ZoomµÄWindows¿Í»§¶ËÖÐ0day£¬¿ÉÖ´ÐÐËÁÒâ´úÂ룻VMware½¨¸´VeloCloudÖÐSQL×¢Èë·ì϶
°ä²¼¹¦·ò 2020-07-101.ACROSÅû¶ZoomµÄWindows¿Í»§¶ËÖÐ0day£¬¿ÉÖ´ÐÐËÁÒâ´úÂë
ÍøÂ簲ȫ¹«Ë¾ACROS SecurityÓÚ7ÔÂ9ÈÕÅû¶ÁËZoomµÄWindows¿Í»§¶ËÖÐ0day£¬¸Ã·ì϶»áÓ°ÏìÔËÐÐÔھɰæWindows OS£¨ÀýÈçWindows 7ºÍWindows Server 2008 R2»ò¸üÔç°æ±¾£©ÉϵÄZoom¿Í»§¶Ë¡£ACROS CEO Mitja Kolsek°µÊ¾£¬¸Ã·ì϶Äܹ»Ê¹Ô¶³Ì¹¥»÷Õßͨ¹ýÈÃÓû§Ö´ÐÐijЩ²Ù×÷£¬ÀýÈç´ò¿ªÎĵµÎļþ£¬ÔÚÊܺ¦ÕßÍÆËã»úÉÏÖ´ÐÐËÁÒâ´úÂë¡£ÔÚÕû¸ö¹¥»÷¹ý³ÌÖУ¬ÏµÍ³¶¼²»»áÏòÓû§·¢³ö°²È«ÖҸ档Ŀǰ£¬ZoomÔÚ×êÑн¨¸´¸Ã·ì϶¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/zoom-working-on-patching-zero-day-disclosed-in-its-windows-client/#ftag=RSSbaffb68
2.VMware°ä²¼°²È«¸üУ¬½¨¸´VeloCloudÖÐSQL×¢Èë·ì϶
VMware°ä²¼Á˰²È«¸üУ¬ÒÔ½¨¸´VeloCloudÖеķì϶£¬¹¥»÷Õß¿ÉÀûÓô˷ì϶À´»ñÈ¡Ãô¸ÐÐÅÏ¢¡£Õâ´Î½¨¸´µÄ·ì϶±»×·×ÙΪCVE-2020-3973£¬ÎªSQL×¢Èë·ì϶£¬ÆäÓ°ÏìÁËVeloCloudµÄVMware SD-WAN¡£¸Ã·ì϶´æÔÚµÄÔÓÉÓÚVeloCloud OrchestratorûÓнøÐÐÏàÒ˵ÄÊäÈëÑéÖ¤£¬Õâ»áµ¼ÖÂSQLäע£¬¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ8.5¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2020/07/08/vmware-releases-security-update-velocloud
3.ºÚ¿Í½Ù³Ö΢ÈíAzureÍйܵÄ240¶à¸ö×ÓÓòÃû´«²¼¶ñÒâÈí¼þ
ºÚ¿Í½Ù³ÖÁË240¶à¸öÍйÜÔÚ΢ÈíAzureµÄ×ÓÓòÃû£¬ÒÔ´«²¼¶ñÒâÈí¼þºÍ¶ñÒâChromeÀ©´ó·¨Ê½µÈÄÚÈÝ¡£Õâ´Î±»½Ù³ÖµÄÍøÕ¾Ô̺¬»ªÄÉÐֵܡ¢½Ì¿ÆÎÄ×éÖ¯¡¢¶«Ö¥¡¢Ê©ÀÖ¡¢¸ÇµÙͼƬÉç¡¢ºìÊ®×ֻᡢÎÖ¶ûÎÖ¡¢»ôÄáΤ¶û¡¢ÏÄÍþÒĺ½¿Õ¹«Ë¾¡¢Ç峺Ƶ·¡¢Î÷ÃÅ×Ó¡¢Å·Ìؿˡ¢Arm¡¢3MºÍNHSµÈ¾¡È˽ÔÖªµÄ¹«Ë¾¡£·ÖÎö¹«Ë¾Victory MediumÊ×´´ÈËEdwards°µÊ¾£¬ÌáÒéÕâ´Î¹¥»÷µÄºÚ¿Í×éÖ¯¸ÃÓ××é»îÔ¾ÁËÎåÄ꣬ƾ¾ÝËûµÄ·ÖÎö£¬¸Ã×éÖ¯µÃµ½Á˹ú¼Ê·¸×ïÍÅ»ïµÄÖ§³Ö£¬±ÈÔ¤ÆÚÒª¸´Ôӵöࡣ
ÔÎÄÁ´½Ó£º
https://www.hackread.com/microsoft-azure-hosted-subdomains-hacked-with-malware/
4.΢ÈíÖÒ¸æÀûÓöñÒâOAuthÀûÓõÄOffice 365ÍøÂç´¹µö»î¶¯
΢ÈíÖÒ¸æËµ£¬Ëæ×ÅÔ¶³Ì¹¤×÷µÄÍÆ¶¯£¬¿Í»§³ýÁËÒª°ÑÎÈ´«Í³µÄƾ֤͵ÇԺ͵ç×ÓÓʼþÍøÂç´¹µö¹¥»÷Ö®±í£¬»¹Ãæ¶ÔÆäËû°²È«Íþв£¬ÀýÕâÑù¿ÉÍøÂç´¹µö£¨Consent phishing£©¡£Consent phishingÊÇÒ»ÖÖ»ùÓÚÀûÓ÷¨Ê½µÄ¹¥»÷µÄ±äÌ壬ּÔÚΪ¶ñÒâOffice 365 OAuthÀûÓ÷¨Ê½Ìṩ¶ÔÊܺ¦ÕßOffice 365ÕÊ»§µÄ½Ó¼ûȨÏÞ¡£¹¥»÷³É¹¦ºó£¬¹¥»÷ÕßÄܹ»½Ó¼ûÊܺ¦ÕßµÄÓʼþ¡¢Îļþ¡¢ÁªÏµÈË¡¢±ã¼ã¡¢ÅäÖÃÎļþÒÔ¼°´æ´¢ÔÚ¹«Ë¾´æ´¢ÏµÍ³SharePointºÍOneDrive for BusinessÔÆÖеÄÃô¸ÐÐÅÏ¢µÈ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-warns-of-office-365-phishing-via-malicious-oauth-apps/
5.½ü3Ä꣬KeeperÍÅ»ïÒÑÌáÒéÕë¶ÔÈ«Çò570¶àÍøÕ¾µÄ¹¥»÷»î¶¯
Gemini Advisory°ä²¼Á˶ԺڿÍ×éÖ¯Keeper MagecartµÄ·ÖÎö»ã±¨£¬·¢ÏÔìä×Ô2017Äê4ÔÂ1ÈÕÒÔÀ´£¬¶ÔÈ«Çò55¸ö¹ú¶ÈÖеÄ570¶àÔÚÏßÉ̳ÇÌáÒéÁËMagecart¹¥»÷»î¶¯¡£×êÑз¢ÏÖ£¬keeperÊÇÓÉ64¸öÓÃÓÚ·Ö·¢¶ñÒâÈí¼þµÄ¹¥»÷ÓòºÍ73¸öÓÃÓڽӹܱ»µÁÊý¾ÝµÄÉøÈëÓò×é³É¡£´óÎÞÊýÊܺ¦ÍøÕ¾¶¼ÍйÜÔÚÃÀ¹ú£¬Æä´ÎÊÇÓ¢¹ú¡¢ºÉÀ¼¡¢·¨¹ú¡¢Ó¡¶ÈµÈ¡£´Ë±í£¬¸Ã×éÖ¯¸ÃżȻ»¹»áʹÓù«¹²ºÍ×Ô½ç˵»ìºÏµÄ²½Ö裬ÒÔʹÆä¶ñÒâ¾ç±¾¸üÄѱ»¼ì²âµ½¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/07/08/magecart-group-8/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+HelpNetSecurity+%28Help+Net+Security%29
6.»ã±¨ÏÔʾ£¬Ä¿Ç°ÓÐ150ÒÚInternet·þÎñƾ֤ÔÚ°µÍøÏúÊÛ
Digital ShadowsµÄÒ»·Ý»ã±¨Ö¸³ö£¬Ä¿Ç°ÓÉÓÚ10Íò´ÎÊý¾Ýй¶ÊÂÎñµ¼ÖµÄ150ÒÚ¸ö±»µÁInternet·þÎñƾ֤ÔÚ°µÍøÏúÊÛ¡£ÕâЩƾ֤ÔÚ½Ó¼ûȨÏ޺ͼÛÖµÉϸ÷²»Ò»Ñù£¬Ô̺¬´ÓÒøÐÐÕÊ»§£¨Õ¼ËùÓÐÍ´´¦µÄ25£¥£©µ½ÊÓÆµºÍÒôÀÖÁ÷·þÎñµÈËùÓÐÄÚÈݵÄÓû§ÃûºÍÃÜÂë¡£ÆäÖУ¬ÒøÐÐºÍÆäËû½ðÈÚÕË»§µÄƾ֤ÊÇ×îÊÜӽӵģ¬Ò²ÊÇ×î°º¹óµÄ£¬¾ùÔÈÊÛ¼ÛΪ70.91ÃÀÔª¡£Æä´ÎÊÇÓÃÓÚ½Ó¼û·À²¡¶¾Èí¼þµÄÊý¾Ý£¬¾ùÔÈÊÛ¼ÛΪ21.67ÃÀÔª¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/15-billion-credentials-currently-up-for-grabs-on-hacker-forums/157247/


¾©¹«Íø°²±¸11010802024551ºÅ