ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ38ÖÜ
Ðû²¼Ê±¼ä 2020-09-21> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2020Äê09ÔÂ14ÈÕÖÁ09ÔÂ20ÈÕ¹²ÊÕ¼Çå¾²Îó²î57¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe Media Encoder CVE-2020-9745Ô½½ç¶ÁÐÅϢй¶Îó²î£»£»£»£»£»£»Gallagher Group Command Centre¿Í»§¶Ë¹ÒÆðÎó²î£»£»£»£»£»£»Hyland OnBase CVE-2020-25248Ŀ¼±éÀúÎó²î£»£»£»£»£»£»IPTV/H.264/H.265ÊÓÆµ±àÂëÆ÷ºóÃÅÃÜÂëÖÎÀíÔ±»á¼ûÎó²î£»£»£»£»£»£»Google Android Framework CVE-2020-0275ȨÏÞÌáÉýÎó²î¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇRazerÊý¾Ý¿â̻¶µ¼ÖÂÆäÔ¼10ÍòÓû§ÐÅϢй¶£»£»£»£»£»£»RedgateÐû²¼2020Äê¶ÈÊý¾Ý¿â״̬¼à²â±¨¸æ£»£»£»£»£»£»Ó¢¹ú¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ£¨NCSC£©Ðû²¼Îó²îÅû¶ָÄÏ£»£»£»£»£»£»¿¨°Í˹»ùÐû²¼2020Äê¹¤ÒµÍøÂçÇå¾²ÊÓ²ìÑо¿±¨¸æ£»£»£»£»£»£»µÂ¹ú¹ºÎïÍøÕ¾windeln.deÊý¾Ý¿â̻¶£¬£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶60ÒÚÌõ¼Í¼¡£¡£¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£
> Ö÷ÒªÇå¾²Îó²îÁбí
1.Adobe Media Encoder CVE-2020-9745Ô½½ç¶ÁÐÅϢй¶Îó²î
Adobe Media Encoder±£´æÔ½½ç¶ÁÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£
https://helpx.adobe.com/security/products/media-encoder/apsb20-57.html
2. Gallagher Group Command Centre¿Í»§¶Ë¹ÒÆðÎó²î
Gallagher Group Command Centre½¨ÉèGuard TourÊÂÎñ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿Éʹ¿Í»§¶ËÔÝʱ¹ÒÆð»ò¶Ï¿ªÅþÁ¬¡£¡£¡£¡£¡£¡£
https://security.gallagher.com/Security-Advisories/CVE-2020-16099
3.Hyland OnBase CVE-2020-25248Ŀ¼±éÀúÎó²î
Hyland OnBase±£´æÂ·¾¶±éÀúÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎĶÁȡϵͳÎļþ»òдÈëϵͳµ½Îļþ¡£¡£¡£¡£¡£¡£
https://seclists.org/fulldisclosure/2020/Sep/21
4. IPTV/H.264/H.265ÊÓÆµ±àÂëÆ÷ºóÃÅÃÜÂëÖÎÀíÔ±»á¼ûÎó²î
IPTV/H.264/H.265ÊÓÆµ±àÂëÆ÷±£´æºóÃÅÃÜÂëÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉδÊÚȨÍêÈ«¿ØÖÆÓ¦Óᣡ£¡£¡£¡£¡£
https://www.kb.cert.org/vuls/id/896979
5. Google Android Framework CVE-2020-0275ȨÏÞÌáÉýÎó²î
Google Android Framework±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
https://source.android.com/security/bulletin/android-11
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢RazerÊý¾Ý¿â̻¶µ¼ÖÂÆäÔ¼10ÍòÓû§ÐÅϢй¶

8ÔÂ19ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Ñо¿Ô±Bob Diachenko·¢Ã÷ÓÎÏ·Ó²¼þÖÆÔìÉÌRazerµÄÔÚÏßÊÐËÁµÄÊý¾Ý¿â̻¶£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÆäÔ¼10ÍòÓû§ÐÅϢй¶¡£¡£¡£¡£¡£¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂë¡¢¶©µ¥ºÅ¡¢¶©µ¥Ã÷ϸÒÔ¼°Õʵ¥ºÍËÍ»õµØµãµÈ¡£¡£¡£¡£¡£¡£RazerÓÚÔÚ9ÔÂ9ÈÕÐÞ¸´Á˸ÃÊý¾Ý¿âЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬£¬²¢ÌåÏÖ¸ÃÊÂÎñÖв¢Ã»ÓÐÆäËûÃô¸ÐÊý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈçÐÅÓÿ¨ºÅ»òÃÜÂëµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/razer-data-leak-exposes-personal-information-of-gamers/
2¡¢RedgateÐû²¼2020Äê¶ÈÊý¾Ý¿â״̬¼à²â±¨¸æ

Redgate×îÐÂÐû²¼ÁË2020Äê¶ÈÊý¾Ý¿â״̬¼à²â±¨¸æ¡£¡£¡£¡£¡£¡£±¨¸æÏÔʾ£¬£¬£¬£¬£¬£¬£¬£¬ÎÞÂÛÊÇÔÚ½ÓÄÉÊý¾Ý¿âDevOps·½Ã棬£¬£¬£¬£¬£¬£¬£¬ÕÕ¾ÉÔÚʹÓÃ¼à¿ØÀ´¸ú×ÙÊý¾Ý¿âÐÔÄܺͰ²ÅÅ·½Ã棬£¬£¬£¬£¬£¬£¬£¬½ðÈÚЧÀÍÐÐÒµµÄÌåÏÖ¶¼ÓÅÓÚÆäËûÐÐÒµ¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬£¬£¬61%µÄ½ðÈÚЧÀÍÐÐÒµÔ±¹¤Ã¿ÖܸüÐÂÖÁÉÙÒ»´ÎÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬£¬¶øÆäËûÐÐÒµÖ»ÓÐ43%µÄÔ±¹¤»áÕâÑù×ö¡£¡£¡£¡£¡£¡£½ðÈÚЧÀ͵ÄЧÀÍÆ÷ÊýĿҲ¸ü¶à£¬£¬£¬£¬£¬£¬£¬£¬36%µÄЧÀÍÆ÷ÓµÓÐ50µ½500¸öʵÀý£¬£¬£¬£¬£¬£¬£¬£¬¶øÆäËû²¿·ÖÖ»ÓÐ26%¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/09/14/database-monitoring-improves-devops-success/
3¡¢Ó¢¹ú¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ£¨NCSC£©Ðû²¼Îó²îÅû¶ָÄÏ

Ó¢¹ú¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ£¨NCSC£©Ðû²¼ÁËÎó²îÅû¶ָÄÏ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ×ÊÖú¹«Ë¾ÊµÑéÎó²îÅû¶Á÷³Ì»òÔÚÒѾ½¨ÉèÎó²îÅû¶Á÷³ÌµÄÇéÐÎÏÂ¶ÔÆä¾ÙÐÐˢС£¡£¡£¡£¡£¡£NCSCÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÖ¸Äϲ¢²»ÊÇÒ»¸öÎó²îÅû¶µÄ¹æÔòÊֲᣬ£¬£¬£¬£¬£¬£¬£¬¶øÊÇΪ¸üºÃµÄʵÑéÌṩÁËÐëÒªµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£ÆäÖ÷Òª·ÖΪÈý¸öÖ÷Òª²¿·Ö£¬£¬£¬£¬£¬£¬£¬£¬ÐÎòÁËÔõÑù½«ÍⲿÎó²îÐÅÏ¢¶¨Ïò¸øºÏÊʵÄÈË£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°±¨¸æÐè×ñÕչرÕÎó²îµÄ¿ò¼Ü±ê×¼¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/uk-government-releases-toolkit-to-easily-disclose-vulnerabilities/
4¡¢¿¨°Í˹»ùÐû²¼2020Äê¹¤ÒµÍøÂçÇå¾²ÊÓ²ìÑо¿±¨¸æ

¿¨°Í˹»ù¶ÔÒßÇéʱ´úµÄ¹¤ÒµÍøÂçÇ徲״̬¾ÙÐÐÁËÑо¿£¬£¬£¬£¬£¬£¬£¬£¬²¢Ðû²¼ÁË2020Äê¹¤ÒµÍøÂçÇå¾²ÊÓ²ìÑо¿±¨¸æ¡£¡£¡£¡£¡£¡£±¨¸æÏÔʾ£¬£¬£¬£¬£¬£¬£¬£¬Áè¼ÝÒ»°ë(53%)µÄÊÜ·ÃÕßÈϿɣ¬£¬£¬£¬£¬£¬£¬£¬COVID-19µ¼Ö¸ü¶àÔ±¹¤ÔڼҰ칫£¬£¬£¬£¬£¬£¬£¬£¬ÕâÒѳÉΪ¶ÔÐÅÏ¢Ç徲ЧÀ͵ÄÒ»ÖÖѹÁ¦²âÊÔ¡£¡£¡£¡£¡£¡£ÓÉÓÚÍⲿÅþÁ¬ÊýÄ¿Öڶ࣬£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚ¾ø´ó´ó¶¼¹«Ë¾¶¼ÔÚ¶ÔOTÍøÂçµÄÇå¾²¼¶±ð¾ÙÐа´ÆÚÆÀ¹À¡£¡£¡£¡£¡£¡£Ðí¶à×éÖ¯²»µÃ²»ÖØÐÂ˼Á¿ËûÃÇÄÚÍøµÄ±£»£»£»£»£»£»¤ÒªÁ죬£¬£¬£¬£¬£¬£¬£¬Ö»ÓÐ7%µÄÊÜ·ÃÕßÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ËûÃǵÄÍøÂçÇå¾²Õ½ÂÔÔÚCOVID-19ʱ´úÏ൱ÓÐÓᣡ£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.kaspersky.com/blog/industrial-cybersecurity-2020/37031/
5¡¢µÂ¹ú¹ºÎïÍøÕ¾windeln.deÊý¾Ý¿â̻¶£¬£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶60ÒÚÌõ¼Í¼

Safety DetectivesµÄÑо¿Ö°Ô±ÔÚÍøÂçÉÏ·¢Ã÷ÁËÒ»¸ö̻¶µÄÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬£¬¾ÊÓ²ì¸ÃÊý¾Ý¿âÊôÓڵ¹úÔÚÏß¹ºÎïÍøÕ¾windeln.de¡£¡£¡£¡£¡£¡£Æä̻¶ÁË6.4TBµÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨60ÒÚÌõ¼Í¼£¬£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶ÁËÁè¼Ý700000Ãû¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñµÄй¶ÐÅÏ¢°üÀ¨Ð¡ÎÒ˽¼ÒÉí·ÝÐÅÏ¢£¨PII£©ºÍÆäËûÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈ緢Ʊ¡¢È«Ãû¡¢IPµØµã¡¢ÄÚ²¿ÈÕÖ¾¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢¼ÒÍ¥µØµã¡¢É¢ÁÐÃÜÂë¡¢¸¶¿î·½·¨ºÍÓû§µÄº¢×ÓСÎÒ˽¼ÒÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/shopping-site-leaks-miners-data-database-mess-up/


¾©¹«Íø°²±¸11010802024551ºÅ