ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ39ÖÜ

Ðû²¼Ê±¼ä 2020-09-28

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2020Äê09ÔÂ21ÈÕÖÁ09ÔÂ27ÈÕ¹²ÊÕ¼Çå¾²Îó²î60¸ö£¬ £¬£¬ÖµµÃ¹Ø×¢µÄÊÇChrome storageÔ½½ç¶Á´úÂëÖ´ÐÐÎó²î£»£»Chrome ExtensionsÕ½ÂÔÈÆ¹ý´úÂëÖ´ÐÐÎó²î£»£»Chrome V8´úÂëÖ´ÐÐÎó²î£»£»Chrome mediaÊý¾ÝÑéÖ¤´úÂëÖ´ÐÐÎó²î£»£»IBM Data Risk Manager FasterXML jackson-databind´úÂëÖ´ÐÐÎó²î¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǵ¹úTutanotaÔâµ½DDoS¹¥»÷µ¼ÖÂЧÀÍÔÝʱÖÐÖ¹£»£»PradeoÐû²¼¡¶ÊÖ»úÒøÐУº¹æÔò¡¢ÍþвºÍڲƭԤ·À¡·°×ƤÊ飻£»NSAÐû²¼Õë¶ÔÔ¶³ÌÊÂÇéÕߺÍϵͳÖÎÀíÔ±µÄÍøÂçÇå¾²Ö¸ÄÏ£»£»2020ÄêQ2 DDoS¹¥»÷µÄ´ÎÊý±ÈÈ¥Äêͬ±ÈÔöÌí570£¥£»£»Î¢Èí³ÆÒѼì²âµ½Ê¹ÓÃZerologonÎó²îÌᳫµÄ×Ô¶¯¹¥»÷¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬ £¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£


Ö÷ÒªÇå¾²Îó²îÁбí


1.Chrome storageÔ½½ç¶Á´úÂëÖ´ÐÐÎó²î


Chrome storage±£´æÔ½½ç¶ÁÎó²î£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇó£¬ £¬£¬ÓÕʹÓû§ÆÊÎö£¬ £¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»ò¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£

https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop_21.html


2. Chrome ExtensionsÕ½ÂÔÈÆ¹ý´úÂëÖ´ÐÐÎó²î


Chrome Extensions±£´æÕ½ÂÔÈÆ¹ýÎó²î£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇó£¬ £¬£¬ÓÕʹÓû§ÆÊÎö£¬ £¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»ò¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£

https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop_21.html


3.Chrome V8´úÂëÖ´ÐÐÎó²î


Chrome V8ÒýÇæ±£´æÔ½½çдÎó²î£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇó£¬ £¬£¬ÓÕʹÓû§ÆÊÎö£¬ £¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»ò¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£

https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop_21.html


4. Chrome mediaÊý¾ÝÑéÖ¤´úÂëÖ´ÐÐÎó²î


Chrome media±£´æÊý¾ÝÑéÖ¤Îó²î£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇó£¬ £¬£¬ÓÕʹÓû§ÆÊÎö£¬ £¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»ò¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£

https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop_21.html


5.IBM Data Risk Manager FasterXML jackson-databind´úÂëÖ´ÐÐÎó²î


IBM Data Risk Manager FasterXML jackson-databind±£´æ·´ÐòÁл¯Îó²î£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£


https://www.ibm.com/support/pages/node/6335281


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢µÂ¹úTutanotaÔâµ½DDoS¹¥»÷µ¼ÖÂЧÀÍÔÝʱÖÐÖ¹


1.jpg


µÂ¹ú¶Ëµ½¶Ë¼ÓÃܵç×ÓÓʼþЧÀÍÌṩÉÌTutanotaÔâµ½DDoS¹¥»÷£¬ £¬£¬µ¼ÖÂЧÀÍÔÝʱÖÐÖ¹ÊýСʱ¡£¡£Ê×´ÎÖ±½ÓÕë¶ÔTutanotaµÄDDoS¹¥»÷±¬·¢ÔÚ9ÔÂ14ÈÕ֮ǰµÄË­ÈËÖÜÄ©£¬ £¬£¬µ¼ÖÂÊý°ÙÃûÓû§ÎÞ·¨»á¼ûЧÀÍ£¬ £¬£¬µ«¸ÃÎÊÌâºÜ¿ì»ñµÃÏàʶ¾ö¡£¡£Ö®ºóÔÚTutanotaµÄЧÀÍÆ÷¹Ø±Õºó£¬ £¬£¬ºÚ¿Í¹¥»÷ÁËÍйÜTutanota¼Í¼µÄDNSÌṩ³ÌÐò£¬ £¬£¬ÕâʹÊý°ÙÍòÓû§ÎÞ·¨»á¼ûÆäTutanotaÕÊ»§¡£¡£ÏÖÔÚ£¬ £¬£¬¸Ã¹«Ë¾ÕýÔÚʵÑé¸üÐÂÆäDNS¼Í¼£¬ £¬£¬²¢½«ËüÃÇÍйÜÔÚÁíÒ»¸öÌṩÉÌ´¦¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/tutanota-encrypted-email-service-suffers-ddos-cyberattacks/


2¡¢PradeoÐû²¼¡¶ÊÖ»úÒøÐУº¹æÔò¡¢ÍþвºÍڲƭԤ·À¡·°×ƤÊé


2.jpg


PradeoÐû²¼ÁË¡¶ÊÖ»úÒøÐУº¹æÔò¡¢ÍþвºÍڲƭԤ·À¡·°×ƤÊ飬 £¬£¬ÏÈÈÝÁËÓйØÒƶ¯ÒøÐеÄʹÓá¢Ö´·¨¿ò¼Ü¡¢Î£º¦ÒÔ¼°±£»£»¤Òƶ¯ÒøÐÐÓ¦ÓóÌÐòÇå¾²µÄ½â¾ö¼Æ»®£¨´Ó¿ª·¢µ½Ö´ÐУ©µÄÏêϸÐÅÏ¢¡£¡£ÆäÖÐдµÀ£¬ £¬£¬Òƶ¯ÒøÐÐЧÀÍѸËÙÊܵ½ÏûºÄÕßµÄϲ»¶£¬ £¬£¬µ½2019Äêµ×£¬ £¬£¬74%µÄÓ¢¹úÈ˺Í75%µÄÃÀ¹úÈËʹÓÃÒÆ¶¯×°±¸À´ÖÎÀíÆä²ÆÎñ¡£¡£¿ÉÊÇÑо¿Åú×¢£¬ £¬£¬ÊÖ»úÒøÐÐÓ¦ÓÃÍùÍùûÓÐÔ¤ÆÚµÄÄÇôÇå¾²£¬ £¬£¬¾ÝRSAµÄڲƭºÍΣº¦Ç鱨ÍŶÓ×î½üÍøÂçµÄÊý¾ÝÆÊÎöÏÔʾ£¬ £¬£¬ÓëÊÖ»úÓ¦ÓÃÏà¹ØµÄڲƭÐÐΪÔÚ2020ÄêµÚÒ»¼¾¶È·­ÁËÒ»·¬¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/09/21/whitepaper-mobile-banking-regulations-threats-and-fraud-prevention


3¡¢NSAÐû²¼Õë¶ÔÔ¶³ÌÊÂÇéÕߺÍϵͳÖÎÀíÔ±µÄÍøÂçÇå¾²Ö¸ÄÏ


3.jpg


ÃÀ¹ú¹ú¼ÒÇå¾²¾Ö(NSA)Ðû²¼ÁËÁ½·ÝÍøÂçÇå¾²ÐÅÏ¢±í(CSIs)£¬ £¬£¬Îª¹ú¼ÒÇ徲ϵͳ(NSS)ºÍ¹ú·À²¿(DoD)ÊÂÇéÖ°Ô±ºÍϵͳÖÎÀíÔ±ÌṩÁ˹ØÓÚÔÚ¼ÒÊÂÇéʱ´ú±£»£»¤ÍøÂçÇå¾²ºÍÓ¦¶ÔÊÂÎñµÄ½¨Òé¡£¡£µÚÒ»·ÝÃûΪÊÜËðСÎÒ˽¼ÒÍøÂçÖ¸±ê»ººÍ½â²½·¥£¬ £¬£¬Ö¼ÔÚÌṩÓйØÔ¶³ÌÊÂÇéÕßÔõÑùʶ±ðºÍ¼õÇáÆäСÎÒ˽¼ÒÍøÂçΣº¦µÄÏêϸÐÅÏ¢¡£¡£µÚ¶þ·ÝÃûΪִÐдøÍâÍøÂçÖÎÀí£¬ £¬£¬ÆäÏòϵͳÖÎÀíÔ±ÌṩÁËÔõÑù¸ôÀëÖÎÀíÁ÷Á¿ºÍÔËÓªÁ÷Á¿µÄÐÅÏ¢¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/nsa-issues-cybersecurity-guidance-remote-workers-system-admins


4¡¢2020ÄêQ2 DDoS¹¥»÷µÄ´ÎÊý±ÈÈ¥Äêͬ±ÈÔöÌí570£¥


4.png


ƾ֤Nexusguard±¨¸æ£¬ £¬£¬DDoS¹¥»÷µÄ´ÎÊýÓëÈ¥ÄêͬÆÚÏà±ÈÔöÌíÁË570£¥¡£¡£¹¥»÷Õß½ÓÄÉÁׯüϸÄåµÄ¹¥»÷·½·¨£¬ £¬£¬ÒÔ·¢¶¯ÖÖÖÖ·Å´óºÍ»ùÓÚUDPµÄ¹¥»÷£¬ £¬£¬ÓÃÁ÷Á¿ÑÍûĿµÄÍøÂ磬 £¬£¬ÕâʹCSPºÜÄÑͨ¹ý¹Å°åµÄ»ùÓÚãÐÖµµÄÒªÁì¾ÙÐмì²â»ººÍ½â¡£¡£Nexusguard»¹·¢Ã÷ÁËÒ»ÖÖеÄÇ÷ÊÆ£¬ £¬£¬¼´¹¥»÷Õß½ÓÄÉ»ìÏý¹¥»÷ǰÑÔÀ´Ìᳫ¸üÆÕ±éµÄ»ùÓÚUDPµÄ¹¥»÷£¬ £¬£¬Ä¿µÄÊÇÌá¸ßCSP¼ì²âºÍÇø·Ö¶ñÒâÁ÷Á¿ÓëÕýµ±Á÷Á¿µÄÄѶÈ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/09/23/bit-and-piece-ddos-attacks-increased-570-in-q2-2020/


5¡¢Î¢Èí³ÆÒѼì²âµ½Ê¹ÓÃZerologonÎó²îÌᳫµÄ×Ô¶¯¹¥»÷


5.png


΢ÈíÇå¾²Ç鱨ÍŶÓÌåÏÖ£¬ £¬£¬ÆäÒѼì²âµ½Ê¹ÓÃZerologonÎó²î£¨CVE-2020-1472 £©ÌᳫµÄ×Ô¶¯¹¥»÷¡£¡£×ÔºÉÀ¼Çå¾²¹«Ë¾Secura BVÔÚ9ÔÂ14ÈÕÅû¶ÁËÓйØZerologonÎó²îµÄÏêϸÐÅÏ¢ºó£¬ £¬£¬ÒÑÓжà¸öÎäÆ÷»¯µÄPoC¿ª·¢´úÂëÔÚÍøÉϹûÕæ¡£¡£Î¢Èí²¢Ã»ÓÐÐû²¼Óйش˴ι¥»÷µÄϸ½Ú£¬ £¬£¬¿ÉÊÇÐû²¼ÁËÓÃÓÚ¹¥»÷µÄÎļþÉ¢ÁС£¡£Òò´ËÇ徲ר¼Ò¾Í½¨Ò飬 £¬£¬ÄÇЩÓòÃû¿ØÖÆÆ÷̻¶µÄ¹«Ë¾Ó¦¾¡¿ìÈÃϵͳÀëÏߣ¬ £¬£¬ÒÔ±ã¶ÔÆä¾ÙÐв¹¶¡¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/microsoft-says-it-detected-active-attacks-leveraging-zerologon-vulnerability/