ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ27ÖÜ

°ä²¼¹¦·ò 2020-07-06

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2020Äê06ÔÂ29ÈÕÖÁ07ÔÂ05ÈÕ¹²ÊÕ¼°²È«·ì϶65¸ö£¬£¬£¬£¬£¬ £¬ £¬£¬ÖµµÃ¹Ø×¢µÄÊÇApache GuacamoleÌØ¶¨PDUÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶; Palo Alto Networks PAN-OS SAMLÑéÖ¤ÈÆ¹ý·ì϶£»£»£»£»£»F5 BIG-IP Traffic Management User½Ó¿Ú´úÂëÖ´Ðзì϶£»£»£»£»£»ZyXEL CloudCNM SecuManagerÓ²±àÂë·ì϶£»£»£»£»£»TOBESOFT Nexacro14/17 ExtCommonApiV13 Library API²»µ±²ÎÊý´¦ÖôúÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇApache°ä²¼°²È«¹«¸æ£¬£¬£¬£¬£¬ £¬ £¬£¬½¨¸´ÆäTomcatÖеÄDoS·ì϶£»£»£»£»£»ºÚ¿Íй¶°ÍÎ÷×Üͳ¼°20Íò¹«ÎñÔ±Ó×ÎÒÐÅÏ¢£¬£¬£¬£¬£¬ £¬ £¬£¬¾¯·½ÈÔÔÚµ÷²éÖУ»£»£»£»£»Î¢Èí°ä²¼´ø±í¸üУ¬£¬£¬£¬£¬ £¬ £¬£¬½¨¸´Windows 10ÖеĴúÂëÖ´Ðзì϶£»£»£»£»£»¶ñÒâÈí¼þTrickBotͨ¹ý²é³­ÆÁÄ»·Ö±æÂÊÒÔÌӱܲ¡¶¾·ÖÎö£»£»£»£»£»¶ñÒâÈí¼þAlina»Ø¹é£¬£¬£¬£¬£¬ £¬ £¬£¬ÀûÓÃDNSËí·ÇÔÊØÐÅÓþ¿¨Êý¾Ý¡£¡£¡£¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬ £¬ £¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£¡£¡£



>³ÁÒª°²È«·ì϶Áбí


1.Apache GuacamoleÌØ¶¨PDUÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶


Apache GuacamoleδÕýÈ·Ñé֤ͨ¹ý¾²Ì¬Ð鹹ͨ·´ÓRDP·þÎñÆ÷½Ó¹ÜµÄÊý¾ÝÖ¸Õ룬£¬£¬£¬£¬ £¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄPDUÒªÇ󣬣¬£¬£¬£¬ £¬ £¬£¬¿É´¥·¢ÄÚ´æ·ÛË飬£¬£¬£¬£¬ £¬ £¬£¬Ö´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£

https://lists.apache.org/thread.html/r26fb170edebff842c74aacdb1333c1338f0e19e5ec7854d72e4680fc@%3Cannounce.apache.org%3E


2. Palo Alto Networks PAN-OS SAMLÑéÖ¤ÈÆ¹ý·ì϶


Palo Alto Networks PAN-OS SAMLÉí·ÝÑéÖ¤´æÔÚÊý¾ÝαÔìÎÊÌâ·ì϶£¬£¬£¬£¬£¬ £¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬ £¬ £¬£¬¿ÉδÊÚȨ½Ó¼û£¬£¬£¬£¬£¬ £¬ £¬£¬½ÚÔìÉ豸¡£¡£¡£¡£¡£¡£¡£

https://security.paloaltonetworks.com/CVE-2020-2021


3. F5 BIG-IP Traffic Management User½Ó¿Ú´úÂëÖ´Ðзì϶


F5 BIG-IP Traffic Management User½Ó¿Ú´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ £¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬ £¬ £¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£

https://support.f5.com/csp/article/K52145254


4. ZyXEL CloudCNM SecuManagerÓ²±àÂë·ì϶


ZyXEL CloudCNM SecuManagerʹÓÃÃÜÂëaxirosµÄrootÕË»§£¬£¬£¬£¬£¬ £¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬ £¬ £¬£¬¿ÉδÊÚȨ½Ó¼ûϵͳ¡£¡£¡£¡£¡£¡£¡£

https://www.zyxel.com/support/vulnerabilities-of-CloudCNM-SecuManager.shtml


5. TOBESOFT Nexacro14/17 ExtCommonApiV13 Library API²»µ±²ÎÊý´¦ÖôúÂëÖ´Ðзì϶


TOBESOFT Nexacro14/17 ExtCommonApiV13 Library API´¦ÖòÎÊý´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ £¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬ £¬ £¬£¬¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£

https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35491



> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢Apache°ä²¼°²È«¹«¸æ£¬£¬£¬£¬£¬ £¬ £¬£¬½¨¸´ÆäTomcatÖеÄDoS·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ô­ÎÄÁ´½Ó£º

https://www.us-cert.gov/ncas/current-activity/2020/06/26/apache-releases-security-advisory-apache-tomcat


2¡¢ºÚ¿Íй¶°ÍÎ÷×Üͳ¼°20Íò¹«ÎñÔ±Ó×ÎÒÐÅÏ¢£¬£¬£¬£¬£¬ £¬ £¬£¬¾¯·½ÈÔÔÚµ÷²éÖÐ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/brazilian-federal-police-investigates-presidential-data-leak/  


3¡¢Î¢Èí°ä²¼´ø±í¸üУ¬£¬£¬£¬£¬ £¬ £¬£¬½¨¸´Windows 10ÖеĴúÂëÖ´Ðзì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-releases-oob-security-updates-for-windows-10-rce-bugs/


4¡¢¶ñÒâÈí¼þTrickBotͨ¹ý²é³­ÆÁÄ»·Ö±æÂÊÒÔÌӱܲ¡¶¾·ÖÎö


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/trickbot-malware-now-checks-screen-resolution-to-evade-analysis/


5¡¢¶ñÒâÈí¼þAlina»Ø¹é£¬£¬£¬£¬£¬ £¬ £¬£¬ÀûÓÃDNSËí·ÇÔÊØÐÅÓþ¿¨Êý¾Ý


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/alina-point-sale-malware-ongoing-campaign/157087/