MicrosoftÐû²¼OfficeÇå¾²¸üУ¬ £¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËÉí·ÝÑéÖ¤µÈÎÊÌ⣻£»£»£» £»£»£»°ÄÖÞ¹«Ë¾Toll GroupÓÖÔâÀÕË÷Èí¼þ¹¥»÷

Ðû²¼Ê±¼ä 2020-05-07

1.MicrosoftÐû²¼OfficeÇå¾²¸üУ¬ £¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËÉí·ÝÑéÖ¤µÈÎÊÌâ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

MicrosoftÐû²¼ÁËÕë¶ÔMicrosoft OfficeµÄ5Ô¸üУ¬ £¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËÕë¶ÔÆß¸ö²î±ð²úÆ·µÄ55¸öÇå¾²ÎÊÌâ²¢Ðû²¼ÁËÎå¸öÀÛ»ý¸üУ¬ £¬£¬£¬£¬£¬£¬Ó°ÏìÁËMicrosoft Office 2016Ì×¼þ¡¢Microsoft Outlook 2016£¬ £¬£¬£¬£¬£¬£¬Microsoft PowerPoint 2016¡¢Microsoft Project 2016¡¢Microsoft Word 2016ºÍSkype for Business 2015²úÆ·¡£ ¡£¡£´Ë´Î¸üÐÂÐÞ¸´µÄ½ÏΪÑÏÖØµÄÎÊÌâÊÇMicrosoft Office 2016ÖÐÆôÓÃÍÑ»úÉí·ÝÑé֤ʱÏÔʾ¿ÕȱÉí·ÝÑéÖ¤ÌáÐѵÄÎÊÌ⣬ £¬£¬£¬£¬£¬£¬ºÍPowerPoint 2016µÄÉí·ÝÑéÖ¤ÎÊÌâ¡£ ¡£¡£ÁíÍ⣬ £¬£¬£¬£¬£¬£¬´Ë´ÎÐû²¼µÄ¸üÐÂÊÊÓÃÓÚ»ùÓÚMicrosoft Installer£¨.msi£©µÄOffice²úÆ·£¬ £¬£¬£¬£¬£¬£¬¶ø²»ÊÊÓÃÓÚOffice¶©ÔÄ»òOffice 2016 Click-to-Run°æ±¾£¬ £¬£¬£¬£¬£¬£¬ÀýÈçMicrosoft Office 365 Home¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-may-office-updates-with-fixes-for-auth-issues/


2.Èí¼þ¹«Ë¾SAPÐû²¼Æä²úÆ·±£´æÎó²î£¬ £¬£¬£¬£¬£¬£¬»ò½«Ó°Ïì9£¥Óû§


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


µÂ¹úÈí¼þ¹«Ë¾SAPÌåÏÖ£¬ £¬£¬£¬£¬£¬£¬ÔÚÄÚ²¿Çå¾²Éó²éʱ·¢Ã÷ÆäÆß¸öÔÆ²úÆ·±£´æÇå¾²Îó²î£¬ £¬£¬£¬£¬£¬£¬²¢ÔÚÖÜÒ»Ðû²¼½«Îó²î֪ͨÊÜÓ°ÏìµÄµÄÓû§£¬ £¬£¬£¬£¬£¬£¬Ô¼ÄªÎªËùÓÐ44ÍòÓû§µÄ9£¥¡£ ¡£¡£´Ë´ÎÊÜÓ°ÏìµÄ7¿î²úƷΪSAP Success Factors¡¢SAP Concur¡¢ SAP/CallidusCloud Commissions¡¢ SAP/Callidus Cloud CPQ¡¢ SAP C4C/Sales Cloud¡¢ SAP Cloud Platform ºÍ SAP Analytics Cloud¡£ ¡£¡£ÓÉÓÚÕâЩÎó²îÉÐδ»ñµÃÐÞ¸´£¬ £¬£¬£¬£¬£¬£¬ÒÔÊǸù«Ë¾ÏÖÔÚÉÐδÏêϸ˵Ã÷ÓйØÎó²îµÄÐÅÏ¢£¬ £¬£¬£¬£¬£¬£¬µ«SAPÌåÏÖ£¬ £¬£¬£¬£¬£¬£¬½«ÓÚ2020ÄêµÚ¶þ¼¾¶ÈÍê³ÉÊÜÓ°ÏìµÄ²úÆ·µÄÇå¾²¸üС£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/sap-notifying-9-of-customers-about-security-bugs-in-some-cloud-products/


3.ºÚ¿Í×éÖ¯ÔÚÒÑÍùÒ»ÖÜÄÚÐ®ÖÆ½ü100Íò¸öWordPressÍøÕ¾


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Çå¾²¹«Ë¾Wordfence·¢³öÖÒÑÔ£¬ £¬£¬£¬£¬£¬£¬Ò»¸öºÚ¿Í×éÖ¯ÔÚÒÑÍùµÄ7ÌìÄÚÒÑÊÔÍ¼Ð®ÖÆ½ü100Íò¸öWordPressÍøÕ¾¡£ ¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬ £¬£¬£¬£¬£¬£¬×Ô4ÔÂ28ÈÕÒÔÀ´£¬ £¬£¬£¬£¬£¬£¬Õâ¸öºÚ¿Í×éÖ¯Ò»Ö±ÔÚ¾ÙÐдó¹æÄ£µÄºÚ¿Í»î¶¯£¬ £¬£¬£¬£¬£¬£¬Ö±µ½×î½ü¼¸Ìì¹¥»÷Á¿²ÅÕæÕýÔöÇ¿¡£ ¡£¡£¸Ã×éÖ¯´ÓÁè¼Ý2.4Íò¸ö²î±ðµÄIPµØµãÌᳫÁ˹¥»÷£¬ £¬£¬£¬£¬£¬£¬²¢ÊÔͼÇÖÈë90¶àÍò¸öWordPressÍøÕ¾¡£ ¡£¡£¹¥»÷ÔÚ5ÔÂ3ÈÕµÖ´ïá۷壬 £¬£¬£¬£¬£¬£¬Æä¶Ô50Íò¸öÓòÌᳫÁËÁè¼Ý2000Íò´Î¹¥»÷¡£ ¡£¡£¾ÝWordfence±¨µÀ£¬ £¬£¬£¬£¬£¬£¬¸Ã×éÖ¯Ö÷ÒªÊÇʹÓÃXSSÎó²îÔÚÍøÕ¾ÉÏÖ²Èë¶ñÒâJavaScript´úÂ룬 £¬£¬£¬£¬£¬£¬ÒÔ½«´«ÈëÁ÷Á¿Öض¨Ïòµ½¶ñÒâÍøÕ¾µÄ¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/a-hacker-group-tried-to-hijack-900000-wordpress-sites-over-the-last-week/


4.Naughty Dog²¹¶¡±£´æÎó²î£¬ £¬£¬£¬£¬£¬£¬¿É»á¼ûAmazon S3ÖÐδ¿¯ÐÐÄÚÈÝ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Naughty DogÐû²¼µÄ²¹¶¡³ÌÐòÖб£´æÒ»¸öÎó²î£¬ £¬£¬£¬£¬£¬£¬Ê¹ºÚ¿ÍÄܹ»»á¼û´æ´¢ÔÚAmazon S3ÖеÄThe Last of UsµÚ¶þ²¿·ÖÖÐδ¿¯ÐеÄÄÚÈÝ¡£ ¡£¡£Ô¼ÄªÒ»ÖÜǰ£¬ £¬£¬£¬£¬£¬£¬ÓÎÏ·µÄ¾ç͸ÊÓÆµ±»Ðû²¼µ½ÁËÍøÉÏ£¬ £¬£¬£¬£¬£¬£¬¼¤ÆðÁËÍæ¼ÒµÄÇ¿ÁÒÌÖÂÛ£¬ £¬£¬£¬£¬£¬£¬Ò²ÎªÓÎÏ·¿ª·¢ÉÌ´øÀ´Ëðʧ¡£ ¡£¡£¾ÝÐÂÎű༭Jason Schreier±¨µÀ£¬ £¬£¬£¬£¬£¬£¬´Ë´ÎÊý¾Ýй¶ʱ¼äÊÇÓÉÓÚÀϾɵÄÓÎÏ·²¹¶¡±£´æÎó²îµ¼ÖµÄ¡£ ¡£¡£´Ë´Î¹¥»÷À´×Ôδ֪µÄºÚ¿ÍÕûÌ壬 £¬£¬£¬£¬£¬£¬ËûÃÇʹÓøÃÎó²î»á¼ûÁËNaughty DogʹÓõÄAmazonЧÀÍÆ÷¡£ ¡£¡£ÔÚ3ÔÂʱ£¬ £¬£¬£¬£¬£¬£¬ºÚ¿Í±ãÇÔÈ¡²¢Ð¹Â¶ÁËÖÁÉÙ1TBµÄ4ÔÂÒªÐû²¼µÄÊý¾ÝºÍËØ²Ä¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/game-patch-gives-hackers-access-to-development-content-on-amazon-s3/


5.ºÚ¿ÍʹÓÃCisco WebexÌᳫ´¹ÂÚ¹¥»÷£¬ £¬£¬£¬£¬£¬£¬ÒÔÇÔÈ¡Óû§Æ¾Ö¤


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


×î½ü·ºÆðÁËеÄÍøÂç´¹ÂÚ¹¥»÷»î¶¯£¬ £¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃαÔìµÄCisco WebexÖ¤Êé¹ýʧÖÒÑÔ£¬ £¬£¬£¬£¬£¬£¬ÒÔÇÔÈ¡Óû§µÄÕÊ»§Æ¾Ö¤¡£ ¡£¡£¾ÝÓʼþÇå¾²¹«Ë¾Abnormal Securityͳ¼ÆµÄÊý¾Ý£¬ £¬£¬£¬£¬£¬£¬´Ë´ÎÊÂÎñÒѹ¥»÷Áè¼Ý5000¸öÊܺ¦Õß¡£ ¡£¡£¹¥»÷ÕßʹÓÿË¡µÄͼÐκÍÃûÌÃÀ´·ÂðCisco WebEx·¢Ë͸øÓû§µÄ×Ô¶¯SSLÖ¤Êé¹ýʧ¾¯±¨£¬ £¬£¬£¬£¬£¬£¬²¢ÖÒÑÔÊܺ¦Õ߯äÒòWebex Meetings SSLÖ¤Êé¹ýʧÒѱ»ÖÎÀíÔ±×èÖ¹£¬ £¬£¬£¬£¬£¬£¬±ØÐèÑéÖ¤ÕÊ»§£¬ £¬£¬£¬£¬£¬£¬´Ó¶øÓÕʹËûÃǵã»÷µÇ¼µÄÁ´½ÓÒÔ½âËøÕÊ»§¡£ ¡£¡£Ö®ºó¸ÃÁ´½Ó±ã»á½«Óû§Öض¨Ïòµ½ÍøÂç´¹ÂÚÍøÕ¾£¬ £¬£¬£¬£¬£¬£¬²¢ÇÔÈ¡ÆäÉϰ¶Æ¾Ö¤¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/cisco-webex-phishing-uses-fake-cert-errors-to-steal-credentials/


6.°ÄÖÞ¹«Ë¾Toll GroupÓÖÔâÀÕË÷Èí¼þ¹¥»÷£¬ £¬£¬£¬£¬£¬£¬ÎªNefilimÍÅ»ï¾ÙÐÐ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


2020Äê5ÔÂ5ÈÕ£¬ £¬£¬£¬£¬£¬£¬°Ä´óÀûÑÇÎïÁ÷¹«Ë¾Toll GroupÔÚÈý¸öÔÂÄÚÓÖÒ»´ÎÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬ £¬£¬£¬£¬£¬£¬µ¼ÖÂËûÃÇÔٴιرÕÁËϵͳ£¬ £¬£¬£¬£¬£¬£¬¾ÝÊÓ²ì´Ë´Î¹¥»÷ÊÇÓɺڿÍ×éÖ¯Nefilim RansomwareÌᳫµÄ¡£ ¡£¡£Toll GroupÔÚ2020Äê2ÔÂ5ÈÕµÚÒ»´ÎÐû²¼£¬ £¬£¬£¬£¬£¬£¬ËûÃÇÔâµ½ÁËÀÕË÷Èí¼þMailtoµÄ±äÖֵĹ¥»÷£¬ £¬£¬£¬£¬£¬£¬²¢±»ÒªÇ󹨱Õϵͳ¡£ ¡£¡£¾ÝÑо¿Ö°Ô±ÊӲ죬 £¬£¬£¬£¬£¬£¬µÚ¶þ´Î¹¥»÷ÖкڿÍÒÀȻʹÓÃÁËCtrix ADC NetscalerЧÀÍÆ÷£¬ £¬£¬£¬£¬£¬£¬ÕâÒ²ÊǵÚÒ»´Î¹¥»÷Öй¥»÷ÕßËùʹÓõÄЧÀÍÆ÷¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/toll-group-hit-by-ransomware-a-second-time-deliveries-affected/