¾ÅÓÎÀϸç

¾ÅÓÎÀϸç

¾ÅÓÎÀÏ¸ç¿Æ¼¼

  • »ù´¡ÉèÊ©Çå¾²

    »ù´¡ÉèÊ©Çå¾²
  • Êý¾ÝÇå¾²

    Êý¾ÝÇå¾²
  • ÔÆÅÌËãÇå¾²

    ÔÆÅÌËãÇå¾²
  • ¹¤Òµ»¥ÁªÍøÇå¾²

    ¹¤Òµ»¥ÁªÍøÇå¾²
  • ÎïÁªÍøÇå¾²

    ÎïÁªÍøÇå¾²
  • ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì

    ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì
  • ËùÓвúÆ·

    ËùÓвúÆ·
  • ËùÓнâ¾ö¼Æ»®

    ËùÓнâ¾ö¼Æ»®

»ù´¡ÉèÊ©Çå¾²


  • Õþ¸®

    Õþ¸®
  • ÔËÓªÉÌ

    ÔËÓªÉÌ
  • ½ðÈÚ

    ½ðÈÚ
  • ÄÜÔ´

    ÄÜÔ´
  • ½»Í¨

    ½»Í¨
  • ÆóÒµ

    ÆóÒµ
  • ¿Æ½ÌÎÄÎÀ

    ¿Æ½ÌÎÄÎÀ

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÏàÖúͬ°éÉó²é¸ü¶à >

ÏàÖúͬ°é¶¯Ì¬

³ÉΪÏàÖúͬ°é

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÊÖÒÕÖ§³ÖÉó²é¸ü¶à >

²úÆ·Ö§³Ö

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

·µ»ØÁбí

¾ÅÓÎÀϸçÍþвÇ鱨Öܱ¨£¨2020.03.02~2020.03.08£©

2020-03-09

 

Ò»¡¢Íþвͨ¸æ

  • V8ÀàÐÍ»ìÏýÎó²î

¡¾Ðû²¼Ê±¼ä¡¿2020-03-04 20:00:00 GMT

¡¾¸ÅÊö¡¿2ÔÂ25ÈÕ £¬¹È¸èChromeä¯ÀÀÆ÷Óë΢ÈíEdgeä¯ÀÀÆ÷Ðû²¼ÁËÇå¾²¸üР£¬ÔÚGoogle Chrome ä¯ÀÀÆ÷80.0.3987.122ÒÔÏÂÓëMicrosoftEdgeä¯ÀÀÆ÷80.0.361.62ÒÔϵİ汾ÖÐ £¬¿ªÔ´ JavaScriptºÍWebAssemblyÒýÇæV8Öб£´æÒ»¸öÀàÐÍ»ìÏýÎó²î£¨CVE-2020-6418£© £¬¿ÉÄܵ¼Ö¹¥»÷Õß²»·¨»á¼ûÊý¾Ý £¬´Ó¶øÖ´ÐжñÒâ´úÂë¡£ÓÐÑо¿Ö°Ô±·¢Ã÷ £¬ÔÚ¸üÐÂÐû²¼Ç° £¬¸ÃÎó²î¾ÍÒѾ­±»¹¥»÷ÕßÓÃÓÚÏÖʵ¹¥»÷¡£

http://blog.nsfocus.net/cve-2020-6418-2/

  • Oracle Coherence·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¡¾Ðû²¼Ê±¼ä¡¿2020-03-06 22:00:00 GMT

¡¾¸ÅÊö¡¿2020Äê1ÔÂ15ÈÕ £¬Oracle¹Ù·½Ðû²¼ÁË2020Äê1ÔÂÒªº¦²¹¶¡¸üÐÂͨ¸æ £¬ÐÞ¸´ÁË334¸ö²î±ðˮƽµÄÎó²î¡£ÆäÖаüÀ¨Ò»¸öOracle Coherence·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-2555£© £¬CVSSÆÀ·ÖΪ9.8£»¸ÃÎó²îÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ý½á¹¹T3ÍøÂçЭÒéÇëÇó¾ÙÐй¥»÷ £¬ÀÖ³ÉʹÓøÃÎó²î¿ÉʵÏÖÔÚÄ¿µÄÖ÷»úÉÏÖ´ÐÐí§Òâ´úÂ롣ʹÓÃÁËOracle Coherence¿âµÄ²úÆ·ÊÜ´ËÎó²îÓ°Ïì £¬ÔÚWebLogic Server 11g Release£¨10.3.4£©¼°ÒÔÉϰ汾µÄ×°ÖðüÖÐĬÈϼ¯³ÉÁËOracle Coherence¿â¡£

http://blog.nsfocus.net/cve-2020-2555/

  • Spring-cloud-config-server·¾¶±éÀúÎó²î

¡¾Ðû²¼Ê±¼ä¡¿2020-03-06 22:00:00 GMT

¡¾¸ÅÊö¡¿¾ÅÓÎÀÏ¸ç¿Æ¼¼Çå¾²Ñо¿Ô±·¢Ã÷spring-cloud-config-server×é¼þÖб£´æÂ·¾¶±éÀúÎó²î£¨CVE-2020-5405£© £¬2ÔÂ26ÈÕSpring¹Ù·½Ðû²¼ÁËÎó²îͨ¸æ²¢ÖÂл¡£¹¥»÷ÕßʹÓôËÎó²î¿ÉÒÔʵÏÖĿ¼±éÀú £¬¶ÁȡδÊÚȨÎļþµÄÄÚÈÝ £¬ÇëÏà¹ØÓû§¾¡¿ìÉý¼¶spring-cloud-config-serverÖÁÐÞ¸´°æ±¾ £¬¶Ô´ËÎó²î¾ÙÐзÀ»¤¡£

http://blog.nsfocus.net/cve-2020-5405/

  • LinuxϵͳpppdÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¡¾Ðû²¼Ê±¼ä¡¿2020-03-06 22:00:00 GMT

¡¾¸ÅÊö¡¿3ÔÂ6ÈÕ £¬US-CERTÐû²¼ÁËÒ»¸ö¹ØÓÚÓ°ÏìPPP daemon(pppd)Èí¼þµÄ±£´æ17ÄêÖ®¾ÃµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²îµÄͨ¸æ £¬Ó°ÏìÏÕЩËùÓлùÓÚLinuxµÄ²Ù×÷ϵͳÒÔ¼°ÍøÂç×°±¸¹Ì¼þ¡£¸ÃÎó²îΪջ»º³åÒç³öÎó²î(CVE-2020-8597) £¬CVSSÆÀ·ÖΪ9.8·Ö£»pppdÖеÄeap.cÔÚ eap_requestºÍeap_responseº¯ÊýÖÐrhostname²ÎÊý±£´æ»º³åÇøÒç³ö £¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß·¢ËͶñÒâαÔìµÄEAP°ü £¬¿ÉÔÚÊÜÓ°ÏìµÄϵͳÖÐÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£

http://blog.nsfocus.net/cve-2020-8597/

¶þ¡¢ÈÈÃÅ×ÊѶ

  • Jackson-databind/FastjsonÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¡¾¸ÅÊö¡¿¿ËÈÕ £¬Jackson-databindÐÞ¸´ÁË2¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-9547/CVE-2020-9548£©¡£Õâ2¸öÎó²îÔ´ÓÚ2ÖÖеÄ×é¼þ£¨ibatis-sqlmapÒÔ¼°anteros-core£©Ê¹ÓøÃÎó²î¿ÉÒÔÈÆ¹ýºÚÃûµ¥ÏÞÖÆ £¬ÔÚÊܺ¦»úеÉÏÔ¶³ÌÖ´ÐдúÂë¡£ÁíÍâ £¬fastjsonÔÚʹÓÃÉÏÊöÊÜÓ°Ïì×é¼þʱ £¬Èô¿ªÆôÁËautoType¹¦Ð§£¨autoType¹¦Ð§Ä¬ÈϹرգ© £¬ÔòÒ²±£´æ¶ÔÓ¦Îó²î¡£

²Î¿¼£ºhttps://github.com/FasterXML/jackson-databind/issues/2634

  • Weblogic CoherenceÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¡¾¸ÅÊö¡¿¿ËÈÕ £¬¾ÅÓÎÀÏ¸ç¿Æ¼¼¼ì²âµ½ÓÐÍâÑóÑо¿Ô±Ðû²¼Á˹ØÓÚOracle Coherence·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-2555£©µÄϸ½Ú±¨¸æ¡£Oracle CoherenceÔÚWeblogic 12cºóµÄ°æ±¾ÖÐĬÈÏÓëWeblogic serverÒ»Æð×°Ö᣾ÅÓÎÀÏ¸ç¿Æ¼¼Ñо¿Ô±ÒѸ´ÏÖ¸ÃÎó²î £¬ËäÈ»OracleÔÚ½ñÄê1Ô·ݵÄÒªº¦²¹¶¡¸üУ¨Critical Patch Update£©ÖÐÒѾ­ÐÞ¸´Á˸ÃÎó²î £¬µ«¼øÓÚΣº¦½Ï´ó £¬½¨Òé¿Í»§ÊµÊ±¼ì²é²¢×°Öò¹¾ÙÐзÀ»¤¡£

²Î¿¼£ºhttps://www.zerodayinitiative.com/blog/2020/3/5/cve-2020-2555-rce-through-a-deserialization-bug-in-oracles-weblogic-server

  • MoleratsÏòÕþ¸®ºÍµçÐÅ×éÖ¯ÌṩºóÃÅ

¡¾¸ÅÊö¡¿MoleratsÍþв×é֯ʹÓÃÓã²æÊ½ÍøÂç´¹ÂÚ¹¥»÷ÏòÕþ¸®¡¢µçÐÅ×éÖ¯ÌṩSparkºóÃÅ £¬¸ÃºóÃÅ¿ÉÈù¥»÷ÕßÔÚÊÜѬȾϵͳÉÏ·­¿ªÓ¦ÓóÌÐò²¢Ö´ÐÐÏÂÁî¡£Molerats(ÓÖÃûGaza cybergang)ÊÇÒ»¸ö³öÓÚÕþÖÎÄîÍ·µÄÍþв×éÖ¯ £¬×Ô2012ÄêÒÔÀ´Ò»Ö±»îÔ¾ £¬¸Ã×éÖ¯µÄÊܺ¦ÕßÖ÷ÒªÔÚÖж«¡¢Å·ÖÞºÍÃÀ¹ú¡£

²Î¿¼£ºhttps://unit42.paloaltonetworks.com/molerats-delivers-spark-backdoor/

  • APT34×é֯ʹÓÃKarkoffÕë¶ÔÀè°ÍÄÛÕþ¸®

¡¾¸ÅÊö¡¿½üÆÚAPT34×éÖ¯Õë¶ÔÀè°ÍÄÛÕþ¸®¾ÙÐÐÍøÂçÌØ¹¤Ô˶¯ £¬Ô˶¯ÖÐʹÓÃжñÒâÈí¼þKarkoffʵÏÖÕì̽Âß¼­ £¬½«×îÖÕµÄÓÐÓøºÔØ·ÖÅɵ½Ìض¨Ä¿µÄ £¬Ê¹ÓÃMicrosoft Exchange Server×÷ΪͨѶÇþµÀ £¬ÍøÂçϵͳÐÅÏ¢¡¢ÓòÃû¡¢Ö÷»úÃûºÍÕýÔÚÔËÐеIJÙ×÷ϵͳ¡£APT34ÊÇÒ»¸öÒÁÀÊÍþв×éÖ¯ £¬ÖÁÉÙ´Ó2014Äê×îÏÈ»îÔ¾ £¬¸Ã×éÖ¯ÔÚÖж«Ìᳫ¹¥»÷Ô˶¯ £¬Ö÷ÒªÕë¶Ô½ðÈÚ¡¢Õþ¸®¡¢ÄÜÔ´¡¢»¯¹¤¡¢µçÐÅºÍÆäËûÐÐÒµ¡£Æ¾Ö¤»ù´¡Éèʩϸ½ÚÆÀ¹À¸Ã×é֯ΪÒÁÀÊÕþ¸®ÊÂÇé¡£

²Î¿¼£ºhttps://blog.yoroi.company/research/karkoff-2020-a-new-apt34-espionage-operation-involves-lebanon-government/

  • ³¯ÏÊKimsuky×éÖ¯Íþвº«¹úÉú³¤ÆäTTP

¡¾¸ÅÊö¡¿Kimsuky £¬Ò²±»³ÆÎªKimsuki¡¢Velvet Chollima £¬ÊÇÒ»¸ö¹éÊôÓÚ³¯ÏʵÄÍþв×éÖ¯ £¬ÖÁÉÙ´Ó2013Äê×îÏÈ»îÔ¾ £¬Õë¶Ôº«¹úÖÇÄÒÍÅ¡¢¹¤Òµ¡¢ºËµçÔËÓªÉ̺Íͳһ²¿µÈ¾ÙÐÐÌØ¹¤Ô˶¯¡£½üÆÚKimsuky×é֯ʹÓÃÒ»ÖÖжñÒâÈí¼þÖ²ÈëÎï¶Ôº«¹ú·¢¶¯ÏµÁй¥»÷Ô˶¯¡£

²Î¿¼£ºhttps://blog.yoroi.company/research/the-north-korean-kimsuky-apt-keeps-threatening-south-korea-evolving-its-ttps/

  • CIA¹¥»÷×éÖ¯£¨APT-C-39£©ºã¾Ã¶ÔÖйúÒªº¦ÁìÓòµÄÍøÂçÉøÍ¸¹¥»÷

¡¾¸ÅÊö¡¿ÃÀ¹úÖÐÑëÇ鱨¾ÖCIA¹¥»÷×éÖ¯£¨APT-C-39£©¶ÔÖйú¾ÙÐеij¤´ïʮһÄêµÄÍøÂç¹¥»÷ÉøÍ¸¡£ÔÚ´Ëʱ´ú £¬Öйúº½¿Õº½Ìì¡¢¿ÆÑлú¹¹¡¢Ê¯ÓÍÐÐÒµ¡¢´óÐÍ»¥ÁªÍø¹«Ë¾ÒÔ¼°Õþ¸®»ú¹¹µÈ¶à¸öµ¥Î»¾ùÔâµ½²î±ðˮƽµÄ¹¥»÷ £¬²¢Ö÷Òª¼¯ÖÐÔÚ±±¾©¡¢¹ã¶«¡¢Õã½­µÈÊ¡·Ý¡£

²Î¿¼£ºhttps://mil.huanqiu.com/article/3xHSlXNmuvU

?

ÄúµÄÁªÏµ·½·¨

*ÐÕÃû
*µ¥Î»Ãû³Æ
*ÁªÏµ·½·¨
*ÑéÖ¤Âë ¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
Ìá½»µ½ÓÊÏä

¹ºÖÃÈÈÏß

  • ¹ºÖÃ×Éѯ:

    400-818-6868-1

Ìá½»ÏîÄ¿ÐèÇó

½Ó´ý¼ÓÈë¾ÅÓÎÀÏ¸ç¿Æ¼¼ £¬³ÉΪÎÒÃǵÄÏàÖúͬ°é£¡
  • *ÇëÐÎòÄúµÄÐèÇó
  • *×îÖÕ¿Í»§Ãû³Æ
  • *ÏîÄ¿Ãû³Æ
  • Äú¸ÐÐËȤµÄ²úÆ·
  • ÏîĿԤËã
ÄúµÄÁªÏµ·½·¨
  • *ÐÕÃû
  • *ÁªÏµµç»°
  • *ÓÊÏä
  • *Ö°Îñ
  • *¹«Ë¾
  • *¶¼»á
  • *ÐÐÒµ
  • *ÑéÖ¤Âë ¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
  • Ìá½»µ½ÓÊÏä
¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾

·þÎñÖ§³Ö

ÖÇÄܿͷþ
ÖÇÄܿͷþ
¹ºÖÃ/ÊÛºóÊÖÒÕÎÊÌâ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
ÔÚÏßÌáµ¥|ÖÇÄÜÎÊ´ð|֪ʶ¿â
Ö§³ÖÈÈÏß
Ö§³ÖÈÈÏß
400-818-6868
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÉçÇø
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÉçÇø
×ÊÁÏÏÂÔØ|ÔÚÏßÎÊ´ð|ÊÖÒÕ½»Á÷

? 2025 NSFOCUS ¾ÅÓÎÀÏ¸ç¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ

ÍøÕ¾µØÍ¼