Lumu°ä²¼2020Äê¶ÈÀÕË÷Èí¼þÓ°Ïì·ÖÎöµÄÐÅϢͼ£»MDSec·¢ÏÖWindows Update¿É±»ÓÃÀ´Ö´ÐжñÒâÎļþ
°ä²¼¹¦·ò 2020-10-13
Lumu°ä²¼ÁËÒ»ÕÅÐÅϢͼ£¬¾ßÌå˵ÁËÈ»ÀÕË÷Èí¼þµÄ³É±¾ºÍÁìÓò£¬ÒÔÔ®ÊÔìóÒµºâÁ¿ËûÃǵÄÊܺ¦·çÏÕ¡£¾Ý·ÖÎö£¬½ñÄêÈ«ÇòÀÕË÷Èí¼þµÄ³É±¾Îª200ÒÚÃÀÔª£¬¾ùÔÈÿ´ÎµÄ¹¥»÷³É±¾³¬¹ý400ÍòÃÀÔª£¬²¢ÇÒÓÐ36£¥µÄÊܺ¦ÕßÖ§¸¶ÁËÊê½ð£¬ÆäÖÐ17£¥»¹Ã»ÄÜÍì»ØËûÃǵÄÊý¾Ý¡£´Ë±í£¬ÔÚ±±ÃÀÓÐ69%µÄ¹«Ë¾»ã±¨³ÆÊܵ½ÁËÀÕË÷Èí¼þµÄÓ°Ï죬¶øÔÚÅ·ÖÞÓÐ57%¡£Ïà½Ï¶øÑÔ£¬±±ÃÀÈ·µ±¾Ö»ú¹¹Êܵ½µÄ¹¥»÷×îΪÑϳÁ£¬Æä´ÎÊÇÔì×÷ÒµºÍ¹¹ÖþÒµ¡£
ÔÎÄÁ´½Ó£º
https://lumu.io/resources/2020-ransomware-flashcard/
2.BetterCloud°ä²¼2020Äê¶ÈSaaSOps״̬·ÖÎö»ã±¨

BetterCloud°ä²¼ÁË2020Äê¶ÈSaaSOps״̬·ÖÎö»ã±¨£¬ÏÔʾÁËSaaSѡȡÂʵÄÉÏÆðÓ÷¢µÄÈËÃǶÔÔËÓª¸´ÔÓÐÔ΢·çÏÕµÄÓÇÓô¡£×Ô2015ÄêÒÔÀ´£¬ÊÜÐÅÀµµÄSaaSÀûÓ÷¨Ê½µÄÊýÁ¿Ôö³¤ÁËÊ®±¶£¬Ô¤¼Æµ½2025Ä꣬½«ÓÐ85£¥µÄÒµÎñÀûÓ÷¨Ê½»ùÓÚSaaS¡£Ëæ×ÅSaaSµÄÔö³¤£¬49%µÄÊÜ·ÃÕßÏàÐÅËûÃÇÓÐÄÜÁ¦¼ø±ðºÍ¼à¿Ø¹«Ë¾ÍøÂçÉÏδ¾ºË×¼µÄSaaSʹÓÃÇé¿ö£¬µ«ÈÔÓÐ76%µÄÈËÒÔΪδ¾ºË×¼µÄÀûÓôæÔÚ°²È«·çÏÕ¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/10/12/saas-adoption-risk/
3.MDSec×êÑÐÈËÔ±·¢ÏÖWindows Update¿É±»ÓÃÀ´Ö´ÐжñÒâÎļþ

MDSec×êÑÐÈËÔ±David Middlehurst·¢ÏÖ£¬Windows Update¿É±»ÓÃÀ´Ö´ÐжñÒâÎļþ¡£WSUS/Windows Update¿Í»§¶Ë£¨wuauclt£©ÊÇλÓÚ£¥windir£¥\ system32\µÄÀûÓ÷¨Ê½£¬¿ÉʹÓû§´ÓºÅÁîÐнÚÔìWindows Update AgentµÄijЩְÄÜ¡£¹¥»÷ÕßÄܹ»Í¨¹ýʹÓúÅÁîÐÐÀûÓÃÌØÔìµÄDLL¼ÓÔØwuauclt£¬´Ó¶øÔÚWindows 10ϵͳÉÏÖ´ÐжñÒâ´úÂë¡£Middlehurst·¢ÏÖwuaucltÒ²Äܹ»ÓÃ×÷LoLBin£¬²¢ÔÚÒ°±íÕÒµ½ÁËÆäÓйصÄÑù±¾¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/windows-update-can-be-abused-to-execute-malicious-files/
4.unit42×êÑÐÈËÔ±Åû¶LinuxÄÚºËÖеÄÌáȨ·ì϶£¨CVE-2020-14386£©

unit42×êÑÐÈËÔ±ÔÚÉóºËLinuxÄÚºËÖеÄÊý¾Ý°üÌ×½Ó×ÖÔ´´úÂëʱ£¬·¢ÏÖÁËLinuxÄÚºËÖеÄÌáȨ·ì϶£¨CVE-2020-14386£©¡£¸Ã·ì϶ÊÇÒ»¸öÄÚ´æ°Ü»µ·ì϶£¬¿ÉÓÃÓÚ½«LinuxϵͳÉϵķÇrootÓû§µÄȨÏÞÉý¼¶ÎªrootÓû§¡£Palo Alto Networks Cortex XDR¿Í»§Äܹ»Í¨¹ý½áºÏʹÓÃÐÐΪÍþв·À»¤£¨BTP£©ºÍ±¾µØÌØÈ¨Éý¼¶±£»¤Ö°ÄÜÀ´Ô¤·À¸Ã·ì϶¡£
ÔÎÄÁ´½Ó£º
https://unit42.paloaltonetworks.com/cve-2020-14386/
5.TelsyÅû¶Õë¶Ôº½¿ÕÐÐÒµµÄSPACE RACEÉç»á¹¤³Ì¹¥»÷

2020Äê5Ô³õ£¬Telsy·ÖÎöÁËÕë¶Ôº½¿ÕÐÐÒµµÄSPACE RACEÉç»á¹¤³Ì¹¥»÷¡£ÕâЩ¹¥»÷ͨ¹ýÉç½»ÍøÂçLinkedIn½øÐУ¬Õë¶Ô¶Ôº½¿Õº½ÌìºÍº½¿Õµç×ÓÁìÓòµÄÓ×ÎÒÌáÒéÉç»á¹¤³Ì¹¥»÷¡£ºÚ¿ÍÔÚLinkedInαÔìÐé¹¹Éí·Ý£¬¼ÙÒâÎÀÐÇÓ°Ïñ¹«Ë¾µÄHRÕÐÆ¸ÈËÔ±£¬²¢Í¨¹ýÄÚ²¿¸öÈËÐÂÎÅÓëÖ¸±êÈËÔ±ÁªÏµ£¬ÓÕʹËûÃÇÏÂÔØÔ̺¬Óйؼٹ¤×÷¼ÙÆÚÐÅÏ¢µÄ¶ñÒ⸽¼þ¡£×êÑÐÈËÔ±ÒÔΪ¸ÃÐж¯ÓëºÚ¿Í×éÖ¯MuddywaterÓйء£
ÔÎÄÁ´½Ó£º
https://www.telsy.com/operation-space-race-reaching-the-stars-through-professional-social-networks/
6.ÃÀ¹úµÄ¼àÓüÒòÊý¾Ý¿âÅäÖÃÃýÎóй¶Çô·¸ÓëÂÉʦ¼äͨ»°µÄÄÚÈÝ

λÓÚÃÀ¹úʥ·Ò×˹µÄ¼àÓüÒòÊý¾Ý¿âÅäÖÃÃýÎóй¶Çô·¸ÓëÂÉʦ¼äͨ»°µÄÄÚÈÝ¡£×êÑÐÈËÔ±Bob Diachenko·¢ÏÖ£¬ÖÁÉÙ´Ó4ÔÂÆðÍ·£¬¼àÓüµÄÒ»¸ö·þÎñÆ÷±ã¶³öÔÚ¹«ÍøÉÏ¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬ä¯ÀÀºÍËÑË÷ͨ»°¼Í¼¡¢Çô·¸ÓëÆä°é¡¢¼ÒÈ˺ÍÂÉʦ֮¼äµÄͨ»°¼Í¼¡¢ºô½ÐÕߵĵ绰ºÅÂë¡¢ÇôͽÃû³ÆÒÔ¼°Í¨»°¹¦·ò¡£¸Ã¼àÓüÈ·ÈÏÁË´ËÊÂÎñ£¬²¢°µÊ¾ÊÇÓÉÓÚµÚÈý·½¹©¸øÉ̲»Ó×ÐÄɾ³ýÁËÃÜÂ룬´Ó¶øµ¼Ö·þÎñÆ÷¶³ö¡£
ÔÎÄÁ´½Ó£º
https://techcrunch.com/2020/10/10/prison-visitation-homewav-leak/


¾©¹«Íø°²±¸11010802024551ºÅ