OracleÐû²¼4ÔÂÖ÷Òª²¹¶¡¸üР£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´397¸öÎó²î£»£»£»£»ºÚ¿ÍÔÚ°µÍø³öÊÛ141ÍòÃÀ¹úÒ½ÉúµÄСÎÒ˽¼ÒÊý¾Ý

Ðû²¼Ê±¼ä 2020-04-15

1.OracleÐû²¼4ÔÂÖ÷Òª²¹¶¡¸üР£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´397¸öÎó²î


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


OracleÔÚÆä4ÔÂÖ÷Òª²¹¶¡¸üÐÂÖÐÐÞ¸´ÁË397¸öÎó²î £¬£¬£¬£¬£¬£¬£¬ÆäÖÐOracle Database Server²úÆ·ÖÐÐÞ¸´ÁË8¸öÎó²î£»£»£»£»µç×ÓÉÌÎñÌ×¼þÖÐÐÞ¸´ÁË74¸öÎó²î £¬£¬£¬£¬£¬£¬£¬°üÀ¨70¸öÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓõÄÎó²î£»£»£»£»OracleÈÚºÏÖÐÐļþÖÐÐÞ¸´ÁË51¸öÎó²î £¬£¬£¬£¬£¬£¬£¬ÆäÖÐ44¸öÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓ㻣»£»£»Java SEÖÐÐÞ¸´ÁË15¸öÎó²î £¬£¬£¬£¬£¬£¬£¬ËùÓÐÎó²î¾ù¿ÉÒÔÔÚ²»¾ÙÐÐÉí·ÝÑéÖ¤µÄÇéÐÎϾÙÐÐÔ¶³ÌʹÓ㻣»£»£»MySQLÖÐÐÞ¸´ÁË45¸öÎó²î £¬£¬£¬£¬£¬£¬£¬ÆäÖÐ9¸öÎó²îÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£¡£¡£¡£¡£¡£ÍêÕûÎó²îÁбíÇë²Î¿¼ÒÔϹٷ½Á´½Ó £¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ìÓ¦ÓøüС£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.oracle.com/security-alerts/cpuapr2020.html


2.΢ÈíÐû²¼4ÔÂÇå¾²¸üР£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´113¸öÎó²î


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


΢ÈíÔÚ4ÔÂÇå¾²¸üÐÂÖÐÐÞ¸´ÁË113¸öÎó²î £¬£¬£¬£¬£¬£¬£¬ÆäÖÐ15¸öÎó²î±»¹éÀàΪÑÏÖØ¼¶±ð £¬£¬£¬£¬£¬£¬£¬93¸ö±»¹éÀàΪÖ÷Òª £¬£¬£¬£¬£¬£¬£¬3¸ö±»¹éÀàΪÖÐµÈ £¬£¬£¬£¬£¬£¬£¬2¸ö±»¹éÀàΪµÍΣ¡£¡£¡£¡£¡£¡£¡£Î¢ÈíÌåÏÖÓÐÁ½¸ö0dayÏÈǰÒѱ»¹ûÕæÅû¶ £¬£¬£¬£¬£¬£¬£¬°üÀ¨Windows OneDriveÌØÈ¨ÌáÉýÎó²î£¨CVE-2020-0935£©ºÍAdobe Font Manager¿âÔ¶³ÌÖ´ÐдúÂëÎó²î£¨CVE-2020-1020£© £¬£¬£¬£¬£¬£¬£¬²¢ÇÒºóÕߺÍÁíÒ»¸öÎó²î£¨Adobe Font Manager¿âÔ¶³ÌÖ´ÐдúÂëÎó²îCVE-2020-0938£©ÒÑÔÚÒ°ÍⱻʹÓᣡ£¡£¡£¡£¡£¡£ÍêÕûÎó²î²¹¶¡Çë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2020-patch-tuesday-fixes-3-zero-days-15-critical-flaws/


3.ºÚ¿ÍÔÚ°µÍø³öÊÛ141ÍòÃÀ¹úÒ½ÉúµÄСÎÒ˽¼ÒÊý¾Ý


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


¾ÝHackread.com±¨µÀ £¬£¬£¬£¬£¬£¬£¬ÍøÂç·¸·¨·Ö×ÓÕýÔÚ°µÍøÂÛ̳ÉϳöÊÛÃÀ¹ú¾³ÄÚ141ÍòÃûÒ½ÉúµÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¾Ý³Æ¸ÃÊý¾Ý¿âÊÇ4ÔÂ11ÈÕ´ÓÔÚÏßЧÀÍqa.findadoctor.comÇÔÈ¡µÄ £¬£¬£¬£¬£¬£¬£¬¸ÃÍøÕ¾Î»ÓÚÐÂÔóÎ÷Öݰ®µÏÉúÊÐ £¬£¬£¬£¬£¬£¬£¬ÓÉMillennium Technology Solutions¹«Ë¾ÓµÓС£¡£¡£¡£¡£¡£¡£±»µÁÊý¾ÝÖаüÀ¨Ò½ÉúµÄÐÕÃû¡¢ÐÔ±ð¡¢ÊÂÇéÒ½ÔºÃû³Æ¡¢Î»Öá¢Óʼĵص㡢ÕïËùµØµã¡¢¹ú¼Ò/µØÇø¡¢µç»°ºÅÂë¡¢ÔÊÐíÖ¤ºÅµÈ £¬£¬£¬£¬£¬£¬£¬µ«²»°üÀ¨µç×ÓÓʼþµØµã £¬£¬£¬£¬£¬£¬£¬Ò²²»°üÀ¨»¼ÕßµÄÕÕÆ¬»ò²¡Àú¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/personal-data-us-doctors-sold-hacker-forum/


4.µçÉÌÍøÕ¾QuiddµÄ400ÍòÓû§ÐÅÏ¢ÔÚ°µÍøÈö²¥


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÃÀ¹úµç×ÓÉÌÎñÍøÕ¾QuiddµÄÔ¼400ÍòÓû§ÕË»§Êý¾ÝÕýÔÚ°µÍøÈö²¥¡£¡£¡£¡£¡£¡£¡£QuiddÊÇÒ»¸öÓÃÓÚÉúÒâÌùÖ½¡¢¿¨Æ¬¡¢Íæ¾ßºÍÆäËüÕä²ØÆ·µÄÔÚÏßÊг¡ £¬£¬£¬£¬£¬£¬£¬Êý¾ÝÐ¹Â¶ËÆºõ±¬·¢ÔÚ2019Äê £¬£¬£¬£¬£¬£¬£¬µ«QuiddÉÐδÐû²¼ÈκÎÇå¾²ÊÂÎñµÄͨ¸æ £¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÉв»ÇåÎú¸Ã¹«Ë¾ÊÇ·ñÖªÏþ¸Ãй¶ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£ZDNet´ÓÈý¸ö²î±ðµÄȪԴ»ñÈ¡ÁËÑù±¾Êý¾Ý £¬£¬£¬£¬£¬£¬£¬Êý¾ÝÖаüÀ¨QuiddÓû§Ãû¡¢µç×ÓÓʼþµØµãºÍÕË»§ÃÜÂë £¬£¬£¬£¬£¬£¬£¬¸ÃÃÜÂëÊÇÓÉbcrypt¹þÏ£Ëã·¨±£»£»£»£»¤µÄ¡£¡£¡£¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬£¬£¬£¬ZDNet»¹´ÓÊý¾ÝÉúÒâÉÌÄÇÀï»ñϤÕâЩÊý¾ÝÖÁÉÙ´Ó´Ó2019Äê10ÔºÍ2019Äê12Ô¾Í×îÏÈ»®·ÖÔÚºÚ¿ÍÂÛ̳ºÍPastebinÉÏÐû²¼¹ã¸æ¡£¡£¡£¡£¡£¡£¡£½¨ÒéQuiddÓû§¾¡¿ì¸ü¸ÄÕË»§ÃÜÂë¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/account-details-for-4-million-quidd-users-shared-on-hacking-forum/


5.APT41ʹÓÃÐÂSpeculoosºóÃŹ¥»÷È«ÇòÆóÒµ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Palo alto NetworksµÄUnit 42Ñо¿ÍŶÓÐû²¼¹ØÓÚAPT41й¥»÷»î¶¯µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯±¬·¢ÔÚ1ÔÂ20ÈÕÖÁ3ÔÂ11ÈÕʱ´ú £¬£¬£¬£¬£¬£¬£¬×¨ÃÅʹÓÃнüÅû¶µÄÎó²îÀ´Õë¶ÔCitrix¡¢CiscoºÍZohoÍøÂç×°±¸¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±»ñµÃÁËÕë¶ÔCitrix×°±¸µÄÓÐÓúÉÔØÑù±¾£¨SpeculoosºóÃÅ£© £¬£¬£¬£¬£¬£¬£¬ÕâЩÑù±¾ÊDZàÒëΪ¿ÉÔÚFreeBSDÉÏÔËÐеĿÉÖ´ÐÐÎļþ¡£¡£¡£¡£¡£¡£¡£ËùÓÐ5¸öÑù±¾µÄÎļþ¾Þϸ´óÖÂÏàͬ £¬£¬£¬£¬£¬£¬£¬µ«Ñù±¾¼¯Ö®¼ä±£´æÏ¸Ð¡²î±ð £¬£¬£¬£¬£¬£¬£¬ÕâÅú×¢ËüÃÇ¿ÉÄÜÔ´×Ôͳһ¿ª·¢Ö°Ô± £¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¾­ÓÉÖØÐ±àÒë»ò´ò²¹¶¡¡£¡£¡£¡£¡£¡£¡£SpeculoosÖ÷ҪʹÓÃCitrix Application Delivery Controller¡¢Citrix GatewayºÍCitrix SD-WAN WANOP×°±¸ÖеÄÎó²îCVE-2019-19781¾ÙÐÐÈö²¥¡£¡£¡£¡£¡£¡£¡£Ê¹ÓÃÕâЩÊý¾Ý £¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±È·¶¨ÁËÔÚ±±ÃÀ¡¢ÄÏÃÀºÍÅ·Ö޵ȵصÄÒ½ÁÆ¡¢¸ßµÈ½ÌÓý¡¢ÖÆÔìÒµ¡¢Õþ¸®ºÍÊÖÒÕЧÀ͵ÈÐÐÒµµÄ¶à¸öÊܺ¦Õß¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/apt41-using-new-speculoos-backdoor-to-target-organizations-globally/


6.Çå¾²³§ÉÌÐû²¼¡¶2020ÄêÍøÂçÍþв·ÀÓù±¨¸æ¡·


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Çå¾²³§ÉÌimpervaÐû²¼¡¶2020ÄêÍøÂçÍþв·ÀÓù±¨¸æ¡· £¬£¬£¬£¬£¬£¬£¬Õâ·Ý±¨¸æÊÓ²ìÁËÈ«Çò1200ÃûÇå¾²´ÓÒµÖ°Ô±¶ÔÆäÃæÁÙµÄÇå¾²ÌôÕ½µÄ¿´·¨Óë¶´²ì¡£¡£¡£¡£¡£¡£¡£¸Ã±¨¸æµÄÒªµã°üÀ¨£ºÕë¶ÔÆóÒµµÄÀֳɵÄÍøÂç¹¥»÷µÖ´ï´´¼Í¼µÄˮƽ-80£¥µÄ×éÖ¯ÖÁÉÙÂÄÀúÁËÒ»´ÎÀֳɵÄÍøÂç¹¥»÷ £¬£¬£¬£¬£¬£¬£¬Áè¼Ý30%µÄ×éÖ¯ÔâÊÜÁËÁù´ÎÒÔÉϵĹ¥»÷£»£»£»£»APIÍø¹Ø¡¢Êý¾Ý¿â·À»ðǽºÍWAFÊǰ²ÅŽ϶àµÄÓ¦ÓóÌÐò/Êý¾ÝÇå¾²²úÆ·£»£»£»£»80.1£¥µÄÊÜ·ÃÕßÒÔΪʹÓÃÒ»¸öƽ̨¼àÊÓÕû¸öÓ¦ÓóÌÐòÇå¾²¿ÍÕ»ÊÇ×îºÃµÄ×ö·¨£»£»£»£»Êý¾ÝºÍ֪ʶ²úȨµÄɥʧ»òʧÔôÊÇÔÆÓ¦ÓóÌÐòÇ徲Σº¦ºÍÌôÕ½µÄÖØÖÐÖ®ÖØ£»£»£»£»ÏÖÔÚÁè¼ÝÈý·ÖÖ®Ò»£¨35.7£¥£©µÄÇå¾²Ó¦ÓóÌÐòºÍЧÀÍÊÇͨ¹ýÔÆ½»¸¶µÄ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.imperva.com/resources/resource-library/reports/2020-cyberthreat-defense-report/