LumuÐû²¼2020Äê¶ÈÀÕË÷Èí¼þÓ°ÏìÆÊÎöµÄÐÅϢͼ£»MDSec·¢Ã÷Windows Update¿É±»ÓÃÀ´Ö´ÐжñÒâÎļþ
Ðû²¼Ê±¼ä 2020-10-13
LumuÐû²¼ÁËÒ»ÕÅÐÅϢͼ£¬Ïêϸ˵Ã÷ÎúÀÕË÷Èí¼þµÄ±¾Ç®ºÍ¹æÄ££¬ÒÔ×ÊÖúÆóҵȨºâËûÃǵÄÊܺ¦Î£º¦¡£¾ÝÆÊÎö£¬½ñÄêÈ«ÇòÀÕË÷Èí¼þµÄ±¾Ç®Îª200ÒÚÃÀÔª£¬Æ½¾ùÿ´ÎµÄ¹¥»÷±¾Ç®Áè¼Ý400ÍòÃÀÔª£¬²¢ÇÒÓÐ36£¥µÄÊܺ¦ÕßÖ§¸¶ÁËÊê½ð£¬ÆäÖÐ17£¥»¹Ã»ÄÜÍì»ØËûÃǵÄÊý¾Ý¡£±ðµÄ£¬ÔÚ±±ÃÀÓÐ69%µÄ¹«Ë¾±¨¸æ³ÆÊܵ½ÁËÀÕË÷Èí¼þµÄÓ°Ï죬¶øÔÚÅ·ÖÞÓÐ57%¡£Ïà½Ï¶øÑÔ£¬±±ÃÀµÄÕþ¸®»ú¹¹Êܵ½µÄ¹¥»÷×îΪÑÏÖØ£¬Æä´ÎÊÇÖÆÔìÒµºÍÐÞ½¨Òµ¡£
ÔÎÄÁ´½Ó£º
https://lumu.io/resources/2020-ransomware-flashcard/
2.BetterCloudÐû²¼2020Äê¶ÈSaaSOps״̬ÆÊÎö±¨¸æ

BetterCloudÐû²¼ÁË2020Äê¶ÈSaaSOps״̬ÆÊÎö±¨¸æ£¬ÏÔʾÁËSaaS½ÓÄÉÂʵÄÉÏÉýÒý·¢µÄÈËÃǶÔÔËÓªÖØ´óÐÔºÍΣº¦µÄµ£ÐÄ¡£×Ô2015ÄêÒÔÀ´£¬ÊÜÐÅÍеÄSaaSÓ¦ÓóÌÐòµÄÊýÄ¿ÔöÌíÁËÊ®±¶£¬Ô¤¼Æµ½2025Ä꣬½«ÓÐ85£¥µÄÓªÒµÓ¦ÓóÌÐò»ùÓÚSaaS¡£Ëæ×ÅSaaSµÄÔöÌí£¬49%µÄÊÜ·ÃÕßÐÅÍÐËûÃÇÓÐÄÜÁ¦Ê¶±ðºÍ¼à¿Ø¹«Ë¾ÍøÂçÉÏδ¾Åú×¼µÄSaaSʹÓÃÇéÐΣ¬µ«ÈÔÓÐ76%µÄÈËÒÔΪδ¾Åú×¼µÄÓ¦Óñ£´æÇ徲Σº¦¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/10/12/saas-adoption-risk/
3.MDSecÑо¿Ö°Ô±·¢Ã÷Windows Update¿É±»ÓÃÀ´Ö´ÐжñÒâÎļþ

MDSecÑо¿Ö°Ô±David Middlehurst·¢Ã÷£¬Windows Update¿É±»ÓÃÀ´Ö´ÐжñÒâÎļþ¡£WSUS/Windows Update¿Í»§¶Ë£¨wuauclt£©ÊÇλÓÚ£¥windir£¥\ system32\µÄÓ¦ÓóÌÐò£¬¿ÉʹÓû§´ÓÏÂÁîÐпØÖÆWindows Update AgentµÄijЩ¹¦Ð§¡£¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓÃÏÂÁîÐÐʹÓÃÌØÖÆµÄDLL¼ÓÔØwuauclt£¬´Ó¶øÔÚWindows 10ϵͳÉÏÖ´ÐжñÒâ´úÂë¡£Middlehurst·¢Ã÷wuaucltÒ²¿ÉÒÔÓÃ×÷LoLBin£¬²¢ÔÚÒ°ÍâÕÒµ½ÁËÆäÏà¹ØµÄÑù±¾¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/windows-update-can-be-abused-to-execute-malicious-files/
4.unit42Ñо¿Ö°Ô±Åû¶LinuxÄÚºËÖеÄÌáȨÎó²î£¨CVE-2020-14386£©

unit42Ñо¿Ö°Ô±ÔÚÉóºËLinuxÄÚºËÖеÄÊý¾Ý°üÌ×½Ó×ÖÔ´´úÂëʱ£¬·¢Ã÷ÁËLinuxÄÚºËÖеÄÌáȨÎó²î£¨CVE-2020-14386£©¡£¸ÃÎó²îÊÇÒ»¸öÄÚ´æËð»µÎó²î£¬¿ÉÓÃÓÚ½«LinuxϵͳÉϵķÇrootÓû§µÄȨÏÞÉý¼¶ÎªrootÓû§¡£Palo Alto Networks Cortex XDR¿Í»§¿ÉÒÔͨ¹ýÍŽáʹÓÃÐÐΪÍþв·À»¤£¨BTP£©ºÍÍâµØÌØÈ¨Éý¼¶±£»¤¹¦Ð§À´Ô¤·À¸ÃÎó²î¡£
ÔÎÄÁ´½Ó£º
https://unit42.paloaltonetworks.com/cve-2020-14386/
5.TelsyÅû¶Õë¶Ôº½¿ÕÐÐÒµµÄSPACE RACEÉç»á¹¤³Ì¹¥»÷

2020Äê5Ô³õ£¬TelsyÆÊÎöÁËÕë¶Ôº½¿ÕÐÐÒµµÄSPACE RACEÉç»á¹¤³Ì¹¥»÷¡£ÕâЩ¹¥»÷ͨ¹ýÉç½»ÍøÂçLinkedIn¾ÙÐУ¬Õë¶Ô¶Ôº½¿Õº½ÌìºÍº½¿Õµç×ÓÁìÓòµÄСÎÒ˽¼ÒÌᳫÉç»á¹¤³Ì¹¥»÷¡£ºÚ¿ÍÔÚLinkedInαÔìÐéÄâÉí·Ý£¬Ã°³äÎÀÐÇÓ°Ïñ¹«Ë¾µÄHRÕÐÆ¸Ö°Ô±£¬²¢Í¨¹ýÄÚ²¿Ë½ÈËÐÂÎÅÓëÄ¿µÄÖ°Ô±ÁªÏµ£¬ÓÕʹËûÃÇÏÂÔØ°üÀ¨ÓйؼÙÊÂÇé¼ÙÆÚÐÅÏ¢µÄ¶ñÒ⸽¼þ¡£Ñо¿Ö°Ô±ÒÔΪ¸ÃÐж¯ÓëºÚ¿Í×éÖ¯MuddywaterÓйء£
ÔÎÄÁ´½Ó£º
https://www.telsy.com/operation-space-race-reaching-the-stars-through-professional-social-networks/
6.ÃÀ¹úµÄÀÎÓüÒòÊý¾Ý¿âÉèÖùýʧй¶Çô·¸Óë״ʦ¼äͨ»°µÄÄÚÈÝ

λÓÚÃÀ¹úʥ·Ò×˹µÄÀÎÓüÒòÊý¾Ý¿âÉèÖùýʧй¶Çô·¸Óë״ʦ¼äͨ»°µÄÄÚÈÝ¡£Ñо¿Ö°Ô±Bob Diachenko·¢Ã÷£¬ÖÁÉÙ´Ó4ÔÂ×îÏÈ£¬ÀÎÓüµÄÒ»¸ö·þÎñÆ÷±ã̻¶ÔÚ¹«ÍøÉÏ¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨ä¯ÀÀºÍËÑË÷ͨ»°¼Í¼¡¢Çô·¸ÓëÆäÅóÙ¡¢¼ÒÈ˺Í״ʦ֮¼äµÄͨ»°¼Í¼¡¢ºô½ÐÕߵĵ绰ºÅÂë¡¢¼à·¸Ãû³ÆÒÔ¼°Í¨»°Ê±¼ä¡£¸ÃÀÎÓüÈ·ÈÏÁË´ËÊÂÎñ£¬²¢ÌåÏÖÊÇÓÉÓÚµÚÈý·½¹©Ó¦É̲»Ð¡ÐÄɾ³ýÁËÃÜÂ룬´Ó¶øµ¼Ö·þÎñÆ÷̻¶¡£
ÔÎÄÁ´½Ó£º
https://techcrunch.com/2020/10/10/prison-visitation-homewav-leak/


¾©¹«Íø°²±¸11010802024551ºÅ