Rapid7Åû¶10¸öÕë¶ÔÆß¿îä¯ÀÀÆ÷ÀûÓõĵØÖ·À¸ºýŪ·ì϶£»£»£» £»£»Oracle 10Ô°²È«¸üн¨¸´402¸ö·ì϶

°ä²¼¹¦·ò 2020-10-22

1.Rapid7Åû¶10¸öÕë¶ÔÆß¿îä¯ÀÀÆ÷ÀûÓõĵØÖ·À¸ºýŪ·ì϶


1.jpg


ÍøÂ簲ȫ¹«Ë¾Rapid7Åû¶ÁË10¸öÕë¶ÔÆß¿îä¯ÀÀÆ÷ÀûÓõĵØÖ·À¸ºýŪ·ì϶¡£¡£¡£ ¡£¡£Õâ´ÎÅû¶µÄ·ì϶±ðÀëΪUCä¯ÀÀÆ÷ÖеÄCVE-2020-7363ºÍCVE-2020-7364¡¢Opera MiniºÍOpera TouchÖеÄCVE TBD-Opera¡¢Yandexä¯ÀÀÆ÷ÖеÄCVE-2020-7369¡¢Boltä¯ÀÀÆ÷ÖеÄCVE-2020-7370¡¢RITSä¯ÀÀÆ÷ÖеÄCVE-2020-7371ºÍApple SafariÖеÄCVE-2020-9987¡£¡£¡£ ¡£¡£¸ÃÎÊÌâÓÚ½ñÄêËêÊ×±»·¢ÏÖ£¬ £¬£¬£¬£¬£¬£¬£¬²¢ÓÚ8Ô»㱨¸øÔì×÷ÉÌ£¬ £¬£¬£¬£¬£¬£¬£¬Ä¿Ç°´óÐͳ§ÉÌÁ¢¼´½øÐÐÁ˽¨¸´£¬ £¬£¬£¬£¬£¬£¬£¬¶øÓ×Ðͳ§ÉÌÈÔÎÞÈËÀí²Ç¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/seven-mobile-browsers-vulnerable-to-address-bar-spoofing-attacks/


2.Group-IB³Æ£¬ £¬£¬£¬£¬£¬£¬£¬¶íÂÞ˹¾ü¹¤ÆóÒµÔøÂÅ´ÎÔâµ½³¯Ïʺڿ͹¥»÷


2.jpg


¾Ý±¨Â·£¬ £¬£¬£¬£¬£¬£¬£¬³¯ÏʺڿÍ×éÖ¯KimsukyÒѶԶíÂÞ˹¾ü¹¤ÆóÒµ½øÐÐÁËÂŴι¥»÷£¬ £¬£¬£¬£¬£¬£¬£¬ÒÔ»ñÈ¡¶íÂÞ˹µÄ¾üʺͼ¼Êõ°ÂÃØ¡£¡£¡£ ¡£¡£Æ¾¾ÝÍøÂ簲ȫ¹«Ë¾Group-IBÊý¾Ý£¬ £¬£¬£¬£¬£¬£¬£¬³¯ÏʺڿÍÓÚ2020Äê´º¼¾¶Ô¶íÂÞ˹¹ú·À»ú¹¹½øÐÐÁ˹¥»÷£¬ £¬£¬£¬£¬£¬£¬£¬ÊÔͼ´ÓÆäº½¿Õº½Ìì¡¢¹ú·À»ú¹¹ÒÔ¼°³ö²ú»ðÅÚÉ豸µÄ¹«Ë¾»ñÈ¡Êý¾Ý¡£¡£¡£ ¡£¡£µçÐÅÆµÂ·SecAtor»ã±¨³Æ£¬ £¬£¬£¬£¬£¬£¬£¬RostecÒ²ÔøÔâµ½¹ý¹¥»÷¡£¡£¡£ ¡£¡£´Ë±í£¬ £¬£¬£¬£¬£¬£¬£¬RostecµÄ×Ó¹«Ë¾RT-Inform»¹Ö¸³ö£¬ £¬£¬£¬£¬£¬£¬£¬´Ó4Ôµ½9ÔÂÕë¶Ô¹úÓÐÆóÒµµÄÍøÂç¹¥»÷ÊýÁ¿ÓÐËùÔö³¤¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2020/10/russian-military-companies-were.html


3.ÃÉÌØÀû¶û¹«½»ÏµÍ³ÔâRansomExx¹¥»÷£¬ £¬£¬£¬£¬£¬£¬£¬ÔÚÏßϵͳÊܵ½Ó°Ïì


3.jpg


10ÔÂ19ÈÕ£¬ £¬£¬£¬£¬£¬£¬£¬ÃÉÌØÀû¶ûµÄSTM¹«¹²½»Í¨ÏµÍ³Ôâµ½RansomExxÀÕË÷Èí¼þ¹¥£¬ £¬£¬£¬£¬£¬£¬£¬ÆäITϵͳ¡¢ÍøÕ¾ºÍ¿Í»§Ö§³ÖÊܵ½Ó°Ïì¡£¡£¡£ ¡£¡£¹ÌÈ»Õâ´ÎÖжϲ¢Ã»ÓÐÓ°Ïìµ½¹«¹²Æû³µ»òµØÌúϵͳµÄÔËÐУ¬ £¬£¬£¬£¬£¬£¬£¬µ«ÓÉÓÚSTMʹÓõÄÊÇÔÚÏßϵͳ£¬ £¬£¬£¬£¬£¬£¬£¬ÒÀÀµSTM°¤¼Ò°¤»§¸¨Öú·þÎñµÄ²Ð¼²ÈËÊܵ½ÁËÓ°Ïì¡£¡£¡£ ¡£¡£Ä¿Ç°STMÍøÕ¾ÒÀÈ»´¦ÓÚ̱»¾×´Ì¬£¬ £¬£¬£¬£¬£¬£¬£¬½Ó¼ûÕ߻ᱻ³Á¶¨Ïòµ½°ä²¼ÁËÓйع«¹²½»Í¨·þÎñºÍ¹¥»÷ÐÅÏ¢µÄwww.lastm.infoÍøÕ¾¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/montreals-stm-public-transport-system-hit-by-ransomware-attack/


4.Oracle°ä²¼10Ô²¹¶¡¸üУ¬ £¬£¬£¬£¬£¬£¬£¬½¨¸´¶à¸ö²úÆ·ÖÐ402¸ö·ì϶


4.jpg


Oracle°ä²¼2020Äê10Ô°²È«¸üУ¬ £¬£¬£¬£¬£¬£¬£¬½¨¸´Á˶à¿î²úÆ·ÖÐ402¸ö·ì϶¡£¡£¡£ ¡£¡£Õâ´Î½¨¸´µÄ½ÏΪÑϳÁµÄ·ì϶Ϊ´óÊý¾ÝÊôÐÔͼ·ÖÎöÖеķì϶£¨CVE-2019-0192£©¡¢Oracle RESTÊý¾Ý·þÎñÖзì϶£¨CVE-2017-7658£©¡¢Oracle TimesTenÄÚ´æÊý¾Ý¿âÖзì϶£¨CVE-2018-11058ºÍCVE-2017-5645£©¡¢OracleͨѶÀûÓ÷¨Ê½Öзì϶£¨CVE-2019-10173¡¢CVE-2020-10683ºÍCVE-2019-10173£©ºÍOracleͨѶÖзì϶£¨CVE-2020-10683¡¢CVE-2020-11973¡¢CVE-2020-2555¡¢ºÍCVE-2020-10683£©µÈ·ì϶¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.oracle.com/security-alerts/cpuoct2020.html


5.Adobe°ä²¼°²È«¸üУ¬ £¬£¬£¬£¬£¬£¬£¬½¨¸´Æä¶à¿î²úÆ·ÖеÄ20¸ö·ì϶


5.jpg


Adobe°ä²¼°²È«¸üУ¬ £¬£¬£¬£¬£¬£¬£¬×ܼƽ¨¸´ÁË20¸ö·ì϶£¬ £¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬18¸ö¿Éµ¼ÖÂËÁÒâ´úÂëÖ´Ðеķì϶¡¢1¸öÌáȨ·ì϶ºÍ1¸öXSS·ì϶¡£¡£¡£ ¡£¡£Õâ´Î½¨¸´µÄÈí¼þ²úÆ·Ô̺¬Adobe Creative Cloud×ÀÃæÀûÓ÷¨Ê½¡¢Adobe InDesign¡¢Adobe Media Encoder¡¢Adobe Premiere Pro¡¢Adobe Photoshop¡¢Adobe After Effects¡¢Adobe Animate¡¢Adobe Dreamweaver¡¢Adobe IllustratorºÍMarketo¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-fixes-18-critical-bugs-affecting-its-windows-macos-apps/


6.Nefilimй¶LuxotticaÈËʺͲÆÕþ²¿ÃÅÃô¸ÐÊý¾Ý


6.jpg


ÀÕË÷Èí¼þ×éÖ¯Nefilimй¶Òâ´óÀûÑÛ¾µ¹«Ë¾LuxotticaÈËʺͲÆÕþ²¿ÃŵÄÃô¸ÐÊý¾Ý¡£¡£¡£ ¡£¡£Luxottica Group SpAÊÇÒ»¼ÒÈ«Çò×î´óµÄÑÛ¾µ¹«Ë¾£¬ £¬£¬£¬£¬£¬£¬£¬ÓÚ9ÔÂ18ÈÕÔâµ½ÁËÍøÂç¹¥»÷£¬ £¬£¬£¬£¬£¬£¬£¬µ¼Ö¸ù«Ë¾µÄÄ³Ð©ÍøÕ¾Ì±»¾¡£¡£¡£ ¡£¡£°²È«¹«Ë¾Bad packet´§Ä¦ÊÇÓÉÓڸù«Ë¾Ê¹ÓÃÁËCitrixµÄADX½ÚÔìÆ÷É豸ʹÆäÒ×Êܵ½CVE-2019-19781·ì϶¹¥»÷¡£¡£¡£ ¡£¡£×êÑÐÈËÔ±Odysseus·¢ÏÖNefilim¹«¿ªÁË´óÁ¿Óë¸Ã¹«Ë¾ÈËʺͲÆÕþ²¿ÃÅÓйصÄÎļþ£¬ £¬£¬£¬£¬£¬£¬£¬Ô̺¬ÕÐÆ¸Á÷³Ì¡¢×¨Òµ¼òÀú¡¢¼¯ÍÅÈËÁ¦×ÊÔ´²¿ÃÅÄÚ²¿½á¹¹¡¢²ÆÕþÔ¤Ëã¡¢Êг¡Ô¤²â·ÖÎöºÍÆäËûÃô¸ÐÊý¾Ý¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/109778/data-breach/luxottica-data-leak-ransomware.html