Microsoft°ä²¼Office°²È«¸üУ¬½¨¸´ÁËÉí·ÝÑéÖ¤µÈÎÊÌ⣻°ÄÖÞ¹«Ë¾Toll GroupÓÖÔâÀÕË÷Èí¼þ¹¥»÷
°ä²¼¹¦·ò 2020-05-071.Microsoft°ä²¼Office°²È«¸üУ¬½¨¸´ÁËÉí·ÝÑéÖ¤µÈÎÊÌâ
Microsoft°ä²¼ÁËÕë¶ÔMicrosoft OfficeµÄ5Ô¸üУ¬½¨¸´ÁËÕë¶ÔÆß¸ö·ÖÆç²úÆ·µÄ55¸ö°²È«ÎÊÌâ²¢°ä²¼ÁËÎå¸öÀÛ»ý¸üУ¬Ó°ÏìÁËMicrosoft Office 2016Ì×¼þ¡¢Microsoft Outlook 2016£¬Microsoft PowerPoint 2016¡¢Microsoft Project 2016¡¢Microsoft Word 2016ºÍSkype for Business 2015²úÆ·¡£Õâ´Î¸üн¨¸´µÄ½ÏΪÑϳÁµÄÎÊÌâÊÇMicrosoft Office 2016ÖÐÆôÓÃÍÑ»úÉí·ÝÑé֤ʱÏÔʾ¿ÕȱÉí·ÝÑéÖ¤ÌáÐѵÄÎÊÌ⣬ºÍPowerPoint 2016µÄÉí·ÝÑéÖ¤ÎÊÌâ¡£Áí±í£¬Õâ´Î°ä²¼µÄ¸üкÏÓÃÓÚ»ùÓÚMicrosoft Installer£¨.msi£©µÄOffice²úÆ·£¬¶ø²»ºÏÓÃÓÚOffice¶©ÔÄ»òOffice 2016 Click-to-Run°æ±¾£¬ÀýÈçMicrosoft Office 365 Home¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-may-office-updates-with-fixes-for-auth-issues/
2.Èí¼þ¹«Ë¾SAP°ä·¢Æä²úÆ·´æÔÚ·ì϶£¬»ò½«Ó°Ïì9£¥Óû§
µÂ¹úÈí¼þ¹«Ë¾SAP°µÊ¾£¬ÔÚÄÚ²¿°²È«Éó²éʱ·¢ÏÔìäÆß¸öÔÆ²úÆ·´æÔÚ°²È«·ì϶£¬²¢ÔÚÖÜÒ»°ä·¢½«·ì϶֪ͨÊÜÓ°ÏìµÄµÄÓû§£¬Ô¼ÄªÎªÈ«Êý44ÍòÓû§µÄ9£¥¡£Õâ´ÎÊÜÓ°ÏìµÄ7¿î²úƷΪSAP Success Factors¡¢SAP Concur¡¢ SAP/CallidusCloud Commissions¡¢ SAP/Callidus Cloud CPQ¡¢ SAP C4C/Sales Cloud¡¢ SAP Cloud Platform ºÍ SAP Analytics Cloud¡£ÓÉÓÚÕâЩ·ì϶ÉÐδµÃµ½½¨¸´£¬ËùÒԸù«Ë¾Ä¿Ç°ÉÐδ¾ßÌå×¢Ã÷Óйطì϶µÄÐÅÏ¢£¬µ«SAP°µÊ¾£¬½«ÓÚ2020ÄêµÚ¶þ¼¾¶ÈʵÏÖÊÜÓ°ÏìµÄ²úÆ·µÄ°²È«¸üС£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/sap-notifying-9-of-customers-about-security-bugs-in-some-cloud-products/
3.ºÚ¿Í×éÖ¯ÔÚ´ÓǰһÖÜÄÚ½Ù³Ö½ü100Íò¸öWordPressÍøÕ¾
°²È«¹«Ë¾Wordfence·¢³öÖҸ棬һ¸öºÚ¿Í×éÖ¯ÔÚ´ÓǰµÄ7ÌìÄÚÒÑÊÔͼ½Ù³Ö½ü100Íò¸öWordPressÍøÕ¾¡£¸Ã¹«Ë¾°µÊ¾£¬×Ô4ÔÂ28ÈÕÒÔÀ´£¬Õâ¸öºÚ¿Í×éÖ¯Ò»ÏòÔÚ½øÐдó¹æÄ£µÄºÚ¿Í»î¶¯£¬Ö±µ½×î½ü¼¸Ìì¹¥»÷Á¿²ÅÕæÕý¼ÓÇ¿¡£¸Ã×éÖ¯´Ó³¬¹ý2.4Íò¸ö·ÖÆçµÄIPµØÖ·ÌáÒéÁ˹¥»÷£¬²¢ÊÔͼÇÖÈë90¶àÍò¸öWordPressÍøÕ¾¡£¹¥»÷ÔÚ5ÔÂ3ÈÕ´ïµ½¶¥·å£¬Æä¶Ô50Íò¸öÓòÌáÒéÁ˳¬¹ý2000Íò´Î¹¥»÷¡£¾ÝWordfence±¨Â·£¬¸Ã×éÖ¯ÖØÒªÊÇÀûÓÃXSS·ì϶ÔÚÍøÕ¾ÉÏÖ²Èë¶ñÒâJavaScript´úÂ룬ÒÔ½«´«ÈëÁ÷Á¿³Á¶¨Ïòµ½¶ñÒâÍøÕ¾µÄ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/a-hacker-group-tried-to-hijack-900000-wordpress-sites-over-the-last-week/
4.Naughty Dog²¹¶¡´æÔÚ·ì϶£¬¿É½Ó¼ûAmazon S3ÖÐδ¿¯ÐÐÄÚÈÝ
Naughty Dog°ä²¼µÄ²¹¶¡·¨Ê½ÖдæÔÚÒ»¸ö·ì϶£¬Ê¹ºÚ¿Í¿ÉÄܽӼû´æ´¢ÔÚAmazon S3ÖеÄThe Last of UsµÚ¶þ²¿ÃÅÖÐδ¿¯ÐеÄÄÚÈÝ¡£Ô¼ÄªÒ»ÖÜǰ£¬ÓÎÏ·µÄ¾ç͸ÊÓÆµ±»°ä²¼µ½ÁËÍøÉÏ£¬¼¤·¢ÁËÍæ¼ÒµÄÇ¿ÁÒ»áÉÌ£¬Ò²ÎªÓÎÏ·¿ª·¢ÉÌ´øÀ´Ëðʧ¡£¾ÝÐÂÎűà×ëJason Schreier±¨Â·£¬Õâ´ÎÊý¾Ýй¶¹¦·òÊÇÓÉÓÚÀϾɵÄÓÎÏ·²¹¶¡´æÔÚ·ì϶µ¼Öµġ£Õâ´Î¹¥»÷À´×Ôδ֪µÄºÚ¿Í¼¯Ì壬ËûÃÇÀûÓø÷ì϶½Ó¼ûÁËNaughty DogʹÓõÄAmazon·þÎñÆ÷¡£ÔÚ3ÔÂʱ£¬ºÚ¿Í±ãÇÔÈ¡²¢Ð¹Â¶ÁËÖÁÉÙ1TBµÄ4ÔÂÒª°ä²¼µÄÊý¾ÝºÍËØ²Ä¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/game-patch-gives-hackers-access-to-development-content-on-amazon-s3/
5.ºÚ¿ÍÀûÓÃCisco WebexÌáÒé´¹µö¹¥»÷£¬ÒÔÇÔÈ¡Óû§Æ¾Ö¤
×î½ü³öÏÖÁËеÄÍøÂç´¹µö¹¥»÷»î¶¯£¬¹¥»÷ÕßʹÓÃαÔìµÄCisco WebexÖ¤ÊéÃýÎóÖҸ棬ÒÔÇÔÈ¡Óû§µÄÕÊ»§Í´´¦¡£¾ÝÓʼþ°²È«¹«Ë¾Abnormal Securityͳ¼ÆµÄÊý¾Ý£¬Õâ´ÎÊÂÎñÒѹ¥»÷³¬¹ý5000¸öÊܺ¦Õß¡£¹¥»÷ÕßʹÓÿË¡µÄͼÐκÍÌåʽÀ´·ÂðCisco WebEx·¢Ë͸øÓû§µÄ×Ô¶¯SSLÖ¤ÊéÃýÎ󾯱¨£¬²¢ÖÒ¸æÊܺ¦Õ߯äÒòWebex Meetings SSLÖ¤ÊéÃýÎóÒѱ»ÖÎÀíÔ±×èÖ¹£¬±ØÐëÑéÖ¤ÕÊ»§£¬´Ó¶øÓÕʹËûÃǵã»÷µÇ¼µÄÁ´½ÓÒÔ½âËøÕÊ»§¡£Ö®ºó¸ÃÁ´½Ó±ã»á½«Óû§³Á¶¨Ïòµ½ÍøÂç´¹µöÍøÕ¾£¬²¢ÇÔÈ¡ÆäµÇ½ƾ֤¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/cisco-webex-phishing-uses-fake-cert-errors-to-steal-credentials/
6.°ÄÖÞ¹«Ë¾Toll GroupÓÖÔâÀÕË÷Èí¼þ¹¥»÷£¬ÎªNefilimÍÅ»ï½øÐÐ
2020Äê5ÔÂ5ÈÕ£¬°Ä´óÀûÑÇÎïÁ÷¹«Ë¾Toll GroupÔÚÈý¸öÔÂÄÚÓÖÒ»´ÎÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂËûÃÇÔٴιعØÁËϵͳ£¬¾Ýµ÷²éÕâ´Î¹¥»÷ÊÇÓɺڿÍ×éÖ¯Nefilim RansomwareÌáÒéµÄ¡£Toll GroupÔÚ2020Äê2ÔÂ5ÈÕµÚÒ»´Î°ä·¢£¬ËûÃÇÔâµ½ÁËÀÕË÷Èí¼þMailtoµÄ±äÖֵĹ¥»÷£¬²¢±»ÒªÇ󹨹ØÏµÍ³¡£¾Ý×êÑÐÈËÔ±µ÷²é£¬µÚ¶þ´Î¹¥»÷ÖкڿÍÒÀÈ»ÀûÓÃÁËCtrix ADC Netscaler·þÎñÆ÷£¬ÕâÒ²ÊǵÚÒ»´Î¹¥»÷Öй¥»÷ÕßËùÀûÓõķþÎñÆ÷¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/toll-group-hit-by-ransomware-a-second-time-deliveries-affected/


¾©¹«Íø°²±¸11010802024551ºÅ