ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ22ÖÜ
°ä²¼¹¦·ò 2020-06-01> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2020Äê05ÔÂ25ÈÕÖÁ05ÔÂ31ÈÕ¹²ÊÕ¼°²È«·ì϶58¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇTrendMicro InterScan Web Security Virtual Appliance LogSettingHandlerºÅÁî×¢Èë·ì϶; IBM Security Identity Governance and IntelligenceδÊÚȨºÅÁîÖ´Ðзì϶£»£»£»£»£»Apple macOS Catalina FontParser´úÂëÖ´Ðзì϶£»£»£»£»£»Inductive Automation Ignition·´ÐòÁл¯´úÂëÖ´Ðзì϶£»£»£»£»£»Ubiquiti Networks AirOS OSºÅÁî×¢Èë·ì϶¡£¡£¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÃÀ¹úCISA¡¢DOEºÍÓ¢¹úµÄNCSC½áºÏ°ä²¼¡¶ICSÍøÂ簲ȫ×î¼Ñʵ¼Ê¡·£»£»£»£»£»ºÚ¿Í×éÖ¯Maze¹¥»÷¸ç˹´ïÀè¼ÓÒøÐУ¬£¬£¬£¬£¬£¬£¬£¬ÇÔÈ¡ÆäÐÅÓþ¿¨ÐÅÏ¢£»£»£»£»£»Ì©¹úÒÆ¶¯ÔËÓªÉÌAIS´æÔÚ°²È«ÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶83ÒÚÌõÓû§¼Í¼£»£»£»£»£»Android·ì϶StrandHogg 2.0±»Åû¶£¬£¬£¬£¬£¬£¬£¬£¬Ó°Ï쳬¹ý10ÒŲ́É豸£»£»£»£»£»Apple°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´macOSºÍSafariÖÐ50¶à·ì϶¡£¡£¡£¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£¡£¡£¡£
>³ÁÒª°²È«·ì϶Áбí
1.Trend Micro InterScan Web Security Virtual Appliance LogSettingHandlerºÅÁî×¢Èë·ì϶
Trend Micro InterScan Web Security Virtual Appliance LogSettingHandlerÀà½âÎömount_device²ÎÊýʱ´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-20-676/
2. IBM Security Identity Governance and IntelligenceδÊÚȨºÅÁîÖ´Ðзì϶
IBM Security Identity Governance and Intelligence´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉδÊÚȨִÐкÅÁî¡£¡£¡£¡£¡£¡£¡£¡£
https://www.ibm.com/blogs/psirt/security-bulletin-ibm-has-announced-a-release-for-ibm-security-identity-governance-and-intelligence-in-response-to-a-security-vulnerability-cve-2020-4231/
3. Apple macOS Catalina FontParser´úÂëÖ´Ðзì϶
Apple macOS Catalina FontParser´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄPDFÎļþÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÔ½½çд£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
https://support.apple.com/zh-cn/HT211170
4. Inductive Automation Ignition·´ÐòÁл¯´úÂëÖ´Ðзì϶
Inductive Automation Ignition´æÔÚ·´ÐòÁл¯·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
https://www.us-cert.gov/ics/advisories/icsa-20-147-01
5. Ubiquiti Networks AirOS OSºÅÁî×¢Èë·ì϶
Ubiquiti Networks AirMax AirOS´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿É×¢ÈëËÁÒâºÅÁî²¢Ö´ÐÓ×£¡£¡£¡£¡£¡£¡£¡£
https://community.ui.com/releases/Security-advisory-bulletin-011-011/d0d411a5-6dcb-4988-9709-d57f50957261
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢ÃÀ¹úCISA¡¢DOEºÍÓ¢¹úµÄNCSC½áºÏ°ä²¼¡¶ICSÍøÂ簲ȫ×î¼Ñʵ¼Ê¡·
ÔÎÄÁ´½Ó£º
https://www.us-cert.gov/ncas/current-activity/2020/05/22/cisa-doe-and-uks-ncsc-issue-guidance-protecting-industrial-control
2¡¢ºÚ¿Í×éÖ¯Maze¹¥»÷¸ç˹´ïÀè¼ÓÒøÐУ¬£¬£¬£¬£¬£¬£¬£¬ÇÔÈ¡ÆäÐÅÓþ¿¨ÐÅÏ¢
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hackers-leak-credit-card-info-from-costa-ricas-state-bank/
3¡¢Ì©¹úÒÆ¶¯ÔËÓªÉÌAIS´æÔÚ°²È«ÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶83ÒÚÌõÓû§¼Í¼
ÔÎÄÁ´½Ó£º
https://techcrunch.com/2020/05/24/thai-billions-internet-records-leak/
4¡¢Android·ì϶StrandHogg 2.0±»Åû¶£¬£¬£¬£¬£¬£¬£¬£¬Ó°Ï쳬¹ý10ÒŲ́É豸
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/critical-android-bug-lets-malicious-apps-hide-in-plain-sight/
5¡¢Apple°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´macOSºÍSafariÖÐ50¶à·ì϶
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/apple-patches-over-40-vulnerabilities-macos-catalina


¾©¹«Íø°²±¸11010802024551ºÅ