ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ38ÖÜ
°ä²¼¹¦·ò 2020-09-21> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2020Äê09ÔÂ14ÈÕÖÁ09ÔÂ20ÈÕ¹²ÊÕ¼°²È«·ì϶57¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe Media Encoder CVE-2020-9745Ô½½ç¶ÁÐÅϢй¶·ì϶£»£»£»£»£»£»Gallagher Group Command Centre¿Í»§¶Ë¹ÒÆð·ì϶£»£»£»£»£»£»Hyland OnBase CVE-2020-25248Ŀ¼±éÀú·ì϶£»£»£»£»£»£»IPTV/H.264/H.265ÊÓÆµ±àÂëÆ÷ºóÃÅÃÜÂëÖÎÀíÔ±½Ó¼û·ì϶£»£»£»£»£»£»Google Android Framework CVE-2020-0275ȨÏÞÌáÉý·ì϶¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇRazerÊý¾Ý¿â¶³öµ¼ÖÂÆäÔ¼10ÍòÓû§ÐÅϢй¶£»£»£»£»£»£»Redgate°ä²¼2020Äê¶ÈÊý¾Ý¿â״̬¼à²â»ã±¨£»£»£»£»£»£»Ó¢¹ú¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©°ä²¼·ì϶Åû¶ָÄÏ£»£»£»£»£»£»¿¨°Í˹»ù°ä²¼2020Äê¹¤ÒµÍøÂ簲ȫµ÷²é×êÑл㱨£»£»£»£»£»£»µÂ¹ú¹ºÎïÍøÕ¾windeln.deÊý¾Ý¿â¶³ö£¬£¬£¬£¬£¬Ð¹Â¶60Òڱʼͼ¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£
> ³ÁÒª°²È«·ì϶Áбí
1.Adobe Media Encoder CVE-2020-9745Ô½½ç¶ÁÐÅϢй¶·ì϶
Adobe Media Encoder´æÔÚÔ½½ç¶Á°²È«·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£
https://helpx.adobe.com/security/products/media-encoder/apsb20-57.html
2. Gallagher Group Command Centre¿Í»§¶Ë¹ÒÆð·ì϶
Gallagher Group Command Centre´´½¨Guard TourÊÂÎñ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿Éʹ¿Í»§¶ËÁÙʱ¹ÒÆð»ò¶Ï¿ªÏνӡ£¡£¡£¡£¡£
https://security.gallagher.com/Security-Advisories/CVE-2020-16099
3.Hyland OnBase CVE-2020-25248Ŀ¼±éÀú·ì϶
Hyland OnBase´æÔÚõè¾¶±éÀú·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎĶÁȡϵͳÎļþ»òдÈëϵͳµ½Îļþ¡£¡£¡£¡£¡£
https://seclists.org/fulldisclosure/2020/Sep/21
4. IPTV/H.264/H.265ÊÓÆµ±àÂëÆ÷ºóÃÅÃÜÂëÖÎÀíÔ±½Ó¼û·ì϶
IPTV/H.264/H.265ÊÓÆµ±àÂëÆ÷´æÔÚºóÃÅÃÜÂë·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿ÉδÊÚȨÆëÈ«½ÚÔìÀûÓᣡ£¡£¡£¡£
https://www.kb.cert.org/vuls/id/896979
5. Google Android Framework CVE-2020-0275ȨÏÞÌáÉý·ì϶
Google Android Framework´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
https://source.android.com/security/bulletin/android-11
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢RazerÊý¾Ý¿â¶³öµ¼ÖÂÆäÔ¼10ÍòÓû§ÐÅϢй¶

8ÔÂ19ÈÕ£¬£¬£¬£¬£¬×êÑÐÔ±Bob Diachenko·¢ÏÖÓÎÏ·Ó²¼þÔì×÷ÉÌRazerµÄÔÚÏßÉ̵êµÄÊý¾Ý¿â¶³ö£¬£¬£¬£¬£¬µ¼ÖÂÆäÔ¼10ÍòÓû§ÐÅϢй¶¡£¡£¡£¡£¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢¶©µ¥ºÅ¡¢¶©µ¥Ã÷ϸÒÔ¼°Õʵ¥ºÍËÍ»õµØÖ·µÈ¡£¡£¡£¡£¡£RazerÓÚÔÚ9ÔÂ9ÈÕ½¨¸´Á˸ÃÊý¾Ý¿â·þÎñÆ÷£¬£¬£¬£¬£¬²¢°µÊ¾¸ÃÊÂÎñÖв¢Ã»ÓÐÆäËûÃô¸ÐÊý¾Ýй¶£¬£¬£¬£¬£¬ÀýÈçÐÅÓþ¿¨ºÅ»òÃÜÂëµÈÐÅÏ¢¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/razer-data-leak-exposes-personal-information-of-gamers/
2¡¢Redgate°ä²¼2020Äê¶ÈÊý¾Ý¿â״̬¼à²â»ã±¨

Redgate×îа䲼ÁË2020Äê¶ÈÊý¾Ý¿â״̬¼à²â»ã±¨¡£¡£¡£¡£¡£»ã±¨ÏÔʾ£¬£¬£¬£¬£¬ÎÞÂÛÊÇÔÚѡȡÊý¾Ý¿âDevOps·½Ã棬£¬£¬£¬£¬»¹ÊÇÔÚʹÓÃ¼à¿ØÀ´¸ú×ÙÊý¾Ý¿â»úÄܺͲ¿Êð·½Ã棬£¬£¬£¬£¬½ðÈÚ·þÎñÐÐÒµµÄ²û·¢¶¼ÓÅÓÚÆäËûÐÐÒµ¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬61%µÄ½ðÈÚ·þÎñÐÐÒµÔ±¹¤Ã¿ÖܸüÐÂÖÁÉÙÒ»´ÎÊý¾Ý¿â£¬£¬£¬£¬£¬¶øÆäËûÐÐÒµÖ»ÓÐ43%µÄÔ±¹¤»áÕâÑù×ö¡£¡£¡£¡£¡£½ðÈÚ·þÎñµÄ·þÎñÆ÷ÊýÁ¿Ò²¸ü¶à£¬£¬£¬£¬£¬36%µÄ·þÎñÆ÷Õ¼ÓÐ50µ½500¸öÊ·ý£¬£¬£¬£¬£¬¶øÆäËû²¿ÃÅÖ»ÓÐ26%¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/09/14/database-monitoring-improves-devops-success/
3¡¢Ó¢¹ú¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©°ä²¼·ì϶Åû¶ָÄÏ

Ó¢¹ú¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©°ä²¼ÁË·ì϶Åû¶ָÄÏ£¬£¬£¬£¬£¬ÒÔÔ®ÊÖ¹«Ë¾Ö´Ðзì϶Åû¶Á÷³Ì»òÔÚÒѾ³ÉÁ¢·ì϶Åû¶Á÷³ÌµÄÇé¿öÏÂ¶ÔÆä½øÐиĽø¡£¡£¡£¡£¡£NCSC°µÊ¾£¬£¬£¬£¬£¬¸ÃÖ¸Äϲ¢²»ÊÇÒ»¸ö·ì϶Åû¶µÄ¹æ¶¨Êֲᣬ£¬£¬£¬£¬¶øÊÇΪ¸üºÃµÄÖ´ÐÐÌṩÁ˱ØÒªµÄÐÅÏ¢¡£¡£¡£¡£¡£ÆäÖØÒª·ÖΪÈý¸öÖØÒª²¿ÃÅ£¬£¬£¬£¬£¬ÃèÊöÁËÈôºÎ½«±í²¿·ì϶ÐÅÏ¢¶¨Ïò¸øÏàÒ˵ÄÈË£¬£¬£¬£¬£¬ÒÔ¼°»ã±¨Ðè×ñѹعطì϶µÄ¿ò¼Ü³ß¶È¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/uk-government-releases-toolkit-to-easily-disclose-vulnerabilities/
4¡¢¿¨°Í˹»ù°ä²¼2020Äê¹¤ÒµÍøÂ簲ȫµ÷²é×êÑл㱨

¿¨°Í˹»ù¶ÔÒßÇéÆÚ¼äµÄ¹¤ÒµÍøÂ簲ȫÇé¿ö½øÐÐÁË×êÑУ¬£¬£¬£¬£¬²¢°ä²¼ÁË2020Äê¹¤ÒµÍøÂ簲ȫµ÷²é×êÑл㱨¡£¡£¡£¡£¡£»ã±¨ÏÔʾ£¬£¬£¬£¬£¬³¬¹ýÒ»°ë(53%)µÄÊÜ·ÃÕßÈϿɣ¬£¬£¬£¬£¬COVID-19µ¼Ö¸ü¶àÔ±¹¤ÔڼҰ칫£¬£¬£¬£¬£¬ÕâÒѳÉΪ¶ÔÐÅÏ¢°²È«·þÎñµÄÒ»ÖÖѹÁ¦²âÊÔ¡£¡£¡£¡£¡£ÓÉÓÚ±í²¿ÏνÓÊýÁ¿¶à¶à£¬£¬£¬£¬£¬´Ë¿Ì¾ø´óÎÞÊý¹«Ë¾¶¼ÔÚ¶ÔOTÍøÂçµÄ°²È«¼¶±ð½øÐж¨ÆÚÆÀ¹À¡£¡£¡£¡£¡£ºÜ¶à×éÖ¯²»µÃ²»³ÁÐÂ˼¿¼ËûÃÇÄÚÍøµÄ±£»£»£»£»£»£»¤²½Ö裬£¬£¬£¬£¬Ö»ÓÐ7%µÄÊÜ·ÃÕß°µÊ¾£¬£¬£¬£¬£¬ËûÃǵÄÍøÂ簲ȫսÊõÔÚCOVID-19ÆÚ¼äÏ൱ÓÐЧ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.kaspersky.com/blog/industrial-cybersecurity-2020/37031/
5¡¢µÂ¹ú¹ºÎïÍøÕ¾windeln.deÊý¾Ý¿â¶³ö£¬£¬£¬£¬£¬Ð¹Â¶60Òڱʼͼ

Safety DetectivesµÄ×êÑÐÈËÔ±ÔÚÍøÂçÉÏ·¢ÏÖÁËÒ»¸ö¶³öµÄÊý¾Ý¿â£¬£¬£¬£¬£¬¾µ÷²é¸ÃÊý¾Ý¿âÊôÓڵ¹úÔÚÏß¹ºÎïÍøÕ¾windeln.de¡£¡£¡£¡£¡£Æä¶³öÁË6.4TBµÄÊý¾Ý£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬60Òڱʼͼ£¬£¬£¬£¬£¬Ð¹Â¶Á˳¬¹ý700000Ãû¿Í»§µÄÓ×ÎÒÐÅÏ¢¡£¡£¡£¡£¡£Õâ´ÎÊÂÎñµÄй¶ÐÅÏ¢Ô̺¬Ó×ÎÒÉí·ÝÐÅÏ¢£¨PII£©ºÍÆäËûÊý¾Ý£¬£¬£¬£¬£¬ÀýÈ緢Ʊ¡¢È«Ãû¡¢IPµØÖ·¡¢ÄÚ²¿ÈÕÖ¾¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢¼ÒÍ¥µØÖ·¡¢É¢ÁÐÃÜÂë¡¢¸¶¿î·½Ê½ºÍÓû§µÄº¢×ÓÓ×ÎÒÐÅÏ¢µÈ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/shopping-site-leaks-miners-data-database-mess-up/


¾©¹«Íø°²±¸11010802024551ºÅ