LumuÐû²¼2020Äê¶ÈÀÕË÷Èí¼þÓ°ÏìÆÊÎöµÄÐÅϢͼ£»£»£»MDSec·¢Ã÷Windows Update¿É±»ÓÃÀ´Ö´ÐжñÒâÎļþ

Ðû²¼Ê±¼ä 2020-10-13
1.LumuÐû²¼2020Äê¶ÈÀÕË÷Èí¼þÓ°ÏìÆÊÎöµÄÐÅϢͼ


2.png


LumuÐû²¼ÁËÒ»ÕÅÐÅϢͼ£¬ £¬ £¬£¬ £¬Ïêϸ˵Ã÷ÎúÀÕË÷Èí¼þµÄ±¾Ç®ºÍ¹æÄ££¬ £¬ £¬£¬ £¬ÒÔ×ÊÖúÆóҵȨºâËûÃǵÄÊܺ¦Î£º¦¡£¡£¡£¾ÝÆÊÎö£¬ £¬ £¬£¬ £¬½ñÄêÈ«ÇòÀÕË÷Èí¼þµÄ±¾Ç®Îª200ÒÚÃÀÔª£¬ £¬ £¬£¬ £¬Æ½¾ùÿ´ÎµÄ¹¥»÷±¾Ç®Áè¼Ý400ÍòÃÀÔª£¬ £¬ £¬£¬ £¬²¢ÇÒÓÐ36£¥µÄÊܺ¦ÕßÖ§¸¶ÁËÊê½ð£¬ £¬ £¬£¬ £¬ÆäÖÐ17£¥»¹Ã»ÄÜÍì»ØËûÃǵÄÊý¾Ý¡£¡£¡£±ðµÄ£¬ £¬ £¬£¬ £¬ÔÚ±±ÃÀÓÐ69%µÄ¹«Ë¾±¨¸æ³ÆÊܵ½ÁËÀÕË÷Èí¼þµÄÓ°Ï죬 £¬ £¬£¬ £¬¶øÔÚÅ·ÖÞÓÐ57%¡£¡£¡£Ïà½Ï¶øÑÔ£¬ £¬ £¬£¬ £¬±±ÃÀµÄÕþ¸®»ú¹¹Êܵ½µÄ¹¥»÷×îΪÑÏÖØ£¬ £¬ £¬£¬ £¬Æä´ÎÊÇÖÆÔìÒµºÍÐÞ½¨Òµ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://lumu.io/resources/2020-ransomware-flashcard/


2.BetterCloudÐû²¼2020Äê¶ÈSaaSOps״̬ÆÊÎö±¨¸æ


2.png


BetterCloudÐû²¼ÁË2020Äê¶ÈSaaSOps״̬ÆÊÎö±¨¸æ£¬ £¬ £¬£¬ £¬ÏÔʾÁËSaaS½ÓÄÉÂʵÄÉÏÉýÒý·¢µÄÈËÃǶÔÔËÓªÖØ´óÐÔºÍΣº¦µÄµ£ÐÄ¡£¡£¡£×Ô2015ÄêÒÔÀ´£¬ £¬ £¬£¬ £¬ÊÜÐÅÈεÄSaaSÓ¦ÓóÌÐòµÄÊýÄ¿ÔöÌíÁËÊ®±¶£¬ £¬ £¬£¬ £¬Ô¤¼Æµ½2025Ä꣬ £¬ £¬£¬ £¬½«ÓÐ85£¥µÄÓªÒµÓ¦ÓóÌÐò»ùÓÚSaaS¡£¡£¡£Ëæ×ÅSaaSµÄÔöÌí£¬ £¬ £¬£¬ £¬49%µÄÊÜ·ÃÕßÏàÐÅËûÃÇÓÐÄÜÁ¦Ê¶±ðºÍ¼à¿Ø¹«Ë¾ÍøÂçÉÏδ¾­Åú×¼µÄSaaSʹÓÃÇéÐΣ¬ £¬ £¬£¬ £¬µ«ÈÔÓÐ76%µÄÈËÒÔΪδ¾­Åú×¼µÄÓ¦Óñ£´æÇ徲Σº¦¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/10/12/saas-adoption-risk/


3.MDSecÑо¿Ö°Ô±·¢Ã÷Windows Update¿É±»ÓÃÀ´Ö´ÐжñÒâÎļþ


3.png


MDSecÑо¿Ö°Ô±David Middlehurst·¢Ã÷£¬ £¬ £¬£¬ £¬Windows Update¿É±»ÓÃÀ´Ö´ÐжñÒâÎļþ¡£¡£¡£WSUS/Windows Update¿Í»§¶Ë£¨wuauclt£©ÊÇλÓÚ£¥windir£¥\ system32\µÄÓ¦ÓóÌÐò£¬ £¬ £¬£¬ £¬¿ÉʹÓû§´ÓÏÂÁîÐпØÖÆWindows Update AgentµÄijЩ¹¦Ð§¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓÃÏÂÁîÐÐʹÓÃÌØÖÆµÄDLL¼ÓÔØwuauclt£¬ £¬ £¬£¬ £¬´Ó¶øÔÚWindows 10ϵͳÉÏÖ´ÐжñÒâ´úÂë¡£¡£¡£Middlehurst·¢Ã÷wuaucltÒ²¿ÉÒÔÓÃ×÷LoLBin£¬ £¬ £¬£¬ £¬²¢ÔÚÒ°ÍâÕÒµ½ÁËÆäÏà¹ØµÄÑù±¾¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/windows-update-can-be-abused-to-execute-malicious-files/


4.unit42Ñо¿Ö°Ô±Åû¶LinuxÄÚºËÖеÄÌáȨÎó²î£¨CVE-2020-14386£©


4.png


unit42Ñо¿Ö°Ô±ÔÚÉóºËLinuxÄÚºËÖеÄÊý¾Ý°üÌ×½Ó×ÖÔ´´úÂëʱ£¬ £¬ £¬£¬ £¬·¢Ã÷ÁËLinuxÄÚºËÖеÄÌáȨÎó²î£¨CVE-2020-14386£©¡£¡£¡£¸ÃÎó²îÊÇÒ»¸öÄÚ´æËð»µÎó²î£¬ £¬ £¬£¬ £¬¿ÉÓÃÓÚ½«LinuxϵͳÉϵķÇrootÓû§µÄȨÏÞÉý¼¶ÎªrootÓû§¡£¡£¡£Palo Alto Networks Cortex XDR¿Í»§¿ÉÒÔͨ¹ýÁ¬ÏµÊ¹ÓÃÐÐΪÍþв·À»¤£¨BTP£©ºÍÍâµØÌØÈ¨Éý¼¶±£»£»£»¤¹¦Ð§À´Ô¤·À¸ÃÎó²î¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/cve-2020-14386/


5.TelsyÅû¶Õë¶Ôº½¿ÕÐÐÒµµÄSPACE RACEÉç»á¹¤³Ì¹¥»÷


5.png


2020Äê5Ô³õ£¬ £¬ £¬£¬ £¬TelsyÆÊÎöÁËÕë¶Ôº½¿ÕÐÐÒµµÄSPACE RACEÉç»á¹¤³Ì¹¥»÷¡£¡£¡£ÕâЩ¹¥»÷ͨ¹ýÉç½»ÍøÂçLinkedIn¾ÙÐУ¬ £¬ £¬£¬ £¬Õë¶Ô¶Ôº½¿Õº½ÌìºÍº½¿Õµç×ÓÁìÓòµÄСÎÒ˽¼ÒÌᳫÉç»á¹¤³Ì¹¥»÷¡£¡£¡£ºÚ¿ÍÔÚLinkedInαÔìÐéÄâÉí·Ý£¬ £¬ £¬£¬ £¬Ã°³äÎÀÐÇÓ°Ïñ¹«Ë¾µÄHRÕÐÆ¸Ö°Ô±£¬ £¬ £¬£¬ £¬²¢Í¨¹ýÄÚ²¿Ë½ÈËÐÂÎÅÓëÄ¿µÄÖ°Ô±ÁªÏµ£¬ £¬ £¬£¬ £¬ÓÕʹËûÃÇÏÂÔØ°üÀ¨ÓйؼÙÊÂÇé¼ÙÆÚÐÅÏ¢µÄ¶ñÒ⸽¼þ¡£¡£¡£Ñо¿Ö°Ô±ÒÔΪ¸ÃÐж¯ÓëºÚ¿Í×éÖ¯MuddywaterÓйء£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.telsy.com/operation-space-race-reaching-the-stars-through-professional-social-networks/


6.ÃÀ¹úµÄÀÎÓüÒòÊý¾Ý¿âÉèÖùýʧй¶Çô·¸Óë״ʦ¼äͨ»°µÄÄÚÈÝ


6.jpg


λÓÚÃÀ¹úʥ·Ò×˹µÄÀÎÓüÒòÊý¾Ý¿âÉèÖùýʧй¶Çô·¸Óë״ʦ¼äͨ»°µÄÄÚÈÝ¡£¡£¡£Ñо¿Ö°Ô±Bob Diachenko·¢Ã÷£¬ £¬ £¬£¬ £¬ÖÁÉÙ´Ó4ÔÂ×îÏÈ£¬ £¬ £¬£¬ £¬ÀÎÓüµÄÒ»¸öЧÀÍÆ÷±ã̻¶ÔÚ¹«ÍøÉÏ¡£¡£¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨ä¯ÀÀºÍËÑË÷ͨ»°¼Í¼¡¢Çô·¸ÓëÆäÅóÙ­¡¢¼ÒÈ˺Í״ʦ֮¼äµÄͨ»°¼Í¼¡¢ºô½ÐÕߵĵ绰ºÅÂë¡¢¼à·¸Ãû³ÆÒÔ¼°Í¨»°Ê±¼ä¡£¡£¡£¸ÃÀÎÓüÈ·ÈÏÁË´ËÊÂÎñ£¬ £¬ £¬£¬ £¬²¢ÌåÏÖÊÇÓÉÓÚµÚÈý·½¹©Ó¦É̲»Ð¡ÐÄɾ³ýÁËÃÜÂ룬 £¬ £¬£¬ £¬´Ó¶øµ¼ÖÂЧÀÍÆ÷̻¶¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://techcrunch.com/2020/10/10/prison-visitation-homewav-leak/