΢Èí°ä²¼×î´ó¹æÄ£Öܶþ²¹¶¡½¨¸´129¸ö·ì϶£»£» £»£»£»£»£»UPnPºÍ̸Öеķì϶CallStranger£¬£¬£¬£¬£¬£¬ £¬£¬¿Éµ¼ÖÂÊý¾Ýй¶»òDDoS¹¥»÷

°ä²¼¹¦·ò 2020-06-10

1.΢Èí°ä²¼×î´ó¹æÄ£µÄÖܶþ²¹¶¡·¨Ê½£¬£¬£¬£¬£¬£¬ £¬£¬¹²½¨¸´129¸ö·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


΢ÈíÓÚ6ÔÂ9ÈÕ°ä²¼ÁË×î´ó¹æÄ£µÄÐÇÆÚ¶þ²¹¶¡·¨Ê½£¬£¬£¬£¬£¬£¬ £¬£¬¹²½¨¸´ÁËMicrosoft²úÆ·ÖеÄ129¸ö·ì϶¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬ £¬£¬Microsoft EdgeºÍVBScriptÒýÇæÖдæÔÚÈý¸ö½ÏΪÑϳÁµÄ·ì϶£¬£¬£¬£¬£¬£¬ £¬£¬±ðÀëÊÇMicrosoftä¯ÀÀÆ÷ÄÚ´æ°Ü»µ·ì϶£¨CVE-2020-1219£©¡¢VBScriptÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-1216£©ºÍVBScriptÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-1216£©£¬£¬£¬£¬£¬£¬ £¬£¬ÕâЩ·ì϶¿É±»ÀûÓÃÀ´Ö´ÐÐÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£»£» £»£»£»£»£»¹ÓÐһЩ½ÏΪÑϳÁµÄ·ì϶¿É±»ÓÃÓÚÍøÂç´¹µö¹¥»÷ÒÔÓÕʹÓû§ÏÂÔØ¶ñÒâÎļþ£¬£¬£¬£¬£¬£¬ £¬£¬±ðÀëÊÇGDI +Ô¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-1248£©¡¢Windows OLEÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-1281£©¡¢ºÍLNKÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-1299£©¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2020-patch-tuesday-largest-ever-with-129-fixes/


2.UPnPºÍ̸Öеķì϶CallStranger£¬£¬£¬£¬£¬£¬ £¬£¬¿Éµ¼ÖÂÊý¾Ýй¶»òDDoS¹¥»÷


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


°²È«¹¤³ÌʦYunus?adirci·¢´Ë¿ÌͨÓü´²å¼´ÓúÍ̸£¨Universal Plug and Play£¬£¬£¬£¬£¬£¬ £¬£¬UPnP£©ÖдæÔÚÃûΪCallStrangerµÄ·ì϶£¨CVE-2020-12695£©£¬£¬£¬£¬£¬£¬ £¬£¬¿ÉÄܵ¼ÖÂÊý¾Ýй¶¡¢DDoS¹¥»÷ÒÔ¼°¶ÔÉ豸ÄÚ²¿¶Ë¿ÚµÄɨÃè¡£¡£¡£¡£¡£¸Ã·ì϶¿ÉÄÜ»áÓ°ÏìËùÓÐ4ÔÂ17ÈÕ֮ǰ°æ±¾µÄUPnPÉ豸£¬£¬£¬£¬£¬£¬ £¬£¬Ô̺¬Windows 10ϵͳ¡¢Â·ÓÉÆ÷¡¢½ÓÈëµã¡¢´òÓ¡»ú¡¢ÓÎÏ·»ú¡¢ÃÅÁåµç»°¡¢Ã½ÌåÀûÓ÷¨Ê½ºÍÉ豸¡¢Ïà»ú¡¢µçÊÓ»úµÈ¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇÓÉUPnP SUBSCRIBEº¯ÊýÖеıêÍ·Öµ»Øµ÷ÒýÆðµÄ£¬£¬£¬£¬£¬£¬ £¬£¬¹¥»÷ÕßÄܹ»»ú¹ØÒ»¸öº¬ÓÐÌåʽÃýÎóµÄ±êÍ·Öµ»Øµ÷µÄTCPÊý¾Ý°ü·¢Ë͵½Ô¶¶ËÉ豸£¬£¬£¬£¬£¬£¬ £¬£¬À´ÀûÓû¥ÁªÍøÉÏÖ§³ÖUPnPºÍ̸µÄÖÇÄÜÉ豸¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/callstranger-upnp-bug-allows-data-theft-ddos-attacks-lan-scans/


3.ÀûÓÃDigilocker´æÔÚ·ì϶£¬£¬£¬£¬£¬£¬ £¬£¬¿É±»ÀûÓÃÈÆ¹ýÉí·ÝÑéÖ¤


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÓÉÓ¡¶Èµç×ÓºÍIT²¿ÃÅÆ¾¾ÝÆäDigital India´òËãÌṩµÄÔÚÏß·þÎñ·¨Ê½Digilocker´æÔÚ·ì϶£¬£¬£¬£¬£¬£¬ £¬£¬¸Ã·ì϶¿ÉÄÜÒѾ­±»ÀûÓÃÈÆ¹ýÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£°²È«×êÑÐÔ±Mohesh Mohan°µÊ¾£¬£¬£¬£¬£¬£¬ £¬£¬DigilockerµÄOTPÖ°Äܲ»×ãÊÚȨ£¬£¬£¬£¬£¬£¬ £¬£¬µ¼Ö¹¥»÷ÕßÄܹ»Í¨¹ýÌá½»ÈκÎÓÐЧÓû§µÄ¾ßÌåÐÅÏ¢½øÐÐOTPÑéÖ¤²¢µÇ¼£¬£¬£¬£¬£¬£¬ £¬£¬Ò²¾ÍÊÇ˵¹¥»÷ÕßÖ»Ðè֪·Óû§Aadhaar ID»òÓйصÄÊÖ»úºÅÂë»òÓû§Ãû¼´¿É½Ó¼ûÈκÎDigilockerÕÊ»§¡£¡£¡£¡£¡£5ÔÂ10ÈÕ×êÑÐÈËÔ±ÏòCERT-In»ã±¨ÁË´Ë·ì϶£¬£¬£¬£¬£¬£¬ £¬£¬5ÔÂ28ÈÕÓ¡¶Èµ±¾ÖÒѽ«Æä½¨¸´¡£¡£¡£¡£¡£        


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/104459/breaking-news/digilocker-critical-falw.html


4.±¾Ì﹫˾Ôâµ½ÀÕË÷Èí¼þSNAKE¹¥»÷£¬£¬£¬£¬£¬£¬ £¬£¬ÆäÈÕ±¾ºÍÅ·ÖÞ·Ö¹«Ë¾Êܵ½Ó°Ïì


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


±¾Ì﹫˾ÓÚ±¾ÖÜÒ»·¢ÏÖ£¬£¬£¬£¬£¬£¬ £¬£¬ÆäÅ·ÖÞºÍÈÕ±¾µÄ·Ö¹«Ë¾Ôâµ½ÁËÀÕË÷²¡¶¾SNAKEµÄ¹¥»÷£¬£¬£¬£¬£¬£¬ £¬£¬²¢µ¼ÖÂITÍøÂçÎÞ·¨Õý³£ÔËÐС£¡£¡£¡£¡£¸Ã¹«Ë¾½²»°È˰µÊ¾£¬£¬£¬£¬£¬£¬ £¬£¬Õâ´Î¹¥»÷²¢Î´Ó°ÏìÈÕ±¾µÄ³ö²ú»ò¾­ÏúÉ̻£¬£¬£¬£¬£¬£¬ £¬£¬Ò²Ã»ÓÐÓ°ÏìÆä¿Í»§¡£¡£¡£¡£¡£×êÑÐÈËÔ±¶ÔÀÕË÷²¡¶¾Ñù±¾½øÐзÖÎöºó·¢ÏÖ£¬£¬£¬£¬£¬£¬ £¬£¬¸ÃÀÕË÷Èí¼þÊ×ÏÈ»áÊÔͼ½âÎömds.honda.comÓò£¬£¬£¬£¬£¬£¬ £¬£¬ÈôÊÇûÓн«Á¢¼´Í˳ö²¢²»¼ÓÃÜÈκÎÎļþ¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬ £¬£¬¸Ã¹«Ë¾°µÊ¾ÔÚµ÷²éÊÂÎñÔ­Òò£¬£¬£¬£¬£¬£¬ £¬£¬²¢»Ø¾øÐ¹Â©¸ü¶àϸ½Ú¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/honda-investigates-possible-ransomware-attack-networks-impacted/


5.º«¹úÐÅÓþЭ»á°µÊ¾£¬£¬£¬£¬£¬£¬ £¬£¬Ô¼90ÍòÕź«¹úÐÅÓþ¿¨ÐÅÏ¢ÔÚ°µÍøÐ¹Â¶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


º«¹úÐÅÓþЭ»á±¾ÖÜÒ»°µÊ¾£¬£¬£¬£¬£¬£¬ £¬£¬Ô¼ÓÐ90ÍòÕź«¹úÐÅÓþ¿¨ÐÅÏ¢Òѱ»Ð¹Â¶£¬£¬£¬£¬£¬£¬ £¬£¬²¢ÔÚ°µÍøÉϽøÐÐÊÛÂô¡£¡£¡£¡£¡£º«¹úÖÕÉó·¨Ôº×¢Ã÷£¬£¬£¬£¬£¬£¬ £¬£¬±»Ð¹Â¶µÄÐÅÓþ¿¨ÖÐԼĪÓÐ41ÍòÕÅÈÔÔÚʹÓÃÖУ¬£¬£¬£¬£¬£¬ £¬£¬Ð¹Â©µÄÐÅÏ¢Ô̺¬¿¨ºÅ¡¢ÓÐЧÆÚºÍÑéÖ¤Âë¡¢¿¨±³ÃæµÄÈýλÊý°²È«Â룬£¬£¬£¬£¬£¬ £¬£¬²¢²»Ô̺¬ÃÜÂë¡£¡£¡£¡£¡£º«¹úµ±¾ÖĿǰÉÐδŪÇåÕâЩÐÅÏ¢ÊÇÈôºÎй©µÄ£¬£¬£¬£¬£¬£¬ £¬£¬ÐÅÓþ¿¨ÒøÐÐÔò°µÊ¾»á½«ÐÅϢй¶ÎÊÌâ֪ͨÊÜÓ°ÏìµÄÓû§£¬£¬£¬£¬£¬£¬ £¬£¬²¢½¨ÒéËûÃǸü»»Ð¿¨¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://en.yna.co.kr/view/AEN20200608011200325?&web_view=true


6.¼ÓÄôó¹«Ë¾Fitness DepotÔâµ½Magecart¹¥»÷£¬£¬£¬£¬£¬£¬ £¬£¬Óû§Ö§¸¶ÐÅϢй¶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¼ÓÄôó»î¶¯Æ÷²Ä¹«Ë¾Fitness Depot°ä·¢£¬£¬£¬£¬£¬£¬ £¬£¬ÉϸöÔ¹«Ë¾µÄµçÉÌÆ½Ì¨Ôâµ½¹¥»÷£¬£¬£¬£¬£¬£¬ £¬£¬Æä¿Í»§µÄÓ×ÎÒÐÅÏ¢ºÍÖ§¸¶ÐÅϢй¶¡£¡£¡£¡£¡£Õâ´Îй¶ÐÅÏ¢Ô̺¬¿Í»§µÄÐÕÃû¡¢µØÖ·¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂëºÍÐÅÓþ¿¨ºÅ¡£¡£¡£¡£¡£Fitness Depot°µÊ¾£¬£¬£¬£¬£¬£¬ £¬£¬¸Ãй¶ÊÂÎñ¿É×·Òäµ½2020Äê2ÔÂ18ÈÕ£¬£¬£¬£¬£¬£¬ £¬£¬ºÚ¿Í½«¶ñÒâ´úÂë×¢ÈëÍøÕ¾£¬£¬£¬£¬£¬£¬ £¬£¬Ê¹µÃÓû§Ò»µ©±»³Á¶¨Ïòµ½´Ë±íµ¥¾Í»áÔÚ²»ÖªÇéµÄÇé¿öϱ»¸´ÔìÐÅÏ¢¡£¡£¡£¡£¡£×êÑÐÈËÔ±·ÖÎö£¬£¬£¬£¬£¬£¬ £¬£¬Õâ´Î¹¥»÷ºÜ¿ÉÄÜÊÇÀ´×ÔºÚ¿Í×éÖ¯Magecart£¬£¬£¬£¬£¬£¬ £¬£¬ÆäÏÈÈëÇÖÁ˸ù«Ë¾µÄµçÉÌÆ½Ì¨£¬£¬£¬£¬£¬£¬ £¬£¬²¢½«»ùÓÚJavaScriptµÄ¶ñÒâ´úÂë×¢ÈëÆä½áÕÊÒ³Ãæ£¬£¬£¬£¬£¬£¬ £¬£¬×îÖÕÖ¸±êÊÇÇÔÈ¡¸Ã¹«Ë¾¿Í»§ËùÌá½»µÄËùÓи¶¿î»òÓ×ÎÒÐÅÏ¢¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fitness-depot-hit-by-data-breach-after-isp-fails-to-activate-the-antivirus/