ºÚ¿ÍÔÚ°µÍø¹ûÕæwattpadµÄ2.7ÒÚÌõÓû§Êý¾Ý;ºÚ¿ÍÐ®ÖÆ±È¶û¸Ç´ÄºÍ°Â°ÍÂíµÈÈËTwitterÕÊ»§¾ÙÐмÓÃÜÇ®±ÒÕ©Æ­

Ðû²¼Ê±¼ä 2020-07-16

1.ºÚ¿ÍÔÚ°µÍø¹ûÕæwattpadµÄ2.7ÒÚÌõÓû§Êý¾Ý


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÏÖÔÚ£¬ £¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÕýÔÚ°µÍøÃâ·Ñ¹ûÕæwattpadµÄ2.7ÒÚÌõÓû§Êý¾Ý¡£¡£¡£¡£ÔçÏÈ£¬ £¬£¬£¬£¬£¬£¬£¬×Ô7ÔÂ7ÈÕ×îÏÈShiny HuntersÔÚ°µÍøÉÏÒÔÊ®¸ö±ÈÌØ±Ò£¨Áè¼Ý100,000ÃÀÔª£©µÄ¼ÛÇ®³öÊÛÕâ¸ö°üÀ¨2ÒÚ¶àÌõ¼Í¼µÄWattpadÊý¾Ý¿â¡£¡£¡£¡£¸ÃÊý¾Ý¿âµÄ¼Í¼°üÀ¨Óû§Ãû¡¢Ãû³Æ¡¢¹þÏ£ÃÜÂë¡¢µç×ÓÓʼþµØµãºÍÒ»Ñùƽ³£µØÀíλÖᣡ£¡£¡£Í¨¹ýÓëй¶Êý¾ÝµÄÓû§ÁªÏµ£¬ £¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÈ·ÈÏÁгöµÄÐÅÏ¢ÊÇ׼ȷµÄ¡£¡£¡£¡£7ÔÂ14ÈÕ£¬ £¬£¬£¬£¬£¬£¬£¬Wattpad³ÆÆäÕýÔÚÆð¾¢ÐÞ¸´¸ÃÎó²î£¬ £¬£¬£¬£¬£¬£¬£¬²¢ÌåÏÖ¸ÃÊÂÎñ²¢Î´Ð¹Â¶ÈκβÆÎñÐÅÏ¢¡¢µç»°ºÅÂë¡¢¹ÊÊ»ò˽ÈËÐÂÎÅ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/wattpad-data-breach-exposes-account-info-for-millions-of-users/


2.ºÚ¿ÍÐ®ÖÆ±È¶û¸Ç´ÄºÍ°Â°ÍÂíµÈÈËTwitterÕÊ»§¾ÙÐмÓÃÜÇ®±ÒÕ©Æ­


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


7ÔÂ15ÈÕÖÜÈý£¬ £¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÐ®ÖÆÁËÊýǧ¸öÊôÓÚ¾«Ó¢Óû§ºÍ×ÅÃû¹«Ë¾µÄ¾­ÓÉÑéÖ¤µÄTwitterÕÊ»§£¬ £¬£¬£¬£¬£¬£¬£¬ÓÃÀ´¾ÙÐмÓÃÜÇ®±ÒÕ©Æ­£¬ £¬£¬£¬£¬£¬£¬£¬°üÀ¨±È¶û¡¤¸Ç´Ä¡¢°£Â¡¡¤Âí˹¿Ë¡¢½Ü·ò¡¤±´×ô˹¡¢Âõ¿Ë¡¤Åí²©¸ñ¡¢°ÝµÇ¡¢°Â°ÍÂí¡¢Æ»¹ûºÍÓŲ½µÈ¡£¡£¡£¡£Ö®ºó£¬ £¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍʹÓÃÕâЩÕË»§Ðû²¼ÍÆÎÄ£¬ £¬£¬£¬£¬£¬£¬£¬ÓÕʹÊܺ¦Õß¹ºÖñÈÌØ±Ò¡£¡£¡£¡£×èÖ¹ÃÀ¹úʱ¼äÖÜÈýÏÂÖç4:45£¬ £¬£¬£¬£¬£¬£¬£¬¸ÃµØµãÒÑÊÕµ½Áè¼Ý110000ÃÀÔªµÄBTC¡£¡£¡£¡£ÏÖÔÚ£¬ £¬£¬£¬£¬£¬£¬£¬Éв»ÇåÎúÕÊ»§ÊÇÔõÑù±»Ð®ÖƵÄ£¬ £¬£¬£¬£¬£¬£¬£¬TwitterÌåÏÖÆäÕýÔÚÊӲ첢½â¾ö´ËÊÂÎñ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

theregister.com/2020/07/15/mass_twitter_account_hacking_bitcoin/


3.OracleÐû²¼7ÔÂÇå¾²¸üУ¬ £¬£¬£¬£¬£¬£¬£¬×ܼÆÐÞ¸´433¸öÎó²î


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Oracle¹Ù·½Ðû²¼Çå¾²¸üУ¬ £¬£¬£¬£¬£¬£¬£¬×ܼÆÐÞ¸´ÁË433¸öÇå¾²Îó²î£¬ £¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁËOracle Weblogic¡¢Oracle SD-WAN AwareºÍOracle SD-WAN EdgeµÈ¶à¿î²úÆ·¡£¡£¡£¡£´Ë´Î¸üÐÂÐÞ¸´ÁËËĸöÆÀ·ÖΪ9.8µÄOracle WebLogic Server·´ÐòÁл¯Îó²î£¨CVE-2020-14625¡¢CVE-2020-14644¡¢CVE-2020-14645 ¡¢CVE-2020-14687£©£¬ £¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Á½¸öÆÀ·ÖΪ10µÄOracle Communications ApplicationsÇå¾²Îó²î£¨CVE-2020-14701¡¢CVE-2020-14606£©¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/07/14/oracle-releases-july-2020-security-bulletin


4.AdobeÐû²¼7ÔÂÇå¾²¸üУ¬ £¬£¬£¬£¬£¬£¬£¬ÐÞ¸´í§Òâ´úÂëÖ´ÐÐÎó²î


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


AdobeÐû²¼ÁËÇå¾²¸üУ¬ £¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁË13¸öÇå¾²Îó²î£¬ £¬£¬£¬£¬£¬£¬£¬°üÀ¨Ó°ÏìÁËWindows°æ±¾µÄCreative Cloud¡¢Adobe Download ManagerºÍAdobe Media EncoderµÄ´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£´Ë´Î¸üÐÂÖÐÖ÷ÒªÐÞ¸´ÁË4¸ö½ÏΪÑÏÖØµÄÎó²î£¬ £¬£¬£¬£¬£¬£¬£¬»®·ÖΪDownload ManagerÖÐÏÂÁî×¢Èëµ¼ÖµÄí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2020-9688£©£¬ £¬£¬£¬£¬£¬£¬£¬Media EncoderÖÐÔ½½çдµ¼ÖµÄí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2020-9650ºÍCVE-2020-9646£©£¬ £¬£¬£¬£¬£¬£¬£¬ÒÔ¼°SymlinkÎó²îµ¼ÖµÄí§ÒâÎļþϵͳдÈëÎó²î£¨CVE-2020-9682£©¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬£¬£¬£¬£¬»¹ÐÞ¸´Á˲»Çå¾²µÄÎļþȨÏÞ¡¢DLLËÑË÷˳ÐòÐ®ÖÆ¡¢²»Çå¾²µÄ¿â¼ÓÔØºÍ·ûºÅÁ´½ÓÎó²îÒÔ¼°Ô½½ç¶ÁÈ¡¶øµ¼ÖÂÌáȨÎó²îµÈÎÊÌâ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/07/14/adobe-releases-security-updates-multiple-products


5.GoogleΪChromeÐû²¼Çå¾²¸üУ¬ £¬£¬£¬£¬£¬£¬£¬ÐÞ¸´38¸öÇå¾²Îó²î


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


GoogleΪChromeÐû²¼Çå¾²¸üУ¬ £¬£¬£¬£¬£¬£¬£¬×ܼÆÐÞ¸´ÁË38¸öÇå¾²Îó²î¡£¡£¡£¡£´Ë´ÎÇå¾²¸üÐÂÖÐÐÞ¸´µÄ½ÏΪÑÏÖØµÄÎó²îΪºǫ́ÌáÈ¡Öжѻº³åÇøÒç³öÎó²î£¨CVE-2020-6510£©¡¢ÄÚÈÝÇå¾²Õ½ÂÔÖеIJàÐŵÀÐÅÏ¢×ß©Îó²î£¨CVE-2020-6511£©¡¢ V8ÖеÄÀàÐÍ»ìÏýÎó²î£¨CVE-2020-6512£©¡¢PDFiumÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2020-6513£©¡¢WebRTCÖеIJ»Êʵ±ÊµÏÖ£¨CVE-2020-6514£©¡¢±êÇ©ÌõÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2020-6515£©¡¢ CORSÖеÄÕ½ÂÔÈÆ¹ýÎó²î£¨CVE-2020-6516 £©ºÍÀúÊ·¼Í¼Öжѻº³åÇøÒç³öÎó²î£¨CVE-2020-6517£©¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/07/14/google-releases-security-updates-chrome


6.VMwareÊӲ췢Ã÷£¬ £¬£¬£¬£¬£¬£¬£¬2020ÄêÍøÂç¹¥»÷ÖØ´óÐÔ´ó·ùÔöÌí


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


VMwareÊӲ췢Ã÷£¬ £¬£¬£¬£¬£¬£¬£¬2020ÄêÍøÂç¹¥»÷µÄÊýÄ¿ºÍÖØ´óÐÔ¾ù´ó·ùÔöÌí¡£¡£¡£¡£ÊӲ췢Ã÷£¬ £¬£¬£¬£¬£¬£¬£¬ÓÐ92£¥µÄÈËÌåÏÖÔÚÒÑÍù12¸öÔÂÖй¥»÷Á¿ÓÐËùÔöÌí£¬ £¬£¬£¬£¬£¬£¬£¬97£¥µÄÈËÌåÏÖËûÃÇÔÚÒÑÍù12¸öÔÂÖÐÔâÊÜÁ˹¥»÷£¬ £¬£¬£¬£¬£¬£¬£¬Æ½¾ùÿ¸ö×éÖ¯ÂÄÀúÁË2.70´Î¹¥»÷ £»£»£»£»£»ÓÐ84£¥µÄÈËÌåÏÖ¹¥»÷±äµÃÔ½·¢ÖØ´ó£¬ £¬£¬£¬£¬£¬£¬£¬95£¥µÄÈËÌåÏÖËûÃÇÍýÏëÔÚÃ÷ÄêÔöÌíÍøÂç·ÀÓùÖ§³ö¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬£¬£¬£¬£¬²Ù×÷ϵͳÎó²îÊÇÍøÂç¹¥»÷ÖеÄÖ÷ÒªÔµ¹ÊÔ­ÓÉ£¬ £¬£¬£¬£¬£¬£¬£¬Æä´ÎÊÇWebÓ¦ÓóÌÐò¹¥»÷ºÍÀÕË÷Èí¼þ¡£¡£¡£¡£ÃÀ¹úÆóÒµÒѾ­Æ½¾ùʹÓÃÁè¼Ý¾ÅÖÖ²î±ðµÄÍøÂçÇå¾²¹¤¾ßÀ´± £»£»£»£»£»¤ËûÃǵÄϵͳ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/07/15/2020-increased-attack-sophistication/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+HelpNetSecurity+%28Help+Net+Security%29