Adobe°ä²¼°²È«¸üУ¬½¨¸´¶à¿î²úÆ·ÖеÄ12¸ö·ì϶£»×êÑÐÈËÔ±·¢ÏÖTeamTNT¿ÉÀûÓÃWeave ScopeÊÕÊÜÔÆÖ÷»ú
°ä²¼¹¦·ò 2020-09-101.Adobe°ä²¼°²È«¸üУ¬½¨¸´¶à¿î²úÆ·ÖеÄ12¸ö·ì϶

Adobe°ä²¼°²È«¸üУ¬Òѽ¨¸´Ó°ÏìÆäAdobe InDesign¡¢Adobe FramemakerºÍAdobe Experience Manager²úÆ·ÖеÄ12¸ö´úÂëÖ´Ðзì϶¡£Õâ´Î¸üн¨¸´ÁËAdobe InDesignÖÐÒòÄÚ´æ°Ü»µµ¼ÖµÄËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2020-9727¡¢CVE-2020-9728¡¢CVE-2020-9729¡¢CVE-2020-9730ºÍCVE-2020-9731£©£¬FramemakerÖÐÔ½½ç¶ÁÈ¡µ¼ÖµĴúÂëÖ´Ðзì϶£¨CVE-2020-9726£©ºÍ»ùÓÚ²Ö¿âµÄ»º³åÇøÒç³öµÄ´úÂëÖ´Ðзì϶£¨CVE-2020-9725 £©£¬ÒÔ¼°Experience ManagerÖеĶà¸öXSS·ì϶¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-vulnerabilities-in-indesign-and-framemaker/
2.Intel°ä²¼°²È«¸üУ¬½¨¸´ÆäAMTÖÐÑϳÁµÄÌáȨ·ì϶

Intel°ä²¼9Ô·ݰ²È«¸üУ¬×ܼƽ¨¸´ÁË9¸ö·ì϶¡£Õâ´Î½¨¸´µÄ×îÑϳÁµÄ·ì϶ΪӰÏìÁË×Ô¶¯ÖÎÀí¼¼Êõ£¨AMT£©µÄÌáȨ·ì϶£¨CVE-2020-8758£©£¬CVSSµÃ·ÖΪ9.8¡£¸Ã·ì϶ÊÇÓÉÓÚÍøÂç×ÓϵͳÖв»Êʵ±µÄ»º³åÇøÏÞ¶ÈËùÖ£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚÆóÒµÍøÂçÉÏÉý¼¶AMTϵͳÉϵÄȨÏÞ¡£¶ÔÓÚδÅäÖÃAMTµÄIntel vProϵͳÓû§À´Ëµ£¬ºÚ¿ÍÈÔ¿Éͨ¹ý±¾µØ½Ó¼û¸ÃϵͳµÄÈÏÖ¤Óû§½øÐÐÌáȨ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/intel-fixes-critical-flaw-in-corporate-remote-management-platform/
3.×êÑÐÈËÔ±·¢ÏÖTeamTNT¿ÉÀûÓÃWeave ScopeÊÕÊÜÔÆÖ÷»ú

IntezerµÄ×êÑÐÈËÔ±·¢ÏÖºÚ¿Í×éÖ¯TeamTNTÀûÓÿªÔ´¹¤¾ßWeave Scope£¬¿ÉÆëÈ«ÊÕÊÜÖ¸±êµÄÔÆÖ÷»ú¡£¾ÝIntezerÃèÊö£¬TeamTNTÊ×ÏÈͨ¹ýÒ»¸ö¶³öµÄDocker API½øÈëÖ¸±êϵͳ£¬ÒÔ´´½¨Ò»¸ö¸É¾»µÄUbuntuÈÝÆ÷£¬²¢½«ÆäÅäÖõ½Êܺ¦Õß·þÎñÆ÷ÉÏ£¬´Ó¶ø»ñµÃ¶ÔÖ÷»úÉϵÄÎļþµÄ½Ó¼ûȨÏÞ¡£Ö®ºó£¬Æä½«ÉèÖÃÒ»¸öÃûΪhildeµÄ±¾µØÓû§£¬²¢½øÐÐÌáȨÒÔͨ¹ýSSHÏνӵ½·þÎñÆ÷¡£×îºó×°ÖÃWeave Scope£¬²¢Í¨¹ý¶Ë¿Ú4040Ïνӵ½Weave ScopeÏÔʾ½çÃæ²¢»ñµÃ½ÚÔìȨ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hackers-use-legit-tool-to-take-over-docker-kubernetes-platforms/
4.¶íÂÞ˹Áª¹úͶƱÆÚ¼äÔøÔâµ½À´×ÔÓ¢ÃÀµÈ¹ú¶ÈµÄDDoS¹¥»÷

¶íÂÞ˹ÔÚ±¾ÖÜÒ»µÄÍøÂ簲ȫ»áÒéÉϰµÊ¾£¬ÆäÔÚ¶íÂÞ˹ÏÜ·¨½¨¸Ä°¸Í¶Æ±ÆÚ¼ä£¨2020Äê6ÔÂ25ÈÕÖÁ7ÔÂ1ÈÕ£©£¬Ôâµ½ÁËÀ´×ÔÓ¢ÃÀµÈ¹ú¶ÈµÄDDoS¹¥»÷¡£¶íÂÞ˹Áª¹ú×Üͳ³ö¸ñ´ú±í°µÊ¾£¬Õâ´Î»î¶¯¶ÔÖÐÑëÑ¡¾ÙίԱ»áºÍ¶íÂÞ˹ÆäËû¹ú¶È»ú¹¹µÄ»ù´¡ÉèÊ©½øÐÐÁË´ó¹æÄ£Ï®»÷£¬ÃÀ¹ú¡¢Ó¢¹ú¡¢ÎÚ¿ËÀ¼ºÍһЩ¶ÀÁªÌå¹ú¶ÈÌáÒéÁËÿÃë¸ß´ï24Íò¸öÒªÇóµÄDDoS¹¥»÷¡£´Ë±í£¬¶íÂÞ˹¹ÙÔ±»ã±¨£¬ÆäÔÚ6ÔÂ27ÈÕÍíÉÏ»¹Ôâµ½Ò»´Î³Á´ó¹¥»÷£¬ºÚ¿ÍÊÔͼͨ¹ý¼à¶½ÔÚÏßͶƱ·þÎñÀ´Ó°Ïìϵͳ¡£
ÔÎÄÁ´½Ó£º
https://www.ehackingnews.com/2020/09/ddos-attacks-from-usa-uk-ukraine-were.html
5.¹þÌØ¸£µÂÊÐITϵͳϰȾÀÕË÷Èí¼þµ¼Ö¸ÃÊпªÑ§ÍƳÙ

¹þÌØ¸£µÂÊÐITϵͳϰȾÀÕË÷Èí¼þµ¼Ö¸ÃÊпªÑ§ÍƳ١£Æ¾¾Ý¹þÌØ¸£µÂ¹«Á¢Ñ§Ìð䲼µÄÉêÃ÷£¬ÀÕË÷Èí¼þ¹¥»÷Ó°ÏìÁËѧÌõĶà¸öÄÚ²¿ITϵͳ£¬µ¼ÖÂÆä·þÎñÖжϡ£Ö»¹Ü±¾µØITÈËÔ±Ò»ÏòÔÚÖÂÁ¦¸´Ô·þÎñ£¬µ«ÊÇÒÀȻδÄÜÔÚÔ¤Ô¼µÄ¿ªÑ§ÈÕʵʱʵÏÖ¡£¸ÃÊÐÓëУ³µ¹«Ë¾Í¨Ñ¶ËùÓõÄITϵͳҲÊܵ½Ó°Ï죬µ¼ÖÂѧÌÃÎÞ·¨ÅäÖúͼලУ³µÂ·Ïߣ¬Òò¶ø¸ÃУ¾ö¶¨ÍƳٿªÑ§¹¦·ò£¬Í¬Ê±ÔÝÍ£Ô¶³Ì½ø½¨¿Î³Ì¡£±¾µØITϵͳ½¨¸´¹¦·òÉÐδȷ¶¨£¬Òò¶ø²¢²»ÄÜÈ·¶¨ÐµĿªÑ§ÈÕÆÚ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/city-of-hartford-postpones-first-day-of-school-after-ransomware-attack/
6.°Í»ù˹̹µçÁ¦¹«Ë¾Ï°È¾Netwalkerµ¼ÖÂÔÚÏß·þÎñÖжÏ

°Í»ù˹̹×î´óµÄ¸öÈ˵çÁ¦¹«Ë¾K-ElectricϰȾNetwalker£¬µ¼Ö¼ƷѺÍÔÚÏß·þÎñÖжϡ£×Ô9ÔÂ7ºÅ£¬K-Electric¿Í»§ÆðÍ·ÎÞ·¨½Ó¼ûÔÚÏß·þÎñ£¬¸Ã¹«Ë¾Ò²ÔÚ³¢ÊÔͨ¹ýµÇ̨վµã³ÁзÓÉÓû§£¬µ«ÒÀȻûÄܽâ¾öÎÊÌâ¡£ºóÓɱ¾µØ°²È«¹«Ë¾µÃÖª£¬ÆäÔâµ½ÁËNetwalkerÀÕË÷Èí¼þ¹¥»÷¡£Õâ´ÎÍøÂç¹¥»÷²úÉúÔÚ9ÔÂ7ÈÕÉÏÎ磬ËüÖØÒªÕë¶ÔµÄÊÇK-ElectricµÄÔÚÏ߼ƷѷþÎñ£¬¶ø·ÇµçÁ¦¹©¸øÏµÍ³£¬ÒÔ´ËË÷Òª385ÍòÃÀÔªµÄÊê½ð¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/netwalker-ransomware-hits-pakistans-largest-private-power-utility/


¾©¹«Íø°²±¸11010802024551ºÅ