Microsoft°ä²¼Windows´ø±í°²È«¸üУ¬½¨¸´ÌáȨ·ì϶£»Concrete5 CMS´æÔÚRCE·ì϶£¬¿Éµ¼Ö·þÎñÆ÷±»ÊÕÊÜ
°ä²¼¹¦·ò 2020-08-201.Microsoft°ä²¼Windows´ø±í°²È«¸üУ¬½¨¸´ÌáȨ·ì϶

MicrosoftΪWindows 8.1ºÍWindows Server 2012 R2°ä²¼ÁË´ø±í°²È«¸üУ¬Ö¼ÔÚ½¨¸´ÌáȨ·ì϶£¬¸Ã·ì϶»áÓ°ÏìWindowsÔ¶³Ì½Ó¼û·þÎñ¡£Õâ´Î½¨¸´µÄÁ½¸ö·ì϶±»×·×ÙΪCVE-2020-1530ºÍCVE-2020-1537£¬¹¥»÷ÕßÔڳɹ¦ÀûÓúó¿É»ñµÃ¸ü¸ßµÄȨÏÞ¡£µ«ÊÇÔÚÀûÓÃÕâЩ·ì϶֮ǰ£¬¹¥»÷Õß±ØÒªÏÈÔÚÊܺ¦ÕßµÄÉ豸ÉϱàдִÐÐÌØÈ¨´úÂë¡£Õâ´Î¸üÐÂͨ¹ý¸üÕýWindows Remote Access´¦ÖÃÄÚ´æºÍÎļþ²Ù×÷µÄ·½Ê½À´½â¾ö·ì϶¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-issues-out-of-band-kb4578013-windows-security-update/
2.Concrete5 CMS´æÔÚRCE·ì϶£¬¿Éµ¼Ö·þÎñÆ÷±»ÊÕÊÜ

EdgescanµÄ×êÑÐÈËÔ±Åû¶ÁËConcrete5 CMSÖеĵÄÔ¶³ÌÖ´ÐдúÂ루RCE£©·ì϶£¬¿Éµ¼Ö·þÎñÆ÷±»ÆëÈ«ÊÕÊÜ£¬Ó°ÏìÁËConcrete5°æ±¾8.5.2¡£¹¥»÷ÕßÀûÓô˷ì϶ʱ£¬±ØÒªÓÐÊʵ±µÄȨÏÞ£¨ÖÎÀíÔ±½ÇÉ«£©ÄÜÁ¦½Ó¼ûÔÊÐíÎļþÀàÐÍÖ°ÄÜ£¬ÒÔ½«PHPÎļþÀàÐÍÔ̺¬ÔÚÔÊÐíµÄÀ©´óÃûÁбíÖС£Ö®ºó£¬¹¥»÷Õß½«ÉÏÔØPHP shellÒÔ½Ó¼û·þÎñÆ÷ϵͳ²¢»ñµÃ·þÎñÆ÷»òϵͳµÄÆëÈ«½ÚÔìȨ¡£¸Ã·ì϶ĿǰÒÑÔÚConcrete5°æ±¾8.5.4Öн¨¸´¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/107294/security/concrete5-cms-rce.html
3.ºÚ¿ÍÀûÓÃMailtoÁ´½Ó¹¥»÷Óʼþ¿Í»§¶Ë£¬Ö¼ÔÚÇÔÈ¡±¾µØÎļþ

µÂ¹ú×êÑÐÈËÔ±·¢ÏÖºÚ¿ÍÀûÓÃMailtoÁ´½Ó¹¥»÷Óʼþ¿Í»§¶Ë£¬ÀýÈçGNOME Evolution¡¢KDE KMail¡¢IBM / HCL NotesºÍ¾É°æ±¾µÄThunderbird£¬Ö¼ÔÚÇÔÈ¡±¾µØÎļþ¡£Mailto ÊÇÒ»ÖÖÌØÊâÀàÐ͵ÄÁ´½Ó£¬ÔÚµã»÷ÕâЩÁ´½Óʱ»á´ò¿ªÒ»¸öеĵç×ÓÓʼþ׫д»ò»Ø´ð´°¿Ú¶ø²»ÊÇÒ»¸öеÄÍøÒ³¡£ÀûÓÃÕâÖÖ¹¥»÷£¬ºÚ¿ÍÄܹ»´ÓÓû§ÏµÍ³ÇÔÈ¡Ãô¸ÐÎļþ£¬ÀýÈç¼ÓÃÜ£¨PGP£©ÃÜÔ¿¡¢SSHÃÜÔ¿¡¢ÅäÖÃÎļþ¡¢¼ÓÃÜÇ®±ÒÇ®°üÎļþ¡¢ÃÜÂë´æ´¢»ò³ÁÒªµÄÒµÎñÎĵµ£¬Ö»ÓÐËüÃÇ´æ´¢ÔÚ¹¥»÷ÕßÒÑÖªµÄÎļþõè¾¶ÖС£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/some-email-clients-are-vulnerable-to-attacks-via-mailto-links/
4.IcedIDÉý¼¶»Ø¹é£¬ÀûÓùؼü×Ö»ìºÏµÈÕ½ÊõÌӱܼì²â

Õ°²©ÍøÂç×êÑÐÈËÔ±·¢ÏÖ£¬ºÚ¿ÍÔÚ×î½üµÄÍøÂç´¹µö»î¶¯ÖÐʹÓÃÁËÉý¼¶µÄÒøÐÐľÂí·¨Ê½IcedID£¬´Ó¶øÊµÏÖÁ˶àÏîÐÂÖ°ÄÜ£¬Ô̺¬ÊÜÃÜÂë±£»¤µÄ¸½¼þ¡¢¹Ø¼ü×Ö»ìºÏºÍ×îµÍÏ޶ȵĺê´úÂë¡£IcedIDбäÌåÊÇͨ¹ý±»ÈëÇֵįóÒµÕÊ»§·Ö·¢£¬²¢Óùؼü×Ö»ìºÏµÄ·½Ê½ÌÓ¹ý´¹µöÓʼþ¹ýÂËÆ÷µÄ¼ì²â¡£¶øºóÔö³¤´øÓÐÃÜÂëµÄ¸½¼þ£¬²¢Ðû³ÆÃÜÂëÔÚÓʼþÕýÎÄÖÐÒÔÓÕʹÊܺ¦Õß´ò¿ªÎļþ¡£ÎļþÖÐÔ̺¬ÓкêWordÎĵµ£¬µ±Êܺ¦Õß´ò¿ªºó±ã»á×°ÖÃľÂí·¨Ê½IcedID¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/icedid-trojan-rebooted-evasive-tactics/158425/
5.Â×¶ØÊý¾ÝÖÐÐÄUPS¹ÊÕÏÖ·þÎñÖжϣ¬¶à¸öISPÔËÓªÉÌÊÜÓ°Ïì

Â×¶Ø»¥ÁªÍøÂòÂôËùÊý¾ÝÖÐÐĵÄUPS²úÉú¹ÊÕϵ¼Ö·þÎñÖжϣ¬¶à¸öISPºÍµçÐŹ«Ë¾ÊÜÓ°Ïì¡£Equinix°µÊ¾£¬8ÔÂ18ÈÕÁ賿4µã40·Ö£¬Equinix IBX LD8²úÉúÁËÍ£µç²¢³öÏÖÁË»ð¾¯(ûÓлð¾¯)£¬µ¼ÖÂEquinixµÄLD8Êý¾ÝÖÐÐĹعء£¾µ÷²é£¬¸ÃÊÂÎñÊÇÓÉÒ»¸ö¹ÊÕϵÄUPSϵͳÒýÆðµÄ¡£Õâ´ÎÑϳÁµÄ·þÎñÖжϣ¬Ó°ÏìÁËÉϰټÒÖ÷»ú¡¢ÔÆÍÆËãºÍµçÐŲ¿ÃŵĿͻ§£¬Ô̺¬Ó¢¹úµçÐÅ(BT)¡¢Ìì¿Õ¹ã²¥¹«Ë¾(Sky)ºÍάÕäýÌå(Virgin Media)µÈ»¥ÁªÍø·þÎñÌṩÉÌ¡£
ÔÎÄÁ´½Ó£º
https://www.theregister.com/2020/08/18/outage_london_internet_exchange/
6.AI¹«Ë¾Cense¹«¿ªÒò´æ´¢¿âÅäÖÃÃýÎóй¶µÄ250ÍòÌõÒ½ÁÆÊý¾Ý

λÓÚŦԼµÄÈËΪÖÇÄܹ«Ë¾Cense¹«¿ªÁË250ÍòÌõÔ̺¬Ãô¸ÐºÍ»úÃÜÊý¾ÝµÄÒ½ÁƼͼ¡£Õâ´Îй¶ÁË2594261·ÝÒ½ÁƼͼ£¬ÆäÖÐÔ̺¬Ó×Îҿɼø±ðÐÅÏ¢(PII)ºÍÆäËûÃô¸ÐÐÅÏ¢£¬È综ÕßÐÕÃû¡¢±£Ïռͼ¡¢Ò½ÁÆÕï¶ÏºÍ¸¶¿îÐÅÏ¢¡£Security DiscoveryÊ×´´ÈËJeremiah Fowlerµ÷²éй¶ÔÒòʱ·¢ÏÖ£¬ÕâЩ¼Í¼ΪÔÝ´æÊý¾Ý£¬×÷Ϊ´æ´¢¿â£¬ÓÃÓÚÔÚCense Bot»òCenseµÄÖÎÀíϵͳÉϼÓÔØÊý¾Ý֮ǰһʱ±£ÁôÊý¾Ý£¬ÈκÎÈ˶¼Äܹ»±à×롢ɾ³ýÉõÖÁÏÂÔØÎļþ£¬¶ø²»±ØÒªÈκÎÖÎÀíÆ¾Ö¤¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/ai-firm-exposes-sensitive-medical-data-online/


¾©¹«Íø°²±¸11010802024551ºÅ