Intel 471Ðû²¼°µÍøÖÐ25ÖÖÖ÷ÒªRaaS²úÆ·µÄÆÊÎö±¨¸æ£»£»£»£»£» £»£»£»FirefoxÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´0day²¢ÐÂÔö½öHTTPSģʽ

Ðû²¼Ê±¼ä 2020-11-18

1.Intel 471Ðû²¼°µÍøÖÐ25ÖÖÖ÷ÒªRaaS²úÆ·µÄÆÊÎö±¨¸æ


1.jpg


Intel 471Ðû²¼ÁËÓйذµÍøÖеÄ25ÖÖÖ÷ÒªRaaS²úÆ·µÄÆÊÎö±¨¸æ¡£¡£¡£¡£Intel 471ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬Ëüƾ֤RaaSµÄÅÓºéˮƽ¡¢¹¦Ð§ºÍÀúÊ·½«ÕâЩÀÕË÷Èí¼þ·ÖΪÈý¸öÌõÀí¡£¡£¡£¡£µÚÒ»²ãΪµ±½ñ×îÖøÃûµÄÀÕË÷Èí¼þ£¬£¬£¬£¬£¬£¬£¬°üÀ¨REvil¡¢Netwalker¡¢DopplePaymer¡¢Egregor£¨Maze£©ºÍRyuk¡£¡£¡£¡£µÚ¶þ²ãΪÀÕË÷Èí¼þÌìϵÄÐÂÐË´ú±í£¬£¬£¬£¬£¬£¬£¬°üÀ¨Avaddon¡¢Conti¡¢Clop¡¢DarkSide¡¢Mespinoza£¨Pysa£©¡¢RagnarLocker¡¢Ranzy£¨Ako£©¡¢SunCryptºÍThanos¡£¡£¡£¡£µÚÈý²ãΪÐÂÐû²¼µÄRaaS²úÆ·£¬£¬£¬£¬£¬£¬£¬°üÀ¨CVartek.u45¡¢Exorcist¡¢Gothmog¡¢Lolkek¡¢Muchlove¡¢Nemty¡¢Rush¡¢Wally¡¢Xinof¡¢ZeoticusºÍZagreuS¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://public.intel471.com/blog/ransomware-as-a-service-2020-ryuk-maze-revil-egregor-doppelpaymer/


2.FirefoxÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´0day²¢ÐÂÔö½öHTTPSģʽ


2.jpg


MozillaÐû²¼FirefoxÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´0day²¢ÐÂÔö½öHTTPSģʽ¡£¡£¡£¡£½öHTTPS¹¦Ð§¿É×Ô¶¯ÐÞ¸ÄURL£¬£¬£¬£¬£¬£¬£¬µ±Óû§ÆôÓÃÁ˸Ãģʽʱ£¬£¬£¬£¬£¬£¬£¬Firefox»á½«Óû§»á¼ûµÄËùÓÐhttp£º// URLÖØÐ´ÎªÆäÇå¾²µÄhttps£º//£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÎÞ·¨ÅþÁ¬µ½Çå¾²URL£¬£¬£¬£¬£¬£¬£¬Ëü½«ÏÔʾÇå¾²ÅþÁ¬²»¿ÉÓõĹýʧÖÒÑÔ¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬´Ë´ÎÇå¾²¸üл¹ÐÞ¸´ÁË21¸öÎó²î£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨FreetypeµÄ0day¡£¡£¡£¡£¸ÃÎó²îÓÉGoogle Project ZeroÅû¶£¬£¬£¬£¬£¬£¬£¬¿ÉÓÃÓÚÕë¶ÔGoogle ChromeµÄ×Ô¶¯¹¥»÷¡£¡£¡£¡£µ«ÆäÓ°ÏìÁËËùÓÐʹÓÃFreetypeµÄÈí¼þ£¬£¬£¬£¬£¬£¬£¬°üÀ¨Mozilla Firefox¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/software/firefox-83-boosts-security-with-https-only-mode-zero-day-fix/


3.Citrix SD-WAN±£´æ¶à¸öÎó²î£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ


3.jpg


Citrix SD-WAN±£´æ¶à¸öÎó²î£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐкÍϵͳ½ÓÊÜ¡£¡£¡£¡£µÚÒ»¸öÎó²îΪstop_pingÖÐδÂÄÀúÖ¤µÄ·¾¶±éÀúºÍshell×¢ÈëÎó²î£¨CVE-2020¨C8271£©£¬£¬£¬£¬£¬£¬£¬¿Éʹδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß»ñµÃrootȨÏÞ¡£¡£¡£¡£µÚ¶þ¸öÎó²îΪConfigEditorÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2020¨C8272£©£¬£¬£¬£¬£¬£¬£¬ÓëCakePHP½«URIת»»Îª¶Ëµãº¯Êý²ÎÊýÓйء£¡£¡£¡£µÚÈý¸öÎó²îΪCreateAzureDeploymentÖеÄShell×¢ÈëÎó²î£¨CVE-2020¨C8273£©¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÁ¬ÏµÊ¹ÓÃÕâÈý¸öÎó²î¿ÉÀֳɽÓÊÜÏµÍ³ÍøÂç¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/citrix-sd-wan-bugs-remote-code-execution/161274/


4.Ñо¿Ö°Ô±³ÆÈÔÓнü25Íò¸öϵͳÈÔÒ×ÊÜBlueKeep RDP¹¥»÷


4.jpg


΢ÈíÅû¶ÁËÓ°ÏìWindows RDPЧÀ͵ÄBlueKeepÎó²îÒ»Äê°ëÖ®ºó £¬£¬£¬£¬£¬£¬£¬ÈÔÈ»ÓÐÁè¼Ý245000¸öWindowsϵͳÒ×Êܵ½´ËÀ๥»÷¡£¡£¡£¡£SANS ISCÑо¿Ö°Ô±³Æ£¬£¬£¬£¬£¬£¬£¬Ö»¹Ü¸ÃÎó²îºÜÊÇÑÏÖØ£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¹ú¼ÒÕþ¸®Ò²¶à´ÎÐû²¼¸üÐÂÖÒÑÔ£¬£¬£¬£¬£¬£¬£¬µ«ÈÔÓÐ25£¥Ò×ѬȾϵͳÒòδ֪Ե¹ÊÔ­ÓÉδ¾ÙÐиüС£¡£¡£¡£Í¬ÑùµØ£¬£¬£¬£¬£¬£¬£¬Áè¼Ý103000¸öWindowsϵͳҲÈÔÈÝÒ×Êܵ½SMBGhostµÄ¹¥»÷¡£¡£¡£¡£SMBGhostÊÇServer Message Block v3£¨SMB£©Ð­ÒéÖеÄÎó²î£¬£¬£¬£¬£¬£¬£¬ÓëBlueKeepÒ»Ñù¶¼¿Éʹ¹¥»÷ÕßÔ¶³Ì¿ØÖÆWindowsϵͳ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/more-than-245000-windows-systems-still-remain-vulnerable-to-bluekeep-rdp-bug/


5.ij¹ûÕæµÄÊý¾Ý¿âй¶10Íò¶à¸öFacebookÓû§µÄÐÅÏ¢


5.jpg


vpnMentorµÄÑо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öÔÚÏß¹ûÕæµÄElasticSearchÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨Áè¼Ý100000¸öFacebookÓû§µÄÐÅÏ¢¡£¡£¡£¡£¸ÃÊý¾Ý¿âµÄÈÝÁ¿Áè¼Ý5.5 GB£¬£¬£¬£¬£¬£¬£¬×ܹ²°üÀ¨13521774¸öÎļþ£¬£¬£¬£¬£¬£¬£¬ÓÚ½ñÄê6ÔÂÖÁ9Ô¼ä¼á³Ö¿ª·Å״̬¡£¡£¡£¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨À¨µç×ÓÓʼþ¡¢ÐÕÃûºÍµç»°ºÅÂ룬£¬£¬£¬£¬£¬£¬»¹°üÀ¨ÓйØÍøÂç·¸·¨·Ö×ÓÔõÑù×Ô¶¯Ö´Ðй¥»÷Á÷³ÌµÄÊÖÒÕÐÅÏ¢¡£¡£¡£¡£vpnMentorÖ¸³ö¸ÃÊý¾Ý¿â¿ÉÄÜÊôÓÚµÚÈý·½£¬£¬£¬£¬£¬£¬£¬Æäͨ¹ýÕë¶ÔFacebookÓû§µÄ´¹ÂÚÍøÕ¾²»·¨»ñµÃµÄÕË»§µÇ¼ƾ֤¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/111018/cyber-crime/100k-facebook-accounts-scam.html


6.AmericoldÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬Æä¶à¸öϵͳÊܵ½Ó°Ïì


6.jpg


Àä¿â¹«Ë¾AmericoldÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬°üÀ¨µç»°ÏµÍ³¡¢µç×ÓÓʼþ¡¢¿â´æÖÎÀíºÍ¶©µ¥ÏµÍ³ÔÚÄڵĶà¸öϵͳÊܵ½Ó°Ïì¡£¡£¡£¡£AmericoldÊÇÒ»¼ÒÁìÏȵÄοؿÍÕ»ÔËÓªÉÌ£¬£¬£¬£¬£¬£¬£¬ÎªÁãÊÛÉÌ¡¢Ê³ÎïЧÀÍÌṩÉ̺ÍÉú²úÉÌÌṩ¹©Ó¦Á´Ð§ÀÍºÍ¿â´æÖÎÀí£¬£¬£¬£¬£¬£¬£¬AmericoldÔÚÈ«ÇòÓµÓÐ183¸ö¿ÍÕ»¡£¡£¡£¡£11ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬£¬AmericoldÈ·¶¨ÆäÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬²¢Á¬Ã¦½ÓÄÉÁËÏìÓ¦²½·¥£¬£¬£¬£¬£¬£¬£¬¹Ø±ÕÅÌËã»úϵͳÒÔ±ÜÃâ¹¥»÷ÉìÕÅ¡£¡£¡£¡£¾ÝÐí¶àÐÂÎÅȪԴ³Æ£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»ÖÖÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬µ«ÏÖÔÚÉв»Ïàʶ¹¥»÷ÏêÇé¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/cold-storage-giant-americold-hit-by-cyberattack-services-impacted/