Oracle°ä²¼4Ô³ÁÒª²¹¶¡¸üУ¬½¨¸´397¸ö·ì϶£»ºÚ¿ÍÔÚ°µÍøÏúÊÛ141ÍòÃÀ¹úÒ½ÉúµÄÓ×ÎÒÊý¾Ý
°ä²¼¹¦·ò 2020-04-151.Oracle°ä²¼4Ô³ÁÒª²¹¶¡¸üУ¬½¨¸´397¸ö·ì϶
OracleÔÚÆä4Ô³ÁÒª²¹¶¡¸üÐÂÖн¨¸´ÁË397¸ö·ì϶£¬ÆäÖÐOracle Database Server²úÆ·Öн¨¸´ÁË8¸ö·ì϶£»µç×ÓÉÌÎñÌ×¼þÖн¨¸´ÁË74¸ö·ì϶£¬Ô̺¬70¸öÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓõķì϶£»OracleÈÚºÏÖÐÑë¼þÖн¨¸´ÁË51¸ö·ì϶£¬ÆäÖÐ44¸öÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓã»Java SEÖн¨¸´ÁË15¸ö·ì϶£¬ËùÓзì϶¾ùÄܹ»ÔÚ²»½øÐÐÉí·ÝÑéÖ¤µÄÇé¿öϽøÐÐÔ¶³ÌÀûÓã»MySQLÖн¨¸´ÁË45¸ö·ì϶£¬ÆäÖÐ9¸ö·ì϶ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓá£ÆëÈ«·ì϶ÁбíÇë²Î¿¼ÒÔϹٷ½Á´½Ó£¬½¨ÒéÓû§¾¡¿ìÀûÓøüС£
ÔÎÄÁ´½Ó£º
https://www.oracle.com/security-alerts/cpuapr2020.html
2.΢Èí°ä²¼4Ô°²È«¸üУ¬½¨¸´113¸ö·ì϶
΢ÈíÔÚ4Ô°²È«¸üÐÂÖн¨¸´ÁË113¸ö·ì϶£¬ÆäÖÐ15¸ö·ì϶±»¹éÀàΪÑϳÁ¼¶±ð£¬93¸ö±»¹éÀàΪ³ÁÒª£¬3¸ö±»¹éÀàΪÖеȣ¬2¸ö±»¹éÀàΪµÍΣ¡£Î¢Èí°µÊ¾ÓÐÁ½¸ö0dayÏÈǰÒѱ»¹«¿ªÅû¶£¬Ô̺¬Windows OneDriveÌØÈ¨ÌáÉý·ì϶£¨CVE-2020-0935£©ºÍAdobe Font Manager¿âÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-1020£©£¬²¢ÇÒºóÕߺÍÁíÒ»¸ö·ì϶£¨Adobe Font Manager¿âÔ¶³ÌÖ´ÐдúÂë·ì϶CVE-2020-0938£©ÒÑÔÚÒ°±í±»ÀûÓá£ÆëÈ«·ì϶²¹¶¡Çë²Î¿¼ÒÔÏÂÁ´½Ó¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2020-patch-tuesday-fixes-3-zero-days-15-critical-flaws/
3.ºÚ¿ÍÔÚ°µÍøÏúÊÛ141ÍòÃÀ¹úÒ½ÉúµÄÓ×ÎÒÊý¾Ý
¾ÝHackread.com±¨Â·£¬ÍøÂç·¸×ï·Ö×ÓÔÚ°µÍøÂÛ̳ÉÏÏúÊÛÃÀ¹ú¾³ÄÚ141ÍòÃûÒ½ÉúµÄÓ×ÎÒÐÅÏ¢¡£¾Ý³Æ¸ÃÊý¾Ý¿âÊÇ4ÔÂ11ÈÕ´ÓÔÚÏß·þÎñqa.findadoctor.comÇÔÈ¡µÄ£¬¸ÃÍøÕ¾Î»ÓÚÐÂÔóÎ÷Öݰ®µÏÉúÊУ¬ÓÉMillennium Technology Solutions¹«Ë¾Õ¼ÓС£±»µÁÊý¾ÝÖÐÔ̺¬Ò½ÉúµÄÐÕÃû¡¢ÐԱ𡢹¤×÷Ò½ÔºÃû³Æ¡¢µØÎ»¡¢ÓʼĵØÖ·¡¢ÕïËùµØÖ·¡¢¹ú¶È/µØÓò¡¢µç»°ºÅÂë¡¢Ðí¿ÉÖ¤ºÅµÈ£¬µ«²»Ô̺¬µç×ÓÓʼþµØÖ·£¬Ò²²»Ô̺¬»¼ÕßµÄÕÕÆ¬»ò²¡Àú¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/personal-data-us-doctors-sold-hacker-forum/
4.µçÉÌÍøÕ¾QuiddµÄ400ÍòÓû§ÐÅÏ¢ÔÚ°µÍø´«²¼
ÃÀ¹úµç×ÓÉÌÎñÍøÕ¾QuiddµÄÔ¼400ÍòÓû§ÕË»§Êý¾ÝÔÚ°µÍø´«²¼¡£QuiddÊÇÒ»¸öÓÃÓÚÂòÂôÌùÖ½¡¢¿¨Æ¬¡¢Íæ¾ßºÍÆäËüÕä²ØÆ·µÄÔÚÏßÊг¡£¬Êý¾ÝÐ¹Â¶ËÆºõ²úÉúÔÚ2019Ä꣬µ«QuiddÉÐδ°ä²¼Èκΰ²È«ÊÂÎñµÄ¹«¸æ£¬Ä¿Ç°Éв»Ã÷ÏԸù«Ë¾ÊÇ·ñͨ´ï¸Ãй¶ÊÂÎñ¡£ZDNet´ÓÈý¸ö·ÖÆçµÄÆðÔ´»ñÈ¡ÁËÑù±¾Êý¾Ý£¬Êý¾ÝÖÐÔ̺¬QuiddÓû§Ãû¡¢µç×ÓÓʼþµØÖ·ºÍÕË»§ÃÜÂ룬¸ÃÃÜÂëÊÇÓÉbcrypt¹þÏ£Ëã·¨±£»¤µÄ¡£´Ë±í£¬ZDNet»¹´ÓÊý¾ÝÂòÂôÉÌÄÇÀï»ñϤÕâЩÊý¾ÝÖÁÉÙ´Ó´Ó2019Äê10ÔºÍ2019Äê12ÔÂ¾ÍÆðÍ·±ðÀëÔÚºÚ¿ÍÂÛ̳ºÍPastebinÉϰ䲼¸æ°×¡£½¨ÒéQuiddÓû§¾¡¿ì¸ü¸ÄÕË»§ÃÜÂë¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/account-details-for-4-million-quidd-users-shared-on-hacking-forum/
5.APT41ÀûÓÃÐÂSpeculoosºóÃŹ¥»÷È«ÇòÆóÒµ
Palo alto NetworksµÄUnit 42×êÑÐÍŶӰ䲼¹ØÓÚAPT41й¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¸Ã¹¥»÷»î¶¯²úÉúÔÚ1ÔÂ20ÈÕÖÁ3ÔÂ11ÈÕÆÚ¼ä£¬×¨ÃÅÀûÓÃнüÅû¶µÄ·ì϶À´Õë¶ÔCitrix¡¢CiscoºÍZohoÍøÂçÉ豸¡£×êÑÐÈËÔ±»ñµÃÁËÕë¶ÔCitrixÉ豸µÄÓÐЧºÉÔØÑù±¾£¨SpeculoosºóÃÅ£©£¬ÕâЩÑù±¾ÊDZàÒëΪ¿ÉÔÚFreeBSDÉÏÔËÐеĿÉÖ´ÐÐÎļþ¡£ËùÓÐ5¸öÑù±¾µÄÎļþ´óÓ×´óÌåÒ»Ñù£¬µ«Ñù±¾¼¯Ö®¼ä´æÔÚ΢Óײî¾à£¬ÕâÅú×¢ËüÃÇ¿ÉÄÜÔ´×Ôͳһ¿ª·¢ÈËÔ±£¬²¢ÇÒ¾¹ý³ÁбàÒë»ò´ò²¹¶¡¡£SpeculoosÖØÒªÀûÓÃCitrix Application Delivery Controller¡¢Citrix GatewayºÍCitrix SD-WAN WANOPÉ豸Öеķì϶CVE-2019-19781½øÐд«²¼¡£ÀûÓÃÕâЩÊý¾Ý£¬×êÑÐÈËԱȷ¶¨ÁËÔÚ±±ÃÀ¡¢ÄÏÃÀºÍÅ·Ö޵ȵصÄÒ½ÁÆ¡¢¸ßµµ½ÌÓý¡¢Ôì×÷Òµ¡¢µ±¾ÖºÍ¼¼Êõ·þÎñµÈÐÐÒµµÄ¶à¸öÊܺ¦Õß¡£
ÔÎÄÁ´½Ó£º
https://unit42.paloaltonetworks.com/apt41-using-new-speculoos-backdoor-to-target-organizations-globally/
6.°²È«³§Ḛ́䲼¡¶2020ÄêÍøÂçÍþв·ÀÓù»ã±¨¡·
°²È«³§ÉÌimperva°ä²¼¡¶2020ÄêÍøÂçÍþв·ÀÓù»ã±¨¡·£¬Õâ·Ý»ã±¨µ÷²éÁËÈ«Çò1200Ãû°²È«´ÓÒµÈËÔ±¶ÔÆäÃæ¶ÔµÄ°²È«ÌôÕ½µÄ¼û½âÓë¶´²ì¡£¸Ã»ã±¨µÄÖØµãÔ̺¬£ºÕë¶ÔÆóÒµµÄ³É¹¦µÄÍøÂç¹¥»÷´ïµ½´´¼Í¼µÄˮƽ-80£¥µÄ×éÖ¯ÖÁÉÙ¾ÀúÁËÒ»´Î³É¹¦µÄÍøÂç¹¥»÷£¬³¬¹ý30%µÄ×éÖ¯Ôâ·êÁËÁù´ÎÒÔÉϵĹ¥»÷£»APIÍø¹Ø¡¢Êý¾Ý¿â·À»ðǽºÍWAFÊDz¿Êð½Ï¶àµÄÀûÓ÷¨Ê½/Êý¾Ý°²È«²úÆ·£»80.1£¥µÄÊÜ·ÃÕßÒÔΪʹÓÃÒ»¸öƽ̨¼à¶½Õû¸öÀûÓ÷¨Ê½°²È«²Ö¿âÊÇ×îºÃµÄ×ö·¨£»Êý¾ÝºÍ֪ʶ²úȨµÄÃÔʧ»òʧÇÔÊÇÔÆÀûÓ÷¨Ê½°²È«·çÏÕºÍÌôÕ½µÄ³ÁÖÐÖ®³Á£»´Ë¿Ì³¬¹ýÈý·ÖÖ®Ò»£¨35.7£¥£©µÄ°²È«ÀûÓ÷¨Ê½ºÍ·þÎñÊÇͨ¹ýÔÆ½»¸¶µÄ¡£
ÔÎÄÁ´½Ó£º
https://www.imperva.com/resources/resource-library/reports/2020-cyberthreat-defense-report/


¾©¹«Íø°²±¸11010802024551ºÅ