ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ16ÖÜ
Ðû²¼Ê±¼ä 2020-04-20> ±¾ÖÜÇ徲̬ÊÆ×ÛÊö
2020Äê04ÔÂ13ÈÕÖÁ19ÈÕ¹²ÊÕ¼Çå¾²Îó²î72¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇGoogle Chrome speech recognizer´úÂëÖ´ÐÐÎó²î; VeeamOne Agent PerformHandshake´úÂëÖ´ÐÐÎó²î£»Apache Heron·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î£»Cisco UCS Director ApplianceStorageUtil unzipĿ¼±éÀú´úÂëÖ´ÐÐÎó²î£»Triangle MicroWorks SCADA Data Gateway DNP3 GET_FILE_INFOÕ»Òç³öÎó²î¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇ°Í»ù˹̹1.15ÒÚÒƶ¯Óû§Êý¾ÝÔÚ°µÍø³öÊÛ£»µ¤ÂóË®±ÃÖÆÔìÉÌDESMIÔâÍøÂç¹¥»÷£¬ÏµÍ³ÈÔδ»Ö¸´£»OracleÐû²¼4ÔÂÖ÷Òª²¹¶¡¸üУ¬ÐÞ¸´397¸öÎó²î£»Ó¢ÌضûÐû²¼4ÔÂÇå¾²¸üУ¬ÐÞ¸´¶à¿î²úÆ·ÖеÄ9¸öÎó²î£»EA SportsÔâ´ó¹æÄ£DDoS¹¥»÷£¬È«Çò·þÎñÖÐÖ¹¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£
>Ö÷ÒªÇå¾²Îó²îÁбí
1. Google Chrome speech recognizer´úÂëÖ´ÐÐÎó²î
Google Chrome speech recognizer±£´æÊͷźóʹÓÃÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉʹӦÓóÌÐò±ÀÀ£»òÖ´ÐÐí§Òâ´úÂë¡£
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_15.html
2. Veeam One Agent PerformHandshake´úÂëÖ´ÐÐÎó²î
Veeam One Agent PerformHandshakeÒªÁì±£´æ·´ÐòÁл¯Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓóÌÐò±ÀÀ£»òÖ´ÐÐí§Òâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-20-545/
3. Apache Heron·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î
Apache Heron±£´æ·´ÐòÁл¯Îó²î£¬ÔÊÐíͨ¹ýÑéÖ¤µÄÖÎÀíÔ±Óû§Ê¹ÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://lists.apache.org/thread.html/r16dd39f4180e4443ef4ca774a3a5a3d7ac69f91812c183ed2a99e959%40%3Cdev.heron.apache.org%3E
4. Cisco UCS Director ApplianceStorageUtil unzipĿ¼±éÀú´úÂëÖ´ÐÐÎó²î
Cisco UCS Director ApplianceStorageUtil unzip´¦Öóͷ£Îļþ²Ù×÷±£´æĿ¼±éÀúÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔrootÕË»§ÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-20-539/
5. Triangle MicroWorks SCADA Data Gateway DNP3 GET_FILE_INFOÕ»Òç³öÎó²î
Triangle MicroWorks SCADA Data Gateway´¦Öóͷ£DNP3 GET_FILE_INFO±£´æÕ»Òç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓóÌÐò±ÀÀ£»òÖ´ÐÐí§Òâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-20-547
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢°Í»ù˹̹1.15ÒÚÒƶ¯Óû§Êý¾ÝÔÚ°µÍø³öÊÛ
°Í»ù˹̹Çå¾²³§ÉÌRewterz·¢Ã÷£¬ÏÖÔÚÓÐ1.15ÒÚ°Í»ù˹̹Òƶ¯Óû§µÄÊý¾ÝÔÚ°µÍøÂÛ̳³öÊÛ£¬¼ÛǮΪ300 BTC£¨Ô¼ºÏ210ÍòÃÀÔª£©¡£ÕâЩÊý¾Ý°üÀ¨Óû§µÄÏêϸСÎÒ˽¼ÒÐÅÏ¢£¬ÀýÈçÐÕÃû¡¢ÍêÕûµØµã¡¢ÊÖ»úºÅÂëÒÔ¼°NICºÅºÍË°ÎñºÅÂë¡£RewterzÍþвÇ鱨ר¼ÒÒÔΪÕâЩÊý¾Ý¿ÉÄÜÊÇÒ»´Î»ò¶à´Î鶵ÄЧ¹û£¬ÏÖÔÚ»¹²»ÇåÎúÊÇ·ñÓÐÈκÎÌض¨µÄµçÐÅÔËÓªÉÌ»òÊÇËùÓеçÐÅÔËÓªÉ̳ÉΪ´Ë´Î¹¥»÷µÄÊܺ¦Õß¡£¸Ãй¶Êý¾ÝµÄ¹æÄ£Òý·¢Á˶ԵçÐŹ«Ë¾Êý¾ÝÇå¾²ÐÔºÍÒþ˽ÐԵĵ£ÐÄ¡£
ÔÎÄÁ´½Ó£º
http://www.rewterz.com/articles/115-million-pakistani-mobile-users-data-go-on-sale-on-dark-web
2¡¢µ¤ÂóË®±ÃÖÆÔìÉÌDESMIÔâÍøÂç¹¥»÷£¬ÏµÍ³ÈÔδ»Ö¸´
µ¤ÂóË®±ÃÖÆÔìÉÌDESMIÔâµ½ÍøÂç¹¥»÷£¬¸Ã¹¥»÷ÊÂÎñ±¬·¢ÔÚÉÏÖÜËĵÄÍíÉÏ£¬Ôâµ½¹¥»÷ºó¹«Ë¾µÄËùÓÐϵͳ¾ù±»¹Ø±Õ¡£Æ¾Ö¤¸Ã¹«Ë¾ÔÚ¹ÙÍøÉÏÐû²¼µÄÖÒÑÔ£¬¹«Ë¾µÄËùÓÐϵͳ¾ù±»¹Ø±Õ£¬²¢ÇÒÕýÔÚ»¹ÔÀú³ÌÖУ¬Ê×Åú²¿·Öϵͳ½«ÔÚ¼¸ÌìÄÚÆô¶¯²¢ÔËÐУ¬ÆäÓàµÄϵͳ½«ÔÚ¼¸ÖÜÖ®ÄÚÔËÐС£ÏÖÔÚÊÓ²ìÈÔÔÚ¾ÙÐÐÖ®ÖУ¬Éв»ÇåÎú¹¥»÷µÄˮƽ£¬DESMIÒѽ«ÊÂÎñ±¨¸æ¸øµ¤ÂóÕþ¸®ºÍ¾¯Ô±¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/101495/hacking/desmi-discloses-cyber-attack.html
3¡¢OracleÐû²¼4ÔÂÖ÷Òª²¹¶¡¸üУ¬ÐÞ¸´397¸öÎó²î
OracleÔÚÆä4ÔÂÖ÷Òª²¹¶¡¸üÐÂÖÐÐÞ¸´ÁË397¸öÎó²î£¬ÆäÖÐOracle Database Server²úÆ·ÖÐÐÞ¸´ÁË8¸öÎó²î£»µç×ÓÉÌÎñÌ×¼þÖÐÐÞ¸´ÁË74¸öÎó²î£¬°üÀ¨70¸öÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓõÄÎó²î£»OracleÈÚºÏÖÐÐļþÖÐÐÞ¸´ÁË51¸öÎó²î£¬ÆäÖÐ44¸öÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓã»Java SEÖÐÐÞ¸´ÁË15¸öÎó²î£¬ËùÓÐÎó²î¾ù¿ÉÒÔÔÚ²»¾ÙÐÐÉí·ÝÑéÖ¤µÄÇéÐÎϾÙÐÐÔ¶³ÌʹÓã»MySQLÖÐÐÞ¸´ÁË45¸öÎó²î£¬ÆäÖÐ9¸öÎó²îÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓá£ÍêÕûÎó²îÁбíÇë²Î¿¼ÒÔϹٷ½Á´½Ó£¬½¨ÒéÓû§¾¡¿ìÓ¦ÓøüС£
ÔÎÄÁ´½Ó£º
https://www.oracle.com/security-alerts/cpuapr2020.html
4¡¢Ó¢ÌضûÐû²¼4ÔÂÇå¾²¸üУ¬ÐÞ¸´¶à¿î²úÆ·ÖеÄ9¸öÎó²î
Ó¢ÌضûÔÚ4Ô²¹¶¡¸üÐÂÖÐÐÞ¸´ÁË9¸öÎó²î£¬ÕâЩÎó²î¾ùΪÖиßΣÎó²î£¬Ó°Ïì¶à¸öÈí¼þ¡¢¹Ì¼þ¼°Æ½Ì¨¡£Ó¢ÌضûÐÞ¸´ÁËPROSet/ÎÞÏßWiFi²úÆ·ÔÚWindows 10ÉϵÄÁ½¸öÎó²î-¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓÉÓÚ²»Çå¾²µÄ¼ÌÐøȨÏÞ¶ø¿ÉÄÜͨ¹ýÍâµØ»á¼û¾ÙÐÐÌØȨÉý¼¶£¨CVE-2020-0557£©£»ÓÉÓÚÄÚºËÇý¶¯³ÌÐòÖеĻº³åÇøÏÞÖƲ»µ±£¬ÎÞÌØȨµÄ¹¥»÷Õß¿ÉÄÜͨ¹ýÏàÁÚÍøÂç»á¼ûÀ´µ¼Ö¾ܾø·þÎñ£¨CVE-2020-0558£©¡£Ó¢Ìضû»¹ÐÞ¸´ÁËNUC mini PCµÄϵͳ¹Ì¼þÖкÍÄ£¿é»¯·þÎñÆ÷MFS2600KISPPÅÌËãÄ£¿éÖеÄÁ½¸öÎó²î£¬°üÀ¨²»×¼È·µÄ»º³åÇøÏÞÖƵ¼ÖµÄLPEÎó²î£¨CVE-2020-0600£©ºÍÌõ¼þ¼ì²é²»µ±µ¼ÖµÄÌáȨÎó²î£¨CVE-2020-0578£©¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/intel-april-platform-update-fixes-high-severity-security-issues/
5¡¢EA SportsÔâ´ó¹æÄ£DDoS¹¥»÷£¬È«Çò·þÎñÖÐÖ¹
ÓÎÏ·¹«Ë¾EA SportsÓÖÒ»´ÎÔâµ½´ó¹æÄ£µÄDDoS¹¥»÷£¬µ¼Ö¸ù«Ë¾µÄ·þÎñÆ÷ÔÚÈ«Çò¹æÄ£ÄÚÍÑ»ú¡£´Ë´Î¹¥»÷±¬·¢ÔÚ4ÔÂ14ÈÕÏÂÖç4:19¡£Æ¾Ö¤Down DetectorµÄʵʱµØͼ£¬´Ë´Î¹¥»÷Ö÷ÒªÓ°ÏìÁËÅ·ÖÞµØÇøµÄ¿Í»§£¬µ«¼ÓÄô󡢰£¼°¡¢ÄϷǵȵصĿͻ§Ò²Êܵ½ÁË»ò¶à»òÉÙµÄÓ°Ïì¡£4ÔÂ15ÈÕÆÆÏþ1µã25·Ö£¬EA SportsÈϿɸù«Ë¾¡°ÂÄÀúÁËһϵÁÐDDoS¹¥»÷¡±¡£ÔÚÐû²¼±¾ÎÄʱ£¬EA SportsµÄ¿Í»§ÈÔÔÚËß¿à·þÎñå´»ú£¬ÕâÅú×¢¸Ã¹«Ë¾ÈÔÔÚÔâÊܹ¥»÷¡£ÖµµÃ×¢ÖصÄÊÇ£¬±©Ñ©Ò²ÔÚ4ÔÂ14ÈÕÆÆÏþ4µã15·Ö×óÓÒÔ⵽һϵÁÐDDoS¹¥»÷£¬µ¼ÖÂÈ«Çò·þÎñÖÐÖ¹¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/ea-sports-down-gaming-giant-hit-by-ddos-attacks/