ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ40ÖÜ
Ðû²¼Ê±¼ä 2020-10-09> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2020Äê09ÔÂ28ÈÕÖÁ10ÔÂ04ÈÕ¹²ÊÕ¼Çå¾²Îó²î56¸ö£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇFoxit Reader Field::ClearItems/Field::DeleteOptionsÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î£»£»£»£»Secudos DOMOS conf_datetimeí§ÒâÏÂÁîÖ´ÐÐÎó²î£»£»£»£»WAVLINK WN530H4 /cgi-bin/live_api.cgiÏÂÁî×¢ÈëÎó²î£»£»£»£»WAVLINK WN530H4 /cgi-bin/makeRequest.cgi»º³åÇøÒç³öÎó²î£»£»£»£»WAVLINK WN530H4 /cgi-bin/¶à¸öÑéÖ¤ÈÆ¹ýÎó²î¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇ£ºCNCERTÐû²¼¡¶2020ÄêÉϰëÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²¼à²âÊý¾ÝÆÊÎö±¨¸æ¡·£»£»£»£»Ñо¿Ö°Ô±·¢Ã÷жñÒâÈí¼þTaurusͨ¹ý¶ñÒâ¹ã¸æ»î¶¯Èö²¥£»£»£»£»ÃÀ¹úºÍ°Ä´óÀûÑÇOffice 365ЧÀÍ·ºÆðAADSTS90033¹ýʧ£»£»£»£»ÃÀ¹ú14¸öÖݱ¨¸æÆä911ЧÀÍÖÐÖ¹£¬£¬£¬£¬£¬£¬ÊÂÎñÔµ¹ÊÔÓÉ»¹ÔÚÊÓ²ìÖУ»£»£»£»ºÚ¿ÍÒÔWin7Éý¼¶ÎªÓÕ¶üÌᳫ´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬ÇÔÈ¡Outlookƾ֤¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£
> Ö÷ÒªÇå¾²Îó²îÁбí
1.Foxit Reader Field::ClearItems/Field::DeleteOptionsÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î
Foxit Reader Field::ClearItems/Field::DeleteOptions±£´æÊͷźóʹÓÃÎó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»òÕßÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://www.foxitsoftware.com/support/security-bulletins.html
2.Secudos DOMOS conf_datetimeí§ÒâÏÂÁîÖ´ÐÐÎó²î
Secudos DOMOS conf_datetime´¦Öóͷ£zone²ÎÊý±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬¿ÉÒÔrootÉÏÏÂÎÄÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£
https://www.secudos.de/en/news-en/domos-release-5-9
3.WAVLINK WN530H4 /cgi-bin/live_api.cgiÏÂÁî×¢ÈëÎó²î
WAVLINK WN530H4 /cgi-bin/live_api.cgi±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬¿ÉÒÔROOTȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£
https://cerne.xyz/bugs/CVE-2020-12124
4.WAVLINK WN530H4 /cgi-bin/makeRequest.cgi»º³åÇøÒç³öÎó²î
WAVLINK WN530H4 /cgi-bin/makeRequest.cgi±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬¿ÉÒÔROOTȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£
https://cerne.xyz/bugs/CVE-2020-12125
5.WAVLINK WN530H4 /cgi-bin/¶à¸öÑéÖ¤ÈÆ¹ýÎó²î
WAVLINK WN530H4 /cgi-bin/±£´æ¶à¸öÑéÖ¤ÈÆ¹ýÎó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬¿ÉÐÞ¸ÄÉèÖ㬣¬£¬£¬£¬£¬¾ÙÐоܾøÐ§À͵ȹ¥»÷¡£¡£¡£¡£
https://cerne.xyz/bugs/CVE-2020-12126
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢CNCERTÐû²¼¡¶2020ÄêÉϰëÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²¼à²âÊý¾ÝÆÊÎö±¨¸æ¡·

ΪÖÜÈ«·´Ó¦2020ÄêÉϰëÄêÎÒ¹ú»¥ÁªÍøÔÚ¶ñÒâ³ÌÐòÈö²¥¡¢Îó²îΣº¦¡¢DDoS¹¥»÷¡¢ÍøÕ¾Çå¾²µÈ·½ÃæµÄÇéÐΣ¬£¬£¬£¬£¬£¬CNCERT¶ÔÉϰëÄê¼à²âÊý¾Ý¾ÙÐÐÁËÊáÀí£¬£¬£¬£¬£¬£¬²¢Ðγɼà²âÊý¾ÝÆÊÎö±¨¸æ¡£¡£¡£¡£±¨¸æÏÔʾ£¬£¬£¬£¬£¬£¬2020ÄêÉϰëÄ꣬£¬£¬£¬£¬£¬²¶»ñÅÌËã»ú¶ñÒâ³ÌÐòÑù±¾ÊýĿԼ1815Íò¸ö£¬£¬£¬£¬£¬£¬ÈÕ¾ùÈö²¥´ÎÊý´ï483ÍòÓà´Î£¬£¬£¬£¬£¬£¬Éæ¼°ÅÌËã»ú¶ñÒâ³ÌÐò¼Ò×åÔ¼1.1ÍòÓà¸ö¡£¡£¡£¡£Æ¾Ö¤Èö²¥ÈªÔ´Í³¼Æ£¬£¬£¬£¬£¬£¬¾³Íâ¶ñÒâ³ÌÐòÖ÷ÒªÀ´×ÔÃÀ¹ú¡¢ÈûÉà¶ûºÍ¼ÓÄôóµÈ£¬£¬£¬£¬£¬£¬¾³ÄڵĶñÒâ³ÌÐòÖ÷ÒªÀ´×ÔÕã½Ê¡¡¢¹ã¶«Ê¡ºÍ±±¾©Êеȡ£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.cert.org.cn/publish/main/46/2020/20200926085042652505447/20200926085042652505447_.html
2¡¢Ñо¿Ö°Ô±·¢Ã÷жñÒâÈí¼þTaurusͨ¹ý¶ñÒâ¹ã¸æ»î¶¯Èö²¥

Ñо¿Ö°Ô±·¢Ã÷еÄÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þTaurusͨ¹ý¶ñÒâ¹ã¸æ»î¶¯Èö²¥¡£¡£¡£¡£TaurusÊÇÒ»ÖÖÏà¶Ô½ÏеĶñÒâÈí¼þ£¬£¬£¬£¬£¬£¬ÓÚ2020Äê´º¼¾·ºÆð£¬£¬£¬£¬£¬£¬Í¨¹ýÕë¶ÔÃÀ¹úÓû§µÄ¶ñÒâ¹ã¸æ»î¶¯¾ÙÐÐÈö²¥¡£¡£¡£¡£Æä×î³õÊÇÓÉPredatorµÄ½¨ÉèÕßËù¿ª·¢£¬£¬£¬£¬£¬£¬Òò´Ë¶þÕß¾ßÓÐÏàͬµÄ¹¦Ð§£¬£¬£¬£¬£¬£¬¼´´Óä¯ÀÀÆ÷¡¢FTP¡¢VPN¡¢µç×ÓÓʼþ¿Í»§¶ËÒÔ¼°¼ÓÃÜÇ®±ÒÇ®°üÇÔȡƾ֤¡£¡£¡£¡£´Ë´Î×îз¢Ã÷µÄ¶ñÒâ»î¶¯Ö÷ÒªÕë¶Ô³ÉÈËÍøÕ¾µÄ»á¼ûÕߣ¬£¬£¬£¬£¬£¬Êܺ¦Õß´ó¶àÀ´×ÔÃÀ¹ú£¬£¬£¬£¬£¬£¬Ò²ÓÐÀ´×Ô°Ä´óÀûÑǺÍÓ¢¹ú¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.malwarebytes.com/malwarebytes-news/2020/09/taurus-project-stealer-now-spreading-via-malvertising-campaign/
3¡¢ÃÀ¹úºÍ°Ä´óÀûÑÇOffice 365ЧÀÍ·ºÆðAADSTS90033¹ýʧ

´Ó9ÔÂ28ÈÕÃÀ¹ú¶«²¿Ê±¼äÏÂÖç5:15×îÏÈ£¬£¬£¬£¬£¬£¬ÃÀ¹úºÍ°Ä´óÀûÑǵÄOffice 365Óû§×îÏÈÄÑÒԵǼÆäµç×ÓÓʼþÕÊ»§»ò»á¼ûµç×ÓÓʼþ£¬£¬£¬£¬£¬£¬²¢»á·ºÆðAADSTS90033¹ýʧÌáÐÑ¡£¡£¡£¡£´Ë´ÎÖÐÖ¹Ó°ÏìÁ˵ç×ÓÓʼþЧÀÍ¡¢Microsoft Teams¡¢Office.com¡¢Power PlatformºÍDynamics365¡£¡£¡£¡£Microsoft×î³õÌåÏÖ£¬£¬£¬£¬£¬£¬ËûÃÇÈ·¶¨Á˵¼ÖÂÖÐÖ¹µÄÔµ¹ÊÔÓÉ£¬£¬£¬£¬£¬£¬¿ÉÊÇÔڻعöÖ®ºóÖÐÖ¹ÒÀȻûÓлñµÃ½â¾ö¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬Microsoft×îÏÈʵÑéͨ¹ý²î±ðµÄЧÀÍÖØÊÓзÓÉÁ÷Á¿£¬£¬£¬£¬£¬£¬²¢ÇÒһЩÓû§±¨¸æËµ¿ÉÒÔÔٴεǼ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-office-365-is-down-in-the-usa-shows-transient-error/
4¡¢ÃÀ¹ú14¸öÖݱ¨¸æÆä911ЧÀÍÖÐÖ¹£¬£¬£¬£¬£¬£¬ÊÂÎñÔµ¹ÊÔÓÉ»¹ÔÚÊÓ²ìÖÐ

±¾ÖÜÒ»£¬£¬£¬£¬£¬£¬ÃÀ¹ú»ªÊ¢¶ÙÖÝ¡¢±öϦ·¨ÄáÑÇÖÝºÍ¶íº¥¶íÖݵÈ14¸öÖݱ¨¸æÆä911ЧÀÍÖÐÖ¹£¬£¬£¬£¬£¬£¬ÏÖÔÚÊÂÎñÔµ¹ÊÔÓÉ»¹ÔÚÊÓ²ìÖС£¡£¡£¡£´Ë´ÎЧÀÍÖÐÖ¹Ó°ÏìÁËËùÓнôÆÈЧÀÍ£¬£¬£¬£¬£¬£¬µ«´ó´ó¶¼ÊÜÓ°ÏìµØÇøµÄ911ЧÀÍÔÚ30·ÖÖÓºÍ60·ÖÖÓÄÚ»Ö¸´¡£¡£¡£¡£ÓÐÐÂÎÅȪԴ³Æ´Ë´ÎÖÐÖ¹»òÓë΢ÈíµÄ´ó¹æÄ£Í£»£»£»£»úÓйء£¡£¡£¡£µ«ÆäËûȪԴÅú×¢£¬£¬£¬£¬£¬£¬Î¢ÈíÖÐÖ¹½öÓ°ÏìÁËOfficeºÍÓëµç×ÓÓʼþÏà¹ØµÄЧÀÍ£¬£¬£¬£¬£¬£¬911ЧÀÍÖÐÖ¹¿ÉÄÜ»ù´¡Óë΢ÈíÎ޹أ¬£¬£¬£¬£¬£¬²¢ÇҺܿÉÄÜÆðÔ´ÓÚPSAP£¨¹«¹²Çå¾²Ó¦´ðµã£©ÌṩÉÌ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/911-services-down-in-multiple-us-states/
5¡¢ºÚ¿ÍÒÔWin7Éý¼¶ÎªÓÕ¶üÌᳫ´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬ÇÔÈ¡Outlookƾ֤

Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬£¬ºÚ¿ÍÒÔWin7Éý¼¶ÎªÓÕ¶üÌᳫ´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬Ö¼ÔÚÇÔÈ¡OutlookÓû§Æ¾Ö¤¡£¡£¡£¡£´Ë´Î»î¶¯Í¨¹ý·¢ËÍÒÔ¡°Re£ºMicrosoft Windows Upgrade¡±ÎªÌâµÄ´¹ÂÚÓʼþ£¬£¬£¬£¬£¬£¬ÓÕʹÊܺ¦Õßµã¿ªÍøÂç´¹ÂÚµÇÂ¼Ò³Ãæ¡£¡£¡£¡£¸ÃÒ³ÃæÊÇαÔìµÄOutlook Web App£¨OWA£©µÇÂ¼Ò³Ãæ£¬£¬£¬£¬£¬£¬ÒªÇóÓû§ÊäÈëµç×ÓÓʼþµØµã¡¢Óò/Óû§ÃûºÍÃÜÂ룬£¬£¬£¬£¬£¬ÒÔ´ËÀ´ÇÔÊØÐÅÏ¢¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬¸Ã´¹ÂÚÓʼþ»¹°üÀ¨ÆäËûÏêϸÐÅÏ¢£¬£¬£¬£¬£¬£¬ÀýÈçÉý¼¶Àú³ÌÖпÉÄÜ»áÓöµ½µÄÎÊÌ⣬£¬£¬£¬£¬£¬ÒÔÔöÌíÆäÕæÊµÐÔ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/windows-7-outlook/159621/


¾©¹«Íø°²±¸11010802024551ºÅ