΢ÈíÐû²¼×î´ó¹æÄ£Öܶþ²¹¶¡ÐÞ¸´129¸öÎó²î£»£»£»UPnPЭÒéÖеÄÎó²îCallStranger£¬£¬£¬£¬£¬ £¬£¬¿Éµ¼ÖÂÊý¾Ýй¶»òDDoS¹¥»÷

Ðû²¼Ê±¼ä 2020-06-10

1.΢ÈíÐû²¼×î´ó¹æÄ£µÄÖܶþ²¹¶¡³ÌÐò£¬£¬£¬£¬£¬ £¬£¬¹²ÐÞ¸´129¸öÎó²î


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


΢ÈíÓÚ6ÔÂ9ÈÕÐû²¼ÁË×î´ó¹æÄ£µÄÐÇÆÚ¶þ²¹¶¡³ÌÐò£¬£¬£¬£¬£¬ £¬£¬¹²ÐÞ¸´ÁËMicrosoft²úÆ·ÖеÄ129¸öÎó²î¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬ £¬£¬Microsoft EdgeºÍVBScriptÒýÇæÖб£´æÈý¸ö½ÏΪÑÏÖØµÄÎó²î£¬£¬£¬£¬£¬ £¬£¬»®·ÖÊÇMicrosoftä¯ÀÀÆ÷ÄÚ´æËð»µÎó²î£¨CVE-2020-1219£©¡¢VBScriptÔ¶³ÌÖ´ÐдúÂëÎó²î£¨CVE-2020-1216£©ºÍVBScriptÔ¶³ÌÖ´ÐдúÂëÎó²î£¨CVE-2020-1216£©£¬£¬£¬£¬£¬ £¬£¬ÕâЩÎó²î¿É±»Ê¹ÓÃÀ´Ö´ÐÐÔ¶³Ì´úÂëÖ´ÐС£¡£¡£»£»£ÉÐÓÐһЩ½ÏΪÑÏÖØµÄÎó²î¿É±»ÓÃÓÚÍøÂç´¹ÂÚ¹¥»÷ÒÔÓÕʹÓû§ÏÂÔØ¶ñÒâÎļþ£¬£¬£¬£¬£¬ £¬£¬»®·ÖÊÇGDI +Ô¶³ÌÖ´ÐдúÂëÎó²î£¨CVE-2020-1248£©¡¢Windows OLEÔ¶³ÌÖ´ÐдúÂëÎó²î£¨CVE-2020-1281£©¡¢ºÍLNKÔ¶³ÌÖ´ÐдúÂëÎó²î£¨CVE-2020-1299£©¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2020-patch-tuesday-largest-ever-with-129-fixes/


2.UPnPЭÒéÖеÄÎó²îCallStranger£¬£¬£¬£¬£¬ £¬£¬¿Éµ¼ÖÂÊý¾Ýй¶»òDDoS¹¥»÷


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Çå¾²¹¤³ÌʦYunus?adirci·¢Ã÷ÔÚͨÓü´²å¼´ÓÃЭÒ飨Universal Plug and Play£¬£¬£¬£¬£¬ £¬£¬UPnP£©Öб£´æÃûΪCallStrangerµÄÎó²î£¨CVE-2020-12695£©£¬£¬£¬£¬£¬ £¬£¬¿ÉÄܵ¼ÖÂÊý¾Ýй¶¡¢DDoS¹¥»÷ÒÔ¼°¶Ô×°±¸ÄÚ²¿¶Ë¿ÚµÄɨÃè¡£¡£¡£¸ÃÎó²î¿ÉÄÜ»áÓ°ÏìËùÓÐ4ÔÂ17ÈÕ֮ǰ°æ±¾µÄUPnP×°±¸£¬£¬£¬£¬£¬ £¬£¬°üÀ¨Windows 10ϵͳ¡¢Â·ÓÉÆ÷¡¢½ÓÈëµã¡¢´òÓ¡»ú¡¢ÓÎÏ·»ú¡¢ÃÅÁåµç»°¡¢Ã½ÌåÓ¦ÓóÌÐòºÍ×°±¸¡¢Ïà»ú¡¢µçÊÓ»úµÈ¡£¡£¡£¸ÃÎó²îÊÇÓÉUPnP SUBSCRIBEº¯ÊýÖеıêÍ·Öµ»Øµ÷ÒýÆðµÄ£¬£¬£¬£¬£¬ £¬£¬¹¥»÷Õß¿ÉÒԽṹһ¸öº¬ÖøÃûÌùýʧµÄ±êÍ·Öµ»Øµ÷µÄTCPÊý¾Ý°ü·¢Ë͵½Ô¶¶Ë×°±¸£¬£¬£¬£¬£¬ £¬£¬À´Ê¹Óû¥ÁªÍøÉÏÖ§³ÖUPnPЭÒéµÄÖÇÄÜ×°±¸¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/callstranger-upnp-bug-allows-data-theft-ddos-attacks-lan-scans/


3.Ó¦ÓÃDigilocker±£´æÎó²î£¬£¬£¬£¬£¬ £¬£¬¿É±»Ê¹ÓÃÈÆ¹ýÉí·ÝÑéÖ¤


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÓÉÓ¡¶Èµç×ÓºÍIT²¿·Öƾ֤ÆäDigital IndiaÍýÏëÌṩµÄÔÚÏßЧÀͳÌÐòDigilocker±£´æÎó²î£¬£¬£¬£¬£¬ £¬£¬¸ÃÎó²î¿ÉÄÜÒѾ­±»Ê¹ÓÃÈÆ¹ýÉí·ÝÑéÖ¤¡£¡£¡£Çå¾²Ñо¿Ô±Mohesh MohanÌåÏÖ£¬£¬£¬£¬£¬ £¬£¬DigilockerµÄOTP¹¦Ð§È±·¦ÊÚȨ£¬£¬£¬£¬£¬ £¬£¬µ¼Ö¹¥»÷Õß¿ÉÒÔͨ¹ýÌá½»ÈκÎÓÐÓÃÓû§µÄÏêϸÐÅÏ¢¾ÙÐÐOTPÑéÖ¤²¢µÇ¼£¬£¬£¬£¬£¬ £¬£¬Ò²¾ÍÊÇ˵¹¥»÷ÕßÖ»ÐèÖªµÀÓû§Aadhaar ID»òÏà¹ØµÄÊÖ»úºÅÂë»òÓû§Ãû¼´¿É»á¼ûÈκÎDigilockerÕÊ»§¡£¡£¡£5ÔÂ10ÈÕÑо¿Ö°Ô±ÏòCERT-In±¨¸æÁË´ËÎó²î£¬£¬£¬£¬£¬ £¬£¬5ÔÂ28ÈÕÓ¡¶ÈÕþ¸®Òѽ«ÆäÐÞ¸´¡£¡£¡£        


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/104459/breaking-news/digilocker-critical-falw.html


4.±¾Ì﹫˾Ôâµ½ÀÕË÷Èí¼þSNAKE¹¥»÷£¬£¬£¬£¬£¬ £¬£¬ÆäÈÕ±¾ºÍÅ·ÖÞ·Ö¹«Ë¾Êܵ½Ó°Ïì


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


±¾Ì﹫˾ÓÚ±¾ÖÜÒ»·¢Ã÷£¬£¬£¬£¬£¬ £¬£¬ÆäÅ·ÖÞºÍÈÕ±¾µÄ·Ö¹«Ë¾Ôâµ½ÁËÀÕË÷²¡¶¾SNAKEµÄ¹¥»÷£¬£¬£¬£¬£¬ £¬£¬²¢µ¼ÖÂITÍøÂçÎÞ·¨Õý³£ÔËÐС£¡£¡£¸Ã¹«Ë¾½²»°ÈËÌåÏÖ£¬£¬£¬£¬£¬ £¬£¬´Ë´Î¹¥»÷²¢Î´Ó°ÏìÈÕ±¾µÄÉú²ú»ò¾­ÏúÉ̻£¬£¬£¬£¬£¬ £¬£¬Ò²Ã»ÓÐÓ°ÏìÆä¿Í»§¡£¡£¡£Ñо¿Ö°Ô±¶ÔÀÕË÷²¡¶¾Ñù±¾¾ÙÐÐÆÊÎöºó·¢Ã÷£¬£¬£¬£¬£¬ £¬£¬¸ÃÀÕË÷Èí¼þÊ×ÏÈ»áÊÔͼÆÊÎömds.honda.comÓò£¬£¬£¬£¬£¬ £¬£¬ÈôÊÇûÓн«Á¬Ã¦Í˳ö²¢²»¼ÓÃÜÈκÎÎļþ¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬ £¬£¬¸Ã¹«Ë¾ÌåÏÖÕýÔÚÊÓ²ìÊÂÎñÔµ¹ÊÔ­ÓÉ£¬£¬£¬£¬£¬ £¬£¬²¢¾Ü¾øÍ¸Â¶¸ü¶àϸ½Ú¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/honda-investigates-possible-ransomware-attack-networks-impacted/


5.º«¹úÐÅÓÃЭ»áÌåÏÖ£¬£¬£¬£¬£¬ £¬£¬Ô¼90ÍòÕź«¹úÐÅÓÿ¨ÐÅÏ¢ÔÚ°µÍøÐ¹Â¶


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


º«¹úÐÅÓÃЭ»á±¾ÖÜÒ»ÌåÏÖ£¬£¬£¬£¬£¬ £¬£¬Ô¼ÓÐ90ÍòÕź«¹úÐÅÓÿ¨ÐÅÏ¢Òѱ»Ð¹Â¶£¬£¬£¬£¬£¬ £¬£¬²¢ÔÚ°µÍøÉϾÙÐÐÊÛÂô¡£¡£¡£º«¹úÖÕÉó·¨ÔºËµÃ÷£¬£¬£¬£¬£¬ £¬£¬±»Ð¹Â¶µÄÐÅÓÿ¨ÖÐԼĪÓÐ41ÍòÕÅÈÔÔÚʹÓÃÖУ¬£¬£¬£¬£¬ £¬£¬×ß©µÄÐÅÏ¢°üÀ¨¿¨ºÅ¡¢ÓÐÓÃÆÚºÍÑéÖ¤Âë¡¢¿¨±³ÃæµÄÈýλÊýÇå¾²Â룬£¬£¬£¬£¬ £¬£¬²¢²»°üÀ¨ÃÜÂë¡£¡£¡£º«¹úÕþ¸®ÏÖÔÚÉÐδŪÇåÕâЩÐÅÏ¢ÊÇÔõÑù×ß©µÄ£¬£¬£¬£¬£¬ £¬£¬ÐÅÓÿ¨ÒøÐÐÔòÌåÏֻὫÐÅϢй¶ÎÊÌâ֪ͨÊÜÓ°ÏìµÄÓû§£¬£¬£¬£¬£¬ £¬£¬²¢½¨ÒéËûÃÇÌæ»»Ð¿¨¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://en.yna.co.kr/view/AEN20200608011200325?&web_view=true


6.¼ÓÄÃÖÁ¹«Ë¾Fitness DepotÔâµ½Magecart¹¥»÷£¬£¬£¬£¬£¬ £¬£¬Óû§Ö§¸¶ÐÅϢй¶


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


¼ÓÄôóÔ˶¯Æ÷²Ä¹«Ë¾Fitness DepotÐû²¼£¬£¬£¬£¬£¬ £¬£¬ÉϸöÔ¹«Ë¾µÄµçÉÌÆ½Ì¨Ôâµ½¹¥»÷£¬£¬£¬£¬£¬ £¬£¬Æä¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢ºÍÖ§¸¶ÐÅϢй¶¡£¡£¡£´Ë´Îй¶ÐÅÏ¢°üÀ¨¿Í»§µÄÐÕÃû¡¢µØµã¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂëºÍÐÅÓÿ¨ºÅ¡£¡£¡£Fitness DepotÌåÏÖ£¬£¬£¬£¬£¬ £¬£¬¸Ãй¶ÊÂÎñ¿É×·Ëݵ½2020Äê2ÔÂ18ÈÕ£¬£¬£¬£¬£¬ £¬£¬ºÚ¿Í½«¶ñÒâ´úÂë×¢ÈëÍøÕ¾£¬£¬£¬£¬£¬ £¬£¬Ê¹µÃÓû§Ò»µ©±»Öض¨Ïòµ½´Ë±íµ¥¾Í»áÔÚ²»ÖªÇéµÄÇéÐÎϱ»¸´ÖÆÐÅÏ¢¡£¡£¡£Ñо¿Ö°Ô±ÆÊÎö£¬£¬£¬£¬£¬ £¬£¬´Ë´Î¹¥»÷ºÜ¿ÉÄÜÊÇÀ´×ÔºÚ¿Í×éÖ¯Magecart£¬£¬£¬£¬£¬ £¬£¬ÆäÏÈÈëÇÖÁ˸ù«Ë¾µÄµçÉÌÆ½Ì¨£¬£¬£¬£¬£¬ £¬£¬²¢½«»ùÓÚJavaScriptµÄ¶ñÒâ´úÂë×¢ÈëÆä½áÕÊÒ³Ãæ£¬£¬£¬£¬£¬ £¬£¬×îÖÕÄ¿µÄÊÇÇÔÈ¡¸Ã¹«Ë¾¿Í»§ËùÌá½»µÄËùÓи¶¿î»òСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fitness-depot-hit-by-data-breach-after-isp-fails-to-activate-the-antivirus/