¼ÖÂITϵͳÖжÏÊýÖÜ

Ó¢¹úŦ¿¨Ë¹¶û´óѧ°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬ÆäÔÚ8ÔÂ30ÈÕÉÏÎçÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂITϵͳÖжϣ¬£¬£¬£¬£¬£¬£¬£¬Ô¤¼ÆÊýÖÜÖ®ºó²Å¿É¸´Ô¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷µ¼Ö¸ôóѧ³ýͨѶϵͳ£¨µç×ÓÓʼþ¡¢Team¡¢CanvasºÍZoom)ÒÔ±íµÄËùÓÐϵͳ£¬£¬£¬£¬£¬£¬£¬£¬ÒªÃ´²»³ÉÓ㬣¬£¬£¬£¬£¬£¬£¬ÒªÃ´±»ÏÞ¶È¡£¡£¡£¡£¡£¡£ºÚ¿Í×éÖ¯DoppelPaymer³ÆÕâ´Î¹¥»÷ÓÉÆäÌáÒ飬£¬£¬£¬£¬£¬£¬£¬²¢°ä²¼ÁË750KbµÄ±»µÁÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬×÷ΪÆäÊý¾Ýй©վµãµÄÖ¤¾Ý¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ransomware-gang-says-they-are-behind-newcastle-university-attack/
6.ÖйúÔÚ9ÔÂ8ÈյĹú¼Ê×êÑлáÌá³ö¡¶È«ÇòÊý¾Ý°²È«½¨Òé¡·

Öйú¹úÎñίԱ¼æ±í³¤ÍõÒã±¾ÖܶþÔÚÈ«ÇòÊý×ÖÖÎÀí×êÑлáÉϰµÊ¾£¬£¬£¬£¬£¬£¬£¬£¬ÎªÓ¦¶ÔÐÂÎÊÌâÐÂÌôÕ½£¬£¬£¬£¬£¬£¬£¬£¬ÖйúÔ¸ÌáÒé¡¶È«ÇòÊý¾Ý°²È«½¨Òé¡·£¬£¬£¬£¬£¬£¬£¬£¬»¶Ó¸÷·½»ý¼«²Î¼Ó¡£¡£¡£¡£¡£¡£Ìá³öÓ¦¶ÔÊý¾Ý°²È«·çÏÕÓ¦×ñÑÈýÏî×¼Ôò£º±ü³Ö¶à±ßÖ÷Òå¡¢Á½È«°²È«·¢Õ¹ºÍ¼áÊØÆ½ÕýÕýÒå¡£¡£¡£¡£¡£¡£²¢°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬Öйúµ±¾ÖÑϸñ¼ùÐÐÊý¾Ý°²È«±£»£»£»£»£»£»£»£»¤ÓйØ×¼Ôò£¬£¬£¬£¬£¬£¬£¬£¬Ã»ÓÐÒ²²»»áÒªÇóÖз½ÆóҵΥ·´±ð¹ú˾·¨ÏòÖйúµ±¾ÖÌṩ¾³±íÊý¾Ý¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
http://world.people.com.cn/n1/2020/0908/c1002-31853722.html


¾©¹«Íø°²±¸11010802024551ºÅ