˼¿ÆÅû¶ÆäAnyConnect¿Í»§¶ËÖÐ0day£¬ÉÐÎÞÓйز¹¶¡£»Adobe°²È«¸üУ¬½¨¸´AcrobatºÍReaderÖжà¸ö·ì϶

°ä²¼¹¦·ò 2020-11-05
1.˼¿ÆÅû¶ÆäAnyConnect¿Í»§¶ËÖÐ0day£¬ÉÐÎÞÓйز¹¶¡


1.jpg


˼¿ÆÅû¶ÆäAnyConnect¿Í»§¶ËÈí¼þµÄ0day£¬Ä¿Ç°ÒÑÓй«¿ª¿ÉÓõĸÅÏëÑéÖ¤ÀûÓôúÂ룬µ«ÉÐÎÞÕë¶ÔÕâ¸öËÁÒâ´úÂëÖ´Ðзì϶µÄ°²È«¸üС£¸Ã·ì϶±»×·×ÙΪCVE-2020-3556£¬´æÔÚÓÚCisco AnyConnect ClientµÄ¹ý³Ì¼äͨѶ£¨IPC£©Í¨Â·ÖУ¬¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õߺͱ¾µØ¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐжñÒâ¾ç±¾¡£¸Ã·ì϶ӰÏìÁËWindows¡¢LinuxºÍmacOS°æ±¾µÄAnyConnect¿Í»§¶Ë£¬Ö»¹ÜûÓв¹¶¡·¨Ê½£¬µ«ÊÇÄܹ»Í¨¹ý½ûÓÃ×Ô¶¯¸üкÍÖÕ³¡ÆôÓþ籾ÉèÖÃÀ´»º½â¸ÃÎÊÌâ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/cisco-discloses-anyconnect-vpn-zero-day-exploit-code-available/


2.Adobe°²È«¸üУ¬½¨¸´AcrobatºÍReaderÖжà¸ö·ì϶


2.jpg


Adobe°ä²¼°²È«¸üУ¬½¨¸´ÁËWindowsºÍmacOS°æ±¾µÄAdobe AcrobatºÍReaderÖÐ×ܼÆ14¸ö·ì϶£¬Õâ´Î½¨¸´µÄ½ÏΪÑϳÁµÄ·ì϶ΪËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2020-24435¡¢CVE-2020-24436¡¢CVE-2020-24430ºÍCVE-2020-24437£©£¬±¾µØÌáȨ·ì϶£¨CVE-2020-24433¡¢CVE-2020-24429ºÍCVE-2020-24428£©£¬ËÁÒâJavaScriptÖ´Ðзì϶£¨CVE-2020-24432£©ÒÔ¼°¶¯Ì¬¿â×¢Èë·ì϶£¨CVE-2020-24431£©¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-security-vulnerabilities-in-acrobat-reader/


3.SaltStack°ä²¼²¹¶¡·¨Ê½£¬½¨¸´3¸öÑϳÁµÄ·ì϶


3.png


SaltStack°ä²¼²¹¶¡·¨Ê½£¬½¨¸´ÁËÓ°ÏìSalt°æ±¾3002¼°¸üµÍ°æ±¾µÄ3¸öÑϳÁµÄ·ì϶¡£SaltÊÇÓÃPython±àдµÄ¿ªÔ´IT»ù´¡¼Ü¹¹ÖÎÀí½â¾ö¹æ»®£¬ÓÚ10Ô±»VMwareÊÕ¹º¡£Õâ´Î½¨¸´µÄ·ì϶±ðÀëΪShell×¢Èë·ì϶£¨CVE-2020-16846£©£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ýSSH¿Í»§¶ËÀûÓÃShell×¢ÈëÔÚSalt-APIÉÏÔËÐдúÂ룻Éí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2020-25592 £©£¬ÀûÓÃÈκÎÖµµÄeauth»òtoken¶¼¿ÉÈÆ¹ýÉí·ÝÑéÖ¤²¢Å²ÓÃSalt ssh£»Óë´ò¿ªºÍ±£Áô¼ÓÃÜ˽ԿÎļþÓйصÄȨÏÞÎÊÌ⣨CVE-2020-17490£©¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/saltstack-reveals-new-critical-vulnerabilities-patch-now/


4.ÀÕË÷ÍÅ»ïREvilÅÄÏÂÐÅÏ¢ÇÔȡľÂíKPOTµÄÔ´´úÂë


4.png


ÔÚÒ»´Î°µÍøÉϽøÐеÄÅÄÂô»î¶¯ÖУ¬ÀÕË÷Èí¼þÍÅ»ïREvilÒÔ6500ÃÀÔªµÄ¼ÛÖµÅĵÃÁËKPOTľÂíµÄÔ´´úÂë¡£KPOTÓÚ2018Äê±»³õ´Î·¢ÏÖ£¬ÊǾ­µäµÄÐÅÏ¢ÇÔÈ¡·¨Ê½£¬Äܹ»´ÓÊÜÏ°È¾ÍÆËã»úÉϵĸ÷ÀàÀûÓÃÖÐÇÔÈ¡ÃÜÂ룬Ô̺¬Webä¯ÀÀÆ÷¡¢µç×ÓÓʼþ¿Í»§¶Ë¡¢VPN¡¢¼ÓÃÜÇ®±ÒÇ®°üºÍÓÎÏ·Èí¼þ ¡£°²È«×êÑÐÔ±Pancak3·¢ÏÖ£¬ÔÚÒ»¸öÔÂǰµÄ°µÍøÅÄÂô»áÉÏ£¬ REvilÍÅ»ïµÄ³ÛÃû³ÉÔ±UNKNÒÔ6500ÃÀÔª¼ÛÖµÂòµ½ÁË×îа汾KPOT 2.0µÄÔ´´úÂë¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/revil-ransomware-gang-acquires-kpot-malware/


5.ÐÂÀÕË÷Èí¼þRegretLockerÖØÒªÕë¶ÔWindowsÐé¹¹»ú


5.png


MalwareHunterTeam·¢ÏÖÐÂÀÕË÷Èí¼þRegretLockerÖØÒªÕë¶ÔWindowsÐé¹¹»ú¡£RegretLockerÓÚ10Ô±»·¢ÏÖ£¬ÊÇÒ»¿îµ¥Ò»µÄÀÕË÷Èí¼þ£¬Ã»ÓÐÈß³¤µÄÀÕË÷¼Í¼£¬²¢ÇÒʹÓõç×ÓÓʼþͨѶ¶ø·ÇTorÖ§¸¶ÍøÕ¾¡£×êÑÐÈËÔ±·¢ÏÖRegretLockerʹÓÃWindowsÐé¹¹´æ´¢API OpenVirtualDisk¡¢AttachVirtualDiskºÍGetVirtualDiskPhysicalPathº¯ÊýÀ´×°ÖÃÐé¹¹´ÅÅÌ¡£Ò»µ©Ðé¹¹´ÅÅÌ×÷ΪÎïÀí´ÅÅÌ×°Öõ½WindowsÖУ¬ÀÕË÷Èí¼þ¾ÍÄܹ»¶Ôÿ¸öÐé¹¹Ó²Å̽øÐе¥¶À¼ÓÃÜ£¬´Ó¶øÌá¸ß¼ÓÃÜ¿ìÂÊ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-regretlocker-ransomware-targets-windows-virtual-machines/    


6.GrowDiariesÊý¾Ý¿âÅäÖÃÃýÎóй¶200Íò´óÂéÖÖÖ²ÕßÐÅÏ¢


6.png


GrowDiariesÒòÊý¾Ý¿âÅäÖÃÃýÎóµ¼ÖÂ200Íò´óÂéÖÖÖ²ÕßÐÅϢй¶¡£GrowDiariesÊÇÒ»¸öÔÚÏßÂÛ̳£¬´óÂéÖÖÖ²ÕßÄܹ»ÔÚÕâÀï°ä·¢¹ØÓÚËûÃÇÖÖÖ²µÄ´óÂéµÄ²©¿Í£¬²¢ÓëÆäËûÓû§½øÐл¥¶¯¡£Õâ´ÎÊÂÎñ×ܹ²Ð¹Â¶ÁËÁ½¸öElasticsearchÊý¾Ý¿â£¬ÆäÖÐÒ»¸öÔ̺¬140ÍòÌõÓû§¼Í¼£¬Ð¹Â¶ÁËÓû§µÄÓû§Ãû¡¢µç×ÓÓʼþµØÖ·ºÍIPµØÖ·£»¶øÁíÒ»¸öÊý¾Ý¿âÔ̺¬³¬¹ý200ÍòÌõÓû§Êý¾Ý£¬Æäй¶ÁËGrowDiariesÍøÕ¾Éϰ䲼µÄÓû§ÎÄÕºÍÓû§µÄÕÊ»§ÃÜÂ롣Ŀǰ£¬Â¶³öÊý¾Ý¿âÒѱ»±£»¤ÆðÀ´¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/configuration-snafu-exposes-passwords-for-two-million-marijuana-growers/