ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ41ÖÜ
°ä²¼¹¦·ò 2020-10-13> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2020Äê10ÔÂ05ÈÕÖÁ10ÔÂ11ÈÕ¹²ÊÕ¼°²È«·ì϶57¸ö£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇGoogle Android Qualcomm¹ØÔ´×é¼þCVE-2020-3654´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»£»Google Android Qualcomm¹ØÔ´×é¼þCVE-2020-3657´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»£»Google Android system×é¼þCVE-2020-0416´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»£»D-Link DAP-136 IP²ÎÊýºÅÁîÖ´Ðзì϶£»£»£»£»£»£»£»£»Facebook WhatsApp RTP ExtensionÕ»Òç¶Âí½Å¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ£ºCISA°ä²¼2019²ÆÄê·çÏÕ·ì϶ÆÀ¹ÀµÄÐÅϢͼ£»£»£»£»£»£»£»£»°²È«¹«Ë¾Arctic Wolf°ä²¼°²È«ÔËÓªÄê¶È»ã±¨£»£»£»£»£»£»£»£»Google°ä²¼µÄChrome°²È«¸üн¨¸´¶à¸ö·ì϶£»£»£»£»£»£»£»£»AdobeÒò·þÎñÖжϵ¼ÖÂÓû§ÎÞ·¨µÇ¼Creative Cloud£»£»£»£»£»£»£»£»Android°æFacebookÖдæÔÚ·ì϶£¬£¬£¬£¬£¬£¬»ò½«µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£¡£
> ³ÁÒª°²È«·ì϶Áбí
1.Google Android Qualcomm¹ØÔ´×é¼þCVE-2020-3654´úÂëÖ´Ðзì϶
Google Android Qualcomm¹ØÔ´×é¼þʵÏÖ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿Éʹ·þÎñ·¨Ê½±ÀÀ£»£»£»£»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
https://source.android.com/security/bulletin/2020-10-01
2.Google Android Qualcomm¹ØÔ´×é¼þCVE-2020-3657´úÂëÖ´Ðзì϶
Google Android Qualcomm¹ØÔ´×é¼þʵÏÖ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿Éʹ·þÎñ·¨Ê½±ÀÀ£»£»£»£»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
https://source.android.com/security/bulletin/2020-10-01
3.Google Android system×é¼þCVE-2020-0416´úÂëÖ´Ðзì϶
Google Android Framework×é¼þʵÏÖ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿Éʹ·þÎñ·¨Ê½±ÀÀ£»£»£»£»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
https://source.android.com/security/bulletin/2020-10-01
4.D-Link DAP-136 IP²ÎÊýºÅÁîÖ´Ðзì϶
D-Link DAP-136´¦ÖÃIP²ÎÊý´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10191
5.Facebook WhatsApp RTP ExtensionÕ»Òç¶Âí½Å
Facebook WhatsApp RTP Extension½âÎö´æÔÚÕ»Òç¶Âí½Å£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
https://www.whatsapp.com/security/advisories/2020/
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢CISA°ä²¼2019²ÆÄê·çÏÕ·ì϶ÆÀ¹ÀµÄÐÅϢͼ

ÍøÂ簲ȫºÍÐÅÏ¢°²È«»ú¹¹(CISA)°ä²¼ÁË2019²ÆÄê½øÐеÄ44Ïî·çÏպͷì϶ÆÀ¹À£¨RVA£©£¬£¬£¬£¬£¬£¬ÒÔ¼°MITERÆ¥µÐÕ½Êõ¡¢¼¼ÊõºÍѧÎÊ£¨ATT£¦CK£©¿ò¼ÜµÄ·ÖÎöÐÅϢͼ¡£¡£¡£¡£¡£¡£¸ÃÐÅϢͼ±íÈ·¶¨ÁËCISAÔÚ¿ç¶à¸ö²¿ÃŵÄRVAsÆÚ¼ä¹Û²ìµ½µÄͨÀý³É¹¦¹¥»÷õè¾¶£¬£¬£¬£¬£¬£¬ÍøÂç¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ¹¥»÷õè¾¶À´¹¥»÷×éÖ¯¡£¡£¡£¡£¡£¡£CISA¼¤ÀøÍøÂçÖÎÀíÔ±ºÍITרҵÈËÔ±²é¿´ÐÅϢͼ²¢ÀûÓÃÍÆ¼öµÄ·ÀÓùÕ½Êõ£¬£¬£¬£¬£¬£¬ÒÔÔ¤·ÀÊܵ½ÒÑÖªÕ½ÊõºÍ¼¼ÊõµÄ¹¥»÷¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2020/10/07/cisa-releases-fy2019-risk-vulnerability-assessment-infographic
2¡¢°²È«¹«Ë¾Arctic Wolf°ä²¼°²È«ÔËÓªÄê¶È»ã±¨

°²È«¹«Ë¾Arctic Wolf°ä²¼ÁËÒ»·Ý°²È«ÔËÓªÄê¶È»ã±¨¡£¡£¡£¡£¡£¡£»ã±¨ÏÔʾ£¬£¬£¬£¬£¬£¬×Ô3ÔÂÒÔÀ´£¬£¬£¬£¬£¬£¬°µÍøÉϹ«¿ªµÄ¹«Ë¾Í´´¦ÊýÁ¿Ôö³¤ÁË429£¥¡£¡£¡£¡£¡£¡£Ôڹ۲쵽µÄ¸ß·çÏÕ°²È«ÊÂÎñÖУ¬£¬£¬£¬£¬£¬ÓÐ35£¥²úÉúÔÚ8:00 PMºÍ8:00 AMÖ®¼ä£¬£¬£¬£¬£¬£¬¶ø14£¥²úÉúÔÚÖÜÄ©£¬£¬£¬£¬£¬£¬ÕâÊǺܶàÄÚ²¿°²È«ÍŶӲ»ÔÚÏߵŦ·ò¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬ÍøÂç´¹µöºÍÀÕË÷Èí¼þ¹¥»÷´ÎÊýÔö³¤ÁË64£¥£¬£¬£¬£¬£¬£¬ºÚ¿Í¸ü¶àµÄÒÔCOVID-19Ö÷ÌâΪµö¶ü£¬£¬£¬£¬£¬£¬À´Õë¶ÔÔ¶³Ì¹¤×÷Õß¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://arcticwolf.com/resources/analyst-reports/security-operations-annual-report
3¡¢Google°ä²¼µÄChrome°²È«¸üн¨¸´¶à¸ö·ì϶

Google°ä²¼µÄChrome°²È«¸üÐÂÕë¶ÔWindows¡¢MacºÍLinux°æ±¾½¨¸´ÁË35¸ö·ì϶¡£¡£¡£¡£¡£¡£ÆäÖнÏΪÑϳÁµÄ·ì϶Ϊ֧¸¶ÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2020-15967£©£¬£¬£¬£¬£¬£¬Æä´ÎΪBlink¡¢WebRTC¡¢NFC¡¢´òÓ¡¡¢ÒôƵ¡¢×Ô¶¯Ìî³äºÍÃÜÂëÖÎÀíÆ÷ÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2020-15968¡¢CVE-2020-15969¡¢CVE-2020-15970¡¢CVE-2020-15971¡¢CVE-2020-15972¡¢CVE-2020-15990ºÍCVE-2020-15991£©¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2020/10/07/google-releases-security-updates-chrome
4¡¢AdobeÒò·þÎñÖжϵ¼ÖÂÓû§ÎÞ·¨µÇ¼Creative Cloud

AdobeÒò·þÎñÖжϣ¬£¬£¬£¬£¬£¬µ¼ÖÂÓû§ÎÞ·¨µÇ¼Creative Cloud»ò½Ó¼ûÆä¶©ÔĵÄÀûÓ÷¨Ê½»ò´æ´¢µÄÊý¾Ý¡£¡£¡£¡£¡£¡£×ÔÃÀ¹ú¶«²¿¹¦·òÉÏÎç9:30ÒÔÀ´£¬£¬£¬£¬£¬£¬Adobe Creative CloudÓû§ÆðÍ·»ã±¨ÎÞ·¨µÇ¼¸Ã·þÎñ»ò½Ó¼û±£ÁôµÄͼÏñºÍÊý¾Ý£¬£¬£¬£¬£¬£¬µ±ËûÃÇÊÔͼµÇ¼µÄʱ³½£¬£¬£¬£¬£¬£¬¾Í»áÏÔʾ¡°²úÉúÁËһЩÃýÎó¡±µÄÌáÐÑ¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬AdobeÒÑÔÚstatus.adobe.comÒ³ÃæÉϰ䲼֪ͨȷÈÏÁËÖжϣ¬£¬£¬£¬£¬£¬µ«²¢Î´ÌṩÈκÎÓйØÕâ´ÎÖжϵľßÌåÐÅÏ¢¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/technology/adobe-creative-cloud-down-users-report-login-data-access-issues/
5¡¢Android°æFacebookÖдæÔÚ·ì϶£¬£¬£¬£¬£¬£¬»ò½«µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ

°²È«×êÑÐÔ±Sayed Abdelhafiz·¢ÏÖ£¬£¬£¬£¬£¬£¬Android°æFacebookÖдæÔÚÑϳÁ·ì϶£¬£¬£¬£¬£¬£¬¸Ã·ì϶»ò½«µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬ÀûÓø÷ì϶¿ÉÄܵ¼ÖÂÀûÓñÀÀ£ÒÔ¼°É豸ÊÕÊÜ¡£¡£¡£¡£¡£¡£FacebookÔÊÐíͨ¹ýÁ½ÖÖ·½Ê½ÏÂÔØÎļþ£¬£¬£¬£¬£¬£¬ÆäÖÐÒ»ÖÖÊÇʹÓá°Îļþ¡±Ñ¡Ï£¬£¬£¬£¬£¬£¬½«ÎļþÏÈÌáÈ¡µ½DownloadManager£¬£¬£¬£¬£¬£¬¶øºó±£Áôµ½Download Director¡£¡£¡£¡£¡£¡£Abdelhafiz·¢ÏÖÄܹ»´´½¨²¢ÏÂÔØÒ»¸ö¶ñÒâÎļþ£¬£¬£¬£¬£¬£¬¶øºóÔÚÖ¸±êÉ豸ÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£FacebookÔڵõ½·ì϶»ã±¨ºó£¬£¬£¬£¬£¬£¬ÒÑÓÚ2020Äê6Ô½¨¸´Á˸÷ì϶¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://latesthackingnews.com/2020/10/08/code-execution-vulnerability-found-in-facebook-for-android/


¾©¹«Íø°²±¸11010802024551ºÅ