˼¿ÆÅû¶ÆäAnyConnect¿Í»§¶ËÖÐ0day£¬ £¬£¬£¬£¬£¬ÉÐÎÞÏà¹Ø²¹¶ ¡£¡£¡£¡£¡£¡£¡£»£»£»£»£»AdobeÇå¾²¸üУ¬ £¬£¬£¬£¬£¬ÐÞ¸´AcrobatºÍReaderÖжà¸öÎó²î

Ðû²¼Ê±¼ä 2020-11-05
1.˼¿ÆÅû¶ÆäAnyConnect¿Í»§¶ËÖÐ0day£¬ £¬£¬£¬£¬£¬ÉÐÎÞÏà¹Ø²¹¶¡


1.jpg


˼¿ÆÅû¶ÆäAnyConnect¿Í»§¶ËÈí¼þµÄ0day£¬ £¬£¬£¬£¬£¬ÏÖÔÚÒÑÓйûÕæ¿ÉÓõĿ´·¨Ñé֤ʹÓôúÂ룬 £¬£¬£¬£¬£¬µ«ÉÐÎÞÕë¶ÔÕâ¸öí§Òâ´úÂëÖ´ÐÐÎó²îµÄÇå¾²¸üР¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î±»×·×ÙΪCVE-2020-3556£¬ £¬£¬£¬£¬£¬±£´æÓÚCisco AnyConnect ClientµÄÀú³Ì¼äͨѶ£¨IPC£©Í¨µÀÖУ¬ £¬£¬£¬£¬£¬¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷ÕߺÍÍâµØ¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐжñÒâ¾ç±¾ ¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁËWindows¡¢LinuxºÍmacOS°æ±¾µÄAnyConnect¿Í»§¶Ë£¬ £¬£¬£¬£¬£¬Ö»¹ÜûÓв¹¶¡³ÌÐò£¬ £¬£¬£¬£¬£¬¿ÉÊÇ¿ÉÒÔͨ¹ý½ûÓÃ×Ô¶¯¸üкÍ×èÖ¹ÆôÓþ籾ÉèÖÃÀ´»º½â¸ÃÎÊÌâ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/cisco-discloses-anyconnect-vpn-zero-day-exploit-code-available/


2.AdobeÇå¾²¸üУ¬ £¬£¬£¬£¬£¬ÐÞ¸´AcrobatºÍReaderÖжà¸öÎó²î


2.jpg


AdobeÐû²¼Çå¾²¸üУ¬ £¬£¬£¬£¬£¬ÐÞ¸´ÁËWindowsºÍmacOS°æ±¾µÄAdobe AcrobatºÍReaderÖÐ×ܼÆ14¸öÎó²î£¬ £¬£¬£¬£¬£¬´Ë´ÎÐÞ¸´µÄ½ÏΪÑÏÖØµÄÎó²îΪí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2020-24435¡¢CVE-2020-24436¡¢CVE-2020-24430ºÍCVE-2020-24437£©£¬ £¬£¬£¬£¬£¬ÍâµØÌáȨÎó²î£¨CVE-2020-24433¡¢CVE-2020-24429ºÍCVE-2020-24428£©£¬ £¬£¬£¬£¬£¬í§ÒâJavaScriptÖ´ÐÐÎó²î£¨CVE-2020-24432£©ÒÔ¼°¶¯Ì¬¿â×¢ÈëÎó²î£¨CVE-2020-24431£© ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-security-vulnerabilities-in-acrobat-reader/


3.SaltStackÐû²¼²¹¶¡³ÌÐò£¬ £¬£¬£¬£¬£¬ÐÞ¸´3¸öÑÏÖØµÄÎó²î


3.png


SaltStackÐû²¼²¹¶¡³ÌÐò£¬ £¬£¬£¬£¬£¬ÐÞ¸´ÁËÓ°ÏìSalt°æ±¾3002¼°¸üµÍ°æ±¾µÄ3¸öÑÏÖØµÄÎó²î ¡£¡£¡£¡£¡£¡£¡£SaltÊÇÓÃPython±àдµÄ¿ªÔ´IT»ù´¡¼Ü¹¹ÖÎÃ÷È·¾ö¼Æ»®£¬ £¬£¬£¬£¬£¬ÓÚ10Ô±»VMwareÊÕ¹º ¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄÎó²î»®·ÖΪShell×¢ÈëÎó²î£¨CVE-2020-16846£©£¬ £¬£¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ýSSH¿Í»§¶ËʹÓÃShell×¢ÈëÔÚSalt-APIÉÏÔËÐдúÂ룻£»£»£»£»Éí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2020-25592 £©£¬ £¬£¬£¬£¬£¬Ê¹ÓÃÈκÎÖµµÄeauth»òtoken¶¼¿ÉÈÆ¹ýÉí·ÝÑéÖ¤²¢Å²ÓÃSalt ssh£»£»£»£»£»Óë·­¿ªºÍÉúÑļÓÃÜ˽ԿÎļþÓйصÄȨÏÞÎÊÌ⣨CVE-2020-17490£© ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/saltstack-reveals-new-critical-vulnerabilities-patch-now/


4.ÀÕË÷ÍÅ»ïREvilÅÄÏÂÐÅÏ¢ÇÔȡľÂíKPOTµÄÔ´´úÂë


4.png


ÔÚÒ»´Î°µÍøÉϾÙÐеÄÅÄÂô»î¶¯ÖУ¬ £¬£¬£¬£¬£¬ÀÕË÷Èí¼þÍÅ»ïREvilÒÔ6500ÃÀÔªµÄ¼ÛÇ®ÅĵÃÁËKPOTľÂíµÄÔ´´úÂë ¡£¡£¡£¡£¡£¡£¡£KPOTÓÚ2018Äê±»Ê״η¢Ã÷£¬ £¬£¬£¬£¬£¬ÊǾ­µäµÄÐÅÏ¢ÇÔÈ¡³ÌÐò£¬ £¬£¬£¬£¬£¬¿ÉÒÔ´ÓÊÜѬȾÅÌËã»úÉϵÄÖÖÖÖÓ¦ÓÃÖÐÇÔÈ¡ÃÜÂ룬 £¬£¬£¬£¬£¬°üÀ¨Webä¯ÀÀÆ÷¡¢µç×ÓÓʼþ¿Í»§¶Ë¡¢VPN¡¢¼ÓÃÜÇ®±ÒÇ®°üºÍÓÎÏ·Èí¼þ ¡£¡£¡£¡£¡£¡£¡£Çå¾²Ñо¿Ô±Pancak3·¢Ã÷£¬ £¬£¬£¬£¬£¬ÔÚÒ»¸öÔÂǰµÄ°µÍøÅÄÂô»áÉÏ£¬ £¬£¬£¬£¬£¬ REvilÍÅ»ïµÄ×ÅÃû³ÉÔ±UNKNÒÔ6500ÃÀÔª¼ÛÇ®Âòµ½ÁË×îа汾KPOT 2.0µÄÔ´´úÂë ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/revil-ransomware-gang-acquires-kpot-malware/


5.ÐÂÀÕË÷Èí¼þRegretLockerÖ÷ÒªÕë¶ÔWindowsÐéÄâ»ú


5.png


MalwareHunterTeam·¢Ã÷ÐÂÀÕË÷Èí¼þRegretLockerÖ÷ÒªÕë¶ÔWindowsÐéÄâ»ú ¡£¡£¡£¡£¡£¡£¡£RegretLockerÓÚ10Ô±»·¢Ã÷£¬ £¬£¬£¬£¬£¬ÊÇÒ»¿î¼òÆÓµÄÀÕË÷Èí¼þ£¬ £¬£¬£¬£¬£¬Ã»ÓÐÈß³¤µÄÀÕË÷¼Í¼£¬ £¬£¬£¬£¬£¬²¢ÇÒʹÓõç×ÓÓʼþͨѶ¶ø·ÇTorÖ§¸¶ÍøÕ¾ ¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷RegretLockerʹÓÃWindowsÐéÄâ´æ´¢API OpenVirtualDisk¡¢AttachVirtualDiskºÍGetVirtualDiskPhysicalPathº¯ÊýÀ´×°ÖÃÐéÄâ´ÅÅÌ ¡£¡£¡£¡£¡£¡£¡£Ò»µ©ÐéÄâ´ÅÅÌ×÷ΪÎïÀí´ÅÅÌ×°Öõ½WindowsÖУ¬ £¬£¬£¬£¬£¬ÀÕË÷Èí¼þ¾Í¿ÉÒÔ¶Ôÿ¸öÐéÄâÓ²Å̾ÙÐе¥¶À¼ÓÃÜ£¬ £¬£¬£¬£¬£¬´Ó¶øÌá¸ß¼ÓÃÜËÙÂÊ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-regretlocker-ransomware-targets-windows-virtual-machines/    


6.GrowDiariesÊý¾Ý¿âÉèÖùýʧй¶200Íò´óÂéݪֲÕßÐÅÏ¢


6.png


GrowDiariesÒòÊý¾Ý¿âÉèÖùýʧµ¼ÖÂ200Íò´óÂéݪֲÕßÐÅϢй¶ ¡£¡£¡£¡£¡£¡£¡£GrowDiariesÊÇÒ»¸öÔÚÏßÂÛ̳£¬ £¬£¬£¬£¬£¬´óÂéݪֲÕß¿ÉÒÔÔÚÕâÀï½ÒÏþ¹ØÓÚËûÃÇݪֲµÄ´óÂéµÄ²©¿Í£¬ £¬£¬£¬£¬£¬²¢ÓëÆäËûÓû§¾ÙÐл¥¶¯ ¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñ×ܹ²Ð¹Â¶ÁËÁ½¸öElasticsearchÊý¾Ý¿â£¬ £¬£¬£¬£¬£¬ÆäÖÐÒ»¸ö°üÀ¨140ÍòÌõÓû§¼Í¼£¬ £¬£¬£¬£¬£¬Ð¹Â¶ÁËÓû§µÄÓû§Ãû¡¢µç×ÓÓʼþµØµãºÍIPµØµã£»£»£»£»£»¶øÁíÒ»¸öÊý¾Ý¿â°üÀ¨Áè¼Ý200ÍòÌõÓû§Êý¾Ý£¬ £¬£¬£¬£¬£¬Æäй¶ÁËGrowDiariesÍøÕ¾ÉÏÐû²¼µÄÓû§ÎÄÕºÍÓû§µÄÕÊ»§ÃÜÂë ¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬ £¬£¬£¬£¬£¬Ì»Â¶Êý¾Ý¿âÒѱ»±£»£»£»£»£»¤ÆðÀ´ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/configuration-snafu-exposes-passwords-for-two-million-marijuana-growers/