ºÚ¿ÍÔÚ°µÍø¹«¿ªwattpadµÄ2.7ÒÚÌõÓû§Êý¾Ý;ºÚ¿Í½Ù³Ö±È¶û¸Ç´ÄºÍ°Â°ÍÂíµÈÈËTwitterÕÊ»§½øÐмÓÃÜÇ®±ÒÚ¿Æ­

°ä²¼¹¦·ò 2020-07-16

1.ºÚ¿ÍÔÚ°µÍø¹«¿ªwattpadµÄ2.7ÒÚÌõÓû§Êý¾Ý


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Ŀǰ £¬ºÚ¿ÍÔÚ°µÍøÃâ·Ñ¹«¿ªwattpadµÄ2.7ÒÚÌõÓû§Êý¾Ý¡£Æð³õ £¬×Ô7ÔÂ7ÈÕÆðÍ·Shiny HuntersÔÚ°µÍøÉÏÒÔÊ®¸ö±ÈÌØ±Ò£¨³¬¹ý100,000ÃÀÔª£©µÄ¼ÛÖµÏúÊÛÕâ¸öÔ̺¬2ÒÚ¶à±Ê¼Í¼µÄWattpadÊý¾Ý¿â¡£¸ÃÊý¾Ý¿âµÄ¼Í¼Ô̺¬Óû§Ãû¡¢Ãû³Æ¡¢¹þÏ£ÃÜÂë¡¢µç×ÓÓʼþµØÖ·ºÍͨ³£µØÀíµØÎ»¡£Í¨¹ýÓëй¶Êý¾ÝµÄÓû§ÁªÏµ £¬Äܹ»È·ÈÏÁгöµÄÐÅÏ¢ÊÇÕýÈ·µÄ¡£7ÔÂ14ÈÕ £¬Wattpad³ÆÆäÔÚÖÂÁ¦½¨¸´¸Ã·ì϶ £¬²¢°µÊ¾¸ÃÊÂÎñ²¢Î´Ð¹Â¶ÈκβÆÕþÐÅÏ¢¡¢µç»°ºÅÂë¡¢¹ÊÊ»ò¸öÈËÐÂÎÅ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/wattpad-data-breach-exposes-account-info-for-millions-of-users/


2.ºÚ¿Í½Ù³Ö±È¶û¸Ç´ÄºÍ°Â°ÍÂíµÈÈËTwitterÕÊ»§½øÐмÓÃÜÇ®±ÒÚ¿Æ­


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


7ÔÂ15ÈÕÖÜÈý £¬ºÚ¿Í½Ù³ÖÁËÊýǧ¸öÊôÓÚ¾«Ó¢Óû§ºÍ³ÛÃû¹«Ë¾µÄ¾­¹ýÑéÖ¤µÄTwitterÕÊ»§ £¬ÓÃÀ´½øÐмÓÃÜÇ®±ÒÚ¿Æ­ £¬Ô̺¬±È¶û¡¤¸Ç´Ä¡¢°£Â¡¡¤Âí˹¿Ë¡¢½Ü·ò¡¤±´×ô˹¡¢Âõ¿Ë¡¤Åí²©¸ñ¡¢°ÝµÇ¡¢°Â°ÍÂí¡¢Æ»¹ûºÍÓŲ½µÈ¡£Ö®ºó £¬ºÚ¿ÍÀûÓÃÕâЩÕË»§°ä²¼ÍÆÎÄ £¬ÓÕʹÊܺ¦Õ߲ɰì±ÈÌØ±Ò¡£½ØÖÁÃÀ¹ú¹¦·òÖÜÈýÏÂÎç4:45 £¬¸ÃµØÖ·ÒÑÊÕµ½³¬¹ý110000ÃÀÔªµÄBTC¡£Ä¿Ç° £¬Éв»Ã÷ÏÔÕÊ»§ÊÇÈôºÎ±»½Ù³ÖµÄ £¬Twitter°µÊ¾ÆäÔÚµ÷²é²¢½â¾ö´ËÊÂÎñ¡£


Ô­ÎÄÁ´½Ó£º

theregister.com/2020/07/15/mass_twitter_account_hacking_bitcoin/


3.Oracle°ä²¼7Ô°²È«¸üР£¬×ܼƽ¨¸´433¸ö·ì϶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Oracle¹Ù·½°ä²¼°²È«¸üР£¬×ܼƽ¨¸´ÁË433¸ö°²È«·ì϶ £¬Ó°ÏìÁËOracle Weblogic¡¢Oracle SD-WAN AwareºÍOracle SD-WAN EdgeµÈ¶à¿î²úÆ·¡£Õâ´Î¸üн¨¸´ÁËËĸöÆÀ·ÖΪ9.8µÄOracle WebLogic Server·´ÐòÁл¯·ì϶£¨CVE-2020-14625¡¢CVE-2020-14644¡¢CVE-2020-14645 ¡¢CVE-2020-14687£© £¬ÒÔ¼°Á½¸öÆÀ·ÖΪ10µÄOracle Communications Applications°²È«·ì϶£¨CVE-2020-14701¡¢CVE-2020-14606£©¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/07/14/oracle-releases-july-2020-security-bulletin


4.Adobe°ä²¼7Ô°²È«¸üР£¬½¨¸´ËÁÒâ´úÂëÖ´Ðзì϶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Adobe°ä²¼Á˰²È«¸üР£¬½¨¸´ÁË13¸ö°²È«·ì϶ £¬Ô̺¬Ó°ÏìÁËWindows°æ±¾µÄCreative Cloud¡¢Adobe Download ManagerºÍAdobe Media EncoderµÄ´úÂëÖ´Ðзì϶¡£Õâ´Î¸üÐÂÖÐÖØÒª½¨¸´ÁË4¸ö½ÏΪÑϳÁµÄ·ì϶ £¬±ðÀëΪDownload ManagerÖкÅÁî×¢Èëµ¼ÖµÄËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2020-9688£© £¬Media EncoderÖÐÔ½½çдµ¼ÖµÄËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2020-9650ºÍCVE-2020-9646£© £¬ÒÔ¼°Symlink·ì϶µ¼ÖµÄËÁÒâÎļþϵͳдÈë·ì϶£¨CVE-2020-9682£©¡£´Ë±í £¬»¹½¨¸´Á˲»°²È«µÄÎļþȨÏÞ¡¢DLLËÑË÷°¤´Î½Ù³Ö¡¢²»°²È«µÄ¿â¼ÓÔØºÍ·ûºÅÁ´½Ó·ì϶ÒÔ¼°Ô½½ç¶ÁÈ¡¶øµ¼ÖÂÌáȨ·ì϶µÈÎÊÌâ¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/07/14/adobe-releases-security-updates-multiple-products


5.GoogleΪChrome°ä²¼°²È«¸üР£¬½¨¸´38¸ö°²È«·ì϶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


GoogleΪChrome°ä²¼°²È«¸üР£¬×ܼƽ¨¸´ÁË38¸ö°²È«·ì϶¡£Õâ´Î°²È«¸üÐÂÖн¨¸´µÄ½ÏΪÑϳÁµÄ·ì϶Ϊºó¶ÜÌáÈ¡Öжѻº³åÇøÒç¶Âí½Å£¨CVE-2020-6510£©¡¢ÄÚÈݰ²È«Õ½ÊõÖеIJàÐÅ·ÐÅϢй©·ì϶£¨CVE-2020-6511£©¡¢ V8ÖеÄÀàÐÍ»ìºÏ·ì϶£¨CVE-2020-6512£©¡¢PDFiumÖеĶѻº³åÇøÒç¶Âí½Å£¨CVE-2020-6513£©¡¢WebRTCÖеIJ»Êʵ±ÊµÏÖ£¨CVE-2020-6514£©¡¢±êÇ©ÌõÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2020-6515£©¡¢ CORSÖеÄÕ½ÊõÈÆ¹ý·ì϶£¨CVE-2020-6516 £©ºÍº¹Çà¼Í¼Öжѻº³åÇøÒç¶Âí½Å£¨CVE-2020-6517£©¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/07/14/google-releases-security-updates-chrome


6.VMwareµ÷²é·¢ÏÖ £¬2020ÄêÍøÂç¹¥»÷¸´ÔÓÐÔ´ó·ùÔö³¤


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


VMwareµ÷²é·¢ÏÖ £¬2020ÄêÍøÂç¹¥»÷µÄÊýÁ¿ºÍ¸´ÔÓÐÔ¾ù´ó·ùÔö³¤¡£µ÷²é·¢ÏÖ £¬ÓÐ92£¥µÄÈ˰µÊ¾ÔÚ´Óǰ12¸öÔÂÖй¥»÷Á¿ÓÐËùÔö³¤ £¬97£¥µÄÈ˰µÊ¾ËûÃÇÔÚ´Óǰ12¸öÔÂÖÐÔâ·êÁ˹¥»÷ £¬¾ùÔÈÿ¸ö×éÖ¯¾­ÀúÁË2.70´Î¹¥»÷£»ÓÐ84£¥µÄÈ˰µÊ¾¹¥»÷±äµÃÔ½·¢¸´ÔÓ £¬95£¥µÄÈ˰µÊ¾ËûÃÇ´òËãÔÚÃ÷ÄêÔö³¤ÍøÂç·ÀÓùÖ§³ö¡£´Ë±í £¬²Ù×÷ϵͳ·ì϶ÊÇÍøÂç¹¥»÷ÖеÄÖØÒªÔ­Òò £¬Æä´ÎÊÇWebÀûÓ÷¨Ê½¹¥»÷ºÍÀÕË÷Èí¼þ¡£ÃÀ¹úÆóÒµÒѾ­¾ùÔÈʹÓó¬¹ý¾ÅÖÖ·ÖÆçµÄÍøÂ簲ȫ¹¤¾ßÀ´±£»¤ËûÃǵÄϵͳ¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/07/15/2020-increased-attack-sophistication/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+HelpNetSecurity+%28Help+Net+Security%29