΢Èí°ä²¼×î´ó¹æÄ£Öܶþ²¹¶¡½¨¸´129¸ö·ì϶ £»UPnPºÍ̸Öеķì϶CallStranger £¬¿Éµ¼ÖÂÊý¾Ýй¶»òDDoS¹¥»÷

°ä²¼¹¦·ò 2020-06-10

1.΢Èí°ä²¼×î´ó¹æÄ£µÄÖܶþ²¹¶¡·¨Ê½ £¬¹²½¨¸´129¸ö·ì϶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


΢ÈíÓÚ6ÔÂ9ÈÕ°ä²¼ÁË×î´ó¹æÄ£µÄÐÇÆÚ¶þ²¹¶¡·¨Ê½ £¬¹²½¨¸´ÁËMicrosoft²úÆ·ÖеÄ129¸ö·ì϶¡£ÆäÖÐ £¬Microsoft EdgeºÍVBScriptÒýÇæÖдæÔÚÈý¸ö½ÏΪÑϳÁµÄ·ì϶ £¬±ðÀëÊÇMicrosoftä¯ÀÀÆ÷ÄÚ´æ°Ü»µ·ì϶£¨CVE-2020-1219£©¡¢VBScriptÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-1216£©ºÍVBScriptÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-1216£© £¬ÕâЩ·ì϶¿É±»ÀûÓÃÀ´Ö´ÐÐÔ¶³Ì´úÂëÖ´ÐС £»¹ÓÐһЩ½ÏΪÑϳÁµÄ·ì϶¿É±»ÓÃÓÚÍøÂç´¹µö¹¥»÷ÒÔÓÕʹÓû§ÏÂÔØ¶ñÒâÎļþ £¬±ðÀëÊÇGDI +Ô¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-1248£©¡¢Windows OLEÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-1281£©¡¢ºÍLNKÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-1299£©¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2020-patch-tuesday-largest-ever-with-129-fixes/


2.UPnPºÍ̸Öеķì϶CallStranger £¬¿Éµ¼ÖÂÊý¾Ýй¶»òDDoS¹¥»÷


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


°²È«¹¤³ÌʦYunus?adirci·¢´Ë¿ÌͨÓü´²å¼´ÓúÍ̸£¨Universal Plug and Play £¬UPnP£©ÖдæÔÚÃûΪCallStrangerµÄ·ì϶£¨CVE-2020-12695£© £¬¿ÉÄܵ¼ÖÂÊý¾Ýй¶¡¢DDoS¹¥»÷ÒÔ¼°¶ÔÉ豸ÄÚ²¿¶Ë¿ÚµÄɨÃè¡£¸Ã·ì϶¿ÉÄÜ»áÓ°ÏìËùÓÐ4ÔÂ17ÈÕ֮ǰ°æ±¾µÄUPnPÉ豸 £¬Ô̺¬Windows 10ϵͳ¡¢Â·ÓÉÆ÷¡¢½ÓÈëµã¡¢´òÓ¡»ú¡¢ÓÎÏ·»ú¡¢ÃÅÁåµç»°¡¢Ã½ÌåÀûÓ÷¨Ê½ºÍÉ豸¡¢Ïà»ú¡¢µçÊÓ»úµÈ¡£¸Ã·ì϶ÊÇÓÉUPnP SUBSCRIBEº¯ÊýÖеıêÍ·Öµ»Øµ÷ÒýÆðµÄ £¬¹¥»÷ÕßÄܹ»»ú¹ØÒ»¸öº¬ÓÐÌåʽÃýÎóµÄ±êÍ·Öµ»Øµ÷µÄTCPÊý¾Ý°ü·¢Ë͵½Ô¶¶ËÉ豸 £¬À´ÀûÓû¥ÁªÍøÉÏÖ§³ÖUPnPºÍ̸µÄÖÇÄÜÉ豸¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/callstranger-upnp-bug-allows-data-theft-ddos-attacks-lan-scans/


3.ÀûÓÃDigilocker´æÔÚ·ì϶ £¬¿É±»ÀûÓÃÈÆ¹ýÉí·ÝÑéÖ¤


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÓÉÓ¡¶Èµç×ÓºÍIT²¿ÃÅÆ¾¾ÝÆäDigital India´òËãÌṩµÄÔÚÏß·þÎñ·¨Ê½Digilocker´æÔÚ·ì϶ £¬¸Ã·ì϶¿ÉÄÜÒѾ­±»ÀûÓÃÈÆ¹ýÉí·ÝÑéÖ¤¡£°²È«×êÑÐÔ±Mohesh Mohan°µÊ¾ £¬DigilockerµÄOTPÖ°Äܲ»×ãÊÚȨ £¬µ¼Ö¹¥»÷ÕßÄܹ»Í¨¹ýÌá½»ÈκÎÓÐЧÓû§µÄ¾ßÌåÐÅÏ¢½øÐÐOTPÑéÖ¤²¢µÇ¼ £¬Ò²¾ÍÊÇ˵¹¥»÷ÕßÖ»Ðè֪·Óû§Aadhaar ID»òÓйصÄÊÖ»úºÅÂë»òÓû§Ãû¼´¿É½Ó¼ûÈκÎDigilockerÕÊ»§¡£5ÔÂ10ÈÕ×êÑÐÈËÔ±ÏòCERT-In»ã±¨ÁË´Ë·ì϶ £¬5ÔÂ28ÈÕÓ¡¶Èµ±¾ÖÒѽ«Æä½¨¸´¡£        


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/104459/breaking-news/digilocker-critical-falw.html


4.±¾Ì﹫˾Ôâµ½ÀÕË÷Èí¼þSNAKE¹¥»÷ £¬ÆäÈÕ±¾ºÍÅ·ÖÞ·Ö¹«Ë¾Êܵ½Ó°Ïì


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


±¾Ì﹫˾ÓÚ±¾ÖÜÒ»·¢ÏÖ £¬ÆäÅ·ÖÞºÍÈÕ±¾µÄ·Ö¹«Ë¾Ôâµ½ÁËÀÕË÷²¡¶¾SNAKEµÄ¹¥»÷ £¬²¢µ¼ÖÂITÍøÂçÎÞ·¨Õý³£ÔËÐС£¸Ã¹«Ë¾½²»°È˰µÊ¾ £¬Õâ´Î¹¥»÷²¢Î´Ó°ÏìÈÕ±¾µÄ³ö²ú»ò¾­ÏúÉ̻ £¬Ò²Ã»ÓÐÓ°ÏìÆä¿Í»§¡£×êÑÐÈËÔ±¶ÔÀÕË÷²¡¶¾Ñù±¾½øÐзÖÎöºó·¢ÏÖ £¬¸ÃÀÕË÷Èí¼þÊ×ÏÈ»áÊÔͼ½âÎömds.honda.comÓò £¬ÈôÊÇûÓн«Á¢¼´Í˳ö²¢²»¼ÓÃÜÈκÎÎļþ¡£Ä¿Ç° £¬¸Ã¹«Ë¾°µÊ¾ÔÚµ÷²éÊÂÎñÔ­Òò £¬²¢»Ø¾øÐ¹Â©¸ü¶àϸ½Ú¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/honda-investigates-possible-ransomware-attack-networks-impacted/


5.º«¹úÐÅÓþЭ»á°µÊ¾ £¬Ô¼90ÍòÕź«¹úÐÅÓþ¿¨ÐÅÏ¢ÔÚ°µÍøÐ¹Â¶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


º«¹úÐÅÓþЭ»á±¾ÖÜÒ»°µÊ¾ £¬Ô¼ÓÐ90ÍòÕź«¹úÐÅÓþ¿¨ÐÅÏ¢Òѱ»Ð¹Â¶ £¬²¢ÔÚ°µÍøÉϽøÐÐÊÛÂô¡£º«¹úÖÕÉó·¨Ôº×¢Ã÷ £¬±»Ð¹Â¶µÄÐÅÓþ¿¨ÖÐԼĪÓÐ41ÍòÕÅÈÔÔÚʹÓÃÖÐ £¬Ð¹Â©µÄÐÅÏ¢Ô̺¬¿¨ºÅ¡¢ÓÐЧÆÚºÍÑéÖ¤Âë¡¢¿¨±³ÃæµÄÈýλÊý°²È«Âë £¬²¢²»Ô̺¬ÃÜÂë¡£º«¹úµ±¾ÖĿǰÉÐδŪÇåÕâЩÐÅÏ¢ÊÇÈôºÎй©µÄ £¬ÐÅÓþ¿¨ÒøÐÐÔò°µÊ¾»á½«ÐÅϢй¶ÎÊÌâ֪ͨÊÜÓ°ÏìµÄÓû§ £¬²¢½¨ÒéËûÃǸü»»Ð¿¨¡£


Ô­ÎÄÁ´½Ó£º

https://en.yna.co.kr/view/AEN20200608011200325?&web_view=true


6.¼ÓÄôó¹«Ë¾Fitness DepotÔâµ½Magecart¹¥»÷ £¬Óû§Ö§¸¶ÐÅϢй¶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¼ÓÄôó»î¶¯Æ÷²Ä¹«Ë¾Fitness Depot°ä·¢ £¬ÉϸöÔ¹«Ë¾µÄµçÉÌÆ½Ì¨Ôâµ½¹¥»÷ £¬Æä¿Í»§µÄÓ×ÎÒÐÅÏ¢ºÍÖ§¸¶ÐÅϢй¶¡£Õâ´Îй¶ÐÅÏ¢Ô̺¬¿Í»§µÄÐÕÃû¡¢µØÖ·¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂëºÍÐÅÓþ¿¨ºÅ¡£Fitness Depot°µÊ¾ £¬¸Ãй¶ÊÂÎñ¿É×·Òäµ½2020Äê2ÔÂ18ÈÕ £¬ºÚ¿Í½«¶ñÒâ´úÂë×¢ÈëÍøÕ¾ £¬Ê¹µÃÓû§Ò»µ©±»³Á¶¨Ïòµ½´Ë±íµ¥¾Í»áÔÚ²»ÖªÇéµÄÇé¿öϱ»¸´ÔìÐÅÏ¢¡£×êÑÐÈËÔ±·ÖÎö £¬Õâ´Î¹¥»÷ºÜ¿ÉÄÜÊÇÀ´×ÔºÚ¿Í×éÖ¯Magecart £¬ÆäÏÈÈëÇÖÁ˸ù«Ë¾µÄµçÉÌÆ½Ì¨ £¬²¢½«»ùÓÚJavaScriptµÄ¶ñÒâ´úÂë×¢ÈëÆä½áÕÊÒ³Ãæ £¬×îÖÕÖ¸±êÊÇÇÔÈ¡¸Ã¹«Ë¾¿Í»§ËùÌá½»µÄËùÓи¶¿î»òÓ×ÎÒÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fitness-depot-hit-by-data-breach-after-isp-fails-to-activate-the-antivirus/