ZoomµÄWindows¿Í»§¶ËÖÐ0day£¬£¬£¬£¬£¬£¬£¬¿ÉÖ´ÐÐí§Òâ´úÂ룻£»£»£»£»£»£»VMwareÐÞ¸´VeloCloudÖÐSQL×¢ÈëÎó²î

Ðû²¼Ê±¼ä 2020-07-10

1.ACROSÅû¶ZoomµÄWindows¿Í»§¶ËÖÐ0day£¬£¬£¬£¬£¬£¬£¬¿ÉÖ´ÐÐí§Òâ´úÂë


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÍøÂçÇå¾²¹«Ë¾ACROS SecurityÓÚ7ÔÂ9ÈÕÅû¶ÁËZoomµÄWindows¿Í»§¶ËÖÐ0day£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²î»áÓ°ÏìÔËÐÐÔھɰæWindows OS£¨ÀýÈçWindows 7ºÍWindows Server 2008 R2»ò¸üÔç°æ±¾£©ÉϵÄZoom¿Í»§¶Ë¡£¡£¡£¡£¡£¡£¡£ACROS CEO Mitja KolsekÌåÏÖ£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÒÔʹԶ³Ì¹¥»÷Õßͨ¹ýÈÃÓû§Ö´ÐÐijЩ²Ù×÷£¬£¬£¬£¬£¬£¬£¬ÀýÈç·­¿ªÎĵµÎļþ£¬£¬£¬£¬£¬£¬£¬ÔÚÊܺ¦ÕßÅÌËã»úÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£ÔÚÕû¸ö¹¥»÷Àú³ÌÖУ¬£¬£¬£¬£¬£¬£¬ÏµÍ³¶¼²»»áÏòÓû§·¢³öÇå¾²ÖÒÑÔ¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬ZoomÕýÔÚÑо¿ÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/zoom-working-on-patching-zero-day-disclosed-in-its-windows-client/#ftag=RSSbaffb68


2.VMwareÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´VeloCloudÖÐSQL×¢ÈëÎó²î


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


VMwareÐû²¼ÁËÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÒÔÐÞ¸´VeloCloudÖеÄÎó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓôËÎó²îÀ´»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄÎó²î±»×·×ÙΪCVE-2020-3973£¬£¬£¬£¬£¬£¬£¬ÎªSQL×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬£¬ÆäÓ°ÏìÁËVeloCloudµÄVMware SD-WAN¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î±£´æµÄÔ­ÓÉÓÚVeloCloud OrchestratorûÓоÙÐкÏÊʵÄÊäÈëÑéÖ¤£¬£¬£¬£¬£¬£¬£¬Õâ»áµ¼ÖÂSQLäע£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.5¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/07/08/vmware-releases-security-update-velocloud


3.ºÚ¿ÍÐ®ÖÆÎ¢ÈíAzureÍйܵÄ240¶à¸ö×ÓÓòÃûÊ¿´«¶ñÒâÈí¼þ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ºÚ¿ÍÐ®ÖÆÁË240¶à¸öÍйÜÔÚ΢ÈíAzureµÄ×ÓÓòÃû£¬£¬£¬£¬£¬£¬£¬ÒÔÈö²¥¶ñÒâÈí¼þºÍ¶ñÒâChromeÀ©Õ¹³ÌÐòµÈÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£´Ë´Î±»Ð®ÖƵÄÍøÕ¾°üÀ¨»ªÄÉÐֵܡ¢½Ì¿ÆÎÄ×éÖ¯¡¢¶«Ö¥¡¢Ê©ÀÖ¡¢¸ÇµÙͼƬÉç¡¢ºìÊ®×ֻᡢÎÖ¶ûÎÖ¡¢»ôÄáΤ¶û¡¢ÏÄÍþÒĺ½¿Õ¹«Ë¾¡¢ÇåÎúƵµÀ¡¢Î÷ÃÅ×Ó¡¢Å·Ìؿˡ¢Arm¡¢3MºÍNHSµÈ¼ÒÓ÷»§ÏþµÄ¹«Ë¾¡£¡£¡£¡£¡£¡£¡£ÆÊÎö¹«Ë¾Victory MediumÊ×´´ÈËEdwardsÌåÏÖ£¬£¬£¬£¬£¬£¬£¬Ìᳫ´Ë´Î¹¥»÷µÄºÚ¿Í×éÖ¯¸ÃС×é»îÔ¾ÁËÎåÄ꣬£¬£¬£¬£¬£¬£¬Æ¾Ö¤ËûµÄÆÊÎö£¬£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯»ñµÃÁ˹ú¼Ê·¸·¨ÍÅ»ïµÄÖ§³Ö£¬£¬£¬£¬£¬£¬£¬±ÈÔ¤ÆÚÒªÖØ´óµÃ¶à¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/microsoft-azure-hosted-subdomains-hacked-with-malware/


4.΢ÈíÖÒÑÔʹÓöñÒâOAuthÓ¦ÓõÄOffice 365ÍøÂç´¹Âڻ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


΢ÈíÖÒÑÔ˵£¬£¬£¬£¬£¬£¬£¬Ëæ×ÅÔ¶³ÌÊÂÇéµÄÍÆ½ø£¬£¬£¬£¬£¬£¬£¬¿Í»§³ýÁËÒª×¢ÖØ¹Å°åµÄƾ֤͵ÇԺ͵ç×ÓÓʼþÍøÂç´¹ÂÚ¹¥»÷Ö®Í⣬£¬£¬£¬£¬£¬£¬»¹ÃæÁÙÆäËûÇå¾²Íþв£¬£¬£¬£¬£¬£¬£¬ÀýÈçÔÊÐíÍøÂç´¹ÂÚ£¨Consent phishing£©¡£¡£¡£¡£¡£¡£¡£Consent phishingÊÇÒ»ÖÖ»ùÓÚÓ¦ÓóÌÐòµÄ¹¥»÷µÄ±äÌ壬£¬£¬£¬£¬£¬£¬Ö¼ÔÚΪ¶ñÒâOffice 365 OAuthÓ¦ÓóÌÐòÌṩ¶ÔÊܺ¦ÕßOffice 365ÕÊ»§µÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Àֳɺ󣬣¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ»á¼ûÊܺ¦ÕßµÄÓʼþ¡¢Îļþ¡¢ÁªÏµÈË¡¢±ã¼ã¡¢ÉèÖÃÎļþÒÔ¼°´æ´¢ÔÚ¹«Ë¾´æ´¢ÏµÍ³SharePointºÍOneDrive for BusinessÔÆÖеÄÃô¸ÐÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-warns-of-office-365-phishing-via-malicious-oauth-apps/


5.½ü3Ä꣬£¬£¬£¬£¬£¬£¬KeeperÍÅ»ïÒÑÌᳫÕë¶ÔÈ«Çò570¶àÍøÕ¾µÄ¹¥»÷»î¶¯


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Gemini AdvisoryÐû²¼Á˶ԺڿÍ×éÖ¯Keeper MagecartµÄÆÊÎö±¨¸æ£¬£¬£¬£¬£¬£¬£¬·¢Ã÷Æä×Ô2017Äê4ÔÂ1ÈÕÒÔÀ´£¬£¬£¬£¬£¬£¬£¬¶ÔÈ«Çò55¸ö¹ú¼ÒÖеÄ570¶àÔÚÏßÉ̳ÇÌᳫÁËMagecart¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£Ñо¿·¢Ã÷£¬£¬£¬£¬£¬£¬£¬keeperÊÇÓÉ64¸öÓÃÓÚ·Ö·¢¶ñÒâÈí¼þµÄ¹¥»÷ÓòºÍ73¸öÓÃÓÚÎüÊÕ±»µÁÊý¾ÝµÄÉøÍ¸Óò×é³É¡£¡£¡£¡£¡£¡£¡£´ó´ó¶¼Êܺ¦ÍøÕ¾¶¼ÍйÜÔÚÃÀ¹ú£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊÇÓ¢¹ú¡¢ºÉÀ¼¡¢·¨¹ú¡¢Ó¡¶ÈµÈ¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯¸ÃÎÞÒ⻹»áʹÓù«¹²ºÍ×Ô½ç˵»ìÏýµÄÒªÁ죬£¬£¬£¬£¬£¬£¬ÒÔʹÆä¶ñÒâ¾ç±¾¸üÄѱ»¼ì²âµ½¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/07/08/magecart-group-8/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+HelpNetSecurity+%28Help+Net+Security%29


6.±¨¸æÏÔʾ£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÓÐ150ÒÚInternetЧÀÍÆ¾Ö¤ÔÚ°µÍø³öÊÛ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Digital ShadowsµÄÒ»·Ý±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÓÉÓÚ10Íò´ÎÊý¾Ýй¶ÊÂÎñµ¼ÖµÄ150ÒÚ¸ö±»µÁInternetЧÀÍÆ¾Ö¤ÔÚ°µÍø³öÊÛ¡£¡£¡£¡£¡£¡£¡£ÕâЩƾ֤ÔÚ»á¼ûȨÏ޺ͼÛÇ®Éϸ÷²»Ïàͬ£¬£¬£¬£¬£¬£¬£¬°üÀ¨´ÓÒøÐÐÕÊ»§£¨Õ¼ËùÓÐÆ¾Ö¤µÄ25£¥£©µ½ÊÓÆµºÍÒôÀÖÁ÷ЧÀ͵ÈËùÓÐÄÚÈݵÄÓû§ÃûºÍÃÜÂë¡£¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬£¬ÒøÐÐºÍÆäËû½ðÈÚÕË»§µÄƾ֤ÊÇ×îÊܽӴýµÄ£¬£¬£¬£¬£¬£¬£¬Ò²ÊÇ×îÌÚ¹óµÄ£¬£¬£¬£¬£¬£¬£¬Æ½¾ùÊÛ¼ÛΪ70.91ÃÀÔª¡£¡£¡£¡£¡£¡£¡£Æä´ÎÊÇÓÃÓÚ»á¼û·À²¡¶¾Èí¼þµÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬Æ½¾ùÊÛ¼ÛΪ21.67ÃÀÔª¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/15-billion-credentials-currently-up-for-grabs-on-hacker-forums/157247/