ZoomµÄWindows¿Í»§¶ËÖÐ0day£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâ´úÂ룻£»£»£»£»£»£»VMware½¨¸´VeloCloudÖÐSQL×¢Èë·ì϶
°ä²¼¹¦·ò 2020-07-101.ACROSÅû¶ZoomµÄWindows¿Í»§¶ËÖÐ0day£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâ´úÂë
ÍøÂ簲ȫ¹«Ë¾ACROS SecurityÓÚ7ÔÂ9ÈÕÅû¶ÁËZoomµÄWindows¿Í»§¶ËÖÐ0day£¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶»áÓ°ÏìÔËÐÐÔھɰæWindows OS£¨ÀýÈçWindows 7ºÍWindows Server 2008 R2»ò¸üÔç°æ±¾£©ÉϵÄZoom¿Í»§¶Ë¡£¡£¡£¡£¡£¡£¡£ACROS CEO Mitja Kolsek°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶Äܹ»Ê¹Ô¶³Ì¹¥»÷Õßͨ¹ýÈÃÓû§Ö´ÐÐijЩ²Ù×÷£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈç´ò¿ªÎĵµÎļþ£¬£¬£¬£¬£¬£¬£¬£¬ÔÚÊܺ¦ÕßÍÆËã»úÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£ÔÚÕû¸ö¹¥»÷¹ý³ÌÖУ¬£¬£¬£¬£¬£¬£¬£¬ÏµÍ³¶¼²»»áÏòÓû§·¢³ö°²È«ÖҸ档¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬ZoomÔÚ×êÑн¨¸´¸Ã·ì϶¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/zoom-working-on-patching-zero-day-disclosed-in-its-windows-client/#ftag=RSSbaffb68
2.VMware°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´VeloCloudÖÐSQL×¢Èë·ì϶
VMware°ä²¼Á˰²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÒÔ½¨¸´VeloCloudÖеķì϶£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓô˷ì϶À´»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ·ì϶±»×·×ÙΪCVE-2020-3973£¬£¬£¬£¬£¬£¬£¬£¬ÎªSQL×¢Èë·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÆäÓ°ÏìÁËVeloCloudµÄVMware SD-WAN¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶´æÔÚµÄÔÓÉÓÚVeloCloud OrchestratorûÓнøÐÐÏàÒ˵ÄÊäÈëÑéÖ¤£¬£¬£¬£¬£¬£¬£¬£¬Õâ»áµ¼ÖÂSQLäע£¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ8.5¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2020/07/08/vmware-releases-security-update-velocloud
3.ºÚ¿Í½Ù³Ö΢ÈíAzureÍйܵÄ240¶à¸ö×ÓÓòÃû´«²¼¶ñÒâÈí¼þ
ºÚ¿Í½Ù³ÖÁË240¶à¸öÍйÜÔÚ΢ÈíAzureµÄ×ÓÓòÃû£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ´«²¼¶ñÒâÈí¼þºÍ¶ñÒâChromeÀ©´ó·¨Ê½µÈÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£Õâ´Î±»½Ù³ÖµÄÍøÕ¾Ô̺¬»ªÄÉÐֵܡ¢½Ì¿ÆÎÄ×éÖ¯¡¢¶«Ö¥¡¢Ê©ÀÖ¡¢¸ÇµÙͼƬÉç¡¢ºìÊ®×ֻᡢÎÖ¶ûÎÖ¡¢»ôÄáΤ¶û¡¢ÏÄÍþÒĺ½¿Õ¹«Ë¾¡¢Ç峺Ƶ·¡¢Î÷ÃÅ×Ó¡¢Å·Ìؿˡ¢Arm¡¢3MºÍNHSµÈ¾¡È˽ÔÖªµÄ¹«Ë¾¡£¡£¡£¡£¡£¡£¡£·ÖÎö¹«Ë¾Victory MediumÊ×´´ÈËEdwards°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬ÌáÒéÕâ´Î¹¥»÷µÄºÚ¿Í×éÖ¯¸ÃÓ××é»îÔ¾ÁËÎåÄ꣬£¬£¬£¬£¬£¬£¬£¬Æ¾¾ÝËûµÄ·ÖÎö£¬£¬£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯µÃµ½Á˹ú¼Ê·¸×ïÍÅ»ïµÄÖ§³Ö£¬£¬£¬£¬£¬£¬£¬£¬±ÈÔ¤ÆÚÒª¸´Ôӵöࡣ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/microsoft-azure-hosted-subdomains-hacked-with-malware/
4.΢ÈíÖÒ¸æÀûÓöñÒâOAuthÀûÓõÄOffice 365ÍøÂç´¹µö»î¶¯
΢ÈíÖÒ¸æËµ£¬£¬£¬£¬£¬£¬£¬£¬Ëæ×ÅÔ¶³Ì¹¤×÷µÄÍÆ¶¯£¬£¬£¬£¬£¬£¬£¬£¬¿Í»§³ýÁËÒª°ÑÎÈ´«Í³µÄƾ֤͵ÇԺ͵ç×ÓÓʼþÍøÂç´¹µö¹¥»÷Ö®±í£¬£¬£¬£¬£¬£¬£¬£¬»¹Ãæ¶ÔÆäËû°²È«Íþв£¬£¬£¬£¬£¬£¬£¬£¬ÀýÕâÑù¿ÉÍøÂç´¹µö£¨Consent phishing£©¡£¡£¡£¡£¡£¡£¡£Consent phishingÊÇÒ»ÖÖ»ùÓÚÀûÓ÷¨Ê½µÄ¹¥»÷µÄ±äÌ壬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚΪ¶ñÒâOffice 365 OAuthÀûÓ÷¨Ê½Ìṩ¶ÔÊܺ¦ÕßOffice 365ÕÊ»§µÄ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£¹¥»÷³É¹¦ºó£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»½Ó¼ûÊܺ¦ÕßµÄÓʼþ¡¢Îļþ¡¢ÁªÏµÈË¡¢±ã¼ã¡¢ÅäÖÃÎļþÒÔ¼°´æ´¢ÔÚ¹«Ë¾´æ´¢ÏµÍ³SharePointºÍOneDrive for BusinessÔÆÖеÄÃô¸ÐÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-warns-of-office-365-phishing-via-malicious-oauth-apps/
5.½ü3Ä꣬£¬£¬£¬£¬£¬£¬£¬KeeperÍÅ»ïÒÑÌáÒéÕë¶ÔÈ«Çò570¶àÍøÕ¾µÄ¹¥»÷»î¶¯
Gemini Advisory°ä²¼Á˶ԺڿÍ×éÖ¯Keeper MagecartµÄ·ÖÎö»ã±¨£¬£¬£¬£¬£¬£¬£¬£¬·¢ÏÔìä×Ô2017Äê4ÔÂ1ÈÕÒÔÀ´£¬£¬£¬£¬£¬£¬£¬£¬¶ÔÈ«Çò55¸ö¹ú¶ÈÖеÄ570¶àÔÚÏßÉ̳ÇÌáÒéÁËMagecart¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£×êÑз¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬keeperÊÇÓÉ64¸öÓÃÓÚ·Ö·¢¶ñÒâÈí¼þµÄ¹¥»÷ÓòºÍ73¸öÓÃÓڽӹܱ»µÁÊý¾ÝµÄÉøÈëÓò×é³É¡£¡£¡£¡£¡£¡£¡£´óÎÞÊýÊܺ¦ÍøÕ¾¶¼ÍйÜÔÚÃÀ¹ú£¬£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊÇÓ¢¹ú¡¢ºÉÀ¼¡¢·¨¹ú¡¢Ó¡¶ÈµÈ¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯¸ÃżȻ»¹»áʹÓù«¹²ºÍ×Ô½ç˵»ìºÏµÄ²½Ö裬£¬£¬£¬£¬£¬£¬£¬ÒÔʹÆä¶ñÒâ¾ç±¾¸üÄѱ»¼ì²âµ½¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/07/08/magecart-group-8/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+HelpNetSecurity+%28Help+Net+Security%29
6.»ã±¨ÏÔʾ£¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°ÓÐ150ÒÚInternet·þÎñƾ֤ÔÚ°µÍøÏúÊÛ
Digital ShadowsµÄÒ»·Ý»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°ÓÉÓÚ10Íò´ÎÊý¾Ýй¶ÊÂÎñµ¼ÖµÄ150ÒÚ¸ö±»µÁInternet·þÎñƾ֤ÔÚ°µÍøÏúÊÛ¡£¡£¡£¡£¡£¡£¡£ÕâЩƾ֤ÔÚ½Ó¼ûȨÏ޺ͼÛÖµÉϸ÷²»Ò»Ñù£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬´ÓÒøÐÐÕÊ»§£¨Õ¼ËùÓÐÍ´´¦µÄ25£¥£©µ½ÊÓÆµºÍÒôÀÖÁ÷·þÎñµÈËùÓÐÄÚÈݵÄÓû§ÃûºÍÃÜÂë¡£¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬£¬£¬ÒøÐÐºÍÆäËû½ðÈÚÕË»§µÄƾ֤ÊÇ×îÊÜ»¶ÓµÄ£¬£¬£¬£¬£¬£¬£¬£¬Ò²ÊÇ×î°º¹óµÄ£¬£¬£¬£¬£¬£¬£¬£¬¾ùÔÈÊÛ¼ÛΪ70.91ÃÀÔª¡£¡£¡£¡£¡£¡£¡£Æä´ÎÊÇÓÃÓÚ½Ó¼û·À²¡¶¾Èí¼þµÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬¾ùÔÈÊÛ¼ÛΪ21.67ÃÀÔª¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/15-billion-credentials-currently-up-for-grabs-on-hacker-forums/157247/


¾©¹«Íø°²±¸11010802024551ºÅ