ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ16ÖÜ
°ä²¼¹¦·ò 2020-04-20> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2020Äê04ÔÂ13ÈÕÖÁ19ÈÕ¹²ÊÕ¼°²È«·ì϶72¸ö£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇGoogle Chrome speech recognizer´úÂëÖ´Ðзì϶; VeeamOne Agent PerformHandshake´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»Apache Heron·´ÐòÁл¯´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»Cisco UCS Director ApplianceStorageUtil unzipĿ¼±éÀú´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»Triangle MicroWorks SCADA Data Gateway DNP3 GET_FILE_INFOÕ»Òç¶Âí½Å¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǰͻù˹̹1.15ÒÚÒÆ¶¯Óû§Êý¾ÝÔÚ°µÍøÏúÊÛ£»£»£»£»£»£»£»µ¤ÂóË®±ÃÔì×÷ÉÌDESMIÔâÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÏµÍ³ÈÔδ¸´Ô£»£»£»£»£»£»£»Oracle°ä²¼4Ô³ÁÒª²¹¶¡¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´397¸ö·ì϶£»£»£»£»£»£»£»Ó¢Ìضû°ä²¼4Ô°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´¶à¿î²úÆ·ÖеÄ9¸ö·ì϶£»£»£»£»£»£»£»EA SportsÔâ´ó¹æÄ£DDoS¹¥»÷£¬£¬£¬£¬£¬£¬£¬È«Çò·þÎñÖжϡ£¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£¡£
>³ÁÒª°²È«·ì϶Áбí
1. Google Chrome speech recognizer´úÂëÖ´Ðзì϶
Google Chrome speech recognizer´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇ󣬣¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_15.html
2. Veeam One Agent PerformHandshake´úÂëÖ´Ðзì϶
Veeam One Agent PerformHandshake²½Öè´æÔÚ·´ÐòÁл¯·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-20-545/
3. Apache Heron·´ÐòÁл¯´úÂëÖ´Ðзì϶
Apache Heron´æÔÚ·´ÐòÁл¯·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíͨ¹ýÑéÖ¤µÄÖÎÀíÔ±Óû§ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
https://lists.apache.org/thread.html/r16dd39f4180e4443ef4ca774a3a5a3d7ac69f91812c183ed2a99e959%40%3Cdev.heron.apache.org%3E
4. Cisco UCS Director ApplianceStorageUtil unzipĿ¼±éÀú´úÂëÖ´Ðзì϶
Cisco UCS Director ApplianceStorageUtil unzip´¦ÖÃÎļþ²Ù×÷´æÔÚĿ¼±éÀú·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬Äܹ»rootÕË»§¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-20-539/
5. Triangle MicroWorks SCADA Data Gateway DNP3 GET_FILE_INFOÕ»Òç¶Âí½Å
Triangle MicroWorks SCADA Data Gateway´¦ÖÃDNP3 GET_FILE_INFO´æÔÚÕ»Òç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-20-547
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢°Í»ù˹̹1.15ÒÚÒÆ¶¯Óû§Êý¾ÝÔÚ°µÍøÏúÊÛ
°Í»ù˹̹°²È«³§ÉÌRewterz·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°ÓÐ1.15ÒÚ°Í»ùË¹Ì¹ÒÆ¶¯Óû§µÄÊý¾ÝÔÚ°µÍøÂÛ̳ÏúÊÛ£¬£¬£¬£¬£¬£¬£¬¼ÛֵΪ300 BTC£¨Ô¼ºÏ210ÍòÃÀÔª£©¡£¡£¡£¡£¡£¡£ÕâЩÊý¾ÝÔ̺¬Óû§µÄ¾ßÌåÓ×ÎÒÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÀýÈçÐÕÃû¡¢ÆëÈ«µØÖ·¡¢ÊÖ»úºÅÂëÒÔ¼°NICºÅºÍ˰ÎñºÅÂë¡£¡£¡£¡£¡£¡£RewterzÍþвµý±¨×¨¼ÒÒÔΪÕâЩÊý¾Ý¿ÉÄÜÊÇÒ»´Î»òÂÅ´Îй¶µÄÁ˾֣¬£¬£¬£¬£¬£¬£¬Ä¿Ç°»¹²»Ã÷ÏÔÊÇ·ñÓÐÈκÎÌØ¶¨µÄµçÐÅÔËÓªÉÌ»òÊÇËùÓеçÐÅÔËÓªÉ̳ÉΪÕâ´Î¹¥»÷µÄÊܺ¦Õß¡£¡£¡£¡£¡£¡£¸Ãй¶Êý¾ÝµÄ¹æÄ£Òý·¢Á˶ԵçÐŹ«Ë¾Êý¾Ý°²È«ÐÔºÍÒþÖÔÐÔµÄÓÇÓô¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
http://www.rewterz.com/articles/115-million-pakistani-mobile-users-data-go-on-sale-on-dark-web
2¡¢µ¤ÂóË®±ÃÔì×÷ÉÌDESMIÔâÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÏµÍ³ÈÔδ¸´Ô
µ¤ÂóË®±ÃÔì×÷ÉÌDESMIÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬¸Ã¹¥»÷ÊÂÎñ²úÉúÔÚÉÏÖÜËĵÄÍíÉÏ£¬£¬£¬£¬£¬£¬£¬Ôâµ½¹¥»÷ºó¹«Ë¾µÄËùÓÐϵͳ¾ù±»¹Ø¹Ø¡£¡£¡£¡£¡£¡£Æ¾¾Ý¸Ã¹«Ë¾ÔÚ¹ÙÍøÉϰ䲼µÄÖҸ棬£¬£¬£¬£¬£¬£¬¹«Ë¾µÄËùÓÐϵͳ¾ù±»¹Ø¹Ø£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÔÚ»¹Ô¹ý³ÌÖУ¬£¬£¬£¬£¬£¬£¬Ê×Åú²¿ÃÅϵͳ½«ÔÚ¼¸ÌìÄÚÆô¶¯²¢ÔËÐУ¬£¬£¬£¬£¬£¬£¬ÆäÓàµÄϵͳ½«ÔÚ¼¸ÖÜÖ®ÄÚÔËÐÓ×£¡£¡£¡£¡£¡£Ä¿Ç°µ÷²éÈÔÔÚ½øÐÐÖ®ÖУ¬£¬£¬£¬£¬£¬£¬Éв»Ã÷ÏÔ¹¥»÷µÄˮƽ£¬£¬£¬£¬£¬£¬£¬DESMIÒѽ«ÊÂÎñ»ã±¨¸øµ¤Â󵱾ֺ;¯Ô±¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/101495/hacking/desmi-discloses-cyber-attack.html
3¡¢Oracle°ä²¼4Ô³ÁÒª²¹¶¡¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´397¸ö·ì϶
OracleÔÚÆä4Ô³ÁÒª²¹¶¡¸üÐÂÖн¨¸´ÁË397¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬ÆäÖÐOracle Database Server²úÆ·Öн¨¸´ÁË8¸ö·ì϶£»£»£»£»£»£»£»µç×ÓÉÌÎñÌ×¼þÖн¨¸´ÁË74¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬Ô̺¬70¸öÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓõķì϶£»£»£»£»£»£»£»OracleÈÚºÏÖÐÑë¼þÖн¨¸´ÁË51¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬ÆäÖÐ44¸öÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓ㻣»£»£»£»£»£»Java SEÖн¨¸´ÁË15¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬ËùÓзì϶¾ùÄܹ»ÔÚ²»½øÐÐÉí·ÝÑéÖ¤µÄÇé¿öϽøÐÐÔ¶³ÌÀûÓ㻣»£»£»£»£»£»MySQLÖн¨¸´ÁË45¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬ÆäÖÐ9¸ö·ì϶ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓᣡ£¡£¡£¡£¡£ÆëÈ«·ì϶ÁбíÇë²Î¿¼ÒÔϹٷ½Á´½Ó£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ìÀûÓøüС£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.oracle.com/security-alerts/cpuapr2020.html
4¡¢Ó¢Ìضû°ä²¼4Ô°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´¶à¿î²úÆ·ÖеÄ9¸ö·ì϶
Ó¢ÌØ¶ûÔÚ4Ô²¹¶¡¸üÐÂÖн¨¸´ÁË9¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬ÕâЩ·ì϶¾ùΪÖиßΣ·ì϶£¬£¬£¬£¬£¬£¬£¬Ó°Ïì¶à¸öÈí¼þ¡¢¹Ì¼þ¼°Æ½Ì¨¡£¡£¡£¡£¡£¡£Ó¢Ìضû½¨¸´ÁËPROSet/ÎÞÏßWiFi²úÆ·ÔÚWindows 10ÉϵÄÁ½¸ö·ì϶-¾¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓÉÓÚ²»°²È«µÄ¼Ì³ÐȨÏÞ¶ø¿ÉÄÜͨ¹ý±¾µØ½Ó¼û½øÐÐÌØÈ¨Éý¼¶£¨CVE-2020-0557£©£»£»£»£»£»£»£»ÓÉÓÚÄÚºËÇý¶¯·¨Ê½ÖеĻº³åÇøÏ޶Ȳ»µ±£¬£¬£¬£¬£¬£¬£¬ÎÞÌØÈ¨µÄ¹¥»÷Õß¿ÉÄÜͨ¹ýÏàÁÚÍøÂç½Ó¼ûÀ´µ¼Ö»ؾø·þÎñ£¨CVE-2020-0558£©¡£¡£¡£¡£¡£¡£Ó¢Ìضû»¹½¨¸´ÁËNUC mini PCµÄϵͳ¹Ì¼þÖкÍÄ£¿£¿£¿£¿£¿£¿£¿é»¯·þÎñÆ÷MFS2600KISPPÍÆËãÄ£¿£¿£¿£¿£¿£¿£¿éÖеÄÁ½¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬Ô̺¬²»ÕýÈ·µÄ»º³åÇøÏ޶ȵ¼ÖµÄLPE·ì϶£¨CVE-2020-0600£©ºÍǰÌá²é³²»µ±µ¼ÖµÄÌáȨ·ì϶£¨CVE-2020-0578£©¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/intel-april-platform-update-fixes-high-severity-security-issues/
5¡¢EA SportsÔâ´ó¹æÄ£DDoS¹¥»÷£¬£¬£¬£¬£¬£¬£¬È«Çò·þÎñÖжÏ
ÓÎÏ·¹«Ë¾EA SportsÓÖÒ»´ÎÔâµ½´ó¹æÄ£µÄDDoS¹¥»÷£¬£¬£¬£¬£¬£¬£¬µ¼Ö¸ù«Ë¾µÄ·þÎñÆ÷ÔÚÈ«ÇòÁìÓòÄÚÍÑ»ú¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷²úÉúÔÚ4ÔÂ14ÈÕÏÂÎç4:19¡£¡£¡£¡£¡£¡£Æ¾¾ÝDown DetectorµÄʵʱµØÍ¼£¬£¬£¬£¬£¬£¬£¬Õâ´Î¹¥»÷ÖØÒªÓ°ÏìÁËÅ·ÖÞµØÓòµÄ¿Í»§£¬£¬£¬£¬£¬£¬£¬µ«¼ÓÄô󡢰£¼°¡¢ÄϷǵȵصĿͻ§Ò²Êܵ½ÁË»ò¶à»òÉÙµÄÓ°Ïì¡£¡£¡£¡£¡£¡£4ÔÂ15ÈÕÁ賿1µã25·Ö£¬£¬£¬£¬£¬£¬£¬EA SportsÈϿɸù«Ë¾¡°¾ÀúÁËһϵÁÐDDoS¹¥»÷¡±¡£¡£¡£¡£¡£¡£ÔÚ°ä²¼±¾ÎÄʱ£¬£¬£¬£¬£¬£¬£¬EA SportsµÄ¿Í»§ÈÔÔÚ±§Ô¹·þÎñå´»ú£¬£¬£¬£¬£¬£¬£¬ÕâÅú×¢¸Ã¹«Ë¾ÈÔÔÚÔâ·ê¹¥»÷¡£¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬£¬£¬£¬£¬±©Ñ©Ò²ÔÚ4ÔÂ14ÈÕÁ賿4µã15·Ö×óÓÒÔ⵽һϵÁÐDDoS¹¥»÷£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÈ«Çò·þÎñÖжϡ£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/ea-sports-down-gaming-giant-hit-by-ddos-attacks/


¾©¹«Íø°²±¸11010802024551ºÅ