GoogleÇå¾²¸üÐÂÐÞ¸´ChromeÖÐÒѱ»Ê¹ÓõÄ0day £» £»£»£»£»FireEyeÅû¶UNC1945ʹÓÃSolarisÖÐ0dayÈëÇÖ

Ðû²¼Ê±¼ä 2020-11-04
1.GoogleÐû²¼Çå¾²¸üУ¬£¬£¬£¬ £¬ £¬ÐÞ¸´ChromeÖÐÒѱ»Ê¹ÓõÄ0day


1.jpg


GoogleÐû²¼Çå¾²¸üУ¬£¬£¬£¬ £¬ £¬ÐÞ¸´ChromeÖеÄ10¸öÎó²î£¬£¬£¬£¬ £¬ £¬ÆäÖаüÀ¨Ò»¸öÔÚÒ°ÍâÒѱ»Æð¾¢Ê¹ÓõÄ0day¡£¡£¡£¡£ ¡£¸Ã0day±»×·×ÙΪCVE-2020-16009£¬£¬£¬£¬ £¬ £¬ÓÉGoogleµÄÍþвÆÊÎöС×飨TAG£©·¢Ã÷£¬£¬£¬£¬ £¬ £¬µ«¸ÃС×鲢δ¹ûÕæ¹ØÓÚ¸ÃÎó²îµÄÏêϸÐÅÏ¢ÒÔ¼°Ê¹Ó㬣¬£¬£¬ £¬ £¬½öÌåÏÖ¸ÃÎó²îλÓÚ´¦Öóͷ£JavaScript´úÂëµÄChrome×é¼þV8ÖС£¡£¡£¡£ ¡£²»¾Ãºó£¬£¬£¬£¬ £¬ £¬GoogleÓÖÐû²¼ÁËAndroid°æChromeÖеÄ0dayµÄ²¹¶¡³ÌÐò£¬£¬£¬£¬ £¬ £¬¸ÃÎó²î±»×·×ÙΪCVE-2020-16010£¬£¬£¬£¬ £¬ £¬ÎªChrome for AndroidÓû§½çÃæ£¨UI£©×é¼þÖеĶѻº³åÇøÒç³öÎó²î¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/google-patches-second-chrome-zero-day-in-two-weeks/


2.FireEyeÅû¶UNC1945ʹÓÃSolarisÖÐ0dayÈëÇֵĹ¥»÷ÊÂÎñ


2.jpg


FireEyeµÄMandiantÅû¶ºÚ¿Í×éÖ¯UNC1945ʹÓÃOracle Solaris²Ù×÷ϵͳÖеÄ0dayÈëÇÖÆóÒµÍøÂçµÄ¹¥»÷ÊÂÎñ¡£¡£¡£¡£ ¡£¸ÃÎó²î±»×·×ÙΪCVE-2020-14871£¬£¬£¬£¬ £¬ £¬Î»ÓÚSolaris²åÈëÉí·ÝÑé֤ģ¿£¿£¿£¿£¿£¿é(PAM)£¬£¬£¬£¬ £¬ £¬¸ÃÎó²îʹUNC1945¿ÉÒÔÈÆ¹ýÉí·ÝÑéÖ¤Àú³Ì£¬£¬£¬£¬ £¬ £¬²¢ÔÚ̻¶µÄSolarisЧÀÍÆ÷ÉÏ×°ÖÃSLAPSTICKµÄºóÃÅ¡£¡£¡£¡£ ¡£Mandiant³ÆºÚ¿ÍÒÔÒÔºóÃÅΪÇÐÈëµã£¬£¬£¬£¬ £¬ £¬ÔÚ¹«Ë¾ÍøÂçÄÚ²¿¾ÙÐÐÕì̽£¬£¬£¬£¬ £¬ £¬²¢ºáÏòÒÆ¶¯µ½ÆäËûϵͳ¡£¡£¡£¡£ ¡£±ðµÄ£¬£¬£¬£¬ £¬ £¬MandiantÒÔΪºÚ¿Í¿ÉÄÜÊÇÔÚ°µÍøÉÏÒÔ3000ÃÀÔªµÄ¼ÛÇ®¹ºÖõĸÃÎó²î¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hacker-group-uses-solaris-zero-day-to-breach-corporate-networks/


3.Ó¢¹úFoI³ÆBBCƽ¾ùÌìÌìÊÕµ½Áè¼Ý25w·ÝÀ¬»øÓʼþ


3.jpg


ƾ֤ÐÅÏ¢×ÔÓÉ(FoI£©±¨µÀ£¬£¬£¬£¬ £¬ £¬Ó¢¹ú¹ã²¥¹«Ë¾(BBC)ÌìÌìÃæÁÙÁè¼Ý25Íò·ÝÀ¬»øÓʼþµÄ¹¥»÷¡£¡£¡£¡£ ¡£Êý¾ÝÏÔʾ£¬£¬£¬£¬ £¬ £¬BBCƽ¾ùÿ¸öÔÂÊÕµ½6704188·âÕ©Æ­»òÀ¬»øÓʼþ£¬£¬£¬£¬ £¬ £¬ÒÔ¼°18662´Î¶ñÒâÈí¼þ¹¥»÷£¬£¬£¬£¬ £¬ £¬È粡¶¾¡¢ÀÕË÷Èí¼þºÍÌØ¹¤Èí¼þ¡£¡£¡£¡£ ¡£ÔÚ2020Äê1ÔÂÖÁ8ÔÂʱ´ú£¬£¬£¬£¬ £¬ £¬×ܹ²×èÖ¹ÁË51898393·âÊÜѬȾµÄµç×ÓÓʼþ¡£¡£¡£¡£ ¡£ÆäÖÐ7Ô·ÝÔâµ½¹¥»÷´ÎÊý×î¶à£¬£¬£¬£¬ £¬ £¬BBCµ±ÔÂÊÕµ½ÁË6787635À¬»øÓʼþºÍ13592´Î¶ñÒâÈí¼þ¹¥»÷¡£¡£¡£¡£ ¡£Æä´ÎÊÇ3Ô£¬£¬£¬£¬ £¬ £¬ÔÚCOVID-19Ê×´ÎÏ®»÷Ó¢¹úʱ£¬£¬£¬£¬ £¬ £¬ÊÕµ½ÁË6768632·âÀ¬»øÓʼþºÍ14089´Î¶ñÒâÈí¼þ¹¥»÷¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/bbc-experiences-malicious-email/


4.ÀÕË÷Èí¼þ×éÖ¯MazeÐû²¼Í˳ö£¬£¬£¬£¬ £¬ £¬²¢½«²»ÔÙй¶¹«Ë¾Êý¾Ý


4.png


ÀÕË÷Èí¼þ×éÖ¯MazeÓÚ2020Äê11ÔÂ2ÈÕÐû²¼ÕýʽÍ˳ö£¬£¬£¬£¬ £¬ £¬²¢½«²»ÔÙÔÚÆäÍøÕ¾ÉÏ×ߩй«Ë¾µÄÊý¾Ý¡£¡£¡£¡£ ¡£ÔçÔÚ9ÔÂÖÐÑ®£¬£¬£¬£¬ £¬ £¬Maze¾Í×èÖ¹Á˶ÔÐÂÊܺ¦ÕߵĹ¥»÷£¬£¬£¬£¬ £¬ £¬²¢ÕûÀíÁËÆäÊý¾Ý×ßÂ©ÍøÕ¾¡£¡£¡£¡£ ¡£Ö®ºó£¬£¬£¬£¬ £¬ £¬ÕýʽÐû²¼ÉùÃ÷£¬£¬£¬£¬ £¬ £¬³ÆMazeÍŶÓÏîÄ¿Õýʽ¹Ø±Õ£¬£¬£¬£¬ £¬ £¬ËùÓÐʹÓøÃÃû³ÆµÄÀÕË÷Èí¼þ¹¥»÷¶¼ÊÇȦÌס£¡£¡£¡£ ¡£µ±±»Îʼ°ÊÇ·ñ»áÏñTeslaCryptºÍShadeÄÇÑùÑ¡ÔñÔÚÍ˳öʱÊÍ·ÅÖ÷½âÃÜÃÜԿʱ£¬£¬£¬£¬ £¬ £¬Maze²¢Î´¾ÙÐлظ´¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/maze-ransomware-shuts-down-operations-denies-creating-cartel/


5.°ü¹Ü¹«Ë¾FolksamÊý¾Ýй¶£¬£¬£¬£¬ £¬ £¬Ó°ÏìÔ¼100ÍòÈðµäסÃñ


5.png


Èðµä×î´óµÄ°ü¹Ü¹«Ë¾Ö®Ò»Folksam¾­ÓÉÄÚ²¿ÉóºËºó·¢Ã÷ÁËÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬ £¬ £¬Ó°ÏìÔ¼100ÍòÈðµäסÃñ¡£¡£¡£¡£ ¡£´Ë´ÎÎüÊÕµ½Óû§Ð¡ÎÒ˽¼ÒÊý¾ÝµÄ¹«Ë¾ÓÐFacebook¡¢¹È¸è¡¢Î¢Èí¡¢ÁìÓ¢ºÍAdobe£¬£¬£¬£¬ £¬ £¬±¾ÒâÊÇÆÊÎöµÇÈÎÃü»§ºÍÆäËû»á¼ûÕßÔÚfolksam.seÉÏËÑË÷µÄÐÅÏ¢£¬£¬£¬£¬ £¬ £¬À´Îª¿Í»§Ìṩ¶¨ÖÆÐ§ÀÍ¡£¡£¡£¡£ ¡£µ«Folksam¹²ÏíµÄÊý¾Ý°üÀ¨ÖÖÖÖÃô¸ÐÐÅÏ¢£¬£¬£¬£¬ £¬ £¬ÈçÉç»áÇå¾²ºÅÂë»òСÎÒ˽¼Ò¹ºÖõŤ»á»òÓÐÉí°ü¹Ü¡£¡£¡£¡£ ¡£¸Ã¹«Ë¾³ÆÔÚ·¢Ã÷й¶ÊÂÎñºó£¬£¬£¬£¬ £¬ £¬±ãÁ¬Ã¦×èÖ¹ÁËÓëÏàÖúͬ°é¹²ÏíÃô¸ÐÐÅÏ¢£¬£¬£¬£¬ £¬ £¬²¢ÒªÇóÊÕµ½ÐÅÏ¢µÄ¹«Ë¾É¾³ýÕâЩÐÅÏ¢¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/folksam-data-breach-leaks-info-of-1m-swedes-to-google-facebook-more/


6.SonicWallÐû²¼µÚÈý¼¾¶ÈÍøÂçÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ


6.png


SonicWallÐû²¼µÚÈý¼¾¶ÈÍøÂçÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£ ¡£±¨¸æÏÔʾ£¬£¬£¬£¬ £¬ £¬È«Çò¹æÄ£ÄÚÆ½¾ùÌìÌì×èÖ¹Áè¼Ý2800Íò´Î¶ñÒâÈí¼þ¹¥»÷£¬£¬£¬£¬ £¬ £¬ÔÚ2020ÄêµÄǰÈý¸ö¼¾¶ÈÖУ¬£¬£¬£¬ £¬ £¬×ܹ²±¬·¢ÁË44ÒڴζñÒâÈí¼þ¹¥»÷£¨Í¬±ÈϽµ39£¥£©ºÍ1.997ÒÚ¸öÀÕË÷Èí¼þ¹¥»÷£¨Í¬±ÈÔöÌí40£¥£©¡£¡£¡£¡£ ¡£±ðµÄ£¬£¬£¬£¬ £¬ £¬SonicWall»¹·¢Ã÷ÈëÇÖʵÑé´ÎÊýÔöÌíÁË19£¥£¨3.5ÍòÒÚ£©¡¢ÎïÁªÍø¶ñÒâÈí¼þÔöÌí30£¥£¨3240Íò£©¡¢¼ÓÃÜÍþвÔöÌí3£¥£¨320Íò£©£¬£¬£¬£¬ £¬ £¬ÒÔ¼°¼ÓÃÜÐ®ÖÆÔöÌí2£¥£¨5790Íò£©¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://blog.sonicwall.com/en-us/2020/10/q3-cyber-threat-intelligence-details-a-september-to-remember/