Google°²È«¸üн¨¸´ChromeÖÐÒѱ»ÀûÓõÄ0day£»£»£»£»£»£»FireEyeÅû¶UNC1945ÀûÓÃSolarisÖÐ0dayÈëÇÖ

°ä²¼¹¦·ò 2020-11-04
1.Google°ä²¼°²È«¸üУ¬ £¬ £¬£¬£¬½¨¸´ChromeÖÐÒѱ»ÀûÓõÄ0day


1.jpg


Google°ä²¼°²È«¸üУ¬ £¬ £¬£¬£¬½¨¸´ChromeÖеÄ10¸ö·ì϶£¬ £¬ £¬£¬£¬ÆäÖÐÔ̺¬Ò»¸öÔÚÒ°±íÒѱ»»ý¼«ÀûÓõÄ0day¡£¡£ ¡£¡£¡£¸Ã0day±»×·×ÙΪCVE-2020-16009£¬ £¬ £¬£¬£¬ÓÉGoogleµÄÍþв·ÖÎöÓ××飨TAG£©·¢ÏÖ£¬ £¬ £¬£¬£¬µ«¸ÃÓ××鲢δ¹«¿ª¹ØÓڸ÷ì϶µÄ¾ßÌåÐÅÏ¢ÒÔ¼°ÀûÓ㬠£¬ £¬£¬£¬½ö°µÊ¾¸Ã·ì϶λÓÚ´¦ÖÃJavaScript´úÂëµÄChrome×é¼þV8ÖС£¡£ ¡£¡£¡£²»¾Ãºó£¬ £¬ £¬£¬£¬GoogleÓÖ°ä²¼ÁËAndroid°æChromeÖеÄ0dayµÄ²¹¶¡·¨Ê½£¬ £¬ £¬£¬£¬¸Ã·ì϶±»×·×ÙΪCVE-2020-16010£¬ £¬ £¬£¬£¬ÎªChrome for AndroidÓû§½çÃæ£¨UI£©×é¼þÖеĶѻº³åÇøÒç¶Âí½Å¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/google-patches-second-chrome-zero-day-in-two-weeks/


2.FireEyeÅû¶UNC1945ÀûÓÃSolarisÖÐ0dayÈëÇֵĹ¥»÷ÊÂÎñ


2.jpg


FireEyeµÄMandiantÅû¶ºÚ¿Í×éÖ¯UNC1945ÀûÓÃOracle Solaris²Ù×÷ϵͳÖеÄ0dayÈëÇÔìóÒµÍøÂçµÄ¹¥»÷ÊÂÎñ¡£¡£ ¡£¡£¡£¸Ã·ì϶±»×·×ÙΪCVE-2020-14871£¬ £¬ £¬£¬£¬Î»ÓÚSolaris²åÈëÉí·ÝÑé֤ģ¿£¿£¿£¿£¿é(PAM)£¬ £¬ £¬£¬£¬¸Ã·ì϶ʹUNC1945Äܹ»ÈƹýÉí·ÝÑéÖ¤¹ý³Ì£¬ £¬ £¬£¬£¬²¢ÔÚ¶³öµÄSolaris·þÎñÆ÷ÉÏ×°ÖÃSLAPSTICKµÄºóÃÅ¡£¡£ ¡£¡£¡£Mandiant³ÆºÚ¿ÍÒÔ¶ûºóÃÅΪÇÐÈëµã£¬ £¬ £¬£¬£¬ÔÚ¹«Ë¾ÍøÂçÄÚ²¿½øÐпúËÅ£¬ £¬ £¬£¬£¬²¢ºáÏòÒÆ¶¯µ½ÆäËûϵͳ¡£¡£ ¡£¡£¡£´Ë±í£¬ £¬ £¬£¬£¬MandiantÒÔΪºÚ¿Í¿ÉÄÜÊÇÔÚ°µÍøÉÏÒÔ3000ÃÀÔªµÄ¼ÛÖµ²É°ìµÄ¸Ã·ì϶¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hacker-group-uses-solaris-zero-day-to-breach-corporate-networks/


3.Ó¢¹úFoI³ÆBBC¾ùÔÈÿÌìÊÕµ½³¬¹ý25w·ÝÀ¬»øÓʼþ


3.jpg


ƾ¾ÝÐÅÏ¢×ÔÓÉ(FoI£©±¨Â·£¬ £¬ £¬£¬£¬Ó¢¹ú¹ã²¥¹«Ë¾(BBC)ÿÌìÃæ¶Ô³¬¹ý25Íò·ÝÀ¬»øÓʼþµÄ¹¥»÷¡£¡£ ¡£¡£¡£Êý¾ÝÏÔʾ£¬ £¬ £¬£¬£¬BBC¾ùÔÈÿ¸öÔÂÊÕµ½6704188·âÚ¿Æ­»òÀ¬»øÓʼþ£¬ £¬ £¬£¬£¬ÒÔ¼°18662´Î¶ñÒâÈí¼þ¹¥»÷£¬ £¬ £¬£¬£¬È粡¶¾¡¢ÀÕË÷Èí¼þºÍ¼äµýÈí¼þ¡£¡£ ¡£¡£¡£ÔÚ2020Äê1ÔÂÖÁ8ÔÂÆÚ¼ä£¬ £¬ £¬£¬£¬×ܹ²×èÖ¹ÁË51898393·âÊÜϰȾµÄµç×ÓÓʼþ¡£¡£ ¡£¡£¡£ÆäÖÐ7Ô·ÝÔâµ½¹¥»÷´ÎÊý×î¶à£¬ £¬ £¬£¬£¬BBCµ±ÔÂÊÕµ½ÁË6787635À¬»øÓʼþºÍ13592´Î¶ñÒâÈí¼þ¹¥»÷¡£¡£ ¡£¡£¡£Æä´ÎÊÇ3Ô£¬ £¬ £¬£¬£¬ÔÚCOVID-19³õ´ÎÏ®»÷Ó¢¹úʱ£¬ £¬ £¬£¬£¬ÊÕµ½ÁË6768632·âÀ¬»øÓʼþºÍ14089´Î¶ñÒâÈí¼þ¹¥»÷¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/bbc-experiences-malicious-email/


4.ÀÕË÷Èí¼þ×éÖ¯Maze°ä·¢Í˳ö£¬ £¬ £¬£¬£¬²¢½«²»ÔÙй¶¹«Ë¾Êý¾Ý


4.png


ÀÕË÷Èí¼þ×éÖ¯MazeÓÚ2020Äê11ÔÂ2ÈÕ°ä·¢ÕýʽÍ˳ö£¬ £¬ £¬£¬£¬²¢½«²»ÔÙÔÚÆäÍøÕ¾ÉÏй©Ð¹«Ë¾µÄÊý¾Ý¡£¡£ ¡£¡£¡£ÔçÔÚ9ÔÂÖÐÑ®£¬ £¬ £¬£¬£¬Maze¾ÍÖÕ³¡Á˶ÔÐÂÊܺ¦ÕߵĹ¥»÷£¬ £¬ £¬£¬£¬²¢ËãÕÊÁËÆäÊý¾ÝÐ¹Â©ÍøÕ¾¡£¡£ ¡£¡£¡£Ö®ºó£¬ £¬ £¬£¬£¬Õýʽ°ä²¼ÉêÃ÷£¬ £¬ £¬£¬£¬³ÆMazeÍŶÓÏîÄ¿Õýʽ¹Ø¹Ø£¬ £¬ £¬£¬£¬ËùÓÐʹÓøÃÃû³ÆµÄÀÕË÷Èí¼þ¹¥»÷¶¼ÊÇȦÌס£¡£ ¡£¡£¡£µ±±»Îʼ°ÊÇ·ñ»áÏñTeslaCryptºÍShadeÄÇÑùÑ¡ÔñÔÚÍ˳öʱ¿ªÊÍÖ÷½âÃÜÃÜԿʱ£¬ £¬ £¬£¬£¬Maze²¢Î´½øÐлش𡣡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/maze-ransomware-shuts-down-operations-denies-creating-cartel/


5.±£ÏÕ¹«Ë¾FolksamÊý¾Ýй¶£¬ £¬ £¬£¬£¬Ó°ÏìÔ¼100ÍòÈðµä¾ÓÃñ


5.png


Èðµä×î´óµÄ±£ÏÕ¹«Ë¾Ö®Ò»Folksam¾­¹ýÄÚ²¿ÉóºËºó·¢ÏÖÁËÊý¾Ýй¶ÊÂÎñ£¬ £¬ £¬£¬£¬Ó°ÏìÔ¼100ÍòÈðµä¾ÓÃñ¡£¡£ ¡£¡£¡£Õâ´Î½Ó¹Üµ½Óû§Ó×ÎÒÊý¾ÝµÄ¹«Ë¾ÓÐFacebook¡¢¹È¸è¡¢Î¢Èí¡¢ÁìÓ¢ºÍAdobe£¬ £¬ £¬£¬£¬±¾ÒâÊÇ·ÖÎöµÇ¼Óû§ºÍÆäËû½Ó¼ûÕßÔÚfolksam.seÉÏËÑË÷µÄÐÅÏ¢£¬ £¬ £¬£¬£¬À´Îª¿Í»§Ìṩ¶¨Ôì·þÎñ¡£¡£ ¡£¡£¡£µ«Folksam¹²ÏíµÄÊý¾ÝÔ̺¬¸÷ÀàÃô¸ÐÐÅÏ¢£¬ £¬ £¬£¬£¬ÈçÉç»á°²È«ºÅÂë»òÓ×ÎҲɰìµÄ¹¤»á»ò»³Ôб£ÏÕ¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾³ÆÔÚ·¢ÏÖй¶ÊÂÎñºó£¬ £¬ £¬£¬£¬±ãÁ¢¼´ÖÕ³¡ÁËÓëºÏ×÷ͬ°é¹²ÏíÃô¸ÐÐÅÏ¢£¬ £¬ £¬£¬£¬²¢ÒªÇóÊÕµ½ÐÅÏ¢µÄ¹«Ë¾É¾³ýÕâЩÐÅÏ¢¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/folksam-data-breach-leaks-info-of-1m-swedes-to-google-facebook-more/


6.SonicWall°ä²¼µÚÈý¼¾¶ÈÍøÂçÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨


6.png


SonicWall°ä²¼µÚÈý¼¾¶ÈÍøÂçÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£ ¡£¡£¡£»ã±¨ÏÔʾ£¬ £¬ £¬£¬£¬È«ÇòÁìÓòÄÚ¾ùÔÈÿÌì×èÖ¹³¬¹ý2800Íò´Î¶ñÒâÈí¼þ¹¥»÷£¬ £¬ £¬£¬£¬ÔÚ2020ÄêµÄǰÈý¸ö¼¾¶ÈÖУ¬ £¬ £¬£¬£¬×ܹ²²úÉúÁË44ÒڴζñÒâÈí¼þ¹¥»÷£¨Í¬±È½µÂä39£¥£©ºÍ1.997ÒÚ¸öÀÕË÷Èí¼þ¹¥»÷£¨Í¬±ÈÔö³¤40£¥£©¡£¡£ ¡£¡£¡£´Ë±í£¬ £¬ £¬£¬£¬SonicWall»¹·¢ÏÖÈëÇÖ³¢ÊÔ´ÎÊýÔö³¤ÁË19£¥£¨3.5ÍòÒÚ£©¡¢ÎïÁªÍø¶ñÒâÈí¼þÔö³¤30£¥£¨3240Íò£©¡¢¼ÓÃÜÍþвÔö³¤3£¥£¨320Íò£©£¬ £¬ £¬£¬£¬ÒÔ¼°¼ÓÃܽٳÖÔö³¤2£¥£¨5790Íò£©¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.sonicwall.com/en-us/2020/10/q3-cyber-threat-intelligence-details-a-september-to-remember/